Terminal sharing system, terminal sharing device, terminal sharing method, terminal sharing program
The terminal sharing system uses ownership and knowledge elements for secure authentication, allowing single sign-on without repeated login inputs, addressing the challenge of balancing security and convenience in shared terminal scenarios.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- 株式会社メドコム
- Filing Date
- 2024-11-08
- Publication Date
- 2026-05-20
AI Technical Summary
Existing technologies fail to balance security and convenience when multiple users share a terminal, as they cannot store a specific user's ID, necessitating repeated login inputs.
A terminal sharing system that combines ownership element information from personal possessions and knowledge element information, such as passwords, to authenticate users, allowing single sign-on and ensuring security without requiring repeated login inputs.
Ensures high-security authentication by combining ownership and knowledge elements, enabling convenient single sign-on for multiple users sharing a terminal.
Smart Images

Figure 2026083744000001_ABST
Abstract
Description
Technical Field
[0004] , , , , , , , , , , , , , ,
[0005] , , , , ,
[0001] The present invention relates to a terminal sharing system, a terminal sharing device, a terminal sharing method, and a terminal sharing program for sharing a terminal among a plurality of users.
Background Art
[0002] As prior arts for sharing a terminal among a plurality of users, Patent Documents 1, 2, etc. are known. Also, as a two-factor authentication system for improving security, Patent Document 3 is known; as a technology related to single sign-on for improving convenience, Patent Document 4 is known; and as an authentication technology using a contactless IC card, Non-Patent Document 1, etc. are known.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Patent Document 2
Patent Document 3
Patent Document 4
Non-Patent Documents
[0004]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, there have been no proposed technologies that can achieve both improved security and convenience in situations where multiple users share a terminal. For example, if a terminal is used exclusively by a specific user, the terminal can store a user ID to identify that user, thus eliminating the need for input. However, a shared terminal cannot store the user ID of a specific user. Therefore, the present invention aims to provide a technology that can achieve both security and convenience in situations where multiple users share a terminal. [Means for solving the problem]
[0006] The terminal sharing system of the present invention consists of a terminal sharing device and a terminal. The terminal includes an ownership element acquisition unit and a knowledge element acquisition unit. The ownership element acquisition unit acquires ownership element information from each user's possessions. The knowledge element acquisition unit acquires knowledge element information for the user's user identification information. The terminal sharing device includes a recording unit, an information conversion unit, and an authentication unit. The recording unit records ownership element information and knowledge element information in association with user identification information. The information conversion unit converts the ownership element information acquired by the terminal's ownership element acquisition unit into the terminal's user identification information. The authentication unit grants login to the terminal if the knowledge element information acquired by the terminal's knowledge element acquisition unit is knowledge element information associated with the terminal's user identification information. [Effects of the Invention]
[0007] According to the terminal sharing system of the present invention, ownership element information is first obtained from the terminal. Then, within the terminal sharing device, the user identification information of the user associated with the ownership element information is set as the user identification information of the terminal user. When knowledge element information associated with the user identification information is obtained from the terminal, login to that terminal is permitted. Security can be ensured because authentication can be performed by combining ownership element information and knowledge element information. In addition, convenience is ensured because the user does not need to enter user identification information. [Brief explanation of the drawing]
[0008] [Figure 1] A diagram showing an example configuration of the terminal sharing system of the present invention. [Figure 2] This diagram shows an example of a processing flow when terminal 200 has a logout information acquisition unit 230. [Figure 3] This diagram shows an example of a processing flow when the terminal sharing device 100 has a clock-out schedule acquisition unit 150. [Figure 4] A diagram showing an example of the processing flow for logout. [Figure 5] A diagram illustrating an example of a computer's functional configuration. [Modes for carrying out the invention]
[0009] The embodiments of the present invention will be described in detail below. Components having the same function will be given the same number, and redundant explanations will be omitted. [Examples]
[0010] Figure 1 shows an example configuration of the terminal sharing system of the present invention. Figure 2 is an example of a processing flow when terminal 200 has a logout information acquisition unit 230, and Figure 3 is an example of a processing flow when terminal sharing device 100 has a scheduled departure acquisition unit 150. Figure 4 is an example of a processing flow related to logout processing. The terminal sharing system 10 consists of terminal sharing device 100 and terminal 200 connected by a data communication network 400. There are usually multiple terminals 200. However, the present invention can also be used when one terminal 200 is shared by multiple users. Systems A310, B320, etc., that provide functions to terminal 200 are connected to the data communication network 400. Although two systems are shown in Figure 1, there may be three or more. For example, in the case of a system used in a hospital, system A310 could handle patient medical record information, and system B320 could handle drug inventory information, etc. Other systems that handle staff work information are also conceivable.
[0011] Terminal 200 includes an ownership element acquisition unit 210 and a knowledge element acquisition unit 220. Terminal 200 is, for example, a smartphone and also has communication functions, recording functions, input / output functions, etc. These terminal functions are provided as a terminal function unit 290. For example, if it is a smartphone, terminal 200 also has the function of connecting to the telephone network 900. As will be described later, terminal 200 may also include a logout information acquisition unit 230.
[0012] The terminal sharing device 100 includes a recording unit 190, an information conversion unit 110, an authentication unit 120, an authorization setting unit 130, and an authentication control unit 140. If the terminal 200 also has the function of connecting to the telephone network 900, the terminal sharing device 100 may also include a login information sharing unit 160. Furthermore, as will be described later, the terminal sharing device 100 may also include a clock-out schedule acquisition unit 150. The recording unit 190 records ownership element information and knowledge element information in association with at least user identification information.
[0013] The ownership element acquisition unit 210 of terminal 200 acquires ownership element information from each user's possessions (S210). "Personal possessions for each user" include, for example, identification cards and credit cards. IC cards are assumed to be "personal possessions for each user," but cards with two-dimensional barcodes may also be included. "Ownership element information" is information obtained from these possessions. This information may change over time, or it may not change. Terminal 200 transmits the ownership element information, along with terminal identification information (for example, terminal ID, telephone number, etc.) that identifies terminal 200, to the terminal sharing device 100.
[0014] The information conversion unit 110 of the terminal sharing device 100 converts the ownership element information acquired by the ownership element acquisition unit 210 of the terminal 200 into user identification information based on the information in the recording unit 190 (S110). The "user identification information" is information corresponding to a so-called login ID. In general services, it is often possible to log in by entering a login ID and a password (an example of knowledge element information). It is desirable that the "user identification information" be different from the "ownership element information" and be assigned to the user. The obtained user identification information may or may not be transmitted to the terminal 200.
[0015] The knowledge element acquisition unit 220 acquires knowledge element information regarding the user's user identification information (S220). The "knowledge element information" is information known only to the user, such as a password or a PIN number. After the terminal 200 transmits the ownership element information and the terminal identification information to the terminal sharing device 100, it requests the user to input the knowledge element information. The terminal 200 transmits the knowledge element information input by the user together with the terminal identification information to the terminal sharing device 100.
[0016] When the terminal 200 includes a logout information acquisition unit 230, the processing flow shown in FIG. 2 is obtained. The logout information acquisition unit 230 acquires logout information, which is information on the timing of logout (S230). The "logout information" may be the time scheduled for logout (e.g., 17:00) or the time until logout (e.g., 7 hours). For example, the logout information acquisition unit 230 may request the user to input the scheduled time of leaving work on that day. The authentication control unit 140 may set the time when the terminal 200 is scheduled to logout according to the logout information (S141).
[0017] When the terminal sharing device 100 includes a leaving work schedule acquisition unit 150, the processing flow shown in FIG. 3 is adopted. The leaving work schedule acquisition unit 150 acquires information on the leaving work schedule time of the user corresponding to the user identification information (S150), and sets it as logout information, which is information on the timing for logging out at the leaving work schedule time, in the authentication control unit 140 (S141). For example, if a system for managing the working hours of staff is connected to the data communication network 400, the leaving work schedule acquisition unit 150 may obtain information on the working hours of the user of that terminal based on the user identification information and acquire the information on the leaving work schedule time. Also, for example, if the number of staff is limited, a schedule table (shift table of staff) may be recorded in the terminal sharing device 100, and the information on the leaving work schedule time may be acquired based on that schedule table. In FIG. 3, the acquisition of the leaving work schedule (S150) is performed before the authentication (S120), but it may be performed at any timing as long as it is before the logout process setting (S141).
[0018] The authentication unit 120 permits the terminal 200 to log in when the knowledge element information acquired by the knowledge element acquisition unit of the terminal 200 is the knowledge element information associated with the user identification information of the user of the terminal 200 (S120). When the terminal 200 includes a logout information acquisition unit 230, the authentication unit 120 may permit the terminal 200 to log in after acquiring the logout information. Since the login is permitted based on the ownership element information and the knowledge element information, security can be ensured at a high level.
[0019] Also, the recording unit 190 may record the authority information, which is information on the authority for the user identification information, in association therewith. Then, the terminal sharing device 100 may also include an authority setting unit 130. When the authentication unit 120 permits the login, the authority setting unit 130 sets the external systems (for example, system A310, system B320, etc.) to be usable according to the authority information corresponding to the user identification information of the terminal 200 (S130). In this way, if the use of a plurality of systems can be set by the authentication unit 120 permitting the login, so-called single sign-on can be realized. Therefore, convenience can be ensured.
[0020] Furthermore, if terminal 200 has the function of connecting to the telephone network 900, the recording unit 190 may also record the terminal's telephone number and information about the logged-in terminal and its user. For example, if a terminal ID different from the telephone number is used as information to identify the terminal, the recording unit 190 will record the terminal IDs and telephone numbers of all terminals 200 that are subject to sharing. The recording unit 190 may also record the logged-in terminal ID and information about the user of that terminal. Recording in this way allows the telephone number of the logged-in terminal to be associated with the user. The terminal sharing device 100 may also include a login information sharing unit 160. When the authentication unit 120 permits login, the login information sharing unit 160 sends the telephone number of the permitted terminal 200 and information about the user of that terminal to the other logged-in terminals 200 (S160). The login information sharing unit 160 also sends the telephone number and user information of each of the other logged-in terminals 200 to the terminal 200 that permitted login (S160).
[0021] Other terminals 200 that are logged in add the received phone number and user information to their phonebook (S291). Also, terminal 200 that is authorized to log in sets the phone number and user information of other logged-in terminals 200 as phonebook information (S295). Phone numbers are fixed to each individual terminal. However, in the case of shared terminals, who is using which phone number terminal changes. By providing a login information sharing unit 160, even when terminals are shared, it is possible to call the person you want to call.
[0022] According to the terminal sharing system 10, ownership element information is first obtained from terminal 200. Then, internally within the terminal sharing device 100, the user identification information of the user associated with that ownership element information is set as the user identification information of the user on terminal 200. When the knowledge element information associated with the user identification information is obtained from terminal 200, login to terminal 200 is permitted. Security can be ensured because authentication can be performed by combining ownership element information and knowledge element information. In addition, convenience is ensured because the user does not need to enter user identification information.
[0023] Next, let's explain logout. In principle, users should log out themselves. However, if a user forgets to log out, another user may impersonate the previous user. Therefore, the terminal sharing system 10 should be equipped with a logout processing function (see Figure 4). The authentication control unit 140 starts the logout process at the scheduled logout time set as logout information (S141) (S142). The authentication control unit 140 notifies terminal 200 that the logout process has started.
[0024] Terminal 200 prompts the user to input ownership element information or knowledge element information. Terminal 200 may request both ownership element information and knowledge element information from the user, request either one, or specify which one to request. If the user wishes to continue using Terminal 200, the ownership element acquisition unit 210 of Terminal 200 acquires ownership element information from the owner of the logged-in user. Alternatively, the knowledge element acquisition unit 220 of Terminal 200 acquires knowledge element information for the user identification information of the logged-in user. Terminal 200 transmits the acquired ownership element information or knowledge element information and terminal identification information to the terminal sharing device 100.
[0025] If the authentication control unit 140 obtains ownership element information from the logged-in user's belongings or obtains knowledge element information for the logged-in user's user identification information within a predetermined period after the start of the logout process (S121, Yes), it cancels the logout process (S144). The authentication control unit 140 resets the new logout timing (the scheduled time for logout) (S145). The new scheduled time for logout may be set by the user via the terminal 200, or it may be set after a predetermined time (for example, after 1 hour).
[0026] If step S121 is No, the authentication control unit 140 logs out terminal 200 (S143). When terminal 200 logs out, the login information sharing unit 160 sends the phone number information of the logged-out terminal 200 to the other logged-in terminals 200 (S161). The other logged-in terminals 200 delete the phone number information of the logged-out terminal 200 from their phonebook information (S292). Also, all information registered in the phonebook of the logged-out terminal 200 is deleted (S296). Through these processes, when a terminal 200 shared by multiple users logs out, the information can be deleted. In addition, since the logout process is performed using the logout schedule, impersonation can be prevented even if the user forgets to log out.
[0027] [Processor, program, recording medium] The functions realized by the components described herein may be implemented in a circuitry or processing circuitry, including general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), CPUs (a Central Processing Unit), conventional circuits, and / or combinations thereof, programmed to realize the functions described herein. A processor includes transistors and other circuits and is considered a circuitry or processing circuitry. A processor may be a programmed processor that executes a program stored in memory.
[0028] In this specification, circuitry, unit, and means are hardware programmed to perform or execute the functions described herein. Such hardware may be any hardware disclosed herein, or any hardware known to be programmed to perform or execute the functions described herein.
[0029] If the hardware is a processor that is considered to be a type of circuitry, then the circuitry, means, or unit is a combination of hardware and software used to constitute the hardware and / or processor.
[0030] The various processes described above can be carried out by loading a program that executes each step of the above method into the recording unit 2020 of the computer 2000 shown in Figure 5, and then causing the control unit 2010, input unit 2030, output unit 2040, display unit 2050, etc. to operate.
[0031] The program describing this process can be recorded on a computer-readable recording medium. Any computer-readable recording medium can be used, such as a magnetic recording device, optical disc, magneto-optical recording medium, or semiconductor memory.
[0032] Furthermore, this program may be distributed, for example, by selling, transferring, or lending portable recording media such as DVDs or CD-ROMs on which the program is recorded. Alternatively, the program may be stored in the storage device of a server computer and distributed by transferring the program from the server computer to other computers via a network.
[0033] A computer executing such a program may, for example, first store the program recorded on a portable storage medium or a program transferred from a server computer in its own storage device. Then, when processing is to be executed, the computer reads the program stored on its own storage medium and executes the processing according to the read program. Alternatively, the computer may directly read the program from the portable storage medium and execute the processing according to that program, or it may sequentially execute the processing according to the received program each time a program is transferred to it from a server computer. Furthermore, the processing may be executed by a so-called ASP (Application Service Provider) type service, where the processing function is realized only by execution instructions and result acquisition, without transferring the program from the server computer to this computer. Moreover, the processing may be executed using a so-called SaaS (Software as a Service) type service, where a part of the server computer is made available to the user along with the program. In this form, the program includes information used for processing by an electronic computer that is equivalent to a program (data that is not a direct instruction to the computer but has the property of defining the computer's processing).
[0034] Furthermore, in this configuration, the device is configured by executing a predetermined program on a computer, but at least a part of these processes may be implemented in hardware. [Explanation of Symbols]
[0035] 10 Terminal sharing system 100 Terminal sharing devices 110 Information conversion unit 120 Authentication unit 130 Authority setting unit 140 Authentication control unit 150 Department for obtaining scheduled departure times 160 Department for sharing login information 190 Recording Unit 200 Terminal 210 Possession element acquisition unit 220 Knowledge element acquisition unit 230 Logout information acquisition unit 290 Terminal function unit 310 System A 320 System B 400 Data communication networks 900 Telephone networks
Claims
1. A terminal sharing system consisting of terminal sharing devices and terminals, The aforementioned terminal is A unit for acquiring ownership elements that acquires ownership element information from each user's possessions, A knowledge element acquisition unit that acquires knowledge element information for the user identification information of the aforementioned user, Equipped with, The aforementioned terminal sharing device is A recording unit that records ownership element information and knowledge element information in association with user identification information, An information conversion unit converts the ownership element information acquired by the ownership element acquisition unit of the terminal into user identification information for the terminal, If the knowledge element information acquired by the knowledge element acquisition unit of the terminal is knowledge element information associated with the user identification information of the terminal, the authentication unit grants permission to log in to the terminal. Equipped with Terminal sharing system.
2. A terminal sharing system according to claim 1, The aforementioned recording unit also records access information, which is information about the permissions granted to user identification information, in association with the user's identification information. The aforementioned terminal sharing device is If the authentication unit grants permission to log in, the permission setting unit configures the system to allow the use of external systems according to the permission information corresponding to the user identification information of the terminal. It also A terminal sharing system characterized by the following:
3. A terminal sharing system according to claim 1, The aforementioned terminal is Logout Information Acquisition Unit: Acquires logout information, which is information about when the user logs out. It also has, The aforementioned terminal sharing device is The authentication control unit performs logout processing for the terminal at the timing indicated by the logout information. It also has, The authentication unit of the terminal sharing device grants permission to log in to the terminal after obtaining the logout information. A terminal sharing system characterized by the following:
4. A terminal sharing system according to claim 1, The aforementioned terminal sharing device is A departure schedule acquisition unit acquires information on the user's scheduled departure time corresponding to user identification information, and sets the said scheduled departure time as logout information, which is information on when the user logs out. The authentication control unit performs logout processing for the terminal at the timing indicated by the logout information. It also A terminal sharing system characterized by the following:
5. A terminal sharing system according to claim 3 or 4, The authentication control unit shall terminate the logout process if, within a predetermined period after the start of the logout process, the ownership element acquisition unit of the terminal acquires ownership element information from the belongings of the logged-in user, or if the knowledge element acquisition unit of the terminal acquires knowledge element information for the user identification information of the logged-in user. A terminal sharing system characterized by the following:
6. A terminal sharing system according to claim 5, If the authentication control unit cancels the logout process, it will perform the logout process for the terminal at the reset timing. A terminal sharing system characterized by the following:
7. A terminal sharing system according to claim 1, The aforementioned recording unit also records the terminal's phone number, as well as information about the logged-in terminal and the user of that terminal. The aforementioned terminal sharing device is When the authentication unit authorizes login, the login information sharing unit transmits the phone number of the authorized device and the user information of that device to other devices that are logged in, and also transmits the phone numbers and user information of each of the other devices that are logged in to the device that authorized login. It also A terminal sharing system characterized by the following:
8. A terminal sharing system according to claim 7, The login information sharing unit, when any terminal logs out, sends the phone number information of the logged-out terminal to the other terminals that are still logged in. A terminal sharing system characterized by the following:
9. A terminal sharing device for sharing a terminal among multiple users, A recording unit that records ownership element information and knowledge element information in association with user identification information, An information conversion unit converts ownership information acquired by the terminal into user identification information for the terminal, If the knowledge element information acquired by the terminal is knowledge element information associated with the user identification information of the terminal, the authentication unit grants permission to log in to the terminal. A terminal sharing device equipped with the following features.
10. A terminal sharing device according to claim 9, The authentication control unit performs the logout process for the terminal at the timing indicated by the logout information, which is information about the timing of the logout. It also A terminal sharing device characterized by the following features.
11. A terminal sharing device according to claim 10, The authentication control unit shall terminate the logout process if, within a predetermined period after the start of the logout process, the terminal obtains ownership information from the belongings of the logged-in user, or if the terminal obtains knowledge element information for the user identification information of the logged-in user. A terminal sharing device characterized by the following features.
12. A terminal sharing device according to claim 9, The aforementioned recording unit also records the terminal's phone number, as well as information about the logged-in terminal and the user of that terminal. When the authentication unit authorizes login, the login information sharing unit transmits the phone number of the authorized device and the user information of that device to other devices that are logged in, and also transmits the phone numbers and user information of each of the other devices that are logged in to the device that authorized login. It also A terminal sharing device characterized by the following features.
13. A terminal sharing device according to claim 12, The login information sharing unit, when any terminal logs out, sends the phone number information of the logged-out terminal to the other terminals that are still logged in. A terminal sharing device characterized by the following features.
14. A terminal sharing method using a terminal sharing device and terminals, The aforementioned terminal sharing device records ownership element information and knowledge element information in association with user identification information. The aforementioned terminal performs an ownership element acquisition step in which it acquires ownership element information from each user's possessions, The terminal sharing device includes an information conversion step in which the ownership information acquired by the terminal is converted into user identification information for the terminal, The terminal performs a knowledge element acquisition step in which it acquires knowledge element information relating to the user identification information of the user, The terminal sharing device performs an authentication step that grants permission to log in to the terminal if the knowledge element information acquired by the terminal is knowledge element information associated with the user identification information of the terminal. Execute How to share a device.
15. A terminal sharing method according to claim 14, Authentication control step: The terminal sharing device performs a logout process for the terminal at the timing indicated by the logout information, which is information about the timing of logout. We will also execute A terminal sharing method characterized by the following:
16. A terminal sharing method according to claim 15, In the authentication control step, if the terminal obtains ownership information from the logged-in user's possessions, or if the terminal obtains knowledge element information for the logged-in user's user identification information, within a predetermined period after the start of the logout process, the logout process is terminated. A terminal sharing method characterized by the following:
17. A terminal sharing method according to claim 14, The aforementioned terminal sharing device also records the terminal's phone number, as well as information about the logged-in terminal and the user of that terminal. If the terminal sharing device allows login in the authentication step, it sends the phone number of the allowed terminal and the user information of that terminal to other terminals that are logged in, and also sends the phone number and user information of each of the other terminals that are logged in to the terminal that allowed login in the login information sharing step. We will also execute A terminal sharing method characterized by the following:
18. A terminal sharing method according to claim 17, The terminal sharing device performs a logout information sharing step in which, when any terminal logs out, it sends the phone number information of the logged-out terminal to other terminals that are currently logged in. We will also execute A terminal sharing method characterized by the following:
19. A terminal sharing program for causing a computer to function as a terminal sharing device according to any one of claims 9 to 13.