System and method for personal identification, and identification tag
Abstract
Problem to be solved.To provide a personal authentication means which cannot be lent or borrowed once personal information is registered and can be used only by the person himself / herself, relatively easily. A personal authentication system is composed of an authentication tag 1, a personal authentication device 2, an information management device 3, and security devices 4 and 5. The personal authentication device 2, the security devices 4 and 5 can perform wireless communication with the authentication tag 1, while the information management device 3 is connected to the information management device 3 by a wireless or wired network 6. The personal authentication device 2 registers personal information and enables the authentication tag 1 when the authentication tag 1 is attached to the user of the facility. If the authentication tag 1 is valid, the security device 4 controls the equipment so that the user can use the equipment. When the authentication tag 1 detects that it has been detached from the user, it invalidates itself. As a result, the user can use the equipment in the facility as long as the authentication tag 1 is attached. [Selection diagram] Fig. 1

Term
Term ended
Projected expiry passed 9 October 2023, 3 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
12 claims: 6 independent, 6 dependent
- 1施設に備えられる設備を利用する利用者に装着される認証タグと、前記施設に設置される個人認証装置と、前記施設の1以上の設備に付設され、前記個人認証装置とネットワーク接続されるセキュリティ装置とから構成され、前記利用者が前記設備を利用しようとするごとに個人認証を行うことによって前記施設のセキュリティを確保する個人認証システムであって、 前記認証タグは、第1の通信手段と、認証タグ着脱検出手段と、第1の制御手段とを備え、 前記第1の通信手段は、前記個人認証装置及び前記セキュリティ装置と通信を行う機能を有し、 前記認証タグ着脱検出手段は、前記認証タグの着脱状態を検出する機能を有し、 前記第1の制御手段は、前記認証タグに固有の番号である認証タグIDを記憶する認証タグID記憶部及びその認証タグIDの有効性を示す認証タグID有効フラグを記憶する認証タグID有効フラグ記憶部を備え、前記認証タグ着脱検出手段が前記認証タグが前記利用者から脱着されたことを検出したとき、前記認証タグID有効フラグを無効にする機能と、前記第1の通信手段を介して前記個人認証装置から前記認証タグID有効フラグを有効にする指示情報を受信したとき、前記認証タグID有効フラグを有効にする機能と、前記第1の通信手段を介して、前記セキュリティ装置からの要求に応じて前記認証タグID有効フラグ記憶部に記憶された認証タグID有効フラグを送信する機能を有し、 前記個人認証装置は、第2の通信手段と、第2の制御手段とを備え、 前記第2の通信手段は、前記認証タグと通信を行う機能を有し、 前記第2の制御手段は、前記認証タグに前記認証タグID有効フラグを有効にする指示情報を送信することによって前記認証タグを有効にする機能を有し、 前記セキュリティ装置は、第3の通信手段と、設備利用制御手段と、第3の制御手段とを備え、 前記第3の通信手段は、前記認証タグと通信を行う機能を有し、 前記設備利用制御手段は、前記利用者による前記設備の利用を可能又は不可とするように前記設備を制御する機能を有し、 前記第3の制御手段は、前記第3の通信手段を介して前記認証タグから受信した認証タグID有効フラグが有効であったとき、前記設備利用制御手段に前記設備を利用可能とするように指示する指示情報を送信する機能を有する ことを特徴とする個人認証システム。
- 2施設に備えられる設備を利用する利用者に装着される認証タグと、前記施設に設置され、前記認証タグを有効にする個人認証装置と、前記施設の1以上の設備に付設され、前記個人認証装置とネットワーク接続されるセキュリティ装置とから構成され、前記利用者が前記設備を利用しようとするごとに個人認証を行うことによって前記施設のセキュリティを確保する個人認証システムであって、 前記認証タグは、第1の無線通信手段と、認証タグ着脱検出手段と、第1の制御手段とを備え、 前記第1の無線通信手段は、前記個人認証装置及び前記セキュリティ装置と無線通信を行う機能を有し、 前記認証タグ着脱検出手段は、前記認証タグの着脱状態を検出する機能を有し、 前記第1の制御手段は、前記認証タグに固有の番号である認証タグIDを記憶する認証タグID記憶部及びその認証タグIDの有効性を示す認証タグID有効フラグを記憶する認証タグID有効フラグ記憶部を備え、前記認証タグ着脱検出手段が前記認証タグが前記利用者から脱着されたことを検出したとき、前記認証タグID有効フラグを無効にすると共に、前記第1の無線通信手段を介して、前記個人認証装置からの要求に応じて前記認証タグ着脱検出手段によって検出された認証タグの着脱状態情報又は前記認証タグID記憶部に記憶された認証タグIDを送信し、前記第1の無線通信手段を介して前記個人認証装置から前記認証タグID有効フラグを有効にする指示情報を受信したとき、前記認証タグID有効フラグを有効にし、前記第1の無線通信手段を介して、前記セキュリティ装置からの要求に応じて前記認証タグID有効フラグ記憶部に記憶された認証タグID有効フラグを送信する機能を有し、 前記個人認証装置は、第2の無線通信手段と、認証情報入力手段と、ID情報記憶手段と、第2の制御手段とを備え、 前記第2の無線通信手段は、前記認証タグと無線通信を行う機能を有し、 前記認証情報入力手段は、前記利用者に固有の情報である認証情報を入力する機能を有し、 前記ID情報記憶手段は、前記認証タグID及び前記認証情報を含むID情報を記憶する機能を有し、 前記第2の制御手段は、前記第2の無線通信手段を介して前記認証タグから受信した認証タグの着脱状態情報が装着状態を示しているとき、前記認証タグから受信した認証タグID及び前記認証情報入力手段によって入力された認証情報を含むID情報を前記ID情報記憶手段に送信し、前記認証タグに前記認証タグID有効フラグを有効にする指示情報を送信することによって前記認証タグを有効にする機能を有し、 前記セキュリティ装置は、第3の無線通信手段と、設備利用制御手段と、第3の制御手段とを備え、 前記第3の無線通信手段は、前記認証タグと無線通信を行う機能を有し、 前記設備利用制御手段は、前記利用者による前記設備の利用を可能又は不可とするように前記設備を制御する機能を有し、 前記第3の制御手段は、前記第3の無線通信手段を介して前記認証タグから受信した認証タグID有効フラグが有効であったとき、前記設備利用制御手段に前記設備を利用可能とするように指示する指示情報を送信する機能を有する ことを特徴とする個人認証システム。
- 3施設に備えられる設備を利用する利用者に装着される認証タグと、前記施設に設置され、前記認証タグを有効にする個人認証装置と、前記施設の1以上の設備に付設されるセキュリティ装置と、前記個人認証装置及び前記セキュリティ装置とネットワーク接続され、共有情報を記憶する情報管理装置とから構成され、前記利用者が前記設備を利用しようとするごとに個人認証を行うことによって前記施設のセキュリティを確保する個人認証システムであって、 前記認証タグは、第1の無線通信手段と、認証タグ着脱検出手段と、第1の制御手段とを備え、 前記第1の無線通信手段は、前記個人認証装置及び前記セキュリティ装置と無線通信を行う機能を有し、 前記認証タグ着脱検出手段は、前記認証タグの着脱状態を検出する機能を有し、 前記第1の制御手段は、前記認証タグに固有の番号である認証タグIDを記憶する認証タグID記憶部及びその認証タグIDの有効性を示す認証タグID有効フラグを記憶する認証タグID有効フラグ記憶部を備え、前記認証タグ着脱検出手段が前記認証タグが前記利用者から脱着されたことを検出したとき、前記認証タグID有効フラグを無効にすると共に、前記第1の無線通信手段を介して、前記個人認証装置からの要求に応じて前記認証タグ着脱検出手段によって検出された認証タグの着脱状態情報又は前記認証タグID記憶部に記憶された認証タグIDを送信し、前記第1の無線通信手段を介して前記個人認証装置から前記認証タグID有効フラグを有効にする指示情報を受信したとき、前記認証タグID有効フラグを有効にし、前記第1の無線通信手段を介して、前記セキュリティ装置からの要求に応じて前記認証タグID有効フラグ記憶部に記憶された認証タグID有効フラグを送信する機能を有し、 前記個人認証装置は、第2の無線通信手段と、認証情報入力手段と、第2の制御手段とを備え、 前記第2の無線通信手段は、前記認証タグと無線通信を行う機能を有し、 前記認証情報入力手段は、前記利用者に固有の情報である認証情報を入力する機能を有し、 前記第2の制御手段は、前記第2の無線通信手段を介して前記認証タグから受信した認証タグの着脱状態情報が装着状態を示しているとき、前記認証タグから受信した認証タグID及び前記認証情報入力手段によって入力された認証情報を含むID情報を前記情報管理装置に送信し、前記認証タグに前記認証タグID有効フラグを有効にする指示情報を送信することによって前記認証タグを有効にする機能を有し、 前記セキュリティ装置は、第3の無線通信手段と、設備利用制御手段と、第3の制御手段とを備え、 前記第3の無線通信手段は、前記認証タグと無線通信を行う機能を有し、 前記設備利用制御手段は、前記利用者による前記設備の利用を可能又は不可とするように前記設備を制御する機能を有し、 前記第3の制御手段は、前記第3の無線通信手段を介して前記認証タグから受信した認証タグID有効フラグが有効であったとき、前記設備利用制御手段に前記設備を利用可能とするように指示する指示情報を送信する機能を有し、 前記情報管理装置は、ID情報記憶手段を備え、 前記ID情報記憶手段は、前記第2の制御手段から前記ID情報を受信し、その受信したID情報を記憶する機能を有する ことを特徴とする個人認証システム。
- 4前記第3の制御手段は、前記第3の無線通信手段を介して前記認証タグから受信した認証タグID有効フラグが有効であったとき、前記認証タグID、その認証タグIDを検出した時刻及び場所を含む位置情報を前記情報管理装置に送信する機能を有し、 前記情報管理装置は、位置情報記憶手段を備え、 前記位置情報記憶手段は、前記第3の制御手段から前記位置情報を受信し、その受信した位置情報を記憶する機能を有する ことを特徴とする請求項3に記載の個人認証システム。
- 5前記第1の制御手段は、前記第1の無線通信手段を介して、前記セキュリティ装置からの要求に応じて前記認証タグID記憶部に記憶された認証タグIDを送信する機能を有し、 前記第3の制御手段は、前記第3の無線通信手段を介して、前記認証タグから受信した認証タグID有効フラグが有効であり、かつ、前記認証タグから受信した認証タグIDが前記ID情報記憶手段に記憶されているとき、前記設備利用制御手段に前記設備を利用可能とするように指示する指示情報を送信する機能を有する ことを特徴とする請求項2乃至請求項4のいずれか一項に記載の個人認証システム。
- 6前記認証タグ着脱検出手段は、認証タグの着脱によって導電線の両端が接触状態又は非接触状態になり、その導電線を流れる電流に違いが発生することを利用したものであることを特徴とする請求項2乃至請求項5のいずれか一項に記載の個人認証システム。
- 7前記認証タグ着脱検出手段は、認証タグの着脱によって赤外線による人体の脈拍検知の有無が発生することを利用したものであることを特徴とする請求項2乃至請求項5のいずれか一項に記載の個人認証システム。
- 8前記認証情報入力手段は、利用者が本人であることを確認することができる身分証明書に記載されている内容を認証情報として入力するものであることを特徴とする請求項2乃至請求項5のいずれか一項に記載の個人認証システム。
- 9前記認証情報入力手段は、予め前記個人認証システムに登録されている利用者の生体情報と、その利用者自身の生体情報とを照合し、それらが一致したとき、その登録されている利用者の生体情報に対応付けられている個人情報を認証情報として入力するものであることを特徴とする請求項2乃至請求項5のいずれか一項に記載の個人認証システム。
- 10施設に備えられる設備を利用する利用者に装着され、その利用者が設備を利用しようとするごとに行われる個人認証に使用される認証タグであって、 前記認証タグは、無線通信手段と、認証タグ着脱検出手段と、制御手段とを備え、 前記無線通信手段は、他装置と無線通信を行う機能を有し、 前記認証タグ着脱検出手段は、前記認証タグの着脱状態を検出する機能を有し、 前記制御手段は、前記認証タグに固有の番号である認証タグIDを記憶する認証タグID記憶部及びその認証タグIDの有効性を示す認証タグID有効フラグを記憶する認証タグID有効フラグ記憶部を備え、前記認証タグ着脱検出手段が前記認証タグが前記利用者から脱着されたことを検出したとき、前記認証タグID有効フラグを無効にすると共に、前記無線通信手段を介して、他装置からの要求に応じて前記認証タグ着脱検出手段によって検出された認証タグの着脱状態情報、前記認証タグID記憶部に記憶された認証タグID又は前記認証タグID有効フラグ記憶部に記憶された認証タグID有効フラグを送信し、前記第1の無線通信手段を介して他装置から前記認証タグID有効フラグを有効にする指示情報を受信したとき、前記認証タグID有効フラグを有効にする機能を有する ことを特徴とする認証タグ。
- 11請求項10に記載の認証タグから送信される認証タグID有効フラグに基づいて認証を行う個人認証方法であって、 前記認証タグから送信される認証タグID有効フラグが有効であるか、無効であるかを判断するステップと、 前記認証タグID有効フラグが無効であれば認証を失敗させるステップと、 前記認証タグID有効フラグが有効であれば認証を成功させるステップと、 を含むことを特徴とする個人認証方法。
- 12請求項10に記載の認証タグから送信される認証タグID及び認証タグID有効フラグに基づいて認証を行う個人認証方法であって、 前記認証タグから送信される認証タグID有効フラグが有効であるか、無効であるかを判断するステップと、 前記認証タグID有効フラグが無効であれば認証を失敗させるステップと、 前記認証タグID有効フラグが有効であれば、前記認証タグから送信される認証タグID及び予め登録されている認証タグIDが一致であるか、不一致であるかを判断するステップと、 前記認証タグIDが一致であれば認証を成功させるステップと、 前記認証タグIDが不一致であれば認証を失敗させるステップと、 を含むことを特徴とする個人認証方法。
Independent claims12
31 paragraphs, as filed
The present invention relates to a personal authentication system, an authentication tag, and a personal authentication method that ensure the security of a facility by performing personal authentication each time a user tries to use the equipment of the facility.
Since many customers come and go to facilities such as hotels, saunas, and sports clubs, appropriate security is required. There are lockers for storing valuables while using the facility, rooms and equipment that can be used only depending on the qualifications you have and the amount you paid, and it is necessary to control access by users to them. There is. Specifically, a wristband type key is distributed to users, and an IC (Integrated Circuit) card in which personal information is registered is distributed to users. In addition, in companies and business establishments, there is a demand to manage the current location of employees and the status of entry and exit in order to thoroughly manage the work of employees, as well as security. In response to this, entry / exit management is performed using a time card. There is also a method in which an employee has an IC card in which personal information is registered in advance, the current position of the employee is detected, and personal authentication is performed at the time of entering and leaving. On the other hand, the progress of personal authentication technology is remarkable, and devices and systems for collating human biometric information patterns to perform personal authentication have been developed. For example, Patent Document 1 discloses a technique in which a blood vessel arrangement pattern in a human finger or the like is registered in advance, and when the knob is gripped to open a door, the blood vessel arrangement pattern is collated.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2003-93368 (paragraphs 0007 to 0011, 0020, FIGS. 6, 7)</text></patcit>
<p> However, the keys and IC cards in the facility are not known even if they are rented or borrowed, and there is a problem that, for example, a user who has not paid a reasonable amount uses a room that can only be used for a limited time. Also, if they are dropped or lost, they may be used by another person. Similarly, even if the IC card at the business establishment or the like is lent or borrowed between employees, it is not known, and at that time, the management of the current position becomes meaningless. The same is true when an employee is spending time elsewhere with his IC card in his hand. On the other hand, personal authentication technology such as Patent Document 1 is very effective for authenticating a specific individual, but in order to apply it to the facility or business establishment, the cost required and the required authentication accuracy are required. It is hard to say that it is appropriate from the viewpoint of. In addition, retaining personal information such as biometric information is not very appropriate for the facilities and business establishments, regardless of the organization having a special task.</p><p> Therefore, in view of the above problems, it is an object of the present invention to provide a personal authentication means that cannot be lent or borrowed once personal information is registered and can be used only by the person himself / herself.</p>
<p> The present invention that solves the above problems includes an authentication tag attached to a user who uses the equipment provided in the facility, a personal authentication device installed in the facility and enabling the authentication tag, and one or more facilities of the facility. It consists of an attached personal authentication device and a security device connected to the network, and a personal authentication system, authentication tag and personal authentication that ensure the security of the facility by performing personal authentication each time the user tries to use the equipment. The method. First, when the second control means of the personal authentication device indicates that the user is wearing the attachment / detachment status information of the authentication tag received from the authentication tag by requesting the authentication tag, the second control means is further described. The ID information including the authentication tag ID received from the authentication tag and the authentication information (for example, the user name) input by the authentication information input means is transmitted to the ID information storage means. The ID information storage means stores the received ID information. As a result, the personal information of the user is registered. Then, the second control means transmits instruction information for enabling the authentication tag ID valid flag to the authentication tag. The first control means of the authentication tag enables (turns on) the authentication tag ID valid flag stored in the authentication tag ID valid flag storage unit when the instruction information is received. As a result, the authentication tag is valid as long as the user wears the authentication tag. Here, the authentication tag ID is a number unique to the authentication tag stored in advance in the authentication tag ID storage unit of the authentication tag. Further, when the authentication tag attachment / detachment detection means of the authentication tag detects that the authentication tag has been attached / detached from the user, the first control means is the authentication tag ID valid flag stored in the authentication tag ID valid flag storage unit. Is disabled (off). As a result, when the user attaches / detaches the authentication tag, the authentication tag can be invalidated even if the authentication tag ID is still stored.</p><p> Next, the third control means of the security device attached to the equipment is applied to the equipment use control means when the authentication tag ID valid flag received from the authentication tag is valid by requesting the authentication tag. Send instructional information instructing to make available. The equipment use control means (locking / unlocking control means) controls the equipment so that the user can use the equipment when the instruction information is received. For example, unlock the doors of each room and locker in the facility. As a result, the user can use the equipment in the facility as long as he / she wears the authentication tag. The ID information storage means shall be provided in the personal authentication device or the information management device provided separately. Further, a location information storage means for storing the location information (authentication tag ID, detection time, detection location) of the authentication tag received from the security device shall be provided in the information management device. As a result, the location information of the authentication tag can be accumulated. As a definition of terms herein, "wearing" means "attaching to the body" and "detachment" means "removing from the body". In addition, "detachment" means "attached to or removed from the body".</p>
<p> According to the present invention described above, the user can use the equipment in the facility as long as he / she wears the authentication tag in which the personal information is registered, which is very convenient. On the other hand, when the user attaches or detaches the authentication tag, the authentication tag becomes invalid, so that it is not possible to lend or borrow with another person. That is, another person cannot impersonate the person and use the authentication tag. In other words, according to the authentication tag attached to the user and registering the personal information, it is possible to guarantee the identity of the person.</p>
Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
<< Configuration and Outline of Personal Authentication System >> First, the configuration and outline of the personal authentication system according to the embodiment of the present invention will be described. As shown in the block configuration diagram of FIG. 1, the personal authentication system is composed of an authentication tag 1, a personal authentication device 2, an information management device 3, and security devices 4 and 5. The personal authentication device 2, the security devices 4 and 5 can perform wireless communication with the authentication tag 1, while the information management device 3 is connected to the information management device 3 by a wireless or wired network 6. Explaining the installation location of each component in a predetermined facility, the authentication tag 1 is attached to the user of the facility. The personal authentication device 2 is installed at the reception desk in the facility, and the information management device 3 is installed near the personal authentication device 2 or at another facility management center. The security device 4 is attached to the equipment in the facility. The security device 5 is installed at the entrance / exit of the facility. A facility user usually enters the facility from the entrance / exit of the facility, registers personal information as an admission procedure at the reception, and then uses the facilities in the facility. After that, after completing the exit procedure at the reception, exit from the doorway. In FIG. 1, the installation location of each component is shown in parentheses.
The authentication tag 1 is attached to a user of the facility to enable the user to use the equipment in the facility. The authentication tag 1 is composed of wireless communication means 11, control means 12, attachment / detachment detection means 15, and the like. The wireless communication means 11 wirelessly communicates with the personal authentication device 2, the security devices 4 and 5, and is realized by a wireless antenna, a transmitter / receiver, or the like. Further, infrared communication may be performed, or other wireless communication may be performed. Furthermore, it is desirable to encrypt the information to be transmitted and received so that the information to be transmitted and received by wireless communication is not illegally acquired or duplicated and used. It should be noted that the wireless communication means of other devices shall be realized in the same manner. The control means 12 plays a central function of the authentication tag 1 and is a CPU (Central Processing). It is realized by Unit) and memory. It should be noted that the control means of other devices shall be realized in the same manner. The control means 12 includes an ID (IDentification) storage unit 13 and an ID valid flag storage unit 14 as a part of the memory. The ID storage unit 13 is a memory that stores an authentication tag ID (hereinafter, simply referred to as ID) which is a number unique to the authentication tag 1, and is realized by, for example, a ROM (Read Only Memory). The ID valid flag storage unit 14 is a memory for storing the authentication tag ID valid flag (hereinafter, simply referred to as ID valid flag), which is a flag indicating the validity of the authentication tag ID, and is, for example, RAM (Random Access Memory). ). If the ID valid flag is on, it indicates that the ID is valid, and if it is off, it indicates that the ID is invalid. The attachment / detachment detecting means 15 detects whether the authentication tag 1 itself is attached to or detached from the user's body, and notifies the control means 12 of the detected attachment / detachment state.
FIG. 2 shows a specific example of the authentication tag 1 including the attachment / detachment detection means 15. Fig. 2 (a) is an example realized by a chest badge such as an employee ID card. If the cloth material 102 of the pocket is inserted into a part of the clip 101 by an electrode or an infrared sensor, it will be in a non-contact state and nothing will be inserted. A switch 103 that is in contact if not is provided is provided. The attachment / detachment of the authentication tag 1 is detected by the difference in the amount of current and infrared reflection depending on the non-contact state and the contact state. Fig. 2 (b) shows an example realized by a wristband. A conductive wire 105 is provided on the band 104, and if it is worn on the wrist, the wearing state is detected by the current flowing through the conductive wire 105, and the wearing state is detected from the wrist. If it is detached, the detached state is detected by interrupting the current of the conductive wire 105. In this wristband type, a method of detecting the pulse inside the wrist by near infrared rays is also conceivable. FIG. 2C shows an example realized by a ring, in which the attachment / detachment state of the authentication tag 1 is detected by detecting the presence / absence of a pulse inside the finger by near infrared rays. In addition to the pulse, the biological information that can be used to detect the attachment / detachment of the authentication tag 1 includes blood pressure, electrocardiogram, body temperature, and the like.
The personal authentication device 2 is a device installed in a facility, especially at a reception desk provided near an entrance / exit, and is used for user entry / exit procedures. As shown in FIG. 1, the personal authentication device 2 is composed of a wireless communication means 21, a control means 22, an authentication information input means 23, and the like. The wireless communication means 21 performs wireless communication with the authentication tag 1. The control means 22 fulfills a central function of the personal authentication device 2. It also has a function to send and receive information to and from the information management device 3 via the network 6. The authentication information input means 23 inputs user-specific authentication information that can confirm the identity of the user. Specifically, the user can be confirmed to be the person himself / herself by referring to a driver's license or passport and inputting using the keyboard, or by using biometric information such as a fingerprint registered in advance. It is conceivable to authenticate that and input the personal information registered in advance in association with the biometric information.
The information management device 3 is a device installed near the personal authentication device 2 or installed in another facility management center to store and manage shared information in the personal authentication system, and is a NAS (Network Attached Storage). It is realized by a dedicated file server that is directly connected). The information management device 3 is composed of an ID information storage means 31, a position information storage means 32, and the like. The ID information storage means 31 stores the ID of the authentication tag 1 attached to the user and the ID information including the user's authentication information when the user's personal information is registered by the personal authentication device 2. It is realized by a hard disk device or the like. The ID information storage means 31 may be provided in the personal authentication device 2. The location information storage means 32 stores location information that is information such as the ID of the authentication tag 1 detected by the security devices 4 and 5, the time at that time, and the location, and is realized by a hard disk device or the like. Figure 3 shows the structure of such information. As shown in FIG. 3A, the ID information stored in the ID information storage means 31 is composed of an authentication tag ID, a user name, a locker number, an entrance time, an exit time, a purchase amount, and a password. .. The authentication tag ID is the ID of the authentication tag 1 attached to the user. The user name is the name of the user input by the authentication information input means 23 of the personal authentication device 2. The locker number indicates the locker number assigned to the user. The admission time is the time when the user enters the facility. It may be recorded by the personal authentication device 2 or it may be recorded by the security device 5. The exit time is the time when the user leaves the facility. This may also be recorded by the personal authentication device 2 or by the security device 5. The password is registered and set by the personal authentication device 2, and once the user attaches or detaches the authentication tag 1, the personal authentication device 2 verifies and confirms the password in order to re-register the personal information. As shown in FIG. 3B, the position information stored in the position information storage means 32 is composed of an authentication tag ID, a detection time, and a detection location. The authentication tag ID is the ID of the authentication tag 1 attached to the user. The detection time and detection location indicate the time and location when the authentication tag ID is detected by the security devices 4 and 5.
The security device 4 is a device attached to the equipment in the facility, for example, the door of each room or a locker, and enables or disables the use of the equipment by the user. As shown in FIG. 1, the security device 4 is composed of a wireless communication means 41, a control means 42, a locking / unlocking control means 43, a door 44, and the like. The wireless communication means 41 performs wireless communication with the authentication tag 1. The control means 42 serves a central function of the security device 4. It also has a function to send and receive information to and from the information management device 3 via the network 6. The locking / unlocking control means 43 locks or unlocks the door 44 according to the instruction information from the control means 42.
The security device 5 is a device installed at the entrance / exit of the facility and detects the entry / exit of a user wearing the authentication tag 1 with the ID valid flag turned on. The security device 5 is composed of a wireless communication means 51, a control means 52, an entrance / exit detection means 53, and the like. The wireless communication means 51 performs wireless communication with the authentication tag 1. The control means 52 serves a central function of the security device 5. It also has a function to send and receive information to and from the information management device 3 via the network 6. The entry / exit detection means 53 detects the passage of the authentication tag 1 for which the ID valid flag is turned on and its direction (entrance / exit). Specifically, a gate through which the user enters and exits is provided, and two sensors are installed above the gate at a predetermined distance in the passage direction of the user. This sensor reads the ID and ID valid flag stored in the authentication tag 1, and is realized by the wireless antenna and the CPU. By recognizing the order in which the ID of the authentication tag 1 and the ID valid flag are read by these two sensors, the passing direction of the user can be specified. For example, when two sensors are sensor A (outside the facility) and sensor B (inside the facility), if the order is A and B, the direction is from A to B (entrance), and the order is If it is B or A, it is the direction from B to A (exit).
<< Operation of the personal authentication system >> Next, the operation of the personal authentication system according to the embodiment of the present invention will be described (see FIGS. 1 and 3 as appropriate). First, the operation performed by the authentication tag 1 alone will be described. In the authentication tag 1, the attachment / detachment detection means 15 monitors whether or not the authentication tag 1 is attached / detached from the user at predetermined time intervals. Then, when the attachment / detachment of the authentication tag 1 is detected, a message to that effect is transmitted to the control means 12. When the control means 12 receives a message to the effect of attachment / detachment from the attachment / detachment detection means 15, the control means 12 turns off the ID valid flag stored in the ID valid flag storage unit 14. As a result, the authentication tag 1 can invalidate the ID when it is detached from the user, and can be disabled from being used by anyone other than the user. The ID is a number unique to the authentication tag 1 stored in the ID storage unit 13 in advance.
Subsequently, the operation when the personal information is registered by the personal authentication device 2 will be described with reference to the flowchart of FIG. A user who enters the facility goes to the reception, receives the authentication tag 1 from the receptionist, and wears it on his or her body. Then, the receptionist presses the registration button (not shown) of the personal authentication device 2. As a result, the personal authentication device 2 starts the operation of personal information registration. First, the control means 22 of the personal authentication device 2 transmits a message requesting the current attachment / detachment state to the authentication tag 1 via the wireless communication means 21 (step S201). In the authentication tag 1, the control means 12 receives the message via the wireless communication means 11, recognizes that the received message is a request for the attachment / detachment state, and requests the attachment / detachment detection means 15 for the attachment / detachment state. Send a message. Upon receiving the message, the attachment / detachment detecting means 15 transmits the attachment / detachment state information of the current authentication tag 1 to the control means 12. Control means 12, the received wearing transmits the de-status information, the personal identification device 2 via the wireless communication unit 11 (step S202). In the personal authentication device 2, the control means 22 receives the attachment / detachment state information, and confirms whether or not the authentication tag 1 is attached to the user based on the received attachment / detachment state information (step S203). If it is attached (Yes in step S203), it sends a message requesting an ID to authentication tag 1 (step S204). If it is not installed (No in step S203), the operation of personal information registration is stopped. In the authentication tag 1, the control means 12 receives the message and recognizes that the message is an ID request. Then, the ID stored in the ID storage unit 13 is transmitted to the personal authentication device 2 (step S205).
Further, in the personal authentication device 2, the control means 22 receives the ID. Next, the authentication information input means 23 inputs the authentication information, which is information unique to the user (step S206). At this time, the receptionist may refer to the driver's license or passport possessed by the user and input from the keyboard, or authenticate the person by biometric information such as a fingerprint registered in advance. Personal information associated with the biometric information may be input. Then, the password required for re-registering the personal information is set (step S207). This may be done by the user or by the receptionist, but in any case, the user needs to remember the set password. Subsequently, the control means 22 registers the ID information in the ID information storage means 31 of the information management device 3 via the network 6 (step S208). The ID information to be registered here includes the ID received from the authentication tag 1, the user name that is a part of the entered authentication information, the locker number assigned to the user, the admission time that is the current time, and the set password. Is. The locker number is selected from currently available lockers by a predetermined algorithm. For example, make sure that many lockers are not available but adjacent lockers are not assigned. Then, send a message instructing authentication tag 1 to turn on the ID valid flag (step S209). In the authentication tag 1, the control means 12 receives the message and turns on the ID valid flag stored in the ID valid flag storage unit 14 (step S210).
Since the authentication tag 1 stored in the reception has been detached for a predetermined time or longer, the ID valid flag stored in the ID valid flag storage unit 14 is turned off. The ID valid flag is not turned on just by attaching this authentication tag 1 to the user. In the personal authentication device 2, the user is personally authenticated, the ID of the authentication tag 1 attached to the user is associated with the user's authentication information, and the associated ID information is registered. After that, the ID valid flag is turned on. As long as the authentication tag 1 is attached, the ID valid flag is on, so the user can use the equipment in the facility.
The operation that enables the security device 4 to use the equipment in the facility will be described with reference to the flowchart of FIG. First, the control means 42 of the security device 4 transmits a message requesting the ID and the ID valid flag to the authentication tag 1 via the wireless communication means 41 (step S301). This message transmission operation is performed at predetermined time intervals. In the authentication tag 1, the control means 12 receives the message via the wireless communication means 11. Then, the ID stored in the ID storage unit 13 and the ID valid flag stored in the ID valid flag storage unit 14 are transmitted to the security device 4 (step S302). The control means 42 of the security device 4 receives the ID and the ID valid flag from the authentication tag 1. Then, it is checked whether or not the received ID valid flag is turned on (step S303). If it is turned on (Yes in step S303), it is checked whether or not the received ID is in the ID information storage means 31 of the information management device 3 (step S304). If the ID is in the ID information storage means 31 (Yes in step S304), for example, the control means 42 sends a message instructing the lock / unlock control means 43 to unlock in order to permit the use of the equipment. The locking / unlocking control means 43 receives the message and unlocks the door 44 (step S305). As a result, the user can open and use the equipment in the facility, for example, the door 44 such as a room or a locker. When the ID valid flag is not on (No in step S303), or when the ID is not in the ID information storage means 31 (No in step S304), the control means 42 ends the operation without doing anything. Therefore, for example, the door. 44 will not open, and users will not be able to use rooms or lockers.
If it can be confirmed that the ID valid flag of the authentication tag 1 is turned on in the operation of the security device 4 (Yes in step S303), it is assumed that the ID is in the ID information storage means 31 and the ID is the ID information. The operation (step S305) that enables the use of the equipment may be performed by omitting the confirmation of whether or not the storage means 31 is present (step S304). The security device 4 can also be applied to vending machines in the facility. For example, when a user becomes able to use a vending machine due to the operation of the security device 4, when the selection button of the vending machine is pressed to acquire a product, the data of the amount of money is transmitted from the control means 42 via the network 6. It is sent to the ID information storage means 31, and the amount is added to the purchase amount of the ID information corresponding to the ID of the authentication tag 1 (see FIG. 3 (a)). It is desirable to encrypt the data of the amount and send it to the network 6 so that the data of the amount will not be illegally acquired or duplicated and used.
Subsequently, the operation when the personal information is re-registered by the personal authentication device 2 will be described with reference to the flowchart of FIG. Since this operation has a part in common with the operation when registering personal information, only a brief explanation will be given for that part. To re-register personal information, use the password set at the time of registration when the user has registered the personal information at the reception desk in the facility and then removed the authentication tag 1 due to an unexpected mistake. Turns on the ID valid flag for tag 1. First, the user attaches the once detached authentication tag 1 and goes to the reception desk to request the re-registration of personal information. Correspondingly, the receptionist presses the re-registration button (not shown) of the personal authentication device 2. As a result, the personal authentication device 2 starts the operation of re-registering the personal information. First, the control means 22 of the personal authentication device 2 transmits a message requesting the current attachment / detachment state to the authentication tag 1 (step S401). In the authentication tag 1, the control means 12 requests the attachment / detachment detection means 15 for the attachment / detachment state, and the attachment / detachment detection means 15 transmits the current attachment / detachment state information of the authentication tag 1 to the control means 12. The control means 12 transmits the received attachment / detachment state information to the personal authentication device 2 (step S402). In the personal authentication device 2, the control means 22 receives the attachment / detachment state information, and confirms whether or not the authentication tag 1 is attached to the user based on the received attachment / detachment state information (step S403). If it is installed (Yes in step S403), it sends a message requesting an ID to authentication tag 1 (step S404). If it is not installed (No in step S403), the operation of re-registering personal information is stopped. In the authentication tag 1, the control means 12 receives the ID request message and transmits the ID stored in the ID storage unit 13 to the personal authentication device 2 in response to the received message (step S405).
Further, in the personal authentication device 2, the control means 22 receives the ID. Then, it is confirmed that the ID information corresponding to the received ID is in the ID information storage means 31 (step S406), and it is checked whether or not there is a record of entering the building, that is, whether or not the building is being entered (step S406). Step S407). Specifically, the ID information (see FIG. 3A) stored in the ID information storage means 31 and corresponding to the received ID contains the entry time and the exit time. If not, it means that you are in the museum. If you are not in the library (No in step S407), the operation of re-registering personal information will be stopped. If you are in the library (Yes in step S407), enter the password remembered by the user using a keyboard or the like (step S408). If the ID matches the password entered in the ID information (Yes in step S409), a message is sent to authentication tag 1 instructing the ID valid flag to be turned on (step S410). In the authentication tag 1, the control means 12 receives the message and turns on the ID valid flag stored in the ID valid flag storage unit 14 (step S411). If the ID and password do not match (No in step S409), try again from the password entry (step S408).
In such an operation of the personal authentication device 2, when the mismatch between the ID and the password (No in step S409) continues for a predetermined number of times or more, the operation of re-registering the personal information may be stopped. This happens when the user forgets the password set when registering the personal information. In such a case, the registration of the personal information that requires the input of the authentication information is performed again. It will be.
Further, the operation of the security device 5 to manage the entrance / exit of the user will be described with reference to the flowchart of FIG. Since this operation has a part in common with the operation of the security device 4, only a brief explanation will be given to that part. First, when the entrance / exit detection means 53 of the security device 5 detects the passage of the user, the entrance / exit detection means 53 transmits the passage direction to the control means 52. If the received passage direction is admission (entry in step S501), the control means 52 ends the operation at that time. If the passing direction is exit (exit in step S501), a message requesting the ID and the ID valid flag is transmitted to the authentication tag 1 via the wireless communication means 51 (step S502). In the authentication tag 1, the control means 12 receives the message via the wireless communication means 11 and transmits the ID and the ID valid flag to the security device 5 (step S503). The control means 52 of the security device 5 receives the ID and the ID valid flag from the authentication tag 1. Then, it is checked whether or not the received ID valid flag is turned on (step S504). If it is turned on (Yes in step S504), it is checked whether or not the received ID is in the ID information storage means 31 of the information management device 3 (step S505). If the ID is in the ID information storage means 31 (Yes in step S505), the current time is recorded at the exit time of the ID information corresponding to the ID (step S506), and the ID valid flag is set in the authentication tag 1. Send a message instructing you to turn it off (step S507). In the authentication tag 1, the control means 12 receives the message and turns off the ID valid flag stored in the ID valid flag storage unit 14 (step S508). When the ID valid flag is not on (No in step S504) or when the ID is not in the ID information storage means 31 (No in step S505), the control means 52 ends the operation without doing anything.
Since the user who entered the facility needs to perform the admission procedure at the reception, when the security device 5 detects the admission (admission in step S501), the security device 5 gives a voice guidance prompting the user to go to the reception. You may make a call. In addition, when leaving the facility, the user usually leaves the facility after completing the exit procedure at the reception. However, if you accidentally leave the library without completing the exit procedure, the authentication tag 1 is still attached, so if the ID valid flag is on and the ID is in the ID information storage means 31, the exit time Shall be recorded. At this time, a voice guidance may be sent to urge the user to go to the reception desk for the formal exit procedure.
<< Embodiment applied to business establishments >> Next, an embodiment in which the personal authentication system already described is applied to business establishments will be described. The explanation that overlaps with the above-mentioned part is omitted, and the points that should be noted as application to business establishments are mainly described. First, when applied to a business establishment, since the user is an employee, it is considered that the personal information is registered in advance. Therefore, as an employee admission procedure, instead of entering the authentication information and setting the password as shown in the flowchart of FIG. 4, the password is entered. If you confirm that the entered password matches the password of the ID information corresponding to the ID of the authentication tag 1 you are wearing, you do not need to register personal information again and set the ID valid flag of the authentication tag 1 Can be turned on. In addition, since employees go out for lunch or business trips, it is difficult to manage the strict exit procedure when leaving the library. For example, wear the authentication tag 1 within 24 hours after the entry procedure. The ID valid flag is turned on as long as it is, but it is possible to turn it off after 24 hours. The operation of turning off the ID valid flag of the authentication tag 1 shall be performed by the nearest security device 4 at that time.
Next, the purpose of applying the personal authentication system to business establishments is to manage the current location of the employee in order to thoroughly manage the work of the employee while maintaining security. Therefore, in the flowchart of FIG. 5, the ID valid flag received from the authentication tag 1 by the control means 42 of the security device 4 attached to the equipment is turned on (Yes in step S303), and the received ID is also the ID information storage means. When it is at 31 (Yes in step S304), make the equipment available (step S305) and leave a new location information for authentication tag 1. That is, as shown in FIG. 3B, the control means 42 stores the detected ID of the authentication tag 1, the detected time, and the location information, which is the location, in the location information storage means of the information management device 3 via the network 6. Send to 32. Then, the position information storage means 32 stores the received position information. The detection location is not limited to the room identification number, and may be a facility name such as a vending machine. In addition, if the security device 5 installed at the entrance / exit also operates in the same manner, it is possible to keep a record of entry / exit.
Next, there is a PC (Personal Computer) as a facility often used in business establishments. By incorporating the function of the security device 4 into the PC and connecting the PC to the network 6, the authentication tag 1 can be used as an access key to the PC. At this time, the employee cannot use the PC unless the authentication tag 1 is attached. Further, a security level can be set in advance for the ID information stored in the ID information storage means 31, and the information that can be viewed can be restricted according to the security level. At this time, the fact that the information was browsed as a countermeasure against information leakage shall be recorded as a log. Furthermore, if the authentication tag 1 is attached or detached and the ID valid flag is turned off, the ID valid flag can be turned on by entering a password or performing fingerprint authentication on the PC. This corresponds to re-registration of personal information. However, in order to enable the re-registration of this personal information, it is necessary to incorporate the function of the personal authentication device 2 into the PC.
Although the embodiment of the present invention has been described above, the program executed by each means shown in FIG. 1 is recorded on a computer-readable recording medium, and the program recorded on the recording medium is read into a computer system. By executing this, the personal authentication system according to the embodiment of the present invention shall be realized. The computer system referred to here includes software such as an OS (Operating System) and hardware such as peripheral devices. Further, although an example of a preferred embodiment of the present invention has been shown above, the present invention is not limited to the above-described embodiment and can be appropriately modified without departing from the spirit of the present invention. For example, in order to enhance security, the authentication tag 1 may emit an alarm sound when the authentication tag 1 is attached or detached or when an employee wearing the authentication tag 1 leaves the place of employment.
<figref num="1">It is a figure which shows the block structure of the personal authentication system which concerns on embodiment of this invention.</figref><figref num="2">It is a figure which shows the specific example of the authentication tag which concerns on embodiment of this invention. (a) shows the chest type. (b) shows a wristband type. (c) shows a ring type.</figref><figref num="3">It is a figure which shows the structure of the shared information which concerns on embodiment of this invention. (a) shows the structure of ID information. (b) shows the structure of the position information.</figref><figref num="4">It is a flowchart which shows the operation of the registration of personal information which concerns on embodiment of this invention.</figref><figref num="5">It is a flowchart which shows the operation which enables the use of the equipment which concerns on embodiment of this invention.</figref><figref num="6">It is a flowchart which shows the operation of the re-registration of personal information which concerns on embodiment of this invention.</figref><figref num="7">It is a flowchart which shows the operation which manages the entrance / exit which concerns on embodiment of this invention.</figref>
Code description
1 Authentication tag 2 Personal authentication device 3 Information management device 4 Security device 6 Network 11 Wireless communication means (first wireless communication means) 12 Control means (first control means) 13 ID storage (authentication tag ID storage) 14 ID valid flag storage unit (authentication tag ID valid flag storage unit) 15 Detachment detection means (authentication tag attachment / detachment detection means) 21 Wireless communication means (second wireless communication means) 22 Control means (second control means) 23 Authentication information Input means 31 ID information storage means 32 Location information storage means 41 Wireless communication means (third wireless communication means) 42 Control means (third control means) 43 Locking / unlocking control means (equipment use control means)
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US12400518B2 | Cited by | United States of America | Applicant |
| US12475760B2 | Cited by | United States of America | Applicant |
| US12518596B2 | Cited by | United States of America | Applicant |
| JP2008198018A | Cited by | Japan | Search report |
| JP2018055513A | Cited by | Japan | Search report |
| JP2008146324A | Cited by | Japan | Search report |
| US12397226B2 | Cited by | United States of America | Applicant |
| JP2024097859A | Cited by | Japan | Search report |
| JP2021101343A | Cited by | Japan | Search report |
| JP2007304834A | Cited by | Japan | Search report |
| US12592121B2 | Cited by | United States of America | Applicant |
| JP2008234247A | Cited by | Japan | Search report |
| US12322241B2 | Cited by | United States of America | Applicant |
| JP2025075081A | Cited by | Japan | Search report |
| US12400515B2 | Cited by | United States of America | Applicant |
| JP2021002355A | Cited by | Japan | Search report |
| JP2007304835A | Cited by | Japan | Search report |
| CN106204777A | Cited by | China | Search report |
| US12194373B2 | Cited by | United States of America | Applicant |
| JP2008234247A | Cited by | Japan | Search report |
5 members in 3 offices
Members5
| Document | Office | Kind | |
|---|---|---|---|
| CN1606025A | China | A | |
| JP2005115786AThis record | Japan | A | |
| SG111219A1 | Singapore | A1 | |
| CN1312630C | China | C | |
| JP4150320B2 | Japan | B2 |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2005115786
- Application
- 351301
Titles2
- Japanese
- 個人認証システム、認証タグ及び個人認証方法
- English
- Personal authentication system, authentication tag and personal authentication method
Classification
- IPC, 8
- B42D15 10
- G06F1 00
- G06F15 00
- G06F21 33
- G06F21 34
- G06K7 00
- G06K17 00
- G06K19 10