Lock control device and emergency key authentication system

The lock control device uses a built-in storage member and selective network queries to ensure reliable emergency unlocking in disaster relief spaces, addressing power consumption and reliability issues in existing systems.

JP7849098B1Active Publication Date: 2026-04-21BLOCKCHAIN LOCK INC
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
BLOCKCHAIN LOCK INC
Filing Date
2025-12-23
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing lock control systems for disaster relief spaces cannot reliably limit unlocking to emergency situations only and may consume excessive power during emergencies, making them unreliable and potentially inoperable.

Method used

A lock control device that identifies key data using a built-in storage member and performs additional identification via a communication network as necessary, minimizing power consumption and ensuring reliable emergency unlocking by querying a server only when needed.

Benefits of technology

The system ensures highly reliable unlocking during emergencies by reducing power consumption and preventing misjudgments, facilitating retrofitting to existing spaces, and maintaining operation during power outages.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007849098000001_ABST
    Figure 0007849098000001_ABST
Patent Text Reader

Abstract

To provide a technical means for controlling a lock that limits unlocking using pre-distributed emergency key data to emergency situations only, and that ensures highly reliable unlocking during such emergencies. [Solution] The control device 1 for the lock 2 of the present invention includes: a key acquisition unit 112 that acquires key data from a two-dimensional code B or other key data providing means; a key determination unit 113 that determines whether the key data corresponds to emergency key data based on key information stored in a directly connected or built-in storage member (e.g., device storage unit 13); an emergency determination unit 114 that, if the key data corresponds to emergency key data, determines whether it is an emergency based on the results of acquiring emergency information from a server 3 via a communication network (e.g., network N); and an unlocking command unit 115 that commands the unlocking of the lock 2 when both requirements are met, namely that the key data corresponds to emergency key data and that it is an emergency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a control device for a lock and an emergency key authentication system.

Background Art

[0002] In order to manage the use of an existing room or building by a third party, a post-installation control device is introduced that enables an existing electronic lock to be unlocked only when a predetermined two-dimensional code is presented and the conditions related to the use are satisfied. For post-installation regardless of the power supply environment, such a control device may be required to operate for a long time without being supplied with power from the outside.

[0003] Regarding such a post-installation control device for an electronic lock, Patent Document 1 reads information encrypted by a public-key cryptosystem from a two-dimensional code, determines whether it corresponds to a reserved time zone corresponding to the decrypted information without communicating with the outside, and issues an unlocking command to the locking device according to the determination result. The technology of Patent Document 1 can provide a lock and a lock control system that can be post-installed in facilities where communication means and / or power supply are limited and can be controlled according to a reservation.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] By the way, disaster countermeasures are being taken in which a disaster space is unlocked by local government officials or other persons in charge in response to a disaster, and the space or the materials stored therein are provided to local residents. Examples of such disaster spaces include local gymnasiums or community centers, facilities that also serve as evacuation shelters (e.g., event halls, shopping malls, accommodation facilities), or disaster storage warehouses.

[0006] In disaster response measures like this, it is preferable to station the person in charge near each space so that they can respond even if the person in charge cannot travel long distances due to the disaster. However, due to various circumstances, it may be difficult to implement such personnel deployment. On the other hand, distributing keys to the space to some or all of the local residents can ensure reliable and rapid unlocking. However, such an operation has the problem that those who have been given the keys can also unlock the space during normal times.

[0007] Given this background, there is a need for lock control that limits unlocking using pre-distributed emergency-only unlocking data (emergency key data) to disasters and other emergencies. The technology described in Patent Document 1 is configured to command unlocking based on a determination result made without communication with the outside, and therefore cannot determine whether or not it is an emergency based on external information. Thus, this technology has room for further improvement in realizing lock control that limits unlocking using pre-distributed emergency key data to emergencies only, and that performs such unlocking with high reliability during emergencies.

[0008] The present invention was made to solve the problems of the prior art described above, and aims to provide a technical means for controlling a lock that limits unlocking using pre-distributed emergency key data to emergency situations only, and that enables highly reliable unlocking in such emergency situations. [Means for solving the problem]

[0009] As a result of diligent research to solve the above problems, the inventors have found that the above problems can be solved by a configuration or other technical configuration that identifies key data based on key information stored in a directly connected or built-in memory element, and then performs additional identification via a communication network as necessary. The inventors have now completed the present invention. Specifically, the present invention provides the following:

[0010] The invention according to the first feature of the present invention provides a lock control device comprising: a key acquisition unit that acquires key data; a key determination unit that determines whether the key data corresponds to emergency key data based on key information stored in a directly connected or built-in storage member; an emergency determination unit that, if the key data corresponds to emergency key data, determines whether it is an emergency based on the result of a query to a server; and an unlocking command unit that commands the unlocking of the lock when both requirements are met, namely that the key data corresponds to emergency key data and that it is an emergency.

[0011] When unlocking a disaster relief space using a pre-distributed contactless medium as an emergency key, it is preferable that the device controlling the lock operates on a built-in power source, such as a primary battery, to facilitate retrofitting to existing spaces and because external power may be unavailable during an emergency. However, built-in power sources typically have limited power capacity. Therefore, there is a concern that devices with high power consumption may not be able to operate adequately during a critical emergency.

[0012] In this case, querying information from external sources is a relatively power-intensive process, raising concerns about increased power consumption of the device.

[0013] According to the invention relating to the first feature, the key acquisition unit and key discrimination unit, which acquire key data from a two-dimensional code, keypad input, or other key data provision means, are not configured to require communication with a server. Therefore, power consumption in acquiring key data and determining whether or not it is emergency key data can be suppressed.

[0014] As mentioned above, unlocking with a pre-distributed emergency key requires that the use of that emergency key be limited to emergencies. Therefore, a procedure is needed to reliably determine whether or not an emergency has occurred, which cannot be achieved solely through information within the device. In this invention, the emergency determination unit can perform a relatively power-intensive process of determining whether the acquired key data corresponds to emergency key data and then querying the server. As a result, this invention can reduce power consumption by keeping communication with the server to a minimum, prevent misjudgments of whether an emergency has occurred, and achieve highly reliable unlocking using emergency key data limited to emergencies.

[0015] Therefore, the invention relating to the first feature can provide a technical means for controlling a lock that limits unlocking using pre-distributed emergency key data to emergency situations only, and enables highly reliable unlocking during such emergencies.

[0016] The invention relating to the second feature of the present invention is the invention relating to the first feature, wherein the emergency determination unit provides a control device that determines whether or not an emergency has occurred based on the results of a query to a server via a wireless network.

[0017] In such devices, wireless communication is preferable as a means of communication because it facilitates retrofitting into existing spaces and increases the flexibility of installation locations. However, since wireless communication processing is a relatively power-intensive process, there are concerns that it may increase the power consumption of the device.

[0018] According to the invention relating to the second feature, by determining whether or not an emergency situation is occurring based on the results of a query to a server via a wireless network, it is possible to facilitate retrofitting to existing spaces and increase the flexibility of the installation target. As mentioned above, there is a concern that communication via a wireless network will increase the power consumption of the device.

[0019] On the other hand, according to the invention relating to the second feature, the key acquisition unit and key discrimination unit, which acquire key data from two-dimensional codes, keypad input, and other key data provision means, do not require wireless communication with a server. Therefore, power consumption in acquiring key data and determining whether it is emergency key data can be suppressed. As a result, the invention can enjoy the benefits of using a wireless network while reducing the risk of running out of power capacity before an emergency occurs due to high power consumption. Consequently, the invention contributes to improved reliability brought about by improved availability during emergencies.

[0020] Therefore, the invention relating to the second feature can provide a technical means for controlling a lock that limits unlocking using pre-distributed emergency key data to emergency situations only, and enables highly reliable unlocking during such emergencies.

[0021] The invention relating to the third feature of the present invention is the invention relating to the first feature, wherein the key discrimination unit determines whether the key data corresponds to unlocking key data based on the key information stored in the storage member, and if it is not determined that it corresponds, it refers to an external database via a communication network and determines whether the key data corresponds to unlocking key data based on the database, and the unlocking command unit commands the unlocking of the lock if the key data corresponds to the unlocking key data, thereby providing a control device.

[0022] Disaster relief spaces, exemplified by local gymnasiums and community centers, facilities that also serve as evacuation shelters (e.g., event halls, shopping malls, accommodation facilities), and disaster relief storage warehouses, may require entry into the space for normal purposes, replenishment of equipment, cleaning, inspection, repair, renovation, and other reasons, even during peacetime when there is no emergency.

[0023] As described above, the circumstances for entry are diverse, and the conditions for allowing entry are also various. In addition, there may be cases where temporary entry occurs, which was not assumed at the time of initial installation of the control device or during regular maintenance work. Due to these circumstances, it may be difficult to pre-store all the key data that can be presented upon entry in the above-described storage member.

[0024] According to the invention according to the third feature, even in the unlocking key data used in normal times, first, a directly connected or built-in storage member is referred to, and when it is found that discrimination cannot be made by this reference, wireless communication related to database reference is performed, so that power consumption can be suppressed even in cases where it does not apply in an emergency. As a result, the invention can further prevent the inability to operate due to power shortage in an emergency by suppressing power consumption in normal times, and can achieve both unlocking in normal times and unlocking with emergency key data limited to an emergency.

[0025] Therefore, the invention according to the third feature can provide a technical means for realizing the control of a lock that limits unlocking with pre-distributed emergency key data only to an emergency and performs such unlocking with high reliability in an emergency.

[0026] The invention according to the fourth feature of the present invention includes a control device according to any one of the first to third features and a server configured to communicate with the control device via a communication network. The server includes a flag management unit that sets an emergency mode flag based on emergency report data indicating whether or not it is an emergency, and an emergency information providing unit that provides emergency information corresponding to the emergency mode flag to the control device via the communication network in response to a request from the control device, and provides an emergency key authentication system.

[0027] Servers that distribute the disaster situation across the country are operated by the Japan Meteorological Agency and other public institutions and private companies. By inquiring such a server via the Internet, emergency information that can be used to determine whether or not it applies in an emergency can be obtained.

[0028] However, disaster-stricken areas may not have access to internet communication. Furthermore, it may be difficult to quickly obtain emergency information from such servers due to server downtime caused by the direct impact of the disaster or high load conditions resulting from a surge in inquiries related to the disaster. In addition, such servers may have access interval restrictions in place to avoid the aforementioned high load conditions.

[0029] In these cases, there are concerns that the control devices for the locks related to the disaster relief space may take time to retrieve emergency information from such servers after a disaster occurs, preventing the rapid opening of the disaster relief space.

[0030] According to the invention relating to the fourth feature, the control device determines whether or not an emergency is occurring based on emergency information corresponding to an emergency mode flag managed by a server (e.g., an existing emergency information server, a server for this system) that can communicate via a dedicated disaster network or other communication network. This flag can be activated by a local person in charge or other operator or a disaster system, independently of the access status to a server that distributes disaster information nationwide.

[0031] Therefore, according to this invention, the control device can continue authentication and unlocking control of the emergency key without being directly affected in the various cases described above. Furthermore, by having a configuration in which the server only needs to refer to minimal information in the form of a flag to provide emergency information, this invention can also prevent queries from multiple control devices belonging to the communication network from causing a high load on the server. In addition, this invention makes it possible for an operator to quickly and simultaneously switch all control devices using the server to an effective emergency mode with a single operation of sending emergency report data indicating that an emergency has occurred.

[0032] Therefore, the invention relating to the fourth feature can provide a technical means for controlling a lock that limits unlocking using pre-distributed emergency key data to emergency situations only, and that ensures highly reliable unlocking during emergencies.

[0033] The invention relating to the fifth feature of the present invention is the invention relating to the third feature, wherein the flag management unit provides an emergency key authentication system that activates the emergency mode flag when the server receives emergency report data from an external terminal or system.

[0034] As mentioned above, the method of determining whether or not an emergency is occurring using a server that distributes disaster information from across the country may raise concerns regarding the speed and reliability of determination during an emergency. This concern is considered to apply not only when the control unit directly uses such a server, but also when the flag management unit uses it.

[0035] According to the invention relating to the fifth feature, by configuring the system to activate the emergency mode flag when emergency report data is received from an operator's terminal, system, or other device, it is possible to prevent a concentration of load on a server that distributes disaster information over a wide area, while ensuring the speed of disaster detection even if the server limits access intervals.

[0036] Therefore, the invention relating to the fifth feature can provide a technical means for controlling a lock that limits unlocking using pre-distributed emergency key data to emergency situations only, and enables highly reliable unlocking during emergencies. [Effects of the Invention]

[0037] According to the present invention, it is possible to provide a technical means for controlling a lock that limits unlocking using pre-distributed emergency key data to emergency situations only, and that ensures highly reliable unlocking during such emergencies. [Brief explanation of the drawing]

[0038] [Figure 1] Figure 1 is a schematic diagram showing an example of a system S according to an embodiment of the present invention. [Figure 2] Figure 2 is a block diagram showing an example of the hardware and software configuration of system S. [Figure 3]Figure 3 shows an example of a key information table 131. [Figure 4] Figure 4 shows an example of a key information database 421. [Figure 5] Figure 5 is a flowchart showing an example of a preferred procedure for unlocking using emergency key data. [Figure 6] Figure 6 is a main flowchart showing an example of a preferred flow of control processing performed by the control device 1. [Figure 7] Figure 7 is a continuation of the previous figure. [Figure 8] Figure 8 is a continuation of the previous figure. [Figure 9] Figure 9 is a flowchart showing an example of a preferred flow of mode management processing performed on server 3. [Figure 10] Figure 10 is a continuation of the previous figure. [Modes for carrying out the invention]

[0039] Firstly, although the following disclosures, figures, and / or claims are described either individually or in combination with one or more other aspects, the subject matter of the immediate disclosure is not intended to be limited in that way. That is, the immediate disclosures, figures, and claims are intended to encompass the various aspects described herein, either individually or in one or more combinations with each other. For example, even if the immediate disclosure describes and illustrates the first, second, and third embodiments in such a way that the first embodiment is described and illustrated particularly in relation to the second embodiment, or the second embodiment is described and illustrated only in relation to the third embodiment, the immediate disclosures and illustrations are not limited in that way and may include only the first embodiment, only the second embodiment, only the third embodiment, or one or more combinations of the first, second, and / or third embodiments, such as the first and second embodiments, the first and third embodiments, the second and third embodiments, or the first, second, and third embodiments.

[0040] In this text, the phrase "or" is used to mean a "non-exclusive" arrangement unless explicitly specified otherwise. For example, "item x is A or B" means either (1) item x is either A or B, or (2) item x is both A and B. In other words, the word "or" is not used to define an "exclusive" arrangement.

[0041] Furthermore, when the phrases "contain at least one" or "contain at least one of the following" are used in the text, they mean that the system or element contains one or more of the elements listed after the phrase. For example, if there are three types of elements, from element 1 to element 3, the phrases "contain at least one" or "contain at least one of the following" are interpreted as any of the following structural arrangements: a device containing element 1, a device containing element 2, a device containing element 3, a device containing element 1 and element 2, a device containing element 1 and element 3, a device containing element 2 and element 3, or a device containing element 1, element 2, and element 3.

[0042] The same interpretation is intended when the phrase "used in at least one of the following" is used in the text. Furthermore, "and / or" as used in the text is used as a linguistic conjunction to indicate that one or more of the listed elements or conditions are included or occur. For example, a device containing the first element, the second element, and / or the third element is interpreted as any of the following structural arrangements: a device containing the first element, a device containing the second element, a device containing the third element, a device containing the first and second elements, a device containing the first and third elements, a device containing the second and third elements, or a device containing the first, second, and third elements.

[0043] Furthermore, the use of the phrase "and / or" in this text signifies a "non-exclusive" arrangement, as stipulated in the Japanese Industrial Standard (JIS) "Format and Preparation Method of Standards Documents JIS Z 8301".

[0044] Hereinafter, an example of an embodiment of the present invention will be described in detail with reference to the drawings.

[0045] <System S> Figure 1 is a schematic diagram showing an example of System S according to an embodiment of the present invention. Figure 2 is a block diagram showing an example of the hardware configuration and software configuration of System S. Hereinafter, preferred embodiments of the emergency key authentication system (System S) according to this embodiment will be described with reference to Figures 1 and 2.

[0046] The following description focuses on the aspect of System S that uses emergency key data as disaster prevention key data to control unlocking during disasters. However, those skilled in the art will easily conceive of applying System S to the control of locks that reliably unlock using emergency key data not only during disasters but also during epidemics (pandemics), terrorist attacks, and other various emergencies. Similarly, System S can be applied to provide control of locks related to unlocking in an emergency mode determined by the administrator. In addition, those skilled in the art will also conceive of using System S to enable an operating mode that is activated only under specific conditions and to apply it to the control of locks that reliably unlock in that mode.

[0047] System S comprises a lock control device 1, a lock 2 controlled by the device, a server 3, and a cloud server 4. Preferably, System S further includes a terminal T that communicates with the server 3 and / or the cloud server 4 via a network N. In System S, the control device 1 and the server 3 are configured to communicate via a communication network, exemplified by a wireless network (Figure 1). From the viewpoint of availability in emergencies, the communication network is preferably a disaster prevention wireless network equipped with an emergency power supply. Furthermore, the server 3 and the cloud server 4 may be configured as a single unit.

[0048] [Control device 1] The control device 1 comprises a device control unit 11, a device storage unit 13, a communication unit 14, an input unit 15, a display unit 16, and a reading unit 17. The control device 1 controls the lock 2 installed at the entrance to the disaster relief space according to the determination result related to unlocking or locking, which is performed using at least the acquired key data.

[0049] The disaster relief space is not particularly limited as long as it is a space that can be locked by lock 2, for example, a disaster relief storage warehouse (Figure 1). Other disaster relief spaces may include local gymnasiums or community centers, facilities that also serve as evacuation shelters (e.g., event halls, shopping malls, accommodation facilities), or storage facilities.

[0050] [Device Control Unit 11] The device control unit 11 comprises a central processing unit (CPU), random access memory (RAM), read-only memory (ROM), and other components.

[0051] The device control unit 11 cooperates with at least one of the components of the control device 1, as exemplified by the device storage unit 13 and the communication unit 14, as needed. The device control unit 11 then implements the software components of the program executed by the control device 1 of this embodiment.

[0052] Examples of these software components include the information update unit 111, the key acquisition unit 112, the key identification unit 113, the emergency identification unit 114, and the unlock command unit 115. Details of these software components will be described later in the explanation of the control process using Figures 6 to 8.

[0053] [Device Storage Unit 13] The device storage unit 13 is a device on which data and / or files are stored, and has a storage unit that stores data using semiconductor memory, memory cards, and other non-temporary storage media. The storage media are configured as directly connected or built-in storage members. An example of a directly connected storage member is a non-temporary storage medium (e.g., a microSD card) directly connected to a storage medium connection terminal of the control device 1. An example of a built-in storage member is a semiconductor memory which is a non-temporary storage medium of the control device 1.

[0054] The device storage unit 13 stores the program executed by the microcomputer, the key information table 131, and other data. In other words, in this embodiment, the key information is stored in a directly connected or built-in storage member.

[0055] (Key Information Table 131) The key information table 131 is configured to store key information. This key information includes data used to determine whether the key data is emergency key data or not. This key information also includes data used to determine whether the key data is unlocking key data or not.

[0056] Examples of key information relating to emergency key data include data representing a given prefix (e.g., prefix "999") that indicates emergency key data. An approach that indicates that the data is emergency key data by including specific plaintext identification data exemplified by the given prefix is ​​preferable because it can reduce the power consumption required by the key discrimination unit 113 to determine whether or not the data is emergency key data. In addition, the key information may also be in the form of data indicating a rule for determining whether or not the data is emergency key data.

[0057] Key information related to unlocking key data includes, for example, the registered unlocking key data itself or data that associates said data with limitations on the date and time when unlocking is permitted. The date and time when unlocking is permitted is not particularly limited. Examples of such limitations include date limitations (e.g., limitations on one or more dates, limitations on one or more days of the week, limitations on one or more days of the month, limitations on one or more days of the month), time limit limitations (e.g., limitations during business hours, limitations during maintenance hours), and limitations on both date and time limit (e.g., limitations corresponding to different business hours on weekdays and weekends).

[0058] Although not a mandatory feature, in order to provide unlocking key data for temporary use, the key information relating to the unlocking key data may include the time from the first use until expiration or the number of times it has been used until expiration. In this case, it is preferable that the key information further includes information necessary to determine whether or not it has expired (e.g., expiration flag, date and time of first use, number of uses to date). Furthermore, the key information may include data used to distinguish between key data that is both emergency key data and unlocking key data.

[0059] In order to provide control that unlocks only the locks 2 corresponding to the authority associated with the key data, even when there are multiple locks 2 to be controlled, it is preferable that the key information further includes information that identifies the locks 2 that can be unlocked by the emergency key data or unlocking key data related to the key information. The number of locks 2 that can be unlocked in the identifying information is at least 1, but it is more preferable that it be possible to set 2 or more. As a result, the control device 1 can provide control that unlocks multiple locks 2 among the controlled objects with a single key data.

[0060] Although not a mandatory configuration, for management using history, it is preferable that the key information table 131 is configured to further store a history of unlocking attempts. This history preferably includes the key data used in the attempt and the date and time the attempt was made. Furthermore, this history may be stored in association with the key information or stored separately from the key information.

[0061] From the viewpoint of reducing power consumption, it is preferable that the history be stored in volatile memory. From the viewpoint of making the history easier to use, it is preferable that the history be sent to an external device (e.g., cloud server 4) at a predetermined timing. On the other hand, if there are circumstances such as the device being installed in a disaster relief space (e.g., a facility that also serves as an evacuation center) where management using the history is particularly necessary, some or all of the history may be stored in non-volatile memory. In this case as well, it is preferable that the history be sent to an external device at a predetermined timing.

[0062] Figure 3 shows an example of a key information table 131. This example includes the first key information "K0001" related to emergency key data, the second key information "K0002" related to unlocking key data that does not limit the unlocking date and time, and the third key information "K0003" related to unlocking key data that has a limited unlocking date and time.

[0063] Note that the format and content of the key information in this example are merely illustrative examples for clarity, and the key information table 131 may also store similar information in other formats (e.g., JSON format, binary data).

[0064] The primary key information includes data "emergency key data:999*" indicating that the prefix for emergency key data is "999". This allows the control device 1 to determine that any key data starting with "999" is emergency key data.

[0065] The second key information includes data indicating that the key data "123456789012" is key information related to unlocking key data equivalent to a master key: "Unlocking key data: 123456789012 Date and time restriction: None". This allows the control device 1 to determine that the key data "123456789012" is unlocking key data and not emergency key data, and to provide control to perform unlocking using that key data without limiting the date and time. Such key information is useful, for example, when providing key data to managers who manage disaster relief spaces or other regular users.

[0066] The third key information includes data indicating that the key data "098765432109" is key information related to unlocking key data corresponding to a temporary key: "Unlocking key data: 098765432109 Date and time limited: △△△△ / △△ / △△ / △△ from △△ to △△". As a result, the control device 1 can determine that the key data "098765432109" is unlocking key data and not emergency key data, and can provide control to execute unlocking using that key data only at the associated date and time. Such key information is useful, for example, when providing temporary key data to maintenance workers or other temporary users entering a disaster relief space.

[0067] By configuring the key information table 131 to store various key information as exemplified, the control device 1 can enable emergency unlocking using emergency key data, as well as diverse management during normal times.

[0068] [Communication Unit 14] The communication unit 14 is configured to communicate with the server 3 via various communication networks. From the viewpoint of facilitating retrofitting to existing spaces and increasing the flexibility of installation locations, it is preferable that the communication unit 14 is configured to communicate with the server 3 via a wireless network. The communication unit 14 includes, for example, communication components compatible with Wi-Fi or other wireless LANs, Low Power Wide Area Networks (LPWANs), and public mobile communication networks.

[0069] Furthermore, the communication unit 14 is configured to transmit control signals to the lock 2. Such transmission is achieved, for example, by short-range wireless communication. Examples of short-range wireless communication include Bluetooth®, Bluetooth LE, and ZigBee®. The transmission of control signals to the lock 2 may also be achieved by wired communication. Examples of wired communication include sending an unlocking signal via electrical contacts, serial communication, and communication conforming to the USB standard.

[0070] [Input Unit 15] The input unit 15 is a component used for inputting key data, registering key information, and other inputs. The input unit 15 includes, for example, a numeric keypad, function keys, a touchpad, and other input means. An example of an input unit 15 that reduces power consumption is one which uses a numeric keypad.

[0071] Furthermore, although not a required configuration, the input unit 15 may include a configuration that enables various types of input in cooperation with an external input component (e.g., a keyboard or mobile device connected via USB or Bluetooth).

[0072] [Display Unit 16] The display unit 16 is a component used to display the results of key data discrimination and other status information. The display unit 16 includes, for example, an LED, a liquid crystal screen, or other display component. As an example of a display unit 16 that reduces power consumption, an LED is used that lights up red when unlocking fails using key data and lights up green when unlocking is successful.

[0073] [Reading Unit 17] The reading unit 17 is not particularly limited as long as it is a component that reads key data from a two-dimensional code B or other medium. Examples of the reading unit 17 include the use of various conventional two-dimensional code reading components, NFC communication components, RFID communication components, Bluetooth communication components, wireless LAN communication components, and other contactless media communication components. An example of a reading unit 17 that allows for various media presentation means (e.g., presentation by display on a mobile terminal, presentation by printed material) while suppressing power consumption is the use of a two-dimensional code reading component.

[0074] (Regarding power saving using input waiting) In order to reduce power consumption, it is preferable that the reading unit 17 enters a sleep state when there is no input via the input unit 15 for an extended period, and attempts to acquire key data when a read command is issued via the input unit 15 or when the input unit 15 is operated, or that such a configuration can be selected. In order to further reduce power consumption, in this configuration, it is preferable that the device control unit 11 and other hardware components enter a sleep state or power-saving state when there is no input via the input unit 15 for an extended period, and recover from the sleep state or power-saving state when a read command is issued via the input unit 15 or when the input unit 15 is operated.

[0075] One example of such a configuration is one in which the control device 1 can switch between a normal mode that constantly attempts to acquire key data and a power-saving mode that attempts to acquire key data in response to the operation of the input unit 15. This provides a control device 1 with a high degree of operational flexibility, for example, by setting it to normal mode when installed in a location with high normal usage and to power-saving mode when installed in a location with low normal usage.

[0076] (Regarding power saving using detection means) Although not a mandatory feature, it is preferable that the reading unit 17 be equipped with detection means for detecting the medium on which the key data is stored or the person presenting it. This allows the control device 1 to reduce power consumption by switching the reading unit 17 to sleep mode when no object related to the medium is detected, without requiring the user to perform an input to start the key data acquisition process. Examples of detection means include various proximity sensors (e.g., infrared proximity sensor, capacitive proximity sensor, laser distance measuring proximity sensor).

[0077] To achieve both reduced power consumption and maintained user convenience, it is preferable that the reading unit 17 be configured to enter a sleep state when there is no input via the input unit 15 or detection by the detection means, and to attempt acquisition when a reading command is issued via the input unit 15, when the input unit 15 is operated, or when an object is detected by the detection means.

[0078] [Power Supply Unit] The control device 1 includes a power supply unit (not shown) that supplies power. The power supply unit preferably includes components that can supply power in the event of a commercial power outage. Examples of such components include a power supply component that uses an external emergency power source and a battery. This allows the control device 1 to control the lock 2 even if the power supply from the commercial power source is interrupted in an emergency. An example of a power supply unit with excellent procurement advantages is one that uses four AA batteries. If installation is expected in a location where securing commercial power is difficult, it is preferable that the power supply unit be configured to use batteries during normal operation.

[0079] [Two-dimensional code B] The medium used to provide the key data to the control device 1 is not particularly limited. In order to reduce power consumption while allowing various media presentation means (e.g., presentation by display on a mobile device, presentation by printed material), a two-dimensional code B is particularly preferred.

[0080] The medium may be an NFC tag, an RFID tag, or any other contactless medium. To reduce the power consumption of the control device 1, an NFC tag using magnetic field coupling is particularly preferred as the contactless medium. Furthermore, when achieving long-distance acquisition while reducing the power consumption of the control device 1, an active RFID tag is preferred.

[0081] From the perspective of enabling the lock 2 to be unlocked in an emergency without having to find and take out a dedicated medium, the medium may be a device that can provide key data via communication through NFC, Bluetooth, Wi-Fi, or other short-range wireless communication means (e.g., a smartphone with a key data transmission application installed). The key data stored in these contactless mediums or devices may be the same as the key data related to the two-dimensional code B.

[0082] One example of an NFC medium that reduces the power consumption of the control device 1 is the use of the NFC reader / writer function of a mobile terminal. In this configuration, the mobile terminal actively writes the key data, which reduces the standby power and reading power of the reading unit 17 compared to the configuration in which the NFC communication component of the reading unit 17 actively reads the key data.

[0083] To avoid requiring the provision of media using display, printing, copying, or other means, the key data may be provided via the input unit 15. The key data provided via the input unit 15 may be the same as the key data related to the two-dimensional code B.

[0084] The key data according to this embodiment is selected from a group that includes the authority to unlock the lock 2 only in emergencies and corresponding emergency key data. An example of emergency key data that is easy for the user to identify when provided via the input unit 15 is key data in which the beginning part of the key data matches a given prefix (e.g., prefix "999") that indicates emergency key data.

[0085] In order to enable unlocking for normal use, maintenance, or other reasons, the key data according to this embodiment may be selected from a group that includes, in addition to emergency key data, unlocking key data corresponding to the authority to unlock lock 2 during normal times, or both during normal times and in emergencies.

[0086] To enable the granting of access rights according to various dates and times, the unlocking key data may correspond to the authority to unlock lock 2 only at specific dates and times. Examples of "specific dates and times" include restrictions related to dates (e.g., restrictions to one or more dates, restrictions to one or more days of the week, restrictions to one or more days of the month, restrictions to one or more days of the month), restrictions related to time periods (e.g., restrictions to business hours, restrictions to maintenance hours), and restrictions related to both dates and time periods (e.g., restrictions corresponding to different business hours on weekdays and weekends).

[0087] Data indicating a specific date and time may be included in the key data itself, or it may be included in the key information corresponding to the key data. In order to reduce the effort required for input via the input unit 15 and to obtain high-level key data, it is preferable that data indicating a specific date and time be included in the key information corresponding to the key data in key data input via the input unit 15, and in the key data itself in key data obtained via the reading unit 17.

[0088] To enable users to utilize multiple disaster relief spaces, emergency key data and unlocking key data may correspond to the authority to unlock multiple locks 2. Although not mandatory, for temporary use, unlocking key data may correspond to authority that expires after a predetermined time has elapsed since the first use or after a given number of uses.

[0089] To prevent the use of unauthorized key data, it is preferable that the key data includes verification data that contributes to authenticity verification (e.g., message authentication code (MAC), digital signature, error detection code, error correction code). To prevent the use of unauthorized key data and the generation of unauthorized key data by analyzing genuine key data, it is preferable that part or all of the key data is encrypted. To achieve both the prevention of the use or generation of unauthorized key data and the reduction of power consumption, it is preferable that at least a part of the key data is encrypted using a symmetric-key cryptography scheme. In particular, if the key data includes data indicating a specific date and time, it is preferable that the data is encrypted to prevent leakage and tampering of said date and time. Furthermore, if the key data includes data indicating the authority to unlock a specific lock 2, it is preferable that the data is encrypted to prevent leakage and tampering of the lock 2 that can be unlocked by said data.

[0090] [Lock 2] Lock 2 is a lock that restricts access to the disaster relief space when locked and allows access to the disaster relief space when unlocked. Lock 2 is controlled by a control signal received from the control device 1 via wireless communication, wired communication, or other communication.

[0091] The lock 2 transitions to the unlocked state when it receives an unlock command from the control device 1, and transitions to the locked state when it receives a lock command from the control device 1. To prevent unauthorized operation, it is preferable that the unlock command information and the lock command information include information that ensures they are legitimate commands.

[0092] The type of lock 2 is not particularly limited. An example of a lock 2 that is easy to procure and to set up in conjunction with the control device 1 is a smart lock configured to be controlled externally via Bluetooth LE communication.

[0093] [Server 3] Server 3 comprises a server control unit 31, a server storage unit 33, and a server communication unit 34. The type is not particularly limited, and may be implemented by a single server device, or by the cooperation of multiple server devices.

[0094] Server 3 executes processes related to providing emergency information indicating whether or not an emergency has occurred. Examples of such processes include enabling the emergency mode flag, deactivating the emergency mode flag, and providing emergency information to control device 1.

[0095] [Server Control Unit 31] The server control unit 31 comprises a central processing unit (CPU), random access memory (RAM), read-only memory (ROM), and other components.

[0096] The server control unit 31 cooperates with at least one of the components of the server 3, as exemplified by the server storage unit 33 and the server communication unit 34, as needed. The server control unit 31 then implements the software components of the program executed on the server 3 of this embodiment.

[0097] Examples of these software components include the flag management unit 311 and the emergency information provision unit 312. Details of these software components will be described later in the explanation of the mode management process using Figures 9 to 10.

[0098] [Server Storage Unit 33] The server storage unit 33 is a device on which data and / or files are stored, and has a storage unit that stores data using semiconductor memory, memory cards and other non-temporary storage media.

[0099] The server storage unit 33 stores programs executed by the microcomputer, emergency mode flags 331, and other data.

[0100] (Emergency Mode Flag 331) The emergency mode flag 331 is not particularly limited as long as it is data that functions as a flag set based on emergency report data indicating whether or not an emergency has occurred. The emergency mode flag 331 can be implemented, for example, by the existence or content of a record stored in a database, or by the existence or content of a file stored in a file system. As long as it is appropriately interpreted by the emergency information provision unit 312, the emergency mode flag 331 may be a flag that is valid when an emergency occurs, or a flag that is valid when an emergency does not occur.

[0101] [Server Communication Unit 34] The server communication unit 34 is configured to communicate with the control device 1 via a communication network. The server communication unit 34 includes, for example, communication components that support Wi-Fi or other wireless LANs, Low Power Wide Area Networks (LPWANs), and public mobile communication networks.

[0102] [Server Power Supply Unit] Server 3 is equipped with a server power supply unit (not shown) that supplies power. Preferably, the server power supply unit includes components that can supply power in the event of a commercial power outage. An example of such components is a power supply component that uses an emergency power supply. This allows Server 3 to provide emergency information even if the power supply from the commercial power source is interrupted during an emergency.

[0103] [Cloud Server 4] Cloud Server 4 performs key data management and other processing. Cloud Server 4 includes a cloud management unit 41, a cloud storage area 42, and means for communication with the outside (not shown). From the viewpoint of availability and scalability, Cloud Server 4 is preferably realized by the cooperation of multiple server devices, but it may also be realized by a single server device.

[0104] [Cloud Management Unit 41] The Cloud Management Unit 41 is a software component that performs key data management and other processing, and is implemented by various hardware components belonging to the Cloud Server 4. An example of the various hardware components is the same hardware components as those in Server 3.

[0105] Examples of processes performed by the cloud management unit 41 include sending the results of referencing the key information database 421 related to key data to the terminal T, editing the key information database 421, issuing unlocking key data based on key management information, and performing data exchange with the control device 1 regarding information related to key data.

[0106] An example of a process for transmitting the results of referencing the key information database 421 related to key data is a process for transmitting to the control device 1 the result of determining whether the key data corresponds to the unlocking key data corresponding to the control device 1 that referenced it; a process for transmitting information relating to the date and time on which unlocking is permitted in addition to the determination result; and a process for transmitting the result of determining whether the key data corresponds to unlocking key data that is valid at the current date and time.

[0107] Furthermore, examples of processes for editing the key information database 421 include processes for registering key management information in the key information database 421, processes for deleting key management information from the key information database 421, and processes for editing key management information stored in the key information database 421.

[0108] [Cloud Storage Area 42] The cloud storage area 42 is an area for storing the key information database 421 and other data, and is implemented by various hardware components belonging to the cloud server 4. An example of various hardware components is the same hardware components as those in the server storage unit 33.

[0109] (Key Information Database 421) The key information database 421 is configured to store key management information. This key management information includes information similar to the key information stored in the key information table 131 (e.g., data related to emergency key data, data related to unlocking key data, data related to date and time restrictions, and other data).

[0110] In order to ensure that only the data necessary for each control device 1 is transmitted, it is preferable that the key management information further includes data that identifies the control device 1 to which the data related to the key management information is to be transmitted.

[0111] In order to manage the synchronization status with the control device 1, it is preferable that the key management information further includes data that identifies the most recent date and time when the data related to the key management information was transmitted to the control device 1.

[0112] Figure 4 shows an example of a key information database 421. This example includes first key management information "M0001" related to emergency key data, second key management information "M0002" related to unlocking key data without restrictions on unlocking dates and times, and third key management information "M0003" related to unlocking key data with restrictions on unlocking dates and times. Note that the format and content of the key management information in this example are just an example for illustrative purposes, and the key information database 421 may store similar information in other formats (e.g., JSON format, binary data).

[0113] The primary key management information includes data indicating that the prefix for emergency key data is "999" ("Emergency Key Data:999*"), data identifying the control device 1 to which the data will be sent ("Destination:D0001"), and data identifying the date and time of the final transmission to the control device 1 ("△△△△ /

[0114] The second key management information includes data indicating that the key data "123456789012" is key management information related to unlocking key data equivalent to the master key ("Unlocking key data: 123456789012 Date and time restriction: None"), data identifying the destination control device 1 ("Destination: D0001, Destination: D0002"), and data specifying the last transmission date and time to each control device 1 ("△△△△ / △△ / △△ / △△ Hour △△ Minute △△ Second", "△△△△ / △△ / △△ / △△ Hour △△ Minute △△ Second"). This allows the cloud server 4 to transmit the data related to the key management information to the appropriate control device 1 and manage its synchronization status.

[0115] The third key management information includes data indicating that the key data "098765432109" corresponds to unlocking key data equivalent to a temporary key, "Unlocking key data: 098765432109 Date and time limited: △△△△ / △△ / △△ / △△ △△ to △△ to △△", data identifying the control device 1 to which the data will be sent, "D0001", and the last transmission date and time to the control device 1, "△△△△ / △△ / △△ / △△ △△ hours △△ minutes △△ seconds". This allows the cloud server 4 to send the data related to the key management information to the appropriate control device 1 and manage its synchronization status.

[0116] By configuring the key information database 421 to store various key management information as exemplified, the cloud server 4 can provide data to multiple control devices 1 that enables each control device 1 to properly control the lock 2.

[0117] [Management of Key Data on Server 3] Server 3 may be configured to perform key data management and other processing, similar to Cloud Server 4. This allows Server 3 to continue making minimum unlocking decisions even when the internet or other external lines or Cloud Server 4 are unavailable during disasters or other emergencies. In such a configuration, Server 3 has a database of key information. Further processing performed by the server control unit 31 in this configuration includes sending the results of referencing the key information database to the terminal T, and synchronizing the key information database with Cloud Server 4.

[0118] From the perspective of keeping Server 3 in a lightweight configuration suitable for emergencies, it is preferable that the key information database in Server 3 be configured to store only a portion of the information stored in the key information database 421. Examples of such configurations include storing only the key data corresponding to the control device 1 with which Server 3 directly communicates, and storing only a specified portion of such key data.

[0119] [Terminal T] Examples of terminal T include mobile devices such as smartphones and tablet devices, and various types of computers such as personal computers and notebook computers.

[0120] Terminal T, used by local government officials and other personnel responsible for managing disaster relief spaces, can execute processes such as requesting server 3 to start emergency mode, requesting server 3 to end emergency mode, and other processes by running a predetermined program.

[0121] Terminals T used by local residents and other users of the disaster relief space can perform various processes related to key information by executing a predetermined program. Examples of such processes include registering, updating, or deleting key information on the cloud server 4, obtaining output data for key data from the cloud server 4, and outputting key data based on the output data. Examples of output data when key data is output via a two-dimensional code B include image data (e.g., PNG image data) and document data including data to display the two-dimensional code B (e.g., HTML data).

[0122] If the key data is provided to the control device 1 via a two-dimensional code B, the output process for the key data may be a display or printing process of the two-dimensional code B. If the key data is provided to the control device 1 via a contactless medium, the output process may be a process of writing the key data to the contactless medium.

[0123] When key data is provided to the control device 1 via NFC, in order to make it available to more users, the output process is preferably a process that causes the control device 1 to read the key data via the NFC reader / writer function of a mobile terminal, or a process that writes the key data to the control device 1 via the NFC reader / writer function. In order to reduce power consumption related to standby power and reading power with the NFC communication component of the control device 1 as the passive side, the output process may be implemented using a process that writes the key data to the control device 1 via the NFC reader / writer function of a mobile terminal.

[0124] [Network N] Network N includes a network that enables the control device 1 and the server 3 to communicate with each other. Network N may be either a wireless network or a wired network. Network N may also be either a wide-area network or a closed network. Preferably, Network N is configured so that the control device 1 and the server 3 can communicate without requiring an internet connection. To facilitate the retrofitting of the control device 1 to an existing space, it is preferable that the network includes a wireless network. Examples of wireless networks include Wi-Fi and other wireless LANs, Low Power Wide Area Networks (LPWANs), and public mobile communication networks.

[0125] From the perspective of ensuring availability during emergencies, it is preferable that the network includes a disaster prevention wireless network. An example of a disaster prevention wireless network with excellent availability when the internet is unavailable is the wireless network related to NervNet (Nashua Solutions Inc.).

[0126] Furthermore, network N includes a network that enables communication between terminal T used by the administrator and server 3. The type of the network is not particularly limited. Preferably, the network includes a wireless network so that the administrator of the disaster relief space can quickly activate emergency mode regardless of their location. The configuration and examples of the wireless network are the same as those of the network that enables communication between control device 1 and server 3.

[0127] Network N preferably includes a network that enables the control device 1 and the cloud server 4 to communicate with each other. To facilitate the retrofitting of the control device 1 to an existing space, the network preferably includes a wireless network. The configuration and examples of the wireless network are similar to those of the network that enables the control device 1 and the server 3 to communicate with each other.

[0128] Network N preferably includes a network that enables server 3 and cloud server 4 to communicate with each other. This network may be various networks using wired or wireless communication (e.g., the Internet).

[0129] Network N preferably includes a network that enables communication between terminals T used by administrators or users and the cloud server 4. This network may be various networks using wired or wireless communication (e.g., the Internet).

[0130] [Flowchart of Unlocking Procedure] Figure 5 is a flowchart showing an example of a preferred flow of the unlocking procedure using emergency key data. The following is a general explanation of the preferred flow of the unlocking procedure in system S of this embodiment, using Figure 5.

[0131] [Disaster Occurrence] When a disaster occurs, local government officials and other personnel responsible for managing disaster relief spaces request server 3 to initiate emergency mode via terminal T. Server 3 sets the emergency mode flag to indicate that an emergency has occurred and initiates emergency mode.

[0132] [Unlocking by Residents] Users of the disaster relief space, as exemplified by residents, present a two-dimensional code B, which contains pre-distributed emergency key data, to the control device 1. The control device 1 obtains the emergency key data from the two-dimensional code B. After confirming that it is emergency key data, the control device 1 requests the server 3 to determine whether or not it is in emergency mode.

[0133] Server 3, in response to a request from control device 1, checks the emergency mode flag and determines whether or not it is in emergency mode. If it is determined that it is not in emergency mode, Server 3 provides emergency information to that effect to Control Device 1. Control Device 1 notifies that unlocking failed. If it is determined that it is in emergency mode, Server 3 provides emergency information to that effect to Control Device 1. Control Device 1 unlocks lock 2 and notifies that unlocking was successful.

[0134] According to the system S of this embodiment, the person in charge and the residents can unlock the door using the emergency key data by following the simple procedure described above. Since the control device 1 unlocks the lock 2 according to the determination result on the server 3, unlocking can be achieved only in emergencies, even though the medium for the emergency key data has been distributed in advance.

[0135] Details of the control processing performed by the control device 1 and the mode management processing performed by the server 3 will be described later with reference to Figures 6 to 10.

[0136] [Main Flowchart of Control Processing] Figure 6 is a main flowchart showing an example of a preferred flow of control processing performed by the control device 1. Figures 7 and 8 are continuations of the previous figures, respectively. The following is a description of an example of a preferred flow of control processing performed by the control device 1, using Figures 6 to 8.

[0137] The control process preferably includes a series of processes related to updating key information stored in a directly connected or built-in storage member (device storage unit 13). Steps S1 and S2 are an example of such processes.

[0138] [Step S1: Determine whether to update the information] The device control unit 11 performs a process to determine whether or not to update the information using the information update unit 111 (information update determination step). If the device control unit 11 determines that it should update the information, it moves the process to step S2; otherwise, it moves the process to step S3. The information to be updated in this step includes at least key information. The key information is stored, for example, in the key information table 131.

[0139] In this step, the procedure for determining whether or not the information update unit 111 will update the information is not particularly limited. The following is an example of such a procedure: A procedure to determine whether to update the information when an information update command is received via the input unit 15. A procedure to determine whether to update the information when it corresponds to a predetermined update timing stored in the device storage unit 13. After determining that it corresponds to a predetermined update timing, a procedure to query the cloud server 4 via the communication unit 14 whether an update is necessary, and determine whether to update the information when a response indicating that an update is necessary is received. This procedure may, for example, be a combination of multiple procedures.

[0140] [Step S2: Update Information] The device control unit 11 uses the information update unit 111 to perform a process to update the information that was to be updated in the previous step (information update execution step). The device control unit 11 then moves the process to step S3.

[0141] When an information update is commanded via the input unit 15, the update procedure in this step preferably includes a procedure to register the unlocking key data specified in accordance with the command in the key information table 131. This specification is achieved, for example, by a procedure in which the unlocking key data and / or the corresponding reservation date and time are entered via the input unit 15, following a series of inputs corresponding to the command to register the unlocking key data. Registration may also be achieved through an interactive flow in cooperation with the display unit 16.

[0142] Furthermore, if an information update is commanded via the input unit 15, the update procedure in this step preferably includes a procedure to delete the unlocking key data to be deleted specified in accordance with the command from the key information table 131. This specification is achieved, for example, by a procedure in which the unlocking key data to be deleted is specified via the input unit 15 following a series of inputs corresponding to the command to delete unlocking key data. Deletion may also be achieved through an interactive flow in cooperation with the display unit 16.

[0143] One example of this process is to display a screen in response to a deletion command, allowing the user to specify the unlocking key data to be deleted from the registered unlocking key data, and then specify the data to be deleted via this screen and the input unit 15.

[0144] Furthermore, if an information update is commanded via the input unit 15, the update procedure in this step preferably includes a procedure to update the unlocking key data to be edited, as specified in accordance with the command, in the key information table 131 with the edited data. This specification is achieved, for example, by specifying the unlocking key data to be edited and the edited data via the input unit 15, following a series of inputs corresponding to the command to edit the unlocking key data. Editing may also be achieved through an interactive flow in cooperation with the display unit 16.

[0145] One example of this process is to display a screen in response to an editing command, allowing the user to specify the unlocking key data to be edited from the registered unlocking key data, and then specify the edited data (e.g., the edited unlocking key data itself, the reservation date and time corresponding to the unlocking key data, or both) via this screen and the input unit 15.

[0146] If the information update unit 111 determines that the key information should be updated based on a predetermined update timing, it instructs the cloud server 4 to transmit, for example, part or all of the unlocking key data list via the communication unit 14, and updates the key information based on the transmitted data. From the viewpoint of reducing power consumption, it is preferable that the information update unit 111 instructs the cloud server 4 to transmit data from the unlocking key data list that has not been received by the control device 1 via the communication unit 14, and updates the key information based on the transmitted data.

[0147] If the information update unit 111 determines that it is necessary to update the data on the cloud server 4 corresponding to the history based on a predetermined update timing, it updates the data, for example, by sending unsent history to the cloud server 4.

[0148] [Step S3: Determine whether key data has been acquired] The device control unit 11 performs a process to determine whether or not key data has been acquired by the key acquisition unit 112 (key acquisition determination step). If the device control unit 11 determines that the data has been acquired, it moves the process to step S4; otherwise, it returns the process to step S1 and repeats the process from step S1 to step S14.

[0149] The key acquisition unit 112 determines, for example, whether key data has been acquired from the two-dimensional code B or other medium by the reading unit 17 or other key data reading means. The following describes the process when key data is acquired from the two-dimensional code B by the reading unit 17 which has a two-dimensional code reading member, but those skilled in the art will easily understand from this description that the process when key data is acquired from other mediums is also included in the technical concept of this embodiment.

[0150] Furthermore, the key acquisition unit 112 may determine that key data has been acquired when key data is input via the input unit 15 (e.g., when key data is input using the numeric keypad on the input unit 15). This allows the control device 1 to achieve unlocking without requiring the provision of media such as display, printing, copying, or other means. Achieving such unlocking contributes to making disaster relief spaces more reliably available during emergencies when malfunctions of various infrastructures and confusion among residents are expected.

[0151] The control process includes a series of steps to determine whether the acquired key data corresponds to emergency key data, and if it corresponds to emergency key data, to determine whether it is an emergency based on the query result to server 3 via the communication network. Steps S4 to S7 are an example of this process.

[0152] [Step S4: Determine whether it corresponds to emergency key data] The device control unit 11 performs a process to determine whether the key data acquired in the previous step corresponds to emergency key data, based on the key information stored in the directly connected or built-in storage member by the key determination unit 113 (emergency key determination step). If the device control unit 11 determines that it corresponds, it moves the process to step S5; otherwise, it moves the process to step S10.

[0153] The determination in this step is performed based on key information that determines whether or not the data is emergency key data stored in a directly connected or built-in storage element (device storage unit 13). An example of such key information is data with a given prefix (e.g., prefix "999") that indicates emergency key data. In addition, such key information may be in the form of data that indicates a rule for determining whether or not the data is emergency key data. Such key information may be stored as data separate from the program, or as integrated data.

[0154] If the control process determines in the previous step that the key data corresponds to emergency key data, it executes a series of processes to determine whether or not an emergency has occurred based on the result of a query to the server 3 via the communication network. Steps S6 to S7 are an example of this process.

[0155] Furthermore, the process may further include a determination based on the results of a previous query. Step S5 is an example of a step that realizes such determination. By further including a determination based on the results of a previous query, the control device 1 can omit wireless communication with the server 3 when the results of a previous query are stored, thereby further reducing the power consumption caused by such wireless communication.

[0156] [Step S5: Determine whether it has been identified as an emergency] The device control unit 11 performs a process to determine whether it has been identified as an emergency by the emergency determination unit 114 (disaster determination preliminary step). If the device control unit 11 determines that it has been identified as an emergency, it moves the process to step S9; otherwise, it moves the process to step S6.

[0157] In this step, the emergency determination unit 114 performs the above determination by, for example, determining that an emergency has been identified if a previous inquiry result indicating an emergency is stored in the device storage unit 13. At this time, the emergency determination unit 114 may determine whether the inquiry result is valid based on the elapsed time or other conditions related to the inquiry result, and only if it is valid may it determine that an emergency has been identified. This reduces the possibility of incorrect determinations that an emergency has been identified based on the inquiry result related to the inquiry continuing even after the situation has returned to normal from the time of the emergency when the inquiry was made.

[0158] [Step S6: Attempting to acquire emergency information via wireless communication] The device control unit 11 uses the emergency determination unit 114 to perform a process to attempt to acquire emergency information from the server 3 via wireless communication (emergency information acquisition step). The device control unit 11 then moves the process to step S7.

[0159] In this step, the emergency determination unit 114 attempts to obtain emergency information from the server 3 via wireless communication through the communication unit 14. The emergency information includes at least one of the following: data indicating that an emergency has occurred or data indicating that an emergency has not occurred. The data may be, for example, the content of a resource stored on the server 3 indicating whether or not an emergency has occurred, or a response indicating the presence or absence of a resource on the server 3 associated with at least one of whether or not an emergency has occurred. The data may also be data indicating the result of connecting to or detecting a communication network that is changed to a state that can be used by the server 3 only during emergencies or normal times.

[0160] From the viewpoint of reducing power consumption caused by wireless communication, it is preferable that the communication unit 14 remains in standby mode without performing wireless communication and starts wireless communication in response to the start of processing in this step. Also, from the same viewpoint, it is preferable that the communication unit 14 further transitions to a state where it does not perform wireless communication after the end of communication. From the viewpoint of reducing power consumption related to the start of wireless communication, it is preferable that this transition occurs after a predetermined time has elapsed since the end of communication.

[0161] From the perspective of reducing power consumption caused by wireless communication, it is preferable that the data is a response indicating the presence or absence of resources on server 3 associated with at least one of whether or not an emergency is occurring.

[0162] Furthermore, emergency information, which is a response indicating the presence or absence of resources on server 3 that indicate an emergency, contributes to limiting unlocking with emergency key data to cases where an emergency is certain. The same applies to emergency information, which is data indicating that an emergency is occurring. On the other hand, emergency information, which is a response indicating the presence or absence of resources on server 3 that indicate a normal state, contributes to ensuring emergency unlocking by extending unlocking with emergency key data to cases where it is not possible to determine whether an emergency is occurring, in addition to cases where an emergency is certain. The same applies to emergency information, which is data indicating a normal state.

[0163] [Step S7: Determining whether an emergency has been identified] The device control unit 11, using the emergency determination unit 114, performs a process to determine whether or not an emergency has been identified based on the trial results described above (disaster determination step). If the device control unit 11 determines that an emergency has been identified, it moves the process to step S9; otherwise, it moves the process to step S8. That is, the emergency determination unit 114 determines whether or not an emergency has been identified based on the results of a query to the server 3 via the communication network.

[0164] The discrimination in this step is achieved by a procedure that enables appropriate discrimination according to the nature of the emergency information. The following is an example of such a procedure.

[0165] If the emergency information is a response indicating the presence or absence of resources on server 3 that would indicate an emergency, the procedure may be such that, for example, if a response indicating the presence of resources is received, it is determined that an emergency has occurred, but if a response indicating the absence of resources is received or if a response indicating the presence of resources is not received by the timeout, it is not determined that an emergency has occurred. If the emergency information is a response indicating the presence or absence of resources on server 3 that would indicate a normal state, the procedure may be such that, for example, if a response indicating the presence of resources is received, it is not determined that an emergency has occurred, but if a response indicating the absence of resources is received or if a response indicating the presence of resources is not received by the timeout, it is determined that an emergency has occurred.

[0166] If the emergency information is data on server 3 indicating that an emergency has occurred, the procedure may, for example, determine that an emergency has occurred if such data is obtained, and not determine that an emergency has occurred if a response indicating that such data is not available is obtained or if the data is not obtained by the timeout. If the emergency information is data on server 3 indicating that it is normal, the procedure may, for example, not determine that an emergency has occurred if a response indicating that such data is available is obtained, and determine that an emergency has occurred if a response indicating that such data is not available is obtained or if the data is not obtained by the timeout.

[0167] If the emergency information is a result of connecting to or detecting a wireless network indicating that an emergency has occurred, the procedure may, for example, determine that an emergency has occurred if the wireless network is successfully detected or connected to, and not determine that an emergency has occurred if the wireless network is not successfully detected or connected to by the timeout. If the emergency information is a result of connecting to or detecting a wireless network indicating that it is normal time, the procedure may, for example, not determine that an emergency has occurred if the wireless network is successfully detected or connected to, and determine that an emergency has occurred if the wireless network is not successfully detected or connected to by the timeout. It should be noted that the form in which the emergency information is a result of connecting to or detecting a specific wireless network is preferable because it contributes to further reducing the power consumption related to the communication unit 14 when the server 3 can manage the wireless network.

[0168] [Step S8: Notification of unlocking failure] The device control unit 11 executes a process to notify of unlocking failure via the unlocking command unit 115 (first unlocking failure step). The device control unit 11 returns to step S1 and repeats the processes from step S1 to step S14. In this step, the unlocking command unit 115 notifies of unlocking failure by, for example, displaying a locked state on the LED lamp of the display unit 16 (e.g., lighting up red).

[0169] [Step S9: Command to unlock the lock] The device control unit 11 executes a process to command the lock 2 to unlock via the unlock command unit 115 (first unlock command step). The device control unit 11 returns the process to step S1 and repeats the process from step S1 to step S14. In this step, the unlock command unit 115 realizes the unlock command by transmitting the unlock command to the lock 2, for example, via Bluetooth LE communication or other communication.

[0170] Based on the processing flow up to this step, it can be said that in this step, the unlocking command unit 115 executes a process to command the unlocking of the lock if both of the following requirements are met: the key data corresponds to emergency key data (proceeding to the branch in the emergency key identification step where this is the case) and it corresponds to an emergency (proceeding to the branch in the disaster identification preliminary step or the disaster identification main step where it corresponds to an emergency).

[0171] In order for users to quickly determine that unlocking has been successful and to be able to use the disaster relief space promptly, it is preferable that in this step, the unlocking command unit 115 further performs a process to notify that unlocking has been successful. The unlocking command unit 115 notifies that unlocking has been successful, for example, by displaying an unlocked status (e.g., green light) on the LED lamp of the display unit 16.

[0172] If it is required that the disaster relief space be continuously available in an emergency, it is preferable that in this step, the unlocking command unit 115 instructs the lock 2 not to perform an automatic re-locking operation after unlocking with respect to the emergency key data.

[0173] The control process preferably further includes a series of processes related to unlocking the lock 2 during normal operation. Steps S10 to S14 are an example of such processes. This enables the control device 1 to control the lock 2 for use in normal operations, replenishment of equipment, cleaning, inspection, repair, renovation, and other reasons related to accessing the disaster relief space.

[0174] [Step S10: Determine whether the data corresponds to unlocking key data using the storage member] The device control unit 11 performs a process to determine whether the acquired key data corresponds to unlocking key data based on the key information stored in the directly connected or built-in storage member (device storage unit 13) by the key determination unit 113 (key internal determination step). If the device control unit 11 determines that the data corresponds, it moves the process to step S14; otherwise, it moves the process to step S11.

[0175] If the unlocking key data is associated with information regarding the date and time when the lock 2 can be unlocked by the key data, it is preferable that the key discrimination unit 113 determines that the acquired key data corresponds to the unlocking key data only if the key data corresponds to the unlocking key data and the current date and time corresponds to that date and time. This allows the control device 1 to provide control over the lock 2, limiting the date and time when it can be unlocked.

[0176] [Step S11: Attempting to access the database via communication] The device control unit 11 uses the key identification unit 113 to perform a process to attempt to access the database via communication (database access step). The device control unit 11 then moves the process to step S12.

[0177] From the viewpoint of reducing power consumption caused by wireless communication, it is preferable that the communication unit 14 remains in standby mode without performing wireless communication and starts wireless communication in response to the start of processing in this step. Also, from the same viewpoint, it is preferable that the communication unit 14 further transitions to a state where it does not perform wireless communication after the end of communication. From the viewpoint of reducing power consumption related to the start of wireless communication, it is preferable that this transition occurs after a predetermined time has elapsed since the end of communication.

[0178] In this step, the key identification unit 113 attempts to access an external database via a communication network using the communication unit 14. The external database is, for example, the key information database 421 owned by the cloud server 4. This allows the control device 1 to unlock the lock 2 using key data not pre-stored in the device storage unit 13, even if it is difficult to pre-store all possible key data in the device storage unit 13, by using only the minimum necessary external database access. This allows the control device 1 to reduce the power consumption caused by wireless communication for external database access.

[0179] The database lookup is achieved, for example, by instructing an external database to perform a search using the acquired key data as the search key. To prevent the leakage of key data through interception of wireless communications or other means, the instruction may be encrypted. From the viewpoint of reducing power consumption, it is preferable that the encryption be a symmetric-key cryptography scheme. The database lookup result may include information indicating whether the key data corresponds to unlocking key data, as well as information regarding the date and time on which lock 2 can be unlocked using the key data.

[0180] [Step S12: Determine if it corresponds to unlocking key data by looking at the database] The device control unit 11 uses the key determination unit 113 to determine whether the acquired key data corresponds to unlocking key data by looking at the database as described above (key external determination step). If the device control unit 11 determines that it corresponds, it moves the process to step S14; otherwise, it moves the process to step S13.

[0181] If the database lookup result is associated with information regarding the date and time when the lock 2 can be unlocked by the key data, it is preferable for the key determination unit 113 to determine that the acquired key data corresponds to unlocking key data only if the key data corresponds to unlocking key data and the current date and time corresponds to that date and time. This allows the control device 1 to provide control over the lock 2, limiting the date and time when it can be unlocked.

[0182] [Step S13: Notification of unlocking failure] The device control unit 11 executes a process to notify of unlocking failure via the unlocking command unit 115 (second unlocking failure step). The device control unit 11 returns the process to step S1 and repeats the processes from step S1 to step S14. In this step, the unlocking command unit 115 notifies of unlocking failure by, for example, displaying a locked state (e.g., red light) on the LED lamp of the display unit 16.

[0183] This step may further include a procedure for storing the history of unlocking attempts in the device storage unit 13. This allows the control device 1 to contribute to understanding the usage status of the disaster relief space, detecting unauthorized unlocking attempts, and other management processes based on the history.

[0184] [Step S14: Command to unlock the lock] The device control unit 11 executes a process to command the lock 2 to unlock via the unlock command unit 115 (second unlock command step). The device control unit 11 returns the process to step S1 and repeats the process from step S1 to step S14. In this step, the unlock command unit 115 realizes the unlock command by transmitting the unlock command to the lock 2, for example, via Bluetooth LE communication or other communication.

[0185] In normal times, if it is necessary to prevent the entrance to the disaster relief space from remaining open, in this step, it is preferable that the unlocking command unit 115 instructs the lock 2 to perform an automatic re-locking operation after unlocking using the unlocking key data, or to issue a command that does not interfere with the automatic re-locking operation that is pre-set for the lock 2. The automatic re-locking operation is triggered by conditions such as the passage of time since unlocking, a predetermined operation on the lock 2, detection that the door to which the lock 2 is attached has become closed, or other conditions.

[0186] [History transmission step] The first unlocking failure step, the first unlocking command step, the second unlocking failure step, and / or the second unlocking command step may further include a procedure for storing the history of the unlocking attempts in the device storage unit 13. This allows the control device 1 to contribute to understanding the usage status of the disaster relief space, detecting unauthorized unlocking attempts, and other management processes based on the history.

[0187] When the purpose is to understand usage status, it is preferable that the first unlock command step and the second unlock command step include steps that include a procedure for storing history. When the purpose is to detect attempts at unauthorized unlocking, it is preferable that the first unlock failure step and the second unlock failure step include steps that include a procedure for storing history.

[0188] Furthermore, if a history is stored, the control process preferably further includes a history transmission step that sends the history to the cloud server 4. This allows the control device 1 to make the history available to the cloud server 4. Providing the history contributes to management processes using the cloud server 4, such as understanding the usage status of the disaster relief space and detecting unauthorized unlocking attempts. From the viewpoint of reducing power consumption related to wireless communication, it is preferable that the provision of the history is configured to send only the unprovided portion of the history. From a similar viewpoint, it is preferable that the provision of the history is performed as a series of processes combined with other communication processes. This reduces the number of times the communication unit 14 transitions to a state of performing wireless communication, thereby reducing power consumption related to such transitions.

[0189] [Effects of Control Processing] By executing the above-described control processing, the control device 1 performs the following steps: a key acquisition step (step S3) for acquiring key data; a key determination step (step S4) for determining whether the key data is emergency key data based on key information stored in a directly connected or built-in storage member; a disaster determination step (steps S5 to S7) for determining whether an emergency has occurred based on the results of a query to a server via a communication network if the key data is emergency key data; and an unlocking command step (step S9) for commanding the unlocking of the lock if both requirements are met, namely that the key data is emergency key data and that an emergency has occurred.

[0190] As a result, the control device 1 allows the key acquisition unit 112 to acquire key data from a two-dimensional code, keypad input, or other key data provision means without requiring communication with an external device during acquisition (step S3). The key discrimination unit 113 also performs a determination of whether the data is an emergency key without requiring communication with an external device during the determination process (step S4). With this configuration, the control device 1 can suppress power consumption in these processes.

[0191] When unlocking with a pre-distributed emergency key, it is required that the use of that emergency key be limited to emergencies. Therefore, a highly reliable procedure is needed to determine whether or not an emergency has occurred, which cannot be achieved solely by the information inside the control device 1.

[0192] In the control process described above, the emergency determination unit 114 can perform a relatively power-intensive process of querying the server after determining that the acquired key data corresponds to emergency key data (step S4) (step S6). Then, the control device 1 commands unlocking based on the query result (step S9). As a result, the control device 1 can reduce power consumption by keeping communication with external devices to a minimum, further reduce the occurrence of misjudgments of emergency applicability, and achieve highly reliable unlocking using emergency key data limited to emergencies. In particular, in a configuration that performs queries via a wireless network, power consumption is expected to be reduced even more significantly because the wireless communication processing, which is a more power-intensive process, is kept to a minimum.

[0193] Therefore, the control device 1 that performs the above-described control process can limit unlocking using pre-distributed emergency key data to emergency situations only, and can realize lock control that ensures highly reliable unlocking in emergency situations.

[0194] Furthermore, the control process may take the form of a series of operations in which the key discrimination unit 113 determines whether the key data corresponds to unlocking key data based on the key information stored in the device storage unit 13 (step S10), and if it is not determined that it corresponds, it refers to an external database via a communication network (step S11), determines whether the key data corresponds to unlocking key data based on the database (step S12), and if the key data corresponds to unlocking key data, the unlocking command unit 115 commands the unlocking of the lock (step S14).

[0195] According to this configuration, even with unlocking key data used during normal times, power consumption can be suppressed even in non-emergency situations by first referring to a directly connected or built-in storage element (device storage unit 13), and only after it is determined that the data cannot be identified by this referral, wireless communication related to database referencing is performed. As a result, the control device 1 can suppress power consumption even during normal times, further preventing malfunction due to power shortages during emergencies, while simultaneously enabling unlocking during normal times and unlocking using emergency key data limited to emergencies. In particular, in a configuration that performs queries via a wireless network, it is expected that power consumption will be reduced even more significantly because the wireless communication processing, which is a more power-consuming process, will be kept to the bare minimum.

[0196] Therefore, the control device 1 that performs the control processing in this manner can limit unlocking using pre-distributed emergency key data to emergency situations only, and can realize lock control that ensures highly reliable unlocking in emergency situations.

[0197] As mentioned above, examples of spaces for use during disasters include local gymnasiums or community centers, facilities that double as evacuation shelters (e.g., event halls, shopping malls, accommodation facilities), or disaster relief storage warehouses.

[0198] Because of this wide variety, disaster relief spaces can have a wide range of characteristics, exemplified by the difficulty of retrofitting lock 2, the difficulty of securing commercial power, or the difficulty of wired communication. These characteristics can narrow the options for retrofitted electronic locks or their control means. In other words, these characteristics can be obstacles to realizing lock control that limits unlocking using pre-distributed emergency key data to emergencies only, and that ensures highly reliable unlocking during emergencies.

[0199] As described above, the control device 1 of this embodiment is basically configured to be separate from the lock 2, and the device power supply unit may be powered by a battery. In this embodiment, the control device 1 queries the server 3 for emergency information via a communication network (step S6). Subsequently, the communication unit 14 of the control device 1 processes a command to unlock the separate lock 2 via short-range wireless communication or wired communication (steps S9, S14).

[0200] These features make it easier to retrofit the control device 1 near a disaster relief space compared to a control device integrated with the lock 2, a control device requiring commercial power, or a control device requiring connection to a server via wired communication. Therefore, the control device 1, with these features, offers exceptional advantages in controlling a lock intended for emergency use, as it limits unlocking using pre-distributed emergency key data to emergencies only, and enables highly reliable unlocking during emergencies, even in disaster relief spaces possessing any of the aforementioned diverse features.

[0201] [Mode Management Process Flowchart] Figure 9 is a flowchart showing an example of a preferred flow of the mode management process performed on Server 3. Figure 10 is a continuation of the previous figure. The following is a description of an example of a preferred flow of the mode management process performed on Server 3, using Figures 9 to 10.

[0202] The mode management process includes a series of processes (flag management processes) that set an emergency mode flag based on emergency report data indicating whether or not an emergency has occurred. Steps S21 to S24 are an example of such processes.

[0203] [Step S21: Determine whether emergency report data indicating an emergency has been acquired] The server control unit 31, using the flag management unit 311, performs a process to determine whether or not emergency report data indicating an emergency has been acquired from the data sent to the server 3 from an external source (emergency report acquisition determination step). If the server control unit 31 determines that it has been acquired, it moves the process to step S22; otherwise, it moves the process to step S23.

[0204] The procedures for acquiring emergency report data in this step include the following examples of corresponding cases: (1) a case where a person operates a management terminal to set a flag; (2) a case where the flag is set automatically upon receiving earthquake warnings, notifications via disaster radio, notifications from external systems, or other information; and (3) a hybrid case combining (1) and (2) above.

[0205] In this step, "external" is not particularly limited as long as it can transmit emergency reporting data. Examples of external entities include an external terminal T and an external system. An example of an external terminal T is a terminal T used by a local government official or other person in charge of managing a disaster relief space. This allows the emergency mode flag to be set even when it is difficult for a server that distributes disaster information over a wide area (e.g., the Japan Meteorological Agency's server) to transmit emergency reporting data. An example of an external system is a disaster response system managed by a local government or other disaster response organization. This allows the system S of this embodiment to set the emergency mode flag to emergency or normal when the disaster response system transitions to an emergency-ready state or a normal-ready state.

[0206] Emergency reporting data is not limited to any data that can be interpreted by Server 3 as indicating an emergency or normal situation. Examples of emergency reporting data include datagrams sent from a dedicated application corresponding to Server 3, disaster situation notification datagrams sent by the disaster response system to linked systems, or emails or short messages from administrators.

[0207] [Step S22: Set emergency mode flag to emergency] The server control unit 31, using the flag management unit 311, executes the process of setting the emergency mode flag to emergency (emergency mode setting step). The server control unit 31 then moves the process to step S25. As a result, the server 3 can provide emergency information indicating that an emergency is occurring in response to subsequent emergency information requests.

[0208] [Step S23: Determine whether emergency report data indicating normal conditions has been acquired] The server control unit 31, using the flag management unit 311, performs a process to determine whether or not emergency report data indicating normal conditions has been acquired from the data sent to the server 3 from an external source (normal conditions report acquisition determination step). If the server control unit 31 determines that it has been acquired, it moves the process to step S24; otherwise, it moves the process to step S25.

[0209] [Step S24: Set emergency mode flag to normal] The server control unit 31, using the flag management unit 311, executes the process of setting the emergency mode flag to normal (normal mode setting step). The server control unit 31 then moves the process to step S25. As a result, the server 3 can provide emergency information indicating that it is in normal mode in response to subsequent emergency information requests.

[0210] The mode management process includes a series of processes (emergency information provision process) that, in response to a request from an external device, provide emergency information corresponding to the emergency mode flag to the external device via a communication network. Steps S25 to S28 are an example of this process.

[0211] [Step S25: Determine if emergency information has been requested] The server control unit 31 performs a process to determine whether the server 3 has received a request for emergency information from an external device, using the emergency information provision unit 312 (emergency information request determination step). If the server control unit 31 determines that a request has been received, it moves the process to step S26; otherwise, it returns the process to step S21 and repeats the process from step S21 to step S28.

[0212] In this step, the "external device" is not particularly limited as long as it is a device selected from a group that includes at least the control device 1. This allows the server 3 to cooperate with the control device 1 to help determine whether or not an emergency situation is occurring that would be difficult to resolve with the control device 1 alone.

[0213] Furthermore, Server 3 may contribute to determining whether or not an emergency is occurring in a device in response to requests for emergency information from other devices that do not correspond to Control Device 1. This enables Server 3 to quickly and simultaneously transition various devices, including Control Device 1 and other devices, into an effective emergency mode with a single operation by the operator to send emergency report data indicating that an emergency has occurred.

[0214] [Step S26: Determine if the emergency mode flag is enabled] The server control unit 31 performs a process to determine whether the emergency mode flag is enabled as an emergency state, using the flag management unit 311 (mode activation determination step). If the server control unit 31 determines that it is enabled as an emergency state, it moves the process to step S27; otherwise, it moves the process to step S28.

[0215] [Step S27: Provide emergency information indicating that an emergency has occurred] The server control unit 31, using the emergency information provision unit 312, executes a process to provide the aforementioned external device with emergency information indicating that an emergency has occurred (emergency information provision step). The server control unit 31 returns to step S21 and repeats the process from step S21 to step S28.

[0216] The emergency information in this step may be the same as the emergency information described in the emergency information acquisition step.

[0217] [Step S28: Provide information indicating that the device is not subject to an emergency] The server control unit 31, using the emergency information provision unit 312, performs the process of providing the external device described above with information indicating that the device is not subject to an emergency (normal information provision step). The server control unit 31 returns to step S21 and repeats the process from step S21 to step S28.

[0218] The information indicating that an emergency is not applicable in this step may be the same as the information described in the emergency information acquisition step.

[0219] [Effects of Mode Management Processing] Server 3, configured to communicate with control device 1 via a communication network, executes the above-described mode management processing to perform a flag management step (steps S21 to S23) in which it sets an emergency mode flag based on emergency report data indicating whether or not an emergency has occurred, and an emergency information provision step (steps S25 to S28) in which it provides emergency information corresponding to the emergency mode flag to control device 1 via the communication network in response to a request from control device 1.

[0220] As a result, server 3 can change the emergency mode by a local person in charge or other operator or a disaster response system, regardless of its access status to the server that distributes disaster information nationwide (steps S21 to S24). Server 3 can then provide emergency information based on the flag to control device 1 in response to a request from control device 1.

[0221] As a result, the control device 1 can determine whether or not an emergency is occurring based on emergency information corresponding to an emergency mode flag managed by a server 3 that can communicate via a dedicated disaster network or other communication network (steps S6 to S7).

[0222] Therefore, with the system S including the server 3 and the control device 1, the control device 1 can continue authentication and unlocking control of emergency keys without being directly affected even if it becomes difficult to access the server that distributes disaster information nationwide during an emergency.

[0223] Furthermore, the configuration, which requires only minimal information such as a flag for server 3 to provide emergency information, also prevents server 3 from experiencing a high load due to inquiries from multiple control devices 1 belonging to the communication network. In addition, the mode management process described above allows the operator to quickly and simultaneously transition all control devices 1 utilizing server 3 into an effective emergency mode with a single operation of sending emergency report data indicating that an emergency has occurred.

[0224] Therefore, the system S, which includes the server 3 that performs the mode management process described above, can limit unlocking using pre-distributed emergency key data to only in emergencies, and can implement lock control that ensures highly reliable unlocking in emergencies.

[0225] Furthermore, the mode management process may take the form of activating the emergency mode flag when the server 3 receives emergency report data from an external terminal T or system (steps S21 to S24).

[0226] According to this configuration, the server 3 activates the emergency mode flag when it receives emergency report data from the operator's terminal T or system or other device. This prevents overloading of external servers that distribute disaster information over a wide area (e.g., the Japan Meteorological Agency's server), while ensuring the speed of disaster detection even if the external server restricts access intervals.

[0227] Therefore, the system S, which includes the server 3 that performs the mode management process described above, can limit unlocking using pre-distributed emergency key data to only in emergencies, and can implement lock control that ensures highly reliable unlocking in emergencies.

[0228] <Example of Use> The following is an example of using the control device 1 of this embodiment.

[0229] [Installation in disaster relief spaces] A contractor, commissioned by a local government official or other person in charge of managing the disaster relief space, installs a lock 2 that can be controlled by short-range wireless communication at the entrance of the disaster relief space, and also installs a control device 1 within the communication range of the lock 2.

[0230] [Initial Setup] The administrator registers the unlocking key data equivalent to the master key they will use via the numeric keypad on the input unit 15. The administrator also registers the unlocking key data used by those who will use the disaster relief space during normal times, along with the date and time when their use is permitted, as needed. This registration may be done via the numeric keypad on the input unit 15 or via the cloud server 4.

[0231] Furthermore, the administrator can set the mode of the control device 1 to normal mode or power-saving mode depending on the operation of the disaster relief space and other circumstances. The administrator can also set the clock of the control device 1 via the keypad of the input unit 15 or other means as needed.

[0232] [Operation Test] The administrator sends emergency report data from terminal T to server 3, indicating an emergency, and causes server 3 to change its emergency mode flag to indicate an emergency. The administrator then displays the two-dimensional code B related to the emergency key data on terminal T and confirms that it can be unlocked. The administrator then sends data reporting that it is a normal operation from terminal T to server 3, and causes server 3 to change its emergency mode flag to indicate a normal operation. The administrator then displays the two-dimensional code B related to the emergency key data on terminal T and confirms that it cannot be unlocked. Furthermore, the administrator displays the two-dimensional code B related to the unlocking key data on terminal T and confirms that it can be unlocked.

[0233] [Pre-distribution of emergency key data] Cloud server 4 provides terminal T with data to display the two-dimensional code B related to the emergency key data, in response to requests from local residents and other users. Cloud server 4 performs a process to verify whether the user is eligible for distribution of the emergency key data, as needed. This allows cloud server 4 to pre-distribute the medium related to the emergency key data (two-dimensional code B) during normal times, when there are fewer concerns about communication failures and other issues related to data distribution, unlike during emergencies.

[0234] [Normal Use] At the monthly check timing and other times, the administrator displays the two-dimensional code B related to the unlocking key data on terminal T, unlocks lock 2, and inspects the emergency supplies and other items stored in the disaster relief space. In addition, the administrator replaces the battery in control device 1 when a predetermined period has elapsed since the last battery replacement.

[0235] A user using unlocking key data registered via the cloud server 4 displays a two-dimensional code B related to the unlocking key data on terminal T and has the control device 1 acquire it. After confirming that the control device 1 cannot identify whether or not it is unlocking key data based on key information stored in a directly connected or built-in memory component, it connects to the wireless network and queries the cloud server 4 to find out whether or not the unlocking key data is registered. Then, after obtaining a response that it is registered, the control device 1 unlocks the lock 2.

[0236] [Use in emergencies] In the event of a disaster, the administrator connects terminal T to the disaster prevention wireless network and sends emergency report data indicating that it is an emergency to server 3. Server 3 sets the emergency mode flag to indicate that it is an emergency.

[0237] Local residents and other users display the two-dimensional code B related to emergency key data on terminal T and present it to control device 1. Control device 1 retrieves the key data from the two-dimensional code B and verifies whether the key data is emergency key data. After confirming that it is emergency key data, control device 1 connects to the disaster prevention wireless network and queries server 3 to determine whether it is an emergency. After confirming that it is an emergency based on the query result, control device 1 unlocks lock 2, allowing users to use the disaster relief space.

[0238] Furthermore, within the scope of the concept of the present invention, those skilled in the art can conceive of various modifications and alterations, and it is understood that such modifications and alterations also fall within the scope of the present invention. For example, any addition, deletion, or design change of components, or addition or modification of processes or conditions, made by a person skilled in the art to the above-described embodiment, is also included within the scope of the present invention, as long as it retains the gist of the present invention. [Explanation of symbols]

[0239] S System (Emergency Key Authentication System) 1. Control device 11. Device Control Unit 111 Information Update Department 112 Key acquisition part 113 Key discrimination section 114 Emergency discrimination section 115 Unlocking Command Unit 13 Device storage 131 Key Information Table 14 Communications Department 15 Input section 16 Display section 17 Reading Unit 2 tablets 3 Servers 31 Server Control Unit 311 Flag Management Department 312 Emergency Information Department 33 Server Storage Unit 331 Emergency Mode Flag 34 Server Communication Unit 4. Cloud Server 41 Cloud Management Department 42. Cloud storage 421 Key Information Database B Two-dimensional code T terminal N Network

Claims

1. A key acquisition unit that acquires key data, A key determination unit that determines whether the key data corresponds to emergency key data based on key information stored in a directly connected or built-in memory element, If the aforementioned key data corresponds to emergency key data, an emergency determination unit determines whether or not it is an emergency based on the results of a query to the server, An unlocking command unit commands the unlocking of the lock when the key data corresponds to the emergency key data and both conditions are met, A lock control device equipped with [a specific feature].

2. The control device according to claim 1, wherein the emergency determination unit determines whether or not an emergency has occurred based on the results of an inquiry to a server via a wireless network.

3. The key discrimination unit determines, based on the key information stored in the storage member, whether the key data corresponds to unlocking key data. If it cannot determine that the data corresponds to unlocking key data, it refers to an external database and determines, based on the database, whether the key data corresponds to unlocking key data. The unlocking command unit commands the unlocking of the lock when the key data matches the unlocking key data. The control device according to claim 1.

4. A control device according to any one of claims 1 to 3, A server configured to communicate with the control device via a communication network, It consists of, The aforementioned server, A flag management unit sets an emergency mode flag based on emergency report data indicating whether or not an emergency has occurred, An emergency information provision unit provides emergency information corresponding to the emergency mode flag to the control device via the communication network in response to a request from the control device, Equipped with, Emergency key authentication system.

5. The emergency key authentication system according to claim 4, wherein the flag management unit activates the emergency mode flag when the server receives emergency report data from an external terminal or system.

Citation Information

Patent Citations

  • Electronic lock management device and electronic lock management program

    JP2017089333A

  • Electronic lock management device and electronic lock management program

    JP2017091417A

  • Lock system, lock management device, and control program for lock system

    JP2017101395A

  • Electronic lock system

    JP2018003410A

  • Electrical and electronic locks and lock control systems

    JP7717372B2