Terminal sharing system, terminal sharing device, terminal sharing method, terminal sharing program
The terminal sharing system addresses the challenge of securing shared terminals by associating ownership and knowledge elements with user IDs, ensuring secure login without manual inputs and enabling single sign-on across systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- 株式会社メドコム
- Filing Date
- 2025-11-26
- Publication Date
- 2026-05-20
AI Technical Summary
Existing technologies fail to provide both enhanced security and convenience when multiple users share a terminal, as they cannot store a specific user's ID, necessitating repeated login inputs.
A terminal sharing system that utilizes an ownership element acquisition unit and a knowledge element acquisition unit to associate ownership and knowledge elements with user identification information, enabling secure login without manual input through a recording unit, information conversion, and authentication unit.
Ensures security by combining ownership and knowledge elements for authentication, while providing convenience by eliminating the need for repeated user identification inputs, and supports single sign-on across multiple systems.
Smart Images

Figure 2026084108000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a terminal sharing system, a terminal sharing device, a terminal sharing method, and a terminal sharing program for sharing a terminal among multiple users.
Background Art
[0002] As prior arts for sharing a terminal among multiple users, Patent Documents 1, 2, etc. are known. Further, as a two-factor authentication system for improving security, Patent Document 3, as a technology related to single sign-on for improving convenience, Patent Document 4, and as an authentication technology using a contactless IC card, Non-Patent Document 1, etc. are known.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Patent Document 2
Patent Document 3
Patent Document 4
Non-Patent Documents
[0004]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, there have been no proposed technologies that can achieve both improved security and convenience in situations where multiple users share a terminal. For example, if a terminal is used exclusively by a specific user, the terminal can store a user ID to identify that user, thus eliminating the need for input. However, a shared terminal cannot store the user ID of a specific user. Therefore, the present invention aims to provide a technology that can achieve both security and convenience in situations where multiple users share a terminal. [Means for solving the problem]
[0006] The terminal sharing system of the present invention consists of a terminal sharing device and a terminal. The terminal includes an ownership element acquisition unit and a knowledge element acquisition unit. The ownership element acquisition unit acquires ownership element information from each user's possessions. The knowledge element acquisition unit acquires knowledge element information for the user's user identification information. The terminal sharing device includes a recording unit, an information conversion unit, and an authentication unit. The recording unit records ownership element information and knowledge element information in association with user identification information. The information conversion unit converts the ownership element information acquired by the terminal's ownership element acquisition unit into the terminal's user identification information. The authentication unit grants login to the terminal if the knowledge element information acquired by the terminal's knowledge element acquisition unit is knowledge element information associated with the terminal's user identification information. [Effects of the Invention]
[0007] According to the terminal sharing system of the present invention, ownership element information is first obtained from the terminal. Then, within the terminal sharing device, the user identification information of the user associated with the ownership element information is set as the user identification information of the terminal user. When knowledge element information associated with the user identification information is obtained from the terminal, login to that terminal is permitted. Security can be ensured because authentication can be performed by combining ownership element information and knowledge element information. In addition, convenience is ensured because the user does not need to enter user identification information. [Brief explanation of the drawing]
[0008] [Figure 1] A diagram showing an example configuration of the terminal sharing system of the present invention. [Figure 2] This diagram shows an example of a processing flow when terminal 200 has a logout information acquisition unit 230. [Figure 3] This diagram shows an example of a processing flow when the terminal sharing device 100 has a clock-out schedule acquisition unit 150. [Figure 4] A diagram showing an example of the processing flow for logout. [Figure 5] A diagram illustrating an example of a computer's functional configuration. [Modes for carrying out the invention]
[0009] The embodiments of the present invention will be described in detail below. Components having the same function will be numbered identically, and redundant explanations will be omitted. [Examples]
[0010] Figure 1 shows an example configuration of the terminal sharing system of the present invention. Figure 2 is an example of a processing flow when terminal 200 has a logout information acquisition unit 230, and Figure 3 is an example of a processing flow when terminal sharing device 100 has a scheduled departure acquisition unit 150. Figure 4 is an example of a processing flow related to logout processing. The terminal sharing system 10 consists of terminal sharing device 100 and terminal 200 connected by a data communication network 400. There are usually multiple terminals 200. However, the present invention can also be used when one terminal 200 is shared by multiple users. Systems A310, B320, etc., that provide functions to terminal 200 are connected to the data communication network 400. Although two systems are shown in Figure 1, there may be three or more. For example, in the case of a system used in a hospital, system A310 could handle patient medical record information, and system B320 could handle drug inventory information, etc. Other systems that handle staff work information are also conceivable.
[0011] Terminal 200 includes an ownership element acquisition unit 210 and a knowledge element acquisition unit 220. Terminal 200 is, for example, a smartphone and also has communication functions, recording functions, input / output functions, etc. These terminal functions are provided as a terminal function unit 290. For example, if it is a smartphone, terminal 200 also has the function of connecting to the telephone network 900. As will be described later, terminal 200 may also include a logout information acquisition unit 230.
[0012] The terminal sharing device 100 includes a recording unit 190, an information conversion unit 110, an authentication unit 120, an authorization setting unit 130, and an authentication control unit 140. If the terminal 200 also has the function of connecting to the telephone network 900, the terminal sharing device 100 may also include a login information sharing unit 160. Furthermore, as will be described later, the terminal sharing device 100 may also include a clock-out schedule acquisition unit 150. The recording unit 190 records ownership element information and knowledge element information in association with at least user identification information.
[0013] The ownership element acquisition unit 210 of terminal 200 acquires ownership element information from each user's possessions (S210). "Personal possessions for each user" include, for example, identification cards and credit cards. IC cards are assumed to be "personal possessions for each user," but cards with two-dimensional barcodes may also be included. "Ownership element information" is information obtained from these possessions. This information may change over time, or it may not change. Terminal 200 transmits the ownership element information, along with terminal identification information (for example, terminal ID, telephone number, etc.) that identifies terminal 200, to the terminal sharing device 100.
[0014] The information conversion unit 110 of the terminal sharing device 100 converts the ownership element information acquired by the ownership element acquisition unit 210 of the terminal 200 into user identification information based on the information in the recording unit 190 (S110). The "user identification information" is information corresponding to a so-called login ID. In general services, it is often possible to log in by entering a login ID and a password (an example of knowledge element information). It is desirable that the "user identification information" be different from the "ownership element information" and be assigned to the user. The obtained user identification information may or may not be transmitted to the terminal 200.
[0015] The knowledge element acquisition unit 220 acquires knowledge element information regarding the user's user identification information (S220). The "knowledge element information" is information known only to the user, such as a password or a PIN number. After the terminal 200 transmits the ownership element information and the terminal identification information to the terminal sharing device 100, it requests the user to input the knowledge element information. The terminal 200 transmits the knowledge element information input by the user together with the terminal identification information to the terminal sharing device 100.
[0016] When the terminal 200 includes a logout information acquisition unit 230, the processing flow shown in FIG. 2 is adopted. The logout information acquisition unit 230 acquires logout information, which is information on the timing of logout (S230). The "logout information" may be the time scheduled for logout (e.g., 17:00) or the time until logout (e.g., 7 hours). For example, the logout information acquisition unit 230 may request the user to input the scheduled time of leaving work on that day. The authentication control unit 140 may set the time when the terminal 200 is scheduled to logout according to the logout information (S141).
[0017] When the terminal sharing device 100 includes a leaving work schedule acquisition unit 150, the processing flow shown in FIG. 3 is adopted. The leaving work schedule acquisition unit 150 acquires information on the leaving work schedule time of the user corresponding to the user identification information (S150), and sets it as logout information, which is information on the timing of logging out, in the authentication control unit 140 (S141). For example, if a system for managing the working hours of staff is connected to the data communication network 400, the leaving work schedule acquisition unit 150 may obtain information on the working hours of the user of the terminal based on the user identification information and acquire the information on the leaving work schedule time. Also, for example, if the number of staff is limited, a schedule table (staff shift table) may be recorded in the terminal sharing device 100, and the information on the leaving work schedule time may be acquired based on the schedule table. In FIG. 3, the acquisition of the leaving work schedule (S150) is performed before the authentication (S120), but it may be performed at any timing as long as it is before the logout process setting (S141).
[0018] The authentication unit 120 permits the terminal 200 to log in when the knowledge element information acquired by the knowledge element acquisition unit of the terminal 200 is the knowledge element information associated with the user identification information of the user of the terminal 200 (S120). When the terminal 200 includes a logout information acquisition unit 230, the authentication unit 120 may permit the terminal 200 to log in after acquiring the logout information. Since the login is permitted based on the ownership element information and the knowledge element information, high-level security can be ensured.
[0019] Also, the recording unit 190 may record the permission information, which is information on the permission for the user identification information, in association therewith. And the terminal sharing device 100 may also include a permission setting unit 130. When the authentication unit 120 permits the login, the permission setting unit 130 sets so that an external system (for example, system A310, system B320, etc.) can be used according to the permission information corresponding to the user identification information of the terminal 200 (S130). In this way, if the use of a plurality of systems can be set by the authentication unit 120 permitting the login, so-called single sign-on can be realized. Therefore, convenience can be ensured.
[0020] Furthermore, if terminal 200 has the function of connecting to the telephone network 900, the recording unit 190 may also record the terminal's telephone number and information about the logged-in terminal and its user. For example, if a terminal ID different from the telephone number is used as information to identify the terminal, the recording unit 190 will record the terminal IDs and telephone numbers of all terminals 200 that are subject to sharing. The recording unit 190 may also record the logged-in terminal ID and information about the user of that terminal. Recording in this way allows the telephone number of the logged-in terminal to be associated with the user. The terminal sharing device 100 may also include a login information sharing unit 160. When the authentication unit 120 permits login, the login information sharing unit 160 sends the telephone number of the permitted terminal 200 and information about the user of that terminal to the other logged-in terminals 200 (S160). The login information sharing unit 160 also sends the telephone number and user information of each of the other logged-in terminals 200 to the terminal 200 that permitted login (S160).
[0021] Other terminals 200 that are logged in add the received phone number and user information to their phonebook (S291). Also, terminal 200 that is authorized to log in sets the phone number and user information of other logged-in terminals 200 as phonebook information (S295). Phone numbers are fixed to each individual terminal. However, in the case of shared terminals, who is using which phone number terminal changes. By providing a login information sharing unit 160, even when terminals are shared, it is possible to call the person you want to call.
[0022] According to the terminal sharing system 10, ownership element information is first obtained from terminal 200. Then, internally within the terminal sharing device 100, the user identification information of the user associated with that ownership element information is set as the user identification information of the user on terminal 200. When the knowledge element information associated with the user identification information is obtained from terminal 200, login to terminal 200 is permitted. Security can be ensured because authentication can be performed by combining ownership element information and knowledge element information. In addition, convenience is ensured because the user does not need to enter user identification information.
[0023] Next, let's explain logout. In principle, users should log out themselves. However, if a user forgets to log out, another user may impersonate the previous user. Therefore, the terminal sharing system 10 should be equipped with a logout processing function (see Figure 4). The authentication control unit 140 starts the logout process at the scheduled logout time set as logout information (S141) (S142). The authentication control unit 140 notifies terminal 200 that the logout process has started.
[0024] Terminal 200 prompts the user to input ownership element information or knowledge element information. Terminal 200 may request both ownership element information and knowledge element information from the user, request either one, or specify which one to request. If the user wishes to continue using Terminal 200, the ownership element acquisition unit 210 of Terminal 200 acquires ownership element information from the owner of the logged-in user. Alternatively, the knowledge element acquisition unit 220 of Terminal 200 acquires knowledge element information for the user identification information of the logged-in user. Terminal 200 transmits the acquired ownership element information or knowledge element information and terminal identification information to the terminal sharing device 100.
[0025] If the authentication control unit 140 obtains ownership element information from the logged-in user's belongings or obtains knowledge element information for the logged-in user's user identification information within a predetermined period after the start of the logout process (S121, Yes), it cancels the logout process (S144). The authentication control unit 140 resets the new logout timing (the scheduled time for logout) (S145). The new scheduled time for logout may be set by the user via the terminal 200, or it may be set after a predetermined time (for example, after 1 hour).
[0026] If step S121 is No, the authentication control unit 140 logs out terminal 200 (S143). When terminal 200 logs out, the login information sharing unit 160 sends the phone number information of the logged-out terminal 200 to the other logged-in terminals 200 (S161). The other logged-in terminals 200 delete the phone number information of the logged-out terminal 200 from their phonebook information (S292). Also, all information registered in the phonebook of the logged-out terminal 200 is deleted (S296). Through these processes, when a terminal 200 shared by multiple users logs out, the information can be deleted. In addition, since the logout process is performed using the logout schedule, impersonation can be prevented even if the user forgets to log out.
[0027] [Processor, program, recording medium] The functions realized by the components described herein may be implemented in a circuitry or processing circuitry, including general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), CPUs (a Central Processing Unit), conventional circuits, and / or combinations thereof, programmed to realize the functions described herein. A processor includes transistors and other circuits and is considered a circuitry or processing circuitry. A processor may be a programmed processor that executes a program stored in memory.
[0028] In this specification, circuitry, unit, and means are hardware programmed to perform or execute the functions described herein. Such hardware may be any hardware disclosed herein, or any hardware known to be programmed to perform or execute the functions described herein.
[0029] If the hardware is a processor that is considered to be a type of circuitry, then the circuitry, means, or unit is a combination of hardware and software used to constitute the hardware and / or processor.
[0030] The various processes described above can be carried out by loading a program that executes each step of the above method into the recording unit 2020 of the computer 2000 shown in Figure 5, and then causing the control unit 2010, input unit 2030, output unit 2040, display unit 2050, etc. to operate.
[0031] The program describing this process can be recorded on a computer-readable recording medium. Any computer-readable recording medium can be used, such as a magnetic recording device, optical disc, magneto-optical recording medium, or semiconductor memory.
[0032] Furthermore, this program may be distributed, for example, by selling, transferring, or lending portable recording media such as DVDs or CD-ROMs on which the program is recorded. Alternatively, the program may be stored in the storage device of a server computer and distributed by transferring the program from the server computer to other computers via a network.
[0033] A computer executing such a program may, for example, first store the program recorded on a portable storage medium or a program transferred from a server computer in its own storage device. Then, when processing is to be executed, the computer reads the program stored on its own storage medium and executes the processing according to the read program. Alternatively, the computer may directly read the program from the portable storage medium and execute the processing according to that program, or it may sequentially execute the processing according to the received program each time a program is transferred to it from a server computer. Furthermore, the processing may be executed by a so-called ASP (Application Service Provider) type service, where the processing function is realized only by execution instructions and result acquisition, without transferring the program from the server computer to this computer. Furthermore, the processing may be executed using a so-called SaaS (Software as a Service) type service, where a part of the server computer is made available to the user along with the program. In this form, the program includes information used for processing by an electronic computer that is equivalent to a program (data that is not a direct instruction to the computer but has the property of defining the computer's processing).
[0034] Furthermore, in this configuration, the device is configured by executing a predetermined program on a computer, but at least a part of these processes may be implemented in hardware. [Explanation of Symbols]
[0035] 10 Terminal sharing system 100 Terminal sharing devices 110 Information conversion unit 120 Authentication unit 130 Authority setting unit 140 Authentication control unit 150 Department for obtaining scheduled departure times 160 Department for sharing login information 190 Recording Unit 200 Terminal 210 Possession element acquisition unit 220 Knowledge element acquisition unit 230 Logout information acquisition unit 290 Terminal function unit 310 System A 320 System B 400 Data communication networks 900 Telephone networks
Claims
1. A terminal sharing system consisting of a terminal sharing device and terminals, for sharing terminals among multiple users, The aforementioned terminal is A unit for acquiring ownership elements that acquires ownership element information from each user's possessions, A logout information acquisition unit that acquires logout information, which is information about when a user logs out. Equipped with, The aforementioned terminal sharing device is A recording unit records user identification information and ownership information in association, as well as the terminal's phone number and information about the logged-in terminal and the user of that terminal. An information conversion unit converts the ownership element information acquired by the ownership element acquisition unit of the terminal into user identification information for the terminal, An authentication unit that grants permission to log in to the aforementioned terminal, The authentication control unit performs logout processing for the terminal at the timing indicated by the logout information. Equipped with, The authentication unit of the terminal sharing device grants permission to log in to the terminal after obtaining the logout information. Terminal sharing system.
2. A terminal sharing system consisting of a terminal sharing device and terminals, for sharing terminals among multiple users, The aforementioned terminal is A knowledge element acquisition unit that acquires user identification information and knowledge element information of the aforementioned user, A logout information acquisition unit that acquires logout information, which is information about when a user logs out. Equipped with, The aforementioned terminal sharing device is A recording unit records user identification information and knowledge element information in association, as well as the terminal's phone number and information about the logged-in terminal and the user of that terminal. An authentication unit grants permission to log in to the terminal when the user identification information and knowledge element information acquired by the terminal are associated with each other. The authentication control unit performs logout processing for the terminal at the timing indicated by the logout information. Equipped with, The authentication unit of the terminal sharing device grants permission to log in to the terminal after obtaining the logout information. Terminal sharing system.
3. A terminal sharing device for sharing a terminal among multiple users, A recording unit records user identification information and ownership information in association, as well as the terminal's phone number and information about the logged-in terminal and the user of that terminal. An information conversion unit converts ownership information acquired by the terminal into user identification information for the terminal, The authentication unit that authorizes login to the terminal, The authentication control unit performs logout processing for the terminal at the timing indicated by the logout information, which is information about the timing of logout. Equipped with, The authentication unit grants permission to log in to the terminal after obtaining the logout information. Terminal sharing device.
4. A terminal sharing device according to claim 3, The authentication control unit shall terminate the logout process if, within a predetermined period after the start of the logout process, the terminal obtains ownership information from the user's belongings while logged in. A terminal sharing device characterized by the following features.
5. A terminal sharing device for sharing a terminal among multiple users, A recording unit records user identification information and knowledge element information in association, as well as the terminal's phone number and information about the logged-in terminal and the user of that terminal. An authentication unit grants permission to log in to the terminal when the user identification information and knowledge element information acquired by the terminal are associated with each other. The authentication control unit performs logout processing for the terminal at the timing indicated by the logout information, which is information about the timing of logout. Equipped with, The authentication unit grants permission to log in to the terminal after obtaining the logout information. Terminal sharing device.
6. A terminal sharing device according to claim 5, If the authentication control unit obtains knowledge element information for the user identification information of the logged-in user within a predetermined period after the start of the logout process, it shall cancel the logout process. A terminal sharing device characterized by the following features.
7. A terminal sharing device according to claim 4 or 6, If the authentication control unit cancels the logout process, it will perform the logout process for the terminal at the reset timing. A terminal sharing device characterized by the following features.
8. A terminal sharing method for multiple users to share a terminal, using a terminal sharing device and a terminal, The aforementioned terminal sharing device records user identification information and ownership information in association, as well as the terminal's phone number and information about the logged-in terminal and the user of that terminal. The aforementioned terminal performs an ownership element acquisition step in which it acquires ownership element information from each user's possessions, The terminal sharing device includes an information conversion step in which the ownership information acquired by the terminal is converted into user identification information for the terminal, The terminal sharing device performs an authentication step that allows the terminal to log in, Authentication control step: The terminal sharing device performs a logout process for the terminal at the timing indicated by the logout information, which is information about the timing of logout. It has, The authentication step grants permission to log in to the terminal after obtaining the logout information. How to share a device.
9. A terminal sharing method for multiple users to share a terminal, using a terminal sharing device and a terminal, The aforementioned terminal sharing device records user identification information and knowledge element information in association, as well as the terminal's telephone number and information about the logged-in terminal and the user of that terminal. The terminal performs a knowledge element acquisition step in which it acquires the user identification information and knowledge element information, The terminal sharing device performs an authentication step that grants login to the terminal when the user identification information and knowledge element information acquired by the terminal are associated with each other. Authentication control step: The terminal sharing device performs a logout process for the terminal at the timing indicated by the logout information, which is information about the timing of logout. It has, The authentication step grants permission to log in to the terminal after obtaining the logout information. How to share a device.
10. A terminal sharing program for causing a computer to function as a terminal sharing device according to any one of claims 3 to 6.