WO2022124103A1 - 機器管理システム、管理装置、通信機器、および機器管理方法 - Google Patents

機器管理システム、管理装置、通信機器、および機器管理方法 Download PDF

Info

Publication number
WO2022124103A1
WO2022124103A1 PCT/JP2021/043453 JP2021043453W WO2022124103A1 WO 2022124103 A1 WO2022124103 A1 WO 2022124103A1 JP 2021043453 W JP2021043453 W JP 2021043453W WO 2022124103 A1 WO2022124103 A1 WO 2022124103A1
Authority
WO
WIPO (PCT)
Prior art keywords
unit
communication
information
management
initial setting
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2021/043453
Other languages
English (en)
French (fr)
Inventor
良太 河原
朋也 赤川
徹 沖山
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Honda Motor Co Ltd
Original Assignee
Honda Motor Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Honda Motor Co Ltd filed Critical Honda Motor Co Ltd
Priority to JP2022568180A priority Critical patent/JPWO2022124103A1/ja
Publication of WO2022124103A1 publication Critical patent/WO2022124103A1/ja
Anticipated expiration legal-status Critical
Priority to JP2025029252A priority patent/JP2025084848A/ja
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication

Definitions

  • the present invention relates to a device management system, a management device, a communication device, and a device management method.
  • the initial setting When starting to use a device, the first setting that needs to be done in order to use the device is called the initial setting.
  • the initial setting For example, in Patent Document 1, as an initial setting method, a virtual environment is constructed and set based on an initial setting file that describes an initial setting procedure, and a setting file generated in the virtual environment is stored in the storage area of the device. Describes how to save.
  • the present invention has been made in consideration of such circumstances, and is a device management system, a management device, a communication device, and a device that can more easily perform initial setting of a device while ensuring sufficient security.
  • One of the purposes is to provide a management method.
  • the device management system, the management device, the communication device, and the device management method according to the present invention have adopted the following configurations.
  • the device management system according to one aspect of the present invention includes a device to be managed and a management device that performs initial setting of the device by communication with the device, and the management device includes the device.
  • the first communication path includes the first communication device communicably connected to the device and the management device, and the first communication device itself. It holds the information necessary for the device connected to the device to be able to communicate with the management device via itself.
  • the management device acquires device information including identification information of the device from a device other than the device and records the device information in the first storage unit.
  • the device information having a registration unit and recorded in the first storage unit is information read from an image attached to the device by image recognition processing.
  • the device includes a second storage unit in which the device information is recorded in advance, and the device information registration unit is recorded in the second storage unit.
  • the device information is acquired from the device via the first communication path, and the management device uses the device information recorded by the device information registration unit in the first storage unit and the first communication path. Further, it is provided with an authentication unit that authenticates the device based on the device information acquired from the device via the device.
  • the device further includes an initial setting unit that performs the initial setting by communication with the management device, and the management device cooperates with the initial setting unit to perform the initial setting.
  • the device setting unit for performing the initial setting of the above is further provided, and the initial setting unit and the device setting unit start cooperation regarding the initial setting when the device is authenticated by the authentication unit.
  • the initial setting unit records the qualification information acquired from the management device via the second communication path in the second storage unit.
  • the device information is transmitted to the management device together with the device information, and the authentication unit receives the device information received from the device, the device information recorded in the first storage unit, and the device information received from the device.
  • the device is certified based on the credential information.
  • the second communication path includes a second communication device communicably connected to the management device.
  • the management device further includes a qualification information issuing unit that provides the qualification information to the second communication device via the second communication path.
  • the communication device is a communication device that performs its own initial setting by communicating with the management device, and cooperates with the management device by communication via the first communication path.
  • the initial setting unit for initializing the communication device, the storage unit for storing the device information including the identification information of the communication device, and the authentication information obtained via the second communication path, and the initial setting.
  • An input unit that accepts the input of the credential information required for the start of the operation, an authentication unit that requests the management device to authenticate the communication device in response to the input of the credential information, and the communication device by the management device.
  • the management device is a management device that performs initial setting of the communication device by communication with the communication device, and cooperates with the communication device by communication via the first communication path.
  • a device setting unit that performs initial setting of the communication device, a device information registration unit that acquires device information including the identification information of the communication device from a device other than the communication device and records it in a storage unit, and the communication device.
  • Credential issuing unit that issues the authentication information required for starting the initial setting via the second communication path, the first device information stored in advance in the communication device, and the communication device.
  • the credential information input to is acquired from the communication device, the communication is based on the first device information and the credential information and the second device information registered by the device information registration unit.
  • a management device including an authentication unit that authenticates a device, and the device setting unit starts cooperation related to the initial setting with the communication device when the communication device is authenticated by the authentication unit. Is.
  • the management device and the device to be managed by the management device communicate with each other regarding the initial setting of the device via the first communication path. It is a device management method in which the management device provides credential information required for starting the initial setting in the device via a second communication path different from the first communication path.
  • the management device and the device to be managed by the management device perform communication related to the initial setting of the device via the first communication path, and the management device determines.
  • the management device determines.
  • FIG. 1 is a system configuration diagram showing a configuration example of the device management system 100 of the present embodiment.
  • the device management system 100 is a management system for information regarding initial settings performed on the battery switch 600, which is an example of a device to be managed.
  • the initial setting is to make basic settings for the device in the factory-shipped state so that the device can be used.
  • the device management system 100 includes an SP terminal 200, a code reader 210, a FW terminal 300, a router 400, a management server 500, and a battery switch 600.
  • the SP terminal 200 is a terminal device used by a service provider (SP: Service Provider) using the battery switch 600.
  • SP Service Provider
  • the code reader 210 is a device that reads coded information such as a bar code and a two-dimensional code attached to the battery changer 600 in a factory-shipped state.
  • the code reader 210 can be connected to the SP terminal 200, decodes the read coded information, and supplies the decoded information to the SP terminal 200. That is, the code reader 210 can read the device information from the image attached to the battery switch 600 by the image recognition process.
  • the FW terminal 300 is a terminal device used by a field worker (FW: Field Worker) who performs initial settings for the battery switch 600.
  • the router 400 is a router that connects the battery switch 600 to the management server 500 so as to be communicable.
  • the battery changer 600 is a device that replaces a used battery with a charged battery. When a used battery is inserted, the battery changer 600 discharges the charged battery and charges the charged battery.
  • the battery changer 600 is an example of a device to be managed by the device management system 100 of the present embodiment.
  • the SP terminal 200 is communicably connected to the management server 500 via the network NW1.
  • the network NW1 is a WAN (Wide Area Network) including a public network such as a cellular network and the Internet.
  • the SP terminal 200 may be connected to the network NW1 by wire communication, or may be connected to the network NW1 by wireless communication.
  • the SP terminal 200 may be communicably connected to the management server 500 via the network NW2 instead of the network NW1.
  • the network NW2 is a WAN configured by using a closed network such as a wide area ether or a leased line. It can be said that the network NW2 is a network with higher security than the network NW1.
  • the FW terminal 300 is communicably connected to the management server 500 via the network NW1.
  • the FW terminal 300 is connected to the network NW1 by wireless communication.
  • the router 400 is connected to the network NW2 and is communicably connected to the management server 500 via the network NW2. Further, the router 400 is communicably connected to the battery switch 600. The router 400 relays communication between the management server 500 and the battery switch 600.
  • the router 400 may be a wireless router, and may function as a wireless LAN master unit based on a wireless LAN (Local Area Network) standard such as Wi-Fi (registered trademark, the same applies hereinafter), and the battery switch 600 may be used. It may be configured to accommodate as a wireless LAN slave unit.
  • a wireless LAN Local Area Network
  • Wi-Fi registered trademark, the same applies hereinafter
  • the management server 500 is communicably connected to the router 400 via the network NW2.
  • the management server 500 may be connected to the NW2 by wire communication or may be connected to the network NW2 by wireless communication.
  • the management server 500 is communicably connected to the battery switch 600 via the router 400.
  • the management server 500 is communicably connected to the SP terminal 200 and the FW terminal 300 via the network NW1.
  • the management server 500 may be connected to the network NW1 by wired communication, or may be connected to the network NW1 by wireless communication.
  • the battery switch 600 is connected to the router 400 so as to be communicable.
  • the battery switch 600 and the management server 500 may be connected by wired communication or wireless communication.
  • the battery switcher 600 to be managed the management server 500 that performs the initial setting of the battery switcher 600 by communication with the battery switcher 600, and the battery switcher 600 communicate with the management server 500.
  • the first communication path used for the operation and the second communication path used for acquiring the credential information required for the battery switch 600 to start the initial setting which is different from the first communication path. It is equipped with a communication path.
  • the first communication path is a path in which the management server 500 and the battery switch 600 communicate with each other via the network NW2.
  • the second communication path is a path through which the FW terminal 300 and the management server 500 communicate with each other via the network NW1.
  • the FW terminal 300 includes a wireless communication unit 310, an input unit 320, a display unit 330, a storage unit 340, and a control unit 350.
  • the control unit 350 is realized by, for example, a hardware processor such as a CPU (Central Processing Unit) executing a program (software).
  • a hardware processor such as a CPU (Central Processing Unit) executing a program (software).
  • Some or all of these components are hardware (circuit parts) such as LSI (Large Scale Integration), ASIC (Application Specific Integrated Circuit), FPGA (Field-Programmable Gate Array), and GPU (Graphics Processing Unit).
  • the program may be realized by (including circuits), or it may be realized by the cooperation of software and hardware.
  • the program may be stored in advance in a storage device (a storage device including a non-transient storage medium) such as an HDD (Hard Disk Drive) or a flash memory, or a removable storage device such as a DVD or a CD-ROM. It is stored in a medium (non-transient storage medium) and may be installed by mounting the storage medium in a drive device.
  • the wireless communication unit 310 is a wireless communication interface that wirelessly connects the FW terminal 300 to the network NW1.
  • the wireless communication unit 310 is configured by using a wireless LAN interface that can be connected to the network NW1.
  • the wireless communication unit 310 is communicably connected to the management server 500 via the network NW1.
  • the input unit 320 is configured by using an input device such as a button, a switch, a keyboard, a mouse, and a touch panel.
  • the input unit 320 receives an operation input to the FW terminal 300.
  • the input unit 320 outputs input information indicating the contents of the received operation input to the control unit 350.
  • the display unit 330 is configured by using a display device such as a liquid crystal display, an organic EL display, or a touch panel.
  • the display unit 330 can display arbitrary information based on the instruction of the control unit 350.
  • the storage unit 340 is configured by using a storage device such as an HDD or a flash memory.
  • the storage unit 340 stores data of a program executed by the FW terminal 300, communication data transmitted / received to / from another device, and various information related to the operation of the FW terminal 300.
  • the control unit 350 has a function of inputting / outputting information to / from the wireless communication unit 310, the input unit 320, the display unit 330, and the storage unit 340, and controlling the operation of the FW terminal 300.
  • the control function of the control unit 350 includes a function of acquiring a one-time password (hereinafter, may be abbreviated as "OTPW") from the management server 500.
  • OTPW one-time password
  • the control unit 350 includes, for example, an OTPW acquisition unit 351 as a configuration for realizing this function.
  • the OTPW acquisition unit 351 requests the management server 500 to issue a one-time password, and acquires the one-time password from the management server 500 as a response to the request.
  • the OTPW acquisition unit 351 displays the acquired one-time password on the display unit 330.
  • the OTPW acquisition unit 351 is realized by an application for field workers (hereinafter referred to as "OTWP application").
  • OTPW application is activated by a field worker operating the FW terminal 300, and displays an input screen for information necessary for issuing a one-time password (for example, a field worker's ID and password) on the display unit 330. Display.
  • the OTPW application sends a one-time password issuance request to the management server 500 together with the information input on the input screen.
  • the OTPW application notifies the on-site worker of the issued one-time password by displaying the issued one-time password display screen on the display unit 330.
  • the router 400 includes a first communication unit 411, a second communication unit 412, an input unit 420, a display unit 430, a storage unit 440, and a control unit 450.
  • the control unit 450 is realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware such as LSI, ASIC, FPGA, GPU (circuit part; including circuitry), or realized by the cooperation of software and hardware. May be good.
  • the program may be stored in advance in a storage device (a storage device including a non-transient storage medium) such as an HDD or a flash memory, or a removable storage medium (non-transient) such as a DVD or a CD-ROM. It is stored in a sex storage medium) and may be installed by attaching the storage medium to a drive device.
  • a storage device a storage device including a non-transient storage medium
  • non-transient such as an HDD or a flash memory
  • a removable storage medium non-transient
  • the first communication unit 411 is a communication interface for connecting the router 400 to the network NW2.
  • the first communication unit 411 is configured by using a LAN interface that can be connected to the network NW2.
  • the first communication unit 411 is communicably connected to the management server 500 via the network NW2.
  • the first communication unit 411 may be a wireless communication interface that connects the router 400 to the network NW2 via wireless communication.
  • the second communication unit 412 is a communication interface for connecting the router 400 to the battery switch 600.
  • the second communication unit 412 is configured by using a LAN interface that can be connected to the network NW2.
  • the second communication unit 412 may be configured to accept a connection request from the battery switch 600 registered in advance.
  • the second communication unit 412 may be a wireless communication interface that connects the router 400 to the battery switch 600 via wireless communication.
  • the input unit 420 is configured by using an input device such as a button, a switch, a keyboard, a mouse, and a touch panel.
  • the input unit 420 receives an operation input to the router 400.
  • the input unit 420 outputs input information indicating the contents of the received operation input to the control unit 450.
  • the display unit 430 is configured by using a display device such as a liquid crystal display, an organic EL display, or a touch panel.
  • the display unit 430 can display arbitrary information based on the instruction of the control unit 450.
  • the storage unit 440 is configured by using a storage device such as an HDD or a flash memory.
  • the storage unit 440 stores data of a program executed by the router 400, communication data transmitted / received to / from another device, and various information related to the operation of the router 400.
  • the control unit 450 has a function of inputting / outputting information to / from the first communication unit 411, the second communication unit 412, the input unit 420, the display unit 430, and the storage unit 440, and controlling the operation of the router 400.
  • the control function of the control unit 450 includes a function as a router for relaying communication and a function for connecting the battery exchange 600 and the router 400 so that the battery exchange 600 can communicate with the management server 500.
  • the control unit 450 includes, for example, a connection control unit 451 and a relay processing unit 452 as a configuration for realizing these functions.
  • the connection control unit 451 has a function of connecting the battery switch 600 to the router 400 so that the battery switch 600 can communicate with the management server 500.
  • the battery switch 600 in the factory default state is not set to perform communication necessary for initial setting with the management server 500 (hereinafter referred to as "management communication setting"), and is not made. It is assumed that the information for setting the management communication is not stored. The purpose of this is to reduce the cost of providing the product by having the on-site worker perform the setting that may differ depending on the usage environment as the initial setting, and the device management system 100 of the present embodiment is It supports the implementation of initial settings by field workers.
  • the management server 500 may also have to be provided in consideration of the events of each country or region. There is. Therefore, in the device management system 100 of the present embodiment, the management communication setting is also performed locally as a part of the initial setting.
  • the connection control unit 451 connects the battery switch 600 to the router 400 while making such management communication settings, and it is assumed that the information necessary for the management communication settings is stored in the storage unit 440 in advance.
  • the connection control unit 451 may be configured to set a DNS (Domain Name System) server capable of resolving the name of the management server 500 in the battery switch 600 when the router 400 and the battery switch 600 are connected. ..
  • the DSN server may be the router 400 or another device capable of communicating with the router 400.
  • the connection control unit 451 may be configured to notify the battery switch 600 of the address information of the management server 500 when the router 400 and the battery switch 600 are connected. By making such a management communication setting, the battery switch 600 is connected to the router 400 in a state where it can communicate with the management server 500. That is, the router 400 holds information necessary for enabling the battery switch 600 connected to itself to communicate with the management server 500 via itself.
  • the relay processing unit 452 has a function of relaying communication between the battery switch 600 connected to the router 400 and the management server 500. This function may be equivalent to the relay function by a conventional router.
  • the router 400 is used for making initial settings for the battery switch 600, and is prepared prior to carrying out the initial setting work at the site and handed over to the on-site worker.
  • the field worker goes to the site with the handed router 400, and when he arrives at the site, he turns on the power of the router 400 and the battery switch 600.
  • the battery exchange 600 attempts to connect to the router 400 in the startup process after the power is turned on, and is connected to the router 400 in a state of being able to communicate with the management server 500 by the above-mentioned function of the connection control unit 451.
  • the management server 500 is an example of the management device in the present invention.
  • the management server 500 includes a first communication unit 511, a second communication unit 512, a storage unit 540, and a control unit 550.
  • the control unit 550 is realized by, for example, a hardware processor such as a CPU executing a program (software).
  • a hardware processor such as a CPU executing a program (software).
  • Some or all of these components may be realized by hardware such as LSI, ASIC, FPGA, GPU (circuit part; including circuitry), or realized by the cooperation of software and hardware. May be good.
  • the program may be stored in advance in a storage device (a storage device including a non-transient storage medium) such as an HDD or a flash memory, or a removable storage medium (non-transient) such as a DVD or a CD-ROM. It is stored in a sex storage medium) and may be installed by attaching the storage medium to a drive device.
  • a storage device a storage device including a non-transient storage medium
  • non-transient such as an HDD or a flash memory
  • a removable storage medium non-transient
  • the first communication unit 511 is a communication interface for connecting the management server 500 to the network NW2.
  • the first communication unit 511 is configured by using a wired communication interface that can be connected to the network NW2.
  • the first communication unit 511 is communicably connected to the router 400 via the network NW2.
  • the first communication unit 511 may be a wireless communication interface that connects the management server 500 to the network NW2 via wireless communication.
  • the second communication unit 512 is a communication interface for connecting the management server 500 to the network NW1.
  • the second communication unit 512 is configured by using a wired communication interface that can be connected to the network NW1.
  • the second communication unit 512 is communicably connected to the SP terminal 200 and the FW terminal 300 via the network NW1.
  • the second communication unit 512 may be a wireless communication interface that connects the management server 500 to the network NW1 via wireless communication.
  • the storage unit 540 is configured by using a storage device such as an HDD or a flash memory.
  • the storage unit 540 stores data of a program executed by the management server 500, communication data transmitted / received to / from another device, and various information related to the operation of the management server 500.
  • the control unit 550 has a function of inputting / outputting information to / from the first communication unit 511, the second communication unit 512, and the storage unit 540, and controlling the operation of the management server 500.
  • the control functions of the control unit 550 include a function of registering device information provided by the SP terminal 200, a function of issuing a one-time password, and a function of authenticating the battery switch 600 for starting the initial setting. It includes a function to execute a process related to the initial setting of the battery switch 600.
  • the control unit 550 includes, for example, a device information registration unit 551, an OTPW issuing unit 552, a device authentication unit 553, and a device setting unit 554 as configurations for realizing these functions.
  • the device information registration unit 551 has a function of registering device information provided from the SP terminal 200 in the storage unit 540.
  • the device information is information that enables the identification of the battery switch 600.
  • the device information provided from the SP terminal 200 is information read by using the code reader 210. Device information is attached to the battery switch 600 shipped from the factory.
  • the manufacturer of the battery switch 600 displays the device information encoded by a bar code, a two-dimensional code, or the like on a box or the like for packing the battery switch 600, and ships the battery switch 600 to the service provider.
  • the service provider acquires device information by reading the code displayed on the delivered item using the code reader 210, and transmits the acquired device information to the management server 500 via the SP terminal 200.
  • the device information registration unit 551 registers the device information received from the SP terminal 200 in the storage unit 540.
  • the device information provided by the SP terminal 200 is an example of the second device information in the present invention.
  • the OTPW issuing unit 552 has a function of issuing a one-time password. Specifically, the OTPW issuing unit 552 issues a one-time password in response to an issuance request from the FW terminal 300, and manages the issued one-time password so that it is valid for a predetermined period.
  • the device authentication unit 553 has a function of authenticating the battery switch 600. Specifically, when the device authentication unit 553 receives the authentication request from the battery switch 600, it tries to authenticate the request source battery switch 600 based on the device information and the one-time password provided together with the certification request.
  • the device information provided from the battery switch 600 is recorded in the storage unit 640 in advance at the time of shipment of the battery switch 600, and the one-time password is a FW terminal by a field worker who performs the initial setting of the battery switch 600. It is obtained from the management server 500 using the 300.
  • the device authentication unit 553 determines that the battery switch 600 of the device information provider is registered in the management server 500 in advance and the provided one-time password is valid, the requesting battery. Authenticate the switch 600.
  • the device authentication unit 553 notifies the requesting battery switch 600 of the authentication result.
  • the device setting unit 554 has a function of executing a process related to the initial setting of the battery switch 600 (hereinafter referred to as "initial setting process"). Specifically, the device setting unit 554 reads the initial setting information registered in advance in the management server 500 from the storage unit 540 by executing the initial setting process, and provides the read initial setting information to the battery exchange 600.
  • the initial setting information is information necessary for the initial setting of the battery switch 600, and is information including setting values of various setting items to be set in the battery switch 600 in the initial setting.
  • the device setting unit 554 performs a predetermined procedure in cooperation with the initial setting unit 653 of the battery exchange 600, and exchanges setting information necessary for each procedure, so that the procedure as a whole is one. Initial setting information shall be provided to the battery switch 600.
  • the initial setting may be configured as a process performed independently by the battery switch 600 based on the initial setting information.
  • the initial setting information may be provided from the management server 500 to the battery switch 600 by one transmission / reception.
  • the initial setting is completed by registering the initial setting information provided from the management server 500 in this way.
  • the battery changer 600 includes a charger 601, a drive unit 602, a power supply unit 603, a communication unit 610, an input unit 620, a display unit 630, a storage unit 640, and a control unit 650.
  • the control unit 650 is realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware such as LSI, ASIC, FPGA, GPU (circuit part; including circuitry), or realized by the cooperation of software and hardware. May be good.
  • the program may be stored in advance in a storage device (a storage device including a non-transient storage medium) such as an HDD or a flash memory, or a removable storage medium (non-transient) such as a DVD or a CD-ROM. It is stored in a sex storage medium) and may be installed by attaching the storage medium to a drive device.
  • a storage device a storage device including a non-transient storage medium
  • non-transient such as an HDD or a flash memory
  • a removable storage medium non-transient
  • the charger 601 is a charger for charging the battery inserted in the battery switch 600.
  • the charger 501 charges the battery inserted in the battery switch 600 as a replacement target by using the electric power supplied by the power supply unit 603.
  • the drive unit 602 is a functional unit that realizes a physical operation related to battery charging, and is composed of a combination of various structural members and electronic components.
  • the drive unit 602 includes structural members (not shown) such as a door and a pedestal that constitute a battery charging unit and a battery charging unit.
  • the drive unit 602 includes parts (not shown) such as a motor, a gear, and a shaft that realize opening and closing of a door and movement of a battery inside the battery switch 600.
  • the battery changer 600 can collect the battery to be replaced in the device and discharge the charged battery to the outside of the device in place of the collected battery.
  • the battery exchange 600 can connect the battery collected in the device to the charger 601 and remove the charged battery from the charger 601.
  • the power supply unit 603 is a functional unit that supplies drive power to the battery switch 600.
  • the power supply unit 603 may be an internal battery or a power supply circuit for inputting power supplied by an external power supply.
  • the internal battery may be a battery or a generator.
  • the communication unit 610 is a communication interface for connecting the battery switch 600 to the router 400.
  • the communication unit 610 is set for management communication when establishing a connection with the router 400 by the function of the connection control unit 451 of the router 400. As a result, the communication unit 610 can communicate with the management server 500 after establishing the connection with the router 400.
  • the communication unit 610 may be a wireless communication interface that connects the battery switch 600 to the router 400 via wireless communication.
  • the input unit 620 is configured by using an input device such as a button, a switch, a keyboard, a mouse, and a touch panel.
  • the input unit 620 receives an operation input to the battery switch 600.
  • the input unit 620 outputs input information indicating the contents of the received operation input to the control unit 650.
  • the display unit 630 is configured by using a display device such as a liquid crystal display, an organic EL display, or a touch panel.
  • the display unit 630 can display arbitrary information based on the instruction of the control unit 650.
  • the storage unit 640 is configured by using a storage device such as an HDD or a flash memory.
  • the storage unit 640 stores data of a program executed by the battery switch 600, communication data transmitted / received to / from another device, and various information related to the operation of the battery switch 600.
  • the control unit 650 has a function of inputting / outputting information to / from the communication unit 610, the input unit 620, the display unit 630, and the storage unit 640, and controlling the operation of the battery switch 600.
  • the control functions of the control unit 650 include a function of controlling various physical operations related to battery charging and replacement, a function of authenticating the implementation of initial settings for the battery switch 600, and initial settings for the battery switch 600. Includes functions to perform.
  • the control unit 650 includes, for example, a drive control unit 651, an authentication unit 652, and an initial setting unit 653 as a configuration for realizing these functions.
  • the drive control unit 651 has a function of controlling various physical operations related to battery charging and replacement. For example, the drive control unit 651 collects the battery to be replaced in the device of the battery changer 600 and collects the battery to be replaced by causing the drive unit 602 to perform a predetermined operation in response to the operation of inserting the battery to be replaced. A charged battery can be discharged outside the device instead of the battery. Further, for example, the drive control unit 651 can start charging the battery by causing the drive unit 602 to perform an operation of connecting the newly collected battery to the charger 601. Further, for example, the drive control unit 651 may cause the drive unit 602 to perform an operation of removing the charged battery from the charger 601.
  • the authentication unit 652 has a function of authenticating the implementation of the initial setting for the battery switch 600. Specifically, the authentication unit 652 requests the management server 500 to authenticate the implementation of the initial setting, and when the authentication is successful, causes the initial setting unit 653 to start the initial setting process.
  • the initial setting unit 653 executes the initial setting process of the battery switch 600 in cooperation with the device setting unit 554 of the management server 500 when the execution of the initial setting is authenticated by the authentication unit 652.
  • the initial setting unit 653 registers the set values of various setting items supplied from the management server 500 in the battery exchange 600 in the exchange of each procedure to be performed with the management server 500 in the initial setting process.
  • the initial setting unit 653 completes the initial setting of the battery switch 600 by registering the set values for all the required items.
  • FIG. 2 is a sequence diagram showing an example of a process flow in which the device management system 100 of the present embodiment performs initial setting of the battery switch 600.
  • FIG. 3 is an image diagram showing an outline of a work flow from when the battery switch 600 is shipped from the factory to when it is delivered to the operation site (hereinafter, simply referred to as “local”) and when it is initially set at the site.
  • local the operation site
  • FIG. 2 will be described with reference to the image diagram of FIG. 3 as appropriate.
  • the battery switch 600 is not set assuming a specific country or business operator.
  • the battery changer 600 is shipped from the factory with common settings for the whole world. Since the information necessary for connecting to the management server 500 (for example, the client certificate for connecting to the management server 500) is not registered in the battery exchange 600 in this state, the power is temporarily turned on in this state. Even so, the battery switch 600 cannot be used because it cannot access the management server 500.
  • the battery exchange 600 stores device information that can identify itself in the storage unit 640 in advance, and the coded information indicating the device information is readable and attached to the factory.
  • the coding information is described on the surface of the seal P attached to the predetermined position L on the surface of the box material B that packs the battery switch 600.
  • the storage unit 640 of the battery exchange 600 has the same mark as the coding information M displayed on the seal P because the device information M is registered in the storage unit 640 of the battery exchange 600 in advance. It shows that it has been done.
  • the device information registered in advance in the storage unit 640 of the battery switch 600 is an example of the first device information in the present invention.
  • the factory-shipped battery switch 600 is delivered to, for example, the business office of the service provider.
  • the service provider reads the coded information attached to the shipped battery switch 600 by the code reader 210 (step S101), and transmits the read device information to the management server 500 via the SP terminal 200 (step). S102).
  • the management server 500 receives the device information transmitted by the SP terminal 200, and registers the received device information in the storage unit 540 (step S103). The processing up to this point is carried out by the time the on-site worker FW starts the on-site work.
  • FIG. 4 is a diagram showing an example of device information in this embodiment.
  • the device information is stored in the storage unit 540 of the management server 500 as a device information table T1 composed of one or more records having each value such as a device ID, a device name, a model number, a shipping date, a shipping source, and a shipping destination.
  • the device ID represents the identification information of the battery switch 600 to be registered.
  • the service provider delivers the battery switch 600 shipped from the factory to the site.
  • the service provider dispatches a field worker FW to the site.
  • the field worker FW goes to the site with the FW terminal 300 and performs preparatory work for initial setting for the battery exchange 600 delivered to the site.
  • the field worker FW unpacks the battery switch 600, connects the battery switch 600 to a local power source, and turns on the power (step S104).
  • the communication unit 610 performs a connection process with the router 400 (step S105), and the authentication unit 652 displays a password input screen for inputting a one-time password on the display unit 630. Display (step S106).
  • the battery exchange 600 can communicate with the management server 500. This is due to, for example, the following management communication settings being made.
  • FIG. 5 is a diagram showing an example of setting information regarding communication with the management server 500 set in the battery switch 600 at the time of shipment from the factory.
  • the network ID is the identification information of the network provided by the router 400 installed in the field
  • the connection password is the password for connecting to the network.
  • the management server name represents the name of the management server 500 on the network.
  • the battery switch 600 communicates with the management server 500 by setting a default gateway, a DSN server capable of resolving the management server name, and the like for the battery switch 600. It becomes possible.
  • the field worker FW inputs an operation to acquire a one-time password to the FW terminal 300.
  • the OTPW acquisition unit 351 requests the management server 500 to issue a one-time password (step S107).
  • the OTPW issuing unit 552 issues a one-time password to the FW terminal 300 (step S108).
  • the OTPW issuing unit 552 manages the issued one-time password so that it is valid for a predetermined period.
  • FIG. 6 is a diagram showing an example of one-time password management in the present embodiment.
  • the one-time password is stored in the storage unit 540 of the management server 500 as a password management table T2 composed of one or more records having each value of a worker ID, a password, and an issue date and time.
  • the worker ID represents the identification information of the field worker who requested the issuance of the one-time password.
  • the password represents the character string of the issued one-time password, and the issue date / time represents the date and time when the one-time password was issued.
  • the OTPW acquisition unit 351 causes the display unit 330 to display the one-time password issued by the management server 500 (step S109).
  • the field worker FW visually confirms the one-time password displayed on the display unit 330, and inputs it to the password input screen displayed on the battery switch 600.
  • the input unit 620 accepts the input operation of the one-time password (step S110), and outputs the input information (hereinafter referred to as "password information") to the authentication unit 652.
  • the authentication unit 652 generates authentication information based on the entered password information and the device information registered in advance in the storage unit 640 (step S111).
  • the authentication information is information for requesting the management server 500 to authenticate the implementation of the initial setting, and is information including password information and device information.
  • the authentication unit 652 requests the management server 500 to authenticate by transmitting the generated authentication information to the management server 500 (step S112).
  • the device authentication unit 553 executes an authentication process that attempts to authenticate the requesting battery exchange 600 based on the authentication information received from the battery exchange 600 (step S113). For example, the device authentication unit 553 determines whether or not the password entered by the field worker is registered in the management server 500 as a valid one-time password based on the password information included in the authentication information, and also authenticates. It is determined whether or not the device information included in the information is registered in the management server 500. The device authentication unit 553 authenticates the requesting battery switch 600 when it is determined that both of these two determination results are true. The device authentication unit 553 determines whether or not the authentication of the battery switch 600 has been successful (step S114). Here, if it is determined that the authentication of the battery switch 600 has failed, the device authentication unit 553 performs a predetermined error process and ends a series of processes (step S115). In this case, the initial setting is not performed for the battery switch 600.
  • step S114 if it is determined in step S114 that the authentication of the battery switch 600 has been successful, the device authentication unit 553 notifies the battery switch 600 to that effect (step S116: notification of initial setting start) and also informs the device setting unit 554. On the other hand, it is instructed to execute the initial setting process of the battery switch 600.
  • the initial setting unit 653 of the battery exchange 600 Upon receiving the initial setting start notification, the initial setting unit 653 of the battery exchange 600 starts cooperation with the device setting unit 554 of the management server 500 and executes the initial setting process (step S117).
  • the initial setting process on the battery switch 600 side is represented by step S117-1
  • the initial setting process on the management server 500 side is represented by step S117-2.
  • FIG. 7 is a diagram showing an example of initial setting information in this embodiment.
  • the initial setting information is stored in the storage unit 540 of the management server 500 as the initial setting table T3 composed of one or more records having the model number and the value of the setting information of each item.
  • the device setting unit 554 identifies the initial setting information to be set according to the model number of the battery changer 600 to be initialized.
  • the initial setting unit 653 inquires the device setting unit 554 for the initial setting value to be set for each procedure to be executed, and the device setting unit 554 asks.
  • the value set in the item according to the procedure being executed is returned to the initial setting unit 653. By repeating such inquiries and responses to execute all the procedures, the initial setting unit 653 completes the initial setting for the battery switch 600.
  • the FW terminal 300 acquires a one-time password from the management server 500, and the battery switch 600 acquires the one-time password and the device information stored in advance. Based on this, the management server 500 is certified. Further, in the device management system 100 of the embodiment, the battery exchange 600 does not store the setting information for communicating with the management server 500 in advance, and can communicate with the management server 500 by connecting to the router 400 on site. It is configured to be. Further, in the device management system 100 of the embodiment, the device information stored in advance in the battery switch 600 is registered in the management server 500 before the battery switch 600 delivers to the site. By providing such a configuration, the device management system 100 of the embodiment can more easily perform initial setting of the device while ensuring sufficient security.
  • the router 400 is an example of the first communication device in the present invention
  • the FW terminal 300 is an example of the second communication device in the present invention.
  • the OTPW issuing unit 552 is an example of the qualification information issuing unit in the present invention.
  • the storage unit 540 of the management server 500 is an example of the first storage unit in the present invention.
  • the storage unit 640 of the battery switch 600 is an example of the second storage unit in the present invention.
  • Storage unit 550 ... Control unit , 551 ... Device information registration section, 552 ... OTPW issuing section, 552 ... Device authentication section, 554 ... Device setting section, 600 ... Battery switch, 601 ... Charger, 602 ... Drive section, 603 ... Power supply section, 610 ... Communication section , 620 ... Input unit, 630 ... Display unit, 640 ... Storage unit, 650 ... Control unit, 651 ... Drive control unit, 652 ... Authentication unit, 653 ... Initial setting unit

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Telephonic Communication Services (AREA)

Abstract

管理対象の機器と、前記機器との通信により前記機器の初期設定を行う管理装置と、を備え、前記管理装置は、前記機器が前記管理装置と通信する際に使用する第1の通信経路と、前記機器において前記初期設定を開始するために必要となる資格情報を取得する際に使用される通信経路であって前記第1の通信経路と異なる第2の通信経路と、のそれぞれを介して通信可能である、機器管理システム。

Description

機器管理システム、管理装置、通信機器、および機器管理方法
 本発明は、機器管理システム、管理装置、通信機器、および機器管理方法に関する。
 本願は、2020年12月11日に出願された日本国特願2020-205884号に基づき優先権を主張し、その内容をここに援用する。
 機器の使用開始に際し、その機器を利用するために最初に行う必要のある設定を初期設定という。例えば、特許文献1には、初期設定の方法として、初期設定の手順を記述した初期設定ファイルに基づいて仮想環境を構築および設定し、その仮想環境で生成した設定ファイルを当該機器の記憶領域に保存する方法が記載されている。
特開2019-113886号公報
 しかしながら、従来の方法では、初期設定を行う機器ごとに、その機器に応じた設定内容を記載した初期設定ファイルを用意することが必要となっていたため、対象機器の台数が多いほど作業負荷が高くなる可能性があった。このような課題を解決する方法の一つとして、初期設定に必要な情報を予め用意された外部装置から取得するように初期設定のプログラムを構成する方法が考えられる。この場合、対象機器に対して初期設定を行う作業者は、まず設置現場において対象機器が外部装置と通信することができりょうに通信設定を行う必要があるが、初期設定の実施時にはさまざまな要因によって通信設定がうまくいかない場合がある。また、初期設定がなされていない機器は、セキュリティ機能が十分に機能していない可能性もある。このような理由により、対象機器の初期設定を安全かつ簡単に行うことができるようにする技術が求められている。
 本発明は、このような事情を考慮してなされたものであり、十分なセキュリティを確保しつつ、より簡単に機器の初期設定を行うことができる機器管理システム、管理装置、通信機器、および機器管理方法を提供することを目的の一つとする。
 この発明に係る機器管理システム、管理装置、通信機器、および機器管理方法は、以下の構成を採用した。
 (1):この発明の一態様に係る機器管理システムは、管理対象の機器と、前記機器との通信により前記機器の初期設定を行う管理装置と、を備え、前記管理装置は、前記機器が前記管理装置と通信する際に使用する第1の通信経路と、前記機器において前記初期設定を開始するために必要となる資格情報を取得する際に使用される通信経路であって前記第1の通信経路と異なる第2の通信経路と、のそれぞれを介して通信可能である、機器管理システムである。
 (2):上記(1)の態様において、前記第1の通信経路は、前記機器および前記管理装置と通信可能に接続された第1の通信機器を含み、前記第1の通信機器は、自身と接続した前記機器が、自身を介して前記管理装置と通信することができるようにするために必要な情報を保持するものである。
 (3):上記(1)または(2)の態様において、前記管理装置は、前記機器の識別情報を含む機器情報を前記機器以外の装置から取得して第1の記憶部に記録する機器情報登録部を備え、前記第1の記憶部に記録される前記機器情報は、画像認識処理により、前記機器に添付された画像から読み取られた情報である。
 (4):上記(3)の態様において、前記機器は、予め前記機器情報が記録されている第2の記憶部を備え、前記機器情報登録部は、前記第2の記憶部に記録されている前記機器情報を前記第1の通信経路を介して前記機器から取得し、前記管理装置は、前記機器情報登録部が前記第1の記憶部に記録した機器情報と、前記第1の通信経路を介して前記機器から取得された機器情報とに基づいて前記機器の認証を行う認証部をさらに備えるものである。
 (5):上記(4)の態様において、前記機器は、前記管理装置との通信により前記初期設定を行う初期設定部をさらに備え、前記管理装置は、前記初期設定部と連携して前記機器の初期設定を行う機器設定部をさらに備え、前記初期設定部および前記機器設定部は、前記認証部によって前記機器が認証された場合に前記初期設定に関する連携を開始するものである。
 (6):上記(5)の態様において、前記初期設定部は、前記第2の通信経路を介して前記管理装置から取得された前記資格情報を、前記第2の記憶部に記録されている前記機器情報とともに前記管理装置に送信し、前記認証部は、前記機器から受信された前記機器情報と、前記第1の記憶部に記録されている前記機器情報と、前記機器から受信された前記資格情報とに基づいて前記機器の認証を行うものである。
 (7):上記(3)~(6)の態様において、前記第2の通信経路は、前記管理装置と通信可能に接続された第2の通信機器を含むものである。
 (8):上記(7)の態様において、前記管理装置は、前記第2の通信経路を介して前記第2の通信機器に前記資格情報を提供する資格情報発行部をさらに備えるものである。
 (9):この発明の一態様に係る通信機器は、管理装置との通信により自身の初期設定を行う通信機器であって、第1の通信経路を介した通信により前記管理装置と連携して前記通信機器の初期設定を行う初期設定部と、前記通信機器の識別情報を含む機器情報を記憶する記憶部と、第2の通信経路を介して得られた資格情報であって、前記初期設定の開始に必要となる資格情報の入力を受け付ける入力部と、前記資格情報が入力されたことに応じて前記管理装置に前記通信機器の認証を要求する認証部と、前記管理装置によって前記通信機器が認証された場合に、前記管理装置との間で前記初期設定に関する連携を開始する初期設定部と、を備える通信機器である。
 (10):この発明の一態様に係る管理装置は、通信機器との通信により前記通信機器の初期設定を行う管理装置であって、第1の通信経路を介した通信により前記通信機器と連携して前記通信機器の初期設定を行う機器設定部と、前記通信機器の識別情報を含む機器情報を前記通信機器以外の装置から取得して記憶部に記録する機器情報登録部と、前記通信機器が前記初期設定を開始するために必要となる資格情報を第2の通信経路を介して発行する資格情報発行部と、前記通信機器に予め記憶されている第1の機器情報と、前記通信機器に入力された資格情報とが前記通信機器から取得された場合に、前記第1の機器情報および前記資格情報と、前記機器情報登録部によって登録された第2の機器情報とに基づいて前記通信機器を認証する認証部と、を備え、前記機器設定部は、前記認証部によって前記通信機器が認証された場合に、前記通信機器との間で前記初期設定に係る連携を開始する、管理装置である。
 (11):この発明の一態様に係る機器管理方法は、管理装置と、前記管理装置の管理対象となる機器とが、前記機器の初期設定に関する通信を第1の通信経路を介して行い、前記管理装置が、前記機器において前記初期設定を開始するために必要となる資格情報を、前記第1の通信経路と異なる第2の通信経路を介して提供する、機器管理方法である。
 (1)~(11)によれば、管理装置と、前記管理装置の管理対象となる機器とが、前記機器の初期設定に関する通信を第1の通信経路を介して行い、前記管理装置が、前記機器において前記初期設定を開始するために必要となる資格情報を、前記第1の通信経路と異なる第2の通信経路を介して提供することにより、高いセキュリティを確保しつつ、より簡単に機器の初期設定を行うことができる。
実施形態の機器管理システムの構成例を示すシステム構成図である。 実施形態の機器管理システムがバッテリ交換機の初期設定を行う処理の流れの一例を示すシーケンス図である。 実施形態のバッテリ交換機が工場出荷されてから現地に配送され、現地にて初期設定されるまでの作業の流れの概略を示すイメージ図である。 実施形態における機器情報の一例を示す図である。 工場出荷時のバッテリ交換機に設定されている管理サーバとの通信に関する設定情報の一例を示す図である。 実施形態におけるワンタイムパスワードの管理の一例を示す図である。 実施形態における初期設定情報の一例を示す図である。
 以下、図面を参照し、本発明の機器管理システム、管理装置、通信機器、および機器管理方法の実施形態について説明する。
 図1は、本実施形態の機器管理システム100の構成例を示すシステム構成図である。機器管理システム100は、管理対象機器の一例であるバッテリ交換機600に対して行われる初期設定に関する情報の管理システムである。初期設定とは、工場出荷後の状態の機器に対して、その機器を使用可能な状態にする基本的な設定を行うことである。機器管理システム100は、SP端末200、コードリーダ210、FW端末300、ルータ400、管理サーバ500、およびバッテリ交換機600を備える。SP端末200は、バッテリ交換機600を用いたサービス事業者(SP:Service Provider)が使用する端末装置である。コードリーダ210は、工場出荷状態のバッテリ交換機600に添付されたバーコードや二次元コード等の符号化情報を読み取る装置である。コードリーダ210は、SP端末200に接続可能であり、読み取った符号化情報を復号し、復号して得られた情報をSP端末200に供給する。すなわち、コードリーダ210は、画像認識処理により、バッテリ交換機600に添付された画像から機器情報を読み取ることができる。
 FW端末300は、バッテリ交換機600に対して初期設定を実施する現場作業員(FW:Field Worker)が使用する端末装置である。ルータ400は、バッテリ交換機600を管理サーバ500と通信可能に接続するルータである。バッテリ交換機600は、使用済みのバッテリを充電済みのバッテリに交換する装置である。バッテリ交換機600は、使用済みのバッテリが投入された場合、充電済みのバッテリを放出し、投入されたバッテリを充電する。バッテリ交換機600は、本実施形態の機器管理システム100の管理対象となる装置の一例である。
 ここで、SP端末200は、ネットワークNW1を介して管理サーバ500と通信可能に接続される。例えば、ネットワークNW1は、セルラー網やインターネット等の公衆網を含むWAN(Wide Area Network)である。SP端末200は、有線通信によってネットワークNW1に接続されてもよいし、無線通信によってネットワークNW1に接続されてもよい。SP端末200は、ネットワークNW1に代えて、ネットワークNW2を介して管理サーバ500と通信可能に接続されてもよい。例えば、ネットワークNW2は、広域イーサや専用線等の閉域網を用いて構成されるWANである。ネットワークNW2は、ネットワークNW1よりもセキュリティの高いネットワークということができる。FW端末300は、ネットワークNW1を介して管理サーバ500と通信可能に接続される。FW端末300は、無線通信によってネットワークNW1に接続される。
 ルータ400は、ネットワークNW2に接続され、ネットワークNW2を介して管理サーバ500と通信可能に接続される。また、ルータ400は、バッテリ交換機600と通信可能に接続される。ルータ400は、管理サーバ500とバッテリ交換機600との間の通信を中継する。なお、ルータ400は、無線ルータであってもよく、例えば、Wi-Fi(登録商標、以下同様)等の無線LAN(Local Area Network)規格に基づく無線LAN親機として機能し、バッテリ交換機600を無線LAN子機として収容するように構成されてもよい。
 管理サーバ500は、ネットワークNW2を介してルータ400と通信可能に接続される。管理サーバ500は、有線通信によってNW2に接続されてもよいし、無線通信によってネットワークNW2に接続されてもよい。管理サーバ500は、ルータ400を介してバッテリ交換機600と通信可能に接続される。一方、管理サーバ500は、ネットワークNW1を介してSP端末200およびFW端末300と通信可能に接続される。管理サーバ500は、有線通信によってネットワークNW1に接続されてもよいし、無線通信によってネットワークNW1に接続されてもよい。
 バッテリ交換機600は、ルータ400と通信可能に接続される。バッテリ交換機600と管理サーバ500とは有線通信によって接続されてもよいし、無線通信によって接続されてもよい。
 このように、実施形態の機器管理システム100は、管理対象のバッテリ交換機600と、バッテリ交換機600との通信によりバッテリ交換機600の初期設定を行う管理サーバ500と、バッテリ交換機600が管理サーバ500と通信する際に使用する第1の通信経路と、バッテリ交換機600が初期設定を開始するために必要となる資格情報を取得する際に使用する通信経路であって第1の通信経路と異なる第2の通信経路と、を備える。第1の通信経路は、管理サーバ500とバッテリ交換機600とがネットワークNW2を介して通信する経路である。また、第2の通信経路は、FW端末300と管理サーバ500とがネットワークNW1を介して通信する経路である。
 以下、機器管理システム100が備える各装置の機能構成について詳細に説明する。まず、FW端末300の構成について説明する。FW端末300は、無線通信部310と、入力部320と、表示部330と、記憶部340と、制御部350と、を備える。これらの構成要素のうち制御部350は、例えば、CPU(Central Processing Unit)などのハードウェアプロセッサがプログラム(ソフトウェア)を実行することにより実現される。これらの構成要素のうち一部または全部は、LSI(Large Scale Integration)やASIC(Application Specific Integrated Circuit)、FPGA(Field-Programmable Gate Array)、GPU(Graphics Processing Unit)などのハードウェア(回路部;circuitryを含む)によって実現されてもよいし、ソフトウェアとハードウェアの協働によって実現されてもよい。プログラムは、予めHDD(Hard Disk Drive)やフラッシュメモリなどの記憶装置(非一過性の記憶媒体を備える記憶装置)に格納されていてもよいし、DVDやCD-ROMなどの着脱可能な記憶媒体(非一過性の記憶媒体)に格納されており、記憶媒体がドライブ装置に装着されることでインストールされてもよい。
 無線通信部310は、FW端末300をネットワークNW1に無線接続する無線通信インタフェースである。例えば、無線通信部310は、ネットワークNW1に接続可能な無線LANインタフェースを用いて構成される。無線通信部310は、ネットワークNW1を介して管理サーバ500と通信可能に接続される。
 入力部320は、ボタンやスイッチ、キーボード、マウス、タッチパネル等の入力装置を用いて構成される。入力部320は、FW端末300に対する操作の入力を受け付ける。入力部320は、受け付けた操作入力の内容を示す入力情報を制御部350に出力する。
 表示部330は、液晶ディスプレイや有機ELディスプレイ、タッチパネル等の表示装置を用いて構成される。表示部330は、制御部350の指示に基づき、任意の情報を表示可能である。
 記憶部340は、HDDやフラッシュメモリ等の記憶装置を用いて構成される。記憶部340には、FW端末300が実行するプログラムのデータや、他の装置との間で送受信された通信データのほか、FW端末300の動作に関する各種情報が記憶される。
 制御部350は、無線通信部310、入力部320、表示部330、および記憶部340との間で情報の入出力を行うとともに、FW端末300の動作を制御する機能を有する。ここで、制御部350の制御機能には、管理サーバ500からワンタイムパスワード(以下「OTPW」と略記する場合がある。)を取得する機能が含まれる。制御部350は、この機能を実現するための構成として、例えば、OTPW取得部351を備える。
 OTPW取得部351は、管理サーバ500に対してワンタイムパスワードの発行を要求し、その要求に対する応答として管理サーバ500からワンタイムパスワードを取得する。OTPW取得部351は、管理サーバ500によってワンタイムパスワードが発行されると、取得したワンタイムパスワードを表示部330に表示させる。例えば、OTPW取得部351は、現場作業員向けのアプリケーション(以下「OTPWアプリ」という。)によって実現される。例えば、OTPWアプリは、現場作業員がFW端末300を操作することによって起動され、ワンタイムパスワードの発行に必要な情報(例えば、現場作業員のIDやパスワードなど)の入力画面を表示部330に表示させる。OTPWアプリは、入力画面に入力された情報とともに管理サーバ500に対してワンタイムパスワードの発行要求を送信する。OTPWアプリは、ワンタイムパスワードが正常に発行された場合には、発行されたワンタイムパスワードの表示画面を表示部330に表示させることで、発行されたワンタイムパスワードを現場作業員に通知する。
 続いて、ルータ400の構成について説明する。ルータ400は、第1通信部411と、第2通信部412と、入力部420と、表示部430と、記憶部440と、制御部450と、を備える。これらの構成要素のうち制御部450は、例えば、CPUなどのハードウェアプロセッサがプログラム(ソフトウェア)を実行することにより実現される。これらの構成要素のうち一部または全部は、LSIやASIC、FPGA、GPUなどのハードウェア(回路部;circuitryを含む)によって実現されてもよいし、ソフトウェアとハードウェアの協働によって実現されてもよい。プログラムは、予めHDDやフラッシュメモリなどの記憶装置(非一過性の記憶媒体を備える記憶装置)に格納されていてもよいし、DVDやCD-ROMなどの着脱可能な記憶媒体(非一過性の記憶媒体)に格納されており、記憶媒体がドライブ装置に装着されることでインストールされてもよい。
 第1通信部411は、ルータ400をネットワークNW2に接続する通信インタフェースである。例えば、第1通信部411は、ネットワークNW2に接続可能なLANインタフェースを用いて構成される。第1通信部411は、ネットワークNW2を介して管理サーバ500と通信可能に接続される。なお、第1通信部411は、無線通信を介してルータ400をネットワークNW2に接続する無線通信インタフェースであってもよい。
 第2通信部412は、ルータ400をバッテリ交換機600に接続する通信インタフェースである。例えば、第2通信部412は、ネットワークNW2に接続可能なLANインタフェースを用いて構成される。第2通信部412は、予め登録されているバッテリ交換機600からの接続要求を受け入れるように構成されてもよい。なお、第2通信部412は、無線通信を介してルータ400をバッテリ交換機600に接続する無線通信インタフェースであってもよい。
 入力部420は、ボタンやスイッチ、キーボード、マウス、タッチパネル等の入力装置を用いて構成される。入力部420は、ルータ400に対する操作の入力を受け付ける。入力部420は、受け付けた操作入力の内容を示す入力情報を制御部450に出力する。
 表示部430は、液晶ディスプレイや有機ELディスプレイ、タッチパネル等の表示装置を用いて構成される。表示部430は、制御部450の指示に基づき、任意の情報を表示可能である。
 記憶部440は、HDDやフラッシュメモリ等の記憶装置を用いて構成される。記憶部440には、ルータ400が実行するプログラムのデータや、他の装置との間で送受信された通信データのほか、ルータ400の動作に関する各種情報が記憶される。
 制御部450は、第1通信部411、第2通信部412、入力部420、表示部430、および記憶部440との間で情報の入出力を行うとともに、ルータ400の動作を制御する機能を有する。ここで、制御部450の制御機能には、通信を中継するルータとしての機能と、バッテリ交換機600が管理サーバ500と通信できるようにバッテリ交換機600とルータ400とを接続する機能とが含まれる。制御部450は、これらの機能を実現するための構成として、例えば、接続制御部451および中継処理部452を備える。
 接続制御部451は、バッテリ交換機600が管理サーバ500と通信することができるようにバッテリ交換機600をルータ400に接続する機能を有する。ここで、工場出荷時の状態のバッテリ交換機600には、管理サーバ500との間で初期設定に必要な通信を行うための設定(以下「管理通信設定」という。)がなされておらず、且つ管理通信設定を行うための情報も記憶されていないものとする。これは、使用環境によって異なる可能性のある設定を初期設定として現場作業員に行ってもらうことによって製品の提供コストを抑えることを目的としたものであり、本実施形態の機器管理システム100は、現場作業員による初期設定の実施を支援するものである。ここで、バッテリ交換機600を使用する国や地域の事情はさまざまに異なり得るものであることを考慮すると、管理サーバ500もそれらの国や地域ごとの事象を考慮して設けられなければならない可能性がある。そのため、本実施形態の機器管理システム100では、管理通信設定も初期設定の一環として現地にて行われるものとしている。接続制御部451は、このような管理通信設定を行いつつバッテリ交換機600をルータ400に接続させるものであり、管理通信設定に必要な情報は予め記憶部440に記憶されているものとする。
 例えば、接続制御部451は、ルータ400とバッテリ交換機600との接続時において、管理サーバ500の名前解決が可能なDNS(Domain Name System)サーバをバッテリ交換機600に設定するように構成されてもよい。この場合、DNSサーバは、ルータ400であってもよし、ルータ400と通信可能な他の装置であってもよい。また、例えば、接続制御部451は、ルータ400とバッテリ交換機600との接続時において、管理サーバ500のアドレス情報をバッテリ交換機600に通知するように構成されてもよい。このような管理通信設定が行われることにより、バッテリ交換機600は管理サーバ500と通信可能な状態でルータ400に接続される。すなわち、ルータ400は、自身と接続したバッテリ交換機600が、自身を介して管理サーバ500と通信することができるようにするために必要な情報を保持するものである。
 中継処理部452は、ルータ400に接続しているバッテリ交換機600と、管理サーバ500との間の通信を中継する機能を有する。この機能は、従来のルータによる中継機能と同等であってよい。
 なお、ルータ400は、バッテリ交換機600に対して初期設定を行うために用いられるものであり、現地での初期設定の作業実施に先立って準備され、現場作業員に渡される。現場作業員は、渡されたルータ400を伴って現地に向かい、現地に到着するとルータ400およびバッテリ交換機600の電源をオンにする。バッテリ交換機600は、電源オン後の起動処理においてルータ400への接続を試み、接続制御部451の上記機能により、管理サーバ500と通信可能な状態でルータ400に接続される。
 続いて、管理サーバ500の構成について説明する。管理サーバ500は、本発明における管理装置の一例である。例えば、管理サーバ500は、第1通信部511と、第2通信部512と、記憶部540と、制御部550と、を備える。これらの構成要素のうち制御部550は、例えば、CPUなどのハードウェアプロセッサがプログラム(ソフトウェア)を実行することにより実現される。これらの構成要素のうち一部または全部は、LSIやASIC、FPGA、GPUなどのハードウェア(回路部;circuitryを含む)によって実現されてもよいし、ソフトウェアとハードウェアの協働によって実現されてもよい。プログラムは、予めHDDやフラッシュメモリなどの記憶装置(非一過性の記憶媒体を備える記憶装置)に格納されていてもよいし、DVDやCD-ROMなどの着脱可能な記憶媒体(非一過性の記憶媒体)に格納されており、記憶媒体がドライブ装置に装着されることでインストールされてもよい。
 第1通信部511は、管理サーバ500をネットワークNW2に接続する通信インタフェースである。例えば、第1通信部511は、ネットワークNW2に接続可能な有線通信インタフェースを用いて構成される。第1通信部511は、ネットワークNW2を介してルータ400と通信可能に接続される。なお、第1通信部511は、無線通信を介して管理サーバ500をネットワークNW2に接続する無線通信インタフェースであってもよい。
 第2通信部512は、管理サーバ500をネットワークNW1に接続する通信インタフェースである。例えば、第2通信部512は、ネットワークNW1に接続可能な有線通信インタフェースを用いて構成される。第2通信部512は、ネットワークNW1を介してSP端末200およびFW端末300と通信可能に接続される。なお、第2通信部512は、無線通信を介して管理サーバ500をネットワークNW1に接続する無線通信インタフェースであってもよい。
 記憶部540は、HDDやフラッシュメモリ等の記憶装置を用いて構成される。記憶部540には、管理サーバ500が実行するプログラムのデータや、他の装置との間で送受信された通信データのほか、管理サーバ500の動作に関する各種情報が記憶される。
 制御部550は、第1通信部511、第2通信部512、および記憶部540との間で情報の入出力を行うとともに、管理サーバ500の動作を制御する機能を有する。ここで、制御部550の制御機能には、SP端末200から提供される機器情報を登録する機能と、ワンタイムパスワードを発行する機能と、初期設定を開始するバッテリ交換機600を認証する機能と、バッテリ交換機600の初期設定に関する処理を実行する機能とが含まれる。制御部550は、これらの機能を実現するための構成として、例えば、機器情報登録部551と、OTPW発行部552と、機器認証部553と、機器設定部554とを備える。
 機器情報登録部551は、SP端末200から提供される機器情報を記憶部540に登録する機能を有する。機器情報は、バッテリ交換機600の特定を可能にする情報である。SP端末200から提供される機器情報は、コードリーダ210を用いて読み取られた情報である。工場出荷されたバッテリ交換機600には、機器情報が付されている。
 例えば、バッテリ交換機600の製造メーカは、バッテリ交換機600を梱包する箱などにバーコードや2次元コード等に符号化された機器情報を表示して、バッテリ交換機600をサービスプロバイダに出荷する。サービスプロバイダは、納品物に表示されているコードを、コードリーダ210を用いて読み取ることにより機器情報を取得し、取得した機器情報を、SP端末200を介して管理サーバ500に送信する。機器情報登録部551は、SP端末200から受信された機器情報を記憶部540に登録する。なお、SP端末200から提供される機器情報は、本発明における第2の機器情報の一例である。
 OTPW発行部552は、ワンタイムパスワードを発行する機能を有する。具体的には、OTPW発行部552は、FW端末300からの発行要求に応じてワンタイムパスワードを発行するとともに、発行したワンタイムパスワードが所定期間有効となるように管理する。
 機器認証部553は、バッテリ交換機600を認証する機能を有する。具体的には、機器認証部553は、バッテリ交換機600から認証要求を受け付けると、認証要求とともに提供される機器情報およびワンタイムパスワードに基づいて要求元のバッテリ交換機600の認証を試みる。ここでバッテリ交換機600から提供される機器情報は、バッテリ交換機600の出荷時において予め記憶部640に記録されたものであり、ワンタイムパスワードはバッテリ交換機600の初期設定を行う現場作業員がFW端末300を用いて管理サーバ500から取得したものである。例えば、機器認証部553は、機器情報の提供元のバッテリ交換機600が管理サーバ500に予め登録されており、且つ提供されたワンタイムパスワードが有効であると判定された場合に、要求元のバッテリ交換機600を認証する。機器認証部553は、要求元のバッテリ交換機600に認証結果を通知する。
 機器設定部554は、バッテリ交換機600の初期設定に関する処理(以下「初期設定処理」という。)を実行する機能を有する。具体的には、機器設定部554は、初期設定処理の実行により、予め管理サーバ500に登録されている初期設定情報を記憶部540から読み出し、読み出した初期設定情報をバッテリ交換機600に提供する。初期設定情報は、バッテリ交換機600の初期設定に必要な情報であり、初期設定においてバッテリ交換機600に設定されるべき各種設定項目の設定値を含む情報である。例えば、本実施形態では、機器設定部554は、バッテリ交換機600の初期設定部653と連携して所定の手順を実施し、各手順において必要な設定情報をやり取りすることにより、手順全体として一の初期設定情報をバッテリ交換機600に提供するものとする。
 なお、このような初期設定情報の提供方法は一例であり、本発明における初期設定情報の提供方法をこれに限定するものではない。例えば、初期設定は、バッテリ交換機600が初期設定情報に基づいて単独で実施する処理として構成されてもよい。このような場合、初期設定情報は、一度の送受信によって管理サーバ500からバッテリ交換機600に提供されてもよい。バッテリ交換機600では、このように管理サーバ500から提供される初期設定情報を登録することによって、初期設定が完了する。
 続いて、バッテリ交換機600の構成について説明する。バッテリ交換機600は、充電器601と、駆動部602と、電源部603と、通信部610と、入力部620と、表示部630と、記憶部640と、制御部650と、を備える。これらの構成要素のうち制御部650は、例えば、CPUなどのハードウェアプロセッサがプログラム(ソフトウェア)を実行することにより実現される。これらの構成要素のうち一部または全部は、LSIやASIC、FPGA、GPUなどのハードウェア(回路部;circuitryを含む)によって実現されてもよいし、ソフトウェアとハードウェアの協働によって実現されてもよい。プログラムは、予めHDDやフラッシュメモリなどの記憶装置(非一過性の記憶媒体を備える記憶装置)に格納されていてもよいし、DVDやCD-ROMなどの着脱可能な記憶媒体(非一過性の記憶媒体)に格納されており、記憶媒体がドライブ装置に装着されることでインストールされてもよい。
 充電器601は、バッテリ交換機600に投入されたバッテリを充電する充電器である。充電器501は、交換対象としてバッテリ交換機600に投入されたバッテリを、電源部603によって供給される電力を用いて充電する。
 駆動部602は、バッテリの充電に関する物理動作を実現する機能部であり、各種の構造部材や電子部品の組み合わせによって構成される。例えば、駆動部602は、バッテリの投入部および取り出し部を構成する扉や台座などの構造部材(図示せず)を含む。また、例えば、駆動部602は、扉の開閉や、バッテリ交換機600の内部におけるバッテリの移動を実現するモータやギア、シャフト等の部品(図示せず)を含む。駆動部602の動作により、バッテリ交換機600は交換対象のバッテリを装置内に回収し、回収したバッテリに代えて充電済みのバッテリを装置外に放出することができる。また、駆動部602の動作により、バッテリ交換機600は、装置内に回収されたバッテリを充電器601に接続するとともに、充電が完了したバッテリを充電器601から取り外すことができる。
 電源部603は、バッテリ交換機600に駆動電力を供給する機能部である。例えば電源部603は内部バッテリであってもよいし、外部電源が供給する電力を入力する電源回路であってもよい。内部バッテリは電池であってもよいし、発電機であってもよい。
 通信部610は、バッテリ交換機600をルータ400に接続する通信インタフェースである。なお、通信部610は、ルータ400の接続制御部451の機能により、ルータ400との接続を確立する際に管理通信設定がなされる。これにより、通信部610は、ルータ400との接続を確立した後、管理サーバ500との通信が可能となる。なお、通信部610は、無線通信を介してバッテリ交換機600をルータ400に接続する無線通信インタフェースであってもよい。
 入力部620は、ボタンやスイッチ、キーボード、マウス、タッチパネル等の入力装置を用いて構成される。入力部620は、バッテリ交換機600に対する操作の入力を受け付ける。入力部620は、受け付けた操作入力の内容を示す入力情報を制御部650に出力する。
 表示部630は、液晶ディスプレイや有機ELディスプレイ、タッチパネル等の表示装置を用いて構成される。表示部630は、制御部650の指示に基づき、任意の情報を表示可能である。
 記憶部640は、HDDやフラッシュメモリ等の記憶装置を用いて構成される。記憶部640には、バッテリ交換機600が実行するプログラムのデータや、他の装置との間で送受信された通信データのほか、バッテリ交換機600の動作に関する各種情報が記憶される。
 制御部650は、通信部610、入力部620、表示部630、および記憶部640との間で情報の入出力を行うとともに、バッテリ交換機600の動作を制御する機能を有する。ここで、制御部650の制御機能には、バッテリの充電および交換に関する各種物理動作を制御する機能と、バッテリ交換機600に対する初期設定の実施を認証する機能と、バッテリ交換機600に対して初期設定を行う機能とが含まれる。制御部650は、これらの機能を実現するための構成として、例えば、駆動制御部651と、認証部652と、初期設定部653とを備える。
 駆動制御部651は、バッテリの充電および交換に関する各種物理動作を制御する機能を有する。例えば、駆動制御部651は、交換対象のバッテリを投入する操作に応じて駆動部602に所定の動作を行わせることにより、交換対象のバッテリをバッテリ交換機600の装置内に回収するとともに、回収したバッテリの代わりに充電済みのバッテリを装置外に放出させることができる。また、例えば、駆動制御部651は、新たに回収されたバッテリを充電器601に接続する動作を駆動部602に行わせることにより、バッテリの充電を開始させることができる。また、例えば、駆動制御部651は、充電が完了したバッテリを充電器601から取り外す動作を駆動部602に行わせてもよい。
 認証部652は、バッテリ交換機600に対する初期設定の実施を認証する機能を有する。具体的には、認証部652は、初期設定の実施についての認証を管理サーバ500に要求し、認証に成功した場合に初期設定部653に初期設定処理を開始させる。
 初期設定部653は、認証部652によって初期設定の実施が認証された場合に管理サーバ500の機器設定部554と連携してバッテリ交換機600の初期設定処理を実行する。初期設定部653は、初期設定処理において、管理サーバ500との間で実施する各手順のやり取りにおいて、管理サーバ500から供給される各種設定項目の設定値をバッテリ交換機600に登録する。初期設定部653は、全ての必須項目について設定値の登録を行うことにより、バッテリ交換機600の初期設定を完了する。
 図2は、本実施形態の機器管理システム100がバッテリ交換機600の初期設定を行う処理の流れの一例を示すシーケンス図である。また、図3は、バッテリ交換機600が工場出荷されてから運用現場(以下単に「現地」という。)に配送され、現地にて初期設定されるまでの作業の流れの概略を示すイメージ図である。以下、図3のイメージ図を適宜参照しながら図2の処理の流れについて説明していく。
 まず、図3の工場出荷時において、バッテリ交換機600には特定の国や事業者等を想定した設定はなされていない。バッテリ交換機600は、全世界向けに共通の設定がなされた状態で工場出荷される。この状態のバッテリ交換機600には、管理サーバ500に接続するために必要な情報(例えば管理サーバ500に接続するためのクライアント証明書など)が登録されていないため、仮にこの状態で電源オンされたとしても、バッテリ交換機600は管理サーバ500にアクセスすることができないため、使用することができない。
 一方、バッテリ交換機600は、自身を特定可能な機器情報を記憶部640に予め記憶しており、この機器情報を示す符号化情報が読み取り可能に添付されて工場を出荷される。例えば、符号化情報は、バッテリ交換機600を梱包する箱材Bの表面の所定位置Lに添付されるシールPの表面に記載される。なお、図3において、バッテリ交換機600の記憶部640に、シールPに表示された符号化情報Mと同じマークを記載しているのは、機器情報Mがバッテリ交換機600の記憶部640に予め登録されていることを表している。なお、バッテリ交換機600の記憶部640に予め登録されている機器情報は、本発明における第1の機器情報の一例である。
 次に、工場出荷されたバッテリ交換機600は、例えばサービス事業者の事業所に配送される。サービス事業者は、出荷されたバッテリ交換機600に添付されている符号化情報をコードリーダ210により読み取り(ステップS101)、読み取った機器情報を、SP端末200を介して管理サーバ500に送信する(ステップS102)。管理サーバ500は、SP端末200が送信した機器情報を受信し、受信した機器情報を記憶部540に登録する(ステップS103)。なお、ここまでの処理は、現場作業員FWが現地での作業を開始するまでに実施されるものである。
 図4は、本実施形態における機器情報の一例を示す図である。例えば、機器情報は、機器ID、機器名称、型番、出荷日、出荷元、および出荷先等の各値を有する1以上のレコードからなる機器情報テーブルT1として管理サーバ500の記憶部540に記憶される。ここで機器IDは、登録対象のバッテリ交換機600の識別情報を表している。サービス事業者は、機器情報の登録が完了すると、工場から出荷されてきたバッテリ交換機600を現地に配送する。バッテリ交換機600が現地に配送されると、サービス事業者は現地に現場作業員FWを派遣する。現場作業員FWは、FW端末300を伴って現地に赴き、現地に配送されているバッテリ交換機600に対して、初期設定を行うための準備作業を行う。
 まず、例えば、現場作業員FWは、バッテリ交換機600の梱包を解き、バッテリ交換機600を現地の電源に接続し、電源を投入する(ステップS104)。バッテリ交換機600では、電源投入後の起動処理において、通信部610がルータ400との接続処理を行う(ステップS105)とともに、認証部652がワンタイムパスワードの入力を求めるパスワード入力画面を表示部630に表示させる(ステップS106)。なお、ステップS105において、ルータ400との接続処理が完了することにより、バッテリ交換機600は、管理サーバ500と通信可能になる。これは、例えば、以下のような管理通信設定がなされることによるものである。
 図5は、工場出荷時のバッテリ交換機600に設定されている管理サーバ500との通信に関する設定情報の一例を示す図である。ネットワークIDは、現地に設置されるルータ400が提供するネットワークの識別情報であり、接続パスワードは、そのネットワークに接続するためのパスワードである。管理サーバ名は、ネットワーク上における管理サーバ500の名称を表す。バッテリ交換機600は、ルータ400に接続していない状態では、管理サーバ名の名前解決ができないため管理サーバ500と通信することができないが、ルータ400との接続時において管理通信設定がなされることにより管理サーバ500と通信することが可能になる。具体的には、図5の例では、バッテリ交換機600に対してデフォルトゲートウェイや、管理サーバ名を解決することができるDNSサーバなどが設定されることにより、バッテリ交換機600が管理サーバ500と通信することが可能となる。
 一方、現場作業員FWは、FW端末300に対してワンタイムパスワードを取得する操作を入力する。この操作入力に応じて、FW端末300では、OTPW取得部351が、管理サーバ500に対してワンタイムパスワードの発行を要求する(ステップS107)。管理サーバ500では、OTPW発行部552が、FW端末300に対してワンタイムパスワードを発行する(ステップS108)。このとき、OTPW発行部552は、発行したワンタイムパスワードが所定期間有効となるように管理する。
 図6は、本実施形態におけるワンタイムパスワードの管理の一例を示す図である。例えば、ワンタイムパスワードは、作業員ID、パスワード、および発行日時の各値を有する1以上のレコードからなるパスワード管理テーブルT2として管理サーバ500の記憶部540に記憶される。ここで、作業員IDは、ワンタイムパスワードの発行を要求した現場作業員の識別情報を表している。パスワードは、発行したワンタイムパスワードの文字列を表し、発行日時はワンタイムパスワードを発行した日時を表す。FW端末300では、OTPW取得部351が、管理サーバ500から発行されたワンタイムパスワードを表示部330に表示させる(ステップS109)。現場作業員FWは、表示部330に表示されたワンタイムパスワードを目視にて確認し、それをバッテリ交換機600に表示されているパスワード入力画面に入力する。
 一方、バッテリ交換機600では、入力部620がワンタイムパスワードの入力操作を受け付け(ステップS110)、入力された情報(以下「パスワード情報」という。)を認証部652に出力する。認証部652は、入力されたパスワード情報と、記憶部640に予め登録されている機器情報とに基づいて認証情報を生成する(ステップS111)。認証情報は、管理サーバ500に対し初期設定の実施ついての認証を要求するための情報であり、パスワード情報および機器情報を含む情報である。認証部652は、生成した認証情報を管理サーバ500に送信することにより、管理サーバ500に認証を要求する(ステップS112)。
 続いて、管理サーバ500では、機器認証部553が、バッテリ交換機600から受信された認証情報に基づいて、要求元のバッテリ交換機600の認証を試みる認証処理を実行する(ステップS113)。例えば、機器認証部553は、認証情報に含まれるパスワード情報に基づいて、現場作業員が入力したパスワードが有効なワンタイムパスワードとして管理サーバ500に登録済みであるか否かを判定するとともに、認証情報に含まれる機器情報が管理サーバ500に登録済みであるか否かを判定する。機器認証部553は、これらの2つの判定結果が両方とも真であると判定された場合に、要求元のバッテリ交換機600を認証する。機器認証部553は、バッテリ交換機600の認証に成功したか否かを判定する(ステップS114)。ここで、バッテリ交換機600の認証に失敗したと判定した場合、機器認証部553は、所定のエラー処理を行って一連の処理を終了する(ステップS115)。この場合、バッテリ交換機600に対して初期設定は実施されないこととなる。
 一方、ステップS114において、バッテリ交換機600の認証に成功したと判定した場合、機器認証部553は、その旨をバッテリ交換機600に通知する(ステップS116:初期設定開始通知)とともに、機器設定部554に対してバッテリ交換機600の初期設定処理の実行を指示する。初期設定開始通知を受けたバッテリ交換機600の初期設定部653は、管理サーバ500の機器設定部554との連携を開始して初期設定処理を実行する(ステップS117)。なお、図2においては、バッテリ交換機600側の初期設定処理をステップS117-1で表し、管理サーバ500側の初期設定処理をステップS117-2で表している。
 図7は、本実施形態における初期設定情報の一例を示す図である。例えば、初期設定情報は、型番および各項目の設定情報の値を有する1つ以上のレコードからなる初期設定テーブルT3として管理サーバ500の記憶部540に記憶される。例えば、図7の例において、機器設定部554は、初期設定を行う対象のバッテリ交換機600の型番によって設定すべき初期設定情報を識別する。例えば、初期設定処理で実行する手順が各項目に対応している場合、初期設定部653は、実施する手順ごとに設定すべき初期設定の値を機器設定部554に問い合わせ、機器設定部554は実施中の手順に応じた項目に設定された値を初期設定部653に応答する。このような問い合わせと応答を繰り返してすべての手順を実行することにより、初期設定部653は、バッテリ交換機600に対する初期設定を完了する。
 このように構成された実施形態の機器管理システム100は、FW端末300が管理サーバ500からワンタイムパスワードを取得し、バッテリ交換機600が取得されたワンタイムパスワードと予め記憶している機器情報とに基づいて管理サーバ500の認証を受ける。また、実施形態の機器管理システム100において、バッテリ交換機600は、管理サーバ500と通信するための設定情報を予め記憶しておらず、現地にてルータ400に接続することによって管理サーバ500と通信可能となるように構成される。また、実施形態の機器管理システム100において、バッテリ交換機600に予め記憶されている機器情報は、バッテリ交換機600が現地に配送する前に管理サーバ500に登録済みである。このような構成を備えることにより、実施形態の機器管理システム100は、十分なセキュリティを確保しつつ、より簡単に機器の初期設定を行うことが可能となる。
 なお、上記実施形態において、ルータ400は本発明における第1の通信機器の一例であり、FW端末300は本発明における第2の通信機器の一例である。また、OTPW発行部552は本発明における資格情報発行部の一例である。また、管理サーバ500の記憶部540は本発明における第1の記憶部の一例である。また、バッテリ交換機600の記憶部640は本発明における第2の記憶部の一例である。
 以上、本発明を実施するための形態について実施形態を用いて説明したが、本発明はこうした実施形態に何等限定されるものではなく、本発明の要旨を逸脱しない範囲内において種々の変形及び置換を加えることができる。
100…機器管理システム、200…SP(Service Provider)端末、210…コードリーダ、300…FW(Field Worker)端末、310…無線通信部、320…入力部、330…表示部、340…記憶部、350…制御部、351…OTPW(One-time Password)取得部、400…ルータ、411…第1通信部、412…第2通信部、420…入力部、430…表示部、440…記憶部、450…制御部、451…接続制御部、452…中継処理部、500…管理サーバ、501…充電器、511…第1通信部、512…第2通信部、540…記憶部、550…制御部、551…機器情報登録部、552…OTPW発行部、553…機器認証部、554…機器設定部、600…バッテリ交換機、601…充電器、602…駆動部、603…電源部、610…通信部、620…入力部、630…表示部、640…記憶部、650…制御部、651…駆動制御部、652…認証部、653…初期設定部

Claims (11)

  1.  管理対象の機器と、
     前記機器との通信により前記機器の初期設定を行う管理装置と、
     を備え、
     前記管理装置は、前記機器が前記管理装置と通信する際に使用する第1の通信経路と、前記機器において前記初期設定を開始するために必要となる資格情報を取得する際に使用される通信経路であって前記第1の通信経路と異なる第2の通信経路と、のそれぞれを介して通信可能である、
     機器管理システム。
  2.  前記第1の通信経路は、前記機器および前記管理装置と通信可能に接続された第1の通信機器を含み、
     前記第1の通信機器は、自身と接続した前記機器が、自身を介して前記管理装置と通信することができるようにするために必要な情報を保持する、
     請求項1に記載の機器管理システム。
  3.  前記管理装置は、
     前記機器の識別情報を含む機器情報を前記機器以外の装置から取得して第1の記憶部に記録する機器情報登録部を備え、
     前記第1の記憶部に記録される前記機器情報は、画像認識処理により、前記機器に添付された画像から読み取られた情報である、
     請求項1または2に記載の機器管理システム。
  4.  前記機器は、予め前記機器情報が記録されている第2の記憶部を備え、
     前記機器情報登録部は、前記第2の記憶部に記録されている前記機器情報を前記第1の通信経路を介して前記機器から取得し、
     前記管理装置は、前記機器情報登録部が前記第1の記憶部に記録した機器情報と、前記第1の通信経路を介して前記機器から取得された機器情報とに基づいて前記機器の認証を行う認証部をさらに備える、
     請求項3に記載の機器管理システム。
  5.  前記機器は、前記管理装置との通信により前記初期設定を行う初期設定部をさらに備え、
     前記管理装置は、前記初期設定部と連携して前記機器の初期設定を行う機器設定部をさらに備え、
     前記初期設定部および前記機器設定部は、前記認証部によって前記機器が認証された場合に前記初期設定に関する連携を開始する、
     請求項4に記載の機器管理システム。
  6.  前記初期設定部は、前記第2の通信経路を介して前記管理装置から取得された前記資格情報を、前記第2の記憶部に記録されている前記機器情報とともに前記管理装置に送信し、
     前記認証部は、前記機器から受信された前記機器情報と、前記第1の記憶部に記録されている前記機器情報と、前記機器から受信された前記資格情報とに基づいて前記機器の認証を行う、
     請求項5に記載の機器管理システム。
  7.  前記第2の通信経路は、前記管理装置と通信可能に接続された第2の通信機器を含む、
     請求項3から6のいずれか一項に記載の機器管理システム。
  8.  前記管理装置は、前記第2の通信経路を介して前記第2の通信機器に前記資格情報を提供する資格情報発行部をさらに備える、
     請求項7に記載の機器管理システム。
  9.  管理装置との通信により自身の初期設定を行う通信機器であって、
     第1の通信経路を介した通信により前記管理装置と連携して前記通信機器の初期設定を行う初期設定部と、
     前記通信機器の識別情報を含む機器情報を記憶する記憶部と、
     第2の通信経路を介して得られた資格情報であって、前記初期設定の開始に必要となる資格情報の入力を受け付ける入力部と、
     前記資格情報が入力されたことに応じて前記管理装置に前記通信機器の認証を要求する認証部と、
     前記管理装置によって前記通信機器が認証された場合に、前記管理装置との間で前記初期設定に関する連携を開始する初期設定部と、
     を備える通信機器。
  10.  通信機器との通信により前記通信機器の初期設定を行う管理装置であって、
     第1の通信経路を介した通信により前記通信機器と連携して前記通信機器の初期設定を行う機器設定部と、
     前記通信機器の識別情報を含む機器情報を前記通信機器以外の装置から取得して記憶部に記録する機器情報登録部と、
     前記通信機器が前記初期設定を開始するために必要となる資格情報を第2の通信経路を介して発行する資格情報発行部と、
     前記通信機器に予め記憶されている第1の機器情報と、前記通信機器に入力された資格情報とが前記通信機器から取得された場合に、前記第1の機器情報および前記資格情報と、前記機器情報登録部によって登録された第2の機器情報とに基づいて前記通信機器を認証する認証部と、
     を備え、
     前記機器設定部は、前記認証部によって前記通信機器が認証された場合に、前記通信機器との間で前記初期設定に係る連携を開始する、
     管理装置。
  11.  管理装置と、前記管理装置の管理対象となる機器とが、前記機器の初期設定に関する通信を第1の通信経路を介して行い、
     前記管理装置が、前記機器において前記初期設定を開始するために必要となる資格情報を、前記第1の通信経路と異なる第2の通信経路を介して提供する、
     機器管理方法。
PCT/JP2021/043453 2020-12-11 2021-11-26 機器管理システム、管理装置、通信機器、および機器管理方法 Ceased WO2022124103A1 (ja)

Priority Applications (2)

Application Number Priority Date Filing Date Title
JP2022568180A JPWO2022124103A1 (ja) 2020-12-11 2021-11-26
JP2025029252A JP2025084848A (ja) 2020-12-11 2025-02-26 機器管理システム、管理装置、通信機器、および機器管理方法

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2020205884 2020-12-11
JP2020-205884 2020-12-11

Publications (1)

Publication Number Publication Date
WO2022124103A1 true WO2022124103A1 (ja) 2022-06-16

Family

ID=81973189

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2021/043453 Ceased WO2022124103A1 (ja) 2020-12-11 2021-11-26 機器管理システム、管理装置、通信機器、および機器管理方法

Country Status (2)

Country Link
JP (2) JPWO2022124103A1 (ja)
WO (1) WO2022124103A1 (ja)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2012226394A (ja) * 2011-04-14 2012-11-15 Sii Data Service Kk 端末設置システム及び端末設置方法
JP2019016880A (ja) * 2017-07-05 2019-01-31 富士通株式会社 ネットワーク機器、ネットワークシステム及びネットワーク機器設定方法
JP2019097027A (ja) * 2017-11-22 2019-06-20 株式会社ノーリツ 通信システム、通信システムの制御方法、及び、中継装置

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP6838009B2 (ja) * 2018-02-28 2021-03-03 株式会社東芝 通信制御装置および通信制御方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2012226394A (ja) * 2011-04-14 2012-11-15 Sii Data Service Kk 端末設置システム及び端末設置方法
JP2019016880A (ja) * 2017-07-05 2019-01-31 富士通株式会社 ネットワーク機器、ネットワークシステム及びネットワーク機器設定方法
JP2019097027A (ja) * 2017-11-22 2019-06-20 株式会社ノーリツ 通信システム、通信システムの制御方法、及び、中継装置

Also Published As

Publication number Publication date
JPWO2022124103A1 (ja) 2022-06-16
JP2025084848A (ja) 2025-06-03

Similar Documents

Publication Publication Date Title
JP6451750B2 (ja) 仮想ネットワークシステム、仮想ネットワーク制御方法、仮想ネットワーク機能データベース、統合制御装置、制御装置およびその制御方法と制御プログラム
EP3104549B1 (en) Home appliance, network connection system for home appliance and network connection method of home appliance
JP3946700B2 (ja) 目的のネットワーク環境に対するネットワーク装置のアドレス可能性の自動確立のための方法および装置
US20220052858A1 (en) Virtual network system, control apparatus, control method, and control program
JP5030681B2 (ja) 機器設定装置、ネットワーク機器、機器名設定方法および機器名設定プログラム
CN101201727A (zh) 通过网络的打印机选择支持装置及系统
US9703969B2 (en) Image forming system, service providing server, information processing terminal, image forming device and non-transitory computer readable recording medium
CN105230039B (zh) 室内控制器以及远程控制系统
JP6670782B2 (ja) 通信装置、通信方法、機器およびコンピュータプログラム
JP2019075802A (ja) 仮想ネットワーク制御方法、提供者端末、登録更新制御装置およびそのプログラム
CN113498494A (zh) 安全系统和维护方法
CN104346111A (zh) 信息处理系统、信息处理装置和信息处理方法
JP5232300B2 (ja) 中央コンピュータとマシン制御部との間でリモート通信を行うためのシステムおよび方法
JP2015133567A (ja) 携帯通信端末、管理サーバ、電子チケットシステム、及びプログラム
WO2022124103A1 (ja) 機器管理システム、管理装置、通信機器、および機器管理方法
KR20130116938A (ko) 중계 통신 시스템
US10067486B2 (en) System and method for providing a control program code
CN112004978B (zh) 密钥信息生成系统及密钥信息生成方法
JP7586763B2 (ja) 遠隔操作制御システム及びプログラム
WO2015125952A1 (ja) 電子機器制御システム、電子機器制御システムの動作方法、サーバ、サーバの動作方法、コントローラ、コントローラの動作方法及びプログラム
JP6734443B2 (ja) 情報処理装置、情報処理方法、コンピュータプログラム及び情報処理システム
JP2024013980A (ja) 通信システム、制御装置、通信方法、及びプログラム
JP2013214825A (ja) 中継装置、通信制御方法及び通信制御プログラム
JP6750260B2 (ja) 情報処理装置およびエージェントシステム
US20190043044A1 (en) Method of data transmission, corresponding device, system and computer program

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21903207

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2022568180

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 202347041747

Country of ref document: IN

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21903207

Country of ref document: EP

Kind code of ref document: A1