Authentication system, information processing device, and information processing method
The authentication system addresses the inefficiencies and security risks of existing methods by implementing two-factor authentication with unique codes and expiration times, ensuring secure and efficient entry and exit management for visitors.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
- Filing Date
- 2024-11-20
- Publication Date
- 2026-06-01
AI Technical Summary
Existing methods for entrance authentication are time-consuming, labor-intensive, and insecure, particularly for temporary visitors, as they often require manual verification or biometric registration, and pre-issued codes can be lost or copied, compromising security.
An authentication system that performs two-factor authentication using a first code stored in a visitor's terminal and a second code issued on-site, issuing an entry pass with a third code for successful entry, and allowing entry only if both authentications succeed, with unique codes for each visitor and expiration times to enhance security.
This system enables secure and simple access authentication by reducing staff workload and visitor stress, preventing unauthorized entry, and managing entry and exit efficiently, even in emergencies.
Smart Images

Figure 2026089308000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an authentication system, an information processing apparatus, and an information processing method.
Background Art
[0002] When entering a company or a facility such as a specific security area, it is common to perform personal authentication. For example, methods of authentication such as confirmation by a security guard, pre-issuance of an entrance code, or biometric authentication using face and fingerprint are known.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, there is room for study on a method for performing entrance authentication in a secure and simple manner.
[0005] The non-limiting embodiments of the present disclosure contribute to providing an authentication system, an information processing apparatus, and an information processing method capable of performing entrance authentication in a secure and simple manner.
Means for Solving the Problems
[0006] An authentication system according to one embodiment of the present disclosure comprises: a terminal used by a visitor to a facility; an information processing device that performs a first authentication on the visitor using a first code stored in the terminal and a second code issued to the visitor when the visitor visits the facility based on the first code, issues an entry pass including a third code if the first authentication is successful, performs a second authentication using the third code to permit entry to the facility, and permits the visitor to enter the facility if the second authentication is successful.
[0007] These comprehensive or specific embodiments may be implemented as systems, devices, methods, integrated circuits, computer programs, or recording media, or as any combination of systems, devices, methods, integrated circuits, computer programs, and recording media. [Effects of the Invention]
[0008] Non-limiting embodiments of this disclosure enable secure and simple access authentication.
[0009] Further advantages and effects of one embodiment of this disclosure will be made apparent from the specification and drawings. Such advantages and / or effects are provided by several embodiments and features described in the specification and drawings, but not all of them are necessarily provided in order to obtain one or more identical features. [Brief explanation of the drawing]
[0010] [Figure 1] Block diagram showing an example configuration of the entrance reception system. [Figure 2] Sequence diagram showing an example of the admission reception process. [Figure 3] Sequence diagram showing an example of the admission reception process. [Figure 4] Sequence diagram showing an example of the admission reception process. [Figure 5] Sequence diagram showing an example of the admission reception process. [Modes for carrying out the invention]
[0011] Preferred embodiments of this disclosure will be described in detail below with reference to the attached drawings. In this specification and the drawings, components having substantially the same function are denoted by the same reference numerals, and redundant descriptions will be omitted.
[0012] In facilities such as offices and schools, there is a need to authenticate whether a person attempting to enter (e.g., a visitor) is authorized to enter (e.g., through identity verification).
[0013] For example, if we consider a visitor making a temporary visit to a facility from outside, verification (authentication) by security personnel requires verification between the security officer and the person in charge at the facility each time the visitor arrives. While this is a reliable method of authentication, it is time-consuming, labor-intensive, and requires significant manpower. Similarly, while biometric authentication provides reliable verification, it is difficult to register and manage the visitor's biometric information in advance for temporary visits.
[0014] Therefore, in recent years, a system has been proposed in which an entry code (also called an authentication code) is issued in advance by the person in charge at the visited location, and the visitor uses the entry code on the day of the visit to authenticate the identity of the person being authenticated (for example, called an "entry reception system" or "entry authentication system").
[0015] Furthermore, in Patent Document 1, visitor information (e.g., name of organization, name) is pre-registered in the entrance reception system by the person in charge at the visited location, and the entrance reception system determines and notifies the visitor in advance of the cipher code to be entered by the visitor upon arrival. When the visitor enters the visitor information (e.g., name of organization, name) along with the pre-notified cipher code into the entrance reception system upon arrival, the entrance reception system grants entry if both the visitor information and the cipher code match. This enables reliable authentication of the visitor's identity.
[0016] In Patent Document 2, visitor information is pre-registered in the entrance reception system, and the entrance reception system notifies the visitor of the reception number in advance. When the visitor inputs the reception number to the entrance reception system, if the reception number matches the visiting place or the scheduled visiting time, etc., the entrance reception system issues a printed medium that can be used as an entrance permit including authentication information such as a two-dimensional code, and allows the visitor to enter the building by having the entrance permit read at the entrance gate. This enables reliable authentication of the visitor.
[0017] However, in the example of Patent Document 1, both the person in charge of the visiting destination and the visitor need to input visitor information for entrance authentication, which is time-consuming. Also, in the examples of Patent Documents 1 and 2, if the visitor loses the authentication code (e.g., password or reception number), there is a possibility of allowing a third party to enter the building, making secure authentication difficult.
[0018] Therefore, in each non-limiting embodiment of the present disclosure, a method for performing entrance authentication by a secure and simple method will be described.
[0019] For example, in one non-limiting embodiment of the present disclosure, the entrance reception system performs two-factor authentication when issuing an entrance permit to a visitor. For example, when the entrance reception system passes the first-stage authentication confirmation (e.g., authentication by an authentication code), it issues an entrance permit with an authentication code such as a two-dimensional code (e.g., QR code (registered trademark)) for the second-stage authentication (e.g., authentication by the entrance permit), and prints the floor of the visiting destination or the time requested for completion of entry, etc., and lets the visitor carry it. Here, the authentication code issued by the entrance reception system may be a unique code, and the same code does not have to be issued. Also, the entrance reception system performs exit management by having the visitor present the entrance permit carried at the time of exit.
[0020] Thereby, in one non-limiting embodiment of the present disclosure, it is possible to perform secure entrance and exit authentication while saving the labor of the person in charge of the visiting destination and reducing the stress of the visitor at the time of entry.
[0021] Hereinafter, non-limiting embodiments of the present disclosure will be described.
[0022] (Embodiment 1) <Example of System Configuration> FIG. 1 is a diagram showing an example of an entrance reception system (also referred to as an entrance authentication system or an entrance / exit authentication system, corresponding to the authentication system) according to the present embodiment. The entrance reception system 1 shown in FIG. 1 may include a reception device 10 (corresponding to, for example, an information processing device), a display / reading unit 20, an output unit 30, an entrance / exit gate 40, and a terminal 50. Each part included in the entrance reception system 1 may be directly connected by wire or wirelessly, or may be connected via a network such as the Internet.
[0023] The reception device 10 may perform the entrance reception process for visitors and control the display / reading unit 20, the output unit 30, and the entrance / exit gate 40. Further, the reception device 10 may communicate with, for example, the terminal 50 used by the visitor. For example, the reception device 10 may be a server that executes various applications for communicating with the terminal 50, reading the authentication code and displaying it on the display / reading unit 20, outputting (for example, printing) the content based on the reading result of the authentication code to the output unit 30, or controlling the entrance / exit gate 40. The reception device 10 may be installed in the facility, for example, or may not be installed.
[0024] The reception device 10 has, for example, a communication unit 11 and a control unit 12.
[0025] The communication unit 11 may communicate, for example, between the reception device 10 and the terminal 50. Further, the communication unit 11 may communicate, for example, between the reception device 10 and a terminal (not shown) operated by the person in charge of the visited place. The communication in the communication unit 11 may be, for example, cellular communication, wireless LAN communication (WiFi (registered trademark) communication) connectable to the Internet, LPWA (Low Power Wide Area) communication, or Bluetooth (registered trademark) communication, or other communication methods.
[0026] The control unit 12 controls the entrance reception process in the entrance reception system 1 (for example, including entrance management and exit management) using, for example, at least one of the information input from the communication unit 11 and the information input from the display / reading unit 20.
[0027] The control unit 12 may include, for example, an issuance control unit 121 that controls the issuance of an entry pass (for example, the first stage of two-factor authentication) and an entry control unit 122 that controls the entry of visitors (for example, the second stage of two-factor authentication). The issuance control unit 121 uses, for example, an authentication code (for example, corresponding to a first code) stored in a terminal 50 used by the facility visitor and a simplified code (for example, corresponding to a second code) issued to the visitor when they visit the facility based on the said authentication code to perform the first stage of authentication (for example, corresponding to the first authentication) for the visitor to the facility, and if authentication is successful, it issues an entry pass that includes a second stage authentication code (for example, corresponding to a third code). The entry control unit 122 uses, for example, the authentication code (for example, corresponding to a third code) included in the entry pass to perform the second stage of authentication (for example, the second authentication) to allow entry to the facility, and if authentication is successful, it allows the visitor to enter the facility (for example, unlocks the entry / exit gate 40).
[0028] The display / reading unit 20 displays information to be presented to the person to be authenticated (e.g., a visitor) in accordance with the control of the reception device 10. The display / reading unit 20 also reads information displayed on a terminal 50 used by the person to be authenticated (e.g., a visitor) and outputs it to the reception device 10. The display / reading unit 20 may be, for example, a display and a camera (or a code reader).
[0029] The output unit 30 performs output processing, such as printing an entry pass (including, for example, an authentication code and visitor information (such as the floor number or the time of entry completion request)) in accordance with the control of the reception device 10. The output unit 30 may be, for example, a printer.
[0030] The entrance / exit gate 40 performs gate opening and closing operations (e.g., unlocking or locking) according to the control of the reception device 10 (e.g., permission or denial of unlocking based on the authentication result of the entry pass). The entrance / exit gate 40 may be configured as an integrated entrance gate and an exit gate, or as separate gates, depending on the usage scenario.
[0031] The display / reading unit 20, the output unit 30, and the entrance / exit gate 40 may be installed, for example, at the entrance of the facility.
[0032] Terminal 50 is a device used (operated) by the visitor, and may be, for example, a smartphone, tablet, or PC (personal computer). Terminal 50 may be used, for example, to display an authentication code (for example, a first authentication code) that has been sent in advance when the visitor arrives, and to confirm a code (for example, a simple code) that is sent from the reception device 10 after authentication (recognition) using the authentication code.
[0033] Note that the entrance reception system 1 may include device configurations not shown in Figure 1, and the device configurations shown in Figure 1 may be excluded from the entrance reception system 1. For example, the entrance reception system 1 may include a storage unit (not shown) that stores information related to the reception process of visitors. Also, for example, at least one of the display function and reading function of the display / reading unit 20 may be excluded from the entrance reception system 1, and the terminal 50 may instead be provided with at least one of the display function and reading function.
[0034] Furthermore, some of the device configurations shown in Figure 1 may be integrated with other device configurations. For example, the display / reading unit 20 and the output unit 30 may be a single device. Alternatively, the component that performs the reading process for the display / reading unit 20 may be provided in the entrance / exit gate 40. Also, some of the functions of the device configurations shown in Figure 1 may be omitted or included in other devices.
[0035] <Example of the operation of the admission reception system> Next, we will explain an example of the operation of the admission reception system 1.
[0036] Figure 2 is a sequence diagram showing an example of the operation of the entrance reception system 1. In the example in Figure 2, the operation of the entrance reception system 1 to authenticate the visitor's entry when the visitor arrives at the facility (for example, a building) where the person they are visiting is located is explained.
[0037] In Figure 2, for example, when scheduling a meeting or other visit is arranged between a visitor and the person in charge at the visited location, the entrance reception system 1 registers account information linked to the visitor based on input by the person in charge at the visited location (S1). The visitor's account information may be, for example, an email address, or other information.
[0038] The entrance reception system 1 (for example, the reception device 10) issues an authentication code (for example, the first authentication code of a two-factor authentication system) to the visitor based on their registered account information (S2). The authentication code may be, for example, a QR code (registered trademark), or any other type of code.
[0039] The entrance reception system 1 then sends the issued authentication code to the account indicated in the corresponding account information, and the visitor obtains the authentication code to use during their visit. For example, the entrance reception system 1 may also send information indicating a URL for the visitor to obtain the authentication code to the visitor's account (S3). Furthermore, the entrance reception system 1 may individually issue a password (issuance password) for the visitor to obtain the authentication code and send it separately to the visitor's account (S4). This enables secure operation of the issuance and delivery of authentication codes. Note that the method of sending the authentication code is not limited to the method shown in Figure 1, and other methods of sending are also possible. For example, the authentication code may be sent by the person in charge at the visited location.
[0040] When a visitor enters the facility, they present the authentication code sent to them in advance to the entrance reception system 1 (for example, the display / reading unit 20) (S5).
[0041] When the entrance reception system 1 detects an authentication code, it sends a simple code to the visitor's account associated with the detected authentication code (S6). The simple code may be, for example, a code equivalent to a one-time password, or any other code. At this time, the entrance reception system 1 (for example, the display / reading unit 20) may display a message prompting the visitor to enter the simple code, such as "A simple code has been sent, please enter the simple code."
[0042] Alternatively, the entrance reception system 1 may provide visitors with a reference number (for example, information identifying visitors who have come to the facility (visitors waiting to enter)) along with the authentication code in advance (not shown). The entrance reception system 1 does not need to perform entry authentication using the authentication code after the visitor presents the authentication code (for example, after detecting the visitor's authentication code) until it is the visitor's turn. For example, when the entrance reception system 1 permits (approves) the entry authentication process for each visitor, it may display the reference number associated with the visitor on a separate display screen in a different location (for example, a waiting room) from the entrance reception system 1 (for example, the entrance / exit gate 40). After presenting the authentication code to the entrance reception system 1, the visitor may wait until their reference number is displayed (approved) on a separate display screen installed in a different location (for example, a waiting room) from the entrance reception system 1 (for example, the entrance / exit gate 40), and after confirming that the reference number is displayed, present the authentication code to the entrance reception system 1 again. This makes it possible to avoid congestion at the entrance reception system 1 during peak hours or at facilities with many visitors.
[0043] In Figure 2, the visitor enters a simple code issued by the entrance reception system 1 into the entrance reception system 1 (S7). When the simple code is entered, the entrance reception system 1 performs authentication processing, such as verifying the authentication code or verifying the consistency between the authentication code and the simple code. If authentication is successful (authentication OK), it issues an entry pass containing an authentication code (for example, the second authentication code of two-factor authentication) that allows entry to the destination within the facility (for example, the room or meeting room of the person in charge at the destination) (S8). On the other hand, if authentication fails (authentication NG), the entrance reception system 1 may perform output processing (for example, screen output, audio or sound output) to notify the visitor that authentication has failed (not shown).
[0044] The entry pass may be, for example, a QR code (registered trademark), or any other type of code. The entry reception system 1 (for example, output unit 30) may print the entry pass. In addition to the authentication code, the entry pass may also include information about the visit. Information about the visit may include at least one of the following: the date and time the visitor actually visited (for example, the date and time the authentication code was received), the scheduled date and time of visit, the validity period of the entry pass (authentication code) (for example, the validity period of the entry pass), information about the destination (for example, the name of the destination, the contact person at the destination (name of the person in charge, phone number), the floor number of the destination), the visitor's account information, the visitor's name, and notes (for example, that the entry pass will become invalid if not entered within the validity period of the authentication code, that it becomes valid from a certain number of minutes before the scheduled visit time, advance notices such as when there is an evacuation drill, etc.). Note that the information about the visit is not limited to this information and may include other information. The visitor may carry the printed entry pass in a name tag holder permanently installed in the facility.
[0045] The visitor pass may not be printed, but instead sent to the account linked to the visitor. The visitor may, for example, display the visitor pass on the screen of terminal 50 and present it to the visitor reception system 1.
[0046] Furthermore, the codes issued by the admission reception system 1 (for example, at least one of the first-stage authentication code, the second-stage authentication code, and the simplified code) may be different for each visitor to the facility and different for each visitor to the facility (for example, called a unique code).
[0047] The visitor presents their entry pass at the entrance / exit gate 40 (S9). When the entry reception system 1 detects the entry pass (authentication code), it performs authentication processing such as verifying the authentication code. If authentication is successful (authentication OK), it allows the visitor to enter the facility and unlocks the entrance / exit gate 40 (S10). The entry reception system 1 may also configure the system so that, if authentication with the entry pass is successful, the visitor can pass through other gates within the facility related to the visitor (for example, gates along the route to their destination) in addition to the entrance / exit gate 40. This allows the visitor to enter the facility (pass through the entrance / exit gate 40) and move to a designated location within the facility (for example, a designated floor) by presenting their entry pass.
[0048] Furthermore, if the entrance reception system 1 (for example, the reception device 10) successfully authenticates the visitor using the visitor ID card, it may also notify the person in charge at the destination that the visitor (for example, a customer) has visited the facility (for example, by sending a visitor message) (automatic notification) (S11).
[0049] Furthermore, if the admission reception system 1 (for example, the reception device 10) successfully authenticates the visitor using the visitor pass, it invalidates the authentication code (the first-stage authentication code for entering the facility) associated with the visitor pass (or visitor) (S12). The admission reception system 1 may also register that the visitor has entered the facility (for example, update the admission management) (S13).
[0050] On the other hand, if the entry authentication fails (in the case of authentication failure), the entry reception system 1 may perform output processing (e.g., screen output, audio or sound output) to notify the visitor or facility manager that authentication has failed (not shown).
[0051] The visitor moves to a designated location within the facility, and after completing a meeting with, for example, the person they are visiting, they move to the facility's entrance (for example, the entrance / exit gate 40). The visitor then presents their visitor pass at the entrance / exit gate 40 (S14). If the entrance reception system 1 detects the visitor pass (authentication code), it performs authentication processing such as verifying the authentication code, and if authentication is successful (authentication OK), it unlocks the entrance / exit gate 40 (S15). The visitor may, for example, return the name tag holder containing their visitor pass. With this, the visitor leaves the facility.
[0052] Furthermore, if the entrance reception system 1 (for example, the reception device 10) successfully authenticates the exit using the entrance pass (second-stage authentication code), it may invalidate the entrance pass and register that the visitor has left the facility (for example, update the exit management) (S16).
[0053] On the other hand, if the entry reception system 1 fails to authenticate the exit (in the case of authentication failure), it may perform output processing (e.g., screen output, audio or sound output) to notify the visitor or facility manager that authentication has failed (not shown).
[0054] The above describes an example of the operation of the admission reception system 1.
[0055] In this way, the admission reception system 1 processes everything from issuing an authentication code to the visitor before their visit to issuing an admission pass upon their visit, based on the registration of the visitor's account information. Therefore, the person in charge at the visiting facility only needs to register the visitor's account information, with whom they have made prior contact, in the admission reception system 1 for the authentication of the visitor entering the facility. Thus, according to this embodiment, admission reception processing can be done in a simple manner, saving the person in charge at the visiting facility time and effort.
[0056] Furthermore, in this embodiment, the entrance reception system 1 performs authentication (first-stage authentication) of visitors to the facility using an authentication code stored in the terminal 50 used by the visitor and a simple code issued to the visitor upon arrival at the facility based on the authentication code. If authentication is successful, an entrance pass is issued. Therefore, visitors can obtain an entrance pass by presenting the authentication code sent in advance and entering the simple code sent to the terminal 50 in response to the presentation of the authentication code. Thus, in this embodiment, entrance reception processing can be carried out in a simple manner without the need for the visiting facility's staff to register visitor information (e.g., organization name, name, etc.) and the visitor to input visitor information, as in Patent Document 1. In addition, in this embodiment, visitors only need to enter the simple code issued upon arrival into the entrance reception system 1, eliminating the need for visitors to individually prepare or search for a pre-sent PIN, as in Patent Document 1. Therefore, this embodiment reduces the workload for the visiting facility's staff and reduces stress for visitors during entry.
[0057] Furthermore, in cases where an entry pass is issued to a visitor using a registration number sent in advance, as in Patent Document 2, there is a risk of a third party issuing an entry pass due to the loss or copying of the registration number. In contrast, according to this embodiment, the entry reception system 1 performs authentication for issuing an entry pass using an authentication code and a simple code issued on the spot at the time of visit. As a result, even if the authentication code is known to a third party, the simple code issued at the time of visit is sent to the visitor's account, making it difficult for a third party to issue an entry pass, thus enabling secure authentication processing for visitors. In addition, in this embodiment, after issuing an entry pass, the entry reception system 1 invalidates the corresponding authentication code (first-stage authentication code), thus avoiding the risk of a third party issuing an entry pass using that authentication code.
[0058] Furthermore, the entrance reception system 1 issues an entry pass to the visitor on the spot if the first stage of authentication is successful. This eliminates the risk of loss of the entry pass or issuance to a third party through a copy, as the entry pass is not issued in advance of the visit, thus enabling secure authentication for visitors.
[0059] Furthermore, the authentication code (or simplified code) issued by the entrance reception system 1 is unique, and no duplicate codes will be issued. This prevents the use of the same code between different visitors or between different visits (for example, preventing the use of duplicate keys).
[0060] Furthermore, the admission reception system 1 prints on the issued admission pass not only an authentication code for passing through the gate (second-stage authentication code), but also information about the visitor's destination (e.g., the floor number of the destination). This allows visitors to enter the facility and proceed to their destination without stress. In addition, since visitors carry the admission pass with their destination information printed on it in their name tag holder, the admission pass can also serve as a visitor's ID card.
[0061] Furthermore, when a visitor leaves the facility, the admission reception system 1 performs authentication (e.g., a third authentication) to allow the visitor to leave the facility upon presentation of their admission pass. If authentication is successful, the system invalidates the admission pass and manages the visitor's departure. Thus, according to this embodiment, visitor departure management can be carried out with consideration not only at the time of entry but also at the time of exit. For example, it is possible to know whether a visitor remains inside the facility without leaving. In addition, in this embodiment, when a visitor leaves the facility, they can exit by presenting their admission pass, which they carry in their name tag holder, to the admission reception system 1. Therefore, for example, there is no need to prepare information equivalent to the authentication code used at the time of entry when leaving, and visitors can exit by presenting their admission pass carried in their name tag holder or an admission pass sent to an account linked to the visitor, so visitors can exit without the trouble of searching for their admission pass.
[0062] Based on the above, according to this embodiment, the entrance reception system 1 can perform entrance authentication in a secure and simple manner. Furthermore, it can perform secure entrance and exit authentication while reducing the workload of the person in charge at the visited location and reducing stress for visitors upon entry.
[0063] [Variations of Embodiment 1] In this embodiment, an example of authentication using a simple code has been described, but the system is not limited to this. Figure 3 is a sequence diagram showing another example of operation of the entrance reception system 1. In the example in Figure 3, the entrance reception system 1 may perform processes S17 and S18 instead of processes S6 and S7 (processing related to the simple code) shown in Figure 2.
[0064] For example, if the entrance reception system 1 (e.g., reception device 10) detects the authentication code presented by the visitor in S5, it notifies the person in charge at the visited location (automatically) that the visitor (e.g., customer) has visited the facility (e.g., by sending a visitor message) (S17).
[0065] When the person in charge at the destination receives a notification of the visitor's arrival from the entrance reception system 1, they approve the visit (S18). Approval of the visit may also be performed, for example, by the person in charge at the destination pressing the approval button on the approval screen displayed by the entrance reception system 1. If the entrance reception system 1 detects approval by the person in charge at the destination, it may determine that authentication was successful (authentication OK) as in Figure 2 and issue an entry pass (S8).
[0066] Furthermore, the recipient of the visitor notification (e.g., visitor message) from the entrance reception system 1 is not limited to the person in charge at the visited location; it may also be, for example, another person or group related to the person in charge at the visited location. In this case, the person in charge at the visited location or any related person who sees the visitor message may approve the visit.
[0067] Furthermore, when the entrance reception system 1 notifies the visitor of the visitor message in S17, it may display or output to the visitor that the message is "awaiting approval" until the visitor's approval is received.
[0068] (Embodiment 2) This embodiment describes a case where a time limit is set for the second stage of two-factor authentication (for example, authentication using an access card).
[0069] Figure 4 is a sequence diagram showing an example of operation of the admission reception system 1 according to this embodiment. In the example in Figure 4, the same reference numerals are used for processes similar to those in Figure 2 or Figure 3, and their descriptions are omitted.
[0070] The admission reception system 1 issues an admission pass to a visitor if authentication using an authentication code (and a simplified code) is successful (S21). When issuing the admission pass, the admission reception system 1 also sets the period during which entry to the facility is permitted using the admission pass (for example, the validity period of the admission pass) (S21).
[0071] The admission reception system 1 invalidates an admission pass if, for example, the visitor does not enter even after the time limit has passed (for example, if authentication using the admission pass is unsuccessful) (S22). If the admission pass is invalidated, even if the visitor presents the admission pass to the admission reception system 1 (S23), the admission reception system 1 determines that authentication using the admission pass (second-stage authentication code) has failed (authentication NG) (S24).
[0072] Furthermore, the time limit (validity period) of the entry pass may be, for example, the time limit from the time the entry pass is issued until the visitor completes their entry (for example, successful authentication using the entry pass). Also, the start time of the time limit is not limited to the time the entry pass is issued, but may be at other times. For example, the start time of the time limit may be the visitor's scheduled arrival time, or a specified time before the scheduled arrival time.
[0073] Furthermore, regarding the time limit setting, it is desirable to set it to a short period of time that would prevent a visitor from losing their entry pass and allowing a malicious third party to obtain it and enter the building. For example, the time limit could be set to the time it is expected that a visitor will obtain their entry pass, place it in their ID holder, and enter the building.
[0074] Alternatively, for example, the admission reception system 1 may display information to visitors regarding the time limit (e.g., validity period) of their admission pass. Or, the admission reception system 1 may indicate (print) the time limit (e.g., validity period) of the admission pass on the admission pass and request that visitors complete their entry between a specified time before (e.g., a few minutes before) and a specified time after (e.g., a few minutes after) their scheduled visit time. Or, the admission reception system 1 may transmit information regarding the time limit of the admission pass to a terminal 50 held by the visitor.
[0075] Furthermore, the admission reception system 1 may, for example, individually set time limits for each visitor.
[0076] Furthermore, for example, if an entry pass that has been invalidated due to a time limit is presented (e.g., S23), the entry reception system 1 may display or output a message to the visitor indicating that the entry pass has been invalidated or prompting them to request a replacement entry pass (S25). For example, the entry reception system 1 may display a message indicating that the entry pass is outside of its valid time (e.g., "It is before the scheduled time, so please present the authentication code again when the valid time begins," or "The time limit has been exceeded, so please start again by presenting the authentication code"), or it may include this as a note in advance when sending the authentication code to the visitor's account.
[0077] In Figure 4, if the time limit for the entry pass is exceeded without entering the facility, the entry pass is automatically invalidated, and the visitor must perform the entry procedure again with the entry reception system 1 (including presenting an authentication code and entering a simplified code) (S5', S6', S7', and S21'). Here, the authentication code for entering the facility (first-stage authentication code) is invalidated after the visitor has completed entry (S12). Therefore, when the entry pass is reissued, the authentication code is not invalidated, and the authentication code can be reused.
[0078] For example, if a visitor presents their entry pass within the valid time limit (S23'), the entry reception system 1 performs authentication processing such as verifying the authentication code. If authentication is successful (authentication OK), it allows the visitor to enter the facility and unlocks the entry / exit gate 40 (S24').
[0079] Thus, in this embodiment, by setting an expiration period for the issued access card, opportunities for the access card to be issued in advance or lost or copied after issuance can be suppressed, thus enabling secure authentication.
[0080] (Embodiment 3) This embodiment describes, for example, the case in which an emergency mode is set when using a facility (e.g., a building) as an evacuation site during a disaster.
[0081] For example, in emergency mode, the entrance reception system 1 switches between different entrance authentication methods for areas that are open as evacuation shelters (e.g., areas that do not require authentication), areas within the evacuation shelters where entry is restricted (e.g., areas that require authentication), and areas that are not open as evacuation shelters (e.g., areas that require the same authentication as in normal mode). Note that this example is not limited to this case, and there may be two or more areas where the entrance authentication method is switched depending on the area.
[0082] In this case, the entrance reception system 1 may display that it is in emergency mode.
[0083] For example, even in emergency mode, the entrance reception system 1 may perform the same authentication as in Embodiment 1 or Embodiment 2 for areas that are not opened as evacuation shelters.
[0084] Figure 5 is a sequence diagram showing an example of operation of the admission reception system 1 according to this embodiment.
[0085] For example, the entrance reception system 1 can set an emergency mode in addition to the normal mode (for example, Embodiment 1 or Embodiment 2) for using the facility as an evacuation site in the event of a disaster (S31). The emergency mode settings may include, for example, the setting of areas to be opened as evacuation shelters (open areas), the setting of areas within the open evacuation shelters where entry is limited to certain evacuees (restricted entry areas), and the setting of areas to be operated in the same manner as under normal circumstances (or areas not to be opened as evacuation shelters).
[0086] If an emergency is detected (S32), the entrance reception system 1 is switched to emergency mode by, for example, the building's disaster prevention center administrator (S33), and transitions to emergency mode (S34). When transitioning to emergency mode, the entrance reception system 1 may, for example, restrict access to certain areas of the facility and open them up as evacuation shelters (S35). However, this is not limited to switching to emergency mode by the facility administrator; for example, the entrance reception system 1 may automatically switch to emergency mode based on an emergency determination that detects an emergency.
[0087] In normal (regular) mode, for example, the entrance reception system 1 may operate by accessing the cloud via a cellular or internet connection to manage visitor schedules and information, and to save and update visit history, while also saving and updating the most recent schedule and visit history, including the current day, locally. In this case, the entrance reception system 1 may operate as a local system independent of the cellular and cloud systems. This allows the entrance reception system 1 to continue operating within the scope of information saved locally up to that point, even if access to the cloud becomes impossible in an emergency, as long as power supply is secured. It may also be possible to manually switch between operating in conjunction with the cellular and cloud systems or operating as a local system independent of the cellular and cloud systems, or to manually switch the frequency of access to the cellular and cloud systems.
[0088] When switching to emergency mode, the entrance reception system 1 may transition to emergency mode and display that the entrance reception system 1 and each entrance area are in emergency mode. The entrance reception system 1 may also display whether each entrance area subject to authentication by the entrance reception system 1 is an area where authentication is free (open area) as an evacuation shelter, an area within the evacuation shelter where entry is restricted (restricted entry area), or an area that is not open as an evacuation shelter. For example, for employees working in a facility (e.g., a building) subject to authentication by the entrance reception system 1, the system may be switched to a mode where entry authentication is performed in the same manner as during normal use.
[0089] The entrance reception system 1 (for example, the reception device 10) performs two-factor authentication as described in Embodiment 1 or Embodiment 2 for visits to a certain area within the facility in normal mode, and in emergency mode, it performs two-factor authentication for visits to a portion of a certain area within the facility (for example, an area that is not open as an evacuation shelter), and does not need to perform two-factor authentication for visits to other areas different from the aforementioned portion of the facility.
[0090] This allows the entry reception system 1 to continue operating the entry authentication system even when switching to emergency mode, by setting (restricting) the areas that can be entered using the same method as normal entry authentication. Therefore, when switching to emergency mode, it becomes possible to respond to nearby evacuees, including the initial evacuation of visitors who have already entered the building.
[0091] Furthermore, in some evacuation shelters, for example, in areas where entry is restricted to vulnerable individuals (e.g., women, the elderly), if an evacuee applies, the entry reception system 1 may issue an entry pass that allows approved individuals to enter the restricted area.
[0092] For example, if an evacuee applies for an entry pass for vulnerable persons (for example, an entry pass for a restricted area) (S36), the facility manager may authenticate the entry pass application (approve the application) (S37) and submit the application for the entry pass for vulnerable persons to the entry reception system 1 (S38).
[0093] The admission reception system 1 may issue admission cards for vulnerable persons based on an application from the facility manager (S39). The admission card issued may have, for example, an authentication code used to authenticate access to the area that can be entered, as well as information indicating the area that can be entered (limited area) (for example, one or more items such as room number, floor number, period of entry, and the name of the person permitted to enter).
[0094] Alternatively, the entry pass may be sent to the account linked to the authorized evacuee without being printed.
[0095] Additionally, a floor plan may be displayed at the entrance (for example, near entrance / exit gate 40) indicating areas that will be open as evacuation shelters, areas within the evacuation shelters where entry will be restricted, and areas that will not be open as evacuation shelters.
[0096] Thus, in this embodiment, the entrance reception system 1 performs processing that takes into account the possibility of the building becoming an evacuation center during disasters, etc., and therefore provides the convenience of being able to continue operations at the same level as during normal times even in emergencies, without having to perform separate operations for normal times and emergencies.
[0097] In this embodiment, we have described an emergency mode in which the facility is opened as an evacuation shelter. However, we are not limited to this, and in other uses, the facility may continue to operate with two-factor authentication in some areas, while operating other areas as open areas (or areas with restricted access) without using two-factor authentication.
[0098] The embodiments of this disclosure have been described above.
[0099] The flowcharts and sequence diagrams shown in each of the embodiments described above do not limit the execution of processes to the order shown. For example, each process shown in the flowchart and sequence may be executed in a different order than shown, and multiple processes may be executed in parallel or simultaneously. The order of the multiple processes shown may also be changed. Furthermore, some of the processes shown in the sequence may be temporarily omitted.
[0100] In the embodiments described above, the notation "...part" used for each component may be replaced with other notations such as "...means," "...circuitry," "...assembly," "...device," "...unit," or "...module."
[0101] <Summary of Embodiments> An authentication system according to one embodiment of the present disclosure comprises: a terminal used by a visitor to a facility; an information processing device that performs a first authentication on the visitor using a first code stored in the terminal and a second code issued to the visitor when the visitor visits the facility based on the first code, issues an entry pass including a third code if the first authentication is successful, performs a second authentication using the third code to permit entry to the facility, and permits the visitor to enter the facility if the second authentication is successful.
[0102] In one embodiment of the present disclosure, at least one of the first code, the second code, and the third code is different for each visitor to the facility and is different information for each visitor to the facility.
[0103] In one embodiment of the present disclosure, the information processing device sets a period during which entry to the facility is permitted based on the second authentication.
[0104] In one embodiment of the present disclosure, the information processing device uses the third code to perform a third authentication to permit exit from the facility.
[0105] In one embodiment of the present disclosure, the visitor pass is printed with at least one of the following: information about the visitor's destination and information about the validity period of the visitor pass.
[0106] In one embodiment of the present disclosure, the information processing device performs two-factor authentication, consisting of the first authentication and the second authentication, for visits to a first area in a first mode, and performs the two-factor authentication for visits to a portion of the first area in a second mode, but does not perform the two-factor authentication for visits to other areas of the first area that are different from the portion of the first area.
[0107] In one embodiment of the present disclosure, the second mode is an emergency mode.
[0108] In one embodiment of the present disclosure, the authentication system operates as a local system independent of the cellular system and the cloud system.
[0109] An information processing device according to one embodiment of the present disclosure comprises: an issuance control unit that performs a first authentication on a visitor using a first code stored on a terminal used by a visitor to a facility and a second code issued to the visitor when the visitor visits the facility based on the first code, and issues an entry pass including a third code if the first authentication is successful; and an entry control unit that performs a second authentication to permit entry to the facility using the third code, and permits the visitor to enter the facility if the second authentication is successful.
[0110] In an information processing method according to one embodiment of the present disclosure, the information processing device performs a first authentication of the visitor using a first code stored in a terminal used by the visitor of the facility and a second code issued to the visitor when the visitor visits the facility based on the first code, issues an entry pass including a third code if the first authentication is successful, performs a second authentication using the third code to permit entry into the facility, and permits the visitor to enter the facility if the second authentication is successful.
[0111] This disclosure can be implemented using software, hardware, or software integrated with hardware.
[0112] Each functional block used in the description of the above embodiments may be implemented partially or entirely as an integrated circuit (LSI), and each process described in the above embodiments may be controlled partially or entirely by a single LSI or a combination of LSIs. An LSI may consist of individual chips, or it may consist of a single chip that includes some or all of the functional blocks. An LSI may have data inputs and outputs. Depending on the degree of integration, LSIs may be referred to as ICs, system LSIs, super LSIs, or ultra LSIs.
[0113] The method of integration is not limited to LSIs; it may also be implemented using dedicated circuits, general-purpose processors, or dedicated processors. Furthermore, FPGAs (Field Programmable Gate Arrays) that can be programmed after LSI manufacturing, or reconfigurable processors that allow for the reconfiguration of the connections and settings of circuit cells within the LSI, may also be used. This disclosure may be implemented as digital or analog processing.
[0114] Furthermore, if advancements in semiconductor technology or related technologies lead to the emergence of integrated circuit technologies that replace LSIs, then naturally, these technologies can be used to integrate functional blocks. The application of biotechnology, for example, is a possible possibility.
[0115] This disclosure is applicable to all types of devices, systems, and equipment having communication capabilities (collectively referred to as communication equipment). Communication equipment may include a radio transceiver and a processing / control circuit. A radio transceiver may include a receiver and a transmitter, or both as functions. A radio transceiver (transmitter, receiver) may include an RF (Radio Frequency) module and one or more antennas. The RF module may include an amplifier, an RF modulator / demodulator, or similar. Non-exclusive examples of communication devices include telephones (mobile phones, smartphones, etc.), tablets, personal computers (PCs) (laptops, desktops, notebooks, etc.), cameras (digital still / video cameras, etc.), digital players (digital audio / video players, etc.), wearable devices (wearable cameras, smartwatches, tracking devices, etc.), game consoles, digital book readers, telehealth / telemedicine devices, vehicles or mobile transport with communication capabilities (cars, airplanes, ships, etc.), and combinations of the above-mentioned devices.
[0116] Communication devices are not limited to portable or movable devices, but also include all kinds of non-portable or fixed devices, devices, and systems, such as smart home devices (appliances, lighting equipment, smart meters or measuring instruments, control panels, etc.), vending machines, and any other "things" that may exist on an IoT (Internet of Things) network.
[0117] Furthermore, in recent years, Cyber-Physical Systems (CPS), a new concept in IoT (Internet of Things) technology that creates new added value through information linkage between the physical and cyber spaces, has been attracting attention. This CPS concept can also be adopted in the above-described embodiment.
[0118] In other words, as a basic configuration of CPS, for example, edge servers located in physical space and cloud servers located in cyberspace are connected via a network, and processing can be distributed and performed by the processors installed on both servers. Here, it is preferable that each processing data generated on the edge server or cloud server is generated on a standardized platform, and by using such a standardized platform, it is possible to improve efficiency when building systems that include various diverse groups of sensors and IoT application software.
[0119] Communication includes data communication via cellular systems, wireless LAN systems, and communication satellite systems, as well as data communication using combinations of these.
[0120] Furthermore, the communication device also includes devices such as controllers and sensors that are connected to or linked to a communication device that performs the communication functions described in this disclosure. For example, this includes controllers and sensors that generate control signals and data signals used by the communication device that performs the communication functions of the communication device.
[0121] Furthermore, communication equipment includes infrastructure facilities such as base stations, access points, and any other devices, devices, and systems that communicate with or control the aforementioned non-limited types of equipment.
[0122] Although various embodiments have been described above with reference to the drawings, it goes without saying that this disclosure is not limited to such examples. It is clear to those skilled in the art that various modifications or alterations can be conceived within the scope of the claims, and these will naturally also fall within the technical scope of this disclosure. Furthermore, the components in the above embodiments may be combined in any way without departing from the spirit of the disclosure.
[0123] The specific examples of this disclosure have been described in detail above, but these are merely illustrative and do not limit the scope of the claims. The technologies described in the claims include various modifications and changes to the specific examples described above. [Industrial applicability]
[0124] One embodiment of the present disclosure is suitable for an authentication system. [Explanation of Symbols]
[0125] 1. Admission Reception System 10 Reception device 11 Communications Department 12 Control Unit 20 Display / Reading Section 30 Output section 40 Entrance / Exit Gates 50 devices 121 Issuance Control Unit 122 Building Access Control Unit
Claims
1. Terminals used by visitors to the facility, An information processing device that performs a first authentication on the visitor using a first code stored in the terminal and a second code issued to the visitor when the visitor visits the facility based on the first code, issues an entry pass including a third code if the first authentication is successful, performs a second authentication using the third code to permit entry to the facility, and permits the visitor to enter the facility if the second authentication is successful, An authentication system equipped with the following features.
2. At least one of the first code, the second code, and the third code is different for each visitor to the facility, and is different information for each visitor to the facility. The authentication system according to claim 1.
3. The information processing device sets a period during which entry to the facility is permitted based on the second authentication. The authentication system according to claim 1.
4. The information processing device uses the third code to perform a third authentication to permit exit from the facility. The authentication system according to claim 1.
5. The aforementioned entry pass shall have at least one of the following printed on it: information regarding the visitor's destination and information regarding the validity period of the entry pass. The authentication system according to claim 1.
6. The aforementioned information processing device is In the first mode, two-factor authentication is performed for a visit to the first area, consisting of the first authentication and the second authentication. In the second mode, two-factor authentication is performed for visits to certain areas within the first area, and two-factor authentication is not performed for visits to other areas within the first area that are different from those areas. The authentication system according to claim 1.
7. The second mode is the emergency mode. The authentication system according to claim 6.
8. The aforementioned authentication system operates as a local system independent of the cellular system and the cloud system. The authentication system according to claim 1.
9. An issuance control unit that performs a first authentication on a visitor using a first code stored on a terminal used by the visitor of the facility and a second code issued to the visitor when the visitor visits the facility based on the first code, and issues an entry pass including a third code if the first authentication is successful, An entry control unit that uses the third code to perform a second authentication to permit entry to the facility, and permits the visitor to enter the facility if the second authentication is successful, An information processing device equipped with the following.
10. Information processing equipment, Using a first code stored on a terminal used by the facility visitor and a second code issued to the visitor upon their visit to the facility based on the first code, a first authentication is performed on the visitor, and if the first authentication is successful, an entry pass including a third code is issued. Using the third code, a second authentication is performed to permit entry to the facility, and if the second authentication is successful, the visitor is permitted to enter the facility. Information processing methods.