Authentication system and authentication method

The authentication system addresses the challenge of mismatched key information by employing a common key management device for secure authentication, ensuring reliable access control even in varying communication environments.

JP2026076482APending Publication Date: 2026-05-12HITACHI BUILDING SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
HITACHI BUILDING SYST CO LTD
Filing Date
2024-10-24
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing authentication systems face challenges in ensuring secure authentication when devices hold mismatched key information, particularly shared keys, due to varying communication environments.

Method used

An authentication system utilizing a common key management device that manages and distributes a first and second common key for decryption processes, enabling authentication even when devices have mismatched key information, through a communication unit, storage unit, decryption processing unit, and authentication unit.

Benefits of technology

Ensures secure authentication by allowing devices with mismatched key information to authenticate successfully, enhancing security and reliability in access control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026076482000001_ABST
    Figure 2026076482000001_ABST
Patent Text Reader

Abstract

To enable authentication even when multiple devices used for authentication hold mismatched common keys. [Solution] An authentication system that has a common key management device for managing a common key and authenticates using an authentication ID includes: a communication unit that transmits authentication information including an authentication ID and a common key to a mobile terminal; a storage unit that stores a first common key and a second common key managed by the common key management device; a decryption processing unit that performs a decryption process using the first common key on an encrypted authentication ID encrypted with the common key by the mobile terminal and transmitted from the mobile terminal, and if the encrypted authentication ID cannot be decrypted with the first common key, performs a decryption process using the second common key on the encrypted authentication ID; and an authentication unit that performs an authentication process using the decrypted authentication ID if the encrypted authentication ID is decrypted with either the first common key or the second common key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to encryption technology, particularly authentication using a common key. Among them, in particular, it relates to a technology for controlling a control target device according to an authentication result.

Background Art

[0002] Currently, encryption technology is used to ensure security in various fields. For example, Patent Document 1 has been proposed for controlling the locking and unlocking of a mobile body using a portable terminal that holds key information.

[0003] In Patent Document 1, the problem is "to enhance the security strength when locking or unlocking a mobile body from a portable terminal". To solve this problem, Patent Document 1 discloses that "the authentication system is an authentication system in which an authentication device authenticates a portable terminal in order to permit control of the mobile body. The portable terminal holds key information, the authentication device holds key information corresponding to the portable terminal, and when the key information included in the authentication request from the portable terminal matches the key information associated with the portable terminal, the portable terminal is authenticated, and each of the portable terminal and the authentication device updates the key information related to the authentication by the same logic after authentication".

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] Here, Patent Document 1 assumes that the same key information is held in both the mobile terminal and the authentication device. However, key information such as certificates and shared keys may be distributed from a so-called server to each device. In this case, depending on the communication environment, it is not always possible to distribute matching key information to both devices. Thus, the challenge is to enable authentication even when two or more devices used for authentication hold mismatched key information, especially shared keys. [Means for solving the problem]

[0006] To solve this problem, the present invention provides an authentication system that has a common key management device for managing a common key and performs authentication using an authentication ID, comprising: a communication unit that transmits authentication information including an authentication ID and a common key to a mobile terminal; a storage unit that stores a first common key and a second common key managed by the common key management device; a decryption processing unit that performs a decryption process using the first common key on an encrypted authentication ID encrypted with the common key by the mobile terminal and transmitted from the mobile terminal, and if the encrypted authentication ID cannot be decrypted with the first common key, performs a decryption process using the second common key on the encrypted authentication ID; and an authentication unit that performs an authentication process using the decrypted authentication ID if the encrypted authentication ID is decrypted with either the first common key or the second common key.

[0007] Furthermore, the present invention also includes an authentication method performed by the authentication system. Moreover, the control of a controlled device using the results of this authentication is also included in the present invention. [Effects of the Invention]

[0008] According to the present invention, authentication becomes possible even when two or more devices used for authentication hold key information that does not match each other, particularly a common key. [Brief explanation of the drawing]

[0009] [Figure 1]This is a schematic diagram of an access control system in one embodiment of the present invention. [Figure 2] This is a functional block diagram of the shared key management device 2 in one embodiment of the present invention. [Figure 3] This figure shows user management information 213 used in one embodiment of the present invention. [Figure 4] This figure shows the shared key management information 214 used in one embodiment of the present invention. [Figure 5] This is a functional block diagram of mobile terminal 3 in one embodiment of the present invention. [Figure 6] This is a functional block diagram of the reading device 5 in one embodiment of the present invention. [Figure 7] This is a functional block diagram of the authentication / control device 6 in one embodiment of the present invention. [Figure 8A] This is a flowchart showing the process of distributing a common key to a mobile terminal 3 in one embodiment of the present invention. [Figure 8B] This is a flowchart showing the process of distributing a common key to a reader 5 and an authentication / control device 6 in one embodiment of the present invention. [Figure 9A] This is a flowchart (1 / 2) illustrating the authentication / control process in one embodiment of the present invention. [Figure 9B] This is a flowchart (2 / 2) illustrating the authentication / control process in one embodiment of the present invention. [Figure 10] This is a hardware configuration diagram of the common key management device 2 in one embodiment of the present invention. [Figure 11] This is a hardware configuration diagram of mobile terminal 3 in one embodiment of the present invention. [Modes for carrying out the invention]

[0010] Hereinafter, one embodiment of the present invention will be described with reference to the drawings. In this embodiment, an example will be described in which the authentication system is applied to an access control system that determines whether to permit entry. For this purpose, in this embodiment, a mobile device is authenticated, and if authenticated, the electronic lock on the door is unlocked. The details will be described below.

[0011] Figure 1 is a schematic diagram of the access control system in this embodiment. In Figure 1, Center 1, mobile terminal 3, and buildings 4-1 to 4-3 are connected via networks 8 and 9. Center 1 is equipped with a common key management device 2, which constitutes the access control system. Furthermore, each of buildings 4-1 to 4-3 is equipped with readers 5-1 to 5-3 and authentication / control devices 6-1 to 6-3, which constitute the access control system. Note that networks 8 and 9 may be common networks such as the Internet.

[0012] First, the shared key management device 2 manages the shared key as key information used for authentication by the authentication / control devices 6-1 to 6-3. Then, the shared key management device 2 distributes this shared key to the mobile terminal 3 and the authentication / control devices 6-1 to 6-3.

[0013] Furthermore, mobile terminal 3 is a device used by users who wish to enter at least one of buildings 4-1 to 4-3 (including rooms within the building). Authentication of mobile terminal 3 or its user enables entry into buildings 4-1 to 4-3 and their rooms.

[0014] In addition, the reading devices 5-1 to 5-3 are each connected to the mobile terminal 3 used for authentication by short-range wireless communication such as so-called BLE communication, and various information can be read from the mobile terminal 3. Further, each of the authentication / control devices 6-1 to 6-3 is connected to the reading devices 5-1 to 5-3 and the network 8. And when each of the authentication / control devices 6-1 to 6-3 authenticates the mobile terminal 3, a control command is output to the electronic locks 7-1 to 7-3. As a result, the electronic locks 7-1 to 7-3 are unlocked, and the user of the mobile terminal 3 can enter the corresponding door. For this reason, the reading devices 5-1 to 5-3 are provided near the corresponding doors.

[0015] Note that the buildings 4-1 to 4-3, the reading devices 5-1 to 5-3, the authentication / control devices 6-1 to 6-3, and the electronic locks 7-1 to 7-3 each have similar functions. Therefore, for simplicity hereinafter, they are referred to as the building 4, the reading device 5, the authentication / control device 6, and the electronic lock 7. Also, these numbers are not limited to the illustrated 3. Furthermore, in each building 4, there may be a plurality of the reading device 5, the authentication / control device 6, and the electronic lock 7, and the numbers thereof do not have to be the same.

[0016] Next, each device will be described. First, FIG. 2 is a functional block diagram of the common key management device 2 in the present embodiment. In FIG. 2, the common key management device 2 includes a storage unit 21, a communication unit 22, a common key generation unit 23, and a common key distribution management unit 24.

[0017] The storage unit 21 stores an authentication ID group 211, a common key group 212, user management information 213, and common key management information 214 as information used in the common key management device 2. The authentication ID group 211 is an ID for managing each process performed in the present embodiment, particularly authentication. Since multiple authentications are performed, it is referred to as an authentication ID "group" in the present embodiment. However, when managing one controlled device or an accessory of the controlled device (for example, a door), the authentication ID may be one. Note that the controlled device includes not only devices such as the electronic lock 7 but also facilities such as elevators.

[0018] Furthermore, the shared key group 212 consists of multiple shared keys managed, for example, generated and distributed by the shared key management device 2. Each of the shared key group 212 is managed in association with one of the authentication ID group 211. Note that the authentication ID group 211 may be omitted because the shared key management information 214, described later, contains the authentication ID.

[0019] Furthermore, user management information 213 is information that manages users who are permitted to enter or who may be permitted to enter. Figure 3 shows the user management information 213 used in this embodiment. In Figure 3, the user management information 213 has the following items for each user: user name, login ID, password, and permission status.

[0020] First, the username indicates the name of the user in question. The username may also include user attributes, such as address, email address, and affiliation (company, department). The login ID and password are used for login verification during the shared key distribution process described later. In addition to, or instead of, the login ID and password, biometric authentication such as iris recognition or fingerprint recognition may be used.

[0021] The permission status indicates whether entry is permitted for the user in question. In the example in Figure 3, the permission status uses time, user ID, and device ID. The time indicates the user's available time, i.e., the time they are allowed to enter the room. If the user is a continuous user, such as an employee of the room, the permission status may be set to unlimited or annually, or it may indicate times when the room is unavailable.

[0022] Furthermore, the user ID is the ID used in the shared key distribution process. Note that if a temporary ID, such as a one-time password, is used as the user ID in the shared key distribution process, it does not need to be stored in the user management information 213.

[0023] Furthermore, the device ID is the device ID of the device permitted for the user in question, and this is an ID that identifies the device related to authentication, similar to the device ID in the shared key management information 214 described later. Note that for users who are not permitted to enter or whose validity period has expired, information indicating denial will be displayed as shown in Figure 3, but this may be set to NULL. Furthermore, for users whose validity period has expired, the permitted information may be stored as history information.

[0024] Furthermore, the common key management information 214 is information for managing the common keys generated and distributed by the common key management device 2. Figure 4 shows the common key management information 214 used in this embodiment. In Figure 4, the common key management information 214 has the following items for each authentication ID: common key ID (latest), common key ID (previous generation), device ID, user ID (1), and user ID (2).

[0025] First, the shared key ID (latest) is an ID that identifies the latest shared key generated by the shared key management device 2. Here, "latest" includes being the most recently generated or activated key and being used preferentially. Furthermore, the shared key ID (one generation prior) is an ID that identifies the shared key one generation prior to the latest shared key generated by the shared key management device 2. Here, "one generation prior" means that it was generated or activated before the latest shared key and, as described later, is used after the latest key. Therefore, "latest" and "one generation prior" include priority levels other than temporal relationships, and they may be separated by two or more generations.

[0026] The expiration date is indicated for the most recent shared key ID and the previous shared key ID. While the expiration date of these shared keys is important, if a shared key is distributed to each user, it may be aligned with the permission status time in user management information 213. In this case, this expiration date will also coincide with the validity period of user ID (1) and user ID (2) described later.

[0027] Furthermore, the device ID is an ID that identifies the device related to authentication, as described above. Here, the device related to authentication is preferably a controlled device such as an electronic lock 7, but it may also be any of the following: the building 4, the reader 5, the authentication / control device 6, or an accessory to the controlled device (such as a door), or at least a combination of two of these.

[0028] Furthermore, User ID(1) and User ID(2) indicate the User IDs of the users to whom the shared key was distributed, respectively. These are the same as the User IDs in User Management Information 213. The validity period and usage history are also stored. The validity period indicates the time during which the user in question is allowed to use, i.e., enter the room. The usage history indicates whether authentication was performed using the shared key in question. If the key has been used, such as "Used on 10 / 1", it may be made impossible for that user to reuse it. In this case, it may be recorded as "Unavailable" in the usage history, or "Used" may be interpreted as "Unavailable". This concludes the explanation of the shared key management device 2, but the shared key management device 2 can be implemented on a computer such as a server. An example of an implementation of the shared key management device 2 on a computer will be described later.

[0029] Next, Figure 5 is a functional block diagram of the mobile terminal 3 in this embodiment. The mobile terminal 3 is an information device used for authentication to allow users to enter a room, and can be implemented as a smartphone or tablet. Alternatively, it may be implemented as an IC card or a dedicated terminal. In Figure 5, the mobile terminal 3 has a storage unit 31, an expiration date management unit 32, an encryption processing unit 33, an input unit 34, an output unit 35, a BLE communication unit 36, and a center communication unit 37.

[0030] The memory unit 31 stores the authentication ID 311, the common key 312, and the expiration date 313 as information used by the mobile terminal 3. The authentication ID 311, as described above, is an ID for managing each process, especially authentication, and is distributed from the common key management device 2.

[0031] Furthermore, the shared key 312 is a shared key distributed to the user from the shared key management device 2. In addition, the expiration date 313 indicates the expiration date of the distributed shared key. These are the same as those of the user management information 213. Note that the authentication ID 311, shared key 312, and expiration date 313 are distributed from the shared key management device 2 as authentication information. Here, the communication status of the mobile terminal 3 with the network 9 (especially the wireless communication status) may be worse than the communication status between the shared key management device 2 and the authentication / control device 6. For this reason, the authentication information, especially the shared key 312, may not be up-to-date. In this embodiment, authentication is possible even if the authentication information (shared key 312) is not up-to-date. Note that the difference in communication status may be due to the use of different networks by the mobile terminal 3 and the authentication / control device 6.

[0032] Furthermore, the expiration date management unit 32 uses the expiration date 313 to determine whether the common key 312 has expired. If the expiration date has expired, the encryption processing in the encryption processing unit 33 (described later) is not performed, and the authentication process is terminated.

[0033] The encryption processing unit 33 uses the common key 312 to encrypt the authentication ID 311 and create an encrypted authentication ID. The input unit 34 accepts operations from the user. Therefore, the input unit 34 can be implemented as an input device such as a keyboard. The output unit 35 outputs, and more preferably displays, various information to the user. Therefore, the output unit 35 can be implemented as a display device such as a display or monitor. The input unit 34 and the output unit 35 may be configured as an integrated unit, such as a touch panel.

[0034] Furthermore, the BLE communication unit 36 ​​communicates with the reader 5 via BLE communication. The BLE communication unit 36 ​​may also communicate with the reader 5 using other wireless communication functions such as NFC. Additionally, the center communication unit 37 communicates with the common key management device 2 via the network 9. Therefore, the center communication unit 37 receives authentication information. The BLE communication unit 36 ​​and the center communication unit 37 may also be configured as a single unit.

[0035] Next, Figure 6 is a functional block diagram of the reader device 5 in this embodiment. The reader device 5 communicates with the mobile terminal 3 and receives or reads information used for authentication. In Figure 6, the reader device 5 has a storage unit 51, a decoding processing unit 52, a registration processing unit 53, a BLE communication unit 54, and a serial communication unit 55.

[0036] First, the storage unit 51 stores the latest common key 511 and the previous common key 512. These are distributed from the common key management device 2 via the authentication / control device 6. In other words, they are included in the common key group 212 and are indicated by the latest common key and the previous common key in the common key management information 214. The latest common key 511 and the previous common key 512 are examples of the first and second common keys, respectively. When the common key is received via the authentication / control device 6, the registration processing unit 53 registers this common key as the latest common key 511, changes the latest common key 511 to the previous common key 512, and deletes the original previous common key 512. However, the original previous common key 512 may be retained. Thus, the memory unit 51 only needs to store the common key (latest) 511 and the common key (previous generation) 512 in a way that allows them to be identified.

[0037] Furthermore, the decryption processing unit 52 performs a decryption process on the encrypted authentication ID, which is the encrypted authentication ID 311 transmitted from the mobile terminal 3. In addition, the BLE communication unit 54 communicates with the mobile terminal 3 via BLE communication. The BLE communication unit 54 may also communicate with the mobile terminal 3 using other wireless communication functions such as NFC.

[0038] Furthermore, the registration processing unit 53 performs the registration process for the latest common key 511 and the previous generation common key 512. The serial communication unit 55 communicates serially with the authentication / control device 6 and receives the common key from the common key management device 2. Note that communication with the authentication / control device 6 is not limited to serial communication. In addition, the BLE communication unit 54 and the serial communication unit 55 may be configured as a single unit.

[0039] Next, Figure 7 is a functional block diagram of the authentication / control device 6 in this embodiment. The authentication / control device 6 controls the electronic lock 7 for authentication processing and entry. In Figure 7, the authentication / control device 6 has a storage unit 61, an authentication unit 62, a control command unit 63, a registration processing unit 64, a serial communication unit 65, and a center communication unit 66.

[0040] First, the storage unit 61 stores the authentication ID 611 and the common key 612 as information used by the authentication / control device 6. These are distributed from the common key management device 2. In other words, the authentication ID 611 is included in the authentication ID group 211. The common key 612 is included in the common key group 212 and is indicated by the common key (latest) in the common key management information 214.

[0041] Furthermore, the authentication unit 62 performs authentication processing using the authentication ID decrypted by the reader 5. The control command unit 63 creates a control command to unlock the electronic lock 7 if authentication is successful by the authentication unit 62. The control command unit 63 then outputs the control command to the electronic lock 7, thereby unlocking the electronic lock 7. The registration processing unit 64 performs registration processing such as registering the authentication ID 611 and the common key 612, and sending the common key to the reader 5.

[0042] Furthermore, the serial communication unit 65 communicates serially with the reader 5 to transmit a common key from the common key management device 2 and to receive an authentication ID from the reader 5. Note that communication with the reader 5 is not limited to serial communication. The serial communication unit 65 may also transmit control commands to the electronic lock 7, and the configuration for transmitting control commands may be separate from the serial communication unit 65.

[0043] Furthermore, the center communication unit 66 communicates with the common key management device 2 via the network 9. Therefore, the center communication unit 66 receives the authentication ID and common key as authentication information from the common key management device 2. The authentication information may also include the expiration date of the common key. In this case, the expiration date is transmitted to the reader 5, and decryption by the decryption processing unit 52 may be limited to cases within the expiration date. Furthermore, authentication may be performed by the authentication unit 62, limited to cases within the expiration date. Additionally, the serial communication unit 65 and the center communication unit 66 may be configured as a single unit.

[0044] This concludes the description of the configuration of this embodiment, but the configurations are not limited to these. For example, the authentication / control device 6 may implement the authentication function and control function in separate devices. Alternatively, the authentication function may be provided in the reader device 5. Furthermore, the encryption function of the reader device 5 may be provided in the authentication / control device 6. In addition, the reader device 5 and the authentication / control device 6 may be configured as an integrated unit.

[0045] Next, the processing flow in this embodiment will be described. The processing in this embodiment can be broadly divided into the common key distribution process shown in Figures 8A and 8B, and the authentication / control process shown in Figures 9A and 9B. The common key distribution process and the authentication / control process will be described below in that order.

[0046] First, Figure 8A is a flowchart showing the process of distributing a common key to the mobile terminal 3 in this embodiment. As a premise of Figure 8A, a user who wishes to enter the room operates the mobile terminal 3 to request a common key. That is, in step S311, the input unit 34 of the mobile terminal 3 receives a login operation from the user. At this time, the input unit 34 receives the login ID and password that have been notified to the user.

[0047] Furthermore, in step S312, the center communication unit 37 transmits a login request to the common key management device 2, including the received login ID and password. Then, in step S211, the communication unit 22 of the common key management device 2 receives the transmitted login request.

[0048] In response, in step S212, the shared key distribution management unit 24 determines whether the user can log in by checking whether the user management information 213 contains the login ID and password included in the login request. If login is possible, in step S213, the shared key distribution management unit 24 sends a login availability notification, including the user ID, to the mobile terminal 3 via the communication unit 22. To do this, the shared key distribution management unit 24 reads the user ID from the shared key management information 214. Alternatively, the shared key distribution management unit 24 may create a user ID using a random number or the like for each login request and register it in the shared key management information 214.

[0049] Furthermore, in step S313, the center communication unit 37 of the mobile terminal 3 receives a login availability notification including the user ID. Also, in step S314, in response to the user's operation on the input unit 34, the center communication unit 37 sends an authentication information request including the user ID. At this time, the input unit 34 receives the user ID from the user for identity verification. For this reason, the login availability notification in step S213 may be sent via SMS or email. Furthermore, it is desirable to include information specifying the room or building the user wishes to enter in the authentication information request. The device ID can be used as this specifying information. This is an effective means for users who enter multiple rooms.

[0050] Then, in step S214, the communication unit 22 of the common key management device 2 receives the authentication information request. In response, in step S215, the common key distribution management unit 24 transmits the relevant authentication information to the mobile terminal 3 via the communication unit 22. To do this, the common key distribution management unit 24 identifies the authentication information corresponding to the user ID from the common key management information 214. The authentication information includes the authentication ID, common key, and expiration date. The common key is identified by the common key ID (latest) in the common key management information 214.

[0051] Furthermore, in step S315, the center communication unit 37 of the mobile terminal 3 receives the transmitted authentication information. Then, in step S316, the expiration date management unit 32 stores the authentication information in the storage unit 19 as authentication ID 311, common key 312, and expiration date 313. As a result, the common key 312 is delivered to the mobile terminal 3. In this example, the common key 312 is delivered triggered by an operation from the user, but for users who continuously use building 4 or its rooms, this process may be executed periodically (more preferably regularly). In this case, the system may be configured to execute steps S213 onwards, or a delivery alert may be displayed on the output unit 35 of the mobile terminal 3 when it is time for delivery, prompting the user to proceed with steps S211 onwards.

[0052] Next, Figure 8B is a flowchart illustrating the distribution process of a common key to the reader 5 and the authentication / control device 6 in this embodiment. In Figure 8B, in step S611, the registration processing unit 64 of the authentication / control device 6 detects the activation of the authentication / control device 6. Then, in step S612, the registration processing unit 64 sends an activation notification to the common key management device 2 via the center communication unit 66, which includes the relevant device ID and indicates that the device has been activated.

[0053] Then, in step S216, the communication unit 22 of the common key management device 2 receives the transmitted startup notification. In response, in step S217, the common key distribution management unit 24 transmits the relevant authentication information to the authentication / control device 6 via the communication unit 22. To do this, the common key distribution management unit 24 identifies the authentication information corresponding to the device ID included in the startup notification from the common key management information 214. The authentication information also includes the authentication ID and the common key. Note that this authentication information may also include an expiration date. The common key can be identified by the common key ID (latest) in the common key management information 214, as in Figure 8A.

[0054] In response, in step S313, the center communication unit 66 of the authentication / control device 6 receives the transmitted authentication information. Then, in step S314, the registration processing unit 64 registers the received authentication information in the storage unit 61. As a result, the authentication ID 611 and the common key 612 are stored in the storage unit 61.

[0055] Furthermore, in step S615, the registration processing unit 64 transmits the common key included in the received authentication information to the reader device 5 via the serial communication unit 65. In response, in step S511, the serial communication unit 55 of the reader device 5 receives the transmitted common key. Then, in step S512, the registration processing unit 53 registers the received common key in the storage unit 51 as the common key (latest) 511. At this time, as described above, the stored common key (previous generation) 512 is invalidated by deletion or other means, and the stored common key (latest) 511 is changed to the common key (previous generation) 512, thereby making the first and second common keys available (effective) on a limited basis. Note that the number of effective common keys is not limited to two, but may be three or more. Even in this case, a priority order for use is determined for each common key.

[0056] This concludes the explanation of Figure 8B. In this example, the distribution process was triggered by the activation of the authentication / control device 6, but this process may also be performed periodically, such as once a day, or in response to instructions from a management terminal connected to the common key management device 2.

[0057] Next, the processing flow for authentication and control using the distributed common key will be described. Figures 9A and 9B together are flowcharts of the authentication / control process in this embodiment. In step S521 in Figure 9A, the BLE communication unit 54 of the reader device 5 regularly broadcasts advice indicating a connection waiting state.

[0058] Furthermore, a user wishing to enter the room moves near the reader 5. Then, in step S321, the BLE communication unit 36 ​​of the mobile terminal 3 receives the broadcasted advertisement. Then, in step S322, the BLE communication unit 36 ​​sends a connection request. In other words, the reader 5 begins operating as a peripheral device.

[0059] Furthermore, in step S522, the BLE communication unit 54 of the reader device 5 receives the transmitted connection request. Then, in step S523, the BLE communication unit 54 sends a connection response in response to the connection request. In response to this, in step S323, the BLE communication unit 36 ​​of the mobile terminal 3 receives the transmitted connection response. As a result, BLE communication is established between the reader device 5 and the mobile terminal 3. Note that if communication is performed using NFC or the like, steps S521 to S323 may be omitted. In this case, the processing from step S324 onwards will be executed. For example, by launching an application on the mobile terminal 3 and bringing the mobile terminal 3 close to the reader device 5, communication from step S325 onwards may be performed using NFC or the like.

[0060] Furthermore, in step S324, the encryption processing unit 33 encrypts the authentication ID 311 in the storage unit 31 with the common key 312 to generate an encrypted authentication ID. Step S324 may also be executed under the following conditions. First, the expiration date management unit 32 uses the expiration date 313 of the storage unit 31 to determine whether the common key 312 is still valid. If it is still valid, step S324 is executed. If it is not still valid, the expiration date management unit 32 outputs an error via the output unit 35 indicating that the common key has expired and entry is not possible. If it is not still valid, the expiration date management unit 32 may also output a message via the output unit 35 prompting the user to request (obtain) the common key (latest) 511 and / or common key (previous generation) 512 from the common key management device 2 to the mobile terminal 3.

[0061] Then, in step S325, the encryption processing unit 33 transmits the generated encrypted authentication ID to the reader device 5 via the BLE communication unit 36. In response, in step S524, the BLE communication unit 54 of the reader device 5 receives the transmitted encrypted authentication ID.

[0062] Furthermore, in step S524, the decryption processing unit 52 performs a first decryption process on the transmitted encrypted authentication ID using the latest common key 511. In response to this, in step S526, the decryption processing unit 52 determines whether the encrypted authentication ID was decrypted in the first decryption process. If it is decrypted (Y), the process proceeds to step S530 (Figure 9B). If it is not decrypted (N), the process proceeds to step S527.

[0063] Furthermore, in step S527, the decryption processing unit 52 performs a first decryption process on the transmitted encrypted authentication ID using the common key (previous generation) 512. In response to this, in step S528, the decryption processing unit 52 determines whether the encrypted authentication ID was decrypted in the second decryption process. If it is decrypted (Y), the process proceeds to step S530 (Figure 9B). If it is not decrypted (N), the process proceeds to step S529.

[0064] Then, in step S529, the decryption processing unit 52 sends an error notification to the mobile terminal 3 via the BLE communication unit 54 indicating that the common key is invalid. Note that the error notification is an example of predetermined information, and other information may be used. For example, information prompting the mobile terminal 3 to request (obtain) the common key (latest) 511 and / or common key (previous generation) 512 from the common key management device 2 may be used. Note that the predetermined information may consist of multiple pieces of information, such as the error notification and the information prompting the acquisition of the common key. The BLE communication unit 54 also disconnects communication with the mobile terminal 3. Note that sending the error notification and disconnecting communication only need to be done at least one of the above. In response, in step S326, the BLE communication unit 36 ​​of the mobile terminal 3 receives the transmitted error notification, and the output unit 35 displays it.

[0065] Next, the process from step S530 onward will be explained using Figure 9B. In step S530, the decoding processing unit 52 of the reading device 5 transmits the decoded authentication ID to the authentication / control device 6 via the serial communication unit 55. Then, in step S621, the serial communication unit 65 of the authentication / control device 6 receives the transmitted authentication ID.

[0066] In response, in step S622, the authentication unit 62 performs authentication using the transmitted authentication ID. That is, the authentication unit 62 determines whether the transmitted authentication ID matches the authentication ID 611 in the storage unit 61. If they match, the authentication unit 62 authenticates that the user is allowed to enter. This also means that the mobile terminal 3 has been authenticated. Thus, in step S622, if the encrypted authentication ID is decrypted using at least one of the first common key, the common key (latest) 511, or the second common key, the common key (previous generation) 512, the authentication unit 62 will perform the authentication process using the decrypted authentication ID. In this case, the mobile terminal or its user will be authenticated. As a result, the authentication process can be performed even if the mobile terminal 3 and the reader 5 hold common keys that do not match each other. In particular, the authentication process can be performed even if the latest common key (the same as the common key (latest) 511) is not delivered to the mobile terminal 3, which generally has a poorer communication environment.

[0067] Then, if authentication is performed in step S622, in step S623, the control command unit 63 executes control processing. More specifically, the control command unit 63 creates an unlock command as a control command for the electronic lock 7. The control command unit 63 then outputs the unlock command to the electronic lock 7 via the serial communication unit 65. The electronic lock 7 unlocks in response to the unlock command. At this time, it is desirable that the electronic lock 7, the reader 5, and the reader 5 announce that the lock has been unlocked by sound or display.

[0068] In step S623, control processing may be performed on multiple controlled devices. For example, the control command unit 63 may coordinately control the entrance gate, elevators, and user's work PC in building 4. Specifically, upon authentication, the control command unit 63 opens the entrance gate, calls the elevator, and starts the PC. In this case, the control command unit 63 may output control commands with a time delay, taking into account the user's movement, and perform control according to the movement.

[0069] Furthermore, in step S624, the control command unit 63 transmits a control history to the common key management device 2 via the center communication unit 66, indicating that it has performed control on the electronic lock 7. Then, in step S221, the communication unit 22 of the common key management device 2 receives the transmitted control history. In response, in step S222, the common key distribution management unit 24 stores the transmitted control history as a usage history in the user management information 213 of the storage unit 21.

[0070] This concludes the explanation of the processing flow in this embodiment. Next, an example of implementation of the common key management device 2 and the mobile terminal 3 of this embodiment will be described. First, the common key management device 2 can be implemented using a computer such as a server or cloud system. Figure 10 is a hardware configuration diagram of the common key management device 2 in this embodiment. In Figure 10, the common key management device 2 has a processing unit 201, a communication device 202, a memory 203, and a sub-storage device 204, which are connected to each other via a communication path.

[0071] First, the processing unit 201 can be implemented as a processor such as a CPU and performs calculations according to the common key management program 205 stored in the secondary memory device 204, which will be described later. The communication device 202 corresponds to the communication unit 22 in Figure 2 and connects to networks 8 and 9 to communicate with other devices such as the mobile terminal 3.

[0072] Furthermore, the memory 203 and the sub-storage device 204 correspond to the storage unit 21 in Figure 2. The memory 203 is where the common key management program 205 and information used for processing by the processing unit 201, which are stored in the sub-storage device 204, are loaded. The sub-storage device 204 can be implemented as so-called storage. The sub-storage device 204 stores the common key management program 205, the authentication ID group 211, the common key group 212, and the common key management information 214.

[0073] Furthermore, the secondary storage device 204 may be implemented using various storage media such as an external HDD (Hard Disk Drive), SSD (Solid State Drive), or memory card, or it may be implemented as a separate device from the common key management device 2, such as a file server.

[0074] Furthermore, the shared key management program 205 is composed of a shared key generation module 206 and a shared key distribution management module 207, each with its own function. Note that each of these modules may be implemented as a separate program.

[0075] Here, the configuration shown in Figure 2, which performs the same function as each module, is as follows: Common key generation module 206: Common key generation unit 23 Common Key Distribution Management Module 207: Common Key Distribution Management Unit 24 Therefore, the processing unit 201 executes the processing of the common key generation unit 23 and the common key distribution management unit 24 in accordance with the common key management program 205. The common key management program 205 can be stored in the sub-memory 204 or other storage media.

[0076] Next, Figure 11 is a hardware configuration diagram of the mobile terminal 3 in this embodiment. In Figure 11, the mobile terminal 3 has a touch panel 301, a processing unit 302, a communication device 303, and a storage device 304, which are connected to each other via a communication path.

[0077] First, the touch panel 301 has a configuration that also serves as the input unit 34 and output unit 35 in Figure 5, and accepts user instructions and operations, and displays various information. The touch panel 301 may also be configured as separate input and output devices. Furthermore, the processing unit 302 can be implemented with a processor such as a CPU (Central Processing Unit), and performs calculations according to the access control program 105 (application) stored in the storage device 304, which will be described later.

[0078] The access control program 305 is composed of an expiration date management module 306 and an encryption processing module 307, each with its own function. Note that each of these modules may be implemented as a separate program.

[0079] Here, the configuration shown in Figure 5, which performs the same function as each module, is as follows: Expiry date management module 306: Expiry date management unit 32 Cryptographic processing module 307: Cryptographic processing unit 33 Therefore, the processing unit 302 will execute the processing of the expiration date management unit 32 and the encryption processing unit 33 in accordance with the access control program 305.

[0080] Furthermore, the storage device 304 stores the access control program 305, authentication ID 311, common key 312, and expiration date 313. The storage device 304 may also be implemented as a main memory device such as memory and a secondary memory device (storage medium) which is a so-called storage device. The secondary memory device may be implemented as an external HDD (Hard Disk Drive), SSD (Solid State Drive), memory card, etc.

[0081] This concludes the description of this embodiment, but the present invention is not limited thereto. The control configuration and processing are optional and can be omitted. Furthermore, it can be applied to purposes other than controlling the electronic lock 7. For example, the authentication result may be used to control login to or startup of a PC or system. Furthermore, the authentication result may be applied to calling and using an elevator. Moreover, the access control system in the above embodiment may be implemented as a function of an attendance management system or a time and attendance management system, or the access control system may be linked with an attendance management system or a time and attendance management system. In addition, key information other than a common key may be used. [Explanation of Symbols]

[0082] 1...Center, 2...Shared Key Management Device, 21...Storage Unit, 211...Authentication ID Group, 212...Shared Key Group, 213...Usage Management Information, 214...Shared Key Management Information, 22...Communication Unit, 23...Shared Key Generation Unit, 24...Shared Key Distribution Management Unit, 3...Mobile Terminal, 31...Storage Unit, 311...Authentication ID, 312...Shared Key, 313...Expiration Date, 32...Expiration Date Management Unit, 33...Encryption Processing Unit, 34...Input Unit, 35...Output Unit, 36...BLE Communication Unit, 37...Center Communication Unit 4...Building, 5...Reader, 51...Storage Unit, 511...Common Key (Latest), 512...Common Key (Previous Generation), 52...Decryption Processing Unit, 53...Registration Processing Unit, 54...BLE Communication Unit, 55...Serial Communication Unit, 6...Authentication / Control Device, 61...Storage Unit, 611...Authentication ID, 612...Common Key, 62...Authentication Unit, 63...Control Command Unit, 64...Registration Processing Unit, 65...Serial Communication Unit, 66...Center Communication Unit, 7...Electronic Lock, 8...Network, 9...Network

Claims

1. In an authentication system that has a shared key management device for managing shared keys and performs authentication using an authentication ID, A communication unit that transmits authentication information, including an authentication ID and a shared key, to a mobile terminal, A storage unit that stores the first common key and the second common key managed by the aforementioned common key management device, A decryption processing unit that performs a decryption process on an encrypted authentication ID encrypted with the shared key by the mobile terminal and transmitted from the mobile terminal using the first shared key, and if the encrypted authentication ID cannot be decrypted with the first shared key, performs a decryption process on the encrypted authentication ID using the second shared key, An authentication system having an authentication unit that, when the encrypted authentication ID is decrypted using either the first common key or the second common key, performs an authentication process using the decrypted authentication ID.

2. In the authentication system described in claim 1, The first common key is the most recent common key generated by the common key management device, The authentication system wherein the second shared key is a shared key that was generated before the first shared key.

3. In the authentication system according to claim 2, Furthermore, the authentication system includes a control command unit that, upon authentication in the authentication process of the authentication unit, creates a control command and outputs the control command to the controlled device.

4. In the authentication system described in claim 1, The authentication unit is an authentication system that authenticates by comparing the authentication ID transmitted from the common key management device with the decrypted authentication ID.

5. In the authentication system according to any one of claims 1 to 4, Furthermore, an authentication system comprising a reader device that communicates with the mobile terminal and has the decryption processing unit, and an authentication / control device that communicates with the reader device and the common key management device and has the authentication unit.

6. In the authentication system described in claim 1, Furthermore, the authentication system includes an output unit that outputs predetermined information if the data cannot be decrypted using the second common key.

7. In an authentication method in which an authentication system having a symmetric key management device that manages a common key authenticates using an authentication ID, The communications department sends authentication information, including the authentication ID and shared key, to the mobile terminal. The storage unit stores the first common key and the second common key managed by the common key management device. The decryption processing unit performs a decryption process on the encrypted authentication ID encrypted with the shared key by the mobile terminal and transmitted from the mobile terminal using the first shared key, and if the encrypted authentication ID cannot be decrypted with the first shared key, it performs a decryption process on the encrypted authentication ID using the second shared key. An authentication method in which, when the authentication unit decrypts the encrypted authentication ID using either the first common key or the second common key, the authentication unit executes an authentication process using the decrypted authentication ID.

8. In the authentication method described in claim 7, The first common key is the most recent common key generated by the common key management device, An authentication method in which the second shared key is a shared key that was generated before the first shared key.

9. In the authentication method described in claim 8, The authentication system further includes a control command unit, The authentication method includes a control unit which, when authenticated by the authentication process in the authentication unit, creates a control command and outputs the control command to the controlled device.

10. In the authentication system according to claim 7, An authentication method in which the authentication unit compares the authentication ID transmitted from the common key management device with the decrypted authentication ID to perform authentication.

11. In the authentication method according to any one of claims 7 to 10, The authentication system further comprises a reader device that communicates with the mobile terminal and has the decryption processing unit, and an authentication / control device that communicates with the reader device and the common key management device and has the authentication unit.