Processing System

The processing system addresses inefficiencies in conventional user authentication by integrating multiple methods and centralized management, enhancing convenience and reducing costs through flexible condition setting and easy retrofitting.

JP7740726B2Active Publication Date: 2025-09-17BITKEY INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023177126
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-10-12
Publication Date
2025-09-17
Estimated Expiration
2043-10-12

AI Technical Summary

Technical Problem

Conventional user authentication systems in facilities face inefficiencies such as the need for physical cards, high costs for method expansion, inflexible entry/exit conditions, and difficulty in centralized management across multiple authentication devices.

Method used

A processing system that integrates a first and second authentication method, allowing for biometric and other methods, with a server device for flexible condition setting and centralized management, enabling easy retrofitting and convenient user access across various facilities.

Benefits of technology

Enhances user authentication efficiency by allowing multiple methods, flexible condition setting, and centralized management, improving convenience and reducing implementation costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007740726000001
    Figure 0007740726000001
  • Figure 0007740726000002
    Figure 0007740726000002
  • Figure 0007740726000003
    Figure 0007740726000003
Patent Text Reader

Abstract

To provide a processing device, a processing program, and a processing method capable of authenticating a user more efficiently.SOLUTION: A processing device includes: a first communication interface configured to be communicably connected to a first authentication device installed in a facility with user access limitations in order to determine whether or not to permit the user to use the facility by authenticating the user with a first authentication method using first authentication information; a second communication interface configured to receive permission information, which is used for permitting the user to use the facility by authenticating the user with a second authentication method different from the first authentication method, from a second authentication device different from the first authentication device; and a processor configured to execute processing for transmitting the permission information to the first authentication device upon receiving the permission information from the second authentication device.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to processing systems used to authenticate users. [Background technology]

[0002] A known prior art ticket gate management system is one that controls the opening and closing of ticket gates to manage entry and exit to a facility, comprising: a contactless information recording medium carried by a person entering or exiting the facility and storing management information necessary for entering or exiting through the ticket gate; a reader that reads the management information stored on the contactless information recording medium; a ticket gate device that opens the ticket gate when the contactless information recording medium is authenticated; and a control device that performs authentication judgment based on the management information read by the reader and controls the opening and closing of the ticket gate, wherein the control device determines whether the person entering or exiting is an individual or a group entering or exiting with a reservation based on the management information read by the reader, and changes the processing procedures related to the authentication judgment and the opening and closing control of the ticket gate based on the judgment result (Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2010-86479 A Summary of the Invention [Problem to be solved by the invention]

[0004] In light of the above-described techniques, the present disclosure aims to provide a processing system capable of more efficiently authenticating users through various embodiments. [Means for solving the problem]

[0005] According to one aspect of the present disclosure, there is provided a processing device including: a first communication interface configured to communicatively connect with a first authentication device installed in a facility where user use is restricted, in order to determine whether to allow the user to use the facility by authenticating the user by a first authentication method using first authentication information; a second communication interface configured to receive, from a second authentication device different from the first authentication device, acceptance information used to allow the user to use the facility by authenticating the user by a second authentication method different from the first authentication method; and a processor configured to execute processing to transmit the acceptance information to the first authentication device upon receiving the acceptance information from the second authentication device.

[0006] According to one aspect of the present disclosure, there is provided a processing program that causes the at least one processor in a processing device including: a first communication interface configured to communicatively connect with a first authentication device installed in equipment whose use by a user is restricted in order to determine whether to allow the user to use the equipment by authenticating the user by a first authentication method using first authentication information; a second communication interface configured to receive, from a second authentication device different from the first authentication device, acceptance information used to allow the user to use the equipment by authenticating the user by a second authentication method different from the first authentication method; and at least one processor, to execute a process for transmitting the acceptance information to the first authentication device upon receiving the acceptance information from the second authentication device.

[0007] According to one aspect of the present disclosure, there is provided a "processing method executed by at least one processor in a processing device including: a first communication interface configured to communicatively connect with a first authentication device installed in a facility where user use is restricted in order to determine whether to allow the user to use the facility by authenticating the user by a first authentication method using first authentication information; a second communication interface configured to receive, from a second authentication device different from the first authentication device, acceptance information used to allow the user to use the facility by authenticating the user by a second authentication method different from the first authentication method; and at least one processor, the processing method including a step of transmitting the acceptance information to the first authentication device upon receiving the acceptance information from the second authentication device."

[0008] According to one aspect of the present disclosure, there is provided a server device including at least one processor, the server device being configured to execute a process of receiving, from a first authentication device installed to authenticate the user by a first authentication method and determine whether to allow the user to use the facility in which the user's use is restricted, first log information indicating that the user has been authenticated, due to the at least one processor receiving an authentication request from the user using first authentication information, receiving second log information from the first authentication device in which the first authentication device receives allowance information generated by authenticating the user by a second authentication method different from the first authentication method, and storing the first log information and the second log information.

[0009] According to one aspect of the present disclosure, there is provided a program that causes a computer having at least one processor to function to execute a process of receiving first log information indicating that a user has been authenticated from a first authentication device installed to authenticate the user using a first authentication method and determine whether to allow the user to use the facility in which user use is restricted, upon receiving an authentication request from the user using first authentication information, receiving second log information indicating that the user has been authenticated from the first authentication device upon receiving allowance information generated by authenticating the user using a second authentication method different from the first authentication method, and storing the first log information and the second log information.

[0010] According to one aspect of the present disclosure, there is provided a "method executed by at least one processor in a computer having the at least one processor, the method including: receiving first log information indicating that the user has been authenticated from a first authentication device installed to authenticate the user by a first authentication method and determine whether to allow the user to use the facility, upon receipt of an authentication request from the user using first authentication information in a facility where user use is restricted; receiving second log information from the first authentication device, upon receipt by the first authentication device of acceptance information generated by authenticating the user by a second authentication method different from the first authentication method; and storing the first log information and the second log information."

[0011] According to one aspect of the present disclosure, there is provided "a processing system including a server device and a processing device, configured to execute a process in which, upon receiving an authentication request from a user using first authentication information in a facility where user use is restricted, the server device receives first log information indicating that the user has been authenticated from a first authentication device installed to authenticate the user using a first authentication method and determine whether or not to allow the user to use the facility, the server device outputs acceptance information generated by authenticating the user using a second authentication method different from the first authentication method to provide to the processing device, the processing device transmits the acceptance information output from the server device to the first authentication device, the server device receives second log information indicating that the user has been authenticated from the first authentication device due to acceptance by the first authentication device, and the server device stores the first log information and the second log information."

[0012] According to one aspect of the present disclosure, there is provided a processing program that causes a processing system including a server device and a processing device to function such that, upon receiving an authentication request from a user using first authentication information in a facility where user use is restricted, the server device receives first log information indicating that the user has been authenticated from a first authentication device installed to authenticate the user using a first authentication method and determine whether to allow the user to use the facility, the server device outputs acceptance information generated by authenticating the user using a second authentication method different from the first authentication method to provide to the processing device, the processing device transmits the acceptance information output from the server device to the first authentication device, the server device receives second log information from the first authentication device indicating that the user has been authenticated upon acceptance by the first authentication device, and the server device executes a process for storing the first log information and the second log information.

[0013] According to one aspect of the present disclosure, there is provided a processing method executed in a processing system including a server device and a processing device, the processing method including: a step in which, upon receiving an authentication request from a user using first authentication information in a facility where user use is restricted, the server device receives first log information indicating that the user has been authenticated from a first authentication device installed to authenticate the user using a first authentication method and determine whether to allow the user to use the facility; a step in which the server device outputs acceptance information generated by authenticating the user using a second authentication method different from the first authentication method to provide to the processing device; a step in which the processing device transmits the acceptance information output from the server device to the first authentication device upon receiving the acceptance information; a step in which the server device receives second log information from the first authentication device indicating that the user has been authenticated upon acceptance by the first authentication device; and a step in which the server device stores the first log information and the second log information. [Effects of the Invention]

[0014] According to the present disclosure, a processing system method that allows for more efficient user authentication can be provided.

[0015] It should be noted that the above effects are merely illustrative for the sake of convenience and are not limiting. In addition to or instead of the above effects, any effect described in this disclosure or an effect obvious to a person skilled in the art may be achieved. [Brief explanation of the drawings]

[0016] [Figure 1] FIG. 1 is a block diagram showing the configuration of a processing system 1 according to an embodiment of the present disclosure. [Figure 2A] FIG. 2A is a block diagram showing a configuration of a processing device 100 according to an embodiment of the present disclosure. [Figure 2B] FIG. 2B is a block diagram showing a configuration of the server device 200 according to an embodiment of the present disclosure. [Figure 3A]FIG. 3A is a diagram conceptually illustrating a user management table stored in the second server device 200-2 according to an embodiment of the present disclosure. [Figure 3B] FIG. 3B is a diagram conceptually illustrating a log management table stored in the second server device 200-2 according to an embodiment of the present disclosure. [Figure 3C] FIG. 3C is a diagram conceptually illustrating authority information according to an embodiment of the present disclosure. [Figure 4A] FIG. 4A is a diagram showing a processing sequence executed by the processing system 1 according to an embodiment of the present disclosure. [Figure 4B] FIG. 4B is a diagram showing a processing sequence executed by the processing system 1 according to an embodiment of the present disclosure. [Figure 4C] FIG. 4C is a diagram showing a processing sequence executed by the processing system 1 according to an embodiment of the present disclosure. [Figure 4D] FIG. 4D is a diagram showing a processing sequence executed by the processing system 1 according to an embodiment of the present disclosure. [Figure 4E] FIG. 4E is a diagram showing a processing sequence executed by the processing system 1 according to an embodiment of the present disclosure. [Figure 5] FIG. 5 is a block diagram showing a configuration of a processing system 1000 according to an embodiment of the present disclosure. [Figure 6] FIG. 6 is a diagram conceptually illustrating a user management table stored in the second server device 200-2 according to an embodiment of the present disclosure. [Figure 7A] FIG. 7A is a diagram showing a processing sequence executed in the processing system 1000 according to an embodiment of the present disclosure. [Figure 7B] FIG. 7B is a diagram showing a processing sequence executed by the processing system 1000 according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0017] 1. Overview of Processing System 1 In conventional buildings, for example, when a building gate uses a card reader for authentication, it is impossible to enter or exit the gate without physically holding a card. Therefore, if a user forgets their card, they are unable to enter or exit the building, and may need to go to a distant reception desk to report that they have forgotten their card and receive a spare card, resulting in inconvenient procedures. Furthermore, even if an authentication method different from the first authentication method is introduced to a building or its gates, the introduction costs are high, and administrators are burdened with the need to replace the gate with one that can handle a different authentication method in addition to the first authentication method, and with additional wiring work. The processing system 1 according to the present disclosure, in a facility with restricted user access, not only authenticates users using the first authentication method with the first authentication device 300-1, but also enables users to authenticate using various authentication methods as the second authentication method with the second authentication device 300-2 via the processing device 100. This allows for easy expansion of authentication methods by retrofitting the processing device 100 without incurring significant introduction costs. Furthermore, by using biometric authentication such as face recognition as the second authentication method, it becomes unnecessary to carry a card, improving convenience. Furthermore, it is possible to combine multiple methods, such as face recognition as well as device authentication and QR codes, as the second authentication method, further improving convenience.

[0018] Furthermore, the processing system 1 according to the present disclosure not only expands the authentication method but also expands the authentication conditions. Conventional building control panels do not allow for flexible assignment of entry / exit conditions to a single user ID. For example, in authority control based on reservation times, it may not be possible to pre-set multiple dates or times as entry / exit conditions, or there may be an upper limit on the number of entry / exit times that can be set. Furthermore, because maintenance management of the building's control panel is performed by the building manager, employees of companies occupying the building communicate directly with the building manager via email, etc., and the permissions are only reflected in the control panel after a certain number of work days have passed. This creates challenges, such as the inability to flexibly set conditions for reservation times and entry / exit, and the inability to quickly update the control panel even if authority conditions are changed.

[0019] The second server device 200-1 in the processing system 1 according to the present disclosure cooperates with the first server device 200-1 to which the control panel of the building is connected, thereby enabling the second server device 200-1 to flexibly set the dates and times as conditions for entry and exit. Furthermore, by cooperating with the first server device 200-1 to which the control panel of the building is connected, for example, via an API, the second server device 200-1 can timely reflect the entry and exit conditions set in the second server device 200-1 in the control panel, making it possible to grant limited authority to a visitor at the time of reception at the entrance of the building according to schedule information registered in advance by an employee of the company occupying the building.

[0020] Furthermore, in a conventional building, if a company or other entity occupying the building has already implemented an access control system, when a user is authenticated at facilities other than the gate (e.g., an office where the user works), an authentication method (e.g., facial recognition, etc.) different from the authentication method at the building gate (e.g., an authentication method using a card reader) may be set. In this case, while facial recognition, etc., is possible at facilities other than the gate, a physical card must be used at the building gate, making it difficult to improve convenience. With the processing system 1 according to the present disclosure, the authentication method at the building gate can also be easily expanded by retrofitting the processing device 100 without incurring huge implementation costs. By using biometric authentication such as facial recognition as a second authentication method, the user does not need to carry a card, thereby improving convenience throughout the access control system for the entire building.

[0021] Furthermore, in conventional buildings, the building manager and the companies that occupy the building manage different objects, making it difficult to centrally manage the access and exit of the entire building. In other words, only the building manager can view the access and exit management system for the entire building, and it is not intended for companies that actually occupy the building to view it. Therefore, when managing the access and exit of an employee of a company that actually occupies the building, there is a problem in that the access and exit management of the employee's entry and exit at the building entrance and the access and exit management within the company's office are separated. For example, when a user is authenticated by an authentication device installed at the building gate, the time of authentication and the user are simply recorded, and the management company that manages the building manages this recorded information. Furthermore, when a user is authenticated by another authentication device installed in another facility (e.g., a conference room, a conference booth, or an office floor) within the building gate, the time of authentication and the user are similarly recorded, and another company (e.g., a company that occupies the building) that manages the other facility manages this recorded information. In other words, it is difficult to share information authenticated at the building gate and information authenticated at other facilities across businesses. With the processing system 1 according to the present disclosure, when both the administrator of building 10 and a company located in building 10 use the same second server device 200-1 for privilege management, necessary information, such as employee information that can pass through and log information indicating authentication, is shared between the two parties, while unnecessary information is kept secret, thereby enabling more flexible expansion of authentication methods even between organizations. Furthermore, by collecting log information that includes not only the time and user information of authentication but also information on the facility where the authentication was performed, it becomes possible to manage more detailed information, such as when, who, and where authentication was performed.

[0022] Furthermore, the second server device 200-1 in the processing system 1 according to the present disclosure can assign user-visible names (e.g., "Gate in front of the elevator on the third floor of Building A") to each authentication device installed at facilities such as each door or each pass-through point on a management screen, and display the names along with a floor map. In addition to device management, the second server device 200-1 can also manage locations, such as building information, floor information, conference room information, and seating information, and people, such as employees, external businesses, and guests, for people management. This allows for highly visible display of access history logs on the management screen, indicating who accessed a facility, when, and where, providing a system that is easy for administrators to manage. By linking the second server device 200-1 with the first server device 200-1, the log information managed by the first server device 200-1 can be displayed with high visibility on a management screen connected to the second server device 200-1, making system management easier for system administrators.

[0023] That is, the processing system 1 according to the present disclosure is a system that, in a facility where user use is restricted, not only authenticates a user using a first authentication method with a first authentication device 300-1 but also allows the user to be authenticated using a second authentication method with a second authentication device 300-2 via a processing device. Typically, the first authentication device 300-1 has, for example, a card reader function and acquires first authentication information when a user's ID card 500-1 is brought close to the first authentication device 300-1. The first authentication device 300-1 then authenticates the user using the acquired first authentication information. Once the user is authenticated, the first authentication device 300-1 transmits an unlocking signal to a locking / unlocking device 400 connected via a communication network to release the restriction on use of the facility. This unlocks the gate connected to the locking / unlocking device 400, allowing the user to use the facility. Furthermore, the first authentication device 300-1 transmits, in response to a request from the first server device 200-1, information on an authorization log that includes information on the fact that the restriction on the user's use has been lifted and that the user's use has been authorized, as well as the time of authorization, etc. In this way, the first server device 200-1 manages the user's usage status.

[0024] Here, a processing system 1 that performs such authentication processing is typically used as equipment in buildings, gates installed in buildings, and the like.

[0025] FIG. 1 is a block diagram illustrating a configuration of a processing system 1 according to an embodiment of the present disclosure. According to FIG. 1, the processing system 1 includes a building 10, which is an example of a facility, in which a first authentication device 300-1 and a locking / unlocking device 400 are communicatively connected to each other via a communication network. Although not specifically illustrated, a gate installed in the building 10 is electrically connected to the locking / unlocking device 400. The gate opens and closes when the gate receives an unlocking signal from the first authentication device 300-1 via the locking / unlocking device 400. The processing system 1 also includes a first server device 200-1 communicatively connected to the first authentication device 300-1 via a gateway 600 and a communication network. The first server device 200-1 transmits an identification code as first authentication information to the first authentication device 300-1 and receives user permission log information from the first authentication device 300-1.

[0026] In the present disclosure, a processing system 1 that already includes a first authentication device 300-1 and the like includes a processing device 100 that is communicatively connected to the first authentication device 300-1 via a communication network, a second authentication device 300-2 that is communicatively connected to the processing device 100 via the communication network, and a second server device 200-2 that is communicatively connected to the second authentication device 300-2 and the first server device 200-1 via the communication network. These processing devices 100 and second authentication devices 300-2 can be installed as retrofits in a building 10 that already has the first authentication device 300-1 and the like installed. Therefore, authentication using the second authentication method can be performed in addition to the first authentication method performed by the already installed first authentication device 300-1, allowing for flexible expansion of authentication methods and management of authentication information.

[0027] In this disclosure, "facility" typically refers to a building or a gate installed in a building, as described above. However, the facility may be any object subject to usage restrictions, the usage of which is restricted by users. Examples of such facility include the following: ·Providing space such as buildings, hotels, apartment complexes, houses, event facilities, or rooms (conference rooms, conference booths, residences) within buildings or apartment complexes; Gates and doors installed in the space that restrict the use of the space, · Items with restricted use, such as electronic devices such as printers and computers, home appliances such as elevators and delivery boxes, or vehicles such as bicycles and cars

[0028] For the sake of convenience, an example will be given in which a building is used as the facility, but the present invention is not limited to this.

[0029] Furthermore, in this disclosure, the term "administrator" simply refers to a person who manages each facility or each server device. Therefore, the administrator may be an individual or an organization such as a company or business. Furthermore, the entire processing system 1 does not need to be managed by the same administrator; the administrator who manages the building 10 and the first server device 200-1 and the administrator who manages the second server device 200-2 may be different persons.

[0030] Furthermore, in the present disclosure, "authentication" may be performed by any authentication method that can authenticate a user. For example, depending on how the information used for authentication is held, examples of authentication include knowledge-based (e.g., memorization by the user), possession-based (e.g., ID card, smartphone, QR code, license, or token), biometric-based (e.g., fingerprint, voice, iris, or face), or a combination thereof. Therefore, although terms such as first authentication method and second authentication method, first authentication device and second authentication device, and first authentication information and second authentication information are used in the present disclosure, they can include any of the methods, devices, and information used to perform the above-mentioned authentication.

[0031] For ease of explanation, the following description will be given assuming that the first authentication information, the first authentication method, and the first authentication device are an identification code (e.g., a six-digit number) that is unique information assigned to each user, a method for determining whether the identification code matches or does not match in the first authentication device, and a card reader for acquiring the identification code from an ID card on which the identification code is stored via near-field wireless communication. Similarly, the following description will be given assuming that the second authentication information, the second authentication method, and the second authentication device are a usage certificate information, a method for authenticating a user based on a usage certificate, and a reader for reading the usage certificate information from a user terminal device. However, the present invention is not limited to this. Furthermore, the authentication information, the authentication methods, and the authentication devices do not need to be different from each other and may be the same type.

[0032] Additionally, in this disclosure, a "user" may be any person who uses the facility, including, by way of example, employees of an institution that occupies the building, residents of an apartment complex, and guests or service providers temporarily permitted to use the facility by employees or residents.

[0033] Furthermore, although the terms "first" and "second" may be used in this disclosure, unless otherwise specified, these are merely names used for the convenience of explanation. Therefore, even if the terms "first" and "second" are used, it does not mean that the elements are limited to those to which they are attached. Naturally, multiple elements such as "third," "fourth," "fifth," and more may be included.

[0034] 2. Configuration of the Processing Device 100 FIG. 2A is a block diagram showing the configuration of a processing device 100 according to an embodiment of the present disclosure. The processing device 100 does not need to include all of the components shown in FIG. 2A ; it may omit some components or add other components. Although not specifically shown, the processing device 100 is used to relay communication between the first authentication device 300-1 and the second authentication device 300-2. Typically, the processing device 100 is retrofitted and connected to the first authentication device 300-1 already installed in the building 10 so as to be communicable via a communication network. Therefore, the processing device 100 may take any form as long as it can perform these functions, and may be a chip or substrate on which each of the components illustrated in FIG. 2A is mounted, or a device formed from these.

[0035] 2, the processing device 100 includes a processor 111 configured with a CPU or the like, a memory 112 including RAM, ROM, nonvolatile memory, an HDD, and the like, a first communication interface 113, and a second communication interface 114. These components are electrically connected to each other via control lines and data lines.

[0036] The processor 111 is configured with a CPU (microcomputer) and functions as a control unit for controlling other connected components based on various programs stored in the memory 112. The processor 111 reads out from the memory 112 a program for executing an application according to the present disclosure and a program for executing an OS, and executes these programs. Specifically, upon receiving permission information from the second authentication device 300-2, the processor 111 executes processing for transmitting the permission information to the first authentication device 300-1, based on the programs stored in the memory 112. The processor 111 is mainly configured with one or more CPUs, but may also be combined with a GPU, FPGA, etc. as appropriate.

[0037] The memory 112 includes RAM, ROM, or nonvolatile memory and functions as a storage unit. The ROM stores instructions and commands for executing the application and OS according to the present disclosure as a program. Such a program is loaded and executed by the processor 111. The RAM is used to write and read data while the program stored in the ROM is being processed by the processor 111. The nonvolatile memory is a memory into which data is written and read by the execution of the program, and the data written therein is saved even after the execution of the program has ended. Specifically, the memory 112 stores a program for the processor 111 to execute a process for transmitting the acceptance information to the first authentication device 300-1 upon receiving the acceptance information from the second authentication device 300-2.

[0038] The first communication interface 113 functions as a first communication unit that transmits and receives information to and from the electrically connected first authentication device 300-1 via a communication processing circuit. The first communication interface 113 transmits to the first authentication device 300-1 acceptance information that is generated when a user is authenticated by the second authentication method. Such a first communication interface 113 is preferably configured using serial communication such as RS-485, RS-422, or USB, a wired LAN, or a combination of these. However, the first communication interface 113 is not limited to the above-mentioned wired communication, and may also be configured using a communication circuit for communication using wireless communication such as short-range wireless communication.

[0039] The second communication interface 114 functions as a second communication unit that transmits and receives information to and from the second authentication device 300-2 via a communication processing circuit and an antenna. The second communication interface 114 receives, from the second authentication device 300-2, permission information generated when a user is authenticated by the second authentication method. The second communication interface 114 is preferably configured using a wireless LAN such as IEEE802.11, a short-range wireless communication method such as Bluetooth (registered trademark), BLE (Bluetooth Low Energy), NFC, or RFID, a wideband wireless communication method such as the LTE method, or a combination of these. However, the second communication interface 114 is not limited to the above wireless communication, and may also be configured using a wired communication method such as serial communication.

[0040] 3. Configuration of Server Device 200 FIG. 2B is a block diagram showing a configuration of a server device 200 according to an embodiment of the present disclosure. The server device 200 does not need to include all of the components shown in FIG. 2B; it may omit some components or add other components. Furthermore, the server device 200 does not need to include the components shown in FIG. 2B in a single housing; the components and processes of the server device 200 may be distributed to multiple processing devices, such as on-premise server devices and cloud server devices. Although the present disclosure includes a first server device 200-1 and a second server device 200-2, the server devices may have the same configuration or different configurations. Here, the configuration and functions of the second server device 200-2 will be mainly described.

[0041] 2B, the server device 200 includes a processor 211 configured with a CPU or the like, a memory 212 including RAM, ROM, nonvolatile memory, an HDD, and the like, and a communication interface 213. These components are electrically connected to each other via control lines and data lines.

[0042] The processor 211 is configured with a CPU (microcomputer) and functions as a control unit for controlling other connected components based on various programs stored in the memory 212. The processor 211 reads out from the memory 212 a program for executing an application according to the present disclosure and a program for executing an OS, and executes them. Specifically, the processor 211 performs the following functions: "a process of generating acceptance information by authenticating a user in a second authentication device 300-2 configured to be able to authenticate the user in a second authentication method using second authentication information different from the first authentication information, for equipment where whether or not to allow the user to use the equipment is determined by a first authentication device 300-1 configured to be able to authenticate the user in a first authentication method using first authentication information," "a process of outputting acceptance information via a communication interface in order to provide the acceptance information to the processing device 100 communicably connected to the first authentication device 300-1," and "a process of providing acceptance information to a user in equipment where the user's use is restricted." The processor 211 executes, based on a program stored in the memory 212, the following operations: "receiving first log information indicating that the user has been authenticated from the first authentication device 300-1, which is installed to authenticate the user by the first authentication method and determine whether or not to allow the user to use the system, upon receipt of an authentication request using first authentication information from the first authentication device 300-1," "receiving second log information indicating that the user has been authenticated from the first authentication device 300-1, upon receipt by the first authentication device 300-1 of allowance information generated by authenticating the user by a second authentication method different from the first authentication method," and "storing the first log information and the second log information." The processor 211 is mainly composed of one or more CPUs, but may also be combined with a GPU, FPGA, etc. as appropriate.

[0043] The memory 212 includes RAM, ROM, nonvolatile memory, and HDD, and functions as a storage unit. The ROM stores instructions and commands for executing the application and OS according to the present disclosure as a program. Such programs are loaded and executed by the processor 211. The RAM is used to write and read data while the program stored in the ROM is being processed by the processor 211. The nonvolatile memory is a memory into which data is written and read by the execution of the program, and the data written therein is saved even after the execution of the program has ended. Specifically, the memory 212 stores programs for the processor 211 to execute the above-mentioned processes, etc. The memory 212 also stores various types of information, such as a user management table (FIG. 3A) and a log management table (FIG. 3B). If necessary, this information may be stored in a database device communicatively connected to the server device 200 (in this case, the database may also be included as part of the memory 212).

[0044] The communication interface 213 functions as a communication unit that transmits and receives information to and from other remotely installed server devices, such as the first server device 200-1, and other devices, such as the second authentication device 300-2, via a communication processing circuit and an antenna. The communication processing circuit processes programs used in the processing system 1, various types of information, and the like, for transmitting and receiving information as the processing progresses. The communication processing circuit processes based on a wideband wireless communication method, such as the LTE method, but can also process based on a narrowband wireless communication method, such as a wireless LAN, such as IEEE802.11, or Bluetooth (registered trademark), or a contactless wireless communication method. Wired communication can also be used instead of or in addition to wireless communication.

[0045] The second server device 200-2 mainly functions as an authority management unit, an allowed information management unit, and an authentication unit by processing a program in the processor 211. In Fig. 2B, the second server device 200-2 is described as performing each of these functions by itself. However, this is not limiting, and the second server device 200-2 may include multiple server devices, each of which may perform each of these functional units.

[0046] 4. Other device configurations As described above, the processing system 1 includes the first authentication device 300-1, the second authentication device 300-2, the locking / unlocking device 400, and the gateway 600. Although the specific configuration of these is not particularly shown, it includes components necessary for executing each process, such as a processor, a memory, and a communication interface, and each component is electrically connected to each other via a control line and a data line.

[0047] The first authentication device 300-1, for example, is installed for authentication at the gate of the building 10 and includes a control panel or control device connected by wire to the locking / unlocking device 400 and the gateway 600, and an authentication unit (e.g., a card reader) communicatively connected to the control panel or control device. The second authentication device 3000-2, for example, is a terminal device such as a smartphone that includes a control unit communicatively connected to the second server device 200-2 and a camera or sensor for user facial authentication. However, these are merely examples, and other forms may naturally be used. The gateway 600 may be any device communicatively connected to the first server device 300-1 and capable of relaying communication between the first authentication device 300-1 and the first server device 300-1. As an example, for a first authentication device 300-1 that only has a wired communication environment, a gateway 600 that is wirelessly connected to the first server device 300-1 relays communication, thereby enabling communication between the first authentication device 300 and the first server device 300-1.

[0048] 5. Information stored in the second server device 200-2 3A is a diagram conceptually illustrating a user management table stored in the second server device 200-2 according to an embodiment of the present disclosure. The information stored in the user management table is updated and stored as needed in accordance with the progress of processing by the processor 211 of the second server device 200-2.

[0049] According to FIG. 3A, the user management table stores attribute information, first authentication information, authority information, second authentication information, and the like, in association with user ID information. "User ID information" is information unique to each user and is used to identify each user. The user ID information is generated in the second server device 200-2, for example, when a user or an administrator transmits a new registration request for a service provided by the processing system 1. "Attribute information" is information related to the attributes of each user. Examples of such attribute information include the user's name (first name), title, nickname, career history, contact information such as telephone number and email address, the address and name of the company to which the user belongs, and the name of the department to which the user belongs. These are stored as needed based on instructions input by the user or administrator, etc.

[0050] The "first authentication information" is information used for authenticating a user when the first authentication method is executed in the first authentication device 300-1. The first authentication information may be any of authentication information corresponding to a knowledge-based, possession-based, or biometric authentication method. Here, an example will be described in which an identification code, which is unique information assigned to each user, is used as the first authentication information (for example, an identification code may be a six-digit number, but the same identification code may be used for each user). The "authority information" is information indicating the authority of each user as to whether or not they are permitted to use the facility. The authority information is, for example, information indicating the time when each user can use the facility (for example, a combination of days of the week and time, such as 9:00 to 17:00 on Mondays) and the location where the facility can be used. This will be specifically described with reference to FIG. 3C.

[0051] The "second authentication information" is information used for authenticating a user when the second authentication method is executed in the second authentication device 300-2. The second authentication information may be any of authentication information corresponding to a knowledge-based, possession-based, or biometric authentication method. Here, an example will be described in which license information granted to each user is used as the second authentication information. Note that, although authentication information different from the first authentication information is exemplified as the second authentication information here, the second authentication information may also be the same as the first authentication information. Naturally, in addition to the second authentication information, multiple pieces of authentication information may be additionally stored, such as third authentication information used for authenticating a user when the third authentication method is executed in the third authentication device, and fourth authentication information used for authenticating a user when the fourth authentication method is executed in the fourth authentication device.

[0052] Although not specifically shown, in relation to the second authentication information of Figure 3A, each piece of information used for signature verification, such as each private key, each public key, and common key used when issuing a license, is also stored in memory 212.

[0053] 3B is a diagram conceptually illustrating a log management table stored in second server device 200-2 according to an embodiment of the present disclosure. Information stored in the log management table is updated and stored as needed in accordance with the progress of processing by processor 211 of second server device 200-2.

[0054] 3B, the log management table stores restricted ID information, unlocking time information, and entry / exit information in association with user ID information. "User ID information" is information unique to each user and is used to identify each user. That is, when a user is authenticated via any of the authentication devices such as the first authentication device 300-1, the user ID information is stored to identify the user.

[0055] The "locking / unlocking ID information" is information specific to the locking / unlocking device for locking / unlocking restricted objects such as equipment whose use by users is restricted, and is information for identifying each locking / unlocking device. Here, restricted objects include the following as described above: ·Providing space such as buildings, hotels, apartment complexes, houses, event facilities, or rooms (conference rooms, conference booths, residences) within buildings or apartment complexes; Gates and doors installed in the space that restrict the use of the space, · Items with restricted use, such as electronic devices such as printers and computers, home appliances such as elevators and delivery boxes, or vehicles such as bicycles and cars and a locking / unlocking device is provided corresponding to each of these facilities. Therefore, it is possible to identify each facility by the locking / unlocking ID information. Note that an authentication device is often installed corresponding to each of the above facilities or each of the locking / unlocking devices. Therefore, it is also possible to use authentication device ID information that identifies each authentication device or facility ID information that identifies each facility as the locking / unlocking ID information. In this embodiment, by using the locking / unlocking device ID information, it is possible to identify the facility that is a restricted object that the user is permitted to use and the locking / unlocking device provided corresponding to it.

[0056] The "unlocking time information" is information related to the time when an unlocking signal is transmitted from the first authentication device 300-1 to the locking / unlocking device 400 as a result of the user being authenticated via the first authentication device 300-1. The unlocking time information may directly indicate the time when the unlocking signal is transmitted, may indicate the time when the unlocking signal is received by the locking / unlocking device 400, or may indicate the time when authentication is performed to transmit the unlocking signal. In other words, the unlocking time information may be any information indicating the time when any process performed in connection with the transmission of the unlocking signal is performed. The "entry / exit information" is information indicating whether each user is currently entering or exiting the building 10. For example, when the first authentication device 300-1 first authenticates a user and generates an unlocking signal, "enter" is stored as the entry / exit information. Thereafter, each time the user is authenticated and an unlocking signal is generated, the entry / exit information is alternately stored as either "exit" or "enter."

[0057] 3C is a diagram conceptually illustrating authority information according to an embodiment of the present disclosure. The information is updated and stored as needed, for example, in response to a request from any administrator.

[0058] The authority information shown in FIG. 3C is generated for each user ID information of a user. That is, by referring to the authority information, it is possible to determine whether the user associated with the user ID information has the authority to use each facility. FIG. 3C shows the authority information of a user having "A1" as user ID information. According to FIG. 3C, restriction target information and time information are stored in association with locking / unlocking ID information. As described in FIG. 3B, the locking / unlocking ID information is information unique to a locking / unlocking device for locking and unlocking a restricted object, such as a facility whose use by a user is restricted, and is information for identifying each locking / unlocking device. Each locking / unlocking device is provided for each facility, and each locking / unlocking device is connected to an authentication device that authenticates the user. However, facility ID information identifying each facility or authentication device ID information identifying each authentication device can also be used as the locking / unlocking ID information.

[0059] "Restriction target information" is information indicating a facility that is a restricted object in which a locking / unlocking device is installed. Examples include information indicating the name of the facility, such as Building 10, and information indicating the location of each facility. "Time information" is information indicating the time each user is permitted to use a facility that is a restricted object in which a locking / unlocking device is installed. The time information may be in units of year, month, week, day, hour, minute, or second. Furthermore, the time information does not necessarily have to be a fixed continuous period, but may be a period specified each time.

[0060] In the case of the above authority information shown in Figure 3C, for example, it is indicated that a user having user ID information "A1" can use the building (gate) in which a locking / unlocking device with locking / unlocking ID information "G1" is installed between 9:00 and 22:00 on weekdays, and can use Room C in which a locking / unlocking device with locking / unlocking ID information "G4" is installed between 12:00 and 13:00 on weekdays.

[0061] 6. Processing sequence performed by processing system 1 (A) Pre-registration process of first authentication information 4A is a diagram showing a processing sequence executed in the processing system 1 according to an embodiment of the present disclosure. Specifically, FIG. 4A shows a processing sequence executed between the first authentication device 300-1, the first server device 200-1, and the second server device 200-2 in order to register, in the first authentication device 300-1, first authentication information used for authenticating a user using a first authentication method in the first authentication device 300-1. The processing in each device is executed by a processor executing a program stored in the memory of each device.

[0062] 4A, the processor 211 of the second server device 200-2 receives a user registration request for a new user via the communication interface 213 from an administrator terminal device available to the administrator. The user registration request includes attribute information and authority information of the user who wishes to newly register. Examples of the attribute information include the user's name (first and last name), title, nickname, career history, contact information such as telephone number and email address, the address of the company to which the user belongs, the name of the company, and the name of the department to which the user belongs. The authority information also includes information (FIG. 3C) indicating the available times and facilities, which have been set for the user by the administrator in advance.

[0063] When the processor 211 of the second server device 200-2 receives the user registration request, it generates new user ID information (S11). Then, the processor 211 of the second server device 200-2 associates the generated user ID information with the received attribute information and authority information and stores them in the user management table (S12). The processor 211 of the second server device 200-2 also generates an identification code, which is information unique to the user, as first authentication information for authenticating the new user, and stores the code in the user management table in association with the user ID information (S13). At a predetermined timing, the processor 211 of the second server device 200-2 transmits, via the communication interface 213 to the first server device 200-1, each piece of user ID information stored in the user management table, and the first authentication information (T11) and authority information associated with each piece of user ID information.

[0064] When the processor 211 of the first server device 200-1 receives each piece of user ID information and the first authentication information and authority information associated with each piece of user ID information from the second server device 200-2 via the communication interface 213, the processor 211 stores the received information in the memory 212 (S14). Then, at a predetermined timing, the processor 211 of the first server device 200-1 transmits each piece of user ID information and the first authentication information (T12) and authority information associated with each piece of user ID information to the first authentication device 300-1 via the communication interface 213.

[0065] When the processor of the first authentication device 300-1 receives each piece of user ID information and the first authentication information and authority information associated with each piece of user ID information from the first server device 200-1 via the communication interface, it stores the received information in memory (S14). The received information is used when authentication is performed by the first authentication device using the first authentication method. This completes the pre-registration process of the first authentication information.

[0066] The first authentication information, first authentication method, and first authentication device may be, for example, an identification code, which is unique information assigned to each user, a method for determining whether the identification code matches or does not match in the first authentication device, and a card reader for acquiring the identification code from an ID card that stores the identification code via near-field wireless communication. In other words, in such a case, the user needs to possess an ID card 500-1 (FIG. 1) that stores an identification code that can be read by a card reader. Therefore, although not shown, an ID card is prepared in advance by an administrator, and the first authentication information (identification code) associated with the user ID information is stored on the ID card by an administrator terminal device or the like. The ID card that stores the first authentication information (identification code) is then given to the user in advance by the administrator.

[0067] (B) Pre-registration process of second authentication information 4B is a diagram showing a processing sequence executed in the processing system 1 according to an embodiment of the present disclosure. Specifically, FIG. 4B shows a processing sequence executed between the second authentication device 300-2 and the second server device 200-2 to generate second authentication information used in the second authentication device 300-2 to authenticate a user using the second authentication method. The processing in each device is executed by a processor running a program stored in the memory of each device.

[0068] (B-1) Registration process of second authentication information The registration process of the second authentication information is performed when the second authentication information used for user authentication is newly registered in the second server device 200-2. As shown in FIG. 4B, the processor 211 of the second server device 200-2 receives a registration request for the second authentication information via the communication interface 213 from an administrator terminal device available to the administrator. To transmit the registration request, the administrator retrofits the processing device 100 to the first authentication device 300-1 and installs the second authentication device 300-2 in the building 10 so that it can communicate with the processing device 100. The registration request includes attribute information of the user who wishes to be newly registered, second authentication information used for authentication by the second authentication device 300-2 (e.g., facial features of the user in the case of using a facial authentication method), and authority information. The attribute information includes, for example, the user's name, title, nickname, career history, contact information such as a telephone number and an email address, the address of the company to which the user belongs, the name of the company, and the name of the department to which the user belongs. The authority information also includes information (FIG. 3C) that indicates the time and facilities that can be used, which are set in advance by an administrator for the user.

[0069] When processor 211 of second server device 200-2 receives a registration request via communication interface 213, it generates new user ID information (S21). Then, processor 211 of second server device 200-2 causes its authority management unit (access control) to associate the received attribute information and authority information with the generated user ID information and store them in a user management table (S22). Furthermore, processor 211 of second server device 200-2 causes its permission information management unit (which references and reads an identification code (first authentication information) as permission information) to generate an identification code that is information unique to the user as first authentication information for authenticating the user, and stores this in the user management table in association with the user ID information (S23). Furthermore, processor 211 of second server device 200-2 causes its authentication management unit (which manages facial features, information used for biometric authentication, etc.) to associate the second authentication information included in the received registration request with the generated user ID information and store it in the user management table (S24). This completes the registration process of the second authentication information.

[0070] In the above description, the processed authority information, first authentication information, and second authentication information are each stored in the memory 212 of the second server device 200-2. This information is used for processes such as authentication using the second authentication method shown in FIG. 4D and other figures, checking the authority information, and referencing the permission information. However, the second authentication information and the authority information may be frequently updated. In such cases, the information can be easily updated to the latest information, and the authentication process can be performed using the updated information. Alternatively, the processed authority information, first authentication information, and second authentication information may be transmitted to the second authentication device 300-2 in advance. Transmitting this information in advance allows the second authentication device 300-2 to perform processes such as authentication using the second authentication method, checking the authority information, and generating the permission information, thereby enabling more flexible responses to problems such as a deterioration in the communication environment.

[0071] (B-2) Hole data setting process The hole data setting process is performed when a new processing device 100 is retrofitted to the first authentication device 300-1 and new hole data is set for the processing device 100. As shown in FIG. 4B, upon the administrator retrofitting the processing device 100 to the first authentication device 300-1, the processor 211 of the second server device 200-2 receives a hole data setting request for the processing device 100 via the communication interface 213, for example, from an administrator terminal device available to the administrator. Upon receiving the registration request via the communication interface 213, the processor 211 of the second server device 200-2 generates a pair of a private key A and a public key A unique to the newly generated hole data in accordance with public key cryptography (S31). The hole data includes processing device ID information, which is information unique to the processing device 100 and is used to identify the processing device 100.

[0072] Next, processor 211 of second server device 200-2 generates common key A for the hole data using the generated private key A for the hole data and public key A for the hole data in accordance with the common key cryptography (S32). Processor 211 of second server device 200-2 stores private key A for the hole data and common key A for the hole data in its own memory 213 (S33), and transmits public key A for the hole data and common key A for the hole data (T31) to processing device 100 via the administrator's administrator terminal device. When processor 111 of processing device 100 receives public key A for the hole data and common key A for the hole data via communication interface 113, it stores the received public key A for the hole data and common key A for the hole data in memory 112 (S34). This completes the hole data setting process.

[0073] (B-3) Administrator setting process The administrator setup process is a process for generating, via the second authentication device 300-2, a private key or the like used to certify that the account is authorized to generate a digital key for the processing device 100 in the processing system 1 including the second server device 200-2 and the processing device 100. As shown in FIG. 4B , the processor of the second authentication device 300-2 receives an administrator setup request via a communication interface, for example, from an administrator terminal device available to the administrator. Upon receiving the registration request via the communication interface, the processor of the second authentication device 300-2 generates a pair of private key B and public key B unique to the administrator according to a public key cryptosystem (S35). The processor of the second authentication device 300-2 then stores the administrator private key B of the generated administrator private key B and administrator public key B in its own memory (S36), and transmits the administrator public key B (T31) to the second server device 200-1. When processor 211 of second server device 200-2 receives administrator public key B via communication interface 213, it stores the received administrator public key B in memory 212 (S37). This completes the administrator setting process.

[0074] (B-4) Digital key issuance process The digital key generation process is a process for issuing a digital key used to authenticate the connection source between the second authentication device 300-2 and the processing device 100. As shown in Fig. 4B, the processor of the second authentication device 300-2 detects an operation input by an administrator via an input interface, for example, and accepts a selection of hole data for which the digital key to be generated is to be used (S41). The processor of the second authentication device 300-2 then transmits a digital key issuance request (T41) for the hole data to the second server device 200-2 via the communication interface. The issuance request includes administrator ID information for the administrator's public key B and hole data ID information for specifying the hole data.

[0075] When processor 211 of second server device 200-2 receives the issuance request via communication interface 213, it generates a digital key including predetermined digital data unique to the digital key (S42). Then, processor 211 of second server device 200-2 encrypts the digital key using common key A of the hole data generated in S32 (S43), and generates signature A for the digital key using private key A of the hole data generated in S31 (S44). Processor 211 of second server device 200-2 transmits the generated digital key and signature A to second authentication device 300-2 via communication interface 213.

[0076] When the processor of the second authentication device 300-2 receives the digital key and signature A via the communication interface, it generates signature B for the received digital key and signature A using the administrator's private key B generated in S35 (S45).The processor of the second authentication device 300-2 then stores the digital key in memory together with signature A generated by private key A of the hall data and signature B generated by private key B of the administrator (S46).This completes the digital key issuance process.

[0077] The digital key issued in FIG. 4B includes information indicating the unlocking conditions such as the validity period, usable time, and number of times the digital key can be used, as well as the administrator's public key B generated in S35.

[0078] (C) Authentication process in the first authentication device 300-1 4C is a diagram showing a processing sequence executed in the processing system 1 according to an embodiment of the present disclosure. Specifically, FIG. 4C shows a processing sequence executed between the first authentication device 300-1, the first server device 200-1, and the second server device 200-2 in order to authenticate a user by the first authentication method using first authentication information in the first authentication device 300-1. The processing in each device is executed by a processor executing a program stored in the memory of each device.

[0079] 4C, the card reader of the first authentication device 300-1 includes a communication interface capable of communicating via a short-range wireless communication method such as NFC. When an ID card 500-1 (FIG. 1) storing first authentication information (identification code) previously assigned to a user is brought close to the card reader of the first authentication device 300-1 (when the ID card 500-1 is located within the communication range of short-range wireless communication), the first authentication device 300-1 acquires the first authentication information from the ID card 500-1 via the card reader (S51). Note that, since the ID card 500-1 is used here, the first authentication information is acquired via a communication interface capable of communicating via short-range wireless communication. However, the acquisition method may be changed as appropriate depending on the type of first authentication information. For example, in the case of knowledge-based authentication (e.g., user memorization), the first authentication information may be acquired via an input interface such as a numeric keypad or keyboard. In the case of possession-based authentication (e.g., ID card, smartphone, QR code, license, or token), the first authentication information may be acquired via a communication interface such as a short-range wireless communication method or a wideband wireless communication method, a camera, or a sensor. In the case of biometric authentication (e.g., fingerprint, voice, iris, or face), the first authentication information may be acquired via a camera or a sensor.

[0080] The processor of the first authentication device 300-1 refers to the first authentication information previously stored in memory in the first authentication information pre-registration process of Fig. 4A and verifies whether there is any first authentication information that matches the first authentication information acquired from the ID card 500-1. If any of the first authentication information previously stored in memory matches the first authentication information acquired from the ID card 500-1, the processor of the first authentication device 300-1 authenticates the user by reading out the user ID information stored in memory in association with the matching first authentication information (S52).

[0081] Next, the processor of the first authentication device 300-1 refers to the authority information (FIGS. 3A and 3C) associated with the read user ID information. Specifically, the processor of the first authentication device 300-1 acquires the time when the first authentication information was acquired from the ID card 500-1 from the timer of the first authentication device 300-1. Then, the processor of the first authentication device 300-1 compares the acquired time with the time information of the facility (building 10) stored as the authority information, and determines whether the acquired time satisfies the available time (for example, 9:00 to 22:00 on weekdays by a combination of day of the week and time). If the acquired time satisfies the available time, the processor of the first authentication device 300-1 generates an unlocking signal to be transmitted to the locking / unlocking device 400, since authentication has been successful and the facility is available for use. The processor of the first authentication device 300-1 transmits the unlocking signal to the locking / unlocking device 400 via the communication interface. Although not shown in the figure, the locking / unlocking device 400, upon receiving the unlocking signal, transmits the unlocking signal to the gate connected to the locking / unlocking device 400, thereby opening the gate and allowing the user to enter the facility. In other words, the restriction on the user's use of the facility is lifted.

[0082] Furthermore, the processor of the first authentication device 300-1 generates an authorization log (first log) including locking / unlocking ID information for identifying the locking / unlocking device 400, user ID information of the authenticated user, information indicating that use of the facility is permitted, and unlocking time information which is the time related to the unlocking signal, and stores the log in memory (S53). In this way, whereas conventionally it was only possible to manage "who (the user identified by the user ID information) was authenticated on a certain day (information in days as time information)", it is now possible to acquire and manage information regarding the facility or its location that is permitted to be used from the locking / unlocking ID information, the user who is authenticated and permitted to use from the user ID information, and the detailed time that use was permitted from the unlocking time information.

[0083] Next, the processor 211 of the first server device 200-1 transmits a transmission request (T51) for the allowed log (first log) stored in the memory to the first authentication device 300-1 via the communication interface 213 at a predetermined interval. Then, upon receiving the transmission request for the allowed log (first log), the processor of the first authentication device 300-1 reads out the allowed log (T52: first log) stored in the memory and transmits it to the first server device 200-1 via the communication interface. Upon receiving the allowed log via the communication interface 213, the processor 211 of the first server device 200-1 stores the received allowed log (first log) in the memory 212 (S54). Note that the interval for transmitting the transmission request for the allowed log (first log) may be any of yearly, monthly, weekly, daily, hourly, minutely, and secondly intervals, and does not necessarily have to be set at a fixed interval. For example, the log may be transmitted once a day, or once every 12 hours on weekdays, and once a day on holidays. The cycles can be changed as desired by an administrator or the like. A transmission request for the allowed log (first log) is not necessarily required, and the allowed log (first log) may be transmitted every time the allowed log (first log) is stored in the first authentication device 300-1, or every time a predetermined amount of allowed logs (first logs) are stored in the first authentication device 300-1 or at predetermined intervals.

[0084] Furthermore, the processor 211 of the second server device 200-2 periodically transmits a transmission request (T53) for the permission log (first log) stored in memory to each server device, including the first server device 200-1 to which the first authentication device 300-1 is connected, via the communication interface 213. Upon receiving the transmission request for the permission log (first log), the processor 211 of the first server device 200-1 reads out the permission log (T54) stored in the memory 212 and transmits it to the second server device 200-2 via the communication interface 213. Upon receiving the permission log (first log) via the communication interface 213, the processor 211 of the second server device 200-2 identifies the log management table corresponding to the locking / unlocking device 400 based on the locking / unlocking ID information included in the received permission log (first log), stores the unlocking time information in association with the user ID information also included in the permission log (first log), and updates the entry / exit information (S55). The interval for transmitting the transmission request for the allowed log (first log) may be any of yearly, monthly, weekly, daily, hourly, and / or minutely, and does not necessarily have to be set at a fixed interval. For example, the allowed log may be transmitted once a day, or once every 12 hours on weekdays, and once a day on holidays. The interval can be changed as desired by an administrator or the like. The transmission request for the allowed log (first log) is not necessarily required. The allowed log (first log) may be transmitted each time a new allowed log (first log) is stored in the first server device 200-1, or may be transmitted each time a predetermined amount of allowed logs (first logs) are stored in the first server device 200-1 or at predetermined intervals. This completes the authentication process in the first authentication device 300-1.

[0085] (D) Authentication process in the second authentication device 300-2 4D and 4E are diagrams showing a processing sequence executed in the processing system 1 according to an embodiment of the present disclosure. Specifically, Fig. 4D and 4E show a processing sequence executed mainly between the second server device 200-2, the second authentication device 300-2, and the processing device 100 in order to authenticate a user by the second authentication method using second authentication information in the second authentication device 300-2. The processing in each device is executed by a processor running a program stored in the memory of each device.

[0086] (D-1) Authentication process using second authentication information According to FIG. 4D, the second authentication device 300-2 includes a sensor (camera) for acquiring facial features of the user. The processor of the second authentication device 300-2 activates the camera by detecting a user's operation input via an input interface, for example. When the processor of the second authentication device 300-2 detects the user's face within the camera's field of view, it acquires a facial image of the user as second authentication information used in the second authentication method (S61). While facial features are used as the second authentication information, the features may be calculated by the second authentication device 300-2 or the second server device 200-2. In this embodiment, the second authentication information includes not only facial features but also the facial image itself and data after image processing for calculating the facial features. Although the above description uses a sensor (camera) to acquire a facial image or facial features as the second authentication information, the acquisition method may be changed as appropriate depending on the type of second authentication information. For example, in the case of knowledge-based authentication (e.g., memorization by a user), the second authentication information may be acquired via an input interface such as a numeric keypad or keyboard. Also, in the case of possession-based authentication (e.g., ID card, smartphone, QR code, license, token, etc.), the second authentication information may be acquired via a communication interface such as a short-range wireless communication method or a wideband wireless communication method, a camera, or a sensor. Also, in the case of biometric-based authentication (e.g., fingerprint, voice, iris, face, etc.), the second authentication information may be acquired via a camera or a sensor.

[0087] When the processor of the second authentication device 300-2 acquires the second authentication information, it transmits the acquired second authentication information (S61) to the second server device 200-2 via the communication interface. When the processor 211 of the second server device 200-2 receives the second authentication information via the communication interface 213, it accesses the database of the authentication management unit and performs authentication using the second authentication method by checking whether the database contains the corresponding second authentication information (S62). Specifically, the processor 211 of the second server device 200-2 checks whether there is user ID information that matches the second authentication information received from the second authentication device 300-2 by checking the second authentication information stored in advance in the user management table by processing such as S24 of FIG. 4B. If there is no match, the processor 211 of the second server device 200-2 cancels subsequent processing, regarding the authentication as a failure.

[0088] On the other hand, if a match is found, the processor 211 of the second server device 200-2 accesses the database of the authority management unit and refers to the authority information (FIGS. 3A and 3C) previously stored in the user management table by processing such as S22 of FIG. 4B to determine whether the corresponding user ID information is included (S63). Specifically, the processor 212 of the second server device 200-2 identifies the user ID information associated with the matching second authentication information and refers to the authority information associated with the user ID information in the user management table. The processor 212 of the second server device 200-2 compares the current time acquired from the timer with the time information of the facility (building 10) stored as the authority information and determines whether the acquired time satisfies the available time (e.g., 9:00 to 22:00 on weekdays, based on a combination of day of the week and time). If the acquired time satisfies the available time, the processor 212 of the second server device 200-2 determines that the facility (building 10) is available for use.

[0089] When the processor 212 of the second server device 200-2 determines that the facility (building 10) is permitted to be used based on the authority information, the processor 212 accesses the database of the permission information management unit and refers to the permission information (FIGS. 3A and 3C) previously stored in the user management table by processing such as S22 of FIG. 4B (S64). Specifically, the processor 212 of the second server device 200-2 reads out the permission information including the first authentication information (identification code) associated with the user ID information associated with the matched second authentication information.

[0090] The processor 212 of the second server device 200-2 transmits the permissible information (T61) read from the permissible information management unit to the second authentication device 300-2 via the communication interface 213. When the processor of the second authentication device 300-2 receives the permissible information via the communication interface, it stores the permissible information in its own memory (S65). This completes the authentication process using the second authentication information. Note that the permissible information is transmitted from the second authentication device 300-2 to the processing device 100 as shown in T91 of FIG. 4E, and therefore it is sufficient that the permissible information is stored at least temporarily for this transmission.

[0091] 4D, the above processes are executed by the authentication unit, the authority management unit, and the permission information management unit in the second server device 200-2. However, for example, the second server device 200-2 may be configured by a server device that executes each of the functional units, and each functional unit may be distributed and executed by the server device.

[0092] In the above, the second server device 200-2 receives the authority information, first authentication information, and second authentication information from the second authentication device 300-2 in advance, thereby allowing the second server device 200-2 to execute each function. Among the information used when executing each function, the second authentication information and authority information in particular may be frequently updated. In such a case, when executing each function in the second server device 200-2, the information can be easily updated to the latest information, and authentication and other processes can be performed using the updated latest information. On the other hand, the authority information, first authentication information, and second authentication information can also be stored in the second authentication device 300-2, and the above-mentioned functions can be executed by the second authentication device 300-2. In such a case, the need for communication with the second server device 200-2 is low, allowing for more flexible response to problems such as a deterioration in the communication environment.

[0093] (D-2) Encryption processing for short-range wireless communication The encryption process for near field wireless communication is a process for performing encryption to establish more secure near field wireless communication between the second authentication device 300-2 and the processing device 100. One example of this is a Diffie-Hellman key sharing scheme in which the second authentication device 300-2 and the processing device 100 exchange public keys generated by each other to generate a common symmetric key. As shown in FIG. 4D, the processor of the second authentication device 300-2 detects the processing device 100 by receiving a signal transmitted at a predetermined interval from the processing device 100 to which the second authentication device 300-2 is to be connected (S71). Upon detecting the processing device 100, the processor of the second authentication device 300-2 transmits a connection request (T71) to the processing device 100 via the communication interface.

[0094] When the processor 111 of the processing device 100 receives the connection request via the second communication interface 114, it permits connection with the second authentication device 300-2 (S72). Then, the processor 111 of the processing device 100 generates a private key C of the processing device 100 and a public key C of the processing device 100 that are unique for communication with the second authentication device 300-2 according to a public cryptosystem (S73). The processor 111 of the processing device 100 stores the generated private key C of the processing device 100 in the memory 112 (S74), and transmits the public key C (T72) of the processing device 100 to the second authentication device 300-2 via the second communication interface 214 (at this time, it also transmits information that the connection is permitted). When the processor of the second authentication device 300-2 receives the public key C of the processing device 100 via the communication interface, it saves the public key C of the processing device 100 in its own memory (S75).

[0095] Next, the processor of the second authentication device 300-2 generates a private key D of the second authentication device 300-2 and a public key D of the second authentication device 300-2 that are unique for communication with the processing device 100 according to a public encryption method (S76). The processor of the second authentication device 300-2 generates a common key C using the generated private key D of the second authentication device 300-2 and the public key C of the processing device 100 received from the processing device 100 (S77). The processor of the second authentication device 300-2 stores the generated private key D of the second authentication device 300-2 and the common key C generated by the second authentication device 300-2 in its own memory (S78). The processor of the second authentication device 300-2 encrypts any information with the common key C (S79), and then transmits the encrypted information and the public key D of the second authentication device 300-2 (T73) to the processing device 100 via the communication interface. When the processor 111 of the processing device 100 receives the public key D of the second authentication device 300-2 via the second communication interface 114, the processor 111 stores the received public key D in the memory 112 (S80).

[0096] Next, the processor 111 of the processing device 100 generates a common key C using the private key C of the processing device 100 generated in S73 and the public key D of the second authentication device 300-2 received from the second authentication device 300-2 (S81). The processor 111 of the processing device 100 decrypts the encrypted information received from the second authentication device 300-2 using the common key C generated by the processing device 100 (S82). If the encrypted information can be decrypted using the common key C generated by the processing device 100, the processor 111 of the processing device 100 generates decryption result information indicating that the common keys C generated by the second authentication device 300-2 and the processing device 100 are the same (i.e., shared), and that the decryption was successful. The processor 111 of the processing device 100 encrypts the decryption result information using the common key C generated by the processing device 100, and then transmits the encrypted decryption result information to the second authentication device 300-2 via the second communication interface 114. This makes it possible to encrypt each piece of information sent and received in communication between the second processing device 300-2 and the processing device 100 using the common key C, thereby improving the security of communication. This completes the encryption process.

[0097] (D-3) Digital key authentication process The digital key authentication process is a process for authenticating the connection source between the second authentication device 300-2 and the processing device 100. According to Fig. 4E, when the second authentication device 300-2 receives the decryption result information in Fig. 4D, it reads out the digital key stored in S46 of Fig. 4B together with signature A based on private key A of the hall data and signature B based on private key B of the administrator in order to transmit the digital key to the processing device 100 (S91). Then, the processor of the second authentication device 300-2 transmits the read digital key, signature A based on private key A of the hall data, and signature B based on private key B of the administrator (T91) to the processing device 100 via the communication interface. Note that the digital key has been encrypted with common key A of the hall data in S43 of Fig. 4B.

[0098] When the processor 111 of the processing device 100 receives the digital key, signature A based on private key A of the hole data, and signature B based on private key B of the administrator via the second communication interface 114, it decrypts the digital key using the common key A of the processing device 100 stored in S34 of Fig. 4B (S92). When the digital key is decrypted, the processor 111 of the processing device 100 verifies signature A based on private key A of the hole data using public key A of the hole data that was previously set in the hole data of the processing device 100 and stored in S34 of Fig. 4B. If the signature verification is successful, the processor 111 of the processing device 100 verifies signature B using the administrator's private key B using the administrator's public key B that was previously set for the administrator and obtained as included in the digital key (S94). When the verification of each signature is successful, the processor 111 of the processing device 100 generates authentication result information indicating that the signature verification has ended and the authentication of the digital key has been successful, and transmits the authentication result information (T92) encrypted with the common key C generated by the processing device 100 to the second authentication device 300-2 via the second communication interface 114. Here, when the authentication of the digital key is successful, the processor 111 of the processing device 100 becomes ready to accept commands from the second authentication device 300-2.

[0099] When the processor of the second authentication device 300-2 receives the authentication result information via the communication interface, it encrypts the allowable information received in S65 of Fig. 4D with the common key C generated by the second authentication device 300-2 (S95), and transmits the encrypted allowable information (T93) via the communication interface to the processing device 100 as an unlocking request. When the processor 111 of the processing device 100 receives the encrypted allowable information via the second communication interface 114, it decrypts the allowable information using the common key C generated by the processing device 100. Then, the processor 111 of the processing device 100 transmits the decrypted allowable information to the first authentication device 300-1 via the first communication interface 113.

[0100] When the processor of the first authentication device 300-1 receives the permission information from the processing device 100, it acquires an identification code (first authentication information) that may be included in the permission information. Subsequent processing is executed in the same manner as in FIG. 4C , although not shown. Specifically, the processor of the first authentication device 300-1 refers to the first authentication information previously stored in memory in the first authentication information pre-registration processing of FIG. 4A, and verifies whether there is any first authentication information that matches the first authentication information acquired from the processing device 100. Then, if any of the first authentication information previously stored in memory matches the first authentication information acquired from the processing device 100, the processor of the first authentication device 300-1 authenticates the user by reading out user ID information stored in memory in association with the matching first authentication information.

[0101] Next, the processor of the first authentication device 300-1 refers to the authority information (FIGS. 3A and 3C) associated with the read user ID information. Specifically, the processor of the first authentication device 300-1 acquires the time when the first authentication information was acquired from the processing device 100 from the timer of the first authentication device 300-1. Then, the processor of the first authentication device 300-1 compares the acquired time with the time information of the facility (building 10) stored as the authority information, and determines whether the acquired time satisfies the available time (for example, a combination of day of the week and time, such as 9:00 to 22:00 on weekdays). If the acquired time satisfies the available time, the processor of the first authentication device 300-1 generates an unlocking signal to be transmitted to the locking / unlocking device 400, since authentication has been successful and the facility is available for use. The processor of the first authentication device 300-1 transmits the unlocking signal to the locking / unlocking device 400 via the communication interface. Although not shown in the figure, the operation of the locking / unlocking device 400 upon receiving the unlock signal is the same as that described with reference to FIG. 4C.

[0102] Furthermore, the processor of the first authentication device 300-1 generates an authorization log (second log) including locking / unlocking ID information for identifying the locking / unlocking device 400, user ID information of the authenticated user, information indicating that use of the facility is permitted and unlocking time information which is the time related to the unlocking signal, and stores the log in memory. After the authorization log (second log) is stored, the authorization log (second log) is transmitted to the first server device 200-1 and the second server device 200-2, and the operations when the authorization log is acquired and managed in the first server device 200-1 and the second server device 200-2 are also similar to those described in Fig. 4C.

[0103] 4D and 4E, the identification code (first authentication information) itself is read out as a result of authentication by the second authentication device 300-2 and transmitted to the processing device 100 as the permission information, but the identification code does not necessarily have to be used. For example, the permission information may include the user ID information of the user authenticated by the second authentication device 300-2 and information indicating that the authentication of the user has been successful, and be transmitted to the processing device 100. This allows the first authentication device 300-1 to perform authentication using the first authentication method based on whether or not the user ID information has been stored in advance.

[0104] 7. Example of a use case for Processing System 1 The processing system 1 that performs the processing as described above is typically used in the following use cases: However, the use cases shown below are merely examples, and the use cases are not limited to the following.

[0105] (A) Employee authentication It is assumed that an administrator of a company that resides in building 10 with restricted use or an administrator of building 10 registers employees of the company as users. In this case, an identification code is stored as first authentication information on an employee ID card and distributed to the employee in advance. When the employee brings the employee ID card close to a card reader, which is the first authentication device, authentication using the identification code is performed, and the employee is authenticated. If the employee is successfully authenticated, a gate installed at the entrance to building 10 opens, and the employee is permitted to enter building 10 (i.e., is permitted to use building 10).

[0106] In addition, in order to provide the employee with various authentication methods, the administrator issues a usage permit to the employee in advance as the employee's second authentication information. Specifically, the usage permit is stored in a user terminal device (smartphone) that the employee can use. Then, when the employee brings the smartphone close to the second authentication device, authentication using the usage permit is performed, and the employee is authenticated. If the authentication of the employee is successful, an identification code (first authentication information) previously associated with the employee is provided to the first authentication device via the processing device 100. Then, authentication using the identification code is performed, and the employee is authenticated. If the authentication of the employee is successful, a gate installed at the entrance of the building 10 opens, and the employee is permitted to enter the building 10 (i.e., is permitted to use the building 10).

[0107] Although not specifically described, the processing system 1 can be used not only for the combination of building 10 and employees, but also for apartment buildings and their residents, event facilities and their users, or cars and their users, etc.

[0108] (B) Authenticating a service provider It is assumed that a resident of an apartment complex with restricted use may register, for example, a parcel delivery person as a user to temporarily allow them to use the complex. In this case, a PIN number to be entered into the numeric keypad of an auto-locking device (first authentication device) of the apartment complex is provided to the delivery person in advance as first authentication information. When the delivery person enters the PIN number into the auto-locking device, which is the first authentication device, authentication using the PIN number is performed, and the delivery person is authenticated. If the authentication of the delivery person is successful, the entrance door of the apartment complex opens, and the delivery person is allowed to enter the apartment complex (i.e., is allowed to use the apartment complex).

[0109] In addition, to provide the deliverer with various authentication methods, the resident issues a usage permit to the deliverer in advance as the second authentication information for the deliverer. Specifically, the usage permit is stored in a user terminal device (smartphone) that the deliverer can use. Then, when the deliverer brings the smartphone close to the second authentication device, authentication using the usage permit is performed, and the deliverer is authenticated. If the authentication of the deliverer is successful, a PIN number (first authentication information) previously associated with the deliverer is provided to the first authentication device via the processing device 100. Then, authentication using the PIN number is performed, and the deliverer is authenticated. If the authentication of the deliverer is successful, the entrance door to the apartment building opens, and the deliverer is permitted to enter the apartment building (i.e., is permitted to use the apartment building).

[0110] Although not specifically described, the processing system 1 can be used not only for combinations of apartment buildings and delivery people, but also for visitors who have been registered by the building 10 and its employees.

[0111] As described above, this embodiment provides a processing device, processing program, and processing method that enable more efficient user authentication. In particular, by retrofitting a second authentication device 300-2 or the like that performs authentication using a second authentication method in addition to the pre-installed first authentication device 300-1 via the processing device 100, more flexible equipment expansion is possible. Furthermore, users can also use a second authentication method other than the first authentication method, enabling more flexible authentication. Furthermore, when acquiring an allowance log in the first authentication device 300-1, it is normally difficult to reflect the results of authentication performed by a different authentication device, such as the second authentication device 300-2. However, by having the second server device 200-2 acquire the allowance log via the first server device 200-1, the second server device 200-2 can centrally manage the allowance logs of not only the first authentication device 300-1 but also the second authentication device 300-2. Furthermore, by collecting log information that includes not only the time of authentication and user information but also information on the equipment that was authenticated, it becomes possible to manage more detailed information such as when, who, and where authentication was performed. Furthermore, when authentication is performed using the second authentication information, authentication is performed by the first authentication device 300-1 in addition to authentication by the second authentication device 300-2, which makes it possible to further improve safety, authenticity of authentication, and confidentiality. In other words, by undergoing multiple authentications, it is possible to improve the authenticity of "who can enter and exit where," and by using multiple authentication means, it is possible to further improve confidentiality for areas with high security levels.

[0112] 8.Other In the above embodiment, a case has been described in which only the locking / unlocking device 400 is controlled via the first authentication device 300-1. However, the object to be controlled is not limited to the locking / unlocking device 400, and it is also possible to control a wider variety of devices. Fig. 5 is a block diagram showing the configuration of a processing system 1000 according to an embodiment of the present disclosure. Specifically, Fig. 5 shows the configuration of the processing system 1000 including an elevator 400-2 and a gateway 600 in addition to the locking / unlocking device 400-1.

[0113] 5, as described above, the processing system 1000 includes the elevator 400-2 in addition to the locking / unlocking device 400-1. The elevator 400-2 is communicably connected to the first server device 200-1 via a communication network. Note that the other components are the same as those of the processing system 1 in FIG. 1.

[0114] FIG. 6 is a diagram conceptually illustrating a user management table stored in the second server device 200-2 according to an embodiment of the present disclosure. In addition to the information stored in the user management table shown in FIG. 3A, the user management table stores control information associated with user ID information. The "control information" is information for controlling the elevator 400-2. For example, for a user with user ID information "A1," the control information stores call information for calling the elevator hall nearest to the gate for an elevator capable of transporting the user to the 8th floor of building 10, and destination information indicating the "8th floor," which is the elevator's usual destination. Such control information is stored, for example, by receiving it from an administrator terminal device available to the administrator together with a user registration request. Note that other information is the same as that shown in FIG. 3A.

[0115] 7A is a diagram showing a processing sequence executed in the processing system 1000 according to an embodiment of the present disclosure. Specifically, FIG. 7A shows a processing sequence executed between the first authentication device 300-1, the first server device 200-1, and the second server device 200-2 in order to register, in the first authentication device 300-1, first authentication information used for authenticating a user using a first authentication method in the first authentication device 300-1. The processing in each device is executed by a processor executing a program stored in the memory of each device.

[0116] 7A, the processor 211 of the second server device 200-2 receives a user registration request for a new user via the communication interface 213 from an administrator terminal device available to the administrator. The user registration request includes attribute information, authority information, and control information of the user who wishes to register. The attribute information includes, for example, the user's name (first and last name), title, nickname, career history, contact information such as a telephone number and email address, the address of the company to which the user belongs, the name of the company, and the name of the department to which the user belongs. The authority information includes information indicating the time and location at which the facility can be used, which is set in advance for the user by the administrator. The control information is information for controlling the elevator 400-2, and includes call information for calling an elevator capable of transporting a user to a specified floor in building 10 to the elevator hall nearest to the gate, and destination information indicating the floor to which the elevator normally transports users.

[0117] When the processor 211 of the second server device 200-2 receives a user registration request, it generates new user ID information (S71). Then, the processor 211 of the second server device 200-2 associates the generated user ID information with the received attribute information and authority information in a user management table and stores the received control information associated with the user ID information in the user management table (S72), and also stores the received control information associated with the user ID information in the user management table (S73). The processor 211 of the second server device 200-2 also generates an identification code, which is information unique to the user, as first authentication information for newly authenticating the user, and stores the identification code in the user management table in association with the user ID information (S74). At a predetermined timing, the processor 211 of the second server device 200-2 transmits each user ID information stored in the user management table, the first authentication information (T71), authority information, and control information associated with each user ID information, to the first server device 200-1 via the communication interface 213.

[0118] When the processor 211 of the first server device 200-1 receives each piece of user ID information and the first authentication information, authority information, and control information associated with each piece of user ID information from the second server device 200-2 via the communication interface 213, the processor 211 stores the received information in the memory 212 (S75). Then, at a predetermined timing, the processor 211 of the first server device 200-1 transmits each piece of user ID information and the first authentication information (T72) and authority information associated with each piece of user ID information to the first authentication device 300-1 via the communication interface 213.

[0119] When the processor of the first authentication device 300-1 receives each piece of user ID information and the first authentication information and authority information associated with each piece of user ID information from the first server device 200-1 via the communication interface, it stores the received information in memory (S76). The received information is used when authentication is performed by the first authentication device using the first authentication method. This completes the pre-registration process of the first authentication information.

[0120] 7B is a diagram showing a processing sequence executed in the processing system 1000 according to an embodiment of the present disclosure. Specifically, FIG. 7B shows a processing sequence executed between the first authentication device 300-1, the first server device 200-1, and the second server device 200-2 in order to authenticate a user by the first authentication method using first authentication information in the first authentication device 300-1. The processing in each device is executed by a processor executing a program stored in the memory of each device.

[0121] 7B, the process shown in FIG. 4C or 4D acquires first identification information (identification code) from the ID card 500-1 or permission information including the identification code that is the first identification information from the processing device 100 (S81). The processor of the first authentication device 300-1 refers to the first authentication information previously stored in memory in the first authentication information pre-registration process of FIG. 7A, and verifies whether there is any first authentication information that matches the first authentication information acquired from the ID card 500-1 or the processing device 100. Then, if any of the first authentication information previously stored in memory matches the first authentication information acquired from the ID card 500-1 or the processing device 100, the processor of the first authentication device 300-1 authenticates the user by reading out user ID information stored in memory in association with the matching first authentication information (S82).

[0122] Next, the processor of the first authentication device 300-1 refers to the authority information associated with the read user ID information. The specific processing is the same as the processing shown in FIG. 4C. If the processor of the first authentication device 300-1 can confirm the authority, it generates an unlocking signal to be sent to the locking / unlocking device 400-1. The processor of the first authentication device 300-1 sends the unlocking signal to the locking / unlocking device 400-1 via a communication interface. Although not specifically shown, upon receiving the unlocking signal, the locking / unlocking device 400-1 sends the unlocking signal to a gate connected to the locking / unlocking device 400-1, which opens the gate and allows the user to enter the facility. In other words, the restriction on the user's use of the facility is lifted.

[0123] In addition, the processor of the first authentication device 300-1 generates an authorization log including locking / unlocking ID information for identifying the locking / unlocking device 400-1, user ID information of the authenticated user, information indicating that use of the facility is permitted, and unlocking time information which is the time related to the unlocking signal, and stores the log in memory (S83).

[0124] Next, the processor 211 of the first server device 200-1 transmits a transmission request (T81) for the tolerance log stored in memory to the first authentication device 300-1 at a predetermined interval via the communication interface 213. Then, when the processor of the first authentication device 300-1 receives the transmission request for the tolerance log, it reads out the tolerance log (T82) stored in memory and transmits it to the first server device 200-1 via the communication interface. When the processor 211 of the first server device 200-1 receives the tolerance log via the communication interface 213, it stores the received tolerance log in the memory 212 (S84). The interval for transmitting the transmission request for the tolerance log and whether or not a transmission request for the tolerance log is sent are the same as those in FIG. 4C.

[0125] Furthermore, after storing the permission log in S84, the processor 211 of the first server device 200-1 reads the control information stored in S75 of FIG. 7A based on the user ID information included in the received permission information. Then, the processor 211 of the first server device 200-1 transmits the control information read via the communication interface 213 to the elevator 400-2, which is the device to be controlled, via the gateway 600. Upon receiving the control information, the elevator 400-2 calls an elevator capable of transporting the user to a specified floor in building 10 to the elevator hall nearest to the gate based on the received control information, and presets the floor number that is the normal destination for the elevator. Specifically, for example, in the case of a user with user ID information "A1," an elevator capable of transporting the user to the 8th floor of building 10 is called to the elevator hall nearest to the gate, and presets the "8th floor" as the normal destination for the elevator.

[0126] The processor 211 of the second server device 200-2 periodically transmits a transmission request (T83) for the permission log stored in memory to each server device, including the first server device 200-1 to which the first authentication device 300-1 is connected, via the communication interface 213. Upon receiving the transmission request for the permission log, the processor 211 of the first server device 200-1 reads the permission log (T84) stored in the memory 212 and transmits it to the second server device 200-2 via the communication interface 213. Upon receiving the permission log via the communication interface 213, the processor 211 of the second server device 200-2 identifies the log management table corresponding to the locking / unlocking device 400 based on the locking / unlocking ID information included in the received permission log, stores the unlocking time information in association with the user ID information also included in the permission log, and updates the entry / exit information (S85). The transmission request for the permission log and whether or not a transmission request for the permission log is issued are the same as those in FIG. 4C .

[0127] Although not particularly shown, the pre-registration process of the second authentication information and the authentication process in the second authentication device 300-2 are executed in the same manner as in FIGS. 4B and 4D.

[0128] 5 to 7B, elevator 400-2 is shown as an example of a device to be controlled, but other devices can also be added. For example, other automatic doors, gates, air conditioning equipment, lighting equipment, etc. inside building 10 can also be processed in the same way.

[0129] As described above, this embodiment provides a processing device, processing program, and processing method that enable more efficient user authentication. In particular, by retrofitting a second authentication device 300-2 or the like that performs authentication using a second authentication method in addition to the pre-installed first authentication device 300-1 via the processing device 100, more flexible equipment expansion is possible. Furthermore, users can also use a second authentication method other than the first authentication method, enabling more flexible authentication. Furthermore, when acquiring an allowance log in the first authentication device 300-1, it is normally difficult to reflect the results of authentication performed by a different authentication device, such as the second authentication device 300-2. However, by having the second server device 200-2 acquire the allowance log via the first server device 200-1, the second server device 200-2 can centrally manage the allowance logs of not only the first authentication device 300-1 but also the second authentication device 300-2. Furthermore, by collecting log information that includes not only the time of authentication and user information but also information about the equipment that was authenticated, it becomes possible to manage more detailed information such as when, who, and where authentication was performed. Furthermore, when authentication is performed using the second authentication information, authentication is performed by the first authentication device 300-1 in addition to authentication by the second authentication device 300-2, which makes it possible to further improve safety and authentication accuracy. Furthermore, by authenticating the user in addition to these, it becomes possible to control in advance the equipment that is expected to be used next (e.g., elevator 400-2), allowing the user to use each equipment more efficiently.

[0130] The processes and procedures described herein can be realized not only by those explicitly described in the embodiments, but also by software, hardware, or a combination thereof. Specifically, the processes and procedures described herein can be realized by implementing logic corresponding to the processes in media such as integrated circuits, volatile memory, nonvolatile memory, magnetic disks, and optical storage. Furthermore, the processes and procedures described herein can be implemented as computer programs and executed by various computers, including processing devices and server devices.

[0131] Although processes and procedures described herein are described as being performed by a single device, software, component, or module, such processes or procedures may be performed by multiple devices, multiple software, multiple components, and / or multiple modules. Furthermore, although various information described herein is described as being stored in a single memory or storage unit, such information may be stored in multiple memories within a single device or multiple memories distributed across multiple devices. Furthermore, software and hardware elements described herein may be realized by integrating them into fewer components or by decomposing them into more components. [Explanation of symbols]

[0132] 1 Processing System 10 Building 100 Processing equipment 200 Server device 200-1 First server device 200-2 Second server device 300-1 First authentication device 300-2 Second authentication device 400 Locking and unlocking device 500-1 ID card 500-2 User terminal device 1000 Processing Systems 400-1 Locking and unlocking device 400-2 Elevator 600 Gateway

Claims

1. A processing system including a server device and a processing device, the server device receives first log information indicating that the user has been authenticated from a first authentication device that is installed in a facility where user use is restricted and that executes a process of authenticating the user by a first authentication method using the first authentication information upon receiving an authentication request from the user using the first authentication information in order to determine whether or not the user is permitted to use the facility; a second authentication device different from the first authentication device outputs, to the processing device, allowance information generated by authenticating the user by a second authentication method different from the first authentication method; When the processing device receives the permission information output from the second authentication device, the processing device transmits the permission information to the first authentication device; the server device receives second log information from the first authentication device, the second log information indicating that the user has been authenticated due to the first authentication device accepting the permission information; the first log information and the second log information are stored in the server device; a processing system configured to perform processing for

2. The processing system of claim 1 , wherein the permission information is the same as the first authentication information.

3. The processing system according to claim 1 , wherein the permission information is unique information previously assigned to the user.

4. The processing system of claim 1, wherein the permission information is transmitted in advance to the second authentication device from a second server device connected to the second authentication device via a communication network, and is also transmitted in advance to the first authentication device via a first server device different from the second server device.

5. The processing system according to claim 1 , wherein the second authentication method is a method using second authentication information different from the first authentication information.

6. the processing device includes a first communication interface configured to communicatively couple with the first authentication device and a second communication interface configured to receive the acceptance information from the second authentication device; The processing system according to claim 1 , wherein the second communication interface uses a communication method different from the communication method used by the first communication interface.

7. The processing system of claim 6 , wherein the second communication interface communicates via short-range wireless communication.

8. The processing system according to claim 7 , wherein the short-range wireless communication in the second communication interface includes encryption processing.

9. The processing system according to claim 1 , wherein the first authentication device authorizes the user to use the system based on the reception of the authorization information.

10. The processing system according to claim 1 , wherein the processing device is installed in the facility by retrofitting the first authentication device that has already been installed in the facility.

11. The processing system according to claim 6 , wherein the processing system is connected to the first authentication device by serial communication via the first communication interface.

12. The processing system of claim 1 , wherein the first log information and the second log information are transmitted from the first authentication device to the server device via another server device that is communicatively connected to the first authentication device and is different from the server device.

13. the server device and the other server device are managed by different administrators, The processing system according to claim 12 , wherein the first log information and the second log information are transmitted from the first authentication device to the server device via the other server device in response to a request from an administrator who manages the server device.

14. The processing system according to claim 12 , wherein the first log information and the second log information include at least one of information indicating equipment that the user is permitted to use and information indicating the time that the user is permitted to use.

15. a processing system including a server device and a processing device, the server device receives first log information indicating that the user has been authenticated from a first authentication device that is installed in a facility where user use is restricted and that executes a process of authenticating the user by a first authentication method using the first authentication information upon receiving an authentication request from the user using the first authentication information in order to determine whether or not the user is permitted to use the facility; a second authentication device different from the first authentication device outputs, to the processing device, allowance information generated by authenticating the user by a second authentication method different from the first authentication method; When the processing device receives the permission information output from the second authentication device, the processing device transmits the permission information to the first authentication device; the server device receives second log information from the first authentication device, the second log information indicating that the user has been authenticated due to the first authentication device accepting the permission information; the first log information and the second log information are stored in the server device; A processing program that functions to perform processing for the purpose.

16. A processing method executed in a processing system including a server device and a processing device, a step in which the server device receives first log information indicating that the user has been authenticated from a first authentication device that is installed in a facility where user use is restricted and that executes a process of authenticating the user by a first authentication method using the first authentication information upon receiving an authentication request from the user using the first authentication information in order to determine whether or not the user is permitted to use the facility; outputting, by a second authentication device different from the first authentication device, acceptance information generated by authenticating the user by a second authentication method different from the first authentication method, for providing to the processing device; a step of transmitting the permission information to the first authentication device by the processing device upon receiving the permission information output from the second authentication device; receiving, by the server device, second log information from the first authentication device, which indicates that the user has been authenticated due to the first authentication device accepting the permission information; storing the first log information and the second log information in the server device; A processing method comprising:

Citation Information

Patent Citations

  • Ticket gate management system

    JP2010086479A

  • Entry / exit control system

    JP2020042440A

  • Wireless communication system, non-temporary computer-readable medium in which connection authentication program is stored and connection authentication method

    WO2016084274A1

  • Authentication system and authentication method

    WO2022208598A1