Authentication device, authentication method, and program

The authentication device uses multiple receiver sets to verify the location of the authenticating device within a specified area, preventing unintended authentication processes, thereby enhancing security and user control.

JP2026091698APending Publication Date: 2026-06-04SINUMY株式会社

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SINUMY株式会社
Filing Date
2024-11-25
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Existing authentication systems allow for hands-free authentication that can be performed in unintended situations, leading to unauthorized processing such as settlement or unlocking.

Method used

An authentication device that includes multiple receiver sets to determine the location of the authenticating device and ensures it is within a designated area before allowing a process, using authentication information and location identification to prevent unintended execution of processes.

Benefits of technology

Prevents unauthorized processes by ensuring the authenticating device is in a specified area, enhancing security and user control over authentication events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026091698000001_ABST
    Figure 2026091698000001_ABST
Patent Text Reader

Abstract

The present invention provides an authentication device that prevents processing from being executed in response to authentication performed in circumstances unintended by the user. [Solution] The authentication device 1 includes first and second receiver sets 11 and 12 that receive authentication requests transmitted from the device to be authenticated 2, an authentication device unit 13 that determines whether the device to be authenticated 2 is legitimate using the received authentication requests, a location unit 14 that identifies the location of the device to be authenticated 2 based on the difference in strength of the authentication requests received by the first and second receiver sets 11 and 12, respectively, a location determination unit 15 that determines whether the identified location is included in the authentication area R2 shown on the floor, and an output unit 16 that outputs a predetermined process relating to the user 5 carrying the device to be authenticated 2 when it is determined that the device to be authenticated 2 is legitimate and the location of the device to be authenticated 2 is included in the authentication area R2.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0006] , ,

[0001] The present invention relates to an authentication device that receives an authentication request transmitted from an authenticated device and performs authentication, etc.

Background Art

[0002] Conventionally, an authentication device that receives an authentication request transmitted from an authenticated device and performs authentication is known (see, for example, Patent Document 1). By performing authentication using such an authentication request, for example, hands-free authentication that does not require an operation by the user can be performed.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in hands-free authentication, there is a problem that authentication may be performed in a situation unintended by the user and judged to be legitimate, and processing such as settlement may be performed.

[0005] The present invention has been made to solve the above problems, and an object thereof is to provide an authentication device or the like that can prevent a predetermined process from being executed in response to authentication performed in a situation unintended by the user.

Means for Solving the Problems

[0006] To achieve the above objective, an authentication device according to one aspect of the present invention includes: a first receiver set including one or more first receivers that receive an authentication request transmitted from a device to be authenticated, which includes authentication information used for authenticating the device to be authenticated; a second receiver set including one or more second receivers that receive an authentication request transmitted from a device to be authenticated; a device authentication unit that performs device authentication, determining whether the device to be authenticated that sent the authentication request is legitimate, using the authentication information contained in the authentication request received by at least one of the one or more first receivers and the one or more second receivers; a location unit that identifies the location of the device to be authenticated based on the difference in strength of the authentication requests received by the first and second receiver sets, respectively; an area determination unit that performs area determination, determining whether the location of the device to be authenticated identified by the location unit is included in an authentication area indicated on the floor; and an output unit that outputs a predetermined process relating to the user carrying the device to be authenticated when the device to be authenticated is determined to be legitimate in device authentication and the location of the device to be authenticated is determined to be included in the authentication area in area determination.

[0007] With this configuration, if the device to be authenticated is determined to be legitimate during device authentication and the location of the device to be authenticated is included in the authentication area, a predetermined process can be executed. For example, if a user does not enter the authentication area indicated on the floor, the predetermined process can be prevented from being executed. Therefore, the predetermined process can be prevented from being executed in response to authentication performed in circumstances unintended by the user.

[0008] Furthermore, in an authentication device according to one aspect of the present invention, the authentication area may be indicated by a mat placed on the floor.

[0009] With this configuration, for example, the position of the authentication area can be changed by changing the position of the mat.

[0010] Furthermore, in an authentication device according to one aspect of the present invention, the authentication area may be displayed on the floor surface.

[0011] Furthermore, an authentication device according to one aspect of the present invention may further include a display unit that displays the authentication area on the floor surface.

[0012] This configuration allows for easier modification of the display position of the authentication area, for example.

[0013] Furthermore, in an authentication device according to one aspect of the present invention, the display unit may change the display position of the authentication area.

[0014] With this configuration, for example, a predetermined process can be performed when a user enters the authentication area after the display position has been changed.

[0015] Furthermore, in an authentication device according to one aspect of the present invention, the output unit may output information regarding the execution of a predetermined process when it is determined in device authentication that the device to be authenticated is legitimate and in area determination that only the location of the device to be authenticated is included in the authentication area.

[0016] This configuration allows a predetermined process to be performed when only one device to be authenticated exists in the authentication domain.

[0017] Furthermore, an authentication device according to one aspect of the present invention further comprises a sensor that acquires information about an authentication area, and a person acquisition unit that uses the information acquired by the sensor to acquire the number of people present in the authentication area, and the output unit may output information regarding the execution of a predetermined process when the device to be authenticated is determined to be legitimate in device authentication, the location of the device to be authenticated is determined to be included in the authentication area in area determination, and the number of people acquired by the person acquisition unit is 1.

[0018] This configuration allows for predetermined processing to be performed only when a single user carrying the device to be authenticated is present in the authentication area.

[0019] Also, in the authentication device according to one aspect of the present invention, the sensor may be a weight sensor that acquires the weight in the authentication area, or an image sensor that acquires an image of the authentication area.

[0020] Further, in the authentication device according to one aspect of the present invention, when it is determined that the device to be authenticated is legitimate in device authentication and it is determined that the position of the device to be authenticated is not included in the authentication area in area determination, a first output is performed. When it is determined that the device to be authenticated is legitimate in device authentication, it is determined that the position of the device to be authenticated is included in the authentication area in area determination, and when the execution of a predetermined process has not been completed, a second output is performed. When the execution of the predetermined process has been completed, it may further include a situation output unit that performs a third output.

[0021] With such a configuration, the user can know about the authentication result, the determination result, the situation regarding the execution of a predetermined process, for example, whether the execution of the predetermined process is possible or whether the execution of the predetermined process has been completed.

[0022] Also, in the authentication device according to one aspect of the present invention, the situation output unit may perform a fourth output when it is determined by the area determination unit that the positions of two or more devices to be authenticated are included in the authentication area.

[0023] With such a configuration, for example, by performing the fourth output, it becomes possible to know the reason why a predetermined process is not performed.

[0024] Also, in the authentication device according to one aspect of the present invention, the predetermined process may be a settlement process.

[0025] Also, in the authentication device according to one aspect of the present invention, the predetermined process may be an unlocking process.

[0026] Further, the authentication method according to one aspect of the present invention is an authentication method processed using a first receiver set including one or more first receivers, a second receiver set including one or more second receivers, a device authentication unit, an identification unit, a region determination unit, and an output unit. The method includes the steps of: one or more first receivers included in the first receiver set receiving an authentication request including authentication information used for authenticating an authentication device, which is transmitted from the authentication device; one or more second receivers included in the second receiver set receiving an authentication request transmitted from the authentication device; the device authentication unit performing device authentication to determine whether the authentication device that transmitted the authentication request is legitimate by using the authentication information included in the authentication request received by at least one of the one or more first receivers and the one or more second receivers; the identification unit identifying the position of the authentication device based on the intensity difference between the authentication requests respectively received by the first and second receiver sets; the region determination unit performing region determination to determine whether the identified position of the authentication device is included in an authentication region shown on the floor; and the output unit performing an output regarding the execution of a predetermined process related to the user carrying the authentication device when it is determined in the device authentication that the authentication device is legitimate and it is determined in the region determination that the position of the authentication device is included in the authentication region.

Advantages of the Invention

[0027] According to an authentication device or the like according to one aspect of the present invention, it is possible to prevent a predetermined process from being executed in response to authentication performed in a situation unintended by the user.

Brief Description of the Drawings

[0028] [Figure 1] Block diagram showing the configuration of an authentication device according to an embodiment of the present invention [Figure 2A] Diagram for explaining an authentication region in the same embodiment [Figure 2B] Diagram for explaining an authentication region in the same embodiment [Figure 3]This figure shows an example of an authentication area set up in front of the vending machine in the same embodiment. [Figure 4] Flowchart showing the operation of the authentication device according to this embodiment. [Figure 5] Block diagram showing another example of the configuration of the authentication device according to the same embodiment. [Figure 6] Block diagram showing another example of the configuration of the authentication device according to the same embodiment. [Figure 7] This figure shows an example of the configuration of the computer system in the same embodiment. [Modes for carrying out the invention]

[0029] The authentication device and authentication method according to the present invention will be described below using embodiments. In the following embodiments, components and steps denoted by the same reference numerals are the same or equivalent and may not be described again. The authentication device according to this embodiment outputs a predetermined process concerning the user carrying the authenticated device when the authenticated device is determined to be legitimate in device authentication and the location of the authenticated device is determined to be within the authentication area indicated on the floor in area determination.

[0030] Figure 1 is a block diagram showing the configuration of the authentication device 1 according to this embodiment. The authentication device 1 according to this embodiment comprises a first receiver set 11, a second receiver set 12, a device authentication unit 13, a identification unit 14, an area determination unit 15, and an output unit 16, and may further comprise a status output unit 17 as needed. The authentication device 1 according to this embodiment may perform device authentication to determine whether the device to be authenticated 2 carried by user 5 is legitimate, and area determination to determine whether the device to be authenticated 2 is included in the authentication area R2 indicated on the floor, and may output a result so that a predetermined process is executed by the execution unit 51. The predetermined process performed by the execution unit 51 may be, for example, a payment process or an unlocking process, or other processing performed on user 5 carrying the device to be authenticated 2 which has been determined to be legitimate. By performing the payment process, user 5 may be able to purchase goods or receive services. The payment process may be performed, for example, in a POS register or a vending machine. Furthermore, once the unlocking process is completed, user 5 may be able to enter the house, a hotel room, a conference room, etc.

[0031] Note that while Figures 1 and 3 show a situation where user 5 is holding the device to be authenticated 2 in their hand, "user 5 is carrying the device to be authenticated 2" does not necessarily mean that user 5 is holding the device to be authenticated 2 in their hand; for example, the device to be authenticated 2 moves in accordance with user 5's movements. The device to be authenticated 2 may be placed, for example, in user 5's clothing pocket or bag. Also, while Figure 1 shows a case where the authentication device 1 receives an authentication request from one device to be authenticated 2 carried by one user 5, the authentication device 1 may receive authentication requests from multiple devices to be authenticated 2, each carried by multiple users 5.

[0032] The authentication device 1 may or may not have an execution unit 51. In the latter case, the authentication device 1 may, for example, control the execution of a predetermined process in an execution unit 51 of an external device.

[0033] The device to be authenticated 2 may be, for example, a smartphone, tablet, PDA (Personal Digital Assistant), laptop computer, transceiver, or other portable information terminal equipped with communication functions, or it may be any other device.

[0034] The first receiver set 11 comprises one or more first receivers 11a. Each of the one or more first receivers 11a receives an authentication request transmitted from the device to be authenticated 2, which includes authentication information used for authenticating the device to be authenticated 2. The device to be authenticated 2 may transmit the authentication request, for example, as radio waves. The first receiver set 11 may be arranged in a first position. The authentication request may include, for example, a user identifier of the user 5 carrying the device to be authenticated 2 that transmits the authentication request, and a device identifier that identifies the device to be authenticated 2. The user identifier may be, for example, the user's telephone number, email address, name, or a string unique to the user. The device identifier may be, for example, the device's address or a string unique to the device. The device's address may be, for example, a physical address such as a MAC address, or another address.

[0035] The second receiver set 12 comprises one or more second receivers 12a. Each of the one or more second receivers 12a receives an authentication request transmitted from the device to be authenticated 2. The second receiver set 12 may be located in a second position different from the first position. The second receiver set 12 may be the same as the first receiver set 11 except for its location.

[0036] From the viewpoint of achieving more accurate location identification of the device to be authenticated 2, it is preferable that the first receiver set 11 includes a plurality of first receivers 11a, and the second receiver set 12 includes a plurality of second receivers 12a. As shown in Figure 1, for example, the first receiver set 11 may include four first receivers 11a, and the second receiver set 12 may include four second receivers 12a, but the number of receivers included in the first and second receiver sets 11 and 12 may be one to three, or five or more. Each receiver 11a, 12a included in the first and second receiver sets 11 and 12 is capable of acquiring the strength of the radio waves of the authentication request.

[0037] If the first receiver set 11 includes a plurality of first receivers 11a, the first position may be, for example, the position of the center of gravity of the plurality of first receivers 11a. More specifically, the position of the center of gravity of each first receiver 11a may be identified, and the position of the center of gravity with respect to the identified plurality of center of gravity positions may be taken as the first position. The plurality of first receivers 11a may be placed close to each other, or they may be placed far apart. In the latter case, however, it is preferable that the plurality of first receivers 11a are within a distance range from the first position to the second position. The same applies to the second position of the second receiver set 12.

[0038] The first receiver 11a and the second receiver 12a may include wireless receiving devices such as antennas for receiving radio waves, or they may not include such devices. Furthermore, the first receiver 11a and the second receiver 12a may be implemented by hardware, or by software such as drivers for operating the receiving devices.

[0039] The authentication request, which is transmitted via radio waves, may be, for example, a pulse wave transmitted intermittently or a continuous wave transmitted continuously. Furthermore, the wireless communication standard used to send and receive the authentication request is not limited. The authentication request may be communicated by, for example, Bluetooth Low Energy (BLE), Bluetooth Basic Rate (BR) / Enhanced Data Rate (EDR), wireless LAN (IEEE 802.11), IEEE 802.15.4 such as ZigBee (registered trademark), or other wireless communication standards. It is preferable that the authentication request be sent and received by short-range wireless communication such as BLE, Bluetooth BR / EDR, or wireless LAN.

[0040] The frequency of the radio waves for the authentication request is not particularly limited, but may be, for example, in the range of 300 MHz to 300 GHz. The device being authenticated 2 may, for example, transmit the authentication request by broadcast or by unicast. It is preferable to transmit the authentication request by broadcast because it is possible to transmit the authentication request without specifying the communication partner. In this embodiment, the case in which the device being authenticated 2 transmits the authentication request by broadcast will be mainly described. It is preferable for the device being authenticated 2 to transmit the authentication request without receiving a transmission instruction from the user 5. The device being authenticated 2 may, for example, transmit the authentication request in response to the reception of a predetermined beacon. The device being authenticated 2 may, for example, transmit the authentication request only once in response to the reception of this beacon, transmit the authentication request for a predetermined period of time, or, if the beacon is being received, continuously repeat the transmission of the authentication request. This beacon may, for example, be transmitted in an area where authentication using the authentication request is performed. As an example, the authentication device 1 may transmit the beacon. In this case, the authentication device 1 may further include a transmitting unit that transmits the beacon.

[0041] The authentication information included in the authentication request may include any information that can be used to authenticate the device under authentication 2, but as an example, it may include encrypted information obtained by encrypting unique information. The unique information may include, for example, time, random value, count value, one-time password, etc. The unique information may also be information specific to the authentication request. That is, the unique information corresponding to the encrypted information included in the authentication request may differ for each authentication request. The unique information may be, for example, information generated by the device under authentication 2, or information transmitted from the authentication device 1 to the device under authentication 2. In the latter case, challenge-response authentication may be performed by the authentication device 1. When the unique information is transmitted from the authentication device 1, the authentication device 1 may further include a transmission unit for transmitting the unique information. In this embodiment, the case in which the unique information is generated by the device under authentication 2 will be mainly described. As with the encrypted information described above, it is preferable that the authentication information includes different information for each authentication request. This is to prevent the authentication information from being reused by a malicious third party. Also, as an example, the encrypted information may be information obtained by encrypting the user identifier and the unique information. In this case, the encrypted information can be considered to be, for example, information that includes a user identifier and authentication information.

[0042] The encryption of unique information may be, for example, symmetric-key cryptography or public-key cryptography. That is, the encryption key used to encrypt unique information may be, for example, a symmetric key or a public key corresponding to authentication device 1. If the encryption key is a symmetric key, it is preferable that authentication device 1 and authenticated device 2 have the same symmetric key. Furthermore, it is preferable that the symmetric key is different for each authenticated device 2.

[0043] Furthermore, the line of sight between the device to be authenticated 2 and the authentication device 1 may or may not be visible. In the latter case, user 5 may carry the device to be authenticated 2 in, for example, a pocket of their clothing or in a bag.

[0044] The device authentication unit 13 performs device authentication to determine whether the device to be authenticated 2 that sent the authentication request is legitimate, using the authentication information contained in the authentication request received by at least one of the one or more first receivers 11a and one or more second receivers 12a. For example, if the authentication information includes encrypted information in which unique information has been encrypted, the device may determine that the device to be authenticated 2 that sent the authentication request is legitimate if the unique information corresponding to the encrypted information matches the unique information stored in the authentication device 1 that corresponds to the device to be authenticated 2 that sent the authentication request, and if they do not match. Whether the unique information corresponding to the encrypted information matches the unique information stored in the authentication device 1 may be determined, for example, by whether the unique information obtained by decrypting the encrypted information matches the unique information stored in the authentication device 1, or by whether the encrypted information matches the result of encrypting the unique information stored in the authentication device 1.

[0045] When unique information is obtained in the authenticated device 2, the unique information stored in the authentication device 1 may be obtained, for example, by the same method as the acquisition of unique information in the authenticated device 2. Also, when the authenticated device 2 receives unique information from the authentication device 1, the unique information stored in the authentication device 1 may be, for example, the unique information that the authentication device 1 transmitted to the authenticated device 2.

[0046] If the cryptographic information contained in the authentication information is encrypted with a common key, the device authentication unit 13 may, for example, read the common key stored on a predetermined recording medium in association with the user identifier contained in the authentication information together with the authentication information, and decrypt the cryptographic information using the read common key, or it may encrypt the unique information stored in the authentication device 1 using the read common key. If the cryptographic information contained in the authentication information is encrypted with a public key, the device authentication unit 13 may, for example, read a private key from a predetermined recording medium and decrypt the cryptographic information using the read private key, or it may read a public key from a predetermined recording medium and encrypt the unique information stored in the authentication device 1 using the read public key.

[0047] The device authentication unit 13 may perform device authentication using a single authentication request, or it may perform device authentication using multiple authentication requests received within a predetermined period. For authentication using multiple authentication requests, please refer to, for example, the above-mentioned Patent Document 1.

[0048] The identification unit 14 identifies the location of the device to be authenticated 2 based on the difference in the strength of the authentication requests received by the first and second receiver sets 11 and 12, respectively. The difference in the strength of the authentication requests may be, for example, the difference in the received signal strength indicator (RSSI) of the authentication requests. If the first and second receiver sets 11 and 12 include two or more receivers, the strength difference may be, for example, the difference in representative values ​​of multiple received signal strengths acquired by two or more receivers in the first and second receiver sets 11 and 12, respectively. The representative values ​​may be, for example, the mean or median. Furthermore, if the first and second receiver sets 11 and 12 include two or more receivers, it is preferable that these two or more receivers have equivalent performance. For example, it is preferable that the antenna gains of the two or more receivers included in the first receiver set 11 or the second receiver set 12 are the same. In determining the location of the wave source using the intensity difference of the received authentication requests, for example, the received intensity of the authentication requests received by the first and second receiver sets 11 and 12, and the first and second positions which are the locations of the first and second receiver sets 11 and 12, may be used to identify an Apollonius circle or line corresponding to the difference in received intensity, and the position on, on, or within that Apollonius circle may be identified as the position of the device to be authenticated 2, or the position of the device to be authenticated 2 may be identified by other methods.

[0049] Furthermore, the position identified by the identification unit 14 may be, for example, a point-like position, or a linear, planar, or three-dimensional position. In this embodiment, the case in which the point-like position of the device to be authenticated 2 is identified by the identification unit 14 will be mainly described. The identified position may be, for example, a position in a two-dimensional plane, or a position in three-dimensional space. In this embodiment, the former case will be mainly described. When identifying a planar position, the identification unit 14 may, for example, identify whether the position of the device to be authenticated 2 is within the authentication area R2.

[0050] The method of determining the location of a wave source using the difference in received radio wave intensity is already well known, and a detailed explanation will be omitted. For information on such methods of determining the location of a wave source, please refer to the following literature, for example. Reference: International Publication No. 2020 / 080314

[0051] The area determination unit 15 performs an area determination to determine whether the location of the device to be authenticated 2, identified by the identification unit 14, is included in the authentication area R2 shown on the floor. If user 5 is carrying the device to be authenticated 2, the location of the device to be authenticated 2 can be considered to be substantially the location of user 5. Therefore, if the area determination unit 15 determines that the location of the device to be authenticated 2 is included in the authentication area R2, it can be considered that user 5, who is carrying the device to be authenticated 2, is located in the authentication area R2. In a real environment, it is preferable that the authentication area R2 is indicated in such a way that user 5 can easily visually distinguish the authentication area R2 from other areas. Alternatively, the area determination unit 15 may read information indicating the authentication area R2 stored on a recording medium (not shown) and use the read information indicating the authentication area R2 to determine whether the identified location of the device to be authenticated 2 is included in the authentication area R2. The information indicating the authentication area R2 may, for example, be information indicating the location of the outline of the authentication area R2.

[0052] The authentication area R2 may, for example, be displayed on the floor. The authentication area R2 displayed on the floor may be, for example, an area drawn on the floor using paint, an area demarcated by applying tape to the floor, or an area displayed by the display unit 21 described later. Alternatively, the authentication area R2 may be indicated by a mat placed on the floor. In this case, for example, an area on the mat placed on the floor may become the authentication area R2. In this case, the position of the authentication area R2 can be changed by changing the arrangement of the mat. When the arrangement of the mat is changed, it is preferable that the changed position of the mat, i.e., the changed position of the authentication area R2, be stored as information indicating the authentication area R2 on a recording medium (not shown).

[0053] Furthermore, it is preferable that, for example, user 5 can easily visually distinguish between the authentication area R2 and other areas in the physical space. For example, the authentication area R2 shown on the floor may have a display indicating that it is the authentication area R2, such as "OK," and other areas may have a display indicating that they are not the authentication area R2, such as "NG."

[0054] As shown in the plan view of Figure 2A, the region R1 in which the location of the device to be authenticated 2 is identified by the identification unit 14 may include the authenticated region R2 and the other non-authenticated region R3. The non-authenticated region R3 may be any region in region R1 other than the authenticated region R2. For example, as shown in Figure 2A, if the location P1 of the device to be authenticated 2 is identified by the identification unit 14, the region determination unit 15 may determine in its region determination that the location P1 of the device to be authenticated 2 is included in the authenticated region R2.

[0055] As another example, as shown in the plan view of Figure 2B, the region R1 in which the location of the device to be authenticated 2 is identified by the identification unit 14 may include the authentication region R2, the gray region R4 provided around the authentication region R2, and the non-authenticated region R3. The non-authenticated region R3 may be any region in region R1 other than the authentication region R2 and the gray region R4. It is preferable that the device to be authenticated 2, i.e., the user 5, is not present in the gray region R4. Therefore, guidance may be provided in the real space to prevent the user from stopping in the gray region R4. By providing the gray region R4, it becomes possible to more accurately determine whether the location of the device to be authenticated 2 is included in the authentication region R2.

[0056] The order of device authentication by the device authentication unit 13 and the domain determination by the domain determination unit 15 does not matter. For example, domain determination may be performed after device authentication. In this case, domain determination may be performed only for the authenticated device 2 that was determined to be legitimate in the device authentication. Alternatively, device authentication may be performed after domain determination. In this case, device authentication may be performed only for the authenticated device 2 that was determined to be included in the authentication domain R2 in the domain determination. Whether the authenticated device 2 subject to device authentication and the authenticated device 2 subject to domain determination are the same device may be determined, for example, using the user identifier or device identifier included in the authentication request. Furthermore, device authentication and domain determination may be performed independently for the authenticated device 2 that sent the authentication request.

[0057] The output unit 16 outputs a message regarding the execution of a predetermined process for the user carrying the authenticated device 2 if the device authentication unit 13 determines that the authenticated device 2 is legitimate and the area determination unit 15 determines that the location of the authenticated device 2 is included in the authentication area R2. Otherwise, the output unit 16 may, for example, not output anything, or it may output a message that the predetermined process will not be executed. The output regarding the execution of the predetermined process may be, for example, an output granting permission to execute the predetermined process, or an output causing the predetermined process to be executed. It is preferable that the output regarding the execution of the predetermined process results in the execution of that predetermined process. For example, in the case of purchasing goods from a vending machine, the predetermined process, namely the payment process, may be performed when the user 5 presses the product selection button on the vending machine after the output unit 16 has output a message regarding the execution of the predetermined process.

[0058] On the other hand, if the device under authentication 2 is determined to be invalid in at least the device authentication stage, the predetermined process does not have to be executed, and if the location of the device under authentication 2 is determined to be not included in the authentication area R2 in at least the area determination stage, the predetermined process does not have to be executed. The predetermined process may be executed, for example, by the execution unit 51. If the predetermined process performed by the execution unit 51 is a settlement process, the output unit 16 may, for example, output a user identifier or device identifier included in the authentication request to the execution unit 51 when outputting information related to the execution of the process. The execution unit 51 may then perform the settlement process using the settlement information associated with the outputted user identifier or device identifier. The settlement information is information used to make a settlement, and may be, for example, credit card or electronic money information.

[0059] For example, if user 5, who is carrying a legitimate device to be authenticated 2, is present in the authentication area R2, the output unit 16 may output a message to ensure that a predetermined process is executed. As a result, user 5 may, for example, purchase goods or have their door unlocked. On the other hand, if user 5, who is carrying a legitimate device to be authenticated 2, is not present in the authentication area R2, the output unit 16 may output a message to prevent the predetermined process from being executed, or it may not output a message to ensure that the predetermined process is executed. As a result, user 5 may be prevented from, for example, making a payment for a purchase or having their door unlocked. In this way, user 5 can decide whether or not to perform a predetermined process, such as payment processing or unlocking processing, depending on whether or not they are present in the authentication area R2 shown on the floor. Therefore, it is possible to prevent predetermined processes from being executed in situations that user 5 did not intend. On the other hand, if a user 5 carrying a legitimate device to be authenticated 2 is present in the authentication area R2, the authentication request sent from the device to be authenticated 2 can be used to automatically perform predetermined processing, allowing user 5 to perform predetermined processing such as payment processing or unlocking processing hands-free.

[0060] Furthermore, the output unit 16 may output information regarding the execution of a predetermined process concerning the user carrying the authenticated device 2 if, for example, the authenticated device 2 is determined to be legitimate in the device authentication by the device authentication unit 13, and the area determination unit 15 determines that the location of the authenticated device 2 is within the authentication area R2 for a predetermined time from the reference time. In this way, for example, the predetermined process can be performed when user 5 stays in the authentication area R2 for a predetermined time from the reference time, and the predetermined process can be prevented from being performed even if user 5 is in the authentication area R2 for only a short time. Therefore, even if user 5 unintentionally enters the authentication area R2, the predetermined process will not be performed by immediately leaving the authentication area R2, and the predetermined process can be executed according to user 5's intentions. The reference time may be, for example, the time when user 5 enters the authentication area R2, the time when user 5 performs some operation such as pressing a product selection button on a vending machine, or any other predetermined time. The specified time may be, for example, between 1 and 5 seconds, or between 2 and 4 seconds. In this way, the specified time may be short.

[0061] The status output unit 17 may output information regarding the authentication status and the status of the execution of a predetermined process. For example, the status output unit 17 may output a first output when the device under authentication 2 is determined to be legitimate and the location of the device under authentication 2 is determined not to be included in the authentication area R2 in the area determination; output a second output when the device under authentication 2 is determined to be legitimate and the location of the device under authentication 2 is determined to be included in the authentication area R2 in the area determination, and the execution of a predetermined process has not been completed; and output a third output when the execution of a predetermined process has been completed. The third output may be output when the device under authentication 2 is determined to be legitimate and the location of the device under authentication 2 is determined to be included in the authentication area R2 in the area determination, and the execution of a predetermined process has been completed. The status output unit 17 may receive, for example, from the execution unit 51 whether the execution of a predetermined process has been completed. Note that the first to third outputs are all different outputs. Different outputs may be outputs with different content, or outputs with different methods of output or devices that perform the output.

[0062] The output from the status output unit 17 may be, for example, displayed on a display device (e.g., a liquid crystal display or an organic EL display), turned on or blinked on a lamp, transmitted via a communication line to a predetermined device, outputted as audio by a speaker, printed by a printer, stored on a recording medium, or transferred to another component. The status output unit 17 may or may not include a device that performs the output (e.g., a display device, a communication device, a speaker, etc.). Furthermore, the status output unit 17 may be implemented by hardware, or by software such as a driver that drives those devices.

[0063] For example, the first output may indicate that user 5 is not in the authentication area R2, the second output may indicate that the system is waiting for a predetermined process to be completed, and the third output may indicate that the predetermined process has been completed. By providing such outputs, user 5 can be informed of the progress of the device authentication, area determination, and execution of the predetermined process. For example, the first output may also be an output recommending that user 5 move to the authentication area R2 if they wish to execute the predetermined process. Then, in response to this output, user 5 may move to the authentication area R2, and after the area determination determines that the location of the device to be authenticated 2 is included in the authentication area R2, the output unit 16 may provide an output regarding the execution of the predetermined process.

[0064] The status output unit 17 may, for example, display strings or graphics indicating the content on a display device, output audio indicating the content from a speaker, or transmit information indicating the content to the authenticated device 2. The status output unit 17 may, for example, perform the first to third outputs using two or more output devices. As an example, the status output unit 17 may display the first output on a display device, output the second output as audio from a speaker, and transmit the third output to the authenticated device 2 via a communication device. The method of output is not limited as long as the user 5 can understand which of the first to third outputs is being performed.

[0065] If the first to third outputs are transmissions of information to the device being authenticated 2, the device being authenticated 2 may output information corresponding to the received information. For example, when the device being authenticated 2 receives information corresponding to the first output, it may vibrate itself; when it receives information corresponding to the second output, it may output a corresponding sound; and when it receives information corresponding to the third output, it may output a corresponding sound.

[0066] Furthermore, the first to third outputs may each be the illumination of lamps of different colors. As shown in Figure 3, if the predetermined process is payment for the purchase of goods in the vending machine 50, the first to third outputs may be, for example, the illumination of the first to third lamps 41 to 43. For example, the first output may be the illumination of the first red lamp 41, the second output may be the illumination of the second green lamp 42, and the third output may be the illumination of the third blue lamp 43.

[0067] Next, the operation of authentication device 1 will be explained using the flowchart in Figure 4.

[0068] (Step S101) The first and second receiver sets 11 and 12 determine whether they have received an authentication request. If they have received an authentication request, they proceed to step S102; otherwise, they repeat the process in step S101 until they receive an authentication request.

[0069] Furthermore, if device authentication is performed using multiple authentication requests, the process of receiving authentication requests in step S101 may be repeated until all of the multiple authentication requests have been received. After all of the multiple authentication requests have been received, the process may proceed to step S102.

[0070] (Step S102) The device authentication unit 13 performs device authentication using the authentication request received by one of the receivers of the first and second receiver sets 11 and 12.

[0071] (Step S103) In the device authentication in step S102, if the device to be authenticated 2 that sent the authentication request is determined to be legitimate, proceed to step S104; otherwise, return to step S101.

[0072] (Step S104) The identification unit 14 identifies the location of the device to be authenticated 2 using the authentication requests received by the first and second receiver sets 11 and 12. If multiple authentication requests are received, the location of the device to be authenticated 2 may be identified using the authentication request received at the latest time, for example, the last authentication request received.

[0073] (Step S105) The area determination unit 15 performs an area determination to determine whether the location of the device to be authenticated 2, which was identified in step S104, is included in the pre-set authentication area R2.

[0074] (Step S106) In the area determination in step S105, if it is determined that the location of the device to be authenticated 2 is included in the authentication area R2, proceed to step S108; otherwise, proceed to step S107.

[0075] Furthermore, if, in device authentication, the device under authentication 2 is determined to be legitimate, and in the area determination, it is determined that the location of the device under authentication 2 is within the authentication area R2 for a predetermined time from the reference point, and output regarding the execution of a predetermined process is generated, then in step S106, it may be determined whether the area determination has determined that the location of the device under authentication 2 is within the authentication area R2 for a predetermined time from the reference point. In this case, the history of the area determination, which is a pair of the time of reception of the authentication request and the result of the area determination related to that authentication request, may be stored on a recording medium (not shown), and this history may be used to determine whether the location of the device under authentication 2 is within the authentication area R2 for a predetermined time from the reference point. Also, if this determination is made, the first output may indicate that the device under authentication 2 is determined to be legitimate, and that the area determination has not determined that the location of the device under authentication 2 is within the authentication area R2 for a predetermined time from the reference point. Also, if this determination is made, it may be output to the user 5 that the predetermined process will not be performed because the device leaves the authentication area R2 before the predetermined time from the reference point is exceeded. This output may be performed, for example, by the status output unit 17. Furthermore, in this case, it is preferable that device authentication is repeated each time an authentication request is received from a device under authentication 2. Note that, for example, after a device authentication for the first authentication request received from a device under authentication 2 determines it to be valid, device authentication may not be performed for subsequent authentication requests sent from that device under authentication 2; only domain determination may be performed.

[0076] (Step S107) The status output unit 17 outputs the first output. Then, the process returns to step S101.

[0077] (Step S108) The status output unit 17 outputs a second output.

[0078] (Step S109) The output unit 16 outputs information regarding the execution of a predetermined process. For example, the execution unit 51 may execute the predetermined process in response to this output, or the execution unit 51 may become ready to execute the predetermined process in response to this output, and then the predetermined process may be executed in response to the user 5 performing a predetermined operation such as selecting a product.

[0079] (Step S110) The status output unit 17 determines whether the execution of the predetermined process has been completed. If the execution of the predetermined process has been completed, the process proceeds to step S111; otherwise, the process in step S110 is repeated until the execution of the predetermined process is completed. The status output unit 17 may also determine that the execution of the predetermined process has been completed when it receives confirmation from the execution unit 51 that the execution of the predetermined process has been completed. Furthermore, if no confirmation of completion of the predetermined process is received after a predetermined time has elapsed since output regarding the execution of the predetermined process was made, the status output unit 17 may determine that a timeout has occurred and return to step S101.

[0080] (Step S111) The status output unit 17 outputs a third output. Then, the process returns to step S101.

[0081] Note that the series of processes shown in the flowchart of Figure 4 are processes using an authentication request sent from one authenticated device 2. If authentication requests are sent from multiple authenticated devices 2, the series of processes shown in the flowchart of Figure 4 may be executed in parallel for each of the multiple authenticated devices 2. Also, the order of processes in the flowchart of Figure 4 is just an example, and the order of each step may be changed if the same result can be obtained. Furthermore, in the flowchart of Figure 4, the process may be terminated by power off or processing termination interrupt.

[0082] Next, the operation of the authentication device 1 according to this embodiment will be explained using a specific example. In this example, the predetermined process is assumed to be the payment process in the vending machine 50 shown in Figure 3, that is, the payment process for purchasing goods. In this example, the authentication device 1 is included inside the vending machine 50. In this example, as shown in Figure 3, an authentication area R2 is set in front of the vending machine 50, and the user 5 can visually recognize it.

[0083] First, let's assume that user 5, who is carrying a legitimate device to be authenticated 2, approaches the vending machine 50. Then, the device to be authenticated 2 receives a beacon transmitted from the authentication device 1 inside the vending machine 50, and in response, the device to be authenticated 2 sends an authentication request. At this point, let's assume that user 5 is located outside the authentication area R2. The authentication request is received by the first and second receiver sets 11 and 12 of the authentication device 1, and the authentication request is passed to the device authentication unit 13. At the same time, the received signal strengths of the authentication request from the multiple first receivers 11a of the first receiver set 11 and the received signal strengths of the authentication request from the multiple second receivers 12a of the second receiver set 12 are passed to the identification unit 14 (step S101).

[0084] When the device authentication unit 13 receives an authentication request, it performs device authentication using the authentication information contained in the authentication request (step S102). Based on this device authentication, it is determined that the device to be authenticated 2 is legitimate (step S103). Then, the device authentication unit 13 sends a message to the output unit 16 indicating that the device to be authenticated 2 is legitimate.

[0085] Upon receiving the received signal strength, the identification unit 14 obtains representative values ​​of the received signal strength acquired by a plurality of first receivers 11a and representative values ​​of the received signal strength acquired by a plurality of second receivers 12a. Using the difference between these representative values ​​of the received signal strength and the first and second positions, which are the positions of the first and second receiver sets 11 and 12, the identification unit 14 identifies the location of the device to be authenticated 2 and passes it to the area determination unit 15 (step S104).

[0086] Upon receiving the identified location of the device to be authenticated 2, the area determination unit 15 performs an area determination to determine whether that location is included in the authentication area R2 (step S105). If this area determination determines that the location of the device to be authenticated 2 is not included in the authentication area R2 (step S106), the area determination unit 15 then sends a message to the output unit 16 indicating that the location of the device to be authenticated 2 is not included in the authentication area R2.

[0087] Upon receiving the device authentication result and the area determination result, the output unit 16 passes the device authentication result and the area determination result to the status output unit 17. The status output unit 17 then lights up the red first lamp 41 accordingly (step S107). Furthermore, since the output unit 16 has determined that the location of the device to be authenticated 2 is not included in the authentication area R2, it does not output any information regarding the execution of the payment process. As a result, the execution unit 51 does not execute the predetermined process. In addition, the user 5 can learn from the lighting of the red first lamp 41 that he is not in the authentication area R2 and therefore cannot purchase goods from the vending machine 50.

[0088] Next, let's assume that user 5 enters the authentication area R2. Then, similar to the process described above, the device authentication is deemed valid, and in this case, the area determination also determines that the location of the device to be authenticated 2 is included in the authentication area R2 (steps S101 to S106). Based on these determination results, the output unit 16 passes the device authentication result and the area determination result to the status output unit 17. Upon receiving the device authentication result and the area determination result, the status output unit 17 turns off the red first lamp 41 and turns on the green second lamp 42 accordingly (step S108). In this way, user 5 is informed that they can purchase goods from the vending machine 50. The output unit 16 also outputs information regarding the execution of the payment process to the execution unit 51 of the vending machine 50 (step S109). In this case, the execution unit 51 may perform payment processing for user 5, i.e., charging for the product selected by user 5, after output related to the execution of payment processing has been made by the output unit 16, and when user 5 presses a button to select a product on the vending machine 50. This charging may be done using, for example, a pre-configured credit card or electronic money.

[0089] When the execution unit 51 completes the payment process, it sends a message to the status output unit 17 indicating that the payment process is complete. Upon receiving the message that the payment process is complete (step S110), the status output unit 17 turns off the green second lamp 42 and turns on the blue third lamp 43 (step S111). In this way, the user 5 is able to know that the payment has been completed.

[0090] For example, if another person is standing in front of the vending machine 50, user 5 can avoid being charged for the product selected by that person by not entering the authentication area R2.

[0091] As described above, with the authentication device 1 according to this embodiment, a predetermined process is executed when the location of the device to be authenticated 2, which is determined to be legitimate in device authentication, is included in the authentication area R2. For example, by preventing user 5, who is carrying a legitimate device to be authenticated 2, from entering the authentication area R2 shown on the floor, it is possible to avoid the execution of predetermined processes such as payment processing in situations unintended by user 5. On the other hand, since a predetermined process is executed when user 5 is in the authentication area R2, user 5 can also perform predetermined processes hands-free without operating the device to be authenticated 2 or the like.

[0092] Furthermore, the status output unit 17 outputs the first to third outputs, allowing the user 5 to know whether a predetermined process can be executed and the status of the execution of the predetermined process through these outputs.

[0093] In this embodiment, we have described a case in which output regarding the execution of a predetermined process is output when the device is determined to be legitimate in device authentication and the location of the device under authentication 2 is determined to be included in the authentication area R2 in the area determination. However, this is not required. For example, the output unit 16 may output regarding the execution of a predetermined process when the device under authentication 2 is determined to be legitimate in device authentication and the location of only the device under authentication 2 is determined to be included in the authentication area R2 in the area determination. In this case, if the location of the device under authentication 2 is determined to be included in the authentication area R2, output regarding the execution of a predetermined process does not need to be output. This is because if the location of the device under authentication 2 is included in the authentication area R2, and both of the two or more devices under authentication 2 are determined to be legitimate in device authentication, it becomes unclear which device under authentication 2 the predetermined process will be performed on. Furthermore, even if, among two or more authenticated devices 2, only one authenticated device 2 is determined to be legitimate in device authentication, it may be unclear whether the user 5 carrying that legitimate authenticated device 2 is in the authentication area R2 of their own free will. Therefore, output regarding the execution of a predetermined process may not be required.

[0094] Furthermore, the status output unit 17 may, for example, output a fourth output when the area determination unit 15 determines that the locations of two or more authenticated devices 2 are included in the authentication area R2. In this case, the user 5 can, for example, learn from the fourth output that the predetermined process will not be executed because the locations of two or more authenticated devices 2 are included in the authentication area R2. The fourth output may be similar to the first to third outputs, except that the first to fourth outputs are all different outputs, such as being displayed on a display device, outputting audio from a speaker, or transmitting information. For example, the fourth output may be the illumination of an orange fourth lamp.

[0095] Furthermore, in this embodiment, the authentication area R2 may be displayed on the floor surface by, for example, a display unit 21. In this case, as shown in Figure 5, the authentication device 1 may further include, for example, a display unit 21 for displaying the authentication area R2 on the floor surface. The display unit 21 may, as one example, be a projector for displaying an image showing the authentication area R2 on the floor surface. Alternatively, the display unit 21 may be a display placed on the floor surface. Preferably, this display has sufficient strength for the user 5 to stand on.

[0096] The display unit 21 may or may not include a display device (for example, a projector or liquid crystal display) that displays the authentication area R2. Furthermore, the display unit 21 may be implemented by hardware or by software such as a driver for the display device.

[0097] Furthermore, if the authentication area R2 is displayed on the floor, the display unit 21 may, for example, change the display position of the authentication area R2. In this case, information indicating the current position of the authentication area R2 may be passed from the display unit 21 to the area determination unit 15. The area determination unit 15 may then use the current position of the authentication area R2 received from the display unit 21 to determine whether the position of the identified device to be authenticated 2 is included in the authentication area R2.

[0098] For example, the display unit 21 may change the display of the authentication area R2 so that the size of the authentication area R2 becomes smaller when there are many people near the authentication area R2, and change the display of the authentication area R2 so that the size of the authentication area R2 becomes larger when there are few people near the authentication area R2. If the authentication device 1 is further equipped with a sensor 31 and a people acquisition unit 32, which will be described later, the display unit 21 may change the display of the authentication area so that the number of people included in the authentication area R2 acquired by the people acquisition unit 32 is one or less.

[0099] As another example, the display unit 21 may display the authentication area R2 in a location that does not include the current position of the device under authentication 2 when the device under authentication is determined to be legitimate. The display unit 21 may, for example, obtain the position of the device under authentication 2 from the identification unit 14. In this way, when user 5 enters the authentication area R2, that is, when user 5 wishes to execute a predetermined process, that predetermined process will be executed.

[0100] Furthermore, in this embodiment, it is possible to determine whether user 5 is present in the authentication area R2 using a method other than the authentication request transmitted from the device being authenticated 2. In this case, as shown in Figure 6, the authentication device 1 may further include a sensor 31 that acquires information about the authentication area R2, and a person acquisition unit 32 that uses the information acquired by the sensor 31 to acquire the number of people present in the authentication area R2. The sensor 31 may be, for example, a weight sensor that acquires the weight in the authentication area R2, or an image sensor that acquires an image of the authentication area R2. The weight in the authentication area R2 may be, for example, the weight of objects present in the authentication area R2. Also, the sensor 31 may be a sensor other than a weight sensor or an image sensor, such as a range sensor such as LiDAR.

[0101] If sensor 31 is a weight sensor, the person acquisition unit 32 may, for example, use the quotient obtained by dividing the weight acquired by the weight sensor by a standard weight per person (e.g., 50 kg), that is, the value obtained by truncating the decimal part of the result of the division, as the number of people present in the authentication area R2.

[0102] If sensor 31 is an image sensor, the person acquisition unit 32 may detect people in the area corresponding to the authentication region R2 in the captured image acquired by the image sensor, and the number of people detected may be taken as the number of people present in the authentication region R2.

[0103] In this case, the output unit 16 may output information regarding the execution of a predetermined process when the device to be authenticated 2 is determined to be legitimate in the device authentication, the location of the device to be authenticated 2 is determined to be included in the authentication area R2 in the area determination, and the number of people obtained by the person acquisition unit 32 is 1.

[0104] By doing so, it is possible to confirm the presence of user 5 in the authentication area R2 using information obtained by sensor 31, so that the predetermined process is executed only when user 5 is definitely present in the authentication area R2. Furthermore, it is possible to prevent the predetermined process from being executed if two or more people are present in the authentication area R2.

[0105] Furthermore, when using the sensor 31 and the person acquisition unit 32 to acquire the number of people present in the authentication area R2, the status output unit 17 may, for example, make a first output when the device under authentication 2 is determined to be legitimate in device authentication and the location of the device under authentication 2 is determined not to be included in the authentication area R2 in area determination; make a second output when the device under authentication 2 is determined to be legitimate in device authentication and the location of the device under authentication 2 is determined to be included in the authentication area R2 in area determination, the number of people acquired by the person acquisition unit 32 is 1, and the execution of a predetermined process has not been completed; make a third output when the execution of a predetermined process has been completed; and make a fourth output when the number of people acquired by the person acquisition unit 32 is 2 or more.

[0106] In this embodiment, the case in which the authentication device 1 has two receiver sets, namely the first and second receiver sets 11 and 12, has been mainly described. However, the authentication device 1 may have three or more receiver sets. That is, the authentication device 1 may have first to N receiver sets, each positioned at the first to Nth positions. N is an integer of 2 or more. The first to Nth receiver sets may be the same as the first and second receiver sets 11 and 12. For example, the Kth receiver set may contain one or more receivers. K is any integer from 1 to N. It is preferable that the first to Nth positions are all different positions. Also, when N is 3 or more, for example, when position determination is made by triangulation, it is preferable that the first to Nth positions do not lie on a single straight line. However, if this is not the case, the first to Nth positions may lie on a single straight line. Furthermore, when N is 4, for example, when determining the position by triangulation, it is preferable that the first to fourth positions are not the vertices of a parallelogram. However, if this is not the case, the first to N positions may be the vertices of a parallelogram. Thus, when the authentication device 1 has first to N sets of receivers, the identification unit 14 may determine the position of the device to be authenticated 2 based on the difference in the intensity of the authentication requests received by each of the first to N sets of receivers. This position determination may be performed, for example, by repeatedly determining Apollonius circles or lines based on the difference in the intensity of the authentication requests received by each of the two sets of receivers in the first to N sets, thereby determining multiple Apollonius circles or lines, and then determining the position on, on, or within the determined Apollonius circles as the position of the device to be authenticated 2.

[0107] Furthermore, in the above embodiment, each process or function may be implemented by centralized processing by a single device or a single system, or by distributed processing by multiple devices or multiple systems.

[0108] Furthermore, in the above embodiment, the exchange of information between each component may, for example, be performed by outputting information from one component and receiving information from the other component if the two components performing the information exchange are physically different, or by moving from the processing phase corresponding to one component to the processing phase corresponding to the other component if the two components performing the information exchange are physically the same.

[0109] Furthermore, in the above embodiment, information related to the processing performed by each component, such as information received, acquired, selected, generated, transmitted, or received by each component, as well as information such as thresholds, formulas, and addresses used by each component in processing, may be temporarily or for a long period of time stored in a recording medium (not shown), even if not explicitly stated in the above description. The storage of information in the recording medium (not shown) may be performed by each component or a storage unit (not shown). The reading of information from the recording medium (not shown) may be performed by each component or a reading unit (not shown).

[0110] Furthermore, in the above embodiment, if the information used in each component, such as thresholds, addresses, and various setting values ​​used by each component in processing, can be changed by the user, then even if not explicitly stated in the above description, the user may be allowed to change such information as appropriate, or not. If the user can change such information, the change may be implemented, for example, by a receiving unit (not shown) that receives change instructions from the user and a changing unit (not shown) that changes the information in response to those change instructions. The receiving unit (not shown) may receive change instructions from an input device, receive information transmitted via a communication line, or receive information read from a predetermined recording medium.

[0111] Furthermore, in the above embodiment, if two or more components included in the authentication device 1 have a communication device, an input device, etc., the two or more components may have a single physical device, or they may have separate devices.

[0112] Furthermore, in the above embodiment, each component may be configured with dedicated hardware, or, if it is a component that can be implemented by software, it may be implemented by executing a program. For example, each component can be implemented by a program execution unit such as a CPU reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. During execution, the program execution unit may execute the program while accessing the storage unit or recording medium. The software that implements the authentication device 1 in the above embodiment is the following program. In other words, this program may be a program that causes a computer to perform the following steps: receiving an authentication request, which includes authentication information used to authenticate the device to be authenticated, transmitted from the device to be authenticated, using a first set of receivers including one or more first receivers; receiving an authentication request transmitted from the device to be authenticated using a second set of receivers including one or more second receivers; performing device authentication, which determines whether the device that sent the authentication request is legitimate, using the authentication information contained in the authentication request received by at least one of the one or more first receivers and one or more second receivers; identifying the location of the device to be authenticated based on the difference in strength of the authentication requests received by the first set of receivers and the second set of receivers, respectively; performing an area determination, which determines whether the identified location of the device to be authenticated is included in the authentication area R2 shown on the floor; and, if the device to be authenticated is determined to be legitimate in the device authentication and the location of the device to be authenticated is determined to be included in the authentication area R2 in the area determination, outputting information regarding the execution of a predetermined process concerning the user carrying the device to be authenticated.

[0113] Furthermore, in the above program, steps such as receiving information and outputting information do not include processes that can only be performed by hardware, such as processes performed by a modem or interface card in the information receiving step.

[0114] Furthermore, this program may be executed by being downloaded from a server or the like, or by being read from a predetermined recording medium (for example, an optical disc such as a CD-ROM, a magnetic disc, or a semiconductor memory). This program may also be used as a program constituting a program product.

[0115] Furthermore, the computer running this program may be a single computer or multiple computers. That is, it may perform centralized processing or distributed processing.

[0116] Figure 7 shows an example of a computer system 900 that executes the above program to realize the authentication device 1 according to the above embodiment. The above embodiment can be realized by computer hardware and a computer program executed thereon.

[0117] In Figure 7, the computer system 900 includes an MPU (Micro Processing Unit) 911, a ROM 912 such as flash memory that stores programs such as boot-up programs, application programs, system programs, and data, a RAM 913 connected to the MPU 911 that temporarily stores instructions for application programs and provides temporary storage space, a touch panel 914, a wireless communication module 915, and a bus 916 that interconnects the MPU 911, ROM 912, etc. The computer system 900 may also include, for example, multiple wireless communication modules 915 corresponding to the first and second receiver sets 11 and 12, or may be connected to multiple wireless communication modules corresponding to the first and second receiver sets 11 and 12. Furthermore, the computer system 900 may include a display and input devices such as a mouse or keyboard instead of the touch panel 914. The computer system 900 may also further include other recording media such as a hard disk.

[0118] The program that causes the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment may be stored in the ROM 912 via the wireless communication module 915. The program is loaded into the RAM 913 when executed. The program may also be loaded directly from the network.

[0119] The program does not necessarily include an operating system (OS) or third-party program that causes the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment. The program may include only the instruction portion that calls appropriate functions or modules in a controlled manner to obtain the desired result. How the computer system 900 operates is well known, and a detailed explanation is omitted.

[0120] Furthermore, the embodiments described above are illustrative examples for specifically carrying out the present invention and do not limit the technical scope of the present invention. The technical scope of the present invention is indicated by the claims rather than by the description of the embodiments, and modifications within the literal scope and equivalent meaning of the claims are intended. [Explanation of symbols]

[0121] 1. Authentication device 11. First receiver set 11a First receiver 12. Second receiver set 12a Second receiver 13. Device Authentication Department 14 Specific section 15 Area judgment section 16 Output section 17 Status Output Unit 21 Display section 31 Sensors 32 Number of people acquisition part

Claims

1. A first receiver set including one or more first receivers that receive an authentication request transmitted from the device to be authenticated, which includes authentication information used for the authentication of the device to be authenticated, A second receiver set including one or more second receivers that receive authentication requests transmitted from the device to be authenticated, A device authentication unit performs device authentication, which determines whether the device to be authenticated that sent the authentication request is legitimate, using authentication information contained in the authentication request received by at least one of the one or more first receivers and the one or more second receivers. A location unit that identifies the location of the device to be authenticated based on the difference in the strength of the authentication requests received by the first and second receiver sets, respectively, An area determination unit performs an area determination to determine whether the location of the device to be authenticated, as identified by the identification unit, is included in the authentication area indicated on the floor, An authentication device comprising: an output unit that outputs a predetermined process relating to the user carrying the authenticated device when, in the device authentication, the authenticated device is determined to be legitimate and, in the area determination, the location of the authenticated device is determined to be included in the authentication area.

2. The authentication device according to claim 1, wherein the authentication area is indicated by a mat placed on the floor.

3. The authentication device according to claim 1, wherein the authentication area is displayed on the floor surface.

4. The authentication device according to claim 3, further comprising a display unit for displaying the authentication area on the floor surface.

5. The authentication device according to claim 4, wherein the display unit changes the display position of the authentication area.

6. The authentication device according to claim 1, wherein the output unit outputs a statement regarding the execution of the predetermined process when the device to be authenticated is determined to be legitimate in the device authentication and when the area determination is determined to be valid and only the location of the device to be authenticated is included in the authentication area.

7. A sensor that acquires information regarding the authentication area, The system further includes a person acquisition unit that acquires the number of people present in the authentication area using information acquired by the aforementioned sensor, The authentication device according to claim 1, wherein the output unit outputs a statement regarding the execution of the predetermined process when the device to be authenticated is determined to be legitimate in the device authentication, the location of the device to be authenticated is determined to be included in the authentication area in the area determination, and the number of people obtained by the number of people acquisition unit is one.

8. The authentication device according to claim 7, wherein the sensor is a weight sensor that acquires weight in the authentication area, or an image sensor that acquires an image of the authentication area.

9. An authentication device according to any one of claims 1 to 8, further comprising a status output unit that performs a first output when the device to be authenticated is determined to be legitimate in the device authentication and the location of the device to be authenticated is determined not to be included in the authentication area in the area determination, a second output when the device to be authenticated is determined to be legitimate in the device authentication and the location of the device to be authenticated is determined to be included in the authentication area in the area determination and the execution of the predetermined process has not been completed, and a third output when the execution of the predetermined process has been completed.

10. The authentication device according to claim 9, wherein the status output unit provides a fourth output when the area determination unit determines that the positions of two or more of the devices to be authenticated are included in the authentication area.

11. The authentication device according to any one of claims 1 to 8, wherein the predetermined process is a payment process.

12. The authentication device according to any one of claims 1 to 8, wherein the predetermined process is an unlocking process.

13. An authentication method that processes data using a first receiver set including one or more first receivers, a second receiver set including one or more second receivers, a device authentication unit, a specification unit, a region determination unit, and an output unit, The first set of receivers includes one or more first receivers that receive an authentication request transmitted from the device to be authenticated, which includes authentication information used for authenticating the device to be authenticated. The steps include: one or more second receivers included in the second receiver set receive an authentication request transmitted from the device to be authenticated; The device authentication unit performs device authentication by determining whether the device to be authenticated that sent the authentication request is legitimate, using the authentication information contained in the authentication request received by at least one of the one or more first receivers and the one or more second receivers. The identifying unit determines the location of the device to be authenticated based on the difference in the strength of the authentication requests received by the first and second receiver sets, respectively. The area determination unit performs an area determination to determine whether the identified location of the device to be authenticated is included in the authentication area indicated on the floor, Authentication method comprising the step of outputting a predetermined process relating to the user carrying the authenticated device when the output unit determines that the authenticated device is legitimate in the device authentication and determines that the location of the authenticated device is included in the authentication area in the area determination.

14. On the computer, A first set of receivers, including one or more first receivers, receives an authentication request transmitted from the device to be authenticated, which includes authentication information used for the authentication of the device to be authenticated. The steps include receiving the authentication request transmitted from the device to be authenticated by a second receiver set including one or more second receivers, A step of performing device authentication to determine whether the device to be authenticated that sent the authentication request is legitimate, using authentication information contained in the authentication request received by at least one of the one or more first receivers and the one or more second receivers; The steps include determining the location of the device to be authenticated based on the difference in the strength of the authentication requests received by the first receiver set and the second receiver set, respectively, The steps include: performing a region determination to determine whether the identified location of the device to be authenticated is included in the authentication area indicated on the floor; A program for performing the following steps: when, in the device authentication, the device to be authenticated is determined to be legitimate, and in the area determination, the location of the device to be authenticated is determined to be included in the authentication area, the program outputs a result relating to the execution of a predetermined process concerning the user carrying the device to be authenticated.