Utilization Control System Using Secure Use Permits
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing utilization control systems face challenges such as increased security risks due to network connectivity, inconvenience for users when multiple service providers are involved, and burdensome registration processes for users and representatives in managing access to facilities.
Innovation Solution
A utilization control system that includes a use permit issuing device, a utilization control device, and a use permit notification device, which utilize Near Field Communication to manage access permissions through use permits with conditions, allowing users to access facilities without network dependence and reducing the need for repeated authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If RFID readers are connected to a server via the Internet to transmit authentication data, then remote server management is enabled, but security risk increases due to network transmission
Solution Approach 1:
The system divides authentication data into multiple components: authentication information stored in the RFID tag, service permission information stored in the terminal device, and use condition information stored in both the terminal device and server. This segmentation ensures that no single component contains all sensitive data, reducing security risk while enabling remote server management through encrypted data exchange.
Solution Approach 2:
The terminal device preliminarily stores service permission information and use condition information before actual authentication occurs. This preliminary action allows the device to independently verify authentication results offline, reducing the need for real-time network communication and thereby reducing security risks associated with Internet transmission.
2Device complexity
If common authentication data is used for all services across different service providers, then system simplicity is maintained, but user convenience deteriorates due to repeated registration
Solution Approach 1:
The terminal device serves multiple functions: it acts as an authentication credential holder, a permission storage unit, and a condition verification device. By making the terminal device universal and capable of storing multiple types of information (authentication data, service permissions, use conditions), the system eliminates the need for repeated registration across different service providers while maintaining reasonable system complexity.
3Extent of automation
If a representative manages room keys and access for a group of users, then centralized control is achieved, but user convenience deteriorates as other users cannot access facilities independently
Solution Approach 1:
The system creates multiple copies of access permissions by storing service permission information in each user's terminal device. Instead of one representative holding the only key, each authorized user receives a copy of the necessary permission data in their own device, enabling independent access while the server maintains centralized control through use condition information.
4Extent of automation
If room keys are lent and returned at a reception desk, then centralized key management is maintained, but user convenience deteriorates when facilities are geographically distant from the reception desk
Solution Approach 1:
The system extracts the key management function from the physical reception desk and embeds it in each user's terminal device. The terminal device stores service permission information and use condition information locally, allowing users to access facilities independently without needing to physically visit the reception desk, while the server continues to maintain centralized control through encrypted data verification.
Data Source
AI summary
The present invention reduces security risks while improving the convenience of utilization control technology of an usage target object. A use permit issuance device (1): stores, for each user, authentication data and an authentication method in association with identification information of one or more users and upon receipt of a use permit issuance request from a setting terminal (5), issues a use permit to generate a signature, and identifies the authentication data associated with the user identification information and the authentication method included in the issuance request, and notifies the setting terminal (5) of setting information including the use permit, the signature and the authentication data. The setting terminal (5) registers the setting information in a use permit notification device (4). The use permit notification device (4) acquires authentication data from a user, and transmits the use permit and the signature of the setting information including the authentication data to a utilization control device (3). The utilization control device (3) verifies the signature, and if the signature verification is established, unlocks use restrictions of a usage target object when a use condition included in the use permit being satisfied.


