Building gate management system, communication terminal in the management system, and program for the communication terminal
Patent Information
- Application Number
- JP2022168806
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-10-21
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2042-10-21
AI Technical Summary
【0021】 本発明は、建物から退去した元居住者が所持する通信端末が、その記憶部に保持している認証用鍵IDを一定期間使用していない場合には、もはや認証用鍵IDを利用する権限がなくなったものと見做し、これにより、例えば前記建物の元居住者が所持している通信端末(特にスマホ)自体に自動的に認証用鍵IDを残さない、或いは自動的に認証用鍵IDを使用不可とすることができる。こりより、認証システムの利便性の向上を図ることができる。
Smart Images

Figure 0007923683000001 
Figure 0007923683000002 
Figure 0007923683000003
Abstract
Description
Technical Field
[0001] The present invention relates to a building gate management system, a communication terminal in the management system, and a program for the communication terminal, and particularly relates to a building gate management system, a communication terminal in the management system, and a program for the communication terminal that can actuate (e.g., unlock, open / close, etc.) locking devices such as electric locks for gates in security zones and automatic door opening / closing devices using an authentication key ID recorded by the communication terminal.
Background Art
[0002] First, Patent Document 1 relates to an authentication device for an access control system in which communication is performed between a smart lock and a server when user authentication is performed on the server side that manages user privileges in a smart lock that performs unlocking / locking via an electronic device such as a smartphone (hereinafter sometimes simply referred to as "smartphone"), wherein the unlocking authentication means of the server determines (authenticates) whether an authentication key ID (identification information) held by the smartphone is available or unavailable.
[0003] That is, the invention of Patent Document 1 is an electric lock system including a lock control terminal that controls unlocking of an electric lock and a mobile terminal carried by a user of a facility where the electric lock is installed, wherein the lock control terminal comprises unlocking authentication means that authenticates that the mobile terminal has an unlocking authority for the electric lock using an electronic certificate received from the mobile terminal and source terminal identification information, and unlocking control means that controls to unlock the electric lock when the unlocking authentication means authenticates that the mobile terminal has the unlocking authority for the electric lock. Then, the unlocking authentication means confirms that the electronic certificate is an electronic certificate for the electric lock when the lock identification information read from the electronically verified certificate matches the lock identification information of the electric lock, and authenticates that the mobile terminal has the unlocking authority for the electric lock when the terminal identification information read from the confirmed electronic certificate matches the source terminal identification information.
[0004] Therefore, claim 5 of Patent Document 1 states that "the lock control terminal (authentication system side) further has a storage unit that stores a blacklist in which terminal identification information of mobile terminals that prohibit unlocking the electric lock is registered, and when it receives the blacklist from the mobile terminal it updates the stored blacklist, and if the source terminal identification information matches the terminal identification information registered in the updated blacklist it does not authenticate that the mobile terminal has the authority to unlock the electric lock."
[0005] The invention described in claim 5 has the effect that the electric lock can properly authenticate that the mobile terminal requesting unlocking has the authority to unlock the electric lock, even without the electric lock communicating with a management device that manages the authority to unlock the electric lock. However, since both the mobile terminal and the lock control terminal (authentication system side) record a blacklist containing the terminal identification information of the mobile terminal itself (including updating the blacklist), and the lock control terminal (authentication system side) always verifies the terminal identification information in the blacklist when a communication connection is established, there are problems such as an increase in the amount of recorded information between terminals, an increase in system complexity, and the retention of information recorded in the blacklist on the mobile terminal.
[0006] Next, Patent Documents 2 and 3 relate to a function that switches between normal mode and silent mode for ringtones, which is one of the "applications" of a mobile terminal known as a smartphone. For example, Patent Document 2 includes a setting time holding means for starting the silent mode setting, and a mode management means for controlling the start of the silent mode setting based on the start setting time held in the setting time holding means, in order to automatically switch between normal mode and silent mode.
[0007] By the way, as is well known, the memory of the aforementioned smartphone stores a large number of applications, but in relation to the building's gate management system, it does not contain any information regarding, for example, the unusability of authentication key IDs for communication terminals owned by former residents of the building. [Prior art documents] [Patent Documents]
[0008] [Patent Document 1] Japanese Patent Publication No. 2019-173523 [Patent Document 2] Japanese Patent Publication No. 2006-50293 [Patent Document 3] Japanese Patent Publication No. 2010-109616 [Overview of the Initiative] [Problems that the invention aims to solve]
[0009] The main objective of the present invention is to address the authentication key IDs registered in the memory of a communication terminal owned by a former resident who has moved out of a building, without recording a blacklist on both the communication terminal and the lock control terminal (authentication system side). Instead, if the communication terminal has not used the authentication key ID it holds in its memory for a certain period of time, it is considered that the user no longer has the authority to use the authentication key ID. This prevents the authentication key ID from being stored on the communication terminal (e.g., a smartphone) owned by the former resident of the building, or makes it impossible to use the authentication key ID. This eliminates the need for authentication of blacklists between terminals (e.g., correspondence) and prevents an increase in the amount of recorded information between terminals. The disabled information includes, for example, a sleep state, but preferably prohibits the use of the authentication key ID (including the deletion of the authentication key ID). The second objective is to disable the use of key information recorded in the memory of the security zone of all common areas when the security zone includes one or more common areas. As a specific embodiment, for example, if the gates of a security zone include gates such as entrances and elevators, the key information recorded in the memory of each authentication system installed in the common area is disabled to prevent unauthorized unlocking of these gates. As an example of the use and implementation of the present invention, for example, if a communication terminal has different authentication key IDs corresponding to the number of buildings, it is also possible to determine whether or not to continue using all of the different authentication key IDs. [Means for solving the problem]
[0010] First, the building gate management system of the present invention is Private and common areas of residents in apartment buildings Security zone each The gate locking device is configured to record an authentication key ID for at least the purpose of unlocking the gate, and the authentication key ID is compared with the registered key information. If the result of the comparison is valid, then the each A locking device for the gate eachA building gate management system comprising an authentication system for operation, wherein the communication terminal is This is a mobile device owned by a former resident who has moved out of the aforementioned apartment building, and the mobile device's storage unit retrieves data from a server via the network. The system comprises an authentication application, a determination means for determining whether the authentication application was launched within a certain period of time, or whether the authentication of the authentication key ID by the authentication application was performed within a certain period of time, and a terminal control unit for controlling a communication terminal. The determination means, by referring to the current time indicated by a time unit, determines that the authentication application was not launched at all within the certain period of time, or by referring to the current time indicated by a time unit, that the authentication of the authentication key ID was not performed at all within the certain period of time. In such cases, the terminal control unit registers information that the authentication key ID is unavailable in a storage unit, thereby preventing the communication terminal from transmitting the authentication key ID to the authentication system thereafter (Claim 1). This eliminates the need for authentication of blacklists between terminals and prevents an increase in the amount of recorded information between terminals.
[0011] In the above configuration, the security zone is characterized by having multiple shared areas (Claim 2). Furthermore, the program of the present invention is In a building gate management system according to claim 1 If the computer determines, by referring to the current time indicated by the timekeeping unit, that either the authentication application was not launched at all within a certain period, or the authentication of the authentication key ID was not performed at all within a certain period, apartment complex The system is characterized by determining that the authentication key ID of a communication terminal owned by a former resident is a control signal for information that the ID cannot be used, and by executing a process to record the information that the ID cannot be used in the storage unit (Claim 3).
[0012] For example, the terminal control unit registers the unavailable information in its storage unit, then transmits the unavailable information to the server, and the server records the unavailable information in its server storage unit. By This makes it easier for servers to centrally manage unavailable information.
[0013] Furthermore, the communication terminal is characterized by being possessed by a former resident who has moved out of the building. This means that even if a former resident who has moved out of the building possesses the communication terminal, if there are multiple gates in the common area, the registered key information for those gates can be erased, for example, thus more reliably preventing unauthorized entry into the building. In the case of apartment buildings, the reason for using the erasure of information in the common area as a trigger is that, for security reasons, when a resident moves out, it is necessary to first prevent the resident from entering the apartment building, so it is generally preferable to erase the key information from the authentication system of the common area.
[0014] Furthermore, the communication terminal is characterized by comprising: a receiving means for receiving an authentication key ID; a registration unit for registering the authentication key ID received by the receiving means in a storage unit; an operation unit; a display unit; a timing unit; a discrimination means; a transmitting means for transmitting the registered authentication key ID to an authentication system; and an authentication application registered in the storage unit.
[0015] In addition, depending on the embodiment, if the communication terminal has different authentication key IDs corresponding to either the number of buildings or the number of gates, the terminal control unit obtains information on the last operation date when the transmission of each authentication key ID was stopped in chronological order by detecting the operation of the operation unit for each authentication key ID from the storage unit, and the determination means determines whether or not to continue using the authentication key ID by referring to the current time indicated by the timing unit. This makes it possible to determine whether or not to continue using all of the authentication key IDs.
[0016] In the building gate management system of the present invention described above, there is an embodiment in which "the communication terminal discrimination means 18 refers to the current time indicated by the timing unit 17 and determines whether or not authentication of the authentication key ID has not been performed at all within a certain period of time." This embodiment means that, regarding the timing of discrimination by the discrimination means 18, it is not necessary to make the determination when the authentication application is launched. Specifically, it is assumed that the authentication application is always running in the background of the smartphone, and the timing of the determination of whether or not the authentication key ID has been used within a certain period of time is determined at predetermined intervals. An embodiment based on this assumption is, for example, that instead of comparing the current time with the last operation history information, the timing unit 17 starts a timer from the last operation and determines whether or not the authentication ID has been used within a certain period of time by referring to the elapsed time. In such an embodiment, if the authentication ID has not been used within a certain period of time, the next authentication is not performed, and the authentication key ID is immediately made unavailable. On the other hand, if authentication using the authentication key ID was performed before the certain period of time elapsed based on the last operation, the current status is maintained.
[0017] Here, the "authentication key ID" is preferably an electrical key in which the identification information and key ID of the communication terminal, the identification information of the authentication system terminal, the identification information of the authentication system gate, and the identification information of the server are appropriately linked. In cases where there are multiple former residents (father, mother, child, etc.) and each possesses their own communication terminal, the authentication key ID of the communication terminal will differ depending on the identification information of each communication terminal. In such cases, there will also be multiple registered key information entries in the authentication system corresponding to the number of authentication key IDs of each individual communication terminal.
[0018] Furthermore, a "security zone" refers to a private space demarcated based on criteria such as gates for entering the premises of a building, such as an apartment complex, office building, or commercial facility; automatic doors for entering the entrance; automatic doors for using elevators; and doors for entering private units. Therefore, a private space can be singular or plural. Also, a "gate" refers to an opening and closing mechanism used for shielding a building.
[0019] It should be noted that the "locking device" includes not only electric locks that have a cylinder lock or thumbturn lock on the lock body and can be mechanically and electrically locked and unlocked, but also driving devices that are equipped with a drive motor, power transmission means, etc., and are used to open the shielding opening / closing body in the horizontal or vertical direction by the driving force of the drive motor. Therefore, the "activation" herein includes cases where the shielding opening / closing body is in a stationary state and the locked state of the locking means for the so-called dead bolt is released, cases where the dead bolt moves in the unlocking direction, and cases where the shielding opening / closing body moves in the opening direction by the driving force of the drive motor. Also, generally, As a building In the case of an apartment complex, security zones include a common area gate used at the entrance and an exclusive area gate corresponding to individual building unit ownership, so there are also a first authentication system for the common area gate and a second authentication system corresponding to the exclusive area gate in the authentication system. In the case of an office building, security zones include a common area gate used at the entrance and an exclusive area gate corresponding to individual building unit ownership or the right of occupancy based on a tenant's lease agreement, so the authentication system also comprises a first authentication system for the common area gate and a second authentication system corresponding to the exclusive area gate.
[0020] Furthermore, the "condition for disabling the authentication key ID" includes either of the following cases: when the authentication application has not been activated within a certain period based on current date and time information, or when a certain period including a plurality of days has elapsed from the set start time of the timer based on the last authentication key ID response, etc. when said authentication application has been used multiple times based on current date and time information. Preferably, said "information on disabling the authentication key ID" corresponds to a state where the authentication key ID is set to sleep mode or a state where the authentication key ID is deleted.
Effects of the Invention
[0021] In the present invention, if a communication terminal possessed by a former resident who has moved out of a building does not use the authentication key ID stored in its storage unit for a certain period of time, it is considered that the authority to use the authentication key ID has been revoked. Accordingly, for example, the authentication key ID can be automatically prevented from being left in the communication terminal (especially a smartphone) possessed by the former resident of the building, or the authentication key ID can be automatically disabled. This makes it possible to improve the convenience of the authentication system. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figures 1 to 6 are respective explanatory views showing a first embodiment of the present invention. [Figure 1] A conceptual configuration diagram showing the entire management system X. [Figure 2] A block diagram showing the configuration of a communication terminal. [Figure 3] A schematic diagram showing the configuration of an authentication system. [Figure 4] A schematic diagram showing the configuration of a server. [Figure 5] An explanatory view showing an example of usage history information registered in a storage area of a storage unit by execution of an authentication application of a communication terminal. [Figure 6] A flowchart in a case where the authentication application of the communication terminal is not activated within a certain period (first embodiment). [Figure 7] A flowchart in a case where the authentication key ID is not used within a certain period (second embodiment). [Figure 8] A flowchart in which a determination means determines whether the authentication key ID has been used within a certain period with reference to the current time indicated by a timer and the width of a count time (third embodiment). MODE FOR CARRYING OUT THE INVENTION
[0023] Figures 1 to 6 are respective explanatory views of a building gate management system X (hereinafter also referred to as "management system X") according to the first embodiment of the present invention. Figure 1 is a conceptual configuration diagram showing the entire management system X.
[0024] <Basic overall structure> In Figure 1, 1 is a security zone of one or more buildings, 2 is a number of gates provided in the security zone, 3 is a locking device for the gate (electric lock, automatic opening / closing door, automatic opening / closing shutter, etc.) provided on the gate itself or near the gate (door frame, wall), 4 is a communication terminal that records the authentication key ID (e.g., authority to unlock an electric lock, authority to open an automatic opening / closing door, etc.) A and the authentication application B for the locking device, respectively, 5 is an authentication system that compares the authentication key ID (code A) with registered key information (code R) and activates the gate locking device 3 when the registered key information R and the authentication key ID match, 6 is a network to which the communication terminal 4 and the authentication system 5 are connected, respectively, and 7 is a server that connects to the authentication system 5 via the network 6 and manages the authentication key ID (code A) in its storage. In the first embodiment, the authentication key ID (code A) and authentication application (code B) managed by the server 7 can be distributed to the communication terminal 4 via the network 6.
[0025] <Configuration of communication terminal 4> Figure 2 is a block diagram showing the configuration of the communication terminal 4. The communication terminal 4 is a portable device such as a smartphone or tablet that is carried by people passing through gate 2 of security zone 1 (for example, residents of the building, people who have been given an authentication key ID by residents, former residents who have moved out of the building, etc.) and used to operate the gate's locking device 3 (unlocking, locking, opening and closing). For convenience, portable devices may also be referred to as "smartphones" here.
[0026] Therefore, the communication terminal 4 or smartphone includes, for example, a terminal control unit 10, a touch panel 11 as an operation unit and display unit, a storage unit 12, a registration unit 12a having a mode switching function for new registration, update registration, change registration, and deletion registration of authentication key IDs (code A), an authentication key ID identification unit 15 that extracts a copy of the authentication key ID (code A) recorded in the storage unit 12, multiple communication units 13 (13a, 13b) for receiving and transmitting authentication key IDs, a timing unit 17, a discrimination means 18, various switches (not shown), a camera function, multiple applications, and an authentication application B (sometimes simply called "app" or "app B").
[0027] In addition, as shown in Figure 1, the communication terminal 4 of this embodiment stores the authentication application (code B) obtained from the server 1 via the network 6 in the storage unit 12. Here, we will briefly explain the functions of each part. The receiving means 14 included in the first communication unit 13a and the transmitting means included in the second communication unit 13b correspond to the so-called antenna unit and wireless unit, and are the transmitting and receiving units of the communication terminal 4. The terminal control unit 10 naturally controls the communication terminal 4. In this embodiment, the terminal control unit 10 controls and manages, for example, the activation (start) and deactivation of the authentication application (code B), and information regarding unavailability when the authentication key ID is deactivated.
[0028] The timing unit 17 also measures the time when authentication application B starts up, the time when it stops up, and the current time. The timing unit 17 always maintains the current time. The timing unit 17 also includes a time correction server, a dedicated time server, etc. (not shown). As shown in Figure 2, the terminal control unit 10 records, in relation to the timing of the timing unit 17, the application usage time (startup and shutdown time) 17a of the authentication application B (simply referred to as "app" in Figure 2), the start time of use of the authentication key ID 17b, etc., in the time storage area 12b of the storage unit 12.
[0029] The predetermined conditions determined by the determination means 18 of the embodiment, in other words, the "conditions for the unavailability of the authentication key ID," are either when the authentication application B has not been launched at all within a certain period of time, or when, based on the last use of the authentication key ID (e.g., response) in the case of multiple uses of the authentication application B, a certain period of time including multiple days has elapsed from the application usage time (including at least one of the application launch setting time or application stop setting time) 17a, or the usage time (e.g., response time) 17b, of the authentication application B recorded by the timing unit 17.
[0030] If the determination means 18 determines that either the authentication application B has not been launched at all within a certain period, or that authentication of the authentication key ID has not been performed at all within a certain period, the terminal control unit 10 registers the information that the authentication key ID is unavailable in the storage unit 12, thereby preventing the communication terminal from transmitting the authentication key ID (code A) to the authentication system 5 thereafter. The time when the application B was used within a certain period, the period during which the application B was not used within a certain period, and / or the time when the authentication key ID was used within a certain period, and the period during which it was not used within a certain period, constitute the "history information" (see Figures 6 and 7).
[0031] However, as shown in Figures 1 and 2, the communication terminal 4 of the embodiment includes a receiving means 14 that receives an authentication key ID (code A) via the network 6 to at least unlock the locking device 3 of the gate 2 of the building's security zone 1, a registration unit 12a that registers the authentication key ID received by the receiving means in a storage unit 12, an operation unit 11, a display unit 11, a timing unit 17, a transmitting means 16 that transmits the registered authentication key ID to the authentication system 5, an authentication key ID identification unit 15 that transmits the authentication key ID to the transmitting means 16, and a time storage area 12b that stores the authentication application B registered in the storage unit 12, the application startup time 17a, the start time of use of the authentication key ID 17b, the application startup stop time 17a, etc., and the condition for the unavailability of the authentication key ID (code A) is either that the authentication application (code B) has not been started at all within a certain period of time, or that authentication of the authentication key ID has not been performed at all within a certain period of time. In this context, "app usage time" includes at least one of either the app launch time 17a or the app launch / deactivation time 17a, so the same symbol is used.
[0032] To reiterate, the terminal control unit 10 has the authentication key ID (code A) of the locking device recorded in its storage unit 12. The first communication unit 13a of the communication unit 13 includes an authentication key ID receiving means 14 that obtains the authentication key ID and application B from the server 7 and passes the authentication key ID and application B to the registration unit 12a. On the other hand, the second communication unit 13b of the communication unit 13 includes an authentication key ID transmission means (unlocking request means) 16 that uses the authentication key ID, to which identification information such as gate identification information, locking device identification information, control unit identification information for the locking device, and server source identification information is appropriately linked via the authentication key ID identification unit 15, and requests the operation of the locking device 3.
[0033] <Configuration of the authentication system> Figure 3 is a schematic diagram showing the configuration of the authentication system. In Figure 3, 20 is the control unit, 21 is the key information registration unit as a storage unit, 22 is the key information deletion means for deleting the authentication key ID registered in the key information registration unit, 23 is the unlocking authentication means for verifying whether the authentication key ID (code A) and the registered key information (code R) match, 24 is the unlocking request means for requesting an unlocking or opening / closing signal from the locking device 3 for the gate 2, 25 is the first communication unit that communicates with the server 7, 26 is the second communication unit that communicates the authentication key ID and deletion signal with the communication terminal 4, 27 is the input / output unit, and 28 is an external device (e.g., a laptop computer) for setting and deleting key information.
[0034] The external device 28 is used, for example, when a new resident moves into a private unit in an apartment building, which is an example of a building's security zone. Before the server distributes the authentication key ID to the communication terminal 4, the administrator or a qualified key maintenance contractor registers the new key information corresponding to the authentication key ID in the key information registration unit 21. Therefore, in this embodiment, when a contractor sets new key information in the key information registration unit 21 via the external device 28, the authentication system 5 notifies the server 7 from the first communication unit 25 that the new key information has been registered. When the server 7 receives the notification, it registers it in its storage unit 33, as will be described later.
[0035] Incidentally, if the external device 28 is, for example, a laptop computer or tablet terminal, it has the function of an external command device for the authentication system 5. Therefore, although not specifically shown in the diagram, it has various files in the external command storage unit, such as a registration file for registering new key information, a change file for changing a registered authentication key ID to another authentication key ID, a prohibition file for prohibiting the use of a registered authentication key ID, a deletion file for deleting a registered authentication key ID, and an authentication key ID distribution file.
[0036] It also has an external command communication processing unit for communicating with the authentication system 5. It also has a control unit that controls the operation of each component such as the external command storage unit and the external command communication processing unit, and performs the transmission of various signals and information between each component. Therefore, for example, in an embodiment in which the authentication system 5 includes the external device 28, the authentication system 5 plays the role (function) of an information presentation device side communication device that presents information regarding the authentication key ID to the server 7.
[0037] Therefore, the authentication system 5 comprises at least a locking device 3 for gate 2, a verification unit (unlocking authentication means) 23 for determining whether or not an authentication key ID is available, a control unit 20 for controlling the locking device 3, a key information registration unit 21 as a storage unit, a plurality of communication units (25, 26) for communicating with the communication terminal 4 and the server 7, and an input / output unit 27, and preferably also includes the external equipment 28.
[0038] Then, if the registered key information R recorded by the key information registration unit 21 is newly registered, updated, or deleted by an external device 28 for setting and deleting key information regarding authentication key IDs, the control unit 20 outputs unavailability information to the server 7 at least at the time of the deletion registration (for example, when a tenant moves out, just before a new tenant moves in, or at an appropriate time between the time of departure and the time of move-in), indicating that the former resident's authentication key ID can no longer be used, for example, regarding the deletion registration of a departing tenant. In the first embodiment, if the authentication system 5 is unable to receive the authentication key ID from the communication terminal 4 for a certain period of time, the authentication system 5 considers that the owner of the communication terminal 4 is no longer qualified to use the authentication key ID, and this triggers the first communication unit 25 of the authentication system 5 to notify the server 7 of the unavailability information via the network.
[0039] However, even if the server 7 receives "unavailable information" from the authentication system 5 regarding the communication terminal 4, the authentication key ID still remains on the communication terminal 4. In this case, the user (for example, the former resident) may not proactively delete the authentication key ID. If the user does not proactively delete the authentication key ID held on the communication terminal 4, the authentication key ID will remain on the smartphone 4 owned by the former resident, for example.
[0040] Therefore, the communication terminal 4 of the embodiment has an authentication application B and a determination means 18 that determines whether the authentication application was started within a certain period of time, or whether authentication by the authentication application was performed within a certain period of time. If the determination means 18 determines that the authentication application B was not started at all within a certain period of time, or that authentication of the authentication key ID was not performed at all within a certain period of time, the terminal control unit 10 registers information that the authentication key ID is unavailable (e.g., deletion information) in the storage unit 12, and as a result, the communication terminal 4 is unable to transmit the authentication key ID to the authentication system 5 thereafter.
[0041] Incidentally, if the locking device 3 is, for example, an electric lock, a cam member or gear member is driven in the unlocking direction by the power of the driving means, and as a result, the deadbolt is pulled back to the lock case side by the bolt. The locking device 3 is not particularly limited, but for example, in the case of an electric lock, it can be locked and unlocked mechanically and electrically. <Configuration of the server> Figure 4 is a schematic diagram showing the configuration of Server 7. Server 7 is preferably a cloud with a large storage capacity and includes a communication unit 31, a control unit 32, a storage unit 33, an operation unit 34, a display unit 35, etc. Here, we will explain the management method of the communication unit 31, the control unit 32, the storage unit 33 and the authentication key ID, the deletion method of the authentication key ID, the destination of the authentication key ID, the distribution of the authentication key distribution application, etc. The specific configuration of Server 7 is not a specific requirement of the present invention, so it will be briefly explained below.
[0042] First, the communication unit 31 is a communication interface that communicates with the communication terminal 4 and the authentication system 5. Next, the control unit 32 processes various types of information as is well known. The control unit 32 is a functional module implemented by a computer program and includes, at the very least, an address information issuing means 36 that issues address information to the communication terminal 4; an authentication key ID issuing means 37 that links the address information and other identification information (gate identification information, lock ID, identification information of the communication terminal, identification information of the control unit, etc.) to an authentication key ID and issues it to the communication terminal 4; an unavailable information registration means 38 that registers information indicating that communication with the communication terminal 4 is impossible to communicate with via the communication unit 31, for example, triggered by the authentication system 5, in the second data list 33b of the storage unit 33, which will be described later; and an authentication application distribution means (application distribution means) 39.
[0043] Next, the storage unit 33 stores the code and various data of computer programs executed on the server 7, and has arbitrary semiconductor memory such as RAM and ROM. However, the storage unit 33 stores and manages authentication applications, and as shown in Figure 1, for example, authentication application B (app B) can be distributed from the server 7 to the communication terminal 4 as a user via the network 6. The storage unit 33 also has a first data list 33a that stores and manages authentication key IDs for distribution to the communication terminal 4, and a second data list (list of prohibited use) 33b that stores and manages records of authentication key IDs that have been distributed to the communication terminal 4 and for which the authentication system 5 has notified that they are unresponsive, and which have been deactivated or deleted. The second data list 33b is a measure to prohibit the reuse of distributed authentication key IDs. Although not specifically shown in the figures, the storage unit 33 also records the incoming history of authentication key IDs received by the communication unit 31 from the communication terminal 4 via the network 6.
[0044] Next, we will describe how the communication terminal 4 accesses the server 7. A preferred embodiment is a method in which the camera of the communication terminal 4 captures a two-dimensional code. For example, a two-dimensional code can be printed on the flat surface of a building wall (gate wall, wall near the gate, etc.) as real estate, or on various items (packaging boxes, postcards, cards, posters, calendars, stands, etc.) as movable property. When the two-dimensional code is read using the camera of the communication terminal 4, a website display screen immediately appears, and touching that display screen allows for easy and rapid connection to the server. Of course, the URL (information ready for transmission) can also be obtained by reading a two-dimensional code that temporarily appears on a television screen using the camera of the communication terminal 4. There are various methods for obtaining it.
[0045] Therefore, if the building gate management system X of the present invention uses "authentication application B", it can download an authentication key distribution application linked to a URL from the server 7 to the communication terminal 4 held by the user, install the authentication key distribution application so that it can be used, and then send the necessary information about the user to the server 7 based on the format of the application.
[0046] However, in the first embodiment, if authentication is not performed at all between the authentication system 5 and the communication terminal 4 within a certain period of time (for example, if there is no response), the registered key information is deemed to be in an unusable state (for example, deleted, deactivated, etc.), and the server 7 stores the authentication key ID of the communication terminal 4 in the second data list (list of prohibited items) 33b of the storage unit 33, and transmits a control signal (preferably a deletion signal) to the communication terminal 4 via the network (local or wide-area communication network) one or more times, rendering the authentication key ID unusable.
[0047] Furthermore, it is preferable that the control signal be transmitted at least twice in total at different times (for example, immediately after a resident can no longer use the security zone due to moving out, immediately before a new resident moves in to use the security zone, and in between the two such instances).
[0048] Furthermore, when security zone 1 comprises at least a first security zone (e.g., common areas of a building) and a second security zone (e.g., private areas of a building), and either server 7 or authentication system 5 outputs a control signal that prevents the use of an authentication key ID, the control signal includes a first control signal for common areas that prevents the use of the gate of the first security zone, and a second control signal for private areas that prevents the use of the gate of the second security zone, which is separate from the first control signal.
[0049] The following is a claim regarding the "program" for communication terminal 4: "A program that causes a computer to run the computer of a communication terminal used in a building gate management method, which consists of a communication terminal 4 that records an authentication key ID for at least unlocking the locking device 3 of the gate 2 of the building's security zone 1, an authentication system 5 that compares the authentication key ID with registered key information and activates the gate locking device 3 if the result of the comparison is valid, a network 6 to which the communication terminal 4 and the authentication system 5 are respectively connected, and a server 7 that connects to the authentication system via the network and manages the authentication key ID, wherein the program causes the computer to determine that the authentication application B has not been started within a certain period of time, or that a certain period of time including several days has elapsed from the time the authentication application was used or the time the authentication key ID was used in the timekeeping unit, based on the last authentication key ID response when the authentication application B has been used multiple times, and to record the unavailable information in the storage unit's list of prohibited use." [Examples]
[0050] Here, we will first explain an example of usage history information registered in the time storage area 12b of the storage unit 12 by the execution of the authentication application B (also simply called "App B") of the communication terminal 4, with reference to Figure 5.
[0051] In the time storage area 12b of the memory unit 12 in Figure 5, the app startup start time and the app usage stop time are recorded. Regarding the app startup start time on the left side of the drawing, for example, on June 1, 2022, if a person returns home from work in the afternoon and uses their smartphone 4 to unlock the gate 2 lock device 3 in security zone 1, the first app startup start time 1 of that day is recorded. Then, if they go out again and, for example, in the evening, use the smartphone 4 to unlock the gate 2 lock device 3 again, the second app startup start time 1-2 of that day is recorded. If this is repeated, app startup start times 1-3, 1-4, 1-n are recorded sequentially. The same applies to June 2, 3, and 4, 2022. The same applies to the app usage stop time on the right side of the drawing.
[0052] However, if the person who was using the aforementioned smartphone 4 were to move out and become a former resident, they would ordinarily not use app B within a certain period of time in security zone 1. This is because, unless there is a special reason, a former resident would not be entitled to use app B. Therefore, if app B is not used for a certain period, for example, two weeks, from June 5th to June 19th, 2022, there will be no usage history information for that period.
[0053] By the way, in Figure 5, the time storage area 12b of the memory unit 12 records the start time of application startup and the stop time of application use. However, it is also possible to replace the information regarding the use of application B with information regarding the use of the authentication key ID. In addition, in Figure 5, the time storage area 12b may also be provided with an area to store, for example, the number of times the application was started or the number of times the authentication key ID was used in a day.
[0054] Therefore, the time storage area 12b of the storage unit 12 records either information regarding the use of application B or information regarding the use of the authentication key ID (operation time and response time) as usage history information. Note that the period is not limited to two weeks, but can be set as appropriate, for example, 20 days, 30 days, 40 days, 50 days, etc. Next, Figure 6 is a flowchart (first embodiment) showing the case when the authentication application for the communication terminal is not launched within a certain period of time, referring to the current time indicated by the timekeeping unit. Furthermore, Figure 7 is identical to the flowchart in Figure 6, and is a flowchart (second embodiment) showing the case when the authentication key ID is not used within a certain period of time, referring to the current time indicated by the timekeeping unit. Note that although it should be written as, for example, step 601, it is abbreviated as "S601, S602, etc."
[0055] First, in Figure 6, S601 is the launch of the authentication application. As mentioned above, "Application B" is already installed on smartphone 4 and is recorded in its memory unit 12. S602 is when Application B acquires the current date and time information, that is, the current time (year, month, day, hour, minute). The current time can be acquired by the timekeeping unit 17 of smartphone 4, a time correction server, a dedicated time server, etc. S603 is when the usage history information recorded in the time storage area in Figure 5 is acquired. The discrimination means 18 refers to the current time indicated by the timekeeping unit 17 and determines whether or not Application B has been launched within a certain period (S604). S605 is the "Yes" case where Application B has been launched within a certain period, in which case the current state is maintained as is. Therefore, Application B can continue to be used as is. On the other hand, S606 is the "No" case where Application B has not been launched within a certain period, in which case, for example, the use of Application B is stopped, or the use of the authentication key ID is stopped, or the authentication key ID is deleted.
[0056] Next, since the flowchart in Figure 7 is essentially the same as the flowchart in Figure 6, the explanations of the overlapping steps S701, S702, S703, S705, and S706 will be omitted (referencing the steps in Figure 6). In the flowchart of Figure 7, the main difference from that of Figure 6 is step S704. In S704, the discrimination means 18 determines whether or not the authentication key ID has been used within a certain period of time based on the current time. Even with this configuration, the same problems and effects as the embodiment in Figure 6 can be achieved.
[0057] Furthermore, Figure 8 is shown to clarify that the timing of the determination by the determination means 18 does not necessarily have to start from the activation of the authentication application (S601 or S701), as the embodiments in Figures 6 and 7 may be interpreted restrictively as always presupposing the activation of the authentication application (S601 or S701) with respect to the timing of the determination by the determination means 18. In explaining the embodiment in Figure 8, the same reference numerals are used for steps that are the same as in Figure 7, and redundant explanations are omitted.
[0058] The main difference between the embodiment in Figure 8 and the embodiment in Figure 7 is that the launch of the authentication application (S701) is a prerequisite. Also, as in Figure 7, the usage information of the authentication key ID is not necessarily obtained from the usage history information (S703 is unnecessary). Therefore, the determination means 18 determines whether or not the authentication key ID has been used within a certain period of time based on the current time (S704). If the authentication key ID has been used within a certain period of time (S704: Yes), the current state is maintained (S705), and it returns to the original state in which the acquisition of the current time can be referenced. In other words, if the authentication state is enabled, it becomes possible to acquire the current time again (S702). Then, it is determined whether or not the authentication key ID has been used within a certain period of time since the previous confirmation of the use of the authentication key ID (S704). If the authentication key ID has not been used within a certain period of time (S704: No), for example, the use of application B is stopped, or the use of the authentication key ID is stopped, or the authentication key ID is deleted (S706).
[0059] Herein, I will add a note about the embodiment shown in Figure 8. This embodiment means that, regarding the timing of the determination by the determination means 18, it is not necessary to determine when the authentication application is launched. Specifically, it is assumed that the authentication application is always running in the background of the smartphone, and that the determination of whether or not the authentication key ID has been used within a certain period (S704) is made at predetermined intervals. An embodiment based on this assumption is, for example, that instead of comparing the current time with the last operation history information, the timing unit 17 starts a timer from the last operation (time information of the last time: current time) and determines whether or not the authentication ID has been used within a certain period by referring to the elapsed time (S704). In such an embodiment, if the authentication ID has not been used within a certain period (for example, 20 days, 30 days, 40 days, etc.), the next authentication is not performed, and the authentication key ID is immediately made unavailable. On the other hand, if authentication using the authentication key ID is performed before the certain period has elapsed based on the last operation, the current status is maintained (S705). In this case, the issue is not the last operation history information, but rather the range of the count time including the current time.
[0060] <Note 1> In a building gate management system, if the security zone comprises at least a first security zone and a second security zone, and the authentication system of the first security zone becomes unavailable due to an external device or a command signal from a command operation unit, the communication terminal may, based on this unavailable state, send a control signal to the server indicating that the authentication key ID is unavailable, and after the server records the unavailable information in its storage unit, it may send the control signal to the authentication system of the second security zone indicating that the authentication key ID is unavailable. Conversely, if the authentication system of the second security zone becomes unavailable due to an external device or a command signal from a command operation unit, the communication terminal may, based on this unavailable state, send a control signal to the server indicating that the authentication key ID is unavailable, and after the server records the unavailable information in its storage unit, it may send the control signal to the authentication system of the first security zone indicating that the authentication key ID is unavailable.
[0061] Furthermore, even within the common areas of the same building, security zones may be divided at common entrances, elevator floors, parking lots, bicycle parking areas, etc., resulting in multiple security zones. Similarly, within the private areas of the same building, if a resident owns multiple rooms (private areas), multiple security zones may exist. In such cases where multiple security zones exist, if the authentication system of any one of the security zones becomes unusable due to a command signal from an external device or a command control unit, the communication terminal may send a control signal to the server indicating that the authentication key ID recorded is unusable, and after the server records the unusable information in its storage unit, it may send the control signal indicating that the authentication key ID is unusable to the authentication system of at least one of the other security zones.
[0062] <Note 2> As one embodiment of the present invention, for example, in the building gate management system of claim 1, if the communication terminal is owned by a former resident who has moved out of the building, and each communication terminal has a different authentication key ID corresponding to either the number of buildings or the number of gates, the terminal control unit 10 may obtain information on the last operation date when the transmission of each authentication key ID stopped in chronological order by detecting the operation of the operation unit 11 for each authentication key ID from the storage unit 12, and the determination means 18 may determine whether or not to continue using the authentication key ID.
[0063] <Note 3> The present invention is based on a building gate management system comprising a communication terminal that records an authentication key ID for at least unlocking the locking device of a security zone gate, and an authentication system that compares the authentication key ID with registered key information and activates the locking device for the gate if the result of the comparison is valid. The identification information that identifies the locking device of the gate is appropriately associated with an identification search key for records in the communication terminal, such as the user's name, date of birth, landline phone number, address, property name, and room number. In short, any information that allows passage through the gate (door) is acceptable, and it is not particularly limited to some of the user's information; it is sufficient if it is associated with all or part of the information about the user. [Industrial applicability]
[0064] This invention can be used in the field of building gate management systems. [Explanation of Symbols]
[0065] X... Building gate management system, 1…Security zone, 2…Gate, 3… Locking device, 4…Communication terminals, 5…Authentication system, 6…Network, 7... Server, 10…Terminal control unit, 12...Storage section, 12a...Registration Department, 12b...Time storage area (usage history information), 13... Communications Department, 16…Method for sending authentication key ID, 17...Timekeeping section, 18...discrimination means, 28...External equipment, 28A...Command operation section, A... Authentication key ID, B... Authentication application, R...Registered key information.
Claims
1. A building gate management system comprising: a communication terminal that records at least an authentication key ID for unlocking the locking devices of each gate in the security zone of the private and common areas of a residential building; and an authentication system that compares the authentication key ID with registered key information and activates the locking device for each gate if the result of the comparison is valid, The aforementioned communication terminal is a mobile device owned by a former resident who has moved out of the aforementioned apartment building, and the mobile device has an authentication application obtained from a server via the network stored in its storage unit. The system includes a determination means for determining whether the authentication application was launched within a certain period of time, or whether the authentication of the authentication key ID by the authentication application was performed within a certain period of time, and a terminal control unit for controlling the communication terminal. The determination means, by referring to the current time indicated by the timekeeping unit, determines that either the authentication application was not started at all within a certain period of time, or the authentication of the authentication key ID was not performed at all within a certain period of time, and the terminal control unit registers the information that the authentication key ID is unavailable in the storage unit, thereby preventing the communication terminal from transmitting the authentication key ID to the authentication system thereafter, in a building gate management system.
2. A building gate management system according to claim 1, characterized in that the security zone has multiple common areas.
3. A program that, when the computer in the building gate management system of Claim 1 determines, by referring to the current time indicated by the timekeeping unit, that the authentication application has not been started at all within a certain period of time, or by referring to the current time indicated by the timekeeping unit, that the authentication of the authentication key ID has not been performed at all within a certain period of time, determines that the signal is a control signal for information that the authentication key ID of the communication terminal owned by a former resident of the apartment building is unavailable, and causes the computer to execute a process to record the unavailable information in the storage unit.
Citation Information
Patent Citations
Personal authentication system and id administration method
JP2003193723A
Silent mode setting system and silent mode setting method
JP2006050293A
Electronic lock system and its program
JP2007077692A
Mobile terminal
JP2010109616A
Access control system, access control method, and access control program
JP2011168991A