Authentication System, Terminal Device, Authentication Method, and Program
The authentication system addresses the challenge of authentication failures due to communication breakdowns by using sound waves to authenticate users or terminal devices based on identification signals, allowing for independent authentication without reliance on the management server.
Patent Information
- Application Number
- JP2021110143
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-07-01
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-07-01
AI Technical Summary
The existing authentication systems, such as the one described in Patent Document 1, face challenges in performing user authentication when there is a failure in communication between the terminal device (mobile terminal) or authentication device (authentication terminal) and the authentication server.
An authentication system that includes a terminal device and an authentication device capable of authenticating users or terminal devices using sound waves, even when communication with a management server is not possible. The system employs a first output unit in the terminal device to output sound waves containing a first identification signal based on setting information provided by the management server, and a comparison is made with a second identification signal stored in the authentication device to authenticate users or terminal devices.
This solution enables user or terminal device authentication to be performed independently of communication with the management server, ensuring continuous authentication capabilities even in cases of network failure.
Smart Images

Figure 0007683357000001 
Figure 0007683357000002 
Figure 0007683357000003
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication system, a terminal device, an authentication method, and a program.
Background Art
[0002] There is an authentication system that performs user authentication using sound waves output by a mobile terminal. For example, there is known an authentication system in which a mobile terminal transmits a sound code of a one-time password created in time synchronization with an authentication server, and an authentication terminal requests the authentication server to authenticate the acquired sound code to perform user authentication (see, for example, Patent Document 1).
Summary of the Invention
Problems to be Solved by the Invention
[0003] In the authentication system disclosed in Patent Document 1, there is a problem that user authentication cannot be performed when a terminal device (mobile terminal) or an authentication device (authentication terminal) cannot communicate with the authentication server.
[0004] One embodiment of the present invention has been made in view of the above problems, and in an authentication system including a terminal device and an authentication device that performs authentication using sound waves output by the terminal device, even when communication with a management server is not possible, it is possible to authenticate a user or a terminal device.
Means for Solving the Problems
[0005] To solve the above problems, an authentication system according to an embodiment of the present invention is an authentication system including a terminal device and an authentication device for authenticating the terminal device. The terminal device has a first output unit that outputs a sound wave including a first identification signal based on setting information provided by a management server and including an identification signal and information on the time when the identification signal is valid. The authentication device compares the first identification signal included in the sound wave output by the terminal device with a second identification signal based on the setting information provided by the management server, and has an authentication unit for authenticating a user using the terminal device or the terminal device. Moreover, the setting information includes setting information for setting a plurality of identification signals whose valid times overlap.
Effects of the Invention
[0006] According to an embodiment of the present invention, in an authentication system including a terminal device and an authentication device that performs authentication using a sound wave output by the terminal device, even when communication with a management server is not possible, a user or a terminal device can be authenticated.
Brief Description of the Drawings
[0007]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
MODE FOR CARRYING OUT THE INVENTION
[0008] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings.
[0009] <Configuration of the System> FIG. 1 is a diagram showing an example of the system configuration of an authentication system according to an embodiment. The authentication system 100 includes, as an example, a terminal device 110, an authentication device 120, a security lock device 121, a management server 130, and the like.
[0010] The terminal device 110 is an information terminal such as a smartphone, a tablet terminal, or a wearable terminal possessed by a user, and can communicate with the management server 130 by connecting to the communication network 101 via wireless communication. The terminal device 110 executes an application program (hereinafter referred to as an app) corresponding to the authentication system 100, and outputs, for example, a sound wave including an identification signal from a speaker included in the terminal device 110 according to a user operation or the like. However, the terminal device 110 is not limited to a general-purpose information terminal, and may be a dedicated terminal device that executes predetermined firmware or the like.
[0011] The authentication device 120 is a device having a computer configuration, which includes a microphone that picks up the sound wave output by the terminal device 110 and can communicate with the management server 130 via the communication network 101. The authentication device 120 extracts the identification signal included in the sound wave output by the terminal device 110 and compares it with the identification signal stored in the authentication device 120 to authenticate the user who uses the terminal device 110 or the terminal device 110 or the like. Further, as an example, when it is confirmed by authentication that the user who uses the terminal device 110 is a legitimate user, the authentication device 120 releases the lock of the security lock device 121.
[0012] The security lock device 121 is a device that locks and unlocks devices, facilities, etc. according to control from the authentication device 120, for example. Note that the authentication device 120 and the security lock device 121 may be integrated.
[0013] The management server 130 is an information processing device having a computer configuration or a system including a plurality of computers. The management server 130 generates, for example, setting information including an identification signal and information on the time when the identification signal is valid, and provides the generated setting information to the terminal device 110 and the authentication device 120. The terminal device 110 and the authentication device 120 acquire the setting information from the management server 130 and store it in a storage unit or the like. Thereby, the terminal device 110 and the authentication device 120 according to the present embodiment do not need to communicate with the management server 130 when performing authentication.
[0014] FIG. 2 is a diagram showing another example of the system configuration of the authentication system according to an embodiment. As shown in FIG. 2, the authentication device 120 may be configured to be connected to the communication network 101 and communicate with the management server 130 by wireless communication or the like.
[0015] Further, the authentication device 120 may be various devices that authenticate the user who uses the terminal device 110. For example, the authentication device 120 may be an output device such as a PJ (Projector), an IWB (Interactive White Board), a digital signage, a HUD (Head Up Display) device, or an industrial machine. Further, the authentication device 120 may be an imaging device, a sound collection device, a medical device, a network home appliance, a connected car mobile phone, a smartphone, a tablet terminal, a game machine, a PDA (Personal Digital Assistant), a digital camera, or a PC (Personal Computer).
[0016] <Hardware Configuration> Next, the hardware configuration of each device included in the authentication system 100 will be described.
[0017] (Hardware Configuration of Terminal Device) FIG. 3 is a diagram showing an example of the hardware configuration of the terminal device according to an embodiment. As shown in FIG. 3, the terminal device 110 includes a CPU (Central Processing Unit) 301, a ROM (Read Only Memory) 302, a RAM (Random Access Memory) 303, a storage device 304, a CMOS (Complementary Metal Oxide Semiconductor) sensor 305, an imaging element I / F (Interface) 306, a sensor 307, a media I / F 309, a GPS (Global Positioning System) receiver 310, and the like.
[0018] Among these, the CPU 301 controls the operation of the entire terminal device 110 by executing a predetermined program. The ROM 302 stores programs used for starting up the CPU 301, such as an IPL (Initial Program Loader). The RAM 303 is used as a work area for the CPU 301. The storage device 304 is realized by, for example, an SSD (Solid State Drive), a flash ROM, etc., and is a large-capacity non-volatile storage device that stores programs such as an OS (Operating System), applications, and various data.
[0019] The CMOS sensor 305 is a type of built-in imaging means that captures a subject (mainly a self-portrait) according to the control of the CPU 301 to obtain image data. Note that the terminal device 110 may have imaging means such as a CCD (Charge Coupled Device) sensor instead of the CMOS sensor 305. The imaging device I / F 306 is a circuit that controls the driving of the CMOS sensor 305. The sensor 307 is various sensors such as an electronic magnetic compass, a gyro compass, and an acceleration sensor that detect geomagnetism. The media I / F 309 controls the reading or writing (storage) of data to / from a recording medium 308 such as a flash memory. The GPS receiver 310 receives GPS signals from GPS satellites.
[0020] In addition, the terminal device 110 includes a long-distance communication circuit 311, an antenna 311a of the long-distance communication circuit 311, a CMOS sensor 312, an imaging device I / F 313, a microphone 314, a speaker 315, an audio input / output I / F 316, a display 317, an external device connection I / F 318, a short-distance communication circuit 319, an antenna 319a of the short-distance communication circuit 319, and a touch panel 320.
[0021] Among these, the long-distance communication circuit 311 is a circuit that communicates with other devices via, for example, the communication network 101. The CMOS sensor 312 is a type of built-in imaging means that captures a subject according to the control of the CPU 301 to obtain image data. The imaging device I / F 313 is a circuit that controls the driving of the CMOS sensor 312. The microphone 314 is a built-in device that converts sound waves into sound wave signals. The speaker 315 is a built-in device that converts sound wave signals into physical vibrations to generate sound waves. The audio input / output I / F 316 is a circuit or the like that processes the input / output of sound wave signals according to the control of the CPU 301.
[0022] The display 317 is a type of display means such as liquid crystal or organic EL (Electro Luminescence) that displays an image of a subject, various icons, etc. The external device connection I / F 318 is an interface for connecting various external devices. The short-distance communication circuit 319 performs short-distance wireless communication such as NFC (Near Field Communication) and Bluetooth (registered trademark). The touch panel 320 is a type of input means for operating the terminal device 110 by a user pressing the display 317.
[0023] Also, the terminal device 110 includes a bus line 321. The bus line 321 includes an address bus, a data bus, and various control signals for electrically connecting each component such as the CPU 301 shown in FIG. 3.
[0024] (Hardware Configuration of Authentication Device) FIG. 4 is a diagram showing an example of the hardware configuration of an authentication device according to an embodiment. The authentication device 120 includes, for example, a CPU 401, a memory 402, a storage device 403, an external device connection I / F 404, a communication I / F 405, an audio input / output I / F 406, a microphone 407, a speaker 408, and a bus line 409, etc.
[0025] The CPU 401 is an arithmetic unit that realizes each function of the authentication device 120 by, for example, reading a program and data stored in a storage device 403 or the like onto the memory 402 and executing processing. The memory 402 includes, for example, a RAM used as a work area of the CPU 401 and a ROM that stores a startup program of the authentication device 120. The storage device 403 is a non-volatile large-capacity storage device that stores an OS, applications, and various data, and is realized by, for example, an HDD (Hard Disk Drive) or an SSD.
[0026] The external device connection I / F 404 is an interface for connecting an external device such as the security lock device 121 to the authentication device 120. The communication I / F 405 is a communication interface for connecting the authentication device 120 to the communication network 101, such as a LAN (Local Area Network) or a WAN (Wide Area Network). The audio input / output I / F 406 includes, for example, an amplification circuit and a volume adjustment circuit that amplify a sound wave signal input from the microphone 407 and a sound wave signal output to the speaker 408. Further, the audio input / output I / F 406 may include, for example, a DSP (Digital Signal Processor) or an ASIC (Application Specific Integrated Circuit) that processes the sound wave signal.
[0027] The microphone 407 is a microphone that acquires sound waves around the authentication device 120 and converts them into sound wave signals. The speaker 408 is a speaker that converts the sound wave signal input from the audio input / output I / F 406 into sound waves and outputs them. Note that the speaker 408 is optional, and the authentication device 120 may not have the speaker 408. The bus line 409 is commonly connected to the above components and is a bus that transmits, for example, an address signal, a data signal, and various control signals.
[0028] (Hardware Configuration of the Management Server) The management server 130 has, for example, the hardware configuration of a computer 500 as shown in FIG. 5. Alternatively, the management server 130 includes a plurality of computers 500.
[0029] FIG. 5 is a diagram showing an example of the hardware configuration of a computer according to an embodiment. The computer 500 includes, for example, a CPU 501, a ROM 502, a RAM 503, an HD (Hard Disk) 504, an HDD controller 505, a display 506, an external device connection I / F 507, a network I / F 508, a keyboard 509, a pointing device 510, a DVD-RW (Digital Versatile Disk Rewritable) drive 512, a media I / F 514, and a bus line 515, etc.
[0030] Among these, the CPU 501 controls the overall operation of the computer 500. The ROM 502 stores, for example, programs used for starting up the CPU 501 such as the IPL. The RAM 503 is used as a work area of the CPU 501, etc. The HD 504 stores various data such as programs. The HDD controller 505 controls the reading and writing of various data to and from the HD 504 according to the control of the CPU 501.
[0031] The display 506 displays various information such as a cursor, menu, window, characters, or images. The external device connection I / F 507 is an interface for connecting various external devices. The network I / F 508 is an interface for performing data communication using the communication network 101.
[0032] The keyboard 509 is a type of input means having a plurality of keys for inputting characters, numerical values, various instructions, etc. The pointing device 510 is a type of input means for selecting and executing various instructions, selecting a processing target, moving a cursor, etc. The DVD-RW drive 512 controls reading or writing of various data with respect to the DVD-RW 511 as an example of a removable recording medium. Note that the DVD-RW 511 is not limited to DVD-RW and may be other recording media. The media I / F 514 controls reading or writing (storage) of data with respect to the media 513 such as a flash memory. The bus line 515 includes an address bus, a data bus, various control signals, etc. for electrically connecting the above-described respective components.
[0033] <Functional Configuration> Next, the functional configuration of the authentication system 100 according to the present embodiment will be described. FIG. 6 is a diagram showing an example of the functional configuration of the authentication system according to an embodiment.
[0034] (Functional Configuration of Terminal Device) The terminal device 110, for example, realizes a first communication unit 611, a first setting unit 612, a first generation unit 613, a first output unit 614, an operation reception unit 615, a storage unit 616, etc. when the CPU 301 executes a program stored in a storage medium such as the storage device 304. Note that at least a part of the above-described respective functional configurations may be realized by hardware.
[0035] The first communication unit 611 executes first communication processing for connecting the terminal device 110 to the communication network 101 and communicating with the management server 130, etc. using, for example, a long-distance communication circuit 311 or the like.
[0036] When the first setting unit 612 can communicate with the management server 130 using the first communication unit 611, it acquires setting information 617 from the management server 130 and executes a first setting process of setting the setting information 617 in the terminal device 110. As an example, the first setting unit 612 stores the setting information 617 acquired from the management server 130 in a storage unit 616 provided in the terminal device 110. As another example, based on the setting information 617 acquired from the management server 130, the first setting unit 612 sets identification signal data and valid time information, which is information on the time when the identification data is valid, in a predetermined storage area of the storage unit 616. Alternatively, the first setting unit 612 may set the identification signal data and the valid time information in the first generation unit 613 or the first output unit 614.
[0037] The first generation unit 613 executes a first generation process of generating a first identification signal based on setting information 617 including an identification signal (identification signal data) provided by the management server 130 and information on the time when the identification signal is valid (valid time information).
[0038] As an example, the setting information 617 acquired by the first setting unit 612 from the management server 130 includes identification signal information 701 and valid time information 702 as shown in FIG. 7(A). Further, the identification signal information 701 includes, for example, identification signal data 711 and encryption information 712. The identification signal data 711 is data representing an identification signal of a predetermined number of bits, for example. The encryption information 712 is information for encrypting the identification signal data 711. The valid time information 702 is information indicating the time (period) when the identification signal generated from the identification signal information 701 is valid.
[0039] The first generation unit 613 generates the first identification signal, for example, by referring to the current time and the valid time information 702 to specify valid identification signal information 701 and encrypting the identification signal data 711 included in the valid identification signal information 701 based on the encryption information 712. Note that encryption by the encryption information 712 is optional and not essential.
[0040] Note that, as shown in FIG. 7(B), the identification signal information 701 may include an identification signal generation library 713. The identification signal generation library 713 is a program for generating an identification signal, and is not limited to a library, and may be, for example, a plug-in or a module. In this case, the first generation unit 613 specifies valid identification signal information 701 by referring to, for example, the current time and the valid time information 702, and generates a first identification signal using the identification signal generation library included in the valid identification signal information 701.
[0041] The first output unit 614 executes a first output process of outputting a sound wave including the first identification signal generated by the first generation unit 613, using, for example, the audio input / output I / F 316 and the speaker 315. For example, the first output unit 614 outputs a sound wave including the first identification signal for a predetermined period in response to a predetermined operation by a user using the terminal device 110.
[0042] FIG. 8 is a diagram for explaining a sound wave including an identification signal according to an embodiment. This diagram shows, for example, an image obtained by performing FFT (fast Fourier transform) analysis on sound waves around the authentication device 120 acquired by the microphone 407 of the authentication device 120.
[0043] Since the sound waves around the authentication device 120 include various noises, it is desirable that the first output unit 614 of the terminal device 110 outputs a sound wave 801 including the first identification signal within a predetermined frequency band with relatively little noise, as shown in FIG. 8.
[0044] As a suitable example, the first output unit 614 outputs a sound wave 801 including a first identification signal using a frequency of 16 kHz or higher within the frequency range (for example, 20 Hz to 20 kHz) that can be acquired by the microphone of the authentication device 120. Thereby, as shown in FIG. 8, the sound wave 801 including the first identification signal is less likely to be affected by noise. In addition, since sound waves with a frequency of 16 kHz or higher are difficult for ordinary people to hear, it is possible to output a sound wave including the first identification signal without giving discomfort to people. However, it is not limited to this, and the terminal device 110 may output a sound wave including the first identification signal using a sound wave with a frequency of less than 16 kHz.
[0045] In addition, in this embodiment, the method for generating a sound wave including an identification signal is not particularly limited. For example, within a predetermined frequency band, it may be a combination of turning on or off sound waves of a plurality of frequencies to represent an identification signal. In this case, for example, by setting the on state of the sound wave as the digital value "1" and the off state of the sound wave as the digital value "0", an identification signal of multiple bits can be represented. However, the method of representing the sound wave ID by the sound wave is not limited to this, and it may be a method of modulating and outputting the identification signal by a predetermined modulation method or the like.
[0046] The operation reception unit 615 receives operations by users who use the terminal device 110. For example, the operation reception unit 615 displays an operation screen on the display 317 and executes an operation reception process for receiving operations on the operation screen using the touch panel 320. Alternatively, the operation reception unit 615 may receive voice operations by users using the microphone 314, the audio input / output I / F 316, and the like.
[0047] The memory unit 616 is realized by, for example, a program executed by the CPU 301 and a storage device 304, etc., and stores, for example, setting information 617 and sound wave information 618 as shown in FIGS. 7(A) and (B). The sound wave information 618 includes information such as the intensity and frequency of a sound wave including the first identification signal output by the first output unit 614. As described above, when the first identification signal is represented by turning on or off a plurality of sound waves within a predetermined frequency band, the sound wave information 618 includes information such as the frequencies of the plurality of sound waves.
[0048] (Functional Configuration of Authentication Device) The authentication device 120 realizes, for example, a second communication unit 621, a second setting unit 622, a first extraction unit 623, an authentication unit 624, a memory unit 625, etc. by the CPU 401 executing a program stored in a storage medium such as a storage device 403. Note that at least a part of each of the above functional configurations may be realized by hardware.
[0049] The second communication unit 621 executes second communication processing for connecting the authentication device 120 to the communication network 101 using, for example, a communication I / F 405, etc. and communicating with the management server 130, etc.
[0050] The second setting unit 622 executes second setting processing for acquiring setting information 626 from the management server 130 and setting a second identification signal based on the setting information 626 in the authentication device 120 when it can communicate with the management server 130 using the second communication unit 621.
[0051] Note that the setting information 617 provided by the management server 130 to the terminal device 110 and the setting information 626 provided by the management server 130 to the authentication device 120 are information representing the same identification signal. However, since the terminal device 110 and the authentication device 120 do not perform time synchronization, for example, due to an error in the internal time, etc., there may be a period in which the first identification signal generated by the terminal device 110 and the second identification signal set in the authentication device 120 are different identification signals. Therefore, here, the identification signal generated by the first generation unit 613 is called the first identification signal, and the identification signal set in the authentication device 120 is called the second identification signal.
[0052] The first extraction unit 623 executes a first extraction process for extracting a first identification signal included in the sound wave output by the terminal device 110. For example, the first extraction unit 623 uses the microphone 407, the audio input / output I / F 406, etc., to analyze the sound wave signal obtained by acquiring the sound wave around the authentication device 120, and extracts the first identification signal. For example, the first extraction unit 623 may extract the first identification signal by performing FFT analysis on the sound wave signal obtained by acquiring the sound wave around the authentication device 120 and determining the presence or absence (on or off) of the sound waves of the plurality of frequencies described above.
[0053] The authentication unit 624 compares the first identification signal extracted by the first extraction unit 623 with the second identification signal set in the authentication device 120, and executes an authentication process for authenticating the user using the terminal device 110 or the terminal device 110. For example, when the first identification signal and the second identification signal match, the authentication unit 624 determines that the user is a legitimate user.
[0054] In the example of FIG. 6, when the user is a legitimate user, the authentication unit 624 transmits a predetermined security signal to the security lock device 121 to unlock the security lock, for example.
[0055] The security lock device 121 includes a security signal receiving unit 601, a lock control unit 602, etc. When the security signal receiving unit 601 receives a predetermined security signal from the authentication unit 624, it requests the lock control unit 602 to unlock. The lock control unit 602 unlocks the security lock according to the control of the security signal receiving unit 601. However, this is just an example, and the authentication unit 624 may permit the use of the device, login, etc. when the user is a legitimate user.
[0056] The memory unit 625 is realized by, for example, a program executed by the CPU 401 and a storage device 403, etc., and stores, for example, setting information 626 and sound wave information 627 as shown in FIGS. 7(A) and (B). The sound wave information 627 includes information such as the intensity and frequency of a sound wave including the first identification signal output by the first output unit 614. The first extraction unit 623 extracts the first identification signal based on this sound wave information 627.
[0057] (Functional Configuration of Management Server) The management server 130 is realized by, for example, one or more computers 500 included in the management server 130 executing a program stored in a predetermined storage medium, thereby realizing a communication unit 631, a user information management unit 632, a setting information providing unit 633, a setting information generating unit 634, a memory unit 635, etc. Note that at least a part of the above functional configurations may be realized by hardware.
[0058] The communication unit 631 executes communication processing for connecting the management server 130 to the communication network 101 using, for example, a network I / F 508, etc., and communicating with the terminal device 110, the authentication device 120, etc.
[0059] The user information management unit 632 stores and manages user information in which the information of the authentication device 120 and the information of the terminal device 110 used by the user registered in association with the authentication device 120 are associated, in a memory unit 635, etc. Note that the information of the authentication device 120 includes, for example, an authentication device ID for identifying the authentication device 120 and destination information for communicating with the authentication device 120. Alternatively, the information of the terminal device 110 includes, for example, a terminal device ID for identifying the terminal device 110 and destination information for communicating with the terminal device 110.
[0060] The setting information providing unit 633 generates setting information including an identification signal and information on the time when the identification signal is valid, using the setting information generation unit 634, and provides the generated setting information to the terminal device 110 and the authentication device 120. For example, the setting information providing unit 633 transmits setting information 617, 626 as shown in FIG. 7(A) or FIG. 7(B) to the destination of the authentication device 120 registered in the user information and the destination of the terminal device 110.
[0061] The setting information generation unit 634 generates, for example, setting information 617, 626 as shown in FIG. 7(A) or FIG. 7(B) in response to a request from the setting information providing unit 633. The storage unit 635 stores various information such as user information managed by the user information management unit 632, for example.
[0062] Note that the functional configuration of the authentication system 100 shown in FIG. 6 is an example. For example, the storage unit 635 may be realized by an external storage server or a cloud service outside the authentication system 100. Further, the setting information generation unit 634 may use an external service that provides a unique identification signal outside the authentication system 100. Further, at least a part of the functional configuration provided in the management server 130 may be provided in other devices such as the authentication device 120 or the terminal device 110.
[0063] For example, when the authentication device 120 is an electronic device such as an image forming apparatus, one of the plurality of authentication devices 120 included in the authentication system 100 may have the functional configuration of the management server 130.
[0064] <Flow of processing> Subsequently, the flow of processing of the authentication method according to the present embodiment will be described by exemplifying a plurality of embodiments.
[0065] [First Embodiment] (Setting process of setting information) FIG. 9 is a sequence diagram showing an example of the setting process of setting information according to the first embodiment.
[0066] In step S901, the setting information providing unit 633 of the management server 130 uses the setting information generation unit 634 to generate setting information 617, 626 including valid time information 702 as shown in FIG. 7, for example. Here, the setting information 617 and the setting information 626 are, for example, setting information with the same content. However, it is not limited to this. As long as the setting information 617 and the setting information 626 represent the same identification signal, for example, a part of the format or the like may be different according to the device. Here, the following description will be made on the assumption that the setting information 617 and the setting information 626 have the same content.
[0067] In steps S902 and S903, the setting information providing unit 633 of the management server 130 refers to the user information managed by the user information management unit 632, for example, and transmits the created setting information to the terminal device 110 and the authentication device 120. Preferably, when the transmission of the setting information to the terminal device 110 fails, the setting information providing unit 633 retries the transmission of the setting information to the terminal device 110. Similarly, when the transmission of the setting information to the authentication device 120 fails, the setting information providing unit 633 retries the transmission of the setting information to the authentication device 120.
[0068] In step S904, the first setting unit 612 of the terminal device 110 sets a valid identification signal based on the setting information 617 received (acquired) from the management server 130. For example, the first setting unit 612 stores the setting information 617 received by the first communication unit 611 from the management server in the storage unit 616. Further, the first setting unit 612 sets valid identification signal information 701 in, for example, the first generation unit 613 or the like based on the valid time information 702 included in the setting information 617.
[0069] In step S905, the second setting unit 622 of the authentication device 120 sets a valid identification signal for the authentication device 120 based on the setting information 626 received (acquired) from the management server 130.
[0070] FIG. 10 is a flowchart showing an example of the terminal process and the authentication device process according to the first embodiment.
[0071] (Processing of the terminal device) In step S904 of FIG. 9, the terminal device 110 set with a valid identification signal executes the processing of the terminal device as shown in FIG. 10(A) in response to, for example, a predetermined operation (such as an authentication operation) by the user.
[0072] In step S1001, the first generation unit 613 of the terminal device 110 generates a first identification signal set by the first setting unit 612.
[0073] In step S1002, the first output unit 614 of the terminal device 110 outputs a sound wave including the first identification signal generated by the first generation unit 613.
[0074] (Processing of the authentication device) In step S905 of FIG. 9, the authentication device 120 set with a valid identification signal executes the processing of the authentication device 120 as shown in FIG. 10(B).
[0075] In step S1011, the second setting unit 622 of the authentication device 120 sets a second identification signal to the authentication unit 624.
[0076] In step S1012, the first extraction unit 623 of the authentication device 120 starts an extraction process of extracting an identification signal from the sound wave around the authentication device 120. By this extraction process, when the terminal device 110 around the authentication device 120 outputs a sound wave including the first identification signal, the first identification signal included in the sound wave is extracted.
[0077] In step S1013, the authentication unit 624 of the authentication device 120 determines whether the first extraction unit 623 has extracted a valid identification signal. For example, when the identification signal extracted by the first extraction unit 623 matches the second identification signal set by the second setting unit 622, the authentication unit 624 determines that a valid identification signal has been extracted. When the first extraction unit 623 extracts a valid identification signal, the authentication unit 624 causes the process to proceed to step S1014. On the other hand, when the first extraction unit 623 has not extracted a valid identification signal, the authentication unit 624 repeatedly executes the process of step S1013.
[0078] In step S1014, the authentication unit 624 refers to the valid time information 702 included in the setting information 626 and determines whether the identification signal extracted by the first extraction unit 623 is a valid time (whether it is still valid). When the identification signal extracted by the first extraction unit 623 is a valid time, the authentication unit 624 causes the process to proceed to step S1015. On the other hand, when the identification signal extracted by the first extraction unit 623 is not a valid time, the authentication unit 624 causes the process to proceed to step S1016.
[0079] When proceeding to step S1015, the authentication unit 624 determines that the authentication of the user using the terminal device 110 (or the terminal device 110) is "OK". Thereby, the authentication unit 624 outputs, for example, a predetermined security signal to the security lock device 121.
[0080] When proceeding to step S1016, the authentication unit 624 determines whether the second identification signal is valid. When the second identification signal is valid (for example, within the valid time of the second identification signal), the process returns to step S1013. On the other hand, when the second identification signal is not valid (for example, outside the valid time of the second identification signal), the process of FIG. 10(B) ends.
[0081] In the processes of FIGS. 10(A) and (B), the terminal device 110 and the authentication device 120 do not have to communicate with the management server 130. Therefore, according to the present embodiment, in the authentication system 100 including the terminal device 110 and the authentication device 120, the user who uses the terminal device 110 or the terminal device 110 can be authenticated without communicating with the management server 130.
[0082] [Second Embodiment] In the second embodiment, an example of setting information when the management server 130 sets a plurality of valid identification signals so that the valid times overlap will be described.
[0083] Before the terminal device 110 outputs a sound wave and the authentication device 120 acquires the sound wave, for example, a delay time is generated due to the time for generating the sound wave, the time for the sound wave to propagate through space, and the time required for extracting the sound wave. In addition, since the terminal device 110 and the authentication device 120 do not perform time synchronization, the internal times may be offset.
[0084] In such a case, for example, there is a risk of authentication failure at the timing of switching from the identification signal 1 to the identification signal 2. Therefore, in the second embodiment, the authentication system 100 sets a plurality of valid identification signals so that at least a part of the valid times overlap.
[0085] FIG. 11 is a diagram for explaining an example of setting information according to the second embodiment. FIG. 11(A) shows an image of a plurality of identification signals 1 to 3 included in the setting information generated by the setting information generation unit 634 of the management server 130. In the example of FIG. 11(A), the valid time of the identification signal 1 is t0 to t2, the valid time of the identification signal 2 is t1 to t4, and in the period of time t1 to t2, the two identification signals 1 and 2 are valid. Similarly, the valid time of the identification signal 3 is t3 to t5, and in the period of time t3 to t4, the two identification signals 2 and 3 are valid.
[0086] Also, as shown in FIG. 11(B), for example, the terminal device 110 and the authentication device 120 perform the switching from the identification signal 1 to the identification signal 2 not at times t1 and t2, but in the time period 1101 between t1 and t2 determined in consideration of the delay time and the deviation of the internal time. Similarly, the terminal device 110 and the authentication device 120 perform the switching from the identification signal 2 to the identification signal 3 not at times t3 and t4, but in the time period 1102 between t3 and t4 determined in consideration of the delay time and the deviation of the internal time. Thereby, the authentication device 120 can correctly authenticate the terminal device 110 even when, for example, a delay in sound waves, a processing delay, or a deviation of the internal time occurs.
[0087] In the example of FIG. 11(A), an example where the identification signals 1 and 2 and the identification signals 2 and 3 overlap is shown. However, the management server 130 may set the valid times of the plurality of identification signals 1, 2, and 3 so that, for example, the identification signals 1, 2, and 3 overlap. Also, in the example of FIG. 11(A), for example, only the identification signal 2 is valid between times t2 and t3, but this is just an example. For example, the management server 130 may set t2 = t3 and set the valid times of the plurality of identification signals 1, 2, and 3 so that the identification signal 2 always overlaps with either the identification signal 1 or 3.
[0088] For example, as shown in FIG. 11(A), when setting the identification signals 1 to 3, the setting information generation unit 634 of the management server 130 may generate the setting information 617 and 626 including the identification signal information 701 corresponding to each of the identification signals 1 to 3 and the valid time information 702.
[0089] [Third Embodiment] In the third embodiment, when the authentication device 120 detects an invalid identification signal, an example of the process when it is determined that the identification signal has been copied (such as data copying or recording) and the identification signal is updated will be described.
[0090] FIG. 12 is a sequence diagram showing an example of the setting process of setting information according to the third embodiment. Since the basic processing content is the same as the setting process of the setting information according to the first embodiment described in FIG. 9, detailed description of the same process as the first embodiment is omitted here.
[0091] In step S1201, the setting information providing unit 633 of the management server 130 generates setting information 1 using the setting information generation unit 634. This setting information 1 may be, for example, a combination of identification signal information 701 and valid time information 702 as shown in FIG. 7, or a combination of a plurality of identification signal information 701 representing a plurality of identification signals 1 to 3 and valid time information 702 as shown in FIG. 11.
[0092] In steps S1202 and S1203, the setting information providing unit 633 of the management server 130 transmits the created setting information 1 to the terminal device 110 and the authentication device 120 by referring to, for example, the user information managed by the user information management unit 632.
[0093] In step S1204, the first setting unit 612 of the terminal device 110 sets a valid identification signal based on the setting information 1 received (acquired) from the management server 130.
[0094] In step S1205, the second setting unit 622 of the authentication device 120 sets a valid identification signal based on the setting information 1 received (acquired) from the management server 130.
[0095] In step S1206, the authentication device 120 executes the processing of the authentication device as shown in FIG. 10(B), for example. When an invalid identification signal is detected, in step S1207, an update request for requesting an update of the setting information is transmitted to the management server 130.
[0096] In step S1208, the setting information providing unit 633 of the management server 130 generates setting information 2 having a different identification signal from the setting information 1 using the setting information generation unit 634 in response to the update request from the authentication device 120.
[0097] In steps S1209 and S1210, the setting information providing unit 633 of the management server 130 transmits the created setting information 2 to the terminal device 110 and the authentication device 120.
[0098] In step S1211, the first setting unit 612 of the terminal device 110 sets a valid identification signal for the terminal device 110 based on the setting information 2 received (acquired) from the management server 130.
[0099] In step S1212, the second setting unit 622 of the authentication device 120 sets a valid identification signal for the authentication device 120 based on the setting information 2 received (acquired) from the management server 130.
[0100] Through the above processing, when the authentication device 120 detects an invalid identification signal, the authentication system 100 can update the identification signal.
[0101] [Fourth Embodiment] In the third embodiment, when the authentication device 120 detects an invalid identification signal, the authentication system 100 updates the identification signal using the management server 130.
[0102] In the fourth embodiment, an example of the processing when the authentication system 100 updates the identification signal without using the management server 130 when the authentication device 120 detects an invalid identification signal will be described.
[0103] [Functional Configuration] FIG. 13 is a diagram showing an example of the functional configuration of the terminal device and the authentication device according to the fourth embodiment.
[0104] (Functional Configuration of Authentication Device) The authentication device 120 according to the fourth embodiment has a second output unit 1301 and a second generation unit 1302 in addition to the functional configuration of the authentication device 120 according to the embodiment described with reference to FIG. 6.
[0105] The second output unit 1301 is realized, for example, by a program executed by the CPU 401. When the first extraction unit 623 extracts an invalid identification signal, the second output unit 1301 outputs an update sound wave including a predetermined identification signal for requesting an update of the setting information, using, for example, the audio input / output I / F 406, the speaker 408, and the like.
[0106] The second generation unit 1302 is realized, for example, by a program executed by the CPU 401, and generates sound wave data of the update sound wave output by the second output unit 1301. Note that the sound wave data of the update sound wave output by the second output unit 1301 may be stored in advance in the storage unit 625 or the like.
[0107] (Functional configuration of the terminal device) The terminal device 110 according to the fourth embodiment has a second extraction unit 1303 in addition to the functional configuration of the terminal device 110 according to the embodiment described with reference to FIG. 6.
[0108] The second extraction unit 1303 is realized, for example, by a program executed by the CPU 301, and executes a second extraction process for extracting a predetermined identification signal included in the update sound wave output by the authentication device 120. For example, the second extraction unit 1303 analyzes a sound wave signal obtained by acquiring sound waves around the terminal device 110 using the microphone 314, the audio input / output I / F 316, and the like, and extracts a predetermined identification signal.
[0109] Note that the functional configuration of the management server 130 may be the same as the functional configuration of the management server 130 according to the embodiment described with reference to FIG. 6.
[0110] <Flow of processing> FIG. 14 is a sequence diagram showing an example of the setting process of the setting information according to the fourth embodiment. Since the basic processing content is the same as the setting process of the setting information according to the first embodiment described with reference to FIG. 9, a detailed description of the same processing as that in the first embodiment is omitted here.
[0111] In step S1401, the setting information providing unit 633 of the management server 130 uses the setting information generation unit 634 to generate a plurality of pieces of setting information 1 and 2 including the valid time information 702. Note that the number of the plurality of pieces of setting information 1 and 2 may be three or more other numbers.
[0112] In steps S1402 and S1403, the setting information providing unit 633 of the management server 130 transmits the created setting information 1 and 2 to the terminal device 110 and the authentication device 120 by referring to, for example, the user information managed by the user information management unit 632.
[0113] In step S1404, the first setting unit 612 of the terminal device 110 sets an identification signal valid for the terminal device 110 based on the setting information 1 among the setting information 1 and 2 received (acquired) from the management server 130.
[0114] In step S1405, the second setting unit 622 of the authentication device 120 sets an identification signal valid for the authentication device 120 based on the setting information 1 among the setting information 1 and 2 received (acquired) from the management server 130.
[0115] In step S1406, the authentication device 120 executes, for example, the authentication process as shown in FIG. 10(B). When an invalid identification signal is detected, the process of step S1407 is executed.
[0116] In step S1407, the second output unit 1301 of the authentication device 120 generates, for example, sound wave data of an update sound wave including a predetermined identification signal using the second generation unit 1302, and outputs the update sound wave using the generated sound wave data.
[0117] In step S1408, when the second extraction unit 1303 of the terminal device 110 extracts the predetermined identification signal included in the update sound wave, the first setting unit 612 sets (updates) a valid identification signal based on the setting information 2 already acquired from the management server 130.
[0118] In step S1409, after the second output unit 1301 of the authentication device 120 outputs the update sound wave, the second setting unit 622 of the authentication device 120 sets a valid identification signal based on the setting information 2 that has been acquired from the management server 130.
[0119] Through the above processing, when the authentication device 120 detects an invalid identification signal, the terminal device 110 and the authentication device 120 can update the identification signal without communicating with the management server 130.
[0120] [Fifth Embodiment] In the fifth embodiment, an example of the processing when the management server 130 updates the setting information after a predetermined time has elapsed after transmitting the setting information to the terminal device 110 and the authentication device 120 will be described.
[0121] FIG. 16 is a sequence diagram showing an example of the setting process of the setting information according to the fifth embodiment. Since the basic processing content is the same as the setting process of the setting information according to the first embodiment described in FIG. 9, detailed description of the same processing as in the first embodiment will be omitted here.
[0122] In step S1501, the setting information providing unit 633 of the management server 130 generates setting information 1 including valid time information 702 using the setting information generation unit 634.
[0123] In steps S1502 and S1503, the setting information providing unit 633 of the management server 130 transmits the created setting information 1 to the terminal device 110 and the authentication device 120 by referring to, for example, the user information managed by the user information management unit 632.
[0124] In step S1504, the first setting unit 612 of the terminal device 110 sets a valid identification signal for the terminal device 110 based on the setting information 1 received (acquired) from the management server 130.
[0125] In step S1505, the second setting unit 622 of the authentication device 120 sets a valid identification signal for the authentication device 120 based on the setting information 1 received (acquired) from the management server 130.
[0126] In step S1506, the setting information providing unit 633 of the management server 130 determines whether a predetermined time has elapsed since the setting information 1 was transmitted to the terminal device 110 and the authentication device 120. Alternatively, the setting information providing unit 633 may determine whether a predetermined time has elapsed since the setting information generation unit 634 generated the setting information 1. If the predetermined time has elapsed, the setting information providing unit 633 executes the process of step S1507.
[0127] In step S1507, the setting information providing unit 633 of the management server 130 uses the setting information generation unit 634 to generate setting information 2 including the valid time information 702.
[0128] In steps S1508 and S1509, the setting information providing unit 633 of the management server 130 transmits the created setting information 2 to the terminal device 110 and the authentication device 120 by referring to, for example, the user information managed by the user information management unit 632.
[0129] In step S1510, the first setting unit 612 of the terminal device 110 sets a valid identification signal for the terminal device 110 based on the setting information 2 received (acquired) from the management server 130.
[0130] In step S1511, the second setting unit 622 of the authentication device 120 sets a valid identification signal for the authentication device 120 based on the setting information 2 received (acquired) from the management server 130.
[0131] Through the above processing, after transmitting the setting information to the terminal device 110 and the authentication device 120, the management server 130 can update the setting information when a predetermined time has elapsed.
[0132] [Sixth Embodiment] In the sixth embodiment, an example of the process when the terminal device 110 and the authentication device 120 update a valid identification signal after a predetermined time has elapsed after setting the valid identification signal will be described.
[0133] (Processing of Terminal Device and Authentication Device) FIG. 16 is a flowchart showing an example of the setting process of the terminal device and the authentication device according to the sixth embodiment.
[0134] In step S1601, the terminal device 110 and the authentication device 120 set a valid identification signal based on the setting information received (acquired) from the management server 130, for example, as shown in FIGS. 17(A) and (B).
[0135] FIG. 17(A) shows an image of an example of the setting information of the identification signal according to the sixth embodiment. In the example of FIG. 17(A), the setting information 1701 includes information such as "date", "setting", "identification signal", and "valid time" as items.
[0136] "Date" and "valid time" are information indicating the date and time when the identification signal is valid. The "identification signal" is an identification signal or a number assigned to the identification signal. For example, "1" represents the "identification signal 1" of the first to fifth embodiments, and "2" represents the "identification signal 2". "Setting" is an identification number for identifying the combination of the "identification signal" and the "valid time". In the example of the setting information 1701 shown in FIG. 17(A), each time the "date" changes, the combination of the "identification signal" and the "valid time" is changed to improve security performance.
[0137] In the example of FIG. 17(B), an image of another example of the setting information of the identification signal according to the sixth embodiment is shown. In the setting information 1702 shown in FIG. 17(B), each time the "date" changes, the "identification signal" is changed to further improve security performance.
[0138] In step S1601, the terminal device 110 and the authentication device 120 set one or more identification signals valid at the current date and time, for example, by referring to the setting information 1701 (or the setting information 1702).
[0139] In step S1602, the terminal device 110 and the authentication device 120 determine whether it is the switching time of the identification signal. For example, the terminal device 110 and the authentication device 120 refer to the setting information 1701 (or the setting information 1702), and when there is an identification signal whose "valid time" ends or an identification signal whose "valid time" starts, it is determined that it is the switching time of the identification signal. If it is the switching time of the identification signal, the terminal device 110 and the authentication device 120 shift the process to step S1603.
[0140] When shifting to step S1603, the terminal device 110 and the authentication device 120 update the valid identification signal based on the setting information 1701 (or the setting information 1702). For example, the terminal device 110 and the authentication device 120 cancel the setting of the identification signal whose "valid time" ends and set a valid identification signal whose "valid time" starts.
[0141] By the above processing, even when the terminal device 110 and the authentication device 120 cannot communicate with the management server 130, they can periodically update the setting of the identification signal.
[0142] As described above, according to each embodiment of the present invention, in an authentication system including a terminal device and an authentication device that performs authentication using sound waves output by the terminal device, even when communication with a management server is not possible, a user or the terminal device can be authenticated.
[0143] <Supplementary Note> Each function of each of the embodiments described above can be realized by one or more processing circuits. Here, the "processing circuit" in this specification refers to a processor programmed to execute each function by software, such as a processor implemented by an electronic circuit, an ASIC (Application Specific Integrated Circuit) designed to execute each function described above, a DSP (digital signal processor), an FPGA (field programmable gate array), and devices such as conventional circuit modules.
[0144] Also, the device group described in the embodiments merely shows one of a plurality of computing environments for implementing the embodiments disclosed in this specification. In one embodiment, the management server 130 includes a plurality of computing devices such as a server cluster. The plurality of computing devices are configured to communicate with each other via any type of communication link including a network or a shared memory, and perform the processing disclosed in this specification. Similarly, the authentication device 120 can include a plurality of computing devices configured to communicate with each other.
[0145] Furthermore, the management server 130 and the authentication device 120 can be configured to share the disclosed processing steps in various combinations. For example, a process executed by a predetermined unit can be executed by the management server 130. Similarly, the function of a predetermined unit can be executed by the authentication device 120. Also, each element of the management server 130 and the authentication device 120 may be combined into one device or divided into a plurality of devices.
Description of Reference Numerals
[0146] 100 Authentication system 110 Terminal device 120 Authentication device 611 First communication unit 612 First setting unit 613 First generation unit 614 First output unit 617, 626, 1701, 1702 Setting information 621 Second communication unit 622 Second setting unit 623 First extraction unit 624 Authentication unit 711 Identification signal data 712 Encryption information 713 Identification signal generation library (program for generating identification signals) 1301 Second output unit 1303 Second extraction unit
Prior art documents
Patent documents
[0147]
Patent Document 1
Claims
1. An authentication system including a terminal device and an authentication device for authenticating the terminal device, wherein the terminal device has a first output unit that outputs a sound wave including a first identification signal based on setting information provided by a management server and including an identification signal and information on a time when the identification signal is valid, and the authentication device has an authentication unit that compares the first identification signal included in the sound wave output by the terminal device with a second identification signal based on the setting information provided by the management server to authenticate a user using the terminal device or the terminal device, and the setting information includes setting information for setting a plurality of identification signals with overlapping valid times, the authentication system.
2. An authentication system including a terminal device and an authentication device for authenticating the terminal device, wherein the terminal device has a first output unit that outputs a sound wave including a first identification signal based on setting information provided by a management server and including an identification signal and information on a time when the identification signal is valid, and the authentication device has an authentication unit that compares the first identification signal included in the sound wave output by the terminal device with a second identification signal based on the setting information provided by the management server to authenticate a user using the terminal device or the terminal device, and the setting information includes identification signal data for generating an identification signal and encryption information for encrypting the identification signal, the authentication system.
3. An authentication system including a terminal device and an authentication device for authenticating the terminal device, wherein the terminal device has a first output unit that outputs a sound wave including a first identification signal based on setting information provided by a management server and including an identification signal and information on a time when the identification signal is valid, and the authentication device has an authentication unit that compares the first identification signal included in the sound wave output by the terminal device with a second identification signal based on the setting information provided by the management server to authenticate a user using the terminal device or the terminal device, and the setting information includes a program for generating an identification signal, the authentication system.
4. An authentication system including a terminal device and an authentication device for authenticating the terminal device, wherein the terminal device has a first output unit that outputs a sound wave including a first identification signal based on setting information provided by a management server and including an identification signal and information on a time when the identification signal is valid, and the authentication device has a first extraction unit that extracts the first identification signal included in the sound wave output by the terminal device, Compare the first identification signal included in the sound wave output by the terminal device with the second identification signal based on the setting information provided by the management server, and authenticate the user who uses the terminal device or the authentication unit that authenticates the terminal device. It has An authentication system in which when the first extraction unit extracts an invalid first identification signal, the first identification signal and the second identification signal are updated.
5. The authentication device has a second output unit that outputs a sound wave including a predetermined identification signal when the first extraction unit extracts an invalid first identification signal. The terminal device is It has a second extraction unit that extracts the predetermined identification signal included in the sound wave output by the authentication device. The authentication system according to claim 4.
6. The authentication system includes the management server that provides the setting information. The terminal device is A first communication unit that communicates with the management server. When communicating with the management server, obtain the setting information from the management server and set the setting information in the terminal device. A first generation unit that generates the first identification signal based on the setting information set in the terminal device. It has The authentication device is A second communication unit that communicates with the management server. When communicating with the management server, obtain the setting information from the management server and set the setting information in the authentication device. The authentication system according to any one of claims 1 to 5.
7. A terminal device included in the authentication system according to any one of claims 1 to 6, A terminal device having a first output unit that outputs a sound wave including a first identification signal based on setting information including an identification signal provided by a management server and information on a time when the identification signal is valid.
8. In the terminal device included in the authentication system according to any one of claims 1 to 6, A program that executes a first output process of outputting a sound wave including a first identification signal based on setting information including an identification signal provided by a management server and information on a time when the identification signal is valid.
9. An authentication method in an authentication system including a terminal device and an authentication device that authenticates the terminal device, The terminal device is Execute a process of outputting a sound wave including a first identification signal based on setting information including an identification signal provided by a management server and information on a time when the identification signal is valid. The authentication device is Compare the first identification signal included in the sound wave output by the terminal device with a second identification signal based on the setting information provided by the management server, and execute a process of authenticating the user who uses the terminal device or the terminal device. The setting information includes setting information for setting a plurality of identification signals with overlapping valid times. Authentication method. **Claim 10**: An authentication method in an authentication system including a terminal device and an authentication device for authenticating the terminal device, The terminal device, Based on setting information including an identification signal and information on the time when the identification signal is valid provided by a management server, execute a process of outputting a sound wave including a first identification signal. The authentication device, Compare the first identification signal included in the sound wave output by the terminal device with a second identification signal based on the setting information provided by the management server, and execute a process of authenticating the user who uses the terminal device or the terminal device. The setting information includes identification signal data for generating an identification signal and encryption information for encrypting the identification signal. Authentication method.
Citation Information
Patent Citations
Unlocking system and unlocking method
JP2010071009A
Authentication system and authentication method
JP2013003746A
Authentication information generation program, authentication information generation device and authentication information generation method
JP2016184350A
Authentication system, authentication device, and recording medium
WO2005057447A1