Authentication device, authentication method, and program
The authentication device addresses the high cost issue of multiple receivers in existing systems by using a smaller number of receiver sets to perform authentication and area determination based on the intensity difference of authentication requests, effectively reducing costs while maintaining functionality.
Patent Information
- Application Number
- JP2025016595
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-02-04
- Publication Date
- 2025-06-30
- Estimated Expiration
- 2045-02-04
AI Technical Summary
The existing authentication systems require a large number of receivers to be arranged in multiple areas for authenticating and determining the position of an authentication target device, leading to high costs.
An authentication device that uses a smaller number of receiver sets to perform authentication and area determination by utilizing the intensity difference of authentication requests received by multiple receiver sets, allowing at least one receiver set to be used for area determination in multiple areas.
The proposed solution reduces the number of receiver sets needed, thereby lowering costs while maintaining effective authentication and area determination capabilities.
Smart Images

Figure 0007699881000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication device that receives an authentication request transmitted from an authentication target device and performs processing such as authentication.
Background Art
[0002] Conventionally, an authentication device that receives an authentication request transmitted from an authentication target device and performs authentication is known (see, for example, Patent Document 1). By performing authentication using such an authentication request, for example, hands-free authentication that does not require an operation by a user can be performed.
[0003] Also, it is possible to receive a signal transmitted from the authentication target device and determine whether the authentication target device is included in a specific area (see, for example, Patent Document 2). Therefore, for example, it is possible to receive an authentication request transmitted from the authentication target device, perform authentication of the authentication target device, and also determine whether the authentication target device is included in a predetermined area.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0005] When receiving an authentication request transmitted from an authentication target device, authenticating the authentication target device, and determining whether the authentication target device is included in a predetermined area in a plurality of areas, it was necessary to arrange a plurality of receivers for each area. For example, when performing authentication of an authentication target device and determination regarding the position of the authentication target device at the entrance and elevator hall of a building, it was necessary to arrange a plurality of receivers at the entrance and also arrange a plurality of receivers at the elevator hall.
[0006] As described above, as the number of areas where authentication of the authentication target device and determination regarding the position of the authentication target device are performed increases, the number of receivers to be arranged accordingly increases, resulting in a problem of high cost.
[0007] The present invention has been made to solve the above problems, and an object thereof is to provide an authentication device or the like that can perform authentication and determination regarding the position of an authentication target device in a plurality of areas using a smaller number of receivers.
Means for Solving the Problems
[0008] To achieve the above object, an authentication device according to an aspect of the present invention includes first to Nth receiver sets each including one or more receivers that receive an authentication request including authentication information used for authentication of an authentication target device transmitted from the authentication target device, an authentication unit that performs device authentication to determine whether the authentication target device that transmitted the authentication request is legitimate using the authentication information included in the authentication request received by at least any one of the one or more receivers included in the first to Nth receiver sets, a determination unit that performs area determination to determine whether the position of the authentication target device is included in first and second areas based on the intensity difference of the authentication requests received by at least two receiver sets among the first to Nth receiver sets, and an output unit that outputs results regarding the device authentication result and the area determination result, where N is 2 or more, and at least the same receiver set is included in at least two receiver sets used for area determination regarding the first area and at least two receiver sets used for area determination regarding the second area. With such a configuration, at least one receiver set can be used for area determination in both the first and second areas. As a result, the number of receiver sets can be reduced as compared to the case where two or more different receiver sets are used for each area determination regarding the first and second areas.
[0009] Also, in the authentication device according to one aspect of the present invention, the first position where the first receiver set is disposed may be included in the first area in a plan view, and the second position where the second receiver set is disposed may be included in the second area in a plan view. With such a configuration, for the first area, area determination can be performed using the first receiver set disposed within the first area in a plan view and the other receiver sets, and for the second area, area determination can be performed using the second receiver set disposed within the second area in a plan view and the other receiver sets.
[0010] Also, in the authentication device according to one aspect of the present invention, when the determination unit determines whether the device to be authenticated is included in the first area and when it determines whether the device to be authenticated is included in the second area, it may use at least the intensity difference of the authentication requests received by the first and second receiver sets. With such a configuration, in the area determination for both the first and second areas, the number of receiver sets can be reduced by using the same first and second receiver sets.
[0011] Also, in the authentication device according to one aspect of the present invention, N is 3 or more, and when the determination unit determines whether the device to be authenticated is included in the first area, it uses at least the intensity difference of the authentication requests received by the first and third receiver sets, and when it determines whether the device to be authenticated is included in the second area, it may use at least the intensity difference of the authentication requests received by the second and third receiver sets. With such a configuration, in the area determination for both the first and second areas, the number of receiver sets can be reduced by using the same third receiver set.
[0012] Also, an authentication method according to an aspect of the present invention is an authentication method processed using a first to Nth receiver sets including one or more receivers, an authentication unit, a determination unit, and an output unit, where N is 2 or more, and at least two receiver sets among the first to Nth receiver sets receive an authentication request including authentication information used for authenticating the authentication device, which is transmitted from the authentication device. The authentication unit uses the authentication information included in the authentication request received by at least any one of the one or more receivers in the step of receiving the authentication request to perform device authentication to determine whether the authentication device that transmitted the authentication request is legitimate. The determination unit performs region determination to determine whether the position of the authentication device is included in the first and second regions based on the intensity difference of the authentication requests received by at least two receiver sets in the step of receiving the authentication request. The output unit performs an output regarding the result of the device authentication and the result of the region determination. At least the same receiver set is included in at least two receiver sets used for region determination regarding the first region and at least two receiver sets used for region determination regarding the second region.
Effects of the Invention
[0013] According to an authentication device or the like according to an aspect of the present invention, the number of receiver sets can be reduced as compared with the case where two or more different receiver sets are used for each region determination regarding the first and second regions.
Brief Description of the Drawings
[0014]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6A
Figure 6B
Figure 7
Embodiments for Carrying Out the Invention
[0015] Hereinafter, an authentication apparatus and an authentication method according to the present invention will be described using embodiments. In the following embodiments, components and steps denoted by the same reference numerals are the same or corresponding, and repeated descriptions may be omitted. The authentication apparatus according to the present embodiment performs region determination for determining whether an authentication request transmitting authentication-requesting apparatus is included in first and second regions based on a strength difference of authentication requests received by two or more receiver sets. And at least the same receiver set is included in at least two receiver sets used for region determination regarding the first region and at least two receiver sets used for region determination regarding the second region.
[0016] FIG. 1 is a block diagram showing the configuration of an authentication apparatus 1 according to the present embodiment, and FIG. 2 is a planar view showing the arrangement positions of first and second regions R1 and R2 and first and second receiver sets 11 and 12. The authentication apparatus 1 according to the present embodiment includes a first receiver set 11, a second receiver set 12, an authentication unit 21, a determination unit 22, and an output unit 23.
[0017] The authentication device 1 performs device authentication as to whether the authentication target device 2 carried by the user 5 is legitimate, and region determination as to whether the authentication target device 2 is included in the first region R1 and the second region R2, and outputs according to the results thereof. Depending on the output, for example, door unlocking, opening / closing processing for doors such as those of houses, buildings, conference rooms, hotel rooms, etc., settlement processing related to purchases of items to be purchased such as goods and services may be performed. In the present embodiment, as an example, when the position of the authentication target device 2 determined to be legitimate by device authentication is determined to be included in the first region R1 by region determination, according to the output of the results of the device authentication and region determination, the door 31 at the entrance of the building opens, and when the position of the authentication target device 2 determined to be legitimate by device authentication is determined to be included in the second region R2 by region determination, the elevator 32 in the building operates according to the output of the results of the device authentication and region determination. This will be mainly described. In this way, for example, the first region R1 may be set outside the door 31 at the entrance of the building, and the second region R2 may be set in the elevator hall of the building. Note that the first and second regions R1 and R2 may or may not be visually identifiable in the real space. In the present embodiment, the latter case will be mainly described. Also, the shape of the first and second regions R1 and R2 in plan view may be, for example, rectangular, circular, or other shapes.
[0018] In addition, in FIG. 1, the situation where the user 5 is holding the authentication target device 2 by hand is shown, but the user 5 carrying the authentication target device 2 means, for example, a state where the authentication target device 2 also moves according to the movement of the user 5, and the user 5 does not necessarily have to hold the authentication target device 2 by hand. The authentication target device 2 may be, for example, placed in the pocket or bag of the user 5's clothes. The same applies to FIG. 4 described later. Also, in FIG. 1, the case where the authentication device 1 receives an authentication request from one authentication target device 2 carried by one user 5 is shown, but the authentication device 1 may receive authentication requests from a plurality of authentication target devices 2 carried by a plurality of users 5, respectively.
[0019] The authentication device 2 may be, for example, a mobile information terminal having a communication function such as a smartphone, a tablet terminal, a PDA (Personal Digital Assistant), a notebook computer, a transceiver, or other devices.
[0020] The first receiver set 11 includes one or more receivers 11a. Each of the one or more receivers 11a receives an authentication request including authentication information used for authenticating the authentication device 2, which is transmitted from the authentication device 2. The authentication device 2 may transmit, for example, an authentication request that is a radio wave. The first receiver set 11 may be disposed at a first position. The authentication request may include, for example, a user identifier of the user 5 carrying the authentication device 2 that transmits the authentication request and a device identifier for identifying the authentication device 2. The user identifier may be, for example, the user's telephone number, an address such as an e-mail, a name, or the like, or a unique string for the user. The device identifier may be, for example, the address of the device or a unique string for the device. The address of the device may be, for example, a physical address such as a MAC address or other address.
[0021] The second receiver set 12 includes one or more receivers 12a. Each of the one or more receivers 12a receives an authentication request transmitted from the authentication device 2. The second receiver set 12 may be disposed at a second position different from the first position. Note that the second receiver set 12 may be the same as the first receiver set 11 except that the disposed position is different.
[0022] From the perspective of realizing more accurate positioning of the authentication device 2, it is preferable that the first receiver set 11 includes a plurality of receivers 11a, and it is preferable that the second receiver set 12 includes a plurality of receivers 12a. As shown in FIG. 1, for example, the first receiver set 11 may include four receivers 11a, and the second receiver set 12 may include four receivers 12a. However, the number of receivers included in the first and second receiver sets 11 and 12 may be any one of 1 to 3, or may be 5 or more. Each of the receivers 11a and 12a included in the first and second receiver sets 11 and 12 can acquire the intensity of the radio wave of the authentication request.
[0023] When the first receiver set 11 includes a plurality of receivers 11a, the first position may be, for example, the position of the center of gravity of the plurality of receivers 11a. More specifically, the position of the center of gravity of each receiver 11a may be specified, and the position of the center of gravity regarding the specified positions of the plurality of centers of gravity may be set as the first position. The plurality of receivers 11a may be arranged, for example, at close positions to each other, or may be arranged at distant positions from each other. Even in the latter case, it is preferable that the plurality of receivers 11a are included within the range of the distance from the first position to the second position. The same applies to the second position of the second receiver set 12.
[0024] In the present embodiment, the case where the authentication device 1 has the first and second receiver sets 11 and 12, that is, two receiver sets, will be mainly described. However, the authentication device 1 may have the first to Nth receiver sets. N is an integer of 2 or more. The first to Nth receiver sets may be respectively arranged at the first to Nth positions. The first to Nth positions are preferably different positions. The first to Nth receiver sets may also be the same as the first and second receiver sets 11 and 12. For example, the Kth receiver set may include one or more receivers. K is an arbitrary integer from 1 to N. In this case, device authentication may be performed using an authentication request received by at least any one of the one or more receivers included in the N receiver sets. Also, for each region for which region determination is performed, region determination may be performed using the intensity difference of authentication requests received by at least two of the N receiver sets.
[0025] As shown in FIG. 2, it is preferable that the first region R1 and the second region R2 are different regions. For example, the first region R1 and the second region R2 may not include a region common to both. Also, as shown in FIG. 2, the first receiver set 11 may be arranged at a position closer to the first region R1 than to the second region R2. Also, the second receiver set 12 may be arranged at a position closer to the second region R2 than to the first region R1. Here, the fact that the first receiver set 11 is arranged at a position closer to the first region R1 than to the second region R2 means, for example, that the distance between the first position where the first receiver set 11 is arranged and the representative position of the first region R1 is smaller than the distance between the first position and the representative position of the second region R2. Also, the fact that the second receiver set 12 is arranged at a position closer to the second region R2 than to the first region R1 means, for example, that the distance between the second position where the second receiver set 12 is arranged and the representative position of the second region R2 is smaller than the distance between the second position and the representative position of the first region R1. The representative positions of the first and second regions R1 and R2 may be, for example, the positions of the centers of gravity of those regions.
[0026] Also, as shown in FIG. 2, the first position where the first receiver set 11 is arranged is included in the first region R1 in a plan view, and the second position where the second receiver set 12 is arranged may be included in the second region R2 in a plan view. In FIG. 2, the case where the first position is the center of the first region R1 and the second position is the center of the second region R2 is shown, but it does not have to be so. The first position and the second position may be appropriately adjusted so that the Apollonius circles described later overlap with the first and second regions R1 and R2. Further, the first and second receiver sets 11 and 12 are preferably arranged at a position approximately the same height as the authentication device 2 carried by the user 5, but if this is difficult, they may be arranged at a location such as the ceiling that does not obstruct the passage of the user 5.
[0027] Note that the receiver 11a and the receiver 12a may include a wireless receiving device such as an antenna for receiving radio waves, or may not include a receiving device. Also, the receiver 11a and the receiver 12a may be realized by hardware, or may be realized by software such as a driver for driving the receiving device.
[0028] The authentication request in the form of radio waves may be, for example, a pulse wave transmitted intermittently, or a continuous wave transmitted continuously. Also, the wireless communication standard for transmitting and receiving the authentication request is not limited. The authentication request may be communicated, for example, by Bluetooth Low Energy (BLE), by Bluetooth Basic Rate (BR) / Enhanced Data Rate (EDR), by Wireless LAN (IEEE802.11), by IEEE802.15.4 such as ZigBee (registered trademark), or by other wireless communication standards. The authentication request is preferably transmitted and received by short-range wireless communication such as BLE, Bluetooth BR / EDR, or Wireless LAN.
[0029] The frequency of the radio wave for authentication requirements is not particularly limited, and for example, it may be a frequency in the range of 300 MHz to 300 GHz. Also, the device 2 to be authenticated may, for example, transmit the authentication requirement by broadcast or communicate by unicast. Since the authentication requirement can be transmitted without specifying the communication partner, it is preferable to transmit the authentication requirement by broadcast. In this embodiment, the case where the device 2 to be authenticated transmits the authentication requirement by broadcast will be mainly described. It is preferable that the device 2 to be authenticated transmits the authentication requirement without receiving an instruction to transmit from the user 5. The device 2 to be authenticated may, for example, transmit the authentication requirement in response to the reception of a predetermined beacon or the like. The device 2 to be authenticated may, for example, transmit the authentication requirement only once in response to the reception of this beacon, transmit the authentication requirement for a predetermined period, or, when receiving this beacon, may continuously repeat the transmission of the authentication requirement. This beacon may be transmitted, for example, in the first and second regions R1 and R2 which are regions where authentication using the authentication requirement is performed. As an example, the authentication device 1 may transmit a beacon. In this case, the authentication device 1 may further include one or more transmission units for transmitting the beacon.
[0030] The authentication information included in the authentication request may contain any information as long as it can be used for authenticating the authenticated device 2. As an example, it may contain encrypted information obtained by encrypting unique information, which is unique information. The unique information may include, for example, time, random number value, count value, one-time password, etc. The unique information may be information unique to the authentication request. That is, for each authentication request, the unique information corresponding to the encrypted information included in the authentication request may be different. The unique information may be, for example, information generated by the authenticated device 2 or information transmitted from the authentication device 1 to the authenticated device 2. In the latter case, challenge-response authentication may be performed by the authentication device 1. When the unique information is transmitted from the authentication device 1, the authentication device 1 may further include a transmission unit for transmitting the unique information. In the present embodiment, the case where the unique information is generated by the authenticated device 2 will be mainly described. Like the above-described encrypted information, it is preferable that the authentication information contains different information for each authentication request. This is to prevent the authentication information from being reused by malicious third parties. Also, as an example, the encrypted information may be information obtained by encrypting the user identifier and the unique information. In this case, the encrypted information may be considered as information including, for example, the user identifier and the authentication information.
[0031] The encryption of the unique information may be, for example, encryption by symmetric-key cryptography or encryption by public-key cryptography. That is, the encryption key used for encrypting the unique information may be, for example, a symmetric key or a public key corresponding to the authentication device 1. When the encryption key is a symmetric key, it is preferable that the authentication device 1 and the authenticated device 2 have the same symmetric key. Also, it is preferable that the symmetric key is different for each authenticated device 2.
[0032] Note that from the authenticated device 2 to the authentication device 1, it may or may not be in sight. In the latter case, the user 5 may carry the authenticated device 2 in, for example, a pocket of clothes or a bag.
[0033] The authentication unit 21 performs device authentication to determine whether the authenticated device 2 that sent the authentication request is legitimate, using the authentication information included in the authentication request received by at least one of the one or more receivers 11a, 12a included in the first and second receiver sets 11, 12. When the authentication device 1 includes N receiver sets, the authentication unit 21 may, for example, use the authentication information included in the authentication request received by at least one of the one or more receivers included in the N receiver sets to determine whether the authenticated device 2 that sent the authentication request is legitimate.
[0034] For example, when the authentication information includes encrypted information obtained by encrypting unique information, when the unique information corresponding to the encrypted information matches the unique information corresponding to the authenticated device 2 that is the source of the authentication information stored in the authentication device 1, it may be determined that the authenticated device 2 that is the source is legitimate, and when it does not match, it may be determined that the authenticated device 2 that is the source is not legitimate. Whether the unique information corresponding to the encrypted information matches the unique information stored in the authentication device 1 may be determined, for example, by whether the unique information obtained by decrypting the encrypted information matches the unique information stored in the authentication device 1, or by whether the encrypted information matches the result of encrypting the unique information stored in the authentication device 1.
[0035] When unique information is obtained in the authenticated device 2, the unique information stored in the authentication device 1 may be, for example, obtained by the same method as the acquisition of the unique information in the authenticated device 2. Also, when the authenticated device 2 receives unique information from the authentication device 1, the unique information stored in the authentication device 1 may be, for example, the unique information that the authentication device 1 sent to the authenticated device 2.
[0036] When the encrypted information included in the authentication information is encrypted with a common key, the authentication unit 21 may, for example, read out the common key stored in a predetermined recording medium in association with the user identifier included in the authentication request together with the authentication information, decrypt the encrypted information using the read common key, or encrypt the unique information stored in the authentication device 1 using the read common key. When the encrypted information included in the authentication information is encrypted with a public key, the authentication unit 21 may, for example, read out the private key from a predetermined recording medium and decrypt the encrypted information using the read private key, or read out the public key from a predetermined recording medium and encrypt the unique information stored in the authentication device 1 using the read public key.
[0037] Note that the authentication unit 21 may perform device authentication using one authentication request, or may perform device authentication using a plurality of authentication requests received within a predetermined period. For authentication using a plurality of authentication requests, refer to, for example, Patent Document 1 above.
[0038] The determination unit 22 performs region determination to determine whether the position of the device 2 to be authenticated is included in the first and second regions R1 and R2 based on the intensity difference of the authentication requests received by the first and second receiver sets 11 and 12. When the authentication device 1 includes N receiver sets, for example, the determination unit 22 may determine whether the position of the device 2 to be authenticated is included in the first and second regions R1 and R2 based on the intensity difference of the authentication requests received by at least two of the first to N receiver sets. For example, when two or more receiver sets used for the region determination regarding the first region R1 are determined in advance, the determination unit 22 may perform the region determination regarding the first region R1 using the difference in reception intensity regarding the authentication requests received by the two or more receiver sets. Similarly, for example, when two or more receiver sets used for the region determination regarding the second region R2 are determined in advance, the determination unit 22 may perform the region determination regarding the second region R2 using the difference in reception intensity regarding the authentication requests received by the two or more receiver sets. In such a case, for example, when the authentication request is not received by two or more receiver sets corresponding to the first region R1, the region determination regarding the first region R1 may not be performed. The same applies to the region determination regarding the second region R2. The two or more receiver sets corresponding to the first region R1 are the two or more receiver sets used for the region determination regarding the first region R1. In the present embodiment, when the determination unit 22 determines whether the device 2 to be authenticated is included in the first region R1 and when determining whether the device 2 to be authenticated is included in the second region R2, the case where at least the intensity difference of the authentication requests received by the first and second receiver sets 11 and 12 is mainly described.
[0039] The determination unit 22 may, for example, identify the position of the device 2 to be authenticated based on the intensity difference of the authentication requests received by the first and second receiver sets 11 and 12, and determine whether the identified position is included in the first and second regions R1 and R2. The intensity difference of the authentication requests may be, for example, the difference in the received signal strength (RSSI: Received Signal Strength Indicator) of the authentication requests. Further, when the first and second receiver sets 11 and 12 each include two or more receivers, the intensity difference may be, for example, the difference between the representative values of the plurality of received signal strengths obtained by two or more receivers in the first and second receiver sets 11 and 12, respectively. The representative value may be, for example, an average value, a median value, or the like. Further, when the first and second receiver sets 11 and 12 include two or more receivers, it is preferable that the two or more receivers have equivalent performance. For example, it is preferable that the antenna gains of the two or more receivers included in the first receiver set 11 or the second receiver set 12 are the same. In identifying the position of the wave source using the intensity difference of the received authentication requests, for example, the received intensities of the authentication requests received by the first and second receiver sets 11 and 12, and the first and second positions that are the positions of the first and second receiver sets 11 and 12 are used to identify an Apollonius circle or line corresponding to the intensity difference, and the position on, above, or within the Apollonius circle or line may be identified as the position of the device 2 to be authenticated, or the position of the device 2 to be authenticated may be identified by other methods.
[0040] Also, the position specified by the determination unit 22 may be, for example, a dot-like position, or may be a linear, planar, or three-dimensional position. The specified position may be, for example, a position in a two-dimensional plane or a position in a three-dimensional space. When specifying a planar position, the determination unit 22 may, for example, specify whether the position of the authentication target device 2 exists within the first and second regions R1 and R2. In this case, for example, when the intensity difference, which is the result of subtracting the representative value of the received signal intensity of the second receiver set 12 from the representative value of the received signal intensity of the first receiver set 11, exceeds the first threshold value, it may be determined that the position of the authentication target device 2 is included in the first region R1. Also, for example, when the intensity difference, which is the result of subtracting the representative value of the received signal intensity of the first receiver set 11 from the representative value of the received signal intensity of the second receiver set 12, exceeds the second threshold value, it may be determined that the position of the authentication target device 2 is included in the second region R2. The first and second threshold values may be respectively predetermined values.
[0041] Note that the specification of the position of the wave source using the received intensity difference of radio waves is already known, and a detailed description thereof will be omitted. For such a method of specifying the position of the wave source, see, for example, Patent Document 2 above.
[0042] After identifying the position of the authentication target device 2, the determination unit 22 may determine whether the identified position is included in the first and second regions R1 and R2. When the user 5 is carrying the authentication target device 2, the position of the authentication target device 2 can be considered to be substantially the position of the user 5. Therefore, when the determination unit 22 determines that the position of the authentication target device 2 is included in the first region R1 or the second region R2, it can be considered that the user 5 carrying the authentication target device 2 is determined to be present in the first region R1 or the second region R2. The determination unit 22 may read information indicating the first and second regions R1 and R2 stored in a recording medium (not shown), and use the read information to determine whether the identified position of the authentication target device 2 is included in the first and second regions R1 and R2. As an example, the information indicating the first and second regions R1 and R2 may be information indicating the positions of the contours of the first and second regions R1 and R2.
[0043] Note that the order of device authentication by the authentication unit 21 and region determination by the determination unit 22 does not matter. For example, region determination may be performed after device authentication. In this case, for example, region determination may be performed only for the authentication target device 2 determined to be valid in device authentication. Also, for example, device authentication may be performed after region determination. In this case, for example, device authentication may be performed only for the authentication target device 2 determined to be included in the first and second regions R1 and R2 in region determination. Whether the authentication target device 2 for device authentication and the authentication target device 2 for region determination are the same device may be determined using, for example, the user identifier or device identifier included in the authentication request. Also, for example, device authentication and region determination may be performed independently for the authentication target device 2 that transmitted the authentication request.
[0044] The output unit 23 outputs information regarding the result of device authentication and the result of area determination. The output unit 23 may output, for example, the result of device authentication itself and the result of area determination itself. Further, for example, when it is determined that the position of the authenticated device 2 determined to be legitimate by device authentication is included in the first area R1 by area determination, the output unit 23 outputs that a legitimate authenticated device 2 exists in the first area R1. When it is determined that the position of the authenticated device 2 determined to be legitimate by device authentication is included in the second area R2 by area determination, the output unit 23 may output that a legitimate authenticated device 2 exists in the second area R2. Then, in response to the output, for example, processing corresponding to the existence of a legitimate authenticated device 2 in the first area R1, processing corresponding to the existence of a legitimate authenticated device 2 in the second area R2, for example, door unlocking processing, door opening / closing processing, payment processing, etc. may be performed.
[0045] In addition, when a process that requires a user identifier or device identifier corresponding to the authenticated device 2 determined to be legitimate, such as payment processing, is performed, the output unit 23 may output, for example, the user identifier or device identifier included in the authentication request transmitted from the authenticated device 2 when outputting that a legitimate authenticated device 2 exists in the first area R1 or the second area R2. Then, the information associated with the output user identifier or device identifier may be used, for example, in payment processing or the like. The information associated with the user identifier or the like used in payment processing may be, for example, credit card or electronic money information.
[0046] Further, the output unit 23 may change the output destination according to, for example, the result of device authentication and the result of area determination. For example, when it is determined that a legitimate authenticated device 2 exists in the first area R1, the output unit 23 outputs this fact to a device that performs processing related to the first area R1 (for example, door opening / closing processing for the first area R1). When it is determined that a legitimate authenticated device 2 exists in the second area R2, the output unit 23 may output this fact to a device that performs processing related to the second area R2 (for example, control processing related to the elevator in the second area R2).
[0047] Here, this output may be, for example, a display on a display device (such as a liquid crystal display or an organic EL display), a transmission via a communication line to a predetermined device, a print by a printer, an audio output by a speaker, a storage in a recording medium, or a delivery to other components. Note that the output unit 23 may or may not include a device (such as a display device or a printer) that performs the output. Also, the output unit 23 may be realized by hardware or by software such as a driver that drives those devices.
[0048] Next, the operation of the authentication device 1 will be described with reference to the flowchart of FIG. 3. (Step S101) The first and second receiver sets 11 and 12 determine whether an authentication request has been received. If an authentication request has been received, the process proceeds to step S102; otherwise, the process of step S101 is repeated until an authentication request is received.
[0049] Note that when device authentication using a plurality of authentication requests is performed, for example, the process of receiving the authentication request in step S101 may be repeated until the reception of the plurality of authentication requests is completed. And after the plurality of authentication requests have been received, the process may proceed to step S102.
[0050] (Step S102) The authentication unit 21 performs device authentication using the authentication request received by either of the first and second receiver sets 11 and 12.
[0051] (Step S103) In the device authentication of step S102, if it is determined that the authenticated device 2 that transmitted the authentication request is legitimate, the process proceeds to step S104; otherwise, the process returns to step S101.
[0052] (Step S104) The determination unit 22 determines whether the position of the device 2 to be authenticated is included in the first area R1 based on the intensity difference of the authentication requests received by the first and second receiver sets 11 and 12 corresponding to the first area R1. Note that this area determination may be performed, for example, by specifying the position of the device 2 to be authenticated and determining whether the specified position is included in the first area R1. Further, when the authentication request transmitted from the device 2 to be authenticated is not received by at least one of the first and second receiver sets 11 and 12, this area determination may not be performed.
[0053] (Step S105) The determination unit 22 determines whether the position of the device 2 to be authenticated is included in the second area R2 based on the intensity difference of the authentication requests received by the first and second receiver sets 11 and 12 corresponding to the second area R2. Note that this area determination may be performed, for example, by specifying the position of the device 2 to be authenticated and determining whether the specified position is included in the second area R2. In this case, for example, the determination unit 22 may perform the area determination using the position of the device 2 to be authenticated specified in step S104. Further, when the authentication request transmitted from the device 2 to be authenticated is not received by at least one of the first and second receiver sets 11 and 12, this area determination may not be performed. Further, for example, when it is determined in step S104 that the position of the device 2 to be authenticated is included in the first area R1, the determination unit 22 may not perform the process of step S105. This is because the position of the device 2 to be authenticated is not included in both the first area R1 and the second area R2.
[0054] (Step S106) The output unit 23 determines whether to perform an output regarding the result of device authentication and the result of area determination. Then, when performing an output, it proceeds to step S107, and when not, it returns to step S101. Note that the output unit 23 may determine to perform an output, for example, when it is determined in one of the area determinations in steps S104 and S105 that the position of the device 2 to be authenticated is included in the first area R1 or the second area R2, and determine not to perform an output when not.
[0055] (Step S107) The output unit 23 outputs the results of device authentication and area determination, and then returns to step S101.
[0056] Note that the order of processing in the flowchart of FIG. 3 is an example, and if the same result can be obtained, the order of each step may be changed. For example, after the area determination regarding the second area R2 is performed, the area determination regarding the first area R1 may be performed. Also, in the flowchart of FIG. 3, the processing may end due to a power-off or a processing end interrupt.
[0057] Next, the operation of the authentication device 1 according to the present embodiment will be described using a specific example. In this specific example, as shown in FIGS. 1 and 2, it is assumed that the first area R1 is set outside the door 31 of the entrance of the building, and the second area R2 is set in the elevator hall of the building. Then, when the authenticated device 2 determined to be legitimate by device authentication exists in the first area R1, the entrance door 31 opens, and when the authenticated device 2 determined to be legitimate by device authentication exists in the second area R2, the elevator 32 operates.
[0058] First, assume that a user 5 carrying a legitimate authenticated device 2 approaches the entrance door 31. Then, the authenticated device 2 receives the beacon transmitted from the authentication device 1, and in response, an authentication request is transmitted from the authenticated device 2. At this point, it is assumed that the user 5 is located outside the first area R1. The authentication request is received by the first and second receiver sets 11, 12 of the authentication device 1. When the authentication request is passed to the authentication unit 21, the reception signal strength of the authentication request by the plurality of receivers 11a of the first receiver set 11 and the reception signal strength of the authentication request by the plurality of receivers 12a of the second receiver set 12 are passed to the determination unit 22 (step S101).
[0059] Upon receiving an authentication request, the authentication unit 21 performs device authentication using the authentication information included in the authentication request (step S102). Suppose that it is determined by this device authentication that the device 2 to be authenticated is legitimate (step S103). Then, the authentication unit 21 passes to the output unit 23 the fact that the device 2 to be authenticated is legitimate.
[0060] Upon receiving the received signal strength, the determination unit 22 obtains the representative value of the received signal strength acquired by the plurality of receivers 11a and the representative value of the received signal strength acquired by the plurality of receivers 12a, and uses the difference between the representative values of the received signal strength and the first and second positions which are the positions of the first and second receiver sets 11, 12 to identify the position of the device 2 to be authenticated, determines whether the identified position is included in the first region R1, and passes the determination result to the output unit 23 (step S104). In this case, suppose that it is determined that the position of the device 2 to be authenticated is not included in the first region R1. Similarly, the determination unit 22 also determines whether the position of the device 2 to be authenticated is included in the second region R2, and passes the determination result to the output unit 23 (step S105). In this case, suppose that it is determined that the position of the device 2 to be authenticated is not included in the second region R2 either. Note that the determination unit 22 may determine whether the position of the device 2 to be authenticated is included in the first or second region R1, R2 by, for example, comparing the difference between the representative values of the received signal strength with the first or second threshold value.
[0061] Upon receiving the result of the device authentication and the result of the region determination, the output unit 23 determines whether to perform an output (step S106). In this specific example, it is assumed that an output is determined to be performed when it is determined that the device 2 to be authenticated, which is determined to be legitimate, exists in the first or second region R1, R2. Therefore, in this case, the output unit 23 determines not to perform an output.
[0062] Next, assume that the user 5 carrying the legitimate authentication device 2 enters the first area R1. Then, similar to the above-described process, it is determined that the device authentication is legitimate, and this time, in the area determination as well, it is determined that the position of the authentication device 2 is included in the first area R1 (steps S101 to S105). According to these determination results, the output unit 23 determines to perform an output (step S106), and outputs information to the effect of opening the door 31 to a control device (not shown) that controls the entrance door 31 (step S107). In response thereto, when the control device opens the door 31, the user 5 carrying the legitimate authentication device 2 can enter the building.
[0063] Thereafter, assume that the user 5 carrying the legitimate authentication device 2 enters the second area R2 of the elevator hall. Then, similar to the above-described process, it is determined that the device authentication is legitimate, and in the area determination as well, it is determined that the position of the authentication device 2 is included in the second area R2 (steps S101 to S105). According to these determination results, the output unit 23 determines to perform an output (step S106), and outputs information to the effect of operating the elevator 32 to a control device (not shown) that controls the elevator 32 (step S107). In response thereto, when the control device operates the elevator 32, the user 5 can move to the desired floor by the elevator 32.
[0064] Even if a person not carrying the legitimate authentication device 2 enters the first area R1, since it is not determined that the device authentication is legitimate (steps S101 to S103), the entrance door 31 will not open.
[0065] As described above, according to the authentication device 1 of the present embodiment, device authentication and region determination in the first and second regions R1 and R2 can be performed using the first and second receiver sets 11 and 12. Therefore, the number of receiver sets can be reduced compared to the case where two or more receiver sets are arranged for each of the first and second regions R1 and R2. For example, when two receiver sets are arranged for each of the first and second regions R1 and R2, device authentication and region determination of the first and second regions R1 and R2 are performed using a total of four receiver sets. However, in the present embodiment, device authentication and region determination of the first and second regions R1 and R2 can be performed using the first and second receiver sets 11 and 12, that is, two receiver sets, and the cost can be reduced.
[0066] In addition, in this embodiment, although the description mainly focuses on the case where the area determination regarding both the first and second regions R1 and R2 is made using the intensity difference of the authentication requests received by the first and second receiver sets 11 and 12, it is not necessary to do so. As shown in FIGS. 4 and 5, the authentication device 1 also includes a third receiver set including a plurality of receivers 13a, and the intensity of the authentication request received by the third receiver set 13 may also be used to perform the area determination regarding the first and second regions R1 and R2. In this case, for example, when the determination unit 22 determines whether the authentication device 2 is included in the first region R1, it uses at least the intensity difference of the authentication requests received by the first and third receiver sets 11 and 13, and when determining whether the authentication device 2 is included in the second region R2, it may use at least the intensity difference of the authentication requests received by the second and third receiver sets 12 and 13. In this case, as shown in FIG. 5, the third position where the third receiver set 13 is arranged may be, for example, farther from the first region R1 than the first position and closer to the first region R1 than the second position. Also, the third position may be, for example, farther from the second region R2 than the second position and closer to the second region R2 than the first position. For example, even when the first and second regions R1 and R2 are separated and the authentication request transmitted by the authentication device 2 existing in the first region R1 cannot be received by the second receiver set 12, or when the authentication request transmitted by the authentication device 2 existing in the second region R2 cannot be received by the first receiver set 11, by arranging the third receiver set 13, the area determination regarding the first and second regions R1 and R2 can be made possible. Also, even in this case, since the area determination regarding the first and second regions R1 and R2 can be made using the first to third receiver sets 11 to 13, that is, three receiver sets, the number of receiver sets can be reduced compared to arranging two receiver sets for each of the first and second regions R1 and R2.
[0067] As described above, the authentication device 1 may include, for example, the first to the Nth receiver sets. N is an integer of 2 or 3 or more. In this case, it is assumed that at least one receiver set is common to at least two receiver sets used for area determination regarding the first area R1 and at least two receiver sets used for area determination regarding the second area R2. As described above, at least two receiver sets used for area determination regarding the first area R1 and at least two receiver sets used for area determination regarding the second area R2 may be exactly the same, or may include different receiver sets. In any case, by having at least one receiver set in common between at least two receiver sets used for area determination regarding the first area R1 and at least two receiver sets used for area determination regarding the second area R2, the number of receiver sets that the authentication device 1 has can be reduced as compared to the case where this is not so, and as a result, the cost can be reduced.
[0068] In addition, in the present embodiment, the case where the first region R1 is set outside the door 31 of the entrance of the building and the second region R2 is set in the elevator hall of the building has been mainly described, but it may not be so. For example, in a store such as a retail store, the first region R1 may be set in front of the first POS register that performs settlement processing, and the second region R2 may be arranged in front of the second POS register that performs settlement processing. Also, for example, the first receiver set 11 may be arranged near the first POS register, and the second receiver set 12 may be arranged near the second POS register. Then, by using the first and second receiver sets 11 and 12 to perform region determination regarding the first and second regions R1 and R2, region determination regarding the first and second regions may be performed using a smaller number of receiver sets. As another example, when the first and second conference rooms are arranged in a proximate position, the first and second regions R1 and R2 may be set outside the doors of the first and second conference rooms, respectively, and the first and second receiver sets 11 and 12 may be arranged near the doors of the first and second conference rooms, respectively. Then, by using the first and second receiver sets 11 and 12 to perform region determination regarding the first and second regions R1 and R2, region determination regarding the first and second regions may be performed using a smaller number of receiver sets.
[0069] In addition, in the present embodiment, the case where region determination is performed for two regions, that is, the first and second regions R1 and R2, has been mainly described. However, even when region determination is performed for three or more regions, when region determination is performed for at least two of the three or more regions, at least one receiver set may be commonly used. By doing so, the number of receiver sets as a whole can be reduced.
[0070] In this embodiment, as an example, when determining the area of the authentication target device 2 using two receiver sets for each area, it is possible to perform area determination for more than N / 2 areas using N receiver sets. For example, FIGS. 1 and 2 show the case where N = 2. In this case, area determination can be performed for areas exceeding 2 / 2 = 1, that is, two areas. Also, FIGS. 4 and 5 show the case where N = 3. In this case as well, area determination can be performed for areas exceeding 3 / 2 = 1.5, that is, two areas. For example, when there is no receiver set commonly used for two areas, the number of areas for which area determination can be performed using N receiver sets is N / 2 or less. However, as in the authentication device 1 according to this embodiment, when there is a receiver set commonly used for two areas, area determination can be performed for more areas than that, and costs can be reduced.
[0071] Also, for example, one or more receivers included in a certain receiver set may be attached to a moving object. As an example, as shown in FIGS. 6A and 6B, a plurality of receivers 11a included in the first receiver set 11 may be respectively attached to the door 31 at the entrance of the building. When the first receiver set 11 includes four receivers 11a, for example, two receivers 11a may be attached to the outside of one door 31, and two receivers 11a may be attached to the outside of the other door 31. In this case, the determination unit 22 may change the method of region determination according to, for example, the position of the receiver 11a, that is, according to the opening and closing of the door 31, or may not. In the former case, for example, the determination unit 22 may change the first threshold value described above according to whether the door 31 is open or closed. As an example, the determination unit 22 may receive information regarding the opening and closing state of the door 31 from a control device (not shown) that controls the door 31, and perform region determination according to the opening and closing state of the door 31 indicated by the information. When the receiver 11a is attached to a moving object such as the door 31, for example, the first position may or may not change according to the movement of the object. As an example, when the four receivers 11a included in the first receiver set 11 are attached to the door 31 such that they are line-symmetric in pairs with the mating portion of the two doors 31 as the axis of symmetry, the position of the center of gravity of the four receivers 11a, that is, the first position, will not change according to the opening and closing of the door 31. In this case, for example, it may not be necessary to change the method of region determination according to the opening and closing of the door 31. On the other hand, when the first position changes according to the movement of the object to which the receiver 11a is attached, it is preferable to change the method of region determination according to the opening and closing of the door 31.
[0072] In FIGS. 6A and 6B, an example is shown in which the four receivers 11a are located on the right side of the first region R1. As another example, the first region R1 may be set such that the position of the center of gravity of the four receivers 11a is located near the center of the first region R1 in a plan view. Further, as shown in FIGS. 6A and 6B, when the positions of the four receivers 11a are present on the right side of the first region R1 in a plan view, as another example, by arranging a radio wave shielding object such as a metal plate or a metal film on the inner surface of the door 31 (that is, the right side surface of the door 31 in FIGS. 6A, etc.), the region determination regarding the first region R1 can be appropriately performed. Further, as another example, when the determination unit 22 specifies the position of the authentication device 2 and determines whether the specified position is included in the first region R1, the four receivers 11a may not be included in the first region R1 in a plan view.
[0073] In the present embodiment, the case where the region determination is performed using two receiver sets has been mainly described. For example, when the authentication device 1 includes the first to Nth receiver sets and N is 3 or more, the region determination may be performed using three or more receiver sets. In this case, for example, when specifying the position by triangulation or the like, it is preferable that the first to Nth positions do not exist on one straight line. Otherwise, the first to Nth positions may exist on one straight line. Further, when N is 4, for example, when specifying the position by triangulation or the like, it is preferable that the first to fourth positions do not become the vertices of a parallelogram. Otherwise, the first to fourth positions may become the vertices of a parallelogram. Note that this position specification may be performed, for example, by repeatedly specifying an Apollonius circle or line based on the intensity difference of the authentication requests received by two receiver sets for different combinations of two receiver sets among three or more receiver sets, specifying a plurality of Apollonius circles or lines, and specifying the position on, in, or inside the specified Apollonius circle or line as the position of the authentication device 2, or it may be performed by other methods.
[0074] In the above embodiment, each process or each function may be realized by centralized processing by a single device or a single system, or may be realized by distributed processing by a plurality of devices or a plurality of systems.
[0075] In the above embodiment, the transfer of information performed between each component may be performed, for example, by the output of information by one component and the reception of information by the other component when the two components that transfer the information are physically different, or when the two components that transfer the information are physically the same, it may be performed by moving from the processing phase corresponding to one component to the processing phase corresponding to the other component.
[0076] In the above embodiment, information related to the processing executed by each component, for example, information received, acquired, selected, generated, transmitted, or received by each component, and information such as thresholds, mathematical formulas, addresses, etc. used in the processing by each component may be temporarily or long-term held in a recording medium not shown even if not specified in the above description. Also, the accumulation of information in the recording medium not shown may be performed by each component or an accumulation unit not shown. Further, the reading of information from the recording medium not shown may be performed by each component or a reading unit not shown.
[0077] Also, in the above-described embodiment, when information used in each component, etc., for example, information such as threshold values, addresses, and various setting values used by each component in processing may be changed by the user, even if not specified in the above description, the user may be allowed to appropriately change such information, or not. When the user can change such information, the change may be realized, for example, by an unillustrated reception unit that receives a change instruction from the user and an unillustrated change unit that changes the information according to the change instruction. The reception of the change instruction by the unillustrated reception unit may be, for example, reception from an input device, reception of information transmitted via a communication line, or reception of information read from a predetermined recording medium.
[0078] Also, in the above-described embodiment, when two or more components included in the authentication device have a communication device, an input device, etc., the two or more components may physically have a single device, or may have separate devices.
[0079] Also, in the above embodiment, each component may be configured by dedicated hardware, or for components that can be realized by software, they may be realized by executing a program. For example, by a program execution unit such as a CPU reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory, each component can be realized. At the time of its execution, the program execution unit may execute the program while accessing a storage unit or a recording medium. Note that the software that realizes the authentication device 1 in the above embodiment is a program as follows. That is, this program causes a computer to perform steps of receiving, by at least two receiver sets out of the first to Nth receiver sets including one or more receivers, an authentication request including authentication information used for authentication of the authentication device, which is transmitted from the device to be authenticated; performing device authentication to determine whether the device to be authenticated that transmitted the authentication request is legitimate, using the authentication information included in the authentication request received by at least any one of the one or more receivers in the step of receiving the authentication request; performing area determination to determine whether the position of the device to be authenticated is included in the first and second areas, based on the intensity difference of the authentication requests received by at least two receiver sets in the step of receiving the authentication request; and performing an output regarding the result of the device authentication and the result of the area determination, where N is 2 or more, and at least the same receiver set is included in at least two receiver sets used for area determination regarding the first area and at least two receiver sets used for area determination regarding the second area. This may be the program.
[0080] Note that in the above program, in steps such as receiving information and outputting information, processing that can only be performed by hardware, for example, processing performed by a communication device such as a modem or an interface card, is not included at least.
[0081] In addition, this program may be executed by being downloaded from a server or the like, or may be executed by reading a program recorded on a predetermined recording medium (for example, an optical disk such as a CD-ROM, a magnetic disk, a semiconductor memory, etc.). Further, this program may be used as a program constituting a program product.
[0082] Also, the computer that executes this program may be singular or plural. That is, centralized processing may be performed, or distributed processing may be performed.
[0083] FIG. 7 is a diagram showing an example of a computer system 900 that executes the above program to realize the authentication device 1 according to the above embodiment. The above embodiment can be realized by computer hardware and a computer program executed thereon.
[0084] In FIG. 7, the computer system 900 includes an MPU (Micro Processing Unit) 911, a ROM 912 such as a boot-up program and other programs, application programs, system programs, and a flash memory or the like in which data is stored, which is connected to the MPU 911 and temporarily stores instructions of the application program and provides a temporary storage space, a RAM 913, a touch panel 914, a wireless communication module 915, and a bus 916 that interconnects the MPU 911, the ROM 912, etc. Note that the computer system 900 may include a plurality of wireless communication modules 915 corresponding to, for example, the first and second receiver sets 11, 12, etc., or may be connected to a plurality of wireless communication modules corresponding to the first and second receiver sets 11, 12, etc. Further, the computer system 900 may include a display and an input device such as a mouse or a keyboard instead of the touch panel 914. Also, the computer system 900 may further include other recording media such as a hard disk.
[0085] A program that causes the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment may be stored in the ROM 912 via the wireless communication module 915. The program is loaded into the RAM 913 during execution. Note that the program may be loaded directly from a network.
[0086] The program does not necessarily have to include an operating system (OS), a third-party program, etc. that cause the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment. The program may include only the part of the instructions that call appropriate functions and modules in a controlled manner so as to obtain a desired result. How the computer system 900 operates is well known, and a detailed description thereof will be omitted.
[0087] Also, the above embodiments are examples for specifically implementing the present invention and do not limit the technical scope of the present invention. The technical scope of the present invention is indicated by the claims rather than the description of the embodiments, and it is intended that changes within the literal scope of the claims and the scope of equivalent meanings are included.
Explanation of Reference Numerals
[0088] 1 Authentication device 2 Authenticated device 11 First receiver set 11a, 12a, 13a Receiver 12 Second receiver set 13 Third receiver set 21 Authentication unit 22 Judgment unit 23 Output unit
Claims
1. a first to an Nth receiver set including one or more receivers for receiving an authentication request transmitted from an authenticatee device and including authentication information used for authenticating the authenticatee device; an authentication unit that performs device authentication by using authentication information included in an authentication request received by at least one of the one or more receivers included in the first to Nth receiver sets to determine whether or not an authenticated device that has transmitted the authentication request is legitimate; a determination unit that performs a region determination to determine whether the location of the authenticatee device is included in a first region or a second region based on a strength difference between authentication requests received by at least two of the first to Nth receiver sets; an output unit that outputs a determination result to a device that processes the first area when it is determined that the authentic device is present in the first area, and outputs a determination result to a device that processes the second area when it is determined that the authentic device is present in the second area, The N is 2 or more, The at least two receiver sets used in the region determination for the first region and the at least two receiver sets used in the region determination for the second region include at least the same receiver sets.
2. a first position where the first receiver set is disposed is included in the first area in a plan view; The authentication device according to claim 1 , wherein the second position where the second receiver set is disposed is included in the second area in a plan view.
3. A first to an Nth receiver set including one or more receivers that receive an authentication request transmitted from an authenticated device, the authentication request including authentication information used to authenticate the authenticated device; an authentication unit that performs device authentication by using authentication information included in an authentication request received by at least one of the one or more receivers included in the first to Nth receiver sets to determine whether or not an authenticated device that has transmitted the authentication request is legitimate; a determination unit that performs a region determination to determine whether the location of the authenticatee device is included in a first region or a second region based on a strength difference between authentication requests received by at least two of the first to Nth receiver sets; an output unit that outputs a result of the device authentication and a result of the area determination, The N is 2 or more, the at least two receiver sets used in the range determination for the first range and the at least two receiver sets used in the range determination for the second range include at least the same receiver sets; the first receiver set includes a plurality of receivers; An authentication device in which the multiple receivers of the first receiver set are respectively attached to a pair of sliding doors that open and close symmetrically, with the abutting part of the pair of doors as the axis of symmetry, and such that the position of the center of gravity of the multiple receivers does not change when the pair of doors are opened or closed.
4. An authentication device as described in any one of claims 1 to 3, wherein the judgment unit uses at least a strength difference between authentication requests received by the first and second receiver sets when determining whether the device to be authenticated is included in the first area and when determining whether the device to be authenticated is included in the second area.
5. A first to an Nth receiver set including one or more receivers that receive an authentication request transmitted from an authenticated device, the authentication request including authentication information used to authenticate the authenticated device; an authentication unit that performs device authentication by using authentication information included in an authentication request received by at least one of the one or more receivers included in the first to Nth receiver sets to determine whether or not an authenticated device that has transmitted the authentication request is legitimate; a determination unit that performs a region determination to determine whether the location of the authenticatee device is included in a first region or a second region based on a strength difference between authentication requests received by at least two of the first to Nth receiver sets; an output unit that outputs a result of the device authentication and a result of the area determination, The N is 3 or more, An authentication device, wherein the judgment unit uses at least a strength difference between authentication requests received by the first and third receiver sets when determining whether the device to be authenticated is included in the first area, and uses at least a strength difference between authentication requests received by the second and third receiver sets when determining whether the device to be authenticated is included in the second area.
6. An authentication method that is processed using first to Nth receiver sets including one or more receivers, an authentication unit, a determination unit, and an output unit, comprising: The N is 2 or more, receiving an authentication request from an authenticatee device, the authentication request including authentication information used to authenticate the authenticatee device, by at least two of the first to Nth receiver sets; a step in which the authentication unit performs device authentication by using authentication information included in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request to determine whether or not the authenticated device that has transmitted the authentication request is valid; a step of performing a region determination by the determination unit to determine whether the location of the authenticated device is included in a first region and a second region based on a strength difference of the authentication request received by at least two receiver sets in the step of receiving the authentication request; a step in which the output unit outputs a result of the determination to a device performing processing related to the first area when it is determined that the authentic device is present in the first area, and outputs a result of the determination to a device performing processing related to the second area when it is determined that the authentic device is present in the second area, The at least two receiver sets used in the region determination for the first region and the at least two receiver sets used in the region determination for the second region include at least the same receiver sets.
7. An authentication method processed using first to Nth receiver sets including one or more receivers, an authentication unit, a determination unit, and an output unit, The N is 2 or more, receiving an authentication request from an authenticatee device, the authentication request including authentication information used to authenticate the authenticatee device, by at least two of the first to Nth receiver sets; a step in which the authentication unit performs device authentication by using authentication information included in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request to determine whether or not the authenticated device that has transmitted the authentication request is valid; a step of performing a region determination by the determination unit to determine whether the location of the authenticated device is included in a first region and a second region based on a strength difference of the authentication request received by at least two receiver sets in the step of receiving the authentication request; The output unit outputs a result of the device authentication and a result of the area determination, the at least two receiver sets used in the range determination for the first range and the at least two receiver sets used in the range determination for the second range include at least the same receiver sets; the first receiver set includes a plurality of receivers; An authentication method in which the multiple receivers of the first receiver set are respectively attached to a pair of sliding doors that open and close symmetrically, with the abutting part of the pair of doors as the axis of symmetry, and such that the position of the center of gravity of the multiple receivers does not change when the pair of doors are opened or closed.
8. An authentication method processed using first to Nth receiver sets including one or more receivers, an authentication unit, a determination unit, and an output unit, The N is 3 or more, receiving an authentication request from an authenticatee device, the authentication request including authentication information used to authenticate the authenticatee device, by at least two of the first to Nth receiver sets; a step in which the authentication unit performs device authentication by using authentication information included in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request to determine whether or not the authenticated device that has transmitted the authentication request is valid; a step of performing a region determination by the determination unit to determine whether the location of the authenticated device is included in a first region and a second region based on a strength difference of the authentication request received by at least two receiver sets in the step of receiving the authentication request; The output unit outputs a result of the device authentication and a result of the area determination, An authentication method, in which, in the step of performing area determination, when determining whether the device to be authenticated is included in the first area, at least a strength difference between authentication requests received by the first and third receiver sets is used, and when determining whether the device to be authenticated is included in the second area, at least a strength difference between authentication requests received by the second and third receiver sets is used.
9. On the computer, receiving an authentication request sent from an authenticatee device, the authentication request including authentication information used to authenticate the authenticatee device, by at least two of the first to Nth receiver sets, each of which includes one or more receivers; performing device authentication to determine whether or not a device to be authenticated that has transmitted the authentication request is valid, using authentication information included in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; performing a region determination step of determining whether the location of the authenticatee device is included in a first region and a second region based on a strength difference of the authentication request received by at least two receiver sets in the step of receiving the authentication request; when it is determined that the authenticator device is present in the first area, outputting the determination result to a device that processes the first area, and when it is determined that the authenticator device is present in the second area, outputting the determination result to a device that processes the second area, The N is 2 or more, The at least two receiver sets used in range determination for the first region and the at least two receiver sets used in range determination for the second region include at least the same receiver sets.
10. A computer comprising: receiving an authentication request sent from an authenticatee device, the authentication request including authentication information used to authenticate the authenticatee device, by at least two of the first to Nth receiver sets, each of which includes one or more receivers; performing device authentication to determine whether or not a device to be authenticated that has transmitted the authentication request is valid, using authentication information included in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; performing a region determination step of determining whether the location of the authenticatee device is included in a first region and a second region based on a strength difference of the authentication request received by at least two receiver sets in the step of receiving the authentication request; and outputting a result of the device authentication and a result of the area determination. The N is 2 or more, the at least two receiver sets used in the range determination for the first range and the at least two receiver sets used in the range determination for the second range include at least the same receiver sets; the first receiver set includes a plurality of receivers; A program in which the multiple receivers of the first receiver set are respectively attached to a pair of sliding doors that open and close symmetrically, with the abutting part of the pair of doors as the axis of symmetry, and such that the position of the center of gravity of the multiple receivers does not change when the pair of doors are opened or closed.
11. A computer comprising: receiving an authentication request sent from an authenticatee device, the authentication request including authentication information used to authenticate the authenticatee device, by at least two of the first to Nth receiver sets, each of which includes one or more receivers; performing device authentication to determine whether or not a device to be authenticated that has transmitted the authentication request is valid, using authentication information included in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; performing a region determination step of determining whether the location of the authenticatee device is included in a first region and a second region based on a strength difference of the authentication request received by at least two receiver sets in the step of receiving the authentication request; and outputting a result of the device authentication and a result of the area determination. The N is 3 or more, A program in which, in the step of performing area determination, when determining whether the device to be authenticated is included in the first area, at least a strength difference between authentication requests received by the first and third receiver sets is used, and when determining whether the device to be authenticated is included in the second area, at least a strength difference between authentication requests received by the second and third receiver sets is used.
Citation Information
Patent Citations
Authentication system and authentication method
JP2010282322A
Authentication system, authentication method for authentication system, positioning device, and positioning program
JP2012181595A
User terminal positional information specifying device
JP2015200504A
Image forming apparatus and program
JP2019181783A
Authentication device, authentication method, and program
JP7555656B1