Information processing system, control device, information processing method, and program
The information processing system addresses the issue of slow authentication on low-cost devices by using a control device and information terminal to share a common key for quick and secure device restriction release.
Patent Information
- Application Number
- PCT/JP2025/023782
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-19
- Filing Date
- 2025-07-02
- Publication Date
- 2026-01-22
AI Technical Summary
Authentication on low-cost devices with limited CPU performance in security systems takes time, reducing user convenience.
An information processing system that uses a control device and an information terminal to perform authentication by sharing a common key after verifying a server certificate, allowing for quick release of device restrictions through challenge-response authentication.
The system reduces the time required to lift device restrictions while maintaining security, enhancing user convenience and reducing power consumption.
Smart Images

Figure JP2025023782_22012026_PF_FP_ABST
Abstract
Description
Information processing system, control device, information processing method, and program
[0001] The present invention relates to an information processing system, a control device, an information processing method, and a program.
[0002] Conventionally, security systems for locking and unlocking doors of facilities have been known. Patent Document 1 discloses a security system that can safely remotely lock and unlock a house without requiring other devices such as a fingerprint authentication device. Patent Document 2 discloses an information processing system that performs authentication using a private key, a public key, a server certificate, etc., and locks and unlocks a delivery locker or a car.
[0003] JP 2014-159692 A JP 2018-74205 A
[0004] In the public key cryptosystem disclosed in Patent Document 2, signature verification is performed based on an algorithm such as ECDSA (Elliptic Curve Digital Signature Algorithm), and therefore security is high. However, when authentication is performed on a low-cost device with limited CPU performance, there is a concern that authentication takes time, reducing user convenience.
[0005] The present invention provides an information processing system and the like that can shorten the time from when a user performs an operation until a restriction on a device is released, while still taking safety into consideration.
[0006] An information processing system according to one aspect of the present invention is an information processing system used to remove restrictions on a device that restricts the operation of an item, and includes an information terminal and a control device. The information terminal has a first memory unit that stores a first private key, a first public key corresponding to the first private key, and a server certificate, and a first communication unit that transmits the server certificate to the control device. The server certificate includes the first public key and a signature for the first public key. The control device has a second memory unit that stores a root certificate including a public key, a second communication unit that receives the server certificate from the information terminal, and a control unit that verifies the signature included in the server certificate using the public key included in the root certificate and shares a common key with the information terminal if the verification is successful. After the common key is shared, the second communication unit transmits a challenge value to the information terminal. The first communication unit transmits a response value generated based on the received challenge value and the common key to the control device. The control unit releases the restriction on the device if verification of the response value received by the second communication unit is successful.
[0007] A control device according to one embodiment of the present invention is a control device that removes restrictions on equipment that restricts the operation of an item, and includes: a memory unit in which a root certificate including a public key is stored; a communication unit that receives the server certificate including a first public key and a signature for the first public key from an information terminal that has a first memory unit in which a first private key, a first public key corresponding to the first private key, and a server certificate is stored; and a control unit that verifies the signature included in the server certificate using the public key included in the root certificate and shares a common key with the information terminal if the verification is successful. After the common key is shared, the communication unit transmits a challenge value to the information terminal, and the information terminal transmits a response value generated based on the received challenge value and the common key to the control device. The control unit removes the restriction on the equipment if the verification of the response value received by the communication unit is successful.
[0008] An information processing method according to one aspect of the present invention is an information processing method executed by an information processing system used to release a restriction on a device that restricts an operation of an article, the information processing system including an information terminal and a control device, the information terminal including a first storage unit that stores a first private key, a first public key corresponding to the first private key, and a server certificate, the server certificate including the first public key and a signature for the first public key, the control device including a second storage unit that stores a root certificate including a public key, the information processing method including the steps of: The method includes a step in which the control device receives the server certificate from the information terminal, a step in which the control device verifies the signature included in the server certificate using the public key included in the root certificate and shares a common key with the information terminal if the verification is successful, a step in which the control device transmits a challenge value to the information terminal after the common key is shared, a step in which the information terminal transmits a response value generated based on the received challenge value and the common key to the control device, and a step in which the control device releases the restriction on the device if the verification of the received response value is successful.
[0009] An information processing method according to one aspect of the present invention is an information processing method executed by a control device that removes restrictions on equipment that restricts the operation of an item, wherein the control device has a memory unit in which a root certificate including a public key is stored, and the information processing method includes the steps of receiving, from an information terminal having a first memory unit in which a first private key, a first public key corresponding to the first private key, and a server certificate are stored, the server certificate including the first public key and a signature for the first public key, verifying the signature included in the server certificate using the public key included in the root certificate, and sharing a common key with the information terminal if the verification is successful, transmitting a challenge value to the information terminal after the common key has been shared, receiving a response value sent by the information terminal, the response value being generated by the information terminal based on the challenge value and the common key received by the information terminal, and removing the restriction on the equipment if the verification of the received response value is successful.
[0010] A program according to one aspect of the present invention is a program for causing a computer to execute the information processing method.
[0011] An information processing system according to an aspect of the present invention can reduce the time it takes for a device restriction to be lifted after a user performs an operation, while still taking safety into consideration.
[0012] FIG. 1 is an external view of an information processing system according to an embodiment. FIG. 2 is a block diagram showing the functional configuration of the information processing system according to an embodiment. FIG. 3 is a sequence diagram of an example operation for storing a server certificate in an information terminal according to an embodiment. FIG. 4 is a diagram showing an example of a format of a server certificate. FIG. 5 is a sequence diagram of example 1 of an operation for unlocking an electric lock using a server certificate. FIG. 6 is a sequence diagram of example 1 of an operation for unlocking an electric lock using an unlocking token. FIG. 7 is a flowchart of authentication processing executed by a control device in example 1 of an operation for unlocking an electric lock using an unlocking token. FIG. 8 is a sequence diagram of example 2 of an operation for unlocking an electric lock using a server certificate. FIG. 9 is a sequence diagram of example 2 of an operation for unlocking an electric lock using an unlocking token. FIG. 10 is a sequence diagram of example 3 of an operation for unlocking an electric lock using a server certificate. FIG. 11 is a sequence diagram of example 3 of an operation for unlocking an electric lock using an unlocking token.
[0013] Hereinafter, the embodiments will be described in detail with reference to the drawings. Note that the embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection forms, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present invention. Furthermore, among the components in the following embodiments, components not recited in independent claims will be described as optional components.
[0014] It should be noted that the drawings are schematic diagrams and are not necessarily strict illustrations. In addition, in the drawings, substantially the same components are denoted by the same reference numerals, and overlapping descriptions may be omitted or simplified.
[0015] (Embodiment) [Configuration] First, the configuration of an information processing system according to an embodiment will be described. Fig. 1 is an external view of the information processing system according to an embodiment. Fig. 2 is a block diagram showing the functional configuration of the information processing system according to an embodiment.
[0016] 1, an information processing system 10 according to an embodiment is a system for safely unlocking an electric lock 60 using an information terminal 20 and a management terminal 30. The information processing system 10 includes the information terminal 20, the management terminal 30, a control device 50, and an electric lock 60. The control device 50 and the electric lock 60 are installed as an electric lock system on a door 81 (or door frame) within a facility 80, for example. The facility 80 is, for example, an apartment building, but may also be a facility other than a residence, such as an office building.
[0017] The information terminal 20 is an information terminal used by users of the facility 80 to unlock the electric lock 60. Users of the facility 80 include not only visitors to the facility 80 (see FIG. 1 ; in other words, non-residents) but also residents residing in the facility 80. The information terminal 20 is, for example, a portable information terminal such as a smartphone or a tablet terminal. The information terminal 20 includes a communication unit 21, an information processing unit 22, a memory unit 23, an operation reception unit 24, a measurement unit 25, a transmission power measurement unit 26, and a display unit 27.
[0018] The communication unit 21 is a communication circuit that enables the information terminal 20 to communicate with each of the management terminal 30 and the control device 50. For example, the communication unit 21 performs wireless communication with the management terminal 30 via a wide area communication network such as the Internet, and performs wireless communication with the control device 50 via a local communication network.
[0019] The information processing unit 22 performs information processing for unlocking the electric lock 60. The information processing unit 22 is realized, for example, by a microcomputer, but may also be realized by a processor. The functions of the information processing unit 22 are realized, for example, by the microcomputer or processor constituting the information processing unit 22 executing a computer program stored in the storage unit 23.
[0020] The storage unit 23 is a storage device that stores information necessary for the information processing, the computer programs, etc. The storage unit 23 is realized by, for example, a semiconductor memory.
[0021] The operation reception unit 24 receives operations from the user. The operation reception unit 24 is realized by, for example, a touch panel, but may also be realized by hardware keys or the like.
[0022] The measurement unit 25 measures the received signal strength (RSSI: Received Signal Strength Indicator) of the wireless communication signal transmitted from the control device 50 to the information terminal 20. The measurement unit 25 is realized by, for example, a measurement circuit. The measurement unit 25 may be realized as a part of the communication unit 21.
[0023] The transmission power measurement unit 26 measures the transmission power (TxPower) of the wireless communication signal transmitted from the information terminal 20 to the control device 50. The transmission power measurement unit 26 is realized by, for example, a measurement circuit. The transmission power measurement unit 26 may be realized as part of the communication unit 21.
[0024] The display unit 27 displays an image. The display unit 27 is realized by, for example, a liquid crystal panel, but may also be realized by an organic EL panel. When the operation reception unit 24 is realized by a touch panel and the touch panel is placed on the display unit 27, the touch panel and the image displayed on the display unit 27 constitute a GUI (Graphical User Interface).
[0025] The management terminal 30 is an information terminal used by a manager or the like of the facility 80. The manager or the like may be the owner of the facility 80 or an employee of the management company of the facility 80. The management terminal 30 is, for example, a portable information terminal such as a smartphone or a tablet terminal. The management terminal 30 includes a communication unit 31, an information processing unit 32, a memory unit 33, an operation reception unit 34, a measurement unit 35, a transmission power measurement unit 36, and a display unit 37.
[0026] The communication unit 31 is a communication circuit that enables the management terminal 30 to communicate with each of the information terminal 20 and the control device 50. The communication unit 31 performs wireless communication with the information terminal 20 via a wide area communication network such as the Internet, and performs wireless communication with the control device 50 via a local communication network, for example.
[0027] The information processing unit 32 performs information processing for granting the information terminal 20 the authority to unlock the electric lock 60, and information processing for unlocking the electric lock 60. The information processing for granting the information terminal 20 the authority to unlock the electric lock 60 is, for example, processing for issuing a server certificate to the information terminal 20 (described later). The information processing unit 32 is realized, for example, by a microcomputer, but may also be realized by a processor. The functions of the information processing unit 32 are realized, for example, by the microcomputer or processor constituting the information processing unit 32 executing a computer program stored in the storage unit 33.
[0028] The storage unit 33 is a storage device that stores information necessary for the information processing, the computer program, etc. The storage unit 33 is realized by, for example, a semiconductor memory.
[0029] The operation reception unit 34 receives operations from the user. The operation reception unit 34 is realized by, for example, a touch panel, but may also be realized by hardware keys or the like.
[0030] The measurement unit 35 measures the received signal strength of the wireless communication signal transmitted by the control device 50 to the management terminal 30. The measurement unit 35 is realized by, for example, a measurement circuit. The measurement unit 35 may also be realized as part of the communication unit 31.
[0031] The transmission power measurement unit 36 measures the transmission power of the wireless communication signal transmitted from the management terminal 30 to the control device 50. The transmission power measurement unit 36 is realized by, for example, a measurement circuit. The transmission power measurement unit 36 may also be realized as part of the communication unit 31.
[0032] The display unit 37 displays an image. The display unit 37 is realized by, for example, a liquid crystal panel, but may also be realized by an organic EL panel. If the operation reception unit 34 is realized by a touch panel and the touch panel is placed on the display unit 37, the touch panel and the image displayed on the display unit 37 constitute a GUI.
[0033] The control device 50 controls the locking and unlocking of the electric lock 60. The control device 50 is built into, for example, the door 81 or the door frame. The control device 50 includes a communication unit 51, a control unit 52, a memory unit 53, an operation reception unit 54, and a measurement unit 55.
[0034] The communication unit 51 is a communication circuit that enables the control device 50 to communicate with each of the information terminal 20 and the management terminal 30. The communication unit 51 performs wireless communication with the information terminal 20 and the management terminal 30, for example, via a local communication network.
[0035] The control unit 52 performs information processing to lock or unlock the electric lock 60. Specifically, the control unit 52 locks or unlocks the electric lock 60 by outputting a control signal to the electric lock 60. The control unit 52 is realized, for example, by a microcomputer, but may also be realized by a processor. The functions of the control unit 52 are realized, for example, by the microcomputer or processor constituting the control unit 52 executing a computer program stored in the storage unit 53.
[0036] The storage unit 53 is a storage device that stores information necessary for the information processing, the computer program, etc. The storage unit 53 is realized by, for example, a semiconductor memory.
[0037] The operation reception unit 54 receives operations from the user. The operation reception unit 54 is realized by, for example, hardware keys such as push buttons, but may also be realized by a touch panel.
[0038] The measurement unit 55 measures the received signal strength (RSSI: Received Signal Strength Indicator) of the wireless communication signal transmitted from the information terminal 20 to the control device 50. The measurement unit 55 is realized by, for example, a measurement circuit. The measurement unit 55 may be realized as a part of the communication unit 51.
[0039] The electric lock 60 locks or unlocks the door 81 based on a control signal output from the control unit 52. Specifically, the electric lock 60 has an electric motor and a transmission mechanism that transmits the driving force of the electric motor to the deadbolt. The driving force of the electric motor is transmitted to the deadbolt via the transmission mechanism, causing the deadbolt to move to a locked or unlocked position.
[0040] [Example of Operation for Storing a Server Certificate in an Information Terminal] First, an example of operation for storing a server certificate in the information terminal 20 will be described. Fig. 3 is a sequence diagram of an example of operation for storing a server certificate in the information terminal 20. In the following example of operation for storing a server certificate and in examples of each operation described later, the information terminal 20 will be described as being used by a user of the facility 80, and the management terminal 30 will be described as being used by a manager or the like of the facility 80. The user may be a non-resident, such as a package delivery person or a person dispatched by a housekeeping service provider, but may also be a resident of the facility 80.
[0041] The server certificate serves as an unlocking permit for the electric lock 60. As shown in Fig. 3, a public key A and a corresponding private key A are stored in the storage unit 23 of the information terminal 20. The public key A and the private key A are generated, for example, when an application program (hereinafter simply referred to as an app) for using the information processing system 10 is installed in the information terminal 20, and are stored in the storage unit 23.
[0042] Furthermore, the storage unit 33 of the management terminal 30 stores a public key B and a corresponding private key B. The public key B and the private key B are stored in the storage unit 33, for example, when an app for using the information processing system 10 is installed in the management terminal 30.
[0043] First, the user performs a predetermined operation on the operation reception unit 24 of the information terminal 20 on which the above-mentioned application is running. The predetermined operation is an operation for installing a server certificate. The operation reception unit 24 receives the predetermined operation (S11).
[0044] When the operation reception unit 24 receives a predetermined operation, the information processing unit 22 generates a server certificate issuance request and causes the communication unit 21 to transmit the generated issuance request to the management terminal 30 (S12). The issuance request includes the public key A. That is, the communication unit 21 transmits the public key A to the management terminal 30. The communication unit 21 transmits the public key A to the management terminal 30 by wireless communication over the wide area communication network.
[0045] The communication unit 31 of the management terminal 30 receives the issuance request including the public key A. If the administrator confirms the user's issuance request and allows the user to unlock the electric lock 60, the information processing unit 32 generates a signature for the received public key A and usage conditions using the private key B (S13). The information processing unit 32 also causes the communication unit 31 to transmit a server certificate including the public key A, usage conditions, and signature to the information terminal 20 (S14). The usage conditions are, for example, information indicating timing requirements (in other words, expiration dates) and are determined in advance, for example, by the administrator who uses the management terminal 30. The timing requirements, for example, specify the start and end points at which the server certificate is valid, but it is sufficient to specify at least the end point.
[0046] The format of the server certificate may be, for example, an X.509 certificate. Fig. 4 is a diagram showing an example of the format of a server certificate. The validity period of the certificate in Fig. 4 corresponds to the above-mentioned usage conditions (timing requirements), the subject public key information corresponds to public key A, and signatureValue corresponds to the signature. Usage conditions other than the expiration date may be stored in the extension area of the format in Fig. 4.
[0047] The communication unit 21 of the information terminal 20 receives the server certificate. The information processing unit 22 stores the received server certificate in the storage unit 23 (S15).
[0048] [Example 1 of operation for unlocking electric lock using server certificate] Example 1 of operation for unlocking electric lock 60 using the server certificate stored as described above will be described. Fig. 5 is a sequence diagram of Example 1 of operation for unlocking electric lock 60 using the server certificate. Fig. 5 shows an example in which an unlock token is stored as a common key in each of the information terminal 20 and the control device 50 when unlocking electric lock 60 using the server certificate.
[0049] 5, a root certificate is stored in the storage unit 53 of the control device 50. The root certificate includes a public key B. The root certificate is generated, for example, by the information processing unit 32 of the management terminal 30, and is stored in the storage unit 53 by being transmitted to the control device 50 by the communication unit 31. The root certificate may be stored in the storage unit 53 by the manufacturing equipment when the control device 50 is manufactured.
[0050] The information processing unit 22 of the information terminal 20 starts (executes) the application when the user performs an operation to start the application (S16).
[0051] The control unit 52 of the control device 50 causes the communication unit 51 to transmit a beacon signal to notify the presence of the control device 50 (S17). The communication unit 51 transmits the beacon signal at predetermined time intervals. The beacon signal may also be called an advertisement signal. The beacon signal is transmitted continuously.
[0052] When the user approaches the door 81, the user performs a predetermined unlocking operation on the operation receiving unit 54 of the control device 50 to unlock the electric lock 60. Note that the door 81 is, for example, a door provided in a private area of the facility 80 (see FIG. 1 ), but it may also be a door provided at the entrance of the facility 80 or a door provided in a common area other than the entrance. The operation receiving unit 54 receives the unlocking operation (S18). The unlocking operation is a simple operation by which the user expresses their intention to unlock the door, unlike the operation of turning a thumb turn or a doorknob, and is, for example, a touch operation on the operation receiving unit 24.
[0053] When the operation receiving unit 54 receives the unlocking operation, the control unit 52 establishes a wireless communication connection between the information terminal 20 (communication unit 21) and the control device 50 (communication unit 51) (S19). This wireless communication is wireless communication via a local communication network, such as short-range wireless communication based on a communication standard such as Bluetooth (registered trademark).
[0054] After the wireless communication connection is established, the control unit 52 of the control device 50 causes the communication unit 51 to transmit an unlocking permission request to the information terminal 20 (S20).
[0055] The communication unit 21 of the information terminal 20 receives the unlocking permission request. In response to the received unlocking permission request, the information processing unit 22 causes the communication unit 21 to transmit the server certificate to the control device 50 (S21). That is, the communication unit 21 transmits the server certificate to the control device 50.
[0056] The communication unit 51 of the control device 50 receives the server certificate. The control unit 52 verifies the signature included in the received server certificate using the public key B included in the root certificate stored in the storage unit 53 (S22). A signature method such as ECDSA is used for signature verification. If the signature verification is successful, the control unit 52 determines the usage conditions included in the server certificate (S23). The usage conditions may be, for example, time-related requirements (whether the server certificate is within its expiration date), etc.
[0057] If the control unit 52 determines that the usage conditions are satisfied, it generates a session key using public key A included in the server certificate (S24). The control unit 52 encrypts the generated session key with public key A and causes the communication unit 51 to transmit the encrypted session key to the information terminal 20 (S25). The information processing unit 22 decrypts the session key using private key A, and thereafter, encrypted communication is established between the information terminal 20 (information processing unit 22) and the control device 50 (control unit 52) by using the session key.
[0058] The information processing unit 22 of the information terminal 20 causes the communication unit 21 to transmit an unlock token request to the control device 50 (S26). That is, the communication unit 21 transmits the unlock token request to the control device 50.
[0059] The control unit 52 of the control device 50 generates an unlock token and stores it in the storage unit 53 (S27). The unlock token is an example of a common key between the information terminal 20 and the control device 50 that will be used for authentication from the next time onwards. The unlock token is stored in the storage unit 53 for each information terminal 20 that has sent an unlock token request. An expiration date may be set for the unlock token, and the unlock token may be stored in the storage unit 53 in association with the expiration date.
[0060] The control unit 52 causes the communication unit 51 to transmit the generated unlock token to the information terminal 20 (S28). That is, the communication unit 51 transmits the unlock token to the information terminal 20. The unlock token is transmitted securely through encrypted communication using a session key.
[0061] The communication unit 21 of the information terminal 20 receives the unlocking token. The information processing unit 22 stores the received unlocking token in the storage unit 23 (S29). Thereafter, the information processing unit 22 causes the communication unit 21 to transmit an unlocking permission command to the control device 50 in response to the received unlocking permission request (S30). That is, the communication unit 21 transmits the unlocking permission command to the control device 50.
[0062] The communication unit 51 of the control device 50 receives the unlocking permission command. The control unit 52 unlocks the electric lock 60 based on the received unlocking permission command (S31).
[0063] If the user does not perform the unlocking operation, the processes of steps S30 and S31 do not need to be executed. For example, in step S18, an operation for initial registration of the information terminal 20 to the control device 50 (in other words, an operation for sharing the unlocking token) may be performed instead of the unlocking operation. In this case, the processes of steps S30 and S31 are not executed, and the unlocking token may be stored in the memory unit 23 of the information terminal 20 by the processes of steps S26 to S29.
[0064] In this way, in the information processing system 10, when an unlocking token is not stored in the storage unit 23 of the information terminal 20, it is possible to unlock the electric lock 60 using a server certificate. Unlocking the electric lock 60 using a server certificate has the advantage that information about the information terminal 20 does not need to be stored in advance in the control device 50.
[0065] Furthermore, by verifying the server certificate, the control device 50 can safely provide the information terminal 20 with an unlocking token for challenge-response authentication to unlock the electric lock 60 from the next time onwards.
[0066] The transmission of the unlock permission command in step S30 may be omitted. Furthermore, the electric lock 60 may be unlocked in step S31 based on the user's unlocking operation on the control device 50 instead of the transmission of the unlock permission command.
[0067] [Example 1 of operation for unlocking electric lock using unlock token] When an unlock token is stored in the memory unit 23, the information terminal 20 can unlock the electric lock 60 using the unlock token instead of a server certificate. Example 1 of operation for unlocking the electric lock 60 using the unlock token will be described below. Figure 6 is a sequence diagram of example 1 of operation for unlocking the electric lock 60 using the unlock token.
[0068] 5, detailed description of steps S16 to S20 will be omitted. In step S20, when the communication unit 21 of the information terminal 20 receives the unlock permission request, the information processing unit 22 confirms that the unlock token is stored in the storage unit 23, and then causes the communication unit 21 to transmit a challenge value request to the control device 50 (S41). In other words, the communication unit 21 transmits the challenge value request to the control device 50.
[0069] The communication unit 51 of the control device 50 receives the challenge value request. The control unit 52 confirms that a valid unlock token for the information terminal 20 is stored in the storage unit 53 (S42), and then generates a challenge value (S43). The challenge value is, for example, a random number that is difficult to infer.
[0070] The control unit 52 causes the communication unit 51 to transmit the generated challenge value to the information terminal 20 (S44). That is, the communication unit 51 transmits the challenge value to the information terminal 20. Note that the unlocking permission request and the challenge value may be transmitted together, and it is not essential that the unlocking permission request and the challenge value be transmitted in order.
[0071] The communication unit 21 of the information terminal 20 receives the challenge value. The information processing unit 22 generates a response value based on the received challenge value and the unlocking token stored in the storage unit 23 (S45). The response value is, for example, a hash value generated from the unlocking token and the challenge value. The information processing unit 22 causes the communication unit 21 to transmit the generated response value to the control device 50 (S46). In other words, the communication unit 21 transmits the response value to the control device 50.
[0072] The communication unit 51 of the control device 50 receives the response value. The control unit 52 determines whether the received response value matches a reference response value (hereinafter referred to as a reference value) calculated from the unlocking token stored in the storage unit 53 in step S27 and the challenge value transmitted in step S44 (S47). In other words, the process of step S47 is a process of verifying the response value. If the control unit 52 determines that the response value matches the reference value (if the verification of the response value is successful), the control unit 52 causes the communication unit 51 to transmit an authentication success notification to the information terminal 20 (S48). In other words, the communication unit 51 transmits the authentication success notification to the information terminal 20.
[0073] The communication unit 21 of the information terminal 20 receives the authentication success notification. In response to the received authentication success notification, the information processing unit 22 causes the communication unit 21 to transmit an unlocking permission command to the control device 50 (S30). That is, the communication unit 21 transmits the unlocking permission command to the control device 50.
[0074] The communication unit 51 of the control device 50 receives the unlocking permission command. The control unit 52 unlocks the electric lock 60 based on the received unlocking permission command (S31).
[0075] In this way, in the information processing system 10, after the unlock token is stored in the memory unit 23 of the information terminal 20, the electric lock 60 can be unlocked by challenge-response authentication (authentication by comparing a response value obtained from the unlock token and a challenge value). Challenge-response authentication can be completed in a shorter time than public key authentication. In other words, by adopting challenge-response authentication, the information processing system 10 can help the user quickly unlock the electric lock 60 while reducing the power consumption of the control device 50. In addition, an expiration date can be set for the unlock token, and by shortening the expiration date of the unlock token, a decrease in security can be suppressed.
[0076] In Example 1 of the operation of unlocking the electric lock 60 using an unlocking token, if a valid unlocking token is not stored in the storage unit 23 in step S42, or if it is determined in step S47 that the response value does not match the reference value (if verification of the response value fails), the processing of steps S21 to S29 may be executed. In other words, if the challenge-response authentication fails, the electric lock 60 may be unlocked and the unlocking token may be shared again based on public key authentication.
[0077] In addition, the transmission of the unlock permission command in step S30 may be omitted. In addition, the electric lock 60 may be unlocked in step S31 based on the user's unlock operation to the control device 50 instead of transmitting the unlock permission command.
[0078] [Details of authentication process of control device] The details of the authentication process executed by the control device 50 in Example 1 of the operation of unlocking the electric lock using the unlocking token will be described with reference to a flowchart. Fig. 7 is a flowchart of the authentication process executed by the control device 50 in Example 1 of the operation of unlocking the electric lock using the unlocking token.
[0079] The communication unit 51 of the control device 50 receives a challenge value request from the information terminal 20 (S51). The control unit 52 determines whether a valid unlocking token for the information terminal 20 is stored in the storage unit 53 (S52). If the control unit 52 determines that a valid unlocking token for the information terminal 20 is not stored in the storage unit 53 (No in S52), the control unit 52 causes the communication unit 51 to send an authentication failure notification indicating that the unlocking token is invalid to the information terminal 20 (S53).
[0080] On the other hand, if the control unit 52 determines that a valid unlock token for the information terminal 20 is stored in the storage unit 53, the control unit 52 generates a challenge value (S54). The challenge value is, for example, a random number that is difficult to guess.
[0081] The control unit 52 causes the communication unit 51 to transmit the generated challenge value to the information terminal 20 (S55). That is, the communication unit 51 transmits the challenge value to the information terminal 20. The control unit 52 enters a standby state for receiving a response value from the information terminal 20.
[0082] The communication unit 51 of the control device 50 receives the response value (S56). The control unit 52 determines whether the received response value matches a reference value calculated from the unlocking token stored in the storage unit 53 and the challenge value transmitted in step S55 (S57). In other words, the process of step S57 is a process of verifying the response value. If the control unit 52 determines that the response value does not match the reference value (No in S57), it causes the communication unit 51 to transmit an authentication failure notification to the information terminal 20 (S53). In other words, the communication unit 51 transmits an authentication failure notification to the information terminal 20.
[0083] If the control unit 52 determines that the response value matches the reference value (Yes in S57), the control unit 52 causes the communication unit 51 to transmit an authentication success notification to the information terminal 20 (S58). That is, the communication unit 51 transmits the authentication success notification to the information terminal 20.
[0084] As described above, by performing challenge-response authentication, the control device 50 can help the user quickly unlock the electric lock 60 while reducing the power consumption of the control device 50.
[0085] If an authentication failure notification is sent in step S53, the processes of steps S21 to S29 may be executed. In other words, if the challenge-response authentication fails, the electric lock 60 may be unlocked and the unlocking token may be shared again based on public key authentication.
[0086] [Example 2 of operation for unlocking electric lock using server certificate] Next, example 2 of operation for unlocking electric lock 60 using server certificate will be described. Fig. 8 is a sequence diagram of example 2 of operation for unlocking electric lock 60 using server certificate. Fig. 8 shows an example in which an unlock token is stored as a common key in each of the information terminal 20 and the control device 50 when unlocking electric lock 60 using server certificate.
[0087] The information processing unit 22 of the information terminal 20 starts (executes) the application when the user performs an operation to start the application (S16).
[0088] The control unit 52 of the control device 50 causes the communication unit 51 to transmit a beacon signal to notify the presence of the control device 50 (S17).
[0089] The user carrying the information terminal 20 moves near the door 81. The measurement unit 25 of the information terminal 20 measures the received signal strength of the beacon signal received by the communication unit 21 (S61), and the information processing unit 22 determines whether the measured received signal strength exceeds a threshold value (S62). The threshold value is stored in the storage unit 23, for example.
[0090] If it is determined in step S62 that the measured received signal strength is equal to or less than the threshold, it is possible that the information terminal 20 is somewhat far from the control device 50 and the user has no intention of unlocking the door 81. For this reason, the processes from step S19 onwards are not executed. On the other hand, if it is determined that the measured received signal strength exceeds the threshold, it is considered that the user is located near the control device 50 and has the intention of unlocking the door 81. Therefore, when the information processing unit 22 determines that the measured received signal strength exceeds the threshold, it establishes a wireless communication connection between the information terminal 20 (communication unit 21) and the control device 50 (communication unit 51) (S19).
[0091] After the wireless communication connection is established, the information processing unit 22 of the information terminal 20 causes the communication unit 21 to transmit the server certificate to the control device 50 (S21). That is, the communication unit 21 transmits the server certificate to the control device 50. Thereafter, the same processes as steps S22 to S29 in Fig. 5 are performed, and the information terminal 20 and the control device 50 each store the unlock token as a common key.
[0092] When the user moves close to the door 81, the user performs a predetermined unlocking operation on the operation acceptance unit 54 of the control device 50 to unlock the electric lock 60, and the operation acceptance unit 54 accepts the unlocking operation (S63). When the unlocking operation is accepted by the operation acceptance unit 54, the control unit 52 causes the communication unit 51 to send an unlocking permission request to the information terminal 20, provided that the processes of steps S21 to S29 (public key authentication) have been successful (S64). In other words, the communication unit 51 sends the unlocking permission request to the information terminal 20.
[0093] The communication unit 21 of the information terminal 20 receives the unlock permission request. The measurement unit 25 measures the received signal strength of the received unlock permission request (S65), and the information processing unit 22 determines whether the measured received signal strength exceeds a threshold value (S66). The threshold value is stored in the storage unit 23, for example.
[0094] If it is determined in step S66 that the measured received signal strength is equal to or less than the threshold, it is possible that the information terminal 20 is somewhat far from the control device 50 and the user has no intention of unlocking the door 81. For this reason, the processes from step S30 onward are not executed. On the other hand, if it is determined in step S66 that the measured received signal strength exceeds the threshold, it is considered that the user is located near the control device 50 and has the intention of unlocking the door 81. Therefore, when the information processing unit 22 determines that the measured received signal strength exceeds the threshold, it causes the communication unit 21 to send an unlock permission command to the control device 50 (S30). That is, the communication unit 21 sends the unlock permission command to the control device 50.
[0095] The communication unit 51 of the control device 50 receives the unlocking permission command. The control unit 52 unlocks the electric lock 60 based on the received unlocking permission command (S31).
[0096] In this way, when the user is located near the control device 50 and is considered to have the intention to unlock the door 81, the information processing system 10 can perform public key authentication and safely unlock the electric lock 60. The threshold value for the received signal strength may be set to an appropriate value empirically or experimentally depending on the characteristics of the information terminal 20.
[0097] In Example 2, where the server certificate is used to unlock the electric lock, public key authentication is started before the user performs the unlocking operation, and public key authentication is completed by the time the user performs the unlocking operation. This significantly reduces the time it takes for the electric lock 60 to be unlocked after the user performs the unlocking operation.
[0098] [Example 2 of operation for unlocking electric lock using unlock token] Next, an example 2 of operation for unlocking the electric lock 60 using an unlock token will be described. Fig. 9 is a sequence diagram of the example 2 of operation for unlocking the electric lock 60 using an unlock token.
[0099] The information processing unit 22 of the information terminal 20 starts (executes) the application when the user performs an operation to start the application (S16).
[0100] The control unit 52 of the control device 50 causes the communication unit 51 to transmit a beacon signal to notify the presence of the control device 50 (S17).
[0101] The user carrying the information terminal 20 moves near the door 81. The measurement unit 25 of the information terminal 20 measures the received signal strength of the beacon signal received by the communication unit 21 (S61), and the information processing unit 22 determines whether the measured received signal strength exceeds a threshold value (S62). The threshold value is stored in the storage unit 23, for example.
[0102] If it is determined in step S62 that the measured received signal strength is equal to or less than the threshold, it is possible that the information terminal 20 is somewhat far from the control device 50 and the user has no intention of unlocking the door 81. For this reason, the processes from step S19 onwards are not executed. On the other hand, if it is determined that the measured received signal strength exceeds the threshold, it is considered that the user is located near the control device 50 and has the intention of unlocking the door 81. Therefore, when the information processing unit 22 determines that the measured received signal strength exceeds the threshold, it establishes a wireless communication connection between the information terminal 20 (communication unit 21) and the control device 50 (communication unit 51) (S19).
[0103] After the wireless communication connection is established, the information processing unit 22 of the information terminal 20 causes the communication unit 21 to send a challenge value request to the control device 50 (S41). That is, the communication unit 21 sends the challenge value request to the control device 50. After that, the same processes as steps S42 to S48 in Fig. 6 are performed. The subsequent processes are the same as in Example 2 of the operation for unlocking the electric lock 60 using a server certificate, and therefore a description thereof will be omitted.
[0104] In this way, when the user is located near the control device 50, is considered to have the intention to unlock the door 81, and the unlock token is shared, the information processing system 10 can quickly and safely unlock the electric lock 60 by performing challenge-response authentication. The threshold value for the received signal strength may be set to an appropriate value empirically or experimentally depending on the characteristics of the information terminal 20.
[0105] In Example 2, in which the electric lock is unlocked using an unlocking token, challenge-response authentication is started before the user performs the unlocking operation, and the challenge-response authentication is completed by the time the user performs the unlocking operation. This significantly reduces the time from when the user performs the unlocking operation until the electric lock 60 is unlocked.
[0106] In Example 2 of the operation of unlocking the electric lock 60 using an unlocking token, if a valid unlocking token is not stored in the storage unit 23 in step S42, or if it is determined in step S47 that the response value does not match the reference value, the processes of steps S21 to S29 may be executed. In other words, if the challenge-response authentication fails, the electric lock 60 may be unlocked and the unlocking token may be shared again based on public key authentication.
[0107] [Example 3 of operation for unlocking electric lock using server certificate] Next, example 3 of operation for unlocking electric lock 60 using server certificate will be described. Fig. 10 is a sequence diagram of example 3 of operation for unlocking electric lock 60 using server certificate. Fig. 10 shows an example in which an unlock token is stored as a common key in each of the information terminal 20 and the control device 50 when unlocking electric lock 60 using server certificate.
[0108] The information processing unit 22 of the information terminal 20 starts (executes) the application when the user performs an operation to start the application (S16).
[0109] The control unit 52 of the control device 50 causes the communication unit 51 to transmit a beacon signal to notify the presence of the control device 50 (S17).
[0110] When the beacon signal is received by the communication unit 21 of the information terminal 20, the information processing unit 22 of the information terminal 20 (or the control unit 52 of the control device 50) establishes a wireless communication connection between the information terminal 20 (communication unit 21) and the control device 50 (communication unit 51) (S19).
[0111] After the wireless communication connection is established, the information processing unit 22 of the information terminal 20 causes the communication unit 21 to transmit the server certificate to the control device 50 (S21).
[0112] Furthermore, the transmission power measurement unit 26 of the information terminal 20 measures the transmission power of a wireless communication signal (e.g., a wireless communication signal including a server certificate) whose received signal strength is to be measured (S71). The information processing unit 22 causes the communication unit 21 to transmit transmission power information indicating the measured transmission power to the control device 50 (S72). That is, the communication unit 21 transmits the transmission power information to the control device 50. Note that the processes of steps S71 and S72 may be omitted.
[0113] The measuring unit 55 of the control device 50 measures the received signal strength of the wireless communication signal received by the communication unit 51 and including the server certificate (S73). The control unit 52 determines whether the measured received signal strength exceeds a threshold (S74). The threshold is stored in the storage unit 53, for example.
[0114] When the communication unit 51 receives transmission power information from the information terminal 20 through the processes of steps S71 and S72, the control unit 52 can make a determination in step S74 after correcting the received signal strength, for example, by normalizing it with the transmission power. If the received signal strength is corrected with the transmission power in this way, the control unit 52 can more accurately determine the received signal strength.
[0115] If it is determined in step S74 that the measured received signal strength is equal to or less than the threshold, it is possible that the information terminal 20 is somewhat far from the control device 50 and the user has no intention of unlocking the door 81. For this reason, the processing from step S22 onwards is not executed.
[0116] On the other hand, if it is determined in step S74 that the measured received signal strength exceeds the threshold, it is considered that the user is located near the control device 50 and intends to unlock the door 81. Therefore, when the control unit 52 determines that the received signal strength exceeds the threshold, it verifies the signature included in the server certificate received in step S21 using the public key B included in the root certificate stored in the storage unit 53 (S22). Thereafter, the same processes as steps S23 to S29 in Fig. 5 are performed, and the unlock token is stored as a common key in each of the information terminal 20 and the control device 50.
[0117] When the user approaches the door 81, the user performs a predetermined unlocking operation on the operation reception unit 54 of the control device 50 to unlock the electric lock 60. When the operation reception unit 54 receives the unlocking operation (S75), the measurement unit 55 measures the received signal strength of the wireless communication signal that is transmitted by the information terminal 20 and received by the communication unit 51 (S76), and the control unit 52 determines whether the measured received signal strength exceeds a threshold value (S77). The threshold value is stored in the storage unit 53, for example.
[0118] In step S76, the measurement unit 55 may measure the received signal strength of any wireless communication signal transmitted by the communication unit 21 of the information terminal 20, which may be, for example, a status notification signal from the information terminal 20. In step S77, a determination may be made based on the received signal strength of a wireless communication signal received immediately before or immediately after step S75, and the processes of steps S76 and S77 may be executed immediately before step S75.
[0119] If it is determined in step S77 that the measured received signal strength is equal to or less than the threshold, it is possible that the information terminal 20 is somewhat far from the control device 50 and the user has no intention of unlocking the door 81. For this reason, the processing from step S30 onwards is not executed.
[0120] On the other hand, if it is determined in step S77 that the measured received signal strength exceeds the threshold, it is considered that the user is located near the control device 50 and intends to unlock the door 81.
[0121] Therefore, when the control unit 52 determines that the measured received signal strength exceeds the threshold, the control unit 52 causes the communication unit 51 to transmit an unlocking permission request to the information terminal 20 (S78).
[0122] The processing of steps S76 to S78 is performed on the condition that the processing of steps S41 to S48 (challenge-response authentication) has been successful at the time the unlocking operation is accepted by the operation acceptance unit 54 (at the time of step S75).
[0123] The communication unit 21 of the information terminal 20 receives the unlocking permission request. In response to the received unlocking permission request, the information processing unit 22 causes the communication unit 21 to transmit an unlocking permission command to the control device 50 (S30). That is, the communication unit 21 transmits the unlocking permission command to the control device 50.
[0124] The communication unit 51 of the control device 50 receives the unlocking permission command. The control unit 52 unlocks the electric lock 60 based on the received unlocking permission command (S31).
[0125] In this way, the information processing system 10 can safely unlock the electric lock 60 by performing public key authentication when the user is located near the control device 50 and is considered to have the intention to unlock the door 81. The threshold value for the received signal strength may be set to an appropriate value empirically or experimentally based on the installation conditions of the control device 50, etc.
[0126] In Example 3, where the server certificate is used to unlock the electric lock, public key authentication is started before the user performs the unlocking operation, and public key authentication is completed by the time the user performs the unlocking operation. This significantly reduces the time it takes for the electric lock 60 to be unlocked after the user performs the unlocking operation.
[0127] The processing of steps S78 and S30 may be omitted, and the control unit 52 may unlock the electric lock 60 when it determines that the received signal strength measured in step S77 exceeds the threshold value.
[0128] [Example 3 of operation for unlocking electric lock using unlock token] Next, an example 3 of operation for unlocking the electric lock 60 using an unlock token will be described. Fig. 11 is a sequence diagram of the example 3 of operation for unlocking the electric lock 60 using an unlock token.
[0129] The information processing unit 22 of the information terminal 20 starts (executes) the application when the user performs an operation to start the application (S16).
[0130] The control unit 52 of the control device 50 causes the communication unit 51 to transmit a beacon signal to notify the presence of the control device 50 (S17).
[0131] When the beacon signal is received by the communication unit 21 of the information terminal 20, the information processing unit 22 of the information terminal 20 (or the control unit 52 of the control device 50) establishes a wireless communication connection between the information terminal 20 (communication unit 21) and the control device 50 (communication unit 51) (S19).
[0132] After the wireless communication connection is established, the information processing unit 22 of the information terminal 20 causes the communication unit 21 to transmit a challenge value request to the control device 50 (S41). That is, the communication unit 21 transmits the challenge value request to the control device 50.
[0133] Furthermore, the transmission power measurement unit 26 of the information terminal 20 measures the transmission power of a wireless communication signal (e.g., a wireless communication signal corresponding to a challenge value request) whose received signal strength is to be measured (S71). The information processing unit 22 causes the communication unit 21 to transmit transmission power information indicating the measured transmission power to the control device 50 (S72). That is, the communication unit 21 transmits the transmission power information to the control device 50. Note that the processes of steps S71 and S72 may be omitted.
[0134] The measuring unit 55 of the control device 50 measures the received signal strength of the wireless communication signal received by the communication unit 51 and corresponding to the challenge value request (S73). The control unit 52 determines whether the measured received signal strength exceeds a threshold value (S74). The threshold value is stored in the storage unit 53, for example.
[0135] When the communication unit 51 receives transmission power information from the information terminal 20 through the processes of steps S71 and S72, the control unit 52 can make a determination in step S74 after correcting the received signal strength, for example, by normalizing it with the transmission power. If the received signal strength is corrected with the transmission power in this way, the control unit 52 can more accurately determine the received signal strength.
[0136] If it is determined in step S74 that the measured received signal strength is equal to or less than the threshold, it is possible that the information terminal 20 is somewhat far from the control device 50 and the user has no intention of unlocking the door 81. For this reason, the processing from step S42 onwards is not executed.
[0137] On the other hand, if it is determined in step S74 that the measured received signal strength exceeds the threshold, it is assumed that the user is located near the control device 50 and intends to unlock the door 81. Therefore, when the control unit 52 determines that the received signal strength exceeds the threshold, it confirms that a valid unlock token for the information terminal 20 is stored in the storage unit 53 in response to the challenge value request received in step S41 (S42). Thereafter, the same processes as steps S43 to S48 in Fig. 6 are performed. The subsequent processes are the same as in Example 2 of the operation for unlocking the electric lock 60 using a server certificate, and therefore a description thereof will be omitted.
[0138] In this way, when the information processing system 10 determines that the user is located near the control device 50 and intends to unlock the door 81, and the unlock token is shared, it can quickly and safely unlock the electric lock 60 by performing challenge-response authentication. The threshold value for the received signal strength may be set to an appropriate value empirically or experimentally based on the installation conditions of the control device 50, etc.
[0139] In Example 3, in which the electric lock is unlocked using an unlocking token, challenge-response authentication is started before the user performs the unlocking operation, and the challenge-response authentication is completed by the time the user performs the unlocking operation. This significantly reduces the time from when the user performs the unlocking operation until the electric lock 60 is unlocked.
[0140] The processing of steps S78 and S30 may be omitted, and the control unit 52 may unlock the electric lock 60 when it determines that the received signal strength measured in step S77 exceeds the threshold value.
[0141] In addition, in example 3 of the operation of unlocking the electric lock 60 using an unlocking token, if a valid unlocking token is not stored in the storage unit 23 in step S42, or if it is determined in step S47 that the response value does not match the reference value, the processing of steps S21 to S29 may be executed. In other words, if the challenge-response authentication fails, the electric lock 60 may be unlocked and the unlocking token may be shared again based on public key authentication.
[0142] [Modification] In the above embodiment, an example has been described in which a user unlocks or locks the electric lock 60 using the information terminal 20. Here, in each of the above-mentioned operation examples, an administrator or the like may unlock or lock the electric lock 60 using the management terminal 30. For example, in each of the above-mentioned operation examples, the information terminal 20, communication unit 21, information processing unit 22, memory unit 23, operation reception unit 24, measurement unit 25, transmission power measurement unit 26, and display unit 27 may be replaced with the management terminal 30, communication unit 31, information processing unit 32, memory unit 33, operation reception unit 34, measurement unit 35, transmission power measurement unit 36, and display unit 37.
[0143] When the electric lock 60 is unlocked using the information terminal 20, the server certificate includes the public key A and a signature generated using the private key B, but when the electric lock 60 is unlocked using the management terminal 30, the server certificate includes the public key B and a signature generated using the private key B. The management terminal 30 can also be considered as an information terminal 20 that has the function of issuing server certificates to other information terminals.
[0144] In the above embodiment, an example has been described in which the control unit 52 of the control device 50 generates an unlock token and the communication unit 51 transmits the generated unlock token to the information terminal 20, thereby sharing the unlock token. However, the unlock token may also be shared by the information processing unit 22 of the information terminal 20 generating an unlock token and the communication unit 21 transmitting the generated unlock token to the control device 50. In other words, the control unit 52 may cause the information terminal 20 to generate an unlock token by transmitting an unlock token request to the information terminal 20 using the communication unit 51, and may share the unlock token with the information terminal 20 by receiving the generated unlock token using the communication unit 51.
[0145] The unlocking token may be shared between the control device 50 and the information terminal 20 by performing information processing based on a key sharing protocol such as Diffie-Hellman (DH). In other words, the control unit 52 of the control device 50 may share the unlocking token with the information terminal 20 by executing information processing based on the key sharing protocol.
[0146] In the above embodiment, the electric lock 60 locks or unlocks the door 81, but the electric lock 60 may also be an electric lock that locks and unlocks the door of an electrically assisted bicycle, a delivery box, a coin locker, or a safe deposit box.
[0147] Furthermore, the control target of the control device 50 is not limited to the electric lock 60. The control device 50 may control any device that releases restrictions on the operation of an item. For example, the control target of the control device 50 may be an automatic door. The information processing system 10 can also be applied to cases where only specific individuals are permitted to control home appliances such as lighting devices and air conditioners.
[0148] In the above embodiment, the usage conditions are included in the server certificate. However, the usage conditions may be transmitted from the information terminal 20 or the management terminal 30 to the control device 50 in a secure manner, separately from the server certificate.
[0149] For example, in examples 1 to 3 of the operation of unlocking an electric lock using a server certificate, the usage conditions may be transmitted from the information terminal 20 to the control device 50 together with the signature of the management terminal 30 by encrypted communication using a session key (performed after step S23). By separating the server certificate and the usage conditions, it becomes possible to flexibly add or change the usage conditions without reissuing the server certificate.
[0150] In the above embodiment, an example was described in which the challenge value is a random number that is difficult to guess, and the response value is a hash value generated from the unlocking token and the challenge value.However, the challenge value may also be a value in which the random number that is difficult to guess is encrypted with the unlocking token, and the response value is a value in which the challenge value is decrypted with the unlocking token.
[0151] In the above embodiment, an example has been described in which the information terminal 20 determines whether the received signal strength of a wireless communication signal exceeds a threshold, and an example has been described in which the control device 50 determines whether the received signal strength of a wireless communication signal exceeds a threshold. However, both the information terminal 20 and the control device 50 may determine whether the received signal strength of a wireless communication signal exceeds a threshold.
[0152] In examples 1 to 3 of the operation of unlocking an electric lock using a server certificate according to the above embodiment, the control device 50 (control unit 52) may transmit pseudo information including a random number to the information terminal 20 after transmitting the server certificate in step S19, and the information terminal 20 may sign the received pseudo information using the private key A and transmit the signed information to the control device 50. After step S18 and before step S21, the control device 50 verifies the signature received from the information terminal 20 using the public key A included in the server certificate, thereby making it possible to prevent the certificate from being stolen.
[0153] In the examples 1 to 3 of the operation of unlocking an electric lock using a server certificate according to the above embodiment, the control device 50 (controller 52) may verify the ID of the control device 50 contained in the server certificate in step S20. This prevents the certificate for another control device from being reused.
[0154] In the above embodiment, an example has been described in which the user operates the operation acceptance unit 54 of the control device 50 to accept the user's unlocking operation. Although not illustrated in the above embodiment, the unlocking operation may be accepted by the operation acceptance unit 24 of the information terminal 20, and the information terminal 20 may notify the control device 50 that the unlocking operation has been performed.
[0155] [Effects, etc.] Hereinafter, examples of inventions obtained from the disclosure of this specification will be described, and effects, etc. obtained from the exemplified inventions will be explained.
[0156] Invention 1 is an information processing system 10 used to release restrictions on equipment that restricts the operation of an item, comprising an information terminal 20 and a control device 50, wherein the information terminal 20 has a memory unit 23 in which a private key A, a public key A corresponding to the private key A, and a server certificate are stored, and a communication unit 21 that transmits the server certificate to the control device 50, wherein the server certificate includes a public key and a signature for the public key, and the control device 50 has a memory unit 53 in which a root certificate including the public key is stored, a communication unit 51 that receives the server certificate from the information terminal 20, and a control unit 52 that verifies the signature included in the server certificate using the public key included in the root certificate and shares an unlocking token with the information terminal 20 if the verification is successful, wherein the communication unit 51 transmits a challenge value to the information terminal 20 after the unlocking token has been shared, and the communication unit 21 transmits a response value generated based on the received challenge value and unlocking token to the control device 50, and the control unit 52 releases the restriction on the equipment if the verification of the response value received by the communication unit 51 is successful. The private key A, the public key A, the memory unit 23, the communication unit 21, the memory unit 53, the communication unit 51, and the unlocking token are examples of the first private key, the first public key, the first memory unit, the first communication unit, the second memory unit, the second communication unit, and the common key. The predetermined release operation corresponds to the predetermined unlocking operation in the above embodiment, and in the above embodiment, releasing the restriction on the device means unlocking the electric lock 60.
[0157] By using public key authentication, such an information processing system 10 can safely share an unlock token between the information terminal 20 and the control device 50, and can perform challenge-response authentication based on the unlock token when a release operation is performed. Since challenge authentication requires less time for authentication than public key authentication, the information processing system 10 can reduce the time from when a user performs a release operation until device restrictions are released, compared to systems that perform public key authentication when a release operation is performed.
[0158] Invention 2 is the information processing system 10 of Invention 1, in which the signature is generated using private key A, and the public key included in the root certificate is public key A. Invention 2 corresponds to the case in which the information terminal 20 of Invention 1 has a function of issuing server certificates to other information terminals.
[0159] Such an information processing system 10 can safely and quickly release restrictions on devices using an information terminal 20 that can issue server certificates to other information terminals. By performing challenge-response authentication based on an unlocking token during a release operation, the information processing system 10 can reduce the time from when a user performs a release operation until the device restrictions are released, compared to systems that perform public key authentication during a release operation.
[0160] Invention 3 is the information processing system 10 of Invention 1, in which the signature is generated using private key B different from private key A, and the public key included in the root certificate is public key B corresponding to private key B. Private key B and public key B are examples of a second private key and a second public key.
[0161] Such an information processing system 10 can safely and quickly release restrictions on devices using the information terminal 20 that receives a server certificate from the management terminal 30. When a release operation is performed, the information processing system 10 performs challenge-response authentication based on an unlocking token, thereby reducing the time from when a user performs a release operation until the device restrictions are released compared to a system that performs public key authentication when a release operation is performed.
[0162] Invention 4 is an information processing system 10 of any of Inventions 1 to 3, in which the control unit 52 generates an unlocking token and shares the unlocking token with the information terminal 20 by having the communication unit 51 transmit the generated unlocking token to the information terminal 20.
[0163] In such an information processing system 10 , the unlocking token generated by the control device 50 is transmitted to the information terminal 20 , thereby enabling the unlocking token to be shared between the information terminal 20 and the control device 50 .
[0164] Invention 5 is an information processing system 10 of any of Inventions 1 to 3, in which the control unit 52 causes the information terminal 20 to generate an unlocking token, and receives the generated unlocking token using the communication unit 51, thereby sharing the unlocking token with the information terminal 20.
[0165] In such an information processing system 10 , the unlocking token generated by the information terminal 20 is transmitted to the control device 50 , thereby enabling the unlocking token to be shared between the information terminal 20 and the control device 50 .
[0166] A sixth aspect of the present invention is the information processing system 10 of any one of the first to third aspects of the present invention, wherein the control unit 52 shares the unlocking token with the information terminal 20 by executing information processing based on a key sharing protocol.
[0167] Such an information processing system 10 allows the control device 50 and the information terminal 20 to share the unlocking token more safely.
[0168] Invention 7 is an information processing system 10 of any of Inventions 1 to 3, in which the information terminal 20 has a measurement unit 25 that measures a first received signal strength of a wireless communication signal received by the communication unit 21 from the control device 50, and the communication unit 21 transmits a response value to the control device 50 on the condition that the measured first received signal strength exceeds a first threshold value.
[0169] Such an information processing system 10 transmits a response value to the control device 50 on the condition that the measured first received signal strength exceeds a first threshold value, thereby enabling the restriction on the device to be lifted more safely while preventing fraud by third parties.
[0170] Invention 8 is the information processing system 10 of any of Inventions 1 to 3, wherein the information terminal 20 has a measurement unit 25 that measures a first received signal strength of a wireless communication signal received by the communication unit 21 from the control device 50, and the communication unit 21 transmits information for releasing the restriction to the control device 50 on the condition that the control device 50 has successfully verified the response value at the timing when the release operation is accepted and the measured first received signal strength exceeds a second threshold. The information for releasing the restriction is the unlock permission command of the above embodiment.
[0171] Such an information processing system 10 can more safely release restrictions on equipment while preventing fraudulent activity by third parties by sending an unlocking permission command to the control device 50 on the condition that the measured first received signal strength exceeds a second threshold value.
[0172] Invention 9 is an information processing system 10 of any of Inventions 1 to 3, in which the control device 50 has a measurement unit 55 that measures a second received signal strength of a wireless communication signal received by the communication unit 51 from the information terminal 20, and the control unit 52 verifies the response value on the condition that the measured second received signal strength exceeds a third threshold.
[0173] Such an information processing system 10 can more safely remove restrictions on devices while preventing fraudulent activity by third parties by sending a server certificate to the control device 50 on the condition that the measured second received signal strength exceeds a third threshold value.
[0174] Invention 10 is an information processing system 10 of any of Inventions 1 to 3, in which the control device 50 has a measurement unit 55 that measures the second received signal strength of the wireless communication signal received by the communication unit 51 from the information terminal 20, and the control unit 52 releases the restriction on the device under the condition that the verification of the response value is successful at the time the release operation is accepted and the measured second received signal strength exceeds a fourth threshold.
[0175] Such an information processing system 10 can lift restrictions on devices more safely while preventing fraudulent activity by third parties by providing a condition that the measured second received signal strength exceeds a fourth threshold value.
[0176] Invention 11 is the information processing system 10 of Invention 9 or 10, in which the information terminal 20 further has a transmission power measurement unit 26 that measures the transmission power of the wireless communication signal, the communication unit 21 transmits transmission power information indicating the measured transmission power to the control device 50, the communication unit 51 receives the transmission power information from the information terminal 20, and the control unit 52 corrects the second received signal strength based on the transmission power information.
[0177] Such an information processing system 10 can more accurately determine the second received signal strength.
[0178] Invention 12 is a control device 50 that releases restrictions on equipment that restricts the operation of an item, and includes: a memory unit 53 in which a root certificate including a public key is stored; a communication unit 51 that receives a server certificate including the public key A and a signature for the public key A from an information terminal 20 that has a memory unit 23 in which a private key A, a public key A corresponding to the private key A, and a server certificate is stored; and a control unit 52 that verifies the signature included in the server certificate using the public key included in the root certificate and shares an unlocking token with the information terminal 20 if the verification is successful. After the unlocking token is shared, the communication unit 51 transmits a challenge value to the information terminal 20, and the information terminal 20 transmits a response value generated based on the received challenge value and unlocking token to the control device 50. The control device 50 releases the restrictions on the equipment if the verification of the response value received by the communication unit 51 is successful.
[0179] Such a control device 50 can reduce the time it takes for the restriction on the device to be lifted after the user performs the lifting operation.
[0180] Invention 13 is an information processing method executed by an information processing system 10 used to release restrictions on a device that restricts the operation of an item, the information processing system 10 including an information terminal 20 and a control device 50, the information terminal 20 including a storage unit 23 storing a private key A, a public key A corresponding to the private key A, and a server certificate, the server certificate including the public key A and a signature for the public key A, the control device 50 including a storage unit 53 storing a root certificate including the public key, the information processing method including the steps of the information terminal 20 transmitting the server certificate to the control device 50, and the control device 50 receiving a command from the information terminal 20. the control device 50 verifies the signature included in the server certificate using a public key included in the root certificate and shares an unlocking token with the information terminal 20 if the verification is successful; the control device 50 transmits a challenge value to the information terminal 20 after the unlocking token has been shared; the information terminal 20 transmits a response value generated based on the received challenge value and unlocking token to the control device 50; and the control device 50 releases restrictions on the device if the verification of the received response value is successful.
[0181] Such an information processing method can shorten the time it takes from when the user performs the cancellation operation until the restriction on the device is cancelled.
[0182] Invention 14 is an information processing method executed by a control device 50 that releases restrictions on equipment that restricts the operation of an item, wherein the control device 50 has a memory unit 53 in which a root certificate including a public key is stored, and the information processing method includes the steps of receiving a server certificate including public key A and a signature for public key A from an information terminal 20 that has a memory unit 23 in which a private key A, a public key A corresponding to the private key A, and a server certificate are stored; verifying the signature included in the server certificate using the public key included in the root certificate, and sharing an unlocking token with the information terminal 20 if the verification is successful; transmitting a challenge value to the information terminal 20 after the unlocking token has been shared; receiving a response value sent by the information terminal 20, which is generated by the information terminal 20 based on the challenge value and unlocking token received by the information terminal 20; and releasing the restrictions on the equipment if the verification of the received response value is successful.
[0183] Such an information processing method can shorten the time it takes from when the user performs the cancellation operation until the restriction on the device is cancelled.
[0184] A fifteenth aspect of the present invention is a program for causing a computer to execute the information processing method of the thirteenth or fourteenth aspect of the present invention.
[0185] According to such a program, the computer can reduce the time it takes for the restriction on the device to be lifted after the user performs the lifting operation.
[0186] Although the embodiments have been described above, the present invention is not limited to the above-described embodiments.
[0187] For example, in the above embodiment, the information processing system is realized by multiple devices, but it may also be realized as a single device. For example, the information processing system may be realized as a single device corresponding to any of an information terminal, a management terminal, and a control device. When the information processing system is realized by multiple devices, the components (especially functional components) of the information processing system may be allocated in any way among the multiple devices.
[0188] In the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. The order of multiple processing operations may be changed, or multiple processing operations may be performed in parallel.
[0189] In the above-described embodiments, each component may be realized by executing a software program suitable for that component, or by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0190] Furthermore, each component may be realized by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or each may be a separate circuit. Furthermore, each of these circuits may be a general-purpose circuit or a dedicated circuit.
[0191] Furthermore, the general or specific aspects of the present invention may be realized as a system, an apparatus, a method, an integrated circuit, a computer program, or a computer-readable recording medium such as a CD-ROM, etc. Furthermore, the general or specific aspects of the present invention may be realized as any combination of a system, an apparatus, a method, an integrated circuit, a computer program, and a recording medium.
[0192] For example, the present invention may be realized as the information terminal, management terminal, control device, or electric lock system (control device and electric lock) of the above-described embodiments.
[0193] The present invention may also be realized as an information processing method executed by a computer such as the information processing system, information terminal, management terminal, or control device of the above-described embodiments. The present invention may also be realized as a program for causing a computer to execute the information processing method. The present invention may also be realized as a computer-readable non-transitory recording medium on which such a program is recorded.
[0194] The present invention may also be realized as an application program for causing a general-purpose information terminal to function as the information terminal or management terminal of the above-described embodiment, or as a computer-readable non-transitory recording medium on which such an application program is recorded.
[0195] In addition, the present invention also includes forms obtained by applying various modifications to each embodiment that a person skilled in the art would think of, or forms realized by arbitrarily combining the components and functions of each embodiment within the scope of the present invention.
[0196] REFERENCE SIGNS LIST 10 Information processing system 20 Information terminal 21, 31, 51 Communication unit 22, 32 Information processing unit 23, 33, 53 Storage unit 24, 34, 54 Operation reception unit 25, 35, 55 Measurement unit 26, 36 Transmission power measurement unit 27, 37 Display unit 30 Management terminal 50 Control device 52 Control unit 60 Electric lock 80 Facility 81 Door
Claims
1. An information processing system used to remove restrictions on a device that restricts the operation of an item, comprising: an information terminal; and a control device, wherein the information terminal has: a first memory unit that stores a first private key, a first public key corresponding to the first private key, and a server certificate; and a first communication unit that transmits the server certificate to the control device, wherein the server certificate includes the first public key and a signature for the first public key; the control device has: a second memory unit that stores a root certificate including a public key; a second communication unit that receives the server certificate from the information terminal; and a control unit that verifies the signature included in the server certificate using the public key included in the root certificate and shares a common key with the information terminal if the verification is successful, wherein the second communication unit transmits a challenge value to the information terminal after the common key has been shared, and the first communication unit transmits a response value generated based on the received challenge value and the common key to the control device, and the control unit releases the restriction on the device if verification of the response value received by the second communication unit is successful.
2. The information processing system according to claim 1, wherein the signature is a signature generated using the first private key, and the public key included in the root certificate is the first public key.
3. The information processing system according to claim 1, wherein the signature is generated using a second private key different from the first private key, and the public key included in the root certificate is a second public key corresponding to the second private key.
4. An information processing system according to any one of claims 1 to 3, wherein the control unit generates the common key and causes the second communication unit to transmit the generated common key to the information terminal, thereby sharing the common key with the information terminal.
5. An information processing system according to any one of claims 1 to 3, wherein the control unit causes the information terminal to generate the common key and receives the generated common key using the second communication unit, thereby sharing the common key with the information terminal.
6. The information processing system according to any one of claims 1 to 3, wherein the control unit shares the common key with the information terminal by executing information processing based on a key sharing protocol.
7. An information processing system according to any one of claims 1 to 3, wherein the information terminal has a first measurement unit that measures a first received signal strength of a wireless communication signal received by the first communication unit from the control device, and the first communication unit transmits the response value to the control device on the condition that the measured first received signal strength exceeds a first threshold value.
8. An information processing system according to any one of claims 1 to 3, wherein the information terminal has a first measurement unit that measures a first received signal strength of a wireless communication signal received by the first communication unit from the control device, and the first communication unit transmits information to the control device to release the restriction, provided that the control device has successfully verified the response value at the time the release operation is accepted and the measured first received signal strength exceeds a second threshold value.
9. An information processing system according to any one of claims 1 to 3, wherein the control device has a second measurement unit that measures a second received signal strength of the wireless communication signal received by the second communication unit from the information terminal, and the control unit verifies the response value on the condition that the measured second received signal strength exceeds a third threshold.
10. The information processing system according to any one of claims 1 to 3, wherein the control device has a second measurement unit that measures a second received signal strength of the wireless communication signal received by the second communication unit from the information terminal, and the control unit releases the restriction on the device on the condition that the verification of the response value is successful at the time the release operation is accepted and the measured second received signal strength exceeds a fourth threshold.
11. The information processing system according to claim 9, wherein the information terminal has a transmission power measurement unit that measures the transmission power of the wireless communication signal, the first communication unit transmits transmission power information indicating the measured transmission power to the control device, the second communication unit receives the transmission power information from the information terminal, and the control unit corrects the second received signal strength based on the transmission power information.
12. A control device that removes restrictions on equipment that restricts the operation of an item, comprising: a memory unit in which a root certificate including a public key is stored; a communication unit that receives a server certificate including a first public key and a signature for the first public key from an information terminal having a first memory unit in which a first private key, a first public key corresponding to the first private key, and a server certificate are stored; and a control unit that verifies the signature included in the server certificate using the public key included in the root certificate and shares a common key with the information terminal if the verification is successful, wherein the communication unit transmits a challenge value to the information terminal after the common key is shared, and the information terminal transmits a response value generated based on the received challenge value and the common key to the control device, and the control unit releases the restriction on the equipment if verification of the response value received by the communication unit is successful.
13. An information processing method executed by an information processing system used to release restrictions on equipment that restricts the operation of an item, the information processing system comprising: an information terminal; and a control device; the information terminal comprising a first storage unit in which a first private key, a first public key corresponding to the first private key, and a server certificate are stored; the server certificate includes the first public key and a signature for the first public key; and the control device comprising a second storage unit in which a root certificate including a public key is stored; the information processing method comprises the steps of: the information terminal transmitting the server certificate to the control device; the control device receiving the server certificate from the information terminal; the control device verifying the signature included in the server certificate using the public key included in the root certificate, and sharing a common key with the information terminal if the verification is successful; the control device transmitting a challenge value to the information terminal after the common key has been shared; and the information terminal transmitting a response value generated based on the received challenge value and the common key to the control device. and when the control device has successfully verified the received response value, releasing the restriction on the device.
14. An information processing method executed by a control device that removes restrictions on equipment that restricts the operation of an item, wherein the control device has a memory unit in which a root certificate including a public key is stored, the information processing method comprising the steps of: receiving a server certificate including a first public key and a signature for the first public key from an information terminal having a first memory unit in which a first private key, a first public key corresponding to the first private key, and a server certificate are stored; verifying the signature included in the server certificate using the public key included in the root certificate, and sharing a common key with the information terminal if the verification is successful; transmitting a challenge value to the information terminal after the common key has been shared; receiving a response value transmitted by the information terminal, the response value being generated by the information terminal based on the challenge value and the common key received by the information terminal; and releasing the restriction on the equipment if verification of the received response value is successful.
15. A program for causing a computer to execute the information processing method according to claim 13 or 14.
Citation Information
Patent Citations
A method for characterizing distance in inductively coupled access systems.
JP2010516925A
Authentication system
JP2012100188A
Electric lock control system, electric lock system, control method for electric lock control system, and program
JP2019044462A