Authentication device, authentication method, and program
The authentication device efficiently handles multiple authentication methods by identifying and determining the appropriate method for key devices, ensuring seamless authentication and reducing failure attempts.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-06-06
- Publication Date
- 2026-04-14
AI Technical Summary
Conventional digital key authentication systems fail to handle multiple authentication methods efficiently, leading to increased failure attempts and potential lockout scenarios due to mismatched authentication methods.
An authentication device that identifies and determines the appropriate authentication method for a key device through communication, utilizing a storage means to associate authentication method information with unique device IDs, and performs authentication using a predetermined sequence if initial methods fail.
Ensures smooth authentication processing by identifying the correct method for multiple key devices, reducing unnecessary attempts and preventing lockout scenarios.
Smart Images

Figure 0007845061000001 
Figure 0007845061000002 
Figure 0007845061000003
Abstract
Description
Technical Field
[0004] , , , , , , ,
[0005] , , ,
[0001] The present invention relates to the technical field of authentication devices, authentication methods, and programs.
Background Art
[0002] Conventionally, digital keys that unlock and lock vehicle or house keys using digital data in electronic devices (key devices) such as contactless IC cards and smartphones have been known. For example, in Patent Document 1, a mobile device establishes a Bluetooth Low Energy communication connection, determines the position of the mobile device based on two-way ranging using impulse radio ultra-wideband, and based on the position of the mobile device, unlocks a door or trunk, permits starting of a vehicle, or activates wireless charging. A system for vehicle passive entry / passive start that executes vehicle functions such as this is disclosed.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In conventional digital key authentication, only one authentication method is supported, there are multiple types of key devices, and the processing in the case of multiple authentication methods is not considered. Therefore, when the authentication methods are different, authentication is attempted multiple times, traces of failed authentication are recorded, the number of failures increases, and the processing may not proceed or the lockout threshold may be reached.
[0005] Therefore, the present invention has been made in view of the above problems and the like, and an object thereof is to provide an authentication device and the like that can smoothly perform authentication processing even when there are multiple authentication methods.
Means for Solving the Problems
[0006] To solve the above problems, the invention described in claim 1 is an authentication device that communicates with a key device and authenticates the key device using digital data, comprising: a storage means for storing information on an authentication method employed by the key device and authentication method identification information that identifies the authentication method through the communication, in association with each other; an authentication method identification information identification means for identifying the authentication method identification information through communication with the key device; an authentication method determination means for determining the authentication method from the authentication method identification information by referring to the storage means; and an authentication means for authenticating the key device using the determined authentication method.
[0007] The invention described in claim 2 is characterized in that the authentication device described in claim 1 further comprises initial connection means for identifying the authentication method and the authentication method identification information by performing an initial connection process between the key device and the authentication device.
[0008] The invention described in claim 3 is characterized in that, in the authentication device described in claim 1 or claim 2, the authentication method identification information identification means identifies the unique ID of the key device as the authentication method identification information in anti-collision processing for preventing collisions of communication signals.
[0009] The invention described in claim 4 is characterized in that, in the authentication device described in claim 1 or claim 2, if the authentication means fails to authenticate, the key device is authenticated by an authentication method different from the authentication method that failed to authenticate, according to a predetermined sequence of authentication methods.
[0010] The invention described in claim 5 is characterized in that, in the authentication device described in claim 4, if the authentication method determination means cannot determine the authentication method from the authentication method identification information by referring to the storage means, it determines the authentication method according to the order of a preset authentication method.
[0011] The invention described in claim 6 is characterized in that, in the authentication device of claim 1 or claim 2, the authentication method identification information identification means identifies the communication method of the key device as the authentication method identification information in the communication initiation process.
[0012] The invention described in claim 7 is an authentication method for communicating with a key device and authenticating the key device by digital data, characterized in that a storage means stores information on an authentication method employed by the key device and authentication method identification information that identifies the authentication method through the communication in association; an authentication method identification information identification means identifies the authentication method identification information through communication with the key device; an authentication method determination means determines the authentication method from the authentication method identification information by referring to the storage means; and an authentication means authenticates the key device by the determined authentication method.
[0013] The invention described in claim 8 is characterized in that a computer included in an authentication device that communicates with a key device and authenticates the key device by digital data is configured to function as an authentication means for which information on an authentication method employed by the key device and authentication method identification information that identifies the authentication method through the communication are associated and stored; authentication method identification information identification means for which the authentication method identification information is identified through communication with the key device; authentication method determination means for which the authentication method is determined from the authentication method identification information by referring to the storage means; and authentication means for which the key device is authenticated by the determined authentication method. [Effects of the Invention]
[0014] According to the present invention, authentication method identification information is identified through communication with a key device, and the authentication method is determined from the authentication method identification information by referring to a storage means that stores the authentication method information adopted by the key device and the authentication method identification information that identifies the authentication method through communication in association. The key device is then authenticated using the determined authentication method. Therefore, even if there are multiple authentication methods, there is no need to attempt authentication unnecessarily, and the authentication process can be performed smoothly. [Brief explanation of the drawing]
[0015] [Figure 1] It is a diagram showing a schematic configuration example of an authentication processing system according to the present embodiment. [Figure 2] It is a diagram showing a schematic configuration example of an authentication device. [Figure 3] It is a diagram showing an example of a database of an authentication device. [Figure 4] It is a diagram showing a schematic configuration example of a key device. [Figure 5] It is a diagram showing a schematic configuration example of a key device. [Figure 6] It is a flowchart showing an example of the operation of the process of initial connection of an authentication device. [Figure 7] It is a flowchart showing an example of the operation of the recognition process of an authentication device. [Figure 8] It is a flowchart showing a modified example of the recognition process of an authentication device.
Embodiments for Carrying Out the Invention
[0016] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. The embodiments described below are embodiments when the present invention is applied to an authentication processing system in which authentication processing is performed between an authentication device installed inside a vehicle and a key device of a user boarding the vehicle. Note that the vehicle is an example of a moving body, such as a two-wheeled vehicle, a four-wheeled vehicle, or a bicycle.
[0017] [1. Schematic Configuration of Authentication Processing System S] First, the schematic configuration of the authentication processing system S according to the present embodiment will be described with reference to FIG. 1 and the like. FIG. 1 is a diagram showing a schematic configuration example of the authentication processing system S according to the present embodiment.
[0018] As shown in FIG. 1, the authentication processing system S includes an authentication device 10 mounted on a vehicle C and a plurality of types of key devices 20, 30, and the like.
[0019] The authentication device 10 is, for example, a control device such as an ECU (Electronic Control Unit) provided in the vehicle C. Based on the authentication result by the authentication device 10, operations such as unlocking / locking the doors of the vehicle C and starting the engine of the vehicle C are performed. Note that the target is not limited to the vehicle C, and it may also be a door of a house, devices such as an air conditioner or a water heater in the house, a personal computer, etc.
[0020] The key device 20 is, for example, a user's smartphone or the like. The key device 30 is, for example, a user's contactless IC card or the like. Note that the key device may be, for example, a key for the vehicle C having a smart entry function. The key device may be any device that communicates with the authentication device 10 and is authenticated by digital data.
[0021] Here, the user is a passenger of the vehicle C and owns the key device 20, key device 30, etc. When the user is an individual owner, the user is the owner of the vehicle C or a family member thereof. When the vehicle C is company-owned, the user is an employee who uses the vehicle C or the like. When the vehicle C is a rental car, the user is a user of the rental car. The digital data is, for example, digital data used for authentication such as a private key, a public key, a common key, an encryption key, a ciphertext, etc.
[0022] The authentication device 10 is capable of short-range wireless communication with the key devices 20 and 30. For short-range wireless communication, technologies such as NFC (Near Field Communication), Bluetooth (registered trademark), or UWB (Ultra Wide Band) are used, for example.
[0023] The authentication device 10 is configured to include, for example, an eSE (embedded Secure Element).
[0024] Figure 2 is a diagram showing a schematic configuration example of the authentication device 10. As shown in Figure 2, the authentication device 10 includes a communication unit 11, a storage unit 12, a control unit 13, etc.
[0025] The communication unit 11 is equipped with multiple types of antennas and performs short-range wireless communication with the key devices 20 and 30 within the range of short-range wireless communication. The communication unit 11 has multiple types of communication functions according to the respective communication standards of the key devices 20 and 30. For example, the communication unit 11 has the function of communicating with the key device 20 using a communication standard for the key device 20, such as Bluetooth (registered trademark). The communication unit 11 has the function of a contactless IC card reader / writer for the key device 30. The communication unit 11 is not limited to wireless communication; if the authentication device 10 and the key device are connected by contact, wired communication may also be used.
[0026] The storage unit 12 is, for example, nonvolatile memory (NVM). The storage unit 12 stores the operating system (OS) and applications. The applications include mutual authentication processing programs, etc. Furthermore, as shown in Figure 3, the storage unit 12 has a database associated with each key device, containing the authentication method (method A, method B, method C, ...) adopted by each key device, the unique ID (UID) of the key device, etc. Examples of authentication methods include symmetric key authentication and public key authentication. Other authentication methods may include two-factor authentication, multi-factor authentication, mutual authentication, mutual authentication, and one-sided authentication. The storage unit 12 is an example of a storage means that stores information on the authentication method adopted by the key device and authentication method identification information that identifies the authentication method through communication, in association with each other. The unique ID of the key device is an example of authentication method identification information.
[0027] Examples of unique IDs include the ID assigned to each key device. These include the device address and MAC address (Media Access Control address) of key device 20, and the chip ID of the IC card of key device 30. The unique ID only needs to be an ID that can distinguish it from other key devices, and it just needs to be unique to that key device.
[0028] Furthermore, the memory unit 12 stores information regarding the priority of communication methods with the key devices 20, 30, etc., and information regarding the priority of authentication methods when recognizing the key devices 20, 30, etc. Examples of communication methods include communication according to NFC standards such as "Type A" and "Type B", communication according to Bluetooth® standards, and communication according to UWB standards. The priority of authentication methods may be set for each version of the standard.
[0029] Furthermore, the memory unit 12 may store the communication method and the authentication method in association. In this case, the communication method is an example of authentication method identification information. For communication methods such as "Type A," which uses contactless communication type A; "Type B," which uses contactless communication type B; and communication using Bluetooth (registered trademark), authentication methods such as symmetric key authentication and public key authentication are stored in association with each. Note that communication methods and authentication methods are highly related, and in standards, each communication method and authentication method is often paired together. The communication method adopted by the key device is an example of authentication method identification information.
[0030] Furthermore, the storage unit 12 stores authentication data associated with the key devices, which is used for mutual authentication processing to establish a secure channel with the key devices 20 and 30. This authentication data is, for example, a key set including a secure channel encryption key, a secure channel MAC (Message Authentication Code) key, and a data encryption key.
[0031] The control unit 13 is comprised of a CPU (Central Processing Unit), RAM (Random Access Memory), and ROM (Read Only Memory), etc. The control unit 13 performs mutual authentication processing to establish a secure session with the key devices 20 and 30 according to the mutual authentication processing program. When mutual authentication between the authentication device 10 and the key devices 20 and 30 is completed by the control unit 13, the ECU of vehicle C performs actions such as unlocking / locking the doors of vehicle C and starting the engine of vehicle C. The authentication device 10 functions as a computer, and the control unit 13 performs various calculations and processes according to the program. The authentication device 10 may have the functions of an ECU, or the ECU may have the functions of the authentication device 10, or the authentication device 10 and the ECU may be separate entities.
[0032] Next, the key device 20, which is a smartphone, is the user's electronic device and, by installing a dedicated key app, functions as a digital key for vehicle C. The key device 20 may have a secure element for authentication, such as a UICC (Universal Integrated Circuit Card).
[0033] Figure 4 shows an example of the general configuration of the key device 20. As shown in Figure 4, the key device 20 comprises a communication unit 21, a storage unit 22, a display unit 23, an operation unit 24, a system control unit 25, and an input / output interface unit 26. The system control unit 25 and the input / output interface unit 26 are connected via a system bus 27.
[0034] The communication unit 21 has an antenna and performs wireless communication according to the communication standards for the authentication device 10 and the key device 20.
[0035] The storage unit 22 stores the operating system and applications. The applications include mutual authentication processing programs, etc. The storage unit 22 also stores authentication data (for example, a key set including a secure channel encryption key, a secure channel MAC key, and a data encryption key) used for mutual authentication processing to establish a secure channel with the authentication device 10.
[0036] The display unit 23 is composed of, for example, a liquid crystal display element or an organic EL (Electro-Luminescence) element. The operation unit 24 is a touch switch type display panel, such as the display unit 23.
[0037] The system control unit 25 includes, for example, a CPU 25a, a ROM 25b, and a RAM 25c. The system control unit 25 uses the CPU 25a to read and execute various programs stored in the ROM 25b, RAM 25c, and storage unit 22. For example, the system control unit 25 performs mutual authentication processing to establish a secure session with the authentication device 10 according to the mutual authentication processing program. After the secure session is established, operations such as unlocking / locking the doors of vehicle C are performed by operating the digital key app displayed on the display unit 23.
[0038] The input / output interface unit 26 is the interface between the communication unit 21 and the storage unit 22 and the system control unit 25.
[0039] Next, the key device 30, which is a contactless IC card, is an electronic information storage medium and is configured to include, for example, a secure element having high tamper resistance.
[0040] Figure 5 shows an example of the general configuration of the key device 30. As shown in Figure 5, the key device 30 is configured to include a communication unit 31, a storage unit 32, and a control unit 33, etc.
[0041] The communication unit 31 is equipped with an antenna and performs short-range wireless communication with the authentication device 10 within the range of short-range wireless communication. The protocol for short-range wireless communication between the authentication device 10 and the key device 30 may be, for example, the NFC protocol (for example, the protocol specified in ISO 14443).
[0042] The storage unit 32 is configured with RAM, NVM, etc. The storage unit 32 stores the operating system and applications. The applications include mutual authentication processing programs, etc. Furthermore, the storage unit 32 stores authentication data used for mutual authentication processing to establish a secure channel with the authentication device 10.
[0043] The control unit 33 performs mutual authentication processing to establish a secure session with the authentication device 10 according to the mutual authentication processing program. After the secure session is established, actions such as unlocking / locking the doors of vehicle C are performed.
[0044] [2. Operation of the Authentication Processing System S] Next, the operation of the authentication processing system S will be explained using a diagram.
[0045] (2.1 Operation of the initial connection process) First, the operation of the initial connection process between the authentication device 10 and each key device 20, 30 will be explained using Figure 6. Figure 6 is a flowchart showing an example of the operation of the initial connection process of the authentication device 10.
[0046] As shown in Figure 6, the authentication device 10 starts the process of initial connection between the authentication device 10 and each key device 20, 30 (step S1). Specifically, the control unit 13 brings each key device 20, 30 closer to the authentication device 10 individually so that they are within range of short-range wireless communication. A software or hardware button to start the initial connection process, such as pairing, is selected, and the initial connection process is started. The control unit 13 refers to the storage unit 12 and attempts to connect with the target key device according to the priority of the communication method. Anti-collision processing is performed using the unique ID of the target key device. Here, examples of anti-collision methods include type A anti-collision methods (e.g., bit collision, time slot) and type B anti-collision methods (e.g., slot marker), but anti-collision processing using a unique ID is preferred.
[0047] After connecting to the target key device, the control unit 13 refers to the storage unit 12 and performs authentication with the target key device according to the order of the authentication method.
[0048] Next, the authentication device 10 identifies the unique ID of the key device and the authentication method for the key device (step S2). Specifically, if pairing is successful in communication using the communication standard for the key device 20, the control unit 13 identifies the device address as the unique ID of the key device 20. Furthermore, if pairing with the target key device is successful, the authentication device 10 identifies the authentication method employed by the key device 20. In the case of a key device 30 such as a contactless IC card, the control unit 13 identifies the unique ID of the key device 30 used in the anti-collision processing that prevents collisions of communication signals between multiple key devices 30 during communication with the authentication device 10 during the initial connection. Furthermore, if authentication with the target key device is successful, the control unit 13 identifies the authentication method. The control unit 13 temporarily stores the identified unique ID and authentication method data in the RAM or the like of the control unit 13. In this way, the authentication device 10 functions as an example of an initial connection means that identifies the authentication method and authentication method identification information through the initial connection process between the key device and the authentication device.
[0049] Next, the authentication device 10 determines whether the initial connection process was successful (step S3). Specifically, the control unit 13 determines whether it was able to reach the final stage of the initial connection process.
[0050] If the initial connection process is successful (Step S3: YES), the authentication device 10 stores the identified unique ID and the identified authentication method (Step S4). For example, as shown in Figure 3, the control unit 13 stores the unique ID and the authentication method in association with each other in the storage unit 12.
[0051] If the initial connection process fails (step S3: NO), the authentication device 10 discards the unique ID and issues an error response (step S5). Specifically, the control unit 13 discards the temporarily stored unique ID and notifies the display unit, etc., of the failure to complete the initial connection process as an error response.
[0052] (2.2 Authentication Operation) Next, the authentication operation in which the authentication device 10 authenticates the key devices 20 and 30 will be explained using Figure 7. Figure 7 is a flowchart showing an example of the operation of the recognition process of the authentication device 10.
[0053] As shown in Figure 7, the authentication device 10 starts the connection process (step S10). When either the key device 20 or 30 enters the range of the authentication device 10's short-range wireless communication, the control unit 13 starts the connection process with the target key device. The control unit 13 refers to the storage unit 12 and attempts to connect with the target key device according to the stored information such as the unique ID and communication method. In the case of a key device 20 such as a smartphone, it attempts to connect using the communication standard for the key device 20. In particular, in the case of a key device 30 such as a contactless IC card, it performs anti-collision processing using the unique ID. When a key device is brought close to the communication unit 11 of the authentication device 10, a collision resolution command is sent from the communication unit 11 to detect whether there are multiple contactless communication devices present. The target key device sends its unique ID to the authentication device 10 as a response.
[0054] Next, the authentication device 10 obtains a unique ID during the connection process (step S11). The control unit 13 receives the unique ID from the target key device. In this way, the authentication device 10 functions as an example of authentication method identification means that identifies authentication method identification information through communication with the key device. In anti-collision processing that prevents collisions of communication signals, the authentication device 10 functions as an example of authentication method identification means that identifies the unique ID of the key device as authentication method identification information.
[0055] Next, the authentication device 10 determines whether the connection was successful (step S12). If the connection fails, the authentication device 10 returns to the process in step S10. If the connection is successful, the authentication device 10 compares the unique ID with internal information (step S13). Specifically, the control unit 13 refers to the database in the storage unit 12, as shown in Figure 3, and searches for the authentication method based on the received unique ID.
[0056] Next, the authentication device 10 determines whether or not there is an authentication method corresponding to the unique ID (step S14). Specifically, the control unit 13 refers to the database in the storage unit 12 and searches based on the unique ID to determine whether or not there is a corresponding authentication method.
[0057] If there is an authentication method corresponding to the unique ID, the authentication device 10 selects the appropriate authentication method (step S15). Specifically, the control unit 13 selects an authentication method corresponding to the unique ID from the database in the storage unit 12. The authentication device 10 functions as an example of an authentication method determination means that determines an authentication method from authentication method identification information by referring to the storage means.
[0058] If there is no authentication method corresponding to the unique ID, the authentication device 10 selects an authentication method in a predetermined order (step S16). Specifically, the control unit 13 selects an authentication method by referring to a database of authentication method priority information predetermined in the storage unit 12.
[0059] Next, the authentication device 10 determines whether or not authentication was successful (step S17). Specifically, the control unit 13 initiates mutual authentication with the target key devices 20 and 30 according to the selected authentication method. The authentication device 10 functions as an example of an authentication means for authenticating key devices according to the determined authentication method.
[0060] If the selected authentication method is a symmetric key authentication method, the authentication device 10 and the target key devices 20 and 30 hold a common key and verify that the other party possesses the correct key. For example, the authentication device 10 generates a random number A and sends it to the target key devices 20 and 30. The target key devices 20 and 30 encrypt random number A with the symmetric key they hold (ciphertext A) and send the generated random number B to the authentication device 10. The authentication device 10 decrypts ciphertext A and verifies that it is random number A. The authentication device 10 encrypts random number B with the symmetric key (ciphertext B) and sends it to the target key devices 20 and 30. The target key devices 20 and 30 decrypt ciphertext B and verify that it matches random number B.
[0061] If the selected authentication method is public key authentication, authentication is performed with the authentication device 10 and the target key devices 20 and 30 already possessing the correct public key of the other party. For example, authentication device 10 generates a random number A and sends it to the target key devices 20 and 30. The target key devices 20 and 30 send the generated random number B, data signed with the private key of the target key devices 20 and 30 (signature B), and the generated random number B to authentication device 10. Authentication device 10 verifies signature B with the public key of the target key devices 20 and 30 and confirms that the other party is the target key devices 20 and 30. Authentication device 10 signs random number B with its private key (signature A) and sends it to the target key devices 20 and 30. The target key devices 20 and 30 verify signature A with the public key of authentication device 10 and confirm that the other party is authentication device 10.
[0062] If authentication fails (step S17: NO), the authentication device 10 determines whether there is another authentication method (step S18). Specifically, the control unit 13 refers to a database of authentication method priority information predetermined in the storage unit 12 to determine whether there is an authentication method that has not yet been selected for the target key devices 20 and 30. In this way, the authentication device 10 functions as an example of an authentication method determination means that, when it is unable to determine the authentication method from the authentication method identification information by referring to the storage means, determines the authentication method according to the order of authentication methods predetermined.
[0063] If there is another authentication method (step S18: YES), the authentication device 10 returns to the process in step S16 and selects the next authentication method from the predetermined order of authentication methods, excluding the authentication method that has already been selected. In this way, if authentication fails, the authentication device 10 functions as an example of an authentication means that authenticates the key device using an authentication method different from the one that failed to authenticate, according to the predetermined order of authentication methods.
[0064] If no other authentication method is available (step S18: NO), the authentication device 10 performs authentication failure processing (step S19). Specifically, the control unit 13 notifies the display unit, etc., of the authentication failure as an error response.
[0065] If authentication is successful, the ECU of vehicle C will perform actions such as unlocking / locking the doors of vehicle C and starting the engine of vehicle C.
[0066] As described above, according to the above embodiment, a unique ID, which is an example of authentication method identification information, is identified by communication with each key device 20, 30. The authentication method is determined from the unique ID by referring to a storage means such as a storage unit 12 that stores the authentication method information adopted by each key device 20, 30 in association with the unique ID, and each key device 20, 30 is authenticated by the determined authentication method. Therefore, even if there are multiple authentication methods, there is no need to attempt authentication unnecessarily, and the authentication process can be performed smoothly.
[0067] Furthermore, when the authentication method and a unique ID, which is an example of authentication method identification information, are identified through the initial connection process between each key device 20, 30 and the authentication device 10, a database can be pre-constructed through the initial connection to store information on the authentication method adopted by the key devices 20, 30 and the unique ID used to identify the authentication method via communication, in association with each other.
[0068] Furthermore, in anti-collision processing to prevent communication signal collisions, when identifying the unique IDs of key devices 20 and 30, the unique IDs of the key devices for identifying the authentication method can be identified by anti-collision processing before the authentication process.
[0069] If authentication fails, the system can determine the authentication method for each key device 20, 30 using a different authentication method than the one that failed, according to the pre-configured order of authentication methods. This is possible even if authentication fails using the authentication method identified from the unique ID or other authentication method identification information. Furthermore, by applying authentication methods in order and performing authentication within the range of pre-configured authentication methods, the authentication process can be stopped after a certain number of attempts within the range of authentication methods.
[0070] When the authentication method cannot be determined from authentication method identification information such as a unique ID by referring to storage means such as the storage unit 12, the authentication method can be determined according to the order of pre-set authentication methods, even if authentication cannot be performed using the authentication method identified from the authentication method identification information. Furthermore, by applying the authentication methods in order and performing authentication within the range of pre-set authentication methods, the authentication process can be stopped after a number of attempts within the range of the authentication methods.
[0071] (modified version) Next, a modified example of the authentication operation will be explained using Figure 8. Figure 8 is a flowchart showing a modified example of the recognition process of the authentication device 10.
[0072] First, the authentication device 10 identifies the communication method (step S20). Specifically, when either the key device 20 or 30 enters the range of the authentication device 10's short-range wireless communication, the control unit 13 starts the connection process with the target key device. The control unit 13 refers to the storage unit 12 and attempts to connect with the target key device according to the stored information such as the unique ID and communication method. The control unit 13 identifies the information of the communication method that was successfully connected. In this way, the authentication device 10 functions as an example of authentication method identification information identification means that identifies the communication method of the key device as authentication method identification information during the communication initiation process.
[0073] Next, the authentication device 10 compares the communication method with internal information (step S21). Specifically, the control unit 13 refers to the database in the storage unit 12, which associates the communication method with the authentication method, and searches for the authentication method based on the identified communication method.
[0074] Next, the authentication device 10 determines whether or not there is an authentication method corresponding to the communication method (step S22). Specifically, the control unit 13 refers to the database in the storage unit 12 and searches based on the identified communication method to determine whether or not there is a corresponding authentication method.
[0075] If there is an authentication method corresponding to the identified communication method, the authentication device 10 selects the appropriate authentication method (step S23). Specifically, the control unit 13 selects an authentication method corresponding to the identified communication method from the database in the storage unit 12.
[0076] If there is no authentication method corresponding to the specified communication method, the authentication device 10 selects an authentication method in a predetermined order, as in step S16 (step S24).
[0077] Next, the authentication device 10 determines whether or not the authentication was successful, as in step S17 (step S25).
[0078] If authentication fails (step 25: NO), the authentication device 10 determines whether there is another authentication method, as in step S18 (step S26).
[0079] If there is another authentication method (step S26: YES), the authentication device 10 returns to the process in step S24 and selects the next authentication method from the predetermined order of authentication methods, excluding the authentication method that has already been selected.
[0080] If no other authentication method is available (step S26: NO), the authentication device 10 performs the authentication failure process as in step S19 (step S27).
[0081] In the above modified example, the communication method of each key device 20, 30 is identified through communication with each key device 20, 30. The authentication method is determined from the communication method by referring to a storage means that stores information on the authentication method adopted by each key device 20, 30 in association with the communication method. Each key device 20, 30 is then authenticated using the determined authentication method. As a result, even if there are multiple authentication methods, there is no need to attempt authentication unnecessarily, and the authentication process can be performed smoothly.
[0082] Furthermore, when identifying the communication method of key devices 20 and 30 during the communication initiation process, the authentication method adopted by key devices 20 and 30 can be identified from the communication method of key devices 20 and 30, even if the unique IDs of key devices 20 and 30 are unknown. For example, even in the case of an anti-collision method that does not use unique IDs, the communication method of key devices 20 and 30 can be identified. Also, even without the process of constructing a prior storage means during the initial connection, the authentication method of key devices 20 and 30 can be identified if a database of communication methods and authentication methods is available. [Explanation of symbols]
[0083] 10 Authentication device 20, 30 key device
Claims
1. In an authentication device that communicates with a key device and authenticates the key device using digital data, A storage means that stores information on the authentication method employed by the key device and authentication method identification information that identifies the authentication method through the communication, in association with each other. A means for identifying authentication method identification information that identifies the authentication method identification information by communicating with the key device, An authentication method determination means that determines the authentication method from the authentication method identification information by referring to the storage means, An authentication means for authenticating the key device according to the authentication method determined above, An authentication device characterized by being equipped with the following features.
2. In the authentication device according to claim 1, An authentication device further comprising initial connection means for identifying the authentication method and the authentication method identification information through an initial connection process between the key device and the authentication device.
3. In the authentication device according to claim 1 or claim 2, An authentication device characterized in that the authentication method identification information identification means identifies the unique ID of the key device as the authentication method identification information in anti-collision processing for preventing collisions of communication signals.
4. In the authentication device according to claim 1 or claim 2, An authentication device characterized in that, if the authentication means fails to authenticate, it authenticates the key device using an authentication method different from the authentication method that failed to authenticate, according to a predetermined sequence of authentication methods.
5. In the authentication device according to claim 4, An authentication device characterized in that, if the authentication method determination means cannot determine the authentication method from the authentication method identification information by referring to the storage means, it determines the authentication method according to a predetermined sequence of authentication methods.
6. In the authentication device according to claim 1 or claim 2, An authentication device characterized in that the authentication method identification means identifies the communication method of the key device as the authentication method identification information in the communication initiation process.
7. In an authentication method that communicates with a key device and authenticates the key device using digital data, A storage step in which a storage means stores information on the authentication method employed by the key device and authentication method identification information that identifies the authentication method through the communication, The authentication method identification information identification means includes an authentication method identification information identification step in which it identifies the authentication method identification information by communicating with the key device, Authentication method determination means determines the authentication method from the authentication method identification information by referring to the storage means, The authentication means includes an authentication step of authenticating the key device according to the determined authentication method, An authentication method characterized by including the following.
8. A computer included in an authentication device that communicates with a key device and authenticates the key device using digital data, A storage means that stores information about the authentication method employed by the key device and authentication method identification information that identifies the authentication method through the communication, in association with each other. Authentication method identification information identification means that identifies the authentication method identification information by communicating with the key device, An authentication method determination means that determines the authentication method from the authentication method identification information by referring to the storage means, and A program characterized by causing the key device to function as an authentication means for authenticating the key device according to the authentication method determined above.
Citation Information
Patent Citations
Terminal security-related parameter negotiation method in wireless mobile Internet system
JP2008533609A
Network device and terminal device
JP2011238162A
Information processor, information processing method and computer program
JP2015176317A
Passive entry / passive start system and method for a vehicle
JP2019528387A
Key sharing method and device
US20170150349A1