Control system, control method, and program

The integrated control system for touch and hands-free authentication ensures secure access control by discarding non-matching authentication results, enhancing security in access management systems.

JP2026014822APending Publication Date: 2026-01-29PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024116285
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-19
Publication Date
2026-01-29

Smart Images

  • Figure 2026014822000001_ABST
    Figure 2026014822000001_ABST
Patent Text Reader

Abstract

To improve security.SOLUTION: The first authentication result acquirer 111 acquires an authentication result of the first authenticator 104 that performs authentication based on the first information acquired by the first acquirer 102. The second authentication result acquirer 112 acquires an authentication result of the second authenticator 105 that performs authentication based on the second information acquired by the second acquirer 103. The control processing unit 113 executes, when a predetermined condition is satisfied, control processing of performing predetermined control related to the mobile object 20 on the basis of at least one of two authentication results corresponding to the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112. The control process is a process of performing predetermined control based on each of the two authentication results when the first information and the second information are not associated with the same moving object 20, and performing predetermined control based on one of the two authentication results and not performing predetermined control based on the other authentication result when the first information and the second information are associated with the same moving object.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a control system, a control method, and a program, and more particularly to a control system, a control method, and a program that perform predetermined control of a moving object. [Background technology]

[0002] Patent Document 1 describes a card reading device having a card, a specification switching means, an intrusion monitoring verification means, and a main control means. The card stores individual ID information of people permitted to enter and exit a room in the entry / exit control device specification, and stores information indicating this in the intrusion monitoring device specification. The reading means reads the information stored on the card. The specification switching means manually switches between the entry / exit control device specification and the intrusion monitoring device specification. Information indicating the intrusion monitoring specification is pre-stored in memory, and the intrusion monitoring verification means compares the information read by the reading means with the information stored in the memory and, if they match, outputs information to set or cancel the intrusion monitoring status. The main control means outputs the information read by the reading means as is when the entry / exit control device specification is set by the specification switching means, and outputs information to set or cancel the intrusion monitoring status from the intrusion monitoring control means when the intrusion monitoring device specification is set. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 7-160963 Summary of the Invention [Problem to be solved by the invention]

[0004] Although the card reading device in Patent Document 1 can perform both entry / exit management and intrusion monitoring, the user must perform an operation (touch operation) to touch the card to the reader in order for the card reading device to read the ID information on the card.

[0005] In recent years, hands-free authentication (reading of authentication information without touch operation) has become possible using wireless communication in a short-range wireless communication system such as UWB. Therefore, for example, it is conceivable to use a first authentication unit that requires a touch operation, such as the card reading device of Patent Document 1, in combination with a second authentication unit that performs hands-free authentication.

[0006] However, when the first authentication unit and the second authentication unit are used together, two authentication results are obtained for one user, and therefore, it is possible that one user may be allowed to enter the room based on one of the two authentication results obtained, while another unauthenticated user may be allowed to enter the room based on the other authentication result, which raises concerns about a reduction in security.

[0007] An object of the present disclosure is to provide a control system, a control method, and a program that can improve security. [Means for solving the problem]

[0008] A control system according to one aspect of the present disclosure includes a first authentication result acquisition unit, a second authentication result acquisition unit, and a control processing unit. The first authentication result acquisition unit acquires an authentication result of a first authentication unit that performs authentication based on first information acquired by the first acquisition unit, which is information associated with a mobile object. The second authentication result acquisition unit acquires an authentication result of a second authentication unit that performs authentication based on second information acquired by the second acquisition unit, which is information associated with the mobile object. The control processing unit executes a control process that performs predetermined control on the mobile object based on at least one of the authentication results acquired by the first authentication result acquisition unit and the authentication result acquired by the second authentication result acquisition unit, when a predetermined condition is satisfied. The control process is a process in which, when the first information and the second information are not associated with the same mobile body, the predetermined control is performed based on each of the authentication result acquired by the first authentication result acquisition unit and the authentication result acquired by the second authentication result acquisition unit, and, when the first information and the second information are associated with the same mobile body, the predetermined control is performed based on one of the authentication results acquired by the first authentication result acquisition unit and the authentication result acquired by the second authentication result acquisition unit, and the predetermined control is not performed based on the other authentication result.

[0009] A control method according to one aspect of the present disclosure includes a first authentication result acquisition step, a second authentication result acquisition step, and a control step. The first authentication result acquisition step acquires an authentication result of a first authentication unit that performs authentication based on first information, which is information associated with a mobile object and acquired by a first acquisition unit. The second authentication result acquisition step acquires an authentication result of a second authentication unit that performs authentication based on second information, which is information associated with the mobile object and acquired by a second acquisition unit. The control step executes a control process that performs predetermined control regarding the mobile object based on at least one of the authentication results acquired in the first authentication result acquisition step and the authentication result acquired in the second authentication result acquisition step, when a predetermined condition is satisfied. The control process is a process in which, when the first information and the second information are not associated with the same mobile body, the predetermined control is performed based on each of the authentication result acquired in the first authentication result acquisition step and the authentication result acquired in the second authentication result acquisition step, and, when the first information and the second information are associated with the same mobile body, the predetermined control is performed based on one of the authentication results acquired in the first authentication result acquisition step and the authentication result acquired in the second authentication result acquisition step, and the predetermined control is not performed based on the other authentication result.

[0010] A program according to one aspect of the present disclosure is a program for causing one or more processors to execute the control method. [Effects of the Invention]

[0011] The control system, control method, and program of the present disclosure have the effect of improving security. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is a block diagram of a control system according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a flowchart illustrating an outline of the operation of the control system. [Figure 3] FIG. 3 is a flowchart illustrating a control process included in the operation of the above embodiment. [Figure 4] FIG. 4 is a flowchart illustrating a specific example of processing for realizing the above operation. [Figure 5] FIG. 5 is a block diagram of a control system according to a modified example. [Figure 6] FIG. 6 is a flowchart illustrating a specific example of processing for realizing the operation of the control system according to the above modification. DETAILED DESCRIPTION OF THE INVENTION

[0013] A control system 100 according to an embodiment of the present disclosure will be described below with reference to Figures 1 to 4. Note that the specific communication methods, specific hardware, and specific numerical values ​​such as time given in the following description are merely examples and may be changed as appropriate.

[0014] (1) Overview First, an overview of a control system 100 according to this embodiment will be described with reference to Fig. 1. As shown in Fig. 1, the control system 100 is realized by a control device 1 alone. The control device 1 is installed together with a controlled device 30 near an access point AL1 to a predetermined area A1.

[0015] (1-1) Control device The control device 1 is a device that performs predetermined control related to the moving object 20.

[0016] (1-1-1) Mobile The mobile body 20 in this embodiment is an autonomously moving object, and is a general term for a human body and an autonomously moving robot (hereinafter, may be simply referred to as a "robot"). The mobile body 20 in this embodiment is basically a human body, that is, a user's body (hereinafter, may be simply referred to as a "user"), but may also be a robot.

[0017] (1-1-1a) Information terminal As shown in Fig. 1, the moving body 20 has an information terminal 201. The information terminal 201 in this embodiment is basically a mobile information terminal carried by a user. The mobile information terminal is, for example, a smartphone, a tablet terminal, a mobile phone, etc. However, the information terminal 201 may also be mounted on a robot.

[0018] (1-1-1b) Communication between the control device and the information terminal: Two types of wireless communication with different communication distances The control device 1 can communicate with the information terminal 201 held by the mobile object 20 by two types of wireless communication with different communication distances. In this embodiment, the two types of wireless communication with different communication distances are both short-range wireless communication, specifically, NFC (Near Field Communication) and Ultra Wide Band (UWB) wireless communication (hereinafter, sometimes referred to as "UWB wireless communication"). Note that NFC and UWB wireless communication will be described later.

[0019] (1-1-1c) Prescribed Control: Access Control The predetermined control in this embodiment includes control of access of the mobile object 20 to the predetermined area A1 (hereinafter, may be simply referred to as "access control"). Note that, as will be described in detail later, access to the predetermined area A1 may be, for example, access to the interior of the room (i.e., entering the room), but may also be access to the exterior of the room (i.e., leaving the room). The access control includes, for example, at least one of control of entry of a user into a room and control of leaving of a user from a room.

[0020] (1-1-1cA) Access permission and prohibition Access control includes permission and prohibition of access. Access control is performed, for example, based on a security policy preset for a predetermined area A1 using the result of authentication for the user. Access control based on the security policy may be, for example, control that allows the user to enter the predetermined area A1 when the result of authentication for the user includes a user ID, and that prohibits the user from entering the predetermined area A1 when the result of authentication for the user does not include a user ID.

[0021] (1-1-1cB) Different access control for each designated area When there are multiple predetermined areas A1, the security policy may be different for each predetermined area A1. Specifically, the access control based on the first security policy for the first room, which is one of the multiple predetermined areas A1, may be, for example, as described above, a control that allows the user to enter the first room when the authentication result for the user includes the user ID, and that prohibits the user from entering the first room when the authentication result for the user does not include the user ID.

[0022] In contrast, access control based on the second security policy for the second room, which is another one of the multiple specified areas A1, may be, for example, a control that allows the user to enter the second room if the result of authentication for the user includes attribute information indicating registered attributes (see "(3-10-1) First variant of authentication"), but prohibits the user from entering the second room if the result of authentication for the user does not include attribute information indicating registered attributes.

[0023] (1-1-1cC) Different access control for entry and exit When the access control includes both control of a user's entry into a room and control of a user's exit from a room, the control of entry and the control of exit may be different from each other. For example, the control of entry may be the same as the access control based on the second security policy, while the control of exit may be the same as the access control based on the first security policy.

[0024] In other words, the control of entry may be such that if the result of authentication for a user includes attribute information indicating a registered attribute, the user is permitted to enter the room, but if the result of authentication for a user does not include attribute information indicating a registered attribute, the user is prohibited from entering the room. In contrast, the control of exit may be such that if the result of authentication for a user includes a user ID, the user is permitted to leave the room, but if the result of authentication for a user does not include a user ID, the user is prohibited from leaving the room.

[0025] (1-2) Designated area The predetermined area A1 is a space that the moving body 20 can enter. The predetermined area A1 is, for example, the inside of a room (indoors), the inside of a building (indoors), or the inside of a site (inside the site). The predetermined area A1 may also be a part of a space indoors, or a part of a space on the site. The part of a space indoors is, for example, the entrance area of ​​a building, the elevator from the entrance area to each floor of the building, each floor, the corridors within a floor, or each room on a floor. The part of a space on the site is, for example, a garden within the site. The predetermined area A1 may also be, for example, the outside of a room (outdoors), the outside of a building (outdoors), or the outside of the site (outside the site).

[0026] (1-3) Access point The access location AL1 is a location through which the mobile object 20 passes when accessing the predetermined area A1. The access location AL1 is, for example, an entrance to the premises, an entrance to the interior of the building, or an entrance to the interior of the building, but it may also be an exit to the exterior of the premises, an exit to the exterior of the building, or the like. The entrance to the premises and the exit to the exterior of the building may be a common entrance (i.e., an entrance / exit to the premises). The entrance to the interior of the building and the exit to the exterior of the building may also be a common entrance (i.e., an entrance / exit to the room). The access location is provided with, for example, a door or a gate.

[0027] (1-3-1) Access to designated areas In this embodiment, access to the predetermined area A1 means entering the predetermined area A1. As described above, the predetermined area A1 may be, for example, within a premises, indoors, or inside a room, but may also be outside a premises, outdoors, or outdoors. Access to the predetermined area A1 may be, for example, entering within a premises, indoors, or inside a room, but may also be leaving the premises, outdoors, or outdoors.

[0028] In this embodiment, entering a premises or indoors (i.e., accessing the premises or indoors) may be referred to as "entering," and entering indoors (i.e., accessing the indoors) may be referred to as "entering." Furthermore, leaving a premises or outdoors (i.e., accessing the outdoors or outdoors) may be referred to as "exiting," and leaving outdoors (i.e., accessing the outdoors) may be referred to as "exiting."

[0029] (1-3-2) Access control mechanism The door or gate provided at the access point AL1 is equipped with an access control mechanism. The access control mechanism is a mechanism for realizing access control. The access control mechanism is, for example, a locking / unlocking mechanism of the door or an opening / closing mechanism of the door.

[0030] (1-4) Controlled device The controlled device 30 is a device that realizes access control by operating an access control mechanism under the control of the control device 1. The controlled device 30 is, for example, a lock control device 30a or a door control device 30b.

[0031] The lock control device 30a is a device that controls the locking and unlocking of the door in accordance with control information from the control device 1. The lock control device 30a operates under the control of the control device 1, thereby automatically locking and unlocking the door.

[0032] The door control device 30b is a device that controls the door opening and closing mechanism in accordance with control information from the control device 1. The lock control device 30a operates under the control of the control device 1, so that the door is automatically opened and closed.

[0033] (1-4-1) Communication between the control device and the controlled device As shown in FIG. 1, the control device 1 is communicably connected to the controlled device 30 via a communication medium 300.

[0034] (1-4-1a) Communication media In this embodiment, the communication medium 300 is a wired LAN (Local Area Network), but may be, for example, wireless communication such as a wireless LAN, or wired communication other than a LAN (see "(3-9) Modified Examples of Communication Medium").

[0035] (1-5) Main parts of the control device As shown in FIG. 1, the control device 1 includes a first authentication result acquisition unit 111, a second authentication result acquisition unit 112, and a control processing unit 113.

[0036] (1-5-1) First authentication result acquisition unit and authentication result The first authentication result acquisition unit 111 acquires the authentication result of the first authentication unit 104. The authentication result is the result of the authentication performed. In this embodiment, the authentication result includes a mobile object ID, an authentication time, and an authentication unit identifier.

[0037] (1-5-1a) Mobile ID The mobile entity ID is information for identifying a mobile entity, and may be, for example, "AA" for identifying mobile entity AA, or "BB" for identifying mobile entity BB.

[0038] (1-5-1b) Authentication time The authentication time is the time when authentication is performed. The authentication time may be, for example, "hh:mm:ss" which indicates the time "hh hours, mm minutes, ss seconds." The authentication time of the first authentication unit 104 and the authentication time of the second authentication unit 105 are basically different times, but may be the same time.

[0039] (1-5-1c) Authentication unit identifier The authentication unit identifier is information for identifying an authentication unit. The authentication unit identifier may be, for example, “1st” to identify the first authentication unit 104, or “2nd” to identify the second authentication unit 105.

[0040] (1-5-1d) Specific example of authentication result of the first authentication unit The mobile object ID included in the authentication result of the first authentication unit 104 may be, for example, "AA." The authentication time included in the authentication result of the first authentication unit 104 is the time when the first authentication unit 104 performed the authentication, and may be, for example, "10:25:30." The authentication unit identifier included in the authentication result of the first authentication unit 104 is the identifier of the first authentication unit 104 that obtained the authentication result, and may be, for example, "1st."

[0041] In this specific example, the authentication result of the first authentication unit 104 may be, for example, the sequence of the above contents, that is, "AA, 10:25:30, 1st."

[0042] (1-5-2) Second authentication result acquisition unit The second authentication result acquisition unit 112 acquires the authentication result of the second authentication unit 105 .

[0043] (1-5-2a) Example of authentication result of the second authentication unit The authentication result of the second authentication unit 105 may be, for example, "AA", 10:25:35, 2nd", or "BB, 10:25:37, 2nd".

[0044] (1-5-3) Control processing section The control processing unit 113 executes the control processing when a predetermined condition is satisfied.

[0045] (1-5-3a) Control processing The control process is a process of performing predetermined control. The predetermined control is control related to the mobile body 20. The predetermined control in this embodiment is the access control as described above, that is, control of the mobile body 20's access to the predetermined area A1 based on a security policy previously set for the predetermined area A1.

[0046] More specifically, the control process is a process of performing predetermined control such as access control based on at least one of the authentication results obtained by the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112. The control process is basically a process of performing predetermined control on the mobile object 20 corresponding to the first information based on the authentication result obtained by the first authentication result acquisition unit 111 when the first authentication result acquisition unit 111 acquires the authentication result, and performing predetermined control on the mobile object 20 corresponding to the second information based on the authentication result obtained by the second authentication result acquisition unit 112 when the second authentication result acquisition unit 112 acquires the authentication result.

[0047] The control processing in this embodiment is processing for performing predetermined control based on each of the authentication results acquired by the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 when the first information and the second information are not associated with the same mobile body 20. Furthermore, when the first information and the second information are associated with the same mobile body 20, the control processing is processing for performing predetermined control based on one of the authentication results acquired by the first authentication result acquisition unit 111 and the authentication result acquired by the second authentication result acquisition unit 112, but not performing predetermined control based on the other authentication result.

[0048] (1-5-3b) Determining whether the data is associated with the same mobile entity 20 If the two moving body IDs acquired from the first information and the second information, respectively, are the same ID, it is determined that the first information and the second information are associated with the same moving body 20.

[0049] Two moving body IDs are the same ID basically when the two moving body IDs match each other. However, even if the two moving body IDs do not match each other, if they are associated with the same moving body 20, the two moving body IDs are considered to be the same ID. For example, when the two moving body IDs are two different types of moving body IDs, the two different types of moving body IDs may be converted into two moving body IDs of the same type using a conversion table (see "(2-2-3) Control Device"). Then, if the two converted moving body IDs match each other, the two different types of moving body IDs before conversion may be determined to be the same ID.

[0050] (1-5-3bA) Two authentication results The two authentication results, the authentication result by the first authentication result acquisition unit 111 and the authentication result by the second authentication result acquisition unit 112, are basically acquired one after the other, but may also be acquired simultaneously.

[0051] (1-5-3bB) Two specific examples of authentication results A first specific example of two authentication results acquired successively by the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 is the authentication result "AA, 10:25:30, 1st" of the first authentication unit 104 and the first authentication result "AA", 10:25:35, 2nd" of the second authentication unit 105. A second specific example of similar two authentication results is the authentication result "AA, 10:25:30, 1st" of the first authentication unit 104 and the second authentication result "BB, 10:25:37, 2nd" of the second authentication unit 105.

[0052] (1-5-3c) One-sided authentication result One of the authentication results acquired by the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 is the authentication result to be used for predetermined control when the first information and the second information are associated with the same mobile object 20 (for example, of the first and second specific examples of the above two authentication results, the first specific example applies and the second specific example does not apply). The one of the authentication results is basically the authentication result acquired earlier (earlier acquired authentication result: for example, "AA, 10:25:30, 1st") of the two authentication results acquired successively by the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 (for example, the first specific example of the two authentication results), but may also be the authentication result acquired later (later acquired authentication result: for example, "AA", 10:25:35, 2nd").

[0053] (1-5-3d) Other authentication results Therefore, the other authentication result is the authentication result that is not used for the specified control when the first information and the second information are associated with the same mobile body 20, and is basically the later-acquired authentication result (e.g., "AA", 10:25:35, 2nd"), but it may also be the earlier-acquired authentication result (e.g., "AA, 10:25:30, 1st"). Furthermore, when the first information and the second information are associated with the same mobile body 20, one of the two authentication results acquired simultaneously by the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 may correspond to one authentication result and the other authentication result.

[0054] (1-5-3e) Specified conditions The predetermined condition in this embodiment is that one of the first authentication unit 104 and the second authentication unit 105 performs authentication within a predetermined time after the other authentication unit performs authentication. In this embodiment, the predetermined time is 10 seconds. However, the predetermined time may be, for example, 5 seconds, 20 seconds, 30 seconds, or 1 minute.

[0055] When the above-mentioned predetermined condition is satisfied, the control processing unit 113 determines whether the first information and the second information are associated with the same mobile body 20, and when it determines that the first information and the second information are associated with the same mobile body 20, it performs predetermined control based on the authentication result of one of the first authentication unit 104 and the second authentication unit 105, and discards the authentication result of the other authentication unit. Note that discarding is not limited to erasing the authentication result from memory, but may also mean putting the authentication result in memory into a state where it is not used for predetermined control. Predetermined control based on the discarded authentication result is not performed.

[0056] In detail, when the above-mentioned specified condition is satisfied, that is, when one of the first authentication unit 104 and the second authentication unit 105 performs authentication and then the other authentication unit performs authentication within a specified time, and two authentication results corresponding to the first authentication unit 104 and the second authentication unit 105 are obtained one after the other within a specified time (for example, the first and second specific examples of the above-mentioned two authentication results apply), the control processing unit 113 determines whether the first information and the second information are associated with the same mobile body 20 (for example, whether the two mobile body IDs corresponding to the first information and the second information match each other). Then, when the first information and the second information are associated with the same mobile body 20 (for example, of the first and second specific examples of the above two authentication results, the first specific example applies and the second specific example does not), the control processing unit 113 may perform a predetermined control based on one of the two authentication results (the first specific example of the two authentication results) obtained (for example, the earlier acquired authentication result "AA, 10:25:30, 1st"), and discard the other authentication result (for example, the later acquired authentication result "AA", 10:25:35, 2nd").

[0057] If the control processing unit 113 determines that the first information and the second information are not associated with the same mobile body 20 (for example, the two mobile body IDs corresponding to the first information and the second information do not match each other), it performs both predetermined control based on the authentication result of one authentication unit and predetermined control based on the authentication result of the other authentication unit.

[0058] In addition, if a predetermined time has passed since one of the first authentication unit 104 and the second authentication unit 105 performed authentication, but the other authentication unit does not perform authentication, the above-mentioned predetermined condition is not met, and the control processing unit 113, for example, does not determine whether the first information and the second information are associated with the same mobile body 20, but performs predetermined control based on the authentication result of the authentication unit that performed authentication.

[0059] Furthermore, if one authentication unit performs authentication after a predetermined time has elapsed since the other authentication unit performed authentication, the predetermined condition is not satisfied, and therefore it is not necessary to determine whether the first information and the second information are associated with the same mobile object 20. The control processing unit 113 not only performs predetermined control based on the authentication result of the one authentication unit, i.e., the authentication unit that performed authentication first, but also performs predetermined control based on the authentication result of the other authentication unit, i.e., the authentication unit that performed authentication later.

[0060] According to the above-mentioned predetermined conditions, i.e., the predetermined conditions including the time difference between the two authentication times, the authentication time when the first authentication unit 104 performed the authentication and the authentication time when the second authentication unit 105 performed the authentication, it becomes possible to perform predetermined control based on only one of the authentication results for two authentication results performed by the first authentication unit 104 and the second authentication unit 105 within a predetermined time difference.

[0061] As a specific example, assume a situation in which a predetermined area A1 is indoors, an access point AL1 is an entrance to the indoors, a mobile object 20 is a user, and the control system 100 controls (allows or prohibits) the user's entry into the indoors. The authentication by the first authentication unit 104 is authentication by NFC, and the authentication by the second authentication unit 105 is authentication by UWB wireless communication. In this case, when a user carrying a smartphone (for example, a user identified by a mobile object ID "AA") approaches the entrance of a building, first, when the smartphone enters the communication range of UWB wireless communication (first time point), second information is acquired from the smartphone, and the second authentication unit 105 performs authentication based on the second information and acquires an authentication result (for example, a pre-acquired authentication result "AA, 10:25:30, 1st"). Then, when the smartphone enters the NFC communication range (for example, at the second time point, 5 seconds after the first time point), the first information is acquired from the smartphone, and the first authentication unit 104 performs authentication based on the first information and acquires the authentication result (for example, the later acquired authentication result “AA”, 10:25:35, 2nd)).

[0062] That is, in this specific example, two authentication results are acquired for one user identified by the mobile entity ID "AA" with a time difference of five seconds. Therefore, if the control processing unit 113 does not perform the control processing, immediately after the first user enters, another user walking behind the first user may be able to enter the building even if the other user is not authenticated, for example, because the other user does not have a smartphone. However, the control processing unit 113 determines that the mobile entity IDs are the same between the two authentication results and that the time difference between the authentication times is "5 seconds," which is less than the predetermined time of "10 seconds." Then, based on these determination results, the control processing performs predetermined control based on one of the two authentication results (e.g., the earlier-acquired authentication result "AA, 10:25:30, 1st") and discards the other authentication result (e.g., the later-acquired authentication result "AA," 10:25:35, 2nd"), thereby reducing the possibility that another unauthenticated user may enter after the first user enters.

[0063] In other words, even if the two authentication results by the first authentication unit 104 and the second authentication unit 105 are authentication results for the same mobile body 20, if the time difference between the two authentication times corresponding to the two authentication results exceeds a predetermined time, predetermined control can be performed based on each of the two authentication results.

[0064] For example, in the above specific example, assume that a user identified by mobile ID "AA" is permitted to enter a building based on the previously acquired authentication result "AA, 10:25:30, 1st" acquired by the first authentication unit 104, and after entering the building, the same user exits, and then re-enters one hour after the previous entry. At the time of re-entry, the second authentication unit 105 acquires a later acquired authentication result "AA, 11:25:30, 2nd".

[0065] In this case, if the specified condition does not include the item regarding the time difference between authentication times, "the time difference is within a specified time," then since the mobile IDs of the two authentication results, the earlier acquired authentication result "AA, 10:25:30, 1st" acquired by the first authentication unit 104 at the time of the previous entry and the later acquired authentication result "AA, 11:25:30, 2nd" acquired by the second authentication unit 105 at the time of re-entry, are the same, the later acquired authentication result "AA, 11:25:30, 2nd" will be discarded, making it difficult for the same user to re-enter.

[0066] However, in this specific example, the predetermined condition includes a clause regarding the time difference between authentication times, "the time difference is within a predetermined time," so the control process determines that the time difference between the authentication times of the earlier-acquired authentication result "AA, 10:25:30, 1st" and the later-acquired authentication result "AA, 11:25:30, 2nd" for the same user is "1 hour," which exceeds the predetermined time of "10 seconds." As a result, the same user is permitted to re-enter the building based on the later-acquired authentication result "AA, 11:25:30, 2nd."

[0067] Furthermore, by including in the specified condition an item regarding the time difference between the authentication times, "the first authentication unit and the second authentication unit each performed authentication," in addition to an item regarding the two authentication unit identifiers corresponding to the two authentication results, "the time difference is within a specified time," it is possible to improve security while avoiding a situation in which it becomes difficult to perform predetermined control on a mobile object that has undergone predetermined control based on the authentication result of one authentication unit, except for the predetermined control based on the authentication result of the other authentication unit, i.e., a situation in which the authentication result of the authentication unit corresponding to the first predetermined control cannot be used for the predetermined control from the second time onwards.

[0068] For example, in the above specific example, if a user identified by mobile ID "AA" is permitted to enter indoors at the first time of entry based on the pre-acquired authentication result "AA, 10:25:30, 1st" acquired by the first authentication unit 104, the predetermined condition includes an item related to the authentication unit identifier, "authentication was performed by both the first authentication unit and the second authentication unit," and therefore, among one or more authentication results acquired at the second or subsequent entry, any authentication result that includes the same authentication unit identifier "1st" as the authentication unit identifier "1st" included in the pre-acquired authentication result "AA, 10:25:30, 1st" is discarded. Therefore, at the second or subsequent entry, the user identified by mobile ID "AA" will only be able to enter indoors with an authentication result that includes an authentication unit identifier "2nd" that is different from the authentication unit identifier "1st" included in the pre-acquired authentication result "AA, 10:25:30, 1st."

[0069] In contrast, by including in the predetermined condition an item regarding the time difference between authentication times, "the time difference is within a predetermined time," in addition to an item regarding the authentication unit identifier, "authentication has been performed by each of the first and second authentication units," authentication results with a time difference exceeding the predetermined time, among one or more authentication results obtained upon second or subsequent entry, even if they contain the same authentication unit identifier "1st," will not be discarded. This makes it possible to avoid a situation where, upon re-entry by the same user, entry is only possible with an authentication result containing an authentication unit identifier different from the authentication unit identifier contained in the authentication result used for the previous entry.

[0070] (1-6) Advantages According to the above configuration of this embodiment, in a control system 100 configured solely with the control device 1, if two authentication results obtained successively by the first authentication unit 104 and the second authentication unit 105 are authentication results for the same mobile body 20, only predetermined control based on one of the authentication results is performed, thereby reducing the possibility of predetermined control based on the other authentication result being performed on another mobile body, thereby improving security.

[0071] (2) Details Next, the control system 100 (control device 1) of this embodiment will be described in detail. In the following description, matters that have already been explained in the overview will be omitted or simplified.

[0072] (2-1) Details of the control device 1, the control system 100 (control device 1) specifically includes a communication unit 101, an authentication unit 10, a processing unit 11, and an output unit 12. The communication unit 101 includes a first communication unit 101a and a second communication unit 101b. The authentication unit 10 includes a first acquisition unit 102 and a first authentication unit 104, and a second acquisition unit 103 and a second authentication unit 105. The processing unit 11 includes a first authentication result acquisition unit 111, a second authentication result acquisition unit 112, a control processing unit 113, and a position related information acquisition unit 114.

[0073] (2-1-1) Communications Department The communication unit 101 communicates with the information terminal 201 held by the mobile object 20. The communication of the communication unit 101 is basically wireless communication. The communication unit 101 performs various types of wireless communication. The various types of wireless communication include, for example, wireless communication by a first communication unit 101a and wireless communication by a second communication unit 101b.

[0074] The various types of wireless communication include UWB wireless communication. By including UWB wireless communication in the various types of wireless communication performed by the communication unit 101, it becomes possible to acquire at least one of the first information and the second information from the information terminal 201 located within a short distance of the communication unit 101, approximately several meters. Furthermore, UWB wireless communication makes it possible to acquire, with a resolution of approximately several centimeters, location-related information regarding at least one of the distance between the communication unit 101 and the information terminal 201 and the location of the information terminal 201.

[0075] (2-1-1a) First Communications Department The first communication unit 101a receives at least one of the first information and the second information via wireless communication from the information terminal 201. The first communication unit 101a in this embodiment receives the first information from the information terminal 201 via wireless communication.

[0076] The wireless communication of the first communication unit 101a is basically a wireless communication different from UWB wireless communication.

[0077] Specifically, the wireless communication of the first communication unit 101a in this embodiment is NFC. The first communication unit 101a receives, for example, the first information from the information terminal 201 of the mobile object 20 located near the access point AL1 via NFC.

[0078] (2-1-1b) Second Communications Department The second communication unit 101b performs UWB wireless communication with the information terminal 201.

[0079] The second communication unit 101b receives at least one of the first information and the second information from the information terminal 201 via UWB wireless communication.

[0080] The second communication unit 101b of this embodiment receives the second information by UWB wireless communication from the information terminal 201. For example, the second communication unit 101b receives the second information by UWB wireless communication from the information terminal 201 of the mobile object 20 located near the access point AL1.

[0081] (2-1-1c) First wireless communication and second wireless communication One of the first acquisition unit 102 and the second acquisition unit 103 acquires the first information or the second information corresponding to the one of the acquisition units through a first wireless communication. The first wireless communication is a wireless communication having a communication range of a communication distance equal to or less than a first reference value.

[0082] The other of the first acquisition unit 102 and the second acquisition unit 103 acquires the first information or the second information corresponding to the other acquisition unit through the second wireless communication. The second wireless communication is wireless communication having a communication range of a communication distance equal to or less than a second reference value that is greater than the first reference value.

[0083] (2-1-1d) Specific examples of combinations of the first communication unit and the second communication unit and the first communication unit and the second communication unit In this embodiment, the first acquisition unit 102 acquires the first information through the first wireless communication, and the second acquisition unit 103 acquires the second information through the second wireless communication. The first wireless communication is NFC communication with a communication distance equal to or less than a first reference value. The second wireless communication is UWB wireless communication with a communication range equal to or less than a second reference value that is greater than the first reference value.

[0084] (2-1-1e) Advantages of the Communications Department According to the above configuration of this embodiment, the area in which information can be obtained from the information terminal 201 can be expanded by using the first wireless communication and the second wireless communication with different communication distances, for example, NFC and UWB wireless communication.

[0085] Furthermore, the NFC of the first communication unit 101a enables acquisition of the first information from the information terminal 201, while the UWB wireless communication of the second communication unit 101b enables acquisition of the second information from the information terminal 201. Furthermore, the UWB wireless communication of the second communication unit 101b enables detection of the position of the information terminal 201 with a resolution of about several centimeters.

[0086] (2-1-2) Authentication section The authentication unit 10 performs various types of authentication, such as authentication of the mobile object 20 by each of a first authentication unit 104 and a second authentication unit 105 (both of which will be described later).

[0087] Authentication means at least identifying the mobile object 20. Authentication includes, for example, acquiring authentication information from the communication unit 101 that has received authentication information (e.g., first information and second information) from the information terminal 201 held by the mobile object 20. Authentication in this embodiment means acquiring a mobile object ID from the authentication information (e.g., each of the first information and second information) acquired from the communication unit 101.

[0088] Specifically, the authentication may include obtaining a mobile entity ID corresponding to the authentication information based on correspondence information in a memory (e.g., a set of pairs of authentication information and mobile entity IDs, described below). However, if the authentication information is a mobile entity ID, the correspondence information is not required.

[0089] The authentication may further include identifying attributes of the mobile unit 20 based on a comparison between the acquired authentication information and pre-registered authentication information (hereinafter, sometimes referred to as "registered authentication information") and acquiring attribute information indicating the identification result (see "(3-10-1) First Modified Example of Authentication"). Alternatively, the authentication may include biometric authentication using biometric information (see "(3-10-2) Second Modified Example of Authentication").

[0090] Authentication is performed based on various algorithms, such as the algorithm for obtaining a mobile ID from authentication information, an algorithm that includes comparing the obtained authentication information with registered authentication information, and an algorithm that uses biometric information, as described above.

[0091] (2-1-2a) First Acquisition Unit and First Authentication Unit The first acquisition unit 102 acquires the first information.

[0092] The first information is information for authenticating the mobile body 20. The first information is information associated with the mobile body 20. The mobile body 20 is a human body (user) or a robot.

[0093] The first information is, for example, information linked to a mobile object ID. Specifically, the first information is, for example, a mobile object ID or a terminal identifier.

[0094] The mobile body ID is information for identifying the mobile body 20, such as an email address assigned to the mobile body 20, or a telephone number of the information terminal 201 held by the mobile body 20. The terminal identifier is information for identifying the information terminal 201 held by the mobile body 20, such as a MAC address.

[0095] The first acquisition unit 102 acquires first information based on a signal received by the first communication unit 101a through near field communication such as NFC.

[0096] The first authentication unit 104 performs authentication based on the first information acquired by the first acquisition unit 102 .

[0097] The authentication performed by the first authentication unit 104 is based on a predetermined algorithm. The authentication algorithm used by the first authentication unit 104 is, for example, an algorithm for acquiring a mobile object ID from the first information.

[0098] (2-1-2b) Second Acquisition Unit and Second Authentication Unit The second acquisition unit 103 acquires the second information.

[0099] The second information is information for authenticating the mobile object 20. The second information is information associated with the mobile object 20.

[0100] The moving body 20 associated with the second information may be a different moving body 20 from the moving body 20 associated with the first information, or may be the same moving body 20. In other words, the first information and the second information may be information associated with the same moving body 20, or may be information associated with different moving bodies 20.

[0101] The second information is, for example, information linked to a mobile object ID, similar to the first information. Note that, hereinafter, information for authenticating the mobile object 20, such as the first information and the second information, may be collectively referred to as "authentication information."

[0102] The second acquisition unit 103 acquires the second information based on a signal received by the second communication unit 101b via UWB wireless communication (described later).

[0103] The second authentication unit 105 performs authentication based on the second information acquired by the second acquisition unit 103 .

[0104] The authentication performed by the second authentication unit 105 is based on a predetermined algorithm. In this embodiment, the authentication algorithm used by the second authentication unit 105 may be the same as or different from the authentication algorithm used by the first authentication unit 104.

[0105] In this embodiment, the authentication algorithm of the second authentication unit 105 is the same type of algorithm as the authentication algorithm of the first authentication unit 104, and specifically, is an algorithm for acquiring a mobile object ID from the second information. However, the authentication algorithm of the second authentication unit 105 may be, for example, an algorithm that includes a comparison between the acquired second information and registered second information.

[0106] (2-1-2c) How to obtain authentication information The first acquisition unit 102 of this embodiment acquires the first information by a first method. The first method is, for example, an acquisition method by wireless communication, preferably an acquisition method by short-range wireless communication. The first method in this embodiment is an acquisition method by NFC, which is a type of short-range wireless communication.

[0107] The second acquisition unit 103 of this embodiment acquires the second information by a second method, which is different from the first method.

[0108] The first method and the second method are basically acquisition methods using different types of wireless communication. When the first method is short-range wireless communication, the second method is, for example, an acquisition method using wireless communication other than short-range wireless communication. Wireless communication other than short-range wireless communication is wireless communication with a longer communication distance than long-range wireless communication, and specifically includes communication via a wireless LAN or wide-area wireless communication such as a mobile phone network.

[0109] When the first method is NFC, the second method is, for example, an acquisition method using short-range wireless communication other than NFC. Short-range wireless communication other than NFC is, for example, Bluetooth (registered trademark) or UWB wireless communication. The second method in this embodiment is UWB wireless communication.

[0110] However, one of the first and second methods may be wireless communication and the other may be wired communication.Furthermore, the first and second methods may be different types of wired communication.

[0111] According to the above configuration of this embodiment, the first information and the second information can be acquired by the first method and the second method that are suited to them, respectively.

[0112] (2-1-2d) Where authentication information is obtained by the first and second methods At least one of the first and second methods is a method of obtaining information corresponding to at least one of the first and second information from a communication unit 101 that performs wireless communication with an information terminal 201 possessed by a mobile body 20.

[0113] In this embodiment, the first method is a method of acquiring first information from the first communication unit 101a, and the second method is a method of acquiring second information from the second communication unit 101b.

[0114] According to the above configuration of this embodiment, the first information can be acquired via the first communication unit 101a that communicates with the information terminal 201 held by the mobile body 20, and the second information can be acquired via the second communication unit 101b that communicates with the information terminal 201 held by the mobile body 20.

[0115] Furthermore, since the first method is an acquisition method using NFC and the second method is an acquisition method using UWB wireless communication, it is possible to acquire first information from the information terminal 201 via the first communication unit 101a that performs NFC, and to acquire second information via the second communication unit 101b that performs UWB wireless communication.

[0116] (2-1-2e) Acquisition source of authentication information of the first acquisition unit and the second acquisition unit At least one of the first acquisition unit 102 and the second acquisition unit 103 acquires, from the communication unit 101, the first information and the second information that corresponds to the at least one of the acquisition units.

[0117] In this embodiment, the first acquisition unit 102 acquires the first information from the communication unit 101, and the second acquisition unit 103 acquires the second information from the communication unit 101. As a result, at least one of the first information and the second information can be acquired via the communication unit 101, which communicates with the information terminal 201 held by the mobile object 20.

[0118] (2-1-3) Processing section The processing unit 11 performs various types of processing. The various types of processing are, for example, the processing of the first authentication result acquisition unit 111, the second authentication result acquisition unit 112, and the control processing unit 113 (all of which have been described above), and the position-related information acquisition unit 114 (described below). The processing unit 11 also performs, for example, various determinations that will be explained using flowcharts.

[0119] Other processing by the processing unit 11 will be explained as appropriate.

[0120] (2-1-3a) Control process details: Output of control information The control processing of the control processing unit 113 includes outputting control information.

[0121] The control information is information for a predetermined control. For example, the control information is information for causing the controlled device 30 to perform a predetermined control. The control processing unit 113 outputs the control information via the output unit 12 (described later).

[0122] By outputting such control information, it is possible to cause at least one of an external device of the control system 100 and an internal device of the control system 100 to perform predetermined control.

[0123] (2-1-3b) First example of prescribed control: Access control The predetermined control in this embodiment includes access control, which is control that permits or prohibits the mobile object 20 from accessing the predetermined area A1 (for example, at least one of the user's entry into the room and the user's exit from the room), as described above.

[0124] The control process in this embodiment includes outputting access control information, which is information for causing the lock control device 30a or the door control device 30b to perform access control.

[0125] The lock control device 30a is a device that controls the locking and unlocking of a door provided at an access point AL1 to a predetermined area A1 such as a room.

[0126] The door control device 30b is a device that controls the opening and closing of a door such as an automatic door provided at an access point AL1 to a predetermined area A1 such as inside a building.

[0127] According to this example, by outputting control information to the lock control device 30a or the door control device 30b, the lock control device 30a or the door control device 30b can be made to perform access control.

[0128] In detail, when two authentication results acquired successively by the first authentication unit 104 and the second authentication unit 105 are authentication results for the same mobile object 20, access control based on one of the authentication results (for example, permission to access a predetermined area A1) is performed, thereby reducing the possibility that access control based on the other authentication result will be performed on another mobile object, thereby improving security.

[0129] (2-1-3c) Second specific example of predetermined control: output control of history information The control process of this embodiment includes control of the output of history information.

[0130] History information is information relating to the history of a predetermined control. History information is, for example, information relating to the history of access control. Specifically, the history information is information indicating at least one of the following numbers (or the number of times): the number of mobile objects 20 permitted to access the predetermined area A1 (or the number of times permitted), and the number of mobile objects 20 prohibited from accessing the predetermined area A1 (or the number of times prohibited).

[0131] The history information may be, for example, time series data of the authentication results of at least one of the first authentication unit 104 and the second authentication unit 105. In this specific example, the history information includes time series data of the authentication results of the first authentication unit 104 and time series data of the authentication results of the second authentication unit 105.

[0132] The control processing unit 113 controls the output of history information via the output unit 12 (described later).

[0133] Output of historical information includes, for example, at least one of transmitting the historical information to an external recording device via the communication medium 300, recording the historical information on a recording medium within the control system 100, and displaying the historical information on a display inside or outside the control system 100.

[0134] The control processing unit 113 controls the output of history information (hereinafter, may be referred to as "output control of history information") via the output unit 12 (described later). The output control of history information means, for example, recording the history information in an external recording device, recording it in an internal recording medium, displaying it on an internal display, or displaying it on an external display.

[0135] According to this example, various types of history information can be recorded in at least one of an external recording device and an internal recording medium, and can be displayed on an internal or external display.

[0136] (2-1-3d) Location-related information acquisition unit The location related information acquisition unit 114 acquires location related information.

[0137] (2-1-3dA) Location-related information The position-related information is information relating to the positional relationship between the second communication unit 101b and the information terminal 201. The position-related information is used for predetermined control, for example, access control.

[0138] The positional relationship is, for example, the distance between second communication unit 101b and information terminal 201, and the relative position of information terminal 201 with respect to second communication unit 101b. If the absolute position (for example, latitude and longitude or coordinates) of second communication unit 101b is known, it is possible to calculate the absolute position of information terminal 201 based on the relative position of information terminal 201 with respect to second communication unit 101b.

[0139] The position-related information is, for example, information relating to at least one of the distance between the second communication unit 101b and the information terminal 201 and the position of the information terminal 201. Note that the position of the information terminal 201 may be the relative position of the information terminal 201 with respect to the second communication unit 101b, or the absolute position of the information terminal 201.

[0140] (2-1-3dB) Location-related information details: location information, distance information, etc. The position-related information includes, for example, position information and distance information. The position information is information (for example, coordinates) relating to the position of the mobile object 20 or the information terminal 201. The position information in this embodiment is information (for example, coordinates with the position of the second wireless communication module as the origin) relating to the position of the information terminal 201 relative to the second communication unit 101b (more specifically, the second wireless communication module that realizes the second communication unit 101b: described later).

[0141] The distance information is information relating to the distance between the second communication unit 101b and the information terminal 201. The distance information is, for example, information indicating the distance between the second communication unit 101b and the information terminal 201. Alternatively, the distance information may be information indicating the distance from the mobile object 20 to the access point AL1.

[0142] The position-related information may further include position change information. The position change information is information relating to a change in the position of the moving object 20 or the information terminal 201. The position change information is information indicating, for example, the moving direction and speed of the information terminal 201.

[0143] (2-1-3dC) Access control based on location-related information The control processing unit 113 performs access control based on the location-related information acquired by the location-related information acquisition unit 114. Specifically, the control processing unit 113 may lock and unlock the door via the lock control device 30a, or close and open the door via the door control device 30b, based on the acquired location information or distance information, for example. Furthermore, by taking location change information into consideration during access control, it is possible to ensure accuracy in the execution timing of locking and unlocking the door, or closing and opening the door via the door control device 30b.

[0144] According to the above configuration of this embodiment, UWB wireless communication by the second communication unit 101b makes it possible to obtain distance information regarding the distance between the second communication unit 101b and the information terminal 201, and location information regarding the location of the information terminal 201, with a resolution of approximately a few centimeters.

[0145] (2-1-3dD) How to obtain location-related information The location-related information acquisition unit 114 acquires the location-related information using signals transmitted and received in the second wireless communication. For example, the location information of the information terminal 201 may be acquired using a received signal strength indicator (RSSI) of a signal received by the second communication unit 101b from the information terminal 201. By acquiring the location-related information using signals transmitted and received in the second wireless communication, which has a long communication distance, it is possible to expand the area in which the location-related information can be acquired.

[0146] The position-related information acquisition unit 114 of this embodiment acquires position-related information using signals transmitted and received via UWB wireless communication.

[0147] Specifically, the location-related information acquisition unit 114 acquires location-related information using signals transmitted and received by the second communication unit 101b via UWB wireless communication between the information terminal 201 carried by the mobile object 20 located near the predetermined area A1. Note that the vicinity of the predetermined area A1 is within a range equivalent to the communication distance of the UWB wireless communication.

[0148] By acquiring location-related information using signals transmitted and received via UWB wireless communication, it is possible to expand the area in which location-related information can be acquired while improving the resolution of the location-related information.

[0149] (2-1-4) Output section The output unit 12 outputs various types of information, such as control information and position-related information.

[0150] The output of the output unit 12 is, for example, transmission to an external device, display on a display, recording on a recording medium, etc. In this embodiment, the external device is the controlled device 30, but may be a server connected to the communication medium 300. In this embodiment, the display is a display within the control system 100, but may be an external display connected to the communication medium 300. In this embodiment, the recording medium is a recording medium within the control system 100, but may be a recording medium of an external recording device connected to the communication medium 300.

[0151] Under the control of the control processing unit 113, the output unit 12 transmits control information such as access control information for predetermined controls such as access control to a controlled device 30, such as a lock control device 30a or a door control device 30b, via a communication medium 300.

[0152] In addition, under the control of the control processing unit 113, the output unit 12 controls the transmission of history information to an external recording device via the communication medium 300, the recording of history information to a recording medium within the control system 100, and the display of history information on a display inside or outside the control system 100.

[0153] (2-2) Hardware (2-2-1) Information terminal The information terminal 201 has two types of wireless communication modules, a processor, and a memory. One of the two types of wireless communication modules (first wireless communication module) realizes first wireless communication (in this embodiment, short-range wireless communication such as NFC) with the first communication unit 101a. The other of the two types of wireless communication modules (second wireless communication module) realizes second wireless communication (in this embodiment, UWB wireless communication) with the second communication unit 101b.

[0154] The information terminal 201 may further include a communication module for performing communication via the communication medium 300 (in this embodiment, wired communication via a wired LAN).

[0155] The memory stores various types of information and programs including first information and second information, and the processor works in cooperation with various communication modules to operate based on the programs and various types of information stored in the memory, thereby realizing the functions of the information terminal 201.

[0156] (2-2-2) Robot A robot, which is a type of moving body 20, has a movement mechanism including wheels and motors for driving the wheels, a detection circuit including an image sensor, and a control circuit that controls the running mechanism based on the output of the detection circuit to achieve autonomous movement. The robot is equipped with an information terminal 201.

[0157] (2-2-3) Control device The control device 1 includes, for example, two types of wireless communication modules (in this embodiment, a first wireless communication module and a second wireless communication module) that are the same as the two types of wireless communication modules included in the information terminal 201, a communication module for performing communication via a communication medium 300 (in this embodiment, wired communication via a wired LAN), a processor, and a memory. The first wireless communication module realizes the function of a first communication unit 101a. The second wireless communication module realizes the function of a second communication unit 101b.

[0158] The memory stores various information such as correspondence information and programs. The correspondence information is information relating to the correspondence between authentication information and mobile body IDs. The correspondence information is, for example, a set of pairs of authentication information and mobile body IDs. The correspondence information in this embodiment includes first correspondence information and second correspondence information. The first correspondence information is a set of pairs of first information and mobile body IDs. The second correspondence information is a set of pairs of second information and mobile body IDs.

[0159] The correspondence information may further include a conversion table. The conversion table is a table for converting two different types of mobile body IDs into the same type of mobile body ID when the mobile body ID acquired from the first information and the mobile body ID acquired from the second information are two different types of mobile body IDs. By converting two different types of mobile body IDs into two mobile body IDs of the same type, it becomes possible to determine whether they correspond to the same mobile body 20. When the authentication information (each of the first information and the second information) is a mobile body ID, the correspondence information (first correspondence information and second correspondence information) may not be necessary.

[0160] The processor works in cooperation with various communication modules and operates based on programs and various information stored in memory, thereby realizing the functions of each of the communication unit 101, authentication unit 10, processing unit 11, output unit 12, first communication unit 101a, second communication unit 101b, first acquisition unit 102, first authentication unit 104, second acquisition unit 103, second authentication unit 105, first authentication result acquisition unit 111, second authentication result acquisition unit 112, control processing unit 113 and location-related information acquisition unit 114.

[0161] (2-2-4) Controlled device The controlled device 30 includes, for example, a communication module (third communication module) for performing communication via the communication medium 300 (in this embodiment, wired communication via a wired LAN), a processor, and a memory. The memory stores programs and the like, and the processor operates based on the programs and the like stored in the memory to realize the functions of the controlled device 30.

[0162] (2-3) Example of control system operation The control system 100 operates, for example, according to the flowcharts of Figures 2 and 3. The processing of Figures 2 and 3 starts when the control system 100 is started, and ends when the operation of the control system 100 is stopped.

[0163] The control system 100 determines whether or not one of the first authentication unit 104 and the second authentication unit 105 has performed authentication (step S1). If it is determined that neither of the first authentication unit 104 nor the second authentication unit 105 has performed authentication (No in step S1), the process returns to step S1.

[0164] If it is determined in step S1 that one of the first authentication unit 104 and the second authentication unit 105 has performed authentication (Yes), the control system 100 determines whether the other authentication unit has performed authentication within a predetermined time (step S2). If it is determined that the other authentication unit has not performed authentication within the predetermined time (No in step S2), the process returns to step S1.

[0165] If it is determined in step S2 that the other authentication unit has authenticated within the predetermined time (Yes), the control system 100 executes control processing (step S3), after which the processing returns to step S1.

[0166] The control process of step S3 is executed in detail according to the flowchart of FIG.

[0167] The control system 100 compares the mobile object IDs between the two authentication results corresponding to the first authentication unit 104 and the second authentication unit 105 (step S31).

[0168] Next, the control system 100 determines whether the two moving object IDs corresponding to the two authentication results match each other (step S32). If it is determined that the two moving object IDs corresponding to the two authentication results do not match each other (No in step S32), the process proceeds to step S34.

[0169] If it is determined in step S32 that the two moving object IDs corresponding to the two authentication results match each other (Yes), the control system 100 performs control based on one of the two authentication results and does not perform control based on the other authentication result (step S33). Thereafter, the process returns to the upper flowchart (see FIG. 2).

[0170] In step S34, the control system 100 performs control based on each of the two authentication results, after which the process returns to the upper-level flowchart (see FIG. 2).

[0171] (2-4) Example of control device processing In the control system 100 of this embodiment, the control device 1 performs the above-described operations (see FIGS. 2 and 3) by executing, for example, the processing of the flowchart in Fig. 4. The processing in Fig. 4 is started in response to the activation of the control device 1 and is ended in response to the stopping of the operation of the control device 1.

[0172] In the control device 1, the processing unit 11 determines whether either the first authentication result acquisition unit 111 or the second authentication result acquisition unit 112 has acquired an authentication result (step S101). The authentication results acquired by each of the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 include a mobile object ID, an authentication time, and an authentication unit identifier. If it is determined that neither the first authentication result acquisition unit 111 nor the second authentication result acquisition unit 112 has acquired an authentication result (No in step S101), the process returns to step S101.

[0173] If it is determined in step S101 that either the first authentication result acquisition unit 111 or the second authentication result acquisition unit 112 has acquired an authentication result (Yes), the processing unit 11 compares the authentication result acquired by either the first authentication result acquisition unit 111 or the second authentication result acquisition unit 112 (hereinafter simply referred to as the "acquired authentication result") with each of the one or more authentication results stored (hereinafter sometimes referred to as "each authentication result") (step S102).

[0174] Next, the processing unit 11 determines whether or not there is an authentication result whose mobile object ID matches the acquired authentication result among the one or more authentication results stored (step S103). If it is determined that there is no authentication result whose mobile object ID matches the authentication result acquired in step S101 among the one or more authentication results stored (No in step S103), the processing proceeds to step S107.

[0175] If it is determined in step S103 that there is an authentication result whose mobile object ID matches the acquired authentication result among one or more stored authentication results (Yes), the processing unit 11 determines whether the two authentication results, the acquired authentication result and the authentication result determined to match the acquired authentication result, are authentication results authenticated by the same authentication unit by comparing the authentication unit identifiers between the two authentication results (step S104).If it is determined that the two authentication results are not authentication results authenticated by the same authentication unit (No in step S104), the processing proceeds to step S107.

[0176] If it is determined in step S104 that the two authentication results are authentication results obtained by the same authentication unit (Yes), the processing unit 11 determines whether the time difference between the time of authentication by the first authentication unit 104 and the time of authentication by the second authentication unit 105 is within a predetermined time by comparing the authentication times between the two authentication results (step S105). If it is determined that the time difference between the time of authentication by the first authentication unit 104 and the time of authentication by the second authentication unit 105 is not within the predetermined time (i.e., exceeds the predetermined time: No in step S105), the processing proceeds to step S107.

[0177] If it is determined in step S105 that the time difference between the time when the first authentication unit 104 performed authentication and the time when the second authentication unit 105 performed authentication is within the predetermined time (Yes), the processing unit 11 discards the acquired authentication result (i.e., does not perform control based on the authentication result: step S106). After that, the processing returns to step S101.

[0178] In step S107, the control processing unit 113 performs control based on the acquired authentication result. Next, the control processing unit 113 stores the acquired authentication result (step S108). After that, the process returns to step S101.

[0179] The above embodiment is merely one of various embodiments of the present disclosure, and various modifications can be made to the above embodiment depending on the design and the like as long as the object of the present disclosure can be achieved.

[0180] (3) Variations Next, various modifications of the embodiment will be described. Note that, in the following, descriptions of commonalities between the embodiment and the present invention will be omitted or simplified, and differences will be described in detail.

[0181] (3-1) First Modified Example of Control System First, a first modified example of the control system 100 will be described with reference to FIGS.

[0182] 5, the control system 100 of this modified example cooperates with an authentication system 200. The control system 100 is realized by a control device 1, and the authentication system 200 is realized by an authentication device 2. The control device 1 and the authentication device 2 are connected to each other via a communication medium 300 so that they can communicate with each other.

[0183] In this modified example, the components of the control system 100 (control device 1: see Figure 1) of the embodiment, namely, the communication unit 101, the authentication unit 10, the processing unit 11, the output unit 12, the first communication unit 101a, the second communication unit 101b, the first acquisition unit 102, the first authentication unit 104, the second acquisition unit 103, the second authentication unit 105, the first authentication result acquisition unit 111, the second authentication result acquisition unit 112, the control processing unit 113 and the location-related information acquisition unit 114, are distributed between the control system 100 and the authentication system 200.

[0184] That is, the control system 100 (control device 1) of this modified example includes a processing unit 11, an output unit 12, a first authentication result acquisition unit 111, a second authentication result acquisition unit 112, a control processing unit 113, and a location-related information acquisition unit 114, as shown in FIG. 5.

[0185] (3-1-1) First authentication result acquisition unit and second authentication result acquisition unit The first authentication result acquisition unit 111 receives the authentication result of the first authentication unit 104 from the authentication system 200. The second authentication result acquisition unit 112 receives the authentication result of the second authentication unit 105 from the second authentication system 200b.

[0186] (3-1-2) Prescribed conditions The specified condition in this modified example is that after one of the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 receives the authentication result, the other authentication result acquisition unit receives the authentication result within a specified time.

[0187] According to such a predetermined condition, if two authentication results received successively by the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 with a time difference within a predetermined time are authentication results performed on the same mobile body 20 with a time difference within a predetermined time, it becomes possible to perform predetermined control based on only one of the authentication results.

[0188] In other words, even if two authentication results are authentication results for the same mobile object 20, if the authentication results are received with a time difference exceeding a predetermined time, it is possible to perform predetermined control based on each of the two authentication results. As a result, it is possible to improve security while avoiding a situation in which it becomes difficult to perform predetermined control based on the authentication result of one authentication unit on a mobile object that has been subjected to predetermined control based on the authentication result of the other authentication unit.

[0189] In addition, a situation in which it becomes difficult to perform predetermined control based on the authentication result of one authentication unit on a mobile object that has undergone predetermined control based on the authentication result of the other authentication unit is, for example, a situation in which only the authentication result of the authentication unit corresponding to the first predetermined control can be used for the second or subsequent predetermined control.

[0190] (3-1-3) Authentication system (authentication device) As shown in FIG. 5, the authentication system 200 (authentication device 2) includes a communication unit 101, an authentication unit 10, a first communication unit 101a, a second communication unit 101b, a first acquisition unit 102, a first authentication unit 104, a second acquisition unit 103, and a second authentication unit 105.

[0191] (3-1-4) Operations performed by the control system in cooperation with the authentication system The operation performed by the control system 100 of this modified example in cooperation with the authentication system 200 is basically the same as the operation of the control system 100 of the embodiment (see FIGS. 2 and 3).

[0192] (3-1-5) Example of control device processing In the control system 100 of this modified example, the control device 1 cooperates with the authentication device 2 to execute, for example, the processing of the flowchart in Fig. 6, thereby realizing the operation of the control system 100 (see Figs. 2 and 3). Note that the processing in Fig. 6 is started in response to the activation of the control device 1 and is ended in response to the cessation of operation of the control device 1.

[0193] In this processing example, the authentication results received by each of the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 do not include an authentication time, but include a mobile object ID and an authentication unit identifier. When each of the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 receives an authentication result, the processing unit 11 acquires the reception time. Then, the processing unit 11 adds the reception time to the authentication result stored in memory.

[0194] In the control device 1, the processing unit 11 determines whether either the first authentication result acquisition unit 111 or the second authentication result acquisition unit 112 has received an authentication result (step S201). If it is determined that neither the first authentication result acquisition unit 111 nor the second authentication result acquisition unit 112 has received an authentication result (No in step S201), the processing returns to step S201.

[0195] If either the first authentication result acquisition unit 111 or the second authentication result acquisition unit 112 determines in step S201 that it has received the authentication result (Yes), the processing unit 11 acquires the reception time indicating the time of reception, for example, by referring to the built-in clock of the processor of the control device 1 (step S201a).

[0196] Next, the processing unit 11 compares the authentication result received by either the first authentication result acquisition unit 111 or the second authentication result acquisition unit 112 in step S201 (hereinafter simply referred to as the "received authentication result") with each of one or more stored authentication results (hereinafter sometimes referred to as "each authentication result") (step S202).

[0197] Next, the processing unit 11 determines whether or not there is an authentication result whose mobile object ID matches the received authentication result among one or more stored authentication results (step S203). If it is determined that there is no authentication result whose mobile object ID matches the received authentication result among one or more stored authentication results (No in step S203), the processing proceeds to step S207.

[0198] If it is determined in step S203 that there is an authentication result whose mobile unit ID matches the received authentication result among one or more stored authentication results (Yes), the processing unit 11 determines whether the two authentication results, the received authentication result and the authentication result determined to match the received authentication result, are authentication results authenticated by the same authentication unit by comparing the authentication unit identifiers between the two authentication results (step S204).If it is determined that the two authentication results are not authentication results authenticated by the same authentication unit (No in step S204), the processing proceeds to step S207.

[0199] If it is determined in step S204 that the two authentication results are authentication results authenticated by the same authentication unit (Yes), the processing unit 11 determines whether the time difference between the time when the first authentication result acquisition unit 111 received the authentication result and the time when the second authentication result acquisition unit 112 received the authentication result is within a predetermined time by comparing the reception time acquired in step S201a with the reception time included in the authentication result that is determined to match the received authentication result (step S205). If it is determined that the time difference between the time when the first authentication result acquisition unit 111 received the authentication result and the time when the second authentication result acquisition unit 112 received the authentication result is not within the predetermined time (that is, the time difference exceeds the predetermined time: No in step S205), the processing proceeds to step S207.

[0200] If it is determined in step S205 that the time difference between the time when the first authentication result acquisition unit 111 receives the authentication result and the time when the second authentication result acquisition unit 112 receives the authentication result is within the predetermined time (Yes), the processing unit 11 discards the received authentication result (i.e., does not perform control based on the authentication result: step S206). Thereafter, the processing returns to step S201.

[0201] In step S207, the control processing unit 113 performs control based on the received authentication result. Next, the control processing unit 113 stores the authentication result including the mobile object ID, the authentication unit identifier, and the reception time by adding the reception time acquired in step S201a to the received authentication result (step S208). After that, the process returns to step S201.

[0202] (3-2) Second Modification of Control System In the control system 100 of this modification, the authentication device 2 in the first modification of the control system (see FIG. 5) is configured with a first authentication system 200a (or a first authentication device) including a first communication unit 101a, a first acquisition unit 102, and a first authentication unit 104, and a second authentication system 200b (or a second authentication device) including a second communication unit 101b, a second acquisition unit 103, and a second authentication unit 105. Each of the first authentication system 200a (or the first authentication device) and the second authentication system 200b (or the second authentication device) is installed near a predetermined area A1 and is connected to the control device 1 via a communication medium 300 so as to be able to communicate with each other.

[0203] In the first authentication system 200a (or the first authentication device), the first communication unit 101a receives first information from the information terminal 201 of the mobile object 20 located near the access point AL1. In the second authentication system 200b (or the second authentication device), the second communication unit 101b receives second information from the information terminal 201 of the mobile object 20 located near the access point AL1.

[0204] In the control device 1, a first acquisition unit 102 constituting the authentication unit 10 acquires, via the communication medium 300, the first information received by a first communication unit 101a of the first authentication system 200a (or the first authentication device). Also, a second acquisition unit 103 constituting the authentication unit 10 acquires, via the communication medium 300, the second information received by a second communication unit 101b of the second authentication system 200b (or the second authentication device).

[0205] (3-3) Third Modification of Control System In the control system 100 of the embodiment (see FIG. 1), the communication unit 101 may be excluded from the components of the control device 1.

[0206] The control system 100 of this modified example is made up of a communication device including a communication unit 101, and a control device 1 including an authentication unit 10, a processing unit 11, and an output unit 12.

[0207] In this modification, the communication device is installed near a predetermined area A1 and is communicatively connected to the control device 1 via a communication medium 300. The control device 1 may be installed near the predetermined area A1 or at a location away from the predetermined area A1. The location of the control device 1 does not matter as long as it can communicate with each of the communication device and the controlled device 30.

[0208] In the communication device, the first communication unit 101a receives first information from the information terminal 201 of the mobile object 20 located near the access point AL1, and the second communication unit 101b receives second information from the information terminal 201 of the mobile object 20 located near the access point AL1.

[0209] In the control device 1, a first acquisition unit 102 constituting the authentication unit 10 acquires, via the communication medium 300, the first information received by a first communication unit 101a of the communication device. A second acquisition unit 103 constituting the authentication unit 10 acquires, via the communication medium 300, the first information and the second information received by a communication unit 101a of the communication device.

[0210] (3-4) Fourth Modification of Control System In a first modified example of the control system 100 (see FIG. 5), the communication unit 101 may be excluded from the components of the control device 1.

[0211] The control system 100 of this modified example is made up of a communication device including a communication unit 101, an authentication device 2 including an authentication unit 10, and a control device 1 including a processing unit 11 and an output unit 12.

[0212] (3-5) Variations of specified conditions (3-5-1) Modifications of the Prescribed Conditions in the Embodiments The predetermined condition in this embodiment is that one of the first authentication unit 104 and the second authentication unit 105 performs authentication and then the other authentication unit performs authentication within a predetermined time, but the predetermined condition in this modified example is that each of the first authentication unit 104 and the second authentication unit 105 performs authentication. In other words, the predetermined condition in this modified example is that each of the authentication results of the first authentication unit 104 and the second authentication unit 105 has been acquired.

[0213] According to this modified example, when the above-mentioned specified conditions are met, that is, when the first authentication unit 104 and the second authentication unit 105 each perform authentication and two authentication results corresponding to the first authentication unit 104 and the second authentication unit 105 are obtained, by executing control processing regardless of the time difference between the authentication times, it is possible to reduce the possibility that one user will be allowed to enter the room based on one authentication result and that another unauthenticated user will be allowed to enter the room based on the other authentication result, thereby improving security.

[0214] (3-5-2) Modification of the Predetermined Condition in the First Modification of the Control System The predetermined condition in the first modification of the control system may be a condition that each of the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 receives an authentication result from the authentication system 200 (authentication device 2).

[0215] In the first modified example of the control system, authentication by first authentication unit 104 is performed in first authentication system 200a, authentication by second authentication unit 105 is performed in second authentication system 200b, and in control system 100, first authentication result acquisition unit 111 receives the authentication result of first authentication unit 104 from first authentication system 200a, and second authentication result acquisition unit 112 receives the authentication result of second authentication unit 105 from second authentication system 200b. In this configuration, when a predetermined condition is satisfied, that is, when each of first authentication result acquisition unit 111 and second authentication result acquisition unit 112 receives an authentication result, control processing is executed regardless of the time difference between the two reception times corresponding to first authentication result acquisition unit 111 and second authentication result acquisition unit 112. This reduces the possibility that one user will be permitted to enter the room based on one authentication result and that another unauthenticated user will be permitted to enter the room based on the other authentication result, thereby improving security.

[0216] (3-6) Modifications of the control target, predetermined control, and control process of the control system In this modification, the control target of the control system 100 is a counting device that counts the number of moving objects 20 that have accessed a predetermined area A1 (for example, the number of users who have entered a room).

[0217] In other words, the predetermined control in this modified example is control of counting by the counting device. The control processing in this modified example is processing for causing the counting device to control counting based on each of the authentication results acquired by the first authentication result acquisition unit 111 and the second authentication result acquisition unit 112 when the first information and the second information are not associated with the same mobile object 20. Furthermore, the control processing is processing for causing the counting device to control counting based on one of the authentication results acquired by the first authentication result acquisition unit 111 and the authentication result acquired by the second authentication result acquisition unit 112 when the first information and the second information are associated with the same mobile object 20, and not causing the counting device to control counting based on the other authentication result.

[0218] When a predetermined condition is satisfied, the control system 100 transmits control information to the counting device for controlling the counting by the counting device as described above.

[0219] (3-7) Modification of Acquisition Destination of First Acquisition Unit and Second Acquisition Unit Either the first acquisition unit 102 or the second acquisition unit 103 may acquire the information corresponding to that either one of the first information and the second information from a source other than the communication unit 101 (for example, an external server, etc.).

[0220] That is, for example, the first acquisition unit 102 may acquire the first information from a source other than the communication unit 101 (for example, a first server that manages the first information), or the second acquisition unit 103 may acquire the second information from a source other than the communication unit 101 (for example, a second server that manages the second information).

[0221] (3-8) Modifications related to wireless communication (3-8-1) Modified example of wireless communication of communication unit The wireless communication of the communication unit 101 may further include wireless communication other than UWB.

[0222] The wireless communication other than UWB is, for example, a short-range wireless communication other than UWB, such as Bluetooth or NFC.

[0223] Alternatively, the wireless communication other than UWB may be wireless communication with a communication distance longer than short-range wireless communication. Wireless communication with a communication distance longer than short-range wireless communication includes, for example, communication via a wireless LAN or wide-area wireless communication such as a mobile phone network. However, communication via a wireless LAN may be included in short-range wireless communication.

[0224] (3-8-2) Modified examples of two types of wireless communication with different communication distances In the embodiment, the two types of wireless communication with different communication distances are both short-range wireless communication, but at least one of the two types of wireless communication does not have to be short-range wireless communication. In this modification, the first wireless communication is short-range wireless communication such as NFC, and the second wireless communication is wide-area wireless communication such as wireless communication for mobile phones.

[0225] In this modification, the information terminal 201 can acquire its own location information by, for example, working in cooperation with a GPS (Global Positioning System) or by using a position detection function of a wireless LAN. The information terminal 201 associates the acquired location information with the second information and transmits it to the control device 1 via wide-area wireless communication.

[0226] In the control device 1, the second communication unit 101b receives the first information and the location information from the information terminal 201. The second acquisition unit 103 acquires the received first information and location information from the second communication unit 101b, thereby detecting that the mobile object 20 carrying the information terminal 201 is located near a predetermined area A1.

[0227] (3-8-3) Modification of the first communication unit In the embodiment, the first communication unit 101a received the first information from the information terminal 201 via wireless communication, but in this modified example, the first communication unit 101a may receive the second information from the information terminal 201 via wireless communication, or may receive each of the first information and the second information from the information terminal 201 via wireless communication.

[0228] In the embodiment, the wireless communication of the first communication unit 101a is basically wireless communication different from UWB wireless communication, but in this modification, it may be UWB wireless communication. In other words, the first communication unit 101a and the second communication unit 101b may be the same communication unit, that is, the communication unit 101 that receives the first information and the second information via UWB wireless communication.

[0229] The wireless communication of the first communication unit 101a in the embodiment is specifically NFC, but may be wireless communication different from NFC or UWB wireless communication, such as wireless LAN communication or Bluetooth wireless communication.

[0230] (3-8-4) Modification of the relationship between the wireless communication of the first communication unit and the wireless communication of the second communication unit In the embodiment, the first acquisition unit 102 acquires the first information through the first wireless communication, and the second acquisition unit 103 acquires the second information through the second wireless communication, but in this modification, for example, the first acquisition unit 102 may acquire the second information through the first wireless communication, and the second acquisition unit 103 may acquire the first information through the second wireless communication. Alternatively, for example, the first acquisition unit 102 may acquire the second information through the second wireless communication, and the second acquisition unit 103 may acquire the first information through the first wireless communication. In this way, any combination of acquisition units, wireless communication, and information is possible.

[0231] In addition, in the embodiment, the first wireless communication is NFC communication and the second wireless communication is UWB wireless communication, but in this modification, the types of the first wireless communication and the second wireless communication do not matter as long as the second wireless communication has a longer communication distance than the first wireless communication. Specifically, for example, the first wireless communication may be NFC and the second wireless communication may be Bluetooth, or the first wireless communication may be Bluetooth and the second wireless communication may be communication via a wireless LAN.

[0232] (3-8-5) Modification of location-related information acquisition unit In the embodiment, the location-related information acquisition unit 114 acquires location-related information using signals transmitted and received via UWB wireless communication, but in this modified example, the location-related information may also be acquired using signals transmitted and received via a second wireless communication other than UWB wireless communication.

[0233] When the first wireless communication is NFC, the second wireless communication other than UWB wireless communication may be a wireless communication having a longer communication distance than NFC. In this modification, the second wireless communication other than UWB wireless communication is, for example, communication via a wireless LAN, and the position-related information acquisition unit 114 acquires the position-related information using signals transmitted and received in communication via the wireless LAN. The position-related information acquisition unit 114 may acquire the position-related information by utilizing a position detection function of the wireless LAN.

[0234] Furthermore, since wireless LAN has a longer communication distance (the wavelength of the radio waves used is longer) than UWB wireless communication, when location-related information is obtained using signals transmitted and received via wireless LAN, the range in which location-related information can be obtained can be expanded compared to when location-related information is obtained using signals transmitted and received via UWB wireless communication.

[0235] (3-9) Modification of communication media In the embodiment, the communication medium 300 is a wired LAN, but may be, for example, a wired communication other than a LAN, or a wireless communication.

[0236] The communication medium 300 is preferably a wireless communication medium having a longer communication distance than the wireless communication medium having a longer communication distance (UWB wireless communication) between the control device 1 and the information terminal 201, for example, of the two types of wireless communication (for example, NFC and UWB wireless communication). A wireless communication medium having a longer communication distance than UWB wireless communication is, for example, a wireless LAN, but may also be a wide-area wireless communication medium such as a wireless communication medium for a mobile phone.

[0237] (3-10) Modified authentication (3-10-1) First Modification of Authentication The authentication in this modification further includes identifying attributes of the mobile object 20 based on a comparison between the acquired authentication information and pre-registered authentication information (hereinafter, sometimes referred to as "registered authentication information"), and acquiring attribute information indicating the identification result. The registered authentication information is further stored in the memory. The authentication result further includes the attribute information.

[0238] The identified attribute of the mobile body 20 is, for example, an attribute (hereinafter sometimes referred to as a "registered attribute") relating to whether the mobile body 20 is a registered mobile body 20 that has already registered authentication information (for example, a registrant whose user ID has already been registered) or an unregistered mobile body 20 that has not yet registered authentication information (for example, an unregistered mobile body whose user ID has not yet been registered).The identification result, that is, attribute information indicating the registered attribute, is then acquired.

[0239] (3-10-2) Second variant of authentication In this modification, the subject of authentication is a human body (user) among the moving body 20.

[0240] At least one of the first acquisition unit 102 and the second acquisition unit 103 acquires information corresponding to at least one of the first information and the second information as biometric information of the human body. At least one of the first authentication unit 104 and the second authentication unit 105 performs biometric authentication using the biometric information.

[0241] The biometric authentication includes face authentication. That is, at least one of the first authentication unit 104 and the second authentication unit 105 may perform face authentication using a face image as the biometric authentication.

[0242] The biometric information in this modification includes a facial image. The facial image is an image of a human face. In this modification, the authentication performed by at least one of the first authentication unit 104 and the second authentication unit 105 is facial authentication.

[0243] The control device 1 further includes a camera for capturing a facial image of the user. The camera may be located outside the control device 1. The outside of the control device 1 means, for example, a location remote from the control device 1 and near the predetermined area A1.

[0244] At least one of the first authentication unit 104 and the second authentication unit 105 performs face authentication based on a face image captured by a camera.

[0245] Alternatively, the authentication performed by at least one of the first authentication unit 104 and the second authentication unit 105 may be biometric authentication other than face authentication. Examples of biometric authentication other than face authentication include iris authentication and voiceprint authentication. Iris authentication is authentication based on an iris image of the iris of the eyeball. Voiceprint authentication is authentication based on the voiceprint waveform of the voiceprint of spoken voice.

[0246] The iris image is acquired via a camera. When performing voiceprint authentication, the control device 1 further includes a microphone for capturing the user's speech, and the voiceprint waveform is acquired via the microphone.

[0247] According to this modification, biometric authentication using biometric information can improve authentication accuracy. For example, by acquiring a face image as biometric information and performing face authentication as biometric authentication, authentication accuracy can be further improved.

[0248] (3-11) Other variations (3-11-1) Distributed placement of each component of the control system In the embodiment (see FIG. 1), each of the components of the control system 100, namely, the communication unit 101, the authentication unit 10, the processing unit 11, the output unit 12, the first communication unit 101a, the second communication unit 101b, the first acquisition unit 102, the first authentication unit 104, the second acquisition unit 103, the second authentication unit 105, the first authentication result acquisition unit 111, the second authentication result acquisition unit 112, the control processing unit 113, and the location-related information acquisition unit 114, do not necessarily belong to a single device (control device 1) as illustrated in FIG. 1, but may belong to various devices that are communicatively connected via a communication medium 300, for example.

[0249] Similarly, in the first variant (see Figure 5), each of the components of the control system 100, namely, the processing unit 11, the output unit 12, the first authentication result acquisition unit 111, the second authentication result acquisition unit 112, the control processing unit 113 and the location-related information acquisition unit 114, does not necessarily belong to a single device (control device 1) as illustrated in Figure 5, but may be distributed among various devices that are communicatively connected via a communication medium 300, etc.

[0250] (3-11-2) Distributed placement of components of the authentication system In the first variant (see FIG. 5), each of the components of the authentication system 200, namely, the communication unit 101, the authentication unit 10, the first communication unit 101a, the second communication unit 101b, the first acquisition unit 102, the first authentication unit 104, the second acquisition unit 103, and the second authentication unit 105, does not necessarily belong to a single device (authentication device 2) as illustrated in FIG. 5, but may be distributed among various devices that are communicatively connected via a communication medium 300, etc.

[0251] (3-11-3) Modified examples of authentication systems: first authentication system and second authentication system In a first modified example (see FIG. 5), authentication system 200 may be configured with first authentication system 200a and second authentication system 200b. In this case, first authentication system 200a and second authentication system 200b may be realized by separate devices (e.g., a first authentication device and a second authentication device).

[0252] The first authentication system 200a includes a first communication unit 101a, a first acquisition unit 102, and a first authentication unit 104. The second authentication system 200b includes a second communication unit 101b, a second acquisition unit 103, and a second authentication unit 105. The first authentication result acquisition unit 111 receives the authentication result of the first authentication unit 104 from the first authentication system 200a. The second authentication result acquisition unit 112 receives the authentication result of the second authentication unit 105 from the second authentication system 200b.

[0253] Note that functions similar to those of the control system 100 may be realized by a control method, a computer program, or a non-transitory recording medium on which a program is recorded.

[0254] (4) Control method A control method according to one aspect of the present disclosure includes a first authentication result acquisition step, a second authentication result acquisition step, and a control step. In the first authentication result acquisition step, the authentication result of the first authentication unit 104 is acquired. The first authentication unit 104 performs authentication based on first information acquired by the first acquisition unit 102. The first information is information associated with the mobile object 20. In the second authentication result acquisition step, the authentication result of the second authentication unit 105 is acquired. The second authentication unit 105 performs authentication based on second information acquired by the second acquisition unit 103. The second information is information associated with the mobile object 20. In the control step, a control process is executed when a predetermined condition is satisfied. The control process is a process of performing predetermined control on the mobile object 20 based on at least one of the authentication results acquired in the first authentication result acquisition step and the authentication result acquired in the second authentication result acquisition step. The control process is a process of performing predetermined control based on each of the authentication result acquired in the first authentication result acquisition step and the authentication result acquired in the second authentication result acquisition step when the first information and the second information are not associated with the same mobile body. Also, when the first information and the second information are associated with the same mobile body, the control process is a process of performing predetermined control based on one of the authentication results acquired in the first authentication result acquisition step and the authentication result acquired in the second authentication result acquisition step, and not performing predetermined control based on the other authentication result.

[0255] The control method may include, for example, steps S1, S101, S201 (first authentication result acquisition step), steps S2, S101, S201 (second authentication result acquisition step), and steps S3, S102 to S107, S202 to S207 (control step) out of steps S1 to S3 described in the flowchart of FIG. 2, steps S31 to S34 described in the flowchart of FIG. 3, steps S101 to S108 described in the flowchart of FIG. 4, and steps S201 to S208 described in the flowchart of FIG. 6.

[0256] (5) Programs and computer systems A program according to one aspect of the present disclosure is a program for causing a computer system to function as the above-described control method. The program is, for example, a program for causing one or more processors to execute the control method. The one or more processors includes the case of a single processor and the case of two or more processors. The one processor is, for example, the processor of the control system 100 realized solely by the control device 1 described in the embodiment, and the two or more processors are, for example, two processors corresponding to the control device 1 and the authentication device 2 constituting the control system 100 described in the first modified example.

[0257] The control system 100 of the present disclosure includes a computer system. The computer system is primarily composed of a processor and memory as hardware. The processor executes a program stored in the memory of the computer system to realize the functions of the control system 100 of the present disclosure. The program may be pre-stored in the memory of the computer system, provided via a telecommunications line, or provided in a non-transitory recording medium readable by the computer system, such as a memory card, optical disk, or hard disk drive. The processor of the computer system is composed of one or more electronic circuits, including a semiconductor integrated circuit (IC) or a large-scale integrated circuit (LSI). The integrated circuits, such as ICs and LSIs, are referred to by different names depending on the degree of integration, and include integrated circuits called system LSIs, very large-scale integrations (VLSIs), and ultra-large-scale integrations (ULSIs). Furthermore, field-programmable gate arrays (FPGAs), which are programmable after the LSI is manufactured, or logic devices that allow the reconfiguration of internal connections or internal circuit partitions of the LSI, can also be used as processors. The electronic circuits may be integrated into one chip or distributed across multiple chips. The chips may be integrated into one device or distributed across multiple devices. The computer system referred to here includes a microcontroller having one or more processors and one or more memories. Therefore, the microcontroller is also composed of one or more electronic circuits including a semiconductor integrated circuit or a large-scale integrated circuit.

[0258] Furthermore, it is not essential for the control system 100 that multiple functions in the control system 100 are concentrated in one housing, and the components of the control system 100 may be distributed across multiple housings. Furthermore, at least some of the functions of the control system 100 may be realized by the cloud (cloud computing) or the like.

[0259] (6) Summary A control system (100) according to a first aspect includes a first authentication result acquisition unit (111), a second authentication result acquisition unit (112), and a control processing unit (113). The first authentication result acquisition unit (111) acquires the authentication result of the first authentication unit (104). The first authentication unit (104) performs authentication based on first information acquired by the first acquisition unit (102). The first information is information associated with the mobile object (20). The second authentication result acquisition unit (112) acquires the authentication result of the second authentication unit (105). The second authentication unit (105) performs authentication based on second information acquired by the second acquisition unit (103). The second information is information associated with the mobile object (20). The control processing unit (113) executes control processing when a predetermined condition is satisfied. The control process is a process of performing predetermined control on the mobile object (20) based on at least one of the authentication results acquired by the first authentication result acquisition unit (111) and the second authentication result acquisition unit (112). The control process is a process of performing predetermined control based on each of the authentication results acquired by the first authentication result acquisition unit (111) and the second authentication result acquisition unit (112) when the first information and the second information are not associated with the same mobile object (20). Furthermore, the control process is a process of performing predetermined control based on one of the authentication results acquired by the first authentication result acquisition unit (111) and the second authentication result acquisition unit (112) when the first information and the second information are associated with the same mobile object (20), but not performing predetermined control based on the other authentication result.

[0260] According to this aspect, when two authentication results obtained successively by the first authentication unit (104) and the second authentication unit (105) are authentication results for the same mobile body (20), by performing only a predetermined control based on one of the authentication results, the possibility of performing a predetermined control based on the other authentication result on another mobile body is reduced, thereby improving security.

[0261] In the control system (100) according to the second aspect, in the first aspect, the predetermined condition is that each of the first authentication unit (104) and the second authentication unit (105) has performed authentication.

[0262] According to this aspect, when a predetermined condition is satisfied, that is, when each of the first authentication unit (104) and the second authentication unit (105) performs authentication, control processing is executed regardless of the time difference between the two authentication times corresponding to the first authentication unit (104) and the second authentication unit (105), thereby making it possible to improve security.

[0263] In the control system (100) according to the third aspect, in the first or second aspect, the predetermined condition is that one of the first authentication unit (104) and the second authentication unit (105) performs authentication, and then the other authentication unit performs authentication within a predetermined time.

[0264] According to this aspect, if two authentication results acquired by the first authentication unit (104) and the second authentication unit (105) successively with a time difference of within a predetermined time are authentication results for the same mobile object (20) with a time difference of within the predetermined time, only predetermined control based on one of the authentication results is performed. In other words, even if the two authentication results are authentication results for the same mobile object (20), if they are authentication results for authentications performed with a time difference of more than a predetermined time, predetermined control can be performed based on each of the two authentication results. As a result, it is possible to improve security while avoiding a situation in which it becomes difficult to perform predetermined control based on the authentication result of one authentication unit on a mobile object that has been subjected to predetermined control based on the authentication result of the other authentication unit (in other words, only the authentication result of the authentication unit corresponding to the first predetermined control can be used for the second or subsequent predetermined control).

[0265] In the control system (100) according to the fourth aspect, in the first aspect, the first authentication result acquisition unit (111) receives the authentication result of the first authentication unit (104) from the first authentication system (200a). The first authentication system (200a) includes the first authentication unit (104). The second authentication result acquisition unit (112) receives the authentication result of the second authentication unit (105) from the second authentication system (200b). The second authentication system (200b) includes the second authentication unit (105). The predetermined condition is that each of the first authentication result acquisition unit (111) and the second authentication result acquisition unit (112) has received an authentication result.

[0266] According to this aspect, in a configuration in which authentication by the first authentication unit (104) is performed in the first authentication system (200a), authentication by the second authentication unit (105) is performed in the second authentication system (200b), and in the control system (100), the first authentication result acquisition unit (111) receives the authentication result of the first authentication unit (104) from the first authentication system (200a), and the second authentication result acquisition unit (112) receives the authentication result of the second authentication unit (105) from the second authentication system (200b), when a predetermined condition is satisfied, that is, when each of the first authentication result acquisition unit (111) and the second authentication result acquisition unit (112) receives an authentication result, control processing is executed regardless of the time difference between the two reception times corresponding to the first authentication result acquisition unit (111) and the second authentication result acquisition unit (112), thereby enabling improvement of security.

[0267] In the control system (100) according to the fifth aspect, in the first or fourth aspect, the first authentication result acquisition unit (111) receives the authentication result of the first authentication unit (104) from the first authentication system (200a). The first authentication system (200a) includes the first authentication unit (104). The second authentication result acquisition unit (112) receives the authentication result of the second authentication unit (105) from the second authentication system (200b). The second authentication system (200b) includes the second authentication unit (105). The predetermined condition is that, after one of the first authentication result acquisition unit (111) and the second authentication result acquisition unit (112) receives the authentication result, the other authentication result acquisition unit receives the authentication result within a predetermined time.

[0268] According to this aspect, if two authentication results received by the first authentication result acquisition unit (111) and the second authentication result acquisition unit (112) in succession with a time difference of less than a predetermined time are authentication results performed for the same mobile object (20) with a time difference of less than a predetermined time, only predetermined control based on one of the authentication results is performed. In other words, even if the two authentication results are authentication results for the same mobile object (20), if they are authentication results received with a time difference of more than a predetermined time, predetermined control can be performed based on each of the two authentication results. As a result, it is possible to improve security while avoiding a situation in which it becomes difficult to perform predetermined control based on the authentication result of one authentication unit on a mobile object that has been subjected to predetermined control based on the authentication result of the other authentication unit (i.e., only the authentication result of the authentication unit corresponding to the first predetermined control can be used for the second or subsequent predetermined control).

[0269] In a control system (100) according to a sixth aspect, in any one of the first to fifth aspects, a first acquisition unit (102) acquires first information by a first method. A second acquisition unit (103) acquires second information by a second method. The second method is a method different from the first method.

[0270] According to this aspect, the first information and the second information can be acquired by the first method and the second method that are suited to them, respectively.

[0271] In the control system (100) according to the seventh aspect, in any of the first to sixth aspects, at least one of the first acquisition unit (102) and the second acquisition unit (103) acquires information corresponding to at least one of the first information and the second information from a communication unit (101) that communicates wirelessly with an information terminal (201) held by a mobile body (20).

[0272] According to this aspect, at least one of the first information and the second information can be acquired via the communication unit (101) that communicates with the information terminal (201) held by the mobile object (20).

[0273] In the control system (100) according to the eighth aspect, the wireless communication includes ultra-wideband wireless communication in the seventh aspect.

[0274] According to this aspect, it is possible to use wideband (UWB) wireless communication to acquire at least one of the first information and the second information from an information terminal (201) located within a short distance of approximately several meters from the communication unit (101). Also, it is possible to use UWB wireless communication to acquire location-related information regarding at least one of the distance between the communication unit (101) and the information terminal (201) and the location of the information terminal (201) with a resolution of approximately several centimeters.

[0275] In a control system (100) according to a ninth aspect, in the seventh aspect, the communication unit (101) includes a first communication unit (101a) and a second communication unit (101b). The first communication unit (101a) receives at least one of first information and second information from an information terminal (201) by wireless communication. The second communication unit (101b) performs ultra-wideband wireless communication with the information terminal (201).

[0276] According to this aspect, at least one of the first information and the second information can be acquired from the information terminal (201) through wireless communication by the first communication unit (101a). Also, at least one of the first information and the second information can be acquired from the information terminal (201) through UWB wireless communication by the second communication unit (101b). Furthermore, the position of the information terminal (201) can be detected with a resolution of about several centimeters through UWB wireless communication by the second communication unit (101b).

[0277] A control system (100) according to a tenth aspect is the same as the ninth aspect, and further includes a position-related information acquisition unit (114). The position-related information acquisition unit (114) acquires position-related information using a signal transmitted and received by ultra-wideband wireless communication of the second communication unit (101b). The position-related information is information relating to at least one of the distance between the second communication unit (101b) and the information terminal (201) and the position of the information terminal (201).

[0278] According to this aspect, the UWB wireless communication of the second communication unit (101b) makes it possible to acquire location-related information regarding at least one of the distance between the second communication unit (101b) and the information terminal (201) and the location of the information terminal (201) with a resolution of about several centimeters.

[0279] In a control system (100) according to an eleventh aspect, in the tenth aspect, one of the first acquisition unit (102) and the second acquisition unit (103) acquires the first information and the second information corresponding to one of the acquisition units through a first wireless communication. The first wireless communication is a wireless communication having a communication range of a communication distance equal to or less than a first reference value. The other of the first acquisition unit (102) and the second acquisition unit (103) acquires the first information and the second information corresponding to the other of the acquisition units through a second wireless communication. The second wireless communication is a wireless communication having a communication range of a communication distance equal to or less than a second reference value that is greater than the first reference value.

[0280] According to this aspect, the area in which information can be obtained from the information terminal (201) can be expanded by using the first wireless communication and the second wireless communication with different communication distances, for example, NFC and UWB wireless communication.

[0281] In a control system (100) according to a twelfth aspect, in the eleventh aspect, the positional related information acquisition unit (114) acquires the positional related information by using a signal transmitted and received in the second wireless communication.

[0282] According to this aspect, it is possible to expand the area in which location-related information can be obtained.

[0283] In a control system (100) according to a thirteenth aspect, in any one of the first to fifth aspects, the moving body (20) is a human body. At least one of the first acquisition unit (102) and the second acquisition unit (103) acquires biometric information of the human body as information corresponding to at least one of the first information and the second information.

[0284] According to this aspect, biometric authentication using biometric information can improve authentication accuracy.

[0285] In a control system (100) according to a fourteenth aspect, in the thirteenth aspect, the biometric information includes an image of a face of a human body.

[0286] According to this aspect, by acquiring a face image as biometric information and performing face authentication as biometric authentication, it is possible to further improve authentication accuracy.

[0287] In a control system (100) according to a fifteenth aspect, in any one of the first to fourteenth aspects, the control process includes outputting control information. The control information is information for predetermined control.

[0288] According to this aspect, by outputting the control information, it is possible to cause at least one of an external device of the control system (100) and an internal device of the control system to perform a predetermined control.

[0289] In a control system (100) according to a sixteenth aspect, in any one of the first to fourteenth aspects, the predetermined control includes access control. The access control is control that permits or prohibits access of a mobile object (20) to a predetermined area (A1).

[0290] According to this aspect, when two authentication results obtained successively by the first authentication unit (104) and the second authentication unit (105) are authentication results for the same mobile body (20), access control based on only one of the authentication results (e.g., permission to access a specified area A1) is performed, thereby reducing the possibility that access control based on the other authentication result will be performed on another mobile body, thereby improving security.

[0291] In the control system (100) according to the seventeenth aspect, in the fifteenth aspect, the predetermined control includes access control. The access control is control that permits or prohibits access of the mobile object (20) to a predetermined area (A1). The control process includes outputting access control information. The access control information is information that causes the lock control device (30a) or the door control device (30b) to perform access control.

[0292] According to this aspect, by outputting control information to the lock control device (30a) or the door control device (30b), the lock control device (30a) or the door control device (30b) can be made to perform access control.

[0293] In a control system (100) according to an eighteenth aspect, in the sixteenth or seventeenth aspect, the control process includes outputting history information. The history information is information relating to the history of access control.

[0294] According to this aspect, by outputting the history information, it is possible to cause at least one of an external device of the control system (100) and an internal device of the control system to display or record the access control history.

[0295] The control system (100) according to a nineteenth aspect is in any one of the first to eighteenth aspects, and further includes at least one of a first acquisition unit (102) and a second acquisition unit (103).

[0296] According to this aspect, the control system (100) can acquire at least one of the first information and the second information by itself.

[0297] A control method according to the twentieth aspect includes a first authentication result acquisition step (S1, S101, S201), a second authentication result acquisition step (S2, S101, S201), and control steps (S3, S102 to S107, S202 to S207). In the first authentication result acquisition step (S1, S101, S201), an authentication result of the first authentication unit (104) is acquired. The first authentication unit (104) performs authentication based on first information acquired by the first acquisition unit (102). The first information is information associated with the mobile object (20). In the second authentication result acquisition step (S2, S101, S201), an authentication result of the second authentication unit (105) is acquired. The second authentication unit (105) performs authentication based on second information acquired by the second acquisition unit (103). The second information is information associated with the mobile object (20). In the control steps (S3, S102 to S107, S202 to S207), a control process is executed when a predetermined condition is satisfied. The control process is a process for performing predetermined control on the moving object (20) based on at least one of the authentication results acquired in the first authentication result acquisition step (S1, S101, S201) and the second authentication result acquisition step (S2, S101, S201). The control process is a process in which, when the first information and the second information are not associated with the same mobile body, predetermined control is performed based on each of the authentication results acquired in the first authentication result acquisition step (S1, S101, S201) and the second authentication result acquisition step (S2, S101, S201), and when the first information and the second information are associated with the same mobile body (20), predetermined control is performed based on one of the authentication results acquired in the first authentication result acquisition step (S1, S101, S201) and the authentication result acquired in the second authentication result acquisition step (S2, S101, S201), and predetermined control is not performed based on the other authentication result.

[0298] According to this aspect, when two authentication results obtained successively by the first authentication unit (104) and the second authentication unit (105) are authentication results for the same mobile body (20), by performing only a predetermined control based on one of the authentication results, the possibility of performing a predetermined control based on the other authentication result on another mobile body (20) is reduced, thereby improving security.

[0299] A program according to a twenty-first aspect is a program for causing one or more processors to execute the control method according to the twentieth aspect.

[0300] According to this aspect, when two authentication results obtained successively by the first authentication unit (104) and the second authentication unit (105) are authentication results for the same mobile body (20), by performing only a predetermined control based on one of the authentication results, the possibility of performing a predetermined control based on the other authentication result on another mobile body (20) is reduced, thereby improving security. [Explanation of symbols]

[0301] 100 Control System 101 Communications Department 101a 1st Communications Department 101b 2nd Communication Department 102 First acquisition part 103 Second acquisition part 104 First Authentication Section 105 Second Authentication Section 11 Processing section 111 First authentication result acquisition unit 112 Second authentication result acquisition unit 113 Control processing section 114 Location-related information acquisition unit 12 Output section 20 Mobile 201 Information terminal 300 Communication media 30 Controlled device 30a Lock control device 30b Door control device A1 designated area 200a First Authentication System 200b Secondary Authentication System

Claims

1. a first authentication result acquisition unit that acquires an authentication result of a first authentication unit that performs authentication based on first information, which is information associated with the mobile object and acquired by the first acquisition unit; a second authentication result acquisition unit that acquires an authentication result of a second authentication unit that performs authentication based on second information acquired by the second acquisition unit, the second information being information associated with the mobile object; a control processing unit that executes a control process to perform a predetermined control on a moving object based on at least one of the authentication results acquired by the first authentication result acquisition unit and the authentication result acquired by the second authentication result acquisition unit when a predetermined condition is satisfied, The control process includes: when the first information and the second information are not associated with the same mobile object, performing the predetermined control based on each of the authentication result acquired by the first authentication result acquisition unit and the authentication result acquired by the second authentication result acquisition unit; When the first information and the second information are associated with the same mobile body, the predetermined control is performed based on one of the authentication result acquired by the first authentication result acquisition unit and the authentication result acquired by the second authentication result acquisition unit, and the predetermined control is not performed based on the other authentication result. Control system.

2. the predetermined condition is a condition that each of the first authentication unit and the second authentication unit has performed authentication. The control system of claim 1 .

3. the predetermined condition is that one of the first authentication unit and the second authentication unit performs authentication within a predetermined time after the other authentication unit performs authentication; The control system of claim 1 .

4. the first authentication result acquisition unit receives the authentication result of the first authentication unit from a first authentication system including the first authentication unit; the second authentication result acquisition unit receives the authentication result of the second authentication unit from a second authentication system including the second authentication unit; the predetermined condition is a condition that each of the first authentication result acquisition unit and the second authentication result acquisition unit receives the authentication result. The control system of claim 1 .

5. the first authentication result acquisition unit receives the authentication result of the first authentication unit from a first authentication system including the first authentication unit; the second authentication result acquisition unit receives the authentication result of the second authentication unit from a second authentication system including the second authentication unit; the predetermined condition is that after one of the first authentication result acquisition unit and the second authentication result acquisition unit receives the authentication result, the other authentication result acquisition unit receives the authentication result within a predetermined time. The control system of claim 1 .

6. the first acquisition unit acquires the first information by a first method; the second acquisition unit acquires the second information by a second method different from the first method; A control system according to any one of claims 1 to 5.

7. At least one of the first acquisition unit and the second acquisition unit acquires information corresponding to the at least one of the first information and the second information from a communication unit that wirelessly communicates with an information terminal held by a mobile object. A control system according to any one of claims 1 to 5.

8. The wireless communication includes ultra-wideband wireless communication. The control system of claim 7.

9. The communication unit a first communication unit that receives at least one of the first information and the second information from the information terminal by wireless communication; a second communication unit that performs ultra-wideband wireless communication with the information terminal; The control system of claim 7.

10. a location-related information acquisition unit that acquires location-related information regarding at least one of a distance between the second communication unit and the information terminal and a location of the information terminal, using a signal transmitted and received by ultra-wideband wireless communication of the second communication unit; 10. The control system of claim 9.

11. The first acquisition unit and the second acquisition unit one acquisition unit acquires information corresponding to the one acquisition unit out of the first information and the second information through first wireless communication having a communication range that is equal to or less than a first reference value; the other acquisition unit acquires the information corresponding to the other acquisition unit out of the first information and the second information through second wireless communication having a communication range of a communication distance equal to or less than a second reference value that is greater than the first reference value; The control system of claim 10.

12. the location-related information acquisition unit acquires the location-related information by using a signal transmitted and received through the second wireless communication. The control system of claim 11.

13. the moving body is a human body, At least one of the first acquisition unit and the second acquisition unit acquires biometric information of the human body as information corresponding to the at least one of the first information and the second information. A control system according to any one of claims 1 to 5.

14. The biometric information includes an image of the face of the human body.

14. The control system of claim 13.

15. the control processing includes outputting control information for the predetermined control. A control system according to any one of claims 1 to 5.

16. The predetermined control includes access control for permitting or prohibiting access to a predetermined area of ​​the mobile object. A control system according to any one of claims 1 to 5.

17. the predetermined control includes access control for permitting or prohibiting access of a mobile object to a predetermined area; The control process includes outputting access control information to cause a lock control device or a door control device to perform the access control.

16. The control system of claim 15.

18. the control process includes outputting history information regarding a history of the access control; 17. The control system of claim 16.

19. The device further includes at least one of the first acquisition unit and the second acquisition unit. A control system according to any one of claims 1 to 5.

20. a first authentication result acquisition step of acquiring an authentication result of a first authentication unit that performs authentication based on first information, which is information associated with the mobile object and acquired by a first acquisition unit; a second authentication result acquisition step of acquiring an authentication result of a second authentication unit that performs authentication based on second information, which is information associated with the mobile object and acquired by the second acquisition unit; a control step of executing a control process for performing a predetermined control on a moving object based on at least one of the authentication results acquired in the first authentication result acquisition step and the authentication result acquired in the second authentication result acquisition step when a predetermined condition is satisfied, The control process includes: performing the predetermined control based on each of the authentication result acquired in the first authentication result acquisition step and the authentication result acquired in the second authentication result acquisition step when the first information and the second information are not associated with the same moving body; When the first information and the second information are associated with the same mobile body, the predetermined control is performed based on one of the authentication result acquired in the first authentication result acquisition step and the authentication result acquired in the second authentication result acquisition step, and the predetermined control is not performed based on the other authentication result. Control method.

21. 21. A method for causing one or more processors to execute the control method of claim 20. program.

Citation Information

Patent Citations

  • Entrance / Exit management equipment, intruder supervisory equipment and card reader

    JP1995160963A