Authentication device, authentication method, and program
The authentication device uses multiple receiver sets to validate device legitimacy and location within a defined area, preventing unintended processing by ensuring user presence, thus enhancing security and control.
Patent Information
- Application Number
- JP2024204990
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2025-12-24
- Estimated Expiration
- 2044-11-25
AI Technical Summary
Hands-free authentication can be performed in unintended situations, leading to unauthorized processing such as payment, without user intent.
An authentication device that includes a first and second receiver set to determine the legitimacy of the device and its location, with an area determination unit to ensure the device is within a predefined authentication area, preventing processing unless the user is intentionally present.
Prevents unauthorized processing by ensuring the user's intent is verified through device authentication and location confirmation within a designated area, enhancing security and user control.
Smart Images

Figure 0007791601000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an authentication device that receives an authentication request transmitted from a device to be authenticated and performs authentication. [Background technology]
[0002] Conventionally, there is known an authentication device that receives an authentication request transmitted from a device to be authenticated and performs authentication (see, for example, Patent Document 1). By performing authentication using such an authentication request, it is possible to perform, for example, hands-free authentication that does not require any operation by the user. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] International Publication No. 2020 / 080301 Summary of the Invention [Problem to be solved by the invention]
[0004] However, hands-free authentication has a problem in that authentication may be performed in a situation not intended by the user, and may be determined to be valid, leading to processing such as payment.
[0005] The present invention has been made to solve the above-mentioned problems, and aims to provide an authentication device etc. that can prevent predetermined processing from being executed in response to authentication performed in a situation not intended by the user. [Means for solving the problem]
[0006] In order to achieve the above-mentioned object, an authentication device according to one embodiment of the present invention comprises: a first receiver set including one or more first receivers that receive an authentication request transmitted from a device to be authenticated, the first receiver set including one or more first receivers that receive the authentication request transmitted from the device to be authenticated, the second receiver set including one or more second receivers that receive the authentication request transmitted from the device to be authenticated; a device authentication unit that performs device authentication to determine whether the device to be authenticated that transmitted the authentication request is legitimate using the authentication information contained in the authentication request received by at least one of the one or more first receivers and the one or more second receivers; an identification unit that identifies the position of the device to be authenticated based on the strength difference between the authentication requests received by the first and second receiver sets, respectively; an area determination unit that performs area determination to determine whether the position of the device to be authenticated identified by the identification unit is included in an authentication area shown on the floor; and an output unit that outputs information regarding the execution of a predetermined process for a user carrying the device to be authenticated when the device authentication determines that the device to be authenticated is legitimate and the area determination determines that the position of the device to be authenticated is included in the authentication area.
[0007] With this configuration, when the device to be authenticated is determined to be valid in device authentication and the location of the device to be authenticated is included in the authentication area, a predetermined process can be executed, and for example, the predetermined process can be prevented from being executed if the user does not enter the authentication area indicated on the floor. Therefore, it is possible to prevent the predetermined process from being executed in response to authentication performed in a situation that the user does not intend.
[0008] In the authentication device according to one aspect of the present invention, the authentication area may be indicated by a mat placed on the floor.
[0009] With this configuration, for example, the position of the authentication area can be changed by changing the position of the mat.
[0010] In the authentication device according to one aspect of the present invention, the authentication area may be displayed on the floor surface.
[0011] The authentication device according to an aspect of the present invention may further include a display unit that displays the authentication area on the floor surface.
[0012] With this configuration, for example, the display position of the authentication area can be changed more easily.
[0013] In the authentication device according to an aspect of the present invention, the display unit may change the display position of the authentication area.
[0014] With this configuration, for example, when the user enters the authentication area after changing the display position, a predetermined process can be performed.
[0015] In addition, in an authentication device according to one aspect of the present invention, the output unit may output information regarding the execution of a specified process when the device to be authenticated is determined to be valid in the device authentication and when it is determined in the area determination that only the position of the device to be authenticated is included in the authentication area.
[0016] With this configuration, when only one authenticated device that is the target of authentication is present in the authentication area, a predetermined process can be performed.
[0017] In addition, an authentication device according to one aspect of the present invention may further include a sensor that acquires information regarding the authentication area, and a number acquisition unit that acquires the number of people present in the authentication area using the information acquired by the sensor, and the output unit may output information regarding the execution of a specified process when the device to be authenticated is determined to be valid in the device authentication, and the position of the device to be authenticated is determined to be included in the authentication area in the area determination, and the number of people acquired by the number acquisition unit is one.
[0018] With this configuration, when only one user carrying the device to be authenticated is present in the authentication area, a predetermined process can be performed.
[0019] In the authentication device according to one aspect of the present invention, the sensor may be a weight sensor that acquires the weight in the authentication area, or an image sensor that acquires an image of the authentication area.
[0020] In addition, an authentication device according to one aspect of the present invention may further include a status output unit that performs a first output when the device to be authenticated is determined to be valid in device authentication and the area determination determines that the position of the device to be authenticated is not included in the authentication area, performs a second output when the device to be authenticated is determined to be valid in device authentication and the area determination determines that the position of the device to be authenticated is included in the authentication area and the execution of a specified process has not been completed, and performs a third output when the execution of the specified process has been completed.
[0021] With this configuration, the user can know the authentication results, judgment results, and the status of the execution of a specified process, such as whether the specified process can be executed or not, and whether the execution of the specified process has been completed.
[0022] In the authentication device according to an aspect of the present invention, the situation output unit may perform a fourth output when the area determination unit determines that the positions of two or more devices to be authenticated are included in the authentication area.
[0023] With this configuration, for example, the fourth output can be provided to inform the user of the reason why a predetermined process is not performed.
[0024] In the authentication device according to an aspect of the present invention, the predetermined process may be a payment process.
[0025] In the authentication device according to an aspect of the present invention, the predetermined process may be an unlocking process.
[0026] Furthermore, an authentication method according to one aspect of the present invention is an authentication method processed using a first receiver set including one or more first receivers, a second receiver set including one or more second receivers, a device authentication unit, an identification unit, an area determination unit, and an output unit, and includes the steps of: one or more first receivers included in the first receiver set receiving an authentication request transmitted from a device to be authenticated, the authentication request including authentication information used to authenticate the device to be authenticated; one or more second receivers included in the second receiver set receiving the authentication request transmitted from the device to be authenticated; and the device authentication unit determining whether or not the authentication information included in the authentication request received by at least one of the one or more first receivers and the one or more second receivers is authenticating the device. the step of performing device authentication using the authentication information to determine whether the authenticated device that transmitted the authentication request is legitimate; the step of the identification unit identifying the position of the authenticated device based on the strength difference between the authentication requests received by the first and second receiver sets, respectively; the step of the area determination unit performing area determination to determine whether the identified position of the authenticated device is included in an authentication area shown on the floor; and the step of the output unit outputting information regarding the execution of a predetermined process for the user carrying the authenticated device when the device authentication determines that the authenticated device is legitimate and the area determination determines that the position of the authenticated device is included in the authentication area. [Effects of the Invention]
[0027] According to an aspect of the present invention, an authentication device or the like can prevent a predetermined process from being executed in response to authentication performed in a situation not intended by the user. [Brief explanation of the drawings]
[0028] [Figure 1] FIG. 1 is a block diagram showing a configuration of an authentication device according to an embodiment of the present invention. [Figure 2A] FIG. 10 is a diagram illustrating an authentication area in the embodiment. [Figure 2B] FIG. 10 is a diagram illustrating an authentication area in the embodiment. [Figure 3]FIG. 2 shows an example of an authentication area set in front of a vending machine according to the embodiment. [Figure 4] A flowchart showing the operation of the authentication device according to the embodiment. [Figure 5] FIG. 2 is a block diagram showing another example of the configuration of the authentication device according to the embodiment. [Figure 6] FIG. 2 is a block diagram showing another example of the configuration of the authentication device according to the embodiment. [Figure 7] FIG. 2 shows an example of the configuration of a computer system according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0029] An authentication device and authentication method according to the present invention will be described below using embodiments. In the following embodiments, components and steps denoted by the same reference numerals are the same or equivalent, and repeated description may be omitted. The authentication device according to this embodiment outputs information related to the execution of a predetermined process for a user carrying the device to be authenticated when the device authentication determines that the device to be authenticated is valid and the area determination determines that the location of the device to be authenticated is included in an authentication area shown on the floor.
[0030] FIG. 1 is a block diagram showing the configuration of an authentication device 1 according to this embodiment. The authentication device 1 according to this embodiment includes a first receiver set 11, a second receiver set 12, a device authentication unit 13, an identification unit 14, a region determination unit 15, and an output unit 16. If necessary, the authentication device 1 may further include a status output unit 17. The authentication device 1 according to this embodiment may perform device authentication to determine whether the device to be authenticated 2 carried by the user 5 is authentic, and region determination to determine whether the device to be authenticated 2 is included in an authentication region R2 displayed on the floor. Based on these results, the authentication device 1 may output information to cause an execution unit 51 to execute a predetermined process. The predetermined process performed by the execution unit 51 may be, for example, a payment process or a lock-opening process, or any other process performed on the user 5 carrying the device to be authenticated 2 determined to be authentic. The payment process may enable the user 5 to purchase a product or receive a service. The payment process may be performed, for example, at a POS register or a vending machine. Furthermore, the unlocking process may allow the user 5 to enter a house, a hotel room, a conference room, or the like.
[0031] 1 and 3 show a situation in which the user 5 holds the device to be authenticated 2 in his / her hand, the user 5 carrying the device to be authenticated 2 may mean, for example, that the device to be authenticated 2 moves in accordance with the movement of the user 5, and the user 5 does not necessarily have to be holding the device to be authenticated 2 in his / her hand. The device to be authenticated 2 may be placed in, for example, a pocket of the clothes of the user 5 or in a bag. Also, while FIG. 1 shows a case in which the authentication device 1 receives an authentication request from one device to be authenticated 2 carried by one user 5, the authentication device 1 may receive authentication requests from, for example, multiple devices to be authenticated 2 carried by multiple users 5.
[0032] The authentication device 1 may or may not have, for example, an execution unit 51. In the latter case, the authentication device 1 may, for example, control the execution of a predetermined process in the execution unit 51 of an external device.
[0033] The device to be authenticated 2 may be, for example, a smartphone, a tablet terminal, a PDA (Personal Digital Assistant), a notebook computer, a portable information terminal with a communication function such as a transceiver, or other devices.
[0034] The first receiver set 11 includes one or more first receivers 11a. Each of the one or more first receivers 11a receives an authentication request transmitted from the device to be authenticated 2, the authentication request including authentication information used to authenticate the device to be authenticated 2. The device to be authenticated 2 may transmit the authentication request in the form of, for example, radio waves. The first receiver set 11 may be located at a first location. The authentication request may include, for example, a user identifier of a user 5 carrying the device to be authenticated 2 transmitting the authentication request, or a device identifier identifying the device to be authenticated 2. The user identifier may be, for example, the user's telephone number, address such as an email address, name, etc., or a character string unique to the user. The device identifier may be, for example, the address of the device or a character string unique to the device. The device address may be, for example, a physical address such as a MAC address, or another address.
[0035] The second receiver set 12 includes one or more second receivers 12a. Each of the one or more second receivers 12a receives an authentication request transmitted from the authenticatee 2. The second receiver set 12 may be located at a second location different from the first location. Note that the second receiver set 12 may be the same as the first receiver set 11 except for the location where it is located.
[0036] From the viewpoint of realizing more accurate location identification of the device to be authenticated 2, it is preferable that the first receiver set 11 includes a plurality of first receivers 11a, and the second receiver set 12 includes a plurality of second receivers 12a. As shown in Fig. 1, for example, the first receiver set 11 may include four first receivers 11a, and the second receiver set 12 may include four second receivers 12a, but the number of receivers included in the first and second receiver sets 11, 12 may be any number from one to three, or may be five or more. Each of the receivers 11a, 12a included in the first and second receiver sets 11, 12 is capable of acquiring the strength of radio waves of an authentication request.
[0037] When the first receiver set 11 includes a plurality of first receivers 11a, the first position may be, for example, the position of the center of gravity of the plurality of first receivers 11a. More specifically, the position of the center of gravity of each of the first receivers 11a may be identified, and the position of the center of gravity of the identified plurality of center of gravity may be set as the first position. The plurality of first receivers 11a may be located, for example, close to each other, or may be located at distant locations. Even in the latter case, it is preferable that the plurality of first receivers 11a are included within a range of the distance from the first position to the second position. The same applies to the second position of the second receiver set 12.
[0038] The first receiver 11a and the second receiver 12a may or may not include a wireless receiving device such as an antenna for receiving radio waves. The first receiver 11a and the second receiver 12a may be realized by hardware or software such as a driver that drives the receiving device.
[0039] The authentication request, which is a radio wave, may be, for example, a pulse wave transmitted intermittently or a continuous wave transmitted continuously. Furthermore, any wireless communication standard may be used to transmit and receive the authentication request. For example, the authentication request may be communicated via Bluetooth Low Energy (BLE), Bluetooth Basic Rate (BR) / Enhanced Data Rate (EDR), wireless LAN (IEEE802.11), IEEE802.15.4 such as ZigBee (registered trademark), or any other wireless communication standard. It is preferable that the authentication request be transmitted and received via short-range wireless communication such as BLE, Bluetooth BR / EDR, or wireless LAN.
[0040] The frequency of the radio wave of the authentication request is not particularly limited, and may be, for example, a frequency in the range of 300 MHz to 300 GHz. Furthermore, the device to be authenticated 2 may transmit the authentication request by broadcast or by unicast, for example. Since the authentication request can be transmitted without specifying the communication partner, transmitting the authentication request by broadcast is preferable. In this embodiment, a case where the device to be authenticated 2 transmits the authentication request by broadcast will be mainly described. It is preferable that the device to be authenticated 2 transmits the authentication request without receiving a transmission instruction from the user 5. The device to be authenticated 2 may transmit the authentication request in response to receiving a predetermined beacon, for example. In response to receiving this beacon, the device to be authenticated 2 may transmit the authentication request only once, or may transmit the authentication request for a predetermined period of time, or may continuously transmit the authentication request while receiving this beacon. This beacon may be transmitted, for example, in an area where authentication using the authentication request is performed. As an example, the authentication device 1 may transmit the beacon. In this case, the authentication device 1 may further include a transmitter for transmitting the beacon.
[0041] The authentication information included in the authentication request may include any information that can be used to authenticate the device to be authenticated 2. For example, it may include cryptographic information obtained by encrypting unique information, which is unique information. The unique information may include, for example, a time, a random number, a count value, or a one-time password. The unique information may be information specific to the authentication request. That is, the unique information corresponding to the cryptographic information included in each authentication request may be different. The unique information may be, for example, information generated by the device to be authenticated 2 or information transmitted from the authentication device 1 to the device to be authenticated 2. In the latter case, challenge-response authentication may be performed by the authentication device 1. When the unique information is transmitted from the authentication device 1, the authentication device 1 may further include a transmitting unit that transmits the unique information. This embodiment mainly describes the case where the unique information is generated by the device to be authenticated 2. Like the cryptographic information described above, it is preferable that the authentication information includes different information for each authentication request. This is to prevent the authentication information from being reused by a malicious third party. Furthermore, for example, the cryptographic information may be information obtained by encrypting a user identifier and unique information. In this case, the encryption information may be considered to be information including, for example, a user identifier and authentication information.
[0042] The encryption of the unique information may be, for example, encryption using a common key encryption or encryption using a public key encryption. That is, the encryption key used to encrypt the unique information may be, for example, a common key or a public key corresponding to the authentication device 1. When the encryption key is a common key, it is preferable that the authentication device 1 and the device to be authenticated 2 have the same common key. It is also preferable that the common key is different for each device to be authenticated 2.
[0043] The device to be authenticated 2 may or may not be in line of sight from the authenticating device 1. In the latter case, the user 5 may carry the device to be authenticated 2 in, for example, a pocket of clothes or a bag.
[0044] The device authentication unit 13 performs device authentication to determine whether the device to be authenticated 2 that transmitted the authentication request is legitimate, using authentication information included in the authentication request received by at least one of the one or more first receivers 11 a and the one or more second receivers 12 a. For example, if the authentication information includes cryptographic information in which unique information is encrypted, the device to be authenticated 2 that transmitted the authentication request may be determined to be legitimate if the unique information corresponding to the cryptographic information matches the unique information stored in the authentication device 1 and corresponding to the device to be authenticated 2 that transmitted the authentication information. Otherwise, the device to be authenticated 2 that transmitted the authentication information may be determined to be invalid. Whether the unique information corresponding to the cryptographic information matches the unique information stored in the authentication device 1 may be determined, for example, by whether the unique information obtained by decrypting the cryptographic information matches the unique information stored in the authentication device 1, or by whether the cryptographic information matches the result of encrypting the unique information stored in the authentication device 1.
[0045] When the unique information is acquired in the device to be authenticated 2, the unique information stored in the authentication device 1 may be, for example, acquired by the same method as that used to acquire the unique information in the device to be authenticated 2. When the device to be authenticated 2 receives the unique information from the authentication device 1, the unique information stored in the authentication device 1 may be, for example, the unique information transmitted from the authentication device 1 to the device to be authenticated 2.
[0046] When the cryptographic information included in the authentication information is encrypted with a common key, the device authentication unit 13 may, for example, read out the common key stored in a predetermined recording medium in association with the user identifier included in the authentication information together with the authentication information, and decrypt the cryptographic information using the read common key, or may use the read common key to encrypt the unique information stored in the authentication device 1. When the cryptographic information included in the authentication information is encrypted with a public key, the device authentication unit 13 may, for example, read out a private key from a predetermined recording medium and decrypt the cryptographic information using the read private key, or may read out a public key from a predetermined recording medium and encrypt the unique information stored in the authentication device 1 using the read public key.
[0047] The device authentication unit 13 may perform device authentication using one authentication request, or may perform device authentication using multiple authentication requests received within a predetermined period. For authentication using multiple authentication requests, see, for example, Patent Document 1 above.
[0048] The identification unit 14 identifies the location of the authenticatee 2 based on the strength difference of the authentication requests received by the first and second receiver sets 11 and 12, respectively. The strength difference of the authentication requests may be, for example, the difference in received signal strength (RSSI: Received Signal Strength Indicator) of the authentication requests. Furthermore, if the first and second receiver sets 11 and 12 include two or more receivers, the strength difference may be, for example, the difference between representative values of multiple received signal strengths acquired by the two or more receivers in the first and second receiver sets 11 and 12, respectively. The representative value may be, for example, an average value, a median value, or the like. Furthermore, if the first and second receiver sets 11 and 12 include two or more receivers, it is preferable that the two or more receivers have equivalent performance. For example, it is preferable that the antenna gains of the two or more receivers included in the first receiver set 11 or the second receiver set 12 are the same. When determining the location of the wave source using the intensity difference of the received authentication request, for example, an Apollonius circle or line corresponding to the difference in reception intensity can be determined using the reception intensity of the authentication request received by the first and second receiver sets 11, 12 and the first and second positions of the first and second receiver sets 11, 12, and the position on the Apollonius circle, line, or within the circle can be determined as the position of the device to be authenticated 2, or the position of the device to be authenticated 2 can be determined by other methods.
[0049] Furthermore, the position identified by the identification unit 14 may be, for example, a point-like position, or a linear, planar, or three-dimensional position. In this embodiment, a case where a point-like position of the device to be authenticated 2 is identified by the identification unit 14 will be mainly described. The identified position may be, for example, a position on a two-dimensional plane, or a position in three-dimensional space. In this embodiment, the former case will be mainly described. When identifying a planar position, the identification unit 14 may, for example, identify whether the position of the device to be authenticated 2 is within the authentication region R2.
[0050] Since the method of determining the location of a wave source using the difference in the received strength of radio waves is already known, a detailed description thereof will be omitted. For such a method of determining the location of a wave source, please refer to the following document, for example: Literature: International Publication No. 2020 / 080314
[0051] The area determination unit 15 performs area determination to determine whether the position of the device to be authenticated 2 identified by the identification unit 14 is included in the authentication area R2 displayed on the floor. When the user 5 carries the device to be authenticated 2, the position of the device to be authenticated 2 can be considered to be substantially the position of the user 5. Therefore, when the area determination unit 15 determines that the position of the device to be authenticated 2 is included in the authentication area R2, it can be considered that the user 5 carrying the device to be authenticated 2 is determined to be present in the authentication area R2. It is preferable that the authentication area R2 be displayed so that the user 5 can easily visually distinguish the authentication area R2 from other areas in the real environment. Alternatively, the area determination unit 15 may read information indicating the authentication area R2 stored in a recording medium (not shown) and use the read information indicating the authentication area R2 to determine whether the identified position of the device to be authenticated 2 is included in the authentication area R2. For example, the information indicating the authentication area R2 may be information indicating the outline of the authentication area R2.
[0052] As one example, the authentication area R2 may be displayed on the floor. The authentication area R2 displayed on the floor may be, for example, an area painted on the floor, an area defined by sticking tape on the floor, or an area displayed by the display unit 21 (described later). As another example, the authentication area R2 may be indicated by a mat placed on the floor. In this case, for example, an area on the mat placed on the floor may become the authentication area R2. In this case, the position of the authentication area R2 can be changed by changing the position of the mat. Note that when the position of the mat is changed, for example, the position of the mat after the change, i.e., the position of the authentication area R2 after the change, is preferably stored in a recording medium (not shown) as information indicating the authentication area R2.
[0053] Furthermore, it is preferable that the user 5 can easily visually distinguish between the authentication area R2 and other areas in the real space. As an example, the authentication area R2 shown on the floor may be displayed with a display indicating that it is the authentication area R2, such as "OK," and the other areas may be displayed with a display indicating that it is not the authentication area R2, such as "NG."
[0054] As shown in the plan view of Fig. 2A, the area R1 in which the position of the device to be authenticated 2 is identified by the identification unit 14 may include an authentication area R2 and a non-authentication area R3. The non-authentication area R3 may be an area in the area R1 other than the authentication area R2. For example, as shown in Fig. 2A, when the identification unit 14 identifies the position P1 of the device to be authenticated 2, the area determination unit 15 may determine in the area determination that the position P1 of the device to be authenticated 2 is included in the authentication area R2.
[0055] As another example, as shown in the plan view of FIG. 2B , the area R1 in which the position of the device to be authenticated 2 is identified by the identification unit 14 may include an authentication area R2, a gray area R4 surrounding the authentication area R2, and a non-authentication area R3 other than these. The non-authentication area R3 may be an area in the area R1 other than the authentication area R2 and the gray area R4. It is preferable that the device to be authenticated 2, i.e., the user 5, is not present in the gray area R4. Therefore, in real space, guidance or the like may be provided to prevent the user from standing in the gray area R4. By providing the gray area R4, it becomes possible to more accurately determine whether the position of the device to be authenticated 2 is included in the authentication area R2.
[0056] The order of device authentication by the device authentication unit 13 and area determination by the area determination unit 15 does not matter. For example, area determination may be performed after device authentication. In this case, area determination may be performed, for example, only for devices to be authenticated 2 that are determined to be valid in device authentication. Also, for example, device authentication may be performed after area determination. In this case, device authentication may be performed, for example, only for devices to be authenticated 2 that are determined to be included in authentication area R2 in area determination. Whether the device to be authenticated 2 that is the subject of device authentication and the device to be authenticated 2 that is the subject of area determination are the same device may be determined, for example, using a user identifier or device identifier included in the authentication request. Also, for example, device authentication and area determination may be performed independently for the device to be authenticated 2 that sent the authentication request.
[0057] When the device authentication unit 13 determines that the authenticated device 2 is valid in device authentication and the area determination unit 15 determines that the location of the authenticated device 2 is included in the authentication area R2, the output unit 16 outputs information regarding the execution of a predetermined process for the user carrying the authenticated device 2. If this is not the case, the output unit 16 may, for example, not output information, or may output information indicating that the predetermined process is not to be executed. The output regarding the execution of the predetermined process may, for example, be information indicating that the execution of the predetermined process is permitted, or information indicating that the predetermined process is to be executed. It is preferable that the output regarding the execution of the predetermined process results in the execution of the predetermined process. For example, when purchasing an item from a vending machine, after the output unit 16 outputs information regarding the execution of the predetermined process, the payment process, which is the predetermined process, may be executed when the user 5 presses a product selection button on the vending machine.
[0058] On the other hand, if at least in device authentication it is determined that the authenticated device 2 is not legitimate, the predetermined process may not be executed, and if at least in area determination it is determined that the position of the authenticated device 2 is not included in the authentication area R2, the predetermined process may not be executed. The predetermined process may be executed, for example, by the execution unit 51. If the predetermined process executed by the execution unit 51 is a payment process, the output unit 16 may, for example, output a user identifier or a device identifier included in the authentication request to the execution unit 51 when outputting information related to the execution of the process. Then, the execution unit 51 may perform the payment process using payment information linked to the output user identifier or device identifier. The payment information is information used to perform payment, and may be, for example, information on a credit card or electronic money.
[0059] For example, when a user 5 carrying a legitimate device to be authenticated 2 is present within the authentication area R2, the output unit 16 may output a signal to cause a predetermined process to be executed. As a result, the user 5 may be able to, for example, purchase a product or unlock a door to their home. On the other hand, when a user 5 carrying a legitimate device to be authenticated 2 is not present within the authentication area R2, the output unit 16 may output a signal to prevent a predetermined process from being executed, or may not output a signal to cause a predetermined process to be executed. As a result, the user 5 may be prevented from, for example, making a payment for the purchase of a product or unlocking a door to their home. In this way, the user 5 can determine whether a predetermined process, such as a payment process or an unlocking process, is to be executed depending on whether or not they are present within the authentication area R2 indicated on the floor. This prevents a predetermined process from being executed in a situation unintended by the user 5. On the other hand, when a user 5 carrying a legitimate authenticated device 2 is present in the authentication area R2, a predetermined process can be automatically performed using the authentication request sent from the authenticated device 2, and the user 5 can perform predetermined processes such as payment processing and unlocking processing hands-free.
[0060] The output unit 16 may output information regarding the execution of a predetermined process for a user carrying the authenticated device 2, for example, when the device authentication unit 13 determines that the authenticated device 2 is valid in device authentication and the area determination unit 15 determines that the location of the authenticated device 2 has been included in the authentication area R2 for a predetermined time period since the reference time point. This allows the predetermined process to be executed when the user 5 stays in the authentication area R2 for a predetermined time period since the reference time point, and prevents the predetermined process from being executed even if the user 5 is in the authentication area R2 for only a short time. Therefore, even if the user 5 unintentionally enters the authentication area R2, the predetermined process is prevented from being executed by immediately exiting the authentication area R2, and the predetermined process can be executed according to the user 5's intention. The reference time point may be, for example, the time point when the user 5 enters the authentication area R2, the time point when the user 5 performs some operation, such as pressing a product selection button on a vending machine, or another predetermined time point. The predetermined time may be, for example, about 1 to 5 seconds, or about 2 to 4 seconds. In this way, the predetermined time may be a short time.
[0061] The status output unit 17 may output information related to the status of authentication and the status of execution of a predetermined process. For example, the status output unit 17 may output a first output when the device authentication determines that the device to be authenticated 2 is authentic and the area determination determines that the location of the device to be authenticated 2 is not included in the authentication area R2. The status output unit 17 may output a second output when the device authentication determines that the device to be authenticated 2 is authentic and the area determination determines that the location of the device to be authenticated 2 is included in the authentication area R2 and the execution of the predetermined process has not been completed. The status output unit 17 may output a third output when the device authentication determines that the device to be authenticated 2 is authentic and the area determination determines that the location of the device to be authenticated 2 is included in the authentication area R2 and the execution of the predetermined process has been completed. The status output unit 17 may receive information related to the completion of the execution of the predetermined process, for example, from the execution unit 51. It is assumed that the first to third outputs are different from each other. The different outputs may be, for example, outputs with different output contents, or outputs with different output methods or devices that perform the output.
[0062] The output from the status output unit 17 may be, for example, a display on a display device (e.g., a liquid crystal display or an organic EL display), a lit or blinking lamp, transmission to a predetermined device via a communication line, audio output through a speaker, printing by a printer, storage on a recording medium, or delivery to another component. The status output unit 17 may or may not include a device that performs output (e.g., a display device, a communication device, a speaker, etc.). The status output unit 17 may be realized by hardware, or may be realized by software such as a driver that drives those devices.
[0063] As an example, the first output may be an output indicating that the user 5 is not in the authentication area R2, the second output may be an output indicating that the predetermined process is waiting to be completed, and the third output may be an output indicating that the predetermined process has been completed. Such outputs allow the user 5 to know the progress of processes related to device authentication, area determination, and execution of the predetermined process. As another example, the first output may be an output recommending that the user 5 move to the authentication area R2 if the user wishes to execute the predetermined process. Then, after the user 5 moves to the authentication area R2 in response to this output, and it is determined in the area determination that the position of the device to be authenticated 2 is included in the authentication area R2, the output unit 16 may output an output related to the execution of the predetermined process.
[0064] The status output unit 17 may, for example, display character strings or figures indicating the contents on a display device, may output audio indicating the contents from a speaker, or may transmit information indicating the contents to the device to be authenticated 2. The status output unit 17 may, for example, perform the first to third outputs using two or more output devices. As an example, the status output unit 17 may display the first output on a display device, output the second output as audio from a speaker, and transmit the third output to the device to be authenticated 2 by a communication device. Note that the output method does not matter as long as the user 5 can understand which of the first to third outputs is being performed.
[0065] When the first to third outputs are transmission of information to the device to be authenticated 2, the device to be authenticated 2 may output according to the received information. As an example, the device to be authenticated 2 may vibrate when receiving according to the first output, output a sound according to the second output when receiving according to the second output, and output a sound according to the third output when receiving according to the third output.
[0066] Furthermore, the first to third outputs may be the lighting of lamps of different colors. As shown in Fig. 3, when the predetermined process is payment for purchasing a product in vending machine 50, the first to third outputs may be, for example, the lighting of first to third lamps 41-43. As an example, the first output may be the lighting of first lamp 41 in red, the second output may be the lighting of second lamp 42 in green, and the third output may be the lighting of third lamp 43 in blue.
[0067] Next, the operation of the authentication device 1 will be described with reference to the flowchart of FIG.
[0068] (Step S101) The first and second receiver sets 11 and 12 determine whether or not an authentication request has been received. If an authentication request has been received, the process proceeds to step S102; if not, the process of step S101 is repeated until an authentication request is received.
[0069] When device authentication is performed using multiple authentication requests, the process of receiving the authentication requests in step S101 may be repeated until the reception of the multiple authentication requests is completed. After the multiple authentication requests are received, the process may proceed to step S102.
[0070] (Step S102) The device authentication unit 13 performs device authentication using the authentication request received by one of the receivers of the first and second receiver sets 11 and 12.
[0071] (Step S103) If it is determined in the device authentication in step S102 that the authenticated device 2 that sent the authentication request is valid, the process proceeds to step S104, and if not, the process returns to step S101.
[0072] (Step S104) The identification unit 14 identifies the location of the authenticatee device 2 using the authentication requests received by the first and second receiver sets 11, 12. When multiple authentication requests are received, the location of the authenticatee device 2 may be identified using the authentication request received latest, for example, the authentication request received last.
[0073] (Step S105) The area determining unit 15 performs area determination to determine whether the position of the device to be authenticated 2 identified in step S104 is included in a preset authentication area R2.
[0074] (Step S106) If it is determined in the area determination in step S105 that the position of the device to be authenticated 2 is included in the authentication area R2, the process proceeds to step S108, and if not, the process proceeds to step S107.
[0075] In addition, if an output regarding the execution of a predetermined process is generated when the device authentication determines that the authenticated device 2 is authentic and the area determination determines that the location of the authenticated device 2 has been included in the authentication area R2 for more than a predetermined time from the reference time point, step S106 may determine whether the area determination determined that the location of the authenticated device 2 has been included in the authentication area R2 for more than a predetermined time from the reference time point. In this case, an area determination history, which is a pair of the reception time of the authentication request and the result of the area determination regarding the authentication request, may be stored in a recording medium (not shown), and this history may be used to determine whether the location of the authenticated device 2 has been included in the authentication area R2 for more than a predetermined time from the reference time point. Furthermore, when this determination is made, the first output may indicate that the device authentication determines that the authenticated device 2 is authentic and that the area determination does not determine that the location of the authenticated device 2 has been included in the authentication area R2 for more than a predetermined time from the reference time point. Furthermore, when this determination is made, a message may be output to the user 5 indicating that the predetermined process will not be performed because the authenticated device 2 has left the authentication area R2 before the predetermined time has passed since the reference time point. This output may be generated by, for example, the status output unit 17. In this case, it is preferable that device authentication is repeatedly performed, for example, every time an authentication request is received from a certain device to be authenticated 2. Note that, for example, after the authentication request received the first time from a certain device to be authenticated 2 is determined to be valid by device authentication, only area determination may be performed for authentication requests transmitted from that device to be authenticated 2, without device authentication being performed.
[0076] (Step S107) The status output unit 17 performs the first output, and then returns to step S101.
[0077] (Step S108) The situation output unit 17 performs the second output.
[0078] (Step S109) The output unit 16 outputs information related to the execution of a predetermined process. For example, the execution unit 51 may execute the predetermined process in response to this output, or the execution unit 51 may become ready to execute the predetermined process in response to this output, and then the predetermined process may be executed in response to the user 5 performing a predetermined operation such as selecting a product.
[0079] (Step S110) The status output unit 17 determines whether the execution of the predetermined process has been completed. If the execution of the predetermined process has been completed, the process proceeds to step S111; if not, the process of step S110 is repeated until the execution of the predetermined process is completed. Note that the status output unit 17 may determine that the execution of the predetermined process has been completed when it receives from the execution unit 51 a notification that the execution of the predetermined process has been completed. Furthermore, if the notification that the execution of the predetermined process has been completed is not received even after a predetermined time has elapsed after an output regarding the execution of the predetermined process, the status output unit 17 may determine that a timeout has occurred and return to step S101.
[0080] (Step S111) The status output unit 17 performs the third output, and then returns to step S101.
[0081] The series of processes shown in the flowchart of Fig. 4 are processes using an authentication request transmitted from one device to be authenticated 2. When authentication requests are transmitted from multiple devices to be authenticated 2, the series of processes shown in the flowchart of Fig. 4 may be executed in parallel for each of the multiple devices to be authenticated 2. The order of the processes in the flowchart of Fig. 4 is an example, and the order of the steps may be changed as long as the same results are obtained. In the flowchart of Fig. 4, the processes may be ended by power-off or an interrupt to end the processes.
[0082] Next, the operation of authentication device 1 according to this embodiment will be described using a specific example. In this specific example, the predetermined process is a payment process in vending machine 50 shown in Fig. 3, i.e., a payment process for purchasing a product. In this specific example, it is assumed that authentication device 1 is included inside vending machine 50. In this specific example, as shown in Fig. 3, an authentication area R2 is set in front of vending machine 50, and user 5 can visually recognize it.
[0083] First, assume that a user 5 carrying a legitimate device to be authenticated 2 approaches a vending machine 50. The device to be authenticated 2 then receives a beacon transmitted from the authentication device 1 inside the vending machine 50, and in response, transmits an authentication request from the device to be authenticated 2. At this point, assume that the user 5 is located outside the authentication area R2. The authentication request is received by the first and second receiver sets 11, 12 of the authentication device 1, and the authentication request is passed to the device authentication unit 13. At the same time, the received signal strength of the authentication request by the multiple first receivers 11a in the first receiver set 11 and the received signal strength of the authentication request by the multiple second receivers 12a in the second receiver set 12 are passed to the identification unit 14 (step S101).
[0084] Upon receiving the authentication request, the device authentication unit 13 performs device authentication using the authentication information included in the authentication request (step S102). Assume that this device authentication determines that the device to be authenticated 2 is legitimate (step S103). Then, the device authentication unit 13 passes information to the output unit 16 indicating that the device to be authenticated 2 is legitimate.
[0085] Upon receiving the received signal strength, the identification unit 14 acquires a representative value of the received signal strength acquired by the plurality of first receivers 11a and a representative value of the received signal strength acquired by the plurality of second receivers 12a, and identifies the location of the authenticated device 2 using the difference between the representative values of the received signal strength and the first and second positions which are the positions of the first and second receiver sets 11, 12, and passes it to the area determination unit 15 (step S104).
[0086] When the identified position of the device to be authenticated 2 is received, the area determination unit 15 performs area determination to determine whether the position is included in the authentication area R2 (step S105). Assume that this area determination determines that the position of the device to be authenticated 2 is not included in the authentication area R2 (step S106). Then, the area determination unit 15 passes to the output unit 16 a message indicating that the position of the device to be authenticated 2 is not included in the authentication area R2.
[0087] Upon receiving the device authentication result and the area determination result, the output unit 16 passes the device authentication result and the area determination result to the status output unit 17. The status output unit 17 then turns on the red first lamp 41 in response to them (step S107). Furthermore, since the output unit 16 has determined that the position of the authenticated device 2 is not included in the authentication area R2, it does not output any information related to the execution of the payment process. As a result, the execution unit 51 does not execute the predetermined process. Furthermore, the lighting of the red first lamp 41 informs the user 5 that he or she is not present in the authentication area R2 and therefore cannot purchase a product from the vending machine 50.
[0088] Next, suppose that user 5 enters authentication area R2. As in the above process, device authentication determines that the device 2 is valid, and this time, the area determination also determines that the location of the device to be authenticated 2 is included in authentication area R2 (steps S101 to S106). In response to these determination results, output unit 16 passes the device authentication result and the area determination result to status output unit 17. Upon receiving the device authentication result and the area determination result, status output unit 17 turns off red first lamp 41 and turns on green second lamp 42 accordingly (step S108). In this way, user 5 is informed that he or she can purchase a product from vending machine 50. Furthermore, output unit 16 outputs information regarding the execution of the payment process to execution unit 51 of vending machine 50 (step S109). In this case, after the output unit 16 has output information regarding the execution of the payment process, when the user 5 presses a button to select a product in the vending machine 50, the execution unit 51 may perform the payment process for the user 5, i.e., the process of charging for the product selected by the user 5. This charging may be, for example, charging using a preset credit card or electronic money.
[0089] When the payment process is completed, the execution unit 51 notifies the status output unit 17. Upon receiving the notification that the payment process is completed (step S110), the status output unit 17 turns off the green second lamp 42 and turns on the blue third lamp 43 (step S111). In this way, the user 5 can know that the payment has been completed.
[0090] For example, if another person is in front of the vending machine 50, the user 5 can avoid being charged for the product selected by the other person by not entering the authentication area R2.
[0091] As described above, according to the authentication device 1 of this embodiment, when the position of the device to be authenticated 2 that is determined to be valid in device authentication is included in the authentication area R2, a predetermined process is executed, so that, for example, by preventing a user 5 carrying a valid device to be authenticated 2 from entering the authentication area R2 shown on the floor, it is possible to prevent a predetermined process such as a payment process from being executed in a situation not intended by the user 5. On the other hand, when the user 5 is in the authentication area R2, a predetermined process is executed, so that the user 5 can execute the predetermined process hands-free without operating the device to be authenticated 2 or the like.
[0092] Furthermore, by the status output unit 17 producing the first to third outputs, the user 5 can learn from the outputs whether or not a predetermined process can be executed and the status regarding the execution of the predetermined process.
[0093] In the present embodiment, a case has been described in which output related to the execution of a predetermined process is performed when the device authentication determines that the device to be authenticated 2 is authentic and the area determination determines that the position of the device to be authenticated 2 is included in the authentication area R2. However, this is not necessarily the case. As an example, the output unit 16 may perform output related to the execution of a predetermined process when the device authentication determines that the device to be authenticated 2 is authentic and the area determination determines that only the position of the device to be authenticated 2 is included in the authentication area R2. In this case, if the area determination determines that the positions of two or more devices to be authenticated 2 are included in the authentication area R2, output related to the execution of a predetermined process does not have to be performed. This is because, if the authentication area R2 includes the positions of two or more devices to be authenticated 2, and both of the two or more devices to be authenticated 2 are determined to be authentic in the device authentication, it would be unclear for which device to be authenticated 2 the predetermined process is to be performed. Furthermore, even if only one of two or more authenticated devices 2 is determined to be legitimate in device authentication, it may be unclear whether the user 5 carrying the legitimate authenticated device 2 is in the authentication area R2 of his or her own volition, so no output regarding the execution of a specified process may be produced.
[0094] Furthermore, the status output unit 17 may perform a fourth output when the area determination unit 15 determines that the positions of two or more devices to be authenticated 2 are included in the authentication area R2. In this case, the user 5 can know from the fourth output that a predetermined process will not be executed because the positions of two or more devices to be authenticated 2 are included in the authentication area R2. The fourth output may be a display on a display device, a sound output from a speaker, or a transmission of information, similar to the first to third outputs, except that the first to fourth outputs are different from each other. As an example, the fourth output may be the lighting of a fourth orange lamp.
[0095] Furthermore, in this embodiment, the authentication area R2 may be displayed on the floor surface by, for example, the display unit 21. In this case, as shown in FIG. 5, the authentication device 1 may further include, for example, a display unit 21 for displaying the authentication area R2 on the floor surface. As an example, the display unit 21 may be a projector for displaying an image indicating the authentication area R2 on the floor surface. As another example, the display unit 21 may be a display placed on the floor surface. It is preferable that this display has enough strength to allow the user 5 to stand on it.
[0096] The display unit 21 may or may not include a display device (for example, a projector or a liquid crystal display) that displays the authentication area R2. The display unit 21 may be realized by hardware, or may be realized by software such as a driver that drives the display device.
[0097] When the authentication area R2 is displayed on the floor, the display unit 21 may, for example, change the display position of the authentication area R2. In this case, information indicating the current position of the authentication area R2 may be passed from the display unit 21 to the area determination unit 15. Then, the area determination unit 15 may use the current position of the authentication area R2 received from the display unit 21 to determine whether the position of the identified device to be authenticated 2 is included in the authentication area R2.
[0098] For example, the display unit 21 may change the display of the authentication area R2 so that the size of the authentication area R2 becomes smaller when there are many people near the authentication area R2, and may change the display of the authentication area R2 so that the size of the authentication area R2 becomes larger when there are few people near the authentication area R2. For example, when the authentication device 1 further includes a sensor 31 and a number-of-people acquisition unit 32 (described later), the display unit 21 may change the display of the authentication area so that the number of people included in the authentication area R2 acquired by the number-of-people acquisition unit 32 is one or less.
[0099] As another example, when the device to be authenticated 2 is determined to be valid in device authentication, the display unit 21 may display the authentication area R2 in a location that does not include the current position of the device to be authenticated 2. The display unit 21 may, for example, acquire the position of the device to be authenticated 2 from the identification unit 14. In this way, when the user 5 enters the authentication area R2, that is, when the user 5 wishes to execute a predetermined process, the predetermined process can be executed.
[0100] Furthermore, in this embodiment, whether or not a user 5 is present in the authentication area R2 may be determined using something other than an authentication request transmitted from the device to be authenticated 2. In this case, as shown in FIG. 6 , the authentication device 1 may further include a sensor 31 that acquires information about the authentication area R2, and a number-of-people acquisition unit 32 that acquires the number of people present in the authentication area R2 using the information acquired by the sensor 31. The sensor 31 may be, for example, a weight sensor that acquires the weight in the authentication area R2, or an image sensor that acquires an image of the authentication area R2. The weight in the authentication area R2 may be, for example, the weight of an object present in the authentication area R2. Furthermore, the sensor 31 may be a sensor other than a weight sensor or an image sensor, for example, a range sensor such as LiDAR.
[0101] If the sensor 31 is a weight sensor, the number of people acquisition unit 32 may, for example, divide the weight acquired by the weight sensor by a standard weight per person (e.g., 50 kg), and use the quotient, i.e., the value obtained by truncating the decimal point of the division result, as the number of people present in the authentication area R2.
[0102] If the sensor 31 is an image sensor, the number acquisition unit 32 may detect people within a range corresponding to the authentication area R2 in the captured image acquired by the image sensor, and the number of people detected may be taken as the number of people present in the authentication area R2.
[0103] In this case, the output unit 16 may output information regarding the execution of a specified process when the device to be authenticated 2 is determined to be valid in the device authentication, the area determination determines that the position of the device to be authenticated 2 is included in the authentication area R2, and the number of people acquired by the number acquisition unit 32 is one person.
[0104] In this way, the presence of user 5 in authentication area R2 can be confirmed using information acquired by sensor 31, and a predetermined process can be executed when user 5 is more definitely present in authentication area R2. Also, when two or more people are present in authentication area R2, the predetermined process can be prevented from being executed.
[0105] Furthermore, when the sensor 31 and the number of people acquisition unit 32 are used to acquire the number of people present in the authentication area R2, the status output unit 17 may, for example, produce a first output when the device to be authenticated 2 is determined to be legitimate in the device authentication and when the area judgment determines that the position of the device to be authenticated 2 is not included in the authentication area R2, produce a second output when the device to be authenticated 2 is determined to be legitimate in the device authentication and when the area judgment determines that the position of the device to be authenticated 2 is included in the authentication area R2, and the number of people acquired by the number of people acquisition unit 32 is one person and the execution of the specified processing has not been completed, produce a third output when the execution of the specified processing has been completed, and produce a fourth output when the number of people acquired by the number of people acquisition unit 32 is two or more people.
[0106] Note that, in this embodiment, the case where the authentication device 1 has two receiver sets, i.e., first and second receiver sets 11 and 12, has been mainly described. However, the authentication device 1 may have three or more receiver sets. That is, the authentication device 1 may have first to Nth receiver sets arranged at first to Nth positions, respectively. N is an integer equal to or greater than two. The first to Nth receiver sets may also be similar to the first and second receiver sets 11 and 12. For example, the Kth receiver set may include one or more receivers. K is an integer between 1 and N. It is preferable that the first to Nth positions are different from each other. Furthermore, when N is three or greater and the positions are identified by, for example, triangulation, it is preferable that the first to Nth positions do not lie on a single straight line. However, if this is not the case, the first to Nth positions may lie on a single straight line. Furthermore, when N is 4, for example, when the position is identified by triangulation or the like, it is preferable that the first to fourth positions are not the vertices of a parallelogram. However, if this is not the case, the first to fourth positions may be the vertices of a parallelogram. In this way, when the authentication device 1 has first to N receiver sets, the identification unit 14 may identify the position of the device to be authenticated 2 based on the intensity difference of the authentication requests received by the first to N receiver sets. Note that this position identification may be performed, for example, by repeatedly identifying an Apollonius circle or line based on the intensity difference of the authentication requests received by each of the two receiver sets for different combinations of two receiver sets among the first to N receiver sets, thereby identifying multiple Apollonius circles or lines, and identifying a position on the identified Apollonius circle, line, or within the circle as the position of the device to be authenticated 2, or by other methods.
[0107] Furthermore, in the above embodiments, each process or function may be realized by centralized processing by a single device or a single system, or may be realized by distributed processing by multiple devices or multiple systems.
[0108] Furthermore, in the above embodiments, the transfer of information between components may be performed, for example, by one component outputting information and the other component receiving information if the two components transferring the information are physically different, or by moving from a processing phase corresponding to one component to a processing phase corresponding to the other component if the two components transferring the information are physically the same.
[0109] Furthermore, in the above-described embodiments, information related to the processing performed by each component, such as information accepted, acquired, selected, generated, transmitted, or received by each component, and information such as thresholds, formulas, and addresses used in processing by each component, may be temporarily or long-term stored in a recording medium (not shown), even if not explicitly stated in the above description. Furthermore, the storage of information in the recording medium (not shown) may be performed by each component or a storage unit (not shown). Furthermore, the reading of information from the recording medium (not shown) may be performed by each component or a reading unit (not shown).
[0110] Furthermore, in the above-described embodiments, if the information used by each component, such as thresholds, addresses, and various setting values used by each component in processing, may be changed by the user, the user may or may not be able to change the information as appropriate, even if not explicitly stated in the above description. If the information is changeable by the user, the change may be realized, for example, by a receiving unit (not shown) that receives a change instruction from the user and a changing unit (not shown) that changes the information in accordance with the change instruction. The change instruction may be received by the receiving unit (not shown), for example, from an input device, by receiving information transmitted via a communication line, or by receiving information read from a predetermined recording medium.
[0111] Furthermore, in the above embodiment, when two or more components included in the authentication device 1 have a communication device, an input device, etc., the two or more components may have a single physical device or may have separate devices.
[0112] Furthermore, in the above-described embodiments, each component may be configured by dedicated hardware, or a component that can be realized by software may be realized by executing a program. For example, each component may be realized by a program execution unit such as a CPU reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. During execution, the program execution unit may execute the program while accessing a storage unit or recording medium. The software that realizes the authentication device 1 in the above-described embodiments is the following program. In other words, this program may be a program for causing a computer to execute the following steps: receiving an authentication request sent from the device to be authenticated using a first receiver set including one or more first receivers, the authentication request including authentication information used to authenticate the device to be authenticated; receiving the authentication request sent from the device to be authenticated using a second receiver set including one or more second receivers; performing device authentication to determine whether the device to be authenticated that sent the authentication request is legitimate using the authentication information included in the authentication request received by at least one of the one or more first receivers and the one or more second receivers; identifying the position of the device to be authenticated based on the strength difference between the authentication requests received by the first receiver set and the second receiver set, respectively; performing area judgment to determine whether the identified position of the device to be authenticated is included in an authentication area R2 shown on the floor; and outputting information regarding the execution of a predetermined process for a user carrying the device to be authenticated when the device authentication determines that the device to be authenticated is legitimate and the area judgment determines that the position of the device to be authenticated is included in the authentication area R2.
[0113] In addition, in the above program, the steps of receiving information and outputting information do not include processing that can only be performed by hardware, such as processing performed by a modem or interface card in the step of receiving information.
[0114] This program may be executed by being downloaded from a server or the like, or by being read from a predetermined recording medium (for example, an optical disk such as a CD-ROM, a magnetic disk, or a semiconductor memory). This program may also be used as a program constituting a program product.
[0115] Furthermore, the computer that executes this program may be a single computer or multiple computers, and may perform centralized processing or distributed processing.
[0116] 7 is a diagram showing an example of a computer system 900 that executes the above program to realize the authentication device 1 according to the above embodiment. The above embodiment can be realized by computer hardware and a computer program executed thereon.
[0117] 7, the computer system 900 includes an MPU (Micro Processing Unit) 911, a ROM 912 such as a flash memory that stores programs such as a boot-up program, application programs, system programs, and data, a RAM 913 connected to the MPU 911 that temporarily stores instructions for the application program and provides temporary storage space, a touch panel 914, a wireless communication module 915, and a bus 916 that interconnects the MPU 911, the ROM 912, and the like. Note that the computer system 900 may include, for example, multiple wireless communication modules 915 corresponding to the first and second receiver sets 11 and 12, or may be connected to multiple wireless communication modules corresponding to the first and second receiver sets 11 and 12. The computer system 900 may also include a display and input devices such as a mouse and a keyboard instead of the touch panel 914. The computer system 900 may also include other recording media such as a hard disk.
[0118] A program that causes the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment may be stored in the ROM 912 via the wireless communication module 915. The program is loaded into the RAM 913 when executed. The program may also be loaded directly from the network.
[0119] The program does not necessarily include an operating system (OS) or a third-party program that causes the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment. The program may include only instructions that call appropriate functions or modules in a controlled manner to achieve the desired results. How the computer system 900 operates is well known, and a detailed description thereof will be omitted.
[0120] Furthermore, the above-described embodiments are merely examples for specifically implementing the present invention, and are not intended to limit the technical scope of the present invention. The technical scope of the present invention is defined by the claims, not by the description of the embodiments, and is intended to include modifications within the literal scope of the claims and within the scope of equivalent meanings. [Explanation of symbols]
[0121] 1 Authentication device 11 First receiver set 11a First receiver 12 Second receiver set 12a Second receiver 13 Device authentication unit 14 Specific section 15 Area judgment section 16 Output section 17 Status output section 21 Display section 31 Sensors 32 Number of people acquisition part
Claims
1. a first receiver set including one or more first receivers that receive an authentication request transmitted from an authenticatee device and including authentication information used to authenticate the authenticatee device; a second receiver set including one or more second receivers for receiving an authentication request transmitted from the authenticatee; a device authentication unit that performs device authentication by using authentication information included in an authentication request received by at least one of the one or more first receivers and the one or more second receivers to determine whether a device to be authenticated that has transmitted the authentication request is legitimate; an identification unit that identifies the location of the prover based on a difference in strength of the authentication requests received by the first and second receiver sets, respectively; an area determination unit that performs area determination to determine whether the position of the device to be authenticated identified by the identification unit is included in an authentication area shown on the floor; an output unit that outputs information about the execution of a predetermined process for a user carrying the device to be authenticated when the device authentication determines that the device to be authenticated is valid and the area determination determines that the location of the device to be authenticated has been included in the authentication area for more than a predetermined time from a reference time point; and a status output unit that performs a first output when the device to be authenticated is determined to be valid in the device authentication and when the area determination determines that the position of the device to be authenticated is not included in the authentication area, performs a second output when the device to be authenticated is determined to be valid in the device authentication and when the area determination determines that the position of the device to be authenticated is included in the authentication area and execution of the specified processing has not been completed, and performs a third output when execution of the specified processing has been completed.
2. The authentication device according to claim 1 , wherein the authentication area is indicated by a mat placed on a floor.
3. The authentication device according to claim 1 , wherein the authentication area is displayed on a floor surface.
4. The authentication device according to claim 3 , further comprising a display unit that displays the authentication area on a floor surface.
5. The authentication device according to claim 4 , wherein the display unit changes a display position of the authentication area.
6. The authentication device according to claim 1, wherein the output unit outputs information regarding the execution of the specified processing when the device to be authenticated is determined to be valid in the device authentication and when the area determination determines that only the position of the device to be authenticated is included in the authentication area.
7. a sensor for acquiring information about the authentication area; a number-of-people acquisition unit that acquires the number of people present in the authentication area using information acquired by the sensor, The authentication device according to claim 1, wherein the output unit outputs information regarding the execution of the predetermined process when the device to be authenticated is determined to be valid in the device authentication, when the area determination determines that the position of the device to be authenticated is included in the authentication area, and when the number of people acquired by the number acquisition unit is one.
8. The authentication device according to claim 7 , wherein the sensor is a weight sensor that acquires a weight in the authentication area, or an image sensor that acquires an image of the authentication area.
9. 9. The authentication device according to claim 1, wherein the situation output unit performs a fourth output when the area determination unit determines that the positions of two or more of the authenticated devices are included in the authentication area.
10. 9. The authentication device according to claim 1, wherein the predetermined process is a payment process.
11. 9. The authentication device according to claim 1, wherein the predetermined process is an unlocking process.
12. 9. The authentication device according to claim 1, wherein the reference time point is a time point at which the user enters the authentication area.
13. 9. The authentication device according to claim 1, wherein the reference time point is a time point at which a user performs a predetermined operation.
14. An authentication method performed using a first receiver set including one or more first receivers, a second receiver set including one or more second receivers, a device authentication unit, an identification unit, a region determination unit, an output unit, and a status output unit, receiving an authentication request transmitted from an authenticatee device by the one or more first receivers included in the first receiver set, the authentication request including authentication information used to authenticate the authenticatee device; receiving an authentication request sent from the authenticatee device by the one or more second receivers included in the second receiver set; a step in which the device authentication unit performs device authentication by using authentication information included in an authentication request received by at least one of the one or more first receivers and the one or more second receivers to determine whether the authenticated device that has transmitted the authentication request is legitimate; the identifying unit identifying the location of the prover based on a difference in strength of the authentication requests received by the first and second receiver sets, respectively; a step in which the area determination unit performs area determination to determine whether the specified position of the device to be authenticated is included in an authentication area indicated on a floor; the output unit outputs information about the execution of a predetermined process for a user carrying the device to be authenticated when the device authentication determines that the device to be authenticated is valid and the area determination determines that the location of the device to be authenticated has been included in the authentication area for more than a predetermined time from a reference time point; the status output unit performs a first output when the device authentication determines that the device to be authenticated is valid and the area determination determines that the location of the device to be authenticated is not included in the authentication area, performs a second output when the device authentication determines that the device to be authenticated is valid and the area determination determines that the location of the device to be authenticated is included in the authentication area and execution of the specified processing has not been completed, and performs a third output when execution of the specified processing has been completed.
15. On the computer, receiving, by a first receiver set including one or more first receivers, an authentication request transmitted from an authenticatee device, the authentication request including authentication information used to authenticate the authenticatee device; receiving the authentication request sent from the prover by a second receiver set including one or more second receivers; performing device authentication using authentication information included in an authentication request received by at least one of the one or more first receivers and the one or more second receivers to determine whether or not a device to be authenticated that has transmitted the authentication request is legitimate; determining the location of the prover based on a difference in strength of authentication requests received by the first receiver set and the second receiver set, respectively; performing area determination to determine whether the identified position of the authenticated device is included in an authentication area indicated on the floor; a step of outputting an output relating to the execution of a predetermined process for a user carrying the device to be authenticated when the device authentication determines that the device to be authenticated is valid and the area determination determines that the location of the device to be authenticated has been included in the authentication area for more than a predetermined time from a reference time point; a program for executing the steps of: performing a first output when the device to be authenticated is determined to be valid in the device authentication and when the area determination determines that the position of the device to be authenticated is not included in the authentication area; performing a second output when the device to be authenticated is determined to be valid in the device authentication and when the area determination determines that the position of the device to be authenticated is included in the authentication area and the execution of the specified processing has not been completed; and performing a third output when the execution of the specified processing has been completed.
Citation Information
Patent Citations
Tamper-proof secure card with stored biometric information and method for using the same
JP2011100434A
Authentication system
JP2012079101A
Image forming device, control method thereof, and program
JP2019142125A
Terminal apparatus
JP2023098153A
Monitoring system
JP2023151179A