Access control device, access control system, access control method, and access control program
The access control system improves user history accuracy by associating location information with entry/exit data, addressing inaccuracies from unauthenticated entries/exists through wireless signal and image recognition, enhancing the precision of user tracking.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- MITSUBISHI ELECTRIC BUILDING SOLUTIONS CORP
- Filing Date
- 2025-07-17
- Publication Date
- 2026-07-29
AI Technical Summary
Existing entrance/exit management systems face inaccuracies in recording user history due to situations like piggybacking, where multiple users enter or exit without authentication, leading to decreased accuracy in entry/exit area history.
An access control system that includes an authentication unit, history management unit, positioning unit, and location management unit to associate user location information with entry/exit history, determining and registering entries/exists without authentication based on wireless signals and image recognition.
Enhances the accuracy of user entry/exit history recording by capturing unauthenticated entries/exists, ensuring comprehensive and precise tracking of user movements.
Smart Images

Figure 0007896746000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an entrance / exit management device, an entrance / exit management system, an entrance / exit management method, and an entrance / exit management program.
Background Art
[0002] Patent Document 1 discloses an example of an entrance / exit management system. In the entrance / exit management system, an authentication terminal is provided at the entrance and exit of a security area where the entrance / exit area is managed. When a user brings an authentication medium close to the authentication terminal, the authentication information of the user is read by the authentication terminal. In the entrance / exit management system, the authentication information read by the authentication terminal is compared with the registered database, and if the authentication information is registered, the history of the entrance / exit area is recorded. In the entrance / exit management system, a history difference, which is the difference between the number of people entering and the number of people leaving each time the entrance / exit area is passed through, is calculated, and the remaining people in the security area are detected based on the history difference.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in the entrance / exit management system of Patent Document 1, for example, in a time zone where the entrance / exit area frequently occurs, such as the commuting time in an office, a situation may occur where a user enters or exits the entrance / exit area together with another user without the authentication information being read by the authentication terminal. Since the entrance / exit area due to piggybacking is not recorded in the history, the accuracy of the history of the entrance / exit area may decrease.
[0005] The present disclosure relates to the solution of such problems. The present disclosure provides an entrance / exit management device, an entrance / exit management system, an entrance / exit management method, and an entrance / exit management program that can store the history of the entrance / exit area of a user with higher accuracy. [Means for solving the problem]
[0006] The access control device relating to this disclosure includes: an authentication unit that authenticates a user based on identification information that identifies the user, read from a portable device carried by the user by a reader installed at the entrance / exit of a pre-set management area in the building; a history management unit that stores the history of entry and exit from the management area based on authentication by the authentication unit; a positioning unit that calculates the user's location information in the building; a location management unit that stores the user's location information in the building and the user's identification information in association; and the authentication based on the user's location information stored by the location management unit and the history of entry and exit from the management area stored by the history management unit. The system includes a determination unit that determines whether or not there are users who have entered or left the management area without authentication by the authentication unit, and a registration unit that, when the determination unit determines that there are users who have entered or left the management area without authentication by the authentication unit, adds the entry and exit of such users to the history of entry and exit of the management area stored in the history management unit, the positioning unit acquires the user's location information based on a wireless signal that includes the user's identification information transmitted from a portable device read by the reader, and the location management unit uses the location information acquired by the positioning unit based on the wireless signal including the user's identification information as the user's location information. Associated with the user's identification information contained in the wireless signal Remember. The access control device relating to this disclosure includes: an authentication unit that authenticates a user based on identification information that identifies the user, read from a portable device carried by the user by a reader installed at the entrance / exit of a pre-set management area in the building; a history management unit that stores the history of entry and exit from the management area based on authentication by the authentication unit; a location management unit that stores the user's location information in the building and the user's identification information in association with each other; and the authentication based on the user's location information stored by the location management unit and the history of entry and exit from the management area stored by the history management unit. The system includes a determination unit that determines whether or not there are users who have entered or left the management area without authentication by the authentication unit, and a registration unit that, when the determination unit determines that there are users who have entered or left the management area without authentication by the authentication unit, adds the user's entry or exit to the history of entry and exit to the management area stored by the history management unit. The location management unit stores the location information of the mobile device itself, which is included in the wireless signal transmitted from the mobile device that the reader reads the user's identification information, and associates this information with the user's identification information included in the wireless signal. The access control device relating to this disclosure includes: an authentication unit that authenticates a user based on identification information that identifies the user, read from a portable device carried by the user by a reader installed at the entrance / exit of a management area set in advance in the building; a history management unit that stores the history of entry and exit of the management area based on authentication by the authentication unit; a positioning unit that calculates the user's location information in the building; a location management unit that stores the user's location information in the building and the user's identification information in association; a determination unit that determines whether or not there is a user who has entered or exited the management area without authentication by the authentication unit, based on the user's location information stored by the location management unit and the history of entry and exit of the management area stored by the history management unit; and a registration unit that, when the determination unit determines that there is a user who has entered or exited the management area without authentication by the authentication unit, adds the user's entry and exit to the history of entry and exit of the management area stored by the history management unit. The positioning unit uses image recognition of images taken by cameras installed in the building to identify the user based on pre-registered feature quantities that identify the user. Identification information andGet location information Furthermore, the position management unit stores the location information of the user obtained by the positioning unit for the user in the image, in association with the user identification information obtained by the positioning unit. .
[0007] The access control system disclosed herein includes a reader installed at the entrances and exits of pre-defined control areas within a building, The above access control device, It is equipped with.
[0008] The access control method relating to this disclosure involves a computer authenticating a user based on identification information read from a user's portable device by a reader installed at the entrance / exit of a pre-configured management area in the building, and storing a history of entry and exit from the management area based on the authentication using the identification information. The user's location information in the building is obtained based on a wireless signal transmitted from a portable device that reads the user's identification information and which includes the user's identification information, and the user's location information is obtained based on the wireless signal which includes the user's identification information. The method involves: storing location information and the user's identification information in association with each other; determining whether or not a user has entered or left the management area without authentication using the identification information, based on the stored location information of the user and the stored history of entry and exit from the management area; and, if it is determined that a user has entered or left the management area without authentication using the identification information, adding the entry and exit of that user to the stored history of entry and exit from the management area. The access control method relating to this disclosure is a method in which a computer performs the following actions: authenticates a user based on identification information that identifies the user, read from a portable device held by the user by a reader installed at the entrance / exit of a management area set in advance in the building; stores a history of entry and exit to the management area based on the authentication using the identification information; stores the user's identification information in association with the location information of the portable device itself in the building, which is included in a wireless signal transmitted from the portable device read by the reader, and the user's identification information included in the wireless signal; determines whether or not there is a user who has entered or exited the management area without undergoing authentication using the identification information, based on the stored location information of the user and the stored history of entry and exit to the management area; and, when it is determined that there is a user who has entered or exited the management area without undergoing authentication using the identification information, adds the entry and exit of that user to the stored history of entry and exit to the management area. The access control method relating to this disclosure is a method in which a computer performs the following actions: authenticates a user based on identification information that identifies the user, read from a portable device held by the user by a reader installed at the entrance / exit of a management area set up in advance in the building; stores a history of entry and exit from the management area based on the authentication using the identification information; acquires the user's location information in the building by image recognition of images taken by a camera installed in the building based on pre-registered feature quantities that identify the user; stores the location information acquired based on the feature quantities that identify the user in association with the user's identification information; determines whether or not there are users who have entered or exited the management area without undergoing authentication using the identification information, based on the stored location information of the user and the stored history of entry and exit from the management area; and, when it is determined that there are users who have entered or exited the management area without undergoing authentication using the identification information, adds the entry and exit of the user to the stored history of entry and exit from the management area.
[0009] The access control program related to this disclosure is installed on a computer. The above entry and exit control method Make it run. [Effects of the Invention]
[0010] According to the access control device, access control system, access control method, or access control program described herein, the history of users entering and leaving the area can be stored with greater accuracy. [Brief explanation of the drawing]
[0011] [Figure 1] This is a diagram showing the configuration of the access control system according to Embodiment 1. [Figure 2]It is a diagram for explaining an example of entry / exit management in the entry / exit management system according to Embodiment 1. [Figure 3] It is a diagram for explaining an example of entry / exit management in the entry / exit management system according to Embodiment 1. [Figure 4] It is a flowchart showing an example of processing in the entry / exit management system according to Embodiment 1. [Figure 5] It is a hardware configuration diagram of the main part of the entry / exit management system according to Embodiment 1. [Figure 6] It is a configuration diagram of the entry / exit management system according to Embodiment 2. [Figure 7] It is a diagram for explaining an example of entry / exit management in the entry / exit management system according to Embodiment 2. [Figure 8] It is a diagram for explaining an example of entry / exit management in the entry / exit management system according to Embodiment 2. [Figure 9] It is a flowchart showing an example of processing in the entry / exit management system according to Embodiment 2. [Figure 10] It is a configuration diagram of the entry / exit management system according to Embodiment 3. [Figure 11] It is a diagram for explaining an example of entry / exit management in the entry / exit management system according to Embodiment 3. [Figure 12] It is a flowchart showing an example of processing in the entry / exit management system according to Embodiment 3. [Figure 13] It is a configuration diagram of the entry / exit management system according to Embodiment 4. [Figure 14] It is a diagram for explaining an example of entry / exit management in the entry / exit management system according to Embodiment 4. [Figure 15] It is a diagram for explaining an example of entry / exit management in the entry / exit management system according to Embodiment 4. [Figure 16] It is a flowchart showing an example of processing in the entry / exit management system according to Embodiment 4.
Embodiments for Carrying Out the Invention
[0012] The embodiments for carrying out the subject matter of this disclosure will be described with reference to the attached drawings. In each drawing, the same or corresponding parts are denoted by the same reference numerals, and redundant explanations are simplified or omitted as appropriate. However, the subject matter of this disclosure is not limited to the following embodiments, and any modification of any component of the embodiments or omission of any component of the embodiments is possible without departing from the spirit of this disclosure.
[0013] Embodiment 1. Figure 1 is a diagram showing the configuration of the access control system 1 according to Embodiment 1.
[0014] The access control system 1 is applied to building 2. Here, building 2 may include not only indoor areas such as rooms and corridors, but also outdoor areas such as the perimeter, courtyard, rooftop, and connecting passages. In building 2, one or more controlled areas 3 are pre-defined. The access control system 1 is a system that manages the entry and exit of users 4 to and from the controlled areas 3 of building 2.
[0015] In this example of access control system 1, door 5 is provided at an entrance / exit on the boundary of the controlled area 3. The boundary of the controlled area 3 may include boundary areas such as the space around the periphery of the controlled area 3 and the space adjacent to the controlled area 3. Door 5 is provided, for example, at the entrance of building 2 or at an entrance / exit to a room inside building 2. In this example of access control system 1, an electric lock 6 is provided on door 5. The electric lock 6 locks and unlocks door 5 based on an external control signal. In the access control system 1, a flapper gate or the like may be provided at an entrance / exit on the boundary of the controlled area 3 instead of, or together with, door 5. Multiple entrances / exits may be provided in the controlled area 3. In the access control system 1, if there are multiple entrances / exits in the controlled area 3 of building 2, an identifier is assigned to identify the entrances / exits.
[0016] Users 4 entering and exiting the controlled area 3 each carry a portable device 7 when passing through building 2. The portable device 7 may be a portable general-purpose information processing device such as a smartphone or wearable device, or it may be a dedicated device for the access control system 1 such as a wireless tag. The portable device 7 is equipped with, for example, wireless LAN (LAN: Local Area Network), wireless PAN (PAN: Personal Area Network), short-range wireless communication, or other wireless communication functions. The portable device 7 stores the identification information of the user 4 who is carrying it. The identification information is information that identifies user 4. The identification information may be, for example, a unique ID (IDentifier) assigned to user 4.
[0017] The access control system 1 includes one or more readers 8. The readers 8 correspond to entrances and exits of the management area 3. The readers 8 are installed at the corresponding entrances and exits. For example, the readers 8 are installed adjacent to the door 5 of the corresponding entrance. At the entrances and exits of the management area 3, readers 8 may be installed both inside and outside the management area 3. The readers 8 are devices that read the identification information of a user 4 from a portable device 7 held by the user 4. The readers 8 read the identification information, for example, by wireless communication with the portable device 7. The user 4 causes the readers 8 to read their identification information, for example, by holding the portable device 7 over the readers 8. If the portable device 7 displays the identification information as an encoded image such as a barcode or a two-dimensional code, the readers 8 may read the identification information by photographing the encoded image.
[0018] In this example of the access control system 1, each reader device 8 is connected to a controller 9. The controller 9 is a device that processes the identification information read by the reader devices 8. The controller 9 is installed in the building 2. The controller 9 is connected to the communication network 10.
[0019] The communication network 10 includes, for example, the Internet, a telephone network, or an optical communication network. The communication network 10 may also include a local network such as a LAN within building 2. The communication network 10 may also include a wired or wireless intranet.
[0020] Multiple receivers 11 are installed in building 2. Each receiver 11 is a device that receives wireless signals transmitted from, for example, a portable device 7 owned by user 4. User 4's portable device 7 transmits wireless signals containing identification information to its surroundings, for example, at pre-set periodic or irregular intervals, or at the timing of operations performed by user 4. Each receiver 11 is connected to an edge server 12. The edge server 12 is a device that performs information processing of wireless signals received by the receivers 11. The edge server 12 is installed in building 2. The edge server 12 is connected to the communication network 10.
[0021] A monitoring device 13 is applied to building 2. The monitoring device 13 is a device used for monitoring building 2. The monitoring device 13 may be located in a monitoring room or other location within building 2, or it may be located at an external location such as an information center. The monitoring device 13 may be a device that presents information for monitoring building 2 to a monitor based on information collected in building 2, or it may be a device that automatically monitors building 2. For example, the monitoring device 13 monitors the status of equipment applied to building 2. Equipment applied to building 2 includes, for example, elevator or escalator systems, air conditioning systems, lighting systems, ventilation systems, hot water supply systems, or other systems or devices. Equipment applied to building 2 may also include access control systems 1 or other security systems. In this example, the monitoring device 13 is connected to a communication network 10. The monitoring device 13 collects information from equipment applied to building 2 through the communication network 10, for example.
[0022] Access control system 1 includes an access control device 14. The access control device 14 is a device responsible for information processing in the access control system 1. The access control device 14 is a computer system consisting of, for example, one or more server devices. Here, a computer system consisting of one or more devices may be simply called a computer. The multiple server devices constituting the access control device 14 may be located in different locations. In this case, the multiple server devices communicate information with each other, for example, through a communication network 10. Some or all of the functions of the access control device 14 may be implemented by, for example, processing, storage, or other resources on a cloud service. The access control device 14 includes a location management device 15 and an authentication device 16.
[0023] The location management device 15 is a device that manages the location information of users 4 in building 2. The location management device 15 is a computer system consisting of, for example, one or more server devices. Some or all of the functions of the location management device 15 may be mounted on a device installed in building 2, for example, an edge server 12. The location management device 15 comprises a data collection unit 17, a positioning unit 18, and a location management unit 19.
[0024] The collection unit 17 is responsible for collecting information representing the location of each user 4 in building 2. The collection unit 17 collects information from, for example, a plurality of receivers 11 installed in building 2 via the edge server 12 and the communication network 10. When the receivers 11 are connected to the communication network 10, the collection unit 17 may also collect information from the receivers 11 via the communication network 10. The collection unit 17 collects information such as the signal strength of a wireless signal containing the user 4's identification information, which is received by each receiver 11 from the user 4's mobile device 7. The collection unit 17 may also collect information from each receiver 11, for example, at pre-set periodic or irregular timings, or when it receives a wireless signal from the mobile device 7. The collection unit 17 may also collect information from each receiver 11 as a response to a request to be sent to each receiver 11.
[0025] The positioning unit 18 is responsible for calculating the location information of each user 4 within building 2. The positioning unit 18 calculates the location information of user 4 based on the information collected by the collection unit 17. The positioning unit 18 may also acquire the location information of user 4 within building 2 based on, for example, information on the signal strength of the wireless signal received by each receiver 11 from the user 4's mobile device 7. When the positioning unit 18 cannot calculate the location information of user 4 within building 2, it may treat the location of user 4 as being outside building 2. The positioning unit 18 may also determine the area within building 2 where user 4 is located. For example, the positioning unit 18 may determine whether user 4 is in the management area 3.
[0026] The location management unit 19 is the part that manages the location information of each user 4 in building 2. The location management unit 19 stores the location information of user 4 in building 2 and the identification information of user 4 in association with each other. The location information of user 4 managed by the location management unit 19 is the location information calculated by the positioning unit 18. The location management unit 19 may store the trajectory of user 4's location information in the form of time-series data, which is a series of information representing the position at each point in time, such as coordinates, or in other formats. The location management unit 19 may store information about user 4's movement as user 4's location information, such as changes in the area where user 4 is located in building 2. The location management unit 19 may store, for example, information about user 4's entry into and exit from the management area 3, which is determined by the positioning unit 18, etc., based on user 4's location information. The location management unit 19 stores entry and exit information by location as a history of entry and exit from the management area 3 based on user 4's location information. Location-based entry and exit information includes, for example, the identification information of user 4 entering and exiting the management area 3, the direction of movement for entry or exit, the time of entry and exit, and the identifier of the entrance / exit used.
[0027] The authentication device 16 is a device that performs authentication processing for users 4 who intend to enter or leave the management area 3. The authentication device 16 is a computer system consisting of, for example, one or more server devices. Some or all of the functions of the authentication device 16 may be mounted on a device installed in the building 2, for example, a controller 9. The authentication device 16 comprises an authentication unit 20, a history management unit 21, a determination unit 22, and a registration unit 23.
[0028] The authentication unit 20 is the part that authenticates user 4 based on the user 4's identification information. The authentication unit 20 obtains the user 4's identification information from the reader 8 that reads the user 4's mobile device 7, via the controller 9 and the communication network 10. If the reader 8 is connected to the communication network 10, the authentication unit 20 may also collect information from the reader 8 via the communication network 10. In the authentication unit 20, for example, the identification information of users 4 who are permitted to enter and exit the management area 3 is pre-registered. The authentication unit 20 determines whether user 4, whose identification information was obtained from the reader 8 installed at the entrance / exit of the management area 3, is registered as a user 4 permitted to enter and exit the management area 3. The authentication unit 20 authenticates user 4 when the user 4's identification information is registered. On the other hand, the authentication unit 20 does not authenticate user 4 when the user 4's identification information is not registered. When the authentication unit 20 authenticates user 4, it notifies the controller 9 of the authentication result. When the controller 9 receives an authentication result for user 4 whose identification information has been read by the reader 8, it outputs an unlock control signal to the electric lock 6 of the entrance door 5 where the reader 8 is installed. As a result, the electric lock 6 of door 5 is unlocked, allowing user 4 to enter and exit the management area 3.
[0029] The history management unit 21 is the part that manages the history of entry and exit to the management area 3. The history management unit 21 stores authentication-based entry and exit information as the history of entry and exit to the management area 3 based on authentication by the authentication unit 20. Authentication-based entry and exit information includes, for example, the identification information of the authenticated user 4, the direction of movement for entry or exit, the time of entry and exit, and the identifier of the entrance and exit used. The entry and exit information managed as the history of entry and exit may include information that distinguishes whether or not the entry or exit was authenticated by the authentication unit 20. In other words, the entry and exit information managed as the history of entry and exit may include information that distinguishes whether it is authentication-based entry and exit information or location-based entry and exit information.
[0030] The determination unit 22 is the part that makes decisions in the authentication process. The determination unit 22 determines, for example, whether there is a user 4 who has entered or left the management area 3 without being authenticated by the authentication unit 20, such as by tailgating. The determination unit 22 may obtain the information used for the decision from outside the authentication device 16. For example, the determination unit 22 obtains the location information of user 4 stored in the location management unit 19 from the location management device 15. The determination unit 22 may obtain the location information of user 4 directly from the location management unit 19 if direct communication between the authentication device 16 and the location management device 15 is possible, or it may obtain it through the communication network 10. Based on the location information of user 4 stored in the location management unit 19 and the history of entry and exit to the management area 3 stored in the history management unit 21, the determination unit 22 determines whether there is a user 4 who has entered or left the management area 3 without being authenticated by the authentication unit 20. For example, the determination unit 22 determines that user 4 entered or left the management area 3 without authentication by the authentication unit 20 when the entry / exit information corresponding to user 4's entry or exit to the management area 3, as determined by the positioning unit 18, is not included in the entry / exit history stored by the history management unit 21.
[0031] The registration unit 23 is responsible for processing such as registering entries into the entry and exit history of the management area 3 stored by the history management unit 21. When the determination unit 22 determines that there is a user 4 who has entered or exited the management area 3 without authentication by the authentication unit 20, the registration unit 23 adds the entry and exit information based on the location of the user 4 to the entry and exit history stored by the history management unit 21.
[0032] Figures 2 and 3 illustrate an example of access control in the access control system 1 according to Embodiment 1.
[0033] As shown in Figure 2, in this example, user 4a with identification information AAA and user 4b with identification information BBB are attempting to enter the management area 3. User 4a possesses mobile device 7a. User 4b possesses mobile device 7b. Here, when individual users such as user 4a and user 4b are not distinguished, they may simply be referred to as user 4. Similarly, when individual mobile devices such as mobile device 7a and mobile device 7b are not distinguished, they may simply be referred to as mobile device 7.
[0034] In building 2, receiver 11 receives wireless signals transmitted by mobile device 7a and mobile device 7b. Information such as the received strength of the wireless signals from mobile device 7a and mobile device 7b is transmitted to the location management device 15 via edge server 12. In the location management device 15, positioning unit 18 calculates the location information of users 4a and 4b based on information such as the received strength of the wireless signals. Positioning unit 18 determines that both users 4a and 4b are outside the management area 3.
[0035] User 4a holds their mobile device 7a over a reader 8 located outside the management area 3 in order to enter the management area 3. The reader 8, upon receiving the mobile device 7a, obtains user 4a's identification information from the mobile device 7a. The user 4a's identification information read by the reader 8 is transmitted to the authentication device 16 via the controller 9. When user 4a is authenticated by the authentication unit 20 of the authentication device 16, user 4a's authentication-based entry and exit information is stored in the history management unit 21. The authentication-based entry and exit information includes user 4a's identification information AAA, information indicating that the direction of movement is entry, the authentication time, and information such as the identifier XXX of the entrance / exit where door 5 is provided. After authentication, user 4a opens door 5 and enters the management area 3.
[0036] As shown in Figure 3, user 4b enters the management area 3 following user 4a. Here, since user 4a has opened the door 5 at the entrance / exit of the management area 3, user 4b does not perform any authentication operations such as holding the mobile device 7b over the reader 8. For this reason, the reader 8 does not read user 4b's identification information from the mobile device 7b.
[0037] In building 2, receiver 11 receives wireless signals transmitted by mobile device 7a and mobile device 7b. In the location management device 15, positioning unit 18 calculates the location information of users 4a and 4b based on information such as the received strength of the wireless signals. Positioning unit 18 determines that both users 4a and 4b are inside the management area 3.
[0038] The location management unit 19 determines that user 4a has entered the management area 3 when user 4a's position moves from outside the management area 3 to inside the management area 3. The location management unit 19 may also identify the entrance / exit that user 4a passed through based on location information such as user 4a's coordinates. When user 4a enters the management area 3, the location management unit 19 stores this information as entry / exit information based on user 4a's position. This entry / exit information based on position includes user 4a's identification information AAA, information indicating that the direction of movement is entry, the time of passage, and the entrance / exit identifier XXX. Similarly, the location management unit 19 stores entry / exit information based on user 4b's position. When determining whether user 4 has entered or left the management area 3, the location management unit 19 notifies the determination unit 22 of user 4's entry / exit information based on position.
[0039] The determination unit 22 checks the consistency between the location-based entry / exit information notified by the location management unit 19 and the authentication-based entry / exit information stored in the history management unit 21. Based on the user 4's identification information in the location-based entry / exit information notified by the location management unit 19, the determination unit 22 extracts the authentication-based entry / exit information stored in the history management unit 21 for the user 4. The determination unit 22 determines whether the notified location-based entry / exit information and the extracted authentication-based entry / exit information are consistent. For example, the determination unit 22 determines that the entry / exit information is inconsistent when the difference between the passage time in the location-based entry / exit information and the authentication time in the authentication-based entry / exit information exceeds a preset tolerance range. For example, the determination unit 22 determines that the entry / exit information is inconsistent when the direction of movement in the location-based entry / exit information and the direction of movement in the authentication-based entry / exit information do not match. For example, the determination unit 22 determines that the entry / exit information is inconsistent when the entrance / exit identifier in the location-based entry / exit information and the entrance / exit identifier in the authentication-based entry / exit information do not match. The determination unit 22 determines that a user 4 entered or left the management area 3 without authentication by the authentication unit 20 if the entry / exit information based on the notified location does not match the entry / exit information based on the extracted authentication. The determination unit 22 also determines that a user 4 entered or left the management area 3 without authentication by the authentication unit 20 if the history management unit 21 does not store any entry / exit information based on authentication for that user 4.
[0040] When the determination unit 22 determines that there is a user 4 who has entered or left the management area 3 without authentication by the authentication unit 20, the registration unit 23 adds the entry and exit information based on the location of the user 4, which has been notified by the location management unit 19, to the entry and exit history stored in the history management unit 21.
[0041] The access control system 1 manages the access history using the same procedure when user 4 leaves the management area 3.
[0042] Figure 4 is a flowchart showing an example of processing in the access control system 1 according to Embodiment 1. Figure 4 shows an example of the processing performed by the authentication device 16 and the location management device 15. The authentication device 16 and the location management device 15 may operate asynchronously with respect to each other.
[0043] In step S101 of the authentication device 16, the authentication unit 20 obtains the user's identification information from the reader 8 via the controller 9 or the like. After that, the authentication device 16 proceeds to step S102.
[0044] In step S102 of the authentication device 16, the authentication unit 20 determines whether user 4, whose identification information has been obtained, is registered as a user 4 who is permitted to enter and exit the management area 3. If user 4 is not permitted to enter and exit, the authentication unit 20 does not authenticate user 4, and the processing of the authentication device 16 ends. On the other hand, if user 4 is permitted to enter and exit, the authentication unit 20 authenticates user 4, and the processing of the authentication device 16 proceeds to step S103.
[0045] In step S103 of the authentication device 16, the history management unit 21 stores the user 4's authentication-based entry and exit information as entry and exit history in the management area 3. After that, the authentication device 16 proceeds to step S104.
[0046] Authenticated user 4 passes through the entrance / exit of management area 3 in order to enter or exit management area 3.
[0047] In step S201 of the location management device 15, the collection unit 17 collects information such as the reception strength of the wireless signal transmitted from the receiver 11 by the mobile device 7 via the edge server 12 or the like. The positioning unit 18 acquires the location information of user 4 based on the information collected by the collection unit 17. The location management unit 19 stores the acquired location information of user 4 in association with the identification information of user 4. After that, the processing of the location management device 15 proceeds to step S202.
[0048] In step S202 of the location management device 15, the location management unit 19 determines, based on the location information of user 4, whether user 4 has entered or left the management area 3. If user 4 has not entered or left the management area 3, the location management device 15 proceeds to step S201. On the other hand, if user 4 has entered or left the management area 3, the location management device 15 proceeds to step S203.
[0049] In step S203 of the location management device 15, the location management unit 19 notifies the determination unit 22 of the authentication device 16 of the entry / exit information based on the location of user 4. After that, the processing of the location management device 15 proceeds to step S201.
[0050] In step S104 of the authentication device 16, the determination unit 22 confirms the consistency between the entry / exit information based on location notified by the location management unit 19 and the entry / exit information based on authentication stored in the history management unit 21. After that, the authentication device 16 proceeds to step S105.
[0051] In step S105 of the authentication device 16, the determination unit 22 determines, based on the results of the consistency check, whether there are any users 4 who have entered or left the management area 3 without authentication by the authentication unit 20. If there are no users 4 who have entered or left without authentication, the authentication device 16 terminates. On the other hand, if there are users 4 who have entered or left without authentication, the authentication device 16 proceeds to step S106.
[0052] In step S106 of the authentication device 16, the registration unit 23 adds the entry and exit information based on the location of user 4, which was notified by the location management unit 19, to the entry and exit history stored in the history management unit 21 for user 4 who entered or left the management area 3 without authentication by the authentication unit 20. After that, the processing of the authentication device 16 is completed.
[0053] As described above, the access control system 1 according to Embodiment 1 comprises a reader 8 and an access control device 14. The reader 8 is installed at the entrance and exit of a pre-set management area 3 in the building 2. The access control device 14 comprises an authentication unit 20, a history management unit 21, a location management unit 19, a determination unit 22, and a registration unit 23. The authentication unit 20 authenticates the user 4 based on identification information that identifies the user 4, which is read by the reader 8 from a portable device 7 held by the user 4. The history management unit 21 stores the history of entry and exit to the management area 3 based on authentication by the authentication unit 20. The location management unit 19 stores the location information of the user 4 in the building 2 and the identification information of the user 4 in association with each other. The determination unit 22 determines whether or not there is a user 4 who entered or left the management area 3 without authentication by the authentication unit 20, based on the location information of user 4 stored by the location management unit 19 and the history of entry and exit to the management area 3 stored by the history management unit 21. When the determination unit 22 determines that there is a user 4 who entered or left the management area 3 without authentication by the authentication unit 20, the registration unit 23 adds the entry and exit of the user 4 to the history of entry and exit to the management area 3 stored by the history management unit 21.
[0054] With this configuration, even if authentication-based entry and exit information is not recorded due to tailgating or other reasons, location-based entry and exit information will be recorded as part of the entry and exit history. This will allow for a higher accuracy recording of user 4's entry and exit history.
[0055] Furthermore, the location management unit 19 stores the location information acquired based on the radio signal used for wireless communication by the portable device 7, which the reader 8 reads the user 4's identification information from, as the location information of the user 4. At this time, since the portable device 7 used for authentication and the portable device 7 used for acquiring location information are the same, discrepancies between entry / exit information obtained by authentication and entry / exit information obtained by location are less likely to occur. As a result, the entry / exit history of user 4 is stored with higher accuracy.
[0056] The location management device 15 may acquire and manage the location information of user 4 by other means. The location management device 15 may acquire the location information of user 4 possessing the mobile device 7 by the location information calculated by the mobile device 7 itself and transmitted from the mobile device 7. For example, when multiple transmitters that emit wireless signals are installed in building 2, the mobile device 7 calculates its own position in building 2 based on the received strength of the wireless signals emitted from each transmitter. At this time, the mobile device 7 transmits the calculated location information to the location management device 15 via the communication network 10 or the like. The mobile device 7 may acquire its own location information by other indoor positioning methods or autonomous navigation, for example. The location management device 15 may acquire the location information of user 4 by image recognition or the like. For example, when one or more cameras that take pictures are installed in building 2, the collection unit 17 collects images of building 2 taken by each camera. In the positioning unit 18, feature quantities that identify user 4 are registered in advance. The positioning unit 18 identifies the user 4 on the image collected by the collection unit 17 and calculates the location information of the identified user 4 using image recognition or other technologies.
[0057] Furthermore, the determination unit 22 may verify the consistency between the entry / exit information based on location notified by the location management unit 19 and the entry / exit information based on authentication stored in the history management unit 21 when there is a possibility of tailgating. The determination unit 22 may omit the consistency verification when tailgating does not occur. For example, the determination unit 22 may omit the consistency verification of entry / exit information when it determines, based on the location information managed by the location management unit 19, that there are no other users 4 around a user 4 entering or leaving the management area 3. For example, the determination unit 22 determines that there are no other users 4 around a user 4 entering or leaving the area when there are no other users 4 within a predetermined distance range around the user 4 entering or leaving. This reduces the processing load on the determination unit 22 related to consistency verification.
[0058] Furthermore, the location management device 15 and the authentication device 16 may be an integrated device. Some or all of the functions of one of the location management device 15 and the authentication device 16 may be mounted on the other of the location management device 15 and the authentication device 16. When each receiver 11 is connected to the communication network 10, some or all of the functions of the edge server 12 may be mounted on the access control device 14, or the building 2 may not have an edge server 12. When each reader 8 is connected to the communication network 10, some or all of the functions of the controller 9 may be mounted on the access control device 14, or the building 2 may not have a controller 9.
[0059] Next, we will explain an example of the hardware configuration of the access control system 1 using Figure 5. Figure 5 is a hardware configuration diagram of the main components of the access control system 1 according to Embodiment 1.
[0060] Some or all of the functions of the access control system 1 can be implemented by a processing circuit. The processing circuit comprises at least one processor 100a and at least one memory 100b. The processing circuit may also include at least one dedicated hardware component along with the processor 100a and memory 100b, or as a substitute for them.
[0061] When the processing circuit includes a processor 100a and a memory 100b, each function of the access control system 1 is implemented by software, firmware, or a combination of software and firmware. At least one of the software and firmware is written as a program. This program is stored in the memory 100b. The processor 100a implements each function of the access control system 1 by reading and executing the program stored in the memory 100b. The program may be a program package that includes multiple subprograms, modules, or libraries. The program is sometimes called a program product.
[0062] The processor 100a is also called a CPU (Central Processing Unit), processing unit, arithmetic unit, microprocessor, microcomputer, or DSP. The memory 100b is composed of non-volatile or volatile semiconductor memory such as RAM, ROM, flash memory, EPROM, or EEPROM.
[0063] When a processing circuit has dedicated hardware, it can be implemented as, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC, an FPGA, or a combination thereof.
[0064] Each function of the access control system 1 can be implemented by a separate processing circuit. Alternatively, each function of the access control system 1 can be implemented collectively by a single processing circuit. For each function of the access control system 1, some may be implemented by dedicated hardware, while others are implemented by software or firmware. In this way, the processing circuit implements each function of the access control system 1 using dedicated hardware, software, firmware, or a combination thereof.
[0065] Embodiment 2. In Embodiment 2, the differences from the example disclosed in Embodiment 1 will be explained in particular detail. For features not described in Embodiment 2, any of the features from the example disclosed in Embodiment 1 may be adopted.
[0066] Figure 6 is a diagram showing the configuration of the access control system 1 according to Embodiment 2.
[0067] The authentication device 16 includes a mode management unit 24. The mode management unit 24 is the part that manages the operating modes of the equipment applied to the building 2. The operating modes of the equipment include, for example, a normal operation mode and a security mode. The normal operation mode is the operating mode of the equipment under normal circumstances. The security mode is an operating mode that corresponds to a situation where the management area 3 is unoccupied. For example, an elevator applied to the building 2 may, in security mode, set the floor where the management area 3 is located as a non-stop floor where the elevator car does not stop. For example, an air conditioning system, lighting system, ventilation system, or hot water supply system applied to the building 2 may, in security mode, suspend operation by, for example, turning off the lights or stopping the heating or cooling. For example, a security system applied to the building 2 may, in security mode, issue an alarm when it detects a person in the management area 3. The mode management unit 24 outputs control signals for switching operating modes to the corresponding equipment, for example, through a communication network 10.
[0068] The determination unit 22 calculates the number of users 4 in the management area 3 based on the entry and exit history of the management area 3 stored by the history management unit 21. For example, the determination unit 22 calculates the number of users 4 present in the management area 3 by the difference between the number of entry and exit information representing user 4's entry and the number of entry and exit information representing user 4's exit. At this time, the determination unit 22 calculates the number of people present by treating authentication-based entry and exit information and location-based entry and exit information equally. Based on the calculated number of people present, the determination unit 22 determines whether the authenticated user 4 is the last person to leave the management area 3 when user 4 leaves the management area 3. The determination unit 22 determines that user 4 who left the management area 3 is the last person to leave when the number of people present in the management area 3 becomes 0. The determination unit 22 determines that user 4 who left the management area 3 is not the last person to leave when the number of people present in the management area 3 is 1 or more.
[0069] Figures 7 and 8 illustrate an example of access control in the access control system 1 according to Embodiment 2.
[0070] As shown in Figure 7, in this example, user 4b, who possesses the portable device 7b, is alone inside the management area 3. At this time, the operating mode of the equipment installed in building 2 is set to normal operation mode.
[0071] In building 2, receiver 11 receives the wireless signal transmitted by the mobile device 7b. In the location management device 15, positioning unit 18 calculates the location information of user 4b based on information such as the received strength of the wireless signal. Positioning unit 18 determines that user 4b is inside the management area 3.
[0072] The determination unit 22 calculates the number of people present as one user 4b based on the entry and exit history of the management area 3 stored by the history management unit 21.
[0073] Subsequently, as shown in Figure 8, user 4b exits the management area 3. To exit the management area 3, user 4b holds their mobile device 7b over the reader 8 inside the management area 3. The reader 8, upon receiving the mobile device 7b, obtains user 4b's identification information from the mobile device 7b. The user 4b's identification information read by the reader 8 is transmitted to the authentication device 16 via the controller 9. Once user 4b is authenticated by the authentication unit 20 of the authentication device 16, user 4b's authentication-based entry and exit information is stored in the history management unit 21. After authentication, user 4b opens the door 5 and exits the management area 3.
[0074] In building 2, receiver 11 receives the wireless signal transmitted by the mobile device 7b. In the location management device 15, positioning unit 18 calculates the location information of user 4b based on information such as the received strength of the wireless signal. Positioning unit 18 determines that user 4b is outside the management area 3.
[0075] The determination unit 22 calculates the number of people in the area to be 0 based on the entry and exit history of the management area 3 stored in the history management unit 21. At this time, the determination unit 22 determines that user 4b is the last person to exit. After the last person to exit leaves the management area 3, the mode management unit 24 outputs a control signal to the corresponding equipment to switch the operating mode to security mode. As a result, the operating mode of the corresponding equipment is automatically switched to security mode without any operation by user 4b or other means.
[0076] Figure 9 is a flowchart showing an example of processing in the access control system 1 according to Embodiment 2. Figure 9 shows an example of the processing of the authentication device 16. The location management device 15 according to Embodiment 2 performs the same processing as the location management device 15 according to Embodiment 1. The authentication device 16 according to Embodiment 2 performs the same processing as the authentication device 16 according to Embodiment 1 from step S101 to step S106. After determining in step S105 that there are no users 4 who have entered or left without authentication, or after additional registration in step S106, the authentication device 16 according to Embodiment 2 proceeds to the processing in step S107.
[0077] In step S107, the determination unit 22 calculates the number of users 4 present in the management area 3 based on the entry and exit history of the management area 3 stored in the history management unit 21. If the calculated number of users present is 1 or more, the authentication device 16 terminates. On the other hand, if the calculated number of users present is 0, the authentication device 16 proceeds to step S108.
[0078] In step S108, the mode management unit 24 outputs a control signal to the corresponding equipment to switch the operating mode to security mode. After that, the authentication device 16 completes its processing.
[0079] As described above, the access control device 14 according to Embodiment 2 includes a mode management unit 24. The mode management unit 24 manages the operating mode of the equipment applied to the building 2. The determination unit 22 calculates the number of occupants, which is the number of users 4 in the management area 3, based on the history of entry and exit to the management area 3 stored in the history management unit 21. The determination unit 22 uses the calculated number of occupants to determine whether the user 4 authenticated by the authentication unit 20 is the last person to exit the management area 3. When the determination unit 22 determines that the user 4 authenticated by the authentication unit 20 is the last person to exit the management area 3, the mode management unit 24 switches its operating mode to a security mode corresponding to the situation where the management area 3 is unoccupied.
[0080] With this configuration, the operating mode of the equipment applied to Building 2 is automatically switched to security mode without requiring any action from the building's administrator or user 4, who is the last person to leave. This reduces the workload for user 4 or the administrator of Building 2. Furthermore, it reduces the likelihood of failure to switch to security mode, thereby improving security in Building 2 and potentially reducing energy consumption in Building 2.
[0081] Embodiment 3. In Embodiment 3, the differences from the examples disclosed in Embodiment 1 or Embodiment 2 will be described in particular detail. For features not described in Embodiment 3, any of the features from the examples disclosed in Embodiment 1 or Embodiment 2 may be adopted.
[0082] Figure 10 is a diagram showing the configuration of the access control system 1 according to Embodiment 3.
[0083] The authentication device 16 comprises an output unit 25 and an input unit 26. The output unit 25 is the part that outputs information to be presented to the user 4. The output unit 25 presents information to the user 4 via a display on a device, for example, by outputting a control signal to a device used by the user 4 via the communication network 10. The output unit 25 presents information to the user 4 by outputting a control signal to a portable device 7 possessed by the user 4. The portable device 7 presents information to the user 4, for example, by displaying it on a screen. The input unit 26 is the part that receives input from the user 4. The input unit 26 accepts input from the user 4 via an input signal from a device used by the user 4 via the communication network 10, for example, by operating the device. The input unit 26 accepts input from the user 4 by receiving an input signal from a portable device 7 possessed by the user 4. The portable device 7 accepts input from the user 4, for example, by touching a touch panel. The output unit 25 and the input unit 26 may communicate signals with the same device or equipment, or they may communicate signals with different devices or equipment.
[0084] Figure 11 is a diagram illustrating an example of access control in the access control system 1 according to Embodiment 3.
[0085] As shown in Figure 11, in this example, user 4b, who was alone inside the controlled area 3, leaves the controlled area 3 carrying the portable device 7b. Before user 4b leaves, the operating mode of the equipment installed in building 2 is set to normal operation mode.
[0086] User 4b holds their mobile device 7b over the reader 8 inside the management area 3 in order to exit the management area 3. The reader 8, upon receiving the mobile device 7b, obtains the user 4b's identification information from the mobile device 7b. The user 4b's identification information read by the reader 8 is transmitted to the authentication device 16 via the controller 9. Once user 4b is authenticated by the authentication unit 20 of the authentication device 16, the entry and exit information of user 4b based on authentication is stored in the history management unit 21. After authentication, user 4b opens the door 5 and exits the management area 3.
[0087] The determination unit 22 calculates the number of people present as 0 based on the entry and exit history of the management area 3 stored in the history management unit 21. At this time, the determination unit 22 determines that user 4b is the last person to exit. After the last person to exit leaves the management area 3, the output unit 25 inquires with user 4b via the portable device 7b whether or not to switch the operating mode to security mode. At this time, the operating mode of the equipment installed in building 2 is set during the inquiry. The operating mode during the inquiry may be the same as the normal operating mode, or it may be an operating mode that includes preparation for switching to security mode.
[0088] User 4b responds to an inquiry from the output unit 25 by inputting a response via the portable device 7b indicating whether or not to switch to security mode. For example, user 4b inputs a response indicating that they will switch to security mode. At this time, the portable device 7b transmits a command to switch to security mode to the input unit 26 as an input signal from user 4. When the input unit 26 receives the command to switch to security mode, the mode management unit 24 outputs a control signal to the corresponding equipment to switch the operating mode to security mode. As a result, the operating mode of the corresponding equipment is automatically switched to security mode without any operation by user 4b.
[0089] Figure 12 is a flowchart showing an example of processing in the access control system 1 according to Embodiment 3. Figure 12 shows an example of the processing of the authentication device 16. The location management device 15 according to Embodiment 3 performs the same processing as the location management device 15 according to Embodiment 2. The authentication device 16 according to Embodiment 3 performs the same processing as the authentication device 16 according to Embodiment 2 from step S101 to step S107 and in step S108. If the number of people in the management area 3 is calculated to be 0 in step S107, the authentication device 16 according to Embodiment 3 proceeds to the processing in step S109.
[0090] In step S109, the output unit 25 asks the user 4 whether or not to switch the operating mode to security mode. After that, the authentication device 16 proceeds to step S110.
[0091] In step S110, the authentication device 16 determines whether the input unit 26 has received a command to switch to security mode. If the input of a command to switch to security mode is received, the authentication device 16 proceeds to step S108. On the other hand, if the input of a command to switch to security mode is not received, the authentication device 16 terminates.
[0092] As described above, the access control device 14 according to Embodiment 3 comprises a mode management unit 24, an output unit 25, and an input unit 26. The mode management unit 24 manages the operating mode of the equipment applied to the building 2. The determination unit 22 calculates the number of occupants, which is the number of users 4 in the management area 3, based on the history of entry and exit to the management area 3 stored by the history management unit 21. Using the calculated number of occupants, the determination unit 22 determines whether the user 4 authenticated by the authentication unit 20 is the last person to exit the management area 3. When the determination unit 22 determines that the user 4 authenticated by the authentication unit 20 is the last person to exit the management area 3, the output unit 25 asks the user 4 whether to switch the operating mode to security mode, which corresponds to the situation where the management area 3 is unoccupied. When the input unit 26 receives a command from the user 4 to switch to security mode, the mode management unit 24 switches the operating mode to security mode. In this example, when the input unit 26 does not receive a command from the user 4 to switch to security mode, the mode management unit 24 maintains the operation mode in normal operation mode without switching to security mode.
[0093] User 4, who is alone in the management area 3, may temporarily leave the management area 3 for reasons such as eating or other reasons. In such cases, user 4 is asked whether it is necessary to switch to security mode, so user 4 does not have to switch back from security mode to normal operation mode after their temporary departure. This further enhances user 4's convenience. In addition, user 4 can perform the operation to switch to security mode on their own portable device 7, further enhancing user 4's convenience.
[0094] The output unit 25 may also inquire via the reader 8 whether or not to switch the operating mode to security mode. The input unit 26 may also receive a command to switch to security mode via the reader 8. This allows switching to security mode to be performed without operation by the building manager or other personnel, thereby reducing the workload for the manager or other personnel.
[0095] Furthermore, if the input unit 26 does not receive a command to switch to security mode within a predetermined confirmation time elapsed from the inquiry by the output unit 25, the mode management unit 24 may switch the operating mode to security mode. This reduces the likelihood of failure to switch to security mode.
[0096] Embodiment 4. In Embodiment 4, the differences from the examples disclosed in Embodiments 1 to 3 will be explained in particular detail. For features not described in Embodiment 4, any of the features from the examples disclosed in Embodiments 1 to 3 may be adopted.
[0097] Figure 13 is a diagram showing the configuration of the access control system 1 according to Embodiment 4.
[0098] The authentication device 16 includes an alarm generation unit 27. The alarm generation unit 27 is the part that generates an alarm to the monitoring device 13. The alarm generation unit 27 outputs alarm information to the monitoring device 13, for example, via a communication network 10.
[0099] Figures 14 and 15 illustrate an example of access control in the access control system 1 according to Embodiment 4.
[0100] As shown in Figure 14, in this example, user 4a, who possesses portable device 7a, and user 4b, who possesses portable device 7b, are both inside the management area 3. At this time, the operating mode of the equipment installed in building 2 is set to normal operation mode.
[0101] In building 2, receiver 11 receives wireless signals transmitted by mobile device 7a and mobile device 7b. In the location management device 15, positioning unit 18 calculates the location information of users 4a and 4b based on information such as the received strength of the wireless signals. Positioning unit 18 determines that both users 4a and 4b are inside the management area 3.
[0102] User 4b holds their mobile device 7b over the reader 8 inside the management area 3 in order to exit the management area 3. The reader 8, upon receiving the mobile device 7b, obtains user 4b's identification information from the mobile device 7b. The identification information of user 4b read by the reader 8 is transmitted to the authentication device 16 via the controller 9. When user 4b is authenticated by the authentication unit 20 of the authentication device 16, user 4b's authentication-based entry and exit information is stored in the history management unit 21. After authentication, user 4b opens door 5 and exits the management area 3. User 4a, the last to exit, exits the management area 3 following user 4b. Here, since user 4b has opened door 5, user 4a does not perform any authentication operations such as holding their mobile device 7a over the reader 8. Therefore, the reader 8 does not read user 4a's identification information from the mobile device 7a. Since entry and exit information representing user 4a's exit due to authentication is not stored as entry and exit history, the determination unit 22 calculates the number of people present as one user 4a based on the entry and exit history of the management area 3 stored by the history management unit 21.
[0103] Subsequently, as shown in Figure 15, users 4a and 4b retreat outside the management area 3. The receiver 11 in building 2 receives the wireless signals transmitted by mobile device 7a and mobile device 7b. In the location management device 15, the positioning unit 18 calculates the respective location information of users 4a and 4b based on information such as the received strength of the wireless signals. The positioning unit 18 determines that both users 4a and 4b are outside the management area 3.
[0104] Here, if, for example, due to a delay in communication or processing, or for other reasons, the entry / exit information representing user 4a's departure location has not been added to the entry / exit history by the registration unit 23, the determination unit 22 calculates the number of people present as one user 4a. On the other hand, the positioning unit 18 determines that both user 4a and user 4b are outside the management area 3, so there is no user 4 whose location information managed by the location management unit 19 is inside the management area 3. At this time, the alarm unit 27 sends an alarm to the monitoring device 13. The alarm unit 27 reports to the monitoring device 13, for example, that there are no people inside the management area 3, but that the security mode has not been switched. The monitor using the monitoring device 13 receives the alarm from the authentication device 16 and, for example, performs an operation to switch to security mode on the monitoring device 13. The monitoring device 13 outputs a control signal to switch the operating mode to security mode to the corresponding equipment, for example, through the communication network 10. As a result, the operating mode of the corresponding equipment is switched to security mode.
[0105] Figure 16 is a flowchart showing an example of processing in the access control system 1 according to Embodiment 4. Figure 16 shows an example of the processing of the authentication device 16. The location management device 15 according to Embodiment 4 performs the same processing as the location management device 15 according to Embodiment 2. The authentication device 16 according to Embodiment 4 performs the same processing as the authentication device 16 according to Embodiment 2 in steps S101 to S107 and in step S108. If the number of people in the management area 3 is calculated to be 0 in step S107, the authentication device 16 according to Embodiment 4 proceeds to the processing in step S108. If the number of people in the management area 3 is calculated to be 1 or more in step S107, the authentication device 16 according to Embodiment 4 proceeds to the processing in step S111. Note that if there is no notification of entry / exit information by location from the location management unit 19, the authentication device 16 may postpone the processing from steps S104 to S106, or may skip these processes.
[0106] In step S111, the alarm unit 27 determines whether user 4 is inside the management area 3 based on location information managed by the location management unit 19. If it is determined that user 4 is inside the management area 3 based on the location information, the authentication device 16 terminates. On the other hand, if it is determined that user 4 is not inside the management area 3 based on the location information, the authentication device 16 proceeds to step S112.
[0107] In step S112, the alarm generation unit 27 sends an alarm to the monitoring device 13. After that, the authentication device 16 completes its processing.
[0108] As described above, the access control device 14 according to Embodiment 4 includes an alarm unit 27. The alarm unit 27 alerts the monitoring device 13 when, despite the number of users 4 in the management area 3 being calculated based on the entry and exit history of the management area 3 stored by the history management unit 21 being one or more, there are no users 4 whose location information stored by the location management unit 19 is within the management area 3.
[0109] If the last person to exit leaves the management area 3 while tailgating, the last person to exit will not be authenticated. Even in such cases, an alert will be sent to the monitoring device 13, allowing the building's security personnel to switch to security mode. This reduces the likelihood of failure to switch to security mode, improves security in building 2, and can potentially reduce energy consumption in building 2.
[0110] To summarize the above explanation, the possible configurations of the technology relating to this disclosure include the configurations listed below as appendices. (Note 1) An authentication unit that authenticates a user based on identification information that identifies the user, read from a portable device carried by the user by a reader installed at the entrance / exit of a pre-set management area in the building, A history management unit that stores the history of entry and exit to the management area based on authentication by the authentication unit, A location management unit that stores the location information of a user in the building and the identification information of the user in association with each other, A determination unit determines whether or not there are users who have entered or left the management area without undergoing authentication by the authentication unit, based on the location information of the user stored by the location management unit and the history of entry and exit from the management area stored by the history management unit. When the determination unit determines that there is a user who has entered or left the management area without undergoing authentication by the authentication unit, the registration unit adds the user's entry and exit to the history of entry and exit to the management area stored in the history management unit. An access control device equipped with the following features. (Note 2) The location management unit stores the location information obtained based on the wireless signal used for wireless communication of the portable device read by the reader, as the location information of the user. Access control device as described in Appendix 1. (Note 3) Mode management unit for managing the operating modes of equipment applied to the aforementioned building. Equipped with, The determination unit uses the number of users in the management area, calculated based on the entry and exit history of the management area stored in the history management unit, to determine whether the user authenticated by the authentication unit is the last person to exit the management area. The mode management unit switches the operating mode to a security mode corresponding to the situation where the management area is unoccupied when the determination unit determines that the user authenticated by the authentication unit is the last person to exit the management area. Access control device as described in Appendix 1 or Appendix 2. (Note 4) A mode management unit that manages the operating modes of the equipment applied to the aforementioned building, An output unit that outputs information to be presented to the user, An input section that accepts input from the user, Equipped with, The determination unit uses the number of users in the management area, calculated based on the entry and exit history of the management area stored in the history management unit, to determine whether the user authenticated by the authentication unit is the last person to exit the management area. When the determination unit determines that the user authenticated by the authentication unit is the last person to exit the management area, the output unit asks the user whether or not to switch the operation mode to a security mode corresponding to the situation where the management area is unoccupied. The mode management unit switches the operating mode to the security mode when the input unit receives a command from the user who made the inquiry via the output unit to switch to the security mode. Access control device as described in Appendix 1 or Appendix 2. (Note 5) The output unit, via a portable device held by the user who has been determined by the determination unit to be the last person to exit the management area, inquires with the user whether or not to switch the operating mode to the security mode. The input unit receives a command to switch to the security mode through the operation of a portable device held by the user. Access control device as described in Appendix 4. (Note 6) The output unit, through the reading device, inquires whether or not to switch the operating mode to the security mode. The input unit receives a command to switch to the security mode through the reading device. Access control device as described in Appendix 4. (Note 7) An alarm unit triggers an alert to the monitoring device used for monitoring the building when, despite the number of users in the management area being calculated based on the entry and exit history of the management area stored in the history management unit being one or more, the location management unit stores location information indicating that there are no users within the management area. An access control device comprising any one of the features described in Appendix 3 to Appendix 6. (Note 8) A reading device installed at the entrance and exit of a pre-defined control area in the building, An authentication unit that authenticates a user based on identification information that identifies the user, read from the user's mobile device by the aforementioned reading device, A history management unit that stores the history of entry and exit to the management area based on authentication by the authentication unit, A location management unit that stores the location information of a user in the building and the identification information of the user in association with each other, A determination unit determines whether or not there are users who have entered or left the management area without undergoing authentication by the authentication unit, based on the location information of the user stored by the location management unit and the history of entry and exit from the management area stored by the history management unit. When the determination unit determines that there is a user who has entered or left the management area without undergoing authentication by the authentication unit, the registration unit adds the user's entry and exit to the history of entry and exit to the management area stored in the history management unit. An access control system equipped with the following features. (Note 9) Computers Authentication of a user is performed based on identification information that identifies the user, which is read from a user's mobile device by a reader installed at the entrance / exit of a pre-configured management area in the building. The system stores the history of entry and exit to the management area based on authentication using the aforementioned identification information, The location information of the user in the said building and the identification information of the said user are stored in association with each other. Based on the stored location information of the user and the stored history of entry and exit from the management area, it is determined whether or not there are users who have entered or exited the management area without undergoing authentication using the identification information. When it is determined that a user has entered or left the management area without undergoing authentication using the aforementioned identification information, the entry and exit of that user is added to the stored history of entry and exit to the management area. An access control method that implements this. (Note 10) On the computer, Authentication of a user is performed based on identification information that identifies the user, which is read from a user's mobile device by a reader installed at the entrance / exit of a pre-configured management area in the building. The system stores the history of entry and exit to the management area based on authentication using the aforementioned identification information, The location information of the user in the said building and the identification information of the said user are stored in association with each other. Based on the stored location information of the user and the stored history of entry and exit from the management area, it is determined whether or not there are users who have entered or exited the management area without undergoing authentication using the identification information. When it is determined that a user has entered or left the management area without undergoing authentication using the aforementioned identification information, the entry and exit of that user is added to the stored history of entry and exit to the management area. An access control program that executes the necessary actions. [Explanation of Symbols]
[0111] 1 Access control system, 2 Building, 3 Management area, 4, 4a, 4b Users, 5 Door, 6 Electric lock, 7, 7a, 7b Portable devices, 8 Reader, 9 Controller, 10 Communication network, 11 Receiver, 12 Edge server, 13 Monitoring device, 14 Access control device, 15 Location management device, 16 Authentication device, 17 Collection unit, 18 Positioning unit, 19 Location management unit, 20 Authentication unit, 21 History management unit, 22 Decision unit, 23 Registration unit, 24 Mode management unit, 25 Output unit, 26 Input unit, 27 Alarm unit, 100a Processor, 100b Memory, 200 Dedicated hardware
Claims
1. An authentication unit that authenticates a user based on identification information that identifies the user, read from a portable device carried by the user by a reader installed at the entrance / exit of a pre-set management area in the building, A history management unit that stores the history of entry and exit to the management area based on authentication by the authentication unit, A positioning unit that calculates the location information of users in the aforementioned building, A location management unit that stores the location information of a user in the building and the identification information of the user in association with each other, A determination unit determines whether or not there are users who have entered or left the management area without authentication by the authentication unit, based on the location information of the user stored in the location management unit and the history of entry and exit from the management area stored in the history management unit. When the determination unit determines that there is a user who has entered or left the management area without undergoing authentication by the authentication unit, the registration unit adds the user's entry and exit to the history of entry and exit to the management area stored in the history management unit. Equipped with, The positioning unit acquires the user's location information based on a wireless signal that includes the user's identification information and is transmitted from a portable device whose identification information is read by the reading device. The location management unit stores the location information obtained by the positioning unit based on a wireless signal containing the user's identification information, as the user's location information, associated with the user's identification information contained in the wireless signal. Access control device.
2. An authentication unit that authenticates a user based on identification information that identifies the user, read from a portable device carried by the user by a reader installed at the entrance / exit of a pre-set management area in the building, A history management unit that stores the history of entry and exit to the management area based on authentication by the authentication unit, A location management unit that stores the location information of a user in the building and the identification information of the user in association with each other, A determination unit determines whether or not there are users who have entered or left the management area without authentication by the authentication unit, based on the location information of the user stored in the location management unit and the history of entry and exit from the management area stored in the history management unit. When the determination unit determines that there is a user who has entered or left the management area without undergoing authentication by the authentication unit, the registration unit adds the user's entry and exit to the history of entry and exit to the management area stored in the history management unit. Equipped with, The location management unit stores the location information of the mobile device itself, which is included in the wireless signal transmitted from the mobile device that the reader reads, and which is calculated by the mobile device, in association with the user's identification information included in the wireless signal. Access control device.
3. An authentication unit that authenticates a user based on identification information that identifies the user, read from a portable device carried by the user by a reader installed at the entrance / exit of a pre-set management area in the building, A history management unit that stores the history of entry and exit to the management area based on authentication by the authentication unit, A positioning unit that calculates the location information of users in the aforementioned building, A location management unit that stores the location information of a user in the building and the identification information of the user in association with each other, A determination unit determines whether or not there are users who have entered or left the management area without authentication by the authentication unit, based on the location information of the user stored in the location management unit and the history of entry and exit from the management area stored in the history management unit. When the determination unit determines that there is a user who has entered or left the management area without undergoing authentication by the authentication unit, the registration unit adds the user's entry and exit to the history of entry and exit to the management area stored in the history management unit. Equipped with, The positioning unit acquires user identification information and location information by image recognition of images taken by cameras installed in the building, based on pre-registered feature quantities that identify the user. The position management unit stores the location information of the user obtained by the positioning unit for the user in the image, in association with the user's identification information obtained by the positioning unit. Access control device.
4. Mode management unit for managing the operating modes of equipment applied to the aforementioned building. Equipped with, The determination unit uses the number of users in the management area, calculated based on the entry and exit history of the management area stored in the history management unit, to determine whether the user authenticated by the authentication unit is the last person to exit the management area. The mode management unit switches the operating mode to a security mode corresponding to the situation where the management area is unoccupied when the determination unit determines that the user authenticated by the authentication unit is the last person to exit the management area. An access control device according to any one of claims 1 to 3.
5. A mode management unit that manages the operating modes of the equipment applied to the aforementioned building, An output unit that outputs information to be presented to the user, An input section that accepts input from the user, Equipped with, The determination unit uses the number of users in the management area, calculated based on the entry and exit history of the management area stored in the history management unit, to determine whether the user authenticated by the authentication unit is the last person to exit the management area. When the determination unit determines that the user authenticated by the authentication unit is the last person to exit the management area, the output unit asks the user whether or not to switch the operation mode to a security mode corresponding to the situation where the management area is unoccupied. The mode management unit switches the operating mode to the security mode when the input unit receives a command from the user who made the inquiry via the output unit to switch to the security mode. An access control device according to any one of claims 1 to 3.
6. The output unit, via a portable device held by the user who has been determined by the determination unit to be the last person to exit the management area, inquires with the user whether or not to switch the operating mode to the security mode. The input unit receives a command to switch to the security mode through the operation of a portable device held by the user. The access control device according to claim 5.
7. The output unit, through the reading device, inquires whether or not to switch the operating mode to the security mode. The input unit receives a command to switch to the security mode through the reading device. The access control device according to claim 5.
8. An alarm unit triggers an alert to the monitoring device used for monitoring the building when, despite the number of users in the management area being calculated based on the entry and exit history of the management area stored in the history management unit being one or more, the location management unit stores location information indicating that there are no users within the management area. The access control device according to claim 4, comprising:
9. A reading device installed at the entrance and exit of a pre-defined control area in the building, An access control device according to any one of claims 1 to 3, An access control system equipped with the following features.
10. Computers Authentication of a user is performed based on identification information that identifies the user, which is read from a user's mobile device by a reader installed at the entrance / exit of a pre-configured management area in the building. The system stores the history of entry and exit to the management area based on authentication using the aforementioned identification information, The user's location information within the building is obtained based on a wireless signal transmitted from a portable device that reads the user's identification information and which includes the user's identification information. Location information obtained based on a wireless signal containing the user's identification information and the user's identification information are stored in association with each other. Based on the stored location information of the user and the stored history of entry and exit from the management area, it is determined whether or not there are users who have entered or exited the management area without undergoing authentication using the identification information. When it is determined that a user has entered or left the management area without undergoing authentication using the aforementioned identification information, the entry and exit of that user is added to the stored history of entry and exit to the management area. An access control method that implements this.
11. Computers Authentication of a user is performed based on identification information that identifies the user, which is read from a user's mobile device by a reader installed at the entrance / exit of a pre-configured management area in the building. The system stores the history of entry and exit to the management area based on authentication using the aforementioned identification information, The user's identification information is stored in association with the location information of the mobile device itself within the building, which is calculated by the mobile device and is included in the wireless signal transmitted from the mobile device read by the reading device, and the user's identification information included in the wireless signal. Based on the stored location information of the user and the stored history of entry and exit from the management area, it is determined whether or not there are users who have entered or exited the management area without undergoing authentication using the identification information. When it is determined that a user has entered or left the management area without undergoing authentication using the aforementioned identification information, the entry and exit of that user is added to the stored history of entry and exit to the management area. An access control method that implements this.
12. Computers Authentication of a user is performed based on identification information that identifies the user, which is read from a user's mobile device by a reader installed at the entrance / exit of a pre-configured management area in the building. The system stores the history of entry and exit to the management area based on authentication using the aforementioned identification information, Based on pre-registered features that identify the user, the system acquires the user's location information within the building through image recognition of images captured by cameras installed in the building. Location information obtained based on features that identify a user and the aforementioned identification information of that user are stored in association with each other. Based on the stored location information of the user and the stored history of entry and exit from the management area, it is determined whether or not there are users who have entered or exited the management area without undergoing authentication using the identification information. When it is determined that a user has entered or left the management area without undergoing authentication using the aforementioned identification information, the entry and exit of that user is added to the stored history of entry and exit to the management area. An access control method that implements this.
13. On the computer, Access control method according to any one of claims 10 to 12 An access control program that executes the necessary actions.