Authentication system, authentication device, and authentication program
The authentication system for connected cars addresses the complexity of conventional remote key unlocking systems by using a one-time password and voice recognition, providing a secure and simplified method for unlocking connected cars.
Patent Information
- Application Number
- JP2022113046
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-14
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-07-14
AI Technical Summary
Conventional remote key unlocking systems for connected cars have complex procedures that are not suitable for temporary use, making them impractical for applications such as picking up luggage by an autonomous vehicle.
An authentication system that includes a server, a connected car, and an administrator terminal, utilizing a one-time password for secure and easy unlocking. The system employs person proximity recognition and voice recognition to authenticate users, simplifying the unlocking process.
The system enables safe and easy unlocking of connected cars by simplifying the authentication process, reducing complexity, and enhancing security against unauthorized access.
Smart Images

Figure 0007685974000001 
Figure 0007685974000002
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication system for remote key unlocking.
Background Art
[0002] Conventionally, various Web services for IoT devices have been provided and can be used by authenticating the user's terminal. For example, in Patent Document 1, as a method of sharing a carsharing key, a technique of remotely operating a key box in a vehicle from a paired smartphone has been proposed.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, the conventional remote key unlocking function has complicated procedures such as premising prior login in a specific smartphone application, and is not suitable for temporary use. For example, when picking up luggage by an autonomous vehicle, in applications such as temporary unlocking, the procedure becomes too complicated to be practical.
[0005] An object of the present invention is to provide an authentication system, an authentication device, and an authentication program that can safely and easily unlock the key lock of a connected car.
Means for Solving the Problems
[0006] The authentication system according to the present invention includes a server, a connected car, and an administrator terminal. The server includes a terminal registration unit that registers by associating the identifier of the administrator terminal and the identifier of the connected car, a password issuance unit that issues a one-time password to the administrator terminal, a data reception unit that waits for transmission of input data based on the one-time password from the connected car when receiving a notification that the user has approached from the connected car, and an authentication processing unit that unlocks the key lock of the connected car when the one-time password can be read from the input data. The connected car includes a person detection notification unit that notifies the server of the detection when the user is detected as approaching by a person proximity recognition process, and an input data transmission unit that transmits input data based on the one-time password input by the user to the server. The administrator terminal includes a start request unit that requests the server to start user authentication after receiving the one-time password from the server.
[0007] In response to a start request for authentication from the administrator terminal, the data reception unit may instruct the connected car to start the person proximity recognition process, and when receiving a notification that the user has approached, wait for transmission of voice data based on the one-time password for a limited time.
[0008] The input data may be voice data in which the user voices the one-time password.
[0009] The input data may be voice data in which the one-time password is encoded and reproduced by a predetermined application.
[0010] The identifier of the connected car may be an IMSI, and the identifier of the administrator terminal may be an MSISDN.
[0011] The authentication device according to the present invention is mounted on a connected car that is linked to an administrator terminal in a server and communicatively connected to the server. When a person proximity recognition process detects that a user has approached, a person detection notification unit notifies the server of the detection. An input data transmission unit shares a one-time password issued by the server to the administrator terminal and transmits input data based on the one-time password input by the user to the server. When the server can read the one-time password from the input data, the key lock of the connected car is released.
[0012] The authentication program according to the present invention is for causing a computer to function as the authentication device.
Effect of the Invention
[0013] According to the present invention, the key lock of the connected car can be released safely and easily.
Brief Description of the Drawings
[0014]
Figure 1
Figure 2
Mode for Carrying Out the Invention
[0015] Hereinafter, an example of an embodiment of the present invention will be described. In this embodiment, an authentication method that combines person proximity recognition by a peripheral camera and voice recognition of a one-time password is used. This enables authentication of a user with a one-time password shared in advance with the owner of the device for IoT devices such as connected cars that have a communication function, a peripheral camera, and an external input microphone, and realizes remote key unlocking. Here, as an example, the IoT device is a connected car, and a server authenticates a user other than the owner and shows an authentication system for remotely unlocking the key.
[0016] FIG. 1 is a diagram showing the functional configuration of the authentication system 1 in the present embodiment. The authentication system 1 includes a server 10, a connected car 20, and an administrator terminal 30 held by an administrator such as the owner of the connected car 20.
[0017] The server 10 is an information processing device including a control unit and a storage unit, as well as a communication device and the like. In response to a request from the owner of the connected car 20, it executes an authentication process for the user to unlock the key lock. The control unit of the server 10 includes a terminal registration unit 11, a password issuance unit 12, a data reception unit 13, and an authentication processing unit 14. These functional units are realized by the control unit executing software stored in the storage unit.
[0018] The terminal registration unit 11 associates and registers the MSISDN as the identifier of the administrator terminal 30 and the IMSI as the identifier of the connected car 20, that is, stores them in the storage unit. Note that the MSISDN is the phone number of the administrator terminal 30, and the IMSI is the unique number recorded in the SIM / eSIM used by the connected car 20.
[0019] The server 10 has a means for communicating with the connected car 20 using this pre-associated IMSI. In the case of a general communication infrastructure for IoT, a proxy server that communicates with IoT devices in a waiting state is provided, and communication can be performed using this. As an authenticated communication path, it is communication connected using a SIM. Thus, the server 10 can communicate securely with each other by recognizing the IMSI of the connected car 20.
[0020] The password issuing unit 12 issues a one-time password as authentication information of the user to the administrator terminal 30.
[0021] When the data receiving unit 13 receives a notification from the connected car 20 that the user has approached, it waits for the transmission of voice data based on the one-time password from the connected car 20. At this time, in response to an authentication start request from the administrator terminal 30, the data receiving unit 13 instructs the connected car 20 to start the person proximity recognition process. Then, when it receives a notification that the user has approached, it waits for the transmission of voice data only for a predetermined period.
[0022] When the authentication processing unit 14 can read the one-time password issued to the administrator terminal 30 by voice recognition processing on the voice data, it releases the key lock of the connected car 20.
[0023] The connected car 20 is equipped with an information processing device (authentication device) capable of communicating with the server 10, and further includes various sensors such as a camera and a microphone for person proximity recognition and password input. The control unit of the authentication device includes a person detection notification unit 21 and an input data transmission unit 22.
[0024] When the person detection notification unit 21 detects that the user has approached through person proximity recognition processing, it notifies the server 10 of the detection. For the person proximity recognition process, for example, the following two types of methods can be applied using the sensors provided in the connected car 20. · Person recognition by surrounding camera video · Object detection by millimeter-wave radar
[0025] The input data transmission unit 22 transmits voice data based on the one-time password input by the user to the server 10. Here, the user inputs the one-time password to the connected car 20 by voice, for example, as follows. · The user reads out the one-time password aloud near the connected car 20.
[0026] · The user encodes the one-time password with an audio modem provided in a predetermined application installed on the user terminal and plays it as sound near the connected car 20. The sound played at this time may be in a high frequency band that is inaudible to humans.
[0027] Note that the input data transmission unit 22 may wait for these two types simultaneously as the input of the one-time password. As a result, while having the user install the application (user registration), ensuring high reliability in reading, and being able to use sound that cannot be heard or is inaudible to humans, the convenience when using it temporarily or in a hurry by the user's voice without using the application can be improved.
[0028] Also, as an alternative to the voice input method of the one-time password, for example, the following method may be adopted. · The user terminal (smartphone) transmits a Bluetooth beacon including the one-time password, which is received by the connected car 20 and transmitted to the server 10 as input data. · Perform Bluetooth GATT communication including the one-time password from the user terminal, which is received by the connected car 20 and transmitted to the server 10 as input data.
[0029] The administrator terminal 30 is a mobile terminal such as a smartphone and includes a start request unit 31. After receiving the one-time password issued from the server 10, the start request unit 31 requests the server 10 to start the authentication of the user. This may be performed in response to the owner's operation input.
[0030] Figure 2 is a sequence diagram showing the processing procedure of the authentication method in this embodiment. In step S1, the administrator terminal 30 registers the association between the MSISDN of the administrator terminal 30 and the IMSI of the connected car 20 with the server 10.
[0031] Note that this registration process is carried out in advance prior to the subsequent authentication procedure. Currently, the communication line is mainly based on a subscription contract, and it is considered that a similar contract is also made for the line used by the connected car 20 such as an autonomous vehicle. At this time, since the operator who conducts the line contract requires the contact information of the owner, it is very likely that the owner's phone number, that is, the MSISDN, will be requested. In this case, the prior association registration is completed at the time of purchase / contract of the connected car 20.
[0032] Hereinafter, it is assumed that the administrator terminal 30 and the connected car 20 have been authenticated by the server 10, and the administrator terminal 30 has logged in to the service provided by the server 10.
[0033] In step S2, the server 10 issues a one-time password to the administrator terminal 30. In step S3, the administrator (administrator terminal 30) shares the one-time password with the user (user terminal) of the connected car 20. The sharing means is arbitrary. For example, in addition to a dedicated application, e-mail, SMS, various messenger applications, etc. may be used.
[0034] In step S4, the administrator terminal 30 requests the server 10 to start one-time password authentication. In step S5, the server 10 instructs the connected car 20 to start the detection notification by the human proximity recognition process. In step S6, the connected car 20 starts the human proximity recognition process using, for example, the surrounding camera video. In step S7, when the user (or another person) approaches the connected car 20 and is recognized by the surrounding camera, the connected car 20 notifies the server 10 that a person has been detected.
[0035] In step S8, in response to receiving the notification in step S7, the server 10 instructs the connected car 20 to wait for voice input. In step S9, the connected car 20 starts to collect ambient voice through the microphone. After that, if it is the correct user, the voice of the one-time password shared with the owner (spoken or output by the audio modem) is input.
[0036] In step S10, the connected car 20 sequentially transmits the collected voice data to the server 10. In step S11, the server 10 analyzes the received voice data and reads the input password. In step S12, when the server 10 confirms that the read password matches the one-time password issued in step S2, it instructs the connected car 20 to end the waiting for voice input. In step S13, the server 10 unlocks the door lock of the connected car 20, and the user uses the connected car 20.
[0037] Note that if the server 10 cannot confirm the one-time password within a predetermined time, it ends the waiting for voice input of the connected car 20. Alternatively, the connected car 20 may spontaneously end the waiting for voice input within a predetermined time.
[0038] According to the present embodiment, the authentication system 1 combines the person proximity recognition function, the microphone function, and the authenticated communication path of the connected car 20, making it possible to perform authentication using a one-time password, which was difficult in the past, with a high authentication strength. For example, if it is a 6-digit one-time password, if a mini speaker that continuously speaks 6-digit numbers every 3 seconds is attached, it will be broken within about 4 days. In the case of the person proximity recognition function of the present embodiment, since it is necessary to place a person or a huge object that is misrecognized as a person around the car for a long time, the attack becomes very difficult.
[0039] Furthermore, the authentication system suppresses attacks by third parties by accepting one-time passwords only for a predetermined time, and in particular, by limiting the reception period of voice data, it is possible to reduce the data traffic when transmitting voice data via cellular communication.
[0040] Also, when considering authentication for a connected car 20 such as an autonomous vehicle, it is assumed that cars from various manufacturers are equipped with different operating systems. Then, since it is conceivable that software updates may be difficult, function aggregation is required on the server side. For this reason, in the connected car 20, various functions such as human proximity detection, collection of ambient sound, and remote door lock are provided as APIs, and the server 10 can use these to provide an authentication procedure.
[0041] Thus, the authentication method of the present embodiment is designed such that the main logic related to authentication is not required in the connected car 20 itself, and on the user side, the use of special software is also not required. On the other hand, by installing a predetermined application (for example, an audio modem, a Bluetooth beacon, etc.) on the user terminal, the user can be authenticated with only a simple operation without having to speak. Also, by performing voice recognition processing on the server 10, sufficient analysis performance can be provided.
[0042] Note that depending on the operating system of the user terminal, there may be cases where an application cannot be used with communication such as Bluetooth or WiFi forcibly turned on. On the other hand, in the case of voice output from a speaker, although permission from the user is usually required, it can be forcibly output regardless of settings such as the manner mode.
[0043] According to the foregoing embodiments, for example, since the authentication strength and convenience for IoT devices can be improved, it becomes possible to contribute to Goal 9 of the Sustainable Development Goals (SDGs) led by the United Nations, "Build resilient infrastructure, promote sustainable industrialization and foster innovation."
[0044] As described above, the embodiments of the present invention have been explained. However, the present invention is not limited to the foregoing embodiments. Also, the effects described in the foregoing embodiments are merely an enumeration of the most suitable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0045] The authentication method by the authentication system 1 is realized by software. When realized by software, the program constituting this software is installed in an information processing apparatus (computer). Further, these programs may be recorded on a removable medium such as a CD-ROM and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a Web service via a network without being downloaded.
Description of Reference Numerals
[0046] 1 Authentication system 10 Server 11 Terminal registration unit 12 Password issuance unit 13 Data reception unit 14 Authentication processing unit 20 Connected car 21 Human detection notification unit 22 Input data transmission unit 30 Administrator terminal 31 Start request unit
Claims
1. A system comprising a server, a connected car, and an administrator terminal, wherein the server includes a terminal registration unit configured to register by associating an identifier of the administrator terminal with an identifier of the connected car; a password issuing unit configured to issue a one-time password to the administrator terminal; a data receiving unit configured to wait for transmission of voice input data from the connected car when receiving a notification that a user has approached from the connected car; and an authentication processing unit configured to unlock the key lock of the connected car when the one-time password is read by voice recognition processing on the input data; wherein the connected car includes a person detection notification unit configured to detect that the user has approached by person proximity recognition processing and notify the server of the detection; and an input data transmission unit configured to transmit, to the server, the input data that is voice uttering the one-time password input by the user who has previously shared the one-time password notified from the administrator terminal with the administrator terminal, or voice reproduced by encoding the one-time password; wherein the administrator terminal is an authentication system including a start request unit configured to request the server to start authentication of a user after receiving the one-time password from the server.
2. A system comprising a server, a connected car, and an administrator terminal, wherein the server includes a terminal registration unit configured to register by associating an identifier of the administrator terminal with an identifier of the connected car; a password issuing unit configured to issue a one-time password to the administrator terminal; a data receiving unit configured to wait for transmission of input data by short-range wireless communication from the connected car when receiving a notification that a user has approached from the connected car; and an authentication processing unit configured to unlock the key lock of the connected car when the one-time password is read from the input data; wherein the connected car includes a person detection notification unit configured to detect that the user has approached by person proximity recognition processing and notify the server of the detection; and an input data transmission unit configured to transmit, to the server, the input data including the one-time password input by short-range wireless communication from a terminal of the user who has previously shared the one-time password notified from the administrator terminal with the administrator terminal; wherein the administrator terminal An authentication system comprising a start request unit that requests the start of user authentication to the server after receiving the one-time password from the server.
3. The data receiving unit In response to an authentication start request from the administrator terminal, instructs the connected car to start the human proximity recognition process, The authentication system according to claim 1 or claim 2, which waits for transmission of the input data for a predetermined time when receiving a notification that the user has approached.
4. The identifier of the connected car is an IMSI, The authentication system according to claim 1 or claim 2, wherein the identifier of the administrator terminal is an MSISDN.
5. Mounted on a connected car that is associated with an administrator terminal in a server and communicatively connected to the server, A human detection notification unit that notifies the server of the detection when it detects that a user has approached by human proximity recognition processing; An input data transmission unit that transmits input data of voice reproduced by encoding the one-time password, which is input by the user who has previously shared the one-time password issued to the administrator terminal by the server with the administrator terminal, to the server, An authentication device that unlocks the key lock of the connected car in response to a command from the server when the one-time password can be read by voice recognition processing for the input data in the server.
6. An authentication program for causing a computer to function as the authentication device according to claim 5.
Citation Information
Patent Citations
Information processing device, authentication device, server device, information processing method, authentication method and program
JP2016170556A
System and method for managing vehicle
JP2016206813A
System and method for managing vehicle
JP2016208494A
Information processing apparatus and unlocking control method
JP2016211157A
A method of signing up a user for a service that controls at least one vehicle function on a user terminal
JP2018508858A