Entrance / Exit Management System, Entrance / Exit Management Method, and Entrance / Exit Management Program
The entry/exit management system addresses the complexity of managing multiple areas by automating account creation and permission assignment, thereby reducing administrative burdens and enhancing efficiency.
Patent Information
- Application Number
- JP2024189249
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-10-28
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-07-09
AI Technical Summary
The existing entry and exit management systems are complex for administrators of multiple areas, requiring manual registration and permission management across different areas, leading to increased processing loads.
An entry/exit management system that includes a grant unit for providing authority information, a reception unit for accepting authentication inputs, a generation unit for creating user accounts, an assignment unit for assigning authority information, and a registration unit for registering accounts in a database, allowing administrators to manage accounts across areas more efficiently.
The system reduces the processing load for administrators by automating the account management and permission processes across different areas, enhancing efficiency and simplifying the registration process.
Smart Images

Figure 0007675916000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an entrance / exit management system, an entrance / exit management method, and an entrance / exit management program for performing entrance / exit management. [Background technology]
[0002] In recent years, entrance and exit to buildings and the like has been controlled by authentication using ID cards, irises, etc. Patent Document 1 discloses an example of performing such authentication using face recognition technology. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent Publication No. 2022-84586 Summary of the Invention [Problem to be solved by the invention]
[0004] In such entrance and exit management, it is essential that an administrator registers information about users who use the system, that is, registers accounts and assigns authority information to the accounts. For example, in the case of a user who uses a second area included in a first area, that is, a tenant included in a building, the administrator of the second area may also register an account on the tenant side in the second area, and since the user uses the first area, the administrator of the second area must also request the administrator of the first area to register an account in the first area and assign authority information to the account. However, this process is problematic in that it is cumbersome for the administrators of both the first and second areas.
[0005] Therefore, the present invention has been made in consideration of the above problems, and aims to provide an entrance / exit management system, an entrance / exit management method, and an entrance / exit management program that can reduce the processing load on the first area administrator and the second area administrator. [Means for solving the problem]
[0006] In order to solve the above problems, an access control system according to one embodiment of the present invention includes an granting unit that grants a predetermined number of authority information pieces for entering a first area to an administrator of a second area included in the first area, a receiving unit that receives input of authentication information for a user of the second area, a generation unit that generates an account for a user of the second area based on the user's authentication information, an allocation unit that assigns one of the predetermined number of authority information pieces to the user account generated by the generation unit, and a registration unit that registers the account in an account database.
[0007] In addition, in order to solve the above problem, an entry / exit management method according to one embodiment of the present invention executes the following steps: a granting step in which a computer grants a predetermined number of authority information pieces for entering a first area to an administrator of a second area included in the first area; a receiving step in which an input of authentication information for a user of the second area is received; a generating step in which an account for a user of the second area is generated based on the user's authentication information; an assignment step in which one of the predetermined number of authority information pieces is assigned to the user's account generated in the generation step; and a registration step in which the account is registered in an account database.
[0008] In addition, in order to solve the above-mentioned problems, an entry / exit management program according to one embodiment of the present invention provides a computer with the following functions: an assignment function that assigns a predetermined number of pieces of authority information for entering a first area to an administrator of a second area included in the first area; a reception function that accepts input of authentication information for a user of the second area; a generation function that generates an account for a user of the second area based on the user's authentication information; an assignment function that assigns one of the predetermined number of pieces of authority information to the user account generated by the generation function; and a registration function that registers the account in an account database.
[0009] In addition, in the above-mentioned entrance / exit management system, the account may include information of a second area authentication medium used by a user to enter the second area, and may include a second area reading unit that reads the second area medium information when entering the second area, and a second area authentication unit that performs authentication based on whether the second area medium information read by the second area reading unit is registered in the account database.
[0010] In addition, in the above-mentioned entrance / exit management system, the authority information may include information of a first area authentication medium used by a user to enter the first area, and the system may be equipped with a first area reading unit that reads the first area medium information when entering the first area, and a first area authentication unit that performs authentication based on whether the first area medium information read by the first area reading unit is registered in an account database.
[0011] In addition, in the above-mentioned entrance / exit management system, the second area authentication medium may be biometric information of a user, and the registration unit may register, as the first area authentication medium, the biometric information of the user registered as the second area authentication medium.
[0012] The above-mentioned entry / exit management system may further include a first storage unit that stores first area history information that is recorded in response to authentication by the first area authentication unit and indicates a history of users entering and exiting the first area, and a first providing unit that provides the first area history information to an administrator of the second area within the scope of authority information granted for the second area.
[0013] The above-mentioned entry / exit management system may further include a second storage unit that stores second area history information that is recorded in response to authentication by the second area authentication unit and indicates a history of users entering and exiting the second area, and a second providing unit that provides the second area history information to an administrator of the second area.
[0014] The above-mentioned entry / exit management system may also include a third area authentication unit that authenticates a user entering a third area outside the first area, a third memory unit that stores third area history information that is recorded in response to authentication by the third area authentication unit and indicates a history of users entering and exiting the third area, a notification unit that notifies an administrator of the first area of information about the authenticated user, and a reward granting unit that grants points to users of the second area who have used the third area.
[0015] In addition, in the above-mentioned entry / exit management system, the privilege granting unit may grant a first privilege to a user using the third area, which is beneficial to the user when using the third area, and the privilege granting unit may grant a second privilege, which is more beneficial than the first privilege, to a user using the third area and who is able to enter the second area.
[0016] In addition, the above-mentioned entrance / exit management system may include a determination unit that determines whether a remaining number obtained by subtracting the number of authority information assigned by the assignment unit from the predetermined number is equal to or less than a predetermined threshold, and a request unit that requests an administrator of the first area to increase the predetermined number when the determination unit determines that the remaining number is equal to or less than the predetermined threshold, and the granting unit may grant the additional authority information to the administrator of the second area. Effect of the Invention
[0017] An entrance / exit management system according to one embodiment of the present invention allows the administrator of the second area to also manage accounts in the first area, and the administrator of the second area no longer needs to contact the administrator of the first area to register an account, thereby reducing the processing load on the administrators of the first and second areas. [Brief description of the drawings]
[0018] [Figure 1] FIG. 1 is a system diagram showing an example of the configuration of an entrance / exit management system. [Diagram 2] 2 is a block diagram showing a configuration example of a first area management device. FIG. [Diagram 3]4] FIG. 4 is a block diagram showing an example of the configuration of a second area management device. [Figure 4] FIG. 2 is a conceptual data diagram showing an example of the configuration of first account information. [Diagram 5] FIG. 13 is a conceptual data diagram showing an example of the configuration of second account information. [Figure 6] 1A is a data conceptual diagram showing an example of a configuration of first area history information showing an entrance / exit history of a first area, and FIG. 1B is a data conceptual diagram showing an example of a configuration of second area history information showing an entrance / exit history of a second area. [Figure 7] FIG. 11 is a sequence diagram showing an example of an exchange in the entrance / exit management system when an account is created. [Figure 8] 13 is a flowchart showing an example of an operation of the second area management device when creating an account. [Figure 9] 13 is a flowchart showing an example of an operation of the first area management device when creating an account. [Figure 10] 13 is a flowchart showing an example of an operation during authentication of a second area. [Figure 11] 13 is a flowchart showing an example of an operation during authentication of a first area. [Figure 12] 13 is a flowchart showing an example of an operation of the second area management device when a user checks a history. [Figure 13] 13 is a flowchart showing an example of an operation performed when checking a history in the first area management device. [Figure 14] FIG. 2 is a block diagram showing an example of the configuration of a third area management device. [Figure 15] 13 is a flowchart showing an operation example of authority information adding processing in the second area management device. [Figure 16] 13 is a flowchart showing an operation example of authority information adding processing in the first area management device. [Figure 17] FIG. 11 is a sequence diagram showing an example of an exchange in the entrance / exit control system when entering a third area. [Figure 18] 13 is a flowchart showing an example of the operation of the third area management device when entering the third area. [Figure 19]13 is a flowchart showing an example of the operation of the first area management device when entering a third area. [Figure 20] FIG. 11 is a diagram illustrating a configuration example of an entrance / exit management system in which account information is integrated and centrally managed. [Figure 21] FIG. 13 is a data conceptual diagram showing an example of the configuration of integrated account information. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0019] Hereinafter, an entrance / exit control system according to one aspect of the present invention will be described in detail with reference to the drawings.
[0020] <Summary> FIG. 1 is a system diagram showing a configuration example of an entrance / exit management system 1. The entrance / exit management system 1 includes a first area management device 100 and a second area management device 200 connected to each other via a network 400 so as to be able to communicate with each other, and a third area management device 300 may also be connected to each other via the network 400 so as to be able to communicate with each other. The first area management device 100 is a device for managing a first area 10 (an area surrounded by a dotted line), and the second area management device 200 is a device for managing a second area 20 (an area surrounded by a dashed line). The management of an area includes at least any of authentication of a user who enters and leaves the area, recording of an entrance / exit history, and management of an account of a user who enters and leaves the area, and may include all of these. Here, the first area 10 is an area that includes the second area 20, and is, for example, a building, but is not limited thereto. The first area 10 may be, for example, a shopping mall or an amusement park. The second area 20 is an area included in the first area 10, and is, for example, a tenant in a building, but is not limited to this. The second area 20 is an area that cannot be entered without passing through a gate provided in the first area 10.
[0021] The first area management device 100 is an information processing device (computer system) that authenticates a gate through which all users who use the building 50 must pass and authenticates users who use the gate, and may be realized, for example, by a server device, a PC, a tablet terminal, etc., but is not limited to these. The first area management device 100, for example, reads authentication information of a user using a reading unit 121 (121a, 121b, 121c, 121d), authenticates the read authentication information of the user, and if the authentication is successful, unlocks a gate 122 (122a, 122b, 122c, 122d) to allow the user to enter the first area 10. The first area management device 100 may also authenticate a user when he or she exits the first area 10. User authentication information may take various forms, and may be of any type that can uniquely identify the user. As an example, the authentication information may be an ID (identifier) card, a two-dimensional barcode, a password, biometric information (iris or fingerprint), etc., but is not limited to these.
[0022] The second area management device 200 is an information processing device (computer system) that authenticates the gate 222 through which all users who use the second area 20 must pass and the users who use the gate 222, and may be realized by, for example, a server device, a PC, a tablet terminal, etc., but is not limited to these. For example, the second area management device 200 reads authentication information of a user by a reading unit 221, authenticates the read authentication information of the user, and if the authentication is successful, unlocks the gate 222 and allows the user to enter the second area 20. The second area management device 200 may also authenticate a user when he or she exits the second area 20. The authentication information used by the second area management device 200 may be the same as that used by the first area management device 100, or may be different.
[0023] In this embodiment, the first area management device 100 grants to the manager of the second area 20 (the second area management device 200) a plurality of pieces of authority information for users of the second area 20 to enter the first area 10. Each piece of authority information is assigned to each user of the second area 20, and is information for managing the users of the second area 20 as users who will enter the first area 10. The authority information includes at least identification information for the first area management device 100 to individually and uniquely identify each user, and may include information on a specific medium (e.g., an ID card) when the medium is used for authentication.
[0024] The second area management device 200 registers account information of users who use the second area 20, and also registers account information of users who use the first area 10 within the scope of the authority information granted by the first area management device 100.
[0025] That is, in the entrance / exit management system 1 according to this embodiment, the authority for account management performed by the first area management device 100 is also given to the administrator of the second area management device 200.
[0026] Each device will be described in detail below.
[0027] <Configuration> <First area management device 100> FIG. 2 is a block diagram showing an example of the configuration of the first area management device 100. As shown in FIG.
[0028] As shown in FIG. 2, the first area management device 100 includes a communication unit 110, an input unit 120, an output unit 130, a storage unit 140, and a control unit 150.
[0029] The communication unit 110 is a communication interface that communicates with devices external to the first area management device 100 via the network 400. The communication unit 110 transmits specified information to a specified external device according to an instruction from the control unit 150. The communication unit 110 also transmits information received from an external device via the network 400 to the control unit 150. For example, the communication unit 110 transmits authority information to the second area management device 200 as an external device according to an instruction from the control unit 150. The communication unit 110 also receives, for example, user information associated with the authority information from the second area management device 200 and transmits it to the control unit 150.
[0030] The input unit 120 has a function of accepting an input from the manager of the first area management device 100 and transmitting it to the control unit 150. The input unit 120 can be realized by, for example, a hardware key or a mouse provided in the first area management device 100, or a soft key such as a touch panel or a touch key. The input to the input unit 120 may be an input by voice, and in this case, the input unit 120 is realized by a microphone. The input unit 120 may accept, for example, an input of authority information to be given to the manager of the second area 20 (the second area management device 200) and transmit it to the control unit 150. Alternatively, the input unit 120 may accept, for example, an input of information on a new user entering the first area 10 and transmit it to the control unit 150.
[0031] The input unit 120 includes a first area reading unit 121. The first area reading unit 121 is provided at a gate 122 which is an entrance to the first area 10, and is a device that reads authentication information of a user. For example, the first area reading unit 121 may be a card reader when the authentication information is an ID card, and may be a camera when the authentication information is an iris. The input unit 120 transmits the authentication information of the user read by the first area reading unit 121 to the control unit 150.
[0032] The output unit 130 has a function of outputting data instructed by the control unit 150. The output by the output unit 130 may be realized by displaying characters or images on a monitor (display device) or the like that is attached to or connected to the first area management device 100, or may be realized by outputting audio from a speaker or earphones (audio output device) that is attached to or connected to the first area management device 100. Alternatively, the output by the output unit 130 may be realized by transmitting information to an external device via the communication unit 110.
[0033] The storage unit 140 is a recording medium that stores various programs and various data required for the first area management device 100 to operate. The storage unit 140 is realized, for example, by a hard disk drive (HDD), a solid state drive (SSD), a flash memory, etc., but is not limited to these. The storage unit 140 may be realized by a cloud storage accessible by the first area management device 100. The storage unit 140 may also configure a ROM or RAM as a work area for executing a program. The storage unit 140 may store a program that authenticates the authentication information read by the first area reading unit 121 and unlocks the gate when the authentication is successful. The storage unit 140 may also store first area account information 141 and first area history information 142. The first area account information 141 is information indicating the account of a user who enters the first area 10 (uses the first area 10). The first area history information 142 is information relating to the history of users entering and leaving the first area 10. The first area account information 141 and the first area history information 142 will be described in detail later.
[0034] The control unit 150 is a processor that executes processes to be realized by the first area management device 100, using various programs and various data stored in the storage unit 140. The control unit 150 authenticates users who enter the first area 10, and registers user account information in response to input from the administrator of the first area management device 100.
[0035] The control unit 150 includes an assignment unit 151 , a registration unit 152 , a first area authentication unit 153 , and a first provision unit 154 .
[0036] The granting unit 151 grants authority information to the administrator of the second area 20 (the second area management device 200) in accordance with an instruction from the administrator of the first area management device 100 input to the input unit 120. The granting unit 151 grants a predetermined number of pieces of authority information to the administrator of the second area 20. As described above, the authority information includes at least identification information (authentication ID) for identifying a user in the first area 10.
[0037] The registration unit 152 registers information of a user who uses the first area 10 in the first area account information 141. The registration unit 152 may register information of a new user in the first area account information according to the contents input by the administrator of the first area management device 100 via the input unit 120. The registration unit 152 may receive the transmitted user information and the authority information via the communication unit 110, triggered by the registration of user information for any of the authority information sent from the second area management device 200 to the second area management device 200, and may register the received user information for the received authority information in the first area account information. That is, the first area account information 141 may be registered by the administrator of the first area 10 in some cases, or by the administrator of the second area 20 in other cases. The registration here may include updating or deleting information. Therefore, the administrator of the first area 10 does not need to register information of all users, and the workload of the administrator can be reduced. Furthermore, if the user's biometric information (e.g., facial recognition) is used as an authentication medium in the first and second areas, it can be registered as common information, eliminating the need for the user to carry a medium such as an ID card and preventing the user from losing the authentication medium, which is expected to improve the security of authentication in the first and second areas.
[0038] The first area authentication unit 153 authenticates the authentication information read by the first area reading unit 121. Here, authentication may be determining whether or not the user who holds the authentication information has the authority to enter the first area 10. That is, the first area authentication unit 153 determines whether or not the authentication information transmitted from the first area reading unit 121 is registered in the first area account information 141. If the authentication information is registered in the first area account information 141, the authentication is successful, and if it is not registered, the authentication is unsuccessful. If the authentication is successful, the first area authentication unit 153 unlocks the gate corresponding to the first area reading unit 121 so that the user can pass through the gate. If the authentication is unsuccessful, the first area authentication unit 153 does not unlock the gate and outputs information indicating the authentication failure to the first area reading unit 121. In this case, the first area reading unit 121 may output a character string or a voice indicating the authentication failure to notify the user that the authentication has failed.
[0039] The first providing unit 154 provides the first area history information upon receiving an instruction from the manager of the first area 10 via the input unit 120 or an access from the manager of the second area 20 from the second area management device 200 via the communication unit 110. When receiving an instruction from the manager of the first area 10, the first providing unit 154 provides all information of the first area history information 142. In this case, the provision of the first area history information by the first providing unit 154 may be realized by displaying it on a monitor as the output unit 130. Furthermore, when the first providing unit 154 receives an access from the manager of the second area 20, the first providing unit 154 provides the first area history information 142 within the scope of the authority information granted to the manager of the second area 20 by the granting unit 151. In other words, only the information of the entry and exit history for the authentication ID indicated by the authority information assigned to the second area 20 is provided. In this case, the provision of the first area history information by the first providing unit 154 may be realized in the form of transmission to the second area management device 200 via the communication unit 110.
[0040] The above is an explanation of the configuration of the first area management device 100.
[0041] <Second area management device 200> FIG. 3 is a block diagram showing an example of the configuration of the second area management device 200. As shown in FIG.
[0042] As shown in FIG. 3, the second area management device 200 includes a communication unit 210, an input unit 220, an output unit 230, a storage unit 240, and a control unit 250.
[0043] The communication unit 210 is a communication interface that communicates with devices outside the second area management device 200 via the network 400. The communication unit 210 transmits specified information to a specified external device according to an instruction from the control unit 250. The communication unit 210 also transmits information received from an external device via the network 400 to the control unit 250. For example, the communication unit 210 transmits authority information and user information associated with the authority information to the first area management device 100 as an external device according to an instruction from the control unit 250. For example, the communication unit 210 also receives authority information from the first area management device 100 and transmits it to the control unit 250.
[0044] The input unit 220 has a function of accepting input from an administrator of the second area management device 200 and transmitting the input to the control unit 250. The input unit 220 can be realized by, for example, a hardware key or a mouse provided in the second area management device 200, or a soft key such as a touch panel or touch keys. Note that the input to the input unit 220 may be a voice input, in which case the input unit 220 is realized by a microphone. The input unit 220 may accept an input of information on a user who uses the second area 20 from, for example, the administrator of the second area management device 200, and transmit the information to the control unit 250.
[0045] The input unit 220 includes a second area reading unit 221. The second area reading unit 221 is provided at a gate 222 which is an entrance to the second area 20, and is a device that reads authentication information of a user. For example, the second area reading unit 221 may be a card reader when the authentication information is an ID card, and may be a camera when the authentication information is an iris. The input unit 220 transmits the authentication information of the user read by the second area reading unit 221 to the control unit 250.
[0046] The output unit 230 has a function of outputting data instructed by the control unit 250. The output by the output unit 230 may be realized by displaying characters or images on a monitor (display device) or the like that is attached to or connected to the second area management device 200, or may be realized by outputting audio from a speaker or earphones (audio output device) that is attached to or connected to the second area management device 200. Alternatively, the output by the output unit 230 may be realized by transmitting information to an external device via the communication unit 210.
[0047] The storage unit 240 is a recording medium that stores various programs and various data required for the second area management device 200 to operate. The storage unit 240 is realized, for example, by a hard disk drive (HDD), a solid state drive (SSD), a flash memory, etc., but is not limited to these. The storage unit 240 may be realized by a cloud storage accessible by the second area management device 200. The storage unit 240 may also configure a ROM or RAM as a work area for executing a program. The storage unit 240 may store a program that authenticates the authentication information read by the second area reading unit 221 and unlocks the gate when the authentication is successful. The storage unit 240 may also store second area account information 241 and second area history information 242. The second area account information 241 is information indicating the account of a user who enters the second area 20 (uses the second area 20). The second area history information 242 is information relating to the history of entry and exit of users who enter and exit the second area 20. The second area account information 241 and the second area history information 242 will be described in detail later.
[0048] The control unit 250 is a processor that executes processes to be realized by the second area management device 200, using various programs and various data stored in the storage unit 240. The control unit 250 authenticates users who enter and leave the second area 20, and registers user account information in response to input from the administrator of the second area management device 200.
[0049] The control unit 250 includes a receiving unit 251 , a generating unit 252 , an allocating unit 253 , a registering unit 254 , a second area authentication unit 255 , and a second providing unit 256 .
[0050] The reception unit 251 receives a predetermined number of pieces of authority information from the first area management device 100. The authority information received by the reception unit 251 is information for entering the first area 10, is information associated with each user who uses the second area 20, and is information for the first area management device 100 to individually manage each user and their authentication information.
[0051] The generating unit 252 generates account information of a user who uses the second area 20. Specifically, the generating unit 252 generates the user's account information based on an input to the input unit 220 by an administrator of the second area 20. The input by the administrator includes an input specifying which second area authentication ID the user uses in the second area 20, and an input of information that allows the second area management device 200 to uniquely identify the user (e.g., the user's name), and may also include an input of other information about the user (e.g., personal information such as the user's email address, age, sex, address, and telephone number). In addition, if the authentication information used in the second area 20 is biometric information of the user, the input of the biometric information may be included. In addition, if the authentication information used in the second area 20 is an ID card or the like, the input of information indicating which ID card is to be given to the user may be included. Therefore, the generation of the user's account information by the generating unit 252 may be a correspondence between a pre-existing (or may be newly created) second area authentication ID and second area authentication information for entering and leaving the second area 20, and information on a new user.
[0052] The allocation unit 253 allocates, to the user's account information generated by the generation unit 252, pieces of authority information that have not yet been associated with a user, among the predetermined number of pieces of authority information received by the reception unit 251.
[0053] The registration unit 254 associates the authority information assigned by the assignment unit 253 with the account information of the user who uses the second area 20 generated by the generation unit 252, and registers the account information in the second area account information 241. The registration by the registration unit 254 includes not only new registration but also updating and deleting information, and the updating and deleting of information are performed by input by the administrator of the second area management device 200 via the input unit 220.
[0054] The second area authentication unit 255 authenticates the authentication information read by the second area reading unit 221. Here, authentication may be determining whether or not the user who holds the authentication information has the authority to enter the second area 20. That is, the second area authentication unit 255 determines whether or not the authentication information transmitted from the second area reading unit 221 is registered in the second area account information 241. If the authentication information is registered in the second area account information 241, the authentication is successful, and if it is not registered, the authentication is unsuccessful. If the authentication is successful, the second area authentication unit 255 unlocks the gate corresponding to the second area reading unit 221 so that the user can pass through the gate. If the authentication is unsuccessful, the second area authentication unit 255 does not unlock the gate and outputs information indicating the authentication failure to the second area reading unit 221. In this case, the second area reading unit 221 may output a character string or a voice indicating the authentication failure to notify the user that the authentication has failed.
[0055] The second providing unit 256 receives an instruction from the manager of the second area 20 via the input unit 220, and provides the second area history information 242. Providing the second area history information 242 may mean outputting (displaying) the second area history information 242 to the output unit 230. Furthermore, the second providing unit 256 receives an instruction from the manager of the second area 20 via the input unit 220, and provides the first area history information 142.
[0056] The above is an explanation of the configuration of the second area management device 200.
[0057] <Data> From here, the first area account information 141, the first area history information 142, the second area account information 241, and the second area history information 242 will be explained.
[0058] <Second Area Account Information 241> Fig. 4 is a conceptual data diagram showing an example of the configuration of second area account information 241. The second area account information 241 is information indicating an account of a user who uses the second area 20. As shown in Fig. 4, the second area account information 241 is information in which a management ID 401, a first area authentication ID 402, first area authentication information 403, a second area authentication ID 404, a second area authentication information 405, a user name 406, and an email address 407 are associated with each other.
[0059] The second area account information 241 is information for managing the accounts of users who use the second area 20 (users who enter and leave the second area 20), and is also information for managing the accounts of the users in the first area 10.
[0060] The management ID 401 is identification information for individually managing the accounts registered in the second area account information 241. The management ID 401 is automatically assigned to each user of the second area 20.
[0061] The first area authentication ID 402 is information included in a predetermined number of pieces of authority information transmitted from the first area management device 100, and is identification information for the first area management device 100 to identify each account of a user in the first area 10.
[0062] The first area authentication information 403 is information used to enter the first area 10, that is, information to be compared with the authentication information read by the first area reading unit 121. The first area authentication information 403 may be determined in advance by the administrator of the first area management device 100, or may be the same as the second area authentication information 405 when the second area authentication information 405 is registered. The first area authentication information 403 may be unique information recorded on the ID card if the authentication medium is an ID card, image information of a two-dimensional barcode unique to the user if the authentication medium is a two-dimensional barcode, image information of an image of the user's eye if the authentication medium is an iris, or image information of an image of the user's fingerprint if the authentication medium is a fingerprint. The authentication medium may basically be common to each user, but may be different. If the first area authentication information 403 is a predetermined medium such as an ID card, it is predetermined information, and if it is biometric information, it is information that is registered by accepting the input of the user's biometric information later. If the first area authentication information 403 is common to the second area authentication information 405, when the second area authentication information 405 is registered, the information is copied and registered as the first area authentication information 403.
[0063] The second area authentication ID 404 is identification information for the second area management device 200 to identify each account of a user in the second area 20. The second area authentication ID 404 may be the same as the first area authentication ID 402.
[0064] The second area authentication information 405 is information used to enter the second area 20, that is, information to be compared with the authentication information read by the second area reading unit 221. The second area authentication information 405 is set by an administrator of the second area 20. If the authentication medium is an ID card, the second area authentication information 405 may be unique information recorded on the ID card; if the authentication medium is a two-dimensional barcode, the second area authentication information 405 may be image information of a two-dimensional barcode unique to the user; if the authentication medium is an iris, the second area authentication information 405 may be image information of an image of the user's eye; if the authentication medium is a fingerprint, the second area authentication information 405 may be image information of an image of the user's fingerprint. The authentication medium may basically be common to each user, but may be different.
[0065] The user name 406 is information indicating who is the user using the corresponding first area authentication ID 402 or second area authentication ID 404, and is information indicating the name of the user.
[0066] The email address 407 is information indicating an email address held by the user indicated by the corresponding username 406 .
[0067] 4, an account with management ID 401 of "mn0201" has "1A20021" registered as first area authentication ID 402, and image information of "20021A.jpg" associated with it as first area authentication information 403. The account also has "2A021" associated as second area authentication ID 404, and image information of "20021A.jpg" associated with it as second area authentication information 405. The user is "Ayama Ao" as indicated by user name 406, and email address 407 is "ayama@XXX.com."
[0068] The second area account information 241 may include information other than that shown in the figure. For example, the gender of the user indicated by the user name 406, a telephone number, authentication information different from the authentication information indicated by the second area authentication information 405 when the second area reading unit 221 can read a plurality of authentication information, a registration date, and other information related to entry and exit may be registered. In addition, the second area account information 241 may not include non-essential information among the information shown in the figure, for example, the management ID 401 may not be included, and if there is no gate in the second area 20, the second area authentication information 405 may not be included. In addition, as shown in FIG. 4, the first area authentication ID 402 as authority information given by the first area management device 100 may be registered in advance, and if no user is associated, the other information may be left blank, and if a new user is registered, information may be added to the blank portion.
[0069] <1st Area Account Information 141> Fig. 5 is a conceptual data diagram showing an example of the configuration of first area account information 141. The first area account information 141 is information indicating the account of a user who uses the first area 10. As shown in Fig. 5, the first area account information 141 is information in which a management ID 501, a first area authentication ID 502, first area authentication information 503, a second area ID 504, a user name 505, and an email address 506 are associated with each other.
[0070] The management ID 501 is identification information for individually managing the accounts registered in the first area account information 141. The management ID 501 is automatically assigned to each user of the first area 10.
[0071] The first area authentication ID 502 is identification information for the first area management device 100 to identify each account of a user in the first area 10. The first area authentication ID 502 also includes the first area authentication ID 402 as authority information given to the administrator of the second area 20 (the second area management device 200).
[0072] The first area authentication information 503 is information used to enter the first area 10, i.e., information to be compared with the authentication information read by the first area reading unit 121. The first area authentication information 503 is set by an administrator of the first area 10. If the authentication medium is an ID card, the first area authentication information 503 may be unique information recorded on the ID card; if the authentication medium is a two-dimensional barcode, the first area authentication information 503 may be image information of a two-dimensional barcode unique to the user; if the authentication medium is an iris, the image information of an image of the user's eye; if the authentication medium is a fingerprint, the image information of an image of the user's fingerprint. The authentication medium may basically be common to each user, but may be different.
[0073] The second area ID 504 indicates which second area 20 the account is granted to when the account is included in the authority information granted to the administrator of the second area 20, and is identification information for identifying which second area 20 the first area management device 100 is. The second area ID 504 is left blank when the account belongs to a user who does not use the second area 20.
[0074] The user name 505 is information indicating who is the user using the corresponding first area authentication ID 502, and is information indicating the name of the user.
[0075] The email address 506 is information indicating an email address held by the user indicated by the corresponding user name 505 .
[0076] In an example shown in FIG. 5, for the account with the management ID 501 being "M02206", "1A20022" is registered as the first area authentication ID 502, and the first area authentication information 403 thereof is associated with the image information of "20022A.jpg". Also, for the said account, "2A" is associated as the second area ID 504, and the user is "B Tian B Zi" as shown by the user name 505, and the email address 407 is "bta@XXX.com".
[0077] Each account of the first area account information 141 may be registered by the administrator of the first area 10, or may be automatically registered triggered by the second area 20 performing user registration in the second area management device 200.
[0078] <Second area history information 242> FIG. 6(a) is a data conceptual diagram showing a configuration example of the second area history information 242. The second area history information 242 is information indicating the history of a user entering and leaving the second area 20. As shown in FIG. 6(a), the second area history information 242 is information in which the management ID 601, the entry / exit person ID 602, the entry / exit information 603, and the use date and time 604 are associated.
[0079] The management ID 601 is identification information given for convenience for the second area management device 200 to manage each history information.
[0080] The entry / exit person ID 602 is the identification information of the user who entered or exited the second area 20 and has been authenticated, and is information corresponding to the second area authentication ID 404 of the second area account information 241 shown in FIG. 4.
[0081] The entry / exit information 603 is information indicating whether the user has entered or exited the second area 20. The entry / exit information 603 is information recorded by the second area authentication unit 255 depending on whether the second area reading unit 221 that reads the authentication information is installed outside the second area 20 or installed inside the second area 20, or whether it is set for entry or exit. If the second area reading unit 221 is installed outside the second area 20 or set for entry, "IN" is recorded, and if it is installed inside the second area 20 or set for exit, "OUT" is recorded.
[0082] The usage date and time 604 is information indicating the date and time when the user entered or left the second area 20. That is, it is information indicating the date and time when the second area authentication unit 255 performed authentication.
[0083] In the example shown in Fig. 6(a), the history with management ID 601 "m092801" has entry / exit user ID 602 of "2A022", entry / exit information 603 of "IN", and usage date / time 604 of "2024 / 5 / 18 15:30". From this history information and the second area account information 241 shown in Fig. 4, it can be seen that Bda Bko entered the second area 20 at 15:30 on May 18, 2024.
[0084] Each history in the second area history information 242 may be added every time a user enters or leaves the second area 20, and if authentication fails, information indicating authentication failure may be added.
[0085] 6(a) and related to the history of entry and exit, the second area history information 242 may include other information. For example, if there are multiple gates through which the user can enter or exit the second area 20, the second area history information 242 may include information indicating which gate the user passed through.
[0086] The existence of the second area history information 242 makes it possible to confirm who entered the second area 20 and when they left the second area 20.
[0087] <1st area history information 142> Fig. 6(b) is a conceptual data diagram showing an example of the configuration of first area history information 142. The first area history information 142 is information showing the history of users entering and leaving the second area 20. As shown in Fig. 6(b), the first area history information 142 is information in which a management ID 611, an entry / exit user ID 612, entry / exit information 613, and a usage date / time 614 are associated with each other.
[0088] The management ID 611 is identification information that is assigned to each piece of history information for the first area management device 100 to conveniently manage it.
[0089] The entry / exit user ID 612 is identification information of a user who has entered or exited the first area 10 and has been authenticated, and corresponds to the first area authentication ID 502 of the first area account information 141 shown in Figure 5.
[0090] The entry / exit information 613 is information indicating whether the user has entered or exited the first area 10. The entry / exit information 613 is information recorded by the first area authentication unit 153 depending on whether the first area reading unit 121 that reads the authentication information is installed outside the first area 10 or installed inside the first area 10, or whether it is set for entry or exit. If the first area reading unit 121 is installed outside the first area 10 or set for entry, "IN" is recorded, and if it is installed inside the first area 10 or set for exit, "OUT" is recorded.
[0091] The usage date and time 614 is information indicating the date and time when the user entered or left the first area 10. That is, it is information indicating the date and time when the first area authentication unit 153 performed authentication.
[0092] In the example shown in FIG. 6(b), the history in which the management ID 611 is "R0239030" has the entry / exit user ID 612 of "1A20022", the entry / exit information 613 of "IN", and the usage date / time 614 of "2024 / 5 / 18 15:27". From this history information and the first area account information 141 shown in FIG. 5, it can be understood that Bda Bko entered the first area 10 at 15:27 on May 18, 2024. Therefore, from the history in which the management ID 611 is "R0239030" and the history in which the management ID 601 is "m092801", it can be understood that Bda Bko passed through the gate to enter the second area 20 three minutes after passing through the gate to enter the first area 10.
[0093] Each history in the first area history information 142 may be added every time a user enters or leaves the first area 10, and if authentication fails, information indicating authentication failure may be added.
[0094] 6(b) and related to the history of entry and exit, the first area history information 142 may include other information. For example, if there are multiple gates through which the user can enter or exit the first area 10, the first area history information 142 may include information indicating which gate the user passed through.
[0095] The existence of the first area history information 142 makes it possible to confirm who entered or exited the first area 10 and when.
[0096] As shown in FIGS. 6(a) and 6(b), the configuration of the first area history information 142 may be similar to the configuration of the second area history information 242, but may also be different.
[0097] <Operation> Now, the operation of the entrance / exit control system 1 will be described.
[0098] <Account registration process> First, an example of exchange between the devices in the entrance / exit management system 1 for registering account information in the second area management device 200 will be described with reference to Fig. 7. Fig. 7 is a sequence diagram showing an example of exchange between the devices in the entrance / exit management system 1.
[0099] 7, the first area management device 100 grants a predetermined number of pieces of authority information, including a first area authentication ID for entering the first area 10, to the second area management device 200 (step S701). The second area management device 200 stores the granted authority information.
[0100] The second area management device 200 generates (registers) new account information of a user who uses the second area 20, based on an input from an administrator of the second area management device 200 (step S702). When the second area management device 200 generates (registers) the account information of the new user, the second area management device 200 associates the account information with any of a predetermined number of pieces of authority information given by the first area management device 100, that is, among the predetermined pieces of authority information, authority information to which a user has not yet been assigned (step S703). When the second area management device 200 associates the authority information, it transmits the associated authority information and the registered user information to the first area management device 100 (step S704).
[0101] When the first area management device 100 receives the authority information and the user information from the second area management device 200, the first area management device 100 registers the user information in the first area account information 141 in association with the authority information (step S705). By this process, the account of the user who uses the first area 10 is also registered in the first area management device 100 simply by registering the user's account in the second area management device 200, so that the burden of account registration on the administrator in the first area management device 100 can be reduced, and since a user who uses the second area 20 in the first area 10 naturally also uses the first area 10, the processing burden on the administrators of both the first and second areas in registering the user's account information can be reduced more than before. In addition, the administrator of the second area can freely register and change information within the scope of the authority information given by the first area management device 100 without depending on the administrator who manages the first area, so that registration of user information and change of authority information can be performed more quickly than before.
[0102] FIG. 8 is a flowchart showing an example of the operation of the second area management device 200 for realizing the exchange shown in FIG.
[0103] 8, the communication unit 210 of the second area management device 200 receives a predetermined number of pieces of authority information transmitted from the first area management device 100 (step S801). The communication unit 110 transmits the received predetermined number of pieces of authority information to the control unit 250.
[0104] The control unit 250 registers each of the predetermined number of pieces of authority information transmitted in the second area account information 241 while leaving the corresponding user information blank (step S802).
[0105] The administrator of the second area management device 200 inputs information about the new user to the input unit 220. The input unit 220 transmits the received input content to the control unit 250. Then, the reception unit 251 of the control unit 250 receives the input of the information about the new user (step S803). The reception unit 251 transmits the received information about the new user to the generation unit 252.
[0106] The generation unit 252 generates account information for the new user by associating the transmitted information of the new user with a second area authentication ID (which may be a newly created ID) to which no user is associated (step S804).
[0107] The allocation unit 253 associates (allocates) the authority information granted by the first area management device 100 to which no user has yet been associated, with the generated account information of the new user (step S805).
[0108] The registration unit 254 registers the account information generated by the generation unit 252 in the second area account information 241 in association with the authority information assigned by the assignment unit 253 (step S806).
[0109] Then, the registration unit 254 transmits the information of the newly registered user together with the associated authority information to the first area management device 100 via the communication unit 210 (step S807), and ends the process.
[0110] In the process shown in FIG. 8, the processes in steps S801 and S802 are basically performed only the first time, and the processes in steps S803 to S806 are repeatedly performed for each user registration.
[0111] FIG. 9 is a flowchart showing an example of the operation of the first area management device 100 for realizing the exchange shown in FIG.
[0112] As shown in FIG. 9, the granting unit 151 of the first area management device 100 transmits a predetermined number of pieces of authority information to the second area management device 200 via the communication unit 110 based on input from the administrator of the first area management device 100 to the input unit 120 (step S901).
[0113] The communication unit 110 receives the account information of the new user transmitted from the second area management device 200 (step S902). The account information includes user information and authority information. The communication unit 110 transmits the received information to the control unit 150.
[0114] The registration unit 152 registers the user information in the first area account information 141 in association with the transmitted authority information (step S903). Then, the registration unit 152 registers the account information in association with the area ID set for the second area management device 200 that transmitted the account information (step S904), and ends the process.
[0115] In the process shown in FIG. 9, step S901 is basically executed when the second area 20 is newly established, and the processes of steps S902 to S904 are executed in the second area management device 200 each time an account is registered.
[0116] <Authentication process> FIG. 10 is a flowchart showing the authentication process in the second area management device 200 in the entrance and exit management system 1. As shown in FIG.
[0117] As shown in FIG. 10, when the second area reading unit 221 provided in the second area 20 reads authentication information from the authentication medium of the user, it transmits the information to the second area authentication unit 255 of the control unit 250 (step S1001).
[0118] When the authentication information is transmitted, the second area authentication unit 255 performs authentication depending on whether the authentication information is registered in the second area authentication information 405 of the second area account information 241 (step S1002). That is, the second area authentication unit 255 performs authentication depending on whether the transmitted authentication information matches any of the second area authentication information 405. If the authentication information is a data string read from an ID card, the second area authentication unit 255 searches for second area authentication information 405 that matches the data string, and if found, the authentication is successful, and if not, the authentication is unsuccessful. If the transmitted authentication information is an iris image, the second area authentication unit 255 searches for second area authentication information 405 that correlates with any of the iris images registered as the second area authentication information 405 by a predetermined degree or more, and if found, the authentication is successful, and if not, the authentication is unsuccessful.
[0119] If the authentication is successful (YES in step S1002), the second area authentication unit 255 outputs a notification of authentication success to the electronic lock of the gate 222 (step S1003). This unlocks the electronic lock of the gate 222, allowing the user to enter or exit the second area 20.
[0120] Then, the second area authentication unit 255 registers the second area authentication ID 404 corresponding to the second area authentication information 405 to which the read authentication information corresponds, the entry / exit information indicating whether the entry into the second area 20 or the exit from the second area 20 was entered, and the date and time of authentication as the usage date and time in the second area history information 242 (step S1004), and terminates the processing.
[0121] On the other hand, if the authentication fails (NO in step S1002), the second area authentication unit 255 outputs information indicating that the authentication failed to the gate 222 or the second area reading unit 221 (step S1005), and ends the process. This allows the gate 222 in the second area 20 to notify the user that the authentication failed, and may prompt the user to read the authentication information again. At this time, the second area authentication unit 255 may also register information indicating that the authentication failed in the second area history information 242.
[0122] The authentication process in the second area management device 200 has been described above.
[0123] Thereby, the second area management device 200 can authenticate a user who enters or exits the second area 20, and record the history. By recording the history, it is possible to later confirm when and who entered or exited the second area 20.
[0124] 11 is a flowchart showing the authentication process in the first area management device 100 in the entrance and exit control system 1. The authentication process in the first area management device 100 is similar to the authentication process in the second area management device 200.
[0125] As shown in FIG. 11, when the second area reading unit 221 provided in the first area 10 reads authentication information from the user's authentication medium, it transmits the information to the first area authentication unit 153 of the control unit 250 (step S1101).
[0126] When the authentication information is transmitted, the first area authentication unit 153 performs authentication depending on whether the authentication information is registered in the first area authentication information 503 of the second area account information 241 (step S1102). That is, the first area authentication unit 153 performs authentication depending on whether the transmitted authentication information matches any of the first area authentication information 503. If the authentication information is a data string read from an ID card, the first area authentication unit 153 searches for first area authentication information 503 that matches the data string, and if there is, the authentication is successful, and if there is not, the authentication is unsuccessful. If the transmitted authentication information is an iris image, the first area authentication unit 153 searches for first area authentication information 503 that correlates with any of the iris images registered as the first area authentication information 503 by a predetermined degree or more, and if there is, the authentication is successful, and if there is not, the authentication is unsuccessful.
[0127] If the authentication is successful (YES in step S1102), the first area authentication unit 153 outputs a notification of authentication success to the electronic lock of the gate 122 (step S1103). This unlocks the electronic lock of the gate 122, allowing the user to enter or exit the first area 10.
[0128] Then, the first area authentication unit 153 registers the first area authentication ID 502 corresponding to the first area authentication information 503 corresponding to the read authentication information, the entry / exit information indicating entry into or exit from the first area 10, and the date and time of authentication as the usage date and time in the first area history information 142 (step S1104), and terminates the processing.
[0129] On the other hand, if the authentication fails (NO in step S1102), the first area authentication unit 153 outputs information indicating that the authentication failed to the gate 122 or the second area reading unit 221 (step S1105), and ends the process. This allows the gate 122 in the first area 10 to notify the user that the authentication failed, and may prompt the user to read the authentication information again. At this time, the first area authentication unit 153 may also register information indicating that the authentication failed in the first area history information 142.
[0130] This allows the first area management device 100 to authenticate users who enter or exit the first area 10, and record the history. By recording the history, it is possible to later confirm when and who entered or exited the first area 10.
[0131] <History confirmation process> The entry and exit history can be confirmed in the second area management device 200 and the first area management device 100. Fig. 12 is a flowchart showing an example of an operation when the manager confirms the history information in the second area management device 200.
[0132] 12, the second area management device 200 receives an access to check the history information (step S1201). The second providing unit 256 of the control unit 250 of the second area management device 200 determines whether the received access is from a user with access authority, that is, an administrator (step S1202). This determination can be made, for example, based on the administrator's ID and password. If there is no access authority (NO in step S1202), there is no authority to check the history information, and the process is terminated.
[0133] If there is access authority (YES in step S1202) and the history information the administrator wants to check is the second area history information 242 (YES in step S1203), the second providing unit 256 reads out the second area history information 242 from the storage unit 240 and causes the output unit 230 to output it (step S1204). This allows the administrator of the second area management device 200 to check the users who entered and left the second area 20 and the dates and times of entry and exit.
[0134] On the other hand, if there is access authority (NO in step S1202) and the history information the administrator wants to check is the first area history information 142 (NO in step S1203), the second providing unit 256 requests the first area history information 142 from the first area management device 100 via the communication unit 210 (step S1205). The request includes the second area ID or the ID of the second area management device 200 to indicate which device is the second area management device 200 making the request.
[0135] The communication unit 210 receives the first area history information within the scope of the authority information granted to the second area 20 (second area management device 200) from the first area management device 100 (step S1206). The communication unit 210 transmits the received first area history information to the second providing unit 256.
[0136] The second providing unit 256 causes the output unit 230 to display (output) the transmitted first area history information (step S1207). As a result, the second area management device 200 can provide the manager of the second area 20 with history information of entry and exit to the first area 10 within the scope of the authority information granted to the second area management device 200, i.e., history information of the first area authentication ID indicated by the authority information.
[0137] If the second area management device 200 receives an input to end the display of history information via the input unit 220 (YES in step S1208), it ends the process, and if not (NO in step S1208), it returns to the process of step S1203.
[0138] In this way, the second area management device 200 can provide the user with not only the history of entry and exit into the second area 20, but also the history of entry and exit into the first area 10.
[0139] FIG. 13 is a flowchart showing an example of an operation of the first area management device 100 in providing history information.
[0140] As shown in FIG. 13, the first area management device 100 receives an access to check the history information (step S1301). The first providing unit 154 of the control unit 150 of the first area management device 100 determines whether the received access is from a user with access authority, i.e., an administrator (step S1302). This determination can be made, for example, based on the ID and password of the administrator. Here, the administrator may be the administrator of the first area 10 or the administrator of the second area 20 included in the first area 10. If there is no access authority (NO in step S1302), there is no authority to check the history information, and the process is terminated.
[0141] If there is access authority and the accessor is the administrator of the first area 10 (YES in step S1303), the first providing unit 154 reads the first area history information 142 from the storage unit 140, and outputs (displays) all of the information to the output unit 130. This allows the administrator of the first area 10 to check all of the first area history information 142.
[0142] On the other hand, if there is access authority and the accessor is not the administrator of the first area 10 but the administrator of the second area 20 (NO in step S1303), only the history information of the user of the second area 20 corresponding to the accessing second area administrator is extracted from the first area history information 142 and transmitted to the second area management device 200 via the communication unit 110 (step S1305). This allows the administrator of the second area management device 200 to check the first area history information 142 with respect to the portion related to the user of the second area 20.
[0143] If the first area management device 100 receives an input to end the output of history information via the input unit 120, or if it receives an input to end access from the second area management device 200 (YES in step S1306), it ends the processing, and if it has not received such an input (NO in step S1306), it returns to the processing of step S1303.
[0144] In this way, in the entrance / exit control system 1, the manager of each area management device can check the entrance / exit history as needed.
[0145] <Authorization information addition process> However, when the number of users using the second area 20 increases, the number of pieces of authority information initially given from the first area management device 100 to the second area management device 200 may be insufficient. Therefore, the second area management device 200 may request the first area management device 100 to add more authority information. Fig. 14 is a flowchart showing an example of the operation of the second area management device 200 when adding authority information, and Fig. 15 is a flowchart showing an example of the operation of the first area management device 100 when a request to add authority information is received.
[0146] As shown in FIG. 14, it is assumed that a new user is registered in the second area management device 200 (step S1401).
[0147] Then, the control unit 250 counts the number of pieces of authority information that are not associated with user information (step S1402). Then, the counted number is compared with a predetermined threshold (step S1403). Here, the predetermined threshold is a threshold that serves as a trigger for requesting additional authority information, and may be an arbitrary number or may be 0.
[0148] If the counted number is equal to or less than a predetermined threshold (YES in step S1403), that is, if the remaining number of pieces of authority information not associated with user information is small or there is no usable authority information, the control unit 250 communicates with the first area management device 100 via the communication unit 210 to request the addition of authority information (step S1404). In response to the request, the first area management device 100 grants the additional authority information to the manager of the second area 20 (the second area management device 200).
[0149] The communication unit 210 receives the additional authority information transmitted from the second area management device 200 (step S1405). The communication unit 210 transmits the received additional authority information to the control unit 250.
[0150] The control unit 250 adds the transmitted additional authority information to the second area account information 241 (or stores it in the storage unit 240) (step S1406), and ends the process.
[0151] FIG. 15 is a flow chart showing an example of the operation on the side of the first area management device 100 in response to this.
[0152] 15, the communication unit 110 of the first area management device 100 receives a request to add authority information from the second area management device 200 (step S1501). The communication unit 110 transmits the received request to add authority information to the control unit 150.
[0153] When the request to add authority information is transmitted to the granting unit 151 of the control unit 150, the granting unit 151 generates or assigns authority information (step S1502). Generating authority information means generating a new first area authentication ID, which may be generating a predetermined number of first area authentication IDs according to a predetermined algorithm, and an authentication ID different from all existing first area authentication IDs is generated. At this time, if the authentication medium is, for example, an ID card, association with the ID card is also performed. The ID card needs to be separately mailed or handed over between administrators.
[0154] Moreover, allocating authority information may mean using, among the first area authentication IDs managed in the first area management device 100, those not associated with a user, as authority information to be granted to the second area management device 200 that has made the addition request. Moreover, in the request for adding authority information, the number of pieces of authority information to be granted may be a predetermined number, or may be a number equivalent to a predetermined ratio (for example, 10%, but not limited to this) of the number of pieces of authority information initially granted to the second area management device 200 that has made the request.
[0155] The assignment unit 151 associates the generated or assigned first area authentication ID 502 with the second area ID 504 of the second area management device 200 making the addition request, and registers the result in the first area account information 141 (step S1503).
[0156] The granting unit 151 transmits the newly generated or assigned authority information for the manager of the second area 20 to the second area management device 200 via the communication unit 110 (step S1504), and ends the process.
[0157] The authority information is essential for users who use the second area 20 because they must pass through the gate 122 related to the first area 10. A predetermined number of pieces of authority information that are assumed to be necessary depending on the size and scale of the second area 20 are initially given by the first area management device 100 (for example, when the second area 20 is laid for a tenant or company). However, as the number of users in the second area 20 increases, there is a possibility that the authority information will be insufficient. Conventionally, in such a case, the administrator of the second area management device 200 would apply to the administrator of the first area management device 100 for additional registration of a user, and the administrator of the second area management device 200 would register the user, which would be troublesome for both administrators. With the present configuration, it is possible to reduce the trouble.
[0158] <Configuration> <Third area management device 300> As shown in FIG. 1, the entrance / exit management system 1 may include a third area management device 300 that manages a third area different from the first area 10. The third area management device 300 (third area) may have some kind of partnership with the first area management device 100 (first area 10). For example, the third area and the first area 10 may be buildings of a group company. In such a group, it is possible to give some kind of reward or benefit to a user who uses the area. Therefore, for example, in a third area that has some kind of partnership with the first area 10, when a user who uses the second area 20 in the first area 10 is successful in authentication, it is possible to give some kind of reward or benefit to the user from the third area management device 300. The reward or benefit may be, for example, preferential treatment at a store in each area. The preferential treatment device may be, for example, a higher discount rate than other users, issuance of a gift certificate, a higher point accrual rate or value in a point card that can be used to purchase products or services, or a priority purchase right for a specific product, but is not limited to these. The reward or privilege may also be a right to use a specific facility in the third area. This right of use may be limited in the number of times it can be used within a specified period, and this number of times may be the time of use.
[0159] The third area management device 300 may be a computer system having substantially the same configuration as the first area management device 100.
[0160] Fig. 16 is a block diagram showing a configuration example of the third area management device 300. As shown in Fig. 16, the third area management device 300 includes a communication unit 310, an input unit 320, a storage unit 330, a storage unit 340, and a control unit 350.
[0161] The communication unit 310 is a communication interface that communicates with devices external to the third area management device 300 via the network 400. The communication unit 310 transmits specified information to the specified external device according to an instruction from the control unit 350. The communication unit 310 also transmits information received from the external device via the network 400 to the control unit 350. For example, the communication unit 310 transmits information of a user who has entered the third area to the first area management device 100 as an external device according to an instruction from the control unit 350.
[0162] The input unit 320 has a function of accepting an input from the manager of the third area management device 300 and transmitting it to the control unit 350. The input unit 320 can be realized by, for example, a hardware key or a mouse provided in the third area management device 300, or a soft key such as a touch panel or a touch key. The input to the input unit 320 may be an input by voice, and in this case, the input unit 320 is realized by a microphone. The input unit 320 may accept, for example, an input of authority information to be given to the manager of the second area 20 (the second area management device 200) and transmit it to the control unit 350. Alternatively, the input unit 320 may accept, for example, an input of information on a new user entering the first area 10 and transmit it to the control unit 350.
[0163] The input unit 320 includes a third area reading unit 321. The third area reading unit 321 is a device provided at a gate that is an entrance to the third area, and reads authentication information of a user. For example, the third area reading unit 321 may be a card reader when the authentication information is an ID card, and may be a camera when the authentication information is an iris. The input unit 320 transmits the authentication information of the user read by the third area reading unit 321 to the control unit 350.
[0164] The output unit 330 has a function of outputting data instructed by the control unit 350. The output by the output unit 330 may be realized by displaying characters or images on a monitor (display device) or the like that is attached to or connected to the third area management device 300, or may be realized by outputting audio from a speaker or earphones (audio output device) that is attached to or connected to the third area management device 300. Alternatively, the output by the output unit 330 may be realized by transmitting information to an external device via the communication unit 310.
[0165] The storage unit 340 is a recording medium that stores various programs and various data required for the operation of the third area management device 300. The storage unit 340 is realized, for example, by a hard disk drive (HDD), a solid state drive (SSD), a flash memory, etc., but is not limited to these. The storage unit 340 may be realized by a cloud storage accessible by the third area management device 300. The storage unit 340 may also configure a ROM or RAM as a work area for executing a program. The storage unit 340 may store a program that authenticates the authentication information read by the third area reading unit 321 and unlocks the gate when the authentication is successful. The storage unit 340 may also store third area account information 341 and third area history information 342. The third area account information 341 is information indicating the account of a user who enters the third area (uses the third area). The third area history information 342 is information about the history of entry and exit of a user who enters and leaves the third area. The configuration of the third area account information 341 may be similar to that of the first area account information 141. In addition, the configuration of the third area history information 342 may be similar to that of the first area history information 142.
[0166] The control unit 350 is a processor that executes processes to be realized by the third area management device 300, using various programs and various data stored in the storage unit 340. The control unit 350 authenticates users who enter the third area, and registers user account information in response to input from an administrator of the third area management device 300.
[0167] The control unit 350 includes a third area authentication unit 351, a notification unit 352, and a reward granting unit 353.
[0168] The third area authentication unit 351 authenticates the authentication information read by the third area reading unit 321. Here, authentication may be determining whether or not the user who holds the authentication information has the authority to enter the first area 10. That is, the third area authentication unit 351 determines whether or not the authentication information transmitted from the third area reading unit 321 is registered in the first area account information 141. If the authentication information is registered in the first area account information 141, the authentication is successful, and if it is not registered, the authentication is unsuccessful. If the authentication is successful, the third area authentication unit 351 unlocks the gate corresponding to the third area reading unit 321 so that the user can pass through the gate. If the authentication is unsuccessful, the third area authentication unit 351 does not unlock the gate and outputs information indicating the authentication failure to the third area reading unit 321. In this case, the third area reading unit 321 may output a character string or a voice indicating the authentication failure to notify the user that the authentication has failed.
[0169] When the third area authentication unit 351 authenticates a user and the authentication is successful, the notification unit 352 notifies (transmits) information about the successfully authenticated user to the affiliated first area management device 100 via the communication unit 310.
[0170] In response to the notification to the first area management device 100 by the notification unit 352, when the reward granting unit 353 receives information from the first area management device 100 via the communication unit 310 that the authenticated user is a specific user (a user who uses the second area in the first area), the reward granting unit 353 grants a reward to the user. Note that when there is a specific user and other users (for example, a user who does not use the second area in the first area) and rewards or benefits are granted to both users, the reward granting unit 353 may change the content of the reward or benefit, and in that case, may be configured to grant a better reward or benefit to the specific user than to the other users, and as an example, the number of points granted may be increased or the range in which a specific store or space can be used may be widened.
[0171] This concludes the description of the configuration of the third area management device 300. The first area management device 100 further receives information on a successfully authenticated user from the third area management device 300, and if the user is a user of the second area 20 in the first area 10, notifies the third area management device 300 that the authenticated user is a specific user (a user who uses the second area 20 in the first area 10).
[0172] <Operation> Figure 17 is a sequence diagram showing interactions between devices in the entrance / exit management system 1 when a user of the first area 10 enters a third area 30 that is affiliated with the first area 10, Figure 18 is a flowchart showing an example of operation of the third area management device 300 at that time, and Figure 19 is a flowchart showing an example of operation of the first area management device 100 at that time.
[0173] 17, the third area management device 300 authenticates a user who enters the third area (step S1701). Then, the third area management device 300 transmits information (e.g., an email address) of the user who has been successfully authenticated to the first area management device 100 (step S1702).
[0174] The first area management device 100 identifies whether the received user information is a user in the second area 20 (step S1703). For example, the third area management device 300 transmits the user's email address as user information to the first area management device, and identifies the user as a user in the second area 20 based on whether the email address is registered in the first area account information 131, and if registered, whether the information is associated with a second area ID. When the first area management device 100 identifies the user as a user in the second area 20, it notifies the third area management device 300 that the user is a specific user (a user in the second area 20 who uses the first area 10) (step S1704).
[0175] When the third area management device 300 receives information that the authenticated user is a specific user, it grants a reward to the user. That is, the third area management device 300 transmits information about the granted reward or benefit to the user terminal (email address) of the authenticated user, that is, the user terminal (email address) of the user in the second area 20.
[0176] The user terminal displays information about the received reward or benefit (step S1705). This allows the user in the second area 20 to recognize that the third area management device 300 has given the reward or benefit.
[0177] FIG. 18 is a flowchart showing an example of the operation of the third area management device 300 for realizing the exchange shown in FIG.
[0178] As shown in FIG. 18, the third area reading unit 321 reads the authentication information and transmits it to the control unit 350 (step S1801).
[0179] The third area authentication unit 351 judges whether the transmitted authentication information is registered or not by referring to the third area account information 341 (step S1802). If the authentication information is not registered (NO in step S1802), the third area authentication unit 351 causes the output unit 330 to output a failure of authentication (step S1808), and ends the process.
[0180] On the other hand, if the authentication is successful (YES in step S1802), the third area authentication unit 351 outputs a successful authentication to the gate of the third area and instructs it to be unlocked (step S1803). The third area authentication unit 351 also registers the entry / exit person ID, whether it is entry / exit, and the date and time of use in the third area history information 342 (step S1804). The third area authentication unit 351 transmits information on the user who has been successfully authenticated to the notification unit 352. Here, the user information is information that can identify who the user is, and may include at least the user's name, and may also include information registered in the third area account information 341, such as the user's email address, age, and sex, and is information that can uniquely identify the user.
[0181] The notification unit 352 transmits the information of the user who has been successfully authenticated, transmitted from the third area authentication unit 351, to the first area management device 100 of the partner via the communication unit 310 (step S1805). Then, the reward granting unit 353 judges whether or not information indicating that the user who has been successfully authenticated is a specific user (user in the second area) has been received from the first area management device 100 (step S1806). If the information has not been received (NO in step S1806), the process ends. On the other hand, if information indicating that the user who has been successfully authenticated is a specific user (user in the second area) has been received from the first area management device 100 (YES in step S1806), the reward granting unit 353 grants a reward to the authenticated user (step S1807) and ends the process. That is, the reward granting unit 353 transmits information indicating the content of the reward to the user's terminal (email address) via the communication unit 110, and ends the process. The reward may be, for example, information such as points that can be used in the first area or the third area that is associated with the user's account, and the points may be deducted by using the points for shopping or the like at stores in the first area or the third area. In this way, the third area management device 300 can give some kind of reward or benefit (for example, a reward or benefit associated with using the third area) to a user who uses the second area 20 in the first area 10 of the first area management device 100 that is affiliated with the third area management device 300, and can encourage the user to repeatedly use the first area or the third area.
[0182] FIG. 19 is a flowchart showing an example of the operation of the first area management device 100 for realizing the exchange shown in FIG.
[0183] 19, the communication unit 110 of the first area management device 100 receives the user information transmitted from the third area management device 300 (step S1901). The communication unit 110 transmits the received user information to the control unit 150.
[0184] The control unit 150 determines whether the transmitted user information is registered in the first area account information 141 and is associated with the second area ID (step S1902).
[0185] When the transmitted user information is registered in the first area account information 141 and is associated with the second area ID (YES in step S1902), the control unit 150 notifies the third area management device 300 that the user who performed authentication in the third area is a specific user (second area user) (step S1903), and ends the process. In this case, the privilege to be granted may be a privilege related to the third area that the user entered, for example, a privilege related to a store existing in the third area, or a right to use a specific store or space in the third area. On the other hand, when the transmitted user information is not registered in the first area account information 141, or is registered but is not associated with the second area ID (NO in step S1902), the control unit 150 notifies the third area management device 300 that the user is not a specific user (second area user) (step S1904), and ends the process.
[0186] In this way, in the entrance / exit management system 1, the third area management device 100 can be configured to allow the user of the second area 20 to receive some kind of benefit in the third area when it detects that the user of the second area 20 belonging to the first area 10 has entered the third area. As a result, the user of the second area 20 can feel a sense of value when using the third area. Note that, although the third area management device 100 is configured to grant a reward to the user here, the entity that grants the reward may be the first area management device 100 or the second area management device 200, and the reward granted at that time may be a reward or benefit related to the first area, not limited to the third area.
[0187] <Summary> As shown in the above embodiment, in the entrance / exit management system 1, the second area management device 200 of the second area 20 included in the first area 10 is granted a predetermined number of pieces of authority information from the first area 10 by the first area management device 100, so that the second area management device 200 can also manage accounts for entering and exiting the first area 10. Therefore, the processing load on the administrator of the first area management device 100 in registering accounts of users of the second area 20 in the first area 10 can be reduced.
[0188] <Supplementary Information> The entrance / exit control system according to the above embodiment is not limited to the above embodiment, and may be realized by other methods. Various modifications will be described below.
[0189] (1) In the above embodiment, an example has been shown in which the first area account information 141 and the second area account information 241 are stored in each management device, but this is not limited to the above.
[0190] The first area management device 100 and the second area management device 200 may be configured to access and manage information related to authentication of the first area 10 in a common database. To be more specific, in this case, for example, as shown in FIG. 20, a network storage 1000 is connected to a network 400. The network storage 1000 is a cloud storage on the network 400 that accepts access from the first area management device 100 and the second area management device 200 and provides the stored information to the first area management device 100 and the second area management device 200. The network storage 1000 may include a processor that processes data in the database. The cloud storage 1000 may be configured to be able to accept access from the third area management device 300 as well. The network storage 1000 may be a device that accepts access only from predetermined devices. For example, when access is accepted from an area management device (100, 200, 300), the area management device may be configured to accept access only from the area management device by presenting unique information such as an electronic certificate to the cloud storage 100.
[0191] The cloud storage 1000 stores integrated account information that is used to register user account information and grant authority information to the accounts in the first area management device 100, the second area management device 200, and the third area management device 300.
[0192] FIG. 21 is a conceptual data diagram showing an example of the configuration of integrated account information 2100 stored in the cloud storage 100. As shown in FIG.
[0193] 21, the integrated account information 2100 is account information managed for each user, and is information in which accounts for the first area, the second area, and the third area are associated with authority information if there is authority. Specifically, the integrated account information 2100 is information in which a management ID 2101, a first area authentication ID 2102, a first area authentication information 2103, a second area authentication ID 2104, a second area authentication information 2105, a third area authentication ID 2106, and a third area authentication information 2107 are associated with each other.
[0194] The management ID 2101 is identification information that is assigned for the sake of convenience in order to manage each account. Since the management ID 2101 is identification information that is unique to each user, it can also be said to be a user ID.
[0195] The first area authentication ID 2102 is identification information of the user in the first area.
[0196] The first area authentication information 2103 is information used for authentication when passing through a gate in the first area. When performing authentication, the first area management device 100 performs authentication by comparing the first area authentication information 2103 with authentication information read by the reading unit.
[0197] The second area authentication ID 2104 is identification information of the user in the second area.
[0198] The second area authentication information 2105 is information used for authentication when passing through a gate in the second area. When performing authentication, the second area management device 200 performs authentication by comparing the second area authentication information 2105 with authentication information read by the reading unit.
[0199] The third area authentication ID 2106 is identification information of the user in the third area.
[0200] The third area authentication information 2107 is information used for authentication when passing through a gate in the third area. When performing authentication, the third area management device 300 performs authentication by comparing the third area authentication information 2107 with authentication information read by the reading unit.
[0201] The user name 2108 is information indicating the name of the user indicated by the corresponding user ID 2102 .
[0202] The email address 2109 is an email address at which the user indicated by the corresponding user ID 2102 can be contacted. The email address 2109 may be an email address provided by an administrator of the second area, or may be an email address at which the user's personal terminal can be contacted.
[0203] In the integrated account information 2100, the first area authentication ID 2102 and the first area authentication information 2103 may be configured to be readable and writable basically only by the administrator of the first area management device 100. Also, in the integrated account information 2100, the second area authentication ID 2104 and the second area authentication information 2105 may be configured to be readable and writable basically only by the administrator of the second area management device 200. Also, in the integrated account information 2100, the third area authentication ID 2106 and the third area authentication information 2107 may be configured to be readable and writable basically only by the administrator of the third area management device 300.
[0204] In the integrated account information 2100, when an administrator of the second area management device 200 registers a new user, the administrator registers information in the second area authentication ID 2104 and the second area authentication information 2105, and also registers information in the corresponding user name 2108 and email address 2109.
[0205] Then, when the second area authentication ID 2104 and the second area authentication information 2105 are registered, the network storage 1000 may copy and register the first area authentication ID 2102 and the first area authentication information 2103 within the scope of the authority information granted from the first area management device 100 to the second area management device 200. In addition, when the first area authentication ID 2102 and the first area authentication information 2103 are registered, if it is determined that authentication information is to be shared between the first area and the third area, the network storage 1000 may also copy and register the third area authentication ID 2106 and the third area authentication information 2106.
[0206] In this way, the presence of the integrated account information 2100 makes it possible to centrally manage user account information and its authority information between related areas.
[0207] In the integrated account information 2100, the first area authentication ID 2102, the second area authentication ID 2104, and the third area authentication ID 2106 may use a common ID or may be common to the user ID 2102, and in that case, they may not be registered in the integrated account information 2100. The first area authentication ID 2102, the second area authentication ID 2104, and the third area authentication ID 2106 may be provided when each area management device wants to manage the account individually. In addition, instead of these area authentication IDs, information on whether or not the user has the right to enter (or exit) the corresponding area may be associated with the area, and each area management device may be configured to determine that the authentication is successful when the reading unit of each area management device reads authentication information and the authentication information is associated with information that the user corresponding to the authentication information has the right to enter (or exit) the area and the authentication information matches. If information indicating that the user does not have the right to enter (or exit) the area is associated with the area, it may be determined that authentication has failed for that area without even checking the authentication information.
[0208] Furthermore, when a common authentication medium is used for the first area authentication information 2103, the second area authentication information 2105, and the third area authentication information 2107, only one authentication information (e.g., a face image) may be registered, and each area management device may be configured to use this common one authentication information during authentication. Note that this does not need to be configured to use common authentication information in all areas, and a configuration may be used in which one authentication information is used in two or more areas, and another authentication information is used in the remaining areas.
[0209] The history information may be configured so that each area management device manages the entry and exit history for the corresponding gate, or the history information may be integrated and managed on the cloud storage 1000. In this case, the history information may be a collection of information in which information is associated with which area (area ID), which gate (gate ID), when (date and time), and who (entrant ID) entered or left. In this case, the range of the history information that can be confirmed (referenced) may be determined depending on which area management device (administrator) is accessed. For example, in the case of access from the second area management device 200, the history information of the cloud storage 1000 is provided with the history information of the second area and the history information associated with the authority information granted by the first area management device 100, and, for example, the history of entry and exit in the third area is not provided.
[0210] In this way, by storing one integrated account information in a storage accessible to all area management devices, it is possible to easily manage the user's account information and also to perform the same operation as that shown in the above embodiment, thereby reducing the workload of the administrator of the first area management device 100 and the administrator of the second area management device 200. Furthermore, by unifying the authentication information and using biometric information, not only will the authentication information not be used by others, but it will also be possible to reliably determine whether the authentication information belongs to the same person when a problem occurs, etc., so that the user's movement route can be traced by linking the history information of the first area, second area, and third area, and improved security can also be expected.
[0211] (2) In the above embodiment, the process of step S802 may be limited to simply storing the received authority information in storage unit 240, and the information may be registered in second area account information 241 in step S806.
[0212] (3) In the above embodiment, the second area management device 200 may be configured to, when detecting the exit of a user, notify the first area management device 100 of that fact. Moreover, the first area management device 100 may be configured to, when detecting the entry of a user, notify the second area management device 200 of that fact.
[0213] (4) In the above embodiment, the second area management device 200 applies to the first area management device 100 to add authority information, but this is not the only possible mode. In the first area management device 100, it is possible to check whether user information is associated with the authority information assigned to the second area 20 by using the first area account information 141. Therefore, the assigning unit 151 may determine whether the number of pieces of authority information not associated with user information is equal to or less than a predetermined number, and when it is determined that the number is equal to or less than the predetermined number, the assigning unit 151 may automatically assign additional authority information to the second area management device 200.
[0214] (5) In the above embodiment, when adding authority information, the second area management device 200 may inquire of the administrator whether to apply for the addition of authority information, and may be configured to make the application for the addition of authority information to the first area management device 100 if permission is obtained from the administrator. Furthermore, when adding authority information, the second area management device 200 may inquire of the administrator of the second area 20 as to input the number of pieces to be added.
[0215] In response to this, the first area management device 100 may also be configured to inquire of the manager of the first area 10 that there has been an application for additional authority information and whether it is OK to grant the additional authority information.
[0216] (6) In the above embodiment, if a separate fourth area exists within the second area 20 and the fourth area is managed by a fourth area management device other than the second area management device 200, the second area management device 200 may be configured to grant authority information for entering the second area 20 to the fourth area management device, similar to the first area management device 100. In this case, unlike the first area management device 100, the authority information that the second area management device 200 grants as the second area authentication ID also includes a part of the authority information granted by the first area management device 100.
[0217] In this way, the relationship between the first area management device 100 and the second area management device 200 may be configured to be applicable to the relationship between the second area management device 200 and the fourth area management device.
[0218] (7) In the above embodiment, the third area management device 300 is configured to transmit information about all users who have been successfully authenticated to the first area management device 100. This configuration may increase the amount of communication and cause congestion in the traffic between the first area management device 100 and the third area management device 300. Therefore, the third area management device 300 may be configured to transmit information about only some users, not all users who have been successfully authenticated. Specifically, the first area management device 100 transmits information about users in the second area 20 who use the first area 10 to the third area management device 300 in advance, and the third area management device 300 stores this information. Then, when performing authentication, information about the users who have been successfully authenticated may be transmitted to the first area management device 100 only when it is determined that authentication has been performed for a user corresponding to the stored information about the users in the second area. The user information transmitted from the first area management device 100 to the third area management device 300 may be information on all users who use the first area 10, or may be information on a specific user selected by an administrator of the first area management device 100. The user information to be transmitted may be information on a user to whom an administrator of the first area management device or the like wishes to give a reward or a privilege.
[0219] (8) In the above embodiment, when an administrator of the second area registers an account of a user in the second area and grants authority information to the account, the account information of the first area is configured to be reflected, but this may be reversed. That is, when an administrator of the first area registers an account of a user in the first area and grants authority information to the account, if it is known that the user is also a user in the second area, the account information of the second area may be configured to be reflected.
[0220] (9) In the above embodiment, when registering account information and assigning authority information to the account, the first area management device 100 may send a confirmation email to the email address stored as the account information. Then, when it is confirmed that the confirmation email has been delivered (when the mailer daemon does not reply), the account information and its authority information may be registered assuming that the user really exists. Furthermore, when the first area management device 100 is unable to send an email to an email address, it may not register the information in the first area account information, and may further inquire of the second area management device 200 as to whether the registered email address is correct or whether the registered user actually exists.
[0221] (10) In the above embodiment, the account management and entrance / exit management in the entrance / exit management system are performed by the processor of the area management device of the entrance / exit management system executing a predetermined program (management application), etc. However, this may be realized by a logic circuit (hardware) or a dedicated circuit formed in an integrated circuit (IC (Integrated Circuit) chip, LSI (Large Scale Integration)) in the device. Furthermore, these circuits may be realized by one or more integrated circuits, and the functions of the multiple functional units shown in the above embodiment may be realized by one integrated circuit. LSIs are sometimes called VLSIs, super LSIs, ultra LSIs, etc. depending on the degree of integration.
[0222] The program may be recorded on a processor-readable recording medium, and the recording medium may be a "non-transient tangible medium" such as a tape, a disk, a card, a semiconductor memory, or a programmable logic circuit. The program may be supplied to the processor via any transmission medium capable of transmitting the program (such as a communication network or a broadcast wave). That is, for example, the program may be downloaded from a network and executed using an information processing device such as a smartphone. The present invention may also be realized in the form of a data signal embedded in a carrier wave, in which the program is embodied by electronic transmission.
[0223] The above program can be implemented using, for example, scripting languages such as ActionScript and JavaScript (registered trademark), and object-oriented programming languages such as Objective-C, Java (registered trademark), C++, Python, and R, but these languages are just examples.
[0224] (11) The various examples shown in the above embodiment may be combined as appropriate. [Explanation of symbols]
[0225] 1. Entrance / Exit Control System 100 First area control device 110 Communications Department 120 Input section 121 First area reader Gate 122 130 Output section 140 Storage section 141 1st Area Account Information 142 Area 1 History Information 150 Control section 151 Granting Department 152 Registration Department 153 1st Area Authentication Department 154 1st provision part 200 Second area control device 210 Communications Department 220 Input section 221 Second area reader Gate 222 230 Output section 240 Storage section 241 2nd Area Account Information 242 Area 2 History Information 250 Control section 251 Reception 252 Generation part 253 Allocation Section 254 Registration Department 255 Second Area Authentication Department 256 2nd provision part 300 Third area control device 310 Communications Department 320 Input section 321 Third area reader 330 Output section 340 Storage section 341 3rd Area Account Information 342 Third Area History Information 350 Control section 351 Third Area Authentication Department 352 Notification Department 353 Reward Department
Claims
1. an assigning unit that assigns a predetermined number of pieces of authority information for entering a first area, the authority information including information on a first area authentication medium used by a user to enter the first area, to a manager of a second area included in the first area; a reception unit that receives an input of authentication information of the user of the second area; a generation unit that generates an account for the user in the second area based on authentication information of the user; an allocation unit that allocates one of the predetermined number of pieces of authority information to the account of the user generated by the generation unit; a registration unit that registers the account, including information on a second area authentication medium used by the user to enter the second area, in an account database; a second area reading unit that reads second area medium information when entering the second area; a second area authentication unit that performs authentication based on whether or not the second area medium information read by the second area reading unit is registered in the account database; a first area reading unit that reads first area medium information when entering the first area; a first area authentication unit that performs authentication based on whether or not the first area medium information read by the first area reading unit is registered in the account database; Equipped with An entrance / exit management system in which the first area medium information and the second area medium information are registered in the account database as one account of one user and used for authentication, and are different from each other.
2. a first storage unit configured to store first area history information that is recorded in response to authentication by the first area authentication unit and indicates a history of users entering and leaving the first area; a first providing unit that provides the first area history information to a manager of the second area within the scope of authority information granted to the second area. The entrance / exit management system according to claim 1 .
3. a second storage unit configured to store second area history information that is recorded in response to authentication by the second area authentication unit and indicates a history of users entering and leaving the second area; a second providing unit that provides the second area history information to a manager of the second area; Equipped 3. The entrance / exit management system according to claim 1 or 2.
4. a determination unit that determines whether a remainder obtained by subtracting the number of pieces of authority information assigned by the assignment unit from the predetermined number is equal to or smaller than a predetermined threshold; a request unit that requests an increase of the predetermined number from a manager of the first area when the determination unit determines that the remaining number is equal to or less than the predetermined threshold value, The entrance / exit management system according to claim 1 , wherein the granting unit grants additional authority information to a manager of the second area.
5. The entrance / exit control system computer a granting step of granting a predetermined number of pieces of authority information for entering a first area, the authority information including information of a first area authentication medium used by a user to enter the first area, to an administrator of a second area included in the first area; a receiving step of receiving an input of authentication information of the user of the second area; generating an account for the user in the second area based on authentication information of the user; an allocation step of allocating one of the predetermined number of pieces of authority information to the account of the user generated in the generation step; a registration step of registering the account including information of a second area authentication medium used by the user to enter the second area in an account database; a second area reading step of reading second area medium information when entering the second area; a second area authentication step of authenticating the second area medium information read in the second area reading step based on whether the second area medium information is registered in the account database; a first area reading step of reading first area medium information when entering the first area; a first area authentication step for authenticating the first area medium information read in the first area reading step based on whether the first area medium information is registered in the account database; Run The entrance / exit management method, in which the first area medium information and the second area medium information are registered in the account database as one account of one user and used for authentication, and are different from each other.
Citation Information
Patent Citations
Entrance / leaving management system and id card
JP2006059161A
Account management system, base account management apparatus, descendant account management apparatus, and program
JP2009071435A
Facility equipment cooperation system, equipment control method, and agent apparatus
JP2009224852A
Security system, information processing device, and method for controlling information processing device
JP2022154997A
Entrance / Exit Management System, Entrance / Exit Management Method, and Entrance / Exit Management Program
JP7675917B1
Cited By
Entrance / Exit Management System, Entrance / Exit Management Method, and Entrance / Exit Management Program
JP7675917B1