Remote control system
The remote control system addresses the issue of inappropriate device locking by using user authentication and location verification to determine if an information processing device has been stolen or lost, thereby reducing information leakage and enabling quick restoration of device functionality.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- FUJITSU CLIENT COMPUTING LTD
- Filing Date
- 2024-11-07
- Publication Date
- 2026-05-19
AI Technical Summary
Existing remote operation systems for information processing devices fail to appropriately distinguish between legitimate user movement and theft or loss, leading to unnecessary device locking and increased risk of information leakage.
A remote control system comprising an information processing device, a portable device, and a management device that performs user authentication and location verification to determine if the device is within a predetermined range, sending lock or unlock commands based on authentication and location confirmation.
Enables appropriate remote control based on theft or loss, reducing the risk of information leakage and allowing rapid restoration of device functionality when not stolen or lost.
Smart Images

Figure 2026082273000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a remote operation system, a management device, and an information processing device.
Background Art
[0002] When theft or loss of an information processing device such as a notebook PC (Personal Computer) occurs, in order to prevent information leakage, a remote operation system has been proposed that locks the information processing device in a state where it cannot be operated by the user through remote operation (for example, see Patent Document 1).
[0003] In addition, there is a method in which when the owner of the information processing device notices theft or loss, the owner reports it to the administrator, and the administrator remotely locks the information processing device using the management device. However, in this method, if the owner is late in noticing theft or loss, the risk of leakage of confidential information stored in the information processing device increases. Therefore, there is also a method of presetting the usage area for the information processing device and performing remote locking when the information processing device goes outside the usage area.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, even when the information processing device goes outside the usage area, theft or loss does not always occur, and there is a possibility that a legitimate owner may move the information processing device. In such a case, it may be inappropriate to lock the information processing device through remote operation. For this reason, conventionally, an appropriate remote operation according to the presence or absence of theft or loss has not been performed.
[0006] In one respect, this project aims to enable appropriate remote control depending on whether or not the device has been stolen or lost. [Means for solving the problem]
[0007] One proposal provides a remote control system. The remote control system comprises an information processing device, a portable device, and a management device. When the information processing device receives a lock command, it enters a locked state, rendering it inoperable by the user. The portable device performs user authentication and determines whether the location of the information processing device is within a predetermined range from its current location. If authentication fails, or if it determines that the location is not within the predetermined range, it sends a lock request signal requesting the information processing device to send a lock command. When the management device receives a lock request signal from the portable device, it sends a lock command to the information processing device. [Effects of the Invention]
[0008] According to one embodiment, appropriate remote operation can be performed depending on whether or not the device has been stolen or lost. [Brief explanation of the drawing]
[0009] [Figure 1] This figure shows an example of a remote control system according to the first embodiment. [Figure 2] This is a diagram illustrating an example of the operation of a remote control system. [Figure 3] This figure shows an example of a remote control system according to the second embodiment. [Figure 4] This diagram shows an example of PC hardware. [Figure 5] This diagram shows the status of theft or loss. [Figure 6] This figure shows an example of the command issuance process. [Figure 7] This is a flowchart showing an example of the processing procedure for a smartphone in a remote control system. [Figure 8] A flowchart illustrating an example of the processing procedure for issuing periodic lock commands. [Figure 9] This flowchart shows an example of the processing procedure for issuing periodic unlock commands. [Figure 10] A flowchart illustrating an example of the processing procedure for issuing irregular lock commands. [Figure 11] This flowchart shows an example of the processing procedure for issuing an irregular unlock command. [Modes for carrying out the invention]
[0010] The embodiments for carrying out the invention will be described below with reference to the drawings.
[0011] (First Embodiment) Figure 1 shows an example of a remote control system according to the first embodiment. Figure 2 shows an example of the operation of the remote control system.
[0012] The remote control system 10 is a system that, in the event of theft or loss of an information processing device 11 such as a notebook PC (hereinafter referred to as a notebook PC), remotely locks the information processing device 11 to a state where it cannot be operated by the user, in order to prevent information leakage. The remote control system 10 comprises an information processing device 11, a portable device 12, and a management device 13.
[0013] The information processing device 11 is an information processing device such as a notebook PC or a tablet computer. The information processing device 11 includes a communication unit 11a and a processing unit 11b.
[0014] The communication unit 11a communicates with the portable device 12 and the management device 13. The communication unit 11a includes, for example, a wireless interface and performs short-range wireless communication with the portable device 12. The communication unit 11a also includes, for example, a network interface and communicates with the management device 13 via a network such as a WAN (Wide Area Network).
[0015] When the communication unit 11a receives a lock command (to be described later) from the management device 13, the processing unit 11b sets the information processing device 11 to a locked state in which it cannot be operated by the user. Also, when the communication unit 11a receives an unlock command transmitted by the management device 13 while the information processing device 11 is in the locked state, the processing unit 11b releases the locked state.
[0016] Such a processing unit 11b can be realized by a processor, which is hardware such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), or DSP (Digital Signal Processor). The processor may include a plurality of processor cores. Also, the processing unit 11b may include a plurality of processors. The processor that executes a certain process among the plurality of processes performed by the information processing device 11 and the processor that executes a process different from the said process among the plurality of processes may be different. Note that a set of a plurality of processors (multiprocessor) may be referred to as a "processor". The processor may be called a processor circuitry.
[0017] Note that the information processing device 11 may have a function of acquiring the position information of the place where it is used. For example, the information processing device 11 may acquire (receive) position information (latitude and longitude) by a receiver of a satellite positioning system such as GPS (Global Positioning System). Alternatively, the information processing device 11 may acquire the position information of the wireless communication router to which it is connected by wireless communication. The method of acquiring the position information is not limited to these methods.
[0018] The portable device 12 is, for example, a smartphone, a smartwatch, a tablet terminal, or the like. The portable device 12 includes a personal authentication unit 12a, a location confirmation unit 12b, and a communication unit 12c.
[0019] The user authentication unit 12a authenticates whether the user of the mobile device 12 is the legitimate owner (the person concerned), i.e., performs user authentication. Various methods can be applied as methods of user authentication, such as biometric authentication (fingerprint authentication, facial recognition, etc.), and input of a passcode or PIN (Personal Identification Number) code. The mobile device 12 performs user authentication periodically. Alternatively, the mobile device 12 may perform user authentication irregularly at the user's instruction. Such a user authentication unit 12a can be implemented using hardware such as a processor, imaging device, etc., including a CPU, MPU, DSP, etc.
[0020] The location confirmation unit 12b determines whether the location of the information processing device 11 is within a predetermined range from its own (portable device 12) current location. Hereafter, this determination may also be referred to as "location confirmation".
[0021] The location confirmation unit 12b can perform location confirmation using a short-range wireless communication signal transmitted by the information processing device 11. When the communication unit 12c receives a short-range wireless communication signal from the information processing device 11, the location confirmation unit 12b determines that the location of the information processing device 11 is within a predetermined range from its current location. When the communication unit 12c cannot receive a short-range wireless communication signal from the information processing device 11, the location confirmation unit 12b determines that the location of the information processing device 11 is not within a predetermined range from its current location. In this way, location confirmation is possible even if the information processing device 11 or the portable device 12 does not have GPS functionality.
[0022] Alternatively, the location confirmation unit 12b may perform location confirmation using first location information representing the location of the information processing device 11 and second location information representing the current location of the portable device 12. The location confirmation unit 12b may determine whether the location of the information processing device 11 is within a predetermined range from its own current location by comparing the second location information with the first location information received by the communication unit 12c from the information processing device 11 or the management device 13. In this way, the range in which theft or loss is considered to have occurred can be appropriately set or changed according to the user's usage situation. For example, the range to be considered within a predetermined range can be appropriately set within a radius of approximately 10m to 100m.
[0023] Such a location confirmation unit 12b can be implemented using hardware such as a processor, a CPU, an MPU, or a DSP, or a GPS receiver.
[0024] The communication unit 12c communicates with the information processing device 11 and the management device 13. The communication unit 12c includes, for example, a wireless interface and performs short-range wireless communication with the information processing device 11. The communication unit 12c also includes, for example, a network interface and communicates with the management device 13 via a network such as a WAN. The communication unit 12c may also communicate with the management device 13 via a network such as a WAN using a wireless interface.
[0025] If the authentication unit 12a fails to authenticate, or if the location confirmation unit 12b determines that the location of the information processing device 11 is not within a predetermined range, the communication unit 12c sends a lock request signal to the management device 13 requesting the transmission of a lock command to the information processing device 11.
[0026] Furthermore, when the information processing device 11 is locked, if the user authentication unit 12a successfully authenticates the user and the location confirmation unit 12b determines that the location of the information processing device 11 is within a predetermined range, the communication unit 12c transmits a lock release request signal to the management device 13.
[0027] The management device 13 functions as a management site for managing the remote operation of the information processing device 11. The management device 13 is, for example, a server computer capable of communicating with the information processing device 11 and the portable device 12 via a WAN network. The management device 13 includes a communication unit 13a and a processing unit 13b.
[0028] The communication unit 13a communicates with the information processing device 11 and the portable device 12. The communication unit 13a includes, for example, a network interface and communicates between the information processing device 11 and the portable device 12 via a network such as a WAN.
[0029] When the communication unit 13a receives a lock request signal transmitted from the mobile device 12, the processing unit 13b instructs the communication unit 13a to send a lock command to the information processing device 11. Also, when the communication unit 13a receives an unlock signal transmitted from the mobile device 12, the processing unit 13b instructs the communication unit 13a to send an unlock command to the information processing device 11.
[0030] Such a processing unit 13b can be implemented by a processor, which is hardware such as a CPU, MPU, or DSP. The processor may have multiple processor cores. The processing unit 13b may also include multiple processors. The processor that executes one of the multiple processes performed by the management device 13 may be different from the processor that executes a different process from the multiple processes.
[0031] The operation example of the remote control system 10 of the first embodiment will be explained below using Figure 2. In the following explanation, it will be assumed that the legitimate owner of the information processing device 11 and the portable device 12 is the same person.
[0032] If the mobile device 12 successfully authenticates the user and determines, through location verification of the information processing device 11, that its location is within a predetermined range from the mobile device 12's current location, it does not send a lock request signal. This is because, in such a situation, it is assumed that the information processing device 11 has not been stolen or lost.
[0033] On the other hand, if the mobile device 12 fails to authenticate the user (indicated as "Authentication NG" in Figure 2), or if it determines that the location of the information processing device 11 is not within a predetermined range from the current location of the mobile device 12, it sends a lock request signal.
[0034] If user authentication fails, even if the information processing device 11 is within a predetermined range from the current location of the mobile device 12, it may have been stolen along with the mobile device 12. Furthermore, even if user authentication is successful, if the information processing device 11 is not within a predetermined range from the current location of the mobile device 12, it may have been stolen or lost.
[0035] Therefore, in this situation, the portable device 12 transmits a lock request signal as described above to prevent information leakage from the information processing device 11. The management device 13, upon receiving the lock request signal, transmits a lock command to the information processing device 11. Upon receiving the lock command, the information processing device 11 enters a locked state, rendering it unusable by the user. This prevents information leakage from the information processing device 11.
[0036] Furthermore, when the information processing device 11 is locked, if the portable device 12 successfully authenticates the user (indicated as "Authentication OK" in Figure 2) and determines that the location of the information processing device 11 is within a predetermined range from the current location of the portable device 12, it sends a lock release request signal. Upon receiving the lock release request signal, the management device 13 sends a lock release command to the information processing device 11. Upon receiving the lock release command, the information processing device 11 releases the lock state and becomes operable by the user.
[0037] For example, this process is performed if the information processing device 11 was outside a predetermined range from the current location of the portable device 12 for some reason other than theft or loss, but was returned to the user, or if a stolen or lost information processing device 11 was returned to the user. Alternatively, if the information processing device 11 is within a predetermined range from the current location of the portable device 12, but authentication fails due to some error, this process is performed when authentication is successful again.
[0038] As described above, the remote control system 10 of the first embodiment includes an information processing device 11, a portable device 12, and a management device 13. When the information processing device 11 receives a lock command, it enters a locked state where it cannot be operated by the user. The portable device 12 performs user authentication and determines whether the location of the information processing device 11 is within a predetermined range from its current location. If the user authentication fails, or if the portable device 12 determines that its location is not within the predetermined range, it sends a lock request signal requesting the information processing device 11 to send a lock command. When the management device 13 receives the lock request signal from the portable device 12, it sends a lock command to the information processing device 11. This enables appropriate remote control depending on whether the device has been stolen or lost.
[0039] Furthermore, the above process can be performed automatically. Therefore, in cases where a user notices that the information processing device 11 has been stolen or lost and logs into the management site using a mobile device 12 or similar, and requests that the information processing device 11 be locked, the risk of leakage of confidential information or personal information can be reduced.
[0040] Furthermore, in the remote control system 10, if the information processing device 11 is locked, the portable device 12 transmits an unlock request signal requesting the unlock state to the information processing device 11 if it has successfully authenticated the user and determined that the user's location is within a predetermined range. When the management device 13 receives the unlock signal, it transmits an unlock command to the information processing device 11. When the information processing device 11 receives the unlock command, it unlocks the device. This process allows the information processing device 11, which has become locked for reasons other than theft or loss, to be quickly returned to an operable state.
[0041] (Second Embodiment) Figure 3 shows an example of a remote control system according to the second embodiment. The remote control system 20 is a system that, in the event of theft or loss of the PC 100, remotely locks the PC 100 to a state where it cannot be operated by the user, for purposes such as preventing information leakage. The remote control system 20 includes the PC 100, a smartphone 200, and a management server 300.
[0042] PC100 is connected to the management server 300 via network 21. PC100 can also communicate with smartphone 200 via wired or wireless communication. Smartphone 200 is connected to the management server 300 via network 21 via wired or wireless communication.
[0043] Note that the PC100 shown in Figure 3 is an example of the information processing device 11 shown in the first embodiment. The PC100 may be a notebook PC, a tablet computer, or the like. The smartphone 200 is an example of the portable device 12 shown in the first embodiment. A tablet terminal or smartwatch can be used instead of the smartphone 200. The management server 300 is an example of the management device 13 shown in the first embodiment.
[0044] Figure 4 shows an example of PC hardware. The PC100 is controlled as a whole by a processor 101. The processor 101 is connected to memory 102 and several peripheral devices via bus 100a.
[0045] PC100 may be a multiprocessor system having multiple processors. A collection of multiple processors in a multiprocessor system can be called a processor 101. A processor 101 may also be called a processor circuit. Each of the multiple processors can execute some or all of the multiple processes executed on PC100. When there are multiple related processes, the processor executing one process may be different from the processor executing a different process.
[0046] The processor 101 is, for example, a CPU, MPU, or DSP. At least some of the functions that the processor 101 performs by executing a program may be implemented by electronic circuits such as an ASIC (Application Specific Integrated Circuit) or a PLD (Programmable Logic Device).
[0047] Memory 102 is used as the main memory of the PC 100. Memory 102 temporarily stores at least a portion of the OS (Operating System) program and application programs that are to be executed by the processor 101. Memory 102 also stores various data used for processing by the processor 101. For example, a volatile semiconductor memory device such as RAM (Random Access Memory) is used as memory 102.
[0048] Peripheral devices include a storage device 103, a graphics controller 104, an input interface 105, an optical drive device 106, a device connection interface 107, a network interface 108, and a wireless interface 109.
[0049] The storage device 103 electrically or magnetically writes and reads data from its built-in recording medium. The storage device 103 is used as an auxiliary storage device for the PC 100. The storage device 103 stores the OS program, application programs, and various data. For example, the storage device 103 can be an HDD (Hard Disk Drive) or an SSD (Solid State Drive).
[0050] The graphics controller 104 is an arithmetic unit that performs image processing. The graphics controller 104 is, for example, a GPU (Graphics Processing Unit). A monitor 104a is connected to the graphics controller 104. The graphics controller 104 displays images on the screen of the monitor 104a according to instructions from the processor 101. The monitor 104a can be an OLED (Electroluminescence) display device or a liquid crystal display device. If a DSP (Demand-Side Programmer) is used as the graphics controller 104, the graphics controller 104 can also perform complex numerical calculations such as matrix calculations.
[0051] The input interface 105 is connected to a keyboard 105a and a mouse 105b. The input interface 105 transmits signals from the keyboard 105a and mouse 105b to the processor 101. Note that the mouse 105b is just one example of a pointing device; other pointing devices can also be used. Other pointing devices include touch panels, tablets, touchpads, and trackballs.
[0052] The optical drive device 106 uses laser light or the like to read data recorded on the optical disc 106a or write data to the optical disc 106a. The optical disc 106a is a portable recording medium on which data is recorded in a way that makes it readable by the reflection of light. Examples of optical discs 106a include DVD (Digital Versatile Disc), DVD-RAM, CD-ROM (Compact Disc Read Only Memory), and CD-R (Recordable) / RW (ReWritable).
[0053] The device connection interface 107 is a communication interface for connecting peripheral devices to the PC 100. For example, a memory device 107a and a memory reader / writer 107b can be connected to the device connection interface 107. The memory device 107a is a recording medium equipped with a communication function with the device connection interface 107. The memory reader / writer 107b is a device that writes data to or reads data from the memory card 107c. The memory card 107c is a card-type recording medium.
[0054] The network interface 108 is connected to the network 21. The network interface 108 transmits and receives data to and from other computers or communication devices via the network 21. The network interface 108 is a wired communication interface, for example, connected by cable to a wired communication device such as a switch or router. Alternatively, the network interface 108 may be a wireless communication interface, connected by radio waves to a wireless communication device such as a base station or access point.
[0055] The wireless interface 109 is a communication interface for short-range wireless communication. The wireless interface 109 can communicate data with the smartphone 200.
[0056] PC100 may also have a receiver for a satellite positioning system such as GPS. Based on the data received by the satellite positioning system receiver, PC100 can obtain location information (latitude and longitude) of the place being used.
[0057] The PC100 can implement the processing functions of the second embodiment using the hardware described above. The management server 300 can also be implemented using the same hardware as shown in Figure 4. The information processing device 11 and management device 13 shown in the first embodiment can also be implemented using the same hardware as the PC100 shown in Figure 4. The processing units 11b and 13b shown in Figure 1 can be implemented using the processor 101, and the communication units 11a and 13a shown in Figure 1 can be implemented using the network interface 108 or the wireless interface 109.
[0058] The PC100 implements the processing functions of the second embodiment by, for example, executing a program recorded on a computer-readable recording medium. The program describing the processing to be executed by the PC100 can be recorded on various recording media. For example, the program to be executed by the PC100 can be stored in the storage device 103. The processor 101 loads at least a portion of the program in the storage device 103 into the memory 102 and executes the program. Alternatively, the program to be executed by the PC100 can be recorded on a portable recording medium such as an optical disc 106a, a memory device 107a, or a memory card 107c. The program stored on the portable recording medium becomes executable after being installed in the storage device 103 under control from the processor 101, for example. The processor 101 can also directly read and execute the program from the portable recording medium.
[0059] Smartphone 200, like PC100, has a processor, wireless interface, etc., but these are omitted from the illustration.
[0060] Figure 5 shows the situation regarding the presence or absence of theft or loss. Figure 5(A) shows an example of a situation where theft or loss has not occurred, and Figure 5(B) shows an example of a situation where theft or loss has occurred.
[0061] Smartphone 200 performs user authentication and verifies the location of PC 100. Location verification is performed by determining whether PC 100 is within a predetermined range from the current location of Smartphone 200.
[0062] Smartphone 200 performs user authentication through methods such as biometric authentication (fingerprint authentication, facial recognition, etc.), and accepting the input of a passcode or PIN code.
[0063] Smartphone 200 can determine its location using the short-range wireless communication signal transmitted by PC 100. When smartphone 200 receives a short-range wireless communication signal from PC 100, it determines that PC 100 is within a predetermined range from its current location. When smartphone 200 does not receive a short-range wireless communication signal from PC 100, it determines that PC 100 is not within a predetermined range from its current location.
[0064] Alternatively, the smartphone 200 can perform location verification using first location information representing the location of PC 100 and second location information representing the current location of the smartphone 200. The smartphone 200 may also determine whether the location of PC 100 is within a predetermined range from its current location by comparing the second location information with the first location information received from PC 100 or the management server 300.
[0065] As shown in Figure 5(A), in situations where PC100 has not been stolen or lost, the smartphone 200 successfully authenticates the user (user authentication OK), and it is determined that PC100 is within a predetermined range from the smartphone 200's current location (location confirmation OK).
[0066] As shown in Figure 5(B), in the event of theft or loss, either the smartphone 200 fails to authenticate (authentication NG), or the PC 100 is determined to be outside the specified range from the smartphone 200's current location (location confirmation NG). If authentication fails, even if location confirmation is successful, there is a possibility that the PC 100 has been stolen along with the smartphone 200.
[0067] Figure 6 shows an example of the command issuance process. Figure 6(A) shows the process of issuing a lock command, and Figure 6(B) shows the process of issuing an unlock command.
[0068] If user authentication or location verification fails, the smartphone 200 sends a lock command to the management server 300, as shown in Figure 6(A). The lock command issuance command corresponds to the lock request signal transmitted by the mobile device 12 according to the first embodiment.
[0069] When the management server 300 receives a lock command issuance command sent by the smartphone 200, it sends a lock command to the PC 100. The lock command corresponds to the lock command sent by the management device 13 according to the first embodiment.
[0070] When the lock command is successfully executed and the PC 100 enters a locked state (a state where user operation is impossible), the management server 300 sends a lock command success response to the smartphone 200. The management server 300 also receives a response from the PC 100 indicating whether or not the lock command was successfully executed.
[0071] When PC100 is locked, if user authentication and location verification are successful, the smartphone 200 sends an unlock command to the management server 300, as shown in Figure 6(B). The unlock command issuance command corresponds to the unlock request signal transmitted by the mobile device 12 according to the first embodiment.
[0072] When the management server 300 receives an unlock command issuance command sent by the smartphone 200, it sends an unlock command to the PC 100. The unlock command corresponds to the unlock command sent by the management device 13 according to the first embodiment.
[0073] When the unlock command is successfully executed and the PC 100 enters an unlocked state (user-operable state), the management server 300 sends a success response to the unlock command to the smartphone 200. The management server 300 also receives a response from the PC 100 indicating whether or not the unlock command was successfully executed.
[0074] Furthermore, the lock command and unlock command commands that the smartphone 200 sends to the management server 300 may be sent via SMS (Short Message Service). The success response of the lock command and unlock command that the management server 300 sends to the smartphone 200, as well as the lock command and unlock command that it sends to the PC 100, may also be sent via SMS.
[0075] In PC100, lock commands and unlock commands received from management server 300 are analyzed by, for example, the BIOS (Basic Input Output System). If a lock command is received, for example, the BIOS disables the keyboard 105a and mouse 105b, rendering PC100 unusable by the user. If an unlock command is received, for example, the BIOS enables the keyboard 105a and mouse 105b, making PC100 usable by the user.
[0076] Furthermore, when PC100 is locked, if user authentication is successful, smartphone 200 may accept a command from the user requesting the erasure of data on PC100 to prevent leakage of confidential or personal information. In this case, smartphone 200 sends a data erasure command issuance command to management server 300. Upon receiving the data erasure command issuance command, management server 300 sends a data erasure command to PC100. Upon receiving the data erasure command, PC100 erases, for example, the data stored in storage device 103.
[0077] Next, an example of the processing procedure for the smartphone 200 in the remote control system 20 of the second embodiment will be described. Figure 7 is a flowchart showing an example of the processing procedure for a smartphone in a remote control system.
[0078] When smartphone 200 is turned on (step S10) and the remote control application is launched (step S11), smartphone 200 performs user authentication (step S12). If user authentication is successful (step S13: YES), the process in step S14 is performed; if user authentication is unsuccessful (step S13: NO), the process in step S19 is performed.
[0079] In step S14, the smartphone 200 checks the location of the PC 100. If the location check is successful (step S15: YES), the process in step S16 is performed; if the location check is unsuccessful (step S15: NO), the process in step S19 is performed.
[0080] In step S16, the smartphone 200 turns off the lock flag. The lock flag is information indicating whether the PC 100 is locked or not. When the lock flag is off (for example, 0), it indicates that the device is not locked (unlocked), and when it is on (for example, 1), it indicates that the device is locked. In step S16, the lock flag is initialized to off.
[0081] Subsequently, the smartphone 200 periodically executes a lock command issuance process (step S17). The procedure for the periodic lock command issuance process will be described later (see Figure 8).
[0082] When the application terminates (step S18), the processing on the smartphone 200 related to remote control ends. Also, in step S19, which is performed when user authentication or location verification fails, the smartphone 200 notifies the user of the failure to start. For example, the smartphone 200 notifies the user of the failure to start by displaying a message on the display screen indicating that the start preparation failed. After that, the processing on the smartphone 200 related to remote control ends.
[0083] Figure 8 is a flowchart showing an example of the processing procedure for issuing periodic lock commands. When a predetermined waiting time has elapsed (step S20), the smartphone 200 determines whether or not the lock flag is off (step S21).
[0084] The smartphone 200 can also perform the following irregular lock command issuance process (see Figure 10) or unlock command issuance process (see Figure 11) via interrupt processing during the standby time. If the irregular lock command issuance process or unlock command issuance process is performed during the standby time, the state of the lock flag (on or off) is unknown, so a lock flag determination process is performed.
[0085] If the smartphone 200 determines that the lock flag is off, it performs user authentication (step S22). The smartphone 200 may also notify the user to perform user authentication via sound or a message on the display screen.
[0086] If identity verification is successful (Step S23: YES), the process in Step S24 is performed; if identity verification is unsuccessful (Step S23: NO), the process in Step S26 is performed.
[0087] If the smartphone 200 determines in step S21 that the lock flag is not off, it performs the process of issuing a periodic unlock command, as described below (see Figure 9).
[0088] In step S24, the smartphone 200 checks the location of the PC 100. If the location check is successful (step S25: YES), the process from step S20 is repeated. If the location check fails (step S25: NO), the process in step S26 is performed.
[0089] In step S26, the smartphone 200 sends a lock command to the management server 300. The smartphone 200 then receives a successful lock command response from the management server 300 (step S27) and turns on the lock flag (step S28).
[0090] In this case, since it is believed that PC100 (or smartphone 200) has been stolen or lost, smartphone 200 may display a message on its screen indicating that PC100 has been locked. Also, when user authentication is OK but location verification is NG, if smartphone 200 is using PC100's location information (the first location information mentioned above) for location verification, it may display PC100's location on its screen based on the location information.
[0091] After processing in step S28, the smartphone 200 performs the following periodic unlock command issuance process.
[0092] Figure 9 is a flowchart showing an example of the processing procedure for issuing periodic unlock commands. When a predetermined waiting time has elapsed (step S30), the smartphone 200 determines whether or not the lock flag is on (step S31).
[0093] The smartphone 200 can also perform the following irregular lock command issuance process (see Figure 10) or unlock command issuance process (see Figure 11) via interrupt processing during the standby time. If the irregular lock command issuance process or unlock command issuance process is performed during the standby time, the state of the lock flag (on or off) is unknown, so a lock flag determination process is performed.
[0094] If the smartphone 200 determines that the lock flag is on, it performs user authentication (step S32). The smartphone 200 may also notify the user to perform user authentication via sound or a message on the display screen.
[0095] If identity verification is successful (step S33: YES), the process in step S34 is performed; if identity verification is unsuccessful (step S33: NO), the process from step S30 is repeated.
[0096] If the smartphone 200 determines in step S31 that the lock flag is not on, it performs the aforementioned periodic lock command issuance process.
[0097] In step S34, the smartphone 200 checks the location of the PC 100. If the location check is successful (step S35: YES), the process in step S36 is performed. If the location check fails (step S35: NO), the process from step S30 is repeated.
[0098] In step S36, the smartphone 200 sends an unlock command to the management server 300. The smartphone 200 then receives a successful unlock command response from the management server 300 (step S37) and turns off the lock flag (step S38).
[0099] At this time, the smartphone 200 may display a message on its screen indicating that the PC 100 has changed from a locked state to an unlocked state (a state in which the user can operate it). Also, if the smartphone 200 is using the location information of the PC 100 (the first location information mentioned above) to confirm its location, it may display the location of the PC 100 on its screen based on the location information.
[0100] After processing in step S38, the smartphone 200 performs the aforementioned periodic lock command issuance process.
[0101] Figure 10 is a flowchart showing an example of the processing procedure for issuing an irregular lock command. The irregular lock command issuance process is executed when the user enters a predetermined command into the smartphone 200, for example, when the user becomes aware of the possibility of theft or loss of the PC 100.
[0102] The smartphone 200 first determines whether the lock flag is off or off (step S40). This lock flag determination process is performed because it is unclear whether the lock flag is on or off if a periodic lock command issuance process or an unlock command issuance process has occurred before an irregular lock command issuance process.
[0103] If smartphone 200 determines that the lock flag is off, it performs user authentication (step S41). If user authentication is successful (step S42: YES), the process in step S43 is performed; if user authentication is unsuccessful (step S42: NO), the process in step S45 is performed.
[0104] If the smartphone 200 determines in step S40 that the lock flag is not off, it performs the process of issuing an irregular unlock command, as described below (see Figure 11).
[0105] In step S43, the smartphone 200 verifies the location of the PC 100. If the location verification is successful (step S44: YES), the smartphone 200 terminates the lock command issuance process without sending a lock command issuance command. This is because if user authentication is successful and the location verification is successful, it is assumed that the PC 100 has not been stolen or lost.
[0106] In this case, the smartphone 200 may display a message on its screen indicating that the PC 100 has not been stolen or lost. Furthermore, if the smartphone 200 is using the PC 100's location information (the first location information mentioned above) to confirm its whereabouts, it may display the PC 100's location on its screen based on that information.
[0107] If location verification fails (step S44: NO), the process in step S45 is performed. In the process in step S45, the smartphone 200 sends a lock command issuance command to the management server 300. The smartphone 200 then receives a successful lock command response from the management server 300 (step S46) and turns on the lock flag (step S47).
[0108] In this case, the smartphone 200 may display a message on its screen indicating that the PC 100 has been locked, as it is believed that the PC 100 has been stolen or lost. Furthermore, if the smartphone 200 is using the PC 100's location information (the first location information mentioned above) to confirm its whereabouts, it may display the PC 100's location on its screen based on that information.
[0109] After processing in step S47, the smartphone 200 terminates the process of issuing the lock command.
[0110] Figure 11 is a flowchart showing an example of the processing procedure for issuing an irregular unlock command. The irregular unlock command issuance process is executed, for example, when a predetermined command is entered into the smartphone 200 by the user.
[0111] Smartphone 200 performs user authentication (step S50). If user authentication is successful (step S51: YES), the process in step S52 is performed. If user authentication fails (step S51: NO), since there is a possibility that smartphone 200 has been stolen or lost along with PC 100, smartphone 200 terminates the unlock command issuance process without sending an unlock command.
[0112] In this case, since it is believed that PC100 (or smartphone 200) has been stolen or lost, smartphone 200 may display a message on its screen indicating that it cannot unlock PC100. Also, when user authentication is OK but location verification is NG, if smartphone 200 is using PC100's location information (the first location information mentioned above) for location verification, it may display PC100's location on its screen based on the location information.
[0113] In step S52, the smartphone 200 checks the location of the PC 100. If the location check is successful (step S53: YES), the process in step S54 is performed. If the location check fails (step S53: NO), the PC 100 may have been stolen, so the smartphone 200 terminates the unlock command issuance process without sending an unlock command.
[0114] In step S54, the smartphone 200 sends an unlock command to the management server 300. The smartphone 200 then receives a successful response from the management server 300 (step S55) and turns off the lock flag (step S56). At this time, the smartphone 200 may display a message on its screen indicating that the lock state of the PC 100 has been released.
[0115] After the processing in step S56, the smartphone 200 terminates the process of issuing the unlock command.
[0116] Note that the processing order shown in Figures 7 to 11 is just an example, and the processing order may be changed as appropriate. Furthermore, the program describing the processing content shown in Figures 7 to 11, to be executed by the smartphone 200, can be stored on various recording media. For example, the program to be executed by the smartphone 200 can be stored in the storage device within the smartphone 200. The processor within the smartphone 200 loads at least a portion of the program from the storage device into the smartphone 200's memory and executes the program. Alternatively, the program to be executed by the smartphone 200 can be recorded on a portable recording media such as an optical disc or memory device. A program stored on a portable recording media can be installed on the storage device via control from the processor, for example, and then become executable. The processor can also directly read and execute the program from the portable recording media.
[0117] As described above, the remote control system 20 of the second embodiment includes a PC 100, a smartphone 200, and a management server 300. When the PC 100 receives a lock command, it enters a locked state where it cannot be operated by the user. The smartphone 200 performs user authentication and verifies the location of the smartphone 200. If user authentication fails or location verification fails, the smartphone 200 sends a lock command issuance command requesting the PC 100 to send a lock command. When the management server 300 receives a lock command issuance command from the smartphone 200, it sends a lock command to the PC 100. This enables appropriate remote control depending on whether the device has been stolen or lost.
[0118] Furthermore, since the above process can be performed automatically, the risk of information leakage can be reduced in cases where a user notices that their PC100 has been stolen or lost, logs into the management site using a smartphone 200, and requests that the PC100 be locked.
[0119] Furthermore, in the remote control system 20, when the PC 100 is locked, the smartphone 200 sends an unlock command to request the unlocking of the PC 100 if user authentication and location verification are successful. The management server 300 then sends an unlock command to the PC 100 upon receiving the unlock signal. The PC 100 unlocks the PC upon receiving the unlock command. This process allows for the rapid restoration of the PC 100, which has become locked for reasons other than theft or loss, to an operable state.
[0120] Furthermore, the smartphone 200 periodically performs user authentication at the aforementioned waiting intervals, and if authentication is successful, it verifies the location of the PC100. This ensures that even if the legitimate owner of the PC100 is unaware of the theft or loss, the PC100 can be automatically locked if user authentication fails or location verification fails when the periodic user authentication timing arrives.
[0121] Furthermore, the smartphone 200 can perform irregular user authentication via interrupt processing during the waiting period before periodic user authentication is performed. If user authentication is successful during these irregular authentications, the smartphone 200 will check the location of the PC 100. This allows the user to lock the PC 100 as soon as they realize that the PC 100 may have been stolen or lost, even before the scheduled time for periodic user authentication arrives.
[0122] The above describes one aspect of the remote control system, management device, and information processing device of the present invention based on embodiments, but these are merely examples and the invention is not limited to those described above. [Explanation of symbols]
[0123] 10 Remote Control Systems 11 Information Processing Devices 11a,12c,13a Communication Department 11b, 13b Processing Unit 12. Mobile devices 12a Identity Verification Department 12b is located in the confirmation department 13 Management Device
Claims
1. An information processing device that enters a locked state where user operation is impossible upon receiving a lock command, A portable device that performs user authentication, determines whether the location of the information processing device is within a predetermined range from the user's current location, and, if authentication fails or if it is determined that the location is not within the predetermined range, transmits a lock request signal requesting the transmission of the lock command to the information processing device. A management device that, upon receiving the lock request signal from the portable device, transmits the lock command to the information processing device, A remote control system.
2. When the information processing device is in the locked state, if it determines that authentication has been successful in the user authentication process and that the user's location is within the predetermined range, the portable device transmits an unlock request signal requesting the release of the locked state. When the management device receives the unlock request signal, it sends an unlock command to the information processing device. The information processing device, upon receiving the unlock command, releases the locked state. The remote control system according to claim 1.
3. The aforementioned information processing device transmits a short-range wireless communication signal, The portable device determines that its location is within the predetermined range when it receives the short-range wireless communication signal transmitted by the information processing device, and determines that its location is not within the predetermined range when it cannot receive the short-range wireless communication signal. The remote control system according to claim 1.
4. The portable device receives first location information representing the location of the information processing device, and compares the first location information with second location information representing the current location of the portable device to determine whether the location is within the predetermined range. The remote control system according to claim 1.
5. The remote control system according to claim 1, wherein the portable device periodically performs the user authentication, and if the user authentication is successful, it determines whether the user's location is within the predetermined range.
6. The remote control system according to claim 5, wherein the portable device performs the personal authentication irregularly by interrupt processing during the waiting time until the periodic personal authentication is performed, and if the authentication is successful in the irregular personal authentication, it determines whether the location is within the predetermined range.
7. A communication unit that communicates via a network between a mobile device used for user authentication and an information processing device that enters a locked state where user operation is impossible upon receiving a lock command, If the mobile device fails authentication in the user authentication process, or if the information processing device is determined to be outside a predetermined range from the current location of the mobile device, the communication unit receives a lock request signal transmitted from the mobile device, and the processing unit instructs the communication unit to transmit the lock command to the information processing device. A control device having the following features.
8. In an information processing device, A communication unit that communicates with a portable device used for user authentication and a management device, and receives a lock command transmitted by the management device when the portable device fails to authenticate the user, or when the portable device determines that the location of the information processing device is not within a predetermined range from the current location of the portable device. When the communication unit receives the lock command, a processing unit sets the information processing device into a locked state that prevents user operation, An information processing device having