Information processing device and information processing system

The integration of secure and non-secure positioning areas with mutual authentication and UWB secure positioning methods addresses reliability and security issues in UWB Downlink TDoA systems, ensuring accurate and tamper-proof positioning results.

WO2026018564A1PCT designated stage Publication Date: 2026-01-22SONY GROUP CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/018877
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-16
Filing Date
2025-05-26
Publication Date
2026-01-22

AI Technical Summary

Technical Problem

Existing information processing systems using UWB Downlink TDoA positioning methods face reliability and security concerns due to the potential for incorrect or tampered positioning results from terminal devices.

Method used

Implementing a secure positioning area with mutual authentication between the terminal device and server before entering the secure area, and using UWB secure positioning with FiRa specifications, along with a non-secure positioning area for initial device positioning, followed by verification of results to enhance reliability and security.

Benefits of technology

Enhances the reliability and security of positioning results by ensuring accurate and tamper-proof measurements through mutual authentication and secure positioning methods, reducing processing load and improving system availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025018877_22012026_PF_FP_ABST
    Figure JP2025018877_22012026_PF_FP_ABST
Patent Text Reader

Abstract

The purpose of the present technology is to provide an information processing device that makes it possible to enhance the security and reliability of positioning results. A first technology is an information processing device (server 20) comprising: a positioning processing unit that performs positioning of a terminal device (10) which has passed through a first region (non-secure positioning region) and then entered a second region (secure positioning region); and an authentication processing unit that, before the terminal device (10) enters the second region (secure positioning region), performs mutual authentication with the terminal device (10) which has reached a prescribed position (start position) away from the second region (secure positioning region).
Need to check novelty before this filing date? Find Prior Art

Description

Information processing device and information processing system

[0001] The present technology relates to an information processing device and an information processing system.

[0002] There is a technology for connecting multiple communication devices via wireless communication to perform payment processing, etc. An information processing system using UWB (Ultra Wide Band) as a wireless communication method has been proposed (Patent Document 1).

[0003] WO2022 / 264509 publication

[0004] In the information processing system of Patent Document 1, the positioning of a terminal device is performed using a Downlink TDoA (Time Difference Of Arrival) method. However, in Downlink TDoA positioning, the terminal device performs its own positioning using the distance measurement results from the anchor and transmits the positioning results to a system server, etc. Therefore, there is a possibility that the positioning results transmitted by the terminal device may be incorrect or may be tampered with, raising concerns about the reliability and security of the positioning results.

[0005] The present technology has been developed in consideration of these points, and aims to provide an information processing device and an information processing system that can improve the reliability and security of positioning results.

[0006] In order to solve the above-mentioned problems, the first technology is an information processing device that includes a positioning processing unit that performs positioning of a terminal device that has passed through a first area and then entered a second area, and an authentication processing unit that performs mutual authentication between the terminal device and a terminal device that has reached a predetermined position away from the second area before the terminal device enters the second area.

[0007] The second technology is an information processing system comprising a terminal device and an information processing device, the terminal device having a positioning processing unit that performs positioning of the terminal device and an authentication processing unit that performs mutual authentication with the information processing device, and the information processing device having a positioning processing unit that performs positioning of the terminal device 10 that has entered a second area after passing through a first area, and an authentication processing unit that performs mutual authentication with the terminal device that has reached a predetermined position away from the second area before the terminal device enters the second area.

[0008] 1 is an explanatory diagram of a secure positioning area and a non-secure positioning area in a first embodiment. FIG. 2 is a block diagram showing the configuration of an information processing system 100. FIG. 3 is a diagram showing movement of a terminal device 10 in a first embodiment. FIG. 4 is a flowchart showing processing of a terminal device 10 in a first embodiment. FIG. 5 is a flowchart showing processing of a server 20 in a first embodiment. FIG. 6 is an explanatory diagram of a secure positioning area and a non-secure positioning area in a second embodiment. FIG. 7 is a diagram showing movement of a terminal device 10 in a second embodiment. FIG. 8 is a flowchart showing processing of a terminal device 10 in a second embodiment. FIG. 9 is a flowchart showing processing of a server 20 in a second embodiment. FIG. 10 is a diagram showing modified examples of a secure positioning area and a non-secure positioning area. FIG. 11 is a diagram showing modified examples of a secure positioning area and a non-secure positioning area. FIG. 12 is a diagram showing modified examples of a secure positioning area and a non-secure positioning area. FIG. 13 is a diagram showing modified examples of a secure positioning area and a non-secure positioning area.

[0009] Hereinafter, embodiments of the present technology will be described with reference to the drawings. The description will be made in the following order: <First embodiment> [Configuration of positioning area] [Configuration of information processing system 100] [Processing in information processing system 100] <Second embodiment> [Configuration of positioning area] [Configuration of information processing system 100] [Processing in information processing system 100] <Modification>

[0010] First Embodiment [Configuration of Positioning Area] First, a positioning area in an information processing system 100 according to a first embodiment will be described with reference to Fig. 1. In the information processing system 100, a terminal device 10 and a server 20 perform positioning to measure the position of the terminal device 10.

[0011] In the first embodiment, a secure positioning area and a non-secure positioning area are set within the space of a facility such as a store or station to which the information processing system 100 is applied. The server 20 switches the positioning method depending on whether the terminal device 10 is located in the secure positioning area or the non-secure positioning area. The non-secure positioning area corresponds to the first area in the claims, and the secure positioning area corresponds to the second area.

[0012] The secure positioning region is a region in which the server 20 measures the position of the terminal device 10 using a UWB positioning function defined by the specifications of FiRa (registered trademark), an organization related to UWB. In this positioning method, mutual authentication is performed between the terminal device 10 and the server 20 before positioning is performed, thereby guaranteeing the reliability and security of the positioning results. Positioning in the secure positioning region is referred to as secure positioning. The server 20 measures the position of the terminal device 10 by secure positioning using distance measurement results between each anchor 30 and the terminal device 10 transmitted from multiple anchors 30 installed in space.

[0013] The secure positioning area is an area where data communication and various processes are carried out between the terminal device 10 and a processing terminal 50 that performs processes such as a payment service used by a user of the terminal device 10. Therefore, the secure positioning area is set as an area with a radius of several meters based on the position of the processing terminal 50, for example.

[0014] Although three secure positioning regions are set in FIG. 1, the number of secure positioning regions is not limited to three and may be more or less than three.

[0015] The non-secure positioning area is set adjacent to the secure positioning area and is an area in which the terminal device 10 measures its own position. The terminal device 10 measures its own position using the Downlink TDoA method, using the distance measurement results between each anchor 30 and the terminal device 10 transmitted from multiple anchors 30 installed in space. There are no particular restrictions on the size of the non-secure positioning area, and it can be any size as long as it can communicate with the anchor 30 via UWB and obtain distance measurement results. The secure positioning area and non-secure positioning area are set as areas in a local coordinate system based on, for example, the position of the processing terminal 50, the position of the anchor 30, other positions, etc.

[0016] In TDoA, the time difference between the arrival times of radio waves transmitted and received between multiple anchors 30 installed at different locations and the terminal device 10 is converted into distance using the speed of light, thereby obtaining a ranging result between the anchors 30 and the terminal device 10. In TDoA, it is necessary to synchronize the time between the terminal device 10 and all anchors 30. Note that in this embodiment, the anchors 30 transmit the ranging results to the terminal device 10, but the process of measuring the time difference, converting the time difference into distance, and obtaining the ranging result may be performed by either the terminal device 10 or the anchor 30.

[0017] A start position is set within the non-secure positioning area. The start position is the position where the terminal device 10 receives a trigger signal transmitted from the BLE beacon 40 and starts positioning using the Downlink TDoA method. The start position is set to be located at the edge of the non-secure positioning area. In the example of FIG. 1 , the start position is set at the edge of the non-secure positioning area on the opposite side to the side where the secure positioning area exists. The start position corresponds to a predetermined position in the claims.

[0018] The start position is also a position where mutual authentication is performed between the terminal device 10 and the server 20. The BLE beacon 40 is assumed to be installed in advance at an appropriate position with radio wave intensity and the like adjusted according to the characteristics of the BLE beacon 40 or the terminal device 10 so that the terminal device 10 can receive the trigger signal at the start position. The BLE beacon 40 is an example of a signal transmission terminal that transmits a trigger signal. One or more BLE beacons 40 may be installed.

[0019] A plurality of anchors 30 are installed in advance within a space in which a secure positioning area and a non-secure positioning area are set in order to obtain distance measurement results to be used for positioning. There is no particular limitation on the number of anchors 30. The anchors 30 continuously transmit distance measurement results between the anchors 30 and the terminal device 10 to the terminal device 10 and the server 20 at predetermined time intervals. Note that the installation positions of the anchors in FIG. 1 are merely an example, and the present technology is not limited to the positions of the anchors 30. The anchors 30 may be installed in any positions as long as they can perform UWB communication with the terminal device 10 and obtain distance measurement results.

[0020] The anchor 30 for transmitting the ranging results used for positioning in the secure positioning region to the server 20 is preferably installed near the processing terminal 50 or configured integrally with the processing terminal 50, for example, by being installed on a circuit board of the processing terminal 50. The other anchors 30 for positioning in the non-secure positioning region may be installed anywhere in space as long as they are capable of UWB communication with the terminal device 10. However, an anchor 30 for obtaining the ranging results used for positioning in the secure positioning region may also be installed at a position away from the processing terminal 50. Furthermore, it is not necessarily necessary to separate the anchors 30 for positioning in the non-secure positioning region from the anchors 30 for positioning in the secure positioning region; a common anchor 30 may transmit the ranging results for positioning in the non-secure positioning region and the secure positioning region to the terminal device 10 and the server 20.

[0021] In the first embodiment, the terminal device 10 must pass through the start position when entering the non-secure positioning area. Furthermore, the terminal device 10 must pass through the non-secure positioning area before entering the secure positioning area. Then, within the secure positioning area, a predetermined process such as payment is performed between the terminal device 10 and the processing terminal 50, etc. Therefore, within a space such as a facility in which the information processing system 100 of the first embodiment is used, the non-secure positioning area must be set so that a user having the terminal device 10 must pass through it before entering the secure positioning area. Furthermore, a flow line must be set so that a user having the terminal device 10, etc., moves from the start position to the non-secure positioning area and then to the secure positioning area. For example, the non-secure positioning area may be set on a route that the user must pass through to get to the processing terminal 50.

[0022] When the information processing system 100 of the present technology is used within a space of a facility such as a store, the start position is set to, for example, the entrance of the facility. Furthermore, the secure positioning area is set as an area surrounding the processing terminal 50 and including the processing terminal 50. The non-secure positioning area is set in an aisle or the like within the facility other than the area surrounding the processing terminal 50 so as to be interposed between the start position and the secure positioning area. However, this is merely an example, and the start position and non-secure positioning area may be set anywhere within the space.

[0023] If the server 20 performs secure positioning of an unspecified number of terminal devices 10 without knowing the number of terminal devices 10 near the processing terminal 50, the processing and communication load will increase, posing a problem in terms of the availability of the information processing system 100 and the server 20. Therefore, a secure positioning area around the processing terminal 50 and a non-secure positioning area through which the terminal devices 10 pass before entering the secure positioning area are set, and the positions of the terminal devices 10 are determined by positioning the terminal devices 10 in the non-secure positioning area, thereby identifying terminal devices 10 that will enter the secure positioning area, and only those terminal devices 10 are positioned in the secure positioning area. This limits the terminal devices 10 that are the targets of secure positioning in the secure positioning area, thereby improving the availability of the information processing system 100. Furthermore, the server 20 manages the positioning method by referring to the positioning results in the non-secure positioning area and switching depending on whether the terminal device 10 is in the non-secure positioning area or the secure positioning area.

[0024] However, in Downlink TDoA positioning performed by the terminal device 10 in a non-secure positioning area, the terminal device 10 uses the distance measurement results obtained from the anchors 30 installed in space to perform its own positioning and transmits the positioning results to the server 20. Therefore, there is a possibility that the positioning results by the terminal device 10 may be incorrect or may be tampered with, and there are concerns about the reliability and security of the positioning results.

[0025] Therefore, in the first embodiment, mutual authentication between the terminal device 10 and the server 20 is performed when the terminal device 10 enters the non-secure positioning area, thereby improving the reliability and security of the positioning results in the non-secure positioning area.

[0026] [Configuration of Information Processing System 100] Next, the configuration of the information processing system 100 will be described with reference to Fig. 2. The information processing system 100 includes a terminal device 10, a server 20, an anchor 30, and a BLE beacon 40.

[0027] The terminal device 10 and the server 20 are communicably connected via a network interface. The anchor 30 and the server 20 are also communicably connected via a network interface. Communication methods include cellular communication, 4G, 5G, Wi-Fi, etc., but any method that enables communication is acceptable.

[0028] The terminal device 10 and anchor 30 can communicate via UWB. UWB is a wireless communication technology that uses an ultra-wideband frequency bandwidth of 3.1 to 10.6 GHz, enabling highly accurate ranging and positioning with an error of approximately ±10 cm. While this differs by country, in Japan, the low band is 3.4 to 4.8 GHz, and the high band is 7.25 to 10.25 GHz. The communication range of UWB is approximately a 10-meter radius, enabling high-speed communication with low power consumption. Specifications and detailed communication procedures are defined in standards such as IEEE 802.15.4 and IEEE 802.15.4z.

[0029] First, the configuration of the terminal device 10 will be described.

[0030] The application processor 11 is composed of a CPU (Central Processing Unit), RAM (Random Access Memory), ROM (Read Only Memory), etc., and executes applications to perform various processes in the terminal device 10.

[0031] When the terminal device 10 receives a trigger signal from the BLE beacon 40, the application processor 11 starts a UWB positioning application, an authentication processing application, and the like.

[0032] The application processor 11 executes a UWB positioning application, sets the UWB communication unit 13 using UWB positioning setting values, notifies the secure element 12 of the start of positioning, notifies the server 20 of the start of positioning, and performs positioning processing using the Downlink TDoA method within the non-secure positioning area. The application processor 11 also executes an authentication processing application and performs mutual authentication with the server 20. The application processor 11 also performs processing to transmit the positioning results with a signature based on the mutual authentication. Furthermore, the application processor 11 executes a predetermined processing application such as a payment application, and performs predetermined processing with the processing terminal 50.

[0033] The secure element 12 holds positioning information such as a UWB session key and other setting values ​​required for UWB communication, and upon receiving a positioning start notification from the application processor 11 , supplies the positioning information to the UWB communication unit 13 .

[0034] The UWB communication unit 13 is configured with a UWB wireless communication module, and transmits and receives radio waves for distance measurement to and from the anchor 30 via UWB communication.

[0035] The BLE communication unit 14 is a BLE communication device that receives a trigger signal transmitted from a BLE beacon 40. Upon receiving the trigger signal, the BLE communication unit 14 notifies the application processor 11.

[0036] In addition, although not shown in the figure, the terminal device 10 may also be equipped with input units such as a mouse, keyboard, or touch panel that the user uses to input various instructions, and a display that displays a GUI (Graphical User Interface) and content, etc.

[0037] The terminal device 10 may be configured as an electronic device such as a smartphone, a smart watch, a tablet terminal, a wearable device, etc. The terminal device 10 may also be a dedicated terminal for various systems to which the present technology is applied, such as a dedicated touchless payment terminal, a touchless ticket gate terminal, an entrance / exit system terminal, or a smart key terminal.

[0038] Next, a description will be given of the configuration of the server 20. The server 20 is an example of an information processing device in the claims.

[0039] The application processor 21 is composed of a CPU, RAM, ROM, etc., and executes applications to perform various processes in the server 20.

[0040] Furthermore, the application processor 21 executes a UWB positioning application and performs secure positioning of the terminal device 10 in the secure positioning area using a UWB positioning function defined by the FiRa (registered trademark) specifications. The UWB positioning application performs secure positioning of the terminal device 10 in the secure positioning area based on distance measurement results transmitted from multiple anchors 30 and the terminal device 10. Note that mutual authentication between the terminal device 10 and the server 20 has already been performed at the start position, so mutual authentication between the terminal device 10 and the server 20 is not required in the secure positioning area.

[0041] The application processor 21 also executes an authentication application and performs mutual authentication processing with the terminal device 10. It also verifies the signature attached to the positioning result transmitted from the terminal device 10. It also performs processing to transmit a negotiation value for positioning to the terminal device 10. The application processor 21 is an example of a positioning processing unit and an authentication processing unit.

[0042] The secure element 22 holds a UWB session key for the anchor and other setting values, and supplies them to the application processor 21 .

[0043] Next, the configuration of the anchor 30 will be described.

[0044] The anchor 30 receives positioning information such as a UWB session key, UWB positioning setting values, and other setting values ​​transmitted from the server 20 .

[0045] The application processor 31 is composed of a CPU, RAM, ROM, etc., and executes applications to perform various processes in the anchor 30.

[0046] The application processor 31 executes a UWB positioning application, sets the UWB communication unit 33 according to the UWB positioning setting values, and transmits the distance measurement results used for Uplink TDoA by the server 20 to the server 20 via the network. The application processor 31 also notifies the encryption processing unit 32 of a decryption trigger.

[0047] The encryption processing unit 32 decrypts the positioning information, such as the UWB session key, UWB positioning setting values, and other setting values, transmitted in an encrypted state from the server 20 , and supplies the decrypted information to the UWB communication unit 33 .

[0048] The UWB communication unit 33 is configured with a UWB wireless communication module, and transmits and receives radio waves for distance measurement to and from the terminal device 10 via UWB communication.

[0049] In order for the terminal device 10 and the server 20 to perform positioning processing, they need distance measurement results transmitted from multiple anchors 30. The anchors 30 may be installed as common anchors for the non-secure positioning area and the secure positioning area, or may be installed separately as anchors for the non-secure positioning area and anchors for the secure positioning area.

[0050] The various applications that operate on the terminal device 10 may be pre-installed on the terminal device 10, or may be distributed by download or storage medium, etc., and installed by a user who owns the terminal device 10. The various applications that operate on the server 20 and the anchor 30 may be pre-installed thereon, or may be distributed by download or storage medium, etc., and installed by a user of the information processing system 100, etc.

[0051] [Processing in Information Processing System 100] Next, processing in the information processing system 100 will be described with reference to Fig. 3 to Fig. 5. For convenience of explanation, Fig. 3 illustrates only the non-secure positioning area, one secure positioning area, the terminal device 10 moving through these areas, the anchor 30 in the secure positioning area, and the processing terminal 50. First, processing in the terminal device 10 will be described with reference to Fig. 4.

[0052] In step S101, as shown in FIG. 3A, when the terminal device 10 reaches the start position and receives a trigger signal transmitted from the BLE beacon 40, the process proceeds to step S102 (Yes in step S101).

[0053] In step S102, the terminal device 10, which has received the trigger signal from the BLE beacon 40 at the start position, performs mutual authentication with the server 20 for UWB secure ranging. This mutual authentication is performed using an authentication method using a common key, an authentication method using an asymmetric key, or the like, according to a method defined in the specifications by FiRa (registered trademark). By notifying the server 20 that the trigger signal from the BLE beacon 40 has been received, the notification can be used as a trigger for mutual authentication between the terminal device 10 and the server 20.

[0054] Next, the terminal device 10 passes through the start position and enters the non-secure positioning area as shown in Fig. 3B, and in step S103 performs positioning of the terminal device 10 itself using the Downlink TDoA method. In Downlink TDoA, the terminal device 10 performs positioning by performing calculations using ranging results periodically transmitted from multiple anchors 30.

[0055] Next, in step S104, the terminal device 10 transmits the positioning result, together with a signature based on the result of the mutual authentication performed at the start position, to the server 20. The timing at which the terminal device 10 performs positioning and transmits the positioning result may be the timing at which the anchor 30 transmits the ranging result every several tens of milliseconds, or may be the timing preset in the UWB positioning application, or may be the timing dynamically specified by the server 20.

[0056] Then, the terminal device 10 passes through the boundary between the non-secure positioning area and the secure positioning area as shown in Figure 3C, and performs positioning in the non-secure positioning area and transmits the positioning results to the server 20 until the terminal device 10 moves to the secure positioning area as shown in Figure 3D and transitions to processing in the secure positioning area (No in step S105).

[0057] It should be noted that the terminal device 10 does not need to transmit the ranging results in the secure positioning region to the server 20. However, if a new secure ranging method is defined in the future in the FiRa (registered trademark) specifications, it may become necessary for the terminal device 10 to transmit the ranging results or the positioning results to the server 20.

[0058] Next, the processing in the server 20 will be described with reference to FIG.

[0059] In step S201, the server 20 performs mutual authentication with the terminal device 10 that has received the trigger signal transmitted from the BLE beacon 40 at the start position as shown in FIG. 3A.

[0060] Next, in step S202, the server 20 receives the positioning result transmitted from the terminal device 10. This positioning result is a positioning result obtained by the terminal device 10 using the Downlink TDoA method in the non-secure positioning area as shown in Fig. 3B. A signature is attached to this positioning result by the terminal device 10.

[0061] Next, in step S203, the server 20 verifies the signature attached to the positioning result transmitted from the terminal device 10 and refers to the positioning result.

[0062] Next, in step S204, when the server 20 detects that the terminal device 10 has entered the secure positioning area based on the positioning result transmitted from the terminal device 10, the process proceeds to step S205 (Yes in step S204).

[0063] When a non-secure positioning area and a secure positioning area are adjacent to each other, if the server 20 detects, based on the positioning results in the non-secure positioning area transmitted from the terminal device 10, that the terminal device 10 has reached the edge of the non-secure positioning area, i.e., the boundary between the non-secure positioning area and the secure positioning area, as shown in Figure 3C, the server 20 can determine that the terminal device 10 has entered the secure positioning area.

[0064] When the terminal device 10 enters the secure positioning area, the server 20 then transitions to processing in the secure positioning area in step S205. When transitioning to processing in the secure positioning area, the server 20 notifies the terminal device 10 to switch the positioning method (such as transmitting various data for switching the operation mode of the terminal device).

[0065] Then, in step S206, the server 20 performs positioning of the terminal device 10 in the secure positioning area, as shown in Fig. 3D, based on multiple ranging results obtained by secure ranging defined by the UWB specifications. Note that, since mutual authentication between the terminal device 10 and the server 20 has already been performed at the start position, mutual authentication between the terminal device 10 and the server 20 is not required in the secure positioning area.

[0066] In this manner, the processing in the first embodiment is performed. According to this embodiment, the server 20 performs positioning of the terminal device 10 in the non-secure positioning region before the secure positioning region in which the server 20 performs secure positioning, thereby making it possible to identify the terminal device 10 that will enter the secure positioning region.

[0067] Then, mutual authentication for secure ranging between the terminal device 10 and the server 20 is performed at the start position before the terminal device 10 enters the secure positioning area, and the terminal device 10 attaches a signature based on the mutual authentication to the positioning result of the Downlink TDoA method and transmits it to the server 20. This makes it possible to improve the reliability and security of the positioning result in positioning using UWB.

[0068] Furthermore, by performing mutual authentication in UWB before the terminal device 10 enters the secure positioning area, there is no need to perform mutual authentication in the secure area, which reduces the processing load in the secure area and shortens the time required for processing in the secure area.

[0069] If security is not a consideration in the information processing system 100, there is no need to attach a signature to the positioning result even if mutual authentication is performed at the start position.

[0070] Although it has been described that the secure positioning area is set as an area including the processing terminal 50 that performs processing such as payment, the processing terminal 50 is not essential. For example, in a system in which a user having a terminal device 10 can make a payment by simply passing through a predetermined position within a store, the secure positioning area is set to include that predetermined position.

[0071] This technology can be applied to systems in which a terminal device 10 communicates with a processing terminal 50 located within a secure positioning area to perform various processes, such as touchless payment systems, touchless ticket gate systems, entry / exit management systems, and smart key systems.

[0072] The non-secure positioning area and the secure positioning area are set as areas in a local coordinate system. However, for example, when the location of the terminal device 10 within a space such as a facility is displayed to the user on the terminal device 10's GUI or the like, the positioning results in local coordinates are converted into absolute coordinates based on map information just before the terminal device 10 and the server 20 complete the positioning process and display the positioning results on the GUI. Furthermore, when the positioning results are stored in a database or when the trajectory of the movement of the terminal device 10 that can be understood from multiple positioning results stored in the database is analyzed, information that can convert the non-secure positioning area and the secure positioning area in local coordinates into absolute coordinates is stored in the database. The map information includes information such as the absolute coordinates of the non-secure positioning area, the absolute coordinates of the secure positioning area, and the absolute coordinates of the anchor 30. In this case, the map information may be included in advance in an application running on the terminal device 10, or the server 20 may transmit the map information to the terminal device 10 upon receiving a notification that the terminal device 10 has received a trigger signal from a BLE beacon 40.

[0073] Second Embodiment [Configuration of Positioning Area] Next, a second embodiment will be described.

[0074] In the second embodiment, a plurality of non-secure positioning areas, namely, a first non-secure positioning area and a second non-secure positioning area, are set in space as shown in Fig. 6. In the second embodiment, the positioning method is switched depending on whether the terminal device 10 is located in the first non-secure positioning area, the second non-secure positioning area, or the secure positioning area.

[0075] The secure positioning area is the same as that in the first embodiment, and positioning in the secure positioning area is performed using the UWB secure positioning function defined by the FiRa (registered trademark) specifications. Although three secure positioning areas are set in Fig. 6, the number of secure positioning areas is not limited to three and may be more or less than three.

[0076] The first non-secure positioning area is set adjacent to the second non-secure positioning area and is an area in which the terminal device 10 performs positioning. The terminal device 10 performs positioning using the Downlink TDoA method using the distance measurement results between each anchor 30 and the terminal device 10 transmitted from multiple anchors 30 installed in space. The first non-secure positioning area is similar to the non-secure positioning area in the first embodiment.

[0077] A start position is set within the first non-secure positioning area. The start position is the same as that in the first embodiment, and is the position where the terminal device 10 receives a trigger signal transmitted from the BLE beacon 40 and starts positioning using the Downlink TDoA method. The start position is set so as to be located at the end of the first non-secure positioning area on the opposite side to the side where the secure positioning area exists. The start position is also the position where mutual authentication is performed between the terminal device 10 and the server 20.

[0078] The second non-secure positioning area is set between the first non-secure positioning area and the secure positioning area so as to be adjacent to the first non-secure positioning area and the secure positioning area, and is an area in which the server 20 performs positioning of the terminal device 10. The server 20 performs positioning using the Uplink TDoA method using distance measurement results between each anchor 30 and the terminal device 10 transmitted from multiple anchors 30 installed in space and the terminal device 10. There are no particular restrictions on the size of the second non-secure positioning area, and it may be any size as long as it is possible to communicate with the anchors 30 via UWB and receive distance measurement results. The second non-secure positioning area corresponds to the third area in the claims.

[0079] As in the first embodiment, a plurality of anchors 30 for positioning and ranging are installed in advance within a space in which the first non-secure positioning area, the second non-secure positioning area, and the secure positioning area are set. There is no particular limitation on the number of anchors 30. The first non-secure positioning area, the second non-secure positioning area, and the secure positioning area are set as areas in a local coordinate system based on the position of the processing terminal 50, the position of the anchors 30, other positions, etc.

[0080] In the second embodiment, the terminal device 10 must pass through the start position when entering the first non-secure positioning area. Furthermore, the terminal device 10 must pass through the first non-secure positioning area before entering the second secure positioning area. Furthermore, the terminal device 10 must pass through the second non-secure positioning area before entering the secure positioning area. Then, within the secure positioning area, a predetermined process such as payment is performed between the terminal device 10 and the processing terminal 50. Therefore, within a space such as a facility where the information processing system 100 of the second embodiment is used, a flow line must be set so that a user of the terminal device 10 moves through the start position, the first non-secure positioning area, the second non-secure positioning area, and the secure positioning area in this order.

[0081] Before the terminal device 10 enters the secure positioning area, the terminal device 10 can be identified by performing positioning in the first non-secure positioning area and the second non-secure positioning area. The server 20 refers to the positioning results in the first non-secure positioning area and the second non-secure positioning area, and manages to switch the positioning method depending on whether the terminal device 10 is located in the first non-secure positioning area, the second non-secure positioning area, or the secure positioning area.

[0082] However, in the Downlink TDoA positioning performed by the terminal device 10 in the first non-secure positioning region, the terminal device 10 performs its own positioning using the distance measurement result obtained by the anchor 30 and transmits the positioning result to the server 20. Therefore, there is a possibility that the positioning result may be incorrect or may be tampered with, and there are concerns about the reliability and security of the positioning result.

[0083] Therefore, in the second embodiment, a second non-secure positioning area is set, and the positioning results in the first non-secure positioning area performed by the terminal device 10 are confirmed with the positioning results in the second non-secure positioning area performed by the server 20, thereby improving the reliability and security of the positioning results.

[0084] [Configuration of Information Processing System 100] The configurations of the information processing system 100, the terminal device 10, the server 20, the anchor 30, and the BLE beacon 40 in the second embodiment are the same as those in the first embodiment.

[0085] The application processor 21 of the server 20 executes a UWB positioning application to perform Uplink TDoA positioning, which calculates the position of the terminal device 10 using the ranging results transmitted from the terminal device 10 and the anchor 30. The application processor 21 also executes a comparison processing application to compare the positioning result of the terminal device 10 using the Downlink TDoA method with the positioning result of the server 20 using the Uplink TDoA method. The application processor 21 is an example of a comparison processing unit.

[0086] [Processing in Information Processing System 100] Next, processing in the information processing system 100 will be described with reference to Fig. 7 to Fig. 9. For convenience of explanation, Fig. 7 illustrates only the first non-secure positioning area, the second non-secure positioning area, one secure positioning area, the terminal device 10 moving in these areas, and the anchor 30 and processing terminal 50 in the secure positioning area.

[0087] First, the processing in the terminal device 10 will be described with reference to Fig. 8. The same processing as in the first embodiment will be referred to with the same step numbers.

[0088] In step S101, as shown in FIG. 7A, when the terminal device 10 receives a trigger signal transmitted from the BLE beacon 40 at the start position, mutual authentication is performed with the server 20 in step S102.

[0089] Next, in step S121, as shown in FIG. 7B, the terminal device 10 that has entered the first non-secure positioning area performs positioning of itself in the first non-secure positioning area using the Downlink TDoA method using the ranging results transmitted from the anchor 30.

[0090] Next, in step S122, the terminal device 10 transmits to the server 20 the positioning result with a signature based on the result of the mutual authentication executed at the start position.

[0091] Then, the terminal device 10 moves to the second non-secure positioning area and performs positioning in the first non-secure positioning area and transmits the positioning results to the server 20 until the server 20 transfers the processing of the information processing system 100 to processing of the second non-secure positioning area (No in step S123).

[0092] On the other hand, when the terminal device 10 moves to the second non-secure positioning area and the server 20 shifts the processing of the information processing system 100 to processing of the second non-secure positioning area, the processing proceeds to step S124 (Yes in step S123).

[0093] Next, in step S124, the terminal device 10 transmits to the server 20 the distance measurement result in the second non-secure positioning region for positioning by the server 20. Since the server 20 performs positioning in the second non-secure positioning region using the Uplink TDoA method, the terminal device 10 transmits the distance measurement result, not the positioning result, to the server 20. At this time, the terminal device 10 attaches a signature based on the result of mutual authentication performed at the start position to the distance measurement result.

[0094] Then, the terminal device 10 moves to the secure positioning region and transmits the distance measurement results in the second non-secure positioning region to the server 20 until the server 20 transfers the processing of the information processing system 100 to processing in the secure positioning region (No in step S125).

[0095] When the terminal device 10 moves to the secure positioning area and the server 20 shifts the processing of the information processing system 100 to processing in the secure positioning area, the processing ends (Yes in step S125).

[0096] Next, the processing in the server 20 will be described with reference to Fig. 9. The same processing as in the first embodiment will be referred to by the same step numbers.

[0097] In step S201, the server 20 performs mutual authentication with the terminal device 10 that has received the trigger signal transmitted from the BLE beacon 40 at the start position as shown in FIG. 9A.

[0098] Next, in step S202, the server 20 receives the Downlink TDoA positioning result transmitted from the terminal device 10. The Downlink TDoA positioning result is signed by the terminal device 10.

[0099] Next, in step S203, the server 20 verifies the signature attached to the positioning result transmitted from the terminal device 10 and refers to the positioning result.

[0100] Then, the server 20 determines the location of the terminal device 10 based on the positioning results transmitted from the terminal device 10, and receives and refers to the positioning results transmitted from the terminal device 10 in steps S202 and S203 until the terminal device 10 reaches the edge of the first non-secure positioning area, i.e., the boundary between the first non-secure positioning area and the second non-secure positioning area (No in step S221).

[0101] As shown in FIG. 7C, when the terminal device 10 reaches the edge of the first non-secure positioning area (the boundary between the first non-secure positioning area and the second non-secure positioning area), the process proceeds to step S222 (Yes in step S221).

[0102] Next, in step S222, the server 20 performs positioning of the terminal device 10 at the edge of the first non-secure positioning area (the boundary between the first non-secure positioning area and the second non-secure positioning area) by the Uplink TDoA method using the ranging results transmitted from the anchor 30 and the terminal device 10. At this time, the server 20 verifies the signature attached to the ranging results transmitted from the terminal device 10 and uses the ranging results.

[0103] Next, in step S223, the server 20 compares and confirms the positioning result using the Downlink TDoA method performed by the terminal device 10 at the edge of the first non-secure positioning area (the boundary between the first non-secure positioning area and the second non-secure positioning area) with the positioning result using the Uplink TDoA method performed by the server 20 at the edge of the first non-secure positioning area (the boundary between the first non-secure positioning area and the second non-secure positioning area).

[0104] If the positioning result by the terminal device 10 and the positioning result by the server 20 do not match, the server 20 may stop the positioning process, or may continue the positioning process by storing the result of no match in the server 20. Note that a match between the positioning results includes a perfect match as well as a case where the result is within a predetermined range of approximation, and the match determination algorithm can be realized using a general filter process or the like.

[0105] When the first non-secure positioning area and the second non-secure positioning area are adjacent to each other, if the server 20 detects from the positioning result that the terminal device 10 has reached the boundary between the first non-secure positioning area and the second non-secure positioning area as shown in Fig. 7C, the server 20 can determine that the terminal device 10 has entered the second non-secure positioning area. When the terminal device 10 enters the second non-secure positioning area, the server 20 then transitions to processing in the second non-secure positioning area in step S224. When transitioning to processing in the second non-secure positioning area, the server 20 notifies the terminal device 10 to switch the positioning method (such as transmitting various data for switching the operating mode of the terminal device).

[0106] Next, in step S225, the server 20 performs positioning of the terminal device 10 in the second non-secure positioning area using the Uplink TDoA method, as shown in Fig. 7D, using the ranging results transmitted from the terminal device 10 and the multiple anchors 30. In the Uplink TDoA method, the server 20 performs positioning by performing calculations using the ranging results periodically transmitted from the terminal device 10 and the anchors 30. At this time, the server 20 verifies the signature attached to the ranging results transmitted from the terminal device 10 and uses the ranging results.

[0107] Note that the user holding the terminal device 10 may move back and forth between the first non-secure positioning area and the second non-secure positioning area. When the terminal device 10 returns from the second non-secure positioning area to the first non-secure positioning area and again reaches the boundary between the first non-secure positioning area and the second non-secure positioning area, steps S221 to S225 are performed again.

[0108] The server 20 performs positioning of the terminal device 10 using the Uplink TDoA method until the terminal device 10 enters the secure positioning region from the second non-secure positioning region (No in step S226).

[0109] On the other hand, when the server 20 detects that the terminal device 10 has entered the secure positioning area based on the positioning result, the process proceeds to step S227 (Yes in step S226).

[0110] Then, in step S227, the server 20 performs positioning of the terminal device 10 within the secure positioning area, as shown in Fig. 7E, based on multiple ranging results by secure ranging defined by the UWB specifications. Note that, since mutual authentication between the terminal device 10 and the server 20 has already been performed at the start position, mutual authentication between the terminal device 10 and the server 20 is not required in the secure positioning area.

[0111] In this manner, the processing in the second embodiment is performed. In the second embodiment, the positioning result of the Downlink TDoA method performed by the terminal device 10 in the first non-secure positioning region is confirmed with the positioning result of the Uplink TDoA method performed by the server 20 in the second non-secure positioning region. This makes it possible to improve the reliability and security of the positioning result by the terminal device 10.

[0112] In the second embodiment, the reliability and security of the Downlink TDoA method positioning results performed by the terminal device 10 can be improved, so mutual authentication between the terminal device 10 and the server 20 at the start position is not essential. If mutual authentication is not performed, a signature is not added to the positioning results and ranging results sent to the server 20. If mutual authentication is not performed at the start position, mutual authentication between the terminal device 10 and the server 20 is performed in the secure positioning area using a method specified in the FiRa (registered trademark) specifications.

[0113] However, the Downlink TDOA positioning result performed by the terminal device 10 may be confirmed with the Uplink TDOA positioning result performed by the server 20, and further, mutual authentication and addition of a signature to the positioning result described in the first embodiment may be performed. Whether to perform mutual authentication and signature may be determined depending on the security level of the information processing system 100. By performing mutual authentication and addition of a signature to the positioning result in addition to performing Uplink TDOA, the reliability and security of the ranging result can be further improved.

[0114] <Modifications> Although the embodiments of the present technology have been specifically described above, the present technology is not limited to the above-described embodiments, and various modifications based on the technical concept of the present technology are possible.

[0115] In the embodiment, the terminal device 10 has been described as being owned by a human user, but the terminal device 10 may also be mounted on a moving object such as a robot, drone, or automobile, or these moving objects may have the functions of the terminal device 10.

[0116] In the embodiment, the secure positioning area and the non-secure positioning area are set to be adjacent to each other without overlapping, but the non-secure positioning area may be set to be included and enclosed within the secure positioning area as shown in Fig. 10. In this case, too, the terminal device 10 always passes through the non-secure positioning area before entering the secure positioning area, so that the positioning process can be performed in the same way as in the embodiment.

[0117] It is also possible to set the secure positioning area and the non-secure positioning area as separate areas, rather than adjacent to each other, as shown in Fig. 11. In this case, start positions may be set in both the secure area and the non-secure positioning area, and it may be determined, depending on the security level, whether mutual authentication is performed only at the start position in the non-secure positioning area, or at the start positions in both the secure area and the non-secure positioning area.

[0118] 12 , the first non-secure positioning area and the second non-secure positioning area may be set as separate areas rather than adjacent to each other. In this case, mutual authentication is first performed at the start position of the first non-secure positioning area. Thereafter, mutual authentication may or may not be performed at the start position of the second non-secure positioning area. Since security can be increased by performing mutual authentication multiple times, whether or not to perform mutual authentication in the second non-secure positioning area may be determined depending on the security level. To perform mutual authentication at multiple start positions, it is necessary to adjust the radio wave intensity and the like according to the characteristics of the BLE beacon 40 or the terminal device 10 so that the terminal device 10 can receive a trigger signal from the BLE beacon 40 at each start position, and to install the BLE beacon 40 in an appropriate position in advance.

[0119] Furthermore, the non-secure positioning area and the secure positioning area may partially overlap as shown in Fig. 13. This also applies to the first non-secure positioning area and the second non-secure positioning area.

[0120] 14, the start position may be set outside the non-secure positioning area and adjacent to the non-secure positioning area. In this case, too, the start position needs to be a position that the terminal device 10 must pass through in order to enter the non-secure positioning area.

[0121] In the embodiment, the secure positioning area and the non-secure positioning area are shown as being elliptical in shape, but they may be polygonal, such as triangular or rectangular, or may be free-form.

[0122] In the non-secure positioning area, positioning using UWB may be performed using Uplink TDoA or TWR (Two Way Ranging) other than Downlink TDoA, or may be performed using a method other than UWB.

[0123] If the UWB communication function of the terminal device 10 is constantly operating and performing UWB positioning, the BLE beacon 40 is not necessary. In this case, when the terminal device 10 detects that it has reached the start position by UWB positioning, preliminary mutual authentication and positioning begin. Also, a UWB-dedicated tag device may be used instead of the BLE beacon 40, or any signal transmission terminal that transmits a trigger signal may be used instead of the BLE beacon 40.

[0124] The distance between the BLE beacon 40 and the terminal device 10 can be measured by utilizing the principle that the strength of the received signal weakens as the distance from the BLE beacon 40 increases. Using this principle, a plurality of BLE beacons 40 can be installed, and the terminal device 10 or the server 20 that receives signals from the BLE beacons 40 can perform positioning of the terminal device 10 using the distance measurement results between each BLE beacon 40 and the terminal device 10. The distance measurement and positioning using the BLE beacon 40 may be combined with the distance measurement and positioning using the anchor 30. The BLE beacon 40 for distance measurement and positioning may be the same device as the beacon for transmitting a trigger signal, or a BLE beacon 40 for distance measurement and positioning may be installed in a space separately from the BLE beacon 40 for transmitting a trigger signal.

[0125] The present technology can also be configured as follows. (1) An information processing device including: a positioning processing unit that performs positioning of a terminal device that has passed through a first area and then entered a second area; and an authentication processing unit that performs mutual authentication with a terminal device that has reached a predetermined position away from the second area before the terminal device enters the second area. (2) The information processing device according to (1), wherein the first area is set so that the terminal device must pass through it before entering the second area. (3) The information processing device according to (1) or (2), wherein the predetermined position is an edge position within the first area or a position near the first area but outside the first area. (4) The information processing device according to (3), wherein the predetermined position is a position that the terminal device must pass through to enter the first area. (5) The information processing device according to any of (1) to (4), wherein the authentication processing unit performs the mutual authentication in response to a notification from the terminal device that it has received a trigger signal from a signal transmission terminal at the predetermined position. (6) The information processing device according to any one of (1) to (5), which receives a positioning result transmitted from the terminal device that performed positioning in the first area. (7) The information processing device according to (6), wherein the positioning of the terminal device in the first area is performed by a Downlink TDoA method using a ranging result transmitted from an anchor. (8) The information processing device according to (6) or (7), wherein the positioning result transmitted from the terminal device is accompanied by a signature using a result of the mutual authentication. (9) The information processing device according to any one of (1) to (8), wherein the positioning processing unit performs positioning of the terminal device in the second area by positioning using UWB. (10) The information processing device according to any one of (1) to (9), wherein the positioning processing unit performs positioning of the terminal device in a third area existing between the first area and the second area. (11) The information processing device according to (10), wherein the positioning processing unit performs positioning of the terminal device in the third area by an Uplink TDoA method using a ranging result transmitted from an anchor.(12) The information processing device according to (10) or (11), wherein the positioning processing unit performs positioning of the terminal device within the third area by an Uplink TDoA method using a ranging result transmitted from the terminal device. (13) The information processing device according to any of (10) to (12), further comprising a comparison processing unit that compares a positioning result by the terminal device with a positioning result by the positioning processing unit. (14) The information processing device according to (13), which compares a positioning result by the terminal device at a boundary between the first area and the third area with a positioning result by the positioning processing unit. (15) The information processing device according to any of (1) to (14), wherein the signal emitting terminal is a BLE beacon. (16) An information processing system comprising a terminal device and an information processing device, the terminal device comprising: a positioning processing unit that performs positioning of the terminal device; and an authentication processing unit that performs mutual authentication with the information processing device; and the information processing device comprising: a positioning processing unit that performs positioning of the terminal device 10 that has passed through a first area and then entered a second area; and an authentication processing unit that performs mutual authentication with the terminal device that has reached a predetermined position away from the second area before the terminal device enters the second area.

[0126] REFERENCE SIGNS LIST 10: Terminal device 11: Application processor 20: Server (information processing device) 21: Application processor 30: Anchor 40: BLE beacon 100: Information processing system

Claims

1. An information processing device comprising: a positioning processing unit that performs positioning of a terminal device that has passed through a first area and then entered a second area; and an authentication processing unit that performs mutual authentication between the terminal device and the terminal device that has reached a predetermined position away from the second area before the terminal device enters the second area.

2. The information processing device according to claim 1, wherein the first area is set so that the terminal device must pass through it before entering the second area.

3. The information processing device according to claim 1, wherein the predetermined position is an edge position within the first area, or a position outside the first area near the first area.

4. The information processing device according to claim 3, wherein the predetermined position is a position that the terminal device must pass through in order to enter the first area.

5. The information processing device according to claim 1, wherein the authentication processing unit performs the mutual authentication in response to a notification from the terminal device that the terminal device has received a trigger signal from a signal transmitting terminal at the predetermined position.

6. The information processing device according to claim 1, wherein the information processing device receives a positioning result transmitted from the terminal device that performed positioning in the first area.

7. The information processing device according to claim 6, wherein the positioning of the terminal device in the first area is performed by a Downlink TDoA method using a ranging result transmitted from an anchor.

8. The information processing device according to claim 6, wherein the positioning result transmitted from the terminal device is accompanied by a signature using the result of the mutual authentication.

9. The information processing device according to claim 1, wherein the positioning processing unit performs positioning of the terminal device in the second area using UWB.

10. The information processing device according to claim 1, wherein the positioning processing unit performs positioning of the terminal device in a third area that exists between the first area and the second area.

11. The information processing device according to claim 10, wherein the positioning processing unit performs positioning of the terminal device within the third area using an Uplink TDoA method using a ranging result transmitted from an anchor.

12. The information processing device according to claim 10, wherein the positioning processing unit performs positioning of the terminal device within the third area using an Uplink TDoA method using the distance measurement result transmitted from the terminal device.

13. The information processing device according to claim 10, further comprising a comparison processing section that compares the positioning result from the terminal device with the positioning result from the positioning processing section.

14. The information processing device according to claim 13, wherein the positioning result by the terminal device at the boundary between the first area and the third area is compared with the positioning result by the positioning processing unit.

15. The information processing device according to claim 1, wherein the signal transmitting terminal is a BLE beacon.

16. An information processing system comprising a terminal device and an information processing device, the terminal device comprising: a positioning processing unit that performs positioning of the terminal device; and an authentication processing unit that performs mutual authentication with the information processing device; and the information processing device comprising: a positioning processing unit that performs positioning of a terminal device 10 that has passed through a first area and then entered a second area; and an authentication processing unit that performs mutual authentication with the terminal device that has reached a predetermined position away from the second area before the terminal device enters the second area.

Citation Information

Patent Citations

  • Passing control method and device of pedestrian channel, storage medium and terminal

    CN116912991A

  • Ultra-wideband ranging method and positioning system suitable for wireless beacon mode

    CN117554889A

  • Collecting a database of spoofed devices

    US20200200858A1

  • Service provision device, service provision method, and program recording medium

    WO2017204053A1

  • Information processing system, information processing terminal, and information processing method

    WO2022264509A1