Mobile authentication system, mobile authentication method, and program
The mobile body authentication device and method address the issue of unauthorized movement by authenticating autonomous mobile bodies through remote identification, position, and time information verification, enhancing safety and security.
Patent Information
- Application Number
- JP2023510233
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-03-31
- Filing Date
- 2021-12-15
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-12-15
AI Technical Summary
Existing technologies fail to adequately prevent unauthorized movement of mobile bodies due to impersonation or unauthorized use, as highlighted in Patent Documents 1 to 3.
A mobile body authentication device and method that acquires and collates remote identification, position, and time information to verify the authenticity of autonomous mobile bodies, using a mobile body authentication system and program to suppress unauthorized movement.
Effectively prevents unauthorized movement of autonomous mobile bodies by verifying and authenticating their remote identification, position, and time information, ensuring secure operation.
Smart Images

Figure 0007708173000001 
Figure 0007708173000002 
Figure 0007708173000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a mobile body authentication device, a mobile body authentication system, a mobile body authentication method, and a program.
Background Art
[0002] In recent years, the spread of mobile bodies that move by remote control or autonomous movement, such as unmanned aerial vehicles, autonomous robots, or autonomous driving vehicles, has been expanding. Also, in order to popularize such mobile bodies, the development of technologies for safely operating mobile bodies is expected.
[0003] Patent Document 1 describes a method for determining the level of authentication for the operation of an unmanned aerial vehicle (UAV). This method includes a step of receiving information regarding the unmanned aerial vehicle, and a step of determining the level of authentication of the user identifier of the unmanned aerial vehicle based on the information and the type of user or the skill level of the user who operates the unmanned aerial vehicle. This method further includes a step of validating the authentication of the unmanned aerial vehicle or the user identifier based on the result of this determination, and a step of permitting the operation of the unmanned aerial vehicle by the user based on this validation.
[0004] Patent Document 2 describes a method for identifying a flying object using a management server and an authentication terminal. This identification method includes a step in which a user terminal that has received the individual information of the flying object transmits the individual information to the management server. Further, this identification method includes a step in which the management server evaluates the individual information, a step in which identification information is generated based on the evaluation, a step in which the identification information is recorded in an identification information database and transmitted to the user terminal, and a step in which the authentication terminal that has received the identification information of the flying object transmits the identification information to the management server, and a step in which the management server refers to the identification information database and authenticates the received identification information.
[0005] Patent Document 3 describes a method for authenticating communication between a first unmanned aircraft and a second unmanned aircraft. This method stores information specifying a set of operations to be executed by the first unmanned aircraft under the control of the computer system mounted on the first unmanned aircraft, and receives a message and authentication information for the message from the second unmanned aircraft, determines that the message is genuine, and modifies the above information. Here, the above authentication information is unique to the sender of the above message. The above determination is executed based at least in part on the authentication information, and the above modification is executed based at least in part on the message. Person A message and authentication information for the message are received from the second unmanned aircraft, it is determined that the message is genuine, and the above information is modified. Here, the above authentication information is unique to the sender of the above message. The above determination is executed based at least in part on the authentication information, and the above modification is executed based at least in part on the message.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
Patent Document 2
Patent Document 3
Summary of the Invention
Problems to be Solved by the Invention
[0007] As described above, it is desired to promote the spread of moving bodies while considering safety, but for this purpose, it is required to suppress the unauthorized movement of moving bodies due to impersonation or the like. Therefore, a technology for suppressing the unauthorized use of moving bodies is required. Note that none of the technologies described in Patent Documents 1 to 3 can sufficiently suppress the unauthorized use of moving bodies.
[0008] In view of the above problems, an object of the present disclosure is to provide a moving body authentication device, a moving body authentication system, a moving body authentication method, and a program capable of suppressing unauthorized movement of a self-mobile moving body.
Means for Solving the Problems
[0009] The mobile body authentication device according to the first aspect of the present disclosure includes an acquisition unit, a collation unit, and an output unit. The acquisition unit acquires remote identification information, which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from the mobile body capable of autonomous movement. The collation unit executes collation based on part or all of the information acquired by the acquisition unit. The output unit outputs the result of the collation by the collation unit.
[0010] The mobile body authentication method according to the second aspect of the present disclosure is a method in which a computer executes the following processes. The processes include acquiring remote identification information, which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from the mobile body capable of autonomous movement. The processes include executing collation based on part or all of the acquired information and outputting the result of the collation.
[0011] The program according to the third aspect of the present disclosure is a program for causing a computer to execute the following processes. The processes include acquiring remote identification information, which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from the mobile body capable of autonomous movement. The processes include executing collation based on part or all of the acquired information and outputting the result of the collation.
Advantages of the Invention
[0012] According to the present disclosure, it is possible to provide a mobile body authentication device, a mobile body authentication system, a mobile body authentication method, and a program capable of suppressing unauthorized movement of a mobile body capable of autonomous movement.
Brief Description of the Drawings
[0013]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Embodiments for Carrying Out the Invention
[0014] Hereinafter, the present invention will be described through embodiments of the invention, but the invention according to the claims is not limited to the following embodiments. Also, not all of the configurations described in the embodiments are necessarily essential as means for solving the problems. For clarity of explanation, the following description and drawings have been appropriately omitted and simplified. In each drawing, the same or equivalent elements are denoted by the same reference numerals, and duplicate explanations are omitted as appropriate. Also, in the drawings, one-way arrows may be attached, but the one-way arrows simply indicate the direction of the flow of a certain signal (data) and do not exclude bidirectionality.
[0015] <Embodiment 1> Embodiment 1 will be described with reference to FIGS. 1 and 2. FIG. 1 is a block diagram showing a configuration example of the mobile body authentication device according to Embodiment 1. As shown in FIG. 1, the mobile body authentication device 1 according to the present embodiment is a device for authenticating a mobile body capable of autonomous movement, and includes an acquisition unit 1a, a collation unit 1b, and an output unit 1c.
[0016] Here, the moving object to be authenticated only needs to be a moving object capable of autonomous movement, and can be vehicles, aircraft, ships, autonomous mobile robots (such as walking robots, etc.) of various sizes and shapes, regardless of whether a driver needs to board or not, as long as it can at least move autonomously. The above vehicle can include a self-driving vehicle.
[0017] The above aircraft can be an unmanned aerial vehicle (UAV: Unmanned Aerial Vehicle), a flying car, etc. Also, the above aircraft may be a vertical take-off and landing aircraft (Vertical Take-Off and Landing Aircraft, Vtol aircraft) or an eVTOL (electric VTOL) aircraft. The above aircraft may be a tilt-rotor aircraft. The above aircraft may be a helicopter. Also, the above aircraft can have, for example, a rotary wing, but is not limited thereto, as long as it can fly by autonomous control. The above aircraft may be a drone carrying luggage or the like, or a manned aircraft with passengers on board.
[0018] Also, the autonomous movement may be movement along a route set in advance, or movement based on remote operation by the user within a permitted movement range where the movement range is permitted in advance. Like the moving object performing the latter movement, the moving object to be authenticated can perform control to autonomously control the attitude while moving according to the operation instructions (such as the moving direction and moving speed) in response to remote control, and can also include a moving object that cannot move autonomously along a route. Thus, the moving object to be authenticated can be, for example, a moving object that moves by remote control or a moving object that moves autonomously under predetermined management.
[0019] The acquisition unit 1a acquires remote identification information, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from a mobile body capable of autonomous movement. The authentication information can be, for example, information obtained by anonymizing the remote identification information, position information, and time information. The acquisition unit 1a can acquire these pieces of information at once, but the acquisition procedure is not limited, for example, it can first acquire the remote identification information, position information, and time information, and then acquire the authentication information. The acquisition unit 1a can acquire various pieces of information as described above by connecting to the mobile body to be authenticated via wireless communication. Note that depending on the type of the mobile body, this connection can also be made by wire.
[0020] Here, the remote identification information is information for managing the remote operation of the mobile body. The remote identification information can be used to identify the body of the mobile body during remote operation, and thus can also be referred to as body identification information. More specific examples of the remote identification information will be described in Embodiment 2.
[0021] The authentication information may be generated by a digital signature method from the remote identification information, position information, and time information, or may be generated by other methods such as a one-time password. However, the authentication information is not limited to these, and any information that can be authenticated by the verification unit 1b described later is acceptable.
[0022] The verification unit 1b performs verification based on part or all of the various types of information acquired by the acquisition unit 1a. When using authentication information for verification, the verification unit 1b preferably has a function of de - anonymizing (decrypting) the anonymized authentication information. The information to be verified against the authentication information in the verification unit 1b is not limited. When the acquisition unit 1a acquires the information that has not been anonymized, the verification unit 1b can also perform verification using the information that has not been anonymized. In this case, the verification unit 1b can be configured to verify the authentication information acquired by the acquisition unit 1a and at least one of the remote identification information, location information, and time information acquired by the acquisition unit 1a. Alternatively, the verification unit 1b may verify at least one of the remote identification information, location information, and time information acquired by the acquisition unit 1a against the corresponding information stored in advance.
[0023] In addition, the mobile body authentication device 1 is composed of its main body and a terminal device connectable to the main body, and the terminal device can also function as a part of the mobile body authentication device 1. In this case, the terminal device receives at least one of the location information, time information, and authentication information about the mobile body from the mobile body, and by performing verification based on the received information, it can detect whether unauthorized information or tampered information has been transmitted. In this case, on the main body side of the mobile body authentication device 1, the detection result is obtained from the terminal device as one of the verification results. Furthermore, on the main body side of the mobile body authentication device 1, it is also possible to verify whether the authentication information transmitted by the mobile body is correct, and to perform verification between the information transmitted by the mobile body and the registered information of the remote identification information registered in advance, the registered information of the movement plan of the mobile body, etc. Thereby, the mobile body authentication device 1 can detect impersonation and the like.
[0024] The output unit 1c outputs the result of the verification in the verification unit 1b. The output destination in the output unit 1c can be, for example, a display device (not shown) provided in the mobile body authentication device 1, a terminal device connectable to the mobile body authentication device 1, etc., and the output destination can be determined in advance. In this way, the mobile body authentication device 1 can suppress the unauthorized movement of the autonomously movable mobile body due to impersonation or the like by performing the above-described verification and output of the verification result.
[0025] An example of the mobile body authentication method according to the present embodiment will be described with reference to the flowchart of FIG. 2. The mobile body authentication device 1 can be configured by a computer or can be configured to incorporate a computer. In the method shown in FIG. 2, such a computer acquires remote identification information, position information, time information, and authentication information from the mobile body (step S1). Next, the computer performs a verification based on part or all of the acquired information (step S2) and outputs the verification result (step S3).
[0026] Note that the mobile body authentication device 1 can have a processor and a storage device (not shown). This storage device can include, for example, a non-volatile memory such as a flash memory or an SSD (Solid State Drive). In this case, the storage device of the mobile body authentication device 1 stores a computer program (hereinafter also simply referred to as a program) for executing the above-described mobile body authentication method. Further, the processor causes the storage device to read the computer program into a buffer memory such as a DRAM (Dynamic Random Access Memory) and executes the program.
[0027] Each component of the mobile authentication device 1 may be implemented by dedicated hardware. Also, some or all of each component may be implemented by general-purpose or dedicated circuitry, a processor, etc., or a combination thereof. These may be configured by a single chip or by a plurality of chips connected via a bus. Some or all of each component of each device may be implemented by a combination of the circuitry etc. described above and a program. Also, as the processor, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (field-programmable gate array), etc. can be used. Note that the description regarding the configuration described here can also be applied to other devices or systems described below in the present disclosure.
[0028] Also, when some or all of each component of the mobile authentication device 1 are implemented by a plurality of information processing devices, circuitry, etc., the plurality of information processing devices, circuitry, etc. may be centrally arranged or may be distributed as in the example using the terminal device. For example, the information processing devices, circuitry, etc. may be implemented in a form in which each is connected via a communication network, such as a client-server system, a cloud computing system, etc. Also, the function of the mobile authentication device 1 may be provided in the form of SaaS (Software as a Service).
[0029] As described above, according to the present embodiment, it becomes possible to suppress an unauthorized movement of a mobile object capable of autonomous movement.
[0030] <Embodiment 2> Next, Embodiment 2 will be described with reference to FIGS. 3 to 7, but various examples described in Embodiment 1 can be applied. FIG. 3 is a schematic diagram showing a configuration example of a mobile authentication system according to the present embodiment.
[0031] As shown in FIG. 3, the mobile body authentication system according to the present embodiment (hereinafter, this system) is an example of a mobile body authentication system. The mobile body to be authenticated is the mobile body 30, and the system includes a mobile body authentication device 10 as an example of the mobile body authentication device 1.
[0032] As shown in FIG. 3, in this system, the mobile body authentication device 10, the terminal device 20, and the remote identification information management system 40 that manages remote identification information are connected via the network N1. It is desirable that this network N1 be a secure network. The remote identification information management system 40 does not necessarily have to be connected to the terminal device 20, and it is sufficient if it is connected to the mobile body authentication device 10. Further, in this system, the terminal device 20 (or the mobile body authentication device 10) can be wirelessly connected to be communicable with the mobile body 30. However, there are cases where the mobile body 30 is impersonating another mobile body or has been modified to be incommunicable.
[0033] Hereinafter, an example of constructing this system will be described in which the mobile body 30 (provided that it has not been modified to be incommunicable) can be connected to the mobile body authentication device 10 via the terminal device 20 as shown in FIG. 3. However, as an alternative configuration, it is also possible to construct a system in which the mobile body 30 can be directly wirelessly connected to the mobile body authentication device 10, or a system in which the mobile body authentication device 10 is mounted on the terminal device 20 in FIG. 3.
[0034] In this system, the mobile bodies to be authenticated other than the mobile body 30 may be of the same model as the mobile body 30 or of different models. An example of the functional configuration of the mobile body 30 will be described later.
[0035] The mobile body 30 can be controlled by a remote controller (control device) 32 by a user (operator) P1, or can move completely autonomously along a set route in a state where the route is set. The remote controller 32 is a device for remotely operating the mobile body 30, and can send a command for causing the mobile body 30 to perform a predetermined operation by wireless communication. The remote controller 32 may be able to acquire data of sensors or the like that the mobile body 30 has. Further, the remote controller 32 may be able to transmit predetermined information to the terminal device 20 or the mobile body authentication device 10 side via the mobile body 30.
[0036] The mobile body authentication device 10 can include a control unit 11 that controls the whole, a storage unit 12, and a communication unit 13 that communicates with the outside, and can be constructed as a single device or as a system in which functions are distributed among a plurality of devices. The acquisition unit 1a in FIG. 1 can be exemplified by the control unit 11 and the communication unit 13 that acquires information according to the control thereof, and the collation unit 1b in FIG. 1 can be exemplified by the control unit 11. Further, the output unit 1c in FIG. 1 can be exemplified by a display device (not shown) that displays the authentication result under the control of the control unit 11 and its control, or by the communication unit 13 that transmits the collation result to the terminal device 20 under the control of the control unit 11 and its control.
[0037] Further, the mobile body authentication device 10 can include an instruction reception unit that receives an instruction to execute collation. In the example of FIG. 3, this instruction reception unit can be constituted by the communication unit 13 and the control unit 11. The control unit 11 receives the above instruction via the communication unit 13.
[0038] The terminal device 20 can be a device used by an administrator P2 who manages and monitors the operations of a plurality of moving objects such as the moving object 30, but it is not limited to the device used by the administrator P2. That is, the terminal device 20 can also be a device used by various persons other than the administrator P2, such as ordinary people or police officers. Further, as the terminal device 20, a terminal device used by the administrator P2 and a terminal device used by a person other than the administrator P2 can also be incorporated into this system. In this case, the administrator P2 and other persons can receive information on the moving object with their own terminal devices. However, for the sake of simplicity of explanation below, an example in which the terminal device 20 is used by the administrator P2 will be given. The terminal device 20 can be a portable computer such as a mobile phone, a smartphone, a tablet terminal, etc., but it may also be a stationary PC (Personal Computer) or the like.
[0039] The remote identification information management system 40 is connected to the moving object authentication device 10 and is an example of a management device that manages remote identification information. It can be constructed as a single device or as a system in which functions are distributed among a plurality of devices. The remote identification information management system can include a control unit 41 that controls the whole, a storage unit 42 that stores remote identification information 44 for each moving object, and a communication unit 43 that communicates with the outside via the network N1 or the like. In this way, the remote identification information management system 40 manages the remote identification information 44 for each of the plurality of moving objects. This remote identification information 44 can be stored together with a flag indicating its validity / invalidity, and its content can also be appropriately updated manually or automatically by the operation side of the remote identification information management system 40. Further, in the storage unit 42, a movement plan (also referred to as a flight plan in the case of a flying object such as an unmanned aircraft) for each moving object such as the moving object 30 can be registered in advance by application.
[0040] Next, with reference to FIG. 4, a configuration example of the moving object 30 in FIG. 3 will be described. FIG. 4 is a block diagram showing a configuration example of the moving object 30. The moving object 30 can mainly include a communication unit 311, a camera 312, a sensor group 313, a control unit 314, a drive unit 315, and a storage unit 320.
[0041] The communication unit 311 includes an interface for wirelessly connecting to the remote controller 32 and an interface for wirelessly connecting to the terminal device 20. The wireless communication method only needs to have no interference in the communication between the two.
[0042] Also, in the configuration where the moving body 30 directly communicates with the moving body authentication device 10 as described above, the communication unit 311 can include an interface for wirelessly connecting to the moving body authentication device 10. The method of this wireless communication is not limited either.
[0043] In this embodiment, similar to Embodiment 1, authentication information or information such as authentication information, remote identification information, position information, and time information is transmitted from the moving body 30. This transmission can be performed to the terminal device 20, but can also be performed to the moving body authentication device 10. In either case, the moving body 30 can be configured to periodically transmit information such as remote identification information. That is, the moving body 30 may be a moving body set to move while periodically transmitting information such as remote identification information.
[0044] The camera 312 captures a landscape every preset period while the moving body 30 is moving and generates image data related to the captured image. The image data related to the image captured by the camera 312 is supplied to the remote controller 32 via the communication unit 311. Also, the moving body 30 can be configured to transmit this image data to the terminal device 20 (or the moving body authentication device 10). The sensor group 313 refers to various sensors provided in the moving body 30. The sensor group 313 may include, for example, an antenna for acquiring position information by GNSS (Global Navigation Satellite System), a gyro sensor, a thermometer, or a hygrometer.
[0045] The control unit 314 includes an arithmetic device such as a CPU or an MCU, and controls the entire mobile body 30. The driving unit 315 is for driving the mobile body 30 to move, and includes, for example, a motor for rotating a rotary wing (propeller) 31 used when the mobile body 30 moves. The storage unit 320 is a storage device including a non-volatile memory such as a flash memory or an SSD, and stores at least remote identification information 321. This embodiment performs processing assuming a case where the remote identification information 321 is falsified by an operator P1 or the like.
[0046] Next, an example of the remote identification information 44, 321 will be described with reference to FIG. 5, but the remote identification information is not limited to the content illustrated here. FIG. 5 is a diagram showing an example of the remote identification information. The remote identification information 44 and the remote identification information 321 illustrated below have different values in part or in whole for each mobile body, but they are basically the same for one mobile body. The remote identification information 44 is constructed as a secure system in the remote identification information management system 40, so that it cannot be falsified from the outside, but the remote identification information 321 on the mobile body 30 side may be falsified by an operator P1 or the like.
[0047] As illustrated in FIG. 5, the remote identification information 44, 321 can include airframe information, administrator information, and user information, and each information can be stored in association with, for example, an identifier of the mobile body.
[0048] The airframe information can include the cumulative travel time, repair history, etc., and these can be updated dynamically. Further, the airframe information can include the expiration date related to the operation qualification of the target mobile body 30, the airframe number (airframe ID), the weight, and the like.
[0049] The administrator information can include the airframe operation record, the number of owned units, etc., and these can be updated dynamically. Further, the administrator information can include the expiration date related to the management qualification of the target mobile body 30, the name or address of the administrator, and the address or residence of the administrator, etc.
[0050] The user information can include the user's movement records, accident history, etc., and these can be dynamically updated. Also, the user information can include the expiration period related to the usage qualification of the target moving body 30, the name of the user P1, and the user's address, etc.
[0051] Next, with reference to FIG. 6, examples of information transmission / reception between devices and collation targets will be described. FIG. 6 is a schematic diagram for explaining information transmission / reception and collation in the moving body authentication system of FIG. 3. In FIG. 6, a unidirectional thin-line arrow indicates the flow of information, a unidirectional thick-line arrow indicates the flow of information involving processing, a bidirectional thin-line arrow indicates the collation process, and a bidirectional thin broken-line arrow indicates the collation process within the terminal device 20.
[0052] As described in Embodiment 1, in this embodiment as well, various information from the moving body 30 will be received by the moving body authentication device 10 as countermeasures against spoofing of the airframe authentication and collation will be performed. For the various information, a configuration can be adopted in which the moving body 30 periodically distributes these information, but it can also be obtained as a result of the terminal device 20 making an information transmission request to the moving body 30.
[0053] In this system, in the configuration as described above, the administrator P2 can perform the following processing while visually observing the moving body 30.
[0054] When the control unit 11 of the moving body authentication device 10 receives an instruction to execute collation, it executes information acquisition from the moving body 30 via the communication unit 13 and executes collation. This instruction can also be performed by the terminal device 20 accessing the remote identification information management system 40 via the moving body authentication device 10 or directly, specifying the remote identification information in a state where the movement plan is viewed, and making an information transmission request to the moving body 30.
[0055] At the time of this verification, the control unit 11 not only verifies the acquired authentication information against the remote identification information 321, time information, and position information, but also performs the following verifications. That is, the control unit 11 further performs at least one of a verification of the time information of the moving body 30 against the time information indicating the current time of itself or the terminal device 20, and a verification of the position information of the moving body 30 against the position information indicating the current position of itself or the terminal device 20.
[0056] Regarding a specific example, first, the terminal device 20 acquires, from the moving body 30 through wireless communication with the moving body 30, position information indicating the current position of the moving body 30, time information indicating the current time, remote identification information 321, and authentication information. This authentication information can be generated by the moving body 30 from the remote identification information 321, position information, and time information, and the generation method is not limited.
[0057] Also, the data format used for the transmission from the moving body 30 to the terminal device 20 and the subsequent transmission from the terminal device 20 to the moving body authentication device 10 is not limited. In the present embodiment, authentication (verification) based on authentication information created from remote identification information including the aircraft ID, etc., time information, and position information is performed, and countermeasures against aircraft impersonation are implemented.
[0058] Next, the terminal device 20 transmits, to the moving body authentication device 10, the position information indicating the current position of the terminal device 20 and the time information indicating the current time of the terminal device 20, together with the remote identification information 321, position information, time information, and authentication information received from the moving body 30.
[0059] Further, the moving body authentication device 10 decodes (non - anonymizes) the received authentication information by decryption or the like, and verifies whether or not it has been tampered with against the also - received remote identification information 321, position information, and time information. In this way, the authentication information is, for example, information generated from information including the remote identification information 321, position information, and time information, and the verification can be performed after decrypting the authentication information.
[0060] Further, the mobile body authentication device 10 collates the received time information and position information of the mobile body 30 with the time information and position information included in the operation plan for the received remote identification information 321, respectively. Also, the terminal device 20 can transmit its own position information and time information to the mobile body authentication device 10, and the mobile body authentication device 10 can collate the position information and time information of the received mobile body 30 with the position information and time information of the received terminal device 20. In this case, it means that the mobile body authentication device 10 executes the confirmation by comparing the position and time of the terminal device 20 itself with the position and time of the mobile body 30. Of course, this confirmation can also be executed on the terminal device 20 side. For example, the terminal device 20 can also collate at least one of the time information, position information, and authentication information received from the mobile body 30 with its own time information, its own position information, and the authentication information it holds (the thin two-way dashed arrows in FIG. 6). The terminal device 20 can transmit the collation result to the mobile body authentication device 10 or other notification destinations.
[0061] In addition, the mobile body authentication device 10 can access the remote identification information management system 40 and collate the remote identification information 321 received from the terminal device 20 with the remote identification information 44 of the target mobile body 30 stored in the remote identification information management system 40. That is, the mobile body authentication device 10 can also collate the acquired remote identification information 321 with the usable remote identification information managed by the remote identification information management system 40.
[0062] The mobile body authentication device 10 performs collation for each piece of information in this way (or receives the collation results for some pieces of information), determines that the collation is successful when the collation for all pieces of information is successful, and determines that the collation has failed in other cases. Also, in the case where collation cannot be performed, it includes the case where the mobile body 30 is modified so that it cannot transmit information, and it can also be determined that the collation has failed when all the necessary information cannot be received from the mobile body 30. Then, the mobile body authentication device 10 outputs its determination result (collation result) by replying to the terminal device 20 that is the instruction source. Note that the output of the collation result may be only when the collation fails. Also, the mobile body authentication device 10 can be configured to transmit this collation result to at least one of a police system (not shown) that controls suspicious mobile bodies and a system of the Ministry of Land, Infrastructure, Transport and Tourism (not shown).
[0063] Through such processing, the mobile body authentication device 10 can perform body authentication and forgery detection of the mobile body 30 with respect to the remote identification information, time, and position, and output the results. Also, although the explanation was based on the premise of collating all of the remote identification information, position, and time, the system can also be constructed so as to collate only any one or two of them.
[0064] Also, when the authentication fails (that is, when forgery or the like is detected), the mobile body authentication device 10 preferably notifies the following various notification destinations to that effect. The notification destinations can include one or more of the terminal device 20 used by the administrator P2 or the like, the mobile body 30, the administrator and user of the mobile body 30 (the person on the side being forged who is a registered person), the operator of the mobile body authentication device 10, the police, the Ministry of Land, Infrastructure, Transport and Tourism, etc.
[0065] In addition, when the verification fails, the mobile body authentication device 10 preferably transmits warning information to the mobile body 30 that is the source of the authentication information via the communication unit 13. This transmission can be executed directly from the mobile body authentication device 10, but can also be executed via the terminal device 20. Of course, since the mobile body 30 may be modified so as not to receive such warning information from the terminal device 20 or to ignore it, such warning information will be transmitted when communication is possible.
[0066] Furthermore, the mobile body authentication device 10 can also transmit an instruction (forced landing signal) to force the mobile body 30 to land via the terminal device 20. However, here too, this can be executed when the terminal device 20 can communicate with the mobile body 30 and the mobile body 30 can receive such an instruction without ignoring it.
[0067] In addition, in this system, the mobile body authentication device 10 can access the remote identification information management system 40 to adopt a configuration that eliminates the need for visual inspection by the administrator P2. In that case as well, for the example of the post-verification process, the same process as the configuration that requires visual inspection can be adopted.
[0068] In order to eliminate the need for visual inspection by the administrator P2, it is a prerequisite that the mobile body authentication device 10 acquires position information indicating the current position of the mobile body 30 via the terminal device 20 (or directly). Then, at the time of verification, the mobile body authentication device 10 further executes a comparison between the time information and position information of the mobile body 30 and the time information and position information set in advance in the storage unit 42 as the operation plan (movement plan) for the mobile body 30 related to the remote identification information 321. This operation plan can be something that has been applied for in advance. However, even when visual inspection is involved, such a comparison with the operation plan can also be executed.
[0069] Also, although the description has been made on the premise that the collation is basically performed only by the mobile authentication device 10, as briefly described, part or all of the collation can also be executed by the terminal device 20. That is, the terminal device 20 can also be configured to perform collation based on remote identification information, time information, location information, and authentication information, whereby the terminal device 20 can detect spoofing. In the case where the collation is performed by the terminal device 20, the processing for the collation result can be basically the same as that described for the mobile authentication device 10, but the mobile authentication device 10 can be included as the notification destination of the collation result. That is, when the authentication fails (that is, when spoofing or the like is detected), the terminal device 20 preferably notifies the following various notification destinations to that effect. As the notification destinations, it can include one or more of the mobile authentication device 10, the mobile body 30, the administrator or user of the mobile body 30 (the person on the side being impersonated who is a registered person), the operator of the mobile authentication device 10, the police, the Ministry of Land, Infrastructure, Transport and Tourism, etc.
[0070] Therefore, this system can be configured to execute collation as follows in the case of (1) when the terminal device 20 receives various information from the mobile body 30 and (2) when the mobile authentication device 10 receives various information from the mobile body 30. In the case of (1) above, the terminal device 20 receives remote identification information, location information, and time information from the mobile body 30, collates them with the location information and time information of the terminal device 20, and checks whether incorrect information is being sent or has been tampered with. Further, the terminal device 20 receives authentication information from the mobile body 30 and authenticates whether the mobile body 30 that sent the information is the correct mobile body, for example, by collating it with pre-prepared information to be authenticated. In the case of (2) above, the mobile authentication device 10 receives remote identification information, location information, and time information sent by the mobile body 30 from the mobile body 30 or the terminal device 20, compares them with the location information and time information of the flight plan registered in advance for each remote identification information, and checks whether they match. Further, the mobile authentication device 10 receives the authentication information sent by the mobile body 30 and authenticates whether the mobile body 30 that sent the information is the correct mobile body, for example, by collating it with pre-prepared information to be authenticated.
[0071] Next, with reference to FIG. 7, an example of the collation process in this system (the mobile body authentication system in FIG. 3) will be briefly described. FIG. 7 is a flowchart for explaining an example of the collation process in this system.
[0072] In this system, first, the mobile body authentication device 10 acquires various information (remote identification information 321, time information, position information, authentication information) from the mobile body 30 via the terminal device 20 (step S11). In step S11, although the position information and time information of the terminal device 20 can also be acquired as described above, if the mobile body authentication device 10 is arranged at a position close to the terminal device 20, the position information and time information indicating the position of the mobile body authentication device 10 can also be used.
[0073] Next, the mobile body authentication device 10 decrypts (non-secretly) the information that needs to be decrypted among the received information (here, the authentication information) (step S12), and collates the decrypted information and the information that does not need to be decrypted with the information prepared by itself (step S13).
[0074] Next, the mobile body authentication device 10 determines whether the collation of the mobile body 30 as a whole is successful or not from the collation results of each information (step S14). If successful, it transmits (outputs) the collation success to the terminal device 20 (step S15) and ends the process. On the other hand, if it fails (in the case of NO in step S14), it transmits (outputs) the collation failure to the terminal device 20 (step S16), and transmits an instruction to stop the use of the target remote identification information 321 to the remote identification information management system 40 (step S17) and ends the process.
[0075] The order of steps S16 and S17 does not matter. Also, of course, the transmission content of step S17 may include information indicating that the collation has failed, or may only be information indicating that the collation has failed. In the remote identification information management system 40 that has received this instruction or information indicating failure, the control unit 41 stops the use of the corresponding remote identification information 44 for at least the aircraft number of the remote identification information 321, or stores it as a target for attention.
[0076] The remote identification information to be subject to usage suspension can be the remote identification information for which some information (for example, only the user, only the user and the administrator, etc.) regarding the remote identification information 321 targeted for the usage suspension instruction matches. The same applies when it is an item requiring attention. In this way, the remote identification information management system 40 can set the remote identification information to the usage suspension state or the attention management state as an object to be subject to usage suspension or requiring attention, and this can be executed by changing the operation qualification or the management qualification or changing the associated flag. Also, when there is no remote identification information 321 targeted for the usage suspension instruction, the remote identification information management system 40 can also store it in the storage unit 42 as an item requiring attention.
[0077] In this way, the remote identification information management system 40 manages the remote identification information for each of a plurality of moving bodies, and when receiving an instruction to suspend the use of the remote identification information from the mobile body authentication device 10, it is preferable to make the remote identification information for the moving body to which the instruction pertains unusable. Also, in step S17, an example was given in which an instruction to suspend the use of the target remote identification information 321 was transmitted to the remote identification information management system 40, but a configuration in which the remote identification information management system 40 includes the mobile body authentication device 10 can also be adopted. In that case, in accordance with such an instruction, the use of the target remote identification information 321 will be suspended.
[0078] As described above, according to the present embodiment, it becomes possible to suppress unauthorized movement of a moving body such as the moving body 30 without permission.
[0079] <Example of Hardware Configuration, etc.> Hereinafter, with reference to FIG. 8, a case where each functional configuration in each device such as the mobile body authentication device in the present disclosure is realized by a combination of hardware and software will be described. FIG. 8 is a block diagram illustrating the hardware configuration of a computer.
[0080] The mobile authentication device, management device, terminal device, and control device in the present disclosure can realize the above-described functions by a computer 500 including the hardware configuration shown in FIG. 8. The computer 500 may be a portable computer such as a smartphone or a tablet terminal, or may be a stationary computer such as a PC. The computer 500 may be a dedicated computer designed to realize each device, or may be a general-purpose computer. The computer 500 can realize a desired function by installing a predetermined application.
[0081] The computer 500 includes a bus 502, a processor 504, a memory 506, a storage device 508, an input / output interface (I / F) 510, and a network interface (I / F) 512. The bus 502 is a data transmission path for the processor 504, the memory 506, the storage device 508, the input / output interface 510, and the network interface 512 to transmit and receive data to and from each other. However, the method of connecting the processor 504 and the like to each other is not limited to bus connection.
[0082] The processor 504 is various processors such as a CPU, a GPU, or an FPGA. The memory 506 is a main storage device realized using, for example, a RAM (Random Access Memory). The storage device 508 is an auxiliary storage device realized using a hard disk, an SSD, a memory card, or a ROM (Read Only Memory). The storage device 508 stores a program for realizing a desired function. The processor 504 reads this program into the memory 506 and executes it to realize each functional component of each device.
[0083] The input / output interface 510 is an interface for connecting the computer 500 and an input / output device. For example, an input device such as a keyboard and an output device such as a display device are connected to the input / output interface 510. The network interface 512 is an interface for connecting the computer 500 to a network.
[0084] In each embodiment, the program described above can be stored using various types of non-transitory computer readable media and supplied to a computer. Non-transitory computer readable media include various types of tangible storage media. Examples of non-transitory computer readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical recording media (e.g., magneto-optical disks). Further, this example includes CD-ROM (Read Only Memory), CD-R, CD-R / W. Further, this example includes semiconductor memories (e.g., mask ROM, PROM (Programmable ROM), EPROM (Erasable PROM), flash ROM, RAM (Random Access Memory)). Also, the program may be supplied to the computer by various types of transitory computer readable media. Examples of transitory computer readable media include electrical signals, optical signals, and electromagnetic waves. Transitory computer readable media can supply the program to the computer via wired communication paths such as electric wires and optical fibers, or wireless communication paths.
[0085] Note that the present disclosure is not limited to the above embodiments and can be appropriately changed without departing from the spirit.
[0086] The present invention has been described with reference to the embodiments, but the present invention is not limited thereto. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the invention.
[0087] Some or all of the above embodiments can be described as follows in the appended claims, but are not limited thereto. (Appended Claim 1) An acquisition unit that acquires remote identification information, which is information for managing remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from a mobile body capable of autonomous movement; A collation unit that executes collation based on some or all of the information acquired by the acquisition unit; An output unit that outputs the result of the collation by the collation unit; A mobile body authentication device comprising the above. (Appended Claim 2) Comprising an instruction reception unit that receives an instruction to execute the collation by the collation unit, When the instruction is received by the instruction reception unit, the acquisition is executed by the acquisition unit, and the collation is executed by the collation unit between the time information of the mobile body and the time information indicating the current time at the mobile body authentication device. The mobile body authentication device according to Appended Claim 1. (Appended Claim 3) Comprising an instruction reception unit that receives an instruction to execute the collation by the collation unit, When the instruction is received by the instruction reception unit, the acquisition is executed by the acquisition unit, and the collation is executed by the collation unit between the position information of the mobile body and the position information indicating the current position of the mobile body authentication device. The mobile body authentication device according to Appended Claim 1 or 2. (Appended Claim 4) The instruction reception unit receives the instruction from a terminal device connected to the mobile body authentication device, When the collation by the collation unit fails, the output unit to notifies the terminal device that sent the instruction of the failure of the collation. The mobile body authentication device according to Appended Claim 2 or 3. (Appended Claim 5) The matching unit executes matching between the time information and position information of the mobile body and the time information and position information preset as the operation plan for the mobile body related to the remote identification information. The mobile body authentication device according to any one of Appendices 1 to 4. (Appendix 6) The authentication information acquired by the acquisition unit is information in which information including the remote identification information, the position information, and the time information acquired by the acquisition unit is anonymized. The mobile body authentication device according to any one of Appendices 1 to 5. (Appendix 7) When the matching in the matching unit fails, the output unit transmits warning information to the mobile body that is the transmission source of the authentication information. The mobile body authentication device according to any one of Appendices 1 to 6. (Appendix 8) When the matching in the matching unit fails, the output unit transmits an instruction to stop using the remote identification information to the management device that manages the remote identification information. The mobile body authentication device according to any one of Appendices 1 to 7. (Appendix 9) The matching unit further matches the remote identification information acquired by the acquisition unit with the available remote identification information managed by the management device. The mobile body authentication device according to Appendix 8. (Appendix 10) The mobile body authentication system includes the mobile body authentication device according to Appendix 8 or 9 and a management device connected to the mobile body authentication device. The management device manages the remote identification information for each of a plurality of mobile bodies. When receiving an instruction to stop using the remote identification information from the mobile body authentication device, the management device makes the remote identification information for the mobile body to which the instruction applies unusable. Mobile body authentication system. (Appendix 11) A computer Obtain remote identification information, which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time on the mobile body, and authentication information from a mobile body capable of autonomous movement, Execute verification based on part or all of the obtained information, Output the result of the verification, Mobile body authentication method. (Appendix 12) Cause a computer to Obtain remote identification information, which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time on the mobile body, and authentication information from a mobile body capable of autonomous movement, Execute verification based on part or all of the obtained information, Output the result of the verification, Program for causing the execution of processing.
[0088] Although the present invention has been described with reference to the embodiments above, the present invention is not limited thereto. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the invention.
[0089] This application claims priority based on Japanese Patent Application No. 2021-062053 filed on March 31, 2021, and incorporates all of its disclosures herein.
Explanation of Reference Numerals
[0090] N1 Network P1 Operator P2 Administrator 1 Mobile body authentication device 1a Acquisition unit 1b Verification unit 1c Output unit 10 Mobile body authentication device 11 Control unit 12 Storage unit 13 Communication unit 20 Terminal device 30 Mobile body 32 Remote controller 40 Remote Identification Information Management System 41 Control Unit 42 Memory Unit 43 Communication Unit 44 Remote Identification Information 311 Communication Unit 312 Camera 313 Sensor Group 314 Control Unit 315 Drive Unit 320 Memory Unit 321 Remote Identification Information (Stored Inside the Mobile Body) 500 Computer 502 Bus 504 Processor 506 Memory 508 Storage Device 510 Input / Output I / F 512 Network I / F
Claims
1. A mobile body authentication device and a management device connected to the mobile body authentication device, wherein the mobile body authentication device, an acquisition means for acquiring remote identification information which is information for managing remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from a mobile body capable of autonomous movement; a collation means for performing collation based on part or all of the information acquired by the acquisition means; an instruction reception means for receiving an instruction to perform collation by the collation means; an output means for outputting the result of collation by the collation means; is provided with, when the instruction is received by the instruction reception means, acquisition by the acquisition means is executed, and collation is performed by the collation means between the time information of the mobile body and the time information indicating the current time at the mobile body authentication device; the management device manages the remote identification information for each of a plurality of mobile bodies; when the collation by the collation means fails, the output means transmits an instruction to stop using the remote identification information to the management device that manages the remote identification information; when receiving an instruction to stop using the remote identification information from the mobile body authentication device, the remote identification information for the mobile body to which the instruction applies is set to a state where it cannot be used; a mobile body authentication system.
2. A mobile body authentication device and a management device connected to the mobile body authentication device, wherein the mobile body authentication device, an acquisition means for acquiring remote identification information which is information for managing remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from a mobile body capable of autonomous movement; a collation means for performing collation based on part or all of the information acquired by the acquisition means; an instruction reception means for receiving an instruction to perform collation by the collation means; an output means for outputting the result of collation by the collation means; is provided with, when the instruction is received by the instruction reception means, acquisition by the acquisition means is executed, and collation is performed by the collation means between the position information of the mobile body and the position information indicating the current position of the mobile body authentication device; the management device manages the remote identification information for each of a plurality of mobile bodies; when the collation by the collation means fails, the output means transmits an instruction to stop using the remote identification information to the management device that manages the remote identification information; When receiving an instruction to stop using the remote identification information from the mobile body authentication device, the remote identification information about the mobile body related to the instruction is made unusable. Mobile body authentication system.
3. The instruction receiving means receives the instruction from a terminal device connected to the mobile body authentication device. When the verification by the verification means fails, the output means notifies the terminal device that sent the instruction to the instruction receiving means of the failure of the verification. The mobile body authentication system according to claim 1 or 2.
4. A mobile body authentication device and a management device connected to the mobile body authentication device are provided. The mobile body authentication device An acquisition means for acquiring remote identification information which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from an autonomously movable mobile body; A verification means for performing verification based on part or all of the information acquired by the acquisition means; An output means for outputting the result of the verification by the verification means; is provided with The verification means performs verification between the time information and position information at the mobile body and the time information and position information preset as the operation plan for the mobile body related to the remote identification information. The management device manages the remote identification information for each of a plurality of mobile bodies. When the verification by the verification means fails, the output means transmits an instruction to stop using the remote identification information to the management device that manages the remote identification information. When receiving an instruction to stop using the remote identification information from the mobile body authentication device, the remote identification information about the mobile body related to the instruction is made unusable. Mobile body authentication system.
5. The authentication information acquired by the acquisition means is information obtained by anonymizing information including the remote identification information, the position information, and the time information acquired by the acquisition means. The mobile body authentication system according to any one of claims 1 to 4.
6. When the verification by the verification means fails, the output means transmits warning information to the mobile body that is the transmission source of the authentication information. The mobile body authentication system according to any one of claims 1 to 5.
7. The mobile authentication device executes an acquisition process of acquiring remote identification information, which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from the mobile body capable of autonomous movement, executes a collation process based on part or all of the acquired information, and outputs the result of the collation in the collation process, and executes a first process. The management device connected to the mobile authentication device manages the remote identification information for each of a plurality of mobile bodies. When the collation fails, the mobile authentication device transmits an instruction to stop using the remote identification information to the management device that manages the remote identification information. When the management device receives an instruction to stop using the remote identification information from the mobile authentication device, it makes the remote identification information for the mobile body to which the instruction applies unusable. When receiving an instruction to execute the collation process, the first process executes the acquisition process, and as the collation process, executes at least one of a collation between the time information of the mobile body and the time information indicating the current time at the mobile authentication device, and a collation between the position information of the mobile body and the position information indicating the current position of the mobile authentication device. Mobile body authentication method.
8. The mobile authentication device acquires remote identification information, which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from the mobile body capable of autonomous movement, executes a collation process based on part or all of the acquired information, and outputs the result of the collation in the collation process. The management device connected to the mobile authentication device manages the remote identification information for each of a plurality of mobile bodies. When the collation fails, the mobile authentication device transmits an instruction to stop using the remote identification information to the management device that manages the remote identification information. When the management device receives an instruction to stop using the remote identification information from the mobile authentication device, it makes the remote identification information for the mobile body to which the instruction applies unusable. The collation process is a process of collating the time information and position information at the mobile body with the time information and position information preset as the operation plan for the mobile body related to the remote identification information. Mobile body authentication method.
9. On a computer Execute an acquisition process to obtain remote identification information, which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from the mobile autonomous mobile body. Execute a verification process based on part or all of the acquired information. Output the result of the verification in the verification process. When the verification fails, a process of sending an instruction to stop the use of the remote identification information to the management device that manages the remote identification information, so that the management device cannot use the remote identification information for the mobile body related to the instruction. When receiving an instruction to execute the verification process, execute the acquisition process, and as the verification process, execute at least one of the verification of the time information of the mobile body and the time information indicating the current time on the computer, and the verification of the position information of the mobile body and the position information indicating the current position of the computer. A program for executing a process.
10. On a computer, Obtain remote identification information, which is information for managing the remote operation of the mobile body, position information indicating the current position of the mobile body, time information indicating the current time at the mobile body, and authentication information from the mobile autonomous mobile body. Execute a verification process based on part or all of the acquired information. Output the result of the verification in the verification process. When the verification fails, a process of sending an instruction to stop the use of the remote identification information to the management device that manages the remote identification information, so that the management device cannot use the remote identification information for the mobile body related to the instruction. The verification process is a process of verifying the time information and position information at the mobile body and the time information and position information preset as the operation plan for the mobile body related to the remote identification information. A program for executing a process.
Citation Information
Patent Citations
Authentication messages between drones
JP2018511248A
Identification method and identification system for air vehicle
JP2019101828A
Method and system for determining level of authentication for operation of unmanned aerial vehicle (UAV)
JP2020144870A
Operation schedule creation device, remote operation server, and operation schedule creation method
WO2020031370A1
Vehicle traveling control method and vehicle traveling control device
WO2020121009A1