Storage equipment management system

The storage device management system addresses unintentional unlocking by using multiple encrypted authentication routes and additional verification methods to enhance security and confirm user presence, ensuring intentional unlocking.

JP7725939B2Active Publication Date: 2025-08-20FUJI ELECTRIC CO LTD
View PDF 13 Cites 0 Cited by

Patent Information

Application Number
JP2021137302
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-25
Publication Date
2025-08-20
Estimated Expiration
2041-08-25

AI Technical Summary

Technical Problem

Existing storage devices can be unintentionally unlocked due to successful impersonation during user authentication, leading to security vulnerabilities.

Method used

A storage device management system that generates and transmits multiple encrypted authentication data via different routes, requiring matching decryption and additional verification methods such as short-range wireless communication, graphical codes, or biometric authentication to ensure intentional unlocking.

Benefits of technology

Prevents unintentional unlocking of storage devices by enhancing security through multiple authentication layers, confirming user presence, and reducing the risk of impersonation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007725939000001
    Figure 0007725939000001
  • Figure 0007725939000002
    Figure 0007725939000002
  • Figure 0007725939000003
    Figure 0007725939000003
Patent Text Reader

Abstract

To provide a storage device management system capable of preventing a storage device from being unlocked without a user's intention.SOLUTION: A storage device management system 1 includes: a storage device 2 including one or more lockable and unlockable storage units 11; a portable terminal 3 of a user who uses the storage device 2; and a management server 4 on a crowd CD. The storage device management system is capable of unlocking the storage units 11 according to an unlocking request from the portable terminal 3 of the user. The management server 4 generates two or more encrypted authentication data on which two or more different encryption processes are performed on one authentication data on the basis of the unlocking request, and transmits the encrypted authentication data to the storage device 2. The storage device 2 generates two or more decrypted authentication data obtained by decrypting the received encrypted authentication data, respectively, and, when the respective decrypted authentication data agree with each other, unlocks a storage unit 11 on which the unlocking request is performed.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a storage equipment management system that can prevent storage equipment from being unlocked unintentionally by a user. [Background technology]

[0002] Conventionally, locker devices that can be used by users who have pre-registered are installed in stations, commercial facilities, etc. Users make a reservation for use from a mobile terminal to a management server that manages the locker device they wish to use, and when they use the locker, they issue an unlock request to the management server, which unlocks the reserved locker device and allows them to use it.

[0003] There is also a locker device that provides a porter service, accepting luggage and other items from travelers and delivering them to their accommodations (see Patent Document 1). This locker device generates encrypted information by encrypting unlocking information, and the user sends this encrypted information to the porter, allowing the porter to unlock the locker device. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent Publication No. 2021-68075 Summary of the Invention [Problem to be solved by the invention]

[0005] When remotely controlling the unlocking of a storage device such as a locker, an unlock command is sent from the management server to the storage device after a user authentication process, and the storage device is unlocked. However, even if the user is not near the storage device, there is a problem in that the storage device may be unlocked if the user authentication process is successfully performed through impersonation. In other words, there are cases where the storage device is unlocked unintentionally by the user due to impersonation.

[0006] Furthermore, since authentication processing may be carried out due to spoofing or incorrect operation, there is a demand for further improvements in security levels.

[0007] The present invention has been made in view of the above, and has an object to provide a storage unit management system that can prevent a storage unit from being unlocked unintentionally by a user. [Means for solving the problem]

[0008] In order to solve the above-mentioned problems and achieve the object, the present invention provides a storage device management system comprising a storage device having one or more storage sections that can be locked and unlocked, a mobile terminal of a user who uses the storage device, and a management server on the cloud, and which can unlock the storage sections in response to an unlocking request from the user's mobile terminal, wherein the management server generates two or more encrypted authentication data, which are obtained by encrypting one authentication data in two or more different ways based on the unlocking request, and sends the encrypted authentication data to the storage device, and the storage device generates two or more decrypted authentication data by decrypting each of the received encrypted authentication data, and if the decrypted authentication data match, it unlocks the storage section for which unlocking has been requested.

[0009] In the above invention, the management server transmits each of the generated encrypted authentication data to the storage device via a plurality of physically different routes.

[0010] In the present invention, one of the plurality of routes is a route that passes through the mobile terminal.

[0011] Furthermore, in the above invention, the present invention is characterized in that the mobile terminal can be connected to the storage device via short-range wireless communication, and the storage device unlocks the storage unit for which unlocking is requested, on the condition that the decrypted authentication data match and the mobile terminal that requested unlocking is connected.

[0012] Furthermore, in the above invention, the present invention is characterized in that a graphic code is presented to the storage device, the mobile terminal reads the graphic code of the storage device and transmits identification information indicated by the graphic code to the storage device, and the storage device unlocks the storage unit for which unlocking is requested on the condition that each decrypted authentication data matches and the identification information matches.

[0013] Furthermore, in the above invention, the present invention is characterized in that the storage device is provided with a biometric authentication means, and the storage device unlocks the storage unit for which unlocking is requested, on the condition that the decrypted authentication data match and the authentication results of the biometric authentication means match. [Effects of the Invention]

[0014] According to the present invention, it is possible to prevent the storage device from being unlocked unintentionally. [Brief explanation of the drawings]

[0015] [Figure 1] FIG. 1 is a block diagram showing the configuration of a storage equipment management system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a sequence diagram showing the unlocking control process performed by the storage equipment management system. [Figure 3] FIG. 3 is a block diagram showing the configuration of the storage equipment management system according to the first modification. [Figure 4] FIG. 4 is a sequence diagram showing the unlocking control process procedure according to the first modification. [Figure 5] FIG. 5 is a block diagram showing the configuration of a storage equipment management system according to the second modification. [Figure 6] FIG. 6 is a sequence diagram showing the unlocking control process procedure according to the second modification. DETAILED DESCRIPTION OF THE INVENTION

[0016] Hereinafter, an embodiment of the present invention will be described with reference to the accompanying drawings.

[0017] <Configuration of storage equipment management system> FIG. 1 is a block diagram showing the configuration of a storage equipment management system 1 according to an embodiment of the present invention. As shown in FIG. 1, the storage equipment management system 1 has a storage equipment 2 located at a station, a convenience store, a delivery facility, or the like. The storage equipment 2 has one or more storage units 11 that can be locked and unlocked. The storage equipment 2 is connectable to a cloud CD. A management server 4 and a transfer server 5 are located on the cloud CD. A mobile terminal 3 is connectable to the cloud CD and can also be connected to the storage equipment 2 via short-range wireless communication.

[0018] The storage device 2 includes a storage device main body 10, a communication unit 21, and a control unit 22. The storage device main body 10 includes one or more storage sections 11, nine storage sections 11 in this example. Each storage section 11 is a storage box with a door 12 that opens toward the front. Alternatively, the storage section 11 may include a storage box with a drawer that slides out toward the front. Each storage section 11 is provided with a locking unit 13 for locking and unlocking, and each locking unit 13 functions as an electronic control key. Therefore, no physical key is required to lock or unlock the storage section 11. The locking mechanism is an auto-lock mechanism that automatically locks the door 12 or drawer when it is closed. In FIG. 1, a handle 14 is provided for opening the door 12. While FIG. 1 shows nine storage sections 11, the storage device may include only one storage section 11. Alternatively, the storage section 11 may be a storage section of a storage device such as a vending machine, whose front door can be opened and closed.

[0019] The communication unit 21 has a communication interface for connecting to the cloud CD via the Internet using a communication method such as LTE (registered trademark), and a communication interface for performing short-range wireless communication using a communication method such as Wi-Fi (registered trademark), Bluetooth (registered trademark), NFC, etc. The short-range wireless communication is preferably performed using low-power BLE.

[0020] The control unit 22 is a control unit that controls the entire storage device 2, and has an unlock control unit 22a that controls unlocking of the lock unit 13 of the storage unit 11. The control unit 22 receives the encrypted authentication data "A" and the encrypted authentication data "B" sent from the management server 4 on the cloud CD, and unlocks the lock unit 13 of the storage unit 11 that requested unlocking if the decrypted authentication data "A" matches the decrypted authentication data "B". Note that the decryption of the encrypted authentication data "A" and the encrypted authentication data "B" and the match determination may be performed by the communication unit 21.

[0021] The management server 4 is a server that manages the storage device 2. Upon receiving an unlocking request from the mobile terminal 3, the authentication data generation unit 4a in the management server 4 performs different encryption processes on authentication data, including the box ID and unit number of the storage unit 11 for which unlocking is requested, to generate encrypted authentication data “A” and encrypted authentication data “B.” The management server 4 then transmits the encrypted authentication data “A” and encrypted authentication data “B” to the storage device 2 via multiple physically different routes. In FIG. 1, the encrypted authentication data “A” is transmitted directly to the storage device 2, and the encrypted authentication data “B” is transmitted to the storage device 2 via the transfer server 5. Note that the encryption strengths of the encrypted authentication data “A” and the encrypted authentication data “B” may be different. The unlocking request from the mobile terminal 3 also includes a fixed authentication value 3a. The fixed authentication value 3a is pre-stored in a software development kit for the mobile terminal 3 or the like and managed by the mobile terminal 3.

[0022] <Storage device unlocking control process> Fig. 2 is a sequence diagram showing the unlocking control process steps performed by the storage equipment management system 1. As shown in Fig. 2, first, the mobile terminal 3 transmits an unlocking request for the storage unit 11 to be unlocked to the management server 4 (step S110). The unlocking request includes, for example, the box ID, unit number, and authentication fixed value 3a of the storage unit 11 to be unlocked.

[0023] The management server 4 creates authentication data based on the unlocking request, and generates encrypted authentication data "A" and encrypted authentication data "B" that have been subjected to different encryption processes (step S120). The management server 4 then sends the encrypted authentication data "A" directly to the storage device 2 (step S130), and sends the encrypted authentication data "B" to the storage device 2 via the transfer server 5 (step S140). As a result, the encrypted authentication data "A" and the encrypted authentication data "B" are sent to the storage device 2 via multiple physically different routes. Furthermore, the storage device 2 receives the encrypted authentication data "A" and the encrypted authentication data "B" from different directions (routes).

[0024] Upon receiving the encrypted authentication data "A" and the encrypted authentication data "B," the storage device 2 decrypts them to generate decrypted authentication data "A" and decrypted authentication data "B" (Step S150). The storage device 2 then determines whether the decrypted authentication data "A" and the decrypted authentication data "B" match (Step S160). If the decrypted authentication data "A" and the decrypted authentication data "B" do not match (Step S160: No), the storage device 2 terminates this process. On the other hand, if the decrypted authentication data "A" and the decrypted authentication data "B" match (Step S160: Yes), the storage device 2 notifies the management server 4 of an authentication completion notification (Step S170), and then the unlocking control unit 22a unlocks the storage unit 11 corresponding to the unit number and box ID (Step S180), terminating this process.

[0025] When the storage unit 11 is unlocked, the front door of the storage unit 11 can be opened, and when the front door is closed, the storage unit 11 is locked. Information on the locking and unlocking is also notified to the management server 4.

[0026] In this embodiment, two pieces of encrypted authentication data "A" and "B" are generated by the management server 4 on the cloud CD, and the encrypted authentication data "A" and "B" are obtained by performing different encryption processes on the same content and are transmitted from two different routes to the storage device 2, thereby improving the security level. Moreover, because the encrypted authentication data is generated on the cloud, this also improves the security level and reduces the load.

[0027] <Variation 1> In the above embodiment, the encrypted authentication data "B" is transmitted to the storage device 2 via the transfer server 5. However, in this first modification, the encrypted authentication data "B" is transmitted to the storage device 2 via the mobile terminal 3. FIG. 3 is a block diagram showing the configuration of the storage device management system 1 according to this first modification. As shown in FIG. 3, the management server 4 transmits the encrypted authentication data "B" to the mobile terminal 3, and the mobile terminal 3 transmits the encrypted authentication data "B" to the storage device 2. Since the mobile terminal 3 is located near the storage device 2, it transmits the encrypted authentication data "B" to the storage device 2 using short-range wireless communication. In this first modification, the storage device 2 adds a weighted condition for unlocking the storage device 2 when the mobile terminal 3 connects via short-range wireless communication, but this weighted condition may be removed.

[0028] <Storage device unlocking control process> FIG. 4 is a sequence diagram showing the unlocking control process procedure according to Modification 1. The unlocking control process procedure in FIG. 4 differs from that shown in FIG. 2 in that, instead of step S140, the management server 4 transmits encrypted authentication data "B" to the portable terminal 3 (step S141), and the portable terminal 3 transmits the received encrypted authentication data "B" to the storage device 2 (step S142). Furthermore, after the process of step S160, the weighted unlocking condition is added. That is, if the decrypted authentication data "A" and the decrypted authentication data "B" match (step S160: Yes), the storage device 2 performs short-range wireless communication with the portable terminal 3 (step S161) and determines whether or not the storage device 2 is connected to the portable terminal 3 (step S162). The authentication fixed value 3a is used for connection with the portable terminal. If the mobile terminal 3 is not connected (step S162: No), the process ends, and if the mobile terminal 3 is connected (step S162: Yes), an authentication completion notification is sent to the management server 4 (step S170). Thereafter, the unlocking control unit 22a unlocks the storage unit 11 corresponding to the unit number and box ID (step S180), and the process ends. The other processes are the same as those in the embodiment.

[0029] In this first modification, as in the embodiment, the encrypted authentication data "A" and "B" are transmitted to the storage device 2 from two directions using different routes, thereby improving the security level. Moreover, the encrypted authentication data is generated on the cloud, which also improves the security level and reduces the load.

[0030] Furthermore, in this modification 1, by using connection of the portable terminal 3 via short-range wireless communication as a weighted condition for unlocking, it is possible to confirm that the portable terminal 3 is in the vicinity of the storage device 2, and to prevent unintentional unlocking of the storage section 11 when the user is not present.

[0031] <Variation 2> In the above-mentioned variant 1, the establishment of communication using short-range wireless communication was an additional requirement for unlocking to confirm that the mobile terminal 3 is in the vicinity of the storage device 2, but in this variant 2, a graphical code such as a QR code (registered trademark) presented on the storage device 2 is read, and identification information of the read graphical code is transmitted to the storage device 2, thereby confirming that the mobile terminal 3 is in the vicinity of the storage device 2.

[0032] FIG. 5 is a block diagram showing the configuration of a storage equipment management system 1 according to Modification 2. As shown in FIG. 5, a graphic code DD is displayed on the front of the storage equipment 2. This graphic code DD may be a sticker or a periodically changed LCD display. The mobile terminal 3 reads the graphic code DD displayed on the storage equipment 2 and transmits the read identification information to the storage equipment 2. A match of this identification information is a weighted requirement for unlocking, similar to the weighted requirement according to Modification 1.

[0033] <Storage device unlocking control process> FIG. 6 is a sequence diagram showing the unlocking control process procedure according to Modification 2. The difference between the unlocking control process procedure shown in FIG. 4 in FIG. 6 is that, instead of steps S161 and S162, the mobile terminal 3 reads the graphic code DD of the storage device 2 (step S163) and transmits the identification information indicated by the graphic code DD to the storage device 2 (step S164). The storage device 2 then determines whether the received identification information matches (step S165). If the identification information does not match (step S165: No), the process ends. On the other hand, if the identification information matches (step S165: Yes), the management server 4 is notified of the authentication completion (step S170), and then the unlocking control unit 22a unlocks the storage unit 11 corresponding to the unit number and box ID (step S180), and the process ends. The other processes are the same as those in Modification 1.

[0034] As a result, in this variant example 2, as in variant example 1, the graphical code DD can be used to confirm that the mobile terminal 3 is in the vicinity of the storage device 2 as a loading requirement for unlocking, thereby preventing unintentional unlocking of the storage unit 11 when the user is not present.

[0035] The timing for reading the graphic code DD in step S163 may be any time before the identification information is transmitted in step S164, and may be, for example, immediately before or after the transmission of the unlocking request (step S110) or immediately after the reception of the encrypted authentication data "B" (step S141).

[0036] <Variation 3> In addition, in the above-described second modification, the graphic code DD is used to confirm that the person (portable terminal 3) is in the vicinity of the storage device 2. However, this is not limiting, and a biometric authentication means may be provided in the storage device 2 so that the person can be identified in front of the storage device 2. The storage device 2 then unlocks the storage unit 11 for which unlocking is requested, on the condition that the decrypted authentication data and the biometric authentication results match. Biometric authentication means include fingerprint authentication, finger vein authentication, face authentication, voice authentication, retina authentication, etc. The biometric authentication process may be performed by the storage device 2 or the management server 4.

[0037] The unlocking weighting requirements in the above-mentioned Modifications 1 to 3 may be combined as appropriate. For example, the unlocking weighting requirements in Modification 2 may be added to the unlocking weighting requirements in Modification 1, or the unlocking weighting requirements in Modification 3 may be added to the unlocking weighting requirements in Modification 1, or all of the unlocking weighting requirements in Modifications 1 to 3 may be added.

[0038] Furthermore, the configurations illustrated in the above embodiments are merely functional schematics and are not necessarily physically configured as shown. In other words, the distribution and integration of each device and component is not limited to that illustrated, and all or part of them can be functionally or physically distributed and integrated in any unit depending on various usage situations, etc. [Explanation of symbols]

[0039] 1 Storage equipment management system 2 Storage device 3. Mobile devices 3a Fixed value for authentication 4 Management Server 4a Authentication data generation unit 5 Transfer Server 10 Storage device body 11 Storage area 12 Doors 13 Rock Club 14 Handle 21 Communication unit 22 Control Unit 22a Unlocking control section CD Cloud

Claims

1. A storage device management system that includes a storage device having one or more storage units that can be locked and unlocked, a mobile device of a user who uses the storage device, and a management server on a cloud, and that can unlock the storage units in response to an unlocking request from the mobile device of the user, the management server generates two or more encrypted authentication data by encrypting one authentication data in two or more different ways based on the unlocking request, and transmits each of the generated encrypted authentication data to the storage device via a plurality of physically different routes; The storage device generates two or more decrypted authentication data by decrypting each of the received encrypted authentication data, and unlocks the storage unit for which unlocking is requested if the decrypted authentication data match.

2. 2. The storage equipment management system according to claim 1, wherein one of the plurality of routes is a route that passes through the mobile terminal.

3. the portable terminal is connectable to the storage device via short-range wireless communication; 3. The storage device management system according to claim 1, wherein the storage device unlocks the storage unit for which unlocking is requested, provided that the decrypted authentication data match and the mobile terminal that made the unlocking request is connected.

4. The storage device is provided with a graphic code, The mobile terminal reads the graphic code of the storage device and transmits the identification information indicated by the graphic code to the storage device; A storage device management system as described in any one of claims 1 to 3, characterized in that the storage device unlocks the storage unit for which unlocking is requested, on the condition that the decrypted authentication data match and the identification information match.

5. The storage device is provided with a biometric authentication means, A storage device management system as described in any one of claims 1 to 4, characterized in that the storage device unlocks the storage unit for which unlocking is requested, on the condition that the decrypted authentication data match and the authentication results of the biometric authentication means match.

Citation Information

Patent Citations

  • Locker system

    JP2003166370A

  • Certificate acquisition method, certificate setting method, certificate acquisition apparatus, certificate setting apparatus, certificate handling system, certificate setting system, program and recording medium

    JP2004320715A

  • Communication device, method of controlling communication device, program

    JP2011124960A

  • Vehicle rent management system

    JP2013175219A

  • Communication system, communication method, and portable machine

    JP2013185376A