WO2026018564A1 - 情報処理装置および情報処理システム - Google Patents
情報処理装置および情報処理システムInfo
- Publication number
- WO2026018564A1 WO2026018564A1 PCT/JP2025/018877 JP2025018877W WO2026018564A1 WO 2026018564 A1 WO2026018564 A1 WO 2026018564A1 JP 2025018877 W JP2025018877 W JP 2025018877W WO 2026018564 A1 WO2026018564 A1 WO 2026018564A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- terminal device
- positioning
- area
- information processing
- secure
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G01—MEASURING; TESTING
- G01S—RADIO DIRECTION-FINDING; RADIO NAVIGATION; DETERMINING DISTANCE OR VELOCITY BY USE OF RADIO WAVES; LOCATING OR PRESENCE-DETECTING BY USE OF THE REFLECTION OR RERADIATION OF RADIO WAVES; ANALOGOUS ARRANGEMENTS USING OTHER WAVES
- G01S5/00—Position-fixing by co-ordinating two or more direction or position line determinations; Position-fixing by co-ordinating two or more distance determinations
- G01S5/02—Position-fixing by co-ordinating two or more direction or position line determinations; Position-fixing by co-ordinating two or more distance determinations using radio waves
- G01S5/10—Position of receiver fixed by co-ordinating a plurality of position lines defined by path-difference measurements, e.g. omega or decca systems
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W64/00—Locating users or terminals or network equipment for network management purposes, e.g. mobility management
Definitions
- This technology relates to information processing devices and information processing systems.
- Patent Document 1 An information processing system that uses UWB (Ultra Wide Band) as the wireless communication method has been proposed.
- the positioning of terminal devices is performed using the Downlink TDoA (Time Difference Of Arrival) method.
- the terminal device uses the distance measurement results from the anchor to determine its own position, and then transmits this positioning result to the system's server, etc.
- the positioning results transmitted by the terminal device may be incorrect or may be tampered with, raising concerns about the reliability and security of the positioning results.
- This technology was developed in consideration of these points, and aims to provide an information processing device and information processing system that can improve the reliability and security of positioning results.
- the first technology is an information processing device that includes a positioning processing unit that performs positioning of a terminal device that has passed through a first area and then entered a second area, and an authentication processing unit that performs mutual authentication between the terminal device and a terminal device that has reached a predetermined position away from the second area before the terminal device enters the second area.
- the second technology is an information processing system comprising a terminal device and an information processing device, the terminal device comprising a positioning processing unit that performs positioning of the terminal device and an authentication processing unit that performs mutual authentication with the information processing device, and the information processing device comprising a positioning processing unit that performs positioning of terminal device 10 that has passed through a first area and then entered a second area, and an authentication processing unit that performs mutual authentication with a terminal device that has reached a predetermined position away from the second area before the terminal device entered the second area.
- FIG. 2 is an explanatory diagram of a secure positioning area and a non-secure positioning area according to the first embodiment.
- FIG. 1 is a block diagram showing a configuration of an information processing system 100.
- FIG. 2 is a diagram illustrating movement of the terminal device 10 in the first embodiment.
- 4 is a flowchart showing a process of the terminal device 10 according to the first embodiment.
- 4 is a flowchart showing a process of the server 20 in the first embodiment.
- FIG. 10 is an explanatory diagram of a secure positioning area and a non-secure positioning area according to the second embodiment.
- FIG. 10 is a flowchart showing a process of a server 20 according to the second embodiment.
- FIG. 10 is a diagram illustrating a modified example of a secure positioning area and a non-secure positioning area.
- FIG. 10 is a diagram illustrating a modified example of a secure positioning area and a non-secure positioning area.
- FIG. 10 is a diagram illustrating a modified example of a secure positioning area and a non-secure positioning area.
- FIG. 10 is a diagram illustrating a modified example of a secure positioning area and a non-secure positioning area.
- FIG. 10 is a diagram showing a modified example of the start position.
- a secure positioning area and a non-secure positioning area are set within the space of a facility such as a store or station to which the information processing system 100 is applied.
- the server 20 switches the positioning method depending on whether the terminal device 10 is located in the secure positioning area or the non-secure positioning area.
- the non-secure positioning area corresponds to the first area in the claims, and the secure positioning area corresponds to the second area.
- the secure positioning area is an area in which the server 20 measures the position of the terminal device 10 using UWB positioning functions defined by the specifications of FiRa (registered trademark), an organization related to UWB. With this positioning method, mutual authentication is performed between the terminal device 10 and the server 20 before positioning is performed, ensuring the reliability and security of the positioning results. Positioning in a secure positioning area is called secure positioning.
- the server 20 measures the position of the terminal device 10 using secure positioning, using the distance measurement results between each anchor 30 and the terminal device 10 transmitted from multiple anchors 30 installed in space.
- the secure positioning area is an area where data communication and various processes take place between the terminal device 10 and a processing terminal 50 that processes payment services and other services used by users of the terminal device 10. Therefore, the secure positioning area is set, for example, as an area with a radius of several meters based on the position of the processing terminal 50.
- the non-secure positioning area is set adjacent to the secure positioning area, and is an area in which the terminal device 10 determines its own position.
- the terminal device 10 determines its own position using the Downlink TDoA method, using the distance measurement results between the terminal device 10 and each anchor 30 transmitted from multiple anchors 30 installed in space.
- There are no particular restrictions on the size of the non-secure positioning area and it can be any size as long as it is possible to communicate with the anchor 30 via UWB and obtain distance measurement results.
- the secure positioning area and non-secure positioning area are set as areas in a local coordinate system based on, for example, the position of the processing terminal 50, the position of the anchor 30, other positions, etc.
- TDoA the time difference between the arrival times of radio waves transmitted and received between multiple anchors 30 and the terminal device 10, which are installed in different locations, is converted into distance using the speed of light, thereby obtaining distance measurement results between the anchors 30 and the terminal device 10.
- the time of the terminal device 10 and all anchors 30 must be synchronized. Note that in this embodiment, the anchors 30 transmit the distance measurement results to the terminal device 10, but the process of measuring the time difference, converting that time difference into distance, and obtaining the distance measurement results can be performed by either the terminal device 10 or the anchors 30.
- a start position is set within the non-secure positioning area.
- the start position is the position at which the terminal device 10 receives a trigger signal transmitted from the BLE beacon 40 and starts positioning using the Downlink TDoA method.
- the start position is set to be located at the edge of the non-secure positioning area. In the example of Figure 1, the start position is set at the edge of the non-secure positioning area on the opposite side to the side where the secure positioning area exists.
- the start position corresponds to a predetermined position in the claims.
- the start position is also the position where mutual authentication is performed between the terminal device 10 and the server 20.
- the BLE beacon 40 is assumed to be installed in advance at an appropriate position, with radio wave strength and other characteristics adjusted to suit the characteristics of the BLE beacon 40 or the terminal device 10, so that the terminal device 10 can receive the trigger signal at the start position.
- the BLE beacon 40 is an example of a signal emitting terminal that emits a trigger signal.
- One or more BLE beacons 40 may be installed.
- anchors 30 are installed in advance to obtain distance measurement results to be used for positioning.
- the anchors 30 continuously transmit distance measurement results between the anchor 30 and the terminal device 10 to the terminal device 10 and the server 20 at predetermined time intervals.
- the installation positions of the anchors in Figure 1 are merely an example, and the present technology is not limited to the positions of the anchors 30.
- the anchors 30 may be installed in any position as long as they can perform UWB communication with the terminal device 10 and obtain distance measurement results.
- the anchor 30 for transmitting the ranging results used for positioning in the secure positioning area to the server 20 is preferably installed near the processing terminal 50 or configured integrally with the processing terminal 50, such as by being installed on the processing terminal 50's circuit board.
- Other anchors 30 for positioning in the non-secure positioning area may be installed anywhere in space as long as they are capable of UWB communication with the terminal device 10.
- anchors 30 for obtaining ranging results used for positioning in the secure positioning area may also be installed at a location away from the processing terminal 50.
- a common anchor 30 may transmit ranging results for positioning in the non-secure positioning area and positioning in the secure positioning area to the terminal device 10 and the server 20.
- the terminal device 10 must pass through the start position when entering the non-secure positioning area. Furthermore, the terminal device 10 must pass through the non-secure positioning area before entering the secure positioning area. Then, within the secure positioning area, predetermined processing such as payment is performed between the terminal device 10 and the processing terminal 50, etc. Therefore, within a space such as a facility in which the information processing system 100 of the first embodiment is used, the non-secure positioning area must be set so that a user having the terminal device 10 must pass through it before entering the secure positioning area. Furthermore, a flow line must be set so that a user having the terminal device 10, etc., moves through the start position, non-secure positioning area, and secure positioning area in that order. For example, the non-secure positioning area can be set on the route that the user will pass through to get to the processing terminal 50.
- the start position is set, for example, to be the entrance to the facility.
- the secure positioning area is set as the area surrounding the processing terminal 50 and including the processing terminal 50 within.
- the non-secure positioning area is set in an aisle or other area within the facility other than the area surrounding the processing terminal 50, so as to be located between the start position and the secure positioning area.
- this is merely an example, and the start position and non-secure positioning area may be set anywhere within the space.
- the server 20 performs secure positioning of an unspecified number of terminal devices 10 without knowing the number of terminal devices 10 near the processing terminal 50, the processing and communication load will increase, posing a problem in terms of the availability of the information processing system 100 and the server 20. Therefore, a secure positioning area around the processing terminal 50 and a non-secure positioning area through which the terminal devices 10 pass before entering the secure positioning area are set, and the location of the terminal devices 10 is identified by positioning the terminal devices 10 in the non-secure positioning area, and terminal devices 10 entering the secure positioning area are identified, and only those terminal devices 10 are positioned in the secure positioning area. This limits the terminal devices 10 that are the subject of secure positioning in the secure positioning area, thereby improving the availability of the information processing system 100. Furthermore, the server 20 manages the positioning method by referring to the positioning results in the non-secure positioning area and switching depending on whether the terminal device 10 is in the non-secure positioning area or the secure positioning area.
- terminal device 10 uses the distance measurement results obtained from anchors 30 installed in space to determine its own position and transmits the positioning results to server 20.
- the positioning results obtained by terminal device 10 may be incorrect or may be tampered with, raising concerns about the reliability and security of the positioning results.
- the information processing system 100 includes a terminal device 10, a server 20, an anchor 30, and a BLE beacon 40.
- the terminal device 10 and the server 20 are connected to each other so that they can communicate via a network interface.
- the anchor 30 and the server 20 are also connected to each other so that they can communicate via a network interface.
- Communication methods include cellular communication, 4G, 5G, Wi-Fi, etc., but any method that enables communication is acceptable.
- the terminal device 10 and anchor 30 can communicate via UWB.
- UWB is a wireless communication technology that uses an ultra-wideband frequency bandwidth of 3.1 to 10.6 GHz, enabling highly accurate ranging and positioning with an error of approximately ⁇ 10 cm. While this differs by country, in Japan the low band is 3.4 to 4.8 GHz, and the high band is 7.25 to 10.25 GHz.
- the communication range of UWB is approximately a 10 m radius, enabling high-speed communication with low power consumption. Specifications and detailed communication procedures are defined in standards such as IEEE 802.15.4 and IEEE 802.15.4z.
- the application processor 11 is composed of a CPU (Central Processing Unit), RAM (Random Access Memory), ROM (Read Only Memory), etc., and executes applications to perform various processes on the terminal device 10.
- CPU Central Processing Unit
- RAM Random Access Memory
- ROM Read Only Memory
- the application processor 11 When the terminal device 10 receives a trigger signal from a BLE beacon 40, the application processor 11 starts a UWB positioning application, an authentication processing application, etc.
- the application processor 11 executes a UWB positioning application, configures the UWB communication unit 13 using UWB positioning setting values, notifies the secure element 12 of the start of positioning, notifies the server 20 of the start of positioning, and performs positioning processing using the Downlink TDoA method within the non-secure positioning area.
- the application processor 11 also executes an authentication processing application and performs mutual authentication with the server 20.
- the application processor 11 also performs processing to attach a signature based on mutual authentication to the positioning results and transmit them.
- the application processor 11 executes predetermined processing applications such as payment, and performs predetermined processing with the processing terminal 50.
- the secure element 12 stores positioning information such as a UWB session key and other setting values required for UWB communication, and upon receiving a positioning start notification from the application processor 11, supplies the positioning information to the UWB communication unit 13.
- the UWB communication unit 13 is composed of a UWB wireless communication module and transmits and receives radio waves for ranging with the anchor 30 via UWB communication.
- the BLE communication unit 14 is a BLE communication device that receives a trigger signal transmitted from a BLE beacon 40. Upon receiving the trigger signal, the BLE communication unit 14 notifies the application processor 11.
- the terminal device 10 may also be equipped with input units such as a mouse, keyboard, or touch panel that the user uses to input various instructions, as well as a display that displays a GUI (Graphical User Interface) and content, etc.
- input units such as a mouse, keyboard, or touch panel that the user uses to input various instructions
- display that displays a GUI (Graphical User Interface) and content, etc.
- the terminal device 10 may be configured as an electronic device such as a smartphone, smartwatch, tablet, or wearable device.
- the terminal device 10 may also be a dedicated terminal for various systems to which the present technology is applied, such as a dedicated touchless payment terminal, a touchless ticket gate terminal, an entrance/exit system terminal, or a smart key terminal.
- Server 20 is an example of an information processing device within the scope of the claims.
- the application processor 21 is composed of a CPU, RAM, ROM, etc., and executes applications to perform various processes on the server 20.
- the application processor 21 also executes a UWB positioning application and performs secure positioning of the terminal device 10 in the secure positioning area using the UWB positioning function defined by the FiRa (registered trademark) specifications.
- the UWB positioning application performs secure positioning of the terminal device 10 in the secure positioning area based on the distance measurement results transmitted from multiple anchors 30 and the terminal device 10. Note that mutual authentication between the terminal device 10 and the server 20 has already been performed at the start position, so mutual authentication between the terminal device 10 and the server 20 is not required in the secure positioning area.
- the application processor 21 also executes an authentication application and performs mutual authentication processing with the terminal device 10. It also verifies the signature attached to the positioning result sent from the terminal device 10. It also performs processing to send a negotiation value for positioning to the terminal device 10.
- the application processor 21 is an example of a positioning processing unit and an authentication processing unit.
- the secure element 22 holds the UWB session key for the anchor and other setting values, and supplies them to the application processor 21.
- the anchor 30 receives positioning information such as the UWB session key, UWB positioning settings, and other settings sent from the server 20.
- the application processor 31 is composed of a CPU, RAM, ROM, etc., and executes applications to perform various processes in the anchor 30.
- the application processor 31 executes a UWB positioning application, configures the UWB communication unit 33 using UWB positioning settings, and transmits the distance measurement results used by the server 20 for Uplink TDoA to the server 20 via the network.
- the application processor 31 also sends a decryption trigger notification to the encryption processing unit 32.
- the encryption processing unit 32 decrypts positioning information, such as the UWB session key, UWB positioning setting values, and other setting values, sent in encrypted form from the server 20, and supplies the decrypted information to the UWB communication unit 33.
- positioning information such as the UWB session key, UWB positioning setting values, and other setting values
- the UWB communication unit 33 is composed of a UWB wireless communication module and transmits and receives radio waves for distance measurement with the terminal device 10 via UWB communication.
- the anchors 30 may be installed as common anchors for both the non-secure positioning area and the secure positioning area, or they may be installed separately as anchors for the non-secure positioning area and anchors for the secure positioning area.
- the various applications that run on the terminal device 10 may be pre-installed on the terminal device 10, or may be distributed by download or storage media, etc., and installed by the user who owns the terminal device 10. Furthermore, the various applications that run on the server 20 and anchor 30 may be pre-installed on them, or may be distributed by download or storage media, etc., and installed by the user of the information processing system 100, etc.
- Figure 3 illustrates only the non-secure positioning area, one secure positioning area, the terminal device 10 moving through these areas, the anchor 30 in the secure positioning area, and the processing terminal 50.
- the processing in the terminal device 10 will be described with reference to Figure 4.
- step S101 as shown in FIG. 3A, when the terminal device 10 reaches the start position and receives a trigger signal transmitted from the BLE beacon 40, the process proceeds to step S102 (Yes in step S101).
- step S102 the terminal device 10, which has received a trigger signal from the BLE beacon 40 at the start position, performs mutual authentication with the server 20 for secure UWB ranging.
- This mutual authentication is performed using a common key authentication method, an asymmetric key authentication method, or the like, in accordance with the method specified in the FiRa (registered trademark) specifications.
- FiRa registered trademark
- the terminal device 10 passes through the starting position and enters the non-secure positioning area as shown in Figure 3B, and in step S103 performs positioning of the terminal device 10 using the Downlink TDoA method.
- the terminal device 10 performs calculations using ranging results periodically transmitted from multiple anchors 30 to perform positioning.
- step S104 the terminal device 10 transmits the positioning results to the server 20, accompanied by a signature based on the results of the mutual authentication performed at the start position.
- the timing at which the terminal device 10 performs positioning and transmits the positioning results may be the timing at which the anchor 30 transmits the ranging results every few tens of milliseconds, or may be a timing preset in the UWB positioning application, or may be a timing dynamically specified by the server 20.
- the terminal device 10 passes through the boundary between the non-secure positioning area and the secure positioning area as shown in Figure 3C, and moves to the secure positioning area as shown in Figure 3D, performing positioning in the non-secure positioning area and transmitting the positioning results to the server 20 until the terminal device 10 transitions to processing in the secure positioning area (No in step S105).
- the terminal device 10 does not need to transmit ranging results to the server 20 in the secure positioning area. However, if a new secure ranging method is defined in the FiRa (registered trademark) specifications in the future, it may become necessary for the terminal device 10 to transmit ranging results or positioning results to the server 20.
- FiRa registered trademark
- step S201 the server 20 performs mutual authentication with the terminal device 10 that received the trigger signal transmitted from the BLE beacon 40 at the start position as shown in FIG. 3A.
- step S202 the server 20 receives the positioning result transmitted from the terminal device 10.
- This positioning result is the positioning result obtained by the terminal device 10 using the Downlink TDoA method in the non-secure positioning area, as shown in Figure 3B.
- a signature is affixed to this positioning result by the terminal device 10.
- step S203 the server 20 verifies the signature attached to the positioning result sent from the terminal device 10 and references the positioning result.
- step S204 when the server 20 detects that the terminal device 10 has entered the secure positioning area based on the positioning result transmitted from the terminal device 10, processing proceeds to step S205 (Yes in step S204).
- the server 20 detects, based on the positioning results in the non-secure positioning area transmitted from the terminal device 10, that the terminal device 10 has reached the edge of the non-secure positioning area, i.e., the boundary between the non-secure positioning area and the secure positioning area, as shown in Figure 3C, the server 20 can determine that the terminal device 10 has entered the secure positioning area.
- step S205 the server 20 transitions to processing in the secure positioning area.
- the server 20 notifies the terminal device 10 to switch the positioning method (such as sending various data to switch the terminal device's operating mode).
- step S206 the server 20 performs positioning of the terminal device 10 in the secure positioning area, as shown in Figure 3D, based on multiple ranging results from secure ranging defined by the UWB specifications. Note that, because mutual authentication between the terminal device 10 and the server 20 has already been performed at the starting position, mutual authentication between the terminal device 10 and the server 20 is not required in the secure positioning area.
- the server 20 performs positioning of the terminal device 10 in a non-secure positioning area before performing secure positioning in a secure positioning area, thereby making it possible to identify the terminal device 10 that will enter the secure positioning area.
- the secure positioning area is set as an area that includes a processing terminal 50 that performs processing such as payment, the processing terminal 50 is not required.
- the secure positioning area is set to include that specified position.
- This technology can be applied to systems in which a terminal device 10 communicates with a processing terminal 50 located within a secure positioning area to perform various processes, such as touchless payment systems, touchless ticket gate systems, entrance/exit management systems, and smart key systems.
- the non-secure positioning area and secure positioning area are set as areas in a local coordinate system.
- the local coordinate positioning results are converted to absolute coordinates based on map information after the terminal device 10 and server 20 complete the positioning process and immediately before displaying the positioning results on the GUI.
- the positioning results are stored in a database or when the trajectory of the terminal device 10's movement, which can be determined from multiple positioning results stored in the database, is analyzed, information that can convert the local coordinate non-secure positioning area and secure positioning area into absolute coordinates is stored in the database.
- the map information includes information such as the absolute coordinates of the non-secure positioning area, the absolute coordinates of the secure positioning area, and the absolute coordinates of the anchor 30.
- the map information may be included in an application running on the terminal device 10 in advance, or the server 20 may transmit the map information to the terminal device 10 upon receiving a notification that the terminal device 10 has received a trigger signal from a BLE beacon 40.
- multiple non-secure positioning areas namely, a first non-secure positioning area and a second non-secure positioning area, are set in space.
- the positioning method is switched depending on whether the terminal device 10 is located in the first non-secure positioning area, the second non-secure positioning area, or the secure positioning area.
- the secure positioning area is the same as in the first embodiment, and positioning in the secure positioning area is performed using the UWB secure positioning function defined by the FiRa (registered trademark) specifications. Note that while three secure positioning areas are set in Figure 6, the number of secure positioning areas is not limited to three and may be more or less than three.
- the first non-secure positioning area is set adjacent to the second non-secure positioning area, and is the area in which the terminal device 10 performs positioning.
- the terminal device 10 performs positioning using the Downlink TDoA method, using the distance measurement results between each anchor 30 and the terminal device 10 transmitted from multiple anchors 30 installed in space.
- the first non-secure positioning area is the same as the non-secure positioning area in the first embodiment.
- a start position is set within the first non-secure positioning area.
- the start position is the same as that in the first embodiment, and is the position where the terminal device 10 receives a trigger signal transmitted from the BLE beacon 40 and starts positioning using the Downlink TDoA method.
- the start position is set so that it is located at the end of the first non-secure positioning area opposite the side where the secure positioning area exists.
- the start position is also the position where mutual authentication is performed between the terminal device 10 and the server 20.
- the second non-secure positioning area is set between the first non-secure positioning area and the secure positioning area, adjacent to the first non-secure positioning area and the secure positioning area, and is an area in which the server 20 performs positioning of the terminal device 10.
- the server 20 performs positioning using the Uplink TDoA method using the ranging results between each anchor 30 and the terminal device 10 transmitted from multiple anchors 30 installed in space and the terminal device 10.
- There are no particular restrictions on the size of the second non-secure positioning area and it can be any size as long as it is possible to communicate with the anchors 30 via UWB and receive ranging results.
- the second non-secure positioning area corresponds to the third area in the claims.
- multiple anchors 30 for positioning and ranging are installed in advance within the space in which the first non-secure positioning area, second non-secure positioning area, and secure positioning area are set.
- the first non-secure positioning area, second non-secure positioning area, and secure positioning area are set as areas in a local coordinate system based on the position of the processing terminal 50, the position of the anchors 30, other positions, etc.
- the terminal device 10 must pass through the start position when entering the first non-secure positioning area. Furthermore, the terminal device 10 must pass through the first non-secure positioning area before entering the second secure positioning area. Furthermore, the terminal device 10 must pass through the second non-secure positioning area before entering the secure positioning area. Then, within the secure positioning area, predetermined processing such as payment is performed between the terminal device 10 and the processing terminal 50. Therefore, within a space such as a facility in which the information processing system 100 of the second embodiment is used, it is necessary to set a flow line that allows a user with a terminal device 10 to move through the start position, first non-secure positioning area, second non-secure positioning area, and secure positioning area in that order.
- the server 20 references the positioning results in the first non-secure positioning area and the second non-secure positioning area, and manages to switch the positioning method depending on whether the terminal device 10 is located in the first non-secure positioning area, the second non-secure positioning area, or the secure positioning area.
- the terminal device 10 uses the distance measurement results obtained by the anchor 30 to determine its own position and transmits the positioning results to the server 20.
- the positioning results may be incorrect or may be tampered with, raising concerns about the reliability and security of the positioning results.
- a second non-secure positioning area is set, and the positioning results in the first non-secure positioning area performed by the terminal device 10 are confirmed with the positioning results in the second non-secure positioning area performed by the server 20, thereby improving the reliability and security of the positioning results.
- the application processor 21 of the server 20 executes a UWB positioning application to perform uplink TDoA positioning, which calculates the position of the terminal device 10 using the ranging results transmitted from the terminal device 10 and the anchor 30.
- the application processor 21 also executes a comparison processing application to compare the positioning results obtained by the terminal device 10 using the downlink TDoA method with the positioning results obtained by the server 20 using the uplink TDoA method.
- the application processor 21 is an example of a comparison processing unit.
- Fig. 7 illustrates only the first non-secure positioning area, the second non-secure positioning area, one secure positioning area, the terminal device 10 moving in these areas, the anchor 30 in the secure positioning area, and the processing terminal 50.
- step S101 as shown in FIG. 7A, when the terminal device 10 receives a trigger signal transmitted from a BLE beacon 40 at the start position, mutual authentication is performed with the server 20 in step S102.
- step S121 the terminal device 10, which has entered the first non-secure positioning area, uses the ranging results transmitted from the anchor 30 to perform positioning of the terminal device 10 itself in the first non-secure positioning area using the Downlink TDoA method.
- step S122 the terminal device 10 transmits the positioning results to the server 20, accompanied by a signature based on the results of the mutual authentication performed at the start position.
- the terminal device 10 moves to the second non-secure positioning area and performs positioning in the first non-secure positioning area and transmits the positioning results to the server 20 until the server 20 transitions the processing of the information processing system 100 to processing in the second non-secure positioning area (No in step S123).
- step S124 (Yes in step S123).
- step S124 the terminal device 10 transmits the distance measurement results in the second non-secure positioning area to the server 20 for positioning by the server 20.
- the server 20 performs positioning using the Uplink TDoA method, so the terminal device 10 transmits the distance measurement results to the server 20 instead of the positioning results.
- the terminal device 10 attaches a signature to the distance measurement results based on the results of mutual authentication performed at the start position.
- the terminal device 10 moves to the secure positioning region and transmits the distance measurement results in the second non-secure positioning region to the server 20 until the server 20 transitions the processing of the information processing system 100 to processing in the secure positioning region (No in step S125).
- step S125 When the terminal device 10 moves to the secure positioning area and the server 20 transitions the processing of the information processing system 100 to processing in the secure positioning area, the processing ends (Yes in step S125).
- step S201 the server 20 performs mutual authentication with the terminal device 10 that received the trigger signal transmitted from the BLE beacon 40 at the start position as shown in FIG. 9A.
- step S203 the server 20 verifies the signature attached to the positioning result sent from the terminal device 10 and references the positioning result.
- the server 20 determines the location of the terminal device 10 based on the positioning results transmitted from the terminal device 10, and receives and references the positioning results transmitted from the terminal device 10 in steps S202 and S203 until the terminal device 10 reaches the edge of the first non-secure positioning area, i.e., the boundary between the first non-secure positioning area and the second non-secure positioning area (No in step S221).
- step S222 when the terminal device 10 reaches the edge of the first non-secure positioning area (the boundary between the first non-secure positioning area and the second non-secure positioning area), processing proceeds to step S222 (Yes in step S221).
- step S223 the server 20 compares and confirms the positioning result obtained by the terminal device 10 using the Downlink TDoA method at the edge of the first non-secure positioning area (the boundary between the first non-secure positioning area and the second non-secure positioning area) with the positioning result obtained by the server 20 using the Uplink TDoA method at the edge of the first non-secure positioning area (the boundary between the first non-secure positioning area and the second non-secure positioning area).
- the server 20 may abort the positioning process, or may store the result of no match in the server 20 and continue the positioning process.
- a match between the positioning results includes not only a perfect match, but also a match within a specified range of approximation, and the match determination algorithm can be implemented using general filter processing, etc.
- the server 20 can determine that the terminal device 10 has entered the second non-secure positioning area.
- the server 20 then transitions to processing in the second non-secure positioning area in step S224.
- the server 20 notifies the terminal device 10 to switch the positioning method (such as sending various data to switch the operating mode of the terminal device).
- step S225 the server 20 uses the ranging results transmitted from the terminal device 10 and multiple anchors 30 to perform positioning of the terminal device 10 in the second non-secure positioning area using the Uplink TDoA method, as shown in Figure 7D.
- the server 20 performs calculations using the ranging results periodically transmitted from the terminal device 10 and anchors 30 to perform positioning.
- the server 20 verifies the signature attached to the ranging results transmitted from the terminal device 10 and uses the ranging results.
- a user holding the terminal device 10 may move back and forth between the first non-secure positioning area and the second non-secure positioning area. If the terminal device 10 returns from the second non-secure positioning area to the first non-secure positioning area and then reaches the boundary between the first and second non-secure positioning areas, steps S221 to S225 are performed again.
- the server 20 performs positioning of the terminal device 10 using the Uplink TDoA method until the terminal device 10 enters the secure positioning area from the second non-secure positioning area (No in step S226).
- step S227 processing proceeds to step S227 (Yes in step S226).
- step S227 the server 20 performs positioning of the terminal device 10 within the secure positioning area, as shown in Figure 7E, based on multiple ranging results obtained by secure ranging as defined by the UWB specifications. Note that, because mutual authentication between the terminal device 10 and the server 20 has already been performed at the start position, mutual authentication between the terminal device 10 and the server 20 is not required in the secure positioning area.
- processing in the second embodiment is performed.
- the positioning results of the Downlink TDoA method performed by the terminal device 10 in the first non-secure positioning area are confirmed with the positioning results of the Uplink TDoA method performed by the server 20 in the second non-secure positioning area. This makes it possible to improve the reliability and security of the positioning results obtained by the terminal device 10.
- mutual authentication between the terminal device 10 and the server 20 at the starting position is not required, as this can increase the reliability and security of the Downlink TDoA method positioning results performed by the terminal device 10. If mutual authentication is not performed, no signature is added to the positioning results and ranging results sent to the server 20. If mutual authentication is not performed at the starting position, mutual authentication between the terminal device 10 and the server 20 is performed in the secure positioning area using a method specified in the FiRa (registered trademark) specifications.
- the Downlink TDoA positioning results performed by the terminal device 10 may be confirmed with the Uplink TDOA positioning results performed by the server 20, and further mutual authentication and the addition of a signature to the positioning results as described in the first embodiment may be performed. Whether to perform mutual authentication and signing may be determined depending on the security level of the information processing system 100. By performing Uplink TDoA as well as mutual authentication and the addition of a signature to the positioning results, the reliability and security of the ranging results can be further improved.
- the terminal device 10 has been described as being owned by a human user, but the terminal device 10 may also be mounted on a mobile object such as a robot, drone, or automobile, and these mobile objects may have the functions of the terminal device 10.
- the secure positioning area and non-secure positioning area are set to be adjacent and not overlapping, but as shown in Figure 10, the non-secure positioning area may also be set to be enclosed within the secure positioning area.
- the terminal device 10 always passes through the non-secure positioning area before entering the secure positioning area, so positioning processing can be performed in the same way as in the embodiment.
- a start position can be set in both the secure area and the non-secure positioning area, and depending on the security level, it can be determined whether mutual authentication is performed only at the start position in the non-secure positioning area, or at the start positions of both the secure area and the non-secure positioning area.
- first non-secure positioning area and the second non-secure positioning area are set as separate areas rather than adjacent areas.
- mutual authentication is first performed at the start position of the first non-secure positioning area. Thereafter, mutual authentication may or may not be performed at the start position of the second non-secure positioning area. Since security can be increased by performing mutual authentication multiple times, whether or not to perform mutual authentication in the second non-secure positioning area may be determined depending on the security level.
- the non-secure positioning area and the secure positioning area may partially overlap. This also applies to the first non-secure positioning area and the second non-secure positioning area.
- the start position may be set outside the non-secure positioning area and adjacent to the non-secure positioning area. In this case, too, the start position must be a position that the terminal device 10 must pass through in order to enter the non-secure positioning area.
- the secure positioning area and non-secure positioning area are shown as elliptical, but they may also be polygonal, such as triangular or rectangular, or may be free-form.
- positioning using UWB may be performed using methods other than Downlink TDoA, such as Uplink TDoA or TWR (Two Way Ranging), or may be performed using methods other than UWB.
- the BLE beacon 40 is not necessary. In this case, when the terminal device 10 detects that it has reached the starting position through UWB positioning, preliminary mutual authentication and positioning begins. Also, a UWB-dedicated tag device may be used instead of the BLE beacon 40, or any signal-emitting terminal that emits a trigger signal may be used instead of the BLE beacon 40.
- Distance measurement between the BLE beacon 40 and the terminal device 10 can be performed by utilizing the principle that the strength of the received signal weakens as the distance from the BLE beacon 40 increases. Utilizing this, multiple BLE beacons 40 can be installed, and the terminal device 10 or server 20 that receives signals from the BLE beacons 40 can use the results of distance measurement between each BLE beacon 40 and the terminal device 10 to determine the position of the terminal device 10. This distance measurement and positioning using the BLE beacon 40 may be combined with distance measurement and positioning using an anchor 30.
- the BLE beacon 40 for distance measurement and positioning may be the same device as the beacon for transmitting a trigger signal, or a BLE beacon 40 for distance measurement and positioning may be installed in space separately from the BLE beacon 40 for transmitting a trigger signal.
- the present technology can also be configured as follows. (1) a positioning processing unit that performs positioning of a terminal device that has passed through the first area and then entered the second area; an authentication processing unit that performs mutual authentication between the terminal device and the information processing device when the terminal device reaches a predetermined position away from the second area before the terminal device enters the second area. (2) The information processing device according to (1), wherein the first area is set so that the terminal device must pass through it before entering the second area. (3) The information processing device according to (1) or (2), wherein the predetermined position is an edge position within the first area, or a position outside the first area near the first area. (4) The information processing device according to (3), wherein the predetermined position is a position through which the terminal device must pass in order to enter the first area.
- the information processing device performs the mutual authentication in response to a notification from the terminal device that has received a trigger signal from a signal transmission terminal at the predetermined position.
- the information processing device which receives a positioning result transmitted from the terminal device that performed positioning in the first area.
- the information processing device wherein the positioning of the terminal device in the first area is performed by a Downlink TDoA method using a ranging result transmitted from an anchor.
- the information processing device according to (6) or (7), wherein the positioning result transmitted from the terminal device is accompanied by a signature using a result of the mutual authentication.
- the information processing device according to any one of (10) to (12), further comprising a comparison processing unit that compares a positioning result by the terminal device with a positioning result by the positioning processing unit.
- a comparison processing unit that compares a positioning result by the terminal device with a positioning result by the positioning processing unit.
- the information processing device (14) The information processing device according to (13), wherein a result of positioning by the terminal device at a boundary between the first area and the third area is compared with a result of positioning by the positioning processing unit.
- the signal transmitting terminal is a BLE beacon.
- the system comprises a terminal device and an information processing device, a positioning processing unit that performs positioning of the terminal device; an authentication processing unit that performs mutual authentication with the information processing device; a terminal device comprising: a positioning processing unit that performs positioning of the terminal device 10 that has passed through the first area and then entered the second area; the information processing device including an authentication processing unit that performs mutual authentication between the terminal device and the information processing device when the terminal device reaches a predetermined position away from the second area before the terminal device enters the second area;
- An information processing system consisting of:
- Terminal device 11 Application processor 20: Server (information processing device) 21... Application processor 30... Anchor 40... BLE beacon 100... Information processing system
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Radar, Positioning & Navigation (AREA)
- Remote Sensing (AREA)
- Mobile Radio Communication Systems (AREA)
- Position Fixing By Use Of Radio Waves (AREA)
Abstract
本技術は、測位結果の信頼性とセキュリティを高めることができる情報処理装置を提供することを目的とする。 第1の技術は、第1の領域(ノンセキュア測位領域)を通過した後に第2の領域(セキュア測位領域)に入った端末装置(10)の測位を行う測位処理部と、端末装置(10)が第2の領域(セキュア測位領域)に入る前に、第2の領域(セキュア測位領域)から離れた所定の位置(開始位置)に到達した端末装置(10)との間で相互認証を行う認証処理部とを備える情報処理装置(サーバ20)である。
Description
本技術は、情報処理装置および情報処理システムに関する。
無線通信により複数の通信装置を接続して決済処理などを行う技術がある。その無線通信方式としてUWB(Ultra Wide Band)を用いた情報処理システムが提案されている(特許文献1)。
特許文献1の情報処理システムにおいてはDownlink TDoA(Time Difference Of Arrival)方式で端末装置の測位を行っている。しかし、Downlink TDoA方式の測位ではアンカーからの測距結果を用いて端末装置が自身の測位を行い、その即位結果をシステムのサーバなどに送信する。よって、端末装置が送信する測位結果が誤っている可能性や改ざんされる可能性などがあり、測位結果の信頼性とセキュリティについて懸念がある。
本技術はこのような点に鑑みなされたものであり、測位結果の信頼性とセキュリティを高めることができる情報処理装置および情報処理システムを提供することを目的とする。
上述した課題を解決するために、第1の技術は、第1の領域を通過した後に第2の領域に入った端末装置の測位を行う測位処理部と、端末装置が第2の領域に入る前に、第2の領域から離れた所定の位置に到達した端末装置との間で相互認証を行う認証処理部とを備える情報処理装置である。
第2の技術は、端末装置と情報処理装置とからなり、端末装置の測位を行う測位処理部と、情報処理装置との間で相互認証を行う認証処理部と、を備える端末装置と、第1の領域を通過した後に第2の領域に入った端末装置10の測位を行う測位処理部と、端末装置が第2の領域に入る前に、第2の領域から離れた所定の位置に到達した端末装置との間で相互認証を行う認証処理部とを備える情報処理装置とからなる情報処理システムである。
以下、本技術の実施形態について図面を参照しながら説明する。なお、説明は以下の順序で行う。
<第1の実施形態>
[測位領域の構成]
[情報処理システム100の構成]
[情報処理システム100における処理]
<第2の実施形態>
[測位領域の構成]
[情報処理システム100の構成]
[情報処理システム100における処理]
<変形例>
<第1の実施形態>
[測位領域の構成]
[情報処理システム100の構成]
[情報処理システム100における処理]
<第2の実施形態>
[測位領域の構成]
[情報処理システム100の構成]
[情報処理システム100における処理]
<変形例>
<第1の実施形態>
[測位領域の構成]
まず、図1を参照して第1の実施形態の情報処理システム100における測位領域について説明する。情報処理システム100では、端末装置10とサーバ20により、端末装置10の位置を測定する測位が行われる。
[測位領域の構成]
まず、図1を参照して第1の実施形態の情報処理システム100における測位領域について説明する。情報処理システム100では、端末装置10とサーバ20により、端末装置10の位置を測定する測位が行われる。
第1の実施形態では、情報処理システム100が適用される店舗や駅などの施設の空間内にセキュア測位領域とノンセキュア測位領域が設定されている。端末装置10がセキュア測位領域とノンセキュア測位領域のどちらに存在するかによってサーバ20は測位方式を切り替える。ノンセキュア測位領域は請求の範囲における第1の領域に相当するものであり、セキュア測位領域は第2の領域に相当するものである。
セキュア測位領域は、UWBに関する団体であるFiRa(登録商標)の仕様により定められているUWBの測位機能を用いて、サーバ20が端末装置10の位置を測位する領域である。この測位方法では、測位を実行する前に端末装置10とサーバ20間の相互認証を行うため、測位結果の信頼性とセキュリティが保証されている。セキュア測位領域における測位をセキュア測位と称する。サーバ20は、空間に設置された複数のアンカー30から送信された、各アンカー30と端末装置10間の測距結果を用いてセキュア測位により端末装置10の測位を行う。
また、セキュア測位領域は、端末装置10を有するユーザが利用する決済サービスなどの処理を行う処理端末50と端末装置10との間でデータ通信や各種の処理が行われる領域である。よって、セキュア測位領域は、例えば処理端末50の位置を基準とした半径数メートルの領域として設定される。
なお、図1においてはセキュア測位領域が三つ設定されているが、セキュア測位領域の数は三つに限られずそれ以上でもよいし、それ以下でもよい。
ノンセキュア測位領域は、セキュア測位領域に隣接して設定され、端末装置10が自身の位置を測位する領域である。端末装置10は、空間に設置された複数のアンカー30から送信された各アンカー30と端末装置10間の測距結果を用いてDownlink TDoA方式で端末装置10自身の測位を行う。なお、ノンセキュア測位領域の大きさには特に制限はなく、アンカー30とUWB通信して測距結果を得ることができればどのような大きさでもよい。セキュア測位領域とノンセキュア測位領域は、例えば、処理端末50の位置、アンカー30の位置、その他の位置などを基準とするローカル座標系の領域として設定される。
TDoAでは、異なる位置に設置された複数のアンカー30と端末装置10間で送受信される電波の到達時刻の時間差を光速を用いて距離に変換することでアンカー30と端末装置10間の測距結果を得ることができる。TDoAでは端末装置10と全てのアンカー30の時刻を同期させる必要がある。なお、本実施形態ではアンカー30が端末装置10に測距結果を送信しているが、時間差を測定してその時間差を距離に変換して測距結果を得る処理は端末装置10とアンカー30のどちらで行ってもよい。
ノンセキュア測位領域内には開始位置が設定されている。開始位置は、端末装置10がBLEビーコン40から送信されたトリガー信号を受信してDownlink TDoA方式による測位を開始する位置である。開始位置はノンセキュア測位領域内の端に位置するように設定する。図1の例では、開始位置はノンセキュア測位領域内のセキュア測位領域が存在する側とは逆側の端に設定されている。開始位置は請求の範囲における所定の位置に相当するものである。
開始位置は端末装置10とサーバ20との間で相互認証を実行する位置でもある。BLEビーコン40は、開始位置で端末装置10がトリガー信号を受信できるように、BLEビーコン40または端末装置10の特性に合わせて電波強度などを調整し、適切な位置に予め設置されているものとする。BLEビーコン40はトリガー信号を発信する信号発信端末の一例である。設置するBLEビーコン40は一つでも複数でもよい。
セキュア測位領域とノンセキュア測位領域が設定される空間内には予め、測位に用いる測距結果を得るための複数のアンカー30が設置されている。アンカー30の数に特に限定はない。アンカー30は、所定の時間間隔で継続してアンカー30と端末装置10間の測距結果を端末装置10とサーバ20に送信する。なお、図1におけるアンカーの設置位置はあくまで一例であり、このアンカー30の位置に本技術が限定されることはない。アンカー30は端末装置10とUWB通信を行い測距結果を得ることができればどのような位置に設置されていてもよい。
セキュア測位領域における測位に用いる測距結果をサーバ20に送信するためのアンカー30は処理端末50の近傍に設置しておくか、処理端末50の基板上に設けるなど処理端末50と一体に構成しておくのが好ましい。その他のノンセキュア測位領域における測位用のアンカー30は端末装置10とUWB通信可能であれば空間内のどこに設けてもよい。ただし、処理端末50から離れた位置にセキュア測位領域における測位に用いる測距結果を得るためのアンカー30を設置してもよい。また、必ずしもノンセキュア測位領域における測位用のアンカー30とセキュア測位領域における測位用のアンカー30とを分ける必要はなく、共通のアンカー30がノンセキュア測位領域における測位とセキュア測位領域における測位のための測距結果を端末装置10とサーバ20に送信するようにしてもよい。
第1の実施形態において、端末装置10は、ノンセキュア測位領域に入る際に必ず開始位置を通過する必要がある。また、端末装置10はセキュア測位領域に入る前に必ずノンセキュア測位領域を通過する必要がある。そして、セキュア測位領域内で端末装置10と処理端末50などの間で決済などの所定の処理が行われる。よって、第1の実施形態の情報処理システム100が利用される施設などの空間内においては、ノンセキュア測位領域は、端末装置10を有するユーザがセキュア測位領域に入る前に必ず通過するように設定する必要がある。また、端末装置10を有するユーザなどが、開始位置、ノンセキュア測位領域、セキュア測位領域の順で移動するような動線を設定する必要がある。例えば、処理端末50に向かうためにユーザが通過する経路にノンセキュア測位領域を設定するなどである。
本技術の情報処理システム100が店舗などの施設の空間内で利用される場合、例えば、施設の入口が開始位置になるように設定する。また、セキュア測位領域は処理端末50の周囲であり、処理端末50を内側に含む領域として設定する。ノンセキュア測位領域は開始位置とセキュア測位領域の間に介在するように施設内の処理端末50周囲以外の通路などにおいて設定する。ただしこれはあくまで一例であり、開始位置とノンセキュア測位領域は空間内のどこに設定してもよい。
処理端末50の近傍にある端末装置10の数がわからずにサーバ20が不特定多数の端末装置10のセキュア測位を行うと処理や通信の負荷が大きくなり、情報処理システム100とサーバ20の可用性の観点で問題がある。そこで、処理端末50の周囲におけるセキュア測位領域と、端末装置10がセキュア測位領域に入る前に通過するノンセキュア測位領域を設定して、ノンセキュア測位領域で端末装置10を測位することで端末装置10の位置を特定してセキュア測位領域に入る端末装置10を特定し、その端末装置10のみをセキュア測位領域で測位する。これにより、セキュア測位領域におけるセキュア測位の対象となる端末装置10が限定されて、情報処理システム100の可用性を高めることができる。また、サーバ20はノンセキュア測位領域における測位結果を参照して端末装置10がノンセキュア測位領域とセキュア測位領域のどちらに存在するかに応じて測位方法を切り替えるよう管理する。
ただし、ノンセキュア測位領域において端末装置10が行うDownlink TDoA方式の測位では空間に設置されたアンカー30で得られた測距結果を用いて端末装置10が自身の測位を行い、測位結果をサーバ20に送信する。よって、端末装置10による測位結果が誤っている可能性や改ざんされる可能性などがあり、測位結果の信頼性とセキュリティについて懸念がある。
そこで、第1の実施形態では、端末装置10とサーバ20間の相互認証を端末装置10がノンセキュア測位領域に入った時点で行うことで、ノンセキュア測位領域における測位結果の信頼性とセキュリティを高める。
[情報処理システム100の構成]
次に図2を参照して、情報処理システム100の構成について説明する。情報処理システム100は、端末装置10、サーバ20、アンカー30、BLEビーコン40を含んで構成されている。
次に図2を参照して、情報処理システム100の構成について説明する。情報処理システム100は、端末装置10、サーバ20、アンカー30、BLEビーコン40を含んで構成されている。
端末装置10とサーバ20はネットワークインターフェースを介して通信可能に接続されている。また、アンカー30とサーバ20もネットワークインターフェースを介して通信可能に接続されている。通信方法としてはセルラー通信、4G、5G、Wi-Fiなどがあるが、通信することができればどのような方法でもよい。
端末装置10とアンカー30はUWBにより通信可能である。UWBは、3.1~10.6GHzの超広帯域の周波数帯域幅を利用する無線通信であり、誤差±10cm程度の高精度な測距と測位が可能である。国により異なるが、日本ではローバンドとして3.4~4.8GHz、ハイバンドとして7.25~10.25GHzを利用している。UWBの通信範囲は半径約10m距離であり、省電力で高速な通信が可能である。仕様や詳細な通信手順などは、IEEE802.15.4、IEEE802.15.4z等で規定されている。
まず、端末装置10の構成について説明する。
アプリケーションプロセッサ11はCPU(Central Processing Unit)、RAM(Random Access Memory)およびROM(Read Only Memory)などから構成されており、アプリケーションを実行して端末装置10における各種の処理を行う。
アプリケーションプロセッサ11は、端末装置10がBLEビーコン40からトリガー信号を受信すると、UWB測位アプリケーション、認証処理アプリケーションなどを起動させる。
アプリケーションプロセッサ11はUWB測位アプリケーションを実行し、UWB測位の設定値によるUWB通信部13の設定、セキュアエレメント12に対する測位開始の通知、サーバ20に対する測位開始の通知、ノンセキュア測位領域内におけるDownlink TDoA方式による測位処理などを行う。また、アプリケーションプロセッサ11は、認証処理アプリケーションを実行し、サーバ20との間で相互認証を行う。また、アプリケーションプロセッサ11は、測位結果に相互認証に基づく署名を付けて送信する処理を行う。さらに、アプリケーションプロセッサ11は、決済などの所定の処理用アプリケーションを実行し、処理端末50との間で所定の処理を行う。
セキュアエレメント12はUWBセッション鍵やその他UWB通信に必要な設定値などの測位用情報を保持しており、アプリケーションプロセッサ11から測位開始の通知を受けるとその測位用情報をUWB通信部13に供給する。
UWB通信部13はUWB無線通信モジュールで構成されており、UWB通信によりアンカー30と測距のための電波の送受信を行う。
BLE通信部14は、BLEビーコン40から発信されているトリガー信号を受信するBLE通信デバイスである。BLE通信部14はトリガー信号を受信するとアプリケーションプロセッサ11に通知する。
その他、図示は省略するが、端末装置10はユーザが各種指示を入力する際に使用するマウス、キーボード、タッチパネルなどの入力部、GUI(Graphical User Interface)やコンテンツなどを表示するディスプレイなどを備えていてもよい。
端末装置10は、例えばスマートフォン、スマートウォッチ、タブレット端末、ウェアラブルデバイスなどの電子機器で構成することができる。また、端末装置10は、タッチレス決済専用端末、タッチレス改札用端末、入退室システム用端末、スマートキー用端末など本技術を適用する各種のシステムの専用端末でもよい。
次に、サーバ20の構成について説明する。サーバ20は請求の範囲における情報処理装置の一例である。
アプリケーションプロセッサ21はCPU、RAMおよびROMなどから構成されており、アプリケーションを実行してサーバ20における各種の処理を行う。
また、アプリケーションプロセッサ21はUWB測位アプリケーションを実行し、FiRa(登録商標)の仕様により定められているUWBの測位機能を用いて、セキュア測位領域においてセキュア測位により端末装置10の測位を行う。UWB測位アプリケーションは、複数のアンカー30および端末装置10から送信される測距結果に基づいてセキュア測位領域内における端末装置10の測位を行う。なお、開始位置で既に端末装置10とサーバ20間の相互認証を実行済みなので、セキュア測位領域では端末装置10とサーバ20間の相互認証は不要である。
また、アプリケーションプロセッサ21は、認証アプリケーションを実行し、端末装置10との相互認証処理を行う。また、端末装置10から送信された測位結果に付けられている署名の検証を行う。また、端末装置10に測位のためのネゴシエーション値を送信するよう処理を行う。アプリケーションプロセッサ21は測位処理部と認証処理部の一例である。
セキュアエレメント22は、アンカー向けUWBセッション鍵やその他の設定値を保持しており、それらをアプリケーションプロセッサ21に供給する。
次に、アンカー30の構成について説明する。
アンカー30は、サーバ20から送信された、UWBセッション鍵、UWB測位の設定値、その他の設定値などの測位用情報を受信する。
アプリケーションプロセッサ31はCPU、RAMおよびROMなどから構成されており、アプリケーションを実行してアンカー30における各種の処理を行う。
アプリケーションプロセッサ31は、UWB測位アプリケーションを実行し、UWB測位の設定値によるUWB通信部33の設定、サーバ20によるUplink TDoAに用いる測距結果をネットワークを介してサーバ20に送信する処理などを行う。また、アプリケーションプロセッサ31は、暗号処理部32に対する復号のトリガー通知を行う。
暗号処理部32は、暗号化された状態でサーバ20から送信されたUWBセッション鍵、UWB測位の設定値、その他の設定値などの測位用情報を復号してUWB通信部33に供給する。
UWB通信部33はUWB無線通信モジュールで構成されており、UWB通信により端末装置10と測距のための電波の送受信を行う。
なお、端末装置10とサーバ20が測位処理を行うためには複数のアンカー30から送信される測距結果が必要である。アンカー30は、ノンセキュア測位領域とセキュア測位領域の共通のアンカーとして設置してもよいし、ノンセキュア測位領域用アンカーとセキュア測位領域用アンカーを区別して設置してもよい。
端末装置10において動作する各種のアプリケーションは、予め端末装置10にインストールされていてもよいし、ダウンロード、記憶媒体などで配布されて、端末装置10を所有するユーザがインストールするようにしてもよい。また、サーバ20、アンカー30において動作する各種アプリケーションは、予めそれらにインストールされていてもよいし、ダウンロード、記憶媒体などで配布されて、情報処理システム100の使用者などがインストールするようにしてもよい。
[情報処理システム100における処理]
次に図3乃至図5を参照して情報処理システム100における処理について説明する。なお、図3においては説明の便宜上、ノンセキュア測位領域、一つのセキュア測位領域とそれらの領域を移動する端末装置10、セキュア測位領域内のアンカー30と処理端末50を抜き出して図示する。まず図4を参照して端末装置10における処理について説明する。
次に図3乃至図5を参照して情報処理システム100における処理について説明する。なお、図3においては説明の便宜上、ノンセキュア測位領域、一つのセキュア測位領域とそれらの領域を移動する端末装置10、セキュア測位領域内のアンカー30と処理端末50を抜き出して図示する。まず図4を参照して端末装置10における処理について説明する。
ステップS101で、図3Aに示すように端末装置10が開始位置に到達してBLEビーコン40から送信されたトリガー信号を受信すると処理はステップS102に進む(ステップS101のYes)。
開始位置でBLEビーコン40からのトリガー信号を受信した端末装置10は、ステップS102で、サーバ20とUWBのセキュア測距のための相互認証を行う。この相互認証はFiRa(登録商標)により仕様で定められている方式に応じて、共通鍵を用いた認証方法や、非対称鍵を用いた認証の認証方法などで行う。BLEビーコン40からのトリガー信号を受信した旨を端末装置10からサーバ20に通知することにより、その通知を端末装置10とサーバ20間の相互認証のトリガーとすることができる。
次に、開始位置を通過して図3Bに示すようにノンセキュア測位領域内に入った端末装置10は、ステップS103で、Downlink TDoA方式により端末装置10自身の測位を行う。Downlink TDoAでは複数のアンカー30から周期的に送信された測距結果を用いて端末装置10が演算を行うことで測位する。
次にステップS104で、端末装置10は開始位置において実行した相互認証の結果に基づく署名を付けた測位結果をサーバ20に送信する。端末装置10が測位と測位結果の送信を行うタイミングは、数十msecごとにアンカー30から測距結果が送信されるタイミングでもよいし、UWB測位アプリケーションにおいて予め設定されたタイミングでもよいし、サーバ20から動的に指定されたタイミングでもよい。
そして、端末装置10は、図3Cに示すようにノンセキュア測位領域とセキュア測位領域の境界を経て、図3Dに示すように端末装置10がセキュア測位領域に移動して、セキュア測位領域の処理に移行するまでノンセキュア測位領域における測位とサーバ20への測位結果の送信を行う(ステップS105のNo)。
なお、端末装置10は、セキュア測位領域で測距結果をサーバ20に送信する必要はない。ただし、FiRa(登録商標)の仕様で、今後、新たにセキュアレンジングの別方式が定義されたときには端末装置10からサーバ20に測距結果もしくは測位結果を送信することが必要になる場合がある。
次に図5を参照してサーバ20における処理について説明する。
ステップS201で、サーバ20は、図3Aに示すように開始位置でBLEビーコン40から送信されたトリガー信号を受信した端末装置10と相互認証を行う。
次にステップS202で、サーバ20は、端末装置10から送信された測位結果を受信する。この測位結果は、図3Bに示すようにノンセキュア測位領域において端末装置10が行ったDownlink TDoA方式による測位結果である。この測位結果には端末装置10により署名が付されている。
次にステップS203で、サーバ20は、端末装置10から送信された測位結果に付されている署名を検証して、その測位結果を参照する。
次にステップS204で、サーバ20が、端末装置10から送信された測位結果に基づいて端末装置10がセキュア測位領域に入ったことを検知すると、処理はステップS205に進む(ステップS204のYes)。
ノンセキュア測位領域とセキュア測位領域とが隣接している場合、端末装置10から送信されたノンセキュア測位領域における測位結果に基づき、図3Cに示すように端末装置10がノンセキュア測位領域の端、すなわちノンセキュア測位領域とセキュア測位領域の境界に到達したことを検知した場合、サーバ20は、端末装置10がセキュア測位領域に入ったと判定することができる。
端末装置10がセキュア測位領域に入ると、次にステップS205で、サーバ20はセキュア測位領域における処理に移行する。セキュア測位領域における処理に移行する際、サーバ20は、端末装置10に対して測位方法切り替えのための通知(端末装置の動作モードを切り替えるための各種データの送信など)を行う。
そしてステップS206で、サーバ20は、UWBの仕様により定められているセキュア測距による複数の測距結果に基づいて、図3Dに示すようにセキュア測位領域にある端末装置10の測位を行う。なお、開始位置で既に端末装置10とサーバ20間の相互認証を実行済みなので、セキュア測位領域では端末装置10とサーバ20間の相互認証は不要である。
このようにして第1の実施形態における処理が行われる。本実施形態によれば、サーバ20がセキュア測位を行うセキュア測位領域の前に、ノンセキュア測位領域で端末装置10の測位を行うことでセキュア測位領域に入る端末装置10を特定することができる。
そして、セキュア測距のための端末装置10とサーバ20間の相互認証を端末装置10がセキュア測位領域に入る前に開始位置で行い、端末装置10はDownlink TDoA方式の測位結果に相互認証に基づく署名を付けてサーバ20に送信する。これにより、UWBを用いた測位において測位結果の信頼性とセキュリティを高めることができる。
またUWBにおける相互認証を端末装置10がセキュア測位領域に入る前に行っておくことで、セキュア領域において相互認証を行う必要がないので、セキュア領域における処理を軽くし、セキュア領域における処理にかかる時間を短縮することができる。
なお、情報処理システム100においてセキュリティを考慮しない場合には、開始位置で相互認証を行っても測位結果に署名を付ける必要はない。
セキュア測位領域は決済などの処理を行う処理端末50を含む領域として設定すると説明したが、処理端末50は必須のものではない。例えば、端末装置10を有するユーザが店舗内の所定の位置を通過するだけで決済を行うことができるシステムにおいてはその所定の位置に含むようにセキュア測位領域を設定する。
本技術は、端末装置10とセキュア測位領域内に存在する処理端末50が通信して各種の処理を行うシステム、例えば、タッチレス決済システム、タッチレス改札システム、入退出管理システム、スマートキーシステムなどに適用することができる。
ノンセキュア測位領域とセキュア測位領域はローカル座標系の領域として設定されている。しかし、例えば、端末装置10が施設などの空間内のどこに存在するかを端末装置10のGUIなどで表示してユーザに提示するような場合は、端末装置10とサーバ20による測位処理が完了し、測位結果をGUIで表示する直前で、ローカル座標の測位結果を地図情報に基づいて絶対座標に変換する。また、測位結果をデータベースに保存するような場合や、そのデータベースに保存された複数の測位結果から把握できる端末装置10の移動の軌跡を分析するような場合は、そのデータベースにローカル座標のノンセキュア測位領域とセキュア測位領域を絶対座標に変換できる情報を一緒に保存する。地図情報は、ノンセキュア測位領域の絶対座標、セキュア測位領域の絶対座標、アンカー30の絶対座標などの情報を含むものである。その場合、予め端末装置10で動作するアプリケーションに地図情報を含めてもよいし、端末装置10がBLEビーコン40からのトリガー信号を受信したことの通知を受けたサーバ20が地図情報を端末装置10に送信してもよい。
<第2の実施形態>
[測位領域の構成]
次に第2の実施形態について説明する。
[測位領域の構成]
次に第2の実施形態について説明する。
第2の実施形態においては、図6に示すように、空間には第1ノンセキュア測位領域と第2ノンセキュア測位領域という複数のノンセキュア測位領域が設定されている。第2の実施形態では端末装置10が第1ノンセキュア測位領域、第2ノンセキュア測位領域、セキュア測位領域のどこにあるかによって測位方式が切り替えられる。
セキュア測位領域は第1の実施形態におけるものと同様であり、セキュア測位領域における測位は、FiRa(登録商標)の仕様により定められているUWBのセキュア測位機能を用いて行われる。なお、図6においてはセキュア測位領域が三つ設定されているが、セキュア測位領域の数は三つに限られずそれ以上でもよいし、それ以下でもよい。
第1ノンセキュア測位領域は第2ノンセキュア測位領域に隣接して設定され、端末装置10が測位を行う領域である。端末装置10は、空間に設置された複数のアンカー30から送信された、各アンカー30と端末装置10間の測距結果を用いてDownlink TDoA方式で測位を行う。第1ノンセキュア測位領域は第1の実施形態におけるノンセキュア測位領域と同様のものである。
第1ノンセキュア測位領域内には開始位置が設定されている。開始位置は第1の実施形態におけるものと同様のものであり、端末装置10がBLEビーコン40から送信されたトリガー信号を受信してDownlink TDoA方式による測位を開始する位置である。開始位置は第1ノンセキュア測位領域のセキュア測位領域が存在する側とは逆側の端に位置するように設定する。また、開始位置は端末装置10とサーバ20との間で相互認証を実行する位置でもある。
第2ノンセキュア測位領域は、第1ノンセキュア測位領域とセキュア測位領域の間において、第1ノンセキュア測位領域とセキュア測位領域に隣接するように設定され、サーバ20が端末装置10の測位を行う領域である。サーバ20は、空間に設置された複数のアンカー30と端末装置10から送信された、各アンカー30と端末装置10間の測距結果を用いてUplink TDoA方式で測位を行う。なお、第2ノンセキュア測位領域の大きさには特に制限はなく、アンカー30とUWB通信して測距結果を受信できればどのような大きさでもよい。第2ノンセキュア測位領域は請求の範囲における第3の領域に相当するものである。
第1の実施形態と同様に、第1ノンセキュア測位領域と第2ノンセキュア測位領域とセキュア測位領域が設定される空間内には予め、測位および測距用の複数のアンカー30が設置されている。アンカー30の数に特に限定はない。第1ノンセキュア測位領域、第2ノンセキュア測位領域、セキュア測位領域は、処理端末50の位置、アンカー30の位置、その他の位置などを基準とするローカル座標系の領域として設定される。
第2の実施形態において、端末装置10は第1ノンセキュア測位領域に入る際に必ず開始位置を通過する必要がある。また、端末装置10は第2セキュア測位領域に入る前に必ず第1ノンセキュア測位領域を通過する必要がある。さらに、端末装置10はセキュア測位領域に入る前に必ず第2ノンセキュア測位領域を通過する必要がある。そして、セキュア測位領域内で端末装置10と処理端末50の間で決済などの所定の処理が行われる。よって、第2の実施形態の情報処理システム100が利用される施設などの空間内においては、端末装置10を有するユーザなどが、開始位置、第1ノンセキュア測位領域、第2ノンセキュア測位領域、セキュア測位領域の順で移動するような動線を設定する必要がある。
端末装置10がセキュア測位領域に入る前に、第1ノンセキュア測位領域と第2ノンセキュア測位領域で測位を行うことでセキュア測位領域に入る端末装置10を特定することができる。サーバ20は第1ノンセキュア測位領域と第2ノンセキュア測位領域における測位結果を参照して、端末装置10が第1ノンセキュア測位領域、第2ノンセキュア測位領域、セキュア測位領域のどこに存在するかに応じて測位方法を切り替えるよう管理する。
ただし、第1ノンセキュア測位領域において端末装置10が行うDownlink TDoA方式の測位では、アンカー30によって得られた測距結果を用いて端末装置10が自身の測位を行い、測位結果をサーバ20に送信する。よって、その測位結果が誤っている可能性や改ざんされる可能性などがあり、測位結果の信頼性とセキュリティについて懸念がある。
そこで第2の実施形態では、第2ノンセキュア測位領域を設定し、サーバ20が行う第2ノンセキュア測位領域における測位結果で端末装置10が行う第1ノンセキュア測位領域における測位結果を確認することで測位結果の信頼性とセキュリティを高める。
[情報処理システム100の構成]
第2の実施形態における情報処理システム100、端末装置10、サーバ20、アンカー30、BLEビーコン40の構成は第1の実施形態と同様である。
第2の実施形態における情報処理システム100、端末装置10、サーバ20、アンカー30、BLEビーコン40の構成は第1の実施形態と同様である。
サーバ20のアプリケーションプロセッサ21は、UWB測位アプリケーションを実行して、端末装置10とアンカー30から送信された測距結果を用いて端末装置10の位置を算出するUplink TDoA方式の測位を行う。また、アプリケーションプロセッサ21は、比較処理アプリケーションを実行して端末装置10によるDownlink TDoA方式による測位結果とサーバ20によるUplink TDoA方式による測位結果とを比較する。アプリケーションプロセッサ21は比較処理部の一例である。
[情報処理システム100における処理]
次に図7乃至図9を参照して情報処理システム100における処理について説明する。なお、図7においては説明の便宜上、第1ノンセキュア測位領域、第2ノンセキュア測位領域、一つのセキュア測位領域とそれらの領域を移動する端末装置10、セキュア測位領域内のアンカー30と処理端末50を抜き出して図示する。
次に図7乃至図9を参照して情報処理システム100における処理について説明する。なお、図7においては説明の便宜上、第1ノンセキュア測位領域、第2ノンセキュア測位領域、一つのセキュア測位領域とそれらの領域を移動する端末装置10、セキュア測位領域内のアンカー30と処理端末50を抜き出して図示する。
まず図8を参照して端末装置10における処理について説明する。第1の実施形態と同じ処理は同じステップ番号を援用する。
ステップS101で、図7Aに示すように端末装置10は開始位置でBLEビーコン40から送信されるトリガー信号を受信すると、ステップS102でサーバ20と相互認証を行う。
次にステップS121で、図7Bに示すように第1ノンセキュア測位領域に入った端末装置10は、アンカー30から送信された測距結果を用いて第1ノンセキュア測位領域でDownlink TDoA方式により端末装置10自身の測位を行う。
次にステップS122で、端末装置10は開始位置において実行された相互認証の結果に基づく署名を付けた測位結果をサーバ20に送信する。
そして、端末装置10は、第2ノンセキュア測位領域に移動してサーバ20が情報処理システム100の処理を第2ノンセキュア測位領域の処理に移行させるまで第1ノンセキュア測位領域における測位とサーバ20への測位結果の送信を行う(ステップS123のNo)。
一方、端末装置10が第2ノンセキュア測位領域に移動して、サーバ20が情報処理システム100の処理を第2ノンセキュア測位領域の処理に移行させると、処理はステップS124に進む(ステップS123のYes)。
次にステップS124で、端末装置10は、サーバ20による測位のための第2ノンセキュア測位領域における測距結果をサーバ20に送信する。第2ノンセキュア測位領域ではサーバ20がUplink TDoA方式で測位を行うため、端末装置10は測位結果ではなく測距結果をサーバ20に送信する。この際、端末装置10は、開始位置において実行した相互認証の結果に基づく署名を測距結果に付ける。
そして、端末装置10は、セキュア測位領域に移動してサーバ20が情報処理システム100の処理をセキュア測位領域の処理に移行させるまで第2ノンセキュア測位領域における測距結果をサーバ20に送信する(ステップS125のNo)。
端末装置10がセキュア測位領域に移動して、サーバ20が情報処理システム100の処理をセキュア測位領域の処理に移行させた場合、処理は終了となる(ステップS125のYes)。
次に図9を参照してサーバ20における処理について説明する。第1の実施形態と同じ処理は同じステップ番号を援用する。
ステップS201で、サーバ20は、図9Aに示すように開始位置でBLEビーコン40から送信されるトリガー信号を受信した端末装置10と相互認証を行う。
次にステップS202で、サーバ20は、端末装置10から送信された、図7Bに示すようにノンセキュア測位領域内にある端末装置10が行ったDownlink TDoA方式による測位結果を受信する。この測位結果には端末装置10により署名が付されている。
次にステップS203で、サーバ20は、端末装置10から送信された測位結果に付されている署名を検証してその測位結果を参照する。
そして、サーバ20は、端末装置10から送信された測位結果に基づき、端末装置10の位置を特定し、端末装置10が第1ノンセキュア測位領域の端、すなわち第1ノンセキュア測位領域と第2ノンセキュア測位領域の境界に到達するまでステップS202とステップS203で端末装置10から送信された測位結果を受信して参照する(ステップS221のNo)。
図7Cに示すように端末装置10が第1ノンセキュア測位領域の端(第1ノンセキュア測位領域と第2ノンセキュア測位領域の境界)に到達すると、処理はステップS222に進む(ステップS221のYes)。
次にステップS222で、サーバ20は、アンカー30および端末装置10から送信された測距結果を用いてUplink TDoA方式により第1ノンセキュア測位領域の端(第1ノンセキュア測位領域と第2ノンセキュア測位領域の境界)における端末装置10の測位を行う。この際、サーバ20は端末装置10から送信された測距結果に付された署名を検証して、その測距結果を利用する。
次にステップS223で、サーバ20は、端末装置10が第1ノンセキュア測位領域の端(第1ノンセキュア測位領域と第2ノンセキュア測位領域の境界)で行ったDownlink TDoA方式による測位結果と、サーバ20が第1ノンセキュア測位領域の端(第1ノンセキュア測位領域と第2ノンセキュア測位領域の境界)で行ったUplink TDoA方式による測位結果を比較して確認する。
端末装置10による測位結果とサーバ20による測位結果とが一致しない場合、サーバ20は測位処理を中止してもよいし、一致しないという結果をサーバ20に保存して測位処理を続けてもよい。なお、測位結果の一致とは完全一致のほか、所定の近似の範囲内である場合も含み、その一致判定アルゴリズムは一般的なフィルター処理などを用いて実現できる。
第1ノンセキュア測位領域と第2ノンセキュア測位領域とが隣接している場合、測位結果により、図7Cに示すように端末装置10が第1ノンセキュア測位領域と第2ノンセキュア測位領域の境界に到達したことをサーバ20が検知した場合、サーバ20は、端末装置10が第2ノンセキュア測位領域に入ったと判定することができる。端末装置10が第2ノンセキュア測位領域に入ると、次にステップS224で、サーバ20は第2ノンセキュア測位領域における処理に移行する。第2ノンセキュア測位領域における処理に移行する際、サーバ20は、端末装置10に対して測位方法切り替えのための通知(端末装置の動作モードを切り替えるための各種データの送信など)を行う。
次にステップS225で、サーバ20は、端末装置10と複数のアンカー30から送信された測距結果を用いて、図7Dに示すように第2ノンセキュア測位領域にある端末装置10の測位をUplink TDoA方式で行う。Uplink TDoA方式では端末装置10とアンカー30から周期的に送信された測距結果を用いてサーバ20が演算を行うことで測位する。この際、サーバ20は端末装置10から送信された測距結果に付された署名を検証して、その測距結果を利用する。
なお、端末装置10を保持するユーザは、第1ノンセキュア測位領域と第2ノンセキュア測位領域間を行き来してしまう場合もある。端末装置10が第2ノンセキュア測位領域から第1ノンセキュア測位領域に戻り、再び端末装置10が第1ノンセキュア測位領域と第2ノンセキュア測位領域の境界に到達した場合には再びステップS221~ステップS225を行う。
サーバ20は、端末装置10が第2ノンセキュア測位領域からセキュア測位領域に入るまでUplink TDoA方式で端末装置10の測位を行う(ステップS226のNo)。
一方、サーバ20が測位結果に基づいて端末装置10がセキュア測位領域に入ったことを検知すると処理はステップS227に進む(ステップS226のYes)。
そして、ステップS227で、サーバ20は、UWBの仕様により定められているセキュア測距による複数の測距結果に基づいて、図7Eに示すようにセキュア測位領域内にある端末装置10の測位を行う。なお、開始位置で既に端末装置10とサーバ20間の相互認証を実行済みなので、セキュア測位領域では端末装置10とサーバ20間の相互認証は不要である。
このようにして第2の実施形態における処理が行われる。第2の実施形態では第1ノンセキュア測位領域において端末装置10が行うDownlink TDoA方式の測位結果を第2ノンセキュア測位領域においてサーバ20が行うUplink TDoA方式の測位結果で確認する。これにより、端末装置10による測位結果の信頼性とセキュリティを高めることができる。
第2の実施形態では、端末装置10が行うDownlink TDoA方式の測位結果の信頼性とセキュリティを高めることができるため、開始位置での端末装置10とサーバ20の相互認証は必須ではない。相互認証を行わない場合、サーバ20に送信する測位結果と測距結果に署名は付加されない。開始位置で相互認証を行わない場合、セキュア測位領域においてFiRa(登録商標)により仕様で定められている方式で端末装置10とサーバ20間の相互認証を行う。
ただし、端末装置10が行うDownlink TDoA方式の測位結果をサーバ20が行うUplink TDOAの測位結果で確認し、さらに、第1の実施形態で説明した相互認証および測位結果に対する署名の付加を行ってもよい。相互認証と署名を行うかは情報処理システム100におけるセキュリティのレベルに応じて決定するとよい。Uplink TDoAの実行に加えて、相互認証および測位結果に対する署名の付加を行うことにより、測距結果の信頼性とセキュリティをより高めることができる。
<変形例>
以上、本技術の実施形態について具体的に説明したが、本技術は上述の実施形態に限定されるものではなく、本技術の技術的思想に基づく各種の変形が可能である。
以上、本技術の実施形態について具体的に説明したが、本技術は上述の実施形態に限定されるものではなく、本技術の技術的思想に基づく各種の変形が可能である。
実施形態では端末装置10は人であるユーザが有するものとして説明を行ったが、端末装置10はロボット、ドローン、自動車などの移動体に搭載されているものでもよいし、それらの移動体が端末装置10の機能を備えていてもよい。
実施形態では、セキュア測位領域とノンセキュア測位領域は重ならず隣接しているように設定されているが、図10に示すようにノンセキュア測位領域をセキュア測位領域の内部に含んで囲うように設定してもよい。この場合も、端末装置10はノンセキュア測位領域を必ず通過してからセキュア測位領域に入るため、実施形態と同様に測位処理を行うことができる。
また、図11に示すように、セキュア測位領域とノンセキュア測位領域を隣接させずに離れた領域として設定することも可能である。その場合、セキュア領域とノンセキュア測位領域の両方に開始位置を設定し、セキュリティレベルに応じて、ノンセキュア測位領域における開始位置のみで相互認証を行うか、セキュア領域とノンセキュア測位領域の両方の開始位置で相互認証を行うかを決定してもよい。
また、図12に示すように、第1ノンセキュア測位領域と第2ノンセキュア測位領域を隣接させずに離れた領域として設定することも可能である。その場合、まず第1ノンセキュア測位領域の開始位置で相互認証を行う。さらに、その後、第2ノンセキュア測位領域の開始位置では相互認証を行ってもよいし、行わなくてもよい。相互認証を複数回行うことによりセキュリティを高めることができるので、セキュリティレベルに応じて第2ノンセキュア測位領域で相互認証を行うか否かを決定してもよい。複数の開始位置で相互認証を行うためには、それぞれの開始位置で端末装置10がBLEビーコン40からのトリガー信号を受信できるようにBLEビーコン40または端末装置10の特性に合わせて電波強度などを調整し、BLEビーコン40を適切な位置に予め設置する必要がある。
また、図13に示すように、ノンセキュア測位領域とセキュア測位領域は一部が重なっていてもよい。これは第1ノンセキュア測位領域と第2ノンセキュア測位領域についても同様である。
また、図14に示すように、開始位置はノンセキュア測位領域の外でノンセキュア測位領域に隣接するように設定してもよい。この場合も開始位置は端末装置10がノンセキュア測位領域に入るために必ず通過する位置である必要がある。
実施形態ではセキュア測位領域とノンセキュア測位領域は楕円形状のものとして示しているが、三角形状や四角形状などの多角形状でもよいし、自由形状でもよい。
ノンセキュア測位領域では、UWBを利用した測位ではDownlink TDoA以外のUplink TDoAやTWR(Two Way Ranging)などで測位してもよいし、UWB以外の方式で測位してもよい。
端末装置10のUWB通信機能を常時動作させてUWB測位を行っている状態であればBLEビーコン40は不要である。この場合、UWB測位により端末装置10が開始位置に到達した検知すると事前相互認証と測位を開始する。また、BLEビーコン40の代わりにUWB専用タグデバイスを用いてもよいし、トリガーとなる信号を発信する信号発信端末であればどのようなものをBLEビーコン40の代わりに用いてもよい。
BLEビーコン40からの距離が遠いほど受信する信号の強度が弱くなる原理を利用してBLEビーコン40と端末装置10間の測距を行うことができる。これを利用して、BLEビーコン40を複数設置し、BLEビーコン40からの信号を受信する端末装置10またはサーバ20において各BLEビーコン40と端末装置10間の測距結果を用いて端末装置10の測位を行うことができる。このBLEビーコン40を用いた測距および測位を、アンカー30を用いた測距および測位を組み合わせて用いてもよい。この測距および測位用のBLEビーコン40はトリガー信号発信のためのビーコンと同じデバイスでもよいし、トリガー信号発信のためのBLEビーコン40とは別に測距および測位用のBLEビーコン40を空間内に設置してもよい。
本技術は以下のような構成も取ることができる。
(1)
第1の領域を通過した後に第2の領域に入った端末装置の測位を行う測位処理部と、
前記端末装置が前記第2の領域に入る前に、前記第2の領域から離れた所定の位置に到達した前記端末装置との間で相互認証を行う認証処理部と
を備える情報処理装置。
(2)
前記第1の領域は、前記端末装置が前記第2の領域に入る前に必ず通過するように設定されている(1)に記載の情報処理装置。
(3)
前記所定の位置は、前記第1の領域内の端の位置、または、前記第1の領域外における前記第1の領域の近傍の位置である(1)または(2)に記載の情報処理装置。
(4)
前記所定の位置は、前記端末装置が前記第1の領域に入るために必ず通過する位置である(3)に記載の情報処理装置。
(5)
前記認証処理部は、前記所定の位置で信号発信端末からのトリガー信号を受信した前記端末装置からの通知に応じて前記相互認証を行う(1)から(4)のいずれかに記載の情報処理装置。
(6)
前記第1の領域で測位を行った前記端末装置から送信された測位結果を受信する(1)から(5)のいずれかに記載の情報処理装置。
(7)
前記第1の領域における前記端末装置の測位は、アンカーから送信された測距結果を用いてDownlink TDoA方式で行われる(6)に記載の情報処理装置。
(8)
前記端末装置から送信された前記測位結果には、前記相互認証の結果を利用した署名が付されている(6)または(7)に記載の情報処理装置。
(9)
前記測位処理部は、UWBを利用した測位で前記第2の領域における前記端末装置の測位を行う(1)から(8)のいずれかに記載の情報処理装置。
(10)
前記測位処理部は、前記第1の領域と前記第2の領域の間に存在する第3の領域における前記端末装置の測位を行う(1)から(9)のいずれかに記載の情報処理装置。
(11)
前記測位処理部は、アンカーから送信された測距結果を用いてUplink TDoA方式で前記第3の領域内における前記端末装置の測位を行う(10)に記載の情報処理装置。
(12)
前記測位処理部は、前記端末装置から送信された測距結果を用いてUplink TDoA方式で前記第3の領域内における前記端末装置の測位を行う(10)または(11)に記載の情報処理装置。
(13)
前記端末装置による測位結果と前記測位処理部による測位結果とを比較する比較処理部を備える(10)から(12)のいずれかに記載の情報処理装置。
(14)
前記第1の領域と前記第3の領域の境界における前記端末装置による測位結果と前記測位処理部による測位の結果とを比較する(13)に記載の情報処理装置。
(15)
前記信号発信端末はBLEビーコンである(1)から(14)のいずれかに記載の情報処理装置。
(16)
端末装置と情報処理装置とからなり、
前記端末装置の測位を行う測位処理部と、
前記情報処理装置との間で相互認証を行う認証処理部と、
を備える端末装置と、
第1の領域を通過した後に第2の領域に入った端末装置10の測位を行う測位処理部と、
前記端末装置が前記第2の領域に入る前に、前記第2の領域から離れた所定の位置に到達した前記端末装置との間で相互認証を行う認証処理部と
を備える前記情報処理装置と、
からなる情報処理システム。
(1)
第1の領域を通過した後に第2の領域に入った端末装置の測位を行う測位処理部と、
前記端末装置が前記第2の領域に入る前に、前記第2の領域から離れた所定の位置に到達した前記端末装置との間で相互認証を行う認証処理部と
を備える情報処理装置。
(2)
前記第1の領域は、前記端末装置が前記第2の領域に入る前に必ず通過するように設定されている(1)に記載の情報処理装置。
(3)
前記所定の位置は、前記第1の領域内の端の位置、または、前記第1の領域外における前記第1の領域の近傍の位置である(1)または(2)に記載の情報処理装置。
(4)
前記所定の位置は、前記端末装置が前記第1の領域に入るために必ず通過する位置である(3)に記載の情報処理装置。
(5)
前記認証処理部は、前記所定の位置で信号発信端末からのトリガー信号を受信した前記端末装置からの通知に応じて前記相互認証を行う(1)から(4)のいずれかに記載の情報処理装置。
(6)
前記第1の領域で測位を行った前記端末装置から送信された測位結果を受信する(1)から(5)のいずれかに記載の情報処理装置。
(7)
前記第1の領域における前記端末装置の測位は、アンカーから送信された測距結果を用いてDownlink TDoA方式で行われる(6)に記載の情報処理装置。
(8)
前記端末装置から送信された前記測位結果には、前記相互認証の結果を利用した署名が付されている(6)または(7)に記載の情報処理装置。
(9)
前記測位処理部は、UWBを利用した測位で前記第2の領域における前記端末装置の測位を行う(1)から(8)のいずれかに記載の情報処理装置。
(10)
前記測位処理部は、前記第1の領域と前記第2の領域の間に存在する第3の領域における前記端末装置の測位を行う(1)から(9)のいずれかに記載の情報処理装置。
(11)
前記測位処理部は、アンカーから送信された測距結果を用いてUplink TDoA方式で前記第3の領域内における前記端末装置の測位を行う(10)に記載の情報処理装置。
(12)
前記測位処理部は、前記端末装置から送信された測距結果を用いてUplink TDoA方式で前記第3の領域内における前記端末装置の測位を行う(10)または(11)に記載の情報処理装置。
(13)
前記端末装置による測位結果と前記測位処理部による測位結果とを比較する比較処理部を備える(10)から(12)のいずれかに記載の情報処理装置。
(14)
前記第1の領域と前記第3の領域の境界における前記端末装置による測位結果と前記測位処理部による測位の結果とを比較する(13)に記載の情報処理装置。
(15)
前記信号発信端末はBLEビーコンである(1)から(14)のいずれかに記載の情報処理装置。
(16)
端末装置と情報処理装置とからなり、
前記端末装置の測位を行う測位処理部と、
前記情報処理装置との間で相互認証を行う認証処理部と、
を備える端末装置と、
第1の領域を通過した後に第2の領域に入った端末装置10の測位を行う測位処理部と、
前記端末装置が前記第2の領域に入る前に、前記第2の領域から離れた所定の位置に到達した前記端末装置との間で相互認証を行う認証処理部と
を備える前記情報処理装置と、
からなる情報処理システム。
10・・・端末装置
11・・・アプリケーションプロセッサ
20・・・サーバ(情報処理装置)
21・・・アプリケーションプロセッサ
30・・・アンカー
40・・・BLEビーコン
100・・・情報処理システム
11・・・アプリケーションプロセッサ
20・・・サーバ(情報処理装置)
21・・・アプリケーションプロセッサ
30・・・アンカー
40・・・BLEビーコン
100・・・情報処理システム
Claims (16)
- 第1の領域を通過した後に第2の領域に入った端末装置の測位を行う測位処理部と、
前記端末装置が前記第2の領域に入る前に、前記第2の領域から離れた所定の位置に到達した前記端末装置との間で相互認証を行う認証処理部と
を備える情報処理装置。 - 前記第1の領域は、前記端末装置が前記第2の領域に入る前に必ず通過するように設定されている
請求項1に記載の情報処理装置。 - 前記所定の位置は、前記第1の領域内の端の位置、または、前記第1の領域外における前記第1の領域の近傍の位置である
請求項1に記載の情報処理装置。 - 前記所定の位置は、前記端末装置が前記第1の領域に入るために必ず通過する位置である
請求項3に記載の情報処理装置。 - 前記認証処理部は、前記所定の位置で信号発信端末からのトリガー信号を受信した前記端末装置からの通知に応じて前記相互認証を行う
請求項1に記載の情報処理装置。 - 前記第1の領域で測位を行った前記端末装置から送信された測位結果を受信する
請求項1に記載の情報処理装置。 - 前記第1の領域における前記端末装置の測位は、アンカーから送信された測距結果を用いてDownlink TDoA方式で行われる
請求項6に記載の情報処理装置。 - 前記端末装置から送信された前記測位結果には、前記相互認証の結果を利用した署名が付されている
請求項6に記載の情報処理装置。 - 前記測位処理部は、UWBを利用した測位で前記第2の領域における前記端末装置の測位を行う
請求項1に記載の情報処理装置。 - 前記測位処理部は、前記第1の領域と前記第2の領域の間に存在する第3の領域における前記端末装置の測位を行う
請求項1に記載の情報処理装置。 - 前記測位処理部は、アンカーから送信された測距結果を用いてUplink TDoA方式で前記第3の領域内における前記端末装置の測位を行う
請求項10に記載の情報処理装置。 - 前記測位処理部は、前記端末装置から送信された測距結果を用いてUplink TDoA方式で前記第3の領域内における前記端末装置の測位を行う
請求項10に記載の情報処理装置。 - 前記端末装置による測位結果と前記測位処理部による測位結果とを比較する比較処理部を備える
請求項10に記載の情報処理装置。 - 前記第1の領域と前記第3の領域の境界における前記端末装置による測位結果と前記測位処理部による測位の結果とを比較する
請求項13に記載の情報処理装置。 - 前記信号発信端末はBLEビーコンである
請求項1に記載の情報処理装置。 - 端末装置と情報処理装置とからなり、
前記端末装置の測位を行う測位処理部と、
前記情報処理装置との間で相互認証を行う認証処理部と、
を備える端末装置と、
第1の領域を通過した後に第2の領域に入った端末装置10の測位を行う測位処理部と、
前記端末装置が前記第2の領域に入る前に、前記第2の領域から離れた所定の位置に到達した前記端末装置との間で相互認証を行う認証処理部と
を備える前記情報処理装置と、
からなる情報処理システム。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2024113454 | 2024-07-16 | ||
| JP2024-113454 | 2024-07-16 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2026018564A1 true WO2026018564A1 (ja) | 2026-01-22 |
Family
ID=98437128
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2025/018877 Pending WO2026018564A1 (ja) | 2024-07-16 | 2025-05-26 | 情報処理装置および情報処理システム |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2026018564A1 (ja) |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2017204053A1 (ja) * | 2016-05-23 | 2017-11-30 | 日本電気株式会社 | サービス提供装置、サービス提供方法およびプログラム記録媒体 |
| US20200200858A1 (en) * | 2018-12-20 | 2020-06-25 | Here Global B.V. | Collecting a database of spoofed devices |
| WO2022264509A1 (ja) * | 2021-06-14 | 2022-12-22 | ソニーグループ株式会社 | 情報処理システム、情報処理端末、および情報処理方法 |
| CN116912991A (zh) * | 2023-07-11 | 2023-10-20 | 上海复微迅捷数字科技股份有限公司 | 行人通道的通过控制方法及装置、存储介质、终端 |
| CN117554889A (zh) * | 2023-11-10 | 2024-02-13 | 河南省联睿智能科技研究院有限公司 | 适用于无线信标方式的超宽带测距方法及定位系统 |
| WO2024106193A1 (ja) * | 2022-11-17 | 2024-05-23 | ソニーグループ株式会社 | 測位装置および測位方法、並びにプログラム |
-
2025
- 2025-05-26 WO PCT/JP2025/018877 patent/WO2026018564A1/ja active Pending
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2017204053A1 (ja) * | 2016-05-23 | 2017-11-30 | 日本電気株式会社 | サービス提供装置、サービス提供方法およびプログラム記録媒体 |
| US20200200858A1 (en) * | 2018-12-20 | 2020-06-25 | Here Global B.V. | Collecting a database of spoofed devices |
| WO2022264509A1 (ja) * | 2021-06-14 | 2022-12-22 | ソニーグループ株式会社 | 情報処理システム、情報処理端末、および情報処理方法 |
| WO2024106193A1 (ja) * | 2022-11-17 | 2024-05-23 | ソニーグループ株式会社 | 測位装置および測位方法、並びにプログラム |
| CN116912991A (zh) * | 2023-07-11 | 2023-10-20 | 上海复微迅捷数字科技股份有限公司 | 行人通道的通过控制方法及装置、存储介质、终端 |
| CN117554889A (zh) * | 2023-11-10 | 2024-02-13 | 河南省联睿智能科技研究院有限公司 | 适用于无线信标方式的超宽带测距方法及定位系统 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20230379655A1 (en) | Communication techniques using passive beacons | |
| US9907008B2 (en) | Cloud-coordinated location system using ultrasonic pulses and radio signals | |
| JP2022104962A (ja) | 自動機能のためにアクセス制御システムと通信及び測距を行うモバイルデバイス | |
| US20180196501A1 (en) | System and Method of Gesture Detection for a Remote Device | |
| KR102228653B1 (ko) | 강화된 인증을 포함하는 태그 식별 시스템 | |
| CN112399334A (zh) | 基于超宽带的定位方法、装置、电子设备和可读存储介质 | |
| US9576479B2 (en) | Road crossing assistance for the visually impaired using two transmitted messages from beacons | |
| US11950170B2 (en) | Passive sensor tracking using observations of Wi-Fi access points | |
| US20140355503A1 (en) | Transmitting service advertisements | |
| WO2009096184A1 (ja) | 通信システム | |
| US20250294316A1 (en) | Techniques for synchronizing ultra-wide band communications | |
| EP3229536A1 (en) | Interactive communication system, method and wearable device therefor | |
| CN120491034A (zh) | 通过移动蜂窝设备进行的测距 | |
| KR101603160B1 (ko) | 네트워크 연동 기능을 가진 비콘 게이트웨이를 이용하는 비콘 서비스 시스템 및 이를 이용한 비콘 신호 기반의 서비스 제공 방법 | |
| US20240276431A1 (en) | Information processing system, information processing terminal, and information processing method | |
| EP4291914A1 (en) | Techniques for localizing an electronic device | |
| KR20200133587A (ko) | 빔 북 정보에 기반하여 영역별 차별화된 서비스 제공 방법 및 장치 | |
| US9332384B2 (en) | Obtaining a geographical position of a mobile device | |
| EP4118848B1 (en) | Passive sensor tracking using observations of wi-fi access points | |
| EP4500797B1 (en) | Contention-based discovery and secure ranging techniques for congested environments | |
| CN110401919A (zh) | 信息处理方法及装置、电子设备、存储介质 | |
| WO2024156082A1 (en) | Concurrency of fast connection and periodic advertisement (pa) | |
| JP2009135689A (ja) | 測位システムおよび測位方法 | |
| KR20170018716A (ko) | iBeacon 기반의 단말 간 3차원 상대위치 인식 방법 및 시스템 | |
| WO2022211960A1 (en) | Techniques for localizing an electronic device |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 25840665 Country of ref document: EP Kind code of ref document: A1 |