Access permission system and access permission method
By storing additional URLs on the storage medium, including encrypted authentication codes, decryption matching is performed when the user terminal accesses, the problem of not being able to access a specific website only through a specific storage medium in the prior art is solved, and the security and functional flexibility of the website are achieved.
Patent Information
- Application Number
- JP2024171883
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2044-09-30
AI Technical Summary
The prior art is difficult to realize the mechanism of accessing specific websites only through specific storage media, resulting in the inability to effectively utilize the website for marketing promotion, mobile orders and other functions.
By storing an additional URL on the storage medium, the URL contains an encrypted authentication code as a parameter, and decryption matches are performed when accessed by the user terminal, ensuring that the target website can only be accessed through a specific storage medium.
It realizes the ability to access specific websites only through specific storage media, enhances the security and flexibility of the website, and supports marketing and mobile orders.
Smart Images

Figure 0007673901000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an access permission system and an access permission method. [Background technology]
[0002] Conventionally, there are many types of technologies that allow only specific users to access a specific web service when the user accesses the service. For example, Japanese Patent Application Laid-Open No. 2018-151795 (Patent Document 1) discloses a web service providing system including a web service providing unit and an authentication unit. Here, the web service providing unit provides a web service to an authenticated user. The authentication unit performs a user authentication process, assigns different identification information to each authenticated user, and transmits the identification information assigned to the user to a user terminal used by the user to receive the desired web service to a web service providing unit that provides the web service desired by the user. The web service providing unit identifies the authentication status of the user using the identification information received from the user terminal, and allows the user to use the web service provided by the web service providing unit if the user has been authenticated. This makes it possible to realize single sign-on at a lower cost.
[0003] Also, Japanese Patent Laid-Open Publication No. 2006-079598 (Patent Document 2) discloses an access control system including an access code generating means, an authentication information notifying means, and an access control means. Here, the access code generating means generates an access code in association with information related to the addresses of one or more access grantees who are permitted to access. The authentication information notifying means receives an access code from the access grantee, and notifies predetermined authentication information to the address of the access grantee obtained based on the access code. The access control means receives the authentication information from the access grantee, and permits access by the access grantee on the condition that the authentication information corresponds to the authentication information notified by the authentication information notifying means. This makes it possible to reliably authenticate whether or not the access request is from a legitimate access grantee.
[0004] Also, Japanese Patent Laid-Open Publication No. 2002-259838 (Patent Document 3) discloses a system for supplying provided information including viewing permission information, which includes a viewing permission information management device, an information providing device, and a user terminal device. Here, the viewing permission information management device generates viewing permission information in response to a request, and records information acquired in relation to the generation of the viewing permission information and information generated in relation to the generation. The information providing device has provided information including the viewing permission information generated by the viewing permission information management device, and provides the provided information to the user terminal device in response to a request from the user terminal device. When the user terminal device receives the provided information, it determines whether or not playback of the provided information is permitted based on the viewing permission information included in the provided information, and if it is determined that playback of the provided information is permitted, it executes playback of the provided information. As a result, by using the viewing permission information in which the viewing permission conditions are described, it is possible to make the user terminal device autonomously determine whether or not playback of the provided information is permitted without inquiring of a special management device or other database servers as to whether or not the viewing permission conditions are satisfied.
[0005] In addition, JP 2024-017815 A (Patent Document 4) discloses a service providing system including an NFC tag sheet and a server. Here, the NFC tag sheet is installed around one's seat at an event venue, and multiple NFC reading units are arranged side by side, each of which is visibly displayed. The server provides different services, each of which includes a web page display corresponding to each connection destination information, to a user's terminal that has acquired connection destination information from the NFC reading unit by short-range wireless communication. This is said to facilitate access to the service.
[0006] Furthermore, Japanese Patent Application Laid-Open No. 2014-157564 (Patent Document 5) discloses an order receiving device including a communication means, an order receiving means, an identification acquisition means, an order sending means, a writing means, a reading means, an order receiving means, a display means, and a confirmation means. Here, the communication means performs data communication with a server that manages order data. The order receiving means accepts an input of a menu item ordered by a customer from among a plurality of menu items that are to be ordered. The identification acquisition means acquires order identification information for identifying the order data of the menu item whose input is accepted by the order receiving means. The order sending means transmits the order data of the menu item whose input is accepted by the order receiving means to the server via the communication means, in association with the order identification information acquired by the identification acquisition means. The writing means writes the order identification information acquired by the identification acquisition means to a portable storage medium. The reading means reads the order identification information from the storage medium. The order receiving means receives from the server via the communication means the order data managed in association with the order identification information read from the storage medium by the reading means. The display means displays the order data received by the order receiving means on the display unit. The confirmation means confirms the order data displayed on the display unit. This makes it possible to notify the server managing the order data of the menu items that the customer has decided to order by utilizing the waiting time.
[0007] Also, JP 2019-079293 A (Patent Document 6) discloses a service application issuing system including a mobile terminal, an IC card, and an installer. Here, the mobile terminal includes a camera unit and an NFC unit. The installer is installed in the mobile terminal, and installs a service application that emulates the operation of an IC card selected by a user in the mobile terminal. The IC card has a contactless communication function. The camera unit captures an image of the IC card to obtain information about the user written on the outer surface of the IC card. The contactless R / W function of the NFC unit obtains issuance data for a service application that activates the service application from the IC card. The obtained information is supplied to the installer to activate the service application. As a result, when issuing a service to a mobile terminal such as a smartphone, there is no need to build a server system, and there is no risk of information leakage.
[0008] In addition, JP 2022-172003 A (Patent Document 7) discloses a product purchasing system including a terminal device and a site management server that manages a shopping site. Here, the terminal device includes a reading unit and a transmission unit. The reading unit reads access information and medium identification information for accessing the site management server from the recording medium. The transmission unit accesses the site management server according to the access information and transmits the medium identification information to the site management server. The site management server includes a display content determination unit and a site provision unit. The display content determination unit determines the display content of the shopping site based on the medium identification information received from the terminal device. The site provision unit provides the terminal device with a shopping site with the display content determined by the display content determination unit. This allows the user to easily use the system.
[0009] Furthermore, Japanese Patent Application Laid-Open No. 2015-194867 (Patent Document 8) discloses a communication terminal including a reading unit, an authentication request unit, and a registration unit. Here, the reading unit reads the URL and authentication information from a membership card on which the URL and authentication information are stored. When the reading unit reads the URL and authentication information, the authentication request unit accesses the site indicated by the URL and transmits the authentication information to execute authentication processing. The registration unit registers the identification information of the terminal itself on the site. If the identification information is registered on the site, the authentication request unit executes authentication processing using the registered identification information instead of the authentication information. This allows the communication terminal to easily access a specific site and improves the security of authentication. [Prior art documents] [Patent documents]
[0010] [Patent Document 1] JP 2018-151795 A [Patent Document 2] JP 2006-079598 A [Patent Document 3] JP 2002-259838 A [Patent Document 4] JP 2024-017815 A [Patent Document 5] JP 2014-157564 A [Patent Document 6] JP 2019-079293 A [Patent Document 7] Patent Publication No. 2022-172003 [Patent Document 8] JP 2015-194867 A Summary of the Invention [Problem to be solved by the invention]
[0011] In recent years, there has been a technology that allows access to a website with a specific URL (Uniform Resource Locator) by using a storage medium such as an NFC (Near Field Communication) tag, a QR code (registered trademark), a two-dimensional barcode, etc. For example, when a user holds a user terminal over a specific storage medium, the user terminal obtains a URL that is pre-stored in the storage medium, and accesses the website based on the URL.
[0012] Here, it is generally important for URL's website to implement SEO (Search Engine Optimization) and MEO (Map Engine Optimization) measures. Also, from a marketing perspective, it is important to link URL's website to SNS (Social Networking Service) to increase awareness of restaurants, service stores, and other stores. Furthermore, it is also important for URL's website to create limited-time menus and post store services and photos to promote the store's appeal and encourage customers to become fans.
[0013] On the other hand, there is a need for stores to allow only user terminals connected to a specific storage medium installed at the store to view a specific website. For example, the store can post content on the specific website according to the season or period, or include content that cannot be accessed from outside, making the user feel special. In addition, since the specific website cannot be accessed by users from outside, it can be used as a menu on the store side, and can also be used as a mobile order system where users can come to the store and place orders and make payments with the store from their own user terminals. For this reason, a mechanism is required that allows only user terminals connected to a specific storage medium to access a specific website.
[0014] However, generally, when a user terminal has accessed a website once, the URL of the website remains in the user terminal as an access history. This poses the problem that the above-mentioned system cannot be built simply by accessing a website based on the URL. In other words, since a user terminal can access a website that it has already accessed once again, it is difficult for stores to easily use marketing, promotions, mobile orders, etc. that utilize websites.
[0015] Here, in the technology described in Patent Document 1, the use of a web service is permitted by user authentication. In the technology described in Patent Document 2, access is permitted for a legitimate accessor by authentication information. In the technology described in Patent Document 3, if the conditions for viewing permission are met, viewing is permitted to a user terminal device. In the technology described in Patent Document 4, different services are provided by an NFC tag sheet, which correspond to each connection destination information and accompany the display of a web page. In the technology described in Patent Document 5, data on a menu item that a customer has decided to order is notified by utilizing waiting time. In the technology described in Patent Document 6, issuance data for a service application is obtained from an IC card. In the technology described in Patent Document 7, a shopping site with display contents determined by a display content determination unit is provided to a terminal device. In the technology described in Patent Document 8, authentication processing is performed by registered identification information instead of authentication information. As described above, the technologies described in Patent Documents 1-8 do not consider the viewpoint that only a user terminal via a specific storage medium can access a specific website, and the above-mentioned problem cannot be solved.
[0016] Therefore, the present invention has been made to solve the above-mentioned problems, and has an object to provide an access permission system and an access permission method that can permit access only to a website via a specific storage medium. [Means for solving the problem]
[0017] The access permission system according to the present invention includes a storage medium, a first determination control unit, a first error control unit, a second determination control unit, a second error control unit, a transfer control unit, and a third error control unit. The storage medium stores an additional URL in which an encryption code obtained by encrypting an authentication code is added to an authentication URL as a parameter. When a user terminal reads the additional URL in the storage medium and accesses the authentication URL of the additional URL, the first determination control unit determines whether or not the encryption code is added to the authentication URL. When the result of the determination indicates that the encryption code is not added to the authentication URL, the first error control unit displays an error screen. When the result of the determination indicates that the encryption code is added to the authentication URL, the second determination control unit decrypts the additional encryption code added to the authentication URL and determines whether or not the decrypted decrypted code matches a registered authentication code associated with a registered authentication URL in a predetermined registration table. When the result of the determination indicates that the decrypted code does not match the registered authentication code, the second error control unit displays an error screen. When the result of the determination indicates that the decryption code matches the registered authentication code, the transfer control unit transfers the user terminal to a target URL to access the URL. A third error control unit displays an error screen when the user terminal accesses the target URL without going through the authentication URL.
[0018] Also, an access permission method according to the present invention includes a storage medium, a first determination control step, a first error control step, a second determination control step, a second error control step, a transfer control step, and a third error control step, where each control step of the access permission method corresponds to each control unit of the access permission system. Effect of the Invention
[0019] According to the present invention, it is possible to permit access to a website only via a specific storage medium. [Brief description of the drawings]
[0020] [Figure 1]1 is a functional block diagram of an access permission system according to the present invention; [Diagram 2] 4 is a flowchart showing an execution procedure of the access permission system according to the present invention. [Diagram 3] FIG. 3A shows an example of setting an authentication URL from a target URL and generating an authentication code, and FIG. 3B shows an example of encrypting the authentication code and generating an additional URL using the encrypted code. [Figure 4] FIG. 4A is a diagram showing an example of a registration table, and FIG. 4B is a diagram showing an example of a case where an administrator stores an additional URL in a storage medium. [Diagram 5] FIG. 5A shows an example of a case where a consumer reads an additional URL from a store's storage medium and accesses an authentication URL, and FIG. 5B shows an example of a case where no encryption code has been added to the authentication URL. [Figure 6] FIG. 6A shows an example of a case where an encrypted code is added to an authentication URL, and FIG. 6B shows an example of a case where the decrypted code does not match the registered authentication code. [Figure 7] FIG. 7A shows an example of a case where the decrypted code matches the registered authentication code, and FIG. 7B shows an example of an order screen. [Figure 8] FIG. 8A shows an example of a payment screen, and FIG. 8B shows an example of a case where a user terminal accesses a target URL without going through an authentication URL. [Figure 9] FIG. 9A shows an example of setting a target URL for each table and installing a storage medium for each table, and FIG. 9B shows an example of a case where a consumer reads an additional URL from the storage medium of the first table. [Figure 10] FIG. 10A shows an example of adding an encryption code and an identification code to an authentication URL and of installing a storage medium for each table, and FIG. 10B shows an example of a case where a consumer reads the added URL from the storage medium of the first table. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0021] Hereinafter, an embodiment of the present invention will be described with reference to the accompanying drawings to help the understanding of the present invention. Note that the following embodiment is an example of the present invention and is not intended to limit the technical scope of the present invention.
[0022] As shown in FIG. 1, an access permission system 1 according to an embodiment of the present invention includes a management terminal 10, a user terminal 11, a storage medium 12, a network 13, and a server 14.
[0023] Here, the management terminal 10 and the user terminal 11 are generally used computers and the like, and are equipped with, for example, a display unit (output unit) for displaying a screen (window), a reception unit (input unit) for receiving input of a predetermined instruction by a user's operation, a communication unit for wireless or wired communication, a storage unit for storing data, and a processing unit for controlling each unit. Here, the reception unit is capable of reading data stored in a storage medium 12, for example. Also, the communication units of the management terminal 10 and the user terminal 11 are capable of communicating with a server 14 via a network 13, for example.
[0024] Moreover, for example, a desktop terminal device can be cited as the administrator terminal 10. Furthermore, for example, a portable terminal device such as a mobile terminal device (smartphone) with a touch panel, a tablet terminal device, or the like can be cited as the user terminal 11.
[0025] Furthermore, the storage medium 12 stores data that can be read by the user terminal 11. There are no particular limitations on the configuration of the storage medium 12, but examples of the configuration include an NFC tag, a QR code (registered trademark), and a two-dimensional barcode.
[0026] The network 13 is communicably connected to each of the management terminal 10, the user terminal 11, and the server 14. The network 13 includes wireless communication networks such as Wi-Fi (registered trademark), a LAN (Local Area Network) via an access point, a WAN (Wide Area Network) via a wireless base station, a third generation (3G) communication method, a fourth generation (4G) communication method such as LTE, a fifth generation (5G) or later communication method, Bluetooth (registered trademark), and a specific low power wireless method.
[0027] The server 14 is a commonly used computer or the like, and includes, for example, a communication unit for wireless and wired communication, a storage unit for storing data, and a processing unit for controlling each unit. The server 14 mainly transmits and receives data to and from the management terminal 10 and the user terminal 11 via the network 13. Here, the server 14 may also serve as a different server 15, or may cooperate with a different server 15.
[0028] The management terminal 10, the user terminal 11, and the server 14 each incorporate a CPU, ROM, RAM, SSD, etc. (not shown), and the CPU uses, for example, the RAM as a working area to execute programs stored in the ROM, SSD, etc. The CPU also executes programs to realize the functions of each control unit, which will be described later.
[0029] Next, the configuration and execution procedure according to an embodiment of the present invention will be described with reference to Figures 1 to 10. For example, a user (requester) of a store such as a restaurant or a service store provides a target URL (hereinafter referred to as a "target URL"; for example, "https: / / abc") of a website that the user wishes to access at that store to an administrator of the access permission system 1, as shown in Figure 3A.
[0030] Here, the user can be, for example, a store manager, owner, or business owner. The target URL is the URL of a website that the user wants consumers or traders (so-called users) to access. The target URL can be, for example, the URL of a store's ordering site or checkout site.
[0031] Then, the administrator uses the provided target URL ("https: / / abc") to create an authentication URL (for example, "https: / / abc / def") that the user terminal 11 will access first (FIG. 2: S101).
[0032] Here, there is no particular limitation on the method for creating the authentication URL, but for example, the administrator can use the management terminal 10 to create the authentication URL by adding a character string (e.g., "def") indicating the access destination to the server 14 to the target URL ("https: / / abc"). Here, the created authentication URL ("https: / / abc / def") is set, for example, as the access destination to the server 14. Therefore, the access destination of the target URL ("https: / / abc") and the access destination of the authentication URL ("https: / / abc / def") may be different.
[0033] Next, when the administrator accesses server 14 from management terminal 10 via network 13 based on the authentication URL ("https: / / abc / def"), generation control unit 101 of server 14 accepts the access from management terminal 10. Then, when the administrator uses management terminal 10 to instruct server 14 to encrypt an authentication code and generate an additional URL, generation control unit 101 generates an authentication code and encrypts the authentication code (FIG. 2: S102).
[0034] Here, the method of generating the authentication code by the generation control unit 101 is not particularly limited, but for example, a random character string (e.g., "ab01") may be generated as the authentication code regardless of the authentication URL ("https: / / abc / def"), or the authentication URL ("https: / / abc / def") may be input into a specified code generation unit, and a character string ("ab01") output from the code generation unit may be generated as the authentication code.
[0035] Now, when the generation control unit 101 generates the authentication code ("ab01"), it encrypts the authentication code (FIG. 2: S103).
[0036] Here, the encryption method of the authentication code by the generation control unit 101 is not particularly limited, but for example, as shown in FIG. 3B, the authentication code ("ab01") is encrypted using a predetermined encryption generation unit to generate an encryption code (for example, "xyz012") by encrypting the authentication code ("ab01"). Here, the encryption method of the encryption generation unit is not particularly limited, but for example, , dark The encoding function can be given.
[0037] Now, when the generation control unit 101 generates the encrypted code, it generates an additional URL (for example, "https: / / abc / def / ?pm=xyz012") by adding the encrypted code ("xyz012") to the authentication URL ("https: / / abc / def") as an encryption parameter (Figure 2: S104).
[0038] Here, the method of generating the additional URL by the generation control unit 101 is not particularly limited, but for example, an encryption code ("xyz012") is added to the authentication URL ("https: / / abc / def") as an encryption parameter to generate an additional URL ("https: / / abc / def / ?pm=xyz012"). When the encryption code is added to the additional URL as an encryption parameter, a specific symbol (for example, "?") is set to the end of the authentication URL, and a specific symbol (for example, "pm") indicating the encryption parameter is set, and for example, "?pm=xyz012" is added to the end of the authentication URL. This makes it possible to add the encryption code to the authentication URL as an encryption parameter.
[0039] Furthermore, parameters added to a URL can generally be viewed when a user accesses the URL using the user terminal 10. Therefore, in the present invention, by making the parameters an encrypted code, even if the user views the encrypted code, this encrypted code is meaningless unless decrypted, so that the authentication code will not be leaked to the user, thereby improving security.
[0040] The added URL is also called, for example, a parameter-attached URL. The symbol indicating the encryption parameter is appropriately designed and changed depending on the type of the encryption parameter. For example, if the encryption code is a hash value, the symbol indicating the encryption parameter may be "hash."
[0041] Then, the generation control unit 101 transmits the additional URL ("https: / / abc / def / ?pm=xyz012") to the management terminal 10, and the management terminal 10 notifies the administrator of the additional URL ("https: / / abc / def / ?pm=xyz012"), whereby the administrator can obtain the additional URL.
[0042] After generating the additional URL, the generation control unit 101 stores the authentication code obtained by decrypting the encryption code in a predetermined registration table as a registered encryption code (FIG. 2: S105).
[0043] Here, the method of storing the registered encryption code by the generation control unit 101 is not particularly limited, but for example, the generation control unit 101 refers to a registration table stored in advance in a predetermined memory. As shown in FIG. 4A, a registration authentication URL 401, a registration authentication code 402, and a registration target URL 403 are stored in advance in association with each other in the registration table 400. Thus, the generation control unit 101 stores the authentication URL of the additional URL ("https: / / abc / def") in association with the registration authentication URL 401 in the registration table 400, and stores the encryption code of the additional URL ("ab01") in association with the registration encryption code 402 in the registration table 400. This makes it possible to register the authentication code in the authentication URL in advance.
[0044] The registered authentication code ("ab01") can be changed as needed by instructions from the user or administrator. Therefore, by setting an expiration date for the registered authentication code, it is usually possible to prevent access to the target URL once the expiration date of the encryption code has passed, even if the additional URL is stored in the same storage medium 12.
[0045] Furthermore, the generation control unit 101 associates the destination URL of the authentication URL ("https: / / abc") with the registration destination URL 403 of the registration table 400 and stores it. This makes it possible to register in advance the destination URL ("https: / / abc") to be forwarded to based on the determination of the authentication URL. Note that, although the authentication URL, authentication code, and destination URL are stored together in the registration table 400, this is not limiting.
[0046] Now, when the administrator acquires the additional URL, the administrator stores the acquired additional URL in a predetermined storage medium 12 (FIG. 2: S106).
[0047] Here, the method of storing the additional URL by the administrator is not particularly limited. For example, as shown in FIG. 4B, the administrator uses the management terminal 10 to store the additional URL ("https: / / abc / def / ?pm=xyz012") in the NFC tag 12a, or to output the QR code (registered trademark) 12b or the two-dimensional barcode 12c corresponding to the additional URL ("https: / / abc / def / ?pm=xyz012"). The administrator can then embed the NFC tag 12a in the storage medium 12, or print or attach the QR code (registered trademark) 12b or the two-dimensional barcode 12c to the storage medium 12, thereby storing the additional URL in the storage medium 12. Here, the storage medium 12 is not particularly limited. For example, the storage medium 12 can be a paper medium, a resin medium, or an electronic medium such as a shop card, a menu card, a poster, a coaster, or a sticker. This allows the administrator to freely design the design of the storage medium 12.
[0048] Now, when the administrator stores the additional URL in the storage medium 12, the administrator provides the storage medium 12 to a user, and the user installs or attaches the storage medium 12 in his or her own store so that it can be used by consumers and traders who visit the store.
[0049] Then, for example, a consumer visits the user's store, finds the storage medium 12 installed there, and reads the additional URL of the storage medium 12 ("https: / / abc / def / ?pm=xyz012") on his / her user terminal 11 (FIG. 2: S201).
[0050] Here, the method by which the user terminal 11 reads the additional URL is not particularly limited. For example, as shown in FIG. 5A, when the additional URL ("https: / / abc / def / ?pm=xyz012") is stored in the NFC tag 12a, the user holds the user terminal 11 over the NFC tag 12a of the storage medium 12. Then, the wireless communication unit of the user terminal 11 and the NFC tag 12a perform short-distance wireless communication, and the user terminal 11 can read the additional URL stored in the NFC tag 12a. In addition, when the additional URL is a QR code (registered trademark) 12b or a two-dimensional barcode 12c, the user activates a camera provided in advance in the user terminal 11 and photographs the QR code (registered trademark) 12b or the two-dimensional barcode 12c with the camera of the user terminal 11, and the user terminal 11 can analyze the QR code (registered trademark) 12b or the two-dimensional barcode 12c and read the additional URL corresponding to the QR code (registered trademark) 12b or the two-dimensional barcode 12c.
[0051] Now, when the user terminal 11 reads the additional URL, the user terminal 11 accesses the server 14 based on the authentication URL of the additional URL (FIG. 2: S202). Then, the determination control unit 102 of the server 14 determines whether or not an encryption code is added to the authentication URL accessed by the user terminal 11 (FIG. 2: S203).
[0052] Here, there is no particular limitation on the judgment method of the first judgment control unit 102, but for example, the first judgment control unit 102 judges whether or not an encryption code ("xyz012") has been added to the authentication URL ("https: / / abc / def") accessed by the user terminal 11.
[0053] If the determination result is that no encryption code has been added to the authentication URL (FIG. 2: S203 NO), the first determination control unit 102 determines that the user terminal 11 has not accessed the server 14 via the storage medium 12. This case corresponds to, for example, a case where the user terminal 11 has accessed the server 14 using the authentication URL ("https: / / abc / def") stored as an access history.
[0054] Now, when the first judgment control unit 102 determines that the user terminal 11 is not accessing the server 14 via the storage medium 12, the first error control unit 103 of the server 14 denies the user terminal 11 access to the target URL ("http: / / abc") related to the authentication URL ("https: / / abc / def") (Figure 2: S204).
[0055] Here, there is no particular limitation on the display method of first error control unit 103, but for example, as shown in FIG. 5B, error screen 500 displays, for example, URL 501 to be accessed ("https: / / abc / def / error") and message 502 indicating an error. Also, error screen 500 does not need to display any message. In other words, it is sufficient for first error control unit 103 to show that access to user terminal 11 has been denied. This allows the consumer to understand that access has been denied.
[0056] In this case, since the consumer does not read the additional URL stored in storage medium 12 and access the authentication URL, server 14 denies access to user terminal 11 of such a consumer. This makes it possible to limit access to user terminal 11 via storage medium 12 at the store. In addition, since the access history of error screen 500 remains in user terminal 11, the authentication URL will not be accessed again from now on.
[0057] On the other hand, in S203, for example, as shown in Fig. 6A, if the determination result shows that some kind of encryption code (e.g., "xyz345") is added to the authentication URL (Fig. 2: S203 YES), the first determination control unit 102 determines that the user terminal 11 is accessing the server 14 via the storage medium 12. Then, the second determination control unit 104 of the server 14 decrypts the added encryption code ("xyz345") added to the authentication URL (Fig. 2: S205), and determines whether the decrypted code matches a registered authentication code associated with the registered authentication URL in a predetermined registration table (Fig. 2: S206).
[0058] Here, the determination method of the second determination control unit 104 is not particularly limited, but for example, as shown in Fig. 6A, the second determination control unit 104 decrypts the added encryption code ("xyz345") and generates a decrypted code (for example, "cd02"). Here, the decryption method of the second determination control unit 104 is not particularly limited, but for example, a method of decrypting the encryption code ("xyz345") using a decryption generation unit corresponding to the encryption generation unit described above can be mentioned.
[0059] Then, the second determination control unit 104 refers to a registration table 400 stored in advance in a predetermined memory. Then, the second determination control unit 104 searches the registration table 400 for a registration authentication URL 401 corresponding to the authentication URL to be accessed ("https: / / abc / def"), and refers to a registration authentication code 402 ("ab01") associated with the searched registration authentication URL 401. Then, the second determination control unit 104 determines whether the generated decryption code ("cd02") matches the referenced registration authentication code 402.
[0060] If the determination result is that the decrypted code does not match the registered authentication code (FIG. 2: S206 NO), the second determination control unit 104 determines that the user terminal 11 is accessing the server 14 via the storage medium 12, but that there is an error in the encryption code. This corresponds to a case where, for example, as shown in FIG. 6B, the user terminal 11 has accessed the authentication URL ("https: / / abc / def") via the store's storage medium 12, but the encryption code of the additional URL of the storage medium 12 has expired.
[0061] Now, when the second determination control unit 104 determines that there is an error in the encryption code, the second error control unit 105 of the server 14 displays an error screen (FIG. 2: S204).
[0062] Here, there is no particular limitation on the display method of the second error control unit 105, but for example, as shown in FIG. 6B, an error screen 600 displays the URL 601 to be accessed ("https: / / abc / def / error") and a message 602 indicating an error, as described above. Also, the error screen 600 may not display any message, or an error screen 600 different from the above may be displayed. In other words, it is sufficient for the second error control unit 105 to show that access to the user terminal 11 has been denied. This allows the consumer to understand that access has been denied.
[0063] This corresponds to the case where, for example, a user or administrator updates the additional URL stored in storage medium 12 to update the encryption code. In this case, when a consumer reads the additional URL stored in storage medium 12 before the update and accesses the authentication URL, although the encryption code has been added as an encryption parameter, the old encryption code cannot be decrypted into the latest correct authentication code. For this reason, server 14 denies access from the user terminal 11 of such a consumer. This makes it possible to limit access to user terminal 11 via storage medium 12 updated at the store. Also, since the access history of error screen 600 remains on user terminal 11, the authentication URL will not be accessed again from now on.
[0064] On the other hand, in S206, for example, as shown in Fig. 7A, if the determination result shows that the decryption code matches the registered encryption code (Fig. 2: S206 YES), the second determination control unit 104 determines that the user terminal 11 is accessing the server 14 via the updated storage medium 12. Then, the transfer control unit 106 of the server 14 transfers the user terminal 11 to the target URL to access it (Fig. 2: S207).
[0065] Here, the transfer method of the transfer control unit 106 is not particularly limited, but for example, as shown in FIG. 7A, the transfer control unit 106 refers to a registration table 400 stored in advance in a predetermined memory, searches the referred registration table 400 for a registration authentication URL 401 corresponding to the access destination authentication URL ("https: / / abc / def"), and refers to a registration objective URL 403 ("https: / / abc") associated with the searched registration authentication URL 401. Then, the transfer control unit 106 uses the referred registration objective URL 403 to change the access destination authentication URL ("https: / / abc / def") to the objective URL ("https: / / abc") and transfers (redirects). Then, the user terminal 11 accesses the objective URL ("https: / / abc") from the authentication URL ("https: / / abc / def"), and displays an objective screen based on the objective URL ("https: / / abc").
[0066] Here, as shown in FIG. 7A, for example, destination screen 700 displays URL 701 ("https: / / abc") to be accessed and message 702 indicating the top screen. Destination screen 700 is a screen related to the user's store. This allows the consumer to have a screen related to the store they visited displayed on their own user terminal 11.
[0067] The destination screen 700 is displayed only on the user terminal 1 via the updated storage medium 12 at the store. Therefore, the store can display content according to the season or period on the destination screen 700, or include content that cannot be accessed from outside.
[0068] Furthermore, since the destination screen 700 can only be accessed by a user terminal 11 via a specific storage medium 12, it is also possible to set the destination URL to, for example, the URL of a platform that aggregates a specific field or industry, so that only consumers and traders in a specific field or industry can access it and communicate and exchange information.
[0069] Here, for example, when a consumer in a store uses the user terminal 11 to switch the screen display from the destination screen 700 to the order screen, the order screen 703 displays the URL 704 to be accessed ("https: / / abc / order") and a message 705 indicating the order screen 703, as shown in FIG. 7B.
[0070] Here, when a consumer places an order for a product or service on the order screen 703, the server 14 accepts the consumer's order information. The user provides the consumer with a product or service based on the consumer's order information accepted by the server 14. In addition, by having the server 14 accept the consumer's order information, it becomes possible to periodically accumulate the consumer's order information, and by analyzing the accumulated consumer's order information, it is possible to encourage the development of new products and services.
[0071] Also, for example, when a consumer goes to a store's cash register to pay and uses the user terminal 11 to switch the screen display from the order screen 700 to the payment screen, the order screen 800 displays the URL 801 to be accessed ("https: / / abc / account") and a message 802 indicating that the payment screen 800 is displayed, as shown in FIG. 8A.
[0072] Here, the consumer will make the accounting and payment while viewing the payment screen 802, and the server 14 will accept the consumer's payment information from the payment screen 802. Based on the consumer's payment information accepted by the server 14, the user can show the consumer the amount and urge them to make the payment.
[0073] There is no particular limitation on this payment method, but for example, the consumer may pay the user in cash to make the payment, or the server 14 may accept the consumer's payment information and cooperate with other servers to provide the consumer with other payment methods such as payment by bank transfer, payment using electronic money, credit card payment, etc. By accepting the consumer's payment information, the server 14 may, for example, be linked to an accounting server to periodically accumulate accounting information using the consumer's payment information, and the accumulated accounting information may be analyzed to immediately check the sales of products and services, as well as expense and profit trends.
[0074] Incidentally, once a user terminal 11 has accessed the target URL 403 ("https: / / abc"), that URL 403 ("https: / / abc") will be stored as an access history. In this case, it will be possible to access the target URL 403 ("https: / / abc") without coming to the store, which may result in fraudulent orders or fraudulent payments.
[0075] Therefore, in the present invention, when the user terminal 11 accesses the target URL without going through the authentication URL (FIG. 2: S208), the third error control unit 107 of the server 14 displays an error screen (FIG. 2: S204), as shown in FIG. 8B.
[0076] Here, there is no particular limitation on the display method of third error control unit 107, but for example, as shown in FIG. 8B, error screen 803 displays destination URL 804 ("https: / / abc / def / error") and message 805 indicating an error, as described above. Also, error screen 803 may not display any message, or an error screen 803 different from the above may be displayed. In other words, it is sufficient for third error control unit 107 to show that access to user terminal 11 has been denied. This allows the consumer to understand that access has been denied.
[0077] In this case, the consumer realizes that the target URL cannot be accessed unless the consumer visits the store and reads the store's storage medium 12. This makes it possible to limit access to the user terminal 11 via the store's storage medium 12. Although the above describes the case where the target URL is accessed directly, error screen 803 is also displayed when a subordinate address of the target URL is accessed directly.
[0078] Incidentally, since the destination screen based on the destination URL cannot be accessed by external consumers or traders, it can be used as a menu on the store side and can be utilized as a mobile order.
[0079] For example, when a user of a store provides an administrator with a destination URL (e.g., "https: / / ghi") indicating the store's ordering website, the administrator uses the destination URL to create an authentication URL ("https: / / ghi / jkl") (FIG. 2: S101). Here, the server 15 of the destination URL is different from the server 14 of the access control system 1 used by the administrator.
[0080] Next, when the administrator uses the management terminal 10 to instruct the server 14 to encrypt the authentication code and generate an additional URL, the generation control unit 101 generates an authentication code (e.g., "xyz01") (Figure 2: S102), and encrypts this to generate a cryptographic code (e.g., "hij012") (Figure 2: S103).
[0081] Then, the generation control unit 101 generates an added URL (for example, "https: / / ghi / jkl / ?pm=hij012") by adding the encryption code ("hij012") to the authentication URL ("https: / / ghi / jkl") as an encryption parameter (FIG. 2: S104).
[0082] Here, when a destination URL ("https: / / ghi") indicating the store's ordering website is to be set for each table for multiple tables in a store, for example, the administrator sets a destination URL (e.g., "https: / / ghi / table1", "https: / / ghi / table2") for each table as shown in Fig. 9A, and the administrator instructs the management terminal 10, and the generation control unit 101 generates an authentication code for each table, generates an encryption code, and generates an additional URL. This makes it possible to set a distinct destination URL for each table.
[0083] Furthermore, the generation control unit 101 stores the authentication code as a registered authentication code in a predetermined registration table based on the added URL (FIG. 2: S105). In this case, as shown in FIG. 9A, the generation control unit 101 stores the authentication URL of the added URL ("http: / / ghi / jkl") in association with the registered authentication URL 401 in the registration table 400, and stores the authentication code of the added URL ("xyz01") in association with the registered authentication code 402 in the registration table 400. Then, the generation control unit 101 stores the target URL of the first table ("https: / / ghi / table1") in association with the registered authentication code 402 ("xyz01") in the registered target URL 403. In contrast, the generation control unit 101 performs this for the target URL for each table.
[0084] Then, the administrator stores the additional URL in a predetermined storage medium 12 (FIG. 2: S106). Here, for example, the administrator creates a QR code (registered trademark) 12b corresponding to the additional URL for the first table ("https: / / ghi / jkl / ?pm=hij012") and prints it on a storage medium 12 such as a coaster. The same is true for the additional URL for the second table ("https: / / ghi / jkl / ?pm=hij345"). This makes it possible to set the storage medium 12 for each table.
[0085] Now, a consumer visits a store, comes to a first table, and reads the additional URL ("https: / / ghi / jkl / ?pm=hij012") of the storage medium 12 of the first table with his / her own user terminal 11 (FIG. 2: S201). Here, as shown in FIG. 9B, the consumer photographs QR code (registered trademark) 12b with the camera of the user terminal 11, thereby reading the additional URL of the storage medium 12 of the first table in the user terminal 11, and accesses the authentication URL of the additional URL (FIG. 2: S202). The first determination control unit 102 of the server 14 determines whether the encryption code is added to the authentication URL (FIG. 2: S203).
[0086] In this case, since the encryption code ("hij012") is added to the authentication URL ("http: / / ghi / jkl"), the first determination control unit 102 determines that the encryption code is added to the authentication URL (FIG. 2: S203 YES).
[0087] Next, the second determination control unit 104 of the server 14 decrypts the additional encryption code added to the authentication URL (FIG. 2: S205), and determines whether the decrypted code matches the registered encryption code associated with the registered authentication URL in a specified registration table (FIG. 2: S206).
[0088] First, the second determination control unit 104 decrypts the additional encryption code ("hij012") added to the authentication URL ("http: / / ghi / jkl") to generate a decrypted code ("xyz01"). Here, since the generated decrypted code matches the registered authentication code ("xyz01") associated with the registered authentication URL ("http: / / ghi / jkl"), the second determination control unit 104 determines that the decrypted code matches the registered authentication code (FIG. 2: S206 YES).
[0089] The transfer control unit 106 of the server 14 then transfers the user terminal 11 to the destination URL to access it (Figure 2: S207), but since the destination URL of the first table ("https: / / ghi / table1") is stored in the registration destination URL 403 associated with the registration authentication code 402 ("xyz01"), the transfer control unit 106 transfers (redirects) the user terminal 11 to the destination URL of the first table ("https: / / ghi / table1").
[0090] Then, the user terminal 11 accesses the destination URL of the first table ("https: / / ghi / table1") and displays a destination screen related to the first table. Here, as shown in FIG. 9B, for example, the destination screen 900 displays the URL 901 ("https: / / ghi / table1") to be accessed, a message 902 indicating the table's identification number (e.g., "TABLE1"), and a function message 903 indicating that mobile ordering is possible (e.g., "Mobile order"), etc. This allows the consumer to display on his / her user terminal 11 the destination screen related to the first table assigned to him / her among the stores he / she visited.
[0091] Also, by setting the destination URL for the first table ("https: / / ghi / table1"), as mentioned above, when a consumer makes a payment at a store, the user can calculate the necessary amount based on the destination URL corresponding to this first table. Also, by linking the destination URL corresponding to the first table with external accounting software (accounting cloud), the user can send the received amount to the accounting server or accounting software to calculate daily or monthly sales.
[0092] Also, in the above, a target URL is set for each table, but this is not limited to the above. For example, the administrator may set a table identification number (e.g., "table1", "table2", etc.) for each table, and set a branch URL that branches off from a specific target URL (e.g., "https: / / ghi") based on the table identification number.
[0093] Specifically, the administrator instructs the management terminal 10, and the generation control unit 101 generates an authentication code (e.g., "xyz01") and encrypts the authentication code to generate an encryption code (e.g., "hij012") as shown in Fig. 10A. Next, the generation control unit 101 adds the encryption code to the authentication URL as an encryption parameter based on the setting of the identification number of this table, and further adds the identification number of the table to the authentication URL as an identification parameter.
[0094] For example, as shown in FIG. 10A, the generation control unit 101 adds an encryption code ("hij012") as an encryption parameter to the authentication URL ("http: / / ghi / jkl"), and generates an added URL (for example, "http: / / ghi / jkl / ?pm=hij012&id=table1") with an identification number ("table1") as an identification parameter. When multiple parameters are added to a parameter-attached URL, a specific symbol (for example, "&") is set between the parameters. In this case, an encryption parameter and an identification parameter are added, so a specific symbol ("&") is set between the encryption parameter and the identification parameter. This makes it possible to add the table identification number to the authentication URL.
[0095] Furthermore, the generation control unit 101 stores the authentication code as a registered authentication code in a predetermined registration table based on the additional URL (FIG. 2: S105). In this case, as shown in FIG. 10A, the generation control unit 101 stores the authentication URL of the additional URL ("https: / / ghi / jkl") in association with the registered authentication URL 401 in the registration table 400, and stores the authentication code of the additional URL ("xyz01") in association with the registered authentication code 402 in the registration table 400. Furthermore, the generation control unit 101 stores the target URL of the authentication URL ("https: / / ghi") in association with the registered target URL 403 in the registration table 400. Here, the table identification number is used to indicate a lower-level URL of the target URL ("https: / / ghi"), and is not stored in the registration table 400.
[0096] Then, the administrator stores the additional URL in a predetermined storage medium 12 (FIG. 2: S106). Here, for example, the administrator creates a QR code (registered trademark) 12b corresponding to the additional URL for the first table ("https: / / ghi / jkl / ?pm=hij012&id=table1") and prints it on a coaster or other storage medium 12. The same applies to the additional URL for the second table ("https: / / ghi / jkl / ?pm=hij012&id=table2").
[0097] Furthermore, when the consumer reads the additional URL ("https: / / ghi / jkl / ?pm=hij012&id=table1") of the first table's storage medium 12 with his / her user terminal 11 and accesses the authentication URL of the additional URL (Figure 2: S202), the first determination control unit 102 of the server 14 determines whether the encryption code has been added to the authentication URL (Figure 2: S203).
[0098] In this case, since the encryption code ("hij012") is added to the authentication URL ("http: / / ghi / jkl"), the first determination control unit 102 determines that the encryption code is added to the authentication URL (FIG. 2: S203 YES).
[0099] Next, the second determination control unit 104 of the server 14 decrypts the additional encryption code added to the authentication URL (FIG. 2: S205), and determines whether the decrypted code matches the registered encryption code associated with the registered authentication URL in a specified registration table (FIG. 2: S206).
[0100] Here, the decrypted code ("xyz01") obtained by decrypting the encrypted code ("hij012") matches the registered authentication code ("xyz01") associated with the registered authentication URL ("https: / / ghi / jkl"), so the second determination control unit 104 determines that the decrypted code matches the registered authentication code (Figure 2: S206 YES).
[0101] The transfer control unit 106 of the server 14 then transfers the user terminal 11 to the target URL to access it (FIG. 2: S207). However, since the table identification number ("table1") was added to the added URL ("https: / / ghi / jkl / ?pm=hij012&id=table1") as an identification parameter, the transfer control unit 107 adds the table identification number ("table1") to the target URL ("https: / / ghi") and transfers (redirects) it to the target URL ("https: / / ghi / table1") corresponding to the table identification number.
[0102] Then, the user terminal 11 accesses the destination URL ("https: / / ghi / table1") corresponding to the table identification number, and displays a destination screen related to the first table. Here, as shown in FIG. 10B, for example, destination screen 1000 displays URL 1001 ("https: / / ghi / table1") to be accessed, message 1002 indicating the table identification number (e.g., "TABLE1"), and function message 1003 indicating that mobile ordering is possible (e.g., "Mobile order"), etc. This allows the consumer to display on his / her user terminal 11 the destination screen related to the first table assigned to him / her among the stores he / she visited.
[0103] Furthermore, in the present invention, by setting the transfer destination by the transfer control unit 106, it is also possible to display an advertisement screen carrying a banner (image) introducing SNS or other stores before displaying a destination screen such as a mobile order on the user terminal 11. This allows the consumer to check the advertisement screen when accessing the destination URL at a store using the user terminal 11 via the storage medium 12, thereby improving the advertising effect by the user.
[0104] In the embodiment of the present invention, the access permission system 1 is configured to include each control unit, but it may be configured to store a program that realizes each control unit in a storage medium and provide the storage medium. In this configuration, the program is read out to an apparatus, and the apparatus realizes each control unit. In this case, the program itself read out from the storage medium provides the effect of the present invention. Furthermore, it is also possible to provide it as a method for storing the steps executed by each control unit in a hard disk. [Industrial Applicability]
[0105] As described above, the access permission system and access permission method of the present invention are useful not only for stores such as restaurants and service stores, but also for all fields requiring access restrictions, such as marketing and promotion fields, and are effective as an access permission system and access permission method that can permit only access to a website via a specific storage medium. [Explanation of symbols]
[0106] 1. Access permission system 10 Management terminal 11 User terminal 12 Storage medium 13 Network 14 Server 101 Generation control unit 102 First judgment control unit 103 First error control section 104 Second judgment control section 105 Second error control section 106 Transfer control section 107 Third Error Control Section
Claims
1. a storage medium for storing an additional URL in which an encrypted code obtained by encrypting an authentication code is added as a parameter to an authentication URL; a first determination control unit that, when a user terminal reads the additional URL of the storage medium and accesses an authentication URL of the additional URL, determines whether the encryption code has been added to the authentication URL; a first error control unit that displays an error screen when the determination result indicates that the encryption code is not added to the authentication URL; a second determination control unit that, when it is determined that the encryption code has been added to the authentication URL, decrypts the added encryption code added to the authentication URL and determines whether the decrypted code matches a registered authentication code associated with the registered authentication URL in a predetermined registration table; a second error control unit that displays the error screen when the decryption code does not match the registered authentication code as a result of the determination; a transfer control unit that transfers the user terminal to a target URL and allows the user terminal to access the target URL when the decrypted code matches the registered authentication code as a result of the determination; a third error control unit that displays the error screen when the user terminal accesses the target URL without passing through the authentication URL; Equipped with a permission system.
2. The encryption method of the encryption code uses an encryption function.
2. The access permission system according to claim 1.
3. The registration table stores a registration authentication URL, a registration authentication code, and a registration target URL in association with each other, the transfer control unit transfers the user terminal to access a registration target URL associated with the registration authentication code that matches the decrypted code in the registration table; 2. The access permission system according to claim 1.
4. a storage medium for storing an additional URL in which an encrypted code obtained by encrypting an authentication code is added as a parameter to an authentication URL; a first determination control step of determining whether or not the encryption code has been added to the authentication URL when the user terminal reads the additional URL of the storage medium and accesses the authentication URL of the additional URL; a first error control step of displaying an error screen when the determination result indicates that the encryption code has not been added to the authentication URL; a second determination control step of decrypting the encryption code added to the authentication URL when the determination result indicates that the encryption code has been added to the authentication URL, and determining whether the decrypted code matches a registered authentication code associated with the registered authentication URL in a predetermined registration table; a second error control step of displaying the error screen when the decrypted code does not match the registered authentication code as a result of the determination; a transfer control step of transferring the user terminal to a target URL and making the user terminal access the target URL when the decrypted code matches the registered authentication code; a third error control step of displaying the error screen when the user terminal accesses the target URL without going through the authentication URL; The access permission method of the access permission system comprising:
Citation Information
Patent Citations
Service provision system and management server
JP2012137962A
Identification data management device, identification data management method, and identification data management program
JP2013069074A
Reward granting device, reward granting program, and reward granting method
JP2024061341A
System for supplying provision information including browsing approval information, browsing approval information management device, information providing device, user terminal device, method of providing provision information to user terminal device, method of creating browsing approval information, method of determining browsing approval information, and recording medium recording provision information
JP2002259838A
Access control system, access control method, and access control program
JP2006079598A