Management device and management system for storage device groups
The management device uses a two-dimensional code to authenticate and unlock multiple storage devices independently, addressing the challenge of managing items in environments with limited communication infrastructure, reducing costs and security risks while enabling flexible device arrangement.
Patent Information
- Application Number
- JP2025012973
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-01-29
- Publication Date
- 2025-08-04
- Estimated Expiration
- 2045-01-29
AI Technical Summary
Existing key management systems face challenges in efficiently managing multiple items without network communication, particularly in environments where communication infrastructure is limited or restricted, leading to high costs and security risks.
A management device that uses a two-dimensional code to authenticate and unlock multiple storage devices independently, without external network communication, by embedding authentication and identification information directly in the code, and utilizing a stand-alone configuration for local operation.
Enables efficient management of multiple items using a single authentication data, reducing costs and security risks, and allowing devices to be arranged flexibly without network dependence.
Smart Images

Figure 0007717415000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a management device and a management system for a group of storage devices.
Background Art
[0002] In rental conference rooms, rental warehouses, hotels, etc., a service is provided in which keys are provided to users according to their reservations, and locations or articles, etc. that are managed using locks corresponding to the keys can be used.
[0003] In such a service, in order to reduce the labor required for key delivery, there may be management in which existing locks are replaced with electric locks, and authentication information for unlocking the electric locks is transmitted to the user's terminal. However, if all existing locks are to be replaced with electric locks for such management, the labor, cost, etc. can be an excessive burden on the administrator.
[0004] In a method of storing keys corresponding to existing locks in a key box and locking the key box with an electric lock, the labor required for key delivery can be reduced without the burden of replacing all existing locks with electric locks.
[0005] Regarding such management, Patent Document 1 discloses a network key management system comprising a management server, a key management machine that manages keys connected to the management server via a network, a reception terminal, and a user terminal. The key management machine has a key management section that controls the lending of keys. The management server has a key management mechanism control section that controls at least the key management section of the key management machine, a user management section that manages information for identifying users and the email addresses of users, a reservation management section that manages the key reservation status, a status management section that manages the key lending status, and a mail control section that controls the sending and receiving of mails between the user terminal. The management server receives a reservation or change of reservation for a user's key use via the reception terminal or the user terminal connected via the network, registers it in the key reservation management section, and when a user borrows a key, the key management mechanism control section controls the key management section of the key management machine to perform lending control of the key for the user who has reserved the key use. When the key lending is completed, the status management section registers that the key lending is completed, and sends an email indicating that the key has been lent from the mail control section to the user who has borrowed the key. The technology of Patent Document 1 aims to rationalize key management operations and enables grasping key use reservations, key usage status, and confirmation of key use via a network or the like.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0007] By the way, due to various circumstances, it may be difficult for a device that controls a key box to communicate with a server that manages keys at an arbitrary timing. Examples of such circumstances include installation in places where the communication infrastructure is not yet developed (underground, remote areas, etc.), restrictions related to communication security, and the burden of battery consumption associated with long-term communication. In addition, a demand for managing multiple items can be considered, such as when lending multiple keys from a key box to a user.
[0008] The technology of Patent Document 1 is premised on the fact that when borrowing a key, the management server can control each key management device one by one via a network. Therefore, the technology of Patent Document 1 has room for further improvement in efficiently managing multiple items in a situation where communication is restricted.
[0009] The present invention has been made to solve the problems of the prior art as described above, and an object thereof is to provide a means for performing management of discriminating and lending a plurality of items managed by a group of storage devices by a single authentication data without requiring external network communication.
Means for Solving the Problems
[0010] As a result of intensive studies to solve the above problems, the present inventors have found that the above problems can be solved by directly embedding information corresponding to a plurality of storage devices in a two-dimensional code and adopting a stand-alone configuration that operates in a local environment and performs authentication and unlocking without communicating with an external cloud server or the like. And the present inventors have completed the present invention. Specifically, the present invention provides the following.
[0011] The invention according to the first feature includes a communication member configured to communicate with a plurality of storage devices, a reading member configured to read a two-dimensional code, and a control member configured to control the communication member and the reading member. The control member includes an acquisition unit that acquires authentication information and identification information of a target storage device among the plurality of storage devices from the two-dimensional code, a determination unit that determines whether an electric lock provided in the target storage device can be unlocked based on the two-dimensional code, and an unlocking unit that transmits unlocking command information to the electric lock determined to be unlockable. The acquisition unit is configured to acquire the identification information of each of the two or more target storage devices from a two-dimensional code in which the identification information of two or more target storage devices is stored. The determination unit performs the determination of whether unlocking is possible based on the authentication information and the identification information without using information obtained from an external server between the reading of the two-dimensional code and the determination. The unlocking unit transmits unlocking command information to the electric lock provided in at least one target storage device among the target storage devices, providing a management device for a group of storage devices.
[0012] According to the invention according to the first feature, the management device does not require network communication with an external server for both the determination of the unlocking target and the execution of unlocking, and can manage the lending of a plurality of articles to be lent by discriminating them using a single authentication data, i.e., the two-dimensional code read by the reading member, and unlocking the electric lock of the storage device storing the article and lending it to the user. That is, the management device of the invention has a technical advantage of not requiring network communication such as communication for cloud authentication, operates even in an environment where network connection is difficult, and realizes cost reduction and reduction of security risks.
[0013] Therefore, the invention according to the first feature can provide a means for managing the lending of a plurality of articles managed by a group of storage devices by discriminating them using a single authentication data without requiring external network communication.
[0014] The invention according to the second feature is the invention according to the first feature, wherein the acquisition unit is further configured to acquire time limit information indicating the time when unlocking is permitted, and the determination unit is configured to determine whether the electric lock provided in the storage device to be used can be unlocked based on the authentication information, the identification information, and the time limit information. A management device is provided.
[0015] According to the invention according to the second feature, by further acquiring time limit information from the two-dimensional code and using it for determining whether unlocking is possible, even in a usage mode where the time when unlocking is permitted is restricted, such as lending with reservation management, it is not necessary to have network communication with an external server. With a single authentication data, it is possible to identify a plurality of articles to be lent, unlock the electric lock of the storage device storing the articles, and perform management for lending to users.
[0016] Therefore, the invention according to the second feature can provide a means for managing lending by identifying a plurality of articles managed by a group of storage devices with a single authentication data without requiring external network communication.
[0017] The invention according to the third feature is the invention according to the first or second feature, wherein the management device further includes a storage member in which a public key is stored, and the acquisition unit is configured to acquire information from an encrypted two-dimensional code encrypted with a secret key corresponding to the public key using the public key. A management device is provided.
[0018] According to the invention according to the third feature, by storing a public key in the management device that cannot be used for generating a forged two-dimensional code even when it is no longer secret, and acquiring information from an encrypted two-dimensional code encrypted with a secret key using this public key, it is possible to prevent the generation and use of forged two-dimensional codes.
[0019] Therefore, the invention according to the third feature can provide a means for managing lending by identifying a plurality of articles managed by a group of storage devices with a single authentication data without requiring external network communication.
[0020] The invention according to the fourth feature is an invention according to any one of the first to third features, wherein the management device further includes a storage member in which usage status information indicating the usage status of each storage device is stored, and the determination unit determines, based on the usage status information, usable storage devices that can be used among the two or more target storage devices, and determines that the electric lock provided in the usable storage device can be unlocked, and provides a management device.
[0021] According to the invention according to the fourth feature, without requiring network communication, it is possible to perform management of discriminating and lending a plurality of articles that can be lent to a user according to the usage status stored in the management device itself using a single authentication data.
[0022] Therefore, the invention according to the fourth feature can provide a means for performing management of discriminating and lending a plurality of articles managed by a storage device group using a single authentication data without requiring external network communication.
[0023] The invention according to the fifth feature is an invention according to any one of the first to fourth features, and includes a plurality of storage devices arranged separately from each other and a management device according to any one of the first to fourth features, wherein the storage device restricts acquisition of the stored key from the outside and has an electric lock configured to communicate with the management device, and the communication member is configured to communicate with the electric lock of the storage device configured separately from the management device, and is a management system for a storage device group.
[0024] Management of lending a plurality of articles is performed by an integrated device of a management device and a plurality of storage devices, such as a lending locker or a delivery box. On the other hand, for example, there may be management of lending a locked space by providing a key near each of the lent spaces after authentication in a shared space, such as room rental in a lodging facility or individual box rental of a safe deposit box. Thus, there is a demand to arrange each storage device at a different position and make them available using a single two-dimensional code.
[0025] The invention according to the fifth feature realizes management that enables each storage device to be arranged at a different position and to be used with a single two-dimensional code by arranging a plurality of storage devices apart from each other. Thereby, the invention enables, for example, management of providing keys near each of the spaces to be lent out.
[0026] In the invention, a communication member configured to communicate with the electric lock of a storage device configured separately from the management device enables remote control of the electric lock that locks the door of each storage device, even though the plurality of storage devices are arranged apart from each other. Thereby, the invention realizes management that enables each storage device to be arranged at a different position and to be used with a single two-dimensional code. Further, the invention can provide different functions to each storage device through such management.
[0027] Therefore, the invention according to the fifth feature can provide a means for performing management of discriminating and lending a plurality of articles managed by a group of storage devices with a single authentication data without requiring external network communication.
Effect of the Invention
[0028] According to the present invention, a means for performing management of discriminating and lending a plurality of articles managed by a group of storage devices with a single authentication data without requiring external network communication can be provided.
Brief Description of the Drawings
[0029]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
DETAILED DESCRIPTION OF THE INVENTION
[0030] First of all, although the following disclosure, charts, and / or claims, etc. are described as being alone or in combination with one or more other aspects, the subject matter of the instant disclosure is not intended to be so limited. That is, the instant disclosure, charts, and claims are intended to include the various aspects described herein, either alone or in one or more combinations with each other. For example, even if the instant disclosure describes and illustrates a first embodiment, a second embodiment, and a third embodiment in such a way that the first embodiment is described and illustrated particularly in relation to the second embodiment, or the second embodiment is described and illustrated only in relation to the third embodiment, the instant disclosure and illustration are not so limited, and may include only the first embodiment, only the second embodiment, only the third embodiment, or one or more combinations of the first, second, and / or third embodiments, for example, the first embodiment and the second embodiment, the first embodiment and the third embodiment, the second embodiment and the third embodiment, or the first, second, and third embodiments.
[0031] Unless otherwise specified, the use of the phrase "or" in this document shall mean a "non-exclusive" arrangement. For example, in the case of "Item x is A or B", it shall mean either of the following: (1) Item x is only one of A or B, (2) Item x is both A and B. In other words, the word "or" is not used to define an "exclusive" arrangement.
[0032] In addition, when the phrases "including at least one" or "including at least one of the following" used in this document are used in combination with a system or element, it shall mean that the system or element includes one or more of the elements listed after the phrase. For example, when there are three types of elements from the first element to the third element, the phrases "including at least one" or "including at least one of the following" shall be interpreted as any of the following structural arrangements: a device including the first element, a device including the second element, a device including the third element, a device including the first and second elements, a device including the first and third elements, a device including the second and third elements, or a device including the first, second, and third elements.
[0033] The same interpretation is intended when the phrase "used in at least one of the following" is used in this document. Furthermore, "and / or" used in this document is used as a linguistic conjunction and is used to indicate that one or more of the described elements or conditions are included or occur. For example, a device including the first element, the second element, and / or the third element shall be interpreted as any of the following structural arrangements: a device including the first element, a device including the second element, a device including the third element, a device including the first and second elements, a device including the first and third elements, a device including the second and third elements, or a device including the first, second, and third elements.
[0034] Note that the use of the phrase "and / or" in this document meaning a "non-exclusive" arrangement is also stipulated in the "Format and Preparation Method of Standard Sheets JIS Z 8301" of the Japanese Industrial Standards (JIS).
[0035] Hereinafter, an example of an embodiment of the present invention will be described in detail with reference to the drawings.
[0036] <Management System S> FIG. 1 is a schematic diagram showing an example of a management system S according to an embodiment of the present invention. FIG. 2 is a block diagram showing an example of the hardware configuration and software configuration of the management system S. Hereinafter, a preferred embodiment of the management system S according to the present embodiment will be described with reference to FIGS. 1 and 2.
[0037] The management system S includes a server 1 that issues a two-dimensional code B and a management device 2 that manages a plurality of storage devices 3 by authentication using the two-dimensional code B. The management system S is also simply referred to as "system S". The system S preferably further includes a user terminal T that communicates with the server 1 via a network N. In the system S, the server 1 and the management device 2 can communicate with each other via the network N.
[0038] 〔Server 1〕 The server 1 includes a server control unit 11, a server storage unit 13, and a server communication unit 14. The type is not particularly limited, and for example, a single server device, a cloud server realized by the cooperation of a plurality of server devices, etc. may be used.
[0039] The server 1 executes processing related to the reservation of the storage device 3. The processing includes, for example, processing for managing reservation information, processing for issuing the two-dimensional code B based on the reservation information, processing for data-linking the reservation information and / or the usage status with the management device 2, and the like.
[0040] [Server Control Unit 11] The server control unit 11 includes a Central Processing Unit (CPU), a Random Access Memory (RAM), a Read Only Memory (ROM), and the like.
[0041] The server control unit 11 cooperates with at least one of the server storage unit 13 and the server communication unit 14 as necessary. And the server control unit 11 realizes a reservation management unit 111, an issuance unit 112, a cooperation unit 113, etc., which are software components of the program executed on the server 1 of the present embodiment.
[0042] Details of the above software components will be described later in the description of the reservation process using FIGS. 5 to 7.
[0043] [Server storage unit 13] The server storage unit 13 is a device in which data and / or files are stored, and has a storage unit that non-temporarily stores data by means of a hard disk, a semiconductor memory, a recording medium, a memory card, etc.
[0044] The server storage unit 13 stores data such as the program for the server 1 of the present embodiment executed by a microcomputer, a reservation table 131, and a secret key used for encrypting the two-dimensional code B. Details of the reservation process executed by this program will be described later with reference to FIGS. 5 to 7.
[0045] (Reservation table 131) The reservation table 131 stores reservation information related to the storage device 3. The reservation information includes at least the identification information (storage device ID) of the target storage device to be used based on the reservation among a plurality of storage devices 3 related to the system S. When reservations are made for two or more storage devices 3, it is preferable that the reservation information includes the identification information of two or more target storage devices. Thereby, the server 1 can issue a two-dimensional code including the identification information of two or more target storage devices.
[0046] When the reservation information includes the identification information of two or more target storage devices to be used, it is preferable that the identification information is associated with the priority order of the target storage devices to be used. Thereby, the server 1 can issue a two-dimensional code further including the priority order of the target storage devices to be used. Such a two-dimensional code contributes to the management device 2 performing such management without requiring network communication in the lending management based on the priority order of articles.
[0047] The reservation information preferably further includes the identification information (management device ID) of the management device 2 that manages the storage device 3. Thereby, the server 1 can issue a two-dimensional code further including the identification information of the management device 2, and can reduce the processing load of the management device 2 related to determining whether the read two-dimensional code relates to the management device 2.
[0048] In order to enable management according to time zones such as limiting the use of the storage device 3 during business hours, the reservation information preferably further includes time limit information related to the use of the storage device 3. Thereby, the server 1 can issue a two-dimensional code further including the time limit information. In order to perform management of the storage device 3 according to the reserved time zone, the time limit information preferably includes reserved time zone information.
[0049] In order to assist in the management of the reservation information in the server 1, it is preferable that the reservation information is stored in association with information (for example, reservation ID) for identifying the reservation information.
[0050] FIG. 3 is an example of the reservation table 131. In this example, first reservation information identified by the reservation ID "R0001", second reservation information identified by the reservation ID "R0002", etc. are stored.
[0051] The first reservation information is information regarding reserving the first storage device identified by the storage device ID "S0001" and the second storage device identified by the storage device ID "S0002" in a time zone corresponding to the time limit information "from January △, △△:00, 2025 to February △, △△:00, 2025". Thereby, the server 1 can manage such a reservation and issue a two-dimensional code including this information.
[0052] On the other hand, the second reservation information is information regarding reserving the third storage device identified by the storage device ID "S0003" and the fourth storage device identified by the storage device ID "S0004" in a time zone corresponding to the time limit information "from January △, △△:00, 2025 to February △, △△:00, 2025". The second reservation information includes the management device ID "C0001" that identifies the first management device that manages the third storage device and the fourth storage device.
[0053] Thereby, the server 1 can enable the management device 2 to quickly determine the necessity of the process related to the second reservation information, and further issue a two-dimensional code that can manage the storage device 3 according to the priority.
[0054] (Private key) It is preferable that a private key of a public-key cryptosystem is stored in the server storage unit 13. The private key is not particularly limited, and for example, a private key of a public-key cryptosystem based on prime factorization (Rivest-Shamir-Adleman (RSA) cryptosystem, Paillier cryptosystem, Rabin cryptosystem, etc.), a public-key cryptosystem based on discrete logarithm (Cramer-Shoup cryptosystem, ElGamal cryptosystem, etc.), a public-key cryptosystem based on lattice cryptography (NTRU cryptosystem, etc.), a public-key cryptosystem based on probabilistic cryptography (McEliece cryptosystem, Efficient Probabilistic Public Key Encryption (EPOC), etc.), or a private key of other public-key cryptosystems may be used.
[0055] By storing the private key of the public-key cryptosystem in the server storage unit 13, the server 1 can issue an encrypted two-dimensional code obtained by encrypting time limit information indicating the time when unlocking is permitted, etc., with this private key. Thereby, even when the public key is not secret, the management system S can prevent the generation of forged two-dimensional codes with encrypted two-dimensional codes that are difficult to forge.
[0056] [Server communication unit 14] The server communication unit 14 is not particularly limited as long as it enables the server 1 to be connected to the network N and communicate. Examples of the server communication unit 14 include a network card compatible with the Ethernet standard, communication devices compatible with wireless LAN, etc.
[0057] [Management device 2] The management device 2 includes a control member 21, a storage member 23, a communication member 24, a reading member 25, an input member 26, and a power supply member 27. The management device 2 manages a plurality of storage devices 3 based on the reservation information obtained from the two-dimensional code B.
[0058] The management device 2 executes processes related to the management of the storage device 3 using the two-dimensional code B. The processes include, for example, a process of obtaining reservation information, etc., from the two-dimensional code B, a process of determining the permissibility of unlocking based on the reservation information, etc., a process of transmitting unlocking command information based on this determination, a process of synchronizing data with the server 1, etc.
[0059] [Control member 21] The control member 21 includes a CPU (Central Processing Unit), a RAM (Random Access Memory), a ROM (Read Only Memory), etc.
[0060] The control member 21 cooperates with at least one of the members of the management device 2 exemplified by the storage member 23, the communication member 24, etc., as necessary. And the control member 21 realizes software components such as an acquisition unit 211, a determination unit 212, an unlocking unit 213, a synchronization unit 214, etc., which are software components of the program executed by the management device 2 of the present embodiment.
[0061] Details of the above software components will be described later in the description of the management process using FIGS. 8 to 11.
[0062] [Storage member 23] The storage member 23 is a device in which data and / or files are stored, and has a storage unit that non-temporarily stores data by a semiconductor memory, a memory card, etc.
[0063] Stored in the storage member 23 are a program executed by a microcomputer, a usage information table 231, a public key, etc. Also, reservation information may be stored in the storage member 23. By storing the reservation information, the management device 2 can manage the storage device 3 based on the reservation information exceeding the data amount of the two-dimensional code B while suppressing the data amount stored in the two-dimensional code B.
[0064] (Usage information table 231) Stored in the usage information table 231 is usage information indicating the usage status of each storage device 3. Thereby, the management device 2 can manage the storage device 3 according to the usage status. Also, thereby, the management device 2 can provide the usage information to the server 1. Based on the provided usage information, the server 1 can perform reservation management according to the usage status.
[0065] The usage status information includes at least the identification information of the storage device 3 (such as storage device ID, etc.) and usage information indicating whether the article stored in the storage device 3 corresponding to the identification information is in use. The usage information may include a part of the time limit information used for unlocking the storage device 3. For example, by including in the usage information the time when a reservation or the like ends among the time limit information, the management device 2 can estimate the time when the article related to the storage device 3 can be used, etc.
[0066] In order to assist in the management of the usage status information in the management device 2, it is preferable that the usage status information be stored in association with information for identifying the usage status information (for example, usage status ID).
[0067] FIG. 4 is an example of the usage status information table 231. In this example, first usage status information identified by the usage status ID "U0001", second usage status information identified by the usage status ID "U0002", etc. are stored.
[0068] The first usage status information includes the storage device ID "S0001" indicating the first storage device and usage information indicating "in use". Thereby, when a two-dimensional code including the first storage device and other storage devices 3 is used, the management device 2 can perform control to unlock a storage device 3 different from the first storage device.
[0069] The second usage status information includes the storage device ID "S0002" indicating the second storage device and usage information indicating "in use" until "January △△, △△:△△, 2025". Thereby, when a two-dimensional code including the first storage device and other storage devices 3 is used, the management device 2 can perform control to unlock a storage device 3 different from the second storage device and a process indicating an estimate of the time when the second storage device can be used.
[0070] (Public key) When a private key of a public-key cryptosystem is stored in the server storage unit 13, it is preferable that a public key of the public-key cryptosystem, which is paired with the private key, be stored in the storage member 23. The encryption key system of the public key is the same as that of the private key.
[0071] When using the two-dimensional code B as a key, there is a concern that the information embedded in the two-dimensional code B may be analyzed and misused for generating an illegal key. If an encrypted two-dimensional code is used as a key instead of the two-dimensional code B in which the information is embedded in plain text, such misuse can be prevented. However, in the process of decrypting the encrypted two-dimensional code by the external server 1, network communication is required. In addition, in such a process, information leakage due to communication interception is also a concern.
[0072] With the configuration in which the public key of the public-key cryptosystem is stored in the storage member 23, the acquisition unit 211 can acquire information from the encrypted two-dimensional code encrypted with the private key by using the public key stored in the storage member 23. Thereby, the management device 2 can perform management for discriminating and lending a plurality of articles that can be lent to the user by using a single encrypted two-dimensional code without requiring network communication.
[0073] In this configuration, due to the characteristic of the public-key cryptosystem that it is difficult to specify the private key from the public key, even if the public key is stolen from the management device 2, the generation of a forged two-dimensional code is prevented. In addition, the management device 2 can acquire time limit information related to the use by the user from the encrypted two-dimensional code and perform management in accordance with the time limit without worrying about forgery.
[0074] [Communication member 24] The communication member 24 is not particularly limited as long as it can communicate with the electric lock 33 of the storage device 3. The communication member 24 is configured to be able to control the electric lock 33, for example, by communication via short-range wireless communication, wired communication, or the like. Communication via short-range wireless communication is, for example, wireless communication compliant with Bluetooth (registered trademark), Bluetooth LE, ZigBee (registered trademark), or the like. Wired communication is, for example, communication for transmitting an unlocking signal at an electrical contact, serial communication, or the like.
[0075] The communication member 24 is preferably configured to communicate with the electric lock 33 of the storage device 3 configured separately from the management device 2. Thereby, when the management device 2 manages a plurality of storage devices 3 arranged separately from each other, the management device 2 can remotely control the electric lock 33 that locks the door 32 of each storage device 3.
[0076] In particular, the communication member 24 is preferably configured to communicate with the electric lock 33 of the storage device 3 by communication via short-range wireless communication. Communication via short-range wireless communication increases the degree of freedom in arranging the management device 2 and the storage device 3. Thereby, the management device 2 arranges each storage device 3 at different positions, such as management of providing keys near each of the lent spaces and management of lending at different locations according to the type of article, and enables them to be used with a single two-dimensional code. Management can be realized in a more diverse arrangement situation. In order to reduce the power consumption in the management device 2 and the storage device 3, the communication via short-range wireless communication is particularly preferably Bluetooth LE.
[0077] [Reading member 25] The reading member 25 is not particularly limited as long as it is a member that reads the two-dimensional code B, and includes various two-dimensional code reading members of the prior art.
[0078] (Detection means) Although not an essential aspect, the reading member 25 preferably includes a detection means for detecting whether a user presenting the two-dimensional code B is in the vicinity. Thereby, when the detection target is not detected, the management device 2 can put the reading member 25 into a sleep state and reduce the power consumption.
[0079] The detection means is not particularly limited, and may be a detection unit including an appropriate sensor exemplified by, for example, a moving object identification sensor capable of detecting a moving object around the reading member 25, a human presence sensor capable of detecting a person around the reading member 25, or the like.
[0080] The detection means preferably includes a moving object identification sensor among others. Thereby, the detection means can both detect the movement of presenting the two-dimensional code B toward the reading member 25 and enable the reading member 25 to read the two-dimensional code B when necessary, and can reduce the power consumption by setting it to the sleep state when not detected for a certain period of time.
[0081] [Input member 26] The input member 26 is a member used for inputting a code that plays the same role as the two-dimensional code B. The input member 26 includes, for example, numeric keys. Thereby, even when the management device 2 cannot perform external network communication and the mobile terminal cannot display the two-dimensional code B, the management device 2 can obtain the code related to the use of the storage device 3 from the user.
[0082] [Power supply member 27] The power supply member 27 supplies power to the management device 2. The power supply member 27 preferably includes a member that supplies power smaller than the power that can be supplied by a commercial power supply. Examples of such a member include various batteries, an AC adapter, a USB power supply member, a solar cell, etc. Thereby, the management device 2 can manage the storage device 3 even in a place where the power supply is limited.
[0083] The power supply member 27 preferably includes a power supply unit that can supply power using a battery among others. Thereby, the administrator who manages the management device 2 can maintain the power supply member 27 by relatively simple management of replacing the battery.
[0084] [Storage device 3] The storage device 3 is a device for storing articles, and includes at least a main body portion 31 and an electric lock 33. The storage device 3 is preferably a small device (lock box) for storing the key K described later. At this time, in order to realize a flexible arrangement of arranging the small storage device 3 in a gap space or the like and a reduction in the introduction cost due to miniaturization, the system S is preferably configured to include a plurality of storage devices 3 arranged apart from each other.
[0085] [Main body portion 31] The main body 31 is configured to store articles. The main body 31 is configured as, for example, a box-shaped body provided with a door 32. In order to make the stored articles easily visible, the main body 31 may store the articles in a state where they are visible from the outside.
[0086] [Door 32] In order to store articles more securely, it is preferable that the storage device 3 includes a door 32 that cooperates with an electric lock 33 to restrict access to the stored articles from the outside.
[0087] [Electric lock 33] The electric lock 33 is a lock that restricts access to the stored articles from the outside in the locked state and enables the stored articles to be accessed from the outside in the unlocked state. The electric lock 33 is configured to communicate with the management device 2 by means of the above-mentioned short-range wireless communication or the like.
[0088] The electric lock 33 transitions to the unlocked state when it receives unlocking command information from the management device 2. The electric lock 33 transitions to the locked state when it receives locking command information from the management device 2. In order to prevent unauthorized operations, it is preferable that the unlocking command information and the locking command information include information that guarantees that they are legitimate commands.
[0089] [Two-dimensional code B] The two-dimensional code B includes various information exemplified by authentication information related to unlocking the storage device 3, identification information of the target storage device among a plurality of storage devices 3, etc. in an encoded form. The format of the two-dimensional code B is not particularly limited, and may be, for example, a QR code (registered trademark) or the like. For stable reading, it is preferable that the QR code (registered trademark) complies with standard specifications such as JIS X 0510 and ISO / IEC 18004.
[0090] The authentication information is not particularly limited as long as it can ensure that the two-dimensional code B is a legitimate code. Examples of the authentication information include specific data indicating that it is a legitimate code, a one-time key that changes according to time, etc., and data encrypted with a secret key that is configured to be specific data when decrypted with a public key.
[0091] The two-dimensional code B stores the identification information of the target storage device among the multiple storage devices 3. The two-dimensional code B is preferably configured to be able to store the identification information of each of the multiple target storage devices. Thereby, even when there are two or more target storage devices and network communication cannot be performed, the discrimination unit 212 can perform accurate discrimination with a single key.
[0092] When the management system S includes a plurality of management devices 2, the two-dimensional code B preferably stores the identification information of the target management device that manages the target storage device among the plurality of management devices 2. Thereby, the management device 2 that reads the two-dimensional code B can determine whether to continue the process by a simple process based on the identification information without going through the procedure of acquiring and discriminating the identification information of each target storage device.
[0093] In order to enable management according to time zones such as limiting the use of the storage device 3 during business hours, the two-dimensional code B preferably further includes time limit information related to the use of the storage device 3. In order to manage the storage device 3 according to the reserved time zone, the time limit information preferably includes reserved time zone information.
[0094] 〔Key K〕 The storage device 3 is preferably a lock box that stores the key K as an item. At this time, the electric lock 33 is preferably a lock that restricts the acquisition of the stored key K from the outside in the locked state and enables the stored key K to be acquired from the outside in the unlocked state. The lock box is also referred to as a key box, a key storage box, etc. The key K is not particularly limited as long as it is an item for unlocking the lock. Examples of the key K include a key for a cylinder lock, a key for a dimple lock, a key using a magnetic card, a key using an IC card, a key using RFID, and the like.
[0095] In order to manage the electric lock according to the reserved time zone, there is a desire to replace the mechanical lock with a smart lock that reads the two-dimensional code as authentication information. However, when there are many mechanical locks, it takes a high introduction cost and labor to replace all of them with such smart locks.
[0096] Since the storage device 3 is a lock box that stores the key K, the management system S of the present embodiment can perform advanced processing of reading the two-dimensional code and managing the items stored in the storage device 3 according to the read reservation information, etc., while suppressing the number of management devices 2 that perform such processing, and can perform detailed management according to the reserved time zone for each key K or group of keys K corresponding to the mechanical lock. Thereby, the management system S can reduce both the introduction cost and the operation burden at the same time.
[0097] 〔User terminal T〕 The user terminal T is, for example, a mobile terminal exemplified by a smartphone and a tablet terminal, or various computers exemplified by a personal computer and a notebook computer.
[0098] By executing a predetermined program, the user terminal T performs processing for making a reservation at the server 1, processing for acquiring the two-dimensional code B corresponding to the reservation from the server 1, processing for displaying the two-dimensional code B on a display or the like, processing for printing the two-dimensional code B by a printing device, and the like.
[0099] 〔Network N〕 The type of the network N is not particularly limited as long as it enables communication between the server 1 and the user terminal T. Examples of the network N include a personal area network, a local area network, an intranet, an extranet, the Internet, a Wi-Fi network, a mobile phone network, or a network combining a plurality of these networks.
[0100] When causing the management device 2 to perform online management processing, the network N preferably includes a network that enables communication between the server 1 and the management device 2. Thereby, the management device 2 can perform processing such as acquiring reservation information from the server 1 and providing usage status to the server 1.
[0101] In order to eliminate the need for wiring work related to the communication of the management device 2 and to realize flexible and easy installation of the management device 2, the network that enables communication between the server 1 and the management device 2 preferably includes a wireless network exemplified by a mobile phone network, Wi-Fi (Wireless Fidelity) compliant with IEEE802.11, etc.
[0102] [Flowchart of reservation processing executed by server 1] FIG. 5 is a flowchart showing an example of a preferred flow of reservation processing executed by the server 1. FIG. 6 is a figure following the previous figure. FIG. 7 is a figure following the previous figure. The following is an explanation of an example of a preferred flow of reservation processing executed by the server 1 using FIGS. 5 to 7.
[0103] The reservation processing includes a series of processes for storing reservation information. Steps S101 to S105 are an example of such processing.
[0104] [Step S101: Determine whether a reservation is requested] The server control unit 11 executes a reservation management unit 111 in cooperation with the server storage unit 13 and the server communication unit 14. Then, the server control unit 11 executes a process of determining whether a reservation is requested by the reservation management unit 111 (reservation determination step). If the server control unit 11 determines that a reservation is requested, it transfers the process to step S102; otherwise, it transfers the process to step S106.
[0105] In this step, the reservation management unit 111 makes the above determination by, for example, a procedure of determining that a reservation is requested when receiving data for requesting a reservation from the user terminal T. The data includes, for example, identification information of the storage device 3 related to the reservation, time limit information indicating the time when unlocking is permitted, and the like.
[0106] [Step S102: Determine Whether Reservation Is Possible] The server control unit 11 executes a process of determining whether the reservation requested in the reservation determination step is possible by the reservation management unit 111 (reservation possibility determination step). If the server control unit 11 determines that it is possible, it transfers the process to step S103; otherwise, it transfers the process to step S105.
[0107] In the reservation possibility determination step, the reservation management unit 111 makes the above determination by, for example, referring to the reservation table 131 and a procedure of determining that a reservation is possible when reservation information corresponding to the combination of the storage device 3 related to the identification information and the time zone related to the time limit information is not stored.
[0108] [Step S103: Identify the Storage Device to Be Reserved] The server control unit 11 executes a process of identifying the storage device 3 to be reserved for the reservation requested in the reservation determination step by the reservation management unit 111 (storage device identification step). The server control unit 11 transfers the process to step S104.
[0109] In this step, the reservation management unit 111 performs the above identification by, for example, referring to the reservation table 131 and identifying the storage device 3 to be reserved from among the storage devices 3 in which reservation information corresponding to the time zone related to the time limit information is not stored, through procedures such as this.
[0110] [Step S104: Store reservation information] The server control unit 11 executes a process of storing the reservation information related to the reservation obtained in the reservation determination step in the reservation table 131 by the reservation management unit 111 (reservation information storage step). The server control unit 11 moves the process to step S106.
[0111] The following step S105 is a step executed when it is not determined that reservation is possible in the reservation availability determination step.
[0112] [Step S105: Notify that reservation is not possible] The server control unit 11 executes a process of notifying the user terminal T or the like that reservation is not possible by the reservation management unit 111 (reservation impossible notification step). The server control unit 11 returns the process to step S101.
[0113] The reservation process includes a series of processes for issuing the two-dimensional code B in which the reservation information is stored. Steps S106 to S110 are an example of such a process.
[0114] [Step S106: Determine whether to issue a two-dimensional code] The server control unit 11 cooperates with the server storage unit 13 and the server communication unit 14 to execute the issuing unit 112. Then, the server control unit 11 executes a process of determining whether to issue the two-dimensional code B by the issuing unit 112 (issuing determination step). If the server control unit 11 determines to issue, it moves the process to step S107, and if not, it moves the process to step S111.
[0115] In this step, the issuing unit 112 determines the above determination by, for example, a procedure of determining to issue the two-dimensional code B when receiving data requesting the issue of the two-dimensional code B from the user terminal T, a procedure of determining to issue the two-dimensional code B when reservation information is stored in the reservation information storage step, and the like.
[0116] [Step S107: Specify identification information of the target storage device for use] The server control unit 11 executes, by the issuing unit 112, a process of specifying the identification information of the target storage device for use related to the two-dimensional code B to be issued (first specification step). The server control unit 11 moves the process to step S108.
[0117] In the first specification step, the issuing unit 112 specifies the identification information of the target storage device for use by, for example, referring to the reservation table 131 and a procedure of specifying the identification information based on the target storage device for use indicated in the reservation information related to the two-dimensional code B to be issued.
[0118] The series of processes for issuing the two-dimensional code preferably includes a procedure of encrypting the information stored in the two-dimensional code B with the private key of the public key cryptosystem. Step S108 is an example of this procedure.
[0119] [Step S108: Encrypt information with the private key] The server control unit 11 executes, by the issuing unit 112, a process of encrypting the information stored in the two-dimensional code B with the private key of the public key cryptosystem (encryption step). The server control unit 11 moves the process to step S109.
[0120] [Step S109: Generate image data of the two-dimensional code] The server control unit 11 executes, by the issuing unit 112, a process of encoding the information stored in the two-dimensional code B to generate image data of the two-dimensional code B (imaging step). The server control unit 11 moves the process to step S110.
[0121] [Step S110: Issue the two-dimensional code] The server control unit 11 executes a process of issuing the two-dimensional code B by the issuing unit 112 (two-dimensional code issuing step). The server control unit 11 moves the process to step S111.
[0122] In the two-dimensional code issuing step, the issuing unit 112 issues a two-dimensional code B including at least the identification information of the target storage device among the plurality of storage devices 3 managed by the system S. The issuing unit 112 issues the two-dimensional code B, for example, by a process of transmitting the above-described image data to the user terminal T.
[0123] The reservation process preferably includes a series of processes for performing data link related to the management device 2 and the reservation information. Thereby, the server 1 can synchronize the reservation information stored in the management device 2 with the reservation information of the server 1 at a predetermined data link timing, so that the management device 2 can manage the storage device 3 based on the reservation information. Steps S111 to S112 are an example of the process.
[0124] When the reservation process includes a series of processes for performing data link related to the management device 2 and the reservation information, the two-dimensional code B may include identification information for identifying the reservation information stored in the management device 2 as reservation information.
[0125] [Step S111: Determine whether to send reservation information] The server control unit 11 cooperates with the server storage unit 13 and the server communication unit 14 to execute the cooperation unit 113. Then, the server control unit 11 executes a process of determining whether to send reservation information by the cooperation unit 113 (reservation information link determination step). If the server control unit 11 determines to send, it moves the process to step S112, and if not, it moves the process to step S113.
[0126] In the reservation information link determination step, the cooperation unit 113 realizes the above determination by, for example, a procedure of determining to send reservation information when the current time corresponds to a predetermined data link timing (for example, outside business hours).
[0127] [Step S112: Transmit reservation information] The server control unit 11 executes, via the cooperation unit 113, a process of transmitting reservation information to the management device 2 (reservation information cooperation execution step). The server control unit 11 moves the process to step S113.
[0128] The reservation process preferably includes a series of processes for performing data cooperation related to the usage status with the management device 2. Thereby, the server 1 can synchronize the usage status of the server 1 with the usage status stored in the management device 2 at a predetermined data cooperation timing, and can manage reservations based on the usage status. Steps S113 to S114 are an example of the process.
[0129] [Step S113: Determine whether to obtain usage status] The server control unit 11 executes, via the cooperation unit 113, a process of determining whether to obtain the usage status from the management device 2 (usage status cooperation determination step). If the server control unit 11 determines to transmit, it moves the process to step S114. If not, it returns the process to step S101 and repeats the processes from step S101 to step S114.
[0130] In the usage status cooperation determination step, the cooperation unit 113 realizes the above determination by, for example, a procedure of determining to obtain the usage status when the current time corresponds to a predetermined data cooperation timing (for example, outside business hours), a procedure of determining to obtain the usage status when the usage status transmitted from the management device 2 is received, and the like.
[0131] [Step S114: Obtain usage status] The server control unit 11 executes, via the cooperation unit 113, a process of obtaining the usage status from the management device 2 (usage status cooperation execution step). The server control unit 11 returns the process to step S101 and repeats the processes from step S101 to step S114.
[0132] [Effect of reservation process] By executing the above-described reservation process in accordance with the program stored in server 1 of the present embodiment, server 1 reserves a target storage device among a plurality of storage devices 3 (from step S101 to step S105), and can issue a two-dimensional code B in which its identification information is stored (from step S106 to step S110).
[0133] In the reservation process, server 1 can issue not only two-dimensional code B including the identification information of one target storage device, but also two-dimensional code B including the identification information of two or more target storage devices.
[0134] Thereby, after the management device 2 reads the two-dimensional code B, server 1, which is external to the management device 2, can determine whether or not to unlock based on the authentication information and the identification information of the target storage device obtained from the read two-dimensional code B itself, regardless of the number of target storage devices, based on the two-dimensional code B which is a single key.
[0135] By the way, when using a two-dimensional code as a key, there is a concern that the information embedded in the two-dimensional code will be analyzed and misused for generating an illegal key. If an encrypted two-dimensional code is used as a key instead of a two-dimensional code with information embedded in plain text, such misuse can be prevented. However, in the process of decrypting an encrypted two-dimensional code on an external server, network communication is required. In addition, in such a process, information leakage due to communication eavesdropping is also a concern.
[0136] Server 1 can issue a two-dimensional code B in which reservation information and the like are encrypted with a private key of the public-key cryptosystem (step S108). Thereby, the management device 2 can manage the discrimination and lending of a plurality of articles that can be lent to users using a single encrypted two-dimensional code B without requiring network communication.
[0137] In addition, since encryption is performed using the private key of the public-key cryptosystem, even if the public key stored in the management device 2 is stolen, generation of an illegal two-dimensional code B can be prevented. This is because the public key is a different key from the private key and it is difficult to predict the private key from the public key, so the public key cannot be used to generate an illegal two-dimensional code B.
[0138] In addition, the server 1 can perform data linking regarding reservation information with the management device 2 (from step S111 to step S112). Thereby, the server 1 synchronizes the reservation information stored in the management device 2 with the reservation information of the server 1 at a predetermined data linking timing, so that the management device 2 can manage the storage device 3 based on the reservation information.
[0139] Also, the server 1 can perform data linking regarding the usage status with the management device 2 (from step S113 to step S114). Thereby, the server 1 synchronizes the usage status of the server 1 with the usage status stored in the management device 2 at a predetermined data linking timing, so that reservation management based on the usage status can be performed.
[0140] As described above, the above-described reservation process and the program for executing the process contribute to providing a means for discriminating and lending a plurality of articles managed by the storage device 3 group with a single authentication data without requiring external network communication during the unlocking permission discrimination process by cooperating with the management device 2.
[0141] 〔Main flowchart of management process executed by management device 2〕 FIG. 8 is a main flowchart showing an example of a preferable flow of the management process executed by the management device 2. FIG. 9 is a figure following the previous figure. FIG. 10 is a figure following the previous figure. FIG. 11 is a figure following the previous figure. The following is an explanation of an example of a preferable flow of the management process executed by the management device 2 using FIGS. 8 to 11.
[0142] The management process includes a series of processes for obtaining information such as reservation information from the two-dimensional code. Steps S201 to S203 are an example of this process.
[0143] [Step S201: Determine whether to read the two-dimensional code] The control member 21 cooperates with the storage member 23, the reading member 25, etc., and executes the acquisition unit 211. Then, the control member 21 executes a process of determining whether to read the two-dimensional code B by the acquisition unit 211 (reading determination step). If the control member 21 determines to read, the process proceeds to step S202; if not, the process proceeds to step S204.
[0144] In the reading determination step, the acquisition unit 211 realizes the above determination by, for example, a procedure of determining to read when the two-dimensional code B is detected by a detection function provided in the reading member 25, a procedure of determining to read when a reading command is given via the input member 26, etc.
[0145] [Step S202: Read the two-dimensional code] The control member 21 executes a process of reading the two-dimensional code B by the acquisition unit 211 (reading execution step). The control member 21 proceeds the process to step S203.
[0146] [Step S203: Obtain information from the two-dimensional code] The control member 21 executes a process of obtaining information from the two-dimensional code B read in the reading execution step by the acquisition unit 211 (information acquisition step). The control member 21 proceeds the process to step S204. In the information acquisition step, the acquisition unit 211 obtains at least the identification information of the target storage device to be used among the plurality of storage devices 3 from the two-dimensional code B. It is preferable that the acquisition unit 211 further obtains authentication information.
[0147] In the information acquisition step, the acquisition unit 211 acquires the identification information of each of the two or more target storage devices from the two-dimensional codes storing the identification information of the two or more target storage devices. This allows the determination unit 212 to perform accurate determination using a single key even when there are two or more target storage devices and network communication is not possible.
[0148] If the two-dimensional code B includes time limit information indicating the time during which unlocking is permitted, the acquisition unit 211 further acquires the time limit information in the information acquisition step. As a result, even in a usage mode in which the time during which unlocking is permitted is limited, such as in rentals involving reservation management, the management device 2 can identify multiple items to be lent out using a single authentication data, unlock the electric lock 33 of the storage device 3 that stores the items, and manage the rental of the items to the user, without requiring network communication with the external server 1.
[0149] If the authentication information is in an encrypted form, in the information acquisition step, the acquisition unit 211 uses the public key stored in the memory member 23 to acquire information from the encrypted two-dimensional code encrypted with the private key corresponding to the public key.
[0150] As mentioned above, there is a concern that plaintext two-dimensional code B could be misused to generate an illegal key. To prevent this, if an external server were to be used to decrypt the encrypted two-dimensional code, network communication would be required, and there would also be concerns about information leakage due to wiretapping.
[0151] The management device 2 prevents the above-mentioned misuse without network communication by using a procedure to obtain information from the encrypted two-dimensional code using a public key.The management device 2 can then use a single encrypted two-dimensional code to identify and manage the multiple items that can be loaned to a user without requiring network communication.
[0152] The management process includes a series of processes related to the lending of items, and steps S204 to S209 are an example of such processes.
[0153] [Step S204: Determine Whether It Corresponds to Lending] The control member 21 cooperates with the storage member 23 and the like to execute the discrimination unit 212. Then, the control member 21 executes a process of determining whether the operation desired by the user corresponds to lending by the discrimination unit 212 (lending discrimination step). If the control member 21 determines that it corresponds, the process proceeds to step S205; if not, the process proceeds to step S210.
[0154] In the lending discrimination step, the discrimination unit 212 realizes the above discrimination by, for example, a procedure of determining that it corresponds to lending when lending is commanded via the input member 26, and a procedure of determining that it corresponds to lending when it is determined based on the usage status information table 231 that the lending related to the two-dimensional code B has not been performed yet.
[0155] [Step S205: Determine Whether It Can Be Unlocked] The control member 21 executes a process of determining whether the electric lock 33 provided in the usage target storage device can be unlocked based on the two-dimensional code B by the discrimination unit 212 (first unlocking discrimination step). If the control member 21 determines that it can be unlocked, the process proceeds to step S206; if not, the process proceeds to step S210.
[0156] To realize the offline control process, in the first unlocking discrimination step, the discrimination unit 212 performs the discrimination based on the above authentication information and identification information, particularly the authentication information, without using the information obtained from an external server (such as server 1) between the reading of the two-dimensional code B and the discrimination. In the first unlocking discrimination step, the discrimination unit 212 realizes the discrimination by, for example, a procedure of determining that it can be unlocked when predetermined information such as time limit information can be read from the reservation information decrypted by the public key.
[0157] When time limit information is acquired, in the first unlocking determination step, it is preferable that the determination unit 212 is configured to determine whether the electric lock 33 provided in the storage device to be used can be unlocked based on the authentication information, identification information, and time limit information. Thereby, even in a usage mode where the time when unlocking is permitted is limited, such as lending with reservation management, the management device 2 does not require network communication with an external server, and can determine a plurality of articles to be lent with a single authentication data, unlock the electric lock 33 of the storage device 3 storing the article, and manage lending to the user.
[0158] Incidentally, there may be a case where a plurality of articles that can be lent in the same manner are managed by the storage device group 3. In such management, when only one of the plurality of articles is lent, the process of unlocking all the storage devices 3 storing the plurality of articles has security concerns.
[0159] When the management device 2 further includes a storage member 23 in which usage status information indicating the usage status of each storage device 3 is stored, the determination unit 212 preferably determines a usable storage device that can be used among two or more storage devices to be used based on the usage status information, and executes a process of determining that the electric lock 33 provided in the usable storage device can be unlocked. Thereby, the management device 2 can unlock only the minimum necessary storage devices 3 according to the usage status without performing network communication. Step S206 is an example of this process.
[0160] [Step S206: Determine whether there is a usable storage device] The control member 21 executes a process of determining whether there is a usable storage device by the determination unit 212 (usable device determination step). If the control member 21 determines that there is, the process proceeds to step S207, and if not, the process proceeds to step S209.
[0161] In order to implement the offline control process, in the usable device determination step, the determination unit 212 performs the determination based on the above-described authentication information and identification information, particularly the identification information, without using the information obtained from an external server (such as server 1, etc.) from the reading of the two-dimensional code B until the determination. In the usable device determination step, the determination unit 212, for example, refers to the usage status information table 231 and realizes the determination by a procedure of determining that any of the storage devices 3 corresponding to the identification information is not in use.
[0162] [Step S207: Specify the storage device to be unlocked] The control member 21 cooperates with the storage member 23 and the like to execute the unlocking unit 213. Then, the control member 21 executes a process of specifying the storage device to be unlocked from among the storage devices to be used (the first storage device to be unlocked specification step) by the unlocking unit 213. The control member 21 moves the process to step S208.
[0163] In the first storage device to be unlocked specification step, the determination unit 212 specifies the storage device to be unlocked, for example, by a procedure of specifying a predetermined number of storage devices 3 randomly selected from the usable storage devices as the storage device to be unlocked, or by a procedure of specifying the storage device to be unlocked based on the information for specifying the storage device to be unlocked input from the input member 26.
[0164] [Step S208: Unlock the storage device to be unlocked] The control member 21 executes a process of unlocking the specified storage device to be unlocked by the unlocking unit 213 (the first unlocking step). The control member 21 moves the process to step S209. The unlocking unit 213 realizes the above-described unlocking by a procedure of transmitting unlocking command information to the electric lock 33 of the specified storage device to be unlocked, that is, the electric lock 33 determined to be unlockable.
[0165] The management process preferably includes a process of updating the usage status according to the lending. Thereby, the management device 2 can determine the usable storage device based on the usage status. Step S209 is an example of such a process.
[0166] [Step S209: Update Usage Status] The control member 21 executes a process of updating the usage status related to the storage device to be unlocked by the unlocking unit 213 (first usage status update step). The control member 21 moves the process to step S210.
[0167] The management process includes a series of processes related to the return of items. Steps S210 to S214 are an example of this process.
[0168] [Step S210: Determine if it Corresponds to Return] The control member 21 executes a process of determining by the determination unit 212 whether the operation desired by the user corresponds to a return (return determination step). If the control member 21 determines that it corresponds, it moves the process to step S211; if not, it moves the process to step S215.
[0169] In the return determination step, the determination unit 212 realizes the above determination by, for example, a procedure of determining that it corresponds to a return when a return is commanded via the input member 26, a procedure of determining that it corresponds to a return when it is determined based on the usage status information table 231 that the lending related to the two-dimensional code B has already been performed, etc.
[0170] [Step S211: Determine if it can be Unlocked] The control member 21 executes a process of determining by the determination unit 212 whether the electric lock 33 provided in the storage device to be used can be unlocked based on the two-dimensional code B (second unlocking determination step). If the control member 21 determines that it can be unlocked, it moves the process to step S212; if not, it moves the process to step S214.
[0171] In order to implement the offline control process, in the second unlocking determination step, the determination unit 212 performs the determination based on the above-described authentication information and identification information, particularly the authentication information, without using the information obtained from an external server (such as server 1) between the reading of the two-dimensional code B and the determination. In the second unlocking determination step, the determination unit 212 realizes the determination, for example, by a procedure of determining that unlocking is possible when predetermined information such as time limit information can be read from the reservation information decrypted by the public key.
[0172] [Step S212: Identify the storage device to be unlocked] The control member 21 cooperates with the storage member 23 and the like to execute the unlocking unit 213. Then, the control member 21 executes, by the unlocking unit 213, a process of identifying the storage device to be unlocked from the storage devices for use (second storage device to be unlocked identification step). The control member 21 moves the process to step S213.
[0173] In the second storage device to be unlocked identification step, the determination unit 212 identifies the storage device to be unlocked, for example, by a procedure of identifying the storage device 3 unlocked using the two-dimensional code B identified based on the usage status information as the storage device to be unlocked, a procedure of identifying the storage device to be unlocked based on the information for identifying the storage device to be unlocked input from the input member 26, and the like.
[0174] [Step S213: Unlock the storage device to be unlocked] The control member 21 executes, by the unlocking unit 213, a process of unlocking the identified storage device to be unlocked (second unlocking step). The control member 21 moves the process to step S214. The unlocking unit 213 realizes the above-described unlocking by a procedure of transmitting unlocking command information to the electric lock 33 of the identified storage device to be unlocked, that is, the electric lock 33 determined to be unlockable.
[0175] The management process preferably includes a process of updating the usage status in response to the return. Thereby, the management device 2 can determine the available storage devices based on the usage status. Step S214 is an example of the process.
[0176] [Step S214: Update Usage Status] The control member 21 executes a process of updating the usage status related to the storage device to be unlocked by the unlocking unit 213 (second usage status update step). The control member 21 moves the process to step S215.
[0177] The management process may include a series of processes of data-linking reservation information with the server 1 in a time shorter than the time for accepting unlocking by the two-dimensional code B (for example, several minutes outside business hours in a day). Thereby, the management device 2 can manage the storage device 3 based on reservation information having a larger data amount than the information stored in the two-dimensional code B while suppressing the power consumption compared to the case of constantly performing data linking. Such management contributes to shortening the time for decryption processing using the public key and reducing the power consumed by the decryption processing when the two-dimensional code B is encrypted with a secret key by suppressing the data amount stored in the two-dimensional code B. Steps S215 to S216 are an example of the process.
[0178] [Step S215: Determine Whether to Receive Reservation Information] The control member 21 cooperates with the storage member 23 and the like to execute the synchronization unit 214. Then, the control member 21 executes a process of determining whether to receive reservation information by the synchronization unit 214 (reservation information reception determination step). If the control member 21 determines that it will receive, it moves the process to step S216, and if not, it moves the process to step S217.
[0179] In the reservation information reception determination step, the synchronization unit 214 realizes the determination by, for example, a procedure of determining to receive reservation information when the current time corresponds to a given timing designated by the administrator, a procedure of determining to receive reservation information when reservation information is transmitted from the server 1, and the like.
[0180] [Step S216: Update Reservation Information] The control member 21 executes a process of updating the reservation information stored in the storage member 23 by the synchronization unit 214 (reservation information update step). The control member 21 moves the process to step S217.
[0181] The management process may include a series of processes for data-linking the usage status with the server 1 in a time shorter than the time for accepting unlocking by the two-dimensional code B (for example, several minutes outside business hours in a day). Thereby, the server 1 can perform reservation management according to the usage status while suppressing the power consumption compared to the case of constantly performing data-linking. Steps S217 to S218 are an example of the process.
[0182] [Step S217: Determine whether to transmit the usage status] The control member 21 executes a process for determining whether to transmit the usage status by the synchronization unit 214 (usage status transmission determination step). If the control member 21 determines to transmit, the process proceeds to step S218. If not, the process returns to step S201, and the processes from step S201 to step S218 are repeated.
[0183] In the reservation information reception determination step, the synchronization unit 214 realizes the determination, for example, by a procedure for determining to transmit the usage status when the current time corresponds to a given timing designated by the administrator, a procedure for determining to transmit the usage status when receiving data for instructing the transmission of the usage status from the server 1, and the like.
[0184] [Step S218: Transmit the usage status] The control member 21 executes a process for transmitting the usage status stored in the storage member 23 to the server 1 by the synchronization unit 214 (usage status transmission step). The control member 21 returns the process to step S201, and the processes from step S201 to step S218 are repeated.
[0185] [Effect of the management process] By executing the above-described management process in accordance with the program stored in the management device 2 of the present embodiment, the management device 2, by the acquisition unit 211, acquires authentication information and identification information of the target storage device among the plurality of storage devices 3 from the two-dimensional code B (from step S201 to step S203), and the discrimination unit 212 discriminates whether or not the electric lock 33 provided in the target storage device can be unlocked based on this two-dimensional code B (step S205, step S211), and the unlocking unit 213 transmits unlocking command information to the electric lock 33 determined to be unlockable.
[0186] At this time, the acquisition unit 211 acquires the identification information of each of the two or more target storage devices from the two-dimensional code in which the identification information of the two or more target storage devices is stored. Further, the discrimination unit 212 performs discrimination based on the authentication information and identification information acquired from the two-dimensional code B without using information obtained from an external server (such as server 1) between the reading and discrimination of the two-dimensional code B. In addition, the unlocking unit 213 transmits unlocking command information to the electric lock 33 provided in at least one of the target storage devices that is the target for unlocking among the target storage devices.
[0187] By executing the above-described management process, the management device 2 can read the two-dimensional code B that serves as the unlocking code by the reading member 25. Then, the management device 2 acquires authentication information and identification information from the read two-dimensional code B by the acquisition unit 211 included in the control member 21. After reading the two-dimensional code B, the discrimination unit 212 included in the control member 21 discriminates whether unlocking is possible.
[0188] At this time, the discrimination unit 212 performs discrimination based on the authentication information obtained from the read two-dimensional code B and the identification information of the storage device to be used, rather than the information obtained from an external server (such as server 1) after reading the two-dimensional code B. Since the acquisition unit 211 is configured to acquire the identification information of each of the two or more storage devices to be used from the two-dimensional code in which the identification information of the two or more storage devices to be used is stored, the discrimination unit 212 can perform accurate discrimination with a single key even when there are two or more storage devices to be used and network communication cannot be performed.
[0189] After the discrimination, the unlocking unit 213 included in the control member 21 of the management device 2 transmits unlocking command information to the electric lock 33 provided in at least one storage device to be unlocked via the communication member 24 configured to communicate with the storage device 3. That is, the unlocking unit 213 can unlock the electric lock corresponding to one or more articles even when network communication with an external server cannot be performed.
[0190] With the above configuration, the management device 2 of the present embodiment does not require network communication with an external server for both discrimination of the unlocking target and execution of unlocking, discriminates a plurality of articles to be lent with a single authentication data, unlocks the electric lock 33 of the storage device 3 containing the articles, and can perform management for lending to users. The management device 2 can provide a means for discriminating and lending a plurality of articles managed by a group of storage devices with a single authentication data without requiring external network communication.
[0191] Further, in the management device 2 that executes the management process, the acquisition unit 211 may be further configured to acquire time limit information indicating the time when unlocking is permitted (step S203), and the discrimination unit 212 may be configured to discriminate whether the electric lock 33 provided in the storage device to be used can be unlocked based on the authentication information, the identification information, and the time limit information (steps S205 to S208).
[0192] According to the above configuration, the acquisition unit 211 of the control member 21 of the management device 2 further acquires time limit information indicating the time when unlocking is permitted from the two-dimensional code B. Then, the determination unit 212 determines whether unlocking is possible based on the information obtained by further adding this time limit information. As a result, the management device 2 of this configuration can, even in a usage mode in which the time when unlocking is permitted is restricted, such as lending with reservation management, discriminate a plurality of articles to be lent using a single authentication data without requiring network communication with an external server, unlock the electric lock 33 of the storage device 3 storing the article, and perform management for lending to a user.
[0193] When the management device 2 that executes management processing further includes a storage member 23 in which a public key is stored (see the section of the storage member 23), the acquisition unit 211 may be configured to acquire information from an encrypted two-dimensional code encrypted with a secret key corresponding to the public key using the public key (step S203).
[0194] When using a two-dimensional code as a key, there is a concern that the information embedded in the two-dimensional code may be analyzed and misused for generating an illegal key. By using an encrypted two-dimensional code as a key instead of a two-dimensional code with information embedded in plain text, such misuse can be prevented. However, network communication is required for the process of decrypting the encrypted two-dimensional code by an external server. In addition, information leakage due to communication eavesdropping is also a concern in such a process.
[0195] According to the above configuration, by the acquisition unit 211 acquiring information from an encrypted two-dimensional code encrypted with a secret key using the public key stored in the storage member 23, the management device 2 can prevent the generation and use of a forged two-dimensional code.
[0196] When the management device 2 further includes a storage member 23 in which usage information indicating the usage status of each storage device 3 is stored (see the item of the usage information table 231), the determination unit 212 may be configured to determine, based on the usage information, usable storage devices among the target storage devices to be used, and to determine that the electric lock 33 provided in the usable storage device can be unlocked (from step S206 to step S208).
[0197] There may be a case where a plurality of articles that can be lent out in the same way are managed by a group of storage devices. In such management, when only one of a plurality of articles is lent out, the process of unlocking all the storage devices 3 in which the plurality of articles are stored has security concerns. If it is a process of managing the usage status and unlocking only the electric lock 33 related to the storage device 3 corresponding to the article that can be used, such concerns can be eliminated. However, in the process of managing the usage status by the external server 1, network communication is required. In addition, in such a process, information leakage due to communication interception is also a concern.
[0198] According to the above configuration, the determination unit 212 determines usable storage devices based on the usage information stored in the storage member 23 included in the management device 2. Thereby, the management device 2 can perform management of determining and lending out a plurality of articles that can be lent to a user according to the usage status with a single authentication data without requiring network communication.
[0199] From the above, according to the management device 2 of the present embodiment, it is possible to provide a means for performing management of determining and lending out a plurality of articles managed by the group of storage devices 3 with a single authentication data without requiring external network communication.
[0200] 〔Dispersed arrangement of the storage device 3〕 The system S of the present embodiment is configured to include a plurality of storage devices 3 arranged apart from each other and a management device 2. The storage device 3 has an electric lock 33 configured to restrict the acquisition of the stored key K from the outside and communicate with the management device 2. The communication member 24 can be configured to communicate with the electric lock 33 of the storage device 3 configured separately from the management device 2. That is, the system S of the present embodiment can adopt a mode of managing a plurality of storage devices 3, which are physical independent lock boxes different from a lending locker device or the like in which a management unit and a storage unit are integrally configured, by an external management device 2.
[0201] Management of lending a plurality of articles is performed by an apparatus in which the management device 2 and the plurality of storage devices 3 are integrally configured, exemplified by a lending locker or a delivery box. On the other hand, for example, like room rental in a lodging facility or individual box rental of a safe deposit box, there may be management of lending a locked space by providing a key near each of the lent spaces after authentication in a shared space. Also, in the lending of articles, management of lending at another location according to the type of article may be required. Thus, there is a demand to arrange each of the storage devices 3 at different positions and make them available using a single two-dimensional code B.
[0202] In the above configuration, since the plurality of storage devices 3 are arranged apart from each other, different from the prior art of storing articles in an apparatus in which a management unit and a storage unit are integrally configured, exemplified by a lending locker device and a delivery box device, management is realized in which each of the storage devices 3 is arranged at a different position and made available using a single two-dimensional code B. By this management, for example, management of providing a key near each of the lent spaces and management of lending at another location according to the type of article become possible.
[0203] In the above configuration, despite the plurality of storage devices 3 being arranged separately from each other, the electric lock 33 of the storage device 3 that locks the door 32 of each storage device 3 can be remotely controlled by the communication member 24 configured to communicate with the electric lock 33 of the storage device 3 which is configured separately from the management device 2. The communication member 24 communicates with the electric lock 33 of the storage device 3, for example, through communication via short-range wireless communication such as Bluetooth (registered trademark). Through this remote control, the system S with the above configuration realizes management that arranges each storage device 3 at a different position and enables them to be used with a single two-dimensional code B. Further, through such management, the system S can give different functions to each of the storage devices 3.
[0204] In the above configuration, the storage device 3 is a device having an electric lock configured to restrict the external acquisition of the stored key K and communicate with the management device 2, that is, a device small enough to store the key K suffices. Therefore, the storage device 3 with the above configuration can be realized as a cheaper lock box that does not require a large device such as a locker device.
[0205] Also, since the said configuration remotely controls a plurality of storage devices 3 arranged separately from each other, even when managing a large number of keys K, it is not a large device that collectively manages a large number of keys like the key management machine described in Patent Document 1, but is configured as a small storage device 3 (lock box) that stores one or a small number of keys in each of the plurality of storage devices 3, and a flexible arrangement can be realized by arranging them in the gap space. In addition, the management device 2 with the above configuration can perform advanced management by offline control that does not communicate with the outside.
[0206] From the above, according to the system S of the present embodiment, it is possible to provide a means for discriminating and lending out a plurality of articles managed by the storage device 3 group by a single authentication data without requiring external network communication.
[0207] <Usage Example> The following is a usage example of the system S and the management device 2 of the present embodiment.
[0208] 〔Use as a lockbox〕 An example will be described in which the storage device 3 of the present embodiment is used as a lockbox (key box), and an article (hereinafter simply referred to as "key K") that functions as a key for locking and unlocking the door of a space to be lent (for example, a hotel room) is stored in the storage device 3.
[0209] [Installation of the management device and the lockbox] The administrator of the system S installs the management device 2 in a space related to the space to be lent (for example, the hotel reception). In addition, the administrator installs a storage device 3 containing a key K (for example, a key to a hotel room) corresponding to each space to be lent.
[0210] [Reservation] The user of the space to be lent accesses the server 1 via the user terminal T or the like and reserves the key K corresponding to the space. This reservation is realized, for example, as a reservation for a hotel room. The server 1 stores reservation information indicating one or a plurality of storage devices 3 containing the key K corresponding to the reservation content desired by the user in the reservation table 131.
[0211] [Issuance of the two-dimensional code] The user instructs the server 1 to issue a two-dimensional code B corresponding to the reservation. The server 1 issues the two-dimensional code B. The user stores the data of the issued two-dimensional code B in the user terminal T or the like.
[0212] For example, in the case of a hotel reservation, the server 1 issues a two-dimensional code B in which the identification information of a plurality of storage devices 3 containing the key K of the room corresponding to the reserved grade (for example, the grade of a twin room) and the time limit information indicating the reserved time zone are embedded.
[0213] [Lending] The user presents the two-dimensional code B to the management device 2. The management device 2 determines whether it can unlock the electric lock 33 of the storage device 3 based on the authentication information, identification information, and time limit information obtained from the two-dimensional code B, as well as the usage status and the like stored in the management device 2. Then, among the available storage devices 3, the management device 2 transmits unlocking command information to the electric lock 33 of an appropriate storage device 3 specified based on the user's input, usage status, priority, etc., and unlocks the electric lock 33. The user borrows the key K from the unlocked storage device 3 and uses the reserved space.
[0214] For example, in the case of the two-dimensional code B related to the above hotel reservation, the management device 2 installed at the hotel reception, based on the usage status stored in the storage member 23, selects, from among a plurality of storage devices 3 (target storage devices to be used) identified by the identification information embedded in the two-dimensional code B presented by the guest, a storage device 3 (usable storage device) excluding the storage device 3 corresponding to the room being used by other guests as the storage device 3 to be unlocked, and unlocks the electric lock 33 thereof.
[0215] [Return] The user presents the two-dimensional code B to the management device 2. The management device 2 determines whether it can unlock the electric lock 33 of the storage device 3 based on the authentication information, identification information, and time limit information obtained from the two-dimensional code B, as well as the usage status and the like stored in the management device 2. Then, among the available storage devices 3, the management device 2 transmits unlocking command information to the electric lock 33 of an appropriate storage device 3 specified based on the user's input, usage status, etc., and unlocks the electric lock 33. The user returns the key K to the unlocked storage device 3.
[0216] [Management of Facilities etc. Using a Lock Box] The storage device 3 of this embodiment can be used, for example, as a lock box for managing the key K of real estate, a lock box for managing the key K of a private accommodation facility having a plurality of rooms, or a lock box for managing the key K of a delivery carrier's vehicle. In these applications, taking advantage of the feature of this embodiment that a plurality of physically independent storage devices 3 can be managed by one management device 2, it is preferable to configure the storage device 3 as a small lock box.
[0217] As a result, users of the system S can flexibly utilize the gap space, suppress the introduction cost, and can easily retrofit the facility. In addition, such a configuration is not a major financial burden of replacing with a larger key management machine when increasing the number of real estate properties, rooms, or vehicles. Instead, it has the advantage of enabling a flexible and cost-effective response by adding a storage device 3 for storing the key K corresponding to the increased real estate property, room, or vehicle and bringing it under the management of the management device 2.
[0218] In the system S of this embodiment, since the management device 2 itself is designed to know "which storage device 3 to open", lending and returning of the key K can be realized as in the above example without communication with an external server such as cloud authentication. The same effect can be obtained even when the storage device 3 is used for other purposes.
[0219] It should be noted that those skilled in the art can conceive various modification examples and correction examples within the scope of the idea of the present invention, and it is understood that those modification examples and correction examples also belong to the scope of the present invention. For example, with respect to the above-described embodiment, those obtained by appropriately adding, deleting, or changing the design of components by those skilled in the art, or those obtained by adding steps or changing conditions, are also included in the scope of the present invention as long as they have the gist of the present invention.
Explanation of Reference Signs
[0220] S Management System 1 Server 11 Server Control Unit 111 Reservation Management Unit 112 Issuing Unit 113 Linking Unit 13 Server Memory Unit 131 Reservation Table 14 Server Communication Unit 2 Management Device 21 Control Member 211 Acquisition Unit 212 Discrimination Unit 213 Unlocking Unit 214 Synchronization Unit 23 Memory Member 231 Usage Information Table 24 Communication Member 25 Reading Member 26 Input Member 27 Power Supply Member 3 Storage Device 31 Main Body 32 Door 33 Electric Lock B Two-dimensional Code K Key T User Terminal N Network
Claims
1. A communication member configured to communicate with a plurality of storage devices, A reading member configured to read a two-dimensional code, A control member for controlling the communication member and the reading member, Comprising: The control member: An acquisition unit that acquires authentication information and identification information of a target storage device among the plurality of storage devices from the two-dimensional code, A determination unit that determines whether an electric lock provided in the target storage device can be unlocked based on the two-dimensional code, An unlocking unit that transmits unlocking command information to the electric lock determined to be unlockable, Having: The acquisition unit is configured to acquire the identification information of each of two or more target storage devices from a two-dimensional code in which the identification information of two or more target storage devices is stored, The determination unit makes the determination based on the authentication information and the identification information without using information obtained from an external server between the reading of the two-dimensional code and the determination, When the acquisition unit acquires the identification information of each of two or more target storage devices, the unlocking unit specifies an unlocking target storage device from among the target storage devices related to the acquired identification information, and transmits unlocking command information to the electric lock provided in the specified unlocking target storage device among the target storage devices, A management device for a group of storage devices.
2. The acquisition unit is further configured to acquire time limit information indicating a time when unlocking is permitted, The determination unit is configured to determine whether an electric lock provided in the target storage device can be unlocked based on the authentication information, the identification information, and the time limit information, The management device according to claim 1.
3. The management device further includes a storage member in which a public key is stored, The acquisition unit is configured to acquire information from an encrypted two-dimensional code encrypted with a secret key corresponding to the public key using the public key, The management device according to claim 1.
4. The management device further includes a storage member in which usage status information indicating the usage status of each storage device is stored, The determination unit determines a usable storage device that can be used among the two or more target storage devices based on the usage status information, and determines that the electric lock provided in the usable storage device can be unlocked, The management device according to claim 1.
5. A plurality of storage devices arranged at intervals from each other, The management device according to any one of claims 1 to 4, Comprising: The storage device has an electric lock configured to restrict the acquisition of the stored key from the outside and communicate with the management device. The communication member is configured to communicate with the electric lock of a storage device configured separately from the management device. A management system for a group of storage devices.
Citation Information
Patent Citations
Locker system using mobile communication terminal and its locker door unlocking method
JP2005139824A
Network key control system and key control server
JP2005188199A
Locker system using bar code or two-dimensional code
JP2007016423A
Locker management system
JP2007186918A
Locker device
JP2013044156A