System, management server, and management method
The system simplifies the tracking of usage relationships between moving objects and users by managing correspondence relationships through state switching, addressing inefficiencies in existing systems and reducing processing costs.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2023-09-22
- Publication Date
- 2026-06-02
AI Technical Summary
Existing systems struggle to efficiently track the usage relationship between moving objects and users, particularly in scenarios involving rental cars or other moving entities, due to mismatches between contractual dates and actual usage, leading to increased processing costs and inefficiencies.
A system comprising a management server, first terminals, and second terminals that manage correspondence relationships between targets, allowing for the activation and deactivation of multiple linking settings based on status information to simplify tracking and reduce unnecessary processing.
Enables efficient tracking of usage relationships by managing linking settings through state switching, reducing redundant processing and costs associated with repeated link setups and teardowns.
Smart Images

Figure 0007868588000001 
Figure 0007868588000002 
Figure 0007868588000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a system, a management server, and a management method.
Background Art
[0002] In Patent Document 1, a fee collection system for collecting fees for services from vehicle users using a medium such as a card has been proposed. Specifically, the fee collection system proposed in Patent Document 1 is based on the ID of an ETC (Electronic Toll Collection System) card, the relationship between the rental car company, the rental date and time of the rental car, and the rental car user (billing information, registration information, settlement information, and usage information), and is configured to allocate the toll for using the highway by the target rental car to the target user.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] One object of the present disclosure is to provide a technique for easily tracking the usage relationship between a first target and a second target.
Means for Solving the Problems
[0005] A system according to a first aspect of this disclosure comprises a management server, a plurality of first terminals corresponding to each first object, and a plurality of second terminals corresponding to each second object. The plurality of first terminals and the plurality of second terminals are configured such that, in response to the occurrence of a usage relationship between the first object and the second object, at least one of the first terminals corresponding to the first object and the second terminals corresponding to the second object sends a linking request to the management server. The management server is configured to accept the setting of a correspondence relationship between the first object and the second object upon receiving the linking request, and, in response to the acceptance of the setting of the correspondence relationship due to two or more linking requests for the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, the management server is configured to activate one of the two or more correspondence relationships and deactivate the other correspondence relationships, depending on the status information obtained from at least one of the first object and the two or more second objects for which the two or more correspondence relationships are established.
[0006] The management server according to a second aspect of this disclosure includes a control unit configured to receive a linking request from at least one of the first terminal of the first target and the second terminal of the second target in response to the occurrence of a usage relationship between the first target and the second target, accept the setting of a correspondence relationship between the first target and the second target upon receipt of the linking request, and, in response to the acceptance of the setting of the correspondence relationship due to two or more linking requests relating to the same first target, if two or more correspondence relationships are established for the same first target with two or more different second targets, activate one of the two or more correspondence relationships and deactivate the other correspondence relationships, according to status information obtained from at least one of the first target and the two or more second targets for which the two or more correspondence relationships are established.
[0007] The management method relating to the third aspect of this disclosure involves a management server that controls the interoperability between the first and second targets. This information processing method involves receiving a linking request from at least one of the first terminal of the first target and the second terminal of the second target in response to the occurrence of a relationship; accepting the setting of a correspondence relationship between the first target and the second target upon receiving the linking request; and, in response to accepting the setting of the correspondence relationship due to two or more linking requests relating to the same first target, establishing two or more correspondence relationships with two or more different second targets for the same first target, activating one of the two or more correspondence relationships and deactivating the other correspondence relationships, based on status information obtained from at least one of the first target and the two or more second targets in which the two or more correspondence relationships are established. [Effects of the Invention]
[0008] This disclosure provides a technology for easily tracking the usage relationship between the first and second objects. [Brief explanation of the drawing]
[0009] [Figure 1] Figure 1 schematically illustrates an example of a scenario in which this disclosure applies. [Figure 2] Figure 2 schematically illustrates an example of a scenario to which this disclosure applies. [Figure 3A] Figure 3A schematically shows an example of the linked information according to this embodiment. [Figure 3B] Figure 3B schematically shows an example of user information according to this embodiment. [Figure 3C] Figure 3C schematically shows an example of mobile information according to this embodiment. [Figure 4A] Figure 4A schematically shows an example of the selection process for the linked settings to be activated according to this embodiment. [Figure 4B] Figure 4B schematically shows an example of the selection process for the linked settings to be activated according to this embodiment. [Figure 4C] Figure 4C schematically shows an example of the selection process for the linked settings to be activated according to this embodiment. [Figure 5] FIG. 5 schematically shows an example of a scene where the active association setting according to the present embodiment is locked. [Figure 6] FIG. 6 schematically shows an example of a process of disassociation according to the present embodiment. [Figure 7] FIG. 7 schematically shows an example of a scene where the association setting according to the present embodiment is maintained in an active or non-active state. [Figure 8] FIG. 8 schematically shows an example of an execution scene of disassociation according to the present embodiment. [Figure 9] FIG. 9 schematically shows an example of a usage scene of association information according to the present embodiment. [Figure 10A] FIG. 10A schematically shows an example of the hardware configuration of the management server according to the present embodiment. [Figure 10B] FIG. 10B schematically shows an example of the hardware configuration of the first terminal according to the present embodiment. [Figure 10C] FIG. 10C schematically shows an example of the hardware configuration of the second terminal according to the present embodiment. [Figure 11] FIG. 11 schematically shows an example of the software configuration of each device according to the present embodiment. [Figure 12] FIG. 12 shows an example of a processing procedure of association setting according to the present embodiment. [Figure 13] FIG. 13 shows an example of a processing procedure of disassociation according to the present embodiment. [Figure 14] FIG. 14 schematically shows an example of a processing process of association setting when the first authentication method is adopted. [Figure 15] FIG. 15 schematically shows an example of a processing process of association setting when the second authentication method is adopted. [Figure 16] FIG. 16 schematically shows an example of a processing process of association setting when the third - 1 authentication method is adopted. [Figure 17A] FIG. 17A schematically shows an example of a processing process of association setting when the third - 2 authentication method is adopted. [Figure 17B]FIG. 17B schematically shows another example of the processing procedure of the association setting when adopting the third - 2 authentication method. [Figure 18A] FIG. 18A schematically shows an example of the processing procedure of the association setting when adopting the fourth authentication method. [Figure 18B] FIG. 18B schematically shows another example of the processing procedure of the association setting when adopting the fourth authentication method.
MODE FOR CARRYING OUT THE INVENTION
[0010] According to the system proposed in Patent Document 1, a user can pay highway tolls by ETC even without holding their own ETC card. However, the inventors of the present invention have found that the conventional system has the following problems.
[0011] That is, with the diversification of MaaS (Mobility as a Service), it is considered that a demand for easily tracking the use of moving objects by users has arisen from the perspective of convenience such as improving settlement efficiency. On the other hand, in the conventional system, according to the rental car contract or reservation, the correspondence relationship between the use date and time and the user can be held as usage information. However, since this use date and time depends on the contract or reservation, the usage information does not always match the actual use of the rental car by the user. In addition, for vehicles used without a contract or reservation (for example, private cars), the generation of usage information is not assumed in the first place. Therefore, according to the conventional system, it is difficult to easily track the use of moving objects by users. Note that this problem does not occur only in the scenario of using a vehicle. Similar problems can occur in scenarios of using moving objects other than vehicles (for example, aircraft, ships, etc.) and in scenarios of using multiple types of moving objects. Furthermore, similar problems can occur in any usage scenario other than moving objects.
[0012] In contrast, the system according to the first aspect of this disclosure comprises a management server, a plurality of first terminals corresponding to each first target, and a plurality of second terminals corresponding to each second target. The plurality of first terminals and the plurality of second terminals are configured such that, in response to the occurrence of a usage relationship between the first target and the second target, at least one of the first terminals corresponding to the first target and the second terminals corresponding to the second target sends a linking request to the management server. The management server is configured to accept the setting of a correspondence relationship between the first target and the second target upon receiving a linking request, and in response to the acceptance of the setting of a correspondence relationship due to two or more linking requests for the same first target, if the setting of two or more correspondence relationships is established for the same first target with two or more different second targets, it is configured to activate the setting of one of the two or more correspondence relationships and deactivate the settings of the other correspondence relationships, according to the status information obtained from at least one of the first target and the two or more second targets for which the setting of two or more correspondence relationships is established.
[0013] In the first aspect of this disclosure, the usage relationship between the first and second objects can be tracked by setting a correspondence (linking setting) between the first and second objects and activating the linking setting. In addition, in the first aspect of this disclosure, multiple linking settings are permitted for one first object (one individual first object), and the usage relationship can be tracked by switching the state (active / inactive). If multiple linking settings are not permitted for one first object, the setting and unsetting of the link would have to be repeated each time a usage relationship occurs and ends, which could lead to increased effort. In particular, if the same usage relationship occurs and ends repeatedly, the setting and unsetting of the same content would be repeated, which could lead to an increase in unnecessary processing costs. In contrast, in the first aspect of this disclosure, in at least some situations, the occurrence and termination of a usage relationship can be handled by switching the state without having to repeatedly set and unset the link. This simplifies the management of the linking. Therefore, according to the first aspect of this disclosure, the usage relationship between the first and second objects can be easily tracked. be.
[0014] The forms of this disclosure are not limited to the examples described above. As another form of the system relating to the above embodiments, one aspect of this disclosure may be an information processing device, an information processing method, a program, or a machine-readable storage medium that stores such a program, which implements all or part of the above components. Here, a machine-readable storage medium is a medium that stores information such as a program by electrical, magnetic, optical, mechanical, or chemical action. The information processing device may be at least one of the management server, the first terminal, and the second terminal relating to the above embodiments. Furthermore, the system relating to the above embodiments may further include at least one of the first server involved in the authentication of the first target and the second server involved in the authentication of the second target.
[0015] For example, the management server according to the second aspect of this disclosure may include a control unit configured to receive a linking request from at least one of the first terminal of the first target and the second terminal of the second target in response to the occurrence of a usage relationship between the first target and the second target, accept the setting of a correspondence relationship between the first target and the second target upon receipt of the linking request, and, in response to the acceptance of the setting of a correspondence relationship due to two or more linking requests for the same first target, if two or more correspondence relationships are established for the same first target with two or more different second targets, then activate the setting of one of the two or more correspondence relationships and deactivate the settings of the other correspondence relationships, according to status information obtained from at least one of the first target and the two or more second targets for which two or more correspondence relationships are established.
[0016] Furthermore, for example, a management method relating to a third aspect of this disclosure may be an information processing method in which a management server, in response to the occurrence of a usage relationship between a first target and a second target, receives a linking request from at least one of the first terminal of the first target and the second terminal of the second target, accepts the setting of a correspondence relationship between the first target and the second target upon receiving the linking request, and, in response to the acceptance of the setting of a correspondence relationship due to two or more linking requests relating to the same first target, establishes the setting of two or more correspondence relationships with two or more different second targets for the same first target, activates the setting of one of the two or more correspondence relationships and deactivates the settings of the other correspondence relationships, in accordance with status information obtained from at least one of the first target and the two or more second targets for which the setting of two or more correspondence relationships has been established.
[0017] Hereinafter, embodiments relating to one aspect of this disclosure (hereinafter also referred to as "this embodiment") will be described based on the drawings. However, this embodiment described below is merely illustrative in all respects of this disclosure. Various improvements or modifications may be made without departing from the scope of this disclosure. In implementing this disclosure, specific configurations may be adopted as appropriate depending on the embodiment. Although the data appearing in this embodiment is described in natural language, more specifically, it is specified in computer-recognizable pseudo-language, commands, parameters, machine code, etc.
[0018] [1. Application Examples] Figure 1 schematically shows an example of a scenario in which this disclosure is applied. The system 100 according to this embodiment consists of a management server 1, a plurality of first terminals 4, and a plurality of second terminals 5. The management server 1 is one or more computers configured to record the correspondence (linking) between first target VAs and second target WAs. Each first terminal 4 corresponds to each first target VA, and each second terminal 5 corresponds to each second target WA.
[0019] In this embodiment, the plurality of first terminals 4 and the plurality of second terminals 5 are the first target VA and the second pair In response to the occurrence of a usage relationship between two target WAs, at least one of the first terminal 4 corresponding to the first target VA and the second terminal 5 corresponding to the second target WA is configured to send a linking request to the management server 1. For example, a one-to-one usage relationship occurs between the first target VA and the second target WA. That is, a usage relationship occurs between one first target VA and one second target WA. One first target VA is a single individual first target VA, and one second target WA is a single individual second target WA. The individual with whom the usage relationship has occurred may be referred to as the "corresponding individual" or "target individual". In response to the occurrence of this usage relationship, at least one of the first terminal 4 corresponding to the corresponding individual of the first target VA and the second terminal 5 corresponding to the corresponding individual of the second target WA sends a linking request to the management server 1 (step S10).
[0020] In response, the management server 1 receives a linking request from at least one of the first terminal 4 of the first target VA and the second terminal 5 of the second target WA. Upon receiving this linking request, the management server 1 accepts the setting of the correspondence relationship between the first target VA and the second target WA (step S20). In response to the accepted linking request, the management server 1 sets the correspondence relationship between the corresponding individual of the first target VA and the corresponding individual of the second target WA (step S30).
[0021] In this process, if no correspondence has been established for the relevant individual of the first target VA with any other second target WA (i.e., no two or more correspondences have been established for the same first target VA with two or more different second target WAs), then no conflict in the linking settings will occur. Therefore, the management server 1 may simply set an active correspondence between the relevant individual of the first target VA and the relevant individual of the second target WA. The fact that no correspondence has been established with any other second target WA means that, regardless of the state (active / inactive), no correspondence has been established with any other second target WA, and may also include the case where an inactive correspondence exists with any other second target WA, but no active correspondence exists.
[0022] On the other hand, if a correspondence relationship has already been established between the corresponding individual of the first target VA and other second target WAs, a conflict in the linking settings will occur. The fact that a correspondence relationship has already been established with other second target WAs means that, in response to receiving two or more linking requests for the same first target VA, two or more correspondence relationships have been established with two or more different second target WAs for the same first target VA. The fact that a correspondence relationship has already been established with other second target WAs may also be constituted by the existence of an active correspondence relationship with other second target WAs. In this case, the management server 1 obtains status information ST10 from at least one of the first target VA and the two or more second target WAs for which two or more correspondence relationships have been established. Then, according to the obtained status information ST10, the management server 1 activates the setting of one of the two or more correspondence relationships and deactivates the settings of the other correspondence relationships. In this way, the management server 1 mediates the conflict in the linking settings.
[0023] Furthermore, when a usage relationship is established between the first target VA and the second target WA, data exchange may be performed between the first terminal 4 corresponding to the relevant individual of the first target VA and the second terminal 5 corresponding to the relevant individual of the second target WA. A linking request may be executed in conjunction with this data exchange. The series of processes from the linking request to the linking setting may be executed in real time in response to the establishment of a usage relationship. Correspondence relationships (links) maintained in an active or inactive state may be released at any time. In response to the disappearance of a usage relationship, an active correspondence relationship may be changed to inactive or released.
[0024] Furthermore, as long as each individual for which a correspondence relationship has been established can be identified, the format of the information indicating the establishment of the correspondence relationship is not particularly limited and may be determined as appropriate depending on the embodiment. In one example, each first target VA may be given a first identifier I10, and the first identifier I10 is used to identify the first Each individual of the target VA may be identified. Similarly, each second target WA may be assigned a second identifier I20, and each individual of the second target WA may be identified by the second identifier I20. Accordingly, establishing a correspondence between the corresponding individual of the first target VA and the corresponding individual of the second target WA may be done by establishing a correspondence between the first identifier I10 assigned to the corresponding individual of the first target VA and the second identifier I20 assigned to the corresponding individual of the second target WA. That is, the establishment of the correspondence may be expressed using the first identifier I10 and the second identifier I20.
[0025] As described above, in this embodiment, the usage relationship between the corresponding individual of the first target VA and the corresponding individual of the second target WA can be tracked by setting a correspondence relationship (linking setting) and activating it between the first target VA and the second target WA. In addition, in this embodiment, linking settings are permitted for each of multiple individuals of the second target WA for a single individual of the first target VA. If a conflict occurs in the linking settings for the corresponding individual of the first target VA when multiple linking settings are established, the conflict is mediated by switching the state (active / inactive), thereby enabling proper tracking of the usage relationship for the corresponding individual of the first target VA. If multiple linking settings are not permitted for each individual of the first target VA, the setting and unsetting of the link will have to be repeated each time a usage relationship occurs and ends, which may lead to increased workload. In particular, if the same usage relationship occurs and ends repeatedly, the setting and unsetting of the link will have to be repeated with the same content, which may lead to an increase in unnecessary processing costs. In contrast, in this embodiment, in at least some situations where usage relationships are tracked, the creation and deletion of usage relationships can be handled by switching states without repeatedly setting and unlinking them. This simplifies the management of linkages. Therefore, according to this embodiment, the usage relationship between the first target VA and the second target WA can be easily tracked.
[0026] (subject) The first target VA and the second target WA are not particularly limited as long as a utilization relationship can be established, and may be appropriately selected depending on the embodiment. The first target VA and the second target WA may each be any thing, such as an object, a person, or another living being. Any thing may include a virtual thing. The establishment of a utilization relationship may be a real or virtual relationship between at least two things, such as one using the other, one possessing the other, one joining to the other, or one connecting to the other. The system 100 of this disclosure may be used in any situation in which a correspondence between two or more things is tracked.
[0027] In this embodiment, when a linking setting is established between a corresponding individual of the first target VA and multiple individuals of the second target WA, the management server 1 performs arbitration processing to select one linking setting from among the multiple linking settings as the active linking setting. In contrast, the handling of the linking settings between a corresponding individual of the second target WA and multiple individuals of the first target VA may be the same as or different from that of the first target VA. That is, when a linking setting is established between a corresponding individual of the second target WA and multiple individuals of the first target VA, the management server 1 may perform arbitration processing to select one linking setting from among the multiple linking settings as the active linking setting, similar to the first target VA. Alternatively, the management server 1 may not perform arbitration processing and may allow multiple active linking settings for the same second target WA. For example, consider a scenario where the first target VA is a user and the second target WA is a mobile entity. If a mobile object is available to multiple users (for example, if the mobile object is a vehicle that can carry multiple passengers), then it is possible for multiple users to have separate active association settings for the same mobile object. In such cases, multiple active association settings for the same second target WA may be permitted. Of the two targets that track usage relationships, one that does not allow multiple active association settings may be selected as the first target VA, and the other target that allows multiple active association settings may be selected as the second target WA.
[0028] (terminal) Each terminal (4, 5) relates to each object (VA, WA). The relationship between each terminal (4, 5) and each object (VA, WA) is not particularly limited and may be determined as appropriate depending on the embodiment. For example, each first terminal 4 may accompany the corresponding first object VA, and each second terminal 5 may accompany the corresponding second object WA. Accompanying may include being temporarily or permanently deployed inside or outside the object, being possessed by the object (person), and being possessed by a person involved with the object (object). Deploying may include loading. Loading may include being permanently placed in the object, as well as being placed in the object at least temporarily when the object is being used. Loading may include being possessed by the user of the object. In addition, either the first terminal 4 or the second terminal 5 may be the object itself. With respect to each terminal (4, 5), multiple terminals may be used as the same individual terminal, for example, such as when one user shares an account across multiple terminals. In this case, multiple terminals used on the same individual may be interpreted as a single terminal on that individual.
[0029] (Target Information) For example, to show the details of each individual of the first target VA, first target information O10 relating to the first target VA may be used. First target information O10 may include a first identifier I10. Similarly, to show the details of each individual of the second target WA, second target information O20 relating to the second target WA may be used. Second target information O20 may include a second identifier I20. First target information O10 and second target information O20 may be stored in any storage area. At least a portion of first target information O10 and second target information O20 may be stored in a manner accessible from at least one of the management server 1, the external server, and each terminal (4, 5).
[0030] The first target information O10 and the second target information O20 may be managed as appropriate. In the example in Figure 1, the first server 2 may be configured to manage the first target information O10, and the second server 3 may be configured to manage the second target information O20. The first server 2 and the second server 3 may each consist of one or more server devices. The first target information O10 may be stored in a memory resource located at least one of the internal and external locations of the first server 2, accessible from the first server 2. The second target information O20 may be stored in a memory resource located at least one of the internal and external locations of the second server 3, accessible from the second server 3. Internal memory resources may include, for example, RAM (Random Access Memory), auxiliary storage devices, storage media, etc. External memory resources may include, for example, external storage devices, external computers (NAS: Network Attached Storage, etc.). In another example, each of the target information (O10, O20) may be stored in the memory resources of the management server 1.
[0031] The unit for managing each piece of target information (O10, O20) is not particularly limited and may be determined as appropriate depending on the embodiment. At least one of the first piece of target information O10 and the second piece of target information O20 may be managed centrally (as a whole) or distributed (separately) for each arbitrary group. The server devices constituting each server (2, 3) may be deployed by one or more operating organizations (entities). At least one of the first server 2 and the second server 3 may be deployed by multiple operating organizations. When deployed by multiple operating organizations, the target information may be shared (i.e., managed centrally) or distributed for each operating organization.
[0032] Furthermore, in one example, sending a linking request and accepting the setting of a correspondence may include authenticating at least one of the corresponding individuals of the first target VA and the corresponding individuals of the second target WA. Authentication of the corresponding individuals may be performed by any method. The authentication process involves each terminal (4, 5), external servers (e.g., first server 2, second server 3) and management server This may be performed by at least one of the methods described in step 1. In one example, each target information (O10, O20) may include information used for authentication of each target (VA, WA) (such as registered unique information). In another example, each server (2, 3) may issue information used for authentication of each target (VA, WA) (a time-limited certificate). If at least part of the authentication process is performed by an external server or management server 1, the linking request may include data used for authentication. Management server 1 may be configured to execute the linking setting process (step S30) only if authentication is successful.
[0033] (identifier) In one example, identifiers (I10, I20) may be used to identify each individual of each target (VA, WA). The data format and structure of each identifier (I10, I20) are not particularly limited, as long as they can identify each individual of each target (VA, WA), and may be appropriately selected depending on the embodiment. In one example, each identifier (I10, I20) may consist of a sequence of symbols including numbers, letters, etc. In another example, each identifier (I10, I20) may use unique information such as identification information uniquely assigned to each target (VA, WA) and information originating from each terminal (4, 5). The uniquely assigned identification information may be, for example, a vehicle registration number, a vehicle identification number (VIN), or a personal identification number. If an IC tag is attached to the target, the uniquely assigned identification information may include information held by the IC tag. Information originating from each terminal (4, 5) includes, for example, the MAC address (Media Access Control address) and terminal identification information (IMEI: International Mobile Equipment Identifier, IMSI: This may be International Mobile Subscriber Identity (MEID: Mobile Equipment Identifier), ICCID: Integrated Circuit Card ID, or other serial numbers, etc.
[0034] (Management Server) Management Server 1 is configured to set up a correspondence between a first target VA and a second target WA in response to a linking request from at least one of the first terminal 4 and the second terminal 5. Management Server 1 may receive the linking request directly from at least one of the first terminal 4 and the second terminal 5, or it may receive it indirectly via an external computer (e.g., first server 2, second server 3, etc.). That is, sending a linking request to Management Server 1 may include sending the linking request directly to Management Server 1 and sending it indirectly via an external computer. In one example, indirect transmission may consist of simply having an external computer relay the linking request. In another example, indirect transmission may consist of sending a request to an external computer for processing involved in linking, such as requesting each server (2, 3) to authenticate each target (VA, WA) and having them send the authentication results to Management Server 1, and having the external computer send some information to Management Server 1 according to the result of its execution. That is, the linking request may also be sent from an external computer to Management Server 1 as a result of data communication for other purposes to the external computer.
[0035] Management Server 1 may be configured to set an active correspondence between the first target VA and the second target WA, or to update the state of the correspondence from inactive to active, in response to the occurrence of a usage relationship. A linking request (request for linking setting) may include a request to establish a new linking setting and a request to change the state of an existing linking setting from inactive to active. If no linking setting exists between the relevant individuals, the linking request may consist of a request to establish a new linking setting. If a linking setting exists between the relevant individuals, the linking request may consist of a request to change the state of the corresponding existing linking setting.
[0036] Information indicating whether or not a linking setting exists between each of the relevant individuals may be managed as appropriate. For example, at least one of the first terminal 4 and the second terminal 5 may, before sending a linking request, By referring to the linking information D10, it may be determined whether or not a linking setting exists between each of the relevant individuals. In another example, at least one of the first terminal 4 and the second terminal 5 may be configured to record a history of past linking requests, and by referring to this history, it may be determined whether or not a linking setting exists between each of the relevant individuals. The past history may be generated by individual processing of the terminals, or it may be generated by sharing the linking information D10 of the relevant individuals with the management server 1. At least one of the first terminal 4 and the second terminal 5 may send a linking request that either establish a new linking setting or change the status of the corresponding existing linking setting to active, depending on the result of the determination.
[0037] In another example, the first terminal 4 and the second terminal 5 may send a linking request without distinguishing whether or not a linking setting already exists between each of the relevant individuals. In this case, when processing the linking request, it may be determined whether or not a linking setting already exists between each of the relevant individuals. For example, the management server 1 may determine whether or not an existing linking setting exists between the relevant individual of the first target VA and the relevant individual of the second target WA specified by the linking request by referring to the linking information D10. Alternatively, for example, whether or not a linking setting already exists between each of the relevant individuals may be determined by an external computer such as the first server 2 or the second server 3. In one example, the external computer may determine whether or not a target linking setting exists by referring to the linking information D10. In another example, the external computer may be configured to record a linking history separately from the linking information D10, and may determine whether or not a target linking setting exists by referring to this history. The linking history may be generated by individual processing on the external computer, or it may be generated by sharing the linking information D10 with the management server 1 at least partially. Depending on the result of the determination, the management server 1 may perform either a process to establish a new linking setting or a process to change the status of the corresponding existing linking setting to active.
[0038] In one example of this embodiment, if there are no existing active linking settings with other individuals of the second target WA, the management server 1 may, in response to a linking request, establish a new correspondence setting or change the state of a specified existing correspondence to active. This allows the management server 1 to establish active correspondences between each individual. The absence of existing active linking settings with other individuals of the second target WA may include the absence of existing linking settings between the individual of the first target VA and other individuals of the second target WA, and the existence of existing linking settings between the individual of the first target VA and other individuals of the second target WA, but all existing linking settings with other individuals of the second target WA being inactive.
[0039] On the other hand, if there are existing active linking settings with other individuals of the second target WA, establishing an active linking setting in response to a linking request (i.e., establishing a new active linking setting or changing the status of the corresponding existing linking setting to active) would result in multiple active linking settings being established for the same individual of the first target VA, causing a linking setting conflict. Therefore, the management server 1, through the arbitration process described above, activates one correspondence setting and deactivates the other correspondence settings according to the status information ST10. In this way, the management server 1 resolves the linking setting conflict. The arbitration rule by status information ST10 (i.e., the method for selecting the active correspondence) may be determined as appropriate depending on the embodiment. In a simple example, the management server 1 may set the status of the correspondence specified by the earliest linking request to active and the status of the other correspondences to deactivate. In this case, status information ST10 may consist of arbitrary information that can determine whether it is the earliest or not. For example, status information ST10 may consist of information such as a timestamp, the time the linking request was sent, the time the linking request was received, and that the linking request was received. Another example of the arbitration rule will be described later (Figures 4A to 4C).
[0040] In one example of this embodiment, authentication processing may be performed on at least one of the first target VA and the second target WA in relation to a linking request. For example, authentication processing may be performed on at least one of the first target VA and the second target WA when a request is made to establish a new linking setting. The same authentication processing as for establishing a new linking setting may also be performed when a request is made to change the state of an existing linking setting. However, adopting this form would result in the same processing being repeated, which could lead to increased processing costs. Therefore, at least a part of the authentication processing may be omitted when a request is made to change the state of an existing linking setting. This makes it preferable that the processing for a request to change the state of an existing linking setting be simpler than the processing for a request to establish a new linking setting. For example, at least one of the first terminal 4 and the second terminal 5 may appropriately acquire data to be used for authentication when a request is made to establish a new linking setting. By storing the data to be used for authentication acquired when a request is made to establish a new linking setting, the processing to acquire data to be used for authentication may be omitted when a request is made to change the state of an existing linking setting. Alternatively, for example, the authentication processing itself may be omitted. In one example, when a request is made to establish a new linkage setting, authentication processing is performed for both the first target VA and the second target WA, whereas when a request is made to change the state of an existing linkage setting, authentication processing for at least one of the first target VA and the second target WA may be omitted. In another example, when a request is made to establish a new linkage setting, authentication processing is performed for at least one of the first target VA and the second target WA, whereas when a request is made to change the state of an existing linkage setting, authentication processing for both the first target VA and the second target WA may be omitted. According to this example, a reduction in processing costs can be expected.
[0041] Furthermore, the management server 1 may be configured to terminate the correspondence between the first target VA and the second target WA, or to update the status of the correspondence from active to inactive, in response to the termination of the usage relationship. When the usage relationship is terminated, at least one of the first terminal 4 and the second terminal 5 may send a request to the management server 1 to terminate the linking (a termination request). The termination request may be sent directly or indirectly to the management server 1, similar to the linking request. The termination request may include requesting the invalidation (termination in the narrow sense) of the corresponding linking setting, and requesting a change in the status of the existing linking setting from active to inactive. Invalidating the linking setting may include deleting the linking setting, providing information indicating termination, and indicating that the termination conditions have been met. Providing information indicating termination may include, for example, adding a termination time, setting a flag indicating termination, or accumulating a transaction indicating termination. Indicating that the termination conditions have been met may include, for example, that the set expiration date has passed. Whether to disable the linking setting or change the status of the linking setting may be appropriately selected by at least one of the terminals (4, 5), management server 1, and external computers (e.g., first server 2, second server 3, etc.). For example, after a correspondence is disabled, this disabled correspondence may be treated as if it does not exist. Accordingly, if a linking request is issued again for the same combination of first target VA and second target WA after it has been disabled, management server 1 may execute a process to establish a new linking setting. While the correspondence (linking) setting is maintained, the status of the correspondence may be updated at any time other than those mentioned above. Note that the broad sense of cancellation (disabling or deactivating) may be read as "resolved," and the cancellation (disabling) of the agreement may be called "cancellation."
[0042] In one example of this embodiment, authentication processing for at least one of the first target VA and the second target WA may be performed in connection with the unlinking request, similar to the linking request described above. The same authentication processing as when requesting to disable a linking setting may also be performed when requesting to change the state of an existing linking setting. At least a portion of the authentication processing may be omitted when requesting to change the state of an existing linking setting. This allows the processing for requests to change the state of an existing linking setting to be configured more simply than the processing for requests to disable a linking setting. In another example, When a linking request is made, authentication processing is performed for at least one of the first target VA and the second target WA, whereas when a delinking request is made, at least a part of the authentication processing may be omitted. As a result, the processing for delinking requests may be configured more simply than the processing for linking requests.
[0043] Furthermore, the linking request and the unlinking request may be configured to specify the target individual to be processed in any way. In a typical example, the linking request and the unlinking request may be configured to specify the target individual to be processed by including a first identifier I10 and a second identifier I20, respectively. However, the method of specifying the target individual to be processed is not limited to this example and may be changed as appropriate depending on the embodiment. In another example, in at least one of the linking request and the unlinking request, at least one of the first identifier I10 and the second identifier I20 may be omitted by using alternative information. For example, an identifier may be assigned as alternative information to the combination of target individuals of the first target VA and the second target WA (linking setting). The assignment of the identifier may be performed at any time, for example, when the initial linking setting is performed. At least one of the linking request and the unlinking request may be configured to specify the target individual of each target (VA, WA) to be processed without including at least one of the first identifier I10 and the second identifier I20 by including this identifier.
[0044] With regard to linking requests, the method for specifying each individual in a request to establish a new linking setting and a request to change the status of an existing linking setting may be the same or different. For example, a request to change the status of an existing linking setting may be configured to specify each individual more simply than a request to establish a new linking setting. For example, a request to establish a new linking setting may be configured to include a first identifier I10 and a second identifier I20, while a request to change the status of an existing linking setting may be configured to include the above alternative information. Similarly, with regard to unlinking requests, the method for specifying each individual in a request to invalidate a linking setting and a request to change the status of an existing linking setting may be the same or different. For example, a request to change the status of an existing linking setting may be configured to specify each individual more simply than a request to invalidate a linking setting. For example, a request to invalidate a linking setting may be configured to include a first identifier I10 and a second identifier I20, while a request to change the status of an existing linking setting may be configured to include the above alternative information.
[0045] The management server 1 may consist of one or more server devices. In this embodiment, the management server 1 may be configured to record information regarding the occurrence and termination of correspondence between the first target VA and the second target WA as linking information D10. The linking information D10 may be stored in memory resources deployed both inside and outside the management server 1. Internal memory resources may include, for example, RAM, auxiliary storage devices, storage media, etc. External memory resources may include, for example, external storage devices, external computers (NAS, etc.), etc.
[0046] The resulting linking information D10 can be used in various situations. For example, linking information D10 can be used to track the relationship between a first target VA and a second target WA. Specifically, while a correspondence relationship is established between the first target VA and the second target WA, linking information D10 can be used to enable the exercise of authority associated with either the first target VA or the second target WA (first target information O10 and second target information O20) from the other. In other words, linking information D10 can be used to enable the exercise of authority on either the first target VA or the second target WA from the other, depending on the linking of the first target VA and the second target WA (Figure 2, described later).
[0047] In one example of this embodiment, the linking information D10 is the first target VA and the corresponding relationship set. To indicate the combination of the second target WA, the information of the first identifier I10 and second identifier I20 of the individual in question may be included. Management server 1 may obtain each identifier (I10, I20) of each target as appropriate. In one example, management server 1 may not pre-store the information of the first identifier I10 and second identifier I20 for setting the correspondence, but may obtain it each time from at least one of the servers (2, 3) and terminals (4, 5). In another example, management server 1 may pre-store information of at least one of the first identifier I10 and second identifier I20 for setting the correspondence.
[0048] The relationship between the management server 1 and each server (2, 3) is arbitrary. In one example, the management server 1 may overlap with the management server of at least one of the first server 2 and the second server 3. In another example, the management server 1 may be different from the management servers of the first server 2 and the second server 3. The system 100 of this disclosure may be produced by the management server 1 being connected to each terminal (4, 5) via a network, and each being deployed in a state capable of performing the above information processing according to the intent of the management server 1's operating body. If each server (2, 3) is involved in information processing related to linking (e.g., authentication processing), each server (2, 3) may be interpreted as being included in the system 100. In this case, the system 100 of this disclosure may be produced by the management server 1 being further connected to each server (2, 3) via a network, and each server (2, 3) being further deployed in a state capable of performing information processing related to linking.
[0049] (Operation example) In one example, one of the first target VA and the second target WA may be a user. Of the first terminal 4 and the second terminal 5, the terminal corresponding to the user may be a user terminal associated with that user. The other of the first target VA and the second target WA may be a usable item used by the user. Of the first terminal 4 and the second terminal 5, the terminal corresponding to the usable item may be a loading terminal loaded onto the usable item. According to this example embodiment, the usage relationship between the user and the usable item can be easily tracked.
[0050] The type of object used is not particularly limited as long as it can be used by the user, and may be appropriately selected depending on the embodiment. For example, the object used may be a mobile device. According to this example embodiment, the usage relationship between the user and the mobile device can be tracked. The type of mobile device may be appropriately selected. A mobile device may be, for example, a vehicle, a railway vehicle, an aircraft (aircraft, drone, etc.), a ship, etc. A mobile device may be at least one of a manually controlled manned aircraft or an automatically controlled unmanned aircraft. If the mobile device is a vehicle, the type of vehicle may be arbitrarily selected. The type of vehicle may be, for example, a two-wheeled vehicle, a three-wheeled vehicle, a four-wheeled vehicle, etc. A vehicle may include a private car, a rental car, a shared car, a taxi, a bus, etc. A vehicle may be at least one of an autonomous vehicle or a manually driven vehicle. The loading terminal may be called a mobile device terminal.
[0051] Figure 2 schematically shows one embodiment of a scenario in which the System 100 of this Disclosure is applied. In the example in Figure 2, the first target VA is the user, and the second target WA is the mobile object. For convenience, in the following explanation of the example in Figure 2, "first" will be treated as relating to the user and "second" as relating to the mobile object. However, the correspondence between "first" and "second" is not limited to the example in Figure 2. "First" and "second" may be interchangeable. That is, the second target WA may be the user, and the first target VA may be the mobile object.
[0052] When the first target VA is a user, an example of the first terminal 4 is a user terminal. The user terminal may be any computer, such as a mobile terminal (smartphone, etc.), a dedicated device (electronic key device, etc.), or other computer device. Typically, the user terminal may be owned by the user who is the linked target (each individual first target VA). The user's account is The account may be shared among multiple computers, and accordingly, each computer sharing the account may be used as a user terminal (first terminal 4) for the same user.
[0053] An example of the first identifier I10 is a user identifier (user ID, My ID). The user identifier may be, for example, a user account ID, a personal number, or user terminal identification information (e.g., MAC address, terminal identification information). An example of the first target information O10 is user information O10A. User information O10A may include any information about the user. For example, user information O10A may include information about the authority of the corresponding user (the corresponding individual user) and be associated with various information E10 for exercising that authority. Various information E10 may include, for example, public personal authentication information, payment information, and other service-related information. Public personal authentication information may include, for example, a personal number. Payment information may include, for example, credit card information, internet banking information, and electronic payment information. Other service-related information may include, for example, information about electronic prescriptions (insurer number, prescription information, etc.). Various information E10 may be managed by an external system or by system 100. The first server 2 may be deployed by public institutions, neutral organizations, various businesses (vehicle manufacturers, service providers, etc.). The first server 2 may also be called a user ID server, my ID server, etc.
[0054] On the other hand, when the second target WA is a mobile object, an example of the second terminal 5 is a mobile terminal (loaded terminal). A mobile terminal may be, for example, a terminal attached to the inside or outside of a mobile object, a terminal carried by a person involved in the operation of the mobile object (e.g., driver, conductor, etc.), or equipment deployed in the facilities of the mobile object (e.g., ticket gate, etc.). When the mobile object is a vehicle, the mobile terminal may be called an in-vehicle terminal.
[0055] An example of the second identifier I20 is a mobile identifier (mobile ID, car ID). The mobile identifier may be, for example, the ID of a mobile account, identification information uniquely assigned to the target mobile (e.g., vehicle registration number, vehicle identification information, etc.), identification information of a mobile terminal, etc. An example of the second target information O20 is mobile information O20A. Mobile information O20A may include arbitrary information about the mobile. In the example in Figure 2, depending on the active linking settings between the user and the mobile, at least some of the permissions of the various information E10 associated with user information O10A may be enabled (activated) by the mobile. The second server 3 may be deployed by public institutions, neutral institutions, various operators (vehicle manufacturers, service operators, etc.). The second server 3 may be referred to as a mobile ID server, car ID server, etc.
[0056] A mobile object is an example of a usable object. The configuration shown in Figure 2 can be applied to any case where the user (possessor) of the usable object changes dynamically. In addition to a mobile object, the usable object may be, for example, rental items, accommodation facilities, etc. Rental items may include rental offices, rental spaces, etc.
[0057] System 100 may be configured to set an active link between the user (first identifier I10) and the corresponding individual item of the item (second identifier I20) or to update the link status from inactive to active when the use of the item begins. System 100 may also be configured to update the link status between the individuals from active to inactive or to release the link when the use ends. The start and end of use may be detected by any method at the timing of, for example, getting on and off a vehicle, lending and returning the item of use. In one example, at least one of the start and end of use may be detected in response to the execution of data exchange between the first terminal 4 and the second terminal 5.
[0058] Furthermore, the materials used are those that can be used repeatedly over a long period of time, and those that can be used temporarily. At the very least, they can be divided into two types. For the sake of explanation, the former will be called "regularly used items" and the latter "temporarily used items." An example of regularly used items is personal property owned by the user, such as a private car. An example of temporarily used items is items owned by someone other than the user, such as rental cars, shared cars, public transportation vehicles, rental items, and accommodation facilities. Public transportation vehicles include, for example, taxis, buses, train cars, aircraft, and ships.
[0059] In system 100, the type of user (whether it is a regularly used item or a temporary item) may or may not be distinguished. If the type of user is distinguished, system 100 may determine the type of user in any way. For example, the target information (such as mobile information) may include information indicating the type of user, and system 100 may determine the type of user based on this information. In another example, the type of user may be determined from information such as an identifier. In yet another example, the information transmitted from at least one of the first terminal 4 and the second terminal 5 to the management server 1 may include information indicating the type of user, and system 100 may determine the type of user based on this information. In yet another example, if the operating organization of the server that handles the user information (second server 3 in the example of Figure 2) is determined according to the type of user, the type of user may be determined according to the affiliation of the operating organization of the server.
[0060] Furthermore, the system 100 may switch the form of, for example, the linking setting process, the conditions for switching the status (active / inactive), the conditions for unlinking, the management method of the linking information D10, and the authentication process, depending on the type of user identified.
[0061] Furthermore, the application of System 100 of this disclosure is not limited to situations where relationships between users and objects are tracked. In another example, both the first target VA and the second target WA may be robotic devices configured to operate autonomously through automatic control. The robotic devices may include mobile objects such as autonomous vehicles and drones. In situations where two or more robotic devices interact autonomously, System 100 of this disclosure may be used to track the occurrence and termination of relationships between the robotic devices.
[0062] As a specific example, one of the first target VA and the second target WA may be a large autonomous vehicle, and the other may be a small autonomous vehicle. The large autonomous vehicle may be configured to accommodate multiple small autonomous vehicles. The small autonomous vehicles may not be able to ride in multiple large autonomous vehicles simultaneously (i.e., at any given time, the small autonomous vehicles are accommodated in only one large autonomous vehicle). Accordingly, the first target VA may be a small autonomous vehicle, and the second target WA may be a large autonomous vehicle. The large autonomous vehicle may retrieve, transport, and release each small autonomous vehicle as appropriate. Each small autonomous vehicle may be operated as appropriate at its release destination. In this case, the system 100 of this disclosure may be configured to track the operational status (e.g., whether or not it is being transported) by setting, switching, and releasing the correspondence between the large autonomous vehicle and the small autonomous vehicles.
[0063] (Data exchange) In this embodiment, the series of processes related to linking settings may be initiated by data exchange between the first terminal 4 and the second terminal 5. That is, the occurrence of a usage relationship (start of usage) may be detected by data exchange. The method of data exchange is not particularly limited and may be appropriately selected depending on the embodiment.
[0064] For example, data exchange between the first terminal 4 and the second terminal 5 may be performed by wireless or wired data communication. Wireless communication may be performed by, for example, NFC (Near Field Communication), Bluetooth (registered trademark), Wi-Fi (registered trademark), etc. Wired communication may be performed by, for example, wired LAN (Local Area Network), USB (Universal Serial Bus), etc. Data communication may take place directly between the first terminal 4 and the second terminal 5, or indirectly via another computer. In another example, data exchange may be performed by methods other than data communication, such as reading a two-dimensional code. For example, data exchange may take place when one of the first terminal 4 or the second terminal 5 displays data on a display, and the other uses a sensor, such as an image sensor, to read the displayed data.
[0065] A linking request may include at least one of the first identifier I10 and the second identifier I20. If the linking request includes the first identifier I10, the first identifier I10 may be transmitted from at least one of the first terminal 4 and the second terminal 5. If the first identifier I10 is transmitted from the first terminal 4, the first terminal 4 may acquire the first identifier I10 at any time. In one example, the first identifier I10 may be stored in the memory resources of the first terminal 4 beforehand. The first terminal 4 may acquire the first identifier I10 from the memory resources. In another example, the first terminal 4 may acquire the first identifier I10 using an input device, sensor, etc. If the first identifier I10 is transmitted from the second terminal 5, the second terminal 5 may be given the first identifier I10 by the first terminal 4 during data exchange, or may acquire it through its own actions. In one example, the second terminal 5 may acquire the first identifier I10 from the first terminal 4 via data communication. In another example, the second terminal 5 may obtain the first identifier I10 from the first terminal 4 by a method other than data communication, such as reading the first identifier I10 displayed as a two-dimensional code on the first terminal 4. In yet another example, the second terminal 5 may obtain the first identifier I10 from either the first target VA or the first terminal 4 using a device such as an input device or a sensor. Obtaining from the first target VA may include obtaining it by having the person related to the second target WA operate a device on behalf of the first target VA, when the second target WA is an object and there is a person related to the second target WA (for example, the second target WA is a person, the second target WA is operated by a person, etc.).
[0066] Similarly, if the linking request includes a second identifier I20, the second identifier I20 may be transmitted from at least one of the first terminal 4 and the second terminal 5. If the second identifier I20 is transmitted from the second terminal 5, the second terminal 5 may acquire the second identifier I20 at any time. In one example, the second identifier I20 may be stored in the memory resources of the second terminal 5 beforehand. The second terminal 5 may acquire the second identifier I20 from the memory resources. In another example, the second terminal 5 may acquire the second identifier I20 using an input device, sensor, etc. If the second identifier I20 is transmitted from the first terminal 4, the first terminal 4 may be given the second identifier I20 by the second terminal 5 during data exchange, or may acquire it through its own actions. In one example, the first terminal 4 may acquire the second identifier I20 from the second terminal 5 via data communication. In another example, the first terminal 4 may obtain the second identifier I20 from the second terminal 5 by a method other than data communication, such as reading the second identifier I20 displayed as a two-dimensional code on the second terminal 5. In yet another example, the first terminal 4 may obtain the second identifier I20 from either the second target WA or the second terminal 5 using a device such as an input device or a sensor. Obtaining from the second target WA may include obtaining it by having the person related to the first target VA operate the device on behalf of the person related to the first target VA when the second target WA is an object and the person related to the first target VA operates the device on their behalf.
[0067] For example, in the example shown in Figure 2 above, the first terminal 4 may obtain the second identifier I20 (mobile identifier) from the second terminal 5 by data communication or reading a code. If the second identifier I20 is a vehicle registration number, the first terminal 4 may obtain the second identifier I20 by photographing the license plate with an image sensor and analyzing the obtained image. The first terminal 4 may also obtain the second identifier I20 via an input device. The second terminal 5 may obtain the second identifier I20 as appropriate. The second terminal 5 may also obtain the first identifier I10 (user identifier) by data communication or reading a code. If the first identifier I10 is a personal number etc. written on a card, the second terminal 5 may photograph the card with an image sensor and obtain The first identifier I10 may be obtained by analyzing the image. The second terminal 5 may obtain the first identifier I10 via an input device. The first terminal 4 may obtain the first identifier I10 as appropriate.
[0068] When an input device is used to acquire data such as each identifier (I10, I20), the acquisition of data from the other target by one terminal may include not only the acquisition of data from the other target by the other target operating the input device, but also the acquisition of data from the other target by the first target operating the input device. For example, in the example in Figure 2 above, if the second identifier I20 is a vehicle registration number and an input device is used to acquire the vehicle registration number, the first terminal 4 may acquire the second identifier I20 from the mobile entity (second target WA) by the input of the vehicle registration number via the input device by the user (first target VA).
[0069] Furthermore, the acquisition of data from one terminal to the other terminal does not necessarily have to be performed during data exchange. One terminal may acquire data from the other terminal at any time other than the data exchange. Any of the above methods may be used for data acquisition. In this case, the data exchange between the first terminal 4 and the second terminal 5 may function merely as a trigger to start a series of processes related to the linking settings.
[0070] (Linking information) Figure 3A schematically shows an example of the linking information D10 according to this embodiment. In the example in Figure 3A, it is assumed that a form is adopted in which the setting of the correspondence relationship is expressed using a first identifier I10 and a second identifier I20. The linking information D10 includes the first identifier I10, the second identifier I20, the setting time, the release time, and the status. The first identifier I10 and the second identifier I20 indicate the corresponding individual of the first target VA and the corresponding individual of the second target WA for which the correspondence relationship (linking) has been set. The setting time indicates the time when the correspondence relationship was set. The setting time may consist of a timestamp. The release time indicates the time when the correspondence relationship was released. The value of the release time may be added when the process of releasing the correspondence relationship is executed. The method of expressing release is not limited to this example. In another example, the release time may be replaced with at least one of an expiration date and a flag. The expiration date indicates the period during which the setting of the correspondence relationship is valid. In this case, whether or not the setting of the correspondence relationship is valid (i.e., whether the correspondence relationship is set or released) is indicated depending on whether or not it is within the expiration date. The flag indicates whether the correspondence has been released or not. The flag may be set when a process to release the correspondence is executed. In yet another example, the linking information D10 may include at least one of the expiration date and the flag, along with a field for the release time. The status indicates whether the correspondence setting is active or inactive. Note that the configuration of the linking information D10 is not limited to the example in Figure 3A, and may be appropriately modified depending on the embodiment, as long as the setting and status of the correspondence can be indicated. In yet another example, the linking information D10 may further include information indicating the type of item used (whether it is a regularly used item or a temporary item). Note that the type of item used does not necessarily have to be identified by separate information. For example, the type of item used may be identified by information such as an identifier. In yet another example, the linking information D10 may further include information indicating the time of the status change (from active to inactive, or from inactive to active).
[0071] The data format of the linking information D10 is not particularly limited and may be appropriately selected depending on the embodiment. The linking information D10 may be stored in any database infrastructure. In one example, the linking information D10 may be stored in a relational database such as a table. In another example, the linking information D10 may be stored on a blockchain infrastructure. In this case, each transaction for linking setting, status change, and unlinking may be accumulated on the blockchain as linking information D10. For example, a transaction for linking setting may include information indicating the first identifier I10, the second identifier I20, the setting time, and the type of status (active or inactive). A transaction for status change may include the second The first identifier I10, the second identifier I20, and information indicating the type of change (whether it is a change from active to inactive or from inactive to active) may be included. The information indicating the type of change may be replaced with information indicating the type of state after the change (whether it is active or inactive). The unlinking transaction may include the first identifier I10, the second identifier I20, and the unlinking time (or information indicating unlinking).
[0072] (First target information) The first target information O10 may include any information relating to the first target VA. For example, the first target information O10 may include the first identifier I10, attribute information of the first target VA, information regarding authorizations, etc. In the example in Figure 2, user information O10A is an example of the first target information O10.
[0073] Figure 3B schematically shows an example of user information O10A according to this embodiment. In the example in Figure 3B, user information O10A includes a user ID (first identifier I10), attribute information, and authorization information. The attribute information may include arbitrary information relating to the attributes of the corresponding user. For example, attribute information may include personal information such as name, address, age, gender, and contact information. The authorization information relates to the authorizations of the corresponding user. For example, authorization information may include information for coordinating with a server that performs information processing related to the target authorization, and information indicating association with various types of information E10. Note that the configuration of user information O10A is not limited to the example in Figure 3B and may be modified as appropriate depending on the embodiment. For example, user information O10A (first target information O10) may further include information used for user (first target VA) authentication (for example, registered unique information).
[0074] The data format of the first target information O10 (user information O10A) is not particularly limited and may be appropriately selected depending on the embodiment. The first target information O10 (user information O10A) may be stored in any database infrastructure. In one example, the first target information O10 (user information O10A) may be stored in a relational database such as a table format. In another example, the first target information O10 (user information O10A) may be stored on a blockchain infrastructure.
[0075] (Second target information) The second target information O20 may include any information relating to the second target WA. For example, the second target information O20 may include the second identifier I20, attribute information of the second target WA, information relating to authorization, etc. In the example in Figure 2, mobile information O20A is an example of the second target information O20.
[0076] Figure 3C schematically shows an example of mobile information O20A according to this embodiment. In the example in Figure 3C, mobile information O20A includes a mobile ID (second identifier I20) and attribute information. The attribute information includes a number, type (type of object), mobile type, and owner information. If the mobile is a vehicle, the number may be the vehicle registration number. The type may be defined arbitrarily. In one example, the type may be defined to indicate a category that can distinguish between regularly used and temporarily used items, such as private cars, rental cars, shared cars, and public transport mobiles. The mobile type indicates a type such as vehicle type. If the mobile type and type (type of object) are the same, the mobile type field may be omitted. Owner information may include arbitrary information about the owner of the mobile. Owner information may include personal information of the owner, such as name, address, age, gender, and contact information. The owner may be a corporation. Note that the configuration of mobile information O20A is not limited to the example in Figure 3C and may be modified as appropriate depending on the embodiment. For example, mobile information O20A (second target information O20) may further include information used for authentication of the mobile entity (second target WA) (e.g., registered unique information). The structure of attribute information may also be changed as appropriate. For example, mobile information O20A (attribute information) may further include information about the mobile terminal, such as the mobile terminal's contact information.
[0077] The data format of the second target information O20 (mobile entity information O20A) is not particularly limited and may be appropriately selected depending on the embodiment. The second target information O20 (mobile entity information O20A) may be stored in any database infrastructure. In one example, the second target information O20 (mobile entity information O20A) may be stored in a relational database such as a table format. In another example, the second target information O20 (mobile entity information O20A) may be stored on a blockchain infrastructure.
[0078] (Notification processing) When the management server 1 performs at least one of the following processes: setting up a link, changing the status, or unlinking a link, it may send a notification indicating the result to at least one of the first terminal 4 and the second terminal 5. The notification transmission path is not particularly limited and may be determined as appropriate depending on the embodiment. In one example, the management server 1 may directly notify at least one of the first terminal 4 and the second terminal 5. In another example, the management server 1 may indirectly notify at least one of the first terminal 4 and the second terminal 5 via external computers such as each server (2, 3).
[0079] If direct notification is required, management server 1 may obtain contact information for each terminal (4, 5) as appropriate. Contact information may include telephone number, email address, account information for communication applications (e.g., Social Networking Service applications), identification number, etc. This may be the case. Management server 1 may obtain information indicating the contact details of each terminal (4, 5) at any time. For example, management server 1 may obtain information indicating the contact details when it receives requests such as linking requests or unlinking requests. Information indicating the contact details may be transmitted from at least one of each terminal (4, 5) and each server (2, 3).
[0080] (Status Information) Status information ST10 is used to select an active correspondence. Status information ST10 is not particularly limited as long as an active correspondence can be selected. The configuration of status information ST10 may be determined as appropriate according to the selection conditions, etc. Furthermore, the management server 1 may, at any time before executing the arbitration process, obtain status information ST10 in real time from at least one of the corresponding individuals of the first target VA (e.g., the corresponding first terminal 4) for which two or more correspondence settings are established, and from each of the two or more corresponding individuals of the second target WA (e.g., each corresponding second terminal 5) for which correspondences are set with the corresponding individuals of the first target VA. This may activate the linking settings between the corresponding individuals of the first target VA and the second target WA for which usage relationships are currently occurring. In this embodiment, at least one of the following three methods may be adopted for selecting an active correspondence.
[0081] (1) Method 1 Figure 4A schematically shows an example of the selection process for the linked settings to be activated by the first method according to this embodiment. In the example in Figure 4A, the first target VA1 is an example of one individual of the first target VA for which two or more correspondence settings have been established with two or more second target WAs (two or more individuals of the second target WA). One individual of the first target VA for which two or more correspondence settings have been established is also referred to as the "first individual of the first target". The second target WA2 and the second target WA3 are examples of other second target WAs (other individuals of the second target WA) for which correspondence settings have already been established with the first target VA1 (the first individual of the first target VA). This assumes a scenario in which a linking request (a request to establish a new linked setting) with the second target WA1 is received when the correspondence setting with the second target WA2 is active and the correspondence setting with the second target WA3 is inactive. Furthermore, this assumes a scenario in which a usage relationship with the first target VA1 is actually occurring in the second target WA1 of the second target WA1 to WA3.
[0082] In the first method, the setting of two or more correspondence relationships is established for the first target VA (first target VA1 Depending on the selection made by ), the association setting to be activated may be selected. That is, the status information ST10 may include the selection made by the first target VA (first target VA1). Accordingly, activating a correspondence setting may be performed by activating the correspondence setting selected by the first target VA (first target VA1).
[0083] In the example shown in Figure 4A, the first target VA1 selects the second target WA1 from the second targets WA1 to WA3. Accordingly, the association settings of the first target VA1 may be updated so that an active association setting is established with the second target WA1, and the association setting status with the second target WA2 is changed from active to inactive.
[0084] Selecting a linked setting to activate may include directly selecting a linked setting to activate, or indirectly selecting a linked setting to activate by selecting a linked setting to deactivate. Selecting a linked setting may also include selecting its second target WA. The selection may be performed automatically by a computer (terminal) or manually.
[0085] Furthermore, the selection of the linking setting to be activated may be accepted by at least one of the first terminal 4 of the first target VA (first target VA1) and the second terminal 5 of the second target WA. The second terminal 5 of the second target WA may be the second terminal 5 of the second target WA (second target WA1 in Figure 4A) with which the usage relationship is currently occurring. Status information ST10 may be transmitted to the management server 1 from at least one of the first terminal 4 and the second terminal 5. In one example, status information ST10 may be transmitted from one terminal that accepted the selection from the first terminal 4 and the second terminal 5. In another example, status information ST10 may be transmitted from a terminal other than the one that accepted the selection from the first terminal 4 and the second terminal 5, as the selection result is exchanged as data.
[0086] Furthermore, the trigger for transmission is arbitrary. In one example, at least one of the first terminal 4 and the second terminal 5 may send status information ST10 to the management server 1 as a voluntary information processing in response to the linking request. In another example, at least one of the first terminal 4 and the second terminal 5 may send status information ST10 to the management server 1 as a reply to an inquiry from the management server 1. The transmitted status information ST10 may be appropriately configured to indicate the selection result of the first target VA. According to one example of this embodiment, the active linking setting can be selected with a simple process.
[0087] (2) Second method Figure 4B schematically shows an example of the selection process for the linked settings to be activated by the second method according to this embodiment. The preconditions for Figure 4B are the same as those for Figure 4A, and the example in Figure 4B assumes the same scenario as in Figure 4A.
[0088] In the second method, the association setting with the second target WA that was most recently involved in the authentication of the first target VA (first target VA1) may be selected as the association setting to be activated. That is, the status information ST10 may include a report of the results of the authentication process performed by the second terminal 5 for the first target VA (first target VA1). Accordingly, activating one target relationship setting may be configured by activating the association setting with the second target WA corresponding to the second terminal 5 that most recently reported the results of the authentication process performed for the first target VA (first target VA1).
[0089] In the example shown in Figure 4B, among the second target WA1 to WA3, the second terminal 5 of the second target WA1 is involved in the most recent authentication process of the first target VA1, and the status information ST10 contains information indicating that this authentication was successful. Accordingly, the association setting for the first target VA1 is: An active linking setting may be established with the second target WA1, and the linking setting status with the second target WA2 may be updated to change from active to inactive.
[0090] The authentication process for the first target VA (first target VA1) may be initiated from at least one of the first terminal 4 and the second terminal 5. In the example shown in Figure 2, the second terminal 5 of the mobile device (second target WA) may authenticate the user (first target VA) by methods such as performing facial recognition using an image sensor provided on the mobile device, performing fingerprint authentication using a fingerprint reader attached to the handle, or having the user speak and performing voiceprint authentication using a microphone provided on the mobile device. However, the authentication method is not limited to these examples and may be appropriately selected depending on the embodiment. Known methods may also be used for authentication.
[0091] If the second terminal 5 is involved in the authentication process, the authentication process may be performed on at least one of the first terminal 4 and the second terminal 5. Furthermore, at least a portion of the authentication process may be performed on at least one of the management server 1 and an external server (e.g., the first server 2). The second terminal 5's involvement in the authentication process may include the second terminal 5 performing at least a portion of the authentication process, and the second terminal 5 performing information processing related to the authentication process, even if the authentication process is performed on other computers (e.g., the first terminal 4, management server 1, and first server 2) (e.g., performing data exchange with the first terminal 4). The authentication process may also be triggered by the second terminal 5.
[0092] Status information ST10 may be sent from at least one of the first terminal 4 and the second terminal 5 to the management server 1. In one example, when at least one of the first terminal 4 and the second terminal 5 performs authentication processing, status information ST10 may be sent from the terminal that has completed the authentication processing among the first terminal 4 and the second terminal 5, or it may be sent from a different terminal. When status information ST10 is sent from another terminal, the completion of authentication processing may be notified from one terminal to the other terminal by any means. In another example, after status information ST10 has been sent from at least one of the first terminal 4 and the second terminal 5, the management server 1 and at least one of the external server may perform at least part of the authentication processing. In this case, status information ST10 may be in an incomplete state at the stage when it is sent from at least one of the first terminal 4 and the second terminal 5. Status information ST10 may be configured to indicate the authentication result of the first target VA after the authentication processing is completed by the management server 1 and at least one of the external server performing at least part of the authentication processing.
[0093] Furthermore, as with the first method, the trigger for transmission can be arbitrary. In one example, at least one of the first terminal 4 and the second terminal 5 may perform information processing related to authentication processing as a voluntary information processing in response to the linking request and send status information ST10 to the management server 1. Performing information processing related to authentication processing may include at least one of the first terminal 4 and the second terminal 5 performing the authentication processing itself, and requesting authentication processing from an external computer (e.g., management server 1, first server 2). In another example, at least one of the first terminal 4 and the second terminal 5 may perform information processing related to authentication processing in response to an inquiry from the management server 1 and send status information ST10 to the management server 1 as a reply to the inquiry. According to one example of this embodiment, by involving the authentication processing of the first target VA, it is possible to appropriately identify the corresponding individual of the first target VA and the individual of the second target WA with which a usage relationship is currently occurring. This makes it possible to expect that an appropriate linking setting will be activated.
[0094] (3) Third method Figure 4C schematically shows an example of the selection process for the linked settings to be activated by the third method according to this embodiment. The preconditions for Figure 4C are the same as those for Figure 4A, and the example in Figure 4C assumes the same scenario as in Figure 4A.
[0095] In the third method, the association setting to be activated may be selected according to the positional relationship between the first individual of the first target VA (first terminal 4) and each individual of the second target WA (each second terminal 5). That is, each first terminal 4 may be equipped with a positioning module 47. Each second terminal 5 may be equipped with a positioning module 57. The status information ST10 may include a first current position measured by the positioning module 47 of the first terminal 4 corresponding to the first target VA (first target VA1 / first individual of the first target VA), and a second current position measured by the positioning module 57 of the second terminal 5 corresponding to each of the two or more second target WAs (each individual of the second target WA). Accordingly, activating a correspondence setting may be configured by activating a correspondence setting between the second current position of the corresponding second terminal 5 and a second target WA that satisfies the conditions for a usage relationship with the first current position of the first terminal 4.
[0096] The conditions for the usage relationship may be set as appropriate. For example, the conditions for the usage relationship may be defined by a distance range DR based on the first current location. In this case, whether or not the conditions for the usage relationship are met may be determined based on whether or not the device is located within the range DR. In the example in Figure 4C, among the second target WA1 to WA3, the second terminal 5 of the second target WA1 is located within the range DR based on the first terminal 4 (first current location) of the first target VA1. The status information ST10 may include at least the first current location of the first terminal 4 of the first target VA1 and the second current location of the second terminal 5 of the second target WA1, and it may be determined as appropriate whether the second terminal 5 of the second target WA1 is located within the range DR. Accordingly, the linking setting of the first target VA1 may be updated so that an active linking setting is established with the second target WA1, and the state of the linking setting with the second target WA2 is changed from active to inactive.
[0097] Furthermore, the range DR may be set appropriately to allow for the determination of the second target WA with which the usage relationship has occurred. The shape of the range DR may be defined arbitrarily. The range DR may be defined so that the distances in each direction are the same, or it may be defined so that the distances differ in at least some directions.
[0098] The types of each positioning module (47, 57) are not particularly limited and may be appropriately selected depending on the embodiment. Each positioning module (47, 57) may be, for example, a GPS (Global Positioning Satellite) module, a GNSS (Global Navigation Satellite System) module, etc.
[0099] Information on each current location (status information ST10) may be transmitted to the management server 1 from each first terminal 4 and each second terminal 5 at any time. For example, each terminal (4, 5) of each target (VA, WA) with established linking settings may report its current location information to the management server 1 as a voluntary information processing, such as by sending it periodically. In this case, the management server 1 may determine a second target WA that satisfies the usage relationship conditions from the most recently reported information on each current location. In another example, the management server 1 may send a request directly or indirectly to each terminal (4, 5) at any time before executing arbitration processing. Each terminal (4, 5) may report its most recent information on each current location to the management server 1 in real time in response to this request. The management server 1 may determine a second target WA that satisfies the usage relationship conditions from the most recently reported information on each current location in real time. In either configuration, there may be cases where a second terminal 5 does not report (respond to) its second current location due to factors such as the second terminal 5 being powered off. In this case, the second target WA corresponding to the second terminal 5 that has not recently reported its second current location may be determined not to meet the conditions for the usage relationship, and accordingly, the correspondence relationship with that second target WA may be set to non-active.
[0100] Furthermore, the recipient of the information about each current location may be appropriately selected depending on the embodiment. In one example, the recipient of the information about each current location may be the management server 1. Accordingly, the information about each current location may be managed by the management server 1. In another example, the reporting of the information about each current location may be to the management server 1. The recipient of the report may be an external server (e.g., first server 2, second server 3). Accordingly, the information of each current location may be managed by an external server. Management server 1 may obtain the information of each current location (status information ST10) from an external server. Reporting to management server 1 may include reporting directly to management server 1 and reporting indirectly to management server 1 via an external server. The reported information of each current location may be discarded after it is no longer used for arbitration processing, or it may be stored as history for at least a predetermined period. When the form of reporting directly to management server 1 is adopted, the information of each current location may be stored on management server 1 or on an external server (e.g., first server 2, second server 3, NAS). Similarly, when the form of reporting indirectly to management server 1 is adopted, the information of each current location may be stored on management server 1 or on an external server. According to one example of this embodiment, by using location information, it is possible to appropriately identify the individual of the second target WA that is currently in a usage relationship with the individual of the first target VA. This can be expected to activate the appropriate linking settings.
[0101] (Lock active settings) For example, in the scenario shown in Figure 2, assume that an active correspondence has been established between the relevant individual (the user) of the first target VA and one individual of the second target WA, which is a public transport vehicle. In this scenario, it is undesirable for the user (the relevant individual of the first target VA) to dissolve (deactivate or cancel) the active correspondence with the relevant individual of the public transport vehicle (the individual of the second target WA) by using another vehicle (another individual of the second target WA), even though the payment for the public transport vehicle has not been completed, and to establish a new active correspondence with the other vehicle. Thus, when the relevant individual of the second target WA is of a certain type, it may be desirable to refuse to establish an active correspondence with other individuals of the second target WA until a certain condition is met (in the above example, payment is completed).
[0102] Therefore, in one example of this embodiment, the management server 1 may be configured to further prevent the establishment of other active correspondences between the first target VA (the corresponding individual of the first target VA) with other second target WAs (other individuals of the second target WAs) after establishing an active correspondence with a first predetermined type of second target WA (one individual of the second target WA), by locking the active correspondence until predetermined conditions are met.
[0103] Establishing an active correspondence with a first predetermined type of second target WA may include establishing a new linking setting in an active state with the relevant individual of the second target WA, and changing the state of the linking setting with the relevant individual of the second target WA from inactive to active. Prohibiting the establishment of other active correspondence settings may include prohibiting the establishment of new linking settings in an active state with other individuals of the second target WA, and prohibiting the change of the state of the linking setting with other individuals of the second target WA from inactive to active. Establishing a new linking setting with other individuals of the second target WA in an inactive state may or may not be permitted.
[0104] The predetermined conditions may be set as appropriate depending on the embodiment. Furthermore, whether or not the predetermined conditions are met may be detected as appropriate. In a simple example, the satisfaction of the predetermined conditions may be detected by a notification from the second terminal 5 corresponding to the individual second target WA of the first predetermined type. In the above example, when settlement is completed, the second terminal 5 of the individual mobile unit may send a notification to the management server 1 indicating settlement completion (satisfaction of the predetermined conditions). The management server 1 may recognize that the predetermined conditions have been met by receiving this notification. The management server 1 may also perform such lock processing for second target WAs of other types other than the first predetermined type. Furthermore, the locking process may be omitted for other types of secondary target WAs.
[0105] Figure 5 schematically shows an example of a scenario in which an active linking setting is locked according to this embodiment. In the example in Figure 5, the second target WA4 is an example of a second target WA of the first predetermined type. The first target VA1 is an example of a first target VA that has established an active correspondence with one of the first predetermined type second target WAs. The second target WA5 is an example of another second target WA (another individual of the second target WA) that attempts to establish an active correspondence with the first target VA1.
[0106] In the example shown in Figure 5, the management server 1 may lock the correspondence between the first target VA1 and the second target WA4 until predetermined conditions are met. If the management server 1 receives a linking request from at least one of the first terminal 4 of the first target VA1 and the second terminal 5 of the second target WA5 during this locking period, the management server 1 may ignore the linking request and not permit the establishment of an active correspondence with the second target WA5 in response to the linking request. In this case, the management server 1 may directly or indirectly send a notification to at least one of the first terminal 4 of the first target VA1 and the second terminal 5 of the second target WA5 indicating that the establishment of other active correspondences is prohibited.
[0107] The management server 1 may release the lock on the correspondence setting with the second target WA in response to detecting that predetermined conditions have been met. This allows the management server 1 to permit the establishment of active correspondence settings with other individuals of the second target WA. After releasing the lock, if the management server 1 receives a linking request from at least one of the first terminal 4 of the first target VA1 and the second terminal 5 of the second target WA5, the management server 1 may establish an active correspondence setting with the second target WA5 in response to the linking request. According to one example of this embodiment, in situations where it is inappropriate to establish other active correspondence settings, the establishment of such other active correspondence settings can be prohibited by locking the established active correspondence setting.
[0108] The first predetermined type may be appropriately selected depending on the embodiment. In one example, the first target VA may be a user. The second target WA of the first predetermined type may be a public transport vehicle. The predetermined condition may be that payment (settlement) for the use of the public transport vehicle has been completed. According to one example of this embodiment, if the fare for the transport vehicle is unpaid, it is possible to prohibit transfer to another vehicle (establishment of an active correspondence relationship with another vehicle).
[0109] (Confirmation process for continued use) As one of the optional configurations, after setting the correspondence between the corresponding individual of the first target VA and the corresponding individual of the second target WA, the management server 1 may further perform a process (confirmation process) to check whether the correspondence continues or not. The method for confirming continued use may be appropriately selected depending on the embodiment.
[0110] In one example, the continuation of the correspondence relationship may be confirmed by authenticating at least one of the first target VA and the second target WA via at least one of the first terminal 4 and the second terminal 5. The authentication method may be any method, similar to the linking setting. In the example in Figure 2, for example, user authentication may be performed by using an image sensor installed on the mobile device to perform facial recognition of the user, a fingerprint reader attached to the handle to perform fingerprint recognition of the user, or the user to speak and voiceprint authentication using a microphone installed on the mobile device. The authentication process may be performed on at least one of the terminals (4, 5), servers (2, 3), and management server 1. When the authentication process is performed on the servers (2, 3), the data used for authentication may be sent directly from the terminals (4, 5) to the servers (2, 3), or to an external server such as the management server 1. The data may also be transmitted indirectly via a computer. When the management server 1 performs the authentication process, the data used for authentication may be transmitted directly from the terminals (4, 5) to the management server 1, or it may be transmitted indirectly via external computers such as each server (2, 3). The management server 1 may acquire the authentication results as appropriate, and if the authentication is successful in the acquired authentication results, it may determine that the correspondence relationship is continuing, and if the authentication is unsuccessful, it may determine that the correspondence relationship is not continuing.
[0111] In another example, if at least one of the first target VA and the second target WA is a user (for example, the case in Figure 2), the management server 1 may directly or indirectly send a confirmation notification including an operator to at least one of the first terminal 4 and the second terminal 5. The operator may consist of, for example, a confirmation button, a reply button, a link, etc. The recipient of the confirmation notification does not necessarily have to correspond to a user. In the case of Figure 2, the management server 1 may send a confirmation notification to at least one of the first terminal 4 and the second terminal 5. The recipient of the confirmation notification may overlap with or differ from the recipient of a notification indicating the result of the linking process. The confirmation notification may be configured to send a response directly or indirectly back to the management server 1 in response to the user's operation of the operator. If the management server 1 receives a response from the operator operation within a predetermined period, it may determine that the correspondence is continuing, and if it does not receive a response, it may determine that the correspondence is not continuing.
[0112] In yet another example, when tracking the correspondence between a first target VA and a second target WA in the real world, each terminal (4, 5) may be equipped with a positioning module (47, 57), as shown in the example in Figure 4C. The first terminal 4 may measure the current location of the first target VA (first terminal 4) using the positioning module 47, and the second terminal 5 may measure the current location of the second target WA (second terminal 5) using the positioning module 57. Each terminal (4, 5) may transmit the obtained current location of each target (VA, WA) directly to the management server 1 or indirectly via an external computer such as each server (2, 3). The management server 1 may determine whether the correspondence is continuing depending on whether the current location of each received target (VA, WA) is close enough to satisfy predetermined conditions for the usage relationship (for example, the user is riding in a mobile vehicle). In other words, the management server 1 may determine that the correspondence relationship is continuing if the current locations of each target (VA, WA) are close enough to satisfy predetermined conditions, and determine that the correspondence relationship is not continuing otherwise. When this configuration is adopted, the management server 1 may store the obtained information on the current location of each target (VA, WA) in association with the linking information D10. This allows the management server 1 to track not only the correspondence relationship of each target (VA, WA) but also the movement history of each target (VA, WA). Furthermore, at least a part of the above processing may be executed on a computer other than the management server 1.
[0113] If the management server 1 determines that the correspondence relationship is continuing, it may maintain the state of the correspondence relationship settings (for example, it may maintain it in an active state). On the other hand, if the management server 1 determines that the correspondence relationship is not continuing, it may cancel the correspondence relationship or change the state of the correspondence relationship from active to inactive. The management server 1 may be configured to update the state of the correspondence relationship by repeatedly executing the confirmation process periodically or irregularly after the correspondence relationship is established until the correspondence relationship is canceled.
[0114] (Unlink) In this embodiment, the management server 1 may be configured to cancel the correspondence (disable or change to non-active) upon receiving a cancellation request from at least one of the first terminal 4 and the second terminal 5 or upon fulfilling a predetermined cancellation condition.
[0115] (I) Request for cancellation In one example, the release request is made using at least one of the first identifier I10 and the second identifier I20. The release request may be configured to indicate the correspondence between the items to be released by including alternative information. In another example, the release request may be configured to indicate the correspondence between the items to be released by including alternative information.
[0116] When the first terminal 4 sends a release request that includes the second identifier I20, the first terminal 4 may obtain the second identifier I20 at any time. For example, when a linking request is made, the first terminal 4 may obtain the second identifier I20 and store the obtained second identifier I20 in a memory resource. When a release request is made, the first terminal 4 may obtain the second identifier I20 from the memory resource. Also, when the first terminal 4 sends a release request that includes the first identifier I10, the first terminal 4 may obtain the first identifier I10 at any time. For example, the first identifier I10 may be stored in a memory resource in advance. The first terminal 4 may obtain the first identifier I10 from the memory resource.
[0117] Similarly, when the second terminal 5 sends a release request that includes the first identifier I10, the second terminal 5 may obtain the first identifier I10 at any time. For example, when a linking request is made, the second terminal 5 may obtain the first identifier I10 and store the obtained first identifier I10 in a memory resource. When a release request is made, the second terminal 5 may obtain the first identifier I10 from the memory resource. Also, when the second terminal 5 sends a release request that includes the second identifier I20, the second terminal 5 may obtain the second identifier I20 at any time. For example, the second identifier I20 may be stored in a memory resource in advance. The second terminal 5 may obtain the second identifier I20 from the memory resource.
[0118] Figure 6 schematically shows an example of the unlinking process according to this embodiment. In the example in Figure 6, as the first route, the first terminal 4 directly sends an unlinking request to the management server 1 (step SZ10). Also, as the second route, the first terminal 4 gives instructions to the second terminal 5 (step SZ10A), causing the second terminal 5 to directly send an unlinking request to the management server 1 (step SZ11A). However, the transmission route of the unlinking request is not limited to this example. The first terminal 4 may indirectly send an unlinking request to the management server 1 via an external computer such as the first server 2. In the second route, the second terminal 5 may indirectly send an unlinking request to the management server 1 via an external computer such as the second server 3. Note that the starting point of the unlinking request is not limited to the first terminal 4. In another example, the second terminal 5 may directly or indirectly send an unlinking request to the management server 1. Furthermore, the second terminal 5 may instruct the first terminal 4 to directly or indirectly send a release request to the management server 1. After receiving the release request, the management server 1 refers to the linking information D10 and releases (disables or deactivates) the correspondence specified by the identifier included in the release request. After this release process, the management server 1 may send a notification indicating the result of the release process to at least one of the first terminal 4 and the second terminal 5, similar to the time of linking setup.
[0119] The trigger for the release request may be set as appropriate depending on the embodiment. In one example, if at least one of the first target VA and the second target WA is a user, the user may operate at least one of the first terminal 4 and the second terminal 5, and a release request may be sent from at least one of the first terminal 4 and the second terminal 5. In other words, the trigger for the release request may be an operation by the user. In another example, upon termination of the usage relationship, arbitrary information processing may be performed at least one of the first terminal 4 and the second terminal 5. The execution of this information processing may be the trigger for a release request to be sent from at least one of the first terminal 4 and the second terminal 5. For example, the arbitrary information processing may be data exchange between the first terminal 4 and the second terminal 5. The method of data exchange during release may be the same as the data exchange during release. The distinction between data exchange during release and data exchange during release may be made as appropriate. For example, in the example in Figure 2, the second terminal 5 may be equipped with separate sensor devices at the entrance and exit, such as at a bus entrance / exit or a train ticket gate. In this case, depending on the sensor device used for data exchange, it may be possible to distinguish between data exchange during linking setup and data exchange during unlinking. Also, for example, When data exchange is performed by an application on the terminal, the application may be configured to switch between a linking mode and a linking / unlinking mode. In this case, the application mode may distinguish between linking mode and unlinking mode.
[0120] In one example, if a request to release a correspondence is received while the correspondence setting is locked by the above-mentioned locking process, the management server 1 may reject the received release request. The management server 1 may directly or indirectly send a notification to at least one of the first terminal 4 and the second terminal 5 indicating that the release of the correspondence is prohibited. On the other hand, after the lock is released due to the fulfillment of predetermined conditions, the management server 1 may accept the release request and release the correspondence. For example, the management server 1 may detect the fulfillment of predetermined conditions in response to the termination of the above-mentioned usage relationship. In one example, the release request may include information indicating the fulfillment of predetermined conditions. In another example, information indicating the fulfillment of predetermined conditions may be sent to the management server 1 prior to the release request. As a result, the management server 1 may accept the release request sent in response to the termination of the above-mentioned usage relationship and release (disable or deactivate) the correspondence specified by the release request.
[0121] In addition, there may be cases where a non-active correspondence relationship is maintained between the corresponding individual of the first target VA and one or more other individuals of the second target WA. In this case, in response to the invalidation or deactivation of the correspondence relationship specified in the deactivation request, the management server 1 may activate one of the non-active correspondence relationships maintained between the same individual of the first target VA and one or more other individuals of the second target WA. The correspondence relationship to be activated may be determined according to the priority, type (e.g., whether it is a regularly used item or a temporarily used item), etc., of each individual of the second target WA. As a specific example, in the example in Figure 2, it is assumed that the first mobile object is a regularly used item (e.g., a private car, etc.) and the second mobile object is a temporarily used item (e.g., a rental car, a shared car, a public transportation mobile object, etc.). In this case, while the correspondence relationship between the target user and the first mobile object is set, the management server 1 may change the state of the previous correspondence relationship (correspondence relationship with the first mobile object) to non-active in response to receiving the setting of a correspondence relationship between the target user and the second mobile object. Then, in response to the deactivation or inactivation of the correspondence with the second mobile entity (temporary use entity), the management server 1 may activate the correspondence between the first mobile entity (permanently used entity) and the target user. This allows for the rapid restoration of the active correspondence setting with the constantly used entity.
[0122] (I-1) Maintaining the linking settings When a cancellation request is made, you may choose to either cancel (disable) the corresponding linking setting or change the state of the linking setting to inactive. However, in certain situations, it may be more efficient to choose not to cancel (disable) the linking setting and instead maintain the linking setting in an active or inactive state. For example, in the scenario shown in Figure 2, if the corresponding individual of the second target WA is a private car, this individual of the second target WA is repeatedly used by the first target VA (user). Therefore, it may be more efficient to handle this by switching between active and inactive states rather than repeatedly creating and destroying the correspondence relationship each time it is used.
[0123] Therefore, in one example of this embodiment, the management server 1 may be further configured to maintain the correspondence relationship in an active or inactive state without canceling (disabling) it until the predetermined relationship is resolved, if a predetermined relationship is established between the first target VA and the second target WA for which a correspondence relationship has been set, and to cancel the correspondence relationship after the predetermined relationship has been resolved. Canceling (disabling) the target relationship may include canceling the target relationship in response to the resolution of the predetermined relationship, and canceling the target relationship in response to receiving a cancellation request after the predetermined relationship has been resolved.
[0124] Figure 7 schematically shows an example of a scenario in which the linking setting according to this embodiment is maintained in an active or inactive state. The first target VA1 and the second target WA6 are examples of a first target VA and a second target WA with which a predetermined relationship is established. In the example in Figure 7, the management server 1 may maintain the correspondence setting between the first target VA1 and the second target WA6 in an active or inactive state while the predetermined relationship is established. On the other hand, after the predetermined relationship is dissolved, the management server 1 may release (disable) the correspondence between the first target VA1 and the second target WA6.
[0125] According to one example of this embodiment, it is possible to expect improved efficiency in the processing related to setting up correspondence relationships when a predetermined relationship is established. The predetermined relationship that defines the object for which the correspondence relationship is maintained may be set appropriately depending on the embodiment. From the viewpoint of improving the efficiency of the processing related to linking settings, it is desirable that the predetermined relationship is a relationship that continues for a certain period of time, and during that period, the creation and destruction of usage relationships are repeated.
[0126] In one example, the predetermined relationship may be an ownership relationship. That is, while an ownership relationship exists between the first target VA and the second target WA, the correspondence relationship between the corresponding individuals of the first target VA and the second target WA is maintained, and after the ownership relationship ends, the correspondence relationship may be released (invalidated). According to this example, when an ownership relationship is established between the first target VA and the second target WA, it is possible to expect to improve the efficiency of the processing related to setting the correspondence relationship.
[0127] The objects (VA, WA) with which ownership relationships are established are not particularly limited and may be appropriately selected depending on the embodiment. In one example, the first object VA may be the user, and the second object WA may be a mobile vehicle owned by the user (for example, a private car). According to this example embodiment, when a mobile vehicle owned by the user appears, it is possible to expect to improve the efficiency of the process related to setting up the correspondence relationship.
[0128] In another example, the first target VA may be a user, and the second target WA may be a mobile object that is leased (targeted) by the user. The predetermined relationship may be that the user is leasing the mobile object. That is, while the relevant individual mobile object is leased to the user, the correspondence relationship between the user and the relevant individual mobile object is maintained, and after the lease period ends, the correspondence relationship may be terminated (invalidated). According to this example, in situations where a leased mobile object (for example, a rental car) is involved, it is possible to expect to improve the efficiency of the processing related to setting up the correspondence relationship.
[0129] Whether or not a predetermined relationship exists can be determined as appropriate depending on the embodiment. For example, whether or not a mobile object (second target WA) is a private car, a rental car, etc., and whether or not a predetermined relationship exists can sometimes be determined from attribute information. In one example, whether or not a predetermined relationship exists can be determined from the attribute information of at least one of the first target VA and the second target WA. The attribute information may be included in each target information (O10, O20). In another example, whether or not a predetermined relationship exists can be determined from information provided by an external system (ownership information, rental information, etc.). The external system may be, for example, a dealer's terminal, a rental company's terminal, etc., that are involved in the predetermined relationship. In yet another example, whether or not a predetermined relationship exists can be determined in response to a notification from at least one of the first terminal 4 of the first target VA and the second terminal 5 of the second target WA.
[0130] Furthermore, the termination of a predetermined relationship may be detected as appropriate depending on the embodiment. In one example, the termination of a predetermined relationship may be detected from information provided by an external system (information on changes in ownership, information on termination of lease, etc.). In another example, at least one of the first terminal 4 and second terminal 5 of the first target VA and second target WA, which had a predetermined relationship, may notify the management server 1 or an external server (Dai It may be sent to Server 1 (2, Second Server 3, etc.). Management Server 1 may detect that the predetermined relationship has been terminated by receiving the notification or by referring to the information of the external server.
[0131] (I-2) Unlinking settings For example, in the scenario shown in Figure 2, depending on the types of the first target VA and the second target WA, the occurrence and termination of usage relationships may be rare, such as when the corresponding individual of the second target WA is a mobile entity on public transportation. In such cases, by choosing to cancel (disable) the linking settings instead of maintaining them, it may be possible to improve the efficiency of the memory resources used to maintain the linking settings.
[0132] Therefore, in one example of this embodiment, the management server 1 may be further configured to, after establishing a correspondence relationship with a second predetermined type of second target WA, cancel (invalidate) the correspondence relationship in response to detecting the termination of use of the second target WA. Termination of use is an example of the termination of the usage relationship. Termination of use may be detected as appropriate depending on the embodiment. In one example, upon termination of use, arbitrary information processing may be performed on at least one of the first terminal 4 and the second terminal 5, and the execution of this information processing may trigger the transmission of a cancellation request from at least one of the first terminal 4 and the second terminal 5. Termination of use may be detected by this cancellation request.
[0133] Figure 8 schematically shows an example of the execution scene of unlinking (deactivating) according to this embodiment. In the example in Figure 8, the second target WA7 is an example of a second target WA of a second predetermined type. The first target VA1 is an example of a first target VA that has established a correspondence with the second target WA of a second predetermined type. In the example in Figure 8, upon commencement of use, the first terminal 4 of the first target VA1 and the second terminal 5 of the second target WA7 may perform data exchange. Triggered by this data exchange, at least one of the first terminal 4 and the second terminal 5 may send a linking request to the management server 1. In the example in Figure 8, it is assumed that the management server 1 has established an active linking setting between the first target VA1 and the second target WA7 in response to this linking request. Subsequently, upon termination of use, the first terminal 4 of the first target VA1 and the second terminal 5 of the second target WA7 may perform data exchange. Triggered by this data exchange, at least one of the first terminal 4 and the second terminal 5 may send a release request to the management server 1. In response to this release request, the management server 1 may release (disable) the correspondence between the first target VA1 and the second target WA7.
[0134] According to one example of this embodiment, when the second target WA is of a second predetermined type, it is possible to expect improved efficiency in the memory resources used to maintain the linking settings. The second predetermined type may be appropriately selected depending on the embodiment. From the viewpoint of improving the efficiency of memory resources, it is desirable that the second predetermined type is one in which an active correspondence relationship is established (i.e., a usage relationship occurs) between the same individual of the first target VA and the same individual of the second target WA infrequently.
[0135] In one example, the first target VA may be a user, and the second target WA may be a mobile entity. The second predetermined type of second target WA may be a mobile entity of public transport. That is, when the user uses the relevant individual mobile entity of public transport, an active correspondence relationship may be established between the relevant individual mobile entity and the user. When the use of the relevant individual mobile entity of public transport ends, the correspondence relationship may be released (deactivated). According to this example, when a mobile entity of public transport (e.g., a taxi) is involved, it is possible to expect to improve the efficiency of the memory resources used to maintain the linking settings.
[0136] (II) Conditions for release The deactivation conditions indicate the conditions for deactivating (disabling or deactivating) the correspondence of the target. The release conditions may be defined as appropriate depending on the embodiment.
[0137] For example, the release condition may be defined as releasing the correspondence at an arbitrarily set release time. The release time may be given, for example, by a user, by another application (such as a scheduler), etc. In this case, the management server 1 may release the correspondence in question when the release time arrives. The release time may be set as the expiration date of the above-mentioned linking information D10. If the release time is set as the expiration date, the management server 1 may treat the correspondence in question as released when the release time arrives.
[0138] In another example, the release condition may be defined as releasing one of the overlapping correspondences when multiple correspondence settings overlap for the same individual of either the first target VA or the second target WA due to an interruption in the setting of a correspondence by another individual of at least one of the first target VA or the second target WA. The number of active correspondences (links) that can be set for the same individual of the second target WA is not limited to one, but may be two or more. Also, the number of correspondences (links) that can be maintained in an inactive state for the same individual of the first target VA may be infinite or finite. Management server 1 may release one of the correspondences that was set and maintained earlier if the overlap of correspondence settings exceeds a threshold (upper limit). The threshold may be given as appropriate. Which correspondence to release may be determined as appropriate according to priority, order, type of target, etc. Management server 1 may send a query regarding release to at least one of the first terminal 4 and the second terminal 5, and determine which correspondence to release based on the response received.
[0139] For example, consider a scenario as shown in Figure 2, where the first target VA is a user and the second target WA is a usable item. In this case, the number of users that can be associated with the same usable item may be infinite or finite. If the number of users that can be associated is finite, the upper limit of the number of users that can be associated may be appropriately set by a threshold. The threshold may be set according to the attributes of the usable item (e.g., the number of possible passengers). When the management server 1 receives a new request to set a correspondence relationship for a particular usable item, it may refer to the association information D10 and extract the previous correspondence relationships that have been set and maintained for that particular usable item. If the newly received correspondence relationship setting causes the overlap of correspondence relationship settings for the relevant usable item to exceed the threshold, the management server 1 may discard the request for the newly received correspondence relationship setting, or release (disable or deactivate) at least one of the extracted previous correspondence relationships. When releasing previous correspondence relationships, the management server 1 may decide which correspondence relationships to release according to the user priority, order (e.g., releasing the correspondence relationships that were set earlier), etc.
[0140] As a concrete example, in the example in Figure 2, we assume that the vehicle is a private car, and that the first user and the second user are, for example, family members, and thus share the private car. The private car can be interpreted as an item used on a regular basis. For the sake of explanation, we assume that the number of users that can be associated with the private car is 1. In this case, while an active correspondence relationship is established between one of the first and second users and the private car, the management server 1 may change the state of the previous correspondence relationship (the correspondence relationship between one user and the private car) from active to inactive when it receives a request to establish a correspondence relationship between the other user and the private car.
[0141] Furthermore, the number of items that can maintain an inactive association with the same user may be infinite or finite. If the number of items that can maintain an association is finite, the upper limit of that number may be appropriately set by a threshold. When the management server 1 receives a new request for a correspondence setting for a target user, it may refer to the association information D10 and extract the correspondences that have been set and maintained for the target user. If the newly received correspondence setting causes the overlap of correspondence settings for the target user to exceed a threshold, the management server 1 discards the request for the newly received correspondence setting or extracts the necessary items. At least one of the linked relationships may be canceled (disabled). When canceling a linked relationship, the management server 1 may decide which relationship to cancel depending on the priority and type of the item (for example, whether it is a regularly used item or a temporary item).
[0142] Furthermore, even when the target correspondence is to be terminated upon the fulfillment of the predetermined termination conditions, the above-mentioned form may be adopted in which the correspondence is not terminated (disabled) until the predetermined relationship is resolved, but is maintained in an active or inactive state. That is, if the predetermined relationship is established, the management server 1 may choose to change the state of the specified correspondence to inactive as a termination process upon the fulfillment of the predetermined termination conditions until the predetermined relationship is resolved. After the predetermined relationship is resolved, the management server 1 may terminate the correspondence.
[0143] (Scenarios for the use of linked information) As described above, the linking information D10 can be used in a variety of situations. For example, the linking information D10 may be used simply to track the occurrence and termination of relationships between the first target VA and the second target WA.
[0144] In another example, the linking information D10 may be used to enable at least a portion of the privileges associated with either the first target VA or the second target WA to be exercised from the other while an active correspondence is established between the first target VA and the second target WA. For example, the management server 1 may be configured to further enable the exercise of privileges associated with the corresponding first target VA (the corresponding individual of the first target VA) via the second target WA (the corresponding individual of the second target WA) with which the active correspondence has been established, in response to the establishment of an active correspondence. The management server 1 may also be configured to further disable the exercise of privileges associated with the corresponding first target VA via the second target WA with which the inactive correspondence has been established, in response to the establishment of an inactive correspondence. In the example in Figure 2, the linking information D10 may be used to enable at least a portion of the privileges associated with a user to be exercised from a mobile device while an active correspondence is established between the user and the mobile device. According to one example of this embodiment, the permission and prohibition of the exercise of authority associated with the first target VA can be controlled by switching the state of the correspondence setting between active and inactive.
[0145] Figure 9 schematically shows an example of a usage scenario for the linking information D10 according to this embodiment. Figure 9 assumes a scenario in the example of Figure 2 where user-linked privileges are exercised from a mobile device. Furthermore, it is assumed that the linking information D10 is configured to indicate a first target VA (user) and a second target WA (mobile device) with which a correspondence relationship has been established, by including a first identifier I10 and a second identifier I20. In addition, it is assumed that user information is managed by the first server 2 and mobile device information is managed by the second server 3. The external system SY1 is deployed at a location where various services are performed (e.g., a parking lot) and is configured to perform information processing to provide the target service to a user who has the target privileges. The configuration and services of the external system SY1 are not particularly limited and may be appropriately selected depending on the embodiment.
[0146] First, in step U10, the external system SY1 may obtain a second identifier I20 (mobile object identifier) from the target mobile object. The method for obtaining the second identifier I20 may be appropriately selected depending on the embodiment. In one example, the external system SY1 may obtain the second identifier I20 from the second terminal 5 by exchanging data with the second terminal 5. The method of data exchange may be the same as the data exchange between the first terminal 4 and the second terminal 5. In another example, if the second identifier I20 is a vehicle registration number, the external system SY1 may obtain the second identifier I20 by photographing the license plate with an image sensor and analyzing the obtained image.
[0147] In step U20, the external system SY1 may use the acquired second identifier I20 as a query to ask the management server 1 whether there is a valid correspondence relationship for the target mobile object at the target date and time. Valid means that an active correspondence relationship setting is maintained at the target date and time. While the target date and time is generally the present (immediate), it is not limited to this. For example, when executing a settlement process for a past date and time, the target date and time may be a past date and time. If a valid correspondence relationship exists, the first identifier I10 (user identifier) of the user associated with the target mobile object is extracted. On the other hand, if no valid correspondence relationship exists and no user associated with the target mobile object is extracted, this process may be terminated.
[0148] In step U30, the external system SY1 may use the extracted first identifier I10 as a query to inquire with the first server 2 about the available privileges for the user associated with the target mobile object. The first server 2 may refer to the first target information O10 (user information O10A) and extract the privileges associated with the target user that can be exercised. If no available privileges are extracted, this process may be terminated. Note that the first target information O10 (user information O10A) may also have a setting for each privilege indicating whether or not the mobile object is allowed to exercise the privilege. The available privileges may be extracted according to this setting. Also, if the target privilege that the external system SY1 is trying to exercise is not included in the available privileges, this process may be terminated. The privileges to be exercised may be specified at any time as appropriate. For example, the privileges to be exercised may be specified in advance by the external system SY1, or they may be specified by the user.
[0149] In step U40, if the available privileges include the privilege in question, the external system SY1 may execute a process to exercise the privilege in question. This allows the privilege associated with the user to be exercised from the mobile device, and the user to receive services via the mobile device. For example, if the privilege information includes public personal authentication information and the privilege in question relates to public personal authentication, the user can receive public services via the mobile device. Also, for example, if the privilege information includes payment information and the privilege in question relates to payment, the user can receive payment services via the mobile device. Payment services may include payments for parking fees, highway tolls, drive-through fees, public transport fees, rental fees, etc. Also, for example, if the privilege information includes information about electronic prescriptions and the privilege in question is to receive medication prescribed by an electronic prescription, the user can exercise the electronic prescription via the mobile device and receive the medication.
[0150] Furthermore, if multiple users are using a single mobile object, such as when multiple users are riding in the same vehicle, the user who exercises the authority may be selected as appropriate. For example, the user who exercises the authority may be selected by activating the correspondence of one user among the multiple users using the same mobile object. In another example, the correspondence of two or more users among the multiple users using the same mobile object may be set to active. In this case, the method of exercising authority may be adjusted as appropriate among the two or more users with active correspondences. For example, the authority of one or more selected users (representatives) may be exercised. User selection may be performed by at least one of the external system SY1, the first terminal 4, and the second terminal 5. Also, for example, if the exercise of authority is payment of a fee, the authority of each user may be exercised according to predetermined rules. As a specific example, the payment amount may be allocated equally among the users, and the authority of each user may be exercised to pay the allocated amount. The amount allocated to each user may be specified as appropriate.
[0151] Another example is that groups may be pre-defined among multiple users, and priority may be assigned to members (users) within these groups. For instance, when a family uses a private car, one group may be set up for each family, and priority may be assigned according to the relationships within the family. For example, parents may have higher priority, and children may have lower priority. Priority information may be managed appropriately in, for example, the first target information O10 (user information O10A). Accordingly, among multiple users using the same mobile device, the correspondence between two or more users within the same group may be set to active. In this case, each user's authority may be exercised according to priority. For example, if a parent and child use a private car and the parent's priority is set high, the parent's authority may be exercised. Exercising authority according to priority may include selecting users to whom authority is exercised according to priority (users with higher priority are selected as targets for authority exercise), and determining the weight of authority exercise according to priority (for example, users with higher priority are allocated higher payment amounts).
[0152] Furthermore, the processing procedure for exercising the above authority is merely an example, and each step may be modified as much as possible. Depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. In addition, in the above processing procedure, the user may be replaced with the first target VA, and the mobile object may be replaced with the second target WA. Moreover, in the above processing procedure, "first" and "second" may be swapped.
[0153] (Data communication between devices) Data communication between each device (management server 1, first server 2, second server 3, first terminal 4, and second terminal 5) is not particularly limited and may be appropriately selected depending on the embodiment. The network between each device may be appropriately selected from, for example, the Internet, wireless communication network, mobile communication network, telephone network, dedicated network, local area network, etc. Data communication between each device is performed using methods such as SSL (Secure Socket Layer) and TLS (Transport Layer Security). Encryption is permitted. For example, each terminal (4, 5) may be equipped with a SIM (Subscriber Identity Module), and data communication between each terminal (4, 5) and the servers (management server 1, first server 2, second server 3) may be performed using encrypted communication via the SIM.
[0154] [2 Example Configurations] [Example Hardware Configuration] (Management Server) Figure 10A schematically shows an example of the hardware configuration of the management server 1 according to this embodiment. The management server 1 according to this embodiment is a computer in which a control unit 11, a storage unit 12, a communication interface 13, an input device 14, an output device 15, and a drive 16 are electrically connected.
[0155] The control unit 11 is a hardware processor, a CPU (Central Processing Unit), It includes RAM, ROM (Read Only Memory), etc., and is configured to perform arbitrary information processing based on programs and various data. The control unit 11 (CPU) is an example of the processor resources of the management server 1.
[0156] The storage unit 12 may be composed of, for example, a hard disk drive, a solid-state drive, or semiconductor memory. The storage unit 12 (and RAM, ROM) is an example of memory resources. In this embodiment, the storage unit 12 stores various information such as the management program 81 and the association information D10. The management program 81 is a program that causes the management server 1 to execute information processing related to setting and canceling the correspondence between the first target VA and the second target WA (Figures 12 and 13 described later). The management program 81 includes a series of instructions for said information processing.
[0157] The communication interface 13 is configured to perform wired or wireless communication over a network. The communication interface 13 may consist of, for example, a wired LAN (Local Area Network) module, a wireless LAN module, etc. The management server 1 controls the communication interface Data communication may be performed with other computers (first server 2, second server 3, first terminal 4, second terminal 5) via -13.
[0158] The input device 14 is a device for inputting data, such as a mouse, keyboard, or operation buttons. The output device 15 is a device for outputting data, such as a display or speaker. The operator can operate the management server 1 by using the input device 14 and the output device 15. The input device 14 and the output device 15 may be integrated into a single unit, such as a touch panel display. The input device 14 and the output device 15 may be connected via an external interface. The external interface may be configured as appropriate to connect to an external device via wired or wireless connection, such as a USB (Universal Serial Bus) port, a dedicated port, or a wireless communication port.
[0159] Drive 16 is a device for reading various information, such as programs, stored in the storage medium 91. At least one of the management program 81 and the association information D10 may be stored in the storage medium 91 instead of or together with the storage unit 12. The storage medium 91 is configured to store various information (stored programs, etc.) by electrical, magnetic, optical, mechanical, or chemical means so that a machine such as a computer can read the information. The management server 1 may obtain at least one of the management program 81 and the association information D10 from the storage medium 91. The storage medium 91 may be a disk-type storage medium such as a CD or DVD, or a non-disk-type storage medium such as semiconductor memory (e.g., flash memory). The type of drive 16 may be appropriately selected according to the type of storage medium 91. Drive 16 may be connected via an external interface.
[0160] Regarding the specific hardware configuration of the management server 1, components can be omitted, replaced, and added as appropriate depending on the embodiment. For example, the control unit 11 may include multiple hardware processors. Hardware processors include microprocessors, FPGAs (field-programmable gate arrays), DSPs (digital signal processors), and GPs. It may consist of a U (Graphics Processing Unit), an ASIC (application-specific integrated circuit), etc. At least one of the input device 14, output device 15 and drive 16 Any of these may be omitted. The linking information D10 may be stored not in the storage unit 12, but on an external computer accessible by the management server 1 (e.g., a NAS). The management server 1 may consist of multiple computers. In this case, the hardware configurations of each computer may or may not be the same. The management server 1 may be an information processing device designed specifically for the services provided, a general-purpose server device, a general-purpose computer, etc.
[0161] (Server 1, Server 2) The hardware configuration of each server (2, 3) may be the same as that of management server 1. For example, each server (2, 3) may be a computer with a control unit, memory unit, communication interface, input device, output device, and drive electrically connected. Each server (2, 3) may consist of one or more computer devices. The processor resources of each server (2, 3) may consist of one or more processors. The type of processor may be selected as appropriate. The first target information O10 may be stored in the memory resources of the first server 2 and in at least one external computer (such as a NAS) accessible by the first server 2. The second target information O20 may be stored in the memory resources of the second server 3 and in at least one external computer (such as a NAS) accessible by the second server 3. Regarding the hardware configuration of each server (2, 3), components can be omitted, replaced, and added as appropriate depending on the embodiment. Each server (2, 3) may be an information processing device designed specifically for the services provided, as well as a general-purpose server device, a general-purpose computer, etc.
[0162] (Terminal 1) Figure 10B schematically shows an example of the hardware configuration of the first terminal 4 according to this embodiment. The first terminal 4 according to this embodiment is a computer in which a control unit 41, a storage unit 42, a communication interface 43, an input device 44, an output device 45, a drive 46, and a positioning module 47 are electrically connected. The control unit 41 to the drive 46 and the storage medium 94 of the first terminal 4 may be configured in the same way as the control unit 11 to the drive 16 and the storage medium 91 of the management server 1.
[0163] The control unit 41 (CPU) is an example of the processor resources of the first terminal 4, and the storage unit 42 (and RAM, ROM) is an example of the memory resources of the first terminal 4. In this embodiment, the storage unit 42 stores various information such as the program 84 and the first identifier I10. The program 84 is a program that causes the first terminal 4 to execute information processing related to association (Figures 12 and 13, described later). The program 84 includes a series of instructions for said information processing. At least one of the program 84 and the first identifier I10 may be stored in the storage medium 94 instead of or together with the storage unit 42. The first terminal 4 may obtain at least one of the program 84 and the first identifier I10 from the storage medium 94. The first terminal 4 may communicate data with other computers (management server 1, first server 2, second server 3, second terminal 5, etc.) via the communication interface 43. The first terminal 4 may be operated via the input device 44 and the output device 45.
[0164] Furthermore, regarding the specific hardware configuration of the first terminal 4, components can be omitted, replaced, and added as appropriate depending on the embodiment. For example, the control unit 41 may include multiple hardware processors. Hardware processors are composed of microprocessors, FPGAs, DSPs, GPUs, ASICs, ECUs (Electronic Control Units), etc. At least one of the input device 44, output device 45, drive 46, and positioning module 47 may be omitted. The first identifier I10 does not have to be stored in the storage unit 42. The first identifier I10 may be acquired each time. To acquire data such as identifiers and information used for authentication, the first terminal 4 may be further equipped with data acquisition devices such as sensors and readers. The communication interface 43 may be composed of multiple types of modules. For example, the communication interface 43 may be equipped with a short-range wireless communication module and a wireless communication module, and the first terminal 4 may communicate data with the second terminal 5 via the short-range wireless communication module and with servers (management server 1, first server 2, second server 3) via the wireless communication module. The first terminal 4 may be composed of multiple computers. In this case, the hardware configuration of each computer may or may not be the same. The first terminal 4 may be an information processing device designed specifically for the services provided, as well as a general-purpose computer, terminal device (e.g., smartphone, tablet PC, etc.).
[0165] (Second terminal) Figure 10C schematically shows an example of the hardware configuration of the second terminal 5 according to this embodiment. The second terminal 5 according to this embodiment is a computer in which a control unit 51, a storage unit 52, a communication interface 53, an input device 54, an output device 55, a drive 56, and a positioning module 57 are electrically connected. The control unit 51 to the drive 56 and the storage medium 95 of the second terminal 5 may be configured in the same way as the control unit 11 to the drive 16 and the storage medium 91 of the management server 1.
[0166] The control unit 51 (CPU) is an example of the processor resources of the second terminal 5, and the storage unit 52 (and RAM, ROM) is an example of the memory resources of the second terminal 5. In this embodiment, the storage unit 52 stores various information such as the program 85 and the second identifier I20. Gram 85 is a program that causes the second terminal 5 to perform information processing related to linking (Figures 12 and 13 described later). Program 85 includes a series of instructions for said information processing. At least one of Program 85 and the second identifier I20 may be stored in the storage medium 95 in place of or together with the storage unit 52. The second terminal 5 may obtain at least one of Program 85 and the second identifier I20 from the storage medium 95. The second terminal 5 may communicate data with other computers (management server 1, first server 2, second server 3, first terminal 4, etc.) via the communication interface 53. The second terminal 5 may be operated via the input device 54 and the output device 55.
[0167] Regarding the specific hardware configuration of the second terminal 5, components can be omitted, replaced, and added as appropriate depending on the embodiment. For example, the control unit 51 may include multiple hardware processors. Hardware processors may consist of microprocessors, FPGAs, DSPs, GPUs, ASICs, ECUs, etc. At least one of the input device 54, output device 55, drive 56, and positioning module 57 may be omitted. The second identifier I20 does not have to be stored in the storage unit 52. The second identifier I20 may be acquired each time. To acquire data such as identifiers and information used for authentication, the second terminal 5 may further be equipped with data acquisition devices such as sensors and readers. The communication interface 53 may be composed of multiple types of modules, similar to the first terminal 4 described above. The second terminal 5 may consist of multiple computers. In this case, the hardware configuration of each computer may or may not be the same. The second terminal 5 may be an information processing device designed specifically for the services provided, as well as a general-purpose computer, terminal device, etc.
[0168] [Example Software Configuration] Figure 11 schematically shows an example of the software configuration of each device (management server 1, first terminal 4, and second terminal 5) according to this embodiment.
[0169] (Management Server) The control unit 11 of the management server 1 loads the management program 81 stored in the memory unit 12 into RAM, and the CPU executes the instructions contained in the management program 81. As a result, the management server 1 operates as a computer equipped with a reception unit 111, a setting unit 112, a deactivation unit 113, and a notification unit 114 as software modules.
[0170] The reception unit 111 is configured to receive a linking request directly or indirectly from at least one of the first terminal 4 of the first target VA and the second terminal 5 of the second target WA, in response to the occurrence of a usage relationship between the individual of the first target VA and the individual of the second target WA. Upon receiving the linking request, the reception unit 111 is configured to accept the setting of a correspondence relationship between the individual of the first target VA and the individual of the second target WA.
[0171] The setting unit 112 is configured to execute the setting process for the received correspondence. The setting process may include setting a new active correspondence between the corresponding individual of the first target VA and the corresponding individual of the second target WA specified in the linking request, and changing the status of the correspondence from inactive to active. In response to receiving the setting of correspondences from two or more linking requests for the same individual of the first target VA, it may be possible to establish two or more correspondences between the same corresponding individual of the first target VA and two or more different individuals of the second target WA. In this case, the setting unit 112 is configured to activate the setting of one of the two or more correspondences and deactivate the settings of the other correspondences, according to the status information ST10 obtained from at least one of the corresponding individual of the first target VA and two or more individuals of the second target WA.
[0172] The release unit 113 is configured to execute a release process for the correspondence relationship upon receiving a release request from at least one of the first terminal 4 and the second terminal 5 or when predetermined release conditions are met. The release process may include releasing (disabling) the correspondence relationship setting and changing the state of the correspondence relationship to inactive.
[0173] The notification unit 114 is configured to send a notification to at least one of the first terminal 4 and the second terminal 5 indicating the result of performing the correspondence setting process. The notification unit 114 is configured to send a notification to at least one of the first terminal 4 and the second terminal 5 indicating the result of performing the correspondence cancellation process.
[0174] (Terminal 1) The control unit 41 of the first terminal 4 executes instructions included in the program 84 using the CPU. As a result, the first terminal 4 operates as a computer equipped with a data exchange unit 411, a setting request unit 412, and a release request unit 413 as software modules. The data exchange unit 411 is configured to perform data exchange with the second terminal 5. The setting request unit 412 is configured to send a linking request (a request for linking settings) to the management server 1. The release request unit 413 is configured to send a release request (a request for linking release) to the management server 1.
[0175] (Second terminal) The control unit 51 of the second terminal 5 executes instructions included in program 85 using the CPU. As a result, the second terminal 5 operates as a computer equipped with a data exchange unit 511, a setting request unit 512, and a release request unit 513 as software modules. The data exchange unit 511 is configured to perform data exchange with the first terminal 4. The setting request unit 512 is configured to send a linking request (a request for linking settings) to the management server 1. The release request unit 513 is configured to send a release request (a request for linking release) to the management server 1.
[0176] (others) In this embodiment, an example is described in which each software module of each device is implemented by a general-purpose CPU. However, some or all of the above software modules may be implemented by one or more dedicated processors. Each of the above modules may also be implemented as a hardware module. With respect to the software configuration of each device, modules may be omitted, replaced, and added as appropriate, depending on the embodiment. For example, if a configuration is adopted in which a linking request is sent from only one of the first terminal 4 and the second terminal 5, the setting request unit may be omitted from the other terminal. Similarly, if a configuration is adopted in which a release request is sent from only one of the first terminal 4 and the second terminal 5, the release request unit may be omitted from the other terminal.
[0177] [3 Examples of operation] (Linking settings) Figure 12 shows an example of the linking setting process procedure by the system 100 according to this embodiment. The following processing procedure is an example of an information processing method executed by a computer. Of the following processing procedures, the processing procedure of the management server 1 is an example of a management method executed by a computer.
[0178] In step S10, in response to the occurrence of a usage relationship between the corresponding individuals of the first target VA and the second target WA, at least one of the control units 41 of the corresponding first terminal 4 and the control unit 51 of the second terminal 5 sends a linking request to the management server 1. In one example, in response to the occurrence of a usage relationship, the control unit 41 of the corresponding first terminal 4 operates as a data exchange unit 411 and the corresponding second Terminal 5 may perform data exchange. The control unit 51 of the second terminal 5 may operate as a data exchange unit 511 and perform data exchange with the first terminal 4. Triggered by this data exchange, the control unit 41 of the first terminal 4 may operate as a configuration request unit 412 and send a linking request to the management server 1. The control unit 51 of the second terminal 5 may operate as a configuration request unit 512 and send a linking request to the management server 1. The linking request may be sent directly to the management server 1, or indirectly via an external computer (first server 2, second server 3, etc.).
[0179] In step S20, the control unit 11 of the management server 1 operates as a reception unit 111 and receives a linking request directly or indirectly from at least one of the first terminal 4 of the corresponding individual of the first target VA and the second terminal 5 of the corresponding individual of the second target WA. Upon receiving this linking request, the control unit 11 accepts the setting of the correspondence relationship between the corresponding individual of the first target VA and the corresponding individual of the second target WA.
[0180] In step S10, if a configuration is adopted in which both the first terminal 4 and the second terminal 5 send the linking request, a single linking request may be sent separately from the first terminal 4 and the second terminal 5, or the same linking request may be sent. If sent separately, some of the data of the linking request may be sent from the first terminal 4 and the remaining data from the second terminal 5. In step S20, in order to identify the combination of the first target VA and the second target WA that are currently requesting the setting of the correspondence, the management server 1 may appropriately identify the correspondence of this data (i.e., determine the combination of corresponding data).
[0181] Data mapping can be identified in any way. For example, the data transmitted from each terminal (4, 5) may include shared information for identifying data mapping. The shared information may consist of information that has relationships, such as matching or a correspondence being established. The management server 1 may identify data mapping based on whether a relationship is established between the shared information contained in the data received from one of the first terminal 4 and the second terminal 5 and the shared information contained in the data received from the other terminal.
[0182] The shared information may be configured in any way. For example, the shared information may consist of a combination of a first identifier I10 and a second identifier I20. The management server 1 may identify the data correspondence based on the match between the combination of identifiers (I10, I20) contained in the data received from the first terminal 4 and the combination of identifiers (I10, I20) contained in the data received from the second terminal 5. In another example, the shared information may consist of temporary information such as random numbers, timestamps, and hash values. In this case, the management server 1 may identify the data correspondence based on the existence of a relationship between the temporary information contained in the data received from the first terminal 4 and the temporary information contained in the data received from the second terminal 5. The shared information may be shared between the first terminal 4 and the second terminal 5 at any time. In a typical example, the first terminal 4 and the second terminal 5 may share the shared information when exchanging data.
[0183] In step S25, the control unit 11 of the management server 1 operates as a setting unit 112 and, upon receiving the setting of correspondence relationships based on two or more linking requests for the same individual of the first target VA, determines whether or not two or more correspondence relationships can be established for the same individual of the first target VA with two or more different individuals of the second target WA. In one example, the control unit 11 refers to the linking information D10 to determine whether or not there is an active existing linking setting with other individuals of the second target WA for the individual of the first target VA specified in the received linking request. If there is no active existing linking setting with other individuals of the second target WA, the control unit 11 proceeds to step S301. On the other hand, if there is an active existing linking setting, the control unit 11 proceeds to step S302.
[0184] In step S301, the control unit 11 operates as a setting unit 112 and updates the linking information D10 to establish a new active correspondence between the corresponding individuals of the first target VA and second target WA specified by the linking request, or to change the state of an existing correspondence to active. Updating the linking information D10 to establish a new correspondence may be done by generating the corresponding new linking information D10. Updating the linking information D10 to change the state of a correspondence to active may be done by recording information indicating the change to active. For example, if the linking information D10 has the configuration shown in Figure 3A, the control unit 11 may change the state of the correspondence to active by storing a value indicating active in the state field of the corresponding linking information D10. If the linking information D10 is configured on a blockchain base, the control unit 11 may change the state of the correspondence to active by generating a transaction indicating the change of the correspondence to active and adding the generated transaction to the blockchain. After updating the linking information D10, the control unit 11 proceeds to the next step S40.
[0185] Meanwhile, in step S302, the control unit 11 operates as a setting unit 112 and acquires status information ST10. The control unit 11 updates the linking information D10 to activate one correspondence setting and deactivate the other correspondence settings according to the status information ST10. In one example of this embodiment, at least one of the above three methods may be used to select the active correspondence. Updating the linking information D10 for establishing a new correspondence setting and changing the state of an existing correspondence to active may be the same as described above. Updating the linking information D10 for changing the state of a correspondence to deactivate may be done by recording information indicating the change to deactivate. In one example, if the linking information D10 has the configuration shown in Figure 3A, the control unit 11 may change the state of the correspondence to deactivate by storing a value indicating deactivation in the state field of the corresponding linking information D10. If the linking information D10 is configured on a blockchain platform, the control unit 11 may change the state of the correspondence to inactive by generating a transaction indicating a change to inactive and adding the generated transaction to the blockchain. After updating the linking information D10, the control unit 11 proceeds to the next step S40. Note that the processing in steps S301 and S302 is an example of the correspondence setting process (step S30 above) in response to the received linking request.
[0186] In step S40, the control unit 11 operates as a notification unit 114 and directly or indirectly sends a notification to at least one of the first terminal 4 and the second terminal 5 indicating the result of the correspondence setting process. Once the notification of the result is complete, the processing procedure for linking settings related to this example of operation is terminated.
[0187] The above processing procedure is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. For example, the linking setting process may include authentication processing for at least one of the first target VA and the second target WA.
[0188] (Unlink) Figure 13 shows an example of the unlinking process procedure by the system 100 according to this embodiment. The following processing procedure is an example of an information processing method executed by a computer. Of the following processing procedures, the processing procedure of the management server 1 is an example of a management method executed by a computer. Note that the example in Figure 13 assumes a scenario in which a release request is sent directly from the first terminal 4 to the management server 1.
[0189] In step SZ10, the control unit 41 of the first terminal 4 operates as a release request unit 413 and sends a release request for the corresponding relationship to the management server 1. In response, the control unit 11 of the management server 1 receives the release request. The corresponding relationship for which release is requested may be specified as appropriate. The trigger for the release request may be selected as appropriate depending on the embodiment.
[0190] In step SZ20, the control unit 11 operates as a release unit 113 and releases (deactivates) the correspondence setting specified by the received release request or changes the state of the correspondence from active to inactive. Updating the linking information D10 in response to the change to inactive may be the same as described above. Updating the linking information D10 in response to releasing (deactivating) the correspondence may consist of recording information indicating that it has been released. For example, if the linking information D10 has the configuration shown in Figure 3A, the control unit 11 may release the target correspondence by adding a release time to the corresponding linking information D10 or by setting a release flag. If the linking information D10 is configured on a blockchain base, the control unit 11 may release the target correspondence by generating a transaction indicating the release and adding the generated transaction to the blockchain.
[0191] In step SZ30, the control unit 11 operates as a notification unit 114 and transmits the result of the unlinking process to the first terminal 4. Once the notification of the result is complete, the processing procedure for unlinking related to this example operation is terminated.
[0192] The above processing procedure is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. For example, as described above, the transmission route for the release request is not limited to the example in Figure 13, and may be appropriately selected depending on the embodiment. The release request may also be transmitted from the second terminal 5 (release request unit 513). The processing of the release request may include authentication processing for at least one of the first target VA and the second target WA. In addition, the control unit 11 of the management server 1 may operate as a release unit 113 instead of step SZ20, and release the correspondence when a predetermined release condition is met.
[0193] [Features] In this embodiment, the processing in step S30 (steps S301 and S302) records information indicating the setting of the correspondence between the relevant individuals of the first target VA and the second target WA. This record makes it possible to track the usage relationship between the relevant individuals of the first target VA and the second target WA. In addition, in this embodiment, it is permitted to set up a link between one individual of the first target VA and multiple individuals of the second target WA. If a conflict occurs in the linking settings for a relevant individual of the first target VA due to the establishment of multiple linking settings, the conflict is mediated by switching the state of the linking settings through the processing in steps S25 and S302. This makes it possible to properly track the usage relationship for the relevant individual of the first target VA. Therefore, in this embodiment, in at least some situations, it is possible to respond to the occurrence and termination of usage relationships by switching the state without repeatedly setting and unlinking the links. Thus, it is possible to easily track the usage relationship between the first target VA and the second target WA.
[0194] [4. Variant] While embodiments of this disclosure have been described in detail above, the above description is merely illustrative in all respects of this disclosure. It goes without saying that various improvements or modifications can be made without departing from the scope of this disclosure. For example, the following modifications are possible. In the following, the same reference numerals are used for components similar to those in the above embodiments, and explanations of points similar to those in the above embodiments have been omitted as appropriate. The following modifications can be combined as appropriate.
[0195] <4.1> In the above embodiment, authentication processing for the first target VA and the second target WA may be performed at least when linking or unlinking. The authentication processing may be performed at least one of the management server 1, external servers (first server 2, second server 3, etc.), and each terminal (4, 5). As an example, at least one of the following four authentication methods may be adopted.
[0196] (A) First authentication method Figure 14 schematically shows an example of the linking setting process when the first authentication method is adopted. In the first authentication method, the second server 3 performs authentication of the second target WA in response to a request from the first terminal 4 of the first target VA, and the first server 2 performs authentication of the first target VA in response to a request from the second terminal 5 of the second target WA. Each terminal (4, 5) requests authentication from each server (2, 3) as a linking request and has the authentication results reported to the management server 1. As a result, each terminal (4, 5) sends a linking request to the management server 1.
[0197] The first server 2 is configured to access a first storage device that stores the first registered unique information CA10 for the authentication of the first target VA. The first storage device may consist of at least one of the memory resources of the first server 2 and an external storage device (such as a NAS). The first registered unique information CA10 may be included in the first target information O10. The second server 3 is configured to access a second storage device that stores the second registered unique information CA20 for the authentication of the second target WA. The second storage device may consist of at least one of the memory resources of the second server 3 and an external storage device (such as a NAS). The second registered unique information CA20 may be included in the second target information O20.
[0198] Each registered unique information (CA10, CA20) is unique information that has been registered in advance for the authentication of each target (VA, WA). The data format and structure of the unique information are not particularly limited as long as they can be used for authentication, and may be appropriately selected depending on the embodiment. The unique information may consist of arbitrary information such as information originating from the target, information originating from the terminal, temporarily generated information, and information generated by any other method.
[0199] Information originating from the target may include, for example, biometric information, uniquely assigned identification information, etc. Biometric information may include, for example, facial images, fingerprints, voiceprints, etc. Uniquely assigned identification information may include, for example, vehicle registration numbers, vehicle identification numbers, personal identification numbers, etc. If an IC tag is attached to the target, the uniquely assigned identification information may include the information held by the IC tag. Information originating from the terminal may include, for example, MAC addresses, terminal identification information, etc. Temporarily generated information may include, for example, one-time passwords, private addresses (dynamically generated addresses), etc. Temporarily generated information may consist of timestamps, random numbers, hash values, etc. Information generated by any other method may include, for example, passwords, passcodes, and other information other than sequences of symbols.
[0200] First, when a usage relationship occurs between the relevant individuals of the first target VA and the second target WA, data exchange is performed between the corresponding first terminal 4 and second terminal 5 (steps SA110, SB110).
[0201] In step SA110, the second terminal 5 obtains the first identifier I10 and the first unique information CA1 from the corresponding individual of the first target VA. The first unique information CA1 corresponds to the first registered unique information CA10. The second terminal 5 may, as appropriate, obtain the first identifier I10 and the first unique information CA1 from the first target VA during data exchange. Obtaining from the first target VA may include obtaining from the first terminal 4. For example, the second terminal 5 may obtain at least one of the first identifier I10 and the first unique information CA1 from the first target VA via an input device, sensor, etc. The second terminal 5 may, as appropriate, obtain the first identifier I10 and the first unique information At least one of the CA1s may be obtained from the first terminal 4.
[0202] Furthermore, in step SB110, the first terminal 4 obtains the second identifier I20 and the second unique information CA2 from the corresponding individual of the second target WA. The second unique information CA2 corresponds to the second registered unique information CA20. The first terminal 4 may, as appropriate, obtain the second identifier I20 and the second unique information CA2 from the second target WA during data exchange. Obtaining from the second target WA may include obtaining from the second terminal 5. For example, the first terminal 4 may obtain at least one of the second identifier I20 and the second unique information CA2 from the second target WA via an input device, sensor, etc. The first terminal 4 may also obtain at least one of the second identifier I20 and the second unique information CA2 from the second terminal 5 during data exchange.
[0203] In step SA120, the second terminal 5 sends a first authentication request to the first server 2, which includes the first identifier I10 and the first unique information CA1. In response, the first server 2 receives the first authentication request for the corresponding individual of the first target VA. Upon receiving the first authentication request, the first server 2 appropriately performs the authentication process for the first target VA. For example, the first server 2 may use the first identifier I10 included in the first authentication request as a query to search for the first target information O10, thereby extracting the first registered unique information CA10 for the corresponding individual of the first target VA from the first target information O10. The first server 2 may compare the extracted first registered unique information CA10 with the first unique information CA1 included in the first authentication request. The comparison may be performed appropriately depending on the unique information used. The first server 2 may determine whether authentication for the corresponding individual of the first target VA is successful or not based on the result of the comparison. In step SA130, the first server 2 reports the authentication result for the relevant individual of the first target VA to the management server 1. In one example, the first server 2 may send the authentication result of the first target VA to the management server 1, along with the first identifier I10 of the first target VA. The first server 2 may send the authentication result to the management server 1 regardless of whether the authentication was successful or not, or it may send the authentication result to the management server 1 only if the authentication is successful.
[0204] Meanwhile, in step SB120, the first terminal 4 sends a second authentication request to the second server 3, which includes the second identifier I20 and the second unique information CA2. In response, the second server 3 receives the second authentication request for the corresponding individual of the second target WA. Upon receiving the second authentication request, the second server 3 appropriately performs the authentication process for the second target WA. For example, the second server 3 may use the second identifier I20 included in the second authentication request as a query to search for the second target information O20, thereby extracting the second registered unique information CA20 for the corresponding individual of the second target WA from the second target information O20. The second server 3 may compare the extracted second registered unique information CA20 with the second unique information CA2 included in the second authentication request. The comparison may be performed appropriately depending on the unique information used. The second server 3 may determine whether authentication for the corresponding individual of the second target WA is successful or not based on the result of the comparison. In step SB130, the second server 3 reports the authentication result for the corresponding individual of the second target WA to the management server 1. In one example, the second server 3 may send the authentication result of the second target WA to the management server 1, along with the second identifier I20 of the second target WA. The second server 3 may send the authentication result to the management server 1 regardless of whether the authentication was successful or not, or it may send the authentication result to the management server 1 only if the authentication is successful.
[0205] One example of the second terminal 5 sending a linking request to the management server 1 is when the second terminal 5 sends a first authentication request to the first server 2 and has the first server 2 send the authentication result to the management server 1. Similarly, one example of the first terminal 4 sending a linking request to the management server 1 is when the first terminal 4 sends a second authentication request to the second server 3 and has the second server 3 send the authentication result to the management server 1. In other words, when the first authentication method is adopted during the linking setup, the processing in steps SA120, SA130, SB120, and SB130 is an example of the processing in step S10.
[0206] Management server 1 receives recognition from each server (2, 3) for the corresponding individual target (VA, WA). The authentication result is received. The management server 1 may identify the matching of authentication result data by using the shared information mentioned above, or by other means, in order to identify the combination of the first target VA and second target WA that are currently requesting the setting of a correspondence relationship. If the authentication results of the first target VA and second target WA received by the management server 1 show that both the first target VA and the second target WA have been successfully authenticated, the management server 1 sets a correspondence relationship between the corresponding individuals of the first target VA and the second target WA. The process for setting the correspondence relationship may be the same as in the above embodiment. Note that the series of processes from data exchange between terminals (4, 5) to the setting of the association may be executed in real time in response to the occurrence of a usage relationship.
[0207] In the first authentication method, when a usage relationship is established between the relevant individuals of the first target VA and the second target WA, authentication is performed on the first server 2 and the second server 3, respectively, for each of the relevant individuals of the first target VA and the second target WA. At this time, authentication of the first target VA is requested from the second terminal 5 of the second target WA. Authentication of the second target WA is requested from the first terminal 4 of the first target VA. In other words, cross-authentication is performed, where each device proceeds with the authentication of the other, rather than proceeding with its own authentication. This is expected to ensure security.
[0208] Note that the processing procedure in Figure 14 is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. For example, the processing order of steps SA110 to SA130 and steps SB110 to SB130 is not particularly limited and may be determined as appropriate depending on the embodiment. At least one of the authentication processing for the first target VA (steps SA110 to SA130) and the authentication processing for the second target WA (steps SB110 to SB130) may be omitted.
[0209] (B) Second authentication method Figure 15 schematically shows an example of the linking setting process when the second authentication method is adopted. In the second authentication method, the management server 1 requests authentication from each server (2, 3) in response to a request from at least one of the first terminal 4 and the second terminal 5. That is, at least one of the first terminal 4 and the second terminal 5 sends a linking request that includes an authentication request for each target (VA, WA). The data (unique information) used for authentication is the same as in the first authentication method.
[0210] First, when a usage relationship is established between the corresponding individuals of the first target VA and the second target WA, data exchange is performed between the corresponding first terminal 4 and second terminal 5 (steps SC110, SD110). At least one of the first terminal 4 and the second terminal 5 sends an authentication request to the management server 1 as a linking request, which includes the first identifier I10, the first unique information CA1, the second identifier I20, and the second unique information CA2 (steps SC120, SD120). In response, the management server 1 receives the authentication request which includes the first identifier I10, the first unique information CA1, the second identifier I20, and the second unique information CA2. The processing in steps SC120 and SD120 is an example of the processing in step S10 described above.
[0211] The distribution of data transmission may be determined as appropriate depending on the embodiment. For example, the second terminal 5 may be responsible for transmitting the first identifier I10 and the first unique information CA1, and the first terminal 4 may be responsible for transmitting the second identifier I20 and the second unique information CA2. That is, in step SC110, the second terminal 5 may obtain the first identifier I10 and the first unique information CA1 from the first target VA. Obtaining from the first target VA may include obtaining from the first terminal 4. In step SC120, the second terminal 5 may send a linking request including the obtained first identifier I10 and the first unique information CA1 to the management server 1. In step SD110, the first terminal 4 may obtain the second identifier I20 and the second unique information CA2 from the second target WA. Obtaining from the second target WA may include obtaining from the second terminal 5. In step SD120, the first terminal 4 includes the obtained second identifier I20 and the second unique information CA2 You may send a linking request to the management server 1.
[0212] The distribution of data transmission is not limited to this example. In another example, at least one of the first identifier I10 and the first unique information CA1 may be transmitted from the first terminal 4. At least one of the second identifier I20 and the second unique information CA2 may be transmitted from the second terminal 5. When a divided transmission configuration is adopted, the management server 1 may identify the matching of authentication request data by using the shared information mentioned above or by other means to identify the corresponding combination of the first target VA and second target WA that are currently requesting the setting of the correspondence relationship. In yet another example, the first identifier I10, the first unique information CA1, the second identifier I20, and the second unique information CA2 may be transmitted from only one of the first terminal 4 and the second terminal 5.
[0213] In step SC130, the management server 1 sends the first identifier I10 and the first unique information CA1 from the received data to the first server 2, requesting the first server 2 to authenticate the corresponding individual of the first target VA. In response, the first server 2 may compare the first unique information CA1 and the first registered unique information CA10, and determine whether the authentication for the corresponding individual of the first target VA was successful or not based on the result of the comparison. In step SC140, the first server 2 returns the authentication result for the corresponding individual of the first target VA to the management server 1.
[0214] Similarly, in step SD130, the management server 1 requests the second server 3 to authenticate the corresponding individual of the second target WA by sending the second identifier I20 and the second unique information CA2. In response, the second server 3 may compare the second unique information CA2 and the second registered unique information CA20, and determine whether the authentication for the corresponding individual of the second target WA is successful or not based on the result of the comparison. In step SD140, the second server 3 sends the authentication result for the corresponding individual of the second target WA to the management server 1.
[0215] Management server 1 receives authentication results for the corresponding individuals of each target (VA, WA) from each server (2, 3). If the authentication results for the first target VA and second target WA received by management server 1 show that both authentication for the first target VA and second target WA is successful, management server 1 sets up a correspondence between the corresponding individuals of the first target VA and second target WA. The process for setting up the correspondence may be the same as in the above embodiment. Note that the series of processes from data exchange between terminals (4, 5) to linking may be executed in real time as usage relationships occur. Other configurations may be the same as in the first authentication method.
[0216] In the second authentication method, when a usage relationship is established between the relevant individuals of the first target VA and the second target WA, authentication is performed on both the first server 2 and the second server 3, respectively. These two authentication methods are expected to ensure security.
[0217] Note that the processing procedure in Figure 15 is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. For example, the processing order of steps SC110 to SC140 and steps SD110 to SD140 is not particularly limited and may be determined as appropriate depending on the embodiment. At least one of the authentication processing for the first target VA (steps SC110 to SC140) and the authentication processing for the second target WA (steps SD110 to SD140) may be omitted.
[0218] (C-1) Authentication method of Section 3-1 Figure 16 schematically shows an example of the linking setting process when adopting the authentication method described in Section 3-1. The authentication method described in Section 3-1 uses a time-limited certificate for authentication instead of unique information. The authentication process is performed by the management server 1.
[0219] The first server 2 is configured to issue the first time-limited certificate CB10 to each individual of the first target VA. The second server 3 is configured to issue the second time-limited certificate CB20 to each individual of the second target WA.
[0220] Each time-limited certificate (CB10, CB20) is configured to expire after its validity period. The configuration of each time-limited certificate (CB10, CB20) is not particularly limited and may be appropriately selected depending on the embodiment, as long as the expiration due to the expiration of the validity period can be controlled. Each time-limited certificate (CB10, CB20) may contain arbitrary information. For example, each time-limited certificate (CB10, CB20) may be composed of random numbers, timestamps, hash values, etc. Each time-limited certificate (CB10, CB20) may be composed of temporary information such as a one-time password.
[0221] The validity period of each time-limited certificate (CB10, CB20) may be managed as appropriate. Expiration due to the expiration of the validity period may be identified as appropriate. For example, whether or not a time-limited certificate has expired may be identified by the expiration of the deadline set for the time-limited certificate, the addition of the time-limited certificate to the revocation list, the removal of the time-limited certificate from the valid list, the renewal with a new time-limited certificate, or the addition of information indicating revocation (e.g., a timestamp). When reference information such as the revocation list and valid list is used for managing the validity period, the reference information may be stored in any storage device accessible from system 100. Typically, the reference information for each time-limited certificate (CB10, CB20) may be stored on each server (2, 3).
[0222] First, in step SE110, the first terminal 4 of the first target VA sends a request to the first server 2 for the issuance of the first time-limited certificate CB10, relating to the first identifier I10 of the first target VA. Upon receiving the request, the first server 2 issues the first time-limited certificate CB10 relating to the first identifier I10. In step SE120, the first server 2 returns the issued first time-limited certificate CB10 to the first terminal 4. In response, the first terminal 4 receives the issued first time-limited certificate CB10 from the first server 2. The first terminal 4 stores the received first time-limited certificate CB10 as the first certificate CB1 for use. Also, in step SE130, the first server 2 notifies the management server 1 of the issued first time-limited certificate CB10. The first server 2 may also notify the first time-limited certificate CB10 with the first identifier I10 attached.
[0223] In step SF110, the second terminal 5 of the second target WA sends a request to the second server 3 for the issuance of the second time-limited certificate CB20, relating to the second identifier I20 of the second target WA. Upon receiving the request, the second server 3 issues the second time-limited certificate CB20 relating to the second identifier I20. In step SF120, the second server 3 returns the issued second time-limited certificate CB20 to the second terminal 5. In response, the second terminal 5 receives the issued second time-limited certificate CB20 from the second server 3. The second terminal 5 stores the received second time-limited certificate CB20 as usable second certificate CB2. Also, in step SF130, the second server 3 notifies the management server 1 of the issued second time-limited certificate CB20. The second server 3 may also notify the management server 1 of the second time-limited certificate CB20 with the second identifier I20 attached.
[0224] When a usage relationship is established between the corresponding individuals of the first target VA and the second target WA, data exchange is performed between the corresponding first terminal 4 and second terminal 5 (steps SE140, SF140). At least one of the first terminal 4 and the second terminal 5 sends an authentication request to the management server 1 as a linking request, which includes the first certificate CB1 and the second certificate CB2 (steps SE150, SF150). In response, the management server 1 receives the first certificate CB1 corresponding to the first time-limited certificate CB10 and the second certificate CB2 corresponding to the second time-limited certificate CB20. The processing in steps SE150 and SF150 is an example of the processing in step S10 described above.
[0225] The distribution of data transmission may be determined as appropriate depending on the embodiment. For example, the second terminal 5 may be responsible for transmitting the first certificate CB1, and the first terminal 4 may be responsible for transmitting the second certificate CB2. That is, in step SE140, the second terminal 5 may obtain the first certificate CB1 from the first terminal 4. In step SE150, the second terminal 5 may send a linking request including the first certificate CB1 to the management server 1. In step SF140, the first terminal 4 may obtain the second certificate CB2 from the second terminal 5. In step SF150, the first terminal 4 may send a linking request including the second certificate CB2 to the management server 1.
[0226] Note that the distribution of data transmission is not limited to this example. In another example, the first certificate CB1 may be sent from the first terminal 4. The second certificate CB2 may be sent from the second terminal 5. In addition, each identifier (I10, I20) may be sent to the management server 1 along with each certificate (CB1, CB2). Each identifier (I10, I20) may be sent from at least one of the first terminal 4 and the second terminal 5. When adopting a split transmission method, the management server 1 may identify the matching of authentication request data by using the shared information mentioned above or by other means to identify the corresponding combination of the first target VA and second target WA that are currently requesting the setting of the correspondence relationship. In yet another example, the first certificate CB1 and the second certificate CB2 may be sent from only one of the first terminal 4 and the second terminal 5.
[0227] Management Server 1 compares the received first certificate CB1 with the first time-limited certificate CB10 notified by the first server 2. Management Server 1 also compares the received second certificate CB2 with the second time-limited certificate CB20 notified by the second server 3. Management Server 1 may appropriately identify the mapping of the data to be compared. Identifying the mapping of the data to be compared means determining the combination of the first time-limited certificate CB10 and the first certificate CB1, and the combination of the second time-limited certificate CB20 and the second certificate CB2. Similar to the mapping of authentication request data, Management Server 1 may identify the mapping of the data to be compared by using the shared information mentioned above. The shared information may be the respective identifiers (I10, I20).
[0228] Furthermore, the method for matching certificates and time-limited certificates may be appropriately selected depending on the relationship between them. For example, time-limited certificates (CB10, CB20) may be used as certificates (CB1, CB2) as they are. In this case, the success or failure of the matching in authentication may be determined based on whether or not the time-limited certificates (CB10, CB20) and certificates (CB1, CB2) match. In another example, time-limited certificates (CB10, CB20) may be arbitrarily converted, and the converted time-limited certificates (CB10, CB20) may be used as certificates (CB1, CB2). In this case, the success or failure of the matching in authentication may be determined based on whether or not a predetermined relationship is established between the time-limited certificates (CB10, CB20) and certificates (CB1, CB2). For example, the first time-limited certificate CB10 may be converted into a hash value, and the resulting hash value may be used as the first certificate CB1. Accordingly, whether or not a relationship is established may be determined by whether or not the hash value of the first time-limited certificate CB10 matches that of the first certificate CB1. The conversion may include data operations such as deletion and addition. At least one of the first time-limited certificate CB10 and the second time-limited certificate CB20 may be used as a certificate as is, and the other may be used as a certificate after conversion. The conversion process may be performed at each terminal (4, 5) or at each server (2, 3). If the conversion process is performed at each server (2, 3), each terminal (4, 5) may receive the converted time-limited certificates (CB10, CB20) from each server (2, 3).
[0229] Management Server 1 may determine the success or failure of authentication for each target (VA, WA) based on the results of each matching. If the matching fails, authentication fails. If the first time-limited certificate CB10 / second time-limited certificate CB20 has expired due to the expiration of its validity period, the matching of the first target VA / second target WA will fail. On the other hand, the first time-limited certificate CB10 and If the two-time certificate CB20 is valid and each verification is successful, authentication of both the first target VA and the second target WA is successful. If authentication of both the first target VA and the second target WA is successful, the management server 1 sets up a correspondence between the corresponding individuals of the first target VA and the second target WA. The process for setting up the correspondence may be the same as in the above embodiment. Note that the series of processes from data exchange between terminals (4, 5) to linking may be executed in real time in response to the occurrence of a usage relationship. Other configurations may be the same as in the first authentication method, etc.
[0230] In method 3-1, authentication of the first target VA and the second target WA is performed using time-limited certificates (CB10, CB20) in response to the establishment of a usage relationship between the relevant individuals of the first target VA and the second target WA. Each time-limited certificate (CB10, CB20) is configured to expire after its validity period. Therefore, it is possible to prevent the permanent use of the same certificate, thereby ensuring security.
[0231] Note that the processing procedure in Figure 16 is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. For example, the processing order of steps SE110 to SE150 and steps SF110 to SF150 is not particularly limited and may be determined as appropriate depending on the embodiment. At least one of the authentication processing for the first target VA (steps SE110 to SE150) and the authentication processing for the second target WA (steps SF110 to SF150) may be omitted.
[0232] Furthermore, the issuance of each time-limited certificate (CB10, CB20) does not necessarily have to be based on a request from each terminal (4, 5). Each server (2, 3) may generate each time-limited certificate (CB10, CB20) on its own initiative. In this case, the processing in steps SE110 and SF110 may be omitted.
[0233] Furthermore, the issuance of each time-limited certificate (CB10, CB20) (steps SE110 to SE130, steps SF110 to SF130) may be performed at any time before the request for linking settings (steps SE150, SF150). For example, the issuance of each time-limited certificate (CB10, CB20) may be performed in advance before the data exchange between the first terminal 4 and the second terminal 5 is performed (steps SE140, SF140). In another example, it may be performed after the data exchange between the first terminal 4 and the second terminal 5 has started, but before the linking request is sent. From the viewpoint of reducing the steps involved in linking settings, it is preferable that the issuance of each time-limited certificate (CB10, CB20) be performed at the former timing.
[0234] Furthermore, in the authentication method described in Section 3-1 above, the matching process for each certificate (CB1, CB2) and each time-limited certificate (CB10, CB20), i.e., the authentication process for each target (VA, WA), is performed by the management server 1. However, the entity that performs the matching process is not limited to the management server 1. In another example, the management server 1 may request each server (2, 3) to perform the matching process by sending each certificate (CB1, CB2) to each server (2, 3). In this case, the matching process may be performed by each server (2, 3).
[0235] (C-2) Authentication method of Section 3-2 In the authentication method described in Section 3-1 above, authentication processing for each target (VA, WA) is performed in response to a linking request from at least one of the first terminal 4 and the second terminal 5. However, the timing of the execution of the authentication processing is not limited to this example. In the authentication method described in Section 3-2, before sending the linking request to the management server 1, authentication processing for at least one of the first target VA and the second target WA may be performed in advance by at least one of the first terminal 4 and the second terminal 5 between at least one of the first server 2 and the second server 3.
[0236] Figure 17A schematically shows an example of the linking setting process when adopting the authentication method described in Section 3-2. In the example in Figure 17A, we assume a scenario in which the authentication process for the first target VA is performed, and the authentication process for the second target WA is omitted.
[0237] First, the processes in steps SE110 and SE120 may be executed between the first terminal 4 and the first server 2 in the same manner as the authentication method described in Section 3-1 above. As a result of the execution, the first time-limited certificate CB10 is issued, and the issued first time-limited certificate CB10 is notified to the first terminal 4. At this time, the first server 2 may store the issued first time-limited certificate CB10 in association with the first identifier I10. The first time-limited certificate CB10 may also be stored as the first target information O10. Notification to the management server 1 (step SE130) may be omitted. In step SE140, the first terminal 4 provides the issued first time-limited certificate CB10 to the second terminal 5 as the first certificate CB1. The first terminal 4 also provides the first identifier I10 to the second terminal 5. In response, the second terminal 5 obtains the first identifier I10 and the first certificate CB1 from the first target VA.
[0238] In step SG110, the second terminal 5 sends an authentication request to the first server 2, which includes the first identifier I10 and the first certificate CB1. Upon receiving the authentication request, the first server 2 compares the received first certificate CB1 with the corresponding first time-limited certificate CB10. The corresponding first time-limited certificate CB10 may be obtained as appropriate. For example, the issued first time-limited certificate CB10 may be stored as first target information O10, and the first server 2 may extract the corresponding first time-limited certificate CB10 by searching the first target information O10 using the first identifier I10 as a query. In step SG120, the first server 2 returns the result of the comparison to the second terminal 5. In response, the control unit 51 of the second terminal 5 receives the result of the comparison.
[0239] If the received verification results show that the first certificate CB1 and the first time-limited certificate CB10 have failed to verify, the second terminal 5 may terminate the linking setting process as appropriate. The second terminal 5 may also request the first terminal 4 to resend the first certificate CB1. On the other hand, if the verification is successful, the second terminal 5 sends a linking request including the first identifier I10 and the second identifier I20 to the management server 1 (step SG130). The processing in step SG130 is an example of the processing in step S10 described above.
[0240] In response, the management server 1 receives a linking request from the second terminal 5. In response to the linking request, the management server 1 sets up a correspondence between the relevant individuals of the first target VA and the second target WA. The process for setting up the correspondence may be the same as in the above embodiment. Note that the series of processes from data exchange between terminals (4, 5) (step SE140) to linking setting may be executed in real time as a usage relationship occurs. Other configurations may be the same as in the first authentication method, etc.
[0241] Note that the processing procedure shown in Figure 17A is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure can be omitted, replaced, or added as appropriate.
[0242] For example, management server 1 may appropriately verify that the matching was successful at first server 2. In one example, first server 2 may also send the matching result to management server 1. For example, the authentication request may further include a second identifier I20. If the matching is successful, first server 2 may send the matching result, including the first identifier I10 and the second identifier I20, to management server 1. This allows first server 2 to activate a linking request to management server 1 for the combination of first identifier I10 and second identifier I20 specified in the matching result. In other words, in one example, verification of successful matching is performed by receiving this matching result. This may be done. Management server 1 may be configured to hold the results of the matching from first server 2, accept requests for association settings for the combination of first identifier I10 and second identifier I20 specified in the matching results, and reject other requests for association settings.
[0243] Furthermore, in the authentication method of Section 3-2, the target of authentication is not limited to the first target VA. In another example, the authentication process for the second target WA may be performed instead of the authentication process for the first target VA. In yet another example, the authentication process for the second target WA may be performed together with the authentication process for the first target VA.
[0244] Figure 17B schematically shows another example of the linking setting process when adopting the authentication method of Section 3-2. In the example of Figure 17B, a scenario is assumed in which the authentication process of the second target WA is performed instead of the authentication process of the first target VA. Except for the fact that the first target VA and the second target WA are swapped, the processing procedure in Figure 17B may be the same as the processing procedure in Figure 17A. That is, the processes of steps SF110 and SF120 are executed between the second terminal 5 and the second server 3, and the second time-limited certificate CB20 is issued, and the issued second time-limited certificate CB20 is notified to the second terminal 5. In step SF140, the second terminal 5 provides the issued second time-limited certificate CB20 as the second certificate CB2 to the first terminal 4. The second terminal 5 also provides the second identifier I20 to the first terminal 4. In step SH110, the first terminal 4 sends an authentication request to the second server 3, including the second identifier I20 and the second certificate CB2. In response, the second server 3 performs a verification process for the second certificate CB2 and the second time-limited certificate CB20. In step SH120, the second server 3 returns the verification result to the first terminal 4. If the verification result shows that the second certificate CB2 and the second time-limited certificate CB20 have been verified, the first terminal 4 sends a linking request to the management server 1, including the first identifier I10 and the second identifier I20 (step SH130). In response, the management server 1 receives the linking request from the first terminal 4. In response to the linking request, the management server 1 sets up a correspondence between the corresponding individuals of the first target VA and the second target WA. In another example, the authentication process for the first target VA and the second target WA may be performed by executing the series of processes shown in Figures 17A and 17B.
[0245] In the authentication method described in section 3-2, the authentication process is performed before the linking request. This reduces the processing load on the management server 1. It also shortens the processing time from the linking request to the configuration process.
[0246] (D) Fourth Authentication Method FIG. 18A schematically shows an example of the processing procedure of the association setting when adopting the fourth authentication method. The fourth authentication method uses an electronic signature with a private key and an electronic certificate. The authentication process is executed by the terminal of the partner to be authenticated. The terminal of the partner to be authenticated is the second terminal 5 when authenticating the first target VA, and the first terminal 4 when authenticating the second target WA. In the example of FIG. 18A, the authentication process of the second target WA is omitted, and the scenario of executing the authentication process of the first target VA is assumed.
[0247] As a preparation stage (preprocessing), a combination of the first private key CC10 and the first public key used for authenticating the first target VA is generated. The method for generating the first private key CC10 and the first public key is not particularly limited and may be appropriately selected according to the embodiment. The first private key CC10 and the first public key may be generated by at least one of the first terminal 4 and an external computer (the first server 2, a certification authority, etc.).
[0248] Next, a first electronic certificate CC1 for the first public key is generated by the certification authority. In one example, the certification authority may generate the first electronic certificate CC1 in response to a request from the first terminal 4. The certification authority may be the first server 2 or an external server other than the first server 2. If the authenticity of the first public key can be verified, the configuration of the first electronic certificate CC1 is not particularly limited and may be appropriately selected according to the embodiment. In one example, the first electronic certificate CC1 may be composed of an electronic signature by the certification authority, ownership information, and the first public key. The certification authority holds a combination of a public key and a private key. The electronic signature by the certification authority may be generated by encrypting the ownership information and the first public key with the private key of the certification authority. In a specific example, the electronic signature by the certification authority may be generated by converting the ownership information and the first public key into a hash value by a hash function and encrypting the obtained hash value with the private key of the certification authority.
[0249] The first digital certificate CC1 is provided to the first terminal 4 by the certification authority. The first digital certificate CC1 may also be stored in any storage area. The expiration date of the first digital certificate CC1 may be managed by a revocation list. The revocation list may also be stored in any storage area. The first digital certificate CC1 and the revocation list may be stored on the first server 2, or on an external server accessible from the first server 2. When the first terminal 4 has the first private key CC10 and the first digital certificate CC1, preparation for the authentication process of the first target VA is complete.
[0250] During the usage phase, when a usage relationship is established between the relevant individuals of the first target VA and the second target WA, data exchange is performed between the corresponding first terminal 4 and second terminal 5 (steps SI110, SI120). In this data exchange, electronic information is shared between the first terminal 4 and the second terminal 5. The electronic information may consist of arbitrary information such as random numbers and timestamps. The electronic information may also include information originating from the first target VA, such as the owner information of the first terminal 4.
[0251] The electronic information may be generated by at least one of the first terminal 4 and the second terminal 5. If the second terminal 5 is involved in the generation of at least a portion of the electronic information, as part of the processing in step SI110, data relating to the electronic information may be provided from the second terminal 5 to the first terminal 4. The first terminal 4 generates the digital signature CD1 by encrypting the first identifier I10 and the electronic information using the first secret key CC10. In a specific example, the first terminal 4 may generate the digital signature CD1 by converting the first identifier I10 and the electronic information into a hash value using a hash function, and then encrypting the resulting hash value with the first secret key CC10.
[0252] In step SI120, the first terminal 4 provides the first identifier I10, the generated digital signature CD1, and the first digital certificate CC1 to the second terminal 5. As a result, the second terminal 5 obtains the first identifier I10, the digital signature CD1, and the first digital certificate CC1 from the first terminal 4. If the first terminal 4 is involved in the generation of at least a part of the electronic information, such as information originating from the first target VA, then as part of the processing in step SI120, data relating to the electronic information may be provided from the first terminal 4 to the second terminal 5.
[0253] Next, the second terminal 5 verifies the validity of the first digital certificate CC1 (steps SI130 and SI135). In the example in Figure 18A, it is assumed that the first server 2 maintains a revocation list. In step SI130, the second terminal 5 queries the first server 2 to determine whether the first digital certificate CC1 is valid. If the first digital certificate CC1 is not registered in the revocation list, it is determined that the first digital certificate CC1 is valid (i.e., its expiration date has not passed). If the first digital certificate CC1 is registered in the revocation list, it is determined that the first digital certificate CC1 is not valid. The first server 2 refers to the revocation list and determines whether the first digital certificate CC1 is valid. In step SI135, the first server 2 returns the determination result to the second terminal 5. The second terminal 5 may also query the first server 2 to determine whether the first identifier I10 is valid. Furthermore, if the revocation list is maintained on an external server, the second terminal 5 may query the external server directly or indirectly (for example, via the first server 2) whether the first digital certificate CC1 is valid. In another example, the second terminal 5 may obtain a revocation list and, by referring to the obtained revocation list, determine whether the first digital certificate CC1 is valid or not. If the first digital certificate CC1 is not valid (i.e., has expired), the second terminal 5 may determine that the verification of the validity of the first digital certificate CC1 is unsuccessful and terminate the linking setting process as appropriate. The second terminal 5 may also request the first terminal 4 to resend the series of information. On the other hand, if the first digital certificate CC1 is valid, the second terminal 5 may obtain the public key of the certification authority as appropriate. The second terminal 5 uses the obtained public key to decrypt the digital signature of the certification authority contained in the first digital certificate CC1. Then, the second terminal 5 compares the obtained decrypted data with the remaining information contained in the first digital certificate CC1 (ownership information and the first public key). If the data was encrypted after being converted to a hash value, the second terminal 5 converts the ownership information and the first public key into hash values using a hash function and compares the obtained hash values with the decrypted data. The second terminal 5 determines that the validity verification of the first digital certificate CC1 is successful if the two match during the matching process, and determines that the validity verification of the first digital certificate CC1 is unsuccessful if the two do not match.
[0254] Furthermore, the second terminal 5 verifies the validity of the digital signature CD1 (step SI140). The second terminal 5 decrypts the digital signature CD1 using the first public key contained in the first digital certificate CC1. The second terminal 5 compares the obtained decrypted data with the shared information (first identifier I10 and digital information). If the data was encrypted after being converted to a hash value, the second terminal 5 converts the shared information (first identifier I10 and digital information) into a hash value using a hash function and compares the obtained hash value with the decrypted data. If the two match in the comparison, the second terminal 5 determines that the verification of the validity of the digital signature CD1 is successful, and if they do not match, it determines that the verification of the validity of the digital signature CD1 is unsuccessful.
[0255] If the validity of both the first digital certificate CC1 and the digital signature CD1 is verified, the second terminal 5 sends a linking request including the first identifier I10 and the second identifier I20 to the management server 1 (step SI150). In response, the management server 1 receives the linking request from the second terminal 5. In response to the linking request, the management server 1 sets up a correspondence between the corresponding individuals of the first target VA and the second target WA. The process of setting up the correspondence may be the same as in the above embodiment. Note that the series of processes from data exchange between terminals (4, 5) to linking setting may be executed in real time as a usage relationship occurs. The process in step SI150 is an example of the process in step S10 above. On the other hand, if the validity of at least one of the first digital certificate CC1 and the digital signature CD1 is not verified, the second terminal 5 may appropriately terminate the linking setting process. The second terminal 5 may request the first terminal 4 to resend the series of information.
[0256] Note that the processing procedure shown in Figure 18A is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. For example, the processing order of verifying the validity of the first digital certificate CC1 (steps SI130 and SI135) and verifying the validity of the digital signature CD1 (step SI140) may be changed as appropriate. In another example, the verification of the validity of the digital signature CD1 may be performed before the verification of the validity of the first digital certificate CC1. The verification process for the validity of the first digital certificate CC1 and the verification process for the validity of the digital signature CD1 may be performed in parallel, at least partially.
[0257] Furthermore, in the fourth authentication method, the target of authentication is not limited to the first target VA. In another example, the authentication process for the second target WA may be performed instead of the authentication process for the first target VA. In yet another example, the authentication process for the second target WA may be performed together with the authentication process for the first target VA.
[0258] Figure 18B shows another example of the linking setting process when the fourth authentication method is adopted. This is schematically illustrated. In the example in Figure 18B, a scenario is assumed in which the authentication process for the second target WA is performed instead of the authentication process for the first target VA. Except for the fact that the first target VA and the second target WA are swapped, the processing procedure and data in Figure 18B may be the same as the processing procedure and data in Figure 18A. That is, in the preparation stage, a combination of the second private key CC20 and the second public key is generated. Next, the second digital certificate CC2 for the second public key is generated by the certification authority. In one example, the second digital certificate CC2 may consist of the certification authority's digital signature, ownership information, and the second public key. The second digital certificate CC2 is provided from the certification authority to the second terminal 5. In the usage stage, when a usage relationship occurs between the corresponding individuals of the first target VA and the second target WA, data exchange is performed between the corresponding first terminal 4 and second terminal 5 (steps SJ110, step SJ120). In this data exchange, electronic information is shared between the first terminal 4 and the second terminal 5. The second terminal 5 generates an electronic signature CD2 by encrypting the second identifier I20 and the electronic information using the second private key CC20. The second terminal 5 provides the second identifier I20, the generated electronic signature CD2, and the second electronic certificate CC2 to the first terminal 4. As a result, the first terminal 4 obtains the second identifier I20, the electronic signature CD2, and the second electronic certificate CC2. The first terminal 4 verifies the validity of the second electronic certificate CC2 (steps SJ130, SJ135). The first terminal 4 also verifies the validity of the electronic signature CD2 (step SJ140). If the validity verification of both the second electronic certificate CC2 and the electronic signature CD2 is successful, the first terminal 4 sends a linking request including the first identifier I10 and the second identifier I20 to the management server 1 (step SJ150). In response, the management server 1 receives the linking request from the first terminal 4. The management server 1 sets up a correspondence between the relevant individuals of the first target VA and the second target WA in response to the linking request. The process for setting up the correspondence may be the same as in the above embodiment. On the other hand, if the verification of the validity of at least one of the second digital certificate CC2 and the digital signature CD2 fails, the first terminal 4 may appropriately terminate the linking setting process. The first terminal 4 may request the second terminal 5 to resend the series of information.In another example, the authentication process for the first target VA and the second target WA may be performed by executing the series of processes shown in Figures 18A and 18B.
[0259] In the fourth authentication method, at least one of the first target VA and the second target WA is authenticated using a private key and a digital certificate. This is expected to ensure security. Furthermore, by performing the authentication process on the terminal side before the linking request, it is expected that the processing load on the management server 1 will be reduced. In addition, the processing time from the linking request to the configuration process can be shortened.
[0260] [5. Supplement] The processes and means described herein can be freely combined and implemented, provided that no technical inconsistencies arise.
[0261] Furthermore, a process described as being performed by a single device may be divided and executed by multiple devices. Conversely, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration used to implement each function can be flexibly changed.
[0262] This disclosure can also be realized by supplying a computer program implementing the functions described in the above embodiments to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. The non-temporary computer-readable storage medium may be any type of disk, such as a magnetic disk (floppy disk, hard disk drive (HDD), etc.), an optical disk (CD-ROM, DVD disk, Blu-ray disk, etc.), or a read-only disk. This includes MORI (ROM), Random Access Memory (RAM), EPROM, EEPROM, magnetic cards, flash memory, optical cards, semiconductor drives (such as solid-state drives), and any type of medium suitable for storing electronic instructions. [Explanation of Symbols]
[0263] 1...Management server, 11...Control unit, 2... Server 1, 3... Server 2 4...First terminal, 41...Control unit, 47...Positioning module, 5...Second terminal, 51...Control unit, 57...Positioning module, ST10...Status information, VA...First target, WA...Second target, I10...First identifier, I20...Second identifier, O10...Primary target information, O10A...User information, O20...Second target information, O20A...Mobile information, D10…Linking information, E10…Various information
Claims
1. Management server, Multiple first terminals corresponding to each first target, and Multiple second terminals corresponding to each second target, Equipped with, The plurality of first terminals and the plurality of second terminals are configured such that, in response to the occurrence of a usage relationship between the first target and the second target, at least one of the first terminals corresponding to the first target and the second terminals corresponding to the second target sends a linking request to the management server. The aforementioned management server Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target, and In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated. It is configured to perform, The status information includes the selection by the first target, Activating the setting of the aforementioned correspondence is performed by activating the setting of the correspondence selected by the first object. system.
2. Management server, Multiple first terminals corresponding to each first target, and Multiple second terminals corresponding to each second target, Equipped with, The plurality of first terminals and the plurality of second terminals are configured such that, in response to the occurrence of a usage relationship between the first target and the second target, at least one of the first terminals corresponding to the first target and the second terminals corresponding to the second target sends a linking request to the management server. 、 The aforementioned management server Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target, and In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated. It is configured to perform, The status information includes a report of the results of the authentication process performed by the second terminal on the first target, Activating the aforementioned correspondence setting is performed by activating the correspondence setting with the second target corresponding to the second terminal that most recently reported the result of the authentication process for the first target. system.
3. Management server, Multiple first terminals corresponding to each first target, and Multiple second terminals corresponding to each second target, Equipped with, The plurality of first terminals and the plurality of second terminals are configured such that, in response to the occurrence of a usage relationship between the first target and the second target, at least one of the first terminals corresponding to the first target and the second terminals corresponding to the second target sends a linking request to the management server. The aforementioned management server Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and After establishing an active correspondence with a first predetermined type of second object, the establishment of other active correspondences with other second objects is prohibited by locking the active correspondence until predetermined conditions are met. It is configured to perform, The first subject mentioned above is the user, The first predetermined type of the second object is a moving object of public transportation, The aforementioned specified condition is that payment for the use of the public transportation vehicle has been completed. system.
4. Management server, Multiple first terminals corresponding to each first target, and Multiple second terminals corresponding to each second target, Equipped with, The plurality of first terminals and the plurality of second terminals are configured such that, in response to the occurrence of a usage relationship between the first target and the second target, at least one of the first terminals corresponding to the first target and the second terminals corresponding to the second target sends a linking request to the management server. The aforementioned management server Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and If a predetermined relationship is established between the first and second objects for which the aforementioned correspondence relationship is set, the correspondence relationship will not be released until the predetermined relationship is resolved, and will be maintained in an active or inactive state. After the predetermined relationship is resolved, the correspondence relationship will be released. It is configured to perform, The aforementioned relationship is a relationship of ownership. The first subject mentioned above is the user, The second object is a mobile object owned by the user. system.
5. Management server, Multiple first terminals corresponding to each first target, and Multiple second terminals corresponding to each second target, Equipped with, The plurality of first terminals and the plurality of second terminals are configured such that, in response to the occurrence of a usage relationship between the first target and the second target, at least one of the first terminals corresponding to the first target and the second terminals corresponding to the second target sends a linking request to the management server. The aforementioned management server Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and If a predetermined relationship is established between the first and second objects for which the aforementioned correspondence relationship is set, the correspondence relationship will not be released until the predetermined relationship is resolved, and will be maintained in an active or inactive state. After the predetermined relationship is resolved, the correspondence relationship will be released. It is configured to perform, The first subject mentioned above is the user, The second object is a mobile vehicle leased by the user, The aforementioned predetermined relationship is that the user is leasing the mobile device. system.
6. Management server, Multiple first terminals corresponding to each first target, and Multiple second terminals corresponding to each second target, Equipped with, The plurality of first terminals and the plurality of second terminals are configured such that, in response to the occurrence of a usage relationship between the first target and the second target, at least one of the first terminals corresponding to the first target and the second terminals corresponding to the second target sends a linking request to the management server. The aforementioned management server Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and The management server, after establishing a correspondence with a second predetermined type of second object, will terminate the correspondence when it detects the end of use of the second object. It is configured to perform, The first subject mentioned above is the user, The second object mentioned above is a moving object, The second predetermined type of the second object is a moving object of public transportation. system.
7. The aforementioned management server In response to the establishment of an active correspondence, the exercise of the authority associated with the corresponding first target via the second target to which the active correspondence has been established is enabled, and In response to the establishment of an inactive correspondence, the exercise of the authority associated with the corresponding first object via the second object to which the inactive correspondence has been established is disabled. It is configured to perform further actions. The system according to any one of claims 1 to 6.
8. Each of the aforementioned first terminals is equipped with a positioning module, Each of the aforementioned second terminals is equipped with a positioning module, The status information includes a first current location measured by the positioning module of a first terminal corresponding to the first target, and a second current location measured by the positioning module of a second terminal corresponding to each of the two or more second targets. Activating the aforementioned correspondence setting is configured by activating the setting of a correspondence between the second current location of the corresponding second terminal and a second object that satisfies the conditions of the usage relationship between the first current location of the first terminal and the second object. The system according to any one of claims 1 to 6.
9. In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target, and Acceptance of the setting of the correspondence relationship based on two or more of the aforementioned linking requests relating to the same first object. In response to this, if two or more correspondence relationships are established between the same first object and two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated. A control unit configured to perform the following actions: The status information includes the selection by the first target, Activating the setting of the aforementioned correspondence is performed by activating the setting of the correspondence selected by the first object. Management server.
10. In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target, and In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated. A control unit configured to perform the following actions: The status information includes a report of the results of the authentication process performed by the second terminal on the first target, Activating the aforementioned correspondence setting is performed by activating the correspondence setting with the second target corresponding to the second terminal that most recently reported the result of the authentication process for the first target. Management server.
11. In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and After establishing an active correspondence with a first predetermined type of second object, the establishment of other active correspondences with other second objects is prohibited by locking the active correspondence until predetermined conditions are met. A control unit configured to perform the following actions: The first subject mentioned above is the user, The first predetermined type of the second object is a moving object of public transportation, The aforementioned specified condition is that payment for the use of the public transportation vehicle has been completed. Management server.
12. In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and If a predetermined relationship is established between the first and second objects for which the aforementioned correspondence relationship is set, the correspondence relationship will not be released until the predetermined relationship is resolved, and will be maintained in an active or inactive state. After the predetermined relationship is resolved, the correspondence relationship will be released. A control unit configured to perform the following actions: The aforementioned relationship is a relationship of ownership. The first subject mentioned above is the user, The second object is a mobile object owned by the user. Management server.
13. In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and If a predetermined relationship is established between the first and second objects for which the aforementioned correspondence relationship is set, the correspondence relationship will not be released until the predetermined relationship is resolved, and will be maintained in an active or inactive state. After the predetermined relationship is resolved, the correspondence relationship will be released. A control unit configured to perform the following actions: The first subject mentioned above is the user, The second object is a mobile vehicle leased by the user, The aforementioned predetermined relationship is that the user is leasing the mobile device. Management server.
14. In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and After establishing a correspondence with a second predetermined type of second object, the correspondence is terminated upon detection of the termination of use of the second object. A control unit configured to perform the following actions: The first subject mentioned above is the user, The second object mentioned above is a moving object, The second predetermined type of the second object is a moving object of public transportation. Management server.
15. The management server, In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target, and In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated. Execute, The status information includes the selection by the first target, Activating the setting of the aforementioned correspondence is performed by activating the setting of the correspondence selected by the first object. Management method.
16. The management server, In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target, and In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated. Execute, The status information includes a report of the results of the authentication process performed by the second terminal on the first target, Activating the aforementioned correspondence setting is performed by activating the correspondence setting with the second target corresponding to the second terminal that most recently reported the result of the authentication process for the first target. Management method.
17. The management server, In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more of the aforementioned linking requests relating to the same first object, if the establishment of two or more correspondence relationships between the same first object and two or more different second objects is established, the establishment of the two or more correspondence relationships Depending on the status information obtained from the first target and at least one of the two or more second targets, activate the setting of one of the two or more correspondence relationships and deactivate the settings of the other correspondence relationships, and After establishing an active correspondence with a first predetermined type of second object, the establishment of other active correspondences with other second objects is prohibited by locking the active correspondence until predetermined conditions are met. Execute, The first subject mentioned above is the user, The first predetermined type of the second object is a moving object of public transportation, The aforementioned specified condition is that payment for the use of the public transportation vehicle has been completed. Management method.
18. The management server, In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and If a predetermined relationship is established between the first and second objects for which the aforementioned correspondence relationship is set, the correspondence relationship will not be released until the predetermined relationship is resolved, and will be maintained in an active or inactive state. After the predetermined relationship is resolved, the correspondence relationship will be released. Execute, The aforementioned relationship is a relationship of ownership. The first subject mentioned above is the user, The second object is a mobile object owned by the user. Management method.
19. The management server, In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and If a predetermined relationship is established between the first and second objects for which the aforementioned correspondence relationship is set, the correspondence relationship will not be released until the predetermined relationship is resolved, and will be maintained in an active or inactive state. After the predetermined relationship is resolved, the correspondence relationship will be released. Execute, The first subject mentioned above is the user, The second object is a mobile vehicle leased by the user, The aforementioned predetermined relationship is that the user is leasing the mobile device. Management method.
20. The management server, In response to the occurrence of a usage relationship between the first target and the second target, a linking request is received from at least one of the first terminal of the first target and the second terminal of the second target. Upon receiving the aforementioned linking request, the system accepts the establishment of a correspondence between the first target and the second target. In response to receiving the establishment of the correspondence relationship through two or more linking requests relating to the same first object, if two or more correspondence relationships are established for the same first object with two or more different second objects, then, in accordance with the status information obtained from at least one of the first object and the two or more second objects, one of the two or more correspondence relationships is activated and the other correspondence relationships are deactivated, and After establishing a correspondence with a second predetermined type of second object, the correspondence is terminated upon detection of the termination of use of the second object. Execute, The first subject mentioned above is the user, The second object mentioned above is a moving object, The second predetermined type of the second object is a moving object of public transportation. Management method.