Management system and management method

JP7916860B2Active Publication Date: 2026-09-08TOYOTA JIDOSHA KK
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023159177
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-09-22
Publication Date
2026-09-08
Estimated Expiration
2043-09-22

AI Technical Summary

Benefits of technology

【0008】 本開示によれば、セキュリティを確保しながら、第1対象及び第2対象の間の利用関係を追跡するための技術を提供することができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007916860000001
    Figure 0007916860000001
  • Figure 0007916860000002
    Figure 0007916860000002
  • Figure 0007916860000003
    Figure 0007916860000003
Patent Text Reader

Abstract

To provide a technology for tracking use relation between a first object and a second object while securing security.SOLUTION: A management system according to one aspect of the present disclosure comprises a first server, a second server, and a management server. In response to use relation occurring between a first object and a second object, the first server authenticates the first object in response to a request from a second terminal of the second object, and the second server authenticates the second object in response to a request from a first terminal of the first object. The management server receives the result of each authentication from each server, and when authentication of both the first object and the second object is successful, sets correspondence between a first identifier of the first object and a second identifier of the second object.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a management system, a management method, and a program. [Background Art]

[0002] Patent Document 1 proposes a toll collection system for collecting service fees from vehicle users using a medium such as a card. Specifically, the toll collection system proposed in Patent Document 1 uses an ID of an ETC (Electronic Toll Collection System) card, Based on the correspondence (billing information, registration information, payment information, and usage information) among a rental car operator, the rental car usage date and time, and the rental car user, the system is configured to allocate the charge for expressway usage by the target rental car to the target user. [Prior Art Documents] [Patent Documents]

[0003] [Patent Document 1] Japanese Unexamined Patent Publication No. 2022-140747 [Summary of the Invention] [Problem to be Solved by the Invention]

[0004] One object of the present disclosure is to provide a technique for tracking the usage relationship between a first object and a second object while ensuring security. [Means for Solving the Problem]

[0005] A management system according to a first aspect of this disclosure comprises a first server, a second server, and a management server. The first server is configured to receive a first authentication request for the first target from the second terminal of the second target in response to the establishment of a usage relationship between the first target and the second target, to authenticate the first target in response to the receipt of the first request, and to transmit the authentication result of the first target to the management server. The second server is configured to receive a second authentication request for the second target from the first terminal of the first target in response to the establishment of a usage relationship between the first target and the second target, to authenticate the second target in response to the receipt of the second request, and to transmit the authentication result of the second target to the management server. The management server is configured to receive the authentication results of the first target and the second target from the first server and the second server, and, if the authentication of both the first target and the second target is successful in the received authentication results of the first target and the second target, to set the correspondence between the first identifier of the first target and the second identifier of the second target.

[0006] A management method relating to a second aspect of this disclosure is an information processing method in which a management server receives the authentication result of the first target from a first server configured to authenticate the first target in response to the receipt of a first authentication request for the first target from the second terminal of the second target in response to the establishment of a usage relationship between the first target and the second target; receives the authentication result of the second target from a second server configured to authenticate the second target in response to the receipt of a second authentication request for the second target from the first terminal of the first target in response to the establishment of a usage relationship between the first target and the second target; and, if the authentication of both the first target and the second target is successful in the received authentication results for the first target and the second target, sets a correspondence between the first identifier of the first target and the second identifier of the second target.

[0007] The program relating to the third aspect of this disclosure is provided to the first terminal of the first target and the second target. This program is designed to perform the following actions when a usage relationship occurs between targets: providing the second terminal of the second target with the first unique information of the first target during data exchange with the second terminal of the second target, thereby causing the second terminal to send an authentication request for the first target, including the first unique information, to the first server on behalf of the first terminal; obtaining the second unique information of the second target from the second target; and sending an authentication request for the second target, including the obtained second unique information, to the second server, thereby causing the second server to attempt to authenticate the second target; and, if both the first and second targets are authenticated, sending the authentication result of the second target to the management server in order to set the correspondence between the first identifier of the first target and the second identifier of the second target on the management server. [Effects of the Invention]

[0008] This disclosure provides a technology for tracking the usage relationship between a first target and a second target while ensuring security. [Brief explanation of the drawing]

[0009] [Figure 1] Figure 1 schematically illustrates an example of a scenario in which this disclosure applies. [Figure 2] Figure 2 schematically illustrates an example of a scenario to which this disclosure applies. [Figure 3A] Figure 3A schematically shows an example of the linked information according to this embodiment. [Figure 3B] Figure 3B schematically shows an example of user information according to this embodiment. [Figure 3C] Figure 3C schematically shows an example of mobile information according to this embodiment. [Figure 4A] Figure 4A schematically shows an example of the unlinking process according to this embodiment. [Figure 4B] Figure 4B schematically shows an example of a simplified linking setup process according to this embodiment. [Figure 5]FIG. 5 schematically illustrates an example of a usage scenario of association information according to the present embodiment. [Figure 6A] FIG. 6A schematically illustrates an example of a hardware configuration of a management server according to the present embodiment. [Figure 6B] FIG. 6B schematically illustrates an example of a hardware configuration of a first server according to the present embodiment. [Figure 6C] FIG. 6C schematically illustrates an example of a hardware configuration of a second server according to the present embodiment. [Figure 6D] FIG. 6D schematically illustrates an example of a hardware configuration of a first terminal according to the present embodiment. [Figure 6E] FIG. 6E schematically illustrates an example of a hardware configuration of a second terminal according to the present embodiment. [Figure 7] FIG. 7 schematically illustrates an example of a software configuration of each device according to the present embodiment. [Figure 8A] FIG. 8A shows an example of a processing procedure for association setting according to the present embodiment. [Figure 8B] FIG. 8B shows an example of a processing procedure for association setting according to the present embodiment. [Figure 8C] FIG. 8C shows an example of a processing procedure for association setting according to the present embodiment. [Figure 8D] FIG. 8D shows an example of a processing procedure for association cancellation according to the present embodiment. [Figure 9] FIG. 9 schematically illustrates an example of an association setting process in a 1-1 proxy pattern according to the present embodiment. [Figure 10] FIG. 10 shows an example of a processing procedure for association setting in a 1-1 proxy pattern according to the present embodiment. [Figure 11] FIG. 11 schematically illustrates a modification of an association setting process in a 1-1 proxy pattern according to the present embodiment. [Figure 12] FIG. 12 schematically illustrates an example of an association setting process in a 1-2 proxy pattern according to the present embodiment. [Figure 13] FIG. 13 shows an example of a processing procedure for association setting in a 1-2 proxy pattern according to the present embodiment. [Figure 14] FIG. 14 schematically shows a modified example of the association setting process in the 1-2nd proxy pattern according to the present embodiment. [Figure 15] FIG. 15 schematically shows an example of the association setting process in the second proxy pattern according to the present embodiment. [Figure 16] FIG. 16 shows an example of the processing procedure for association setting in the second proxy pattern according to the present embodiment. [Figure 17] FIG. 17 schematically shows an example of the association setting process in the third proxy pattern according to the present embodiment. [Figure 18] FIG. 18 shows an example of the processing procedure for granting proxy authority in the third proxy pattern according to the present embodiment. DESCRIPTION OF EMBODIMENTS

[0010] According to the system proposed in Patent Document 1, a user can pay highway tolls via ETC even if the user does not carry their own ETC card. However, the inventors of the present invention have found that the conventional system has the following problems.

[0011] That is, with the diversification of MaaS (Mobility as a Service), advantages such as improved payment efficiency From a convenience standpoint, there is a need to track users' use of mobile devices while ensuring security. In contrast, conventional systems can maintain usage information, such as the correspondence between usage date and time and the user, based on rental car contracts or reservations. However, since this usage date and time depend on the contract or reservation, the usage information does not necessarily match the actual use of the rental car by the user. In addition, for vehicles used without a contract or reservation (e.g., private cars), the generation of usage information is not anticipated in the first place. Therefore, with conventional systems, it is difficult to track users' use of mobile devices while ensuring security. Moreover, this problem is not limited to situations where vehicles are used. Similar problems can occur when using mobile devices other than vehicles (e.g., aircraft, ships, etc.) and when using multiple types of mobile devices. Furthermore, similar problems can occur in any usage situation other than those involving mobile devices.

[0012] In contrast, the management system according to the first aspect of this disclosure comprises a first server, a second server, and a management server. The first server is configured to receive a first authentication request for the first target from the second terminal of the second target in response to the establishment of a usage relationship between the first target and the second target, to authenticate the first target in response to the receipt of the first request, and to transmit the authentication result of the first target to the management server. The second server is configured to receive a second authentication request for the second target from the first terminal of the first target in response to the establishment of a usage relationship between the first target and the second target, to authenticate the second target in response to the receipt of the second request, and to transmit the authentication result of the second target to the management server. The management server is configured to receive the authentication results for the first and second targets from the first and second servers, and, if the authentication of both the first and second targets is successful in the received authentication results for the first and second targets, to set the correspondence between the first identifier of the first target and the second identifier of the second target.

[0013] In the first aspect of this disclosure, authentication of the first and second targets is performed on the first and second servers, respectively, in response to the establishment of a usage relationship between the first and second targets. At this time, the authentication of the first target is requested not from the first terminal of the first target, but from the second terminal of the second target. The authentication of the second target is requested not from the second terminal, but from the first terminal. In other words, security can be expected to be ensured by cross-authentication, where each party proceeds with the authentication of the other rather than proceeding with its own authentication. Furthermore, when authentication of both the first and second targets is successful, a correspondence (linking) between the first identifier and the second identifier is established. The record of this linking setting allows for the establishment of a usage relationship between the first and second targets. The person in charge becomes traceable. Therefore, according to the first aspect of this disclosure, the usage relationship between the first object and the second object can be tracked while ensuring security.

[0014] The form of this disclosure is not limited to the examples above. As another form of the management system according to the above embodiment, one aspect of this disclosure may be an information processing device, an information processing method, a program, or a machine-readable storage medium that stores such a program, which implements all or part of the above components. Here, a machine-readable storage medium is a medium that stores information such as a program by electrical, magnetic, optical, mechanical, or chemical action. The information processing device may be at least one of the management server, first server, and second server according to the above embodiment. Furthermore, one aspect of this disclosure may be either a first terminal or a second terminal related to the management system according to the above embodiment. At least one of the first terminal and the second terminal may be included in the management system according to the above embodiment. Moreover, one aspect of this disclosure may be an information processing method, a program, or a storage medium that stores such a program, which are related to either the first terminal or the second terminal.

[0015] For example, a management method relating to a second aspect of this disclosure may be an information processing method in which a management server receives the authentication result of the first target from a first server configured to authenticate the first target in response to the receipt of a first authentication request for the first target from the second terminal of the second target in response to the establishment of a usage relationship between the first target and the second target; receives the authentication result of the second target from a second server configured to authenticate the second target in response to the receipt of a second authentication request for the second target from the first terminal of the first target in response to the establishment of a usage relationship between the first target and the second target; and, if the authentication of both the first target and the second target is successful in the received authentication results for the first target and the second target, sets up a correspondence between the first identifier of the first target and the second identifier of the second target.

[0016] Furthermore, for example, a program relating to the third aspect of this disclosure may be a program that causes the first terminal of the first target to, when a usage relationship occurs between the first target and the second target, to provide the second terminal with the first unique information of the first target during data exchange with the second terminal of the second target, thereby causing the second terminal to send an authentication request for the first target, including the first unique information, to the first server on behalf of the first terminal; to obtain the second unique information of the second target from the second target; and to send an authentication request for the second target, including the obtained second unique information, to the second server, thereby causing the second server to attempt authentication of the second target; and, if authentication of both the first target and the second target is successful, to send the result of authentication of the second target to the management server in order to set the correspondence between the first identifier of the first target and the second identifier of the second target on the management server.

[0017] Hereinafter, embodiments relating to one aspect of this disclosure (hereinafter also referred to as "this embodiment") will be described based on the drawings. However, this embodiment described below is merely illustrative in all respects of this disclosure. Various improvements or modifications may be made without departing from the scope of this disclosure. In implementing this disclosure, specific configurations may be adopted as appropriate depending on the embodiment. Although the data appearing in this embodiment is described in natural language, more specifically, it is specified in computer-recognizable pseudo-language, commands, parameters, machine code, etc.

[0018] [1. Application Examples] Figure 1 schematically shows an example of a scenario in which this disclosure is applied. The management system 100 according to this embodiment comprises a management server 1, a first server 2, and a second server 3. The management server 1 is one or more computers configured to record the correspondence (linking) between the first object and the second object. The first server 2 is one or more computers configured to perform authentication of the first object. It is a computer. The second server 3 is one or more computers configured to perform authentication for the second target. The first server 2 and the second server 3 may each be referred to as an authentication server, an ID (identification) server, etc.

[0019] In this embodiment, when a usage relationship is established between the first target and the second target, data exchange is performed between the first terminal 4 of the first target and the second terminal 5 of the second target (steps SA10, SB10). The first terminal 4 obtains data to be used for authentication of the second target, and the second terminal 5 obtains data to be used for authentication of the first target.

[0020] The second terminal 5 sends a first authentication request for the first target to the first server 2. In response, the first server 2 receives a first authentication request for the first target from the second terminal 5, in recognition of the establishment of a usage relationship between the first and second targets (step SA20). The first request includes data used for the authentication of the first target. The first server 2 authenticates the first target upon receiving the first request. The first server 2 sends the authentication result of the first target to the management server 1 (step SA30).

[0021] The first terminal 4 sends a second authentication request for the second target to the second server 3. In response, the second server 3 receives a second authentication request for the second target from the first terminal 4, in recognition of the establishment of a usage relationship between the first and second targets (step SB20). The second request includes data used for the authentication of the second target. The second server 3 authenticates the second target upon receiving the second request. The second server 3 sends the authentication result of the second target to the management server 1 (step SB30).

[0022] Management server 1 receives the authentication results for the first target and the second target from the first server 2 and the second server 3. If the authentication results for both the first target and the second target are successful, management server 1 sets up a correspondence (linking) between the first identifier I10 of the first target and the second identifier I20 of the second target (step SC20). In one example, management server 1 generates linking information D10 that shows the setting of the correspondence between the first identifier I10 and the second identifier I20, and saves the generated linking information D10. Management server 1 may return the result of this linking process to at least one of the first terminal 4 and the second terminal 5 (step SC30).

[0023] Furthermore, the series of processes from data exchange between terminals (4, 5) to linking settings may be executed in real time as usage relationships arise. The set linking (correspondence relationship) may be released as appropriate when the usage relationship between the first target and the second target ceases to exist. Setting the correspondence relationship between the first identifier I10 and the second identifier I20 may be treated as setting the correspondence relationship between the first target and the second target. In addition, the first terminal 4 requesting authentication of the second target from the second server 3, the second terminal 5 requesting authentication of the first target from the first server 2, the first server 2 sending the authentication result (result of successful authentication) of the first target to the management server 1, and the second server 3 sending the authentication result (result of successful authentication) of the second target to the management server 1 may each be treated as a request to the management system 100 (management server 1) to set the correspondence relationship (linking setting).

[0024] As described above, in this embodiment, when a usage relationship is established between the first target and the second target, authentication of the first target and the second target is performed on the first server 2 and the second server 3, respectively. At this time, authentication of the first target is requested from the second terminal 5 of the second target (step SA20). Authentication of the second target is requested from the first terminal 4 of the first target (step SB20). In other words, cross-referencing authentication is performed, where each party proceeds with the authentication of the other party rather than proceeding with their own authentication. This is expected to ensure security. Furthermore, when authentication of both the first target and the second target is successful, the first identifier I10 and the second identifier I2 A correspondence of 0 is set (step SC20). This linking setting is recorded (linking information D10), making it possible to track the usage relationship between the first target and the second target. Therefore, according to this embodiment, it is possible to track the usage relationship between the first target and the second target while ensuring security.

[0025] (subject) The first and second objects are not particularly limited as long as a utilization relationship can be established, and may be appropriately selected depending on the embodiment. The first and second objects may be any things such as objects, people, other living beings, etc. Any things may include virtual things. The establishment of a utilization relationship may be a real or virtual relationship between at least two things, such as one using the other, one possessing the other, one joining to the other, or one connecting to the other. The management system 100 of this disclosure may be used in any situation in which a correspondence between two or more things is tracked.

[0026] (terminal) Each terminal (4, 5) relates to each object. The relationship between each terminal (4, 5) and each object is not particularly limited and may be determined as appropriate depending on the embodiment. In one example, either the first terminal 4 or the second terminal 5 may be held by the corresponding object. Either the first terminal 4 or the second terminal 5 may be loaded onto the corresponding object. Loading may include not only being permanently placed on the object, but also being placed on the object at least temporarily when the object is being used. Loading may include being held by the user of the object. Furthermore, either the first terminal 4 or the second terminal 5 may be the object itself.

[0027] (certification) The first server 2 uses the data contained in the first request received from the second terminal 5 to perform authentication processing for the first target. The second server 3 uses the data contained in the second request received from the first terminal 4 to perform authentication processing for the second target. The method for authenticating each target is not limited and may be appropriately selected depending on the embodiment.

[0028] In one example, the first server 2 may be connected to a first storage device that stores first registered unique information C10 for authentication of the first target. The first storage device may consist of one or more storage devices deployed either inside or outside the first server 2. Registered unique information is unique information that has been registered in advance for authentication. The first storage device may store first identifier I10 and first registered unique information C10, and first registered unique information C10 may be associated with first identifier I10. First identifier I10 and first registered unique information C10 may be included in first target information O10 relating to the first target. The second terminal 5 may obtain first identifier I10 and first unique information C1 of the first target, and accordingly, the first request from the second terminal 5 may include first identifier I10 and first unique information C1 as data used for authentication of the first target.

[0029] Authenticating a first target may consist of comparing the first unique information C1 included in the received first request with the first registered unique information C10 associated with the first identifier I10. For example, the first server 2 may extract the first registered unique information C10 of the first target from the first target information O10 by using the first identifier I10 as a query to search for the first target information O10. The first server 2 may compare the extracted first registered unique information C10 with the received first unique information C1. Depending on the result of the comparison, the first server 2 may determine whether the authentication of the first target has been successful or not. The first server 2 may send the authentication result of the first target to the management server 1, attaching the first identifier I10 of the first target.

[0030] Similarly, the second server 3 stores the second registered unique information C20 for authentication of the second target. The second storage device may be connected to be accessible. The second storage device may consist of one or more storage devices deployed either inside or outside the second server 3. The second storage device may store the second identifier I20 and the second registered unique information C20, and the second registered unique information C20 may be associated with the second identifier I20. The second identifier I20 and the second registered unique information C20 may be included in the second target information O20 relating to the second target. The first terminal 4 may obtain the second identifier I20 and the second unique information C2 of the second target, and the second request from the first terminal 4 may include the second identifier I20 and the second unique information C2 as data used for authentication of the second target.

[0031] Authenticating a second target may consist of comparing the second unique information C2 included in the received second request with the second registered unique information C20 associated with the second identifier I20. For example, the second server 3 may extract the second registered unique information C20 of the second target from the second target information O20 by using the second identifier I20 as a query to look up the second target information O20. The second server 3 may compare the extracted second registered unique information C20 with the received second unique information C2. Depending on the result of the comparison, the second server 3 may determine whether the authentication of the second target was successful or not. The second server 3 may send the authentication result of the second target to the management server 1, attaching the second identifier I20 of the second target.

[0032] When a usage relationship is established between the first target and the second target, the first terminal 4 may provide the second terminal 5 with the first unique information C1 of the first target during data exchange with the second terminal 5. This allows the first terminal 4 to have the second terminal 5 send an authentication request for the first target, including the first unique information C1, to the first server 2 on behalf of the first terminal 4. The first terminal 4 may also obtain the second unique information C2 of the second target from the second target. By sending an authentication request for the second target, including the obtained second unique information C2, to the second server 3, the first terminal 4 may cause the second server 3 to attempt to authenticate the second target. Furthermore, if both the first and second targets are authenticated, the first terminal 4 may send the authentication result of the second target to the management server 1 in order to set the correspondence between the first identifier I10 and the second identifier I20 in the management server 1.

[0033] When a usage relationship is established between the first and second targets, the second terminal 5 may provide the first terminal 4 with the second unique information C2 of the second target during data exchange with the first terminal 4. This allows the second terminal 5 to have the first terminal 4 send an authentication request for the second target, including the second unique information C2, to the second server 3 on behalf of the second terminal 5. The second terminal 5 may also obtain the first unique information C1 of the first target from the first target. By sending an authentication request for the first target, including the obtained first unique information C1, to the first server 2, the second terminal 5 may cause the first server 2 to attempt to authenticate the first target. If both the first and second targets are authenticated, the second terminal 5 may send the authentication result of the first target to the management server 1 in order to set the correspondence between the first identifier I10 and the second identifier I20 in the management server 1.

[0034] Furthermore, if the authentication of the first target fails, the first server 2 may or may not send the authentication result to the management server 1. For example, the first server 2 may send the authentication result to the management server 1 only if the authentication of the first target is successful. If the authentication of the first target fails, the first server 2 may return the result to the second terminal 5 and cause the second terminal 5 to reissue the first authentication request for the first target. Similarly, the second server 3 may or may not send the authentication result to the management server 1 if the authentication of the second target fails. For example, the second server 3 may send the authentication result to the management server 1 only if the authentication of the second target is successful. If the authentication of the second target fails, the second server 3 may return the result to the first terminal 4 and cause the first terminal 4 to reissue the second authentication request for the second target.

[0035] (Unique information) Each unique piece of information (C1, C2) is used for authentication of each target. The data format and structure of each unique piece of information (C1, C2) are not particularly limited, as long as they can be used for authentication of each target, and may be appropriately selected depending on the embodiment. Each unique piece of information (C1, C2) may consist of arbitrary information such as information originating from each target, information originating from each terminal, temporarily generated information, and information generated by any other method.

[0036] Information originating from each object may include, for example, biometric information, uniquely assigned identification information, etc. Biometric information may include, for example, facial images, fingerprints, voiceprints, etc. Uniquely assigned identification information may include, for example, vehicle registration numbers, vehicle identification numbers (VINs), personal identification numbers, etc. If an IC tag is attached to an object, the uniquely assigned identification information may include the information held by the IC tag.

[0037] Information originating from each device may include, for example, the MAC address (Media Access Control address), device identification information (IMEI: International Mobile Equipment Identifier, IMSI: International Mobile Subscriber Identity, MEID: Mobile Equipment Identifier, ICCID: Integrated Circuit Card ID, and other serial numbers, etc.).

[0038] Temporarily generated information may include, for example, a one-time password or a private address (a dynamically generated address). Temporarily generated information may consist of a timestamp, random numbers, hash values, etc. Information generated by any other method may include, for example, passwords, passcodes, and other information other than symbolic sequences. At least some of the information, such as identification information and terminal-derived information, may be used as identifiers rather than unique information.

[0039] Each unique piece of information (C1, C2) may be acquired as appropriate. In one example, at least one of the first unique piece of information C1 and the second unique piece of information C2 may be stored in the corresponding terminal beforehand. For example, the first unique piece of information C1 may be stored in the first terminal 4. In another example, at least one of the first unique piece of information C1 and the second unique piece of information C2 may be acquired by any device such as an input device or sensor. For example, if the first target is a person and the first unique piece of information C1 is a face image, the face image may be acquired by an image sensor (camera).

[0040] (identifier) Each identifier (I10, I20) is used to identify each object. The data format and structure of each identifier (I10, I20) are not particularly limited, as long as they can identify each object, and may be appropriately selected depending on the embodiment. In one example, each identifier (I10, I20) may consist of a sequence of symbols including numbers, letters, etc.

[0041] Each identifier (I10, I20), like each unique piece of information (C1, C2), may be acquired as appropriate. In one example, at least one of the first identifier I10 and the second identifier I20 may be stored in the corresponding terminal beforehand. In another example, at least one of the first identifier I10 and the second identifier I20 may be acquired by any device such as an input device or sensor. For example, identifiers may be obtained by input via an input device. Alternatively, for example, identifiers may be converted into a code, and the identifier may be obtained by reading (decoding) that code.

[0042] (Server 1 / Server 2) The first server 2 and the second server 3 may each consist of one or more server devices. The first server 2 and the second server 3 may each be configured to manage target information (O10, O20) related to their respective targets.

[0043] In this embodiment, each target information (O10, O20) is used for the authentication of each target. This includes registered unique information (C10, C20). Each registered unique information (C10, C20) corresponds to each unique information (C1, C2) obtained during authentication. Each unique information (C10, C20) may be pre-registered at any time before a linking request, such as when creating an account or adding a new target.

[0044] The success or failure of authentication for each target is determined based on the result of matching each unique information (C1, C2) with each registered unique information (C10, C20). The matching method may be appropriately selected depending on the embodiment. In a simple example, the success or failure of authentication may be determined based on whether the received unique information matches the registered unique information. In another example, the success or failure of authentication may be determined based on the degree of matching between the received unique information and the registered unique information. A trained model generated by machine learning may be used for matching. During matching, the received unique information and the registered unique information may be compared directly, or they may be compared indirectly after being converted into features, etc.

[0045] The unit for managing each piece of target information (O10, O20) is not particularly limited and may be determined as appropriate depending on the embodiment. At least one of the first piece of target information O10 and the second piece of target information O20 may be managed centrally (as a whole) or distributed (separately) for each arbitrary group. The server devices constituting each server (2, 3) may be deployed by one or more operating organizations (entities). At least one of the first server 2 and the second server 3 may be deployed by multiple operating organizations. When deployed by multiple operating organizations, the target information may be shared (i.e., managed centrally) or distributed for each operating organization.

[0046] When authentication server devices are deployed in a distributed manner, each terminal (4, 5) may appropriately identify the server device to which it requests authentication. In one example, one of the first terminal 4 and the second terminal 5 may be notified of the server device to which it requests authentication by the other. In another example, the server device to which authentication is requested may be identifiable by at least one of the identifiers (I10, I20) and unique information (C1, C2), such as a telephone number or credit card number. In this case, each terminal (4, 5) may identify the server device to which authentication is requested by at least one of the identifiers (I10, I20) and unique information (C1, C2).

[0047] (Management Server) The management server 1 may consist of one or more server devices. The management server 1 of this disclosure is configured to record information regarding the occurrence and termination of correspondence between the first object and the second object as linking information D10. The linking information D10 may be held in one or more storage devices deployed either inside or outside the management server 1.

[0048] The resulting linking information D10 can be used in various situations. For example, linking information D10 can be used to track the relationship between a first object and a second object. Specifically, while a correspondence relationship is established between the first object and the second object, linking information D10 can be used to enable the exercise of authority associated with either the first object or the second object (first object information O10 and second object information O20) from the other object. In other words, linking information D10 can be used to enable the exercise of authority on either the first object or the second object from the other object, depending on the linking of the first and second objects (Figure 2, described later).

[0049] In this embodiment, the linking information D10 includes information on the first identifier I10 and the second identifier I20 in order to indicate a combination of a first target and a second target for which a correspondence relationship has been established. The management server 1 may acquire each identifier (I10, I20) for each target as appropriate. In one example, the management server 1 does not pre-store information on the first identifier I10 and the second identifier I20 for which the correspondence relationship is established, but acquires it each time from at least one of the servers (2, 3) and each terminal (4, 5). This is acceptable. In another example, the management server 1 may pre-store information on at least one of the first identifier I10 and the second identifier I20 for establishing the correspondence.

[0050] The relationship between the management server 1 and each server (2, 3) and their operating organizations is arbitrary. In one example, the operating organization of management server 1 may overlap with the operating organization of at least one of the first server 2 and the second server 3. In another example, the operating organization of management server 1 may be different from the operating organizations of the first server 2 and the second server 3. The management system 100 of this disclosure may be produced by connecting management server 1 to each server (2, 3) and each terminal (4, 5) via a network, and deploying each in a state capable of performing the above information processing according to the intentions of the operating organization of management server 1.

[0051] Furthermore, in the example shown in Figure 1, during authentication of each target, the first terminal 4 communicates with the second server 3 and the second terminal 5 communicates with the first server 2, but each terminal (4, 5) does not communicate with the management server 1. However, the processing steps in the management system 100 of this disclosure are not limited to this example. Each terminal (4, 5) may communicate with the management server 1 during authentication of each target. For example, the first terminal 4 may be instructed to send data to the second server 3 by communicating with the management server 1, and the second terminal 5 may also be instructed to send data to the first server 2 by communicating with the management server 1.

[0052] (Operation example) In one example, one of the first and second objects may be a user. Of the first terminal 4 and the second terminal 5, the terminal corresponding to the user may be a user terminal associated with that user. The other of the first and second objects may be an object used by the user. Of the first terminal 4 and the second terminal 5, the terminal corresponding to the object may be a loading terminal loaded onto the object. According to this example, it is possible to track the usage relationship between the user and the object while ensuring security.

[0053] The type of object used is not particularly limited as long as it can be used by the user, and may be appropriately selected depending on the embodiment. For example, the object used may be a mobile device. According to this example embodiment, the usage relationship between the user and the mobile device can be tracked. The type of mobile device may be appropriately selected. A mobile device may be, for example, a vehicle, a railway vehicle, an aircraft (aircraft, drone, etc.), a ship, etc. A mobile device may be at least one of a manually controlled manned aircraft or an automatically controlled unmanned aircraft. If the mobile device is a vehicle, the type of vehicle may be arbitrarily selected. The type of vehicle may be, for example, a two-wheeled vehicle, a three-wheeled vehicle, a four-wheeled vehicle, etc. A vehicle may include a private car, a rental car, a shared car, a taxi, a bus, etc. A vehicle may be at least one of an autonomous vehicle or a manually driven vehicle. The loading terminal may be called a mobile device terminal.

[0054] Figure 2 schematically illustrates one embodiment of a scenario in which the management system 100 of this disclosure is applied. In the example in Figure 2, the first object is the user, and the second object is the mobile object. For convenience, in the following explanation of the example in Figure 2, "first" will be treated as relating to the user, and "second" as relating to the mobile object. However, the correspondence between "first" and "second" is not limited to the example in Figure 2. "First" and "second" may be interchangeable. That is, the second object may be the user, and the first object may be the mobile object.

[0055] When the first target is a user, an example of the first terminal 4 is a user terminal. The user terminal may be any computer, such as a mobile terminal (smartphone, etc.), a dedicated device (electronic key device, etc.), or other computer device. Typically, the user terminal may be owned by the user who is the linked target (first target). The user's account may be on multiple computers. The account may be shared between users, and accordingly, each computer sharing the account may be used as a user terminal (first terminal 4) for the same user.

[0056] An example of the first identifier I10 is a user identifier (user ID, My ID). The user identifier may be, for example, a user account ID, a personal number, or user terminal identification information (e.g., MAC address, terminal identification information). An example of the first unique information C1 is user-specific information. User-specific information may be, for example, the user's biometric information (e.g., facial image, fingerprint, voiceprint, etc.), user terminal identification information, temporarily generated information, or other information generated by any method.

[0057] An example of the first target information O10 is user information O10A. User information O10A includes registered user-specific information. Registered user-specific information is an example of the first registered unique information C10 and corresponds to user-specific information obtained during authentication. In addition to registered user-specific information, user information O10A may include arbitrary information about the user (Figure 3B described later). In one example, user information O10A may include information about the corresponding user's authority and be associated with various information E10 for exercising that authority. Various information E10 may include, for example, public personal authentication information, payment information, and other service-related information. Public personal authentication information may include, for example, personal identification numbers. Payment information may include, for example, credit card information, internet banking information, and electronic payment information. Other service-related information may include, for example, information about electronic prescriptions (insurer number, prescription information, etc.). Various information E10 may be managed by an external system or by management system 100. The first server 2 may be deployed by public institutions, neutral organizations, various businesses (vehicle manufacturers, service providers, etc.). The first server 2 may also be called a user ID server, my ID server, etc.

[0058] On the other hand, when the second object is a moving object, an example of the second terminal 5 is a mobile terminal (loaded terminal). A mobile terminal may be, for example, a terminal attached to the inside or outside of a moving object, a terminal carried by a person involved in the operation of the moving object (e.g., driver, conductor, etc.), or equipment deployed in the facilities of the moving object (e.g., ticket gate, etc.). When the moving object is a vehicle, the mobile terminal may be called an in-vehicle terminal.

[0059] An example of the second identifier I20 is a mobile entity identifier (mobile entity ID, car ID). The mobile entity identifier may be, for example, the ID of a mobile entity account, identification information uniquely assigned to the target mobile entity (e.g., vehicle registration number, vehicle identification information, etc.), identification information of a mobile entity terminal, etc. An example of the second unique information C2 is mobile entity unique information. The mobile entity unique information may be, for example, identification information uniquely assigned to the target mobile entity, identification information of a mobile entity terminal, temporarily generated information, or other information generated by any method.

[0060] An example of the second target information O20 is mobile device information O20A. Mobile device information O20A includes registered mobile device-specific information. Registered mobile device-specific information is an example of the second registered unique information C20 and corresponds to the mobile device-specific information obtained during authentication. In addition to the registered mobile device-specific information, mobile device information O20A may include arbitrary information about the mobile device (see Figure 3C below). In the example in Figure 2, depending on the settings for linking the user and the mobile device, at least some of the permissions of the various information E10 associated with user information O10A may be enabled (activated) by the mobile device. The second server 3 may be deployed by public institutions, neutral institutions, various businesses (vehicle manufacturers, service operators, etc.). The second server 3 may be called a mobile device ID server, car ID server, etc.

[0061] A mobile object is an example of an object used. The configuration shown in Figure 2 can be applied to any case where the user (possessor) of the object changes dynamically. Besides mobile objects, other examples of objects used include rental items and accommodations. Accommodation facilities are acceptable. Rental items may include rental offices, rental spaces, etc.

[0062] The management system 100 may be configured to set up a link between the first identifier I10 and the second identifier I20 when the use of an item begins, and to unlink the link when the use ends. The start and end of use may be detected by any method at the timing of, for example, getting on and off a vehicle, lending out and returning an item. In one example, at least one of the start and end of use may be detected when data exchange takes place between the first terminal 4 and the second terminal 5.

[0063] Furthermore, items used can be divided into at least two types: those that can be used repeatedly over a long period of time, and those that can be used temporarily. For the sake of explanation, the former will be referred to as "regularly used items," and the latter as "temporarily used items." An example of regularly used items is the user's property, such as a private car. An example of temporarily used items is items owned by someone other than the user, such as rental cars, shared cars, public transportation, rental items, and accommodation facilities. Public transportation includes, for example, taxis, buses, train cars, aircraft, and ships.

[0064] In the management system 100, the type of user (whether it is a regularly used item or a temporary item) may or may not be distinguished. If the type of user is distinguished, the management system 100 may determine the type of user in any way. For example, the target information (mobile information, etc.) may include information indicating the type of user, and the management system 100 may determine the type of user based on this information. In another example, the type of user may be determined from at least one of an identifier and unique information. In yet another example, the information transmitted from at least one of the first terminal 4 and the second terminal 5 to the management server 1 may include information indicating the type of user, and the management system 100 may determine the type of user based on this information. In yet another example, if the operating organization of the server handling the user information (second server 3 in the example of Figure 2) is determined according to the type of user, the type of user may be determined according to the affiliation of the operating organization of the server.

[0065] Furthermore, the management system 100 may switch the form of, for example, the linking setting process, the conditions for unlinking, the management method of the linking information D10, and the authentication process, depending on the type of user identified. For example, the management system 100 may be configured to perform linking settings for some types of users using the authentication process of this disclosure, and to perform linking settings for the remaining types of users using an authentication process different from that of this disclosure.

[0066] Furthermore, the application of the management system 100 of this disclosure is not limited to situations where relationships between users and objects are tracked. In another example, both the first and second objects may be robotic devices configured to operate autonomously through automatic control. Robotic devices may include mobile objects such as autonomous vehicles and drones. In situations where two or more robotic devices interact autonomously, the management system 100 of this disclosure may be used to track the occurrence and termination of relationships between the robotic devices.

[0067] As a specific example, one of the first and second objects may be a large autonomous vehicle, and the other may be a small autonomous vehicle. The large autonomous vehicle may be configured to accommodate multiple small autonomous vehicles. The large autonomous vehicle may retrieve, transport, and release each small autonomous vehicle as appropriate. Each small autonomous vehicle may be operated as appropriate at its release destination. In this case, the management system 100 of this disclosure may be configured to track whether or not a vehicle is being transported (retrieved) by setting and releasing the correspondence between the large autonomous vehicle and the small autonomous vehicles.

[0068] (Method of correspondence) In this embodiment, the management server 1 receives the authentication result for the first target from the first server 2 and the authentication result for the second target from the second server 3. In order to identify the combination of the first and second targets for which a correspondence setting is currently requested, the management server 1 identifies the correspondence of the authentication results received from each server (2, 3). Then, if authentication of the first and second targets is successful in the associated authentication result, the management server 1 sets a correspondence between the first and second targets in the associated authentication result.

[0069] The mapping may be identified in any way. For example, the data transmitted from each terminal (4, 5) to the management server 1 via each server (2, 3) may include shared information for identifying the mapping. The shared information may consist of information that has relationships, such as matching or establishing a correspondence. The management server 1 may identify the mapping in accordance with whether a relationship is established (matching is established) between the shared information contained in the data (authentication results) received through each route. The shared information may be configured as appropriate depending on the embodiment. The shared information may be acquired at each terminal (4, 5) at any time, such as during data exchange. Each terminal (4, 5) may send an authentication request including the shared information to each server (2, 3). Each server (2, 3) may send the shared information along with the authentication result to the management server 1 (i.e., relay the shared information).

[0070] In one example, the shared information may include a combination of a first identifier I10 and a second identifier I20. Each terminal (4, 5) sends an authentication request including the first identifier I10 and the second identifier I20, and each server (2, 3) relays this, so that the management server 1 can receive authentication results including the first identifier I10 and the second identifier I20 from each route. The management server 1 may associate the authentication results of each route by comparing the first identifier I10 and the second identifier I20 included in the authentication result of each route.

[0071] That is, the first request may include a first identifier I10 and a second identifier I20. The second request may also include a first identifier I10 and a second identifier I20. Transmitting the authentication result of the first target may consist of transmitting the authentication result of the first target with the first identifier I10 and second identifier I20 included in the first request attached. Transmitting the authentication result of the second target may consist of transmitting the authentication result of the second target with the first identifier I10 and second identifier I20 included in the second request attached. The management server 1 may associate the received authentication results of the first and second targets according to the match between the first identifier I10 and second identifier I20 attached to the authentication result of the first target received from the first server 2 and the first identifier I10 and second identifier I20 attached to the authentication result of the second target received from the second server 3. Setting the correspondence between the first identifier I10 and the second identifier I20 may consist of setting the correspondence between the first identifier I10 and the second identifier I20 corresponding to the authentication results of the first and second targets that are associated with each other. According to one example of this embodiment, the data for each route can be associated with the management server 1 in a simplified manner, thereby enabling the setting of the correspondence to be performed appropriately.

[0072] Furthermore, the first terminal 4 may obtain the first identifier I10 at any time before sending the authentication request. For example, the first identifier I10 may be stored in the memory resources of the first terminal 4, and the first terminal 4 may obtain the first identifier I10 from the memory resources. In another example, the first terminal 4 may obtain the first identifier I10 using an input device, sensor, etc. The same applies to the second terminal 5 obtaining the second identifier I20. For example, the second terminal 5 may obtain the second identifier I20 from its memory resources. In another example, the second terminal 5 may obtain the second identifier I20 using an input device, sensor, etc.

[0073] In another example, the shared information may include supplementary information for verification. The supplementary information may be provided as appropriate. In a typical example, the supplementary information is used in the data exchange between the first terminal 4 and the second terminal 5. It may be generated by each server (2, 3). For example, each server (2, 3) may receive arbitrary shared information, such as a combination of the first identifier I10 and the second identifier I20, from each terminal (4, 5). Each server (2, 3) may generate the supplementary information by transforming (for example, hashing) the shared information received from each terminal (4, 5). Management server 1 may receive authentication results including the supplementary information from each route. Management server 1 may associate the authentication results of each route by comparing the supplementary information included in the authentication results of each route.

[0074] In other words, transmitting the authentication result of the first target may consist of transmitting the authentication result of the first target with the first ancillary information attached. Transmitting the authentication result of the second target may consist of transmitting the authentication result of the second target with the second ancillary information attached. Management server 1 may compare the first ancillary information attached to the authentication result of the first target received from first server 2 with the second ancillary information attached to the authentication result of the second target received from second server 3. The comparison may be performed in any way. For example, the comparison may be performed in the same way as the unique information described above. The comparison may be, for example, determining whether a relationship is established, such as a match or a correspondence relationship. Management server 1 may associate the received authentication results of the first and second targets according to the success of the comparison of the first and second ancillary information. Setting the correspondence relationship between the first identifier I10 and the second identifier I20 may consist of setting the correspondence relationship between the first identifier I10 and the second identifier I20 that corresponds to the authentication results of the first and second targets that are associated with each other. In one example of this embodiment, by using supplementary information, the data for each route can be associated with the management server 1, thereby enabling the setting of the correspondence relationship to be performed appropriately. In another example, the shared information may consist of the first identifier I10, the second identifier I20, and the supplementary information.

[0075] The configuration of the supplementary information may be appropriately selected depending on the embodiment. In one example, the first and second supplementary information may consist of temporary information such as timestamps, random numbers, and hash values. By using temporary information as supplementary information, the reuse of shared information can be suppressed. As a result, improved security can be expected.

[0076] As described above, supplementary information may be generated in at least one of the terminals (4, 5) and servers (2, 3). For example, the usage relationship between the first target and the second target may arise when data communication is performed between the first terminal 4 and the second terminal 5. Shared temporary information may be generated during the data communication between the first terminal 4 and the second terminal 5. The first request and the second request may each include the generated shared temporary information. The first supplementary information may be obtained from the shared temporary information included in the first request. The second supplementary information may be obtained from the shared temporary information included in the second request. This makes it possible to appropriately obtain supplementary information composed of temporary information, and as a result, improved security can be expected. The shared temporary information may be generated as appropriate by at least one of the first terminal 4 and the second terminal 5. Furthermore, obtaining supplementary information may involve, for example, using the temporary information as supplementary information as is, or generating supplementary information by performing a predetermined conversion process on the temporary information.

[0077] Furthermore, if management server 1 receives an authentication result from either first server 2 or second server 3, and does not receive an authentication result from the other server within a certain period, it may query the other server. For example, if the data for each route includes a first identifier I10 and a second identifier I20, management server 1 may query the server that is experiencing a delay in sending the authentication result by notifying the corresponding identifiers (notifying first server 2 of the first identifier I10 and second server 3 of the second identifier I20).

[0078] Each server (2, 3) sends the authentication result to the management server 1 in response to the inquiry. The following processes may be executed. For example, if the authentication process is delayed, each server (2, 3) may increase the priority of the authentication process for the target specified in the query (for example, the target specified by the identifier included in the query) and shorten the time until the authentication result is sent. In another example, if an authentication request has not been received from the terminal (4, 5), each server (2, 3) may query the target terminal (4, 5) specified in the query.

[0079] (Data exchange) In this embodiment, the series of processes related to the linking settings may be triggered by data exchange between the first terminal 4 and the second terminal 5 (steps SA10 and SB10). The method of data exchange is not particularly limited and may be appropriately selected depending on the embodiment.

[0080] For example, data exchange between the first terminal 4 and the second terminal 5 may be performed by wireless or wired data communication. Wireless communication may be performed by, for example, NFC (Near Field Communication), Bluetooth (registered trademark), Wi-Fi (registered trademark), etc. Wired communication may be performed by, for example, wired LAN (Local Area Network), USB (Universal Serial Bus), etc. Data communication may take place directly between the first terminal 4 and the second terminal 5, or indirectly via another computer. In another example, data exchange may be performed by methods other than data communication, such as reading a two-dimensional code. For example, data exchange may take place when one of the first terminal 4 or the second terminal 5 displays data on a display, and the other uses a sensor, such as an image sensor, to read the displayed data.

[0081] At least part of the process in which the first terminal 4 provides the first identifier I10 and the first unique information C1 to the second terminal 5, and the process in which the second terminal 5 provides the second identifier I20 and the second unique information C2 to the first terminal 4, may be performed during data exchange. Alternatively, during data exchange, the first terminal 4 may acquire the second identifier I20 and the second unique information C2 through a voluntary action, and the second terminal 5 may acquire the first identifier I10 and the first unique information C1 through a voluntary action.

[0082] In one example, if the second terminal 5 holds at least one of the second identifier I20 and the second unique information C2, the first terminal 4 may obtain at least one of the second identifier I20 and the second unique information C2 from the second terminal 5 by data communication. In another example, the first terminal 4 may obtain at least one of the second identifier I20 and the second unique information C2 from the second terminal 5 by a method other than data communication, such as reading data displayed as a two-dimensional code on the second terminal 5. In yet another example, the first terminal 4 may, in data exchange, use a device such as an input device or sensor to obtain at least one of the second identifier I20 and the second unique information C2 from either the second object or the second terminal 5. Obtaining from the second object may include obtaining it by the first object operating a device on behalf of the first object, if the first object is a person and the second object is an object. The same applies to the acquisition of the first identifier I10 and the first unique information C1 by the second terminal 5.

[0083] For example, in the example shown in Figure 2 above, the first terminal 4 may obtain the second identifier I20 (mobile entity identifier) ​​by data communication or by reading a code. If the second unique information C2 (mobile entity unique information) is a vehicle registration number, the first terminal 4 may obtain the second unique information C2 by taking a picture of the license plate with an image sensor and analyzing the obtained image. The second terminal 5 may also obtain the first identifier I10 (user identifier) ​​by data communication or by reading a code. If the first unique information C1 (user unique information) is a facial image, the second terminal 5 may obtain the first unique information C1 by taking a picture of the user's face with an image sensor.

[0084] When an input device is used to acquire data, one terminal acquiring data from another object is equivalent to the other object acquiring data from the other object by operating the input device. Furthermore, this may include the acquisition of data from the other object by one object operating an input device. For example, in the example in Figure 2 above, if the second unique information C2 (mobile object unique information) is a vehicle registration number and an input device is used to acquire the vehicle registration number, the first terminal 4 may acquire the second unique information C2 from the mobile object (second object) by the input of the vehicle registration number via the input device by the user (first object).

[0085] Furthermore, the acquisition of data from one terminal to the other terminal does not necessarily have to be performed during data exchange. One terminal may acquire data from the other terminal at any time other than the data exchange. Any of the above methods may be used for data acquisition. In this case, the data exchange between the first terminal 4 and the second terminal 5 may function merely as a trigger to start a series of processes related to the linking settings.

[0086] (Linking information) Figure 3A schematically shows an example of the linking information D10 according to this embodiment. In the example in Figure 3A, the linking information D10 includes a first identifier I10, a second identifier I20, a setting time, and a release time. The first identifier I10 and the second identifier I20 indicate the first and second targets with which a correspondence (linking) has been established. The setting time indicates the time when the correspondence was established. The setting time may consist of a timestamp. The release time indicates the time when the correspondence was released. The value of the release time may be added when a process to release the correspondence is executed. The method of expressing release is not limited to this example. In another example, the release time may be replaced with at least one of an expiration date and a flag. The expiration date indicates the period during which the setting of the correspondence is valid. In this case, whether or not the setting of the correspondence is valid (i.e., whether the correspondence is established or released) is indicated depending on whether or not it is within the expiration date. The flag indicates whether or not the correspondence has been released. The flag may be set when a process to release the correspondence is executed. In yet another example, the linking information D10 may include at least one of an expiration date and a flag, along with a field for the release time. The configuration of the linking information D10 is not limited to the example in Figure 3A, and may be modified as appropriate depending on the embodiment, as long as the setting of the correspondence can be shown. In yet another example, the linking information D10 may further include information indicating the type of item used (whether it is a regularly used item or a temporary item). The type of item used does not necessarily have to be identified by separate information. For example, the type of item used may be identified by information such as an identifier.

[0087] The data format of the linking information D10 is not particularly limited and may be appropriately selected depending on the embodiment. The linking information D10 may be stored in any database infrastructure. In one example, the linking information D10 may be stored in a relational database such as a table. In another example, the linking information D10 may be stored on a blockchain infrastructure. In this case, each linking setting and unlinking transaction may be accumulated on the blockchain as linking information D10. For example, a linking setting transaction may include a first identifier I10, a second identifier I20, and the setting time. An unlinking transaction may include a first identifier I10, a second identifier I20, and the unlinking time (or information indicating unlinking).

[0088] (First target information) The first target information O10 includes the first registered unique information C10. The first target information O10 may include any information about the first target other than the first registered unique information C10. For example, the first target information O10 may include the first identifier I10, attribute information of the first target, information about permissions, etc. In the example in Figure 2, user information O10A is an example of the first target information O10.

[0089] Figure 3B schematically shows an example of user information O10A according to this embodiment. Example of Figure 3B The user information O10A includes a user ID (first identifier I10), registered user-specific information (first registered unique information C10), attribute information, and authorization information. The attribute information may include any information relating to the attributes of the corresponding user. For example, the attribute information may include personal information such as name, address, age, gender, and contact information. The authorization information relates to the authorizations of the corresponding user. For example, the authorization information may include information for coordinating with a server that performs information processing related to the target authorization, and information indicating association with various types of information E10. Note that the configuration of user information O10A is not limited to the example in Figure 3B and may be modified as appropriate depending on the embodiment.

[0090] The data format of the first target information O10 (user information O10A) is not particularly limited and may be appropriately selected depending on the embodiment. The first target information O10 (user information O10A) may be stored in any database infrastructure. In one example, the first target information O10 (user information O10A) may be stored in a relational database such as a table format. In another example, the first target information O10 (user information O10A) may be stored on a blockchain infrastructure.

[0091] (Second target information) The second target information O20 includes the second registered unique information C20. The second target information O20 may include any information about the second target other than the second registered unique information C20. The second target information O20 may include, for example, the second identifier I20, attribute information of the second target, information about authorizations, etc. In the example in Figure 2, mobile information O20A is an example of the second target information O20.

[0092] Figure 3C schematically shows an example of mobile information O20A according to this embodiment. In the example in Figure 3C, mobile information O20A includes a mobile ID (second identifier I20), registered mobile unique information (second registered unique information C20), and attribute information. The attribute information includes a number, type, and owner information. If the mobile is a vehicle, the number is the vehicle registration number, and the type is the vehicle type. If the vehicle registration number is used as the mobile unique information, the number may be omitted from the attribute information. The owner information may include arbitrary information about the owner of the mobile. For example, the owner information may include personal information of the owner such as name, address, age, gender, and contact information. The owner may also be a corporation. Note that the configuration of mobile information O20A is not limited to the example in Figure 3C and may be modified as appropriate depending on the embodiment. The configuration of the attribute information may also be modified as appropriate. For example, mobile information O20A may further include information about the mobile terminal, such as the contact information of the mobile terminal.

[0093] The data format of the second target information O20 (mobile entity information O20A) is not particularly limited and may be appropriately selected depending on the embodiment. The second target information O20 (mobile entity information O20A) may be stored in any database infrastructure. In one example, the second target information O20 (mobile entity information O20A) may be stored in a relational database such as a table format. In another example, the second target information O20 (mobile entity information O20A) may be stored on a blockchain infrastructure.

[0094] (Notification method for linking settings) The management server 1 may send a notification indicating the result of the linking process to at least one of the first terminal 4 and the second terminal 5 (step SC30). The notification transmission route is not particularly limited and may be determined as appropriate depending on the embodiment. In one example, the management server 1 may directly notify at least one of the first terminal 4 and the second terminal 5 (Figures 1 and 2). In another example, the management server 1 may indirectly notify at least one of the first terminal 4 and the second terminal 5 via external computers such as each server (2 and 3).

[0095] If direct notification is required, management server 1 will obtain the contact information for each terminal (4, 5) as appropriate. You may do so. Contact information includes phone number, email address, account information for communication applications (e.g., Social Networking Service applications), identification number, etc. This may be the case. For example, in at least one of the routes from step SA10 to step SA30 and from step SB10 to step SB30, the data arriving at the management server 1 from each terminal (4, 5) may include information indicating the contact details of each terminal (4, 5). The management server 1 may obtain information indicating the contact details of each terminal (4, 5) in the received data. The information indicating the contact details may be transmitted from at least one of each terminal (4, 5) and each server (2, 3).

[0096] (Confirmation process for continued use) As one of the optional configurations, after setting the correspondence between the first target and the second target, the management server 1 may further perform a process (confirmation process) to check whether the correspondence continues or not. The method for confirming continued use may be appropriately selected depending on the embodiment.

[0097] In one example, the continuation of the correspondence relationship may be confirmed by authenticating at least one of the first target and the second target via at least one of the first terminal 4 and the second terminal 5. Authentication in the confirmation process may be performed in the same way as authentication using unique information (C1, C2), or it may be different. To increase certainty, the other target may be authenticated via one of the first terminal 4 and the second terminal 5, similar to the authentication route during the linking setting described above. In the example in Figure 2, user authentication may be performed by methods such as using an image sensor installed on the mobile device to perform facial recognition of the user, using a fingerprint reader attached to the handle to perform fingerprint authentication of the user, or having the user speak and performing voiceprint authentication using a microphone installed on the mobile device. The authentication process may be performed on the terminals (4, 5) or on the servers (2, 3). When the authentication process is performed on the servers (2, 3), the data used for authentication may be sent directly from the terminals (4, 5) to the servers (2, 3), or it may be sent indirectly via an external computer such as the management server 1. The data used for authentication in the verification process may be the same as or different from the unique information (C1, C2). The management server 1 may obtain the authentication result as appropriate, and if the authentication is successful in the obtained authentication result, it may determine that the correspondence relationship is continuing, and if the authentication is unsuccessful, it may determine that the correspondence relationship is not continuing.

[0098] In another example, if at least one of the first and second targets is a user (for example, the case in Figure 2), the management server 1 may directly or indirectly send a confirmation notification including an operator to at least one of the first terminal 4 and the second terminal 5. The operator may consist of, for example, a confirmation button, a reply button, a link, etc. The recipient of the confirmation notification does not necessarily have to correspond to a user. In the case of Figure 2, the management server 1 may send a confirmation notification to at least one of the first terminal 4 and the second terminal 5. The recipient of the confirmation notification may overlap with or differ from the recipient of the notification indicating the result of the linking process. The confirmation notification may be configured to send a response directly or indirectly back to the management server 1 in response to the user's operation of the operator. If the management server 1 receives a response from the operator operation within a predetermined period, it may determine that the correspondence is continuing, and if it does not receive a response, it may determine that the correspondence is not continuing.

[0099] In another example, when tracking the correspondence between a first and second object in the real world, each terminal (4, 5) may be equipped with a positioning module such as a GPS (Global Positioning Satellite) module or a GNSS (Global Navigation Satellite System) module. The first terminal 4 may measure the current location of the first object (first terminal 4) using its positioning module, and the second terminal 5 may measure the current location of the second object (second terminal 5) using its positioning module. Each terminal (4, 5) may transmit the obtained current location of each object directly to the management server 1 or indirectly via an external computer such as each server (2, 3). The management server 1 receives the data. Whether the correspondence relationship continues can be determined based on whether the current location of each object is close enough to satisfy predetermined conditions for the usage relationship (for example, the user is riding in a mobile vehicle). That is, the management server 1 may determine that the correspondence relationship continues if the current locations of each object are close enough to satisfy predetermined conditions, and that the correspondence relationship does not continue otherwise. If this configuration is adopted, the management server 1 may store the obtained information on the current location of each object in association with the linking information D10. This allows the management server 1 to track the movement history of each object along with the correspondence relationship of each object. Furthermore, at least a part of the above processing may be executed on a computer other than the management server 1.

[0100] If the management server 1 determines that the correspondence relationship is continuing, it may maintain the setting of the correspondence relationship. On the other hand, if the management server 1 determines that the correspondence relationship is not continuing, it may terminate the correspondence relationship. The management server 1 may be configured to update the status of the correspondence relationship by repeatedly executing the confirmation process periodically or irregularly from the time the correspondence relationship is established until the correspondence relationship is terminated.

[0101] (Unlink) In this embodiment, the management server 1 may be configured to terminate the correspondence upon receiving a termination request from at least one of the first terminal 4 and the second terminal 5, or upon fulfilling a predetermined termination condition.

[0102] (I) Cancellation Request In one example, a request to unlink (unlink) includes at least one of the first identifier I10 and the second identifier I20. Simply put, the first terminal 4 may send an unlinking request to the management server 1 that includes the first identifier I10 but does not include the second identifier I20. Similarly, the second terminal 5 may send an unlinking request to the management server 1 that includes the second identifier I20 but does not include the first identifier I10. If duplication of correspondence settings is permitted, the unlinking request may include both the first identifier I10 and the second identifier I20. In one example, either the first terminal 4 or the second terminal 5 may send an unlinking request to the management server 1 that includes both the first identifier I10 and the second identifier I20. In another example, the first terminal 4 may send an unlinking request that includes one of the first identifier I10 and the second identifier I20, and the second terminal 5 may send an unlinking request that includes the other. In yet another example, the management server 1 may assign identifiers to the configured correspondences and notify at least one of the first terminal 4 and the second terminal 5 of the assigned identifiers at any time, such as in a notification indicating the result of the linking process. At least one of the first terminal 4 and the second terminal 5 may specify the correspondence to be unlinked by sending an unlinking request containing this identifier to the management server 1, and cause the management server 1 to unlink the specified correspondence. According to this example, the first identifier I10 and the second identifier I20 can be omitted from the information included in the unlinking request. This is expected to improve the efficiency of data communication in the unlinking request.

[0103] When the first terminal 4 sends a release request that includes the second identifier I20, the first terminal 4 may retrieve the second identifier I20 at any time. In a typical example, the first terminal 4 may store the second identifier I20 obtained when the request for the above-mentioned linking setting was made as the current linking information in its memory resources. When a request for release is made, the first terminal 4 may retrieve the second identifier I20 from its memory resources. The first terminal 4 may also retrieve the first identifier I10 at any time. In one example, the first identifier I10 may be stored in the memory resources in advance. When creating the current linking information, the first terminal 4 may store the second identifier I20 in association with the first identifier I10. When sending a release request, the first terminal 4 may retrieve the first identifier I10 from its memory resources.

[0104] Similarly, if the second terminal 5 sends a release request that includes the first identifier I10, the second terminal 5 may obtain the first identifier I10 at any time. In a typical example, the second terminal 5 The first identifier I10 obtained when requesting the above linking setting may be stored in memory resources as the current linking information. When requesting to unlink, the second terminal 5 may obtain the first identifier I10 from memory resources. The second terminal 5 may also obtain the second identifier I20 at any time. For example, the second identifier I20 may be stored in memory resources in advance. When creating the current linking information, the second terminal 5 may store the first identifier I10 in association with the second identifier I20. When sending an unlinking request, the second terminal 5 may obtain the second identifier I20 from memory resources.

[0105] Figure 4A schematically shows an example of the unlinking process according to this embodiment. In the example in Figure 4A, as the first route, the first terminal 4 directly sends an unlinking request to the management server 1 (step SZ10). Also, as the second route, the first terminal 4 gives instructions to the second terminal 5 (step SZ10A), causing the second terminal 5 to directly send an unlinking request to the management server 1 (step SZ11A). However, the transmission route of the unlinking request is not limited to this example. The first terminal 4 may indirectly send an unlinking request to the management server 1 via an external computer such as the first server 2. In the second route, the second terminal 5 may indirectly send an unlinking request to the management server 1 via an external computer such as the second server 3. Note that the starting point of unlinking is not limited to the first terminal 4. In another example, the second terminal 5 may directly or indirectly send an unlinking request to the management server 1. Furthermore, the second terminal 5 may instruct the first terminal 4 to directly or indirectly send a release request to the management server 1. After receiving the release request, the management server 1 refers to the linking information D10 and releases the correspondence specified by the identifier included in the release request. After this release process, the management server 1 may send a notification indicating the result of the release process to at least one of the first terminal 4 and the second terminal 5, similar to the time of linking setup.

[0106] In one example, the processing of a cancellation request may include authentication processing for at least one of the first and second targets. The authentication processing may be the same as the authentication processing in the linking setting process or the confirmation process for continued use described above. However, authentication processing is not necessarily required when a cancellation request is made. In another example, the processing of a cancellation request may be simplified by omitting the authentication processing.

[0107] The trigger for the cancellation request may be set as appropriate depending on the embodiment. In one example, if at least one of the first target and the second target is a user, a cancellation request may be sent from at least one of the first terminal 4 and the second terminal 5 by an operation of at least one of the first terminal 4 and the second terminal 5 by the user. In other words, the trigger for the cancellation request may be an operation by the user. In another example, upon termination of the usage relationship, arbitrary information processing may be performed on at least one of the first terminal 4 and the second terminal 5. This arbitrary information processing may be used as a trigger to send a cancellation request from at least one of the first terminal 4 and the second terminal 5. For example, the arbitrary information processing may be data exchange between the first terminal 4 and the second terminal 5. The method of data exchange when a cancellation request is made may be the same as the data exchange when setting up the linking (steps SA10 and SB10). The distinction between data exchange when setting up the linking and data exchange when a cancellation request is made may be appropriately distinguished. For example, in the example in Figure 2, the second terminal 5 may be equipped with separate sensor devices at the entrance and exit, such as at a bus entrance / exit or a train ticket gate. In this case, depending on the sensor device used for data exchange, a distinction may be made between the time of linking setup and the time of unlinking request. Also, for example, if data exchange is performed by an application on a terminal, the application may be configured to switch between a linking setup mode and an unlinking request mode. In this case, a distinction may be made between the time of linking setup and the time of unlinking request depending on the application mode.

[0108] In addition, any internal processing may be performed at each terminal (4, 5) in connection with the processing of the deactivation request. For example, if the current linking information has been created at at least one of the terminals, terminal 4 and terminal 5, then at least one of the terminals may perform the following internal processing in connection with the processing of the deactivation request. The current linking information may be updated with past linking information. The update process may be set as appropriate depending on the embodiment. For example, the update process may be to delete the current linking information. In this case, the current linking information may be deleted completely or saved as past linking history. Alternatively, for example, the update process may be to invalidate the current linking information by adding invalidation information such as the end time and the setting of the end flag to the current linking information. If one of the first terminal 4 and the second terminal 5 is configured to send a release request, the first terminal may send a notification to the other terminal to inform them of the release of the linking upon sending the release request or the completion of the release. If the other terminal has created current linking information, the other terminal may execute the update process described above upon receiving the notification.

[0109] (II) Conditions for release The release condition indicates the condition for releasing the correspondence between the objects. The release condition may be defined as appropriate depending on the embodiment.

[0110] For example, the release condition may be defined as releasing the correspondence at an arbitrarily set release time. The release time may be given, for example, by a user, by another application (such as a scheduler), etc. In this case, the management server 1 may release the correspondence in question when the release time arrives. The release time may be set as the expiration date of the above-mentioned linking information D10. If the release time is set as the expiration date, the management server 1 may treat the correspondence in question as released when the release time arrives.

[0111] In another example, the release condition may be defined to release one of the overlapping correspondences when multiple correspondence settings overlap for the same target due to an interruption in the setting of a correspondence by at least one of the other first target and other second targets. The number of correspondences (links) that can be set for the same target is not limited to one, but may be two or more. Management server 1 may release one of the correspondences that were set and maintained earlier if the overlap of correspondence settings exceeds a threshold (upper limit). The threshold may be given as appropriate. Which correspondence to release may be determined as appropriate according to priority, order, type of target, etc.

[0112] For example, consider a scenario where one of the first and second targets is a user, and the other is a usable item. In this case, the number of users that can be associated with the same usable item may be infinite or finite. If the number of users that can be associated is finite, the upper limit of the number of users that can be associated may be appropriately set by a threshold. The threshold may be set according to the attributes of the usable item. When the management server 1 receives a new request for a correspondence setting for a target usable item, it may refer to the association information D10 and extract the previous correspondences that have been set and maintained for the target usable item. If the newly received correspondence setting causes the overlap of correspondence settings for the target usable item to exceed the threshold, the management server 1 may discard the request for the newly received correspondence setting, or release at least one of the extracted previous correspondences. When releasing previous correspondences, the management server 1 may decide which correspondences to release according to the user priority, order (for example, releasing the correspondences that were set earlier), etc.

[0113] As a concrete example, in the example in Figure 2, we assume that the vehicle is a private car, and that the first user and the second user are, for example, family members, and therefore share the private car. The private car can be interpreted as an item used on a regular basis. For the sake of explanation, we assume that the number of users that can be associated with the private car is 1. In this case, while the correspondence between one of the first user and the private car is established, the management server 1 may, upon receiving the establishment of a correspondence between the other user and the private car, cancel the previous correspondence (the correspondence between one user and the private car).

[0114] Similarly, the number of items that can be associated with the same user may be infinite or finite. This is acceptable. If the number of items that can be linked is finite, the upper limit of the number of items that can be linked may be appropriately set by a threshold. When the management server 1 receives a new request for a correspondence setting for a target user, it may refer to the linking information D10 and extract the previous correspondences that have been set and maintained for the target user. If the newly received correspondence setting causes the overlap of correspondence settings for the target user to exceed a threshold, the management server 1 may discard the request for the newly received correspondence setting or release at least one of the extracted previous correspondences. When releasing a previous correspondence, the management server 1 may decide which correspondence to release depending on the priority and type of the item (for example, whether it is a regularly used item or a temporary item).

[0115] As a concrete example, in the example in Figure 2, we assume that the first mobile object is a regularly used item (e.g., a private car) and the second mobile object is a temporarily used item (e.g., a rental car, a car-sharing service, or a public transportation-related mobile object). In this case, while the correspondence between the target user and the first mobile object is being set up, the management server 1 may, upon receiving the setting of a correspondence between the target user and the second mobile object, cancel the previous correspondence (the correspondence with the first mobile object).

[0116] In this specific example, if the correspondence with the second mobile object (temporary use object) is terminated, the management server 1 may re-establish the correspondence between the first mobile object (permanently used object) and the target user, which was terminated earlier. This allows for the quick restoration of the correspondence setting with the constantly used object. Furthermore, if both the first and second mobile objects are constantly used or temporary use objects, the management server 1 may arbitrate the settings of overlapping correspondences as appropriate. For example, the management server 1 may discard newly received requests for setting correspondences as long as the previous correspondence is not terminated.

[0117] As described above, the management server 1 may terminate the correspondence relationship upon receiving a termination request from at least one of the first terminal 4 and the second terminal 5, or upon fulfillment of predetermined termination conditions. According to one example of this embodiment, the termination of the usage relationship between the first target and the second target can be tracked. The linking information D10 after the correspondence relationship has been terminated may be saved as history.

[0118] (Simplified processing for linking settings) For example, if the same combination of first and second targets repeatedly creates and terminates a usage relationship, the management system 100 may perform authentication processing for both the first and second targets each time, repeatedly setting and canceling the relationship. However, if the frequency of creating and terminating usage relationships is high, performing authentication processing for the same first and second targets each time may be cumbersome. In particular, in cases where one of the first and second targets is a user and the other is a constantly used item, performing authentication for both each time can be cumbersome.

[0119] Therefore, in another example, the management system 100 may be configured to omit the authentication process for at least one of the first and second targets when setting up the association for the same combination of the first and second targets in subsequent association setting processes. That is, the management system 100 may be configured to accept requests to set up the association for combinations of the first and second targets for which an association has been set up in the past, by omitting the authentication process for at least one of the first and second targets. For the sake of explanation, the process of setting up the association by omitting the authentication process for at least one of the first and second targets will also be called the "simplified association setting process," and the normal route process that does not omit the authentication process will also be called the "normal association setting process." In one example, in the simplified association setting process, the authentication process for one of the first and second targets may be executed. In another example, in the simplified association setting process, the authentication process may be omitted for both the first and second targets.

[0120] Information on combinations of first and second objects for which a correspondence has been established in the past is: Management may be performed by at least one of the management server 1, each server (2, 3), and each terminal (4, 5). For example, the linking information D10 may be maintained as history even after the correspondence is terminated. Management server 1 may determine from the history of linking information D10 whether the combination of the first target and the second target for which a request for setting up a correspondence has been received is a combination for which a correspondence has been set up in the past. If it is determined that the combination is one for which a correspondence has been set up in the past, management server 1 may perform the linking setting using a simplified process. In addition, at any time such as when setting up the linking, the first terminal 4 may obtain the second identifier I20 of the second target and store the obtained second identifier I20 as the destination for the simplified process. The second terminal 5 may also obtain the first identifier I10 of the first target and store the obtained first identifier I10 as the destination for the simplified process. As a result, at least one of the first terminal 4 and the second terminal 5 may retain information about counterparties with which correspondence relationships have been established in the past, and may use the retained counterparty information to request a simplified linking setting. Also, the first server 2 may obtain the second identifier I20 of the second target from at least one of the management server 1 and each terminal (4, 5), and store the obtained second identifier I20 in association with the first target information O10 of the first target that corresponds to the counterparty for the simplified processing. The second server 3 may also obtain the first identifier I10 of the first target from at least one of the management server 1 and each terminal (4, 5), and store the obtained first identifier I10 in association with the second target information O20 of the second target that corresponds to the counterparty for the simplified processing. As a result, at least one of the first server 2 and the second server 3 may retain information about counterparties with which correspondence relationships have been established in the past, and may use the retained counterparty information to support the simplified linking setting.

[0121] Furthermore, the management system 100 may be configured to allow simplified processing for some of the first and second targets, for example, by allowing simplified processing for regularly used items, not allowing simplified processing for temporarily used items, and linking them each time using normal processing. Whether or not to allow simplified processing may be switched as appropriate. For example, whether or not to allow simplified processing may be switched depending on the type of at least one of the first and second targets. As a specific example, if one of the first and second targets is a user and the other is a used item, then as described above, whether or not to allow simplified processing may be switched depending on the type of used item (whether it is a regularly used item or a temporarily used item).

[0122] Whether or not simplified processing is permitted can be switched using any method. For example, at least one of the management server 1, each server (2, 3), and each terminal (4, 5) may identify the type of user and switch whether or not simplified processing is permitted depending on the result of the identification. The type of user may be identified by individual information included in the target information, or by information such as an identifier. In another example, for example, a program that includes a mode to permit simplified processing may be installed only on terminals of users for which simplified processing is permitted, such as terminals of users for which simplified processing is permitted (second terminal 5 in Figure 2), and whether or not simplified processing is permitted may be switched by the operation of this terminal. The operation of the mode to permit simplified processing may include, for example, storing the information of the other party or sending a request for linking settings using simplified processing.

[0123] A request for simplified linking settings may be sent from at least one of the first terminal 4 and the second terminal 5. At least one of the first terminal 4 and the second terminal 5 may send the request for simplified linking settings directly to the management server 1, or it may send it indirectly to the management server 1 via external computers such as each server (2, 3). For example, the first terminal 4 may send the request for simplified linking settings directly to the management server 1, or it may send it indirectly via external computers such as the first server 2 and the second server 3. The first terminal 4 may instruct the second terminal 5 to send the request for simplified linking settings directly to the management server 1, or it may send it indirectly via external computers such as the first server 2 and the second server 3. Similarly, the second terminal 5 may send the request for simplified linking settings directly to the management server 1, or it may send it indirectly via external computers such as the first server 2 and the second server 3. 5 may, by giving instructions to the first terminal 4, have the first terminal 4 directly send a request for simplified linking settings to the management server 1, or it may send it indirectly via an external computer such as the first server 2 or the second server 3.

[0124] Whether a request is processed using simplified processing or standard processing may be determined as appropriate. For example, a request for linking settings may include information indicating whether or not it is simplified processing. Management server 1 and at least one of the other servers (2, 3) may determine whether it is simplified processing or standard processing based on this information. In another example, management server 1 and at least one of the other servers (2, 3) may determine whether an authentication request (request for linking settings) from each terminal (4, 5) is simplified processing or standard processing based on the target information included (for example, the combination of the first identifier I10 and the second identifier I20). Management server 1 may directly accept requests for linking settings that are determined to be simplified processing from each terminal (4, 5).

[0125] Basically, a request for simplified linking settings may include a first identifier I10 and a second identifier I20. The first identifier I10 and the second identifier I20 included in the request may be obtained from either each terminal (4, 5) or each server (2, 3) during the process of transmission from at least one of the first terminal 4 and the second terminal 5 to the management server 1. However, a request for simplified linking settings is not limited to this configuration. At least one of the first identifier I10 and the second identifier I20 may be omitted from the information included in the request. In another example, similar to the example of the cancellation request above, the management server 1 may store (register) combinations that permit simplified processing by assigning identifiers to the correspondence between the first identifier I10 and the second identifier I20 during past linking settings. The management server 1 may notify at least one of the first terminal 4 and the second terminal 5 of the assigned identifiers at any time, such as in a notification indicating the result of the linking process. At least one of the first terminal 4 and the second terminal 5 may send a request for linking settings that includes this identifier to the management server 1, thereby causing the management server 1 to perform a simplified linking setting. In one example of this embodiment, the first identifier I10 and the second identifier I20 can be omitted from the information included in the request. This is expected to improve the efficiency of data communication in the request for linking settings.

[0126] In one example, when the simplified process employs a configuration in which authentication processing is performed for one of the first or second target, the authentication processing for one of the first or second target may be performed in the same transmission format as in the normal process. For example, the first terminal 4 may request authentication of the second target from the second server 3. The second terminal 5 may request authentication of the first target from the first server 2. However, the transmission format of the authentication processing in the simplified process is not limited to this example. In another example, the first terminal 4 may request authentication of the first target from the first server 2. The second terminal 5 may request authentication of the second target from the second server 3. The authentication results may be sent to the management server 1 from at least one of the servers (2, 3) and each terminal (4, 5).

[0127] Furthermore, when adopting a configuration that performs authentication processing for one of the first or second target, the terminal that sends the request for simplified linking settings may store at least a portion of the data (identifier, unique information) used for the authentication of that one target. For example, when adopting authentication processing in the same form as the normal processing described above, the second terminal 5 may store at least one of the first identifier I10 and first unique information C1 of the first target in its memory resources at any time, such as during past linking settings. The second terminal 5 may retrieve at least one of the first identifier I10 and first unique information C1 from its memory resources and use the retrieved information to send an authentication request for the first target to the first server 2. This further reduces the effort required for linking settings.

[0128] Figure 4B schematically shows an example of the process of setting up the linkage using a simplified process according to this embodiment. In the example in Figure 2, authentication processing for the user (first target) is performed, and the mobile entity (second target) is set. This scenario assumes a configuration in which the authentication process for the first terminal is omitted and the authentication process is performed using the same route as normal processing. In step SA10, during data exchange, the first terminal 4 provides the first identifier I10 and the first unique information C1 to the second terminal 5. The second terminal 5 obtains the first identifier I10 and the first unique information C1 from the user. In step SA20, the second terminal 5 sends a request to the first server 2 for a simplified linking setting accompanied by an authentication request including the first identifier I10 and the first unique information C1. This request may also include the second identifier I20. The first server 2 performs the user authentication process in response to the request received from the second terminal 5. In step SA30, the first server 2 sends the user authentication result to the management server 1. If the user authentication is successful based on the received result, the management server 1 sets the correspondence (linking) between the first identifier I10 and the second identifier I20 (step SC20). Whether or not a request is for a simplified linking setting can be appropriately determined by at least one of the first server 2 and the management server 1. The processing and transmission route for the simplified linking setting request are not limited to the example in Figure 4B and may be appropriately changed depending on the embodiment. For example, a simplified linking setting request including an authentication request for the first target may be sent from the first terminal 4 to the first server 2. The simplified processing may be configured to omit the authentication processing for the user (first target) and execute the authentication processing for the mobile device (second target). A simplified linking setting request including an authentication request for the mobile device may be sent from the first terminal 4 or the second terminal 5 to the second server 3. At least one of the first identifier I10 and the second identifier I20 may be omitted from the simplified linking setting request.

[0129] As an optional configuration, management server 1 and at least one of the servers (2, 3) may acquire identification information (MAC address, terminal identification information, etc.) of at least one of the first terminal 4 and second terminal 5 that are permitted to use simplified processing, as part of the registration process for devices permitted to use simplified processing, and store the acquired identification information. This registration process may be performed at any time, such as during past linking settings. Management server 1 and at least one of the servers (2, 3) may be configured to accept requests for linking settings using simplified processing only from terminals identified by the identification information.

[0130] The trigger for a request for simplified linking settings may be the same as for normal processing. That is, triggered by data exchange between the first terminal 4 and the second terminal 5, at least one of the first terminal 4 and the second terminal 5 may send a request for simplified linking settings. However, the trigger for simplified processing is not limited to this example. In another example, if at least one of the first target and the second target is a user, an operation by the user on at least one of the first terminal 4 and the second terminal 5 may cause at least one of the first terminal 4 and the second terminal 5 to send a request for simplified linking settings. That is, the trigger for a request for simplified linking settings may be an operation by the user. In another example, the trigger for a request for simplified linking settings may be an instruction from another application (such as a scheduler). In another example, similar to the cancellation request described above, arbitrary information processing may be performed on at least one of the first terminal 4 and the second terminal 5 in conjunction with the occurrence of the usage relationship. This arbitrary information processing may trigger a request for simplified linking settings to be sent from at least one of the first terminal 4 and the second terminal 5.

[0131] Basically, the process for canceling a correspondence set up by the simplified process (cancellation process for the simplified process) may be the same as the process for canceling a link in the normal process (cancellation process for the normal process). However, the cancellation process for the simplified process does not necessarily have to be the same as the cancellation process for the normal process. Correspondences set up by the simplified process may be canceled as appropriate. In another example, if the transmission route for the request to set up a correspondence by the simplified process and the transmission route for the request to cancel it for the normal process are different, the transmission route for the cancellation request for the simplified process may be aligned with the transmission route for the request to set up the correspondence by the simplified process.

[0132] (Scenarios for the use of linked information) As described above, linking information D10 can be used in a variety of situations. For example, linking information D10 may be used simply to track the occurrence and termination of relationships between the first and second objects. In another example, linking information D10 may be used to enable at least a portion of the permissions associated with one of the first or second objects to be exercised from the other while a correspondence relationship between the first and second objects is established. In the example in Figure 2, linking information D10 may be used to enable at least a portion of the permissions associated with a user to be exercised from the mobile object while a correspondence relationship between a user and a mobile object is established.

[0133] Figure 5 schematically shows an example of a usage scenario for the linked information D10 according to this embodiment. Figure 5 assumes a scenario in the example of Figure 2 where user-linked privileges are exercised from a mobile device. The external system SY1 is deployed at a location where various services are performed (e.g., a parking lot) and is configured to perform information processing to provide the target service to a user who has the target privileges. The configuration and services of the external system SY1 are not particularly limited and may be appropriately selected depending on the embodiment.

[0134] First, in step U10, the external system SY1 obtains the second identifier I20 (mobile object identifier) ​​from the target mobile object. The method for obtaining the second identifier I20 may be appropriately selected depending on the embodiment. In one example, the external system SY1 may obtain the second identifier I20 from the second terminal 5 by exchanging data with the second terminal 5. The method of data exchange may be the same as the data exchange between the first terminal 4 and the second terminal 5. In another example, if the second identifier I20 is a vehicle registration number, the external system SY1 may obtain the second identifier I20 by photographing the license plate with an image sensor and analyzing the obtained image.

[0135] In step U20, the external system SY1 uses the acquired second identifier I20 as a query to ask the management server 1 whether there is a valid correspondence relationship for the target mobile object at the target date and time. Valid means that the setting is maintained (not canceled) at the target date and time. While the target date and time is generally the present (immediate), it is not limited to this. For example, when executing a settlement process for a past date and time, the target date and time may be a past date and time. If a valid correspondence relationship exists, the first identifier I10 (user identifier) ​​of the user associated with the target mobile object is extracted. On the other hand, if no valid correspondence relationship exists and no user associated with the target mobile object is extracted, this process may be terminated.

[0136] In step U30, the external system SY1 uses the extracted first identifier I10 as a query to inquire with the first server 2 about the available privileges for the user associated with the target mobile object. The first server 2 refers to the first target information O10 (user information O10A) and extracts the privileges associated with the target user that can be exercised. If no available privileges are extracted, this process may be terminated. Note that the first target information O10 (user information O10A) may also have a setting for each privilege indicating whether or not the mobile object is allowed to exercise the privilege. The available privileges may be extracted according to this setting. Also, if the target privilege that the external system SY1 is trying to exercise is not included in the available privileges, this process may be terminated. The privileges to be exercised may be specified at any time as appropriate. For example, the privileges to be exercised may be specified in advance in the external system SY1, or they may be specified by the user.

[0137] In step U40, if the target authority is included in the available authority, the external system SY1 executes the process to exercise the target authority. This allows the authority associated with the user to be exercised from the mobile entity, and the user can receive services through the mobile entity. For example, if the authority information includes public personal authentication information, and the target authority relates to public personal authentication, the user can receive public services through the mobile entity. Also, for example... For example, if the authorization information includes payment information and the authorization in question relates to payment, the user can receive payment services via a mobile device. Payment services may include payments for parking fees, highway tolls, drive-through fees, public transport fees, rental fees, etc. Also, for example, if the authorization information includes information about electronic prescriptions and the authorization in question is to receive medication prescribed by an electronic prescription, the user can use the electronic prescription and receive medication via a mobile device.

[0138] The processing procedure for exercising the above authority is merely an example, and each step may be modified as much as possible. Depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. In addition, in the above processing procedure, the user may be replaced with the first target, and the moving object may be replaced with the second target. Furthermore, in the above processing procedure, "first" and "second" may be swapped.

[0139] (Data communication between devices) Data communication between each device (management server 1, first server 2, second server 3, first terminal 4, and second terminal 5) is not particularly limited and may be appropriately selected depending on the embodiment. The network between each device may be appropriately selected from, for example, the Internet, wireless communication network, mobile communication network, telephone network, dedicated network, local area network, etc. Data communication between each device is performed using methods such as SSL (Secure Socket Layer) and TLS (Transport Layer Security). Encryption is permitted. For example, each terminal (4, 5) may be equipped with a SIM (Subscriber Identity Module), and data communication between each server (2, 3) and each terminal (4, 5) may be performed using encrypted communication via the SIM.

[0140] [2 Example Configurations] [Example Hardware Configuration] (Management Server) Figure 6A schematically shows an example of the hardware configuration of the management server 1 according to this embodiment. The management server 1 according to this embodiment is a computer in which a control unit 11, a storage unit 12, a communication interface 13, an input device 14, an output device 15, and a drive 16 are electrically connected.

[0141] The control unit 11 is a hardware processor, a CPU (Central Processing Unit), It includes RAM (Random Access Memory), ROM (Read Only Memory), etc., and is configured to perform arbitrary information processing based on programs and various data. The control unit 11 (CPU) is an example of the processor resources of the management server 1.

[0142] The storage unit 12 may be composed of, for example, a hard disk drive, a solid-state drive, or semiconductor memory. The storage unit 12 (and RAM, ROM) is an example of memory resources. In this embodiment, the storage unit 12 stores various information such as the management program 81 and the association information D10. The management program 81 is a program that causes the management server 1 to execute information processing related to setting and canceling the correspondence between the first target and the second target (see Figures 8A to 8D described later). The management program 81 includes a series of instructions for said information processing.

[0143] The communication interface 13 is configured to perform wired or wireless communication over a network. The communication interface 13 may consist of, for example, a wired LAN (Local Area Network) module, a wireless LAN module, etc. The management server 1 may perform data communication with other computers (first server 2, second server 3, first terminal 4, second terminal 5) via the communication interface 13.

[0144] The input device 14 is, for example, a device for inputting data such as a mouse, keyboard, or control buttons. The output device 15 is, for example, a device for outputting to a display, speaker, etc. The operator can operate the management server 1 by using the input device 14 and the output device 15. The input device 14 and the output device 15 may be integrated together, for example, by a touch panel display. The input device 14 and the output device 15 may be connected via an external interface. The external interface may be appropriately configured to connect to an external device by wire or wireless, for example, by a USB (Universal Serial Bus) port, a dedicated port, a wireless communication port, etc.

[0145] Drive 16 is a device for reading various information, such as programs, stored in the storage medium 91. At least one of the management program 81 and the association information D10 may be stored in the storage medium 91 instead of or together with the storage unit 12. The storage medium 91 is configured to store various information (stored programs, etc.) by electrical, magnetic, optical, mechanical, or chemical means so that a machine such as a computer can read the information. The management server 1 may obtain at least one of the management program 81 and the association information D10 from the storage medium 91. The storage medium 91 may be a disk-type storage medium such as a CD or DVD, or a non-disk-type storage medium such as semiconductor memory (e.g., flash memory). The type of drive 16 may be appropriately selected according to the type of storage medium 91. Drive 16 may be connected via an external interface.

[0146] Regarding the specific hardware configuration of the management server 1, components can be omitted, replaced, and added as appropriate depending on the embodiment. For example, the control unit 11 may include multiple hardware processors. Hardware processors include microprocessors, FPGAs (field-programmable gate arrays), DSPs (digital signal processors), and GPs. It may consist of a U (Graphics Processing Unit), an ASIC (application-specific integrated circuit), etc. At least one of the input device 14, output device 15 and drive 16 Any of these may be omitted. The linking information D10 may be stored not in the storage unit 12, but on an external computer accessible by the management server 1 (e.g., NAS: Network Attached Storage, etc.). The management server 1 may consist of multiple computers. In this case, the hardware configuration of each computer may or may not be the same. The management server 1 may be an information processing device designed specifically for the services provided, a general-purpose server device, a general-purpose computer, etc.

[0147] (Server 1) Figure 6B schematically shows an example of the hardware configuration of the first server 2 according to this embodiment. The first server 2 according to this embodiment is a computer in which a control unit 21, a storage unit 22, a communication interface 23, an input device 24, an output device 25, and a drive 26 are electrically connected. The control unit 21 to the drive 26 and the storage medium 92 of the first server 2 may be configured in the same way as the control unit 11 to the drive 16 and the storage medium 91 of the management server 1.

[0148] The control unit 21 (CPU) is an example of the processor resources of the first server 2, and the storage unit 22 (and RAM, ROM) is an example of the memory resources of the first server 2. In this embodiment, the storage unit 22 stores various information such as the program 82 and the first target information O10. The storage unit 22 is an example of the first storage device. The program 82 is a program that causes the first server 2 to execute information processing related to the authentication of the first target (Figure 8A, etc., described later). The program 82 includes a series of instructions for said information processing. At least one of the program 82 and the first target information O10 may be stored in the storage medium 92 instead of or together with the storage unit 22. The first server 2 may obtain at least one of the program 82 and the first target information O10 from the storage medium 92. The first server 2 performs data communication with other computers (second terminal 5, management server 1, etc.) via the communication interface 23. The first server 2 may be operated via the input device 24 and the output device 25.

[0149] Regarding the specific hardware configuration of the first server 2, components can be omitted, replaced, and added as appropriate depending on the embodiment. For example, the control unit 21 may include multiple hardware processors. Hardware processors may consist of microprocessors, FPGAs, DSPs, GPUs, ASICs, etc. At least one of the input device 24, output device 25, and drive 26 may be omitted. The first target information O10 may be stored not in the storage unit 22, but in an external computer accessible by the first server 2 (e.g., a NAS, etc.). The first server 2 may consist of multiple computers. In this case, the hardware configurations of each computer may or may not be the same. The first server 2 may be an information processing device designed specifically for the services provided, a general-purpose server device, a general-purpose computer, etc.

[0150] (Second server) Figure 6C schematically shows an example of the hardware configuration of the second server 3 according to this embodiment. The second server 3 according to this embodiment is a computer in which a control unit 31, a storage unit 32, a communication interface 33, an input device 34, an output device 35, and a drive 36 are electrically connected. The control unit 31 to the drive 36 and the storage medium 93 of the second server 3 may be configured in the same way as the control unit 11 to the drive 16 and the storage medium 91 of the management server 1.

[0151] The control unit 31 (CPU) is an example of the processor resources of the second server 3, and the storage unit 32 (and RAM, ROM) is an example of the memory resources of the second server 3. In this embodiment, the storage unit 32 stores various information such as the program 83 and the second target information O20. The storage unit 32 is an example of the second storage device. The program 83 is a program that causes the second server 3 to execute information processing related to the authentication of the second target (Figure 8B, etc., described later). The program 83 includes a series of instructions for said information processing. At least one of the program 83 and the second target information O20 may be stored in the storage medium 93 instead of or together with the storage unit 32. The second server 3 may retrieve at least one of the program 83 and the second target information O20 from the storage medium 93. The second server 3 may communicate data with other computers (first terminal 4, management server 1, etc.) via the communication interface 33. The second server 3 may be operated via the input device 34 and the output device 35.

[0152] Regarding the specific hardware configuration of the second server 3, components can be omitted, replaced, and added as appropriate depending on the embodiment. For example, the control unit 31 may include multiple hardware processors. Hardware processors may consist of microprocessors, FPGAs, DSPs, GPUs, ASICs, etc. At least one of the input device 34, output device 35, and drive 36 may be omitted. The second target information O20 may be stored not in the storage unit 32, but in an external computer accessible by the second server 3 (e.g., a NAS, etc.). The second server 3 may consist of multiple computers. In this case, the hardware configurations of each computer may or may not be the same. The second server 3 may be an information processing device designed specifically for the services provided, a general-purpose server device, a general-purpose computer, etc.

[0153] (Terminal 1) Figure 6D schematically shows an example of the hardware configuration of the first terminal 4 according to this embodiment. The first terminal 4 according to this embodiment is a computer in which a control unit 41, a storage unit 42, a communication interface 43, an input device 44, an output device 45, and a drive 46 are electrically connected. The control unit 41 to the drive 46 and the storage medium 94 of the first terminal 4 may be configured in the same way as the control unit 11 to the drive 16 and the storage medium 91 of the management server 1.

[0154] The control unit 41 (CPU) is an example of the processor resources of the first terminal 4, and the storage unit 42 (and RAM, ROM) is an example of the memory resources of the first terminal 4. In this embodiment, the storage unit 42 stores various information such as the program 84 and the first identifier I10. The program 84 is a program that causes the first terminal 4 to execute information processing related to association (Figures 8A to 8B, 8D, etc., described later). The program 84 includes a series of instructions for the information processing. At least one of the program 84 and the first identifier I10 may be stored in the storage medium 94 instead of or together with the storage unit 42. The first terminal 4 may obtain at least one of the program 84 and the first identifier I10 from the storage medium 94. The first terminal 4 may communicate data with other computers (second server 3, second terminal 5, etc.) via the communication interface 43. The first terminal 4 may be operated via the input device 44 and the output device 45.

[0155] Furthermore, regarding the specific hardware configuration of the first terminal 4, components can be omitted, replaced, and added as appropriate depending on the embodiment. For example, the control unit 41 may include multiple hardware processors. Hardware processors are composed of microprocessors, FPGAs, DSPs, GPUs, ASICs, ECUs (Electronic Control Units), etc. It is permissible to omit at least one of the input device 44, output device 45, and drive 46. The first identifier I10 does not need to be stored in the storage unit 42. The first identifier I10 may be acquired each time. To acquire data such as identifiers and unique information, the first terminal 4 may be further equipped with data acquisition devices such as sensors and readers. The communication interface 43 may be composed of multiple types of modules. For example, the communication interface 43 may include a short-range wireless communication module and a wireless communication module, and the first terminal 4 may communicate data with the second terminal 5 via the short-range wireless communication module and with the second server 3 via the wireless communication module. The first terminal 4 may be composed of multiple computers. In this case, the hardware configuration of each computer may or may not be the same. The first terminal 4 may be an information processing device designed specifically for the services provided, as well as a general-purpose computer, terminal device (e.g., smartphone, tablet PC, etc.).

[0156] (Second terminal) Figure 6E schematically shows an example of the hardware configuration of the second terminal 5 according to this embodiment. The second terminal 5 according to this embodiment is a computer in which a control unit 51, a storage unit 52, a communication interface 53, an input device 54, an output device 55, and a drive 56 are electrically connected. The control unit 51 to the drive 56 and the storage medium 95 of the second terminal 5 may be configured in the same way as the control unit 11 to the drive 16 and the storage medium 91 of the management server 1.

[0157] The control unit 51 (CPU) is an example of the processor resources of the second terminal 5, and the storage unit 52 (and RAM, ROM) is an example of the memory resources of the second terminal 5. In this embodiment, the storage unit 52 stores various information such as the program 85 and the second identifier I20. The program 85 is a program that causes the second terminal 5 to execute information processing related to association (Figures 8A to 8B, 8D, etc., described later). The program 85 includes a series of instructions for the information processing. At least one of the program 85 and the second identifier I20 may be stored in the storage medium 95 instead of or together with the storage unit 52. The second terminal 5 may obtain at least one of the program 85 and the second identifier I20 from the storage medium 95. The second terminal 5 may communicate data with other computers (first server 2, first terminal 4, etc.) via the communication interface 53. The second terminal 5 may be operated via the input device 54 and the output device 55.

[0158] Furthermore, regarding the specific hardware configuration of the second terminal 5, depending on the embodiment, components can be omitted, replaced, and added as appropriate. For example, the control unit 51 may have multiple hardware components. A processor may be included. The hardware processor may consist of a microprocessor, FPGA, DSP, GPU, ASIC, ECU, etc. At least one of the input device 54, output device 55, and drive 56 may be omitted. The second identifier I20 does not have to be stored in the storage unit 52. The second identifier I20 may be acquired each time. To acquire data such as identifiers and unique information, the second terminal 5 may be further equipped with data acquisition devices such as sensors and readers. The communication interface 53 may be composed of multiple types of modules, similar to the first terminal 4 described above. The second terminal 5 may consist of multiple computers. In this case, the hardware configuration of each computer may or may not be the same. The second terminal 5 may be an information processing device designed specifically for the services provided, as well as a general-purpose computer, terminal device, etc.

[0159] [Software Configuration Example] Figure 7 schematically shows an example of the software configuration of each device (management server 1, first server 2, second server 3, first terminal 4, and second terminal 5) according to this embodiment.

[0160] (Management Server) The control unit 11 of the management server 1 loads the management program 81 stored in the memory unit 12 into RAM, and the CPU executes the instructions contained in the management program 81. As a result, the management server 1 operates as a computer equipped with a verification unit 111, a setting unit 112, a deactivation unit 113, and a notification unit 114 as software modules.

[0161] The matching unit 111 is configured to identify the correspondence of authentication results received from each server (2, 3). The setting unit 112 is configured to set the correspondence between the first identifier I10 and the second identifier I20 in the authentication results of the first and second targets received from each server (2, 3) if both the authentication of the first and second targets is successful. The release unit 113 is configured to release the correspondence upon receipt of a release request from at least one of the first terminal 4 and the second terminal 5 or upon fulfillment of predetermined release conditions. The notification unit 114 is configured to send a notification to at least one of the first terminal 4 and the second terminal 5 indicating the result of the process of setting the correspondence. The notification unit 114 is configured to send a notification to at least one of the first terminal 4 and the second terminal 5 indicating the result of the process of releasing the correspondence.

[0162] (Server 1) The control unit 21 of the first server 2 executes instructions included in program 82 using the CPU. As a result, the first server 2 operates as a computer equipped with an authentication unit 211 and a notification unit 212 as software modules. The authentication unit 211 is configured to perform authentication processing for the first target in response to an authentication request for the first target. The notification unit 212 is configured to send a notification indicating the result of the authentication processing.

[0163] (Second server) The control unit 31 of the second server 3 executes instructions included in program 83 using the CPU. As a result, the second server 3 operates as a computer equipped with an authentication unit 311 and a notification unit 312 as software modules. The authentication unit 311 is configured to perform authentication processing for the second target in response to an authentication request for the second target. The notification unit 312 is configured to send a notification indicating the result of the authentication processing.

[0164] (Terminal 1) The control unit 41 of the first terminal 4 executes the instructions included in the program 84 using the CPU. As a result, the first terminal 4 operates as a computer equipped with a data exchange unit 411, a setting request unit 412, and a release request unit 413 as software modules. The data exchange unit 411 is configured to perform data exchange with the second terminal 5. The setting request unit 412 is The system is configured to request the management system 100 to set up a correspondence between the first and second targets by sending data used for authenticating the second target. The release request unit 413 is configured to request the management system 100 to release the correspondence.

[0165] (Second terminal) The control unit 51 of the second terminal 5 executes instructions included in program 85 using the CPU. As a result, the second terminal 5 operates as a computer equipped with a data exchange unit 511, a setting request unit 512, and a release request unit 513 as software modules. The data exchange unit 511 is configured to perform data exchange with the first terminal 4. The setting request unit 512 is configured to request the management system 100 to set up the correspondence between the first and second targets by sending data used for authentication of the first target. The release request unit 513 is configured to request the management system 100 to release the correspondence.

[0166] (others) In this embodiment, an example is described in which each software module of each device is implemented by a general-purpose CPU. However, some or all of the above software modules may be implemented by one or more dedicated processors. Each of the above modules may also be implemented as a hardware module. With respect to the software configuration of each device, modules may be omitted, replaced, and added as appropriate, depending on the embodiment. For example, if a configuration is adopted in which a release request is sent from only one of the first terminal 4 and the second terminal 5, the release request section (413, 513) may be omitted from the other terminal.

[0167] [3 Examples of operation] (Linking settings) Figures 8A to 8C show an example of the linking setting process procedure by the management system 100 according to this embodiment. The following processing procedure is an example of a management method executed by a computer. In the example in Figures 8A to 8C, it is assumed that each terminal (4, 5) adopts a configuration in which it acquires data used for authentication during data exchange.

[0168] In step SAB100, the control unit 41 of the first terminal 4 operates as a data exchange unit 411 and performs data exchange with the second terminal 5. The control unit 51 of the second terminal 5 operates as a data exchange unit 511 and performs data exchange with the first terminal 4. Data exchange may be performed as appropriate depending on the occurrence of a usage relationship between the first and second targets. Data exchange may be performed by data communication or by other methods. In step SA10, the control unit 51 of the second terminal 5 obtains the first identifier I10 and the first unique information C1 from the first target. In step SB10, the control unit 41 of the first terminal 4 obtains the second identifier I20 and the second unique information C2 from the second target. The processing in steps SA10 and SB10 may be performed within the data exchange processing.

[0169] In step SA20, the control unit 51 of the second terminal 5 operates as a setting request unit 512 and requests the management system 100 to perform the linking setting by sending an authentication request (first request) for the first target to the first server 2. In response, the control unit 21 of the first server 2 receives the first request from the second terminal 5. In one example, the first request includes a first identifier I10 and first unique information C1.

[0170] In step SA25, the control unit 21 of the first server 2 operates as an authentication unit 211 and attempts to authenticate the first target in response to the receipt of the first request. For example, the control unit 21 uses the received first identifier I10 as a query to search for the first target information O10 and extracts the first registered unique information C10 of the requesting first target. The control unit 21 compares the extracted first registered unique information C10 with the received first unique information C1. The control unit 21 then performs the comparison. Depending on the result, the success or failure of the authentication of the first target is determined. In step SA30, the control unit 21 operates as a notification unit 212 and sends the authentication result of the first target to the management server 1. In response, in step SA31, the control unit 11 of the management server 1 receives the authentication result of the first target from the first server 2.

[0171] Meanwhile, in step SB20, the control unit 41 of the first terminal 4 acts as a setting request unit 412 and sends an authentication request for the second target (second request) to the second server 3, requesting the management system 100 to perform the linking settings. In response, the control unit 31 of the second server 3 receives the second request from the first terminal 4. In one example, the second request includes a second identifier I20 and second unique information C2.

[0172] In step SB25, the control unit 31 of the second server 3 operates as an authentication unit 311 and attempts to authenticate the second target in response to the receipt of the second request. For example, the control unit 31 extracts the second registered unique information C20 of the requesting second target by searching for the second target information O20 using the received second identifier I20 as a query. The control unit 31 compares the extracted second registered unique information C20 with the received second unique information C2. The control unit 31 determines whether the authentication of the second target was successful or not based on the result of the comparison. In step SB30, the control unit 31 operates as a notification unit 312 and sends the authentication result of the second target to the management server 1. Accordingly, in step SB31, the control unit 11 of the management server 1 receives the authentication result of the second target from the second server 3.

[0173] In step SC10, the control unit 11 of the management server 1 operates as a matching unit 111 and identifies the correspondence between the authentication results received from each server (2, 3). In one example, any of the above methods may be used for the correspondence. The process in step SC10 may be repeated until the authentication results for the first and second targets that are associated with each other are found. After the matching is successful, the control unit 11 may proceed to the next step SC101.

[0174] In step SC101, the control unit 11 determines whether the authentication of both the first and second targets, which are associated with each other, is successful. If the authentication of both the first and second targets is successful, the control unit 11 proceeds to the next step SC20. On the other hand, if the authentication of at least one of the first and second targets is unsuccessful, the control unit 11 skips the processing in step SC20 and proceeds to step SC30.

[0175] In step SC20, the control unit 11 operates as a setting unit 112 and sets the correspondence between the first identifier I10 and the second identifier I20. In one example, the control unit 11 generates linking information D10 that shows the correspondence between the first identifier I10 and the second identifier I20, and saves the generated linking information D10. In step SC30, the control unit 11 operates as a notification unit 114 and directly or indirectly sends a notification to at least one of the first terminal 4 and the second terminal 5 indicating the result of the process of setting the correspondence. Once the notification of the result is complete, the processing procedure for linking setting related to this example operation is terminated.

[0176] The above processing procedure is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate.

[0177] For example, in step SA25, if the authentication of the first target fails, the first server 2 does not need to execute the process in step SA30. That is, the first server 2 may only send the authentication result to the management server 1 if the authentication of the first target is successful. Furthermore, if the authentication of the first target fails, the first server 2 will send the result back to the second terminal 5. The second server 5 may be instructed to reissue the first authentication request for the first target. Similarly, if the authentication of the second target is unsuccessful in step SB, the second server 3 does not need to execute the process in step SB30. If the authentication of the second target is unsuccessful, the second server 3 may return the result to the first terminal 4 and instruct the first terminal 4 to reissue the second authentication request for the second target. If both the first server 2 and the second server 3 adopt a configuration in which the authentication result is sent to the management server 1 only when authentication is successful, the process in step SC101 may be omitted.

[0178] Furthermore, in data exchange, the order in which the data used for each authentication is acquired is not limited to the examples in Figures 8A and 8B, and may be changed as appropriate. The processing in step SA10 may be executed after step SB10, or it may be executed at least partially in parallel with the processing in step SB10. The processing in step SA20 may be executed at any time after step SA10. The processing in step SA20 may be executed before step SB10. The processing in step SB20 may be executed at any time after step SB10. The processing in step SB20 may be executed before step SA.

[0179] Furthermore, the order of the authentication processes for the first and second targets is not particularly limited and may be determined as appropriate depending on the embodiment. The process in step SA25 may be executed at any time after step SA20. The process in step SA25 may be executed before step SB10. The process in step SB25 may be executed at any time after step SB20. The process in step SB25 may be executed before step SA10. The processes in steps SA10 to SA31 may be executed at least partially in parallel with the processes in steps SB10 to SB31.

[0180] (Unlink) Figure 8D shows an example of the unlinking process procedure by the management system 100 according to this embodiment. The following process procedure is an example of a management method executed by a computer. In the example in Figure 8D, authentication processing is omitted, and a scenario is assumed in which an unlinking request is sent directly from the first terminal 4 to the management server 1.

[0181] In step SZ10, the control unit 41 of the first terminal 4 operates as a release request unit 413 and sends a request to the management server 1 to release the correspondence. In response, the control unit 11 of the management server 1 receives the release request. The correspondence to be released may be specified as appropriate. The trigger for the release request may be selected as appropriate depending on the embodiment.

[0182] In step SZ20, the control unit 11 operates as a release unit 113 and releases the correspondence specified by the received release request. Release may consist of generating information indicating that the correspondence has been released and recording the generated information. For example, if the linking information D10 has the configuration shown in Figure 3A, the control unit 11 may release the correspondence by adding a release time to the corresponding linking information D10 or by setting a release flag. If the linking information D10 is configured on a blockchain base, the control unit 11 may release the correspondence by generating a transaction indicating the release of the link and adding the generated transaction to the blockchain.

[0183] In step SZ30, the control unit 11 operates as a notification unit 114 and transmits the result of the unlinking process to the first terminal 4. Once the notification of the result is complete, the processing procedure for unlinking related to this example operation is terminated.

[0184] The above processing procedure is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps may be omitted, replaced, and Additional items can be added.

[0185] For example, as described above, the transmission route for the release request is not limited to the example in Figure 8D, and may be appropriately selected depending on the embodiment. The release request may also be transmitted from the second terminal 5 (release request unit 513). The processing of the release request may include authentication processing for at least one of the first target and the second target. In addition, the control unit 11 of the management server 1 may operate as a release unit 113 instead of step SZ20, and release the correspondence when predetermined release conditions are met.

[0186] [Features] In this embodiment, when a usage relationship is established between the first and second targets, authentication of the first and second targets is performed in steps SA25 and SB25. At this time, in step SA20, authentication of the first target is requested from the second terminal 5. In step SB20, authentication of the second target is requested from the first terminal 4. Security can be expected to be ensured by this cross-referencing authentication. Furthermore, in the processing of step SC20, if authentication of both the first and second targets is successful, a correspondence relationship between the first identifier I10 and the second identifier I20 is set. This linkage setting record (linkage information D10) makes it possible to track the usage relationship between the first and second targets. Therefore, according to this embodiment, it is possible to track the usage relationship between the first and second targets while ensuring security.

[0187] [4. Variant] While embodiments of this disclosure have been described in detail above, the above description is merely illustrative in all respects of this disclosure. It goes without saying that various improvements or modifications can be made without departing from the scope of this disclosure. For example, the following modifications are possible. In the following, the same reference numerals are used for components similar to those in the above embodiments, and explanations of points similar to those in the above embodiments have been omitted as appropriate. The following modifications can be combined as appropriate.

[0188] <4.1> In the above embodiment, as one example of its use, the linking information D10 may be used to exercise the authority associated with one of the first and second objects from the other. In the examples in Figures 2 and 5, as an example of its use, one object (user) is assumed to exercise its authority through the other object (user / mobile object). However, the form in which authority is exercised is not limited to this example. In another example, the management system 100 may be configured so that the first object can exercise the authority of the other first object through the second object. And / or, the management system 100 may be configured so that the second object can exercise the authority of the other second object through the first object. That is, a proxy individual of one of the first and second objects may be configured to exercise the authority of the proxy requesting individual (target individual) of the first object through the other object (any individual of the other object). In the examples in Figures 2 and 5, the management system 100 may be configured so that a proxy user can exercise the authority of the target user (proxy requester) from the user (mobile object).

[0189] The method of delegating authority may be configured as appropriate. As an example, one of the following three methods may be adopted for delegating authority. For the sake of explanation, the following assumes that the first and second targets are the user and the object (mobile entity). That is, each delegation pattern in the examples of Figures 2 and 5 will be explained. However, the scope of application of each delegation pattern is not limited to the case where the first and second targets are the user and the object. Also, in each of the following delegation patterns, the user (first target) may be read as either the first or second target, and the object (second target) may be read as the other of the first or second target. Typically, the object may be the mobile entity mentioned above.

[0190] (1) First proxy pattern (proxy authentication / proxy linking) As a first proxy pattern, the management system 100 may be configured to set up a correspondence between the target user (proxy requester) and the user (second target) in response to the successful authentication of the target user (first target) and the user (second target) through proxy authentication processing by the proxy user. The management system 100 may then be configured to allow the proxy user to exercise the authority associated with the target user via the user while this correspondence is set up. The proxy user is an example of a proxy entity, and the target user (proxy requester) is an example of a proxy request entity (target entity).

[0191] In other words, the user terminal associated with the user (first terminal 4 in the example in Figure 2) may be a proxy user terminal owned by a proxy user acting on behalf of the user. In this case, when a usage relationship arises between the first target and the second target, data exchange may be performed as appropriate between the target user terminal, the proxy user terminal, and the loading terminal. In one example, the usage relationship between the first target and the second target may arise through data communication between the target user terminal and the proxy user terminal owned by the user, and between the proxy user terminal and the loading terminal.

[0192] The proxy authentication method is not particularly limited and may be set appropriately depending on the embodiment. The proxy authentication method is configured such that the proxy user terminal performs at least a part of the authentication process for the target user (first target) and the item used (second target) in the above embodiment on behalf of the target user terminal. As an example, one of the following two methods may be adopted as the proxy authentication method.

[0193] (1-1) 1-1 proxy pattern Figure 9 schematically shows an example of the linking setting process in the 1-1 proxy pattern according to this embodiment. Figure 10 shows an example of the linking setting processing procedure in the 1-1 proxy pattern according to this embodiment. In the examples of Figures 9 and 10, the first terminal 4A is a proxy user terminal and corresponds to the first terminal 4 in the examples of Figures 2 and 5 of the above embodiment. The first target is the target user (proxy requester) who requests proxy services. The target user terminal 6A is a terminal owned by the target user. The hardware configuration of the first terminal 4A and the target user terminal 6A may be the same as that of the first terminal 4, etc., in the above embodiment. In the examples of Figures 9 and 10, a scenario is assumed in which the first identifier I10 passes through the first terminal 4A, and the first unique information C1 does not pass through the first terminal 4A.

[0194] First, in step SD10, the control unit of the target user terminal 6A acts as a proxy designation unit and accepts the designation of a proxy user from the target user. The proxy user may be designated as appropriate. In a typical example, the target user terminal 6A may store an address book and select a proxy user from the users registered in the address book. In another example, the target user terminal 6A may access a list of users via an external computer such as the first server 2 and accept the selection of a proxy user from the users registered in the list. Once a proxy user is designated, the control unit of the target user terminal 6A acts as a notification unit and exchanges data with the first terminal 4A of the proxy user designated by the target user, notifying that proxy authority has been granted. In response, the control unit of the first terminal 4A of the proxy user receives a notification of the granting of proxy authority from the target user terminal 6A. In one example, this notification may include the target user's first identifier I10 (user identifier) ​​and contact information. The contact information may include a telephone number, email address, and account information for a communication application (e.g., a Social Networking Service application). , or an identification number, etc. Similar to the data exchange between the first terminal 4 and the second terminal 5 described above, the data exchange between the target user terminal 6A and the first terminal 4A may be carried out by wireless or wired data communication, or by methods other than data communication, such as reading a two-dimensional code. Furthermore, the target user terminal 6A may directly give notification of the granting of power of attorney to the first terminal 4A. Alternatively, the data may be transmitted indirectly via an external computer such as the first server 2. When data communication is adopted as the method of data exchange, this notification of the granting of proxy authority is an example of data communication between the target user terminal and the proxy user terminal possessed by the user. As a result, the target user terminal 6A grants the first terminal 4A the authority to authenticate on its behalf and causes it to execute the process of setting up the correspondence relationship with the user's device.

[0195] In step SAB100A, the control unit of the first terminal 4A of the authorized proxy user operates as a data exchange unit and performs data exchange with the second terminal 5. The control unit 51 of the second terminal 5 operates as a data exchange unit 511 and performs data exchange with the first terminal 4A. Similar to the data exchange between the first terminal 4 and the second terminal 5 described above, the data exchange between the first terminal 4A and the second terminal 5 may be performed by wireless or wired data communication, or by methods other than data communication, such as reading a two-dimensional code. When data communication is adopted as the method of data exchange, this data exchange between the first terminal 4A and the second terminal 5 is an example of data communication between a proxy user terminal and a loading terminal.

[0196] In step SD20, the control unit of the first terminal 4A provides the first identifier I10 and contact information to the second terminal 5. In response, the control unit 51 of the second terminal 5 obtains the first identifier I10 and contact information from the proxy user. As a result, the first terminal 4A causes the second terminal 5 to notify the target user terminal 6A of an authorization request for proxy linking, and, upon authorization, causes the target user (first user) to send an authentication request (first request) to the first server 2. In one example, the authorization request for proxy linking may include a query for the target user's first unique information C1 (user unique information). Note that the method by which the second terminal 5 obtains this information is not limited to this example. In another example, at least one of the first identifier I10 and contact information may be input into the second terminal 5 by the proxy user operating the second terminal 5.

[0197] In step SD30, the control unit 51 of the second terminal 5 operates as a data exchange unit 511 and notifies the target user terminal 6A of an approval request for proxy linking, including a query for the first unique information C1. In response, in step SA10A, the control unit of the target user terminal 6A accepts an operation from the target user to approve or deny the proxy linking. Depending on whether the target user has performed the operation to approve, the control unit of the target user terminal 6A operates as a data exchange unit and provides the second terminal 5 with the result of the proxy linking approval and the target user's first unique information C1 (user unique information). In response, the second terminal 5 obtains the target user's first unique information C1. As a result, the target user terminal 6A instructs the second terminal 5 to coordinate with the first terminal 4A and send a linking setting request to the management system 100 (send the target user's authentication request to the first server 2). On the other hand, if the target user does not approve, the processing procedure for linking setting by proxy authentication may be terminated as appropriate.

[0198] In principle, the data exchange in step SD30 and step SA10A may be performed by direct or indirect data communication via wireless or wired connection. In step SA10A, the control unit of the target user terminal 6A may appropriately acquire the first unique information C1 from the target user and transmit the acquired first unique information C1 directly or indirectly to the second terminal 5. However, the method of data exchange between the second terminal 5 and the target user terminal 6A is not limited to this example, and in some cases, methods other than data communication, such as reading a two-dimensional code, may be used.

[0199] In step SB10, similar to the first terminal 4 described above, the control unit of the first terminal 4A appropriately obtains the second identifier I20 and the second unique information C2 from the user. In one example, the second terminal 5 may provide the second identifier I20 and the second unique information C2 to the first terminal 4A. This allows the second terminal 5 to cause the first terminal 4A to send a request to the management system 100 for linking settings including the second identifier I20 and the second unique information C2 (sending an authentication request for the user to the second server 3). (You can let them believe it.)

[0200] In step SB20, the control unit of the first terminal 4A acts as a setting request unit and sends an authentication request (second request) for the user, including the second identifier I20 and the second unique information C2, to the second server 3, thereby requesting the management system 100 to perform the linking setting. In step SA20, the control unit 51 of the second terminal 5 acts as a setting request unit 512 and sends an authentication request (first request) for the target user, including the first identifier I10 and the first unique information C1, to the first server 2, thereby requesting the management system 100 to perform the linking setting. The processing from step SA20 and step SB20 onward may be executed in the same manner as in the above embodiment. As a result of the execution, a correspondence relationship between the target user and the user is established depending on whether authentication of the target user and the user is successful. Once the correspondence relationship is established, the processing procedure for linking setting by proxy authentication is completed. While the correspondence relationship is established, the proxy user can exercise the authority of the target user (proxy requester) from the user.

[0201] In the proxy pattern described in 1-1 above, the notification paths for the first identifier I10 and the first unique information C1 are not limited to the examples shown above. The first identifier I10 may be notified directly or indirectly from the target user terminal 6A to the second terminal 5 at any time, for example, in step SA10A, without going through the first terminal 4A. In this case, the first identifier I10 may be omitted from the notification of granting proxy authority. The first unique information C1 may also be given to the first terminal 4A at any time, for example, in step SD10. In this case, the first unique information C1 may be given from the first terminal 4A to the second terminal 5. In this case, the first unique information C1 may be omitted from the data given to the second terminal 5 in step SA10A. However, in order to avoid giving the first unique information C1 to the proxy user, it is preferable to adopt the configurations shown in Figures 9 and 10 above, which do not go through the first terminal 4A. Furthermore, the authorization process for proxy linking may be omitted. If the authorization process for proxy linking is omitted and a configuration is adopted in which the first unique information C1 is provided from the first terminal 4A to the second terminal 5, the processing in steps SD30 and SA10A may be omitted. In this case, the contact information of the target user may be omitted from the notification of the granting of proxy authority and the data provided to the second terminal 5 in step SD20.

[0202] Furthermore, in the proxy pattern described in 1-1 above, step SD10 may specify, along with the designation of the proxy user, at least one of the expiration date of the proxy exercise and the authority (valid authority) that permits the proxy exercise. Accordingly, designation information may be generated that is configured to indicate at least one of the specified expiration date and valid authority. The designation information for at least one of the specified expiration date and valid authority may be managed as appropriate. In one example, the designation information may be transmitted from the target user terminal 6A to the first server 2, where it is managed in association with the first target information O10 (user information O10A). The first server 2 may notify the management server 1 of the designation information as appropriate. In another example, the designation information may be notified from the target user terminal 6A to the management server 1 via at least one of the first terminal 4A and the second terminal 5 (i.e., together with the transmission of data used for authentication), where it is managed in association with the linking information D10. In yet another example, the designation information may be transmitted directly or indirectly from the target user terminal 6A to the management server 1 and managed by the management server 1. In this case, management server 1 may appropriately associate the authentication results received from each server (2, 3) with the specified information. The method of association may be the same as the method of association for the authentication results described above. For example, the authentication result data and specified information that reach management server 1 via at least one of the routes of the target user and the item may include agent information as shared information. This agent information may be used to associate the authentication results with the specified information. The agent information may be any information relating to the delegated user. The agent information may include, for example, attribute information of the delegated user (e.g., personal information such as name, address, age, gender, contact information), identification information (e.g., account name, identifier, etc.). The agent information may also include information of the same type as the above-mentioned unique information (C1, C2). Note that the timing for specifying the valid authority and expiration date is in step SD10. It does not have to be limited to this. At least one of the valid authority and the expiration date may be specified at any time before the correspondence is terminated.

[0203] Furthermore, in the proxy pattern described in 1-1 above, the first terminal 4A may directly transmit the proxy information to the management server 1, or it may transmit it indirectly via an external computer such as the second terminal 5. For example, the first terminal 4A may transmit the proxy information to the management server 1 via the second server 3 in the authentication route of the user (steps SB20 to SB31). The first terminal 4A may provide the proxy information to the second terminal 5 during data exchange, and instruct the second terminal 5 to transmit the proxy information to the management server 1 via the first server 2 in the authentication route of the target user (steps SA20 to SA31). As a result, the management server 1 may distinguish whether the established correspondence is due to proxy linking or not by generating linking information D10 that includes the proxy information. Because the linking information D10 includes the proxy information, the proxy user who set up the correspondence can be tracked. Using this proxy information, the users who can exercise the authority of the target user on their behalf may be restricted to the designated proxy user (the user identified by the proxy information). The method for distinguishing whether a correspondence is due to proxy linking or not is not limited to this example. In another example, the data reaching the management server 1 through each authentication route may be appropriately distinguished as to whether or not it is a request due to proxy linking. The management server 1 may generate linking information D10 that includes information indicating whether or not the correspondence was set up by proxy linking.

[0204] Furthermore, in the proxy pattern described in 1-1 above, the second terminal 5 may obtain proxy information from the first terminal 4A. Then, when requesting approval for proxy linking in step SD30, the second terminal 5 may notify the target user terminal 6A of the obtained proxy information. This allows the target user to be informed of the proxy user performing the proxy linking. In addition, in step SD10, the target user terminal 6A may generate designated proxy information indicating the specified proxy. The proxy information notified from the second terminal 5 may correspond to this designated proxy information. The target user terminal 6A may determine whether the proxy user performing the proxy linking matches the designated proxy user by comparing the designated proxy information with the proxy information notified from the second terminal 5. If it is determined that the proxy user performing the proxy linking matches the designated proxy user, the target user terminal 6A may automatically send an approval notification for proxy linking, including the first unique information C1, to the second terminal 5, or may allow the target user to perform the approval operation. Furthermore, the second terminal 5 does not necessarily have to obtain agent information from the first terminal 4A. For example, the second terminal 5 may obtain agent information from the agent user without using the first terminal 4A, for example, by taking a picture of the agent user using an image sensor. Also, the verification of the agent user and the notification of approval including the first unique information C1 do not necessarily have to be performed on the target user terminal 6A. At least one of the verification of the agent user and the notification of approval may be performed on an external computer such as the first server 2.

[0205] The designated agent information may include authentication information, and the agent information may include agent authentication information corresponding to the authentication information. The authentication information may be the same as the unique information (C10, C20), supplementary information, etc., described above. For example, the authentication information may be temporary information consisting of, for example, a timestamp, a random number, a hash value, etc. In this case, the authentication information may be appropriately generated by the target user terminal 6A or an external computer when the agent is designated in step SD10. The target user terminal 6A may provide the authentication information to the first terminal 4A at any timing such as step SD10. The first terminal 4A may hold the authentication information as agent authentication information and provide the agent information, including the agent authentication information, to the second terminal 5. Then, by comparing the authentication information and the agent authentication information, it may be determined whether the agent user performing the agent linking matches the designated agent user. The method for comparing the designated agent information and agent information may be the same as the method for comparing the unique information, supplementary information, etc., described above.

[0206] Furthermore, in the proxy pattern described in 1-1 above, if the target user terminal 6A does not respond within a certain period after notifying the approval request in step SD30, the second terminal 5 may notify the target user terminal 6A of a reminder to prompt a response in step SA10A. In addition, the approval process for the proxy linking using the designated proxy information may be performed on an external computer such as the first server 2, rather than on the target user terminal 6A. In this case, the designated proxy information may be provided to the external computer when specifying the proxy user in step SD10. If there is no response from the target user terminal 6A, the second terminal 5 may substitute the approval process by querying this external computer. In addition, the first unique information C1 may also be provided to the external computer, and the second terminal 5 may obtain the first unique information C1 from the external computer in response to the approval of the proxy linking.

[0207] Furthermore, in the proxy pattern described in 1-1 above, the correspondence established in response to the proxy linking request may be terminated as appropriate. Similar to the above embodiment, the management server 1 may be configured to terminate the correspondence upon receipt of a termination request from at least one of the first terminal 4A and the second terminal 5, or upon the fulfillment of predetermined termination conditions. The termination request and predetermined termination conditions according to the above embodiment may also be applied in this modified example. In addition, in this modified example, predetermined termination conditions may be set according to at least one of the expiration date of the proxy right and the valid authority. For example, the termination condition may be defined to terminate the correspondence upon the arrival of the specified expiration date. The termination condition may also be defined to terminate the correspondence upon exercise of the specified valid authority (i.e., the authority is extinguished / invalidated). Furthermore, the termination condition may be defined to terminate the previous correspondence established by proxy linking when the target user is attempting to establish a correspondence with a user in order to exercise the valid authority themselves, resulting in a duplication of correspondence settings for the target user.

[0208] Furthermore, the management server 1 may be configured to cancel the correspondence in response to receiving a cancellation request from the target user terminal 6A. The target user terminal 6A may send the cancellation request directly to the management server 1, or it may send it indirectly via an external computer such as the first server 2. Similar to the above embodiment, the cancellation request from the target user terminal 6A may include at least one of the first identifier I10 and the second identifier I20 that specify cancellation, or it may not include both the first identifier I10 and the second identifier I20. Also, if it is identified whether or not the correspondence was set up by proxy linking, the cancellation request from the target user terminal 6A may include only the first identifier I10 and not the second identifier I20, thereby specifying that the correspondence by proxy linking specified by the first identifier I10 should be canceled.

[0209] Furthermore, in the proxy pattern described in 1-1 above, after the configuration process for setting the correspondence relationship by proxy linking is completed, the control unit 11 of the management server 1 may operate as a notification unit 114 and send a notification indicating the execution result of the configuration process by proxy linking directly or indirectly to at least one of the first terminal 4A, the second terminal 5, and the target user terminal 6A. When notifying the target user terminal 6A directly, the management server 1 may obtain the contact information of the target user terminal 6A at any time. For example, if a form is adopted in which the contact information of the target user terminal 6A is exchanged as data between the first terminal 4A and the second terminal 5, the contact information of the target user terminal 6A may be transmitted to the management server 1 through the authentication route of either the target user or the item being used. If a form is adopted in which the target user terminal 6A communicates data with the management server 1, the management server 1 may obtain the contact information of the target user terminal 6A during this data communication.

[0210] The processing procedure shown in Figure 10 above is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. For example, the processing in step SB20 may be executed at any time after step SB10. If waiting for the completion of proxy approval is not required, the processing in steps SB10 and SB20 may be performed at any time after the second unique information C2 becomes available from the user. It may be executed at any given time, and may be executed before step SD20. While the processing of step SB10 is executed before step SD20, the processing of step SB20 may be executed after step SD20. Also, for example, the processing of step SA20 may be executed at any time after step SA10A. The processing of step SA20 may be executed before step SB10. When adopting a form in which the first identifier I10 and the first unique information C1 are provided from the first terminal 4A, the processing of step SA20 may be executed at any time after the first identifier I10 and the first unique information C1 have been obtained.

[0211] (modified version) In the proxy pattern described in 1-1 above, the second terminal 5 obtains the target user's first unique information C1 (user-specific information) and sends the obtained first unique information C1 to the first server 2. However, the transmission path of the first unique information C1 is not limited to this example. As a variation, the authentication process may proceed without the first unique information C1, and the first server 2 may query the target user terminal 6A.

[0212] Figure 11 schematically shows a modified example of the linking setting process in the 1-1 proxy pattern according to this embodiment. In the example in Figure 11, the first target information O10 (user information O10A) includes the contact information of the target user (first target) as attribute information. Figure 11 assumes a scenario in which the configuration of this modified example is applied to the example in Figure 9.

[0213] First, in step SD10, the target user terminal 6A accepts the designation of a proxy user and sends a notification of the granting of proxy authority to the designated proxy user's first terminal 4A. The contact information of the target user may be omitted in this notification of the granting of proxy authority. In step SD20B, the second terminal 5 obtains the first identifier I10. In step SB10, the first terminal 4A obtains the second identifier I20 and the second unique information C2. The authentication process for the user from step SB20 onward may be performed in the same manner as in the above embodiment. As a result of the execution, the management server 1 receives the authentication result of the user from the second server 3.

[0214] Meanwhile, in step SA20B, the second terminal 5 sends an authentication request (first request) for the target user (first identifier I10) to the first server 2, which does not include the first unique information C1. In response, the first server 2 receives the first identifier I10. In step SA210B, the control unit 21 of the first server 2 operates as an authentication unit 211 and uses the received first identifier I10 as a query to search for the first target information O10 (user information O10A), thereby extracting the target user's first registered unique information C10 and contact information. The control unit 21 sends an authorization request for proxy linking, including a query for the first unique information C1, to the target user terminal 6A for the extracted contact information. In response, the control unit of the target user terminal 6A accepts an operation from the target user to approve or reject the proxy linking. In step SA211B, in response to the target user performing an operation to approve, the control unit of the target user terminal 6A transmits the result of the proxy linking approval and the target user's first unique information C1 (user-specific information) to the first server 2. In response, the control unit 21 of the first server 2 receives the first unique information C1. On the other hand, if the target user does not approve, the processing procedure for setting up the linking by proxy authentication in this modified example may be terminated as appropriate. The control unit of the target user terminal 6A may also obtain the first unique information C1 from the target user as appropriate.

[0215] The control unit 21 of the first server 2 operates as an authentication unit 211 and compares the extracted first registered unique information C10 with the received first unique information C1. The control unit 21 determines whether the authentication of the target user is successful or not based on the result of the comparison. In step SA30, the control unit 21 operates as a notification unit 212 and sends the authentication result of the target user to the management server 1. The management server 1 receives the authentication result of the target user in response. After this, the management server 1 performs the above-mentioned Similar to the implementation method, the processes from step SC10 onward may be executed. As a result of the execution, a correspondence relationship between the target user and the object will be established depending on whether authentication of the target user and the object is successful. Once the correspondence relationship is established, the process procedure for setting up the linkage by proxy authentication is completed.

[0216] In this modified example, the configuration other than those described above may be the same as the configuration described above for the examples in Figures 9 and 10. Also, in this modified example, when specifying a proxy user by the processing in step SD10, or after, and before step SA210B, the target user terminal 6A may access the first server 2 to pre-execute the processing in step SA211B. In this case, the processing in step SA210B may be omitted. The authentication request for the user's item from the second terminal 5 (second request) and the pre-authentication by pre-executing step SA211B may be appropriately associated. In one example, the second request and pre-authentication may include proxy information as shared information, and this proxy information may be used to perform the respective associations. When this form is adopted, in response to the authentication request from the second terminal 5 by the processing in step SA20B, the first server 2 may perform the association processing and send the authentication result of the target user using the first unique information C1 obtained in advance as the processing in step SA30 to the management server 1. At least a part of the authentication processing of the target user may be performed on the target user terminal 6A.

[0217] (1-2) 1st-2nd proxy patterns Figure 12 schematically shows an example of the linking setting process in the 1-2 proxy pattern according to this embodiment. Figure 13 shows an example of the linking setting processing procedure in the 1-2 proxy pattern according to this embodiment. In the examples of Figures 12 and 13, the first terminal 4C is a proxy user terminal and corresponds to the first terminal 4 in the examples of Figures 2 and 5 of the above embodiment and the first terminal 4A of the 1-1 proxy pattern. The first target is the target user (proxy requester) who requests proxy services. The target user terminal 6C is a terminal owned by the target user and corresponds to the target user terminal 6A of the 1-1 proxy pattern. The hardware configuration of the first terminal 4C and the target user terminal 6C may be the same as that of the first terminal 4, etc., in the above embodiment. In the examples of Figures 12 and 13, a scenario is assumed in which the first identifier I10 and the first unique information C1 do not pass through the first terminal 4C.

[0218] First, in step SE10, the control unit of the target user terminal 6C acts as a proxy designation unit and accepts the designation of a proxy user from the target user. The control unit of the target user terminal 6C acts as a notification unit and exchanges data with the first terminal 4C of the proxy user designated by the target user, notifying that proxy authority has been granted. In response, the control unit of the first terminal 4C of the proxy user receives a notification of the granting of proxy authority from the target user terminal 6C. In one example, this notification may include authentication information. The authentication information may be the same as in the proxy pattern of 1-1 above. For example, the authentication information may be temporarily generated information. The first terminal 4C may retain the authentication information included in the received notification as proxy authentication information. Other processing in step SE10 may be the same as in step SD10 above. When data communication is adopted as the method of data exchange, this notification of the granting of proxy authority is an example of data communication between the target user terminal and the proxy user terminal held by the user. As a result, the target user terminal 6C is granted the authority to authenticate on behalf of the first terminal 4C and is instructed to execute the process of establishing a correspondence between it and the device being used.

[0219] In step SA10C, the control unit of the target user terminal 6C receives the designation of the user(s) that are permitted to be linked by the proxy user. The user(s) permitted to be linked by proxy may be designated as appropriate depending on the embodiment. In one example, the user(s) of the second terminal 5, which is the data exchange partner, may be designated as the user(s) permitted to be linked by proxy by directly exchanging data between the target user terminal 6C and the second terminal 5 using a method such as short-range wireless communication. In another example, the target user terminal 6C may access a list of users via an external computer and designate the user(s) permitted to be linked by proxy from the users registered in the list. The list contains each user's The list may include information such as identification information and contact information for the second terminal 5. The list may be stored on the target user terminal 6C. The items may be specified manually by the target user, or they may be specified by arbitrary information processing, such as selecting items that meet certain conditions. After the items are specified, the control unit of the target user terminal 6C operates as a data exchange unit and notifies the second terminal 5 of the specified item of the designated agent information including authentication information, the first identifier I10, and the first unique information C1. The designated agent information may be acquired as appropriate according to the designation of the agent user. The designated agent information may be the same as the agent pattern in 1-1 above. Accordingly, the second terminal 5 of the specified item receives the designated agent information including authentication information, the first identifier I10, and the first unique information C1. In order for the agent user to identify the specified item, information about the specified item may be provided to the first terminal 4C from the target user terminal 6C or an external computer as appropriate. In step SA10C, the target user terminal 6C causes the second terminal 5 of the designated item to perform a verification process to confirm the authenticity of the proxy user who responded to the application for use of the item, and also causes the first terminal 4C of the proxy user to coordinate with the management system 100 to send a request for linking settings.

[0220] In step SAB100C, the control unit of the first terminal 4C of the authorized proxy user operates as a data exchange unit and performs data exchange with the second terminal 5 of the designated item. The control unit 51 of the second terminal 5 operates as a data exchange unit 511 and performs data exchange with the first terminal 4C. The method of data exchange in step SAB100C may be the same as in step SAB100A. When data communication is adopted as the method of data exchange, the data exchange between the first terminal 4C and the second terminal 5 is an example of data communication between the proxy user terminal and the loading terminal.

[0221] In step SE20, the control unit of the first terminal 4C submits an application for use of the product by providing agent information, including agent authentication information, to the second terminal 5. As a result, the first terminal 4C causes the second terminal 5 to verify the authenticity of the agent, and, if the agent verification is successful, causes the first server 2 to send an authentication request (first request) for the target user using the first identifier I10 and first unique information C1 that it holds (sending a request for linking settings to the management system 100).

[0222] In step SE201, the control unit 51 of the second terminal 5 verifies the authenticity of the proxy user by comparing the proxy information included in the application for use with the designated proxy information received from the target user terminal 6C (i.e., it performs the proxy user authentication process). Comparing the proxy information with the designated proxy information includes comparing the proxy authentication information with the authentication information. The control unit 51 of the second terminal 5 determines whether the proxy user verification is successful or not based on the result of the comparison. If the proxy user verification is successful, the control unit 51 of the second terminal 5 permits the proxy user to use the service and enables subsequent processing related to proxy linking. On the other hand, if the proxy user verification is unsuccessful, the processing procedure for setting up linking by proxy authentication may be terminated as appropriate.

[0223] In step SB10, the control unit of the first terminal 4C appropriately obtains the second identifier I20 and the second unique information C2 from the user. In step SB20, the control unit of the first terminal 4C requests the management system 100 to perform a linking setting by sending an authentication request (second request) for the user, including the second identifier I20 and the second unique information C2, to the second server 3. In step SA20, the control unit 51 of the second terminal 5 requests the management system 100 to perform a linking setting by sending an authentication request (first request) for the target user, including the first identifier I10 and the first unique information C1, to the first server 2. The processing in steps SB10, SB20, and SA20 may be the same as the proxy pattern in 1-1 above. The processing in step SA20 and from step SB20 onward may be executed in the same manner as in the above embodiment. As a result of the execution, a correspondence relationship between the target user and the user is set up depending on whether the authentication of the target user and the user is successful. Once the correspondence relationship is set up, the processing procedure for linking setting by proxy authentication is completed. Correspondence While this setting is enabled, the proxy user can exercise the rights of the target user (the person requesting the proxy) from within the service.

[0224] In addition, in the proxy patterns 1-2 described above, the notification paths for the first identifier I10 and the first unique information C1 are not limited to the examples shown above. At least one of the first identifier I10 and the first unique information C1 may be provided to the second terminal 5 via the first terminal 4C. In this case, at least one of the first identifier I10 and the first unique information C1 may be omitted from the data provided to the second terminal 5 in step SA10C.

[0225] Furthermore, in the proxy patterns described in 1-2 above, in the specification of the user in step SA10C, a specific individual may typically be specified. However, the method of specifying the user is not limited to this example. In another example, the user may not be specified as a specific individual, but rather as belonging to a specific operating organization or within any other range. In this case, for example, data sent in advance, such as designated proxy information, may be held on an external computer such as the first server 2. The second terminal 5 may download data from the target user terminal 6C from the external computer as a preprocessing step SE20. The data to be downloaded may be selected as appropriate. For example, the target user may be specified by an operation by the proxy user, data from the first terminal 4C, etc., and the second terminal 5 may download data corresponding to the specified target user. The target user may be specified as appropriate by the first identifier I10, etc. After downloading the data, the second terminal 5 may accept the usage application from the proxy user and execute the processing from step SE201 onwards. Furthermore, even when the item to be used is specified as a specific individual, the second terminal 5 may download the data from the target user terminal 6C when used by a proxy user. For example, if the period for which the proxy user can use the item is specified in advance, the second terminal 5 may download the data from the target user terminal 6C before the expiration of the usage period.

[0226] The processing procedure shown in Figure 13 above is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps may be omitted, replaced, or added as appropriate. For example, the notification of the grant of agency in step SE10 may be performed after step SA10C. The processing of step SE10 and the processing of step SA10C may be performed at least partially in parallel. The processing of step SA10C may be performed before step SE10. The processing of step SA20 may be performed at any time after step SE201. The processing of step SA20 may be performed before step SB10. The processing of step SA20 and the processing of steps SB10 and SB20 may be performed at least partially in parallel.

[0227] Furthermore, the configuration of the first-1 proxy pattern may be applied as appropriate to any configuration of the first-2 proxy pattern other than those described above. For example, in the first-2 proxy pattern, at least one of the expiration date of the proxy exercise and the authority to permit the proxy exercise (valid authority) may be specified. The management server 1 may generate linking information D10 which includes the proxy information. The management server 1 may also generate linking information D10 which includes information indicating whether or not a correspondence relationship has been set up by proxy linking. The correspondence relationship set up in response to a proxy linking request may be released in the same manner as the first-1 proxy pattern. The control unit 11 of the management server 1 may send a notification indicating the result of the setting process by proxy linking to at least one of the first terminal 4C, the second terminal 5, and the target user terminal 6C.

[0228] (modified version) Similar to the modified version of the proxy pattern in 1-1 above, the transmission path of the first unique information C1 is not limited to the example of the proxy pattern in 1-2 above. As a modified version, the authentication process proceeds without the first unique information C1, and the first server 2 queries the target user terminal 6C. That's good too.

[0229] Figure 14 schematically shows a modified example of the linking setting process in the first-to-second proxy pattern according to this embodiment. In the example in Figure 14, the first target information O10 (user information O10A) includes the contact information of the target user (first target) as attribute information. Figure 14 assumes a scenario in which the configuration of this modified example is applied to the example in Figure 12.

[0230] First, as in the examples in Figures 12 and 13 above, in step SE10, the target user terminal 6C accepts the designation of a proxy user. The target user terminal 6C notifies the designated proxy user's first terminal 4C of the granting of proxy authority. In step SA10D, the target user terminal 6C accepts the designation of a user that the proxy user is permitted to link by proxy. The target user terminal 6C provides the designated proxy information, including authentication information, and the first identifier I10 to the designated user's second terminal 5. Step SA10D may be the same as step SA10C above, except that the first unique information C1 is omitted.

[0231] Steps SB10 and SE20 are the same as the examples in Figures 12 and 13 above. In step SE20, the first terminal 4C submits a usage request to the second terminal 5 of the designated item. The second terminal 5 verifies the authenticity of the agent. If the verification is successful, the second terminal 5 activates the subsequent processing related to the agent linking. In step SB10, the first terminal 4C appropriately obtains the second identifier I20 and the second unique information C2 from the item.

[0232] The authentication process for the user from step SB20 onward may be performed in the same manner as in the above embodiment. As a result of the execution, the management server 1 receives the authentication result for the user from the second server 3. Furthermore, the processes in steps SA20D, SA210D, SA211D, and SA30 may be performed in the same manner as steps SA20B, SA210B, SA211B, and SA30 in the modified proxy pattern of 1-1 described above. As a result of the execution, the management server 1 receives the authentication result for the target user from the first server 2. After this, the management server 1 may execute the processes from step SC10 onward, in the same manner as in the above embodiment. As a result of the execution, a correspondence relationship between the target user and the user is set up depending on whether the authentication of the target user and the user has been successful. Once the correspondence relationship is set up, the processing procedure for setting up the linkage by proxy authentication is completed.

[0233] In this modified example, the configuration other than those described above may be the same as the configuration described above for the examples in Figures 12 and 13. Also, in this modified example, as with the modified example of the proxy pattern in 1-1 above, the processing in step SA211D may be performed in advance. As a result, the processing in step SA210D may be omitted.

[0234] (2) Second proxy pattern As a second proxy pattern, the management system 100 may be configured to grant proxy authority to the proxy user, but the authentication process may be performed by the target user. That is, the user terminal associated with the user (first terminal 4 in the example in Figure 2) may be a target user terminal owned by the target user. In one example, the usage relationship between the first target and the second target may be established by data communication between the target user terminal and the loading terminal, mediated by a proxy user terminal owned by the proxy user acting on behalf of the target user.

[0235] Figure 15 schematically shows an example of the linking setting process in the second proxy pattern according to this embodiment. Figure 16 shows an example of the linking setting processing procedure in the second proxy pattern according to this embodiment. In Figures 15 and 16, the first target is the target user requesting proxy services (proxy requester). The first terminal 4E is the target user terminal and corresponds to the first terminal 4 in the example in Figures 2 and 5 of the above embodiment. The proxy user terminal 6E is the terminal owned by the proxy user. This is the end. A proxy user is an example of a proxy individual, and a target user (proxy requester) is an example of a proxy request individual (target individual). The hardware configuration of the first terminal 4E and the proxy user terminal 6E may be the same as that of the first terminal 4 etc. in the above embodiment.

[0236] First, in step SF10, the control unit of the first terminal 4E operates as a proxy designation unit and accepts the designation of a proxy user from the target user. The designation of the proxy user may be performed in the same manner as in step SD10, etc. Once a proxy user is designated, the control unit of the first terminal 4E operates as a notification unit and exchanges data with the designated proxy user terminal 6E and notifies the granting of proxy authority. In response, the proxy user terminal 6E receives the notification of the granting of proxy authority from the first terminal 4E. In one example, this notification may include the contact information of the target user. Similar to the data exchange between the first terminal 4 and the second terminal 5, the data exchange between the proxy user terminal 6E and the first terminal 4E may be performed by wireless or wired data communication, or by methods other than data communication, such as reading a two-dimensional code. Furthermore, the first terminal 4E may directly give the notification of the granting of proxy authority to the proxy user terminal 6E, or it may transmit it indirectly via an external computer such as the first server 2. As a result, the first terminal 4E may have the proxy user terminal 6E perform mediation processing for data exchange with the second terminal 5.

[0237] In step SF20, the control unit of the proxy user terminal 6E operates as a data exchange unit and performs data exchange with the second terminal 5. The control unit 51 of the second terminal 5 operates as a data exchange unit 511 and performs data exchange with the proxy user terminal 6E. Similar to the data exchange between the first terminal 4 and the second terminal 5 described above, the data exchange between the proxy user terminal 6E and the second terminal 5 may be performed by wireless or wired data communication, or by methods other than data communication, such as reading a two-dimensional code. The control unit of the proxy user terminal 6E provides the second terminal 5 with the contact information of the target user. As a result, the proxy user terminal 6E causes the second terminal 5 to start data exchange with the first terminal 4E and, in coordination with the first terminal 4E, to send a request for linking settings to the management system 100 (send an authentication request for the target user to the first server 2). The processing in steps SF10 and SF20 is an example of mediation by a proxy user terminal owned by the proxy user.

[0238] In step SAB100E, the control unit 51 of the second terminal 5 operates as a data exchange unit 511 and performs data exchange with the first terminal 4E by accessing the contact information received from the proxy user terminal 6E. The control unit of the first terminal 4E operates as a data exchange unit and performs data exchange with the second terminal 5 in response to access from the second terminal 5. Basically, data exchange between the first terminal 4E and the second terminal 5 may be performed by wireless or wired data communication. However, the data exchange in step SAB100E does not necessarily have to be performed by data communication. In another example, data exchange between the first terminal 4E and the second terminal 5 may be performed by a method other than data communication, such as reading a two-dimensional code. In this case, the contact information of the target user may be omitted from the data in steps SF10 and SF20. The processing in step SF20 may simply be a trigger for the data exchange in step SAB100E.

[0239] The processing in steps SA10E and SB10E may be the same as in steps SA10 and SB10 in the above embodiment. The user authentication processing from step SA20 onwards, and the user authentication processing from step SB20 onwards may be performed in the same manner as in the above embodiment. As a result of performing these authentication processes, the management server 1 receives the authentication results for the user and the user. After this, the management server 1 may perform the processing from step SC10 onwards, as in the above embodiment. As a result of the execution, a correspondence relationship is set between the target user and the user depending on whether the authentication of the target user and the user is successful. Once the correspondence relationship is set, the processing procedure for setting up the linkage using the second proxy pattern is completed. While the correspondence relationship is set, the proxy user can exercise the authority of the target user (proxy requester) from the user.

[0240] Note that the processing procedure in Figure 16 above is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure may be omitted, replaced, or added as appropriate. For example, if a configuration is adopted in which data exchange between the first terminal 4E and the second terminal 5 is performed by data communication, steps SA10E and SA20 may be executed at any time after access from the second terminal 5. The processing of steps SA10E and SA20 may be executed at least partially in parallel with the processing of steps SB10E and SB20. The processing of step SA20 may be executed before step SB20. If the first terminal 4E and the second terminal 5 are connected before the processing of step SB10E, the processing of steps SA10E and SA20 may be executed before step SB10E.

[0241] Further, configurations other than those described above for the second proxy pattern may be applied with the configurations of the aforementioned 1-1st proxy pattern and 1-2nd proxy pattern as appropriate. For example, in the second proxy pattern, at least one of the expiration date of proxy exercise and the authority to permit proxy exercise (effective authority) may be specified. The management server 1 may generate association information D10 including agent information. The management server 1 may generate association information D10 including information indicating whether or not the correspondence is set by proxy association. The agent information may be provided from the proxy user terminal 6E to the first terminal 4E in step SB10E via the second terminal 5. Accordingly, the first terminal 4E may confirm whether the access of the second terminal 5 is access through the mediation of the specified proxy user. The management server 1 may transmit a notification indicating the execution result of the association setting to at least one of the first terminal 4E, the second terminal 5, and the proxy user terminal 6E. The set correspondence relationship may be canceled by a method similar to that of the aforementioned 1-1st proxy pattern. In another example, the management server 1 may be configured not to accept a cancellation request from the proxy user terminal 6E. In still another example, the management server 1 may be configured to accept a cancellation request from the proxy user terminal 6E via the first terminal 4E or the second terminal 5.

[0242] (3) Third proxy pattern The first proxy pattern and the second proxy pattern enable an authorized proxy user to exercise the rights of the target user while the correspondence between the target user for whom the proxy is requested and the used object is set. In contrast, as a third proxy pattern, the management system 100 may be configured such that the target user can exercise the proxy right granted by another user while the correspondence between the target user and the used object is set. That is, the management system 100 may be configured not to associate the proxy requester with the used object, but to associate the proxy user with the used object. In the third proxy pattern, the user terminal associated with the user (the first terminal 4 in the example of FIG. 2) may be a target user terminal possessed by the user. One of the first identifier I10 and the second identifier I20 that corresponds to the user (the first identifier I10 in the example of FIG. 2) may be associated with a proxy right of another user other than said user.

[0243] FIG. 17 schematically illustrates an example of the association setting process in the third proxy pattern according to the present embodiment. FIG. 18 shows an example of the processing procedure for granting a proxy right in the third proxy pattern according to the present embodiment. In FIG. 17 and FIG. 18, the first target is the user to whom the proxy right is granted. The first terminal 4F is a target user terminal, and corresponds to the first terminal 4 in the examples of FIG. 2 and FIG. 5 of the above embodiment. The other user terminal 6F is a terminal possessed by another user (proxy requester) who requests the target user to act as a proxy. Typically, said another user is a different user from the target user who has an account on the same service (the first server 2) as the target user. The user to whom the proxy right is granted is an example of a proxy individual, and the other user (proxy requester) is an example of a proxy requesting individual (another individual). The hardware configurations of the first terminal 4F and the other user terminal 6F may be the same as those of the first terminal 4 and the like in the above embodiment.

[0244] First, in step SG10, the control unit of the other user terminal 6F operates as a proxy designation unit, and accepts designation of a proxy user from the proxy requester (the other user). The designation of the proxy user may be performed in the same manner as in step SD10 and the like described above.

[0245] In step SG101, the control unit of another user terminal 6F accesses the first server 2. The control unit 21 of the first server 2 operates as an authentication unit 211 and performs user authentication for the other user terminal 6F that has received the access request. The authentication in step SG101 may be the same as the authentication using identifiers and unique information in steps SA25 and SB25 described above. Typically, the authentication process in step SG101 is a login process. Once authentication is successful, the control unit 21 of the first server 2 grants proxy authority to the target user designated as a proxy user in response to a request from the other user terminal 6F. The granting of proxy authority may be expressed in any data format. In one example, as part of the proxy authority granting process, the control unit 21 may associate the information of the proxy requester (for example, the identifier of the proxy requester) with the user information O10A of the target user designated as a proxy user. Associating the information of the proxy requester with the user information O10A of the target user is an example of associating the proxy authority of another user other than the target user with the first identifier I10 of the target user. The management system 100 may be configured as appropriate so that the exercise of authority in proxy mode is possible when the information of the proxy requester is associated with it.

[0246] In step SG20, the control unit 21 of the first server 2 sends a notification to the first terminal 4F of the target user designated as the proxy user, informing them that they have been granted proxy authority on behalf of another user. The control unit 21 may send the notification of the grant of proxy authority directly to the first terminal 4F, or it may send it indirectly via an external computer such as another user terminal 6F. Once the notification of the grant of proxy authority is completed, the proxy authority granting process in the third proxy pattern is completed. In one example, the first terminal 4F may perform a linking process to set up a correspondence with the user, independently of the proxy authority granting process in Figure 18, by the target user. In another example, the linking process may be executed triggered by the notification of the grant of proxy authority. The series of processes for setting up the correspondence between the target user (first terminal 4F) and the user (second terminal 5) may be the same as in the above embodiment. As a result of performing the linking process, the correspondence between the target user and the user is set up depending on whether authentication of the target user and the user is successful. Once the correspondence is established, the processing procedure for linking using the third proxy pattern is completed. While the correspondence is established, the target user (proxy user) can exercise the authority of the other user (proxy requester) from the object.

[0247] Note that the processing procedure shown in Figure 18 above is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the above processing procedure can be omitted, replaced, or added as appropriate. For example, if a user list is maintained in an accessible manner from the first server 2 and a proxy user is designated on the first server 2, the processing of step SG10 may be executed on the first server 2 via another user terminal 6F after the other user terminal 6F has accessed the first server 2. In this case, the processing of step SG101 may be executed before step SG10.

[0248] Furthermore, the configurations of the third proxy pattern other than those described above may be appropriately applied to the proxy pattern described in 1-1 above. For example, in the third proxy pattern as well, the management server 1 may generate linking information D10 which includes proxy information. At least one of the expiration date of the proxy exercise and the authority that permits the proxy exercise (effective authority) may be specified. In this case, the proxy rights granted by other users may expire when the specified effective authority is reached. The granted proxy rights may expire upon the exercise of the specified effective authority. In addition, the first server 2 may be configured to delete the proxy rights granted by other users in response to requests from other users (proxy requesters).

[0249] (Features) According to this modified version, each user will be able to exercise the authority of a proxy requester through the device being used. This increases the scalability of authority exercise. For example, consider a scenario where authority information includes information about electronic prescriptions, and the authority in question is to pick up medication prescribed by the electronic prescription. In this case, the user does not have to pick up the prescribed medication themselves, but can grant proxy authority to another user, such as a taxi driver, and have that user pick up the prescribed medication via a mobile device.

[0250] [5. Supplement] The processes and means described herein can be freely combined and implemented, provided that no technical inconsistencies arise.

[0251] Furthermore, a process described as being performed by a single device may be divided and executed by multiple devices. Conversely, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration used to implement each function can be flexibly changed.

[0252] The present disclosure can also be realized by supplying a computer program implementing the functions described in the embodiments above to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. Non-temporary computer-readable storage mediums include, for example, any type of disk such as magnetic disks (floppy disks, hard disk drives (HDDs), etc.), optical disks (CD-ROMs, DVDs, Blu-ray discs, etc.), read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic cards, flash memory, optical cards, semiconductor drives (solid-state drives, etc.), and any type of medium suitable for storing electronic instructions. [Explanation of symbols]

[0253] 1...Management server, 11...Control unit, 2...First server, 21...Control unit, 3...Second server, 31...Control unit, 4...First terminal, 41...Control unit, 5...Second terminal, 51...Control unit, C1...First unique information, I10...First identifier, O10...Primary target information, O10A...User information, C10...First registered unique information, C2...Second unique information, I20...Second identifier, O20...Second target information, O20A...Mobile information, C20...Second registered unique information, D10…Linking information, E10…Various information

Claims

1. First server, Second server, and Management server Equipped with, The first server is, In response to the establishment of a usage relationship between the first target and the second target, the first authentication request for the first target is received from the second terminal of the second target. In response to receiving the first request, authenticate the first object, and To transmit the authentication result of the first target to the management server, It is configured to perform, The second server is, In response to the establishment of a usage relationship between the first target and the second target, the second authentication request for the second target is received from the first terminal of the first target. In response to receiving the second request, authenticate the second object, and To transmit the authentication result of the second target to the management server, It is configured to perform, and The aforementioned management server Receiving the authentication results of the first target and the second target from the first server and the second server, and In the authentication results of the received first and second targets, if both the first and second targets are authenticated, the correspondence between the first identifier of the first target and the second identifier of the second target is set. It is configured to perform, The first request includes the first identifier and the second identifier, The second request includes the first identifier and the second identifier, Transmitting the authentication result of the first target comprises transmitting the authentication result of the first target with the first identifier and second identifier included in the first request attached, Transmitting the authentication result of the second target comprises transmitting the authentication result of the second target with the first identifier and the second identifier included in the second request attached, The management server is assigned to the authentication result of the first target received from the first server. Further, the authentication results of the received first and second targets are associated with the first and second identifiers, depending on the match between the first and second identifiers attached to the authentication results of the second target received from the second server. Setting the correspondence between the first identifier and the second identifier is accomplished by setting the correspondence between the first identifier and the second identifier that corresponds to the authentication results of the first and second objects associated with each other. Management system.

2. The management server is configured to further perform the action of canceling the correspondence relationship upon receiving a cancellation request from at least one of the first terminal and the second terminal or upon fulfilling a predetermined cancellation condition. The management system according to claim 1.

3. The first server is connected to a first storage device that stores first registered unique information for authentication of the first target, which is first registered unique information associated with the first identifier, and is configured to access the first storage device. The second server is connected to a second storage device that stores the second registered unique information for authentication of the second target, which is associated with the second identifier. The first request further includes first unique information, The aforementioned second request further includes second unique information, Authenticating the first object is performed by comparing the first unique information contained in the received first request with the first registered unique information associated with the first identifier. Authenticating the second object involves comparing the second unique information contained in the received second request with the second registered unique information associated with the second identifier. The management system according to claim 1.

4. Transmitting the authentication result of the first target comprises transmitting the authentication result of the first target with the first supplementary information attached. Transmitting the authentication result of the second target comprises transmitting the authentication result of the second target with the second supplementary information attached. The management server further performs the following: In response to the successful matching of the first supplementary information and the second supplementary information, it associates the authentication results of the received first and second targets. Setting the correspondence between the first identifier and the second identifier is accomplished by setting the correspondence between the first identifier and the second identifier that corresponds to the authentication results of the first and second objects associated with each other. The management system according to claim 1.

5. The first and second ancillary information are composed of temporary information. The management system according to claim 4.

6. The usage relationship between the first target and the second target arises when data communication is performed between the first terminal and the second terminal. In the data communication between the first terminal and the second terminal, shared temporary information is generated. The first request and the second request each include the generated shared temporary information, The first ancillary information is obtained from the shared temporary information included in the first request, The second supplementary information is obtained from the shared temporary information included in the second request. The management system according to claim 5.

7. One of the first and second objects is a user. Of the first and second terminals, the terminal corresponding to the user is a user terminal associated with the user. The other of the first object and the second object is a product used by the user, Of the first and second terminals, the terminal corresponding to the item being used is a loading terminal that is loaded onto the item being used. The management system according to any one of claims 1 to 6.

8. The aforementioned object is a mobile object. The management system according to claim 7.

9. The user terminal associated with the aforementioned user is a proxy user terminal owned by a proxy user acting on behalf of the aforementioned user. The management system according to claim 7.

10. The usage relationship between the first target and the second target is established through data communication between the target user terminal and the proxy user terminal owned by the user, and between the proxy user terminal and the loading terminal. The management system according to claim 9.

11. The user terminal associated with the aforementioned user is the target user terminal owned by the aforementioned user. The usage relationship between the first target and the second target arises when data communication between the target user terminal and the loading terminal is performed through the mediation of a proxy user terminal held by a proxy user acting on behalf of the user. The management system according to claim 7.

12. The user terminal associated with the aforementioned user is the target user terminal owned by the aforementioned user. One of the first and second identifiers, which corresponds to the user, is associated with the power of attorney of another user other than the user. The management system according to claim 7.

13. The management server, In response to the establishment of a usage relationship between the first target and the second target, and in response to the receipt of a first authentication request for the first target from the second terminal of the second target, the authentication result of the first target is received from the first server configured to authenticate the first target. In response to the establishment of a usage relationship between the first target and the second target, and in response to the receipt of a second authentication request for the second target from the first terminal of the first target, the authentication result of the second target is received from the second server configured to authenticate the second target, and In the authentication results of the received first and second targets, if both the first and second targets are authenticated, the correspondence between the first identifier of the first target and the second identifier of the second target is set. A management method that performs the following: The first request includes the first identifier and the second identifier, The second request includes the first identifier and the second identifier, Receiving the authentication result of the first target comprises receiving the authentication result of the first target to which the first identifier and the second identifier included in the first request are attached, Receiving the authentication result of the second target means that the first identifier included in the second request and is configured to receive the authentication result of the second target to which the second identifier has been assigned, The management server further associates the received authentication results of the first and second targets with the first identifier and second identifier attached to the authentication result of the first target received from the first server, in accordance with the match between the first identifier and second identifier attached to the authentication result of the second target received from the second server. Setting the correspondence between the first identifier and the second identifier is accomplished by setting the correspondence between the first identifier and the second identifier that corresponds to the authentication results of the first and second objects associated with each other. Management method.

14. The management server further performs the action of canceling the correspondence relationship upon receiving a cancellation request from at least one of the first terminal and the second terminal or upon fulfillment of predetermined cancellation conditions. The management method according to claim 13.

15. Receiving the authentication result of the first target is comprised of receiving the authentication result of the first target to which the first supplementary information is attached. Receiving the authentication result of the second target is comprised of receiving the authentication result of the second target to which the second supplementary information is attached. The management server further performs the following: In response to the successful matching of the first supplementary information and the second supplementary information, it associates the authentication results of the received first and second targets. Setting the correspondence between the first identifier and the second identifier is accomplished by setting the correspondence between the first identifier and the second identifier that corresponds to the authentication results of the first and second objects associated with each other. The management method according to claim 13.

16. One of the first and second objects is a user. Of the first and second terminals, the terminal corresponding to the user is a user terminal associated with the user. The other of the first object and the second object is a product used by the user, Of the first and second terminals, the terminal corresponding to the item being used is a loading terminal that is loaded onto the item being used. The management method according to any one of claims 13 to 15.

17. The aforementioned object is a mobile object. The management method according to claim 16.

Citation Information

Patent Citations

  • Authentication and registration system

    JP2020068024A

  • Vehicle payment support device

    JP2022140747A

  • Control method for information processing device and information processing device

    JP2023073149A