User identification system and user identification method

The user identification system improves vehicle occupant identification by associating on-board device IDs with mobile terminal IDs and dynamic passwords, addressing security gaps in existing vehicle entry/exit systems.

JP7785876B2Active Publication Date: 2025-12-15KK TOSHIBA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024137771
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-08-19
Publication Date
2025-12-15
Estimated Expiration
2036-08-02

AI Technical Summary

Technical Problem

Existing systems that use on-board unit IDs for vehicle entry/exit control cannot accurately identify individuals within the vehicle, posing security risks in high-security areas.

Method used

A user identification system that utilizes an on-board device ID matching device to identify a mobile terminal ID carried by the vehicle occupant, combined with a facility variable password and mobile terminal password for enhanced authentication, ensuring accurate identification of individuals.

Benefits of technology

The system provides higher accuracy in identifying individuals within a vehicle by requiring proximity of the mobile terminal to the vehicle and using dynamic facility passwords, thereby enhancing security and preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007785876000001
    Figure 0007785876000001
  • Figure 0007785876000002
    Figure 0007785876000002
  • Figure 0007785876000003
    Figure 0007785876000003
Patent Text Reader

Abstract

To provide an entry / exit system and an entry / exit control method, capable of identifying a person in a vehicle with higher accuracy.SOLUTION: An entry / exit system of an embodiment includes an on-vehicle unit ID collation device, an entry / exit management device and an entry / exit roadside device. An information control unit of the on-vehicle unit ID collation device identifies a portable terminal ID of a portable terminal possessed by a person riding on a vehicle on the basis of an on-vehicle unit ID as identification information for an on-vehicle unit of the vehicle entering the entry / exit system, and transmits the portable terminal ID to the entry / exit management device. An authentication processing unit of the entry / exit management device executes authentication processing on collation information received by the entry / exit management device. An entry / exit control unit of the entry / exit roadside device determines opening or closing of the entry / exit control unit on the basis of the result of the authentication processing.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] FIELD An embodiment of the present invention relates to a user identification system and a user identification method. [Background technology]

[0002] Previously, there were systems that used the on-board unit ID transmitted from ETC on-board units to control the opening and closing of entry / exit control units in apartment buildings and commercial facilities. However, since the on-board unit ID transmitted from the on-board unit is an ID associated with the vehicle, it was not possible to accurately identify the people inside the vehicle. As a result, these systems could not be used in places where high security was required. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2005-227996 [Patent Document 2] Japanese Patent Application Laid-Open No. 2009-294310 [Non-patent literature]

[0004] [Non-Patent Document 1] "Apartment Parking Lot (Apartment ETC System)", [online], [searched May 24, 2016], Internet<URL:http: / / www.furuno.com / jp / dsrc / case / enter_leave / > Summary of the Invention [Problem to be solved by the invention]

[0005] The problem to be solved by the present invention is to provide a user identification system and a user identification method that can identify a person in a vehicle with higher accuracy. [Means for solving the problem]

[0006] The entry / exit system of the embodiment has an on-board device ID matching device, an entry / exit management device, and an entry / exit roadside device. The information control unit of the on-board device ID matching device identifies the mobile terminal ID of the mobile terminal carried by a person riding in a vehicle that has entered the entry / exit system based on the on-board device ID, which is identification information of the on-board device of the vehicle, and transmits the mobile terminal ID to the entry / exit management device. The entry / exit management device authentication processing unit performs authentication processing on the matching information received by the entry / exit management device. The entry / exit control unit of the entry / exit roadside device determines whether to open or close the entry / exit restriction unit based on the result of the authentication processing. [Brief explanation of the drawings]

[0007] [Figure 1] 1 is a schematic diagram showing a specific application example of the entrance / exit system 1 of the first embodiment. [Figure 2] FIG. 1 is a system configuration diagram showing the system configuration of an entrance / exit system 1. [Figure 3] 2 is a schematic block diagram showing the functional configuration of the vehicle-mounted device 100. [Figure 4] FIG. 5 is a schematic block diagram showing the functional configuration of a mobile terminal 500. [Figure 5] FIG. 2 is a sequence diagram showing the flow of processing in the entrance / exit system 1 according to the first embodiment. [Figure 6] FIG. 10 is a system configuration diagram showing the system configuration of an entrance / exit system 2 according to a second embodiment. [Figure 7] FIG. 10 is a sequence diagram showing the flow of processing until a business operator registers an in-vehicle device ID, a facility ID, and a mobile terminal ID in association with each other in the entrance / exit system 2 according to the second embodiment. [Figure 8] FIG. 10 is a sequence diagram showing the flow of processing in the entrance / exit system 2 according to the second embodiment. [Figure 9] FIG. 10 is a system configuration diagram showing the system configuration of an entrance / exit system 3 according to a third embodiment. [Figure 10] FIG. 11 is a sequence diagram showing a processing flow until the use of an in-vehicle device ID and a mobile terminal ID is started in the entry / exit system 3 according to the third embodiment. [Figure 11]FIG. 11 is a sequence diagram showing the flow of processing by the entrance / exit system 3 in the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0008] Hereinafter, an entrance / exit system and an entrance / exit control method according to an embodiment will be described with reference to the drawings.

[0009] (First embodiment) Fig. 1 is a schematic diagram showing a specific application example of the first embodiment of the entrance / exit system 1. In Fig. 1, the entrance / exit system 1 is a system that controls the entrance / exit of a vehicle using an in-vehicle device 100 mounted on the vehicle. 1, a facility 10 is surrounded by a fence or the like. An entrance / exit roadside device 200 and an entrance / exit control device 600 are installed at the entrance / exit of the facility 10. An in-vehicle ID matching device 300 and an entrance / exit management device 400 are connected to the entrance / exit roadside device 200 via a network 700. A mobile terminal 500 is carried by a driver of the vehicle or the like.

[0010] The vehicle-mounted device ID verification device 300 is, for example, a dedicated information processing device managed by an external organization such as a government. The entry / exit management device 400 is an information processing device that stores an authentication information table that associates mobile terminal IDs, facility variable passwords, and mobile terminal passwords that are preset by vehicle-mounted device users and do not need to be updated. Here, the mobile terminal ID is identification information for the mobile terminal 500. The mobile terminal ID may be any value that does not overlap with other mobile terminal IDs. The mobile terminal ID may be, for example, an email address, a serial number, a MAC address, etc. The mobile terminal password is information that is stored in the authentication information table in advance by the vehicle-mounted device user. The facility variable password is password information that is periodically generated by the entry / exit management device 400. The facility variable password is information that is changed at short intervals, such as daily. Therefore, the facility variable password is information that is not known even to those riding in the vehicle until notified. The combination of the facility variable password, the mobile terminal password, and the mobile terminal ID is hereinafter referred to as "verification information."

[0011] The vehicle-mounted device 100 is an in-vehicle device for receiving an electronic toll collection service using ETC. An in-vehicle device ID is set for the vehicle-mounted device 100 when the vehicle-mounted device 100 is installed in a vehicle. The mobile terminal 500 is a terminal capable of short-range wireless communication or medium-range wireless communication. Specifically, the mobile terminal 500 is a portable terminal such as a smartphone or a tablet.

[0012] In the entry / exit system 1 configured in this manner, authentication is performed not only using the vehicle-mounted device ID, which is the identification information of the vehicle-mounted device 100, but also using the facility variable password and the mobile terminal password. This makes it possible to authenticate people who are actually riding in the vehicle, making it possible to identify people inside the vehicle with higher accuracy. Furthermore, in the entry / exit system 1 configured in this manner, unless the vehicle-mounted device 100 and the mobile terminal 500 are near the entry / exit roadside device 200, they cannot be authenticated by the entry / exit management device 400. This makes it possible to prevent the mobile terminal 500 from being operated by someone located away from the vehicle. This also makes it possible to identify people inside the vehicle with higher accuracy.

[0013] Note that the vehicle-mounted device ID is very important information and must be managed strictly. Therefore, it is desirable that the vehicle-mounted device ID verification device 300, which has a table in which the vehicle-mounted device IDs are registered, be managed by a strict organization. For example, the vehicle-mounted device ID verification device 300 may be configured as a server device operated by a public organization such as an affiliated organization. On the other hand, although verification information including a mobile terminal ID (e.g., an email address) is personal information and important, it does not need to be managed as strictly as the vehicle-mounted device ID, and it is preferable that it be flexibly registered and updated for each facility 10. For this reason, the verification information is managed by the entry / exit management device 400. In the above-described entry / exit system 1, the vehicle-mounted device ID and the mobile terminal ID are associated and managed in the vehicle-mounted device ID verification device 300, and the mobile terminal ID is transmitted to the entry / exit management device 400. In other words, the vehicle-mounted device ID is not transmitted to the entry / exit management device 400. With this configuration, it is possible to manage the vehicle-mounted device ID more strictly and maintain security.

[0014] Next, a description will be given of each component that makes up the entrance / exit system 1 with reference to a configuration diagram. FIG. The ingress / exit roadside device 200 includes an in-vehicle communication unit 201, an encryption processing unit 202, an IP communication unit 204, a terminal communication unit 203, a communication control unit 205, an ingress / exit control unit 206, and an ingress / exit communication unit 207. The ingress / exit roadside device 200 includes a plurality of network interfaces, a CPU (Central Processing Unit) connected by a bus, a memory, an auxiliary storage device, etc. All or part of the functions of the ingress / exit roadside device 200 may be realized using hardware such as an ASIC (Application Specific Integrated Circuit), a PLD (Programmable Logic Device), or an FPGA (Field Programmable Gate Array). The ingress / exit roadside device 200 may be configured using a plurality of information processing devices.

[0015] The vehicle-mounted device communication unit 201 is a network interface for communicating with the vehicle-mounted device 100. The wireless communication may be, for example, DSRC (Dedicated Short Range Communication) used as the conventional ETC system or ETC2.0 system.

[0016] The encryption processing unit 202 executes encryption processing of the vehicle-mounted device ID and generates an encrypted vehicle-mounted device ID.

[0017] The terminal communication unit 203 is a network interface for the entrance / exit roadside unit 200 to communicate with the mobile terminal 500. For example, the wireless communication is preferably a short-distance wireless communication method to prevent communication from a long distance. For example, the wireless communication may be wireless LAN (Wifi), Bluetooth (registered trademark), or NFC (Near Field Communication).

[0018] The IP communication unit 204 is a network interface for communication with the entry / exit roadside unit 200. The IP communication unit 204 communicates with the vehicle-mounted device ID verification device 300 via the network 700 to inquire about the mobile terminal ID.

[0019] The communication control unit 205 controls the execution of authentication processing by the entrance / exit roadside unit 200 when a vehicle equipped with the on-board device 100 enters the entrance / exit system 1.

[0020] The entrance / exit control unit 206 controls the entrance / exit inhibitor 600 to open the gate based on an instruction from the entrance / exit management device 400 .

[0021] The entry / exit communication unit 207 is a network interface that allows the entry / exit roadside device 200 to communicate with the entry / exit inhibitor 600. The entry / exit communication unit 207 communicates with the entry / exit inhibitor 600. The communication method may be, for example, wired communication. The communication method may also be, for example, wireless communication such as Bluetooth or wireless LAN.

[0022] The entry / exit inhibitor 600 is a device that actually prevents vehicles from entering. Specifically, the entry / exit inhibitor 600 is composed of a barrier, a shutter, etc. The entry / exit inhibitor 600 includes a communication unit 601, an entry / exit control unit 602, and an entry / exit inhibitor 603.

[0023] The communication unit 601 is an interface unit that communicates with the entrance / exit roadside unit 200, and the communication method may be any method such as Bluetooth, wireless LAN, or wired LAN.

[0024] The entry / exit control unit 602 notifies the entry / exit suppression unit 603 of an open gate command based on the gate open command from the entry / exit roadside unit 200. After notifying the open gate command, the entry / exit control unit 602 notifies the entry / exit suppression unit 603 of a close gate command when a predetermined time has elapsed. Furthermore, the entry / exit control unit 602 may notify the entry / exit suppression unit 603 of a close gate command after the vehicle-mounted device 100 passes through the entry / exit suppression unit 603 that has opened the gate.

[0025] The entry / exit control unit 603 opens the gate when it receives a notice of an open gate instruction from the entry / exit control unit 602. Also, the entry / exit control unit 603 closes the gate when it receives a notice of a close gate instruction from the entry / exit control unit 602. Also, the entry / exit control unit 603 may have different entrance and exit sections.

[0026] The vehicle-mounted ID matching device 300 includes an IP communication unit 301, a device information storage unit 302, an information control unit 303, and a decryption processing unit 304. The vehicle-mounted ID matching device 300 is configured using an information processing device such as a mainframe, a workstation, or a personal computer. The vehicle-mounted ID matching device 300 can be any device that is capable of providing the functions described below. The vehicle-mounted ID matching device 300 includes a network interface, a CPU connected via a bus, a memory, an auxiliary storage device, and the like. Note that all or part of the functions of the vehicle-mounted ID matching device 300 may be realized using hardware such as an ASIC, PLD, or FPGA.

[0027] The IP communication unit 301 is a network interface for communication by the vehicle-mounted device ID verification device 300. The IP communication unit 301 communicates with the entry / exit roadside unit 200 and the entry / exit management device 400 via the network 700.

[0028] The device information storage unit 302 is configured using a storage device such as a magnetic hard disk drive or a semiconductor storage device. The device information storage unit 302 stores an in-vehicle device ID table 311. As shown in FIG. 2, the in-vehicle device ID record has values ​​of an in-vehicle device ID and a mobile terminal ID.

[0029] In the example shown in Figure 2, the topmost vehicle-mounted device ID record in the vehicle-mounted device ID table 311 has an vehicle-mounted device ID of "XXX" and a mobile terminal ID of "xxx@xxx". This vehicle-mounted device ID record indicates that if the vehicle-mounted device ID received by the vehicle-mounted device ID verification device 300 is "XXX", the information control unit 303 will obtain the mobile terminal ID "xxx@xxx". Note that the vehicle-mounted device ID table 311 shown in Figure 2 is merely one specific example. Therefore, the vehicle-mounted device ID table 311 may be configured in a manner different from that shown in Figure 2.

[0030] The information control unit 303 executes a decryption process of the encrypted vehicle-mounted device ID in the decryption processing unit 304. The information control unit 303 acquires the mobile terminal ID stored in the record where the vehicle-mounted device ID satisfies (e.g., matches) a predetermined requirement from the vehicle-mounted device ID table 311 in the device information storage unit 302. The information control unit 303 transmits the mobile terminal ID to the entry / exit management device 400.

[0031] The decryption processing unit 304 executes the decryption process of the encrypted vehicle-mounted device ID, and notifies the information control unit 303 of the decrypted vehicle-mounted device ID.

[0032] The entrance / exit control device 400 comprises an IP communication unit 401, an authentication control unit 402, an authentication information storage unit 403, an authentication processing unit 404, and a facility variable password generation unit 405. The entrance / exit control device 400 is configured using information processing devices such as network equipment, mainframes, workstations, and personal computers. The entrance / exit control device 400 can be any device that is capable of providing the functions described below. The entrance / exit control device 400 comprises a network interface, a CPU connected via a bus, memory, an auxiliary storage device, and the like. Note that all or part of the functions of the entrance / exit control device 400 may be realized using hardware such as an ASIC, PLD, or FPGA.

[0033] The IP communication unit 401 is a network interface for communication with the entry / exit control device 400. The IP communication unit 401 communicates with the entry / exit roadside unit 200 and the vehicle-mounted device ID verification device 300 via the network 700.

[0034] The authentication control unit 402 receives the mobile terminal ID from the vehicle-mounted device ID matching device 300. The authentication control unit 402 acquires the facility variable password from the authentication information storage unit 403 and transmits it to the vehicle-mounted device 100. The authentication control unit 402 executes authentication processing of the matching information in the authentication processing unit 404. The authentication control unit 402 transmits the result of the authentication processing executed by the authentication processing unit 404 to the entry / exit roadside unit 200.

[0035] The authentication information storage unit 403 is configured using a storage device such as a magnetic hard disk device, a semiconductor storage device, etc. The authentication information storage unit 403 stores an authentication information table 411.

[0036] As shown in FIG. 2, the authentication information table 411 has matching information for each authentication information record. The facility variable password is authentication information that is periodically generated by the facility variable password generation unit 405. The facility variable password may be, for example, a character string including numbers and letters. The mobile terminal password is authentication information that is pre-registered in the authentication information record by the user of the vehicle-mounted device 100 (hereinafter referred to as the "vehicle-mounted device user"). The mobile terminal password may be any information that is used as existing authentication information, such as a character string including numbers and letters, a combination of pictures, or a line pattern. The mobile terminal password may be, for example, biometric information such as a fingerprint or face. The mobile terminal password may be a combination of multiple pieces of information.

[0037] In the example shown in FIG. 2, the authentication information record at the top of the authentication information table 411 has a device ID of "xxx@xxx", a facility variable password of "QQQQ", and a mobile terminal password of "RRRR". When the authentication information received by the access control device 400 has a mobile terminal ID of "xxx@xxx", a facility variable password of "QQQQ", and a mobile terminal password of "RRRR", the authentication processing unit 404 determines that authentication has been successful. Note that the authentication information table 411 shown in FIG. 2 is merely one specific example. Therefore, the authentication information table 411 may be configured in a manner different from that shown in FIG. 2. For example, the authentication information table 411 may include the date and time when the mobile terminal password was updated.

[0038] The authentication processing unit 404 executes authentication processing based on the verification information received by the entrance / exit management device 400 and the authentication information record stored in the authentication information storage unit 403. Specifically, if the verification information received by the entrance / exit management device 400 and the authentication information record stored in the authentication information storage unit 403 satisfy (e.g., match) a predetermined authentication condition, the authentication processing unit 404 determines that the in-vehicle device 100 is a device having legitimate authority. On the other hand, if the verification information received by the entrance / exit management device 400 and the authentication information record stored in the authentication information storage unit 403 do not satisfy (e.g., do not match) a predetermined authentication condition, the authentication processing unit 404 determines that the in-vehicle device 100 is a device not having legitimate authority.

[0039] The facility variable password generation unit 405 generates a facility variable password at a predetermined frequency. The facility variable password generation unit 405 registers the generated facility variable password as facility variable password in the authentication information table 411 of the authentication information storage unit 403. The facility variable password may be generated once a day, for example. A random value is generated for each record of the facility variable password.

[0040] The network 700 connects the entry / exit roadside device 200, the vehicle-mounted ID verification device 300, and the entry / exit management device 400 so that they can communicate with each other. The network 700 may be configured, for example, by the Internet.

[0041] FIG. 3 is a schematic block diagram showing the functional configuration of the in-vehicle device 100. The in-vehicle device 100 is configured using an ETC in-vehicle device mounted on a vehicle. The in-vehicle device 100 includes a network interface, a CPU, a memory, an auxiliary storage device, and the like, all connected via a bus. By executing an authentication program, the in-vehicle device 100 functions as a device including a communication unit 101, an information control unit 102, an in-vehicle device information storage unit 103, an audio output unit 104, a display unit 105, and a card input / output unit 106. Note that all or part of the functions of the in-vehicle device 100 may be realized using hardware such as an ASIC, a PLD, or an FPGA. The authentication program may be recorded on a computer-readable recording medium. Examples of the computer-readable recording medium include portable media such as a flexible disk, a magneto-optical disk, a ROM, a CD-ROM, and a semiconductor storage device, and storage devices such as a hard disk and a semiconductor storage device built into a computer system. Note that the in-vehicle device 100 may also be configured using in-vehicle devices such as a car navigation system or an audio system mounted on a vehicle.

[0042] The communication unit 101 is a network interface capable of communicating with the vehicle-mounted device communication unit 201. The communication unit 101 communicates with the entry / exit roadside unit 200. The communication may be, for example, a DSRC communication system.

[0043] The information control unit 102 controls the execution of authentication processing of the vehicle-mounted device 100. The vehicle-mounted device ID is acquired from the vehicle-mounted device information storage unit 103 and transmitted to the vehicle-mounted device ID matching device 300 via the entry / exit roadside device 200. The information control unit 102 notifies the voice output unit 104 of the facility variable password information received from the entry / exit roadside device 200. The information control unit 102 notifies the display unit 105 of the facility variable password information received from the entry / exit roadside device 200. The vehicle-mounted device ID is identification information of the vehicle-mounted device of a vehicle that has entered the entry / exit system. The vehicle-mounted device ID may be any value that does not overlap with other vehicle-mounted device IDs. The vehicle-mounted device ID may be, for example, the WCN (Wireless Call Number) or serial number of an ETC (Electronic Toll Collection System) vehicle-mounted device.

[0044] The vehicle-mounted device information storage unit 103 is configured using a storage device such as a magnetic hard disk device, a semiconductor storage device, etc. The vehicle-mounted device information storage unit 103 stores the vehicle-mounted device ID.

[0045] The audio output unit 104 is configured using an existing audio output device such as a speaker, earphones, headphones, etc. The audio output unit 104 may be an interface for connecting an audio output device to the in-vehicle device 100. In this case, the audio output unit 104 generates an audio signal from audio data and outputs the audio signal to the audio output device connected to itself.

[0046] The display unit 105 is a video output device such as a CRT (Cathode Ray Tube) display, a liquid crystal display, or an organic EL (Electro Luminescence) display. The display unit 105 may be an interface for connecting the video output device to the vehicle-mounted device 100. In this case, the display unit 105 generates a video signal from video data and outputs the video signal to the video output device connected to the display unit 105.

[0047] The card input / output unit 106 includes a card slot into which the card 107 is inserted. The card input / output unit 106 acquires and registers information for the card 107 inserted into the card slot. In the example of FIG. 3, the card input / output unit 106 includes one card slot into which one card 107 is inserted. However, the configuration may be different from that shown in FIG. 3. For example, the number of card slots included in the card input / output unit 106 may be two or more.

[0048] Card 107 is a card for settling tolls using the ETC system. Card 107 is used by inserting it into a card slot provided in card input / output unit 106. Information recorded on card 107 includes pre-recorded identification information unique to each card 107, and information indicating the type of service provided to the organization that issues card 107 (specifically, a credit card company or an institution affiliated with a credit card company) or the user of card 107. In addition to the card information, card 107 also records information on the entrance toll gate where the user began using the road and the exit toll gate where the user finished using the road.

[0049] 4 is a schematic block diagram showing the functional configuration of the mobile terminal 500. The mobile terminal 500 is configured using an information processing device such as a tablet computer, a personal computer, or a smartphone. The mobile terminal 500 includes a short-range wireless communication unit 501, an input / output control unit 502, a display unit 503, and an input unit 504. The mobile terminal 500 includes a network interface, a CPU, a memory, an auxiliary storage device, and the like, all connected via a bus. The mobile terminal 500 is owned by, for example, a person riding in a vehicle.

[0050] The short-distance wireless communication unit 501 is a network interface for communication with the mobile terminal 500. The short-distance wireless communication unit 501 is a communication unit for short-distance wireless communication for communication with the entrance / exit roadside unit 200. The communication method may be Bluetooth, wireless LANS, NFC, or the like.

[0051] The input / output control unit 502 executes input / output processing for receiving authentication from the entrance / exit control device 400. The input / output control unit 502 transmits input information to the entrance / exit control device 400 via the entrance / exit roadside unit 200.

[0052] Display unit 503 is a video output device such as a CRT display, a liquid crystal display, an organic EL display, etc. Display unit 503 may be an interface for connecting the video output device to mobile terminal 500. In this case, display unit 503 generates a video signal from video data and outputs the video signal to the video output device connected to itself.

[0053] The input unit 504 is configured using an existing input device such as a touch panel, a button, a switch, etc. The input unit 504 may be an interface for connecting the input device to the mobile terminal 500. In this case, the input unit 504 generates input data from an input signal input to the input device and inputs the input data to the mobile terminal 500. The input unit 504 transmits the input signal to the entrance / exit roadside unit 200. When the input unit 504 is configured using a touch panel, the input unit 504 and the display unit 503 may be configured integrally.

[0054] Next, the operation will be described. FIG. 5 is a sequence diagram showing the processing flow of the entrance / exit system 1 in the first embodiment. As a preliminary step, the vehicle-mounted device user notifies the vehicle-mounted device ID and the mobile terminal ID to the vehicle-mounted device ID verification device 300. Alternatively, the vehicle-mounted device user may transmit the vehicle-mounted device ID and the mobile terminal ID from the vehicle-mounted device 100 to the vehicle-mounted device ID verification device 300. Alternatively, the vehicle-mounted device user may transmit the vehicle-mounted device ID and the mobile terminal ID from the mobile terminal 500 to the vehicle-mounted device ID verification device 300 (step S101). Next, the vehicle-mounted device ID verification device 300 executes a registration process for the received vehicle-mounted device ID and the mobile terminal ID. Specifically, the vehicle-mounted device ID verification device 300 registers the vehicle-mounted device ID and the mobile terminal ID in association with each other in the vehicle-mounted device ID table 311 (step S102). The vehicle-mounted device ID verification device 300 transmits the mobile terminal ID to the entrance / exit management device 400 (step S103). The vehicle-mounted device user transmits the mobile terminal password that he / she has determined to the entry / exit management device 400. Alternatively, the vehicle-mounted device user may transmit the mobile terminal password from the mobile terminal 500 to the entry / exit management device 400 (step S104). The facility variable password generation unit 405 generates the facility variable password. The entry / exit management device 400 registers the received mobile terminal ID, mobile terminal authentication information, and facility variable authentication information in the authentication information table 411 in association with each other (step S105). This completes the advance preparation.

[0055] Next, the information control unit 102 acquires the vehicle-mounted device ID from the vehicle-mounted device information storage unit 103, and transmits it to the entry / exit roadside unit 200 via the communication unit 101 (step S201).

[0056] The vehicle-mounted device communication unit 201 notifies the vehicle-mounted device ID to the communication control unit 205. The communication control unit 205 executes encryption processing of the vehicle-mounted device ID using the encryption processing unit 202. The encryption processing unit 202 generates an encrypted vehicle-mounted device ID from the vehicle-mounted device ID (step S202). The communication control unit 205 transmits the encrypted vehicle-mounted device ID to the vehicle-mounted device ID matching device 300 via the IP communication unit 204 (step S203).

[0057] The IP communication unit 301 notifies the information control unit 303 of the encrypted vehicle-mounted device ID. The information control unit 303 executes a decryption process of the encrypted vehicle-mounted device ID using the decryption processing unit 304. The decryption processing unit 304 generates a vehicle-mounted device ID from the encrypted vehicle-mounted device ID (step S204). The information control unit 303 identifies an vehicle-mounted device ID record with a matching vehicle-mounted device ID from the vehicle-mounted device ID table 311 in the device information storage unit 302 (step S205). If the vehicle-mounted device IDs match (step S205-YES), the information control unit 303 acquires the value of the mobile terminal ID (step S206). If the vehicle-mounted device IDs do not match (step S205-NO), the vehicle-mounted device ID verification device 300 terminates the process (step S207). The information control unit 303 transmits the mobile terminal ID to the entry / exit management device 400 via the IP communication unit 301 (step S208).

[0058] The IP communication unit 401 notifies the authentication control unit 402 of the mobile terminal ID. The authentication control unit 402 obtains the value of the facility variable password from the authentication information record that matches the mobile terminal ID, from the authentication information table 411 in the authentication information storage unit 403 (step S209). The authentication control unit 402 transmits the value of the facility variable password to the vehicle-mounted device 100 via the IP communication unit 401 and the entrance / exit roadside unit 200 (steps S210 to S211).

[0059] The information control unit 102 speaks the value of the facility variable identification information through the voice output unit 104. The information control unit 102 displays the value of the facility variable identification information through the display unit 105 (step S212).

[0060] The input unit 504 receives the verification information through an operation by a person in the vehicle (step S213). The person in the vehicle may be, for example, the user of the on-board device or the driver of the vehicle. The input unit 504 notifies the verification information to the input / output control unit 502. The input / output control unit 502 transmits the verification information to the entry / exit management device 400 via the short-range wireless communication unit 501 and the entry / exit roadside device 200 (steps S214 to S215).

[0061] The IP communication unit 401 notifies the authentication control unit 402 of the verification information. The authentication control unit 402 executes authentication processing of the verification information in the authentication processing unit 404. Specifically, the authentication processing unit 404 compares the verification information received from the mobile terminal 500 with the verification information stored in the authentication information record, and if a predetermined authentication condition is met (for example, they match), the authentication processing unit 404 determines that the on-board device 100 is a device with legitimate authority. On the other hand, if the predetermined condition is not met (for example, they do not match), the authentication processing unit 404 determines that the on-board device 100 is a device without legitimate authority (step S216). The authentication control unit 402 transmits the authentication processing execution result to the entry / exit roadside unit 200 (step S217).

[0062] The IP communication unit 204 notifies the entrance / exit control unit 206 of the result of the authentication process. The entrance / exit control unit 206 executes processing based on the result of the authentication process (step S218). If the result of the authentication process is successful (step S218-YES), the entrance / exit control unit 206 sends an instruction to open the gate to the entrance / exit inhibitor 600 via the entrance / exit communication unit 207 (step S219). On the other hand, if the result of the authentication process is not successful (step S218-NO), the entrance / exit control unit 206 ends the processing (step S220).

[0063] The communication unit 601 notifies the entrance / exit control unit 602 of the gate opening instruction. Upon receiving the gate opening instruction, the entrance / exit control unit 602 executes the gate opening process of the entrance / exit control unit 603 (step S221).

[0064] 5, the verification information acquired in step S213 may be encrypted in the encryption processing unit 202. In this case, when the verification information is transmitted from the entrance / exit roadside unit 200 to the entrance / exit control device 400 in step S215, it is possible to prevent the verification information from being intercepted. As a result, more secure entrance / exit control is possible compared to when the verification information is transmitted without being encrypted.

[0065] Second Embodiment First, an overview of the entry / exit system 2 in the second embodiment will be described. The second embodiment is used when a business operator installs entry / exit roadside devices 200a at two or more locations. For example, when vehicle management is performed within the premises of a construction site or the like, the construction company associates the in-vehicle device 100 with the entry / exit roadside device 200a. Therefore, when there are multiple construction sites, the association process places a heavy burden on the construction company. Therefore, the entry / exit system 2 reduces the burden of this association process. Specifically, an in-vehicle device ID, a facility ID, and a mobile terminal ID are associated and registered in the in-vehicle device ID verification device 300a. The facility ID is an identifier that identifies the entry / exit roadside device 200a. The facility ID may be any value that does not overlap with other facility IDs. The facility ID may be, for example, the name of the facility or an arbitrary character string. The in-vehicle device ID verification device 300a identifies the mobile terminal ID using the in-vehicle device ID and facility ID received from the entry / exit roadside device 200a. If at least one of the vehicle-mounted device ID and the facility ID is different, the vehicle equipped with this vehicle-mounted device 100 is deemed to be attempting to enter the unauthorized access roadside unit 200a. Therefore, this vehicle is not allowed to enter the construction site. With this configuration, construction companies are no longer required to perform linking for each construction site. This reduces the burden of linking on construction companies.

[0066] The entry / exit system 2 will be described in detail below using Figure 6. Figure 6 is a system configuration diagram showing the system configuration of the entry / exit system 2 in the second embodiment. The entry / exit system 2 in the second embodiment differs from the first embodiment in that a facility ID is newly used. Only the differences from the first embodiment will be described below. The entry / exit system 2 differs from the entry / exit system 1 in the first embodiment in that it has an entry / exit roadside device 200a instead of the entry / exit roadside device 200 and an in-vehicle ID matching device 300a instead of the in-vehicle ID matching device 300, but in other respects it has the same configuration as the entry / exit system 1.

[0067] The entry / exit roadside device 200a includes an encryption processing unit 202a that performs encryption processing on the vehicle-mounted device ID and the facility ID, instead of the encryption processing unit 202 that performs encryption processing on the vehicle-mounted device ID. The entry / exit roadside device 200a includes a communication control unit 205a that controls authentication processing of the vehicle-mounted device 100 using the vehicle-mounted device ID and the facility ID, instead of the communication control unit 205 that controls authentication processing of the vehicle-mounted device 100 using the vehicle-mounted device ID. The entry / exit roadside device 200a further includes an installer information storage unit 208a that stores the facility ID. The entry / exit roadside device 200a has the same configuration as the entry / exit roadside device 200 in other respects.

[0068] The vehicle-mounted device ID matching device 300a includes a device information storage unit 302a that stores a facility ID instead of the device information storage unit 302 that stores the vehicle-mounted device ID and the mobile terminal ID. The vehicle-mounted device ID matching device 300a includes an information control unit 303a that controls the process of identifying the mobile terminal ID from the vehicle-mounted device ID and the facility ID instead of the information control unit 303 that controls the process of identifying the mobile terminal ID from the vehicle-mounted device ID. The vehicle-mounted device ID matching device 300a includes a decryption processing unit 304a that performs the decryption process of the encrypted vehicle-mounted device ID and the encrypted facility ID instead of the decryption processing unit 304 that performs the decryption process of the encrypted vehicle-mounted device ID. The vehicle-mounted device ID matching device 300a has the same configuration as the vehicle-mounted device ID matching device 300 in other respects.

[0069] The vehicle-mounted device ID table 311a differs from the vehicle-mounted device ID table 311 in the first embodiment in that it further includes a column for facility IDs, but has the same configuration as the vehicle-mounted device ID table 311 in other respects.

[0070] In the example shown in Figure 6, the vehicle-mounted device ID record a at the top of the vehicle-mounted device ID table 311a indicates that when the vehicle-mounted device ID received by the vehicle-mounted device ID verification device 300a is "XXX" and the facility ID is "AAA", the information control unit 303a acquires the mobile terminal ID as "xxx@xxx". Note that the vehicle-mounted device ID table 311a shown in Figure 6 is only one specific example. Therefore, the vehicle-mounted device ID table 311a may be configured in a manner different from that shown in Figure 6. For example, the vehicle-mounted device ID table 311a may register a timestamp when the vehicle-mounted device ID record a was generated.

[0071] FIG. 7 is a sequence diagram showing the processing flow until an operator associates and registers an in-vehicle device ID, a facility ID, and a mobile terminal ID in the entrance / exit system 2 in the second embodiment. In the entrance / exit system 2, multiple in-vehicle device IDs 200a are installed. Therefore, the operator decides which in-vehicle device user will enter and exit through which in-vehicle device ID roadside device 200a. For this purpose, the operator uses an in-vehicle device ID usage consent. The in-vehicle device ID usage consent indicates which in-vehicle device user will be allowed to enter and exit through which in-vehicle device ID roadside device 200a. The operator obtains the in-vehicle device user's approval for the in-vehicle device ID usage consent. Thereafter, the operator registers the contents of the in-vehicle device ID usage consent in the in-vehicle device ID verification device 300a. After registration, the in-vehicle device user can enter and exit through the in-vehicle device ID usage consent indicated in the in-vehicle device ID usage consent.

[0072] First, the vehicle-mounted device user performs a user registration process for the vehicle-mounted device ID and the mobile terminal ID. The user registration process may be performed, for example, on a web page for user registration (step S301).

[0073] Next, the operator prepares an in-vehicle device ID usage consent form. The in-vehicle device ID usage consent form contains the "in-vehicle device user name," "in-vehicle device ID," "license expiration date," "mobile terminal ID," and "facility ID." Note that the items in this in-vehicle device ID usage consent form are merely a specific example. Therefore, an in-vehicle device ID usage consent form may be composed of items different from those in this in-vehicle device ID usage consent form. For example, the in-vehicle device ID usage consent form may have a field for the facility name. The in-vehicle device ID usage consent form may also be an electronic medium such as a web form (step S302).

[0074] The operator sends the vehicle-mounted device ID use consent to the vehicle-mounted device user (step S303). The vehicle-mounted device user executes approval processing for the vehicle-mounted device ID use consent. Specifically, the approval processing is performed by the vehicle-mounted device user signing the vehicle-mounted device ID use consent. The approval processing may also be performed by electronic signature. The vehicle-mounted device ID use consent that has undergone approval processing is designated as an approved vehicle-mounted device ID use consent (step S304). The vehicle-mounted device user sends the approved vehicle-mounted device ID use consent to the operator (step S305). The operator transmits the approved vehicle-mounted device ID use consent to the vehicle-mounted device ID verification device 300a. The operator may also send the approved vehicle-mounted device ID use consent to the management organization of the vehicle-mounted device ID verification device 300a (step S306).

[0075] The vehicle-mounted device ID matching device 300a generates a vehicle-mounted device ID table 311a (step S307). The vehicle-mounted device ID matching device 300a generates a vehicle-mounted device ID record a in which the "vehicle-mounted device ID", "facility ID", and "mobile terminal ID" written in the approved vehicle-mounted device ID usage consent are registered (step S308).

[0076] 8 is a sequence diagram showing the processing flow of the entry / exit system 2 in the second embodiment. First, the information control unit 102 acquires the vehicle-mounted device ID from the vehicle-mounted device information storage unit 103, and transmits it to the entry / exit roadside unit 200a via the communication unit 101 (step S201).

[0077] The vehicle-mounted device communication unit 201 notifies the communication control unit 203a of the vehicle-mounted device ID. The communication control unit 205a acquires the facility ID stored in the installer information storage unit 208a. The communication control unit 205a performs encryption processing of the vehicle-mounted device ID and facility ID in the encryption processing unit 202a. The encryption processing unit 202a generates an encrypted vehicle-mounted device ID from the vehicle-mounted device ID. The encryption processing unit 202a generates an encrypted facility ID from the facility ID (step S202a). The communication control unit 205a transmits the encrypted vehicle-mounted device ID and encrypted facility ID to the vehicle-mounted device ID matching device 300a via the IP communication unit 204 (step S203a).

[0078] The IP communication unit 301 notifies the information control unit 303a of the encrypted vehicle-mounted device ID and the encrypted facility ID. The information control unit 303a executes a decryption process of the encrypted vehicle-mounted device ID and the encrypted facility ID using the decryption processing unit 304a. The decryption processing unit 304a generates a vehicle-mounted device ID from the encrypted vehicle-mounted device ID. The decryption processing unit 304a generates a facility ID from the encrypted facility ID (step S204a). The information control unit 303a identifies a vehicle-mounted device ID record in which the vehicle-mounted device ID and facility ID match from the vehicle-mounted device ID table 311a in the device information storage unit 302a (step S205a). If the vehicle-mounted device ID and facility ID match (step S205a-YES), the information control unit 303a acquires the value of the mobile terminal ID (step S206). If the vehicle-mounted device IDs do not match (step S205a-NO), the vehicle-mounted device ID verification device 300a terminates the process (step S207). The information control unit 303a transmits the mobile terminal ID to the entrance / exit management device 400 via the IP communication unit 301 (step S208).

[0079] The IP communication unit 401 notifies the authentication control unit 402 of the mobile terminal ID. The authentication control unit 402 obtains the value of the facility variable password from the authentication information record that matches the mobile terminal ID, from the authentication information table 411 in the authentication information storage unit 403 (step S209). The authentication control unit 402 transmits the value of the facility variable password to the vehicle-mounted device 100 via the IP communication unit 401 and the entrance / exit roadside unit 200a (steps S210 to S211).

[0080] The information control unit 102 speaks the value of the facility variable identification information through the voice output unit 104. The information control unit 102 displays the value of the facility variable identification information through the display unit 105 (step S212).

[0081] The input unit 504 receives the verification information through an operation by a person riding in the vehicle (step S213). The input unit 504 notifies the verification information to the input / output control unit 502. The input / output control unit 502 transmits the verification information to the entry / exit management device 400 via the short-range wireless communication unit 501 and the entry / exit roadside device 200a (steps S214 to S215).

[0082] The IP communication unit 401 notifies the authentication control unit 402 of the verification information. The authentication control unit 402 executes authentication processing of the verification information in the authentication processing unit 404. Specifically, the authentication processing unit 404 compares the verification information received from the mobile terminal 500 with the verification information stored in the authentication information record, and if a predetermined authentication condition is met (for example, they match), the authentication processing unit 404 determines that the on-board device 100 is a device with legitimate authority. On the other hand, if the predetermined condition is not met (for example, they do not match), the authentication processing unit 404 determines that the on-board device 100 is a device with unauthorized authority (step S216). The authentication control unit 402 transmits the authentication result to the entry / exit roadside unit 200a (step S217).

[0083] The IP communication unit 204 notifies the entrance / exit control unit 206 of the result of the authentication process. The entrance / exit control unit 206 executes processing based on the result of the authentication process (step S218). If the result of the authentication process is successful (step S218-YES), the entrance / exit control unit 206 sends an instruction to open the gate to the entrance / exit inhibitor 600 via the entrance / exit communication unit 207 (step S219). On the other hand, if the result of the authentication process is not successful (step S218-NO), the entrance / exit control unit 206 ends the processing (step S220).

[0084] The communication unit 601 notifies the entrance / exit control unit 602 of the gate opening instruction. Upon receiving the gate opening instruction, the entrance / exit control unit 602 executes the gate opening process of the entrance / exit control unit 603 (step S221).

[0085] (Third embodiment) First, an outline of the entrance / exit system 3 in the third embodiment will be described. The third embodiment is assumed to be an entrance / exit system that allows entry and exit with a simple configuration without using a mobile terminal 500 in a place such as an apartment parking lot where high security such as identity verification is not required. For this purpose, the following processing is executed.

[0086] In the first embodiment, authentication processing is performed using the facility variable password and the mobile terminal password transmitted from the mobile terminal 500, but in the third embodiment, authentication processing is performed using only the mobile terminal ID without using these two pieces of information. Also, in the first embodiment, the mobile terminal ID is transmitted from the mobile terminal 500 to the entry / exit management device 400, but in the third embodiment, it is transmitted from the vehicle-mounted ID matching device 300 to the entry / exit management device 400 without going through the mobile terminal 500. With this configuration, in the third embodiment, it is possible to realize entry / exit without using the mobile terminal 500.

[0087] The entrance / exit system 3 will be described in detail below with reference to Fig. 9. Fig. 9 is a system configuration diagram showing the system configuration of the entrance / exit system 3 in the third embodiment. The entrance / exit system 3 in the third embodiment differs from the first embodiment in that it does not use a mobile terminal 500. Only the differences from the first embodiment will be described below.

[0088] The ingress / egress roadside device 200b does not have the terminal communication unit 203. The ingress / egress roadside device 200b has the same configuration as the ingress / egress roadside device 200 in other respects.

[0089] The entrance / exit management device 400b has an authentication control unit 402b instead of the authentication control unit 402. The entrance / exit management device 400b has an authentication information storage unit 403b that stores a mobile terminal ID instead of the authentication information storage unit 403 that stores matching information. The entrance / exit management device 400b has an authentication processing unit 404b that performs authentication processing using a mobile terminal ID instead of the authentication processing unit 404 that performs authentication processing using matching information. The entrance / exit management device 400b does not have a facility variable password generation unit 405. The entrance / exit management device 400b has the same configuration as the entrance / exit management device 400 in other respects.

[0090] The authentication information storage unit 403b stores an authentication information table 411b. The authentication information record b has a mobile terminal ID. In the example shown in FIG. 9, the authentication information record b at the top of the authentication information table 411b has a mobile terminal ID of "xxx@xxx". When the mobile terminal ID received from the vehicle-mounted device ID verification device 300 is "xxx@xxx", the authentication processing unit 404b determines that authentication has been successful for this authentication information record b. Note that the authentication information table 411b shown in FIG. 9 is merely one specific example. Therefore, the authentication information table 411b may be configured in a manner different from that shown in FIG. 9. For example, the authentication information table 411b may have the date and time when the mobile terminal ID was registered.

[0091] FIG. 10 is a sequence diagram showing the flow of processing until the use of the vehicle-mounted device ID and the mobile terminal ID is started in the entrance / exit system 3 in the third embodiment. First, the vehicle-mounted device user transmits the vehicle-mounted device ID and the mobile terminal ID to the vehicle-mounted device ID verification device 300. The transmission may also be from a web page. The transmission may also be sent to the management organization of the vehicle-mounted device ID verification device 300 (step S401). Next, the vehicle-mounted device ID verification device 300 executes a registration process for the vehicle-mounted device ID and the mobile terminal ID. Specifically, the vehicle-mounted device ID verification device 300 generates a vehicle-mounted device ID record in the vehicle-mounted device ID table. The vehicle-mounted device ID verification device 300 registers the vehicle-mounted device ID and the mobile terminal ID in the vehicle-mounted device ID record (step S402).

[0092] The vehicle-mounted device user notifies the business operator (e.g., a condominium management organization) of the vehicle-mounted device ID and permission to use the vehicle-mounted device ID (step S403). Upon receiving the vehicle-mounted device ID and permission to use the vehicle-mounted device ID, the business operator transmits the vehicle-mounted device ID to the vehicle-mounted device ID verification device 300. The transmission may be for each vehicle-mounted device user. The transmission may be for all vehicle-mounted device users after receiving their vehicle-mounted device IDs. The transmission may be from a web page. The transmission may be sent to the management organization of the vehicle-mounted device ID verification device 300 (step S404). The vehicle-mounted device ID verification device 300 identifies the mobile terminal ID using the vehicle-mounted device ID (step S405). The vehicle-mounted device ID verification device 300 transmits the mobile terminal ID to the entry / exit management device 400b (step S406). The entrance / exit management device 400b registers the mobile terminal ID in the authentication information table 411b (step S407). With the above, the entrance / exit system 3 starts using the vehicle-mounted device ID and the mobile terminal ID.

[0093] 11 is a sequence diagram showing the processing flow of the entry / exit system 3 in the third embodiment. First, the information control unit 102 acquires the vehicle-mounted device ID from the vehicle-mounted device information storage unit 103, and transmits it to the entry / exit roadside unit 200b via the communication unit 101 (step S201).

[0094] The vehicle-mounted device communication unit 201 notifies the vehicle-mounted device ID to the communication control unit 205. The communication control unit 205 executes encryption processing of the vehicle-mounted device ID using the encryption processing unit 202. The encryption processing unit 202 generates an encrypted vehicle-mounted device ID from the vehicle-mounted device ID (step S202). The communication control unit 205 transmits the encrypted vehicle-mounted device ID to the vehicle-mounted device ID matching device 300 via the IP communication unit 204 (step S203).

[0095] The IP communication unit 301 notifies the information control unit 303 of the encrypted vehicle-mounted device ID. The information control unit 303 executes a decryption process of the encrypted vehicle-mounted device ID using the decryption processing unit 304. The decryption processing unit 304 generates a vehicle-mounted device ID from the encrypted vehicle-mounted device ID (step S204). The information control unit 303 identifies an vehicle-mounted device ID record with a matching vehicle-mounted device ID from the vehicle-mounted device ID table 311 in the device information storage unit 302 (step S205). If the vehicle-mounted device IDs match (step S205-YES), the information control unit 303 acquires the value of the mobile terminal ID (step S206). If the vehicle-mounted device IDs do not match (step S205-NO), the vehicle-mounted device ID verification device 300 terminates the process (step S207). The information control unit 303 transmits the mobile terminal ID to the entry / exit management device 400b via the IP communication unit 301 (step S208).

[0096] The IP communication unit 401 notifies the authentication control unit 402b of the mobile terminal ID. The authentication control unit 402b causes the authentication processing unit 404b to execute authentication processing of the mobile terminal ID. Specifically, the authentication processing unit 404b compares the mobile terminal ID received from the vehicle-mounted device ID matching device 300 with the mobile terminal ID registered in the authentication information record b, and if a predetermined authentication condition is met (for example, they match), the authentication processing unit 404b determines that the vehicle-mounted device 100 is a device with legitimate authority. On the other hand, if the predetermined condition is not met (for example, they do not match), the authentication processing unit 404b determines that the vehicle-mounted device 100 is a device without legitimate authority (step S216b). The authentication control unit 402b transmits the authentication processing execution result to the entry / exit roadside unit 200 (step S217).

[0097] The IP communication unit 204 notifies the entrance / exit control unit 206 of the result of the authentication process. The entrance / exit control unit 206 executes processing based on the result of the authentication process (step S218). If the result of the authentication process is successful (step S218-YES), the entrance / exit control unit 206 sends an instruction to open the gate to the entrance / exit inhibitor 600 via the entrance / exit communication unit 207 (step S219). On the other hand, if the result of the authentication process is not successful (step S218-NO), the entrance / exit control unit 206 ends the processing (step S220).

[0098] The communication unit 601 notifies the entrance / exit control unit 602 of the gate opening instruction. Upon receiving the gate opening instruction, the entrance / exit control unit 602 executes the gate opening process of the entrance / exit control unit 603 (step S221).

[0099] According to at least one of the embodiments described above, by having an authentication processing function for authentication information and a mobile terminal ID, it is possible to identify a person inside the vehicle with higher accuracy.

[0100] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These embodiments can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, as well as within the scope of the invention described in the claims and their equivalents. [Explanation of symbols]

[0101] 1...entrance / exit system, 2...entrance / exit system, 3...entrance / exit system, 10...facility, 100...vehicle-mounted device, 101...communication unit, 102...information control unit, 103...vehicle-mounted device information storage unit, 104...audio output unit, 105...display unit, 106...card input / output unit, 107...card, 200...entrance / exit roadside device, 201...vehicle-mounted device communication unit, 202...encryption processing unit, 203...terminal communication unit, 204...IP communication unit, 205...communication control unit, 206...entrance / exit control unit, 207...entrance / exit communication unit, 300...vehicle-mounted device ID matching device, 301...IP communication unit, 302...device information storage unit, 303...information control unit, 304...decryption processing unit, 311...vehicle-mounted device ID table, 400...entrance / exit management device, 401...IP communication unit, 402...authentication control unit, 403...authentication information storage unit, 40 4...authentication processing unit, 405...facility variable password generation unit, 411...authentication information table, 500...mobile terminal, 501...short-range wireless communication unit, 502...input / output control unit, 503...display unit, 504...input unit, 600...entry / exit restrictor, 601...communication unit, 602...entry / exit control unit, 603...entry / exit restrictor, 200a...entry / exit roadside device, 202a...encryption processing unit, 205a...communication control unit, 208a...installer information storage unit, 300a...vehicle-mounted device ID matching device, 302a...device information storage unit, 303a...information control unit, 304a...decryption processing unit, 311a...vehicle-mounted device ID table, 200b...entry / exit roadside device, 400b...entry / exit management device, 402b...authentication control unit, 403b...authentication information storage unit, 404b...authentication processing unit, 411b...authentication information table

Claims

1. a device information storage unit that stores a record in which an in-vehicle device ID, which is identification information of the in-vehicle device, is associated with user information that can uniquely identify a user of the in-vehicle device; a communication unit that receives, from an access roadside device provided near a facility to be managed, information indicating an on-board device ID that the access roadside device has received from an on-board device of a vehicle; an acquisition unit that acquires the user information related to a record stored in the device information storage unit when the record matches the vehicle-mounted device ID indicated by the received information; an authentication processing unit that receives, from a terminal communication unit provided near the facility to be managed, verification information acquired by the terminal communication unit from a mobile terminal of the user located near the terminal communication unit, and performs authentication processing based on the acquired user information and the received verification information; A user identification system comprising:

2. The verification information is information for identifying the user by verifying it with the user information. The user identification system according to claim 1 .

3. 2. The user identification system according to claim 1, wherein the verification information includes a password that is periodically generated.

4. 2. The user identification system according to claim 1, wherein the verification information includes a password preset by the user.

5. The record stored in the device information storage unit further includes a facility ID of the facility to be managed, The communication unit receives the facility ID. The user identification system according to any one of claims 1 to 4.

6. the communication unit receives the encrypted vehicle-mounted device ID as information indicating the vehicle-mounted device ID, The acquisition unit decrypts the encrypted vehicle-mounted device ID, and if a record that matches the vehicle-mounted device ID obtained by the decryption is stored in the device information storage unit, acquires the user information related to the record. The user identification system according to any one of claims 1 to 5.

7. an entry / exit control unit that determines whether or not an entry / exit control unit that restricts entry into or exit from the facility to be managed is open or closed based on the execution result of the authentication process; The user identification system according to claim 1 , comprising:

8. The entry / exit control unit does not open the gate when a record that matches the vehicle-mounted device ID indicated by the received information is not stored in the device information storage unit. The user identification system according to claim 7.

9. A user identification method performed by a user identification system including a device information storage unit that stores a record associating an on-board device ID, which is identification information of an on-board device, with user information that can uniquely identify a user of the on-board device, and one or more information processing devices, a receiving step in which the information processing device receives, from an access roadside device provided near a facility to be managed, information indicating an on-board device ID received by the access roadside device from an on-board device of a vehicle; an information acquisition step of the information processing device acquiring the user information related to a record stored in the device information storage unit when the record matches the vehicle-mounted device ID indicated by the received information; an authentication processing step in which the information processing device receives, from a terminal communication unit provided near the facility to be managed, verification information acquired from a mobile terminal of the user near the terminal communication unit, and performs authentication processing based on the acquired user information and the received verification information; A user identification method having the following.

Citation Information

Patent Citations

  • Parking lot management system

    JP2005227996A

  • Parking lot reservation system, parking lot reservation method, parking lot management server and program

    JP2008242555A

  • Utterance right adjusting system and voice output device

    JP2009294310A