CN115035633A - Access control system and access control method - Google Patents

Access control system and access control method Download PDF

Info

Publication number
CN115035633A
CN115035633A CN202210103009.XA CN202210103009A CN115035633A CN 115035633 A CN115035633 A CN 115035633A CN 202210103009 A CN202210103009 A CN 202210103009A CN 115035633 A CN115035633 A CN 115035633A
Authority
CN
China
Prior art keywords
random number
dimensional code
code
information
access
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN202210103009.XA
Other languages
Chinese (zh)
Other versions
CN115035633B (en
Inventor
秋丸雄祐
增田康宏
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hitachi Building Systems Co Ltd
Original Assignee
Hitachi Building Systems Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hitachi Building Systems Co Ltd filed Critical Hitachi Building Systems Co Ltd
Publication of CN115035633A publication Critical patent/CN115035633A/en
Application granted granted Critical
Publication of CN115035633B publication Critical patent/CN115035633B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/00174Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys
    • G07C9/00309Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06KGRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
    • G06K7/00Methods or arrangements for sensing record carriers, e.g. for reading patterns
    • G06K7/10Methods or arrangements for sensing record carriers, e.g. for reading patterns by electromagnetic radiation, e.g. optical sensing; by corpuscular radiation
    • G06K7/14Methods or arrangements for sensing record carriers, e.g. for reading patterns by electromagnetic radiation, e.g. optical sensing; by corpuscular radiation using light without selection of wavelength, e.g. sensing reflected white light
    • G06K7/1404Methods for optical code recognition
    • G06K7/1408Methods for optical code recognition the method being specifically adapted for the type of code
    • G06K7/14172D bar codes
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/00174Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys
    • G07C9/00309Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks
    • G07C2009/0042Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks the transmitted data signal containing a code which is changed
    • G07C2009/00476Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks the transmitted data signal containing a code which is changed dynamically
    • G07C2009/005Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks the transmitted data signal containing a code which is changed dynamically whereby the code is a random code

Landscapes

  • Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Electromagnetism (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Toxicology (AREA)
  • Artificial Intelligence (AREA)
  • Computer Vision & Pattern Recognition (AREA)
  • Theoretical Computer Science (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Time Recorders, Dirve Recorders, Access Control (AREA)
  • Lock And Its Accessories (AREA)
  • Alarm Systems (AREA)

Abstract

本发明提供出入管理系统及方法,能够使控制出入的装置与个人终端间的信息收发不依赖于不稳定的无线通信,稳定且瞬时地执行认证处理。在出入管理系统,控制终端(2)具备:随机数生成部(5),生成能唯一决定二维码的随机数;二维码输出部(6),生成将随机数生成部(5)生成的随机数作为信息嵌入的二维码图像,显示于与控制终端(2)连接的二维码读取器的画面;以及二维码认证部(7),判定从显示于个人终端(30)画面的出入认证用的二维码图像读取的随机数是否是二维码读取器生成的随机数。个人终端(30)具备二维码生成部(34),生成将从显示于二维码读取器的二维码图像读取的随机数作为信息嵌入的出入认证用的二维码图像并显示于画面。

Figure 202210103009

The present invention provides an access management system and method, which enables stable and instantaneous authentication processing to be performed without relying on unstable wireless communication for information transmission and reception between an access control device and a personal terminal. In the access management system, the control terminal (2) is provided with: a random number generator (5) that generates a random number that can uniquely determine a two-dimensional code; a two-dimensional code output part (6) that generates a random number generator (5) that generates a random number The random number of the two-dimensional code image embedded as information is displayed on the screen of the two-dimensional code reader connected to the control terminal (2); Whether the random number read by the QR code image for the screen access authentication is a random number generated by the QR code reader. The personal terminal (30) includes a two-dimensional code generation unit (34) that generates and displays a random number read from the two-dimensional code image displayed on the two-dimensional code reader as information embedded in a two-dimensional code image for access authentication on the screen.

Figure 202210103009

Description

出入管理系统以及出入管理方法Access management system and access management method

技术领域technical field

本发明涉及出入管理系统以及出入管理方法。The present invention relates to an access management system and an access management method.

背景技术Background technique

在进行向大厦等的出入时,从安全、出入管理的观点出发,有时在入口设置有认证装置和根据认证结果进行动作的开锁装置。通常,将IC卡等认证介质放置在认证装置上,读取登记在相应的认证介质中的唯一编号等信息,在判定为被给予了通行对象的门等的许可的情况下,开锁装置工作而成为能够出入的结构。When entering or leaving a building or the like, from the viewpoint of safety and access control, an authentication device and an unlocking device that operates according to the authentication result may be installed at the entrance. Usually, an authentication medium such as an IC card is placed on the authentication device, and information such as a unique number registered in the corresponding authentication medium is read, and when it is determined that permission has been given to a door or the like to pass through, the unlocking device is activated and into a structure that can be accessed.

在专利文献1中,公开了在个人终端与出入设备之间使用无线通信技术来收发出入时的认证信息,从而控制出入设备的技术。Patent Document 1 discloses a technique for controlling the access device by using wireless communication technology between a personal terminal and an access device to send and receive authentication information at the time of access.

专利文献1:日本特开2013-204233号公报Patent Document 1: Japanese Patent Laid-Open No. 2013-204233

发明内容SUMMARY OF THE INVENTION

发明要解决的课题The problem to be solved by the invention

专利文献1所记载的技术的便利性受无线通信的稳定性影响,在无线通信因设置场所、环境而不稳定的情况下,便利性大幅受损。The convenience of the technique described in Patent Document 1 is affected by the stability of wireless communication, and when the wireless communication is unstable depending on the installation location and environment, the convenience is greatly impaired.

本发明是鉴于上述状况而完成的,其目的在于,使控制出入的装置与个人终端之间的信息的收发不依赖于不稳定的无线通信,能够稳定且瞬时地执行认证处理。The present invention has been made in view of the above-mentioned circumstances, and an object of the present invention is to enable stable and instantaneous authentication processing to be performed without relying on unstable wireless communication for transmission and reception of information between an access control device and a personal terminal.

用于解决课题的手段means of solving problems

为了解决上述课题,本发明的一个方式的出入管理系统包括:控制终端,其具有所连接的出入设备的管理功能以及出入人员的认证功能;以及个人终端,其保持确定出入人员的二维码的识别信息,并具有二维码的读取以及生成功能。In order to solve the above-mentioned problems, an access management system according to an aspect of the present invention includes: a control terminal having a management function of the connected access equipment and an authentication function of an access person; Identification information, and has the function of reading and generating two-dimensional codes.

所述控制终端具备:The control terminal has:

随机数生成部,其以预先决定的周期生成并发行能够唯一地决定二维码的随机数;a random number generation unit that generates and issues a random number capable of uniquely determining the two-dimensional code at a predetermined cycle;

二维码输出部,其生成将由该随机数生成部发行的随机数作为信息而嵌入的二维码图像,并显示在与控制终端连接的二维码读取器的画面上;以及A two-dimensional code output unit that generates a two-dimensional code image in which the random number issued by the random number generating unit is embedded as information, and displays it on a screen of a two-dimensional code reader connected to the control terminal; and

二维码认证部,其判定从显示于个人终端的画面的用于出入认证的二维码图像读取的随机数是否是由二维码读取器生成的随机数。A two-dimensional code authentication unit that determines whether or not the random number read from the two-dimensional code image for access authentication displayed on the screen of the personal terminal is a random number generated by the two-dimensional code reader.

所述个人终端具备:The personal terminal has:

二维码生成部,其生成将从显示于二维码读取器的二维码图像读取的随机数作为信息而嵌入的用于出入认证的二维码图像,并显示于画面。A two-dimensional code generation unit that generates a two-dimensional code image for access authentication embedded as information from a random number read from a two-dimensional code image displayed on a two-dimensional code reader, and displays it on a screen.

发明效果Invention effect

根据本发明的至少一个方式,能够使控制出入的控制终端与个人终端之间的信息的收发不依赖于不稳定的无线通信,而稳定且瞬时地执行认证处理。According to at least one aspect of the present invention, it is possible to stably and instantaneously execute authentication processing without relying on unstable wireless communication for transmission and reception of information between a control terminal that controls access and a personal terminal.

上述以外的课题、结构以及效果通过以下的实施方式的说明而变得明确。Problems, structures, and effects other than those described above will be clarified by the description of the following embodiments.

附图说明Description of drawings

图1是表示本发明的一实施方式涉及的包含大厦内的控制终端、个人终端以及信息管理装置的出入管理系统的整体结构例的概略图。1 is a schematic diagram showing an overall configuration example of an access management system including a control terminal, a personal terminal, and an information management apparatus in a building according to an embodiment of the present invention.

图2是表示本发明的一实施方式涉及的QR码读取器的概略结构和个人终端的概略结构的图。2 is a diagram showing a schematic configuration of a QR code reader and a schematic configuration of a personal terminal according to an embodiment of the present invention.

图3是表示本发明的一实施方式的控制终端的硬件结构例的框图。3 is a block diagram showing an example of a hardware configuration of a control terminal according to an embodiment of the present invention.

图4是表示本发明的一实施方式的信息管理装置(数据中心)的硬件结构例的框图。4 is a block diagram showing an example of a hardware configuration of an information management apparatus (data center) according to an embodiment of the present invention.

图5是表示本发明的一实施方式的个人终端的硬件结构例的框图。5 is a block diagram showing an example of a hardware configuration of a personal terminal according to an embodiment of the present invention.

图6是表示本发明的一实施方式涉及的控制终端的随机数发行履历区域的数据结构例的图。6 is a diagram showing an example of a data structure of a random number issuance history area of a control terminal according to an embodiment of the present invention.

图7是表示本发明的一实施方式涉及的控制终端的通行许可列表记录区域的数据结构例的图。7 is a diagram showing an example of the data structure of the access permission list recording area of the control terminal according to the embodiment of the present invention.

图8是表示本发明的一实施方式涉及的信息管理装置(数据中心)的个人信息记录区域的数据结构例的图。8 is a diagram showing an example of a data structure of a personal information recording area of an information management device (data center) according to an embodiment of the present invention.

图9是表示本发明的一实施方式涉及的信息管理装置(数据中心)的通行许可列表记录区域的数据结构例的图。9 is a diagram showing an example of a data structure of a pass permission list recording area of an information management device (data center) according to an embodiment of the present invention.

图10是表示本发明的一实施方式涉及的个人终端的QR码信息区域的数据结构例的图。10 is a diagram showing an example of a data structure of a QR code information area of a personal terminal according to an embodiment of the present invention.

图11是表示本发明的一实施方式涉及的出入管理系统整体的动作例的时序图。11 is a sequence diagram showing an example of the operation of the entire access management system according to the embodiment of the present invention.

图12是表示本发明的一实施方式涉及的信息管理装置的通行许可列表制作部的处理例的流程图。12 is a flowchart showing an example of processing performed by the access permission list creation unit of the information management device according to the embodiment of the present invention.

图13是表示本发明的一实施方式涉及的信息管理装置的个人终端通信部的处理例的流程图。13 is a flowchart showing an example of processing performed by the personal terminal communication unit of the information management apparatus according to the embodiment of the present invention.

图14是表示本发明的一实施方式涉及的控制终端的随机数生成部的处理例的流程图。14 is a flowchart showing an example of processing performed by the random number generation unit of the control terminal according to the embodiment of the present invention.

图15是表示本发明的一实施方式涉及的个人终端的QR码生成部的处理例的流程图。15 is a flowchart showing an example of processing performed by the QR code generation unit of the personal terminal according to the embodiment of the present invention.

图16是表示本发明的一实施方式涉及的控制终端的QR码认证部的处理例的流程图。16 is a flowchart showing an example of processing performed by the QR code authentication unit of the control terminal according to the embodiment of the present invention.

附图标记说明Description of reference numerals

1…大厦(大厦设施)、2…控制终端、3…通信装置、4…控制装置、5…随机数生成部、6…QR码输出部、7…QR码认证部、8…控制终端DB、8A…随机数发行履历区域、8B…通行许可列表记录区域、9…专有部(1)、9A…QR码读取器、9B…电子锁、10…专有部(2)、10A…QR码读取器、10B…电子锁、20…信息管理装置(数据中心)、21…通信装置、22…控制装置、23…通行许可列表制作部、24…个人终端通信部、25…出入人员信息存储区域、25A…出入人员主信息区域、25B…个人信息记录区域、25C…通行许可列表记录区域、30…个人终端、31…通信装置、32…控制装置、33…专用应用程序、34…QR码生成部、35…个人终端DB、35A…QR码信息区域、40…出入人员信息登记PC、41…通信装置、50…出入管理系统、N…网络线路、PA1~PA2…QR码读取器概略结构、PB1~PB2…个人终端概略结构、MA1~MA5…随机数发行履历区域、MB1~MB5…通行许可列表记录区域、MC1~MC6…个人信息记录区域、MD1~MD7…通行许可列表记录区域、ME1~ME5…QR码信息区域。1...building (building facility), 2...control terminal, 3...communication device, 4...control device, 5...random number generation unit, 6...QR code output unit, 7...QR code authentication unit, 8...control terminal DB, 8A...random number issuance history area, 8B...pass permission list recording area, 9...exclusive part (1), 9A...QR code reader, 9B...electronic lock, 10...exclusive part (2), 10A...QR code Code reader, 10B...electronic lock, 20...information management device (data center), 21...communication device, 22...control device, 23...pass permission list creation unit, 24...personal terminal communication unit, 25...entry and exit information Storage area, 25A...entry and exit master information area, 25B...personal information recording area, 25C...pass permission list recording area, 30...personal terminal, 31...communication device, 32...control device, 33...dedicated application, 34...QR Code generation unit, 35...personal terminal DB, 35A...QR code information area, 40...entry and exit personnel information registration PC, 41...communication device, 50...entry and exit management system, N...network line, PA1 to PA2...QR code reader Schematic structure, PB1 to PB2... Personal terminal schematic structure, MA1 to MA5... Random number issuance history area, MB1 to MB5... Access permission list recording area, MC1 to MC6... Personal information recording area, MD1 to MD7... Access permission list recording area , ME1~ME5…QR code information area.

具体实施方式Detailed ways

以下,参照附图对用于实施本发明的方式的例子进行说明。在本说明书和附图中,对具有实质上相同的功能或结构的构成要素标注相同的符号并省略重复的说明。Hereinafter, an example of an embodiment for carrying out the present invention will be described with reference to the drawings. In this specification and the drawings, components that have substantially the same function or structure are denoted by the same reference numerals, and repeated explanation is omitted.

[出入管理系统的整体结构][Overall structure of access management system]

首先,参照图1对本发明的一实施方式涉及的出入管理系统的整体结构进行说明。First, with reference to FIG. 1, the whole structure of the access control system concerning one Embodiment of this invention is demonstrated.

图1是表示本发明的一实施方式涉及的包含大厦内的控制终端、个人终端的出入管理系统的整体结构例的概略图。出入管理系统50通过设置于用户出入的设施(建筑物、管理分区等)的控制终端2、用户携带的个人终端30、设置于数据中心的信息管理装置20的协作,来管理对设施的出入。FIG. 1 is a schematic diagram showing an overall configuration example of an access management system including a control terminal and a personal terminal in a building according to an embodiment of the present invention. The access management system 50 manages access to the facility through the cooperation of the control terminal 2 installed in the facility (building, management area, etc.) where the user accesses, the personal terminal 30 carried by the user, and the information management device 20 installed in the data center.

在出入管理系统50中,出入人员信息登记人员进行利用由设置有出入管理设备的设施1(以下称为“大厦设施1”)管理的出入设备(例如,QR码读取器9A、电子锁9B)的出入人员的信息的登记。由此,出入管理系统50仅在出入人员信息登记人员许可的情况下进行对大厦设施1的专有部的退出。在图1的例子中,作为大厦设施1示出了A大厦的任意层(n层)。In the access management system 50, the access person information registration personnel use access equipment (eg, QR code reader 9A, electronic lock 9B) managed by facility 1 (hereinafter referred to as "building facility 1") provided with access management equipment ) registration of the information of the entry and exit personnel. Thereby, the access control system 50 performs withdrawal from the exclusive part of the building facility 1 only when the access person information registration person permits. In the example of FIG. 1 , an arbitrary floor (n floor) of Building A is shown as the building facility 1 .

本实施方式的出入管理系统50在将表示允许出入的信息传递给QR码读取器时,能够稳定且瞬时地传递信息,并且防止不允许出入的第三者的出入。The access control system 50 of the present embodiment can transmit the information stably and instantaneously when the information indicating the access is permitted to the QR code reader, and can prevent the access of a third party who is not permitted to access.

如图1所示,在出入管理系统50中,设置有出入设备的大厦设施1内的各设备经由通信装置3,经由形成广域网的网络线路N与信息管理装置20连接。例如,出入设备是控制终端2、专有部9以及专有部10。设置于共用部的控制终端2具备控制装置4、随机数生成部5、QR码输出部6、QR码认证部7以及控制终端存储区域8(图中为“控制终端DB8”)。As shown in FIG. 1, in the access management system 50, each facility in the building facility 1 provided with access facilities is connected to the information management apparatus 20 via the communication apparatus 3 via the network line N forming the wide area network. For example, the access equipment is the control terminal 2 , the exclusive part 9 , and the exclusive part 10 . The control terminal 2 provided in the common unit includes a control device 4, a random number generator 5, a QR code output unit 6, a QR code authentication unit 7, and a control terminal storage area 8 (“control terminal DB8” in the figure).

在作为管理分区的专有部9(以下,也称为“专有部(1)”)的出入用的门上,设置有与控制装置4连接的QR码读取器9A和电子锁9B。在专有部10(以下,也称为“专有部(2)”)的出入用的门上,设置有与控制装置4连接的QR码读取器10A和电子锁10B。A QR code reader 9A and an electronic lock 9B connected to the control device 4 are provided on the access door of the exclusive part 9 (hereinafter, also referred to as "exclusive part ( 1 )") which is a management area. A QR code reader 10A and an electronic lock 10B connected to the control device 4 are provided on a door for entry and exit of the exclusive part 10 (hereinafter, also referred to as "an exclusive part (2)").

QR码读取器9A、10A是读取出入专有部9、10的人所持有的QR码(注册商标)并转换为二进制数据的装置。QR码读取器是二维码读取器的示例。在本实施方式中,作为二维码而利用QR码,但也可以应用QR码以外的矩阵型二维码或堆叠型二维码。The QR code readers 9A and 10A are devices that read QR codes (registered trademarks) held by persons who enter and exit the exclusive parts 9 and 10 and convert them into binary data. A QR code reader is an example of a two-dimensional code reader. In the present embodiment, a QR code is used as the two-dimensional code, but a matrix-type two-dimensional code or a stack-type two-dimensional code other than the QR code may be applied.

电子锁9B、10B是按照大厦设施1的每个管理分区设置在该管理分区的边界的锁。根据来自控制终端2的解锁指令以及上锁指令进行电子锁9B、10B的解锁以及上锁,由此对门进行开闭,控制出入人员向管理分区的通行。The electronic locks 9B and 10B are locks provided at the boundary of each management zone of the building facility 1 . The electronic locks 9B and 10B are unlocked and locked according to the unlocking command and the locking command from the control terminal 2 , thereby opening and closing the door, and controlling the passage of people entering and leaving to the management area.

另外,在出入管理系统50中,经由网络线路N连接信息管理装置20和个人终端30。Moreover, in the access control system 50, the information management apparatus 20 and the personal terminal 30 are connected via the network line N.

另外,对于出入设备,能够以A大厦1层2个、2层6个的方式在大厦设施1内设定多个设备,根据系统结构、出入设备的结构等,成为对象的出入设备的数量发生变化。另外,对于个人终端30而言,能够设定满足用于导入与出入管理系统50对应的应用程序的要件的个人终端30即可,不受制造商、机型等束缚。In addition, as for the access facility, a plurality of facilities can be set up in the building facility 1, such as two on the first floor of Building A and six on the second floor, and the number of targeted access facilities can be generated according to the system configuration, the structure of the access facility, and the like. Variety. In addition, as for the personal terminal 30, a personal terminal 30 that satisfies the requirements for introducing an application program corresponding to the access management system 50 can be set, and is not limited by a manufacturer, a model, or the like.

大厦设施1具有出入设备。此外,大厦设施1具有用于管理出入设备的各设备的控制终端2以及与网络线路N进行连接的通信装置3。通信装置3被用作路由装置。Building facility 1 has access facilities. Moreover, the building facility 1 has the control terminal 2 for managing each facility of an access facility, and the communication apparatus 3 connected with the network line N. The communication device 3 is used as a routing device.

信息管理装置20具有与网络线路N进行连接的通信装置21、通行许可列表制作部23、个人终端通信部24、出入人员信息存储区域25(以下,称为“出入人员信息DB25”)。The information management device 20 includes a communication device 21 connected to the network line N, a pass permission list creation unit 23, a personal terminal communication unit 24, and an entry/exit information storage area 25 (hereinafter, referred to as "entry/exit information DB 25").

个人终端30具有与网络线路N进行连接的通信装置31、专用应用33、QR码生成部34以及个人终端存储区域35(以下,称为“个人终端DB35”)。The personal terminal 30 includes a communication device 31 connected to the network line N, a dedicated application 33, a QR code generator 34, and a personal terminal storage area 35 (hereinafter, referred to as "personal terminal DB 35").

出入人员信息登记PC40是进行出入人员信息的登记的登记人员进行向信息管理装置20登记出入人员信息的作业时所使用的客户端用计算机。出入人员信息登记PC40使用个人计算机等。由出入人员信息登记PC40输入的出入人员信息经由通信装置41被发送至信息管理装置20,并登记于出入人员信息DB25。通信装置41具有与通信装置3相同的结构。The entry and exit information registration PC 40 is a client computer used when a registrant who registers entry and exit information performs an operation of registering entry and exit information in the information management device 20 . A personal computer or the like is used as the entry and exit person information registration PC 40 . The entry and exit information entered by the entry and exit information registration PC 40 is transmitted to the information management device 20 via the communication device 41 and registered in the entry and exit information DB 25 . The communication device 41 has the same configuration as the communication device 3 .

[控制终端][Control Terminal]

接着,对控制终端2进行更具体的说明。Next, the control terminal 2 will be described in more detail.

控制终端2内的控制装置4将由信息管理装置20的通行许可列表制作部23制作的许可列表经由网络线路N和通信装置3存储到控制终端DB8中。另外,将由随机数生成部5生成的随机数存储到随机数发行履历区域8A中。另外,将由QR码输出部6生成的QR码图像输出到QR码读取器9A的画面。另外,将由QR码读取器9A的内置照相机(图2的QR码读取照相机PA2)取得的QR码图像发送至QR码认证部7。另外,在接受QR码认证部7中的认证判定的结果而进行电子锁9B的开锁的情况下,向电子锁9B发送开锁命令。The control device 4 in the control terminal 2 stores the permission list created by the pass permission list creation unit 23 of the information management device 20 in the control terminal DB 8 via the network line N and the communication device 3 . In addition, the random number generated by the random number generating unit 5 is stored in the random number issuance history area 8A. In addition, the QR code image generated by the QR code output unit 6 is output to the screen of the QR code reader 9A. In addition, the QR code image acquired by the built-in camera of the QR code reader 9A (the QR code reading camera PA2 in FIG. 2 ) is sent to the QR code authentication unit 7 . In addition, when the electronic lock 9B is unlocked in response to the result of the authentication determination in the QR code authentication unit 7 , an unlock command is transmitted to the electronic lock 9B.

控制终端2内的随机数生成部5对每个QR码读取器生成用于唯一地决定QR码读取器的随机数。随机数生成部5将生成的随机数与随机数发行履历区域8A中的过去的发行履历进行对照,如果是过去未使用的随机数,则新存储到随机数发行履历区域8A中。在随机数发行履历区域8A中已经保存有相同的随机数的情况下,随机数生成部5再次进行随机数生成处理。The random number generator 5 in the control terminal 2 generates a random number for uniquely determining the QR code reader for each QR code reader. The random number generation unit 5 compares the generated random number with the past issuance history in the random number issuance history area 8A, and if it is a random number that has not been used in the past, newly stores it in the random number issuance history area 8A. When the same random number is already stored in the random number issuance history area 8A, the random number generation unit 5 performs the random number generation process again.

控制终端2内的QR码输出部6(二维码输出部的一例)从存储在随机数发行履历区域8A中的随机数中取得最新的随机数,并且生成嵌入有该随机数信息的QR码。将所生成的QR码图像输出到QR码读取器9A的画面。定期地执行该QR码输出部6的处理,判定存储在随机数发行履历区域8A中的当前显示中的QR码所使用的随机数的使用次数是否为1次、或者QR码是否显示了指定的时间以上。然后,QR码输出部6在判定为当前显示中的QR码所使用的随机数的使用次数为1次或者QR码持续显示了指定的时间以上的情况下,生成嵌入了新的随机数的QR码,并再次显示于QR码读取器9A。The QR code output unit 6 (an example of the two-dimensional code output unit) in the control terminal 2 obtains the latest random number from the random numbers stored in the random number issuance history area 8A, and generates a QR code in which the random number information is embedded . The generated QR code image is output to the screen of the QR code reader 9A. The processing of the QR code output unit 6 is periodically executed, and it is determined whether the random number used for the currently displayed QR code stored in the random number issuance history area 8A has been used once, or whether the QR code has displayed a specified number of times. over time. Then, the QR code output unit 6 generates a QR in which a new random number is embedded when it is determined that the number of times of use of the random number used in the currently displayed QR code is one or that the QR code has been displayed for a specified time or longer. code and displayed again on the QR code reader 9A.

控制终端2内的QR码认证部7(二维码认证部的一例)经由QR码读取器9A取得显示于个人终端30的QR码,并取得QR码生成日期时间、随机数、QRID(详情后述)。然后,QR码认证部7对QR码生成日期时间和当前时刻进行比较,判定从QR码生成日期时间起的经过时间是否在出入管理系统50中设定的固定时间内。The QR code authentication unit 7 (an example of the two-dimensional code authentication unit) in the control terminal 2 acquires the QR code displayed on the personal terminal 30 via the QR code reader 9A, and acquires the QR code generation date and time, random number, QRID (details). described later). Then, the QR code authentication unit 7 compares the QR code generation date and time with the current time, and determines whether or not the elapsed time from the QR code generation date and time is within the fixed time set in the access management system 50 .

在该时间判定中满足了判定条件的情况下,接下来QR码认证部7将所取得的随机数与随机数发行履历区域8A进行比较,判定是否存在作为QR码读取器9A用的随机数而发行的履历且使用次数是否为0次。When the determination conditions are satisfied in this time determination, the QR code authentication unit 7 next compares the acquired random number with the random number issuance history area 8A, and determines whether or not there is a random number for the QR code reader 9A. And whether the history of issuance and the number of times of use is 0.

在该随机数判定中满足了判定条件的情况下,接下来,QR码认证部7判定所取得的QRID在通行许可列表记录区域8B中是否许可了QR码读取器9A的通行。When the determination conditions are satisfied in this random number determination, the QR code authentication unit 7 next determines whether or not the acquired QRID has permitted the passage of the QR code reader 9A in the passage permission list recording area 8B.

在该QRID判定中满足了判定条件的情况下,接着QR码认证部7许可允许了QR码读取器9A的通行,向电子锁9B发送开锁命令。When the determination conditions are satisfied in this QRID determination, the QR code authentication unit 7 then permits the passage of the QR code reader 9A, and transmits an unlock command to the electronic lock 9B.

控制终端DB8具有随机数发行履历区域8A和通行许可列表记录区域8B。对于随机数发行履历区域8A和通行许可列表记录区域8B的详细内容,参照图6以及图7在后面叙述。The control terminal DB 8 has a random number issuance history area 8A and a pass permission list recording area 8B. Details of the random number issuance history area 8A and the pass permission list recording area 8B will be described later with reference to FIGS. 6 and 7 .

[信息管理装置][Information Management Device]

接着,对信息管理装置20进行更具体的说明。Next, the information management device 20 will be described in more detail.

信息管理装置20内的控制装置22经由网络线路N和通信装置21,将由出入人员信息登记PC40输入的出入人员的信息存储在出入人员主信息区域25A中。另外,在出入人员信息被存储于出入人员主信息区域25A之后,将通行许可列表制作部23制作的通行许可列表存储于通行许可列表记录区域25C。另外,在通行许可列表记录区域25C中存储了通行许可列表之后,从个人信息记录区域25B中确定个人终端,个人终端通信部24经由网络线路N和通信装置21向对象的个人终端30发送存储于通行许可列表记录区域25C中的QRID。The control device 22 in the information management device 20 stores the entry and exit person information input by the entry and exit person information registration PC 40 in the entry and exit person master information area 25A via the network line N and the communication device 21 . In addition, after the entry/exit person information is stored in the entry/exit person master information area 25A, the passage permission list created by the passage permission list creation unit 23 is stored in the passage permission list recording area 25C. In addition, after the access permission list is stored in the access permission list recording area 25C, the personal terminal is specified from the personal information recording area 25B, and the personal terminal communication unit 24 transmits the data stored in the target personal terminal 30 via the network line N and the communication device 21 to the target personal terminal 30 . The QRID in the pass permission list recording area 25C.

通行许可列表制作部23对于从出入人员信息登记PC40登记的出入人员信息,将出入人员的信息(例如姓名)和出入信息(例如出入日期时间)关联起来,为了唯一地检索这些信息,在出入管理系统50内发行唯一的随机数作为QRID。将发行的QRID与出入人员信息关联起来的信息存储在通行许可列表记录区域25C中。The access permission list creation unit 23 associates the information (for example, the name) of the person entering and leaving with the entry and exit information (for example, the entry and exit date and time) with respect to the entry and exit information registered from the entry and exit information registration PC 40, and in order to uniquely retrieve these information, the entry and exit management is performed. A unique random number is issued within the system 50 as a QRID. Information that associates the issued QRID with the entry and exit information is stored in the passage permission list recording area 25C.

个人终端通信部24将记录于通行许可列表记录区域25C中的QRID发送给对象的个人终端。The personal terminal communication unit 24 transmits the QRID recorded in the pass permission list recording area 25C to the target personal terminal.

出入人员信息DB25具有出入人员主信息区域25A、个人信息记录区域25B以及通行许可列表记录区域25C。在出入人员主信息区域25A中,作为出入人员主信息,登记并存储有与出入人员相关的信息、与出入预定相关的信息、与大厦设施相关的信息等。另外,关于个人信息记录区域25B和通行许可列表记录区域25C的详细情况,参照图8和图9在后面叙述。The entry/exit person information DB 25 has an entry/exit person main information area 25A, a personal information recording area 25B, and a passage permission list recording area 25C. In the entry/exit master information area 25A, as entry/exit master information, information regarding entry/exit persons, information regarding entry/exit schedule, information regarding building facilities, and the like are registered and stored. In addition, the details of the personal information recording area 25B and the pass permission list recording area 25C will be described later with reference to FIGS. 8 and 9 .

[个人终端][personal terminal]

接下来,对个人终端30更具体地进行说明。Next, the personal terminal 30 will be described in more detail.

个人终端30具备通信装置31、控制装置32、专用应用程序33、QR码生成部34、个人终端存储区域35(图中“个人终端存储区域35”)。以下,将专用应用程序简称为专用应用。The personal terminal 30 includes a communication device 31, a control device 32, a dedicated application 33, a QR code generator 34, and a personal terminal storage area 35 ("personal terminal storage area 35" in the figure). Hereinafter, the dedicated application is simply referred to as a dedicated application.

个人终端30内的控制装置32将从信息管理装置20发送的QRID信息经由网络线路N和通信装置21存储于QR码信息区域35A。另外,控制装置32从由QR码生成部34读取到的大厦设施1的QR码读取器所显示的QR码图像取得随机数。然后,控制装置32根据QR码图像生成嵌入了随机数的QR码,并显示于个人终端30的画面PB2。The control device 32 in the personal terminal 30 stores the QRID information transmitted from the information management device 20 in the QR code information area 35A via the network line N and the communication device 21 . In addition, the control device 32 acquires a random number from the QR code image displayed by the QR code reader of the building facility 1 read by the QR code generation unit 34 . Then, the control device 32 generates a QR code with embedded random numbers from the QR code image, and displays it on the screen PB2 of the personal terminal 30 .

QR码生成部34(二维码生成部的一例)从显示于大厦设施1的QR码读取器的QR码图像中取得随机数。然后,QR码生成部34使用所取得的随机数、存储于QR码信息区域35A的QRID以及从个人终端30取得的当前时刻来生成QR码,并显示于个人终端30的画面PB2。The QR code generation unit 34 (an example of the two-dimensional code generation unit) acquires a random number from the QR code image displayed on the QR code reader of the building facility 1 . Then, the QR code generation unit 34 generates a QR code using the acquired random number, the QRID stored in the QR code information area 35A, and the current time acquired from the personal terminal 30 and displays it on the screen PB2 of the personal terminal 30 .

个人终端DB35具有作为QR码信息而存储QRID的QR码信息区域35A。对于QR码信息区域35A的详细内容,参照图10在后面叙述。The personal terminal DB 35 has a QR code information area 35A in which a QRID is stored as QR code information. Details of the QR code information area 35A will be described later with reference to FIG. 10 .

[QR码读取器以及个人终端的概略结构][Schematic structure of QR code reader and personal terminal]

接下来,参照图2对QR码读取器以及个人终端的概要结构进行说明。Next, the schematic configuration of the QR code reader and the personal terminal will be described with reference to FIG. 2 .

图2表示QR码读取器9A、10A的概略结构和个人终端30的概略结构。图2左侧所示的QR码读取器9A、10A构成为具备QR码显示部PA1和QR码读取照相机PA2。在QR码显示部PA1中,显示嵌入有用于唯一地确定QR码读取器的随机数的QR码图像。另外,QR码读取照相机PA2位于QR码显示部PA1的下部,被调整为在与通常的个人终端30(例如智能手机)正对的情况下,能够使个人终端30的画面PB2收敛于QR码读取照相机PA2的视场角内。FIG. 2 shows a schematic configuration of the QR code readers 9A and 10A and a schematic configuration of the personal terminal 30 . The QR code readers 9A and 10A shown on the left side of FIG. 2 are configured to include a QR code display unit PA1 and a QR code reading camera PA2. In the QR code display part PA1, a QR code image in which a random number for uniquely identifying a QR code reader is embedded is displayed. In addition, the QR code reading camera PA2 is located at the lower part of the QR code display part PA1, and is adjusted so that the screen PB2 of the personal terminal 30 can be adjusted to the QR code when it faces the normal personal terminal 30 (for example, a smartphone). Read within the field of view of camera PA2.

图2右侧所示的个人终端30构成为具备照相机PB1和画面PB2。照相机PB1是所谓的内置照相机,设置在与画面PB2相同的面。在使QR码读取器9A、10A与个人终端30正对时,大致成为照相机PB1与QR码显示部PA1对置、画面PB2与QR码读取照相机PA2对置的配置。图2右侧的例子是通常的移动终端(例如智能手机、平板型终端)的结构,但只要是具备照相机PB1和画面PB2的结构即可,并不限定上下关系等。例如,即使是在画面PB2下部设置有照相机PB1的终端,也能够通过使终端上下反转而视为与图2右图相同。The personal terminal 30 shown on the right side of FIG. 2 is configured to include a camera PB1 and a screen PB2. The camera PB1 is a so-called built-in camera, and is provided on the same surface as the screen PB2. When the QR code readers 9A and 10A and the personal terminal 30 face each other, the camera PB1 and the QR code display part PA1 are generally opposed to each other, and the screen PB2 and the QR code reading camera PA2 are opposed to each other. The example on the right side of FIG. 2 is a configuration of a normal mobile terminal (eg, a smartphone, a tablet terminal), but the vertical relationship is not limited as long as the configuration includes a camera PB1 and a screen PB2. For example, even if it is a terminal provided with the camera PB1 in the lower part of the screen PB2, it can be regarded as the same as the right figure in FIG. 2 by inverting the terminal up and down.

接下来,参照图3~图5对控制终端2、信息管理装置20以及个人终端30各自的硬件结构进行说明。Next, the hardware configuration of each of the control terminal 2 , the information management device 20 , and the personal terminal 30 will be described with reference to FIGS. 3 to 5 .

[控制终端的硬件结构][Hardware structure of the control terminal]

图3是表示图1所示的控制终端2的硬件结构例的框图。图2所示的控制终端2的硬件结构例相当于计算机,能够使用个人计算机等来实现。FIG. 3 is a block diagram showing an example of a hardware configuration of the control terminal 2 shown in FIG. 1 . The example of the hardware configuration of the control terminal 2 shown in FIG. 2 corresponds to a computer, and can be realized using a personal computer or the like.

控制终端2具备与系统总线连接的CPU(Central Processing Unit:中央处理单元)110、ROM(Read Only Memory:只读存储器)120、RAM(Random Access Memory:随机存取存储器)130以及非易失性存储装置140。另外,具备用于进行与外部装置的通信的网络接口(图中表述为“网络IF”)150。The control terminal 2 includes a CPU (Central Processing Unit) 110 connected to a system bus, a ROM (Read Only Memory) 120 , a RAM (Random Access Memory) 130 , and a nonvolatile storage device 140 . In addition, a network interface (referred to as "network IF" in the figure) 150 for communicating with an external device is provided.

CPU110从ROM120读出实现控制终端2的各部的功能的软件的程序代码并执行。在RAM130中暂时写入在控制终端2内进行的运算处理的中途产生的变量等。CPU110通过执行记录在ROM120中的程序代码来实现控制终端2的各种功能。The CPU 110 reads out and executes the program code of the software that realizes the functions of each part of the control terminal 2 from the ROM 120 . Variables and the like generated in the middle of arithmetic processing performed in the control terminal 2 are temporarily written in the RAM 130 . The CPU 110 realizes various functions of the control terminal 2 by executing the program codes recorded in the ROM 120 .

作为网络接口150,例如使用NIC(Network Interface Card:网络接口卡)等,能够经由与NIC的端子连接的LAN(Local Area Network:局域网)、专用线等在装置间收发各种数据。网络接口150与大厦设施1内的通信装置3连接。As the network interface 150 , for example, a NIC (Network Interface Card) or the like is used, and various data can be transmitted and received between devices via a LAN (Local Area Network) connected to a terminal of the NIC, a dedicated line, or the like. The network interface 150 is connected to the communication device 3 in the building facility 1 .

非易失性存储装置140由硬盘、SSD(Solid State Drive:固态硬盘)等非易失性的存储装置构成,半永久地存储并保存CPU110进行动作所需的程序、数据等。另外,非易失性存储装置140构成图1的控制终端DB8。The nonvolatile storage device 140 is constituted by a nonvolatile storage device such as a hard disk and an SSD (Solid State Drive), and semi-permanently stores and stores programs, data, and the like necessary for the operation of the CPU 110 . In addition, the nonvolatile storage device 140 constitutes the control terminal DB8 of FIG. 1 .

在控制终端2中,根据需要设置有输入部160和输出部170。向各个输入部160输入对应的QR码读取器9A、10A的读取结果、表示电子锁9B、10B的开闭状态的传感器信号等。另外,输出部170分别输出针对对应的QR码读取器9A、10A以及电子锁9B、10B的控制信号。In the control terminal 2, the input part 160 and the output part 170 are provided as needed. The reading results of the corresponding QR code readers 9A and 10A, sensor signals indicating the opening and closing states of the electronic locks 9B and 10B, and the like are input to each input unit 160 . In addition, the output unit 170 outputs control signals for the corresponding QR code readers 9A and 10A and the electronic locks 9B and 10B, respectively.

[信息管理装置(数据中心)的硬件结构][Hardware structure of information management device (data center)]

图4是表示图1所示的信息管理装置20(数据中心)的硬件结构例的框图。图4所示的信息管理装置20的硬件结构是计算机的一例,能够使用个人计算机等来实现。FIG. 4 is a block diagram showing an example of the hardware configuration of the information management apparatus 20 (data center) shown in FIG. 1 . The hardware configuration of the information management apparatus 20 shown in FIG. 4 is an example of a computer, and can be realized using a personal computer or the like.

信息管理装置20也具备与系统总线连接的CPU210、ROM220、RAM230、以及非易失性存储装置240(相当于图1的出入人员信息DB25)。另外,信息管理装置20具备用于进行与外部装置的通信的网络接口(图中表述为“网络IF”)250。通信装置21通过网络接口250来实现。这些结构以及功能与在图3中说明的控制终端2的硬件结构以及功能相同,因此省略说明。但是,信息管理装置20能够删除与图3所示的输入部160以及输出部170相当的结构。The information management device 20 also includes a CPU 210 , a ROM 220 , a RAM 230 , and a nonvolatile storage device 240 (corresponding to the entry and exit information DB 25 in FIG. 1 ) connected to the system bus. In addition, the information management device 20 includes a network interface (referred to as "network IF" in the figure) 250 for performing communication with an external device. The communication device 21 is realized by the network interface 250 . These configurations and functions are the same as those of the hardware configuration and functions of the control terminal 2 described in FIG. 3 , and thus the description is omitted. However, the information management device 20 can delete the configuration corresponding to the input unit 160 and the output unit 170 shown in FIG. 3 .

[个人终端的硬件结构][Hardware structure of personal terminal]

图5是表示图1所示的个人终端30的硬件结构例的框图。图5所示的个人终端30的硬件结构是计算机的一个例子,能够使用个人计算机等来实现。FIG. 5 is a block diagram showing an example of the hardware configuration of the personal terminal 30 shown in FIG. 1 . The hardware configuration of the personal terminal 30 shown in FIG. 5 is an example of a computer, and can be realized using a personal computer or the like.

个人终端30也具备与系统总线连接的CPU310、ROM320、RAM330以及非易失性存储装置360(相当于图1的个人终端DB35)。通过CPU310执行记录在ROM320中的专用应用33的程序代码,来实现个人终端30的各种功能。另外,个人终端30具备用于进行与外部装置的通信的网络接口(图中表述为“网络IF”)370。通信装置31通过网络接口370来实现。这些结构以及功能与在图3中说明的控制终端2的硬件结构以及功能相同,因此省略说明。The personal terminal 30 also includes a CPU 310 , a ROM 320 , a RAM 330 , and a nonvolatile storage device 360 (corresponding to the personal terminal DB 35 in FIG. 1 ) connected to the system bus. Various functions of the personal terminal 30 are realized by the CPU 310 executing the program code of the dedicated application 33 recorded in the ROM 320 . In addition, the personal terminal 30 includes a network interface (referred to as "network IF" in the figure) 370 for performing communication with an external device. The communication device 31 is realized by the network interface 370 . These configurations and functions are the same as those of the hardware configuration and functions of the control terminal 2 described in FIG. 3 , and thus the description is omitted.

并且,个人终端30具备显示装置340以及输入装置350。显示装置340是液晶显示器等显示面板,显示GUI(Graphical User Interface:图形用户界面)画面、由CPU310进行的处理的结果等。输入装置350使用触摸面板、鼠标等指示设备、键盘等,用户能够操作输入装置350来输入信息、指示。输入装置350生成与用户的操作对应的输入信号并供给至CPU310。此外,控制终端2以及信息管理装置20也可以具备显示装置340以及输入装置350。Further, the personal terminal 30 includes a display device 340 and an input device 350 . The display device 340 is a display panel such as a liquid crystal display, and displays a GUI (Graphical User Interface) screen, results of processing performed by the CPU 310 , and the like. The input device 350 uses a touch panel, a pointing device such as a mouse, a keyboard, and the like, and the user can operate the input device 350 to input information and instructions. The input device 350 generates an input signal corresponding to the user's operation and supplies it to the CPU 310 . In addition, the control terminal 2 and the information management device 20 may include a display device 340 and an input device 350 .

接下来,对控制终端2、信息管理装置20以及个人终端30各自所具备的存储区域(DB)中保存的信息(表格)进行说明。Next, the information (tables) stored in the storage areas (DB) included in the control terminal 2 , the information management device 20 , and the personal terminal 30 will be described.

[随机数发行履历区域][Random number issuance history area]

图6表示控制终端2的随机数发行履历区域8A的数据结构例。随机数发行履历区域8A为表格结构,作为其构成要素而设置有编号(No.)MA1、发行QR码读取器MA2、随机数MA3、发行时间MA4以及使用次数MA5。以下,将图6所示的表格称为出入时刻记录区域表格。FIG. 6 shows an example of the data structure of the random number issuance history area 8A of the control terminal 2 . The random number issuance history area 8A has a table structure, and as its constituent elements, a number (No.) MA1, an issuance QR code reader MA2, a random number MA3, an issuance time MA4, and a usage count MA5 are provided. Hereinafter, the table shown in FIG. 6 will be referred to as an entry/exit time recording area table.

编号(No.)MA1表示记录了出入时刻记录区域表格内的记录的顺序。The number (No.) MA1 indicates the order in which the records in the entry and exit time recording area table are recorded.

发行QR码读取器MA2表示唯一地识别发行了随机数的QR码读取器的信息(标识符或名称)。例如,图中的QR1表示QR码读取器9A,QR2表示QR码读取器10A。The issuing QR code reader MA2 represents information (identifier or name) that uniquely identifies the QR code reader that issued the random number. For example, QR1 in the figure represents the QR code reader 9A, and QR2 represents the QR code reader 10A.

随机数MA3由字符、符号等构成,表示随机数的内容。随机数的位数、字符种类等内含的信息是任意的。另外,该随机数在设置有出入设备的设施内是唯一的。The random number MA3 is composed of characters, symbols, etc., and represents the content of the random number. The information contained in the random number, such as the number of digits and the type of characters, is arbitrary. In addition, this random number is unique within a facility provided with an access facility.

发行时间MA4表示发行了该随机数的日期和时刻。The issuance time MA4 indicates the date and time when the random number was issued.

使用次数MA5表示使用了该随机数的次数。The number of times of use MA5 indicates the number of times the random number is used.

当随机数生成部5发行随机数时,新存储发行QR码读取器MA2、随机数MA3、发行时间MA4以及使用次数MA5。When the random number generation unit 5 issues the random number, the issued QR code reader MA2, the random number MA3, the issue time MA4, and the number of times of use MA5 are newly stored.

[通行许可列表记录区域][Passing permission list recording area]

图7表示控制终端2的通行许可列表记录区域8B的数据结构例。通行许可列表记录区域8B为表格结构,作为其构成要素,设置有编号(No.)MB1、QRID MB2、通行许可QR读取器MB3、出入开始日期时间MB4、以及出入结束日期时间MB5。以下,将图7所示的表格称为通行许可列表记录区域表格。FIG. 7 shows an example of the data structure of the access permission list recording area 8B of the control terminal 2 . The access permission list recording area 8B has a table structure, and as its constituent elements, a number (No.) MB1, QRID MB2, access permission QR reader MB3, access start date and time MB4, and access end date and time MB5 are provided. Hereinafter, the table shown in FIG. 7 is referred to as a pass permission list recording area table.

编号(No.)MB1表示记录通行许可列表记录区域表格内的记录的顺序。The number (No.) MB1 indicates the order of recording the records in the pass permission list recording area table.

QRID MB2表示唯一地识别QR码的信息(标识符)。QRID MB2 represents information (identifier) that uniquely identifies the QR code.

通行许可QR读取器MB3表示唯一地识别许可了通行的QR码读取器的信息(标识符或名称)。The passage permission QR code reader MB3 represents information (identifier or name) that uniquely identifies the QR code reader for which the passage is permitted.

出入开始日期时间MB4表示出入人员开始出入的日期和时刻。The entry/exit start date and time MB4 indicates the date and time when the entry/exit person starts going in and out.

出入结束日期时间MB5表示出入人员结束出入的日期和时刻。The entry and exit end date and time MB5 indicates the date and time when the entry and exit personnel finished their entry and exit.

在更新了信息管理装置20的通行许可列表记录区域25C的情况下,在通行许可列表记录区域8B中新存储QRID MB2、通行许可QR读取器MB3、出入开始日期时间MB4以及出入结束日期时间MB5。When the access permission list recording area 25C of the information management device 20 is updated, the QRID MB2, the access permission QR reader MB3, the entry/exit start date and time MB4, and the entry/exit end date and time MB5 are newly stored in the access permission list recording area 8B. .

[个人信息记录区域][Personal Information Recording Area]

图8表示信息管理装置20(数据中心)的个人信息记录区域25B的数据结构例。个人信息记录区域25B为表格结构,作为其构成要素设置有编号(No.)MC1、姓名MC2、QRID MC 3、个人终端IP地址MC4、邮件地址MC5以及个人终端ID MC 6。以下,将图8所示的表格称为个人信息记录区域表格。FIG. 8 shows an example of the data structure of the personal information recording area 25B of the information management apparatus 20 (data center). The personal information recording area 25B has a table structure, and as its constituent elements, a number (No.) MC1, a name MC2, a QRID MC3, a personal terminal IP address MC4, a mail address MC5, and a personal terminal ID MC6 are provided. Hereinafter, the table shown in FIG. 8 is referred to as a personal information recording area table.

编号(No.)MC1表示记录个人信息记录区域表格内的记录的顺序。The number (No.) MC1 indicates the order in which the records in the personal information recording area table are recorded.

姓名MC2表示出入人员的姓名。The name MC2 indicates the name of the person entering and leaving.

QRID MC 3表示唯一地识别QR码的信息(标识符)。The QRID MC 3 represents information (identifier) that uniquely identifies the QR code.

个人终端IP地址MC4表示个人终端30在通信中使用的IP地址。The personal terminal IP address MC4 indicates the IP address used by the personal terminal 30 for communication.

邮件地址MC5表示个人终端30使用的电子邮件的地址。该邮件地址MC5不是必须的构成要素。The mail address MC5 represents the address of the electronic mail used by the personal terminal 30 . This mail address MC5 is not an essential component.

个人终端ID MC 6表示唯一地识别个人终端30的信息(标识符)。例如,作为个人终端ID,使用对每个网络接口分配的固有的MAC(Media Access Control:媒体访问控制)地址。The personal terminal ID MC6 represents information (identifier) that uniquely identifies the personal terminal 30 . For example, as the personal terminal ID, a unique MAC (Media Access Control) address assigned to each network interface is used.

个人终端IP地址MC4、邮件地址MC5、个人终端ID MC 6预先保存在个人信息记录区域25B中,QRID MC 3被登记为出入人员信息后被新保存。The personal terminal IP address MC4, the mail address MC5, and the personal terminal ID MC6 are preliminarily stored in the personal information recording area 25B, and the QRID MC3 is newly stored after being registered as entry and exit information.

[通行许可列表记录区域][Passing permission list recording area]

图9表示信息管理装置20(数据中心)的通行许可列表记录区域25C的数据结构例。通行许可列表记录区域25C为表格结构,作为其构成要素,设置有编号(No.)MD1、通行许可大厦MD2、大厦IP地址MD3、QRID MD4、通行许可QR读取器MD5、出入开始日期时间MD6、以及出入结束日期时间MD7。以下,将图9所示的表格称为通行许可列表记录区域表格。FIG. 9 shows an example of the data structure of the access permission list recording area 25C of the information management device 20 (data center). The access permission list recording area 25C has a table structure, and as its constituent elements, number (No.) MD1, access permission building MD2, building IP address MD3, QRID MD4, access permission QR reader MD5, and entry/exit start date and time MD6 are provided. , and the end date and time MD7 of the access. Hereinafter, the table shown in FIG. 9 is referred to as a pass permission list recording area table.

在登记了出入人员信息之后,新存储相应的通行许可大厦MD2、大厦IP地址MD3、QRID MD4、通行许可QR读取器MD5、出入开始日期时间MD6、出入结束日期时间MD7。After the entry and exit personnel information is registered, the corresponding access permission building MD2, building IP address MD3, QRID MD4, access permission QR reader MD5, access start date and time MD6, and access end date and time MD7 are newly stored.

[QR码信息区域][QR code information area]

图10表示个人终端30的QR码信息区域35A的数据结构例。QR码信息区域35A为表格结构,作为其构成要素,设置有编号(No.)ME1、QRID ME2、通行许可QR读取器ME3、出入开始日期时间ME4、以及出入结束日期时间ME5。以下,将图10所示的表格称为QR码信息区域表格。FIG. 10 shows an example of the data structure of the QR code information area 35A of the personal terminal 30 . The QR code information area 35A has a table structure, and as its constituent elements, a number (No.) ME1, a QRID ME2, an access permission QR reader ME3, an entry/exit start date and time ME4, and an entry/exit end date and time ME5 are provided. Hereinafter, the table shown in FIG. 10 is referred to as a QR code information area table.

QR码信息区域表格的编号(No.)ME1、QRID ME 2、通行许可QR读取器ME3、出入开始日期时间ME4以及出入结束日期时间ME5与通行许可列表记录区域表格(图7)的同名的构成要素相同,因此省略说明。QR code information area table number (No.) ME1, QRID ME 2, access permission QR reader ME3, entry/exit start date and time ME4, and entry/exit end date and time ME5 have the same names as the access permission list recording area table (Fig. 7) Since the components are the same, the description is omitted.

这样,新存储编号(No.)ME1、QRID ME 2、通行许可QR读取器ME3、出入开始日期时间ME4、出入结束日期时间ME5。In this way, the numbers (No.) ME1, QRID ME2, access permission QR reader ME3, entry/exit start date and time ME4, and entry/exit end date and time ME5 are newly stored.

[出入管理系统整体的动作][Operation of the entire access management system]

接着,参照图11对出入管理系统50整体的动作进行说明。Next, the operation of the entire access management system 50 will be described with reference to FIG. 11 .

图11是表示出入管理系统50整体的动作例的时序图。在此,参照图11说明的内容是出入管理系统50整体的动作的概要。FIG. 11 is a sequence diagram showing an example of the operation of the entire access management system 50 . Here, the content described with reference to FIG. 11 is an outline of the operation of the entire access management system 50 .

首先,作为前提,出入人员信息登记人员操作出入人员信息登记PC40,向数据中心的信息管理装置20发送出入人员以及通行预定等信息,以便事先对并设于想要进行出入的门的控制终端2(认证装置)中的认证结果进行许可。First, as a premise, the entry and exit information registrant operates the entry and exit information registration PC 40, and transmits information such as entry and exit personnel and passage plans to the information management device 20 of the data center, so that the control terminal 2 installed at the door to be entered and exited in advance can be checked in advance. The authentication result in the (authentication device) is approved.

信息管理装置20将出入人员信息、许可出入的出入设备、许可出入的日期时间信息(有效日期时间)等关联起来设定为通行许可列表表格,并存储在出入人员信息DB25中。此时,信息管理装置20分配能够唯一地确定存储在通行许可列表表格中的一系列信息(图中标记为“通行模式”)的ID(以下,称为“QRID”),并保存在通行许可列表表格中(S1)。同时,通行许可列表表格的信息(QRID、通行模式)也被发送到设置于出入人员出入的大厦设施1的控制终端2(S2),并存储在控制终端2内的控制终端DB8中(S3)。在信息管理装置20中事先存储有设置有出入设备的大厦设施1的信息。控制终端2定期地生成随机数(S4)。The information management device 20 associates the entry/exit personnel information, the entry/exit equipment permitted to enter/exit, the date and time information (valid date and time) of the entry/exit permission, and the like into a pass permission list table, and stores it in the entry/exit personnel information DB 25 . At this time, the information management device 20 assigns an ID (hereinafter, referred to as "QRID") that can uniquely identify a series of information (marked as "passing mode" in the figure) stored in the pass-through list table, and stores it in the pass-through in the list form (S1). At the same time, the information (QRID, access mode) of the access permission list table is also transmitted to the control terminal 2 installed in the building facility 1 where people come and go (S2), and is stored in the control terminal DB8 in the control terminal 2 (S3) . In the information management apparatus 20, information of the building facility 1 in which the access facility is installed is stored in advance. The control terminal 2 periodically generates random numbers (S4).

信息管理装置20在确认了存储有上述出入人员信息之后进行动作,将包含QRID等的通行许可列表表格的信息(通行模式)发送给个人终端30的专用应用33(S5)。在从信息管理装置20向个人终端30通知的信息中至少包含QRID和有效日期时间的信息。个人终端30的专用应用33将发送的上述信息储存于个人终端30内的个人终端DB35中(S6)。此时,假设事先进行了个人终端30的利用者对专用应用33的利用者登记。The information management device 20 operates after confirming that the entry and exit information is stored, and transmits the information (pass mode) of the pass permission list table including QRID and the like to the dedicated application 33 of the personal terminal 30 (S5). The information notified from the information management apparatus 20 to the personal terminal 30 includes at least the QRID and the information of the effective date and time. The dedicated application 33 of the personal terminal 30 stores the transmitted information in the personal terminal DB 35 in the personal terminal 30 (S6). At this time, it is assumed that the user registration of the user of the personal terminal 30 in the dedicated application 33 is performed in advance.

若在出入人员进入之前启动专用应用33,则个人终端30内置的照相机PB1以启动状态待机。此时,在并设于对象的门的QR码读取器(例如QR码读取器9A)所具备的画面中,显示嵌入了能够唯一地确定QR码读取器的随机数的QR码(S8)。出入人员在启动专用应用33并确认照相机PB1为启动状态后,对个人终端30进行随机数取得操作,以便能够通过照相机PB1读取显示于QR码读取器的QR码(S7)。即,使个人终端30与QR码读取器正对。When the dedicated application 33 is activated before the entry and exit of the person, the camera PB1 built in the personal terminal 30 stands by in an activated state. At this time, on the screen of the QR code reader (for example, the QR code reader 9A) installed at the door of the object, a QR code ( S8). After the entry and exit person activates the dedicated application 33 and confirms that the camera PB1 is activated, the personal terminal 30 obtains a random number so that the QR code displayed on the QR code reader can be read by the camera PB1 (S7). That is, the personal terminal 30 and the QR code reader are made to face each other.

正对后,个人终端30使用照相机PB1读取显示于QR码读取器的QR码,取得随机数(S9)。另外,控制终端2也可以在检测到与个人终端30正对之后,在QR码读取器上显示QR码。After facing, the personal terminal 30 uses the camera PB1 to read the QR code displayed on the QR code reader, and acquires a random number (S9). In addition, the control terminal 2 may display the QR code on the QR code reader after detecting that it faces the personal terminal 30 directly.

专用应用33基于将从QR码读取器的QR码取得的随机数、事先从信息管理装置20接收到的QRID、QR码生成时刻(当前时刻)组合而成的信息,生成用于出入认证的QR码并显示于个人终端30的画面(S10)。接下来,QR码读取器读取显示于个人终端的QR码,取得随机数、QRID以及QR码生成时刻(S11)。The dedicated application 33 generates an entry-exit authentication code based on a combination of the random number obtained from the QR code of the QR code reader, the QRID received from the information management device 20 in advance, and the QR code generation time (current time). The QR code is displayed on the screen of the personal terminal 30 (S10). Next, the QR code reader reads the QR code displayed on the personal terminal, and acquires the random number, QRID, and QR code generation time (S11).

最后,QR码读取器通过读取显示在个人终端30上的QR码,取得随机数和QRID等信息,与事先存储在大厦设施1的控制终端2中的通行许可列表表格进行比较,在判定为通行许可的情况下,对对象的门的电子锁9B进行开锁(S12)。Finally, the QR code reader reads the QR code displayed on the personal terminal 30 to obtain information such as random numbers and QRIDs, and compares it with the access permission list table stored in the control terminal 2 of the building facility 1 in advance, and determines In the case of permission to pass, the electronic lock 9B of the target door is unlocked (S12).

例如,控制终端2将当前时刻与取得的QR码生成时刻进行比较,判定两者时间差是否在预定的时间内。如果在一定时间内,则接着控制终端2将从QR码取得的随机数与记录在控制终端2内的随机数的发行履历进行比较,判定是否与QR码读取器所显示的随机数一致且未使用。在随机数一致且未使用的情况下,将取得的QRID与记录于控制终端2的通行许可列表表格进行比较,判定QRID是否许可了向对象的出入设备的通行。在许可了通行的情况下,进行门的开锁。此时,随机数存储使用次数,相同的随机数为2次,无法使用。For example, the control terminal 2 compares the current time and the acquired QR code generation time, and determines whether the time difference between the two is within a predetermined time. If it is within a certain period of time, the control terminal 2 then compares the random number acquired from the QR code with the issuance history of the random number recorded in the control terminal 2, and determines whether it matches the random number displayed by the QR code reader. and not used. When the random numbers match and are not used, the acquired QRID is compared with the passage permission list table recorded in the control terminal 2, and it is determined whether the QRID permits passage to the target access facility. When the passage is permitted, the door is unlocked. At this time, the random number is stored for the number of times of use, and the same random number is used twice and cannot be used.

在以上的一系列的认证动作中,通过利用确定QR码读取器的随机数、确定出入人员的QRID等认证信息,在控制终端2与个人终端30之间进行收发时,能够在确保安全性的同时稳定且瞬时地进行。在本实施方式中,由于在出入人员将显示有QR码的个人终端30举到QR码读取器的同时在通行的期间内完成认证处理,因此出入的认证操作较为容易。In the above series of authentication operations, by using authentication information such as a random number specifying a QR code reader and a QRID specifying an entry and exit person, security can be ensured when transmitting and receiving between the control terminal 2 and the personal terminal 30 . stably and instantaneously at the same time. In the present embodiment, the authentication process for entering and exiting is easy because the authentication process is completed while the person passing by while holding the personal terminal 30 displaying the QR code to the QR code reader.

以下,参照图12~图16对构成出入管理系统50的信息管理装置20、控制终端2以及个人终端30的各处理进行说明。Hereinafter, each process of the information management device 20 , the control terminal 2 , and the personal terminal 30 constituting the access management system 50 will be described with reference to FIGS. 12 to 16 .

[出入人员信息登记处理][Incoming and outgoing personnel information registration processing]

在此,对登记任意的出入人员信息的登记人员通过与网络线路N连接的任意的出入人员信息登记PC40登记出入人员信息,并向个人终端30发送必要的信息为止的处理的流程进行说明。Here, the flow of processing until a registrant who registers arbitrary entry/exit information via the arbitrary entry/exit information registration PC 40 connected to the network line N registers entry/exit information and transmits necessary information to the personal terminal 30 will be described.

(通行许可列表制作部的处理)(Processing by the Permit List Creation Department)

图12是表示信息管理装置20的通行许可列表制作部23的处理例的流程图。FIG. 12 is a flowchart showing an example of processing performed by the access permission list creation unit 23 of the information management device 20 .

根据图12,预先存储有出入人员的个人信息(例如姓名)和出入目的地的信息(例如与想要通行的门对应的读卡器(CR)的信息)(步骤SA1)。当存储上述出入人员信息时,开始通行许可列表制作部23的处理。According to FIG. 12 , personal information (eg, name) of the person entering and exiting and information of the entering and exiting destination (eg, information of the card reader (CR) corresponding to the door to be passed) are stored in advance (step SA1 ). When the above-mentioned entry/exit person information is stored, the process of the passage permission list creation unit 23 is started.

通行许可列表制作部23判定应该存储在出入人员信息DB25中的出入人员信息是否备齐(步骤SA2)。在此,在出入人员信息备齐的情况下(步骤SA2的“是”),通行许可列表制作部23对出入人员1人的每个数据发行唯一的随机数即QRID(步骤SA3),将出入人员信息和QRID存储在通行许可列表记录区域25C的MD2~MD7和个人信息记录区域25B的MC3中(步骤SA4)。The passage permission list creation unit 23 determines whether or not the entry/exit information to be stored in the entry/exit information DB 25 is available (step SA2). Here, when the entry and exit information is complete (“Yes” in step SA2 ), the access permission list creation unit 23 issues a QRID, which is a unique random number, for each data of one entry and exit person (step SA3 ), The personal information and QRID are stored in MD2 to MD7 of the pass permission list recording area 25C and MC3 of the personal information recording area 25B (step SA4).

此时,在出入人员信息不备齐等出入人员信息存在缺陷的情况下(步骤SA2的“否”),通行许可列表制作部23进行既定的错误通知(步骤SA5)。不执行步骤SA2以后的QRID的发行以及出入人员信息和QRID的信息的存储处理(步骤SA3、SA4)。At this time, when the entry and exit information is defective, for example, the entry and exit information is not available (NO in step SA2 ), the passage permission list creation unit 23 performs a predetermined error notification (step SA5 ). The issuance of the QRID after the step SA2 and the storage process of the entry and exit person information and the QRID information are not performed (steps SA3 and SA4).

另外,在步骤SA3中发行的QRID在出入管理系统50内成为唯一的值,通过使用QRID,能够唯一地决定何时、谁得到出入哪里的许可。并且,个人信息记录区域25B的MC2、MC4~MC6通过事先在个人终端登记作业中从安装于个人终端30的专用应用33进行利用者登记而预先完成输入。In addition, the QRID issued in step SA3 becomes a unique value within the access control system 50, and by using the QRID, it is possible to uniquely determine when and who gets permission to access where. In addition, MC2, MC4 to MC6 of the personal information recording area 25B are previously input by performing user registration from the dedicated application 33 installed in the personal terminal 30 in the personal terminal registration operation.

通行许可列表制作部23将步骤SA4或者SA5结束的情况通知给个人终端通信部24。The pass permission list creation unit 23 notifies the personal terminal communication unit 24 of the completion of step SA4 or SA5.

(个人终端通信部的处理)(Processing by the Personal Terminal Communication Section)

图13是表示信息管理装置20的个人终端通信部24的处理例的流程图。FIG. 13 is a flowchart showing an example of processing performed by the personal terminal communication unit 24 of the information management apparatus 20 .

在图12的步骤SA4的处理后,在信息管理装置20的个人终端通信部24中,判定在通行许可列表记录区域25C和个人信息记录区域25B中是否存在相同的QRID(步骤SB1)。After the process of step SA4 in FIG. 12, the personal terminal communication unit 24 of the information management device 20 determines whether or not the same QRID exists in the pass permission list recording area 25C and the personal information recording area 25B (step SB1).

然后,在存在相同的QRID的情况下(步骤SB1的“是”),个人终端通信部24判定在个人信息记录区域25B的对象QRID的记录中是否存储有个人终端IP地址MC4、个人终端ID MC6(步骤SB2)。然后,在存储有上述信息的情况下(步骤SB2的“是”),个人终端通信部24向个人终端IP地址MC4发送QRID等信息(步骤SB3)。Then, when the same QRID exists (“Yes” in step SB1 ), the personal terminal communication unit 24 determines whether or not the personal terminal IP address MC4 and personal terminal ID MC6 are stored in the record of the target QRID in the personal information recording area 25B. (step SB2). Then, when the above-mentioned information is stored (“Yes” in step SB2 ), the personal terminal communication unit 24 transmits information such as QRID to the personal terminal IP address MC4 (step SB3 ).

此时,在步骤SB1中,个人终端通信部24在通行许可列表记录区域25C和个人信息记录区域25B中不存在相同的QRID的情况下(步骤SB1的“否”),进行既定的错误通知,不执行其以后的处理(在此为步骤SB2~SB3)(步骤SB5)。At this time, in step SB1, when the same QRID does not exist in the pass permission list recording area 25C and the personal information recording area 25B (“No” in step SB1), the personal terminal communication unit 24 performs a predetermined error notification, The subsequent processes (here, steps SB2 to SB3) are not executed (step SB5).

另外,在步骤SB2中,个人终端通信部24在个人信息记录区域25B中不存在个人终端IP地址MC4、个人终端ID MC 6的情况下(步骤SB2的“否”),进行既定的错误通知,不执行其以后的处理(在此为步骤SB3)(步骤SB4)。In addition, in step SB2, when the personal terminal communication unit 24 does not have the personal terminal IP address MC4 and personal terminal ID MC6 in the personal information recording area 25B (“No” in step SB2), a predetermined error notification is performed, The subsequent processing (here, step SB3 ) is not executed (step SB4 ).

[随机数生成部的处理][Processing by the random number generator]

在此,对生成使用了针对与控制终端2连接的每个QR码读取器发行的随机数的QR码并显示于QR码读取器的画面为止的处理的流程进行说明。Here, the flow of processing until a QR code using a random number issued for each QR code reader connected to the control terminal 2 is generated and displayed on the screen of the QR code reader will be described.

图14是表示控制终端2的随机数生成部5的处理例的流程图。FIG. 14 is a flowchart showing an example of processing performed by the random number generation unit 5 of the control terminal 2 .

首先,随机数生成部5在达到了预先指定的周期(例如1分钟)的情况下(步骤SC1的“是”)、或者随机数已使用的情况下(步骤SC2的“是”)(详情后述),开始随机数生成处理。即,即使在未达到指定的周期的情况下(步骤SC1的“否”),在随机数已使用的情况下(步骤SC2的“是”),也开始随机数生成处理。另一方面,在未达到指定的周期的情况下(步骤SC1的“否”)、在随机数未使用完毕的情况下(步骤SC2的“否”),不开始随机数生成处理。First, when the random number generation unit 5 has reached a predetermined period (for example, 1 minute) (“Yes” in Step SC1 ), or when the random number has been used (“Yes” in Step SC2 ) (the details will be described later). described above) to start the random number generation process. That is, even when the predetermined cycle has not been reached (“NO” in step SC1 ), and when the random number has been used (“YES” in step SC2 ), the random number generation process is started. On the other hand, when the predetermined cycle has not been reached (“NO” in step SC1 ) or when the random number has not been used up (“NO” in step SC2 ), the random number generation process is not started.

在步骤SC1、SC2的处理后,随机数生成部5对每个QR码读取器发行新的随机数(步骤SC3)。将在步骤SC3中生成的随机数与随机数发行履历区域8A进行比较(步骤SC4)。在随机数发行履历区域8A中存在相同的随机数的情况下(步骤SC4的“否”),使处理返回到步骤SC3。After the processing of steps SC1 and SC2, the random number generator 5 issues a new random number to each QR code reader (step SC3). The random number generated in step SC3 is compared with the random number issuance history area 8A (step SC4). When the same random number exists in the random number issuance history area 8A (NO in step SC4 ), the process returns to step SC3 .

然后,在不存在相同的随机数的情况下(步骤SC4的“是”),随机数生成部5将新生成的随机数和关联信息(发行QR码读取器、发行时间)存储在随机数发行履历区域8A的MA2~MA4中,在使用次数MA5中存储“0”(步骤SC5)。接下来,随机数生成部5使用新生成的随机数来生成QR码,并发送至对象的QR码读取器(在此为QR码读取器9A),并输出至画面(步骤SC6)。Then, when the same random number does not exist (“Yes” in step SC4 ), the random number generating unit 5 stores the newly generated random number and related information (issuance QR code reader, issuance time) in the random number In MA2 to MA4 of the issuance history area 8A, "0" is stored in the usage count MA5 (step SC5). Next, the random number generating unit 5 generates a QR code using the newly generated random number, transmits it to the target QR code reader (the QR code reader 9A in this case), and outputs it to the screen (step SC6 ).

[QR码的生成以及认证][QR code generation and authentication]

接下来,参照图15和图16说明QR码的生成和认证处理。在此,说明从显示于现场(大厦设施1)的QR码读取器的QR码取得随机数,生成仅能通过对象的QR码读取器认证的出入用QR码为止的个人终端30和控制终端2的处理流程。Next, the generation and authentication processing of the QR code will be described with reference to FIGS. 15 and 16 . Here, a description will be given of the personal terminal 30 and control until a random number is obtained from a QR code displayed on a QR code reader displayed on the site (building facility 1 ), and a QR code for access that can be authenticated only by the target QR code reader is generated. Processing flow of terminal 2.

(QR码生成部的处理)(Processing by the QR code generator)

图15是表示个人终端30的QR码生成部34的处理例的流程图。FIG. 15 is a flowchart showing an example of processing performed by the QR code generation unit 34 of the personal terminal 30 .

首先,QR码生成部34为了读取并设于想要出入的设施的门的QR码读取器(在此为QR码读取器9A)的画面上的QR码,在执行专用应用33并确认照相机PB1为启动状态后,使个人终端30与QR码读取器9A正对(步骤SD1)。First, in order to read the QR code on the screen of the QR code reader (in this case, the QR code reader 9A) installed at the door of the facility to be entered and exited, the QR code generation unit 34 executes the dedicated application 33 and After confirming that the camera PB1 is in the activated state, the personal terminal 30 and the QR code reader 9A are made to face each other (step SD1).

正对后,QR码生成部34通过照相机PB1读取QR码读取器9A的QR码,取得随机数(步骤SD2)。接着,将事先存储在QR码信息区域35A中的QRID、在步骤SD2中取得的随机数、从个人终端30取得的当前时刻(以下,也称为“QR码生成时刻”)进行组合,生成用于出入认证的QR码(步骤SD3)。After the alignment, the QR code generation unit 34 reads the QR code of the QR code reader 9A with the camera PB1, and acquires a random number (step SD2). Next, the QRID previously stored in the QR code information area 35A, the random number acquired in step SD2, and the current time acquired from the personal terminal 30 (hereinafter, also referred to as "QR code generation time") are combined to generate a QR code for access authentication (step SD3).

QR码生成部34将在步骤SD3中生成的QR码立即显示在个人终端30的画面上(步骤SD4)。接下来,QR码生成部34在检测到从QR码生成时刻起经过了预先设定的固定时间(例如,30秒)、或者手动的结束操作(例如,专用应用的结束)的情况下,结束QR码的显示(步骤SD6)。The QR code generation unit 34 immediately displays the QR code generated in step SD3 on the screen of the personal terminal 30 (step SD4). Next, when the QR code generation unit 34 detects that a predetermined fixed time (for example, 30 seconds) has elapsed from the time of generation of the QR code, or when a manual termination operation (for example, termination of the dedicated application) is performed, the operation is terminated. The QR code is displayed (step SD6).

在步骤SD4的处理后,出入人员将个人终端30向QR码读取器举起(SD5)。其中,步骤SD2~SD4的处理在个人终端30与QR码读取器9A正对的状态下进行,实质上个人终端30保持与QR码读取器9A正对的状态(举起的状态)。After the process of step SD4, the entry and exit person lifts the personal terminal 30 toward the QR code reader (SD5). However, the processes of steps SD2 to SD4 are performed with the personal terminal 30 facing the QR code reader 9A, and the personal terminal 30 is substantially kept facing the QR code reader 9A (lifted state).

(QR码认证部的处理)(Processing by the QR code authentication section)

图16是表示控制终端2的QR码认证部7的处理例的流程图。FIG. 16 is a flowchart showing an example of processing performed by the QR code authentication unit 7 of the control terminal 2 .

在通过图15的步骤SD4将用于出入认证的QR码显示在个人终端30的画面上的期间,在通过QR码读取器9A进行了读取的情况下(步骤SE1),QR码认证部7从用于出入认证的QR码取得QR码生成时刻、随机数、QRID(步骤SE2)。While the QR code for access authentication is displayed on the screen of the personal terminal 30 in step SD4 of FIG. 15 , when the QR code reader 9A reads it (step SE1 ), the QR code authentication unit 7. The QR code generation time, random number, and QRID are acquired from the QR code used for access authentication (step SE2).

接下来,QR码认证部7对QR码生成时刻进行判定(步骤SE3),在判定为QR码生成时刻在预先设定的时间(例如,30秒)内的情况下(步骤SE3的“是”),进入步骤SE4。Next, the QR code authentication unit 7 determines the QR code generation time (step SE3 ), and when it is determined that the QR code generation time is within a preset time (for example, 30 seconds) (“Yes” in step SE3 ) ), go to step SE4.

接下来,QR码认证部7判定从便携终端60取得的随机数是否存在于随机数发行履历区域8A(随机数MA3)且使用次数MA5是否为“0”(步骤SE4)。然后,在判定为存在所取得的随机数且未使用的情况下(步骤SE4的“是”),进入步骤SE6。Next, the QR code authentication unit 7 determines whether the random number acquired from the portable terminal 60 exists in the random number issuance history area 8A (random number MA3) and whether the number of times of use MA5 is "0" (step SE4). Then, when it is determined that the acquired random number exists and is not used (YES in step SE4), the process proceeds to step SE6.

接着,QR码认证部7判定从便携终端60取得的QRID是否存在于通行许可列表记录区域8B(QRID MB2)、且得到了通过对象的门的许可(通行许可QR读取器MB3)(步骤SE6)。Next, the QR code authentication unit 7 determines whether or not the QRID acquired from the portable terminal 60 exists in the pass permission list recording area 8B (QRID MB2), and the permission to pass through the target door (pass permission QR reader MB3) is obtained (step SE6 ). ).

另外,在步骤SE4中判定为“是”的情况下,即在判定为所取得的随机数已使用的情况下,QR码认证部7将随机数发行履历区域8A的使用次数MA5更新为“1”,并以随机数生成部5再次发行随机数的方式进行处理(步骤SE5)。由此,QR码读取器9A的QR码输出部6更新该QR码读取器9A中显示中的QR码。In addition, when it is determined as "Yes" in step SE4, that is, when it is determined that the acquired random number has been used, the QR code authentication unit 7 updates the usage count MA5 of the random number issuance history area 8A to "1" ”, and the random number generator 5 issues a random number again (step SE5). Thereby, the QR code output unit 6 of the QR code reader 9A updates the QR code being displayed on the QR code reader 9A.

接着,QR码认证部7在所取得的QRID得到了通过并设于举起了个人终端30的QR码读取器9A的门的许可的情况下(步骤SE6的“是”),对并设于对象的门的电子锁(在此为电子锁9B)进行开锁(步骤SE7)。Next, when the acquired QRID is permitted to pass through the door that is installed in the QR code reader 9A of the personal terminal 30 held up (“Yes” in step SE6 ), the QR code authentication unit 7 will The electronic lock (here, the electronic lock 9B) of the subject's door is unlocked (step SE7).

另一方面,在从QR码生成时刻起经过了一定时间以上的情况下(步骤SE3的“否”)、或者所取得的随机数为非法或已使用的情况下(步骤SE4的“否”)、或者QRID为非法或不许可通行的情况下(步骤SE6的“否”),进行既定的错误通知,QR码认证部7不进行电子锁9B的开锁操作(步骤SE8)。On the other hand, when a predetermined time or more has elapsed since the time of generating the QR code (“No” in step SE3 ), or when the acquired random number is illegal or used (“No” in step SE4 ) Or, when the QRID is illegal or not permitted to pass (“NO” in step SE6 ), a predetermined error notification is performed, and the QR code authentication unit 7 does not perform the unlocking operation of the electronic lock 9B (step SE8 ).

这样,本实施方式的QR码认证部7对随机数的判定是参照记录有该随机数的使用次数的随机数发行历史,过去已发行且未使用、过去未发行、或者过去已发行但已使用中的任意一个。In this way, the determination of the random number by the QR code authentication unit 7 of the present embodiment refers to the random number issuance history in which the frequency of use of the random number is recorded, whether it has been issued in the past and not used, or has not been issued in the past, or has been issued in the past but has been used. any of the .

这样,QR码认证部7假定多个模式的判定结果,在判定为该随机数已使用的情况下,对随机数生成部5指示随机数的重新发行。因此,重新发行随机数,并且还更新嵌入有该随机数的QR码。因此,能够防止安全性的降低。In this way, the QR code authentication unit 7 instructs the random number generation unit 5 to reissue the random number when it is determined that the random number has been used, assuming the determination results of the plurality of patterns. Therefore, the random number is reissued, and the QR code embedded with the random number is also updated. Therefore, a reduction in safety can be prevented.

[具体例][specific example]

接下来,参照图1以及图6~图10,列举具体的例子对出入管理系统50的动作进行说明。Next, with reference to FIG. 1 and FIGS. 6 to 10 , the operation of the access management system 50 will be described with reference to a specific example.

例如,假定在大厦设施1的专有部(1)中存在想要从“2021/02/01的09:00”到“2021/02/01的18:00”为止想要出入的出入人员A。此时,假定出入人员A事先完成了个人终端30(例如智能手机)的事先登记作业。另外,为了对出入人员A给予对专有部(1)的出入许可,出入人员信息登记人员事先将出入人员A的个人信息和出入信息从出入人员信息登记PC40登记到信息管理装置20中。在完成上述出入人员信息登记后,在信息管理装置20的通行许可列表制作部23中,对新登记的出入人员A的信息发行新的唯一的QRID(在此为789789789)。然后,通行许可列表制作部23将出入人员信息和QRID(789789789)存储在个人信息记录区域25B(MC2~MC6)和通行许可列表记录区域25C(MD2~MD7)中。For example, it is assumed that there is an inbound and outbound person A who wants to enter and exit from "09:00 on 2021/02/01" to "18:00 on 2021/02/01" in the exclusive part (1) of the building facility 1 . At this time, it is assumed that the entry/exit person A has completed the pre-registration operation of the personal terminal 30 (for example, a smartphone) in advance. In addition, in order to grant access permission to the exclusive part (1) to the access person A, the access person information registration person registers the personal information and access information of the access person A from the access person information registration PC 40 to the information management device 20 in advance. After completing the registration of the entry/exit information, a new unique QRID (here 789789789) is issued to the information of the newly registered entry/exit A in the passage permission list creation unit 23 of the information management device 20 . Then, the access permission list creation unit 23 stores the access person information and the QRID (789789789) in the personal information recording area 25B ( MC2 to MC6 ) and the access permission list recording area 25C ( MD2 to MD7 ).

此时,通行许可列表记录区域25C的信息的一部分(MD4~MD7)也存储在大厦设施1的控制终端2内的通行许可列表记录区域8B(MB2~MB5)中。接着,在个人终端通信部24中,对个人信息记录区域25B的个人终端IP地址(在此设为789.789.789.789)发送QRID(789789789)等信息。At this time, part of the information ( MD4 to MD7 ) in the access permission list recording area 25C is also stored in the access permission list recording area 8B ( MB2 to MB5 ) in the control terminal 2 of the building facility 1 . Next, the personal terminal communication unit 24 transmits information such as QRID (789789789) to the personal terminal IP address (here, 789.789.789.789) in the personal information recording area 25B.

接着,设为出入人员A在“2021/02/01的10:00”进入专用部(1)之前。首先,出入人员A将个人终端30的专用应用33设为执行状态,确认照相机PB1已启动,使QR码读取器9A与个人终端30正对。Next, it is assumed that the entry and exit person A enters the dedicated section ( 1 ) before "10:00 of 2021/02/01". First, the entry and exit person A sets the dedicated application 33 of the personal terminal 30 to the execution state, confirms that the camera PB1 is activated, and makes the QR code reader 9A face the personal terminal 30 directly.

个人终端30通过读取显示于QR码读取器9A的QR码,来取得QR码读取器9A专用的随机数(在此,设为aBc789)。然后,个人终端30的QR码生成部34使用该随机数(aBc789)、未图示的QR码生成时刻(在此,设为2021/02/01_10:00:30)、QRID(789789789),在个人终端30生成用于出入认证的QR码,并显示于画面。The personal terminal 30 acquires a random number dedicated to the QR code reader 9A (here, aBc789) by reading the QR code displayed on the QR code reader 9A. Then, the QR code generation unit 34 of the personal terminal 30 uses the random number (aBc789), the QR code generation time not shown (here, 2021/02/01_10:00:30), and the QRID (789789789) to generate a The personal terminal 30 generates a QR code for access authentication and displays it on the screen.

接着,假定QR码读取器9A在“2021/02/01_10:00:40”读取了保持正对的个人终端30所显示的用于出入认证的QR码。此时,在控制终端2的QR码认证部7中,由于在预先设定的用于出入认证QR码的读取期限(在此设为30秒)以内,因此判定该QR码为有效。Next, it is assumed that the QR code reader 9A has read the QR code for access authentication displayed on the personal terminal 30 kept facing at "2021/02/01_10:00:40". At this time, the QR code authentication unit 7 of the control terminal 2 determines that the QR code is valid because it is within a preset time limit for reading the QR code for access authentication (here, 30 seconds).

接着,在QR码认证部7中,取得的随机数(aBc789)存在于随机数发行履历区域8A中,使用次数MA5也为“0”,因此判定读取了显示于QR码读取器9A的QR码的随机数。最后,所取得的QRID(789789789)存在于通行许可列表记录区域8B中,在“2021/02/01的10:00:40”的读取时间内得到了向QR码读取器9A的通行许可,因此判定为许可了通行,电子锁9B被开锁。Next, in the QR code authentication unit 7, since the acquired random number (aBc789) exists in the random number issuance history area 8A, and the use count MA5 is also "0", it is determined that the display displayed on the QR code reader 9A has been read. Random number for the QR code. Finally, the acquired QRID (789789789) exists in the access permission list recording area 8B, and the access permission to the QR code reader 9A is obtained within the reading time of "2021/02/01 10:00:40" , it is determined that the passage is permitted, and the electronic lock 9B is unlocked.

如上所述,本发明的一实施方式涉及的出入管理系统(出入管理系统50)是包含具有所连接的出入设备的管理功能以及出入人员的认证功能的控制终端(控制终端2)、以及保持确定出入人员的二维码的识别信息并具有二维码的读取以及生成功能的个人终端(个人终端30)的系统。As described above, the access management system (access management system 50 ) according to an embodiment of the present invention includes a control terminal (control terminal 2 ) having a function for managing connected access equipment and an authentication function for persons entering and leaving, and a hold confirmation A system of a personal terminal (personal terminal 30 ) that has the identification information of the two-dimensional code of the person entering and leaving, and has the function of reading and generating the two-dimensional code.

上述控制终端(控制终端2)具备:随机数生成部(随机数生成部5),其以预先决定的周期生成并发行能够唯一地决定二维码的随机数;二维码输出部(QR码输出部6),其生成嵌入有由该随机数生成部发行的随机数作为信息的二维码图像,并显示于与控制终端连接的二维码读取器(QR码读取器9A、10A)的画面;以及二维码认证部(QR码认证部7),其判定从显示于个人终端的画面的用于出入认证的二维码图像读取的随机数是否为由二维码读取器生成的随机数。The control terminal (control terminal 2) includes: a random number generating unit (random number generating unit 5) that generates and issues a random number capable of uniquely determining a two-dimensional code at a predetermined cycle; a two-dimensional code output unit (QR code); The output unit 6) generates a two-dimensional code image in which the random number issued by the random number generating unit is embedded as information, and displays it on the two-dimensional code reader (QR code reader 9A, 10A) connected to the control terminal ) screen; and a two-dimensional code authentication part (QR code authentication part 7) that determines whether the random number read from the two-dimensional code image for access authentication displayed on the screen of the personal terminal is read by the two-dimensional code A random number generated by the generator.

上述个人终端(个人终端30)具备二维码生成部(QR码生成部34),该二维码生成部生成将从显示于二维码读取器的二维码图像读取的随机数作为信息而嵌入的用于出入认证的二维码图像,并显示于画面。The personal terminal (personal terminal 30) described above includes a two-dimensional code generating unit (QR code generating unit 34) that generates a random number read from a two-dimensional code image displayed on a two-dimensional code reader as a random number. The QR code image for access authentication is embedded in the information and displayed on the screen.

在如以上那样构成的本实施方式的出入管理系统50中,使信息的收发不依赖于不稳定的无线通信,相互正对的QR码读取器和个人终端30经由QR码图像相互进行信息的收发。由此,与QR码读取器连接的控制终端2能够稳定且瞬时地进行出入的认证处理。In the access control system 50 of the present embodiment configured as described above, the QR code reader and the personal terminal 30 facing each other mutually exchange information via the QR code image without relying on unstable wireless communication to transmit and receive information. send and receive. As a result, the control terminal 2 connected to the QR code reader can stably and instantaneously perform the authentication process for entry and exit.

通常,QR码图像的特征在于复制的容易性,因此担心由于用于出入认证的QR码图像的复制而导致安全性降低。与此相对,在本实施方式中,通过读取分别显示在QR码读取器和个人终端上的QR码图像,克服了能够容易地复制QR码图像的担忧。In general, QR code images are characterized by the ease of copying, and thus there is a concern that security is lowered due to the copying of the QR code images used for access authentication. In contrast, in the present embodiment, by reading the QR code images displayed on the QR code reader and the personal terminal, respectively, the concern that the QR code image can be easily copied is overcome.

仅在出入人员实际在对象的门前进行了认证操作的情况下,能够稳定且瞬间地发行仅对对象的门能够使用1次的QR码。因此,出入的认证操作容易,并且能够确保利用QR码时的出入管理的安全性。A QR code that can be used only once for the target door can be issued stably and instantaneously only when the person entering or leaving the door actually performs the authentication operation in front of the target door. Therefore, the authentication operation of access is easy, and the security of access management when using the QR code can be ensured.

并且,本发明不限于上述的一实施方式,只要不脱离请求专利保护的范围所记载的本发明的主旨,当然能够取得其他各种应用例、变形例。In addition, the present invention is not limited to the above-described one embodiment, and it goes without saying that other various application examples and modifications can be obtained without departing from the gist of the present invention described in the scope of claims.

例如,上述的一实施方式是为了容易理解地说明本发明而详细且具体地说明了出入管理系统的结构的实施方式,并不限定于必须具备所说明的全部结构要素。另外,对于各实施方式的结构的一部分,也能够进行其他结构要素的追加或置换、删除。For example, the above-described one embodiment is an embodiment in which the configuration of the access management system is described in detail and concretely in order to explain the present invention easily, and is not limited to having all the described constituent elements. In addition, with respect to a part of the structure of each embodiment, addition, replacement, or deletion of other components can be performed.

另外,上述的各结构、功能、处理部等的一部分或者全部例如也可以通过由集成电路设计等而由硬件实现。作为硬件,也可以使用FPGA(Field Programmable Gate Array:现场可编程门阵列)、ASIC(Application Specific Integrated Circuit:专用集成电路)等广义的处理器设备。In addition, a part or all of each of the above-described structures, functions, processing units, and the like may be realized by hardware, for example, by designing an integrated circuit or the like. As hardware, a processor device in a broad sense, such as an FPGA (Field Programmable Gate Array) and an ASIC (Application Specific Integrated Circuit), may be used.

另外,在图11~图16所示的时序图以及流程图中,也可以在不对处理结果造成影响的范围内,并行地执行多个处理,或者变更处理顺序。In addition, in the sequence diagrams and flowcharts shown in FIGS. 11 to 16 , a plurality of processes may be executed in parallel or the order of the processes may be changed within a range that does not affect the processing results.

Claims (6)

1. An access management system, comprising: a control terminal having a management function of the connected access device and an authentication function of the access person; and a personal terminal which holds identification information of a two-dimensional code for identifying an entering or exiting person and has a function of reading and generating the two-dimensional code,
the control terminal is provided with:
a random number generation unit that generates and issues a random number capable of uniquely determining the two-dimensional code at a predetermined cycle;
a two-dimensional code output unit that generates a two-dimensional code image in which the random number issued by the random number generation unit is embedded as information, and displays the two-dimensional code image on a screen of a two-dimensional code reader connected to the control terminal; and
a two-dimensional code authentication unit that determines whether or not the random number read from the two-dimensional code image for entry/exit authentication displayed on the screen of the personal terminal is the random number generated by the two-dimensional code reader,
the personal terminal includes:
and a two-dimensional code generation unit that generates the two-dimensional code image for authentication of entrance and exit embedded with a random number read from the two-dimensional code image displayed on the two-dimensional code reader as information, and displays the two-dimensional code image on a screen.
2. The access management system of claim 1,
the random number capable of uniquely deciding the two-dimensional code is unique within a facility provided with an access device.
3. The access management system of claim 1,
the two-dimensional code authentication unit instructs the random number generation unit to reissue the random number when it is determined that the random number is used.
4. The access management system of claim 1,
the two-dimensional code authentication unit determines the random number by referring to a random number issuance history in which the number of times the random number is used is recorded, and determines that the random number has been issued and unused in the past, has not been issued in the past, and has been issued and used in the past.
5. The access management system of claim 1,
when the person who enters or exits enters a facility in which the entrance/exit device is installed, the personal terminal acquires the random number generated by the control terminal by facing the two-dimensional code reader to the personal terminal, and the two-dimensional code reader reads the two-dimensional code image generated by the personal terminal.
6. An access management method for an access management system, the access management system comprising: a control terminal having a management function of the connected access device and an authentication function of the access person; and a personal terminal which holds identification information of a two-dimensional code for identifying an entering or exiting person and has a function of reading and generating the two-dimensional code,
in the control terminal:
a random number generation unit that generates and issues a random number capable of uniquely determining the two-dimensional code at a predetermined cycle;
a two-dimensional code output unit that generates a two-dimensional code image in which the random number issued by the random number generation unit is embedded as information, and displays the two-dimensional code image on a screen of a two-dimensional code reader connected to the control terminal; and
a two-dimensional code authentication unit that determines whether or not the random number read from a two-dimensional code image for entry/exit authentication displayed on a screen of the personal terminal is a random number generated by the two-dimensional code reader,
in the personal terminal:
the two-dimensional code generation unit generates the two-dimensional code image for entrance/exit authentication in which the random number read from the two-dimensional code image displayed on the two-dimensional code reader is embedded as information, and displays the two-dimensional code image on a screen.
CN202210103009.XA 2021-03-04 2022-01-27 Access management system and access management method Active CN115035633B (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2021-034816 2021-03-04
JP2021034816A JP7442473B2 (en) 2021-03-04 2021-03-04 Room entry/exit control system and entry/exit control method

Publications (2)

Publication Number Publication Date
CN115035633A true CN115035633A (en) 2022-09-09
CN115035633B CN115035633B (en) 2024-11-26

Family

ID=83119738

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202210103009.XA Active CN115035633B (en) 2021-03-04 2022-01-27 Access management system and access management method

Country Status (2)

Country Link
JP (1) JP7442473B2 (en)
CN (1) CN115035633B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP7569418B1 (en) 2023-07-26 2024-10-17 株式会社アクシオ User Authentication System

Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101855861A (en) * 2007-11-16 2010-10-06 富士通天株式会社 Authentication method, authentication system, vehicle-mounted device, and authentication device
CN104252602A (en) * 2013-06-27 2014-12-31 日立欧姆龙金融系统有限公司 Transaction processing system and transaction processing method
CN104780043A (en) * 2014-01-14 2015-07-15 中国电信股份有限公司 Access control method and system based on two-dimension code
CN104933793A (en) * 2015-06-11 2015-09-23 宁波飞拓电器有限公司 Two-dimension code electronic key implementation method based on digital signature
JP2015233263A (en) * 2014-06-11 2015-12-24 コニカミノルタ株式会社 Authentication system and authentication method
CN106698126A (en) * 2015-11-18 2017-05-24 株式会社日立大厦系统 Elevator system and elevator maintenance operation method
CN106966245A (en) * 2016-01-14 2017-07-21 株式会社日立大厦系统 Lift maintenance system
CN108460876A (en) * 2018-03-20 2018-08-28 中电科(天津)网络信息安全有限公司 A kind of time sync-type Quick Response Code guard method and system
CN110412904A (en) * 2018-04-26 2019-11-05 株式会社日立大厦系统 Building maintenance system and building maintenance assistance method
CN110995654A (en) * 2019-11-05 2020-04-10 合肥优尔电子科技有限公司 Remote terminal temporary authorization method, device and system based on dynamic two-dimensional code
CN111242248A (en) * 2018-11-09 2020-06-05 中移(杭州)信息技术有限公司 A method, device and computer storage medium for monitoring personnel information

Patent Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101855861A (en) * 2007-11-16 2010-10-06 富士通天株式会社 Authentication method, authentication system, vehicle-mounted device, and authentication device
CN104252602A (en) * 2013-06-27 2014-12-31 日立欧姆龙金融系统有限公司 Transaction processing system and transaction processing method
CN104780043A (en) * 2014-01-14 2015-07-15 中国电信股份有限公司 Access control method and system based on two-dimension code
JP2015233263A (en) * 2014-06-11 2015-12-24 コニカミノルタ株式会社 Authentication system and authentication method
CN104933793A (en) * 2015-06-11 2015-09-23 宁波飞拓电器有限公司 Two-dimension code electronic key implementation method based on digital signature
CN106698126A (en) * 2015-11-18 2017-05-24 株式会社日立大厦系统 Elevator system and elevator maintenance operation method
CN106966245A (en) * 2016-01-14 2017-07-21 株式会社日立大厦系统 Lift maintenance system
CN108460876A (en) * 2018-03-20 2018-08-28 中电科(天津)网络信息安全有限公司 A kind of time sync-type Quick Response Code guard method and system
CN110412904A (en) * 2018-04-26 2019-11-05 株式会社日立大厦系统 Building maintenance system and building maintenance assistance method
CN111242248A (en) * 2018-11-09 2020-06-05 中移(杭州)信息技术有限公司 A method, device and computer storage medium for monitoring personnel information
CN110995654A (en) * 2019-11-05 2020-04-10 合肥优尔电子科技有限公司 Remote terminal temporary authorization method, device and system based on dynamic two-dimensional code

Also Published As

Publication number Publication date
CN115035633B (en) 2024-11-26
JP7442473B2 (en) 2024-03-04
JP2022135183A (en) 2022-09-15

Similar Documents

Publication Publication Date Title
KR101233527B1 (en) Entrance/exit management system and entrance/exit management method
CN109074693B (en) Virtual panel for access control system
CN109573753B (en) Elevator request authorization system of third party
JP2009150192A (en) Admission restricting device and admission restriction system
CN113490936A (en) Face authentication device and face authentication method
JP5513234B2 (en) Visitor management device
US20220262184A1 (en) Property management systems
CN115035633A (en) Access control system and access control method
CN112734248A (en) Real estate intelligent management system
CN110599651A (en) Access control system based on unified authorization center and control method
JP7450569B2 (en) Visitor management system and visitor management method
KR20220120853A (en) Apparatus and method for controlling access to security area
JP5106264B2 (en) Elevator security control system and elevator security control method
JP2011048454A (en) Access management system
JP7165929B2 (en) Authentication information output system, processing method, and program
JP2023156476A (en) Facility lending system and facility lending method
TWM650324U (en) Unmanned hotel accommodation system
US20210234931A1 (en) Information processing apparatus and non-transitory computer readable medium
JP7615074B2 (en) Entrance/Exit Management System and Entrance/Exit Management Method
JP2007172039A (en) Login management system and method using location information of user
JP6840055B2 (en) Relay device and electric lock
US20250046138A1 (en) Server Device, Method, And Program
RU2825278C1 (en) Method of controlling and managing access
JP2015161163A (en) Access management system and access management method
US20240232737A1 (en) Reception system and reception method

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant