Authentication device, authentication method, and program
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-01-21
- Publication Date
- 2026-08-13
Smart Images

Figure JP2026001849_13082026_PF_FP_ABST
Abstract
Description
Authentication Device, Authentication Method, and Program
[0001] The present invention relates to an authentication device that receives an authentication request transmitted from an authentication target device and performs processes such as authentication.
[0002] Conventionally, an authentication device that receives an authentication request transmitted from an authentication target device and performs authentication is known (see, for example, Patent Document 1). By performing authentication using such an authentication request, for example, hands-free authentication that does not require an operation by a user can be performed.
[0003] It is also possible to receive a signal transmitted from the authentication target device and determine whether the authentication target device is included in a specific area (see, for example, Patent Document 2). Therefore, for example, it is possible to receive an authentication request transmitted from the authentication target device, perform authentication of the authentication target device, and also determine whether the authentication target device is included in a predetermined area.
[0004] International Publication No. 2020 / 080301 International Publication No. 2020 / 080314
[0005] When receiving an authentication request transmitted from an authentication target device, performing authentication of the authentication target device, and determining whether the authentication target device is included in a predetermined area in a plurality of areas, it was necessary to arrange a plurality of receivers for each area. For example, when performing authentication of the authentication target device and determination regarding the position of the authentication target device at the entrance and elevator hall of a building, it was necessary to arrange a plurality of receivers at the entrance and also arrange a plurality of receivers at the elevator hall.
[0006] As described above, as the number of areas for performing authentication of the authentication target device and determination regarding the position of the authentication target device increases, the number of receivers to be arranged accordingly increases, resulting in a problem of high cost.
[0007] The present invention has been made to solve the above problems, and an object thereof is to provide an authentication device or the like that can perform authentication of an authentication target device and determination regarding the position in a plurality of areas using a smaller number of receivers.
[0008] To achieve the above objective, an authentication device according to one aspect of the present invention comprises: first to N sets of receivers, each including one or more receivers that receive an authentication request transmitted from a device to be authenticated, which includes authentication information used for authenticating the device to be authenticated; an authentication unit that performs device authentication, determining whether the device that transmitted the authentication request is legitimate, using the authentication information included in the authentication request received by at least one of the one or more receivers included in the first to N sets of receivers; a determination unit that performs region determination, determining whether the location of the device to be authenticated is included in the first and second regions based on the difference in the intensity of the authentication requests received by at least two sets of receivers in the first to N sets of receivers; and an output unit that outputs the results of device authentication and the results of region determination, wherein N is 2 or more, and at least two sets of receivers used for region determination regarding the first region and at least two sets of receivers used for region determination regarding the second region include at least the same set of receivers. With this configuration, at least one set of receivers can be used for region determination of both the first and second regions. As a result, the number of receiver sets can be reduced compared to the case where two or more different receiver sets are used for each region determination related to the first and second regions.
[0009] Furthermore, in an authentication device according to one aspect of the present invention, the first position where the first receiver set is arranged may be included in the first region in a plan view, and the second position where the second receiver set is arranged may be included in the second region in a plan view. With this configuration, for the first region, region determination can be performed using the first receiver set arranged within the first region in a plan view and the other receiver sets, and for the second region, region determination can be performed using the second receiver set arranged within the second region in a plan view and the other receiver sets.
[0010] Furthermore, in an authentication device according to one aspect of the present invention, the determination unit may use at least the difference in strength of the authentication requests received by the first and second receiver sets when determining whether the device to be authenticated is included in the first area and when determining whether the device to be authenticated is included in the second area. With this configuration, the number of receiver sets can be reduced by using the same first and second receiver sets in both the area determination of the first and second areas.
[0011] Furthermore, in an authentication device according to one aspect of the present invention, N is 3 or more, and the determination unit may use at least the difference in strength of the authentication requests received by the first and third receiver sets when determining whether the device to be authenticated is included in the first area, and may use at least the difference in strength of the authentication requests received by the second and third receiver sets when determining whether the device to be authenticated is included in the second area. With this configuration, the number of receiver sets can be reduced by using the same third receiver set in the area determination for both the first and second areas.
[0012] Furthermore, an authentication method according to one aspect of the present invention is an authentication method processed using a first to Nth receiver set including one or more receivers, an authentication unit, a determination unit, and an output unit, wherein N is two or more, and the method comprises the steps of: at least two receiver sets in the first to Nth receiver sets receive an authentication request transmitted from a device to be authenticated, which includes authentication information used for authenticating the device to be authenticated; the authentication unit performing device authentication, which determines whether the device that sent the authentication request is legitimate, using the authentication information included in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; the determination unit performing a region determination, which determines whether the location of the device to be authenticated is included in the first and second regions, based on the difference in the intensity of the authentication requests received by at least two receiver sets in the step of receiving the authentication request; and the output unit outputting the results of device authentication and the results of the region determination, wherein at least the same receiver set is included in the at least two receiver sets used in the region determination for the first region and the at least two receiver sets used in the region determination for the second region.
[0013] According to one aspect of the present invention, the number of receiver sets can be reduced compared to the case in which two or more different receiver sets are used for each area determination related to the first and second areas.
[0014] Block diagram showing the configuration of the authentication device according to an embodiment of the present invention. Plan view illustrating the arrangement of the first and second regions and the receiver set in the same embodiment. Flowchart showing the operation of the authentication device according to the same embodiment. Block diagram showing an example of another configuration of the authentication device according to the same embodiment. Plan view illustrating another example of the arrangement of the first and second regions and the receiver set in the same embodiment. Plan view illustrating another example of the arrangement of the first and second regions and the receiver set in the same embodiment. Plan view illustrating another example of the arrangement of the first and second regions and the receiver set in the same embodiment. Diagram showing an example of the configuration of the computer system in the same embodiment.
[0015] The authentication device and authentication method according to the present invention will be described below using embodiments. In the following embodiments, components and steps denoted by the same reference numerals are the same or equivalent and may not be described again. The authentication device according to this embodiment performs a region determination to determine whether the device to be authenticated that transmits an authentication request is included in the first and second regions, based on the difference in the intensity of authentication requests received by two or more receiver sets. At least two receiver sets used in the region determination for the first region and at least two receiver sets used in the region determination for the second region include at least the same receiver sets.
[0016] Figure 1 is a block diagram showing the configuration of the authentication device 1 according to this embodiment, and Figure 2 is a plan view showing the arrangement of the first and second regions R1 and R2 and the first and second receiver sets 11 and 12. The authentication device 1 according to this embodiment comprises a first receiver set 11, a second receiver set 12, an authentication unit 21, a determination unit 22, and an output unit 23.
[0017] The authentication device 1 performs device authentication to determine whether the device to be authenticated 2 carried by user 5 is legitimate, and area determination to determine whether the device to be authenticated 2 is included in the first area R1 and the second area R2, and outputs according to the results. Depending on the output, for example, the device may perform processes such as unlocking and opening doors to houses, buildings, conference rooms, hotel rooms, etc., or payment processing for the purchase of goods or services. In this embodiment, as an example, the device authentication will mainly describe a case where, when the location of the device to be authenticated 2 is determined to be legitimate by device authentication and is determined to be included in the first area R1 by area determination, the entrance door 31 of the building will open according to the output of the device authentication and area determination results, and when the location of the device to be authenticated 2 is determined to be legitimate by device authentication and is determined to be included in the second area R2 by area determination, the elevator 32 of the building will operate according to the output of the device authentication and area determination results. Thus, for example, the first area R1 may be set outside the entrance door 31 of the building, and the second area R2 may be set in the elevator hall of the building. The first and second regions R1 and R2 may or may not be visually identifiable in real space. This embodiment will mainly describe the latter case. Furthermore, the planar shapes of the first and second regions R1 and R2 may be, for example, rectangular, circular, or other shapes.
[0018] In Figure 1, user 5 is shown holding the device to be authenticated 2 in their hand. However, for user 5 to be carrying the device to be authenticated 2, it is sufficient if, for example, the device to be authenticated 2 moves in accordance with user 5's movements; user 5 does not necessarily have to be holding the device to be authenticated 2 in their hand. The device to be authenticated 2 may be placed, for example, in user 5's clothing pocket or bag. The same applies to Figure 4, which will be described later. Also, in Figure 1, the authentication device 1 is shown receiving an authentication request from one device to be authenticated 2 carried by one user 5. However, the authentication device 1 may receive authentication requests from multiple devices to be authenticated 2, each carried by multiple users 5.
[0019] The device to be authenticated 2 may be, for example, a smartphone, a tablet device, a PDA (Personal Digital Assistant), a laptop computer, a transceiver, or any other device equipped with communication functions.
[0020] The first receiver set 11 comprises one or more receivers 11a. Each of the one or more receivers 11a receives an authentication request transmitted from the device to be authenticated 2, which includes authentication information used for authenticating the device to be authenticated 2. The device to be authenticated 2 may transmit the authentication request, for example, as radio waves. The first receiver set 11 may be arranged in a first position. The authentication request may include, for example, a user identifier of the user 5 carrying the device to be authenticated 2 that transmits the authentication request, and a device identifier that identifies the device to be authenticated 2. The user identifier may be, for example, the user's telephone number, email address, name, or a string unique to the user. The device identifier may be, for example, the device's address or a string unique to the device. The device's address may be, for example, a physical address such as a MAC address, or another address.
[0021] The second receiver set 12 comprises one or more receivers 12a. Each of the one or more receivers 12a receives an authentication request transmitted from the device to be authenticated 2. The second receiver set 12 may be located in a second position different from the first position. The second receiver set 12 may be the same as the first receiver set 11 except for its location.
[0022] From the viewpoint of achieving more accurate location identification of the device to be authenticated 2, it is preferable that the first receiver set 11 includes a plurality of receivers 11a, and the second receiver set 12 includes a plurality of receivers 12a. As shown in Figure 1, for example, the first receiver set 11 may include four receivers 11a, and the second receiver set 12 may include four receivers 12a, but the number of receivers included in the first and second receiver sets 11 and 12 may be one to three, or five or more. Each receiver 11a, 12a included in the first and second receiver sets 11 and 12 is capable of acquiring the strength of the radio waves for the authentication request.
[0023] If the first receiver set 11 includes a plurality of receivers 11a, the first position may be, for example, the position of the center of gravity of the plurality of receivers 11a. More specifically, the position of the center of gravity of each receiver 11a may be identified, and the position of the center of gravity with respect to the identified plurality of center of gravity positions may be taken as the first position. The plurality of receivers 11a may be arranged in close proximity to each other, or they may be arranged in distant positions. In the latter case, however, it is preferable that the plurality of receivers 11a are within the distance range from the first position to the second position. The same applies to the second position of the second receiver set 12.
[0024] This embodiment mainly describes the case where the authentication device 1 has first and second receiver sets 11 and 12, i.e., two receiver sets, but the authentication device 1 may have first to N receiver sets, where N is an integer of 2 or more. The first to N receiver sets may be arranged at positions 1 to N, respectively. It is preferable that the positions 1 to N are all different. The first to N receiver sets may also be the same as the first and second receiver sets 11 and 12. For example, the K receiver set may include one or more receivers, where K is any integer from 1 to N. In this case, device authentication may be performed using authentication requests received by at least one of the one or more receivers included in the N receiver sets. Furthermore, for each region where region determination is performed, region determination may be performed using the difference in the intensity of authentication requests received by at least two of the N receiver sets.
[0025] As shown in Figure 2, it is preferable that the first region R1 and the second region R2 are different regions. For example, the first region R1 and the second region R2 do not have to contain any regions common to both. Also, as shown in Figure 2, the first receiver set 11 may be positioned closer to the first region R1 than to the second region R2. Similarly, the second receiver set 12 may be positioned closer to the second region R2 than to the first region R1. Here, when we say that the first receiver set 11 is positioned closer to the first region R1 than to the second region R2, it means, for example, that the distance between the first position where the first receiver set 11 is positioned and a representative position in the first region R1 is smaller than the distance between the first position and a representative position in the second region R2. Furthermore, the statement that the second receiver set 12 is positioned closer to the second region R2 than to the first region R1 means, for example, that the distance between the second position where the second receiver set 12 is positioned and a representative position in the second region R2 is smaller than the distance between the second position and a representative position in the first region R1. The representative positions of the first and second regions R1 and R2 may be, for example, the positions of the centroids of those regions.
[0026] Furthermore, as shown in Figure 2, the first position where the first receiver set 11 is located may be included in the first region R1 in a plan view, and the second position where the second receiver set 12 is located may be included in the second region R2 in a plan view. Note that Figure 2 shows the case where the first position is at the center of the first region R1 and the second position is at the center of the second region R2, but this is not required. The first and second positions may be adjusted as appropriate so that the Apollonius circle described later overlaps with the first and second regions R1 and R2. In addition, it is preferable that the first and second receiver sets 11 and 12 be located at a height similar to that of the authentication device 2 carried by the user 5, but if this is difficult, they may be located in a place that does not obstruct the passage of the user 5, such as on the ceiling.
[0027] Furthermore, receivers 11a and 12a may include wireless receiving devices such as antennas for receiving radio waves, or they may not include receiving devices. Also, receivers 11a and 12a may be implemented by hardware, or by software such as drivers for operating the receiving devices.
[0028] The authentication request, which is a radio wave, may be, for example, a pulse wave transmitted intermittently or a continuous wave transmitted continuously. Furthermore, the wireless communication standard used to send and receive the authentication request is not limited. The authentication request may be communicated by, for example, Bluetooth Low Energy (BLE), Bluetooth Basic Rate (BR) / Enhanced Data Rate (EDR), wireless LAN (IEEE 802.11), IEEE 802.15.4 such as ZigBee®, or by other wireless communication standards. The authentication request is preferably sent and received by short-range wireless communication such as BLE, Bluetooth BR / EDR, or wireless LAN.
[0029] The frequency of the radio waves for the authentication request is not particularly limited, but may be, for example, in the range of 300 MHz to 300 GHz. The device to be authenticated 2 may, for example, transmit the authentication request by broadcast or by unicast. It is preferable to transmit the authentication request by broadcast because it is possible to transmit the authentication request without specifying the communication partner. In this embodiment, the case in which the device to be authenticated 2 transmits the authentication request by broadcast will be mainly described. It is preferable for the device to be authenticated 2 to transmit the authentication request without receiving a transmission instruction from the user 5. The device to be authenticated 2 may, for example, transmit the authentication request in response to the reception of a predetermined beacon. The device to be authenticated 2 may, for example, transmit the authentication request only once in response to the reception of this beacon, transmit the authentication request for a predetermined period of time, or, if this beacon is being received, continuously repeat the transmission of the authentication request. This beacon may, for example, be transmitted in the first and second areas R1 and R2, which are areas where authentication using the authentication request is performed. As an example, the authentication device 1 may transmit the beacon. In this case, the authentication device 1 may further include one or more transmitting units that transmit beacons.
[0030] The authentication information included in the authentication request may include any information that can be used to authenticate the device being authenticated 2, but as an example, it may include encrypted information obtained by encrypting unique information. The unique information may include, for example, a time, a random value, a count value, a one-time password, etc. The unique information may also be information specific to the authentication request. That is, the unique information corresponding to the encrypted information included in the authentication request may differ for each authentication request. The unique information may be, for example, information generated by the device being authenticated 2, or information transmitted from the authentication device 1 to the device being authenticated 2. In the latter case, challenge-response authentication may be performed by the authentication device 1. When the unique information is transmitted from the authentication device 1, the authentication device 1 may further include a transmission unit for transmitting the unique information. In this embodiment, the case in which the unique information is generated by the device being authenticated 2 will be mainly described. As with the encrypted information described above, it is preferable that the authentication information includes different information for each authentication request. This is to prevent the authentication information from being reused by a malicious third party. Also, as an example, the encrypted information may be information obtained by encrypting the user identifier and the unique information. In this case, the encrypted information can be considered to be, for example, information that includes a user identifier and authentication information.
[0031] The encryption of unique information may be, for example, symmetric-key encryption or public-key encryption. That is, the encryption key used to encrypt unique information may be, for example, a symmetric key or a public key corresponding to the authentication device 1. If the encryption key is a symmetric key, it is preferable that the authentication device 1 and the authenticated device 2 have the same symmetric key. Furthermore, it is preferable that the symmetric key is different for each authenticated device 2.
[0032] Furthermore, the line of sight between the device to be authenticated 2 and the authentication device 1 may or may not be visible. In the latter case, user 5 may carry the device to be authenticated 2 in, for example, a pocket of their clothing or in a bag.
[0033] The authentication unit 21 performs device authentication by using the authentication information contained in the authentication request received by at least one of the one or more receivers 11a, 12a included in the first and second receiver sets 11, 12 to determine whether the device to be authenticated 2 that sent the authentication request is legitimate. If the authentication device 1 is equipped with N receiver sets, the authentication unit 21 may, for example, use the authentication information contained in the authentication request received by at least one of the one or more receivers included in the N receiver sets to determine whether the device to be authenticated 2 that sent the authentication request is legitimate.
[0034] For example, if the authentication information includes encrypted information in which unique information has been encrypted, the authentication device 1 may determine that the sending device 2 is legitimate if the unique information corresponding to the encrypted information matches the unique information stored in the authentication device 1 that corresponds to the sending device 2 of the authentication information, and determine that the sending device 2 is not legitimate if they do not match. Whether the unique information corresponding to the encrypted information matches the unique information stored in the authentication device 1 may be determined, for example, by whether the unique information obtained by decrypting the encrypted information matches the unique information stored in the authentication device 1, or by whether the encrypted information matches the result of encrypting the unique information stored in the authentication device 1.
[0035] When unique information is acquired in the device being authenticated 2, the unique information stored in the authentication device 1 may be acquired by, for example, the same method as the acquisition of unique information in the device being authenticated 2. Also, when the device being authenticated 2 receives unique information from the authentication device 1, the unique information stored in the authentication device 1 may be, for example, the unique information that the authentication device 1 transmitted to the device being authenticated 2.
[0036] If the cryptographic information contained in the authentication information is encrypted with a common key, the authentication unit 21 may, for example, read the common key stored on a predetermined recording medium in association with the user identifier included in the authentication request together with the authentication information, and decrypt the cryptographic information using the read common key, or it may encrypt the unique information stored in the authentication device 1 using the read common key. If the cryptographic information contained in the authentication information is encrypted with a public key, the authentication unit 21 may, for example, read a private key from a predetermined recording medium and decrypt the cryptographic information using the read private key, or it may read a public key from a predetermined recording medium and encrypt the unique information stored in the authentication device 1 using the read public key.
[0037] The authentication unit 21 may perform device authentication using a single authentication request, or it may perform device authentication using multiple authentication requests received within a predetermined period. For authentication using multiple authentication requests, please refer to, for example, the above-mentioned Patent Document 1.
[0038] The determination unit 22 performs a region determination to determine whether the location of the device to be authenticated 2 is included in the first and second regions R1 and R2, based on the difference in strength of the authentication requests received by the first and second receiver sets 11 and 12. If the authentication device 1 is equipped with N receiver sets, the determination unit 22 may determine whether the location of the device to be authenticated 2 is included in the first and second regions R1 and R2 based, for example, on the difference in strength of the authentication requests received by at least two receiver sets in the first to Nth receiver sets. For example, if two or more receiver sets to be used in the region determination for the first region R1 are predetermined, the determination unit 22 may perform the region determination for the first region R1 using the difference in received strength of the authentication requests received by those two or more receiver sets. Similarly, if two or more receiver sets to be used in the region determination for the second region R2 are predetermined, the determination unit 22 may perform the region determination for the second region R2 using the difference in received strength of the authentication requests received by those two or more receiver sets. In such cases, for example, if no authentication request is received by two or more receiver sets corresponding to the first region R1, a region determination regarding the first region R1 may not be performed. The same applies to the region determination regarding the second region R2. Two or more receiver sets corresponding to the first region R1 refer to two or more receiver sets used in the region determination regarding the first region R1. In this embodiment, the case in which the determination unit 22 uses at least the difference in intensity of the authentication requests received by the first and second receiver sets 11 and 12 when determining whether the device to be authenticated 2 is included in the first region R1 and whether the device to be authenticated 2 is included in the second region R2 will be mainly described.
[0039] The determination unit 22 may, for example, determine the location of the device to be authenticated 2 based on the difference in the intensity of the authentication requests received by the first and second receiver sets 11 and 12, and determine whether the determined location is included in the first and second regions R1 and R2. The difference in the intensity of the authentication requests may be, for example, the difference in the received signal strength indicator (RSSI) of the authentication requests. Also, if the first and second receiver sets 11 and 12 each contain two or more receivers, the difference in intensity may be, for example, the difference in representative values of multiple received signal strengths acquired by two or more receivers in the first and second receiver sets 11 and 12. The representative values may be, for example, the mean, the median, etc. Also, if the first and second receiver sets 11 and 12 contain two or more receivers, it is preferable that the two or more receivers have equivalent performance. For example, it is preferable that the antenna gains of the two or more receivers included in the first receiver set 11 or the second receiver set 12 are the same. In determining the location of the wave source using the intensity difference of the received authentication requests, for example, the received intensity of the authentication requests received by the first and second receiver sets 11 and 12, and the first and second positions which are the locations of the first and second receiver sets 11 and 12, may be used to identify an Apollonius circle or line corresponding to the difference in received intensity, and the position on, on, or within that Apollonius circle may be identified as the position of the device to be authenticated 2, or the position of the device to be authenticated 2 may be identified by other methods.
[0040] Furthermore, the location identified by the determination unit 22 may be, for example, a point-like location, or a linear, planar, or three-dimensional location. The identified location may be, for example, a location in a two-dimensional plane, or a location in three-dimensional space. When identifying a planar location, the determination unit 22 may, for example, determine whether the location of the device to be authenticated 2 is within the first and second regions R1 and R2. In this case, for example, if the intensity difference obtained by subtracting the representative value of the received signal intensity of the second receiver set 12 from the representative value of the received signal intensity of the first receiver set 11 exceeds the first threshold, it may be determined that the location of the device to be authenticated 2 is included in the first region R1. Also, for example, if the intensity difference obtained by subtracting the representative value of the received signal intensity of the first receiver set 11 from the representative value of the received signal intensity of the second receiver set 12 exceeds the second threshold, it may be determined that the location of the device to be authenticated 2 is included in the second region R2. The first and second thresholds may each be predetermined values.
[0041] The method of identifying the location of a wave source using the difference in received radio wave intensity is already publicly known, and a detailed explanation will be omitted. For an example of such a method for identifying the location of a wave source, please refer to the above-mentioned Patent Document 2.
[0042] The determination unit 22 may, after identifying the location of the device to be authenticated 2, determine whether the identified location is included in the first and second regions R1 and R2. If user 5 is carrying the device to be authenticated 2, the location of the device to be authenticated 2 can be considered to be substantially the location of user 5. Therefore, if the determination unit 22 determines that the location of the device to be authenticated 2 is included in the first region R1 or the second region R2, it can be considered that user 5, who is carrying the device to be authenticated 2, is located in the first region R1 or the second region R2. The determination unit 22 may read information indicating the first and second regions R1 and R2 stored in a recording medium (not shown), and use the read information to determine whether the identified location of the device to be authenticated 2 is included in the first and second regions R1 and R2. The information indicating the first and second regions R1 and R2 may, for example, be information indicating the location of the contours of the first and second regions R1 and R2.
[0043] The order of device authentication by the authentication unit 21 and domain determination by the determination unit 22 does not matter. For example, domain determination may be performed after device authentication. In this case, domain determination may be performed only for the authenticated device 2 that was determined to be legitimate in device authentication. Alternatively, device authentication may be performed after domain determination. In this case, device authentication may be performed only for the authenticated device 2 that was determined to be included in the first and second domains R1 and R2 in domain determination. Whether the authenticated device 2 subject to device authentication and the authenticated device 2 subject to domain determination are the same device may be determined, for example, using the user identifier or device identifier included in the authentication request. Furthermore, device authentication and domain determination may be performed independently for the authenticated device 2 that sent the authentication request.
[0044] The output unit 23 outputs information regarding the result of device authentication and the result of area determination. The output unit 23 may output, for example, the result of device authentication itself and the result of area determination itself. Further, for example, when it is determined that the position of the authenticated device 2 determined to be legitimate by device authentication is included in the first area R1 by area determination, the output unit 23 outputs that a legitimate authenticated device 2 exists in the first area R1, and when it is determined that the position of the authenticated device 2 determined to be legitimate by device authentication is included in the second area R2 by area determination, the output unit 23 may output that a legitimate authenticated device 2 exists in the second area R2. Then, depending on the output, for example, processing corresponding to the existence of a legitimate authenticated device 2 in the first area R1 or processing corresponding to the existence of a legitimate authenticated device 2 in the second area R2, such as door unlocking processing, door opening / closing processing, payment processing, etc., may be performed.
[0045] In addition, when a process that requires a user identifier or device identifier corresponding to the authenticated device 2 determined to be legitimate, such as payment processing, is performed, the output unit 23 may also output, for example, the user identifier or device identifier included in the authentication request transmitted from the authenticated device 2 when outputting that a legitimate authenticated device 2 exists in the first area R1 or the second area R2. Then, the information associated with the output user identifier or device identifier may be used, for example, in payment processing or the like. The information associated with the user identifier or the like used in payment processing may be, for example, credit card or electronic money information.
[0046] Further, the output unit 23 may change the output destination according to, for example, the result of device authentication and the result of area determination. For example, when it is determined that a legitimate authenticated device 2 exists in the first area R1, the output unit 23 outputs this fact to a device that performs processing related to the first area R1 (for example, door opening / closing processing of the first area R1), and when it is determined that a legitimate authenticated device 2 exists in the second area R2, the output unit 23 may output this fact to a device that performs processing related to the second area R2 (for example, control processing related to the elevator in the second area R).
[0047] Here, this output may be, for example, display on a display device (such as a liquid crystal display or an organic EL display), transmission via a communication line to a predetermined device, printing by a printer, audio output by a speaker, storage in a recording medium, or delivery to other components. Note that the output unit 23 may include a device that performs output (such as a display device or a printer), or may not include it. Also, the output unit 23 may be realized by hardware, or may be realized by software such as a driver that drives those devices.
[0048] Next, the operation of the authentication device 1 will be described using the flowchart of FIG. 3. (Step S101) The first and second receiver sets 11 and 12 determine whether an authentication request has been received. If an authentication request has been received, the process proceeds to step S102; otherwise, the process of step S101 is repeated until an authentication request is received.
[0049] When device authentication using a plurality of authentication requests is performed, for example, the process of receiving the authentication request in step S101 may be repeated until the reception of the plurality of authentication requests is completed. Then, after the plurality of authentication requests have been received, the process may proceed to step S102.
[0050] (Step S102) The authentication unit 21 performs device authentication using the authentication request received by any one of the first and second receiver sets 11 and 12.
[0051] (Step S103) In the device authentication of step S102, if it is determined that the authenticated device 2 that transmitted the authentication request is legitimate, the process proceeds to step S104; otherwise, the process returns to step S101.
[0052] (Step S104) The determination unit 22 determines whether the location of the device to be authenticated 2 is included in the first region R1 based on the difference in the strength of the authentication requests received by the first and second receiver sets 11 and 12 corresponding to the first region R1. This region determination may be performed, for example, by identifying the location of the device to be authenticated 2 and determining whether the identified location is included in the first region R1. Furthermore, if the authentication request transmitted from the device to be authenticated 2 is not received by at least one of the first and second receiver sets 11 and 12, this region determination may not be performed.
[0053] (Step S105) The determination unit 22 determines whether the location of the device to be authenticated 2 is included in the second region R2 based on the difference in the strength of the authentication requests received by the first and second receiver sets 11 and 12 corresponding to the second region R2. This region determination may be performed, for example, by identifying the location of the device to be authenticated 2 and determining whether the identified location is included in the second region R2. In this case, for example, the determination unit 22 may perform the region determination using the location of the device to be authenticated 2 identified in step S104. Furthermore, if the authentication request transmitted from the device to be authenticated 2 is not received by at least one of the first and second receiver sets 11 and 12, this region determination does not need to be performed. Also, if the determination unit 22 determines, for example, in step S104 that the location of the device to be authenticated 2 is included in the first region R1, it does not need to perform the process in step S105. This is because the location of the device to be authenticated 2 cannot be included in both the first region R1 and the second region R2.
[0054] (Step S106) The output unit 23 determines whether to output the results of the device authentication and the area determination. If output is to be performed, the process proceeds to step S107; otherwise, it returns to step S101. The output unit 23 may, for example, decide to perform output if, in either step S104 or S105, it is determined that the location of the device to be authenticated 2 is included in the first area R1 or the second area R2, and decide not to perform output otherwise.
[0055] (Step S107) The output unit 23 outputs the results of the device authentication and the area determination. Then, the process returns to step S101.
[0056] Note that the order of processing in the flowchart in Figure 3 is just one example, and the order of each step may be changed if similar results can be obtained. For example, the region determination for the second region R2 may be performed first, followed by the region determination for the first region R1. Also, in the flowchart in Figure 3, the process may be terminated by power off or a processing termination interrupt.
[0057] Next, the operation of the authentication device 1 according to this embodiment will be explained using a specific example. In this example, as shown in Figures 1 and 2, the first area R1 is set outside the entrance door 31 of the building, and the second area R2 is set in the elevator hall of the building. When the device to be authenticated 2, which has been determined to be legitimate by the device authentication, is located in the first area R1, the entrance door 31 opens, and when the device to be authenticated 2, which has been determined to be legitimate by the device authentication, is located in the second area R2, the elevator 32 operates.
[0058] First, let's assume that user 5, who is carrying a legitimate device to be authenticated 2, approaches the entrance door 31. The device to be authenticated 2 then receives a beacon transmitted from the authentication device 1, and in response, the device to be authenticated 2 transmits an authentication request. At this point, let's assume that user 5 is located outside the first area R1. The authentication request is received by the first and second receiver sets 11 and 12 of the authentication device 1, and the authentication request is passed to the authentication unit 21. At the same time, the received signal strength of the authentication request from the multiple receivers 11a of the first receiver set 11 and the received signal strength of the authentication request from the multiple receivers 12a of the second receiver set 12 are passed to the determination unit 22 (step S101).
[0059] When the authentication unit 21 receives an authentication request, it performs device authentication using the authentication information contained in the authentication request (step S102). Based on this device authentication, it is determined that the device to be authenticated 2 is legitimate (step S103). Then, the authentication unit 21 sends a message to the output unit 23 indicating that the device to be authenticated 2 is legitimate.
[0060] Upon receiving the received signal strength, the determination unit 22 obtains a representative value of the received signal strength acquired by the multiple receivers 11a and a representative value of the received signal strength acquired by the multiple receivers 12a. Using the difference between these representative values of the received signal strength and the first and second positions, which are the positions of the first and second receiver sets 11 and 12, the determination unit 22 identifies the location of the device to be authenticated 2, determines whether the identified location is included in the first region R1, and passes the determination result to the output unit 23 (step S104). In this case, it is determined that the location of the device to be authenticated 2 is not included in the first region R1. Similarly, the determination unit 22 also determines whether the location of the device to be authenticated 2 is included in the second region R2 and passes the determination result to the output unit 23 (step S105). In this case, it is determined that the location of the device to be authenticated 2 is not included in the second region R2 either. The determination unit 22 may, for example, determine whether the location of the device to be authenticated 2 is included in the first or second region R1, R2 by comparing the difference between representative values of the received signal strength with a first or second threshold.
[0061] Upon receiving the results of device authentication and area determination, the output unit 23 determines whether to output (step S106). In this specific example, it is determined that output should be performed if the authenticated device 2, which has been determined to be legitimate, is located in the first or second area R1 or R2. Therefore, in this case, the output unit 23 will determine not to output.
[0062] Next, suppose user 5, who is carrying a legitimate device to be authenticated 2, enters the first area R1. Then, similar to the process described above, the device is judged to be legitimate in the device authentication, and this time, in the area judgment, it is also determined that the location of the device to be authenticated 2 is included in the first area R1 (steps S101 to S105). In accordance with these judgment results, the output unit 23 decides to output (step S106) and outputs information to the control device (not shown) that controls the entrance door 31, indicating that the door 31 should be opened (step S107). In response, the control device opens the door 31, allowing user 5, who is carrying a legitimate device to be authenticated 2, to enter the building.
[0063] Suppose that user 5, who is carrying a legitimate device to be authenticated 2, enters the second area R2 of the elevator hall. Then, similar to the process described above, the device authentication will be deemed legitimate, and in the area determination, it will be determined that the location of the device to be authenticated 2 is included in the second area R2 (steps S101 to S105). In accordance with these determination results, the output unit 23 decides to output (step S106) and outputs information to the control device (not shown) that controls the elevator 32, indicating that the elevator 32 should be operated (step S107). In response, the control device operates the elevator 32, allowing user 5 to move to the desired floor by elevator 32.
[0064] Furthermore, even if a person who does not possess a valid authentication device 2 enters the first area R1, they will not be deemed legitimate in the device authentication process (steps S101 to S103), and therefore the entrance door 31 will not open.
[0065] As described above, according to the authentication device 1 of this embodiment, device authentication and area determination in the first and second areas R1 and R2 can be performed using the first and second receiver sets 11 and 12. Therefore, the number of receiver sets can be reduced compared to the case where two or more receiver sets are provided for each of the first and second areas R1 and R2. For example, if two receiver sets are provided for each of the first and second areas R1 and R2, a total of four receiver sets will be used to perform device authentication and area determination in the first and second areas R1 and R2. However, in this embodiment, device authentication and area determination in the first and second areas R1 and R2 can be performed using the first and second receiver sets 11 and 12, i.e., two receiver sets, thereby reducing costs.
[0066] In this embodiment, the case in which region determination for both the first and second regions R1 and R2 is performed using the difference in intensity of authentication requests received by the first and second receiver sets 11 and 12 has been mainly described, but this is not required. As shown in Figures 4 and 5, the authentication device 1 also includes a third receiver set containing a plurality of receivers 13a, and the region determination for the first and second regions R1 and R2 may also be performed using the intensity of authentication requests received by the third receiver set 13. In this case, the determination unit 22 may, for example, use at least the difference in intensity of authentication requests received by the first and third receiver sets 11 and 13 when determining whether the device to be authenticated 2 is included in the first region R1, and use at least the difference in intensity of authentication requests received by the second and third receiver sets 12 and 13 when determining whether the device to be authenticated 2 is included in the second region R2. In this case, as shown in Figure 5, the third position where the third receiver set 13 is located may be, for example, a position further from the first region R1 than the first position, and closer to the first region R1 than the second position. Alternatively, the third position may be, for example, a position further from the second region R2 than the second position, and closer to the second region R2 than the first position. For example, even if the first and second regions R1 and R2 are far apart, and the second receiver set 12 cannot receive an authentication request transmitted by the device to be authenticated 2 located in the first region R1, or the first receiver set 11 cannot receive an authentication request transmitted by the device to be authenticated 2 located in the second region R2, the placement of the third receiver set 13 makes it possible to perform region determination regarding the first and second regions R1 and R2. Furthermore, even in this case, since region determination regarding the first and second regions R1 and R2 can be performed using the first to third receiver sets 11 to 13, i.e., three receiver sets, the number of receiver sets can be reduced compared to arranging two receiver sets for each of the first and second regions R1 and R2.
[0067] As described above, the authentication device 1 may, for example, be equipped with first to N receiver sets, where N is an integer of 2 or more. In this case, at least two receiver sets used in the domain determination for the first domain R1 and at least two receiver sets used in the domain determination for the second domain R2 are assumed to include at least the same receiver sets. As explained above, the at least two receiver sets used in the domain determination for the first domain R1 and at least two receiver sets used in the domain determination for the second domain R2 may, for example, be exactly the same, or they may include different receiver sets. In either case, by having at least one receiver set common to the at least two receiver sets used in the domain determination for the first domain R1 and at least two receiver sets used in the domain determination for the second domain R2, the number of receiver sets that the authentication device 1 has can be reduced compared to when this is not the case, and as a result, costs can be reduced.
[0068] Furthermore, although this embodiment mainly describes the case where the first region R1 is set outside the entrance door 31 of the building and the second region R2 is set in the elevator hall of the building, this is not required. For example, in a retail store, the first region R1 may be set in front of the first POS register that processes payments, and the second region R2 may be located in front of the second POS register that processes payments. Also, for example, the first receiver set 11 may be located near the first POS register, and the second receiver set 12 may be located near the second POS register. By performing region determination regarding the first and second regions R1 and R2 using the first and second receiver sets 11 and 12, region determination regarding the first and second regions may be performed using a smaller number of receiver sets. As another example, when the first and second conference rooms are located in close proximity, the first and second regions R1 and R2 may be set outside the doors of the first and second conference rooms, respectively, and the first and second receiver sets 11 and 12 may be placed near the doors of the first and second conference rooms, respectively. Then, by performing region determination regarding the first and second regions R1 and R2 using the first and second receiver sets 11 and 12, the region determination regarding the first and second regions may be performed using a smaller number of receiver sets.
[0069] Furthermore, although this embodiment mainly describes the case where region determination is performed for two regions, namely the first and second regions R1 and R2, even when region determination is performed for three or more regions, at least one receiver set may be used in common when region determination is performed for at least two of those three or more regions. By doing so, the total number of receiver sets can be reduced.
[0070] In this embodiment, as an example, when performing domain determination of the authenticated device 2 using two receiver sets for each domain, domain determination can be performed for a number of domains exceeding N / 2 using N receiver sets. For example, Figures 1 and 2 show the case where N=2, in which case domain determination can be performed for more than 2 / 2 = 1 domain, i.e., 2 domains. Also, Figures 4 and 5 show the case where N=3, in which case as well, domain determination can be performed for more than 3 / 2 = 1.5 domains, i.e., 2 domains. For example, if there is no receiver set used in common for two domains, the number of domains for which domain determination can be performed using N receiver sets will be N / 2 or less. However, as with the authentication device 1 in this embodiment, if there is a receiver set used in common for two domains, domain determination can be performed for a number of domains exceeding that, thereby reducing costs.
[0071] Furthermore, for example, one or more receivers included in a receiver set may be attached to a moving object. For example, as shown in Figures 6A and 6B, a plurality of receivers 11a included in the first receiver set 11 may each be attached to the entrance door 31 of a building. If the first receiver set 11 includes four receivers 11a, for example, two receivers 11a may be attached to the outside of one door 31 and two receivers 11a may be attached to the outside of the other door 31. In this case, the determination unit 22 may change the method of area determination depending on the position of the receivers 11a, i.e., depending on the opening and closing of the door 31, or it may not. In the former case, for example, the determination unit 22 may change the first threshold described above depending on whether the door 31 is open or closed. For example, the determination unit 22 may receive information on the open / closed state of the door 31 from a control device (not shown) that controls the door 31, and perform area determination according to the open / closed state of the door 31 indicated by that information. When the receiver 11a is attached to a moving object such as a door 31, the first position may or may not change in accordance with the movement of the object. For example, if the four receivers 11a included in the first receiver set 11 are attached to the doors 31 in pairs so as to be symmetrical with respect to the abutting portion of the two doors 31 as the axis of symmetry, then the position of the center of gravity of the four receivers 11a, i.e., the first position, will not change in accordance with the opening and closing of the doors 31. In this case, for example, the method of determining the region does not need to be changed in accordance with the opening and closing of the doors 31. On the other hand, if the first position changes in accordance with the movement of the object to which the receiver 11a is attached, it is preferable to change the method of determining the region in accordance with the opening and closing of the doors 31.
[0072] In addition, while Figures 6A and 6B show an example where the four receivers 11a are located on the right side of the first region R1, as another example, the first region R1 may be set such that the center of gravity of the four receivers 11a is located near the center of the first region R1 in a plan view. Furthermore, as shown in Figures 6A and 6B, when the four receivers 11a are located on the right side of the first region R1 in a plan view, as another example, a radio wave shielding material such as a metal plate or metal film may be placed on the inner surface of the door 31 (i.e., the right side surface of the door 31 in Figure 6A, etc.) to enable appropriate region determination regarding the first region R1. Furthermore, as yet another example, when the determination unit 22 identifies the position of the device to be authenticated 2 and determines whether the identified position is included in the first region R1, the four receivers 11a do not need to be included in the first region R1 in a plan view.
[0073] Furthermore, although this embodiment mainly describes the case where area determination is performed using two receiver sets, for example, if the authentication device 1 is equipped with first to Nth receiver sets and N is 3 or more, area determination may be performed using three or more receiver sets. In this case, when determining the location by, for example, tripoint surveying, it is preferable that the first to Nth locations do not lie on a single straight line, but if this is not the case, the first to Nth locations may lie on a single straight line. Also, when N is 4, for example, when determining the location by tripoint surveying, it is preferable that the first to fourth locations do not become the vertices of a parallelogram, but if this is not the case, the first to fourth locations may become the vertices of a parallelogram. This location identification may be performed, for example, by identifying multiple Apollonius circles or lines based on the difference in strength of authentication requests received by two receiver sets, for different combinations of two receiver sets in three or more receiver sets, and then identifying the location on, on, or within the identified Apollonius circle as the location of the device under authentication 2, or by other methods.
[0074] Furthermore, in the above embodiment, each process or function may be implemented by centralized processing by a single device or a single system, or by distributed processing by multiple devices or multiple systems.
[0075] Furthermore, in the above embodiment, the exchange of information between each component may, for example, be performed by outputting information from one component and receiving information from the other component if the two components performing the information exchange are physically different, or by moving from the processing phase corresponding to one component to the processing phase corresponding to the other component if the two components performing the information exchange are physically the same.
[0076] Furthermore, in the above embodiment, information related to the processing performed by each component, such as information received, acquired, selected, generated, transmitted, or received by each component, as well as information such as thresholds, formulas, and addresses used by each component in processing, may be temporarily or for a long period of time stored in a recording medium (not shown), even if not explicitly stated in the above description. The storage of information in the recording medium (not shown) may be performed by each component or a storage unit (not shown). The reading of information from the recording medium (not shown) may be performed by each component or a reading unit (not shown).
[0077] Furthermore, in the above embodiment, if the information used in each component, such as thresholds, addresses, and various setting values used by each component in processing, can be changed by the user, then even if not explicitly stated in the above description, the user may be allowed to change such information as appropriate, or not. If the user can change such information, the change may be implemented, for example, by a receiving unit (not shown) that receives change instructions from the user and a changing unit (not shown) that changes the information in response to those change instructions. The receiving unit (not shown) may receive change instructions from an input device, receive information transmitted via a communication line, or receive information read from a predetermined recording medium.
[0078] Furthermore, in the above embodiment, if two or more components included in the authentication device have a communication device, an input device, etc., the two or more components may have a single physical device, or they may have separate devices.
[0079] Furthermore, in the above embodiment, each component may be made up of dedicated hardware, or, if a component can be implemented by software, it may be implemented by executing a program. For example, each component can be implemented by a program execution unit such as a CPU reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. During execution, the program execution unit may execute the program while accessing the storage unit or recording medium. The software that implements the authentication device 1 in the above embodiment is the following program. In other words, this program causes a computer to perform the following steps: receiving an authentication request from a device to be authenticated, which includes authentication information used to authenticate the device to be authenticated, with at least two receiver sets in a first to N receiver set containing one or more receivers; performing device authentication, which determines whether the device that sent the authentication request is legitimate, using the authentication information contained in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; performing a region determination, which determines whether the location of the device to be authenticated is included in the first and second regions, based on the difference in the strength of the authentication requests received by at least two receiver sets in the step of receiving the authentication request; and outputting the results of the device authentication and the region determination, where N is two or more, and the program may include at least the same receiver sets in the at least two receiver sets used in the region determination for the first region and the at least two receiver sets used in the region determination for the second region.
[0080] Furthermore, in the above program, steps such as receiving information and outputting information do not include any processes that can only be performed by hardware, such as processes performed by communication devices like modems or interface cards.
[0081] Furthermore, this program may be executed by downloading it from a server or the like, or by reading a program recorded on a predetermined recording medium (for example, an optical disc such as a CD-ROM, a magnetic disc, or a semiconductor memory). This program may also be used as a program that constitutes a program product.
[0082] Furthermore, the computer running this program may be a single computer or multiple computers. That is, it may perform centralized processing or distributed processing.
[0083] Figure 7 shows an example of a computer system 900 that executes the above program to realize the authentication device 1 according to the above embodiment. The above embodiment can be realized by computer hardware and a computer program executed thereon.
[0084] In Figure 7, the computer system 900 includes an MPU (Micro Processing Unit) 911, a ROM 912 such as flash memory that stores programs such as boot-up programs, application programs, system programs, and data, a RAM 913 connected to the MPU 911 that temporarily stores instructions for application programs and provides temporary storage space, a touch panel 914, a wireless communication module 915, and a bus 916 that interconnects the MPU 911, ROM 912, etc. The computer system 900 may also include, for example, a plurality of wireless communication modules 915 corresponding to the first and second receiver sets 11, 12, etc., or may be connected to a plurality of wireless communication modules corresponding to the first and second receiver sets 11, 12, etc. The computer system 900 may also include a display and input devices such as a mouse or keyboard instead of the touch panel 914. Furthermore, the computer system 900 may further include other recording media such as a hard disk.
[0085] The program that causes the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment may be stored in the ROM 912 via the wireless communication module 915. The program is loaded into the RAM 913 when executed. The program may also be loaded directly from the network.
[0086] The program does not necessarily include an operating system (OS) or third-party program that causes the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment. The program may include only the portion of instructions that call appropriate functions or modules in a controlled manner to obtain the desired result. How the computer system 900 operates is well known, so a detailed explanation is omitted.
[0087] Furthermore, the embodiments described above are illustrative examples for specifically carrying out the present invention and do not limit the technical scope of the present invention. The technical scope of the present invention is indicated by the claims rather than by the description of the embodiments, and modifications within the literal scope and equivalent meaning of the claims are intended.
Claims
1. A first to N receiver set including one or more receivers that receive authentication requests transmitted from a device to be authenticated, which include authentication information used for authenticating the device to be authenticated; an authentication unit that performs device authentication, which determines whether the device that transmitted the authentication request is legitimate, using the authentication information included in the authentication request received by at least one of the one or more receivers included in the first to N receiver sets; a determination unit that performs area determination, which determines whether the location of the device to be authenticated is included in first and second areas, based on the difference in the intensity of authentication requests received by at least two receiver sets in the first to N receiver sets; and an output unit that outputs a determination result to a device that processes the first area if it is determined that a legitimate device to be authenticated is in the first area, and outputs a determination result to a device that processes the second area if it is determined that a legitimate device to be authenticated is in the second area, wherein N is 2 or more. An authentication device in which at least two sets of receivers used in the area determination for the first area and at least two sets of receivers used in the area determination for the second area include at least the same set of receivers.
2. The authentication device according to claim 1, wherein the first position where the first receiver set is located is included in the first region in a plan view, and the second position where the second receiver set is located is included in the second region in a plan view.
3. The system comprises: first to N receiver sets, each including one or more receivers that receive authentication requests transmitted from a device to be authenticated, which include authentication information used to authenticate the device to be authenticated; an authentication unit that performs device authentication, determining whether the device that transmitted the authentication request is legitimate, using the authentication information included in the authentication request received by at least one of the one or more receivers included in the first to N receiver sets; a determination unit that performs region determination, determining whether the location of the device to be authenticated is included in first and second regions, based on the difference in the intensity of authentication requests received by at least two receiver sets in the first to N receiver sets; and an output unit that outputs the results of the device authentication and the results of the region determination, wherein N is two or more, and at least two receiver sets used in the region determination for the first region and at least two receiver sets used in the region determination for the second region include at least the same receiver sets, and the first receiver set includes a plurality of receivers. Authentication device wherein the plurality of receivers of the first receiver set are mounted on a pair of sliding doors that open and close symmetrically, such that they are line-symmetric with respect to the abutting portion of the pair of doors as the axis of symmetry, and such that the position of the center of gravity of the plurality of receivers does not change when the pair of doors are opened and closed.
4. The authentication device according to any one of claims 1 to 3, wherein the determination unit uses at least the difference in intensity of the authentication requests received by the first and second receiver sets when determining whether the device to be authenticated is included in the first area and when determining whether the device to be authenticated is included in the second area.
5. Authentication device comprising: first to N sets of receivers, each including one or more receivers that receive authentication requests transmitted from a device to be authenticated, which include authentication information used for authenticating the device to be authenticated; an authentication unit that performs device authentication, determining whether the device that transmitted the authentication request is legitimate, using the authentication information included in the authentication request received by at least one of the one or more receivers included in the first to N sets of receivers; a determination unit that performs area determination, determining whether the location of the device to be authenticated is included in first and second areas, based on the difference in intensity of authentication requests received by at least two sets of receivers in the first to N sets of receivers; and an output unit that outputs the result of the device authentication and the result of the area determination, wherein N is 3 or more, and the determination unit uses at least the difference in intensity of authentication requests received by the first and third sets of receivers when determining whether the device to be authenticated is included in the first area, and uses at least the difference in intensity of authentication requests received by the second and third sets of receivers when determining whether the device to be authenticated is included in the second area.
6. An authentication method processed using a first to N receiver set including one or more receivers, an authentication unit, a determination unit, and an output unit, wherein N is two or more, and the method comprises: a step in which at least two receiver sets in the first to N receiver sets receive an authentication request transmitted from a device to be authenticated, which includes authentication information used for the authentication of the device to be authenticated; a step in which the authentication unit performs device authentication, determining whether the device that transmitted the authentication request is legitimate, using the authentication information contained in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; and a step in which the determination unit performs region determination, determining whether the location of the device to be authenticated is included in the first and second regions, based on the difference in the intensity of the authentication requests received by at least two receiver sets in the step of receiving the authentication request. Authentication method comprising the steps of: when the output unit determines that a legitimate device to be authenticated is located in the first area, it outputs a determination result to a device that processes the first area; and when the output unit determines that a legitimate device to be authenticated is located in the second area, it outputs a determination result to a device that processes the second area; wherein at least two receiver sets used for area determination in the first area and at least two receiver sets used for area determination in the second area include at least the same receiver set.
7. An authentication method processed using a first to N set of receivers including one or more receivers, an authentication unit, a determination unit, and an output unit, wherein N is two or more, and the method comprises: a step in which at least two receiver sets in the first to N set of receivers receive an authentication request transmitted from a device to be authenticated, which includes authentication information used for authenticating the device to be authenticated; a step in which the authentication unit performs device authentication, determining whether the device that transmitted the authentication request is legitimate, using the authentication information included in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; a step in which the determination unit performs a region determination, determining whether the location of the device to be authenticated is included in first and second regions, based on the difference in the intensity of the authentication requests received by at least two receiver sets in the step of receiving the authentication request; and a step in which the output unit outputs the result of the device authentication and the result of the region determination, wherein at least two of the receiver sets used in the region determination for the first region and at least two of the receiver sets used in the region determination for the second region include at least the same receiver sets. Authentication method wherein the first receiver set includes a plurality of receivers, and the plurality of receivers of the first receiver set are mounted on a pair of sliding doors that open and close symmetrically, such that they are line-symmetric with respect to the abutting portion of the pair of doors as the axis of symmetry, and such that the position of the center of gravity of the plurality of receivers does not change when the pair of doors are opened and closed.
8. An authentication method processed using a first to N set of receivers including one or more receivers, an authentication unit, a determination unit, and an output unit, wherein N is three or more, and comprises: a step in which at least two receiver sets in the first to N set of receivers receive an authentication request transmitted from a device to be authenticated, which includes authentication information used for authenticating the device to be authenticated; a step in which the authentication unit performs device authentication, determining whether the device that transmitted the authentication request is legitimate, using the authentication information included in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; a step in which the determination unit performs a region determination, determining whether the location of the device to be authenticated is included in first and second regions, based on the difference in the intensity of the authentication requests received by at least two receiver sets in the step of receiving the authentication request; and a step in which the output unit outputs the result of the device authentication and the result of the region determination. Authentication method comprising the step of determining the area, wherein when determining whether the device to be authenticated is included in the first area, at least the difference in strength of the authentication requests received by the first and third receiver sets is used, and when determining whether the device to be authenticated is included in the second area, at least the difference in strength of the authentication requests received by the second and third receiver sets is used.
9. The computer is made to perform the following steps: a step in which at least two receiver sets in a first to N receiver set, each containing one or more receivers, receive an authentication request that includes authentication information used to authenticate the device to be authenticated, transmitted from the device to be authenticated; a step in which the computer performs device authentication to determine whether the device that sent the authentication request is legitimate, using the authentication information contained in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; a step in which the computer performs region determination to determine whether the location of the device to be authenticated is included in the first and second regions, based on the difference in the strength of the authentication requests received by at least two receiver sets in the step of receiving the authentication request; and a step in which the computer outputs a result of the determination to a device that processes the first region if it is determined that a legitimate device to be authenticated is located in the second region, wherein N is two or more. A program in which at least two receiver sets used in the domain determination for the first domain and at least two receiver sets used in the domain determination for the second domain include at least the same receiver set.
10. The computer is made to perform the following steps: a step of having at least two receiver sets in a first to N receiver set, each containing one or more receivers, receive an authentication request transmitted from a device to be authenticated, which includes authentication information used to authenticate the device to be authenticated; a step of performing device authentication, which determines whether the device that sent the authentication request is legitimate, using the authentication information contained in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; a step of performing a region determination, which determines whether the location of the device to be authenticated is included in the first and second regions, based on the difference in the strength of the authentication requests received by at least two receiver sets in the step of receiving the authentication request; and a step of outputting the result of the device authentication and the result of the region determination, wherein N is two or more, at least two of the receiver sets used in the region determination for the first region and at least two of the receiver sets used in the region determination for the second region include at least the same receiver set, and the first receiver set includes a plurality of receivers. A program wherein the plurality of receivers of the first receiver set are mounted on a pair of sliding doors that open and close symmetrically, such that they are line-symmetric with respect to the abutting portion of the pair of doors as the axis of symmetry, and such that the position of the center of gravity of the plurality of receivers does not change as the pair of doors open and close.
11. A program that causes a computer to perform the following steps: a step of having at least two receiver sets in a first to N receiver set, each containing one or more receivers, receive an authentication request that includes authentication information used to authenticate the device to be authenticated, transmitted from the device to be authenticated; a step of performing device authentication, which determines whether the device that sent the authentication request is legitimate, using the authentication information contained in the authentication request received by at least one of the one or more receivers in the step of receiving the authentication request; a step of performing a region determination, which determines whether the location of the device to be authenticated is included in the first and second regions, based on the difference in the intensity of the authentication requests received by at least two receiver sets in the step of receiving the authentication request; and a step of outputting the result of the device authentication and the result of the region determination, wherein N is 3 or more, and in the step of performing the region determination, at least the difference in the intensity of the authentication requests received by the first and third receiver sets is used when determining whether the device to be authenticated is included in the first region, and at least the difference in the intensity of the authentication requests received by the second and third receiver sets is used when determining whether the device to be authenticated is included in the second region.