COMMUNICATION AUTHENTICATION APPARATUS AND COMMUNICATION SYSTEM COMPRISING SAME
20200280844 ยท 2020-09-03
Inventors
Cpc classification
H04M1/72403
ELECTRICITY
H04W4/80
ELECTRICITY
Y02D30/70
GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
H04L63/18
ELECTRICITY
H04W12/47
ELECTRICITY
H04L63/0853
ELECTRICITY
International classification
Abstract
Provided are a communication authentication apparatus and a communication system that enable authentication for easily and safely connecting a communication device to an access point, and improvement of convenience and safety by appropriately controlling communication with the communication device. The communication authentication apparatus (10) for performing authentication for connecting the communication device (20) to the access point (40) of a wireless LAN includes an NFC unit (12) having a function of authentication by performing communication using NFC with the communication device (20) by proximity or contact with the communication device (20), and a power supply circuit (13). When the power supply circuit (13) is in a completely power-off state or a power-saving state, the communication authentication apparatus (10) controls to start up the power supply circuit (13) from the complete power-off state or the power-saving state in response to communication with the communication device (20) in the NFC unit (12).
Claims
1-5. (canceled)
6. A communication system: comprising a communication device; and a communication authentication apparatus performing authentication for connecting the communication device to an access point of a wireless LAN, wherein the communication device comprises a storage unit storing an application having a function for receiving authentication by the communication authentication apparatus, wherein the communication authentication apparatus comprises an NFC unit performing communication using NFC with the communication device by proximity or contact of the communication device, wherein the communication authentication apparatus performs authentication for connecting the communication device to the access point by performing communication using NFC with the communication device by proximity or contact of the communication device, and transmits encrypted data to the communication device, and wherein the authenticated communication device decrypts the data received from the communication authentication apparatus, and connects to the access point by acquiring from the decrypted data authentication information of the access point to which the communication device is connected.
7. The communication system according to claim 6, further comprising a display unit performing a display related to the application, wherein the authenticated communication device displays on the display unit authentication information on an access point to which the communication is connected or image data including the authentication information.
8. The communication system according to claim 7, wherein a display of authentication information of the access point or a display of image data including authentication information is performed for a predetermined period of time.
9. A communication system comprising: a communication device; and a communication authentication apparatus performing authentication of the communication device, wherein the communication authentication apparatus comprises: a first communication unit performing communication using NFC with the communication device by proximity of contact of the communication device; and a second communication unit performing another wireless communication using a communication method different form the first communication unit, wherein the first communication unit of the communication authentication apparatus performs authentication of the communication device by performing communication using NFC with the communication device by proximity or contact of the communication device, and transmits encrypted data to the communication device, wherein the authenticated communication device decrypts data received from the communication device, thereby becoming ready to transmit another data to the communication device using the decrypted data, and wherein the other data transmitted from the communication device authenticated by the communication authentication apparatus is configured to be transmitted to another receiving communication device via the second communication unit of the communication authentication apparatus.
10. The communication system according to claim 9, wherein the other data is data related to an order in a store where the communication authentication apparatus is installed, and wherein the communication authentication apparatus checks the data related to the order transmitted from the authenticated communication device, if necessary adjusts the data to correct data, and transmits the corrected data via the second communication device to a terminal device of an operator of the store as the other communication device.
11. A communication system comprising: a communication device and a communication authentication apparatus performing authentication of the communication device, wherein the communication authentication apparatus comprises: a first communication unit performing communication using NFC with the communication device by proximity or contact of the communication device; and a second communication unit performing communication performing another wireless communication using a communication method different from the fist communication unit, wherein the first communication unit of the communication authentication apparatus performs authentication of the communication device by performing communication using NFC with the communication device by proximity or contact of the communication device, and transmits encrypted data to the communication device, and wherein the communication device authenticated in the communication authentication apparatus is configured to decrypt the data received from the communication authentication apparatus, transmit the decrypted data to a sever via a communication network, thereby receiving key data of a locking device from the server, and transmit the received key data using communication by the second communication unit, thereby locking/unlocking the locking device.
12. A communication system: comprising a communication device; and a communication authentication apparatus performing authentication of the communication device, wherein the communication device comprises a storage unit storing an application having a function for receiving authentication by the communication authentication apparatus, wherein the communication authentication apparatus comprises an NFC unit performing communication using NFC with the communication device by proximity or contact of the communication device, wherein the communication authentication apparatus performs communication using NFC with the communication device by proximity or contact of the communication device, thereby performing authentication of the communication device, and transmits encrypted data to the communication device, and wherein the authenticated communication device decrypts the data received from the communication authentication apparatus, thereby becoming ready to transmit data related to an order in a store where the communication authentication apparatus is installed to a terminal device of a store operator using the decrypted data.
Description
[BRIEF DESCRIPTION OF THE DRAWINGS]
[0018]
[0019]
[0020]
[0021]
[0022]
[0023]
[0024]
[0025]
[0026]
[0027]
[0028]
[0029]
[0030]
[0031]
[0032]
MODE FOR CARRYING OUT THE INVENTION
[0033] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings.
[0034]
[0035] The communication authentication apparatus 10 includes a microcomputer module 11, an NFC circuit (first communication unit) 12 and a power supply circuit 13. Further, the microcomputer module 11 includes a CPU (control unit) 14 that controls each unit constituting the communication authentication apparatus 10, a ROM 15 and a RAM 16, which are storage means for storing data, and a Bluetooth (registered trademark) communication circuit (second communication unit) 17, and a wireless LAN communication circuit 18. The NFC circuit 12 includes a sensor unit 12a for communication with the outside, and is configured to enable NFC wireless communication with the smartphone 20 via the sensor unit 12a. The
[0036] Bluetooth communication circuit 17 is configured to enable wireless communication with the smartphone 20 using the Bluetooth communication method. The wireless LAN communication circuit 18 is configured to enable wireless communication with a wireless LAN access point (AP) 40 using a wireless LAN communication method such as the Wi-Fi standard.
[0037] The smartphone 20 includes a CPU (control unit) 21 that controls each unit constituting the smartphone 20, an NFC circuit 22, a Bluetooth communication circuit 23, a wireless LAN communication circuit 24, a storage unit 25 that stores various data, a display unit 26 that outputs image information and an input device 27 such as a touch panel. The NFC circuit 22 includes a sensor unit 22a for communication with the outside, and is configured to enable wireless communication by NFC with the NFC circuit 12 of the communication authentication apparatus 10 via the sensor unit 22a. The Bluetooth communication circuit 23 is configured to enable wireless communication with the Bluetooth communication circuit 17 of the communication authentication apparatus 10 using the Bluetooth communication method. The wireless LAN communication circuit 24 is configured to enable wireless communication with the communication authentication apparatus 10 and with the wireless LAN access point 40 using a wireless LAN communication method such as the Wi-Fi standard.
[0038] Further, an application software that performs an authentication procedure with the communication authentication apparatus 10 by NFC wireless communication and connects to a wireless LAN access point based on this authentication is installed on the smartphone 20. This application software should be downloaded and installed from a website or the like stored in the server 50 that provides the application software by connecting the smartphone 20 to the Internet (communication network) W (see
[0039] Here, the communication by the above-described NFC is a wireless communication technology that enables communication when two devices are in close proximity (separated from several cm to several tens of cm) or in contact with each other. (Hereinafter, both close proximity and contact may be collectively referred to as proximity or close.) Therefore, the NFC circuit 22 of the smartphone 20 is configured so as to enable the NFC wireless communication with the communication authentication apparatus 10 when arranged close to the NFC circuit 12 of the communication authentication apparatus 10. More specifically, as shown in
[0040] Here, a processing procedure of establishing BLE (Bluetooth Low Energy) communication by an NFC touch performed between the communication authentication apparatus 10 and the smartphone 80 of the store operator will be described. The processing of establishing the BLE communication is mainly performed on the smartphone 80 of the store operator, which is a terminal for performing (initial) setting of the communication authentication apparatus 10 and the like. This processing can be also performed to another communication device such as the visitor's smartphone 20.
[0041]
[0042] Thereafter, when the communication authentication apparatus 10 enters a BLE searchable state, the communication authentication apparatus 10 transmits a BLE advertisement packet (ST1-4). Here, the BLE advertisement packet includes a unique ID of an NFC chip. Then, the smartphone 80 that has touched the communication authentication apparatus 10 performs authentication by reacting only to the advertisement packet that matches the ID of the communication authentication apparatus 10 obtained from NFC. As a result, it is determined whether BLE communication can be established within a predetermined period of time (for example, 10 seconds) (ST1-5). As a result, if the BLE communication cannot be established within the predetermined period of time (NO), the processing returns to ST1-1. If the BLE communication can be established within the predetermined period of time (YES), a command processing (BLE command processing) by BLE communication is performed (ST1-6). In this BLE command processing, for example, processing of status notification, password authentication and network transmission/reception are performed. Further, as processings involving the password authentication, processings such as network connection setting (Wi-Fi information, server setting), rewriting of an NFC tag, and firmware updating are performed. Thereafter, the processing returns to step ST1-1 by disconnecting the BLT connection. By performing the processing illustrated in
[0043] Next, as a preparation for performing the authentication procedure of the smartphone 20 using the communication authentication apparatus 10, a processing procedure for setting information of a wireless LAN (Wi-Fi or the like) being in a store to the communication authentication apparatus 10 will be described. Here, the case in which the store operator performs the processing using their smartphone 80 will be described.
[0044] An authentication procedure of the smartphone 20 using the communication authentication apparatus 10 will be described.
[0045]
[0046] Next,
[0047] In the flowchart of
[0048] Then, in response to the fact that the body of the smartphone 20 has been touched to the sensor unit 12a of the NFC circuit 12 of the communication authentication apparatus 10, encrypted data is transmitted from the communication authentication apparatus 10 to the smartphone 20 (ST4-2). After that, the smartphone 20 decrypts the received data, and acquires an SSID and a password for Wi-Fi from the decrypted data (ST4-3). Then, a connection to Wi-Fi is performed using the acquired SSID and password (ST4-4). Thus, the connection of the smartphone 20 to Wi-Fi is completed.
[0049] In the flowchart of
[0050] Then, in response to the fact that the body of the smartphone 20 has been touched to the sensor unit 12a of the NFC circuit 12 of the communication authentication apparatus 10, encrypted data is transmitted from the communication authentication apparatus 10 to the smartphone 20 (ST5-2). Thereafter, the smartphone 20 decrypts the received data, and acquires an SSID and a password for Wi-Fi from the decrypted data (ST5-3). Then, a connection to Wi-Fi is performed using the acquired SSID and password (ST5-4). Thus, the connection of the smartphone to Wi-Fi is completed. The procedure up to this point are the same as that of ST4-1 to ST4-4 in
[0051] Thereafter, Wi-Fi encryption information display for authentication is transferred from the smartphone 20 that is an authenticated communication device to the PC 30 that is another unauthenticated communication device (ST5-5). The procedure for transferring the encryption information display is performed specifically using a method shown in
[0052]
[0053] As described above, the communication authentication apparatus 10 of the present embodiment includes the NFC circuit (NFC unit) 12 having the function of performing authentication for connecting the smartphone (communication device) 20 to the access point 40 by performing communication using NFC with the smartphone 20 by proximity or contact of the smartphone 20, the microcomputer module 11 having the CPU 14 for controlling the NFC circuit 12, and the power supply circuit 13 that supplies power to the system of the communication authentication apparatus 10 including the NFC circuit 12 and the microcomputer module 11 (CPU 14). And, when the power supply circuit 13 is in the complete power-off state or the power-saving state, the power supply circuit 13 is controlled to start from the complete power off state or the power saving state in response to the communication with the smartphone 20 in the NFC unit 12.
[0054] In the communication authentication apparatus 10 of the above-described configuration including the NFC circuit 12 having the function of performing authentication for connecting the smartphone 20 to the access point 40 of the wireless LAN by performing communication using NFC with the smartphone 20 by proximity or contact of the smartphone 20, when the power supply circuit is in the complete power-off state or the power-saving state, in the response to the communication with the smartphone 20 in the NFC circuit 12, the power supply circuit 13 is controlled to start from the complete power-off state or the power-saving state. This enables start-up of the power supply circuit 13 of the communication authentication apparatus 10 so as to supply power only when necessary, and accordingly enables effective reduction of power consumption of the communication authentication apparatus 10. In addition, since the power supply circuit 13 is configured to be activated in response to the communication of the NFC circuit 12, the authentication of the smartphone 20 can be performed quickly and reliably.
[0055] Moreover, the communication system 100 of the present embodiment includes the smartphone 20 and the communication authentication apparatus 10 that performs authentication for connecting the smartphone 20 to the access point 40 of the wireless LAN. The smartphone 20 includes the storage unit 25 that stores the application having a function for receiving authentication by the communication authentication apparatus 10, and a display unit 26 that performs a display related to the application. In addition, the communication authentication apparatus 10 includes the circuit 12 having the function of performing authentication for connecting the smartphone 20 to the access point 40 by performing communication using the NFC with the smartphone 20 by proximity or contact of the smartphone 20. The communication authentication apparatus 10 performs authentication for connecting the smartphone 20 to the access point 40 by performing communication using NFC with the smartphone 20 by proximity or contact of the smartphone 20. And, the authenticated smartphone 20 is configured to display the authentication information (namely, SSID and password) 62 of the access point 40 to which the smartphone 20 is connected or the two-dimensional code 61 including the authentication information on the display unit 26.
[0056] The communication system 100 of the above-described configuration is configured so that the authentication information 62 of the access point 40 to which the smartphone 20 is connected or the two-dimensional code 61 including this authentication information is displayed on the display unit 26 of the authenticated smartphone 20. This enables authentication for connecting the PC 30 as the other communication device to the access point 40 using the display of the authentication information 62 or the two-dimensional code 61 including this authentication information. In other words, when the authentication information 62 is displayed on the display unit 26 of the authenticated smartphone 20, the PC 30 can be authenticated by manually inputting the display of the authentication information 62 to the PC 30. When the two-dimensional code 61 including the authentication information is displayed on the display unit 26, the PC 30 can be authenticated by capturing the two-dimensional code 61 with a camera (imaging means) of the PC 30. Therefore, it is possible to securely authenticate the connection of the PC 30 to the access point 40 by a simple procedure.
Second Embodiment
[0057] Next, a second embodiment of the present invention will be described. In the description of the second embodiment and the corresponding drawings, components that are the same as or correspond to those of the first embodiment are denoted by the same reference numerals, and detailed description of those portions will be omitted below. Items other than those to be described below and those to be illustrated below are the same as those in the first embodiment. This also applies to the third and subsequent embodiments.
[0058] In the present embodiment, when a visitor of the store 200 places an order for a product or the like from their smartphone 20, the communication authentication apparatus 10 is configured to authenticate the transmission of order data from the smartphone 20. Therefore, in the present embodiment, whether or not the smartphone 20 is connected to the access point 40 in the wireless LAN environment in the store 200 does not directly affect the authentication. Hence, it is not necessarily essential for the smartphone 20 to connect to the wireless LAN access point 40 in the store 200 by the authentication of the communication authentication apparatus 10. On the other hand, the communication authentication apparatus 10 is connected to the access point 40 of the wireless LAN in the wireless LAN communication circuit 18, and to the server 50 on the Internet W via the wireless LAN. Therefore, an exchange of data between the smartphone 20 and the in-store computer 70, and an exchange of data between the communication authentication apparatus 10 and the in-store computer 70 are performed via the server 50.
[0059] A processing in which a visitor (customer) of the store 200 sends order information of a product or the like to the computer 70 of the store operator using their smartphone 20 will be described.
[0060] In addition, by performing the above-described authentication, the communication authentication apparatus 10 and the computer 70 of the store operator can transmit store information (for example, information on recommended products and services of the day) to the visitor's smartphone 20 via the Internet W or the like. Further, the communication authentication apparatus 10 can identify the visitor who owns the smartphone 20 based on the information obtained from the visitor's smartphone 20 at the time of authentication. Based on this information, the computer 70 of the store operator can grasp a past visit history of the visitor, a purchase history of products, and the like. Therefore, the content (information) to be transmitted as described above can be varied for each visitor according to their visit history or purchase history.
[0061] Thereafter, the visitor inputs order information such as a product with the authenticated smartphone 20 (namely, performs an order) (ST6-5). The input of the order information of the product or the like is performed by, for example, selecting a desired product from a list menu displayed on the display screen of the smartphone 20. After that, it is determined whether or not the NFC touch of the smartphone 20 to the communication authentication apparatus 10 has been performed (ST6-6). As a result, if the NFC touch is not performed (NO), the processing waits until the NFC touch is performed, and proceeds to subsequent steps only when the NFC touch is performed (YES). Then, when the NFC touch is performed, if the smartphone 20 is not connected to the Internet (communication network) W (NO in ST6-7), the order data is transmitted from the smartphone 20 to the communication authentication apparatus 10 (ST6-8). Data transmission and reception at this time is performed via the wireless LAN communication circuit 24, 18. The communication authentication apparatus 10 that has received the transmitted order data checks the transmitted order data and adjusts it (if necessary) to correct data (ST6-9). Checking and adjusting the order data here means, for example, confirming that the order data transmitted by the sender (such as fee data, orderer information, etc.) has not been improperly falsified, and in the event that such falsification has been found, correcting the order data to correct data. Thereafter, the checked and adjusted order data is transmitted from the communication authentication apparatus 10 to the store operator's computer 70 via the server 50 on the Internet W (ST6-10). Data transmission by the communication authentication apparatus 10 at this time is performed via the wireless LAN communication circuit 18. On the other hand, when the smartphone 20 is connected to the Internet W in the previous ST6-7 (YES in ST6-7), the order data is transmitted from the smartphone 20 directly through the server 50 via the Internet W to the computer 70 of the operator (ST6-11). The store operator's computer 70 receives the order data transmitted through any of the above-described routes and accordingly confirms the order (ST6-12). Thereafter, the store operator's computer 70 transmits an order receipt confirmation to the visitor's smartphone 20 via the server 50 (ST6-13). Upon receiving the order receipt confirmation, the smartphone 20 confirms with this reception that the order has been successfully received (ST6-14). When there is an order again, the above-described processing from ST6-5 to ST6-14 is repeated.
[0062] As described above, the communication system 100 according to the second embodiment includes the smartphone 20 and the communication authentication apparatus 10 that authenticates data transmitted from the smartphone 20. The communication authentication apparatus 10 includes the NFC circuit (first communication unit) 12 having the function of authenticating data transmitted from the smartphone 20 by performing communication using NFC with the smartphone 20 by proximity or contact of the smartphone 20, and the wireless LAN communication circuit 18 for performing another wireless communication using a communication method different from that of the NFC circuit 12. The NFC circuit 12 of the communication authentication apparatus 10 authenticates data transmitted from the smartphone 20 by performing communication using NFC with the smartphone 20 by proximity or contact of the smartphone 20. The data transmitted from the smartphone 20 that has been authenticated by the communication authentication apparatus 10 is transmitted from the wireless LAN communication circuit 18 of the communication authentication apparatus 10 through the access point 40 via the server 50 on the Internet W to the store operator's computer (namely, communication device for reception) 70.
[0063] The communication system 100 of the present embodiment is configured so that the data transmitted from the smartphone 20 authenticated by the communication authentication apparatus 10 is transmitted from the wireless LAN communication circuit 18 of the communication authentication apparatus 10 to the store operator's computer 70 via the server 50 on the Internet W through the access point 40. This enables transmission only of the information permitted (authenticated) by the communication authentication apparatus 10 out of the data transmitted from the smartphone 20 to the computer 70 of the store operator, which is another communication device. In other words, for example, in a store such as a restaurant, a visitor (customer) of the store inputs information related to their order by operating a communication device such as their own smartphone 20. In that case, the data related to the order can be transmitted to the computer 70 of the store operator only when the visitor brings the smartphone 20 close to or in contact with the communication authentication apparatus 10 (NFC touch). Further, at this time, the data transmitted from the smartphone 20 is transmitted to the store operator's computer 70 via the communication authentication apparatus 10. This can prevent transmission of the transmitted data if the transmitted data is improperly falsified, and can transmit the data after being appropriately corrected. As a result, it is possible for the visitor to safely and reliably place an order from their own smartphone 20 or the like, and the store operator can safely and properly receive the order from visitor's the smartphone 20 or the like.
Third Embodiment
[0064] Next, a third embodiment of the present invention will be described.
[0065]
[0066] Thereafter, the visitor touches the locking device 80 provided on the door 90 or the like so as to authenticate the smartphone 20 (ST7-9). Thereby, the authentication of the smartphone 20 is completed by the locking device 80 (ST7-10), and the completion of the authentication is notified from the locking device 80 to the smartphone 20 (ST7-11). Here, as shown in
[0067] As described above, in the present embodiment, the door 90 and the like can be unlocked using the smartphone 20 that has been authenticated by touching the communication authentication apparatus 10, thereby enabling further improvement of convenience for shop visitors and the like. In the above description, the case where the locking device 80 is unlocked by the smartphone 20 storing the key data 85 has been described. However, the locking may be performed in addition thereto. In the above-described embodiment, the case where the locking device 80 is attached to the door 90 of the room in the store has been described. However, the locking device 80 may be attached to something that needs to be locked/unlocked, for example, a box (safe or storage box). Alternatively, the key data of the present embodiment can be used not only for unlocking and locking the locking device, but also for starting a computer or a device (for example, a game device). Also, in this case, when a user having the smartphone 20 enters the room and locks the door 90 (namely, the locking device 80) of the room, the smartphone 20 may be automatically connected to the Wi-Fi in the room by transmitting information on the Wi-Fi in the room from the locking device 80 to the smartphone 20.
Fourth Embodiment
[0068] Next, a fourth embodiment of the present invention will be described.
[0069] The functions that can be set in the communication authentication apparatus 10 here include, for example, the following. [0070] Check-in: Whether the person entered the place. [0071] Checkout: Whether the person has left the place. [0072] Membership management: Who performed a particular action on that place (such as using contents of a device provided therein). [0073] Product order: To purchase a product from a specific display menu. [0074] URL Display: URL information held by the touched place. [0075] Authentication: Matching key information of the touching terminal. [0076] Information acquisition: Displaying information related to a store or the like on the touching smartphone 20.
[0077] In other words, the administrator M displays management information of the communication authentication apparatus 10 (10-1, 10-2, 10-3 . . . ) on the management screen 51 of the server 50, and in this state, selects the functions that can be set by the communication authentication apparatus 10 and operates the setting (ST8-1). Thus, the selected data is set (written) in the ROM 15 or the like via the NFC circuit 12 in the corresponding communication authentication apparatus 10 (10-1, 10-2, 10-3 . . . ) (ST8-2).
[0078] As described above, according to the present embodiment, since the selection and setting operation of the functions that can be set for the plurality of communication authentication apparatuses 10 (10-1, 10-2, 10-3 . . . ) can be collectively performed, management of the plurality of communication authentication apparatuses 10 (10-1, 10-2, 10-3 . . . ) is facilitated, and in addition the convenience thereof is improved. In this embodiment, in addition to the selection and setting of the functions that can be set in the communication authentication apparatus 10 (10-1, 10-2, 10-3 . . . ), batch updating of a firmware of the communication authentication apparatus 10 (10-1, 10-2, 10-3 . . . ), and collective acquisition of current information such as detection values of a temperature/humidity sensor held by the communication authentication apparatus 10 (10-1, 10-2, 10-3 . . . ) are performable on the management screen 51 of the server 50.
[0079] As described above, the embodiments of the present invention have been described. However, the present invention is not limited to the above-described embodiments, and various modifications may be made within the scope of the claims and the technical idea described in the specification and the drawings.