Access permission system and access permission method

The access permission system uses encrypted authentication codes to restrict website access to specific storage media, ensuring secure and targeted content display and mobile ordering by preventing unauthorized access.

JP2026062370AActive Publication Date: 2026-04-09TUNE UP CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Existing systems fail to allow access to websites only through specific storage media, such as NFC tags or QR codes, leading to challenges in utilizing website-based marketing, promotions, and mobile ordering since user devices can repeatedly access previously visited URLs.

Method used

An access permission system that uses an encrypted authentication code added as a parameter to a URL, requiring decryption and matching with a registered code to allow access, and displaying error screens for unauthorized access attempts.

Benefits of technology

Enables access to websites only through specific storage media, enhancing security and allowing targeted content display and mobile ordering, while preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026062370000001_ABST
    Figure 2026062370000001_ABST
Patent Text Reader

Abstract

This invention provides an access permission system and access permission method that allows access to a website only through a specific storage medium. [Solution] The access permission system 1 comprises a user terminal 11, a storage medium 12, and a server. The server comprises a first determination control unit, a second determination control unit, and a transfer control unit. The storage medium stores an additional URL in which an encrypted code obtained by encrypting the authentication code is attached as a parameter to the authentication URL. When the user terminal accesses the authentication URL, the first determination control unit determines whether or not an encrypted code is attached to the authentication URL. If an additional encrypted code is attached, the second determination control unit decrypts the additional encrypted code and determines whether or not the decrypted code matches a registered authentication code associated with a registered authentication URL in a predetermined registration table. If they match, the transfer control unit transfers the user terminal to the target URL for access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an access permission system and an access permission method.

Background Art

[0002] Conventionally, there are various techniques that enable only a specific user to access a specific web service when the user accesses the web service. For example, Japanese Patent Application Laid-Open No. 2018-151795 (Patent Document 1) discloses a web service providing system including a web service providing unit and an authentication unit. Here, the web service providing unit provides a web service to an authenticated user. The authentication unit performs authentication processing for a user, assigns different identification information to each user who has completed authentication, and causes the user terminal used by the user to receive the provision of a desired web service to transmit the identification information assigned to the user to the web service providing unit that provides the web service desired by the user. The web service providing unit identifies the authentication state of the user using the identification information received from the user terminal, and permits the user to use the web service provided by itself when the user is authenticated. This is said to enable single sign-on at a lower cost.

[0003] Further, Japanese Patent Application Laid-Open No. 2006-079598 (Patent Document 2) discloses an access control system including an access code generation means, an authentication information notification means, and an access control means. Here, the access code generation means generates an access code in association with information related to the address of one or more access permitters whose access is permitted. The authentication information notification means receives an access code from an accessor and notifies predetermined authentication information to the address of the access permitter obtained based on the access code. The access control means receives authentication information from the accessor and permits access by the accessor on the condition that the authentication information corresponds to the authentication information notified by the authentication information notification means. This is said to be able to reliably authenticate whether an access request is from a legitimate accessor.

[0004] Furthermore, Japanese Patent Publication No. 2002-259838 (Patent Document 3) discloses a system for supplying information including access permission information, comprising an access permission information management device, an information providing device, and a user terminal device. In this system, the access permission information management device generates access permission information in response to requests and records information acquired in connection with the generation of access permission information and information generated in connection with the generation. The information providing device has information including access permission information generated by the access permission information management device and provides the information to the user terminal device in response to a request from the user terminal device. When the user terminal device receives the information, it determines whether it is permitted to reproduce the information from the access permission information contained in the information, and if it determines that it is permitted, it reproduces the information. This makes it possible to have the user terminal device autonomously determine whether or not the conditions for access permission are met by using access permission information which describes the conditions for access permission, without querying a special management device or other database server.

[0005] Furthermore, Japanese Patent Publication No. 2024-017815 (Patent Document 4) discloses a service provision system comprising an NFC tag sheet and a server. In this system, the NFC tag sheet is installed around the user's seat at an event venue, and multiple NFC readers, each clearly identifiable, are arranged side by side. The server obtains connection destination information from the NFC readers via short-range wireless communication and provides different services, each corresponding to the connection destination information, to the user's terminal, accompanied by the display of a web page. This is intended to facilitate access to the service.

[0006] Furthermore, Japanese Patent Publication No. 2014-157564 (Patent Document 5) discloses an order receiving device comprising a communication means, an order receiving means, an identification acquisition means, an order transmission means, a writing means, a reading means, an order receiving means, a display means, and a confirmation means. Here, the communication means communicates data with a server that manages order data. The order receiving means accepts input from the customer of the menu items to be ordered from among a plurality of menu items that are the subject of the order. The identification acquisition means acquires order identification information to identify the order data of the menu items accepted by the order receiving means. The order transmission means transmits the order data of the menu items accepted by the order receiving means to the server via the communication means, associating it with the order identification information acquired by the identification acquisition means. The writing means writes the order identification information acquired by the identification acquisition means to a portable storage medium. The reading means reads the order identification information from the storage medium. The order receiving means receives order data, which is managed in association with the order identification information read from the storage medium by the reading means, from the server via the communication means. The display means displays the order data received by the order receiving means on the display unit. The confirmation means confirms the order data displayed on the display unit. This makes it possible to notify the server that manages the order data of the menu items that the customer has decided to order while waiting.

[0007] Furthermore, Japanese Patent Publication No. 2019-079293 (Patent Document 6) discloses a service application issuance system comprising a mobile terminal, an IC card, and an installer. Here, the mobile terminal includes a camera unit and an NFC unit. The installer is installed on the mobile terminal and installs a service application on the mobile terminal that emulates the operation of the IC card selected by the user. The IC card has contactless communication capabilities. By imaging the IC card with the camera unit, information about the user written on the outer surface of the IC card is acquired. The contactless R / W function of the NFC unit acquires service application issuance data from the IC card to activate the service application. The acquired information is supplied to the installer to activate the service application. As a result, when issuing services to mobile terminals such as smartphones, there is no need to build a server system and there is no risk of information leakage.

[0008] Furthermore, Japanese Patent Publication No. 2022-172003 (Patent Document 7) discloses a product purchase system comprising a terminal device and a site operation server that operates a shopping site. Here, the terminal device comprises a reading unit and a transmitting unit. The reading unit reads access information and media identification information from a recording medium for accessing the site operation server. The transmitting unit accesses the site operation server according to the access information and transmits the media identification information to the site operation server. The site operation server comprises a display content determination unit and a site provision unit. The display content determination unit determines the display content of the shopping site based on the media identification information received from the terminal device. The site provision unit provides the terminal device with the shopping site with the display content determined by the display content determination unit. This makes it easy for users to use.

[0009] Furthermore, Japanese Patent Publication No. 2015-194867 (Patent Document 8) discloses a communication terminal comprising a reading unit, an authentication request unit, and a registration unit. In this terminal, the reading unit reads the URL and authentication information from a membership card that stores the URL and authentication information. When the reading unit reads the URL and authentication information, the authentication request unit accesses the site indicated by the URL, transmits the authentication information, and initiates the authentication process. The registration unit registers the terminal's identification information with the site. If the identification information is already registered with the site, the authentication request unit initiates the authentication process using the registered identification information instead of the authentication information. This allows the communication terminal to easily access a specific site and improves the security of authentication. [Prior art documents] [Patent Documents]

[0010] [Patent Document 1] Japanese Patent Publication No. 2018-151795 [Patent Document 2] Japanese Patent Publication No. 2006-079598 [Patent Document 3] Japanese Patent Publication No. 2002-259838 [Patent Document 4] Japanese Patent Publication No. 2024-017815 [Patent Document 5] Japanese Patent Publication No. 2014-157564 [Patent Document 6] Japanese Patent Publication No. 2019-079293 [Patent Document 7] Japanese Patent Publication No. 2022-172003 [Patent Document 8] Japanese Patent Publication No. 2015-194867 [Overview of the project] [Problems that the invention aims to solve]

[0011] In recent years, technologies have emerged that allow users to access websites with specific URLs (Uniform Resource Locators) using storage media such as NFC (Near Field Communication) tags, QR codes (registered trademark), and two-dimensional barcodes. For example, a user can hold their device over a designated storage medium, allowing the device to retrieve a URL pre-stored on the medium and access a website based on that URL.

[0012] In this context, SEO (Search Engine Optimization) and MEO (Map Engine Optimization) are generally important for websites using URLs. Furthermore, from a marketing perspective, it is important to increase awareness of businesses such as restaurants and service establishments by linking URL websites with social networking services (SNS). In addition, it is important for URL websites to showcase the appeal of the business and cultivate loyal customers by creating limited-time menus, posting information about the business's services and photos.

[0013] On the other hand, stores have a need to allow only user terminals connected to specific storage media to access certain websites. For example, a store can make a website feel special by posting seasonal or period-specific content, or by including content that cannot be accessed externally. Furthermore, since the specific website is not accessible to external users, it can be used as a menu within the store, allowing users to place orders and make payments from their own devices while in the store, thus enabling mobile ordering. For these reasons, a system is needed that allows only user terminals connected to specific storage media to access specific websites.

[0014] However, generally speaking, once a user's device accesses a website, the URL of that website remains in the user's access history. This presents a challenge in that the aforementioned system cannot be built simply by accessing websites based on their URLs. In other words, because a user's device can access a website it has already visited again, stores face the challenge of not being able to easily utilize website-based marketing, promotions, mobile ordering, etc.

[0015] Here, the technology described in Patent Document 1 allows the use of a web service by authenticating the user. The technology described in Patent Document 2 allows access by legitimate users based on authentication information. The technology described in Patent Document 3 allows browsing on the user terminal device if the conditions for browsing permission are met. The technology described in Patent Document 4 provides different services, accompanied by the display of a web page, corresponding to each connection destination information, using an NFC tag sheet. The technology described in Patent Document 5 notifies the customer of the menu items they have decided to order while they are waiting. The technology described in Patent Document 6 obtains service application issuance data from an IC card. The technology described in Patent Document 7 provides the terminal device with a shopping site with display content determined by a display content determination unit. The technology described in Patent Document 8 performs the authentication process using registered identification information instead of authentication information. Thus, the technologies described in Patent Documents 1-8 lack the perspective that only user terminals connected via a specific storage medium can access a specific website, and therefore cannot solve the above-mentioned problems.

[0016] Therefore, the present invention has been made to solve the aforementioned problems and aims to provide an access permission system and access permission method that can permit access to a website only through a specific storage medium. [Means for solving the problem]

[0017] The access permission system according to the present invention includes a storage medium, a first determination control unit, a first error control unit, a second determination control unit, a second error control unit, a transfer control unit, and a third error control unit. The storage medium stores an additional URL in which an encrypted code obtained by encrypting an authentication code is added as a parameter to an authentication URL. When the user terminal reads the additional URL of the storage medium and accesses the authentication URL of the additional URL, the first determination control unit determines whether the encrypted code is added to the authentication URL. If the encrypted code is not added to the authentication URL as a result of the determination, the first error control unit displays an error screen. When the encrypted code is added to the authentication URL as a result of the determination, the second determination control unit decrypts the additional encrypted code added to the authentication URL, and determines whether the decrypted code matches a registered authentication code associated with a registered authentication URL in a predetermined registration table. If the decrypted code does not match the registered authentication code as a result of the determination, the second error control unit displays an error screen. When the decrypted code matches the registered authentication code as a result of the determination, the transfer control unit transfers the user terminal to the target URL for access. If the user terminal accesses the target URL without passing through the authentication URL, the third error control unit displays an error screen.

[0018] Further, the access permission method according to the present invention includes a storage medium, a first determination control step, a first error control step, a second determination control step, a second error control step, a transfer control step, and a third error control step. Here, each control step of the access permission method corresponds to each control unit of the access permission system.

Effect of the Invention

[0019] According to the present invention, it is possible to permit access only to a website via a specific storage medium.

Brief Description of the Drawings

[0020] [Figure 1]It is a functional block diagram of an access permission system according to the present invention. [Figure 2] It is a flowchart for showing an execution procedure of an access permission system according to the present invention. [Figure 3] It is a diagram (FIG. 3A) showing an example when an authentication URL is set from a target URL and an authentication code is generated, and a diagram (FIG. 3B) showing an example when the authentication code is encrypted and an additional URL is generated using the encrypted code. [Figure 4] It is a diagram (FIG. 4A) showing an example of a registration table, and a diagram (FIG. 4B) showing an example when an administrator stores an additional URL in a storage medium. [Figure 5] It is a diagram (FIG. 5A) showing an example when a consumer reads an additional URL from a storage medium of a store and accesses an authentication URL, and a diagram (FIG. 5B) showing an example when no encrypted code is added to the authentication URL. [Figure 6] It is a diagram (FIG. 6A) showing an example when an encrypted code is added to an authentication URL, and a diagram (FIG. 6B) showing an example when a decrypted code does not match a registered authentication code. [Figure 7] It is a diagram (FIG. 7A) showing an example when a decrypted code matches a registered authentication code, and a diagram (FIG. 7B) showing an example of an order screen. [Figure 8] It is a diagram (FIG. 8A) showing an example of a payment screen, and a diagram (FIG. 8B) showing an example when a user terminal accesses a target URL without going through an authentication URL. [Figure 9] It is a diagram (FIG. 9A) showing an example when a target URL is set for each table and an example when a storage medium for each table is installed, and a diagram (FIG. 9B) showing an example when a consumer reads an additional URL from a storage medium of the first table. [Figure 10] It is a diagram (FIG. 10A) showing an example when an encrypted code and an identification code are added to an authentication URL and an example when a storage medium for each table is installed, and a diagram (FIG. 10B) showing an example when a consumer reads an additional URL from a storage medium of the first table. [Modes for carrying out the invention]

[0021] The following describes embodiments of the present invention with reference to the attached drawings to facilitate understanding of the invention. Note that the following embodiments are merely examples of the present invention and do not limit the technical scope of the invention.

[0022] As shown in Figure 1, the access permission system 1 according to an embodiment of the present invention comprises a management terminal 10, a user terminal 11, a storage medium 12, a network 13, and a server 14.

[0023] Here, the management terminal 10 and the user terminal 11 are commonly used computers, and for example, they include a display unit (output unit) that displays a screen (window), a reception unit (input unit) that receives input of predetermined instructions by user operation, a communication unit for wireless or wired communication, a storage unit for storing data, and a processing unit that controls each unit. Here, the reception unit can, for example, read data stored in the storage medium 12. In addition, the communication units of the management terminal 10 and the user terminal 11 can communicate with the server 14 via the network 13, for example.

[0024] Furthermore, the administrator terminal 10 may be, for example, a desktop terminal device. The user terminal 11 may be, for example, a portable terminal device such as a mobile terminal device with a touch panel (smartphone) or a tablet terminal device.

[0025] Furthermore, the storage medium 12 stores data that can be read by the user terminal 11. There are no particular limitations on the configuration of the storage medium 12, but examples include NFC tags, QR codes (registered trademarks), two-dimensional barcodes, etc.

[0026] Furthermore, network 13 is connected to the management terminal 10, the user terminal 11, and the server 14 in a communication-enabled manner. Network 13 includes wireless communication networks such as Wi-Fi®, LAN (Local Area Network) via access points, WAN (Wide Area Network) via wireless base stations, third-generation (3G) communication methods, fourth-generation (4G) communication methods such as LTE, fifth-generation (5G) and later communication methods, Bluetooth®, and specified low-power wireless methods.

[0027] Furthermore, server 14 is a commonly used computer, and for example, it includes a communication unit for wireless and wired communication, a storage unit for storing data, and a processing unit for controlling each unit. Server 14 also primarily sends and receives data with the management terminal 10 and user terminal 11 via the network 13. Here, server 14 may also function as a different server 15, or it may cooperate with a different server 15.

[0028] Furthermore, the management terminal 10, user terminal 11, and server 14 all have built-in CPUs, ROMs, RAMs, SSDs, etc. (not shown). The CPU, for example, uses RAM as a workspace and executes programs stored in the ROMs, SSDs, etc. Each control unit, described later, also realizes its function by having the CPU execute programs.

[0029] Next, the configuration and execution procedure of an embodiment of the present invention will be described with reference to Figures 1-10. For example, a user (client) of a store such as a restaurant or service store provides the administrator of the access permission system 1 with the URL of the website they want to access at that location (hereinafter referred to as the "target URL," for example, "https: / / abc"), as shown in Figure 3A.

[0030] Here, the user could be, for example, a store manager, owner, or business owner. The target URL is the URL of a website that the user wants consumers or business partners (so-called users) to access. The target URL could be, for example, the URL of a store's ordering site or accounting site.

[0031] The administrator then uses the provided target URL ("https: / / abc") to create an authentication URL (for example, "https: / / abc / def") that the user terminal 11 will access first (Figure 2: S101).

[0032] There are no particular limitations on how the authentication URL is created, but for example, an administrator can create it by using the management terminal 10 to append a string indicating the access destination to server 14 (for example, "def") to the target URL ("https: / / abc"). The created authentication URL ("https: / / abc / def") is then set as the access destination to server 14, for example. Therefore, the access destination of the target URL ("https: / / abc") and the access destination of the authentication URL ("https: / / abc / def") may be different.

[0033] Next, when the administrator accesses the server 14 via the network 13 using the management terminal 10 based on the authentication URL ("https: / / abc / def"), the generation control unit 101 of the server 14 accepts the access from the management terminal 10. Then, when the administrator instructs the server 14 to encrypt the authentication code and generate an additional URL using the management terminal 10, the generation control unit 101 generates the authentication code and encrypts the authentication code (Figure 2: S102).

[0034] Here, there are no particular limitations on the method of generating the authentication code in the generation control unit 101. For example, it may generate a random string (e.g., "ab01") as the authentication code, regardless of the authentication URL ("https: / / abc / def"), or it may generate a string ("ab01") output from a predetermined code generation unit by inputting the authentication URL ("https: / / abc / def") into the code generation unit.

[0035] Now, when the generation control unit 101 generates an authentication code ("ab01"), it encrypts the authentication code (Figure 2: S103).

[0036] Here, the method for encrypting the authentication code in the generation control unit 101 is not particularly limited, but for example, as shown in Figure 3B, the authentication code ("ab01") is encrypted using a predetermined encryption generation unit to generate an encrypted code (e.g., "xyz012"), and the authentication code is then encrypted. Here, the encryption generation unit is not particularly limited, but for example, an encryption function such as a hash function can be used.

[0037] Now, when the generation control unit 101 generates the encrypted code, it generates an additional URL (for example, "https: / / abc / def / ?pm=xyz012") by adding the encrypted code ("xyz012") as an encrypted parameter to the authentication URL ("https: / / abc / def") (Figure 2: S104).

[0038] Here, the method for generating the additional URL by the generation control unit 101 is not particularly limited, but for example, the additional URL ("https: / / abc / def / ?pm=xyz012") is generated by adding the encryption code ("xyz012") as an encryption parameter to the authentication URL ("https: / / abc / def"). Here, when adding the encryption code as an encryption parameter to the additional URL, a specific symbol (e.g., "?") is set to the end of the authentication URL, and a specific symbol indicating the encryption parameter (e.g., "pm") is set, so for example, "?pm=xyz012" is added to the end of the authentication URL. In this way, the encryption code can be added to the authentication URL as an encryption parameter.

[0039] Furthermore, parameters attached to a URL can generally be seen by a user when accessing it using the user terminal 10. Therefore, in this invention, by making the parameters into an encrypted code, even if a user sees the encrypted code, this encrypted code is meaningless unless it is decrypted, thus preventing the authentication code from being leaked to the user and enhancing security.

[0040] Furthermore, an appended URL is also called a parameterized URL. The symbol used to indicate an encryption parameter is appropriately designed and modified depending on the type of encryption parameter. For example, if the encryption code is a hash value, the symbol used to indicate the encryption parameter can be "hash".

[0041] The generation control unit 101 then sends the additional URL ("https: / / abc / def / ?pm=xyz012") to the management terminal 10, and the management terminal 10 notifies the administrator of the additional URL ("https: / / abc / def / ?pm=xyz012"). This allows the administrator to obtain the additional URL.

[0042] Now, when the generation control unit 101 generates an additional URL, it stores the authentication code obtained by decrypting the encrypted code as the registered encrypted code in a predetermined registration table (Figure 2: S105).

[0043] Here, there are no particular limitations on how the generation control unit 101 stores the registered cryptographic code, but for example, the generation control unit 101 refers to a registration table that is pre-stored in a predetermined memory. As shown in Figure 4A, the registration table 400 stores the registration authentication URL 401, the registration authentication code 402, and the registration purpose URL 403 in association with each other. The generation control unit 101 stores the authentication URL of the additional URL ("https: / / abc / def") associated with the registration authentication URL 401 in the registration table 400, and stores the cryptographic code of the additional URL ("ab01") associated with the registration cryptographic code 402 in the registration table 400. This makes it possible to pre-register the authentication code for the authentication URL.

[0044] Furthermore, the registration authentication code ("ab01") can be changed as needed at the instruction of the user or administrator. Therefore, by setting an expiration date for the registration authentication code, it is possible to prevent access to the target URL once the encryption code's expiration date has passed, even if the additional URL is stored on the same storage medium 12.

[0045] Furthermore, the generation control unit 101 associates the target URL of the authentication URL ("https: / / abc") with the registration target URL 403 in the registration table 400 and stores it there. This makes it possible to pre-register the target URL ("https: / / abc") to which the user will be redirected based on the authentication URL determination. Although the registration table 400 is configured to store the authentication URL, authentication code, and target URL together, it is not limited to this configuration.

[0046] Now, when the administrator obtains an additional URL, they store the obtained additional URL in a predetermined storage medium 12 (Figure 2: S106).

[0047] There are no particular limitations on how the administrator stores the additional URL, but for example, as shown in Figure 4B, the administrator can use the management terminal 10 to store the additional URL ("https: / / abc / def / ?pm=xyz012") on the NFC tag 12a, or output a QR code (registered trademark) 12b or a two-dimensional barcode 12c corresponding to the additional URL ("https: / / abc / def / ?pm=xyz012"). The administrator can then store the additional URL in the storage medium 12 by embedding the NFC tag 12a in the storage medium 12, or by printing or attaching the QR code (registered trademark) 12b or the two-dimensional barcode 12c to the storage medium 12. There are no particular limitations on the storage medium 12, but examples include paper media such as shop cards, menu cards, posters, coasters, and stickers, as well as plastic media and electronic media. This allows the administrator to freely design the storage medium 12.

[0048] Once the administrator stores the additional URL in the storage medium 12, they provide the storage medium 12 to the user, who then installs or attaches the storage medium 12 in their store so that consumers and business partners visiting the store can use it.

[0049] Then, for example, a consumer visits the user's store, finds the storage medium 12 installed there, and reads the attached URL of the storage medium 12 ("https: / / abc / def / ?pm=xyz012") using their user terminal 11 (Figure 2: S201).

[0050] Here, there are no particular limitations on how the user terminal 11 reads the additional URL. For example, as shown in Figure 5A, if the additional URL ("https: / / abc / def / ?pm=xyz012") is stored in the NFC tag 12a, the user holds the user terminal 11 over the NFC tag 12a on the storage medium 12. Then, the wireless communication unit of the user terminal 11 and the NFC tag 12a perform short-range wireless communication, and the user terminal 11 can read the additional URL stored in the NFC tag 12a. Alternatively, if the additional URL is a QR code (registered trademark) 12b or a two-dimensional barcode 12c, the user activates the camera pre-installed on the user terminal 11 and takes a picture of the QR code (registered trademark) 12b or two-dimensional barcode 12c with the user terminal 11's camera. The user terminal 11 then analyzes the QR code (registered trademark) 12b or two-dimensional barcode 12c and reads the additional URL corresponding to the QR code (registered trademark) 12b or two-dimensional barcode 12c.

[0051] When the user terminal 11 reads the added URL, the user terminal 11 accesses the server 14 based on the authentication URL of the added URL (Figure 2: S202). Then, the determination control unit 102 of the server 14 determines whether or not an encryption code is attached to the authentication URL accessed by the user terminal 11 (Figure 2: S203).

[0052] Here, there are no particular limitations on the determination method of the first determination control unit 102, but for example, the first determination control unit 102 determines whether or not an encryption code ("xyz012") is attached to the authentication URL ("https: / / abc / def") that the user terminal 11 accesses.

[0053] If the determination result indicates that no encryption code is attached to the authentication URL (Figure 2: S203NO), the first determination control unit 102 determines that the user terminal 11 has not accessed the server 14 via the storage medium 12. In this case, for example, it corresponds to the case where the user terminal 11 accessed using an authentication URL ("https: / / abc / def") stored in the access history.

[0054] Now, if the first determination control unit 102 determines that the user terminal 11 is not accessing the server 14 via the storage medium 12, the first error control unit 103 of the server 14 will deny the user terminal 11 access to the target URL ("http: / / abc") related to the authentication URL ("https: / / abc / def") (Figure 2: S204).

[0055] There are no particular limitations on how the first error control unit 103 displays information, but for example, as shown in Figure 5B, the error screen 500 may display, for example, the URL 501 of the accessed site ("https: / / abc / def / error") and a message 502 indicating the error. Alternatively, the error screen 500 may not display any message at all. In other words, it is sufficient for the first error control unit 103 to indicate that access from the user terminal 11 has been denied. This allows the consumer to understand that access has been denied.

[0056] In this case, since the consumer has not accessed the authentication URL by reading the additional URL stored in the storage medium 12, the server 14 rejects access from such a consumer's user terminal 11. This makes it possible to limit access to user terminals 11 via the storage medium 12 at the store. Furthermore, since the user terminal 11 retains an access history of the error screen 500, it will not access the authentication URL again in the future.

[0057] On the other hand, in S203, for example, as shown in Figure 6A, if the determination result indicates that some kind of encryption code (for example, "xyz345") is attached to the authentication URL (Figure 2: S203YES), the first determination control unit 102 determines that the user terminal 11 is accessing the server 14 via the storage medium 12. Then, the second determination control unit 104 of the server 14 decrypts the attached encryption code ("xyz345") attached to the authentication URL (Figure 2: S205) and determines whether the decrypted code matches the registration authentication code associated with the registration authentication URL in a predetermined registration table (Figure 2: S206).

[0058] Here, there are no particular limitations on the determination method of the second determination control unit 104, but for example, as shown in Figure 6A, the second determination control unit 104 decrypts the added cipher code ("xyz345") and generates the decrypted code (for example, "cd02"). Here, there are no particular limitations on the decryption method of the second determination control unit 104, but for example, one method is to decrypt the cipher code ("xyz345") using the decryption generation unit corresponding to the cipher generation unit described above.

[0059] The second determination control unit 104 then refers to a registration table 400 that has been pre-stored in a predetermined memory. The second determination control unit 104 then searches the registration authentication URL 401 in the registration table 400 for the authentication URL of the access destination ("https: / / abc / def") and refers to the registration authentication code 402 ("ab01") associated with the found registration authentication URL 401. The second determination control unit 104 then determines whether the generated decryption code ("cd02") matches the referenced registration authentication code 402.

[0060] If the determination result shows that the decryption code does not match the registered authentication code (Figure 2: S206NO), the second determination control unit 104 determines that the user terminal 11 is accessing the server 14 via the storage medium 12, but that there is an error in the encryption code. In this case, for example, as shown in Figure 6B, the user terminal 11 has accessed the authentication URL ("https: / / abc / def") via the store's storage medium 12, but the encryption code of the additional URL on the storage medium 12 has expired.

[0061] Now, if the second determination control unit 104 determines that there is an error in the encryption code, the second error control unit 105 of the server 14 displays an error screen (Figure 2: S204).

[0062] There are no particular limitations on how the second error control unit 105 displays information, but for example, as shown in Figure 6B, the error screen 600 may display the accessed URL 601 ("https: / / abc / def / error") and an error message 602, similar to those described above. Alternatively, the error screen 600 may not display any message, or a different error screen 600 may be displayed. In other words, it is sufficient for the second error control unit 105 to indicate that access from the user terminal 11 has been denied. This allows the consumer to understand that access has been denied.

[0063] In this case, for example, the user or administrator updates the additional URL stored on the storage medium 12 to update the encryption code. In this case, if a consumer reads the additional URL stored on the storage medium 12 before the update and accesses the authentication URL, although the encryption code is attached as an encryption parameter, the old encryption code will not decrypt it into the latest correct authentication code. As a result, the server 14 will reject access from such a consumer's user terminal 11. This makes it possible to limit access to user terminals 11 via the updated storage medium 12 at the store. Furthermore, since the access history of the error screen 600 remains on the user terminal 11, it will not access the authentication URL again in the future.

[0064] On the other hand, in S206, for example as shown in Figure 7A, if the result of the determination is that the decryption code matches the registered encryption code (Figure 2: S206 YES), the second determination control unit 104 determines that the user terminal 11 is accessing the server 14 via the updated storage medium 12. Then, the transfer control unit 106 of the server 14 transfers the user terminal 11 to access the target URL (Figure 2: S207).

[0065] Here, there are no particular limitations on the transfer method of the transfer control unit 106, but for example, as shown in Figure 7A, the transfer control unit 106 refers to a registration table 400 that is pre-stored in a predetermined memory, searches for a registration authentication URL 401 corresponding to the authentication URL of the access destination ("https: / / abc / def") in the referenced registration table 400, and refers to the registration purpose URL 403 ("https: / / abc") associated with the found registration authentication URL 401. Then, the transfer control unit 106 uses the referenced registration purpose URL 403 to change the authentication URL of the access destination ("https: / / abc / def") to the purpose URL ("https: / / abc") and transfers (redirects). As a result, the user terminal 11 accesses the purpose URL ("https: / / abc") from the authentication URL ("https: / / abc / def") and displays the purpose screen based on the purpose URL ("https: / / abc").

[0066] Here, the target screen 700 displays, for example, the URL 701 to access ("https: / / abc") and a message 702 indicating that it is the top screen, as shown in Figure 7A. The target screen 700 is a screen related to the user's store. This allows consumers to display screens related to the store they have visited on their user terminal 11.

[0067] The target screen 700 is displayed exclusively to user terminals 1 accessed via the storage medium 12 after it has been updated at the store. Therefore, the store can display content on the target screen 700 that is appropriate for the season or period, or include content that cannot be accessed externally.

[0068] Furthermore, since the target screen 700 can only be accessed by user terminals 11 via a specific storage medium 12, it is possible to set the target URL to, for example, the URL of a platform that aggregates a specific field or industry, so that only consumers and traders in that specific field or industry can access it to communicate and exchange information.

[0069] Here, for example, if a customer in a store uses the user terminal 11 to switch the screen display from the destination screen 700 to the order screen, the order screen 703 will display, for example, the accessed URL 704 ("https: / / abc / order") and a message 705 indicating that it is the order screen 703, as shown in Figure 7B.

[0070] Here, when a consumer places an order for goods or services from the order screen 703, the server 14 receives the consumer's order information. Based on the consumer's order information received by the server 14, the user provides the goods or services to the consumer. Furthermore, by receiving consumer order information, the server 14 can periodically accumulate consumer order information, and by analyzing and interpreting the accumulated consumer order information, it is possible to promote the development of new goods and services.

[0071] Furthermore, for example, when a consumer goes to the store's cash register to pay and switches the screen display from the order screen 700 to the payment screen using the user terminal 11, the order screen 800 will display, for example, the accessed URL 801 ("https: / / abc / account") and a message 802 indicating that it is the payment screen 800, as shown in Figure 8A.

[0072] Here, the consumer will perform the accounting and payment while viewing the payment screen 802 on the user's screen, and the server 14 will receive the consumer's payment information from the payment screen 802. Based on the consumer's payment information received by the server 14, the user can show the consumer the amount due and prompt them to make the payment.

[0073] There are no particular limitations on this payment method; for example, consumers may pay users in cash to complete the payment, or server 14 may, by receiving the consumer's payment information, cooperate with other servers to provide consumers with other payment methods such as bank transfers, electronic money payments, or credit card payments. By server 14 receiving the consumer's payment information, it becomes possible, for example, to link server 14 with an accounting server to periodically accumulate accounting information using the consumer's payment information. By analyzing and interpreting the accumulated accounting information, it becomes possible to immediately check the sales performance, expense trends, and profit trends of products and services.

[0074] Incidentally, once a user terminal 11 accesses the target URL 403 ("https: / / abc"), that URL 403 ("https: / / abc") will be stored in its access history. In this case, it becomes possible to access the target URL 403 ("https: / / abc") even without coming to the store, which could lead to fraudulent orders or payments.

[0075] Therefore, in this invention, if the user terminal 11 accesses the target URL without going through the authentication URL (Figure 2: S208), the third error control unit 107 of the server 14 displays an error screen, as shown in Figure 8B (Figure 2: S204).

[0076] There are no particular limitations on how the third error control unit 107 displays information, but for example, as shown in Figure 8B, the error screen 803 may display the accessed URL 804 ("https: / / abc / def / error") and an error message 805, similar to those described above. Alternatively, the error screen 803 may not display any message, or a different error screen 803 may be displayed. In other words, it is sufficient for the third error control unit 107 to indicate that access from the user terminal 11 has been denied. This allows the consumer to understand that access has been denied.

[0077] In this case, consumers realize that they cannot access the target URL unless they visit the store and read the store's storage medium 12. This makes it possible to limit access to user terminals 11 via the storage medium 12 at the store. Although the above explanation described the case of directly accessing the target URL, the same error screen 803 will be displayed even if the user directly accesses a lower-level address of the target URL.

[0078] By the way, since the target screen accessed via the target URL is not accessible to external consumers or traders, it can be used as a menu by the store and thus utilized for mobile ordering.

[0079] For example, if a store user provides the administrator with a target URL (e.g., "https: / / ghi") that points to the store's order website, the administrator uses the target URL to create an authentication URL ("https: / / ghi / jkl") (Figure 2: S101). Here, the server 15 of the target URL is different from the server 14 of the access control system 1 used by the administrator.

[0080] Next, when the administrator instructs the server 14 to encrypt the authentication code and generate an additional URL using the management terminal 10, the generation control unit 101 generates an authentication code (for example, "xyz01") (Figure 2: S102) and then generates an encrypted code (for example, "hij012") by encrypting it (Figure 2: S103).

[0081] The generation control unit 101 then generates an additional URL (for example, "https: / / ghi / jkl / ?pm=hij012") by adding the encryption code ("hij012") as an encryption parameter to the authentication URL ("https: / / ghi / jkl") (Figure 2: S104).

[0082] Here, if a target URL ("https: / / ghi") indicating the store's order website is to be set for each of the store's multiple tables, for example, the administrator sets a target URL (e.g., "https: / / ghi / table1", "https: / / ghi / table2") for each table, as shown in Figure 9A. The administrator then instructs the management terminal 10, and the generation control unit 101 generates an authentication code, an encryption code, and an additional URL for each table. This makes it possible to set a distinct target URL for each table.

[0083] Furthermore, the generation control unit 101 stores the authentication code as the registration authentication code in a predetermined registration table based on the added URL (Figure 2: S105). In this case, as shown in Figure 9A, the generation control unit 101 stores the authentication URL of the added URL ("http: / / ghi / jkl") associated with the registration authentication URL 401 of the registration table 400, and stores the authentication code of the added URL ("xyz01") associated with the registration authentication code 402 of the registration table 400. Then, the generation control unit 101 stores the target URL of the first table ("https: / / ghi / table1") associated with the registration authentication code 402 ("xyz01") in the registration target URL 403. The generation control unit 101 performs this for the target URL of each table.

[0084] Then, the administrator stores the additional URLs in a designated storage medium 12 (Figure 2: S106). For example, the administrator creates a QR code (registered trademark) 12b corresponding to the additional URL for the first table ("https: / / ghi / jkl / ?pm=hij012") and prints it on a storage medium 12 such as a coaster. The same applies to the additional URL for the second table ("https: / / ghi / jkl / ?pm=hij345"). This makes it possible to configure the storage medium 12 for each table.

[0085] Now, when a consumer visits the store and goes to the first table, they read the additional URL ("https: / / ghi / jkl / ?pm=hij012") of the storage medium 12 on the first table with their user terminal 11 (Figure 2: S201). Here, as shown in Figure 9B, when the consumer reads the additional URL of the storage medium 12 on the first table with the user terminal 11 by taking a picture of the QR code (registered trademark) 12b with the camera of the user terminal 11 and accesses the authentication URL of the additional URL (Figure 2: S202), the first determination control unit 102 of the server 14 determines whether or not the encryption code is attached to the authentication URL (Figure 2: S203).

[0086] Here, since the authentication URL ("http: / / ghi / jkl") has an encryption code ("hij012") attached to it, the first determination control unit 102 determines that the authentication URL has an encryption code attached to it (Figure 2: S203YES).

[0087] Next, the second determination control unit 104 of the server 14 decrypts the additional cryptographic code attached to the authentication URL (Figure 2: S205) and determines whether the decrypted code matches the registration cryptographic code associated with the registration authentication URL in a predetermined registration table (Figure 2: S206).

[0088] First, the second determination control unit 104 decrypts the additional encryption code ("hij012") attached to the authentication URL ("http: / / ghi / jkl") and generates a decryption code ("xyz01"). Here, since the generated decryption code matches the registration authentication code ("xyz01") associated with the registration authentication URL ("http: / / ghi / jkl"), the second determination control unit 104 determines that the decryption code matches the registration authentication code (Figure 2: S206YES).

[0089] Then, the transfer control unit 106 of server 14 will transfer the user terminal 11 to the target URL for access (Figure 2: S207). Here, since the registration target URL 403 associated with the registration authentication code 402 ("xyz01") stores the target URL of the first table ("https: / / ghi / table1"), the transfer control unit 106 transfers (redirects) the user terminal 11 to the target URL of the first table ("https: / / ghi / table1").

[0090] The user terminal 11 then accesses the target URL of the first table ("https: / / ghi / table1") and displays the target screen for the first table. Here, the target screen 900 displays, for example, the accessed URL 901 ("https: / / ghi / table1"), a message 902 indicating the table identification number (e.g., "TABLE1"), and a function message 903 indicating that mobile ordering is possible (e.g., "Mobile order"). This allows the consumer to display the target screen for the first table they were assigned to in the store they visited on their user terminal 11.

[0091] Furthermore, by setting the target URL for the first table ("https: / / ghi / table1"), as described above, when consumers pay and make payments at a store, the user can calculate the necessary amount based on the target URL corresponding to this first table. In addition, by linking the target URL corresponding to the first table with external accounting software (accounting cloud), it becomes possible to send the received payments to the accounting server or accounting software to calculate daily or monthly sales.

[0092] Furthermore, while a target URL was set for each table as described above, this is not the only option. For example, an administrator could set a table identification number (e.g., "table1", "table2", etc.) for each table and set branch URLs that diverge from a specific target URL (e.g., "https: / / ghi") based on the table identification number.

[0093] Specifically, the administrator instructs the management terminal 10, and the generation control unit 101 generates an authentication code (e.g., "xyz01") as shown in Figure 10A, encrypts the authentication code, and generates an encrypted code (e.g., "hij012"). Next, based on the setting of the identification number in this table, the generation control unit 101 adds the encrypted code as an encrypted parameter to the authentication URL, and further adds the identification number of the table as an identification parameter to the authentication URL.

[0094] For example, as shown in Figure 10A, the generation control unit 101 adds an encryption code ("hij012") as an encryption parameter to the authentication URL ("http: / / ghi / jkl") and generates an appended URL (for example, "http: / / ghi / jkl / ?pm=hij012&id=table1") with an identification number ("table1") as an identification parameter. When multiple parameters are added to a parameterized URL, a specific symbol (for example, "&") is placed between the parameters. In this case, since an encryption parameter and an identification parameter are added, a specific symbol ("&") is placed between the encryption parameter and the identification parameter. This makes it possible to add the table's identification number to the authentication URL.

[0095] Furthermore, the generation control unit 101 stores the authentication code as the registration authentication code in a predetermined registration table based on the added URL (Figure 2: S105). In this case, as shown in Figure 10A, the generation control unit 101 stores the authentication URL of the added URL ("https: / / ghi / jkl") associated with the registration authentication URL 401 of the registration table 400, and stores the authentication code of the added URL ("xyz01") associated with the registration authentication code 402 of the registration table 400. In addition, the generation control unit 101 stores the target URL of the authentication URL ("https: / / ghi") associated with the registration target URL 403 of the registration table 400. Note that, here, the table identification number is used to indicate a subordinate URL of the target URL ("https: / / ghi"), and is therefore not stored in the registration table 400.

[0096] Then, the administrator stores the additional URLs in a designated storage medium 12 (Figure 2: S106). For example, the administrator creates a QR code (registered trademark) 12b corresponding to the additional URL for the first table ("https: / / ghi / jkl / ?pm=hij012&id=table1") and prints it on a storage medium 12 such as a coaster. The same applies to the additional URL for the second table ("https: / / ghi / jkl / ?pm=hij012&id=table2").

[0097] Furthermore, when a consumer reads the additional URL ("https: / / ghi / jkl / ?pm=hij012&id=table1") of the storage medium 12 of the first table on their user terminal 11 and accesses the authentication URL of the additional URL (Figure 2: S202), the first determination control unit 102 of the server 14 determines whether or not the encryption code is attached to the authentication URL (Figure 2: S203).

[0098] Here, since the authentication URL ("http: / / ghi / jkl") has an encryption code ("hij012") attached to it, the first determination control unit 102 determines that the authentication URL has an encryption code attached to it (Figure 2: S203YES).

[0099] Next, the second determination control unit 104 of the server 14 decrypts the additional cryptographic code attached to the authentication URL (Figure 2: S205) and determines whether the decrypted code matches the registration cryptographic code associated with the registration authentication URL in a predetermined registration table (Figure 2: S206).

[0100] Here, the decrypted code ("xyz01") obtained by decrypting the encrypted code ("hij012") matches the registration authentication code ("xyz01") associated with the registration authentication URL ("https: / / ghi / jkl"). Therefore, the second determination control unit 104 determines that the decrypted code matches the registration authentication code (Figure 2: S206YES).

[0101] Then, the transfer control unit 106 of server 14 will transfer the user terminal 11 to the target URL for access (Figure 2: S207). However, since the appended URL ("https: / / ghi / jkl / ?pm=hij012&id=table1") has the table identification number ("table1") appended as an identification parameter, the transfer control unit 107 appends the table identification number ("table1") to the target URL ("https: / / ghi") and transfers (redirects) to the target URL ("https: / / ghi / table1") corresponding to the table identification number.

[0102] The user terminal 11 then accesses the target URL ("https: / / ghi / table1") corresponding to the table identification number and displays the target screen for the first table. Here, the target screen 1000 displays, for example, the accessed URL 1001 ("https: / / ghi / table1"), a message 1002 indicating the table identification number (e.g., "TABLE1"), and a function message 1003 indicating that mobile ordering is possible (e.g., "Mobile order"). This allows the consumer to display the target screen for the first table they were assigned to in the store they visited on their user terminal 11.

[0103] Furthermore, in this invention, by setting the transfer destination using the transfer control unit 106, it is also possible to display an advertising screen containing SNS or other store introduction banners (images) on the user terminal 11 before displaying the target screen such as mobile ordering. This makes it possible for consumers to see the advertising screen when they access the target URL via the storage medium 12 at a store using the user terminal 11, thereby improving the advertising effect on the user.

[0104] In this embodiment of the present invention, the access permission system 1 is configured to include each control unit, but it is also possible to configure the system to store a program that implements each control unit on a storage medium and provide the storage medium. In this configuration, the program is read by a device, and the device implements each control unit. In this case, the program read from the storage medium itself performs the effects of the present invention. Furthermore, it is also possible to provide a method for storing the processes executed by each control unit on a hard disk. [Industrial applicability]

[0105] As described above, the access permission system and access permission method according to the present invention are useful not only for stores such as restaurants and service shops, but also for all fields that require access restrictions, such as marketing and promotion fields, and are effective as an access permission system and access permission method that can permit access to websites only through a specific storage medium. [Explanation of Symbols]

[0106] 1 Access permission system 10 Management terminals 11 User terminals 12 Storage medium 13 Networks 14 Servers 101 Generation Control Unit 102 First determination control unit 103 First Error Control Unit 104 Second determination control unit 105 Second Error Control Unit 106 Transfer Control Unit 107 Third Error Control Unit

Claims

1. A storage medium that stores an additional URL in which an encrypted code obtained by encrypting the authentication code is added as a parameter to the authentication URL, When a user terminal reads the added URL on the storage medium and accesses the authentication URL of the added URL, a first determination control unit determines whether or not the encryption code is attached to the authentication URL. If, as a result of the above determination, the authentication URL does not have the encryption code attached, the first error control unit displays an error screen, If, as a result of the above determination, the authentication URL has the encryption code attached, a second determination control unit decrypts the attached encryption code attached to the authentication URL and determines whether the decrypted code matches the registration authentication code associated with the registration authentication URL in a predetermined registration table. If, as a result of the above determination, the decryption code does not match the registration authentication code, a second error control unit displays the error screen, If, as a result of the above determination, the decryption code matches the registration authentication code, the transfer control unit transfers the user terminal to access the target URL, A third error control unit displays the error screen when the user terminal accesses the target URL without going through the authentication URL. An access permission system equipped with the following features.

2. The encryption method for the aforementioned encryption code uses an encryption function that includes a hash function. The access permission system according to claim 1.

3. The aforementioned registration table stores the registration authentication URL, the registration authentication code, and the registration purpose URL in association with each other. The transfer control unit transfers the user terminal to access the registration purpose URL associated with the registration authentication code that matches the decryption code in the registration table. The access permission system according to claim 1.

4. A storage medium that stores an additional URL in which an encrypted code obtained by encrypting the authentication code is added as a parameter to the authentication URL, When a user terminal reads the added URL on the storage medium and accesses the authentication URL of the added URL, a first determination control step determines whether or not the encryption code is attached to the authentication URL. If, as a result of the above determination, the authentication URL does not have the encryption code attached, the first error control step is to display an error screen. If, as a result of the above determination, the authentication URL has the encryption code attached, a second determination control step is performed to decrypt the attached encryption code attached to the authentication URL and determine whether the decrypted code matches the registration authentication code associated with the registration authentication URL in a predetermined registration table. If, as a result of the above determination, the decryption code does not match the registration authentication code, a second error control step is performed to display the error screen, If, as a result of the above determination, the decryption code matches the registration authentication code, a transfer control step is performed to transfer the user terminal to the target URL and access it. A third error control step is performed to display the error screen when the user terminal accesses the target URL without going through the authentication URL, Access permission methods for an access permission system.

Citation Information

Patent Citations

  • System for supplying provision information including browsing approval information, browsing approval information management device, information providing device, user terminal device, method of providing provision information to user terminal device, method of creating browsing approval information, method of determining browsing approval information, and recording medium recording provision information

    JP2002259838A

  • Access control system, access control method, and access control program

    JP2006079598A

  • Order reception device, restaurant system and order reservation program

    JP2014157564A

  • Communication terminal, member card and authentication system

    JP2015194867A

  • Web service providing system, web service providing method, web server, authentification server, and computer program

    JP2018151795A