Authentication device and authentication method

The authentication device automates temporary access for companions of authorized users using device peripheral information, improving security and convenience by limiting and extending access based on trust relationships.

JP7868413B2Active Publication Date: 2026-06-02DENSO CORP

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
DENSO CORP
Filing Date
2022-05-31
Publication Date
2026-06-02

Smart Images

  • Figure 0007868413000001
    Figure 0007868413000001
  • Figure 0007868413000002
    Figure 0007868413000002
  • Figure 0007868413000003
    Figure 0007868413000003
Patent Text Reader

Abstract

To provide an authentication device capable of increasing security in authentication and improving convenience when giving authority to control an apparatus even to an unregistered user who is not registered as a regular user.SOLUTION: An authentication device includes: an authentication unit 213 that authenticates an authorized user; a short-distance communication unit 211 that acquires an advertising signal; a companion-of-authorized-user identification unit 214 that identifies, when the authorized user is authenticated by the authenticating unit 213, whether or not a companion-of-authorized-user is accompanied; a companion-of-authorized-user information identification unit 215 that identifies, when it is identified that there is the companion-of-authorized-user, information of the companion-of-authorized-user from the advertisement signal acquired by the short-range communication unit 211; and an authority granting unit 217 that uses the identified companion-of-authorized-user information to authorize the companion to use a target apparatus as well. The authentication unit 213 establishes authentication for the companion who is given authority by the authority granting unit 217 at time of subsequent authentication.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an authentication device and an authentication method.

Background Art

[0002] Regarding a predetermined device, there is known a technique for giving an unauthorized user who is not registered as a regular user the right to use the device. Patent Document 1 discloses a technique for permitting a temporary user to drive with a temporary key based on an operation input of a registered driver determined by a biometric authentication system.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the technique disclosed in Patent Document 1, in order to permit a temporary user to drive with a temporary key, it was necessary to take the trouble of an operation input of a registered driver. Here, in order to reduce the trouble of the user, it is conceivable to automate the permission of driving with a temporary key. However, when automating the permission of driving with a temporary key, it is necessary not to give permission to a user who should not be given permission.

[0005] One object of this disclosure is to provide an authentication device and an authentication method that can improve the convenience while enhancing the security in authentication when giving an unauthorized user who is not registered as a regular user the right to use the device.

Means for Solving the Problems

[0006] The above objectives are achieved by a combination of features described in the independent claims, and the subordinate claims provide further advantageous specific examples of the disclosure. The reference numerals in parentheses in the claims indicate correspondences with specific means described in the embodiments described later as one aspect, and do not limit the technical scope of this disclosure.

[0007] To achieve the above objectives, this disclosure First The authentication device comprises an authentication unit (203, 203a, 213) that authenticates authorized users who have been granted the authority to use a designated device, an information acquisition unit (201, 211) that acquires device peripheral information, which is information obtained around the device, a companion identification unit (204, 214) that identifies whether or not the authorized user has a companion when the authentication unit has successfully authenticated the authorized user, a companion information identification unit (205, 215) that identifies the companion's information from the device peripheral information acquired by the information acquisition unit when the companion identification unit has identified the presence of a companion, and an authorization granting unit (207, 207a, 207b, 217, 217b) that uses the companion's information identified by the companion information identification unit to grant the companion the authority to use the device, and the authentication unit will establish authentication for companions who have been granted authority by the authorization granting unit during subsequent authentication attempts. The device includes a restriction unit (209, 219) that sets a limit on the period during which the authority to use the device is granted to a companion, and the restriction unit causes the authority to use the device granted to the companion to expire after a set time has elapsed since the authority was granted, and the restriction unit extends the period during which the authority to use the device is granted to the companion each time the information of the same companion is identified in the companion information identification unit as authentication of a legitimate user is established in the authentication unit. . To achieve the above objective, the second authentication device of this disclosure comprises an authentication unit (203, 203a, 213) that authenticates a legitimate user authorized to use a predetermined device, an information acquisition unit (201, 211) that acquires device peripheral information, which is information obtained around the device, a companion identification unit (204, 214) that identifies whether or not the legitimate user has a companion when the authentication unit has successfully authenticated the legitimate user, a companion information identification unit (205, 215) that identifies the companion's information from the device peripheral information acquired by the information acquisition unit when the companion identification unit has identified that there is a companion, and an authorization granting unit (207, 207a, 207b, 217, 217b) that uses the companion's information identified by the companion information identification unit to grant the companion the right to use the device, and the authentication unit will authenticate the companion who has been authorized by the authorization granting unit at the next authentication time. The device is configured to allow a companion to use the device, and includes a restriction unit (209, 219) that sets a limit on the period during which the companion is granted the right to use the device. The restriction unit causes the companion's right to use the device to expire after a set time has elapsed since the right was granted. The device acquires, as peripheral device information, at least an advertisement signal that is transmitted sequentially from a mobile terminal carried by a person to notify the surroundings of the presence of that mobile terminal. The companion information identification unit (215) identifies advertisement signals other than those of a legitimate user that can be acquired by the information acquisition unit (211) as information of a companion. The restriction unit (219) temporarily extends the period during which the companion is granted the right to use the device when pairing, which is the execution of a key exchange protocol triggered by input from the companion who is the user of the mobile terminal, occurs between the mobile terminal and the device. To achieve the above objective, the third authentication device of this disclosure comprises an authentication unit (203, 203a, 213) that authenticates a legitimate user authorized to use a predetermined device, an information acquisition unit (201, 211) that acquires device peripheral information, which is information obtained around the device, a companion identification unit (204, 214) that identifies whether or not the legitimate user has a companion when the authentication unit has successfully authenticated the legitimate user, a companion information identification unit (205, 215) that identifies the companion's information from the device peripheral information acquired by the information acquisition unit when the companion identification unit has identified that there is a companion, and an authorization granting unit (207, 207a, 207b, 217, 217b) that uses the companion's information identified by the companion information identification unit to grant the companion the right to use the device, and the authentication unit shall ensure that authentication is successful for companions authorized by the authorization granting unit at subsequent authentication times. Therefore, the system includes a restriction unit (209, 219) that sets a limit on the period during which the authority to use the device is granted to a companion, and the restriction unit causes the authority to use the device granted to the companion to expire after a set time has elapsed since the authority was granted, and acquires at least advertising signals that are transmitted sequentially from a mobile terminal carried by a person to notify those around that mobile terminal of the presence of that mobile terminal as peripheral information of the device, and the companion information identification unit (215) identifies advertising signals other than those of the regular user that can be acquired by the information acquisition unit (211) as information of the companion, and the restriction unit (219) temporarily extends the period during which the authority to use the device is granted to the companion when the information acquisition unit acquires information from the regular user's mobile terminal indicating that the regular user's mobile terminal has received advertising signals from the same companion for a predetermined period of time or longer.

[0008] To achieve the above objectives, this disclosure First The authentication method includes an authentication step performed by at least one processor to authenticate a legitimate user authorized to use a predetermined device; an information acquisition step to acquire device peripheral information, which is information obtained around the device; a companion identification step to identify whether or not the legitimate user has companions if the authentication of the legitimate user is successful in the authentication step; a companion information identification step to identify the companion's information from the device peripheral information acquired in the information acquisition step if the companion is identified as having companions in the companion identification step; and an authorization granting step to grant the companion the right to use the device using the companion's information identified in the companion information identification step. In the authentication step, for companions who have been granted authorization in the authorization granting step, authentication will be successful at subsequent authentication sessions. The system includes a restriction step that sets a limit on the period during which a companion is granted permission to use the equipment, in which the permission to use the equipment granted to the companion is revoked after a set time has elapsed since the permission was granted, and in the restriction step, each time the information of the same companion is identified in the companion information identification step as authentication of a legitimate user is successful in the authentication step, the period during which the companion is granted permission to use the equipment is extended.. To achieve the above objective, the second authentication method of this disclosure includes an authentication step performed by at least one processor to authenticate a legitimate user authorized to use a predetermined device; an information acquisition step to acquire device peripheral information, which is information obtained around the device; a companion identification step to identify whether or not the legitimate user has a companion if the authentication of the legitimate user is successful in the authentication step; a companion information identification step to identify the companion's information from the device peripheral information acquired in the information acquisition step if the companion identification step identifies that there is a companion; and an authorization granting step to grant the companion the right to use the device using the companion's information identified in the companion information identification step, wherein the authentication step ensures that the authentication of the companion granted in the authorization granting step is successful at subsequent authentications. This includes a restriction step that sets a limit on the period during which a companion is granted permission to use the device, in which the permission to use the device granted to the companion is revoked after a set time has elapsed since the permission was granted, and at least advertising signals that are transmitted sequentially from a mobile terminal carried by a person to notify those around that mobile terminal of its presence as peripheral device information, in which the companion information identification step identifies advertising signals other than those of the legitimate user that can be obtained in the information acquisition step as information of the companion, and in the restriction step, if pairing, which is the execution of a key exchange protocol triggered by input from the companion who is the user of the mobile terminal, occurs between the mobile terminal and the device, the period during which the companion is granted permission to use the device is temporarily extended. To achieve the above objective, the third authentication method of this disclosure includes an authentication step performed by at least one processor to authenticate a legitimate user authorized to use a predetermined device; an information acquisition step to acquire device peripheral information, which is information obtained around the device; a companion identification step to identify whether or not there are companions of the legitimate user if the authentication of the legitimate user is successful in the authentication step; a companion information identification step to identify the companion's information from the device peripheral information acquired in the information acquisition step if the companion identification step identifies that there are companions; and an authorization granting step to grant the companion the right to use the device using the companion's information identified in the companion information identification step, wherein in the authentication step, the authentication of companions who have been granted authorization in the authorization granting step will be successful at subsequent authentications, and the companion The system includes a restriction step that sets a limit on the period during which the user is granted the right to use the equipment, in which the right to use the equipment granted to the companion is revoked after a set time has elapsed since the right was granted, and at least advertising signals that are transmitted sequentially from the mobile terminal carried by the person to notify those around the mobile terminal of its presence as peripheral information for the equipment, in which the companion information identification step identifies advertising signals other than those of the regular user that can be obtained in the information acquisition step as information of the companion, and in the restriction step, if the information acquisition step obtains information from the regular user's mobile terminal indicating that the regular user's mobile terminal has received advertising signals from the same companion for a predetermined period of time or longer, the period during which the companion is granted the right to use the equipment is temporarily extended.

[0009] According to this system, if a legitimate user is authenticated and it is determined that the legitimate user has a companion, the companion will also be granted permission to use the device. Then, during subsequent authentications, the companion who has been granted permission will also be authenticated. Therefore, it becomes possible to grant permission to use the device to a companion without the legitimate user having to perform any action to grant permission. Furthermore, since the companion is granted permission to use the device using information about the companion that is identified from the device's surroundings, it becomes possible to prevent granting permission to users who should not be granted it. As a result, when granting permission to use the device to unregistered users who are not registered as legitimate users, it becomes possible to improve both the security of authentication and convenience. [Brief explanation of the drawing]

[0010] [Figure 1] This figure shows an example of the schematic configuration of authentication system 1. [Figure 2] This figure shows an example of a schematic configuration of the vehicle-side unit 2. [Figure 3] This figure shows an example of a schematic configuration of the imaging control unit 20. [Figure 4] This figure shows an example of a schematic configuration of the communication-side control unit 21. [Figure 5] This flowchart shows an example of the flow of authorization-related processing in the imaging control unit 20. [Figure 6] This flowchart shows an example of the flow of authorization-related processing in the communication-side control unit 21. [Figure 7] This flowchart shows an example of the flow of related processing after assignment in the communication-side control unit 21. [Figure 8] This figure shows an example of a schematic configuration of the imaging control unit 20a. [Figure 9]It is a diagram showing an example of a schematic configuration of the authentication system 1b. [Figure 10] It is a diagram showing an example of a schematic configuration of the facility side unit 2b. [Figure 11] It is a diagram showing an example of a schematic configuration of the imaging side control unit 20b. [Figure 12] It is a diagram showing an example of a schematic configuration of the communication side control unit 21b.

Embodiments for Carrying out the Invention

[0011] While referring to the drawings, a plurality of embodiments for disclosure will be described. For the sake of convenience of explanation, among the plurality of embodiments, for parts having the same functions as the parts shown in the drawings used in the previous explanations, the same reference numerals may be assigned, and the explanations thereof may be omitted. For parts assigned the same reference numerals, the explanations in other embodiments can be referred to.

[0012] (Embodiment 1) <Schematic Configuration of Authentication System 1> Hereinafter, Embodiment 1 of the present disclosure will be described with reference to the drawings. The authentication system 1 shown in FIG. 1 includes a vehicle side unit 2, a mobile terminal 4, and a mobile terminal 6. The vehicle side unit 2 is used in the vehicle Ve. In the example of this embodiment, the vehicle Ve is, for example, an automobile. The vehicle Ve using the vehicle side unit 2 is not necessarily limited to an automobile.

[0013] The mobile terminal 4 is a communication terminal carried by a user. Assume that the mobile terminal 4 is carried by the authorized user AU of the vehicle Ve. The authorized user AU may be, for example, the administrator of the vehicle Ve. For example, a multifunctional mobile phone such as a smartphone may be used as the mobile terminal 4. The mobile terminal 4 performs wireless communication compliant with the Bluetooth Low Energy (Bluetooth is a registered trademark) standard. Hereinafter, this wireless communication is referred to as BLE communication. In BLE communication, the mobile terminal 4 wirelessly transmits a wireless signal including source information at a predetermined transmission interval. Thereby, the mobile terminal 4 performs advertising to notify the presence of its own terminal. This wireless transmission is broadcast communication. The communication range of BLE communication is about several tens to 100 m. Hereinafter, the wireless signal periodically transmitted for the purpose of advertising is referred to as an advertising signal. The advertising signal can also be described as information transmitted from the mobile terminal without requiring a user operation. The source information is unique identification information (hereinafter referred to as terminal ID) assigned to the mobile terminal 4. In BLE communication, when pairing based on a user operation is performed between the mobile terminal 4 and other devices, unicast communication between the paired devices becomes possible. Pairing is the execution of a key exchange protocol.

[0014] The mobile terminal 6 is a communication terminal carried by the companion CP of the authorized user AU. For example, a multifunctional mobile phone such as a smartphone may be used as the mobile terminal 6. Assume that the mobile terminal 6 has the same functions as the mobile terminal 4. That is, an advertising signal is also periodically transmitted from the mobile terminal 6.

[0015] The mobile terminal 4 preferably stores the time during which it can continuously receive the advertising signals sequentially transmitted from the mobile terminal 6. Hereinafter, this time is referred to as the Adv reception time. The Adv reception time may be stored in association with the terminal ID of the mobile terminal 6 included in the advertising signal. Then, when unicast communication is performed between the mobile terminal 4 and the vehicle-side unit 2, the mobile terminal 4 may transmit the Adv reception time and the terminal ID to the vehicle-side unit 2.

[0016] As mentioned above, vehicle-side unit 2 is used in vehicle Ve. Details of vehicle-side unit 2 are described below.

[0017] <Outline configuration of vehicle-side unit 2> Next, we will explain the general configuration of the vehicle-side unit 2 using Figure 2. As shown in Figure 2, the vehicle-side unit 2 includes an imaging-side control unit 20, a communication-side control unit 21, a wide-area communication module 22, a locator 23, a map database (hereinafter referred to as DB) 24, a vehicle status sensor 25, an HCU (Human Machine Interface Control Unit) 26, a user input device 27, an indoor camera 28, an outdoor camera 29, a vehicle control unit 30, and a drive unit 31. For example, the imaging-side control unit 20, the communication-side control unit 21, the wide-area communication module 22, the locator 23, the map DB 24, the vehicle status sensor 25, the HCU 26, the vehicle control unit 30, and the drive unit 31 may be configured to be connected to the in-vehicle LAN (see LAN in Figure 1). The indoor camera 28 and the outdoor camera 29 may also be configured to be connected to the LAN.

[0018] The wide-area communication module 22 transmits and receives information via wireless communication with a center outside the vehicle Ve. In other words, it performs wide-area communication. The wide-area communication module 22 receives traffic congestion information and other data from the center via wide-area communication.

[0019] The locator 23 is equipped with a GNSS (Global Navigation Satellite System) receiver and an inertial sensor. The GNSS receiver receives positioning signals from multiple positioning satellites. The inertial sensor includes, for example, a gyroscope and an accelerometer. The locator 23 sequentially determines the vehicle position of the vehicle Ve on which the locator 23 is mounted by combining the received positioning signals with the measurement results from the inertial sensor. The vehicle position can be expressed, for example, in latitude and longitude coordinates.

[0020] Map DB24 is a non-volatile memory that stores map data. Map data may include, for example, link data, node data, and road attribute data. Alternatively, map data distributed from the center may be received via the wide-area communication module 11 and stored in Map DB24. In this case, Map DB24 can be a volatile memory.

[0021] The vehicle status sensor 25 is a group of sensors for detecting various states of the vehicle. Examples of the vehicle status sensor 25 include a vehicle speed sensor, a steering sensor, and a seating sensor. The vehicle speed sensor detects the speed of the vehicle Ve. The steering sensor detects the steering angle of the vehicle Ve. The seating sensor detects whether or not an occupant is seated in each seat of the vehicle Ve. For example, a pressure-sensitive sensor embedded in the seating surface of each seat can be used as the seating sensor. The vehicle status sensor 25 outputs the detected sensing information to the in-vehicle LAN. Alternatively, the sensing information detected by the vehicle status sensor 25 may be output to the in-vehicle LAN via an ECU installed in the vehicle Ve.

[0022] The HCU26 performs various processes related to the interaction between the vehicle Ve's system and its occupants. The HCU26 performs these processes by executing control programs stored in non-volatile memory. The HCU26 receives input from the occupants of the vehicle Ve via the user input device 27.

[0023] The user input device 27 receives input from the user. This user input device 27 corresponds to an input receiving device. Here, the user is the occupant of vehicle Ve. The user input device 27 can be an operating device that receives operation input from the user. The operating device may be a mechanical switch or a touch switch integrated with a display. Examples of displays include a meter MID (Multi Information Display) and a CID (Center Information Display). Note that the user input device 27 is not limited to an operating device that receives operation input. For example, it may be a voice input device that receives voice commands from the user.

[0024] The interior camera 28 captures a predetermined area inside the vehicle Ve. The interior camera 28 captures an area including each seat of the vehicle Ve. There may be multiple interior cameras 28. The interior camera 28 comprises, for example, a near-infrared light source and a near-infrared camera. The interior camera 28 captures occupants illuminated with near-infrared light by the near-infrared light source using the near-infrared camera.

[0025] The exterior camera 29 images a predetermined area outside the vehicle Ve. The exterior camera 29 only needs to image the area around the vehicle Ve, including the area near the doors. This door may be limited to, for example, the driver's side door. This door may also be the passenger side door, the trunk door, etc. There may be multiple exterior cameras 29. The exterior camera 29 may include, for example, a near-infrared light source and a near-infrared camera. The exterior camera 29 photographs a person illuminated with near-infrared light by the near-infrared light source using the near-infrared camera. The exterior camera 29 may be, for example, a color camera using a CCD (Charge Coupled Device).

[0026] The vehicle control unit 30 authorizes the use of equipment in vehicle Ve. Equipment subject to authorization for use will be referred to as "target equipment" below. The vehicle control unit 30 performs authentication verification with the imaging-side control unit 20 and the communication-side control unit 21. If authentication is confirmed to be successful in either the imaging-side control unit 20 or the communication-side control unit 21, the vehicle control unit 30 authorizes the use of the target equipment. Examples of target equipment include door lock motors and drive sources. These are equipment installed in the vehicle. Authorization for the use of the door lock motor is equivalent to authorization for unlocking the doors. Authorization for the use of the drive source is equivalent to authorization for starting the drive source. When the vehicle control unit 30 detects a predetermined trigger, it performs authentication verification with the imaging-side control unit 20 and the communication-side control unit 21.

[0027] The vehicle control unit 30 may, for example, detect the operation of the lock / unlock switch and perform authentication verification to authorize unlocking. The lock / unlock switch is a switch used to request the locking or unlocking of the doors of the vehicle Ve. For the driver's and passenger's doors, the lock / unlock switch is provided, for example, on the outer door handle. For the trunk door, the lock / unlock switch is provided, for example, on the rear bumper. The lock / unlock switch may be a touch switch or a mechanical button switch. In addition, authentication verification to authorize unlocking may be performed using triggers other than the operation of the lock / unlock switch.

[0028] The vehicle control unit 30 only needs to perform authentication verification to authorize the starting of the drive source when it detects, for example, the operation of the start switch. The start switch is a switch for requesting the starting of the drive source of the vehicle Ve. The start switch is located, for example, in front of the driver's seat. A mechanical button switch can be used as the start switch.

[0029] The drive unit 31 drives the target equipment authorized for use by the vehicle control unit 30. If unlocking is permitted, the drive unit 31 unlocks the door lock. Unlocking the door lock can be done by outputting an unlocking signal to the door lock motor. If starting the drive source is permitted, the drive unit 31 starts the drive source. Examples of drive sources include internal combustion engines and motor generators.

[0030] The imaging control unit 20 includes, for example, a processor, memory, I / O, and a bus connecting them. It executes various authentication processes by running a control program stored in memory. The imaging control unit 20 authenticates the user based on information obtained from the indoor camera 28 or the outdoor camera 29. The memory referred to here is a non-transitory tangible storage medium that non-temporarily stores computer-readable programs and data. This non-transitory tangible storage medium is implemented using semiconductor memory or the like. Details of the imaging control unit 20 will be described later.

[0031] The communication-side control unit 21 includes, for example, a processor, memory, I / O, and a bus connecting them. It executes various authentication processes by running a control program stored in memory. The communication-side control unit 21 authenticates the user based on information obtained from the mobile terminal 4 or mobile terminal 6. The memory referred to here is a non-transitory tangible storage medium that non-temporarily stores computer-readable programs and data. The non-transitory tangible storage medium is implemented using semiconductor memory or the like. Details of the communication-side control unit 21 will be described later.

[0032] <Outline configuration of the imaging control unit 20> Next, the schematic configuration of the imaging-side control unit 20 will be explained using Figure 3. As shown in Figure 3, the imaging-side control unit 20 includes an image information acquisition unit 201, a registration unit 202, an authentication unit 203, a companion identification unit 204, a companion information identification unit 205, a seating area identification unit 206, an authorization granting unit 207, a setting unit 208, and a restriction unit 209 as functional blocks. This imaging-side control unit 20 corresponds to an authentication device. Furthermore, the execution of processing by each functional block of the imaging-side control unit 20 by a computer corresponds to the execution of an authentication method. Note that some or all of the functions performed by the imaging-side control unit 20 may be configured hardware-wise using one or more ICs, etc. Also, some or all of the functional blocks provided by the imaging-side control unit 20 may be realized by a combination of software execution by a processor and hardware components.

[0033] The image information acquisition unit 201 acquires information obtained around the target device (hereinafter referred to as "device surrounding information"). This image information acquisition unit 201 corresponds to the information acquisition unit. The processing performed by this image information acquisition unit 201 corresponds to the information acquisition process. The image information acquisition unit 201 acquires images captured by the indoor camera 28 as device surrounding information. The image information acquisition unit 201 also acquires images captured by the outdoor camera 29 as device surrounding information. The indoor camera 28 and the outdoor camera 29 correspond to imaging devices. It is preferable for the image information acquisition unit 201 to acquire device surrounding information sequentially. The images acquired by the image information acquisition unit 201 are referred to as acquired images below.

[0034] The registration unit 202 has pre-registered authentication information for legitimate users (AUs). Non-volatile memory can be used for the registration unit 202. A legitimate user (AU) is a user authorized to use the target device. The authentication information can be the facial features of the legitimate user (AU). These features can be detected using facial image recognition technology.

[0035] The authentication unit 203 performs authentication. The processing in this authentication unit 203 corresponds to the authentication process. It authenticates legitimate user AUs. The authentication unit 203 only needs to perform authentication when requested by the vehicle control unit 30. The authentication unit 203 extracts a human face image from the acquired image. The authentication unit 203 detects facial features from the extracted face image. The authentication unit 203 compares the detected facial features with the facial features of legitimate user AUs registered in the registration unit 202. The authentication unit 203 establishes authentication if there is a face image whose features match those of a legitimate user AU. On the other hand, the authentication unit 203 fails to establish authentication if there is no face image whose features match those of a legitimate user AU. In this context, a match of features means a match above a threshold. In other words, the authentication unit 203 performs facial authentication. Note that the information for authentication may be a face image instead of facial features. In this case as well, the authentication unit 203 can detect and compare facial features from the face image.

[0036] The authentication unit 203 sends the authentication result to the vehicle control unit 30. The vehicle control unit 30 verifies the authentication based on the authentication result sent from the authentication unit 203. If the vehicle control unit 30 receives a result indicating successful authentication, it verifies that the authentication is successful. On the other hand, if the vehicle control unit 30 receives a result indicating unsuccessful authentication, it verifies that the authentication is unsuccessful. If the vehicle control unit 30 verifies that the authentication is successful, it permits the use of the target device. On the other hand, if the vehicle control unit 30 verifies that the authentication is unsuccessful, it does not permit the use of the target device. Note that the process of detecting facial features from the facial image may be handled by the control units of the indoor camera 28 and the outdoor camera 29.

[0037] The companion identification unit 204 identifies the presence or absence of a companion CP of the legitimate user AU when the authentication unit 203 has successfully authenticated the legitimate user AU. This processing in the companion identification unit 204 corresponds to the companion identification step. The companion identification unit 204 only needs to identify that there is a companion if a face image other than that of the legitimate user AU is recognized from the image acquired by the image information acquisition unit 201. A face image other than that of the legitimate user AU is a face image whose features do not match those of the legitimate user AU. This face image other than that of the legitimate user AU corresponds to the face image of the companion CP. The companion identification unit 204 may also identify that there is a companion if the aforementioned seating sensor detects that two or more people are seated in seats.

[0038] The companion information identification unit 205 identifies the companion CP information when the companion identification unit 204 identifies that there is a companion. The companion information identification unit 205 identifies the companion CP information from the equipment surrounding information acquired by the image information acquisition unit 201. This processing in the companion information identification unit 205 corresponds to the companion information identification step. The companion information identification unit 205 only needs to identify the face image of a person other than the regular user recognized from the acquired image as the companion CP information. It is preferable for the companion information identification unit 205 to sequentially identify the companion CP information from the acquired images obtained sequentially.

[0039] The seating area identification unit 206 identifies the seating area of ​​the accompanying person CP in the vehicle Ve when the accompanying person identification unit 204 identifies the presence of an accompanying person. The seating area may be, for example, an area for each seat. For example, the seating area of ​​the accompanying person CP may be identified as the seating area of ​​the accompanying person CP if the seating sensor detects that a seat other than the driver's seat is occupied. Alternatively, the seating area identification unit 206 may identify the seating area of ​​the accompanying person CP from the position where the accompanying person CP's face image was recognized in the acquired image.

[0040] The authorization granting unit 207 uses the information of the accompanying CP identified by the accompanying information identification unit 205 to grant the accompanying CP the authority to use the target equipment. This processing in the authorization granting unit 207 corresponds to the authorization granting process. As an example, the facial feature quantities of the accompanying CP are registered in the registration unit 202 as authentication information. For accompanying CPs whose facial feature quantities are registered in the registration unit 202, authentication will be successful at subsequent authentication sessions. In other words, the authentication unit 203 will establish authentication for accompanying CPs that have been granted authority by the authorization granting unit 207 at subsequent authentication sessions.

[0041] This allows accompanying CPs to be granted access to the target device without the regular user AU having to perform any actions to grant permission. Furthermore, access to the target device is granted to accompanying CPs using information about them that is identified from device peripheral information obtained around the target device. Therefore, it becomes possible to prevent granting access to users who should not be granted it. As a result, when granting access to devices to unregistered users who are not registered as regular users, it becomes possible to improve both the security of authentication and convenience.

[0042] Preferably, the authorization granting unit 207 grants the authority to use the target device to a companion CP if the companion information identification unit 205 continuously identifies the information of the same companion CP for a specified period of time or longer. If the authorization granting unit 207 is unable to continuously identify the information of the same companion CP for a specified period of time or longer, it does not need to grant the authority to use the target device to that companion CP. The specified period can be set arbitrarily. For example, the specified period can be set to 5 minutes. Users who are in the same room as a legitimate user AU for a certain period of time or longer are presumed to have a trust relationship with the legitimate user AU. With the above configuration, it becomes possible to grant the authority to use the target device only to users who are presumed to have a trust relationship with the legitimate user AU. As a result, security is further improved.

[0043] Preferably, the authorization granting unit 207 grants the companion CP the authority to use the target equipment, but limited to the seating area in the vehicle Ve. In this case, the authorization granting unit 207 can register the seating area in which the use of the target equipment is permitted, linked to the authentication information of the companion CP, in the registration unit 202. Hereinafter, the seating area in which the use of the target equipment is permitted will be referred to as the permitted area. The permitted area may be set in advance by the user, for example, via the user input device 27. Preferably, the authentication unit 203 does not complete the authentication if the seating area of ​​the companion CP identified by the seating area identification unit 206 is not a seating area to which authority has been granted. On the other hand, the authentication unit 203 can complete the authentication if it is a seating area to which authority has been granted. This makes it possible to restrict the authority to use the target equipment granted to the companion CP according to the seating area of ​​the companion CP. For example, if the companion CP is seated anywhere other than the driver's seat, it is possible not to grant the authority to start the driving power source.

[0044] It is preferable that the setting unit 208 sets the aforementioned specified time in accordance with the input received by the user input device 27. This allows the user to freely set the specified time.

[0045] It is preferable for the restriction unit 209 to set a limit on the period during which it grants the accompanying CP the authority to use the target equipment. Hereinafter, this period will be referred to as the authority granting period. It is preferable for the restriction unit 209 to revoke the authority to use the target equipment granted to the accompanying CP after a set time has elapsed since the authority was granted. The period from when the authority is granted until the set time has elapsed is the time limit granting period. With the above configuration, the authority to use the target equipment granted to anyone other than the regular user AU can be made temporary. The authority granting period can be set to an arbitrary value. For example, the default authority granting period can be set to 12 hours. The restriction unit 209 can determine the end of the authority granting period using a timer circuit or the like. When the authority granting period for a certain accompanying CP has ended, the restriction unit 209 can delete the authentication information for that accompanying CP registered in the registration unit 202.

[0046] The restriction unit 209 preferably revokes the privilege to use the target equipment granted to the accompanying CP in response to the input received by the user input device 27. An input requesting the revocation of privileges will be referred to as a revocation input below. This allows the privilege to use the target equipment granted to the accompanying CP to be revoked at the request of the regular user AU.

[0047] The restriction unit 209 preferably extends the period for which it grants permission to use the target equipment to a companion CP each time the companion information identification unit 205 identifies the same companion CP as authentication of a legitimate user AU is successful in the authentication unit 203. In other words, the more often a companion CP accompanies a legitimate user AU when using the target equipment, the longer the permission grant period should be set. For example, a certain amount of time can be added to the default permission grant period. This reduces the effort required to obtain permission again for companion CPs that accompany legitimate user AUs more frequently. The restriction unit 209 should also store the setting value of the permission grant period for companion CPs whose permission has expired and whose permission has been lost. Then, each time a companion CP accompanies a legitimate user AU when using the target equipment, the setting value of the permission grant period for that companion CP should be increased. The setting value should be stored in non-volatile memory.

[0048] <Outline configuration of the communication-side control unit 21> Next, the schematic configuration of the communication-side control unit 21 will be explained using Figure 4. As shown in Figure 4, the communication-side control unit 21 includes a short-range communication unit 211, a registration unit 212, an authentication unit 213, a companion identification unit 214, a companion information identification unit 215, a driving-related information acquisition unit 216, an authorization granting unit 217, a setting unit 218, and a restriction unit 219 as functional blocks. This communication-side control unit 21 also corresponds to an authentication device. Furthermore, the execution of processing for each functional block of the communication-side control unit 21 by a computer corresponds to the execution of an authentication method. Note that some or all of the functions performed by the communication-side control unit 21 may be configured hardware-wise using one or more ICs, etc. Also, some or all of the functional blocks provided by the communication-side control unit 21 may be realized by a combination of software execution by a processor and hardware components.

[0049] The short-range communication unit 211 performs wireless communication compliant with the Bluetooth Low Energy standard via an antenna. The short-range communication unit 211 performs unicast communication with the paired mobile terminals 4 and 6. The short-range communication unit 211 acquires device peripheral information obtained around the target device. This short-range communication unit 211 corresponds to the information acquisition unit. The processing in this short-range communication unit 211 also corresponds to the information acquisition process. The short-range communication unit 211 acquires advertisement signals that are sequentially transmitted from the mobile terminals 4 and 6 as device peripheral information.

[0050] The registration unit 212 has pre-registered authentication information for legitimate user AUs. Non-volatile memory can be used for the registration unit 212. The authentication information can be the terminal ID of the legitimate user AU's mobile terminal 4.

[0051] The authentication unit 213 performs authentication. The processing in this authentication unit 213 also corresponds to the authentication process. It authenticates legitimate user AUs. Similar to the authentication unit 203, the authentication unit 213 only needs to perform authentication when requested by the vehicle control unit 30. The authentication unit 213 extracts the terminal ID from the advertised signal acquired by the short-range communication unit 211. The authentication unit 213 compares the extracted terminal ID with the terminal IDs of legitimate user AUs registered in the registration unit 212. The authentication unit 213 establishes authentication if a terminal ID matching the terminal ID of a legitimate user AU exists. On the other hand, the authentication unit 213 fails to establish authentication if no terminal ID matching the terminal ID of a legitimate user AU exists. In other words, the authentication unit 213 performs ID authentication. The authentication unit 213 sends the authentication result to the vehicle control unit 30. The vehicle control unit 30 verifies the authentication in the same way as when it receives the authentication result from the authentication unit 203. The vehicle control unit 30 confirms the success of the authentication process when it receives a result indicating that the authentication has been successful.

[0052] The companion identification unit 214 identifies whether or not there is a companion CP of the legitimate user AU when the authentication unit 213 has successfully authenticated the legitimate user AU. This processing in the companion identification unit 214 also corresponds to the companion identification process. The companion identification unit 214 only needs to identify that there is a companion when the short-range communication unit 211 has acquired an advertisement signal that includes a terminal ID other than that of the legitimate user AU. The companion identification unit 214 may also identify that there is a companion when the aforementioned seating sensor detects that two or more seats are occupied.

[0053] The companion information identification unit 215 identifies the companion CP information when the companion identification unit 214 identifies that there is a companion. The companion information identification unit 215 identifies the companion CP information from the advertisement signal acquired by the short-range communication unit 211. This processing in the companion information identification unit 215 corresponds to the companion information identification step. The companion information identification unit 215 only needs to identify the terminal ID included in the advertisement signal other than the regular user AU, which was acquired by the short-range communication unit 211, as the companion CP information. The advertisement signal other than the regular user AU referred to here is an advertisement signal that does not include the terminal ID of the regular user AU. In other words, it is the advertisement signal of the companion CP. It is preferable for the companion information identification unit 215 to sequentially identify the terminal ID of the companion CP from the advertisement signals that are obtained sequentially.

[0054] The driving-related information acquisition unit 216 acquires information about the driving status of vehicle Ve (hereinafter referred to as driving-related information). Driving-related information includes traffic congestion information. The driving-related information acquisition unit 216 can acquire traffic congestion information via the wide-area communication module 22. Driving-related information includes the vehicle speed of vehicle Ve. The driving-related information acquisition unit 216 can acquire the vehicle speed from the aforementioned vehicle speed sensor. Driving-related information includes the steering angle of vehicle Ve. The driving-related information acquisition unit 216 can acquire the steering angle from the aforementioned steering sensor. Driving-related information includes the vehicle position of vehicle Ve. The driving-related information acquisition unit 216 can acquire the vehicle position from the locator 23.

[0055] The authorization granting unit 217 uses the information of the accompanying user identified by the accompanying user information identification unit 215 to grant the accompanying user the authority to use the target device. This processing in the authorization granting unit 217 corresponds to the authorization granting process. For example, the terminal ID of the accompanying user is registered in the registration unit 212 as authentication information. For accompanying user CPs whose terminal IDs are registered in the registration unit 212, authentication will be successful during subsequent authentications. In other words, the authentication unit 213 will establish authentication for accompanying user CPs that have been granted authority by the authorization granting unit 217 during subsequent authentications. As a result, when granting the authority to use the device to unregistered users who are not registered as legitimate users, it becomes possible to improve both the security of authentication and convenience.

[0056] It is preferable that the authorization granting unit 217 grants the authorization to use the target device to a companion CP based on the companion information identification unit 215's identification of the same companion CP's advertisement signal for a specified period of time or longer. The processing in the authorization granting unit 217 can be the same as in the authorization granting unit 207. This makes it possible to grant authorization to use the target device only to users who are presumed to have a trust relationship with the legitimate user AU.

[0057] It is preferable that the authorization granting unit 217 grants the authority to use the target device to the accompanying CP based on the accompanying information identification unit 215 continuously identifying the same accompanying CP's advertisement signal for a specified period of time or longer while the vehicle Ve is traveling at a predetermined speed or higher. The short-range communication unit 211 can also receive advertisement signals other than those of the regular user AU and accompanying CP. Therefore, even if the accompanying information identification unit 215 can continuously identify the same advertisement signal for a specified period of time or longer, it may not be the advertisement signal of the accompanying CP. In contrast, by setting the condition that the vehicle Ve is traveling at a predetermined speed or higher, it is possible to suppress the erroneous granting of authority to a user who is not a passenger in the vehicle Ve. Therefore, it is possible to further improve the security of authentication. The predetermined speed can be a value that distinguishes it from driving in traffic congestion, for example. As an example, the predetermined speed can be 20 km / h. The authorization granting unit 217 can use the driving-related information acquired by the driving-related information acquisition unit 216 to determine if vehicle Ve is driving at a predetermined speed or higher. In this case, the driving-related information should be the vehicle speed of vehicle Ve.

[0058] It is preferable that the authorization granting unit 217 also includes the condition that the vehicle Ve is in motion after making a specified number of right and left turns as a condition for granting authorization to the accompanying CP to use the target device. If the vehicle Ve has made a specified number of right and left turns, the likelihood of the accompanying information identification unit 215 continuously identifying the advertisement signal of a user not riding in the vehicle Ve for a specified period of time or longer is low. Therefore, with the above configuration, it is possible to further suppress the erroneous granting of authorization to a user not riding in the vehicle Ve. Thus, it becomes possible to further improve the security of authentication.

[0059] The authorization granting unit 217 may, in the same manner as the authorization granting unit 207, grant the accompanying CP the authority to use the target equipment, but limited to the seating area in the vehicle Ve. The setting unit 218 preferably sets the aforementioned specified time in accordance with the input received by the user input device 27, in the same manner as the setting unit 208. This makes it possible for the user to freely set the specified time.

[0060] The restriction unit 219, similar to the restriction unit 209, preferably sets a limit on the period during which it grants the accompanying CP the authority to use the target equipment. When the authorization period for a particular accompanying CP has ended, the restriction unit 219 should delete the authentication information for that accompanying CP registered in the registration unit 212.

[0061] It is preferable that the restriction unit 219, in the same manner as the restriction unit 209, revokes the authority to use the target equipment granted to the accompanying CP in response to the deletion input received by the user input device 27. This allows the authority to use the target equipment granted to the accompanying CP to be revoked at the request of the regular user AU.

[0062] The restriction unit 219, similar to the restriction unit 209, preferably extends the period for which it grants the authority to use the target equipment to the accompanying CP each time the accompanying information identification unit 215 identifies the information of the same accompanying CP as authentication of a legitimate user AU is successful in the authentication unit 213.

[0063] The restriction unit 219 preferably temporarily extends the authorization period for the accompanying CP when pairing is performed between the mobile terminal 6 and the short-range communication unit 211. This pairing is to be caused by an operation of the mobile terminal 6. In other words, it is to be pairing initiated by input from the accompanying CP. Temporary extension of the authorization period means temporarily lengthening the authorization period for the accompanying CP while authorization is granted. Here, temporary extension refers to an extension limited to the period from the granting of authorization to the termination of authorization. This makes it possible to temporarily extend the authorization to use the target device granted to the accompanying CP at the accompanying CP's request.

[0064] The restriction unit 219 preferably temporarily extends the authorization period for a companion CP when it obtains specific information about the companion CP from the regular user AU's mobile terminal 4 using the short-range communication unit 211. The specific information about the companion CP is the Adv reception time, which is the time during which the mobile terminal 6 has continuously received an advertisement signal from the same companion CP for a predetermined period of time or longer. The predetermined time can be set to any arbitrary value. For example, the predetermined time can be set to 5 minutes. For example, a companion CP who has been acting together with the regular user AU after getting out of the vehicle Ve may need to return to the vehicle Ve separately from the regular user AU. If the authorization period for the companion CP has expired in this case, convenience will be reduced. However, with the above configuration, it is possible to temporarily extend the authorization period for such a companion CP, thus improving convenience.

[0065] <Authorization-related processing in the imaging-side control unit 20> Next, using the flowchart in Figure 5, we will explain an example of the process for granting permission to use the target equipment to the accompanying CP in the imaging control unit 20 (hereinafter referred to as the permission granting process). The flowchart in Figure 5 should be configured to start when an authentication request is received from the vehicle control unit 30.

[0066] First, in step S1, the image information acquisition unit 201 acquires an image captured by the indoor camera 28 or the outdoor camera 29. In step S2, the authentication unit 203 performs face recognition using the features detected based on the image acquired in S1.

[0067] In step S3, if authentication of the legitimate user AU is successful (YES in S3), the process proceeds to step S4. On the other hand, if authentication of the legitimate user AU is unsuccessful (NO in S3), the authorization granting process is terminated. The imaging control unit 20 sends a response regarding the authentication result to the vehicle control unit 30.

[0068] In step S4, the companion identification unit 204 determines whether the regular user AU has a companion CP. If it determines that there is a companion (YES in S4), it proceeds to step S5. On the other hand, if it determines that there is no companion (NO in S4), it terminates the authorization granting process. In step S5, the companion information identification unit 205 identifies the facial image of a person other than the regular user, recognized from the acquired image, as the information of the companion CP.

[0069] In step S6, if the companion information identification unit 205 continuously identifies the face image of the same companion CP for a specified period of time or longer (YES in S6), the process proceeds to step S7. On the other hand, if the face image of the same companion CP cannot be continuously identified for a specified period of time or longer (NO in S6), the authorization granting process is terminated. In step S7, the companion CP whose face image was continuously identified for a specified period of time or longer is granted the authority to use the target device.

[0070] In step S8, if the accompanying CP granted permission in S7 is the multiple time permission has been granted cumulatively (YES in S8), the process proceeds to step S9. On the other hand, if it is not the multiple time permission has been granted cumulatively (YES in S8), the permission granting process ends. In step S9, the set value for the permission granting period for the accompanying CP granted permission in S7 is added. Then, the permission granting process ends.

[0071] <Authorization-related processing in the communication-side control unit 21> Next, using the flowchart in Figure 6, we will explain an example of the flow of authorization-related processing in the communication-side control unit 21. The flowchart in Figure 6 should also be configured to start when an authentication request is received from the vehicle control unit 30.

[0072] First, in step S21, if the near-field communication unit 211 acquires an advertised signal (YES in S21), the process proceeds to step S22. On the other hand, if the near-field communication unit 211 fails to acquire an advertised signal (NO in S21), the authorization granting process is terminated. For example, if the near-field communication unit 211 fails to acquire an advertised signal within a set time after receiving an authentication request, the authorization granting process should be terminated. In step S22, the authentication unit 213 performs ID authentication using the terminal ID included in the advertised signal acquired in S21.

[0073] In step S23, if authentication of the legitimate user AU is successful (YES in S23), the process proceeds to step S24. On the other hand, if authentication of the legitimate user AU is unsuccessful (NO in S23), the authorization granting process is terminated. The communication-side control unit 21 sends a response regarding the authentication result to the vehicle control unit 30.

[0074] In step S24, the companion identification unit 214 determines whether the regular user AU has a companion CP. If it determines that there is a companion (YES in S24), it proceeds to step S25. On the other hand, if it determines that there is no companion (NO in S24), it terminates the authorization granting process. In step S25, the companion information identification unit 215 identifies the terminal ID included in the advertisement signal other than that of the regular user AU, which was obtained by the short-range communication unit 211, as the companion CP information.

[0075] In step S26, if the companion information identification unit 215 continuously identifies the advertisement signal of the same companion CP for a specified time or longer (YES in S26), the process proceeds to step S27. On the other hand, if the advertisement signal of the same companion CP cannot be continuously identified for a specified time or longer (NO in S26), the authorization granting process is terminated. In step S27, the companion CP whose advertisement signal was continuously identified for a specified time or longer is granted the authority to use the target equipment.

[0076] In step S28, if the accompanying CP granted authority in S27 is the multiple time authority has been granted (YES in S28), the process proceeds to step S29. On the other hand, if it is not the multiple time authority has been granted (YES in S28), the authority granting process ends. In step S29, the set value for the authority grant period for the accompanying CP granted authority in S27 is added. Then, the authority granting process ends.

[0077] <Post-assignment related processing in the communication-side control unit 21> Next, using the flowchart in Figure 7, we will explain an example of the processing flow after the authorization is granted to the accompanying CP in the communication-side control unit 21 (hereinafter referred to as post-authorization related processing). The flowchart in Figure 7 should be configured to start when the communication-side control unit 21 grants the accompanying CP the authority to use the target equipment.

[0078] First, in step S40, if the authorization period has expired (YES in S40), the process proceeds to step S41. On the other hand, if the authorization period has not expired (NO in S40), the process proceeds to step S42. In step S41, the restriction unit 219 revokes the authorization granted to the accompanying CP. Then, the post-authorization related processing is completed.

[0079] In step S42, if the user input device 27 receives a loss input (YES in S42), the process proceeds to S41. On the other hand, if the user input device 27 does not receive a loss input (NO in S42), the process proceeds to step S43. The limiting unit 219 can determine whether or not the user input device 27 has received a loss input.

[0080] In step S43, if pairing has occurred between the companion CP's mobile terminal 6 and the short-range communication unit 211 (YES in S43), the process proceeds to step S44. On the other hand, if pairing has not occurred (NO in S43), the process proceeds to step S45. In step S44, the restriction unit 219 temporarily extends the authorization period for the companion CP.

[0081] In step S45, if the short-range communication unit 211 obtains the aforementioned specific information about the accompanying CP from the regular user AU's mobile terminal 4 (YES in S45), the process proceeds to step S46. On the other hand, if the specific information is not obtained (NO in S45), the process returns to S40 and is repeated. In step S46, the restriction unit 219 temporarily extends the authorization period for the accompanying CP. Then, the process returns to S40 and is repeated.

[0082] Embodiment 1 shows a configuration in which the vehicle-side unit 2 includes both the imaging-side control unit 20 and the communication-side control unit 21, but it is not necessarily limited to this configuration. For example, the vehicle-side unit 2 may include only one of the imaging-side control unit 20 or the communication-side control unit 21.

[0083] (Embodiment 2) The configuration is not limited to Embodiment 1; the configuration of Embodiment 2 described below may also be used. Below, an example of the configuration of Embodiment 2 will be explained with reference to a diagram. The authentication system 1 of Embodiment 2 is the same as the authentication system 1 of Embodiment 1, except that it includes an imaging-side control unit 20a instead of the imaging-side control unit 20 included in the vehicle-side unit 2.

[0084] Here, we will explain the schematic configuration of the imaging-side control unit 20a using Figure 8. As shown in Figure 8, the imaging-side control unit 20a includes an image information acquisition unit 201, a registration unit 202a, an authentication unit 203a, a companion identification unit 204, a companion information identification unit 205, a seating area identification unit 206, an authorization granting unit 207a, a setting unit 208, and a restriction unit 209 as functional blocks. The imaging-side control unit 20a is the same as the imaging-side control unit 20 of Embodiment 1, except that it includes a registration unit 202a, an authentication unit 203a, and an authorization granting unit 207a instead of a registration unit 202, an authentication unit 203, and an authorization granting unit 207. This imaging-side control unit 20a also corresponds to an authentication device. Furthermore, the execution of processing for each functional block of the imaging-side control unit 20a by a computer corresponds to the execution of an authentication method.

[0085] The authorization granting unit 207a is the same as the authorization granting unit 207 of Embodiment 1, except that it changes the type of equipment for which the accompanying CP is authorized to use, depending on the seating area in the vehicle Ve. For example, for the driver's seat, it is sufficient to grant the authority to either unlock or start the drive source. On the other hand, for seats other than the driver's seat, the authority to unlock is granted, but the authority to start the drive source is not. The authorization granting unit 207a registers the types of equipment for which use is permitted, linked to the authentication information of the accompanying CP, for each seating area in the registration unit 202a. The registration unit 202a is the same as the registration unit 202 of Embodiment 1, except in this respect.

[0086] The authentication unit 203a, for companion CPs who have been granted authority by the authorization granting unit 207a, establishes authentication for the use of target equipment of a type corresponding to the companion CP's seating area during authentication. The companion CP's seating area can be identified by the seating area identification unit 206. This makes it possible to restrict the types of target equipment that companion CPs are authorized to use according to their seating area.

[0087] (Embodiment 3) The configuration may not be limited to the embodiment described above, but may also be that of Embodiment 3 described below. For example, a smart entry system may be used for the authentication of a legitimate user AU. In this case, the authentication of the legitimate user AU is performed by the smart entry system. On the other hand, the authentication of an authorized accompanying CP is performed as described in the embodiment described above.

[0088] (Embodiment 4) The configuration may be not limited to the embodiments described above, but may also be that of Embodiment 4 described below. Below, an example of the configuration of Embodiment 4 will be explained with reference to a diagram.

[0089] <Outline configuration of authentication system 1b> The authentication system 1b shown in Figure 9 includes a facility-side unit 2b, a mobile terminal 4b, and a mobile terminal 6. The facility-side unit 2b is used in facility Fc. Facility Fc may be, for example, the house of a legitimate user AU. Details of the facility-side unit 2b will be described later. The mobile terminal 4b is a communication terminal carried by the legitimate user AU. The mobile terminal 4b is the same as the mobile terminal 4 in Embodiment 1, except that it does not store and transmit Adv reception time.

[0090] <Outline configuration of facility-side unit 2b> Next, we will explain the general configuration of the facility-side unit 2b using Figure 10. As shown in Figure 10, the facility-side unit 2b includes an imaging-side control unit 20b, a communication-side control unit 21b, an HCU (Human Machine Interface Control Unit) 26, a user input device 27, an indoor camera 28b, an outdoor camera 29b, a facility-side control unit 30b, and a drive unit 31b. For example, the imaging-side control unit 20b, the communication-side control unit 21b, the HCU 26b, the facility-side control unit 30b, and the drive unit 31b may be configured to be connected to a LAN. The indoor camera 28b and the outdoor camera 29b may also be configured to be connected to a LAN.

[0091] The HCU26 performs various processes related to the interaction between the facility Fc system and the user. The HCU26 is the same as the HCU26 in Embodiment 1, except that it is used in facility Fc instead of vehicle Ve.

[0092] The user input device 27 receives input from the user. The user here is a user of facility Fc. The user input device 27 is the same as the user input device 27 of Embodiment 1, except that it is used in facility Fc instead of vehicle Ve.

[0093] The indoor camera 28b images a predetermined area inside the facility Fc. There may be multiple indoor cameras 28b. The indoor camera 28b may be, for example, a color camera. The indoor camera 28b may also include, for example, a near-infrared light source and a near-infrared camera. As the indoor camera 28b, a camera attached to equipment used within the facility Fc may be used.

[0094] The outdoor camera 29b captures a predetermined area outside the facility Fc. The outdoor camera 29b only needs to capture the area around facility Fc, including the area near the doors of facility Fc. These doors may be limited to, for example, the entrance door. There may be multiple outdoor cameras 29b. The outdoor camera 29b may be a color camera or a near-infrared camera.

[0095] The facility-side control unit 30b authorizes the use of equipment in facility Fc. Equipment subject to authorization for use will be referred to as "target equipment" below. The facility-side control unit 30b verifies authentication with the imaging-side control unit 20b and the communication-side control unit 21b. If authentication is confirmed to be successful by either the imaging-side control unit 20b or the communication-side control unit 21b, the facility-side control unit 30b authorizes the use of the target equipment. Examples of target equipment include door lock motors. Authorizing the use of a door lock motor is equivalent to authorizing the unlocking of a door. When the facility-side control unit 30b detects a predetermined trigger, it verifies authentication with the imaging-side control unit 20b and the communication-side control unit 21b.

[0096] The facility-side control unit 30b can, for example, perform authentication verification to authorize unlocking when it detects operation of the lock / unlock switch. The lock / unlock switch is a switch used to request the locking or unlocking of the facility Fc door. The facility-side control unit 30b may also use the detection of a person being located within a predetermined distance from the facility Fc door, for example using an infrared sensor, as a trigger for authentication verification.

[0097] The drive unit 31b drives the target equipment authorized for use by the facility-side control unit 30b. If unlocking is permitted, the drive unit 31b will unlock the door lock. Unlocking the door lock can be done by outputting an unlock signal to the door lock motor.

[0098] The imaging control unit 20b is the same as the imaging control unit 20 of Embodiment 1, except that some processing differs. The imaging control unit 20b authenticates the user based on information obtained from the indoor camera 28b or the outdoor camera 29b. Details of the imaging control unit 20b will be described later.

[0099] The communication-side control unit 21b is the same as the communication-side control unit 21 of Embodiment 1, except that some processing differs. The communication-side control unit 21b performs user authentication based on information obtained from the mobile terminal 4b or mobile terminal 6. Details of the communication-side control unit 21b will be described later.

[0100] <Outline configuration of the imaging control unit 20b> Next, the schematic configuration of the imaging-side control unit 20b will be explained using Figure 11. As shown in Figure 11, the imaging-side control unit 20b includes an image information acquisition unit 201, a registration unit 202, an authentication unit 203, a companion identification unit 204, a companion information identification unit 205, an authorization granting unit 207b, a setting unit 208, and a restriction unit 209 as functional blocks. The imaging-side control unit 20b differs from the imaging-side control unit 20 in that it does not have a seating area identification unit 206. The imaging-side control unit 20b also differs from the imaging-side control unit 20 in that it has an authorization granting unit 207b instead of an authorization granting unit 207. Aside from these points, the imaging-side control unit 20b is the same as the imaging-side control unit 20. This imaging-side control unit 20b also corresponds to an authentication device. Furthermore, the execution of processing for each functional block of the imaging-side control unit 20b by a computer corresponds to the execution of an authentication method.

[0101] The image information acquisition unit 201 acquires images from the indoor camera 28b and the outdoor camera 29b. Except for this, the image information acquisition unit 201 is the same as the image information acquisition unit 201 of Embodiment 1. The indoor camera 28b and the outdoor camera 29b also correspond to imaging devices.

[0102] The authentication unit 203 sends the authentication result to the facility-side control unit 30b. The facility-side control unit 30b verifies the authentication based on the authentication result sent from the authentication unit 203, in the same manner as the vehicle control unit 30. If the facility-side control unit 30b confirms that the authentication is successful, it permits the use of the target equipment.

[0103] The companion identification unit 204 identifies whether or not there is a companion CP of the legitimate user AU when the authentication unit 203 has successfully authenticated the legitimate user AU. This processing in the companion identification unit 204 corresponds to the companion identification process. The companion identification unit 204 only needs to identify the presence of a companion if it recognizes a face image other than that of the legitimate user AU from the image acquired by the image information acquisition unit 201.

[0104] The authorization granting unit 207b is the same as the authorization granting unit 207, except that it does not perform processing using the seating area specified by the seating area identification unit 206. The processing in this authorization granting unit 207b also corresponds to the authorization granting process.

[0105] <Outline configuration of the communication-side control unit 21b> Next, the general configuration of the communication-side control unit 21b will be explained using Figure 12. As shown in Figure 12, the communication-side control unit 21b includes a short-range communication unit 211, a registration unit 212, an authentication unit 213, a companion identification unit 214, a companion information identification unit 215, an authorization granting unit 217b, a setting unit 218, and a restriction unit 219 as functional blocks. The communication-side control unit 21b differs from the communication-side control unit 21 in that it does not have a driving-related information acquisition unit 216. The communication-side control unit 21b also differs from the communication-side control unit 21 in that it has an authorization granting unit 207b instead of an authorization granting unit 207. Aside from these points, the communication-side control unit 21b is the same as the communication-side control unit 21. This communication-side control unit 21b also corresponds to an authentication device. Furthermore, the execution of processing for each functional block of the communication-side control unit 21b by a computer corresponds to the execution of an authentication method.

[0106] The short-range communication unit 211 performs unicast communication with the paired mobile terminals 4b and 6. The short-range communication unit 211 acquires the advertisement signals transmitted sequentially from the mobile terminals 4b and 6. Except for these points, the short-range communication unit 211 is the same as the short-range communication unit 211 of Embodiment 1.

[0107] The authentication unit 213 sends the authentication result to the facility-side control unit 30b. The companion identification unit 214 identifies whether or not there are companions CP of the regular user AU when the authentication unit 213 has successfully authenticated the regular user AU. The companion identification unit 214 only needs to identify the presence of a companion when the short-range communication unit 211 receives an advertisement signal containing a terminal ID other than that of the regular user AU.

[0108] The authorization granting unit 217b is the same as the authorization granting unit 217, except that it does not perform processing using the driving-related information identified by the driving-related information acquisition unit 216. The processing in this authorization granting unit 217b also corresponds to the authorization granting process.

[0109] Even with the configuration of Embodiment 4, it becomes possible to grant access to the target device to a companion CP without the regular user AU having to perform any operations to grant access. Furthermore, access to the target device is granted to the companion CP using information about the companion CP identified from the device peripheral information obtained around the target device. Therefore, it becomes possible to suppress the granting of access to users who should not be granted access. As a result, when granting access to the device to unregistered users who are not registered as regular users, it becomes possible to enhance security in authentication while also improving convenience.

[0110] (Embodiment 5) In the embodiments described above, an example was shown in which BLE communication was used for wireless communication between the short-range communication unit 211 and the mobile terminals 4, 4b and 6, but this is not necessarily the only option. For example, wireless communication compliant with the Bluetooth standard may be used. In addition, other types of wireless communication may be used.

[0111] This disclosure is not limited to the embodiments described above, and various modifications are possible within the scope of the claims. Embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of this disclosure. Furthermore, the control unit and method described in this disclosure may be implemented by a dedicated computer comprising a processor programmed to execute one or more functions embodied by a computer program. Alternatively, the apparatus and method described in this disclosure may be implemented by a dedicated hardware logic circuit. Alternatively, the apparatus and method described in this disclosure may be implemented by one or more dedicated computers comprising a combination of a processor that executes a computer program and one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by the computer on a computer-readable non-transitional tangible recording medium.

[0112] (Disclosed technical ideas) This specification discloses several technical concepts, as set forth in the following paragraphs. Some paragraphs may be written in a multiple dependent form, where subsequent paragraphs alternately refer to preceding paragraphs. Furthermore, some paragraphs may be written in a multiple dependent form, referring to other multiple dependent forms. These paragraphs written in multiple dependent forms define several technical concepts.

[0113] Technical thought 1 The authentication unit (203, 203a, 213) authenticates authorized users who have been granted the authority to use the specified equipment, Information acquisition unit (201, 211) acquires device peripheral information, which is information obtained in the vicinity of the aforementioned device, When the authentication unit successfully authenticates the legitimate user, the accompanying person identification unit (204, 214) identifies whether or not the legitimate user has any accompanying persons, When the companion identification unit identifies that there is a companion, the companion information identification unit (205, 215) identifies the companion's information from the peripheral device information acquired by the information acquisition unit, The system includes an authorization granting unit (207, 207a, 207b, 217, 217b) that uses the information of the companion identified by the companion information identification unit to grant the companion the authority to use the equipment, The authentication unit is an authentication device that, for the accompanying person who has been granted authority by the authorization granting unit, will complete the authentication process at subsequent authentication sessions.

[0114] Technical thought 2 The authentication device described in Technical Concept 1, The information acquisition unit acquires, as information about the surroundings of the equipment, at least images captured by imaging devices (28, 28b, 29, 29b) that capture images of the surroundings of the equipment, The companion information identification unit is an authentication device that identifies facial images other than those of the regular user, recognized from the image, as information of the companion.

[0115] Technical thought 3 The authentication device described in Technical Concept 2, The aforementioned information acquisition unit sequentially acquires information about the surroundings of the device. The aforementioned companion information identification unit sequentially identifies the information of the companion from the equipment peripheral information acquired by the information acquisition unit. The authorization granting unit is an authentication device that grants the authorization to use the equipment to a companion if the companion information identification unit continuously identifies the information of the same companion for a specified period of time or longer.

[0116] Technical thought 4 Authentication device as described in Technical Idea 2 or 3, The aforementioned equipment is equipment installed in a vehicle, The authorization granting unit (207) grants the accompanying person the authority to use the equipment, but limited to the seating area in the vehicle. When the companion identification unit identifies that there is a companion, the unit includes a seating area identification unit (206) that identifies the seating area of ​​the companion. The authentication unit (203) is an authentication device that, with respect to the companion who has been granted authority by the authority granting unit to limit the seating area, fails to complete authentication if, at the time of authentication, the seating area of ​​the companion identified by the seating area identification unit is not the seating area to which authority has been granted.

[0117] Technical thought 5 Authentication device as described in Technical Idea 2 or 3, The aforementioned equipment is equipment installed in a vehicle, There are multiple types of the aforementioned devices for which the right to use is granted. The authorization granting unit (207a) changes the type of equipment to which the accompanying person is authorized to use, depending on the seating area in the vehicle. When the companion identification unit identifies that there is a companion, the unit includes a seating area identification unit (206) that identifies the seating area of ​​the companion. The authentication unit (203a) is an authentication device that, at the time of authentication, establishes authentication for the use of the type of equipment corresponding to the seating area of ​​the companion, as identified by the seating area identification unit, for the companion who has been authorized by the authorization granting unit.

[0118] technical thought 6 A certification device described in any one of the technical ideas 1 to 5, The information acquisition unit (211) acquires, as peripheral information of the device, at least an advertisement signal transmitted sequentially from a mobile terminal carried by a person to notify the surroundings of the presence of the mobile terminal, The companion information identification unit (215) is an authentication device that identifies the advertised signals other than those of the regular user, which can be obtained by the information acquisition unit, as information of the companion.

[0119] Technical thought 7 The authentication device described in Technical Idea 6, The authorization granting unit (217, 217b) is an authentication device that grants the authority to use the equipment to a companion, based on the companion information identification unit having identified the same companion's advertisement signal as the companion's advertisement signal, which is the advertisement signal of a companion other than the regular user, for a specified period of time or longer.

[0120] Technical thought 8 The authentication device described in Technical Idea 7, The aforementioned equipment is equipment installed in a vehicle, The vehicle is equipped with a driving-related information acquisition unit (216) that acquires driving-related information, which is information about the driving status of the vehicle. The authorization granting unit (217) is an authentication device that, using the driving-related information acquired by the driving-related information acquisition unit, grants the authority to use the equipment to the companion based on the companion information identification unit continuously identifying the advertisement signal of the same companion for a specified period of time or longer while the vehicle is driving at a predetermined speed or higher.

[0121] Technical thought 9 The authentication device described in Technical Idea 8, The authorization granting unit is an authentication device that, using the driving-related information acquired by the driving-related information acquisition unit, grants the authorization to use the equipment to the companion if the companion information identification unit continuously identifies the advertisement signal of the same companion for a specified period of time or longer while the vehicle is driving at a predetermined speed or higher and has made a specified number of right and left turns or more.

[0122] Technical thought 10 Authentication device as described in Technical Idea 3 or 7, An authentication device comprising a setting unit (208, 218) that sets the predetermined time in accordance with the input received by an input receiving device (27, 27b) that receives input from a user.

[0123] Technical thought 11 An authentication device described in any one of the technical ideas 1 to 10, An authentication device comprising a restriction section (209, 219) that sets a limit on the period during which the accompanying person is granted the authority to use the device.

[0124] Technical thought 12 Authentication device as described in Technical Idea 11, The restriction unit is an authentication device that, in response to input received by an input receiving device (27, 27b) that receives input from a user, revokes the authority to use the equipment granted to the companion.

[0125] Technical thought 13 Authentication device as described in Technical Idea 11, The restriction unit is an authentication device that revokes the authority to use the equipment granted to the companion when a set time has elapsed since the authority was granted.

[0126] Technical thought 14 Authentication device as described in Technical Idea 13, The restriction unit is an authentication device that, each time the authentication unit authenticates the legitimate user and the companion information identification unit identifies the information of the same companion, extends the period during which the companion is granted the right to use the equipment.

[0127] Technical thought 15 Authentication device as described in Technical Idea 13 or 14, As peripheral information for the aforementioned device, at least an advertisement signal is acquired that is sequentially transmitted from a mobile terminal carried by a person, to notify those around the mobile terminal of its presence. The companion information identification unit (215) identifies the advertised signals other than those of the regular user that can be acquired by the information acquisition unit (211) as information of the companion, The restriction unit (219) is an authentication device that temporarily extends the period during which the companion is granted permission to use the device when pairing, which is the execution of a key exchange protocol triggered by input from the companion who is the user of the mobile terminal, is performed between the mobile terminal and the device.

[0128] Technical thought 16 An authentication device described in any one of the technical ideas 13 to 15, As peripheral information for the aforementioned device, at least an advertisement signal is acquired that is sequentially transmitted from a mobile terminal carried by a person, to notify those around the mobile terminal of its presence. The companion information identification unit (215) identifies the advertised signals other than those of the regular user that can be acquired by the information acquisition unit (211) as information of the companion, The restriction unit (219) is an authentication device that, when the information acquisition unit obtains information from the authorized user's mobile terminal indicating that the authorized user has received the same companion's advertisement signal for a predetermined period of time or longer, temporarily extends the period during which the companion is granted permission to use the device.

[0129] Technical thought 17 Run by at least one processor, An authentication process that authenticates legitimate users who have been granted the authority to use the specified equipment, An information acquisition step to acquire device peripheral information, which is information obtained around the aforementioned device, If the authentication of the authorized user is successful in the authentication step, the companion identification step is to identify whether or not the authorized user has any companions, If the presence of a companion is identified in the companion identification step, the companion information identification step identifies the companion's information from the equipment peripheral information acquired in the information acquisition step, The process includes a steps to grant authority to the companion, using the companion information identified in the companion information identification step, thereby granting the companion the authority to use the equipment. The authentication method described above allows authentication to be completed for the accompanying person who was granted authority in the authorization granting step, at subsequent authentication sessions. [Explanation of symbols]

[0130] 1,1b Authentication system, 2 Vehicle-side unit, 2b Facility-side unit, 4,4b Mobile terminal, 6 Mobile terminal, 20,20a,20b Imaging-side control unit (authentication device), 21,21b Communication-side control unit (authentication device), 27,27b User input device (input reception device), 28,28b Indoor camera (imaging device), 29,29b Outdoor camera (imaging device), 201 Image information acquisition unit (information acquisition unit), 203,203a Authentication unit, 204 Companion identification unit, 205 Companion information identification unit, 207,207a,207b Authorization granting unit, 208 Setting unit, 209 Restriction unit, 211 Short-range communication unit (information acquisition unit), 213 Authentication unit, 214 Companion identification unit, 215 Companion information identification unit, 217,217b Authorization granting unit, 218 Setting section, 219 Restriction section

Claims

1. Authentication units (203, 203a, 213) that authenticate legitimate users who have been granted the authority to use the specified equipment, Information acquisition unit (201, 211) that acquires device peripheral information, which is information obtained in the vicinity of the aforementioned device, When the authentication unit has successfully authenticated the legitimate user, the accompanying person identification unit (204, 214) identifies whether or not the legitimate user has any accompanying persons, When the companion identification unit identifies that there is a companion, the companion information identification unit (205, 215) identifies the companion's information from the peripheral device information acquired by the information acquisition unit, The system includes an authorization granting unit (207, 207a, 207b, 217, 217b) that uses the information of the companion identified by the companion information identification unit to grant the companion the authority to use the equipment, The authentication unit will, for the accompanying person who has been granted authority by the authorization granting unit, establish authentication at subsequent authentication times. The system includes a limiting section (209, 219) that sets a limit on the period during which the accompanying person is granted the right to use the equipment, The aforementioned restriction unit causes the authority to use the equipment granted to the companion to be revoked when a set time has elapsed since the authority was granted. The restriction unit is an authentication device that, each time the authentication unit authenticates the legitimate user and the companion information identification unit identifies the same companion, extends the period during which the companion is granted the right to use the equipment.

2. Authentication units (203, 203a, 213) that authenticate legitimate users who have been granted the authority to use the specified equipment, Information acquisition unit (201, 211) that acquires device peripheral information, which is information obtained in the vicinity of the aforementioned device, When the authentication unit has successfully authenticated the legitimate user, the accompanying person identification unit (204, 214) identifies whether or not the legitimate user has any accompanying persons, When the companion identification unit identifies that there is a companion, the companion information identification unit (205, 215) identifies the companion's information from the peripheral device information acquired by the information acquisition unit, The system includes an authorization granting unit (207, 207a, 207b, 217, 217b) that uses the information of the companion identified by the companion information identification unit to grant the companion the authority to use the equipment, The authentication unit will, for the accompanying person who has been granted authority by the authorization granting unit, establish authentication at subsequent authentication times. The system includes a limiting section (209, 219) that sets a limit on the period during which the accompanying person is granted the right to use the equipment, The aforementioned restriction unit causes the authority to use the equipment granted to the companion to be revoked when a set time has elapsed since the authority was granted. As peripheral information for the aforementioned device, at least an advertisement signal is acquired that is sequentially transmitted from a mobile terminal carried by a person, to notify those around the mobile terminal of its presence. The companion information identification unit (215) identifies the advertised signals other than those of the regular user that can be acquired by the information acquisition unit (211) as information of the companion, The restriction unit (219) is an authentication device that temporarily extends the period during which the companion is granted permission to use the device when pairing, which is the execution of a key exchange protocol triggered by input from the companion who is the user of the mobile terminal, is performed between the mobile terminal and the device.

3. Authentication units (203, 203a, 213) that authenticate legitimate users who have been granted the authority to use the specified equipment, Information acquisition unit (201, 211) that acquires device peripheral information, which is information obtained in the vicinity of the aforementioned device, When the authentication unit has successfully authenticated the legitimate user, the accompanying person identification unit (204, 214) identifies whether or not the legitimate user has any accompanying persons, When the companion identification unit identifies that there is a companion, the companion information identification unit (205, 215) identifies the companion's information from the peripheral device information acquired by the information acquisition unit, The system includes an authorization granting unit (207, 207a, 207b, 217, 217b) that uses the information of the companion identified by the companion information identification unit to grant the companion the authority to use the equipment, The authentication unit will, for the accompanying person who has been granted authority by the authorization granting unit, establish authentication at subsequent authentication times. The system includes a limiting section (209, 219) that sets a limit on the period during which the accompanying person is granted the right to use the equipment, The aforementioned restriction unit causes the authority to use the equipment granted to the companion to be revoked when a set time has elapsed since the authority was granted. As peripheral information for the aforementioned device, at least an advertisement signal is acquired that is sequentially transmitted from a mobile terminal carried by a person, to notify those around the mobile terminal of its presence. The companion information identification unit (215) identifies the advertised signals other than those of the regular user that can be acquired by the information acquisition unit (211) as information of the companion, The restriction unit (219) is an authentication device that, when the information acquisition unit obtains information from the authorized user's mobile terminal indicating that the authorized user has received the same companion's advertisement signal for a predetermined period of time or longer, temporarily extends the period during which the companion is granted permission to use the device.

4. An authentication device according to any one of claims 1 to 3, The information acquisition unit acquires, as information about the surroundings of the device, at least images captured by imaging devices (28, 28b, 29, 29b) that capture images of the surroundings of the device, The companion information identification unit is an authentication device that identifies facial images other than those of the regular user, recognized from the image, as information of the companion.

5. The authentication device according to claim 4, The aforementioned information acquisition unit sequentially acquires information about the surroundings of the device. The aforementioned companion information identification unit sequentially identifies the information of the companion from the equipment peripheral information acquired by the information acquisition unit. The authorization granting unit is an authentication device that grants the authorization to use the equipment to a companion if the companion information identification unit continuously identifies the information of the same companion for a specified period of time or longer.

6. The authentication device according to claim 4, The aforementioned equipment is equipment installed in a vehicle, The authorization granting unit (207) grants the accompanying person the authority to use the equipment, but limited to the seating area in the vehicle. When the companion identification unit identifies that there is a companion, the unit includes a seating area identification unit (206) that identifies the seating area of ​​the companion. The authentication unit (203) is an authentication device that, with respect to the companion who has been granted authority by the authority granting unit to limit the seating area, fails to complete authentication if, at the time of authentication, the seating area of ​​the companion identified by the seating area identification unit is not the seating area to which authority has been granted.

7. The authentication device according to claim 4, The aforementioned equipment is equipment installed in a vehicle, There are multiple types of the aforementioned devices for which the right to use is granted. The authorization granting unit (207a) changes the type of equipment to which the accompanying person is authorized to use, depending on the seating area in the vehicle. When the companion identification unit identifies that there is a companion, the unit includes a seating area identification unit (206) that identifies the seating area of ​​the companion. The authentication unit (203a) is an authentication device that, at the time of authentication, establishes authentication for the use of the type of equipment corresponding to the seating area of ​​the companion, as identified by the seating area identification unit, for the companion who has been authorized by the authorization granting unit.

8. An authentication device according to any one of claims 1 to 3, The information acquisition unit (211) acquires, as peripheral information of the device, at least an advertisement signal transmitted sequentially from a mobile terminal carried by a person to notify the surroundings of the presence of the mobile terminal, The companion information identification unit (215) is an authentication device that identifies the advertisement signals other than those of the regular user, which can be obtained by the information acquisition unit, as information of the companion.

9. The authentication device according to claim 8, The authorization granting unit (217, 217b) is an authentication device that grants the authority to use the equipment to a companion, based on the companion information identification unit having identified the same companion's advertisement signal as the companion's advertisement signal, which is the advertisement signal of a companion other than the regular user, for a specified period of time or longer.

10. The authentication device according to claim 9, The aforementioned equipment is equipment installed in a vehicle, The vehicle is equipped with a driving-related information acquisition unit (216) that acquires driving-related information, which is information about the driving status of the vehicle. The authorization granting unit (217) is an authentication device that, using the driving-related information acquired by the driving-related information acquisition unit, grants the authority to use the equipment to the companion based on the companion information identification unit continuously identifying the advertisement signal of the same companion for a specified period of time or longer while the vehicle is driving at a predetermined speed or higher.

11. The authentication device according to claim 10, The authorization granting unit is an authentication device that, using the driving-related information acquired by the driving-related information acquisition unit, grants the authorization to use the equipment to the companion if the companion information identification unit continuously identifies the advertisement signal of the same companion for a specified period of time or longer while the vehicle is driving at a predetermined speed or higher and has made a specified number of right and left turns or more.

12. The authentication device according to claim 5, An authentication device comprising a setting unit (208, 218) that sets the predetermined time in accordance with the input received by an input receiving device (27, 27b) that receives input from a user.

13. The authentication device according to claim 9, An authentication device comprising a setting unit (208, 218) that sets the predetermined time in accordance with the input received by an input receiving device (27, 27b) that receives input from a user.

14. An authentication device according to claim 2 or 3, The restriction unit is an authentication device that, each time the authentication unit authenticates the legitimate user and the companion information identification unit identifies the same companion, extends the period during which the companion is granted the right to use the equipment.

15. The authentication device according to claim 3, As peripheral information for the aforementioned device, at least an advertisement signal is acquired that is sequentially transmitted from a mobile terminal carried by a person, to notify those around the mobile terminal of its presence. The companion information identification unit (215) identifies the advertised signals other than those of the regular user that can be acquired by the information acquisition unit (211) as information of the companion, The restriction unit (219) is an authentication device that temporarily extends the period during which the companion is granted permission to use the device when pairing, which is the execution of a key exchange protocol triggered by input from the companion who is the user of the mobile terminal, is performed between the mobile terminal and the device.

16. Run by at least one processor, An authentication process that authenticates legitimate users who have been granted the authority to use the specified equipment, An information acquisition step to acquire device peripheral information, which is information obtained around the aforementioned device, If the authentication of the authorized user is successful in the authentication step, the companion identification step is to identify whether or not the authorized user has any companions, If the presence of a companion is identified in the companion identification step, the companion information identification step identifies the companion's information from the equipment peripheral information acquired in the information acquisition step, The process includes a steps to grant authority to the companion, using the companion information identified in the companion information identification step, thereby granting the companion the authority to use the equipment. In the aforementioned authentication process, the accompanying person who was granted authority in the aforementioned authorization granting process will be authorized to complete authentication at subsequent authentication sessions. This includes a restriction step that sets limits on the period during which the accompanying person is authorized to use the equipment, The aforementioned restriction process involves revoking the authority to use the equipment granted to the companion after a set time has elapsed since the authority was granted. The restriction step is an authentication method in which, each time the authentication of the legitimate user is established in the authentication step and the information of the same accompanying person is identified in the accompanying person information identification step, the period for which the accompanying person is granted the right to use the equipment is extended.

17. Run by at least one processor, An authentication process that authenticates legitimate users who have been granted the authority to use the specified equipment, An information acquisition step to acquire device peripheral information, which is information obtained around the aforementioned device, If the authentication of the authorized user is successful in the authentication step, the companion identification step is to identify whether or not the authorized user has any companions, If the presence of a companion is identified in the companion identification step, the companion information identification step identifies the companion's information from the equipment peripheral information acquired in the information acquisition step, The process includes a steps to grant authority to the companion, using the companion information identified in the companion information identification step, thereby granting the companion the authority to use the equipment. In the aforementioned authentication process, the accompanying person who was granted authority in the aforementioned authorization granting process will be authorized to complete authentication at subsequent authentication sessions. This includes a restriction step that sets limits on the period during which the accompanying person is authorized to use the equipment, The aforementioned restriction process involves revoking the authority to use the equipment granted to the companion after a set time has elapsed since the authority was granted. As peripheral information for the aforementioned device, at least an advertisement signal is acquired that is sequentially transmitted from a mobile terminal carried by a person, to notify those around the mobile terminal of its presence. In the aforementioned companion information identification step, the advertised signals other than those of the regular user that can be obtained in the information acquisition step are identified as information of the companion. The aforementioned restriction step is an authentication method that temporarily extends the period during which the accompanying person is granted permission to use the device when pairing, which is the execution of a key exchange protocol triggered by input from the accompanying person who is the user of the mobile terminal, occurs between the mobile terminal and the device.

18. Run by at least one processor, An authentication process that authenticates legitimate users who have been granted the authority to use the specified equipment, An information acquisition step to acquire device peripheral information, which is information obtained around the aforementioned device, If the authentication of the authorized user is successful in the authentication step, the companion identification step is to identify whether or not the authorized user has any companions, If the presence of a companion is identified in the companion identification step, the companion information identification step identifies the companion's information from the equipment peripheral information acquired in the information acquisition step, The process includes a steps to grant authority to the companion, using the companion information identified in the companion information identification step, thereby granting the companion the authority to use the equipment. In the aforementioned authentication process, the accompanying person who was granted authority in the aforementioned authorization granting process will be authorized to complete authentication at subsequent authentication sessions. This includes a restriction step that sets limits on the period during which the accompanying person is authorized to use the equipment, The aforementioned restriction process involves revoking the authority to use the equipment granted to the companion after a set time has elapsed since the authority was granted. As peripheral information for the aforementioned device, at least an advertisement signal is acquired that is sequentially transmitted from a mobile terminal carried by a person, to notify those around the mobile terminal of its presence. In the aforementioned companion information identification step, the advertised signals other than those of the regular user that can be obtained in the information acquisition step are identified as information of the companion. The restriction step involves an authentication method that, when the information acquisition step obtains information from the authorized user's mobile terminal indicating that the authorized user has continuously received the advertisement signal of the same companion for a predetermined period of time or longer, the period for which the companion is granted permission to use the device is temporarily extended.