Authentication system

The authentication system addresses issues of identifier spoofing and security vulnerabilities by integrating location information with identifiers, providing advanced authentication and improved security through spatial verification.

WO2025253512A1PCT designated stage Publication Date: 2025-12-11ZERO CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/020405
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-04
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Conventional authentication methods face issues such as unauthorized copying and spoofing of identifiers, and security vulnerabilities due to reliance on single-factor authentication.

Method used

An authentication system that combines an identifier with location information to authenticate objects or individuals, using a storage means to associate identifiers with installation location data, a receiving means to acquire and verify this information, and an output means to provide notifications based on predetermined conditions.

Benefits of technology

Enhances security by preventing unauthorized copying and spoofing, ensuring accurate authentication through the integration of spatial relationships and location verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024020405_11122025_PF_FP_ABST
    Figure JP2024020405_11122025_PF_FP_ABST
Patent Text Reader

Abstract

[Problem] To provide a technique that helps prevent blurring of determination from occurring in legal consultation cases such as in contract document examination and legal consultation businesses. [Solution] A legal consultation management system according to the present invention has a client terminal, a legal personnel terminal, and a legal consultation management server. The system comprises: a management unit for managing consultation related to law as a consultation case, separately for each case; a consultation reception unit for receiving a consultation case to be handled from the client terminal; a consultation case display unit for displaying the consultation case to be handled on the legal personnel terminal; a retrieval unit for retrieving a similar case similar to the consultation case to be handled by referencing the consultation cases managed; and a similar case display unit for displaying information on the retrieved similar case on the legal personnel terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication System

[0001] The present invention particularly relates to an authentication system that utilizes position information of an object or a person.

[0002] Patent Document 1 provides a technology that reduces the burden of inputting personal information when applying for a credit card and enables reliable identity verification to be performed when applying. That is, when a credit card application processing system according to the present invention receives a credit card application request via a web browser, it receives both the applicant's personal information described in a QR code (registered trademark) and the applicant's location information acquired by the web browser, and rejects the request if the location information does not match the applicant's address.

[0003] Patent Document 2 provides a payment claim administration agency system that can reliably prevent intentional fraudulent claims from osteopathic clinics and massage parlors. Specifically, the system is interposed between the medical institution system managed by the medical institution and the review system managed by the receipt review and payment agency, and includes a center system managed by the billing agency and a therapist mobile terminal 20 carried by the therapist. A fixture 50 with a special code readable by the therapist mobile terminal 20 is installed in the user's home in advance. During a home care visit, the special code of the fixture 50 read using a reader unit 21 and the latitude and longitude information of the current location acquired by a GPS unit 22 are transmitted. The center system analyzes the special code information of the fixture 50 and the latitude and longitude information acquired by the GPS, confirms the visit to the user's home and the performance of the massage treatment, confirms that no fraudulent claims have been made, and automatically creates a receipt.

[0004] Patent Document 3 provides an identification system that is easy to introduce and allows for more accurate identification. solution

[0005] The system comprises a mobile terminal 2 capable of acquiring identification information of a visitor V, an identification server 3 that determines whether or not a visit by the visitor V is appropriate based on the identification information received from the mobile terminal 2 and pre-stored identification information, and television broadcasting equipment 4 that performs two-way television broadcasting to a television set 5 in the home H to be visited. If the identification server 3 determines that the visit is appropriate, it transmits an authentication code to the mobile terminal 2, and the television broadcasting equipment 4 transmits an authentication result to the television set 5 based on the authentication code received from the television set 5 and the authentication code of the identification server 3.

[0006] JP 2022-116848 A JP 2009-032129 A JP 2014-191740 A

[0007] None of the above techniques are sufficient to prevent fraud.

[0008] Therefore, the present invention provides a new authentication system.

[0009] According to the present invention, an authentication server is provided which comprises: a storage means for storing an identifier associated with an object and installation location information of the object in association with each other; a receiving means for receiving the identifier acquired by a terminal and the terminal location information of the terminal; and an output means for outputting a predetermined notification when the installation location information corresponding to the identifier and the terminal location information satisfy a predetermined condition.

[0010] According to the present invention, when legal personnel or the like are performing contract review work or legal consultation work, they can easily refer to information on similar cases in which decisions have been made in the past, thereby making it possible to support them in preventing inconsistencies in their decisions regarding legal consultation cases.

[0011] In particular, details of similar cases can be displayed in a list using thumbnails, etc., and by selecting a thumbnail, the contents of the similar case can be confirmed in the same window, allowing for quick work.

[0012] It is an authentication system according to a first embodiment of the present invention, It is a sequence diagram of the system of Figure 1. It is an authentication system according to a second embodiment of the present invention, It is a sequence diagram of the system of Figure 3.

[0013] The details of the embodiments of the present invention will be listed and described below. The present invention has the following configuration. [Item 1] An authentication server comprising: a storage means for storing an identifier associated with an object and installation location information of the object in association with each other; a receiving means for receiving the identifier acquired by a terminal and terminal location information of the terminal; and an output means for outputting a predetermined notification when the installation location information corresponding to the identifier and the terminal location information satisfy a predetermined condition. [Item 2] The authentication server according to item 1, wherein the object is fixed to a house, and the identifier is affixed to the object. [Item 3] The authentication server according to item 1, wherein the object is fixed to a house, and the identifier is affixed to a member different from the object. [Item 4] The authentication server according to item 1, wherein the object is fixed to a house, and the identifier is affixed to a power distribution facility for the object. [Item 5] The authentication server according to item 1, wherein the identifier is affixed to a position that is easily visible from outside the premises where the object is installed. [Item 6] The authentication server according to item 1, wherein the terminal is equipped with a camera unit, and the receiving means is receiving means that receives the identifier acquired by the camera unit of the terminal. [Item 7] The authentication server according to item 1, wherein the object has a function of transmitting the identifier using wireless communication technology, the terminal acquires the identifier using the wireless communication technology, and the receiving means is receiving means that receives the identifier acquired by the terminal. [Item 8] The authentication server according to item 1, wherein the output means is output means that outputs a notification including authentication permission when the installation location information corresponding to the identifier and the terminal location information are within a predetermined range.[Item 9] The authentication server according to item 1, wherein the output means outputs a notification including authentication denial when the installation location information corresponding to the identifier and the terminal location information are outside a predetermined range. [Item 10] The authentication server according to item 1, wherein the installation location information corresponding to the identifier and the terminal location information are compared consecutively two or more times within a predetermined time to determine whether the installation location information corresponding to the identifier and the terminal location information satisfy a predetermined condition, and the output means outputs a notification including authentication approval when the installation location information corresponding to the identifier and the terminal location information are within a predetermined range at least a predetermined number of times. [Item 11] The authentication server, comprising: a storage means for storing an identifier associated with a drone port and the installation location information of the drone port in association with each other; a receiving means for receiving the identifier acquired by a terminal and the terminal location information of the terminal; and an output means for outputting an authentication notification when the installation location information corresponding to the identifier and the terminal location information are within a certain range. [Item 12] The authentication server according to Item 2, wherein the identifier is attached to the power distribution equipment of the drone port. [Item 13] An authentication server comprising: a storage means for storing an identifier associated with a target person and a target terminal of the target person in association with each other; a receiving means for receiving the identifier acquired by a terminal, terminal location information of the terminal, and target terminal location information of the target terminal; and an output means for outputting a predetermined notification when the installation location information corresponding to the identifier and the terminal location information satisfy a predetermined condition. [Item 14] The authentication server according to Item 1, wherein the identifier is attached to a certificate of the target person. [Item 15] The authentication server according to Item 1, wherein the identifier is displayed on a screen of the target terminal. [Item 16] The authentication server according to Item 1, wherein the identifier is attached to the device of the target terminal.[Item 17] The authentication server according to Item 1, wherein the identifier is affixed to a position that is easily visible when coming into contact with the target person. [Item 18] The authentication server according to Item 1, wherein the terminal is equipped with a camera unit, and the receiving means is receiving means that receives the identifier acquired by the camera unit of the terminal. [Item 19] The authentication server according to Item 1, wherein the target terminal is equipped with a function for transmitting the identifier using wireless communication technology, the terminal acquires the identifier using the wireless communication technology, and the receiving means is receiving means that receives the identifier acquired by the terminal. [Item 20] The authentication server according to Item 1, wherein the output means is output means that outputs a notification including authentication permission when the installation location information corresponding to the identifier and the target terminal location information are within a predetermined range. [Item 21] The authentication server according to item 1, wherein the output means outputs a notification including authentication denial when the installation location information corresponding to the identifier and the target terminal location information are outside a predetermined range. [Item 22] The authentication server according to item 1, wherein the output means compares the target terminal location information corresponding to the identifier with the terminal location information two or more times in succession within a predetermined time to determine whether the target terminal location information corresponding to the identifier and the terminal location information satisfy a predetermined condition, and the output means outputs a notification including authentication permission when the target terminal location information corresponding to the identifier and the terminal location information are within a predetermined range a predetermined number of times or more.

[0014] <First embodiment> A first embodiment of the present invention will be described below with reference to the drawings. The present invention relates to an authentication technology based on identification of an object and location information. In particular, the present invention relates to an authentication server that determines the positional relationship between an object and a terminal using an identifier assigned to the object and location information of the terminal, and outputs a notification when a predetermined condition is met.

[0015] Conventionally, authentication using only an identifier has been the mainstream method for authenticating an object. However, this method has had problems such as unauthorized copying of identifiers and spoofing. The present invention aims to achieve more advanced authentication and improve security by combining the identifier of the object with the location information of the terminal.

[0016] The authentication server of the present invention includes a storage unit that stores an identifier assigned to an object and installation location information of the object in association with each other, a receiving unit that receives the identifier acquired from a terminal and the location information of the terminal, and an output unit that outputs a predetermined notification when the installation location information corresponding to the received identifier and the location information of the terminal satisfy a predetermined condition.

[0017] According to the present invention, by performing authentication by combining the identifier of an object with the location information of a terminal, advanced authentication that takes into account the relative positions of the object and the terminal is possible. This prevents unauthorized copying and spoofing of identifiers and improves security. Furthermore, by outputting a notification when a predetermined condition is met, the authentication result can be properly communicated to the user.

[0018] <Network Configuration> A network configuration using the authentication server of the present invention will be described below, as shown in Fig. 1. The authentication server of the present invention is communicably connected to a terminal via a network. The authentication server has a database that stores identifiers and installation location information of objects.

[0019] The terminal has a means for reading an identifier assigned to an object. For example, a barcode reader, a QR Code (registered trademark) reader, an RFID reader, an NFC reader, etc. is used. The terminal also has a means for acquiring its own location information using GPS, Wi-Fi, base station information, etc. The terminal transmits the read identifier and its acquired location information to an authentication server via a network.

[0020] The authentication server retrieves the installation location information of the object corresponding to the received identifier from the database and compares it with the location information received from the terminal. If the installation location information and the terminal location information satisfy a predetermined condition, the authentication server outputs a predetermined notification to the terminal.

[0021] The predetermined notification may take various forms, such as a message displayed on the device screen, sound, vibration, light, etc. The content of the notification may vary depending on the purpose, such as notification of authentication results, provision of information about the target object, or granting of access rights.

[0022] Such a network configuration enables advanced authentication that takes into account the positional relationship between the object and the terminal.

[0023] <Hardware Configuration: Target (Drone Port)> The target in this embodiment is a drone port. A drone port is a facility for drone takeoff, landing, charging, and maintenance. An identifier (e.g., a QR code (registered trademark), RFID tag, etc.) is assigned to the drone port (described later). The identifier includes information unique to the drone port (ID). In addition, a location information acquisition means such as a GPS receiver or a beacon transmitter is installed in the drone port. This makes it possible to acquire accurate location information for the drone port.

[0024] <Hardware Configuration: Authentication Server> The authentication server is composed of a high-performance computer system. The main hardware components are as follows: 1. CPU (Central Processing Unit): Equipped with a CPU with high-speed processing capabilities, it can process multiple requests in parallel. 2. Memory (RAM): Equipped with large-capacity memory, it can process requests from multiple terminals at high speed. 3. Storage (HDD / SSD): Equipped with large-capacity storage, it stores a database that associates and stores identifiers of objects (drone ports) with installation location information. 4. Network Interface: Equipped with multiple high-speed network interfaces, it can handle simultaneous access from multiple terminals. In addition, to ensure security, the authentication server also incorporates a firewall and access control system.

[0025] <Hardware Configuration: Terminal> Terminals can take various forms, including smartphones, tablets, and dedicated terminals. The main hardware components are as follows: 1. CPU: Has the processing power to run applications and perform communication processing. 2. Memory (RAM): Used to run applications and temporarily store data. 3. Storage (Flash Memory): Used to permanently store applications and data. 4. Communication Interface: Equipped with a wireless communication interface such as Wi-Fi or mobile network, this communicates with the authentication server. 5. Identifier Reader: A part used to read the identifier of the target object (drone port). Barcode readers, QR Code (registered trademark) readers, RFID readers, NFC readers, etc. are used. 6. Location Information Acquisition Unit: Acquires the location information of the terminal itself using means such as a GPS receiver, Wi-Fi positioning, or base station positioning.

[0026] <Drone and Hardware Registration> 1. Drone Port Registration: The drone port administrator registers the identifier and installation location information of each drone port with the authentication server. The registered information is stored in the authentication server's database. 2. User (drone pilot) Registration: Users who will use drones register with the authentication server in advance. When registering, they register their personal information and information about the drone they will be using. 3. Using a Drone Port: When a user uses a drone, they first read the drone port's identifier using their device. The device then sends the read identifier and their own location information to the authentication server. 4. Authentication Processing: The authentication server retrieves the installation location information of the drone port corresponding to the received identifier from its database and compares it with the location information received from the device. If the installation location information and the device's location information meet specified conditions (e.g., within a certain distance), the authentication server allows the user to use the drone port. 5. Notification of Authentication Result: The authentication server notifies the user's device of the authentication result. If permitted, the user can take off and land their drone using the drone port. If denied, the user cannot use the drone port. 6. Flying the drone: After authentication, the user controls the drone and flies it to the destination. During flight, the drone periodically sends its location information to the authentication server, allowing the flight status to be monitored. 7. Returning the drone: After the user has finished using the drone, they land it back at the drone port. Upon landing, the authentication process is carried out again, and the drone's return is recorded. This method of use allows for safe and efficient management of drone port authentication and drone usage.

[0027] <Storage Means> The storage means in the authentication server of the present invention stores the identifier of the target object (drone port) and its installation location information in association with each other. Details of the storage means are described below. 1. Database System: The storage means is generally implemented by a database system. A database system is a software system for efficiently storing, managing, and searching large amounts of data. Typical database systems include relational databases (RDBs) and NoSQL databases. 2. Data Structure: To store and associate drone port identifiers and installation location information, an appropriate data structure must be designed. An example table structure is shown below. Drone Port Table: | Drone Port ID (Primary Key) | Identifier | Latitude | Longitude | Altitude | Address | Registration Date and Time | In this table, a unique drone port ID is assigned to each drone port, and the identifier is stored in association with installation location information (latitude, longitude, altitude), address, and registration date and time. 3. Index: In database systems, indexes are commonly used to improve search performance. In this invention, since searches for identifiers are expected to be performed frequently, it is desirable to create an index on the identifier column. This improves the response speed of searches specifying identifiers. 4. Backup and Replication: To ensure data availability and fault tolerance, it is desirable to introduce a backup and replication mechanism into the storage means. Backup allows regular backups of the database to be taken, reducing the risk of data loss. Replication synchronizes data between multiple servers, allowing service to continue even if some servers are down. 5. Security Measures: Since the storage means stores important drone port information, appropriate security measures are required. Access control ensures that only authenticated users can access the data. Data encryption also reduces the risk of data leakage due to unauthorized access.By combining these mechanisms, the storage means in the authentication server of the present invention can safely and efficiently manage drone port identifiers and installation location information.

[0028] <Receiving Means> The receiving means in the authentication server of the present invention is for receiving the identifier and terminal location information sent from the terminal. Details of the receiving means are described below. 1. Communication Protocol: The receiving means uses an appropriate communication protocol to communicate with the terminal. Typically, HTTP (Hypertext Transfer Protocol) or HTTPS (HTTP over SSL / TLS) is used. These protocols are standard protocols for communication on the Internet and are available for many terminals and servers. 2. API Endpoint: The receiving means provides an API endpoint for accepting requests from the terminal. An API endpoint is defined as a combination of a specific URL and an HTTP method (GET, POST, PUT, DELETE, etc.). The terminal sends an identifier and terminal location information to the authentication server by sending a request to the appropriate URL. 3. Request Verification: The receiving means must verify the request received from the terminal. Request validation includes the following items: - Request format validation: Checking whether the request is sent in the appropriate format. - Authentication token validation: Validating the authentication token to ensure that the terminal has been authenticated. - Parameter validation: Checking whether the identifier and location information parameters are sent in the appropriate format. If the validation results in the request being invalid, an appropriate error response is returned. 4. Data analysis: After the received request passes validation, the receiving means extracts data from the request body and analyzes the identifier and terminal location information. The analyzed data is used in subsequent processing (such as comparing location information). 5. Returning a response: The receiving means returns the result of request processing to the terminal. The response includes the authentication result (success or failure) and, if necessary, additional information (such as the reason for authentication failure). The response is returned in a format such as JSON. By combining these mechanisms, the receiving means in the authentication server of the present invention can safely and efficiently receive the identifier and terminal location information sent from the terminal and pass them on to subsequent processing.

[0029] The output means in the authentication server of the present invention outputs a predetermined notification when the installation location information corresponding to the identifier and the terminal location information satisfy a predetermined condition. Details of the output means are described below. 1. Comparing Location Information: The output means first acquires, from the storage means, the installation location information corresponding to the identifier received from the receiving means. Next, it compares the acquired installation location information with the terminal location information received from the receiving means. During the comparison, it determines whether a predetermined condition is satisfied. Examples of the predetermined condition include: - The distance between the installation location information and the terminal location information is less than a certain value. - The latitude and longitude of the installation location information and the terminal location information are both within a certain range. - The altitude difference between the installation location information and the terminal location information is less than a certain value. 2. Generating a Notification: If the comparison of the location information satisfies a predetermined condition, the output means generates a predetermined notification. The content of the notification includes information such as the success or failure of authentication and the availability of the drone port. The notification can be generated in various formats, such as a text message, a voice message, or a push notification. Notification examples: - Authentication success: "Authentication completed. The drone port is now available for use." - Authentication failure (distance): "Authentication failed. You are too far from the drone port." - Authentication failure (altitude): "Authentication failed. The altitude is inappropriate." 3. Notification output: The generated notification is output using an appropriate means. The output destination is primarily the terminal, but output to other systems is also possible if necessary. - Output to terminal: The generated notification is sent to the terminal. For transmission, mechanisms such as API response and push notification are used. The terminal notifies the user by displaying the received notification on the screen. - Output to other systems: If the authentication result needs to be linked to another system (such as a drone management system or billing system), the output means sends a notification to the other system. For linkage, mechanisms such as web API, message queue, and file transfer are used. 4. Logging: The output means records the results of the authentication process as a log. The log includes the contents of the authentication request (identifier, terminal location information), the authentication results, and the notification content.The logs are used for system operation and monitoring, as well as for troubleshooting. By combining these mechanisms, the output means in the authentication server of the present invention can generate appropriate notifications based on the results of the location information comparison and output them to terminals or other systems.

[0030] In an embodiment of the present invention, the following variations are possible for the placement of the identifier on the drone port, which is the target object. 1. Direct attachment to the drone port: This method attaches the identifier directly to the drone port itself. With this method, the identifier and drone port are integrated, making it easy to identify the drone port by reading the identifier. Possible locations for attaching the identifier include the outer surface of the drone port or the drone landing surface. 2. Attachment to a component other than the drone port: This method attaches the identifier to a component other than the drone port. With this method, the identifier and drone port are physically separated, so reading the identifier and identifying the drone port must be performed separately. Possible locations for attaching the identifier include a wall near the drone port or a sign dedicated to the drone port. 3. Attachment to power distribution equipment at the drone port: This method attaches the identifier to power distribution equipment for the drone port. With this method, the identifier and drone port are electrically connected, making it possible to control the power supply to the drone port by reading the identifier. Possible locations for attaching the identifier include a distribution board or power cable. 4. Mounting in a location visible from outside the site: This method mounts the identifier in a location that is easily visible from outside the site where the drone port is installed. With this method, users who use the drone port can read the identifier without entering the site. Possible locations for mounting the identifier include the exterior wall of the site or a gatepost. These embodiments provide various options for the placement of the identifier. The placement of the identifier can be appropriately selected depending on the installation environment and usage of the drone port. For example, if the drone port is installed indoors, it is appropriate to mount the identifier on the drone port itself. On the other hand, if the drone port is installed outdoors, it is appropriate to mount the identifier in a location that is visible from outside the site.

[0031] Furthermore, in embodiments of the present invention, the following embodiments are possible for the method of acquiring an identifier, the conditions for authentication, and the prevention of fraudulent use of location information. 1. Identifier Acquisition Method: a. Photographing with a Camera Unit: If the terminal is equipped with a camera unit, the identifier is acquired by photographing it with the camera. The receiving means receives the identifier acquired by the camera unit of the terminal. With this method, the identifier can be represented by a visual pattern such as a barcode or QR Code (registered trademark). b. Acquisition with Wireless Communication Technology (Claim 7): If the object has the function of transmitting an identifier via wireless communication technology, the terminal acquires the identifier using wireless communication technology. The receiving means receives the identifier acquired by the terminal. With this method, the identifier can be transmitted via short-range wireless communication technology such as RFID or NFC. 2. Authentication Conditions: a. Authentication Permission Within a Predetermined Range: The output means outputs a notification including authentication permission if the installation location information corresponding to the identifier and the terminal location information are within a predetermined range. Under this condition, authentication is permitted if the terminal is located near the drone port. b. Authentication Not Allowed Outside Predetermined Range: The output means outputs a notification including authentication not allowed if the installation location information corresponding to the identifier and the terminal location information are outside a predetermined range. Under this condition, authentication is denied if the terminal is away from the drone port. 3. Preventing Fraudulent Location Information: Multiple Consecutive Authentication: The installation location information corresponding to the identifier and the terminal location information are compared two or more times consecutively within a predetermined time to determine whether they satisfy a predetermined condition. The output means outputs a notification including authentication allowed if the installation location information corresponding to the identifier and the terminal location information are within a predetermined range at least a predetermined number of times. This method can prevent temporary inaccuracies in location information and falsification of location information. Combining these embodiments can provide various options for acquiring identifiers, authentication conditions, and preventing fraudulent location information. For example, a method of expressing an identifier as a QR code (registered trademark) and acquiring it by photographing it with a camera unit can be combined with a condition that allows authentication within a predetermined range. It is also possible to combine a method of transmitting an identifier via NFC and acquiring it at the terminal with multiple consecutive authentications to prevent fraudulent location information.As described above, in the embodiment of the present invention, multiple options are provided for obtaining identifiers, authentication conditions, and preventing fraudulent use of location information, allowing the optimal combination to be selected depending on the installation environment and usage pattern of the drone port.

[0032] <Processing flow> As shown in Figure 2, first, the user registers with the authentication server. Next, the user starts using the drone port on the terminal, and the terminal reads the drone port's identifier. After that, the terminal obtains its own location information and sends the identifier and location information to the authentication server. Finally, the authentication server performs the authentication process.

[0033] If authentication is successful, the following steps are executed: a. The authentication server sends an authentication permission notification to the terminal. b. The terminal displays the authentication result to the user. c. The user uses the drone port. d. The user flies the drone. e. The user returns the drone to the drone port. f. The drone port notifies the authentication server of the return process.

[0034] If the authentication fails, the following steps are executed: a) The authentication server sends an authentication rejection notice to the terminal b) The terminal displays the authentication result to the user

[0035] Second Embodiment The present invention relates to an authentication server that authenticates a target person using an identifier associated with the target person and location information of the target terminal. A storage unit associates and stores the identifier with the target terminal, and a receiving unit receives the identifier, terminal location information, and target terminal location information acquired from the terminal. An output unit outputs a predetermined notification when the installation location information and terminal location information corresponding to the identifier satisfy a predetermined condition.

[0036] The present invention relates to a system for authenticating a target person, and in particular to authentication technology that uses location information. Problems to be solved by the invention: Conventional authentication systems use authentication information such as passwords or ID cards, which poses security issues due to theft or loss of authentication information. Furthermore, managing and issuing authentication information requires time and effort and costs. The present invention aims to solve these problems and provide a safer and more efficient authentication system.

[0037] According to the present invention, authentication is performed using an identifier associated with a target person and location information of the target terminal, thereby eliminating security issues caused by theft or loss of authentication information. Furthermore, by using location information, authentication can be performed taking into account the target person's current location, ensuring higher security. Furthermore, there is an effect of reducing the effort and cost required for managing and issuing authentication information.

[0038] <Network Configuration> As shown in Figure 3, the authentication system of the present invention is a network system consisting of an authentication server, a target terminal, and a terminal that performs authentication. The authentication server has storage means, receiving means, and output means, and is communicably connected to the target terminal and the terminal that performs authentication via the network. The target terminal is a terminal carried by the target person and has a location information acquisition function such as GPS. The authentication terminal is a terminal installed at a location where authentication is required and has an identifier reading function and a location information acquisition function.

[0039] <Hardware configuration> The authentication server, target device, and authenticating device are each equipped with the necessary hardware and communicate with each other via a network. The authentication server functions as the core of the system, processing information sent from the target device and authenticating device and outputting the authentication results. The target device and authenticating device are responsible for acquiring location information and reading identifiers, and sending the necessary information to the authentication server.

[0040] <Storage Means> The storage means is provided in the authentication server, and serves to store an identifier associated with a target person and the target terminal of the target person in association with each other. Specifically, the following information is stored. 1. Target person information: - Target person ID - Target person name - Organization to which the person belongs - Position - Contact information (telephone number, email address, etc.) 2. Identifier information: - Identifier ID - Identifier type (RFID tag, barcode, NFC tag, etc.) - Identifier issue date and time - Identifier expiration date 3. Target terminal information: - Target terminal ID - Target terminal type (smartphone, tablet, wearable device, etc.) - OS information of the target terminal - Model information of the target terminal 4. Association information: - Association between the target person ID and identifier ID - Association between the target person ID and target terminal ID The storage means includes a database system for managing this information. The database system satisfies the following requirements: - Ensures data integrity and consistency - Enables efficient data search, addition, update, and deletion - Has data backup and recovery functions - Has access control functions to ensure data security The storage means is constructed in storage (HDD, SSD, etc.) within the authentication server and operates in conjunction with the CPU and memory. The storage means also has an interface for exchanging data with other systems via a network. The information stored in the storage means is used to compare the identifier received by the receiving means with the terminal location information and target terminal location information, and is used to output the authentication result by the output means.

[0041] <Receiving Means> The receiving means is provided in the authentication server, and is responsible for receiving the identifier acquired by the terminal, the terminal location information of the terminal, and the target terminal location information of the target terminal. The receiving means has the following functions. 1. Receiving information from the terminal: - Receiving identifier information sent from the terminal performing authentication - Receiving terminal location information sent from the terminal performing authentication - Receiving target terminal location information sent from the target terminal 2. Verifying received data: - Checking the integrity of the received data - Checking the format of the received data - Checking the validity of the received data 3. Analyzing received data: - Analyzing identifier information and extracting identifier ID - Analyzing terminal location information and extracting location coordinates - Analyzing target terminal location information and extracting location coordinates 4. Temporarily saving received data: - Temporarily saving received data in a buffer - Reading data from the buffer and handing it over to another functional module The receiving means receives information from the terminal via a network interface in the authentication server. The received data is passed to each functional module in the receiving means via a protocol stack. The functions of the receiving means are executed by the CPU in the authentication server, and memory is used for temporary data storage. The receiving means operates in conjunction with other functional modules (storage means, output means, etc.) to provide information necessary for the authentication process. The receiving means takes the following measures to ensure security: - Encryption of communications - Authentication and authorization of terminals - Detection and prevention of unauthorized access - Verification and filtering of received data These measures enable the receiving means to receive highly reliable information and provide it to the authentication process.

[0042] According to one embodiment of the present invention, the identifier is attached to the employee ID card of the target person. The employee ID card is an identification card issued by the organization to which the target person belongs, and contains information such as the target person's name, department, and employee number. The identifier is attached to the front or back of the employee ID card in the form of a barcode, QR code (registered trademark), RFID tag, or the like. This makes it possible for the identifier to be easily read when the target person presents the employee ID card.

[0043] According to one embodiment of the present invention, the identifier is displayed on the screen of the target terminal. The target terminal is a mobile terminal such as a smartphone or tablet terminal carried by the target person. The identifier is displayed on the screen of the target terminal in the form of a barcode, QR code (registered trademark), or the like. This allows the target person to easily read the identifier by presenting the screen of the target terminal.

[0044] According to one embodiment of the invention, an identifier is attached to a target terminal device. The target terminal is a mobile terminal such as a smartphone or tablet terminal carried by the target person. The identifier is attached to the surface of the target terminal's housing in the form of a sticker, engraving, RFID tag, or the like. This makes it possible for the target person to easily read the identifier when they present the target terminal.

[0045] According to one embodiment of the present invention, the identifier is attached to a position that is easily visible when coming into contact with the target person. The identifier is attached to the target person's clothing or belongings in the form of a badge, patch, sticker, or the like. The identifier is attached to a position that is easily visible from the outside, such as the target person's chest, back, or arm. This makes it possible to easily read the identifier when coming into contact with the target person.

[0046] According to one embodiment of the present invention, the terminal is equipped with a camera unit, and the receiving means receives the identifier acquired by the camera unit of the terminal. The camera unit of the terminal captures an image of the identifier assigned to the target person and acquires it as image data. The acquired image data of the identifier is transmitted from the terminal to the receiving means of the authentication server. The receiving means analyzes the received image data of the identifier and extracts the identifier. This makes it possible to acquire the identifier assigned to the target person in a contactless manner.

[0047] According to one embodiment of the present invention, the target terminal has a function of transmitting an identifier via wireless communication technology, the terminal acquires the identifier via the wireless communication technology, and the receiving means receives the identifier acquired by the terminal. The wireless communication technology is a short-range wireless communication technology such as NFC (Near Field Communication), Bluetooth, or Wi-Fi. The target terminal transmits the identifier using a built-in wireless communication module. The terminal receives the identifier transmitted from the target terminal via the wireless communication module and transmits it to the receiving means of the authentication server. This makes it possible to contactlessly acquire the identifier from the target terminal of the target person.

[0048] According to one embodiment of the present invention, the output means outputs a notification including authentication permission when the installation location information corresponding to the identifier and the target terminal location information are within a predetermined range. The installation location information is information indicating the location of the target person assigned the identifier and is registered in advance in the storage means of the authentication server. The target terminal location information is information indicating the current location of the target terminal and is acquired by a positioning function such as GPS of the target terminal. The output means calculates the distance between the installation location information and the target terminal location information and determines whether the distance is within a predetermined range. The predetermined range is a preset distance threshold. If the distance is within the threshold, the output means outputs a notification including authentication permission. This makes it possible to confirm that the target person is within the predetermined range and then permit authentication.

[0049] According to one embodiment of the present invention, the output means outputs a notification including a message that authentication is not permitted when the installation location information corresponding to the identifier and the target terminal location information are outside a predetermined range. The installation location information is information indicating the location of the target person assigned the identifier and is registered in advance in the storage means of the authentication server. The target terminal location information is information indicating the current location of the target terminal and is acquired by a positioning function such as a GPS of the target terminal. The output means calculates the distance between the installation location information and the target terminal location information and determines whether the distance is outside a predetermined range. The predetermined range is a preset distance threshold. If the distance exceeds the threshold, the output means outputs a notification including a message that authentication is not permitted. This makes it possible to not permit authentication when the target person is outside the predetermined range.

[0050] According to one embodiment of the present invention, target terminal location information corresponding to an identifier is compared with the terminal location information to determine whether the target terminal location information satisfies a predetermined condition at least twice consecutively within a predetermined time period, and the output means outputs a notification including authentication permission when the target terminal location information corresponding to the identifier and the terminal location information are within a predetermined range at least the predetermined number of times. By comparing the target terminal location information with the terminal location information consecutively multiple times within a predetermined time period, the effects of temporary instability of the location information and positioning errors can be reduced. The predetermined time period is a short period of time, for example, several seconds to several tens of seconds. The predetermined number of times is, for example, two or more times. The output means outputs a notification of authentication permission when, among the results of the multiple comparisons, the results of the predetermined number of comparisons are within a predetermined range. This makes it possible to prevent authentication errors caused by inaccurate location information.

[0051] <Processing Flow> As shown in FIG. 4, first, the target person presents an identifier to the terminal. Next, the terminal transmits the identifier to the authentication server. After that, the terminal transmits terminal location information to the authentication server. Next, the target terminal transmits the target terminal location information to the authentication server. The authentication server acquires installation location information corresponding to the identifier and compares the terminal location information with the target terminal location information. If the location information meets a predetermined condition, the authentication server transmits an authentication permission notification to the terminal, and the terminal transmits an authentication permission notification to the target person. On the other hand, if the location information does not meet the predetermined condition, the authentication server transmits an authentication denial notification to the terminal, and the terminal transmits an authentication denial notification to the target person. Finally, the authentication server records an authentication log.

[0052] This system is equipped with a server and terminals that are configured to be able to communicate with each other via the Internet. Note that this system may be configured as a cloud-based / network-based system provided by a designated business operator, or as an on-premise system that is operated independently within the company that adopts the system.

[0053] <Hardware Configuration Example> Each of the above-described functional blocks can be configured using, for example, hardware provided in a server device (terminal device), a DSP (Digital Signal Processor), or software. For example, when configured using software, each of the above-described functional blocks is actually configured with a CPU, RAM, ROM, etc. of a computer, and is realized by running a program stored in a recording medium such as the RAM, ROM, hard disk, or semiconductor memory.

[0054] The above-described embodiment is merely an example for facilitating understanding of the present invention, and is not intended to limit the present invention. The present invention can be modified and improved without departing from the spirit thereof, and it goes without saying that the present invention includes equivalents thereof.

Claims

1. An authentication server comprising: a storage means for storing an identifier associated with an object and installation location information of the object in association with each other; a receiving means for receiving the identifier acquired by a terminal and the terminal location information of the terminal; and an output means for outputting a predetermined notification when the installation location information corresponding to the identifier and the terminal location information satisfy a predetermined condition.

2. An authentication server according to claim 1, wherein the object is fixed to a house, and the identifier is attached to the object.

3. An authentication server according to claim 1, wherein the object is fixed to a house, and the identifier is attached to a member different from the object.

4. An authentication server according to claim 1, wherein the object is fixed to a house, and the identifier is attached to a power distribution facility for the object.

5. An authentication server according to claim 1, wherein the identifier is attached to a position that is easily visible from outside the site where the object is installed.

6. An authentication server according to claim 1, wherein the terminal is equipped with a camera unit, and the receiving means is a receiving means for receiving the identifier acquired by the camera unit of the terminal.

7. An authentication server according to claim 1, characterized in that the object has a function of transmitting the identifier by wireless communication technology, the terminal acquires the identifier by the wireless communication technology, and the receiving means receives the identifier acquired by the terminal.

8. An authentication server according to claim 1, wherein the output means outputs a notification including authentication permission when the installation location information corresponding to the identifier and the terminal location information are within a predetermined range.

9. An authentication server according to claim 1, wherein the output means outputs a notification including a denial of authentication when the installation location information corresponding to the identifier and the terminal location information are outside a predetermined range.

10. An authentication server as claimed in claim 1, characterized in that the installation location information corresponding to the identifier is compared with the terminal location information at least twice consecutively within a predetermined time to determine whether or not the installation location information corresponding to the identifier satisfies a predetermined condition, and the output means outputs a notification including authentication permission when the installation location information corresponding to the identifier and the terminal location information are within a predetermined range at least a predetermined number of times.

11. An authentication server comprising: a storage means for storing an identifier associated with a drone port in association with the installation location information of the drone port; a receiving means for receiving the identifier acquired by a terminal and the terminal location information of the terminal; and an output means for outputting an authentication notification when the installation location information corresponding to the identifier and the terminal location information are within a certain range.

12. An authentication server according to claim 2, wherein the identifier is attached to a power distribution facility of the drone port.

13. An authentication server comprising: a storage means for storing an identifier associated with a target person and a target terminal of the target person in association with each other; a receiving means for receiving the identifier acquired by a terminal, terminal location information of the terminal, and target terminal location information of the target terminal; and an output means for outputting a predetermined notification when the installation location information corresponding to the identifier and the terminal location information satisfy a predetermined condition.

14. An authentication server according to claim 1, characterized in that the identifier is attached to a certificate of the subject person.

15. An authentication server according to claim 1, wherein the identifier is displayed on the screen of the target terminal.

16. An authentication server according to claim 1, wherein the identifier is attached to the device of the target terminal.

17. An authentication server according to claim 1, wherein the identifier is attached in a position that is easily visible when coming into contact with the target person.

18. An authentication server according to claim 1, wherein the terminal is equipped with a camera unit, and the receiving means is a receiving means for receiving the identifier acquired by the camera unit of the terminal.

19. An authentication server as described in claim 1, characterized in that the target terminal has a function of transmitting the identifier using wireless communication technology, the terminal acquires the identifier using the wireless communication technology, and the receiving means receives the identifier acquired by the terminal.

20. An authentication server as described in claim 1, characterized in that the output means outputs a notification including authentication permission when the installation location information corresponding to the identifier and the target terminal location information are within a predetermined range.

21. An authentication server as described in claim 1, wherein the output means outputs a notification including a denial of authentication when the installation location information corresponding to the identifier and the target terminal location information are outside a predetermined range.

22. An authentication server as described in claim 1, characterized in that the target terminal location information corresponding to the identifier is compared with the terminal location information two or more times consecutively within a predetermined time to determine whether the target terminal location information corresponds to the identifier and the terminal location information satisfy a predetermined condition, and the output means outputs a notification including authentication permission when the target terminal location information corresponding to the identifier and the terminal location information are within a predetermined range for more than a predetermined number of times.

Citation Information

Patent Citations

  • Door unlocking system, terminal, equipment control system, and door unlocking method

    JP2023173267A

  • Program, method and information processing device

    JP7237397B1