Authentication system, authentication method, and recording medium

By acquiring and comparing the card appearance feature information input by the user terminal, and using a learning model for authentication, the problem of insufficient IC card counterfeiting detection in the existing technology is solved, and higher holding authentication security and distributed processing load are achieved.

CN115053219BActive Publication Date: 2026-01-30RAKUTEN GROUP INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202080043490.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-28
Publication Date
2026-01-30
Estimated Expiration
2040-12-28

AI Technical Summary

Technical Problem

Existing technologies cannot effectively determine the counterfeiting of IC cards without random patterns or IC chips, resulting in insufficient security for cardholder authentication.

Method used

By acquiring card appearance feature information and recognition information input by the user terminal, image comparison is performed using a learning model, and authentication is performed by combining it with pre-registered registration information, thus distributing the authentication processing load and improving security.

Benefits of technology

It improves the security of cardholder authentication, prevents unauthorized holders from authenticating by forging card information, reduces the risk of confidential information leakage, and distributes the authentication processing load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115053219B_ABST
    Figure CN115053219B_ABST
Patent Text Reader

Abstract

The input information acquisition unit (101, 201) of the authentication system (S) acquires input information related to the appearance features of the card held by the user, input from the user terminal (30). The identification information acquisition unit (104, 202) acquires identification information that can identify the card. The registration information acquisition unit (105, 203) acquires registration information related to the appearance features that is pre-associated with the identification information and registered in the server (10, 20). The authentication unit (102) performs authentication based on the input information and the registration information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to authentication systems, authentication methods, and recording media. Background Technology

[0002] Previously, techniques for preventing illegal activities by malicious third parties related to authentication using a user's card were known. For example, Patent Document 1 describes a technique for determining IC card counterfeiting by comparing feature information extracted by photographing a random pattern formed on the surface of the IC card with identification information obtained from the IC chip of the IC card, and pre-stored comparison information as correct answers.

[0003] Prior technology documents

[0004] Patent documents

[0005] Patent Document 1: International Publication No. 2014 / 016883 Summary of the Invention

[0006] The problem that the invention aims to solve

[0007] However, the technology in Patent Document 1 cannot determine the counterfeiting of IC cards without a random pattern, nor can it determine the counterfeiting of cards without an IC chip. The technology in Patent Document 1 can only detect counterfeits for very specific types of cards, lacking universality, and therefore cannot sufficiently improve the security of cardholder authentication.

[0008] One of the purposes of this disclosure is to improve the security of holding authentication.

[0009] Methods for solving problems

[0010] The authentication system disclosed herein includes: an input information acquisition unit for acquiring input information related to the appearance features of a card held by a user terminal; an identification information acquisition unit for acquiring identification information capable of identifying the card; a registration information acquisition unit for acquiring registration information related to the appearance features that is pre-associated with the identification information and registered in a server; and an authentication unit for performing authentication based on the input information and the registration information.

[0011] Invention Effects

[0012] According to this disclosure, security is enhanced in holding authentication. Attached Figure Description

[0013] Figure 1 This is a diagram illustrating an example of the overall structure of an authentication system.

[0014] Figure 2This is an example of a photographic image.

[0015] Figure 3 This is a diagram representing an example of an input image.

[0016] Figure 4 This is a functional block diagram illustrating an example of the functionality implemented by the authentication system of the first embodiment.

[0017] Figure 5 This is a diagram representing an example of data storage in a user database.

[0018] Figure 6 This is a diagram representing an example of data storage in a card database.

[0019] Figure 7 This is a flowchart illustrating an example of the processing performed in the first embodiment.

[0020] Figure 8 This is a functional block diagram of the second embodiment.

[0021] Figure 9 This is a flowchart illustrating an example of the processing performed in the second embodiment.

[0022] Figure 10 This is the function block diagram in the variant example.

[0023] Figure 11 This is an example of an authentication design that focuses on the background of the card.

[0024] Figure 12 This is an example of an authentication design that focuses on the background of the card.

[0025] Figure 13 This is a diagram illustrating an example of certification that focuses on the future design of the card.

[0026] Figure 14 This is a diagram illustrating an example of certification that focuses on the future design of the card.

[0027] Figure 15 This is an example of a selection screen. Detailed Implementation

[0028] [1. First Implementation Method]

[0029] The following describes an example of a first embodiment of the authentication system disclosed herein. In the authentication system, possession authentication is performed. Possession authentication is the authentication of an item held only by a legitimate person. The item used for possession authentication is not limited to tangible objects, but can also be intangible objects such as electronic data. In the first embodiment, an example of possession authentication using an IC card (hereinafter simply referred to as a card) from a transportation system is given. Hereinafter, possession authentication will sometimes be referred to simply as authentication.

[0030] [1-1. Overall Structure of the Authentication System]

[0031] Figure 1 This is a diagram illustrating an example of the overall structure of an authentication system. (Example:) Figure 1 As shown, the authentication system S includes: an operator server 10, an issuer server 20, and a user terminal 30. The operator server 10, issuer server 20, and user terminal 30 are each capable of connecting to a network N, such as the Internet. Figure 1 In this example, one operator server 10, one issuer server 20, and one user terminal 30 are shown, but there can also be multiple of them.

[0032] The operator server 10 is a server computer corresponding to an operator that provides services using the card. An operator is a company that provides services to users. In the first embodiment, an example of a transportation system service using the card is given, where the operator is a railway company or a bus company, etc.

[0033] The operator server 10 includes a control unit 11, a storage unit 12, and a communication unit 13. The control unit 11 includes at least one processor. The storage unit 12 includes volatile memory such as RAM and non-volatile memory such as a hard disk. The communication unit 13 includes at least one of a communication interface for wired communication and a communication interface for wireless communication.

[0034] The issuer server 20 is a server computer corresponding to the issuer of the issued card. The issuer is the company that provides cards to users. In the first embodiment, the case where the issuer and operator are the same is described, but the issuer and operator may also be different. The issuer server 20 includes a control unit 21, a storage unit 22, and a communication unit 23. The physical structures of the control unit 21, storage unit 22, and communication unit 23 are the same as those of the control unit 11, storage unit 12, and communication unit 13, respectively.

[0035] User terminal 30 is a computer operated by a user. For example, user terminal 30 is a smartphone, tablet terminal, wearable terminal, or personal computer. User terminal 30 includes: control unit 31, storage unit 32, communication unit 33, operation unit 34, display unit 35, camera unit 36, and IC chip 37. The physical structures of control unit 31, storage unit 32, and communication unit 33 are the same as those of control unit 11, storage unit 12, and communication unit 13, respectively.

[0036] The operation unit 34 is an input device such as a touch panel. The display unit 35 is a liquid crystal display or an organic EL display. The imaging unit 36 ​​includes at least one camera. The IC chip 37 is a chip capable of short-range wireless communication. The IC chip 37 can be a chip of any standard, such as a FeliCa (registered trademark) chip, or a so-called Type A or Type B chip in contactless standards. The IC chip 37 includes hardware such as an antenna corresponding to the standard, and stores information required for the services used by the user.

[0037] Furthermore, at least one of the programs and data stored in storage units 12, 22, and 32 can be supplied via network N. Additionally, each of the operator server 10, the issuer server 20, and the user terminal 30 may include at least one of a reading unit (e.g., an optical disc drive, a memory card slot) for reading computer-readable information storage media and an input / output unit (e.g., a USB port) for inputting and outputting data with external devices. For example, at least one of the programs and data stored in the information storage media can be supplied via either the reading unit or the input / output unit.

[0038] [1-2. Overview of the First Embodiment]

[0039] In the first embodiment, an example is given of a user registering a card in a transportation system application (hereinafter referred to simply as an application) to explain the processing of the authentication system S. The application in the first embodiment is a program for using a user terminal 30 to utilize the services of the transportation system. The application is pre-downloaded and installed on the user terminal 30.

[0040] Registering a card in an application enables the application to access services equivalent to those available through the card itself. For example, this is equivalent to being able to access card information from an application, associate card information with an application, or associate card information with a user account; registering the card in the application is equivalent to registering the card in the application. Alternatively, registering card information in the operator server 10 or the IC chip 37 is equivalent to registering the card in the application.

[0041] Card information is the information that identifies a card. Card information includes at least the card number, which is a unique identifier for the card. Card information may also include supplementary information attached to the card. Supplementary information is information other than the card number, such as the card's expiration date, the user's name, or the card's issue date.

[0042] For example, a user registers for application use to issue user account information. Then, in order to register a card within the application, the user performs an operation to register the card from the application's menu, etc. If this operation is performed, the camera unit 36 ​​is activated, and the image captured by the camera unit 36 ​​is displayed on the display unit 35. Furthermore, the captured image can also be displayed as part of the application registration process.

[0043] Figure 2 This is an example of a captured image. For example... Figure 2 As shown, the image captured continuously by the capturing unit 36 ​​is displayed on the capturing screen G1. A guide g10, used to guide the positional relationship between the capturing unit 36 ​​and the card, is displayed on the captured image. In the first embodiment, it is required to capture the card from the front at a predetermined size. For example, the user places the card on a table and takes the picture with the edge of the card aligned with the guide g10.

[0044] If a user takes a picture of the card, the user terminal 30 sends the captured image of the card to the operator server 10. Since this captured image is an image input from the user terminal 30 to the operator server 10, it will be referred to as the input image below. In the first embodiment, input means sending data.

[0045] Figure 3 This is a diagram representing an example of an input image. For example... Figure 3 As shown, the input image I displays various information contained in the card C. For example, the input image I displays information such as text or numbers printed on the surface of the card C, information that can be visually confirmed by the embossed shape, or parts exposed on the outside of the card C.

[0046] exist Figure 3 In the example, the input image I includes an illustration i10, card name n11, markings m12 and m13, IC chip c14, hologram h15, card number n16, expiration date e17, issue date d18, and name n19. Furthermore, the IC chip c14 is a chip embedded in the card C itself, not the IC chip 37 of the user terminal 30. The portion of the IC chip c14 exposed from the card C appears in the input image I.

[0047] In the first embodiment, the issuing server 20 registers a registration image reflecting the issued card C. Therefore, if the user is the legitimate holder of card C, a registration image reflecting the card C identical to the input image I is registered to the issuing server 20. If the operator server 10 receives input image I from the user terminal 30, it forwards it to the issuing server 20. The issuing server 20 determines whether input image I is similar to the registration image. The issuing server 20 sends the determination result to the operator server 10.

[0048] If the operator server 10 receives a result indicating that the input image I is similar to the registered image, it determines that the user is a legitimate holder and authentication is successful. In this case, if... Figure 2 As shown, a success screen G2 indicating successful authentication and registration is displayed on the user terminal 30. Afterwards, the user can access the same services from the application as when using the physical card C.

[0049] On the other hand, if the operator server 10 receives a determination result that the input image I is not similar to the registered image, it determines that the user is not a legitimate holder, and authentication fails. In this case, such as Figure 2 As shown, the user terminal 30 displays a failure screen G3 indicating that authentication failed and registration was not completed. The user returns to the shooting screen G1 to retake the photo of card C, or inquires with the call center.

[0050] As described above, in the authentication system S, authentication is performed based on the input image I reflecting the card C held by the user and the registration image pre-registered in the issuing server 20. Even if a malicious third party attempts to register illegally obtained card information into the application, authentication will fail because the appearance characteristics of the card C cannot be determined. In the first embodiment, by utilizing the appearance characteristics of the card C, the security of possession authentication is improved. The following is a detailed description of this technology.

[0051] [1-3. Functions implemented in the first embodiment]

[0052] Figure 4 This is a functional block diagram illustrating an example of the functions implemented by the authentication system S in the first embodiment. Here, the functions implemented by each of the operator server 10, the issuer server 20, and the user terminal 30 will be described.

[0053] [1-3-1. Functions implemented in the carrier's server]

[0054] like Figure 4As shown, the operator server 10 implements a data storage unit 100, an input information acquisition unit 101, an authentication unit 102, and a registration unit 103. The data storage unit 100 is mainly implemented by the storage unit 12. The other functions are mainly implemented by the control unit 11.

[0055] [Data Storage Department]

[0056] Data storage unit 100 stores the data required for authentication. For example, user database DB1 is described for data storage unit 100.

[0057] Figure 5 This is a diagram representing a data storage instance of user database DB1. For example... Figure 5 As shown, the user database DB1 is a database that stores information related to users. For example, the user database DB1 stores: user account, password, name, and card information. When a user registers to use the service, a user account is issued, and a new record is created in the user database DB1. This record stores the password and name specified during registration.

[0058] In the first embodiment, the registration of card information after service usage registration is completed is described; however, it is also possible not to register card information during service usage registration. The card information stored in the user database DB1 is the card information of card C registered in the application. The number of cards C that can be registered in the application is not limited to one; multiple cards can also be registered.

[0059] The card information stored in the user database DB1 only needs to include the minimum information required to provide services. That is, not all information associated with card C needs to be stored in the user database DB1. The card information stored in the user database DB1 can be just the card number, or it can include... Figure 5 Information beyond what is shown (security code, password in so-called 3D Secure authentication, etc.). Furthermore, in Figure 5 In the database, the card information is displayed as is, but the card information can also be stored in a hashed state in the user database DB1.

[0060] [Input Information Acquisition Department]

[0061] The input information acquisition unit 101 acquires the input image input from the user terminal 30. In the first embodiment, since the operator server 10 communicates directly with the user terminal 30, the input information acquisition unit 101 directly acquires the input image from the user terminal 30. However, if a computer mediates the communication between the operator server 10 and the user terminal 30, the input information acquisition unit 101 can acquire the input image forwarded by that computer. That is, the input information acquisition unit 101 can also indirectly acquire the input image from the user terminal 30.

[0062] An input image is an example of input information. Therefore, the location described as an input image in the first embodiment can be renamed input information. Input information is information related to the appearance characteristics of the card C held by the user. Input information is information entered during authentication. Input information is equivalent to a query during authentication. Input information is not limited to an image and can be in any form. For example, input information can be text, numbers, or a combination thereof.

[0063] The appearance of a card C refers to its physical appearance. The characteristics of the appearance are image features, visual features, optical features, or physical shape features such as embossing. Features include color, density, style, brightness, outline, shape, size, or combinations thereof. For example, illustrations, photographs, styles, background colors, text, numbers, logos, graphics, holograms, physical shapes, or combinations thereof contained in a card C correspond to the characteristics of the card C's appearance. Physical shape refers to the embossed or raised shape, or the card C's outline, thickness, or size.

[0064] In the first embodiment, the case where the surface (face) of card C is shown in the input image is described. However, the back of card C may also be shown in the input image, or both the surface and back of card C may be shown. Furthermore, the input image may only show a portion of the surface of card C, without showing the entire surface. Additionally, card C of any size and orientation may be shown in the input image; for example, card C taken at an angle may be shown.

[0065] [Certification Department]

[0066] The authentication unit 102 performs authentication based on an input image representing the card C held by the user and a registered image representing the card C held by the user. In the first embodiment, the authentication unit 102 performs authentication based on a comparison result between the input image and the registered image. This comparison result is a determination result of whether the input image and the registered image are similar. The determination result of similarity represents any value among a first value that means similarity and a second value that means dissimilarity. Theoretically, an accidental similarity between two images can occur, so similarity in the first embodiment also includes the meaning of similarity.

[0067] Furthermore, various methods can be used to determine whether images are similar. In the first embodiment, the case using a learning model, which will be described later, will be explained, but other methods such as cosine similarity, histogram distribution, or template matching (pattern matching) can also be used. In the first embodiment, the case of determining whether images are similar overall will be explained, but the case of determining whether images are similar locally can also be explained.

[0068] In the first embodiment, the comparison between the input image and the registered image is not performed by the authentication unit 102 of the operator server 10, but by the comparison unit 204 of the issuer server 20. The authentication unit 102 obtains the comparison result from the comparison unit 204 of the issuer server 20 and performs authentication. If the input image and the registered image are similar, authentication is successful. If the input image and the registered image are dissimilar, authentication fails.

[0069] [Registration Department]

[0070] The registration unit 103 performs registration processing related to the card C corresponding to the card number based on the execution result of the authentication performed by the authentication unit 102. Registration processing is a process used to enable the use of the registered card C. In the first embodiment, registering the card C in an application is equivalent to registration processing. Especially when no application is used, registration processing simply means recording the card information in any computer, such as the operator server 10.

[0071] The card C of the registration target is the card C that is registered through the registration process. The card C of the registration target is identified by its card number. In the first embodiment, the card C shown in the input image corresponds to the card C of the registration target. In the first embodiment, the case where the card number of the card C of the registration target is obtained from the input image using optical character recognition is described, but the card number can be obtained by any method. For example, the user can manually enter the card number, or the card number can be pre-stored in the user terminal 30. In this case, the card number of the card C of the registration target is entered into the operator server 10 along with the input image.

[0072] If authentication is successful, the registration department 103 performs the registration process; if authentication fails, the registration process is not performed. That is, the success or failure of authentication is a condition for whether or not the registration process is performed. If a user's authentication is successful, the registration department 103 performs the registration process by storing the card information of the target card C in the record corresponding to the user's account in the user database DB1. The user account is entered upon login. The card information of the target card C is obtained from the issuing server 20.

[0073] [1-3-2. Functionality Implemented in the Publisher's Server]

[0074] like Figure 4 As shown, the issuer server 20 implements a data storage unit 200, an input information acquisition unit 201, an identification information acquisition unit 202, a registration information acquisition unit 203, and a comparison unit 204. The data storage unit 200 is mainly implemented by the storage unit 22. The other functions are mainly implemented by the control unit 21.

[0075] [Data Storage Department]

[0076] Data storage unit 200 stores the data required for authentication. For example, regarding data storage unit 200, the card database DB2 will be described.

[0077] Figure 6 This is a diagram representing an example of data storage in the DB2 card database. For example... Figure 6 As shown, card database DB2 is a database that stores card information for cards C that have been issued. For example, card number, expiration date, name, and registration image are stored in card database DB2. If a new card C is issued, a new record is created in card database DB2, and the card information for that card C is stored.

[0078] Furthermore, the card information stored in the card database DB2 can be just the card number, or it can include... Figure 6 Information other than that shown (security code, password in so-called 3D Secure authentication, etc.). If card C is registered in the application, all or part of the card information of card C stored in card database DB2 is stored in user database DB1.

[0079] When card C is issued, the issuer registers the image. In the first embodiment, the issuer photographs card C from the front at a predetermined size. The orientation and size are guided in the shooting screen G1's guide g10. The number of registered images for each card C1 is not necessarily one, but can be multiple. For example, card C can be photographed from various angles and stored in a database DB2 of multiple registered image cards.

[0080] [Input Information Acquisition Department]

[0081] The input information acquisition unit 201 acquires the input image input from the user terminal 30. In the first embodiment, the input information acquisition unit 201 acquires the input image forwarded from the operator server 10. That is, the input information acquisition unit 201 indirectly acquires the input image input from the user terminal 30. Alternatively, the input image may be directly input from the user terminal 30 to the issuer server 20. In this case, the input information acquisition unit 201 directly acquires the input image input from the user terminal 30.

[0082] [Identification Information Acquisition Department]

[0083] The identification information acquisition unit 202 acquires the card number of the registered object's card C. The card number is an example of identification information. Therefore, the location recorded as the card number in the first embodiment can be renamed as identification information. Identification information is information capable of identifying the card C. Identification information is not limited to the card number, as long as it uniquely identifies the card C. A combination of multiple pieces of information, such as the card number, expiration date, and name, can also be considered identification information. Furthermore, for example, identification information can be equivalent to ID identification information that corresponds one-to-one with the card C.

[0084] In the first embodiment, the identification information acquisition unit 202 acquires the card number from the input image. For example, the identification information acquisition unit 202 performs optical character recognition on the input image to identify at least one of the characters and numbers contained in the input image and acquire the card number. Furthermore, the area in the input image showing card C can be determined by contour extraction or the like.

[0085] Optical character recognition can also be performed on the entire card C. Since the card number is contained within a defined area of ​​the card C, the recognition information acquisition unit 202 performs optical character recognition on the defined area of ​​the card C shown in the input image. This area can be any position, size, and shape, such as near the center, lower right, or upper left of the card C. Information that can determine this area is pre-stored in the data storage unit 200. The area including the card number varies depending on the type of card C, so this area can also be defined for each type.

[0086] Furthermore, the method for recognizing at least one of text and numbers from an image can utilize various methods, not limited to optical character recognition. For example, it could be a method using a learning model or a template matching method. Additionally, the card number can be obtained using a predetermined method, but it may not need to be obtained from the input image. The recognition information acquisition unit 202 can acquire a card number manually entered by the user, or it can acquire a card number stored in the user terminal 30.

[0087] [Registration Information Acquisition Department]

[0088] The registration information acquisition unit 203 acquires the registration image that is associated with the card number acquired by the identification information acquisition unit 202. In the first embodiment, since the registration image is stored in the card database DB2, the registration information acquisition unit 203 acquires the registration image from the card database DB2. The registration information acquisition unit 203 acquires the registration image stored in the record with the same card number as that acquired by the identification information acquisition unit 202. Furthermore, if the registration image is stored in an external computer or an external information storage medium, the registration information acquisition unit 203 can acquire the registration image from the external computer or the external information storage medium.

[0089] A registration image is an example of registration information. The location described as a registration image in the first embodiment can be renamed registration information. Registration information is information related to the appearance of card C that is pre-associated with the card number and registered in the issuer's server 20. Registration information serves as the correct answer during authentication. Registration information is equivalent to an index during authentication. Registration information is not limited to an image form and can be any form. For example, registration information can be text, numbers, or a combination thereof. Registration information can also be information that can be compared with input information. Registration information can be in the same form as the input information or a different form.

[0090] In the first embodiment, the case where the surface of card C is shown in the registration image will be described. However, the back of card C may be shown in the registration image, or both the surface and the back of card C may be shown. Furthermore, it is not necessary to show the entire surface of card C in the registration image; only a portion of the surface may be shown. The registration image only needs to reflect the portions of card C used for authentication on both sides. The portion of card C shown in the registration image and the portion of card C shown in the input image can be shared.

[0091] [Comparative Section]

[0092] The comparison unit 204 compares the input image and the registered image. The comparison unit 204 determines whether the input image and the registered image are similar. That is, the comparison unit 204 determines whether the card C shown in the input image is similar to the card C shown in the registered image. A similarity score above a threshold means similarity, and a similarity score below the threshold means dissimilarity.

[0093] In cases where each of the input image and the registration image contains a portion other than card C, the comparison unit 204 determines whether the area showing card C in the input image and the area showing card C in the registration image are similar. That is, the comparison unit 204 removes the portion other than card C from the input image, and after removing the portion other than card C from the registration image, determines whether they are similar. Removing the portion other than card C has the same meaning as cutting out the portion showing card C.

[0094] If neither the input image nor the registered image contains any portion other than card C, the comparison unit 204 determines whether the entire input image and the entire registered image are similar. In this case, since card C is shown in the entire image, it is not necessary to remove any portion other than card C. Furthermore, even if each of the input image and the registered image contains a portion other than card C, it is possible to determine whether they are similar without removing that portion.

[0095] In the first embodiment, as described above, an example of a method for determining whether images are similar is a method that utilizes a learning model. The learning model is a model that utilizes machine learning (artificial intelligence). Machine learning itself can employ various techniques, such as deep learning or neural networks. That is, the learning model itself can utilize various models used for determining whether images are similar.

[0096] The learning model's program and parameters are stored in data storage unit 200. This learning model learns from multiple pairs of similar images, i.e., training data. If the learning model is given two images as input, it repeatedly performs convolution and pooling to calculate the features of each image. These features are represented by multi-dimensional vectors.

[0097] The learning model calculates the distance between two features in a vector space. This distance is equivalent to the similarity between two images. The shorter the distance, the higher the similarity; the longer the distance, the lower the similarity. Similarity is a score representing the degree of similarity. The higher the similarity, the higher the probability that the two images are similar; the lower the similarity, the lower the probability that the two images are similar. This probability is also called likelihood.

[0098] If the distance between two features is less than a threshold, the learning model outputs a first value indicating that the two images are similar. If the distance is less than the threshold, the learning model outputs a second value indicating that the two images are dissimilar. The output of the learning model represents the determination of whether two images are similar. This output can also be called a label indicating whether two images are similar.

[0099] The comparison unit 204 inputs the input image acquired by the input information acquisition unit 101 and the registered image acquired by the registration information acquisition unit 203 into the learning model. The learning model outputs a determination result indicating whether the input image and the registered image are similar. The comparison unit 204 sends the determination result output from the learning model to the operator server 10 as a comparison result.

[0100] Alternatively, the learning model may output a similarity score instead of a similarity determination result. In this case, the comparison unit 204 determines whether the input image and the registered image are similar by judging whether the similarity score output from the learning model is above a threshold. The comparison unit 204 sends the similarity determination result based on the similarity score output from the learning model to the operator server 10 as a comparison result.

[0101] Alternatively, the comparison unit 204 may not send a similarity determination result, but instead send the similarity between the input image and the registered image to the operator server 10 as a comparison result. In this case, the authentication unit 102 of the operator server 10 performs authentication by determining whether the similarity received from the issuer server 20 is above a threshold. If the similarity is above the threshold, authentication is successful. If the similarity is below the threshold, authentication fails.

[0102] [1-3-3. Functions implemented on the user terminal]

[0103] like Figure 4 As shown, the user terminal 30 implements a data storage unit 300, a display control unit 301, and a receiving unit 302. The data storage unit 300 is implemented primarily by a storage unit 32. The display control unit 301 and the receiving unit 302 are each primarily implemented by a control unit 31. The data storage unit 300 stores data required for the processing described in the first embodiment. For example, the data storage unit 300 stores applications of a transportation system. The display control unit 301 uses the application... Figure 2 The screens described herein are displayed on the display unit 35. The receiving unit 302 receives user operations on each screen.

[0104] [1-4. Processes performed in the first embodiment]

[0105] Figure 7 This is a flowchart illustrating an example of the processing performed in the first embodiment. The control units 11, 21, and 31 execute the process according to the programs stored in the storage units 12, 22, and 32, respectively. Figure 7 The process shown is... This process is... Figure 4 This is an example of the processing performed by the shown functional module. This processing is performed when the application on user terminal 30 is launched and an operation for registering card C is performed from the prescribed menu.

[0106] like Figure 7 As shown, the user terminal 30 activates the camera unit 36 ​​and displays the images continuously captured by the camera unit 36 ​​on the shooting screen G1 (S100). When the user touches the shooting screen G1, the user terminal 30 causes the camera unit 36 ​​to capture the image of the card C, generate an input image, and send the input image to the operator server 10 (S101). In addition, the user has already logged into the application, and the user's user account is also sent to the operator server 10.

[0107] If the operator server 10 receives an input image from the user terminal 30 (S102), it forwards the input image to the issuing server 20 (S103). If the issuing server 20 receives an input image from the operator server 10 (S104), it performs optical character recognition on the input image to obtain the card number (S105). The issuing server 20 refers to the card database DB2 and obtains a registration image associated with the card number obtained in S105 (S106).

[0108] The issuing server 20 compares the input image received in S104 with the registration image obtained in S106 (S107) and sends the comparison result to the operator server 10 (S108). In S107, the issuing server 20 inputs the input image and the registration image into the learning model and obtains a similarity determination result output from the learning model. In S108, the issuing server 20 sends the determination result output from the learning model as the comparison result. This comparison result includes the card number obtained in S105.

[0109] If the operator server 10 receives a comparison result from the issuer server 20 (S109), it performs authentication by referring to the comparison result (S110). If the comparison result indicates similarity and authentication is successful (S110; Success), the operator server 10 performs the registration process for the card C of the registration object (S111), and this process ends.

[0110] In S111, the operator server 10 associates the card information of the registered object's card C with the user's user account and registers it in the user database DB1. This card information can be included in the comparison result in S109, or it can be obtained from the issuing server 20 in S111. The operator server 10 sends the display data for the success screen G2 to the user terminal 30 and displays the success screen G2.

[0111] On the other hand, if the comparison result does not indicate similarity and authentication fails (S110; failure), the process in S111 is not executed, and this process ends. In this case, the card information of the registered object's card C is not registered in the user database DB1. The operator server 10 sends the display data for the failure screen G3 to the user terminal 30, displaying the failure screen G3.

[0112] According to the authentication system S of the first embodiment, authentication is performed by establishing a registration image associated with the card number of the card C of the registered object, thereby improving the security of card C possession authentication. Furthermore, a malicious third party may dislike having their face reflected in a photo for some reason, so requesting a photo of the card C can create a psychological defense. Additionally, card information such as card numbers is sometimes registered on various servers, making it relatively easy for malicious third parties to obtain. On the other hand, since the registration image is only registered on the issuing server 20 and not on other servers, in principle, a third party cannot obtain it. Therefore, even if a third party illegally obtains card information, in principle, unless they seize the card C itself, they cannot determine the appearance characteristics of the card C. Therefore, by utilizing the appearance characteristics of the card C to perform authentication, illegal registration by a third party who has illegally obtained card information can be prevented. For example, authentication by entering the security code of the card C is generally also called possession authentication, but the possession authentication of the first embodiment requires knowledge of information such as the security code to succeed, thus making it a secure and robust possession authentication. Similarly, when the input information and registration information are information other than the image, the security of holding the card is improved because the third party is generally unaware of the appearance characteristics of the card.

[0113] Furthermore, in the authentication system S, the issuing server 20 performs a comparison between the input image and the registered image, and the operator server 10 performs authentication by obtaining the comparison result from the issuing server 20. Therefore, it is unnecessary for the operator server 10 to manage the registered image or to send the registered image over the network N. As a result, the registered image, being confidential information, is difficult to leak, effectively improving security. Additionally, by distributing the processing required for authentication between the operator server 10 and the issuing server 20, the processing load during authentication can be distributed.

[0114] Furthermore, in the authentication system S, registration processing related to the card C corresponding to the card number is performed based on the authentication execution result, thereby improving the security of card C registration. That is, it can prevent unauthorized registration by third parties who have illegally obtained card information.

[0115] [2. Second Implementation]

[0116] Next, a second embodiment of the authentication system S will be described. In this second embodiment, the comparison between the input image and the registered image is performed by the operator server 10, not the issuer server 20. Similar to the first embodiment, the registered image is registered in the issuer server 20. Hereinafter, details identical to those in the first embodiment will be omitted.

[0117] Figure 8 This is a functional block diagram of the second embodiment. For example... Figure 8 As shown, the operator server 10 includes: a data storage unit 100, an input information acquisition unit 101, an authentication unit 102, a registration unit 103, an identification information acquisition unit 104, and a registration information acquisition unit 105. The identification information acquisition unit 104 and the registration information acquisition unit 105 are primarily implemented by the control unit 11. Furthermore, since the function of the comparison unit 204 described in the first embodiment is incorporated into the authentication unit 102, therefore... Figure 8 The comparison unit 204 is not shown. Furthermore, the input information acquisition unit 201 can be omitted.

[0118] The data storage unit 100 in the second embodiment stores a registration image database DB3. The registration image database DB3 is a database that stores at least the card number and registration image pairs from the card database DB2 described in the first embodiment. Furthermore, since the registration image database DB3 is equivalent to... Figure 6 The card number and registration image are from the DB2 card database, so the illustration is omitted.

[0119] The processing of the identification information acquisition unit 104 is the same as that of the identification information acquisition unit 202 in the first embodiment. For example, the identification information acquisition unit 104 uses optical character recognition to obtain the card number from the input image obtained by the input information acquisition unit 101. The processing of the registration information acquisition unit 105 is also largely the same as that of the registration information acquisition unit 203 in the first embodiment, but the registration information acquisition unit 105 obtains the registration image from the issuer server 20.

[0120] For example, the registration information acquisition unit 105 stores the registration image obtained from the issuer server 20 into the registration image database DB3. Each time a card C is issued, the issuer server 20 sends the card number and registration image to the operator server 10. If the operator server 10 receives the card number and registration image, the registration information acquisition unit 105 stores their pair in the registration image database DB3. The registration image database DB3 can store all card numbers and registration images from the card database DB2, or it can store only a portion of the card numbers and registration images.

[0121] Furthermore, the registration information acquisition unit 105 can acquire the registration image during authentication, instead of storing the registration image in the registration image database DB3 in advance. For example, if the card number is acquired by the identification information acquisition unit 104, the registration information acquisition unit 105 can request the registration image of card C represented by that card number from the issuing server 20. The issuing server 20 acquires the registration image from the card database DB2 and sends it to the operator server 10. The registration information acquisition unit 105 acquires the registration image sent by the issuing server 20. In this way, by dynamically acquiring the registration image during authentication, the operator server 10 does not need to store the registration image database DB3.

[0122] Figure 9 This is a flowchart illustrating an example of the processing performed in the second embodiment. For example... Figure 9 As shown, if the issuing server 20 issues a new card C and adds it to the card database DB2, it sends a card number and registration image pair to the operator server 10 (S200). If the operator server 10 receives the card number and registration image pair (S201), it stores the received pair in the registration image database DB3 (S202). The subsequent processing in S203 to S205 is the same as that in S100 to S102.

[0123] The operator server 10 performs optical character recognition on the input image received in S205 to obtain the card number (S206). The operator server 10 then refers to the registration image database DB3 to obtain a registration image associated with the card number obtained in S206 (S207). The operator server 10 performs authentication by comparing the input image and the registration image (S208). The processing in S208 is the same as that in S107, and the processing in S110 is then performed in the same way. The subsequent processing in S209 is the same as that in S111.

[0124] According to the second embodiment, authentication is performed by comparing the input image with the registered image using the carrier server 10. This eliminates communication between the carrier server 10 and the issuing server 20 after the input image is entered, thus enabling faster authentication. Furthermore, since the issuing server 20 does not perform the comparison between the input image and the registered image, its processing load is reduced.

[0125] [3. Variations]

[0126] Furthermore, this disclosure is not limited to the embodiments described above. Appropriate modifications can be made without departing from the spirit of this disclosure.

[0127] Figure 10 This is a functional block diagram from a variant example. For example... Figure 10 As shown, in the following modified examples, in addition to the functions described in the embodiments, the forming determination unit 106 described in modified example (7) and the shooting determination unit 107 described in modified example (8) are also implemented. These functions are mainly implemented by the control unit 11. Furthermore, in Figure 10 In the first embodiment, a formation determination unit 106 and a shooting determination unit 107 are added to the functional modules. However, in the second embodiment, a formation determination unit 106 and a shooting determination unit 107 may also be added to the functional modules.

[0128] (1) For example, in the first and second embodiments, the case of performing authentication based on the overall appearance of the card C was described, but authentication can also be performed with regard to the design of the background in the card C. Since the card C in the first and second embodiments includes a background, when determining whether the card C shown in the input image and the card C shown in the registration image are similar in their overall appearance, the design of the background is also taken into account in the similarity determination. However, in this variation, authentication with a stronger focus on the design of the background is described.

[0129] In this embodiment, the appearance of card C is characterized by the design of its background. The authentication unit 102 performs authentication based on the design of the background represented by the input image and the design of the background represented by the registered image. Authentication succeeds when their background designs are similar. Authentication fails when their background designs are dissimilar.

[0130] The background is the part excluding the foreground. The background is the part further back (below, inside) than the foreground. The background is the part hidden by the foreground. The background is the part of the face of card C excluding the card information. The foreground is the part further forward (top, near the front) than the background. The foreground is the part that hides the background. The foreground is the part that overlaps with the background. The foreground is the part of the face of card C containing the card information.

[0131] When the user uses the physical SIM card C instead of an application, the portion of the card that the user is unaware of is equivalent to the background, and the portion that the user acknowledges is equivalent to the foreground. Information other than the card information registered with the operator's server 10 can also be equivalent to the foreground. In SIM card C, the portion where the foreground and background overlap is represented by the foreground, taking precedence over the background. This portion can also represent the foreground without representing the background at all, or it can represent the foreground more prominently than the background.

[0132] For example, the background can be an illustration, photograph, graphic, style, pattern, color, or a combination thereof. The background may appear entirely within card C or partially within a portion of card C. Figure 3 In the example, illustration i10 corresponds to the background. IC chip c14 internally stores card information, but its appearance as card information is not meaningful, so it also corresponds to the background. IC chip c14 can have multiple patterns. The parts of card C without symbols also have some color, so they also correspond to the background.

[0133] exist Figure 3In the example, since the card name n11, markings m12, m13, hologram h15, card number n16, expiration date e17, issue date d18, and name n19 are present on the background, they are equivalent to the foreground. These foregrounds are text, numbers, graphics, logos, or combinations thereof. Furthermore, as part of the background, it may also include text, numbers, graphics, logos, or combinations thereof.

[0134] Figure 11 The image shows an example of a certification design that focuses on the background of Card C. (See image for reference.) Figure 11 As shown, in this variation, the foreground portion of card C in the input image I is masked. For example, in methods utilizing learning models, even if only the background design is considered, if the input image I contains a foreground, it may be affected by the features of the foreground. Therefore, in this variation, masking is used to make the features of the foreground disappear or reduce.

[0135] Masking itself can be performed through various masking processes. For example, filling with a specified color such as white or black, filling with the surrounding (background) color, or blurring are examples of masking processes. The portion of card C to be masked is predetermined. The portion to be masked sometimes varies depending on the type of card C, so in this case, the portion to be masked is determined according to each type of card C. The type of card C is stored in the card database DB2. Data representing the portion to be masked is pre-stored on the operator server 10 or the issuer server 20.

[0136] If we take an example of the process of the first embodiment, the comparison unit 204 masks a predetermined foreground portion for the input image I. The foreground portion of the registered image is masked in advance, but the comparison unit 204 may also mask the foreground portion of the registered image at this time. The portion in the input image I that is the object to be masked is the same as the portion in the registered image that is the object to be masked. Furthermore, they do not need to be completely identical, and some deviation is allowed.

[0137] The comparison unit 204 compares the input image I with its foreground portion masked and the registration image with its foreground portion masked. The comparison method itself is as described in the first embodiment. The authentication unit 102 obtains the comparison result from the comparison unit 204 and performs the authentication process as described in the first embodiment. In the case of the second embodiment, the authentication unit 102 simply performs the masking of the input image I. The authentication unit 102 performs authentication by comparing the input image I with its foreground portion masked and the registration image with its foreground portion masked.

[0138] In addition, Figure 11In the example, the case where masking is performed by leaving only the illustration i10 is explained. However, since the surface pattern of the IC chip c14 can also be used as a background feature, the IC chip c14 can also be left unmasked. Furthermore, it is not necessary to mask all foreground features; if the foreground features are small, they can be left unmasked.

[0139] Furthermore, the methods used for designing with an eye on the background are not limited to masking. Various image processing techniques can be applied that can make the features of the foreground disappear or reduce. For example, the background portion of the input image I can be cropped. In this case, the entire background portion can be cropped, or only a portion with characteristic patterns, etc., can be cropped.

[0140] Figure 12 This diagram illustrates an example of certification design that focuses on the background of Card C. For example... Figure 12 As shown, the portion of SIM card C to be cut is predetermined. The portion to be cut sometimes varies depending on the type of SIM card C; in this case, the portion to be cut is determined according to each type of SIM card C. The data indicating the portion to be cut is pre-stored in the operator server 10 or the issuer server 20. Furthermore, in Figure 12 In this method, the input image I before and after cropping the background is set to the same size, but the size of the cropped input image I can be reduced.

[0141] The comparison unit 204 compares the input image I with its background portion cropped and the registered image with its background portion cropped. The comparison method itself is as described in the first embodiment. The authentication unit 102 obtains the comparison result from the comparison unit 204 and performs the authentication process as described in the first embodiment. In the case of the second embodiment, the authentication unit 102 simply performs background cropping on the input image I. The authentication unit 102 performs authentication by comparing the input image I with its background portion cropped and the registered image with its background portion cropped.

[0142] According to variation (1), by performing authentication based on the design of the background of the input image representation and the design of the background of the registration image representation, the security of possession authentication can be effectively improved. For example, if a third party illegally obtains card information, the issuer can be determined based on the specified bits of the card number. In this case, it is assumed that the third party will attempt to illegally register using a composite image obtained by combining the illegally obtained card information with a sample image provided by the issuer's website. However, if the issuer's card C also contains designs from previous issues, there are often a large number of designs, and the third party cannot determine which design the actual card C is using only the card information. Therefore, by utilizing the design of the background of card C for authentication, a secure and robust possession authentication can be achieved.

[0143] Furthermore, in the first and second embodiments, the case where registration images are stored in the card database DB2 for each user has been described. However, if users using cards C with the same background can share the registration image representing that background, it is not necessary to store registration images for each user. Only the background portion of card C is shown in the registration image. When multiple types of backgrounds exist, the background type is associated with the card number in the card database DB2. In this case, registration images exist for each background type, and during authentication, the registration image for each background type is associated with the card number of the card C being registered. This eliminates the need to prepare registration images for each user, reducing the memory consumption of the issuing server 20.

[0144] (2) Additionally, for example, the case where the background is an illustration has been described, but the background can also be a photograph. As long as any subject is reflected in the photograph, such as an athlete, singer, car, scenery, or building, it can be used. The design of the background can also perform authentication focused on the photograph. In this variation, the case where the background is an illustration or photograph in card C is described.

[0145] For example, authentication unit 102 performs authentication based on the design of the illustration or photograph representing the input image and the design of the illustration or photograph representing the registered image. Authentication succeeds if the background illustration or photograph design is similar. Authentication fails if the background illustration or photograph design is dissimilar.

[0146] The authentication process itself is the same as in variant (1), which involves masking the foreground or cropping a portion of the background illustration or photograph. As in the first and second embodiments, the determination of whether the background illustration or photograph is similar also considers whether the input image and the registration image are similar as a whole, but by performing masking or cropping, the design of the illustration or photograph can be more focused on.

[0147] According to variation (2), by performing authentication based on the design of the illustration or photograph representing the input image and the design of the illustration or photograph representing the registered image, the security of possession authentication can be effectively improved. For example, illustrations or photographs of card C are also easily issued, and more designs exist. Therefore, the background illustrations or photographs become information that is more difficult for third parties to determine. If there are many designs, it is very troublesome for third parties to create synthetic images in a loop, so the possibility of third parties abandoning illegal behavior is increased. Thus, more robust security can be achieved.

[0148] (3) For example, when multiple types of background designs exist within the same type of card C, the consistency of the design type can be used as a condition for authentication. Cards of the same type refer to cards issued by the same entity and from the same series. Shared functions such as electronic money functionality can also be considered equivalent to cards of the same type.

[0149] For example, illustrations in the background of card C containing the same characters but with different appearances are equivalent to being in the same series. Additionally, different characters appearing in the same story included in the background of card C are equivalent to being in the same series. Furthermore, photographs in the background of card C containing the same subjects but with different poses and expressions are also equivalent to being in the same series.

[0150] In this variation, the authentication unit 102 performs authentication based on the type of background design represented by the input image and the type of background design represented by the registered image. Authentication succeeds when the types of background designs match. Authentication fails when the types of background designs do not match. Even in this variation, authentication focusing on the type of design within the same series can be performed by performing the same masking or clipping as in variation (1).

[0151] For example, even in depicting and Figure 3 For a series of cards featuring the same dog character, authentication will fail if the dog's clothing or expression differs. Furthermore, even cards from the same series may have different designs depending on their release period. Even a series of cards depicting a character from a particular manga may have different designs between cards released in 2018 and those released in 2020. Authentication Department 102 can also perform authentication based on these differences in design. Authentication itself can be performed based solely on the similarity of the background image.

[0152] According to variation (3), when multiple background designs exist in the same type of card C, authentication can be performed based on the type of background design represented by the input image and the type of background design represented by the registered image, which can effectively improve the security of the cardholder authentication. For example, even if a third party illegally obtains the card information, it is difficult to determine the type of design in the same series, thus achieving more robust security.

[0153] (4) Additionally, for example, the appearance features used in the authentication can also be the design of the foreground in card C. In this variation, for Figure 3The size and font of the card number n16 are used as a foreground design in this example, but other foreground designs can be used. For example, in authentication, the size, color, and font of the card name n11, the size, color, and shape of the markings m12 and m13, the size, color, and shape of the hologram h15, the size, color, and font of the issue date d18, and the size, color, and font of the name n19 can also be used. Furthermore, the presence or absence of these foreground elements, and their quantity, can also be used for authentication.

[0154] In this variation, the authentication unit 102 performs authentication based on the design of the foreground represented by the input image and the design of the foreground represented by the registration image. Authentication succeeds if their designs are similar, and fails if their designs are dissimilar. Since the card C in the first and second embodiments also includes a foreground design, when determining whether the overall similarity between the card C shown in the input image and the card C shown in the registration image is similar, the similarity determination also considers the foreground design. However, in this variation, authentication with a stronger focus on the foreground design will be described.

[0155] Figure 13 This diagram illustrates an example of a certification design focused on the future prospects of Card C. (See diagram for example.) Figure 13 As shown, in this variation, the parts of card C in the input image I other than card number n16 are masked. For example, in a method using a learning model, even if only the design of card number n16 is considered, if the input image I contains other parts, it may be affected by the features of those other parts. Therefore, in this variation, masking makes the features of other parts disappear or decrease.

[0156] The masking itself, as described in variation (1), predetermines the portion of card C to be masked. Taking an example of the process in the first embodiment, the comparison unit 204 masks the portion of the input image I other than card number n16. While other portions of the registration image are masked beforehand, the comparison unit 204 can also mask other portions of the registration image at this time.

[0157] The comparison unit 204 compares the input image I, whose other parts are masked, with the registration image, whose other parts are masked. The comparison method itself is as described in the first embodiment. The authentication unit 102 obtains the comparison result from the comparison unit 204 and performs the authentication process, which is also as described in the first embodiment. In the case of the second embodiment, the authentication unit 102 simply performs the masking of the input image I. The authentication unit 102 performs authentication by comparing the input image I, whose other parts are masked, with the registration image, whose other parts are masked.

[0158] Figure 14This diagram illustrates an example of a certification design focused on the future prospects of Card C. (See diagram for example.) Figure 14 As shown, similar to variation (1), the card number n16 can be cut without masking. The points where the part to be cut is predetermined are also the same as in variation (1).

[0159] Simply compare the input image I with card number n16 cropped and the registration image with card number n16 cropped. In this case, the issuing server 20 does not need to register the entire face of card C as the registration image; it only needs to register the image of the foreground portion. For example, only the image of the logo or number portion can be stored as the registration image in the card database DB2.

[0160] According to variation (4), as a feature of appearance, the design of the foreground in card C is utilized to perform authentication based on the design of the foreground represented by the input image and the design of the foreground represented by the registration image, which can effectively improve the security of possession authentication. For example, even if a third party illegally obtains the card information, the card information does not contain the design, so the design of the foreground cannot be determined, thus achieving more robust security.

[0161] (5) Additionally, for example, when there are multiple types of foreground designs in the same type of card C, the consistency of the design types can be set as a condition for certification. The meaning of the same type of card C is as explained in variant example (3). In this variant example, as an example of foreground design, the markings m12 and m13 are explained.

[0162] The authentication unit 102 performs authentication based on the type of foreground design represented by the input image and the type of foreground design represented by the registered image. Authentication succeeds if their types match. Authentication fails if their types do not match. Even in this variant, authentication focusing on the type of designs within the same series can be performed by performing the same masking and clipping as in variant (4).

[0163] For example, markings m12 and m13 indicate functions such as electronic money functionality of card C. Even if the function itself remains unchanged, markings m12 and m13 will change. The same applies to other foreground elements; even with the same issuer, the design of hologram h15 and other markings will change. For example, the design of hologram h15 and other markings differs between card C issued in 2018 and card C issued in 2020. The authentication department 102 can also perform authentication based on these different design types. Authentication itself can be performed based solely on the similarity of the images of the foreground elements to be considered.

[0164] According to variation (5), when multiple types of foreground designs exist in a card C of the same type, authentication can be performed based on the type of foreground design represented by the input image and the type of foreground design represented by the registered image, which can effectively improve the security of possession authentication. For example, even if a third party illegally obtains card information, it is difficult to determine the type of foreground design in the same series, thus achieving more robust security.

[0165] (6) Furthermore, for example, even if the appearance of the foreground is the same, it may be located in the lower right or upper left depending on the type or issuance period of the card C, rather than in the upper right. Therefore, the appearance feature used for authentication can also be the position of the foreground in the card C. That is, not only the appearance of the foregrounds such as m12 and m13 can be considered in the authentication, but the configuration within the card C can also be taken into account. In addition, in this variant example, the case of using the individual positions of multiple foregrounds in authentication is explained, but it is also possible to use the configuration of only one foreground in authentication.

[0166] The authentication unit 102 can also perform authentication based on the position of the foreground represented by the input image and the position of the foreground represented by the registered image. If their positions are consistent, authentication is successful. If their positions are inconsistent, authentication fails. Even in this variant, authentication based on the position of the foreground can be performed by performing the same masking and clipping as in variant (4).

[0167] For example, the authentication unit 102 performs authentication by determining whether the positional relationship between multiple foregrounds in the input image is consistent with the positional relationship between multiple foregrounds represented in the registered image. Authentication succeeds if their positional relationships are consistent. Authentication fails if their positional relationships are inconsistent. Even if the appearances of foregrounds such as markers m12 and m13 are identical, authentication fails if their positions are different.

[0168] Furthermore, the authentication unit 102 may determine whether the positional relationship is consistent based on the coordinates of the foreground positions in the images, rather than determining whether the images are similar to each other. For example, the authentication unit 102 may determine the coordinates of the markers m12 and m13 in the input image, and determine that the positional relationship is consistent if the deviation from the coordinates of the markers m12 and m13 in the registered image is less than a threshold.

[0169] According to variation (6), as a feature of appearance, authentication is performed based on the position of the foreground in card C, using the position of the foreground represented by the input image and the position of the foreground represented by the registered image, which can effectively improve security. For example, even if a third party illegally obtains the card information, the card information does not contain the configuration of the foreground, so the configuration of the foreground cannot be determined, thus achieving more robust security.

[0170] (7) In addition, for example, a malicious third party may sometimes obtain a copy of a piece of paper containing card C. In this case, the third party may photograph the paper and input it as an input image, so it can be determined whether the card C reflected in the input image is the card formed on the paper.

[0171] The authentication system S in this modified example includes a formation determination unit 106. The formation determination unit 106 determines whether the input image shows a piece of paper with an image of a card C formed on it. That is, the formation determination unit 106 determines whether the input image is an image of a real card C or an input image of a piece of paper with an image of a real card C formed on it.

[0172] In this modified example, the formation determination unit 106 will be described as performing determination processing based on the light reflection of the hologram h15 portion. The formation determination unit 106 calculates the average brightness of the hologram h15 portion in the input image and determines whether the average value is above a threshold. If the average value is above the threshold, it is determined that no paper is shown (no real card C is shown). If the average value is below the threshold, it is determined that paper is shown.

[0173] Furthermore, the determination method of the formation determination unit 106 is not limited to the examples described above. For example, pattern matching may be performed by simply cropping each hologram h15 portion of the input image and the registered image. Alternatively, for example, multiple input images may be generated by having the user take pictures of the card C from multiple angles, and the formation determination unit 106 determines the thickness of the card C through image analysis and determines whether the thickness is above a threshold. If the thickness is above the threshold, it is determined that no paper is shown (no real card C is shown). If the thickness is less than the threshold, it is determined that paper is shown.

[0174] The authentication unit 102 also performs authentication based on the determination result of the formation determination unit 106. Authentication succeeds if the paper containing card C is not displayed in the input image and the input image is similar to the registered image. Authentication fails if the paper containing card C is displayed in the input image, or if the input image is dissimilar to the registered image. In other words, in this modified example, there are two conditions for successful authentication; both conditions must be met for authentication to succeed. Authentication fails if either condition is not met.

[0175] According to variation (7), by also performing authentication based on whether the input image shows the paper with card C, the security of possession authentication can be effectively improved. For example, even if a third party obtains a copy of the paper with card C in some form, they will not be able to successfully authenticate using that paper, thus achieving more robust security.

[0176] (8) In addition, for example, a malicious third party may sometimes obtain image data of card C. In this case, the third party may input the image as an input image, so it can also be determined whether the card C reflected in the input image is a card captured by the camera unit 36 ​​of the user terminal 30.

[0177] The authentication system S in this modified example includes a shooting determination unit 107. The shooting determination unit 107 determines whether the shooting unit 36 ​​of the user terminal 30 generates an input image. That is, the shooting determination unit 107 determines whether the input image is generated by the shooting unit 36 ​​of the user terminal 30 or whether it is an input image that is not generated by the shooting unit 36 ​​of the user terminal 30 but is captured by another camera and forwarded to the user terminal 30.

[0178] For example, when user terminal 30 takes a picture of card C through camera unit 36, it generates shooting identification information that can recognize the meaning of the image and sends it along with the input image. Shooting determination unit 107 determines whether camera unit 36 ​​of user terminal 30 has generated an input image by determining whether shooting identification information has been received. If shooting identification information has been received, the determination is affirmative; if shooting identification information has not been received, the determination is negative.

[0179] Furthermore, the determination method can be any method. For example, information about the terminal that generates the input image can be appended to the input image, and the image capture determination unit 107 can determine whether the image capture unit 36 ​​of the user terminal 30 has generated an input image by referring to this appended information. If the information shows the user terminal 30, the determination is affirmative; if the information does not show the user terminal 30, the determination is negative.

[0180] Alternatively, for example, a request can be made to photograph card C at a specified angle in the shooting screen G1. This angle is not necessarily frontal; it can be a tilted angle. For example, a request can also be made to photograph card C at an angle randomly selected from multiple angles. In this case, the registration image is taken at the same angle as the requested angle. Alternatively, for example, card C can be photographed at a specified angle at the moment the registration image is generated, and this angle can be stored in the card database DB2. A request can also be made in the shooting screen G1 to photograph card C at this angle.

[0181] The shooting determination unit 107 determines the shooting angle of card C based on the shape and deformation of the card C's outline contained in the input image. The shooting determination unit 107 can determine whether the shooting unit 36 ​​of the user terminal 30 generates an input image by determining whether the determined angle is the angle requested by the user. It is highly likely that a photo of card C obtained by a malicious third party through some method is not taken at this angle, so the above determination can also be performed by determining the shooting angle of card C.

[0182] The authentication unit 102 also performs authentication based on the determination result of the imaging determination unit 107. Authentication succeeds if it is determined that the imaging unit 36 ​​of the user terminal 30 has generated an input image, and the input image is similar to the registered image. Authentication fails if it is not determined that the imaging unit 36 ​​of the user terminal 30 has generated an input image, or if the input image is dissimilar to the registered image. That is, in this modified example, there are two conditions for successful authentication; both conditions must be met for authentication to succeed. Authentication fails if either condition is not met.

[0183] According to variation (8), by performing authentication based on the determination result of whether the imaging unit 36 ​​of the user terminal 30 generates an input image, security can be effectively improved. For example, even if a third party obtains the image data of card C in some form, it will be unable to successfully authenticate using that image data, thus achieving more robust security.

[0184] (9) Alternatively, for example, authentication can be performed by having the user select the background design of card C without using image processing. If the user does not actually hold card C, the correct design cannot be selected, so selecting the background design is also a form of authentication. In this modified example, the display control unit 301 causes the user terminal 30 to display a selection screen for selecting any one of several types of designs.

[0185] Figure 15 This is an example image representing a selection screen. For example... Figure 15 As shown, the selection screen G4 displays an input table f40 for inputting the card number of the card C to be registered, an input table f41 for inputting the validity period of the card C to be registered, and a list l42 of the design of the card C. In this variant example, since no input image is generated, the user manually inputs the card number, etc.

[0186] Multiple design categories can be selectively displayed in list l42. Figure 15 In this example, 120 designs are displayed in list l42, and the user can select any number of designs. Figure 15 As shown, even the presence or absence of markings will result in different patterns. Figure 15 Cards not shown in the list, but which depict cat characters or athletes, may be optionally displayed. List 142 includes not only cards actually issued by the publisher, but also virtual designs.

[0187] In this variation, the input information represents the design type selected in the selection screen G4. The design type can be identified by a unique ID. The input information is the ID representing the design type selected by the user. The registration information represents any one of the multiple design types. Similarly, when card C is issued, the registration information, representing the ID of the design type of card C, is stored as registration information in the card database DB2.

[0188] The authentication unit 102 performs authentication based on the type of design represented by the input information and the type of design represented by the registration information. Authentication succeeds if their types match, and fails if they do not match. That is, authentication succeeds if the ID of the input information and the ID of the registration information match, and fails if they do not match. Furthermore, the user can choose either a background design or a foreground design. Alternatively, the user can choose both a background and a foreground design.

[0189] According to variation (9), by performing authentication based on an input image representing the type of design selected in the selection screen G4 and a registration image representing any one of the multiple types of designs, the security of the authentication process can be effectively improved. For example, since it is not necessary to photograph the card C on the user terminal 30, authentication can be performed even without the photographing unit 36. In addition, since authentication is performed without image processing of the input image, authentication can be completed quickly. By simplifying the authentication process, the processing load on the operator server 10 and the issuer server 20 can be reduced.

[0190] (10) Furthermore, for example, the application of authentication system S in transportation system services has been described, but authentication system S can also be applied to services such as electronic payment services, e-commerce services, electronic ticketing services, registration services, financial services, communication services, or SNS services. In this variant example, the application of authentication system S to electronic payment services will be described.

[0191] In this variation, a credit card will be used as an example of card C. Card C is not limited to credit cards; it can be any card C that can be used in electronic payment services. For example, card C is a cash card, debit card, loyalty card, electronic money card, or other electronic value card C.

[0192] In this variation, the operator is a company providing electronic payment services. The issuer is a company issuing credit cards. Therefore, in this variation, the operator and the issuer are different. The operator and the issuer are interconnected and can send arbitrary data between the operator's server 10 and the issuer's server 20. The operator and the issuer can also be companies within the same group.

[0193] The card information of the issued credit cards is stored in the card database DB2 on the issuer's server 20. For example, the card information includes: credit card number, expiration date, name, and security code. The registration image reflects at least one side of the front and back of the credit card. Each time a credit card is issued, the issuer photographs the credit card to generate a registration image, which is then stored in the card database DB2 along with the card information.

[0194] The user database DB1 of the operator server 10 stores the card information of the credit cards registered in the application. This variant application is an electronic payment application. Electronic payment applications can perform electronic payments through various methods. For example, the user selects the credit card to be used for payment, and the user terminal 30 displays a barcode or QR code, which is then read by a reader in the store, thereby executing the payment using that credit card. Alternatively, for example, payment can be executed using the user-selected credit card by reading the store's barcode or QR code through the camera unit 36 ​​of the user terminal 30. The payment method itself is not limited to these examples, as long as the electronic payment application can execute payments using registered credit cards. For example, it is also possible to execute payments using registered credit cards without using a code.

[0195] To illustrate the process similar to the first embodiment, a user launches an electronic payment application installed on user terminal 30 and takes a picture of their credit card using camera unit 36. User terminal 30 generates an input image showing the photographed credit card and sends it to operator server 10. Operator server 10 forwards the input image to issuing server 20, which performs optical character recognition (OCR) on the input image to obtain the credit card number.

[0196] The issuing server 20 refers to the card database DB2 to obtain the registration image associated with the credit card number. The issuing server 20 compares the input image and the registration image and sends the comparison result to the operator server 10. The operator server 10 performs authentication based on the comparison result. If authentication is successful, the operator server 10 registers the credit card number and other information in the user database DB1.

[0197] Even in this modified example, registration processing based on the same procedure as in the second embodiment can be performed. In this case, a pair of credit card numbers and registration images is stored in the registration image database DB3 of the operator server 10. If the operator server 10 receives an input image, it performs optical character recognition to obtain the credit card number. The operator server 10 refers to the registration image database DB3 to obtain the registration image associated with the credit card number. The operator server 10 performs authentication by comparing the input image and the registration image. If authentication is successful, the operator server 10 registers the credit card number, etc., in the user database DB1.

[0198] According to variation (10), security is improved when registering a credit card in an electronic payment service.

[0199] (11) In addition, variations of the above description can be combined, for example.

[0200] Alternatively, for example, authentication system S can also perform authentication by comparing card information (e.g., validity period and name) obtained through optical character recognition of the input image with card information (e.g., validity period and name) stored in card database DB2. If they match, authentication succeeds. If they do not match, authentication fails. This comparison can be performed by the issuing server 20 as in the first embodiment, or by the operator server 10 as in the second embodiment.

[0201] Alternatively, for example, the authentication system S can also perform authentication based on the input image and registration information in forms other than images. For instance, the registration information could be a label indicating the type of illustration depicted as the background of card C. For example, if the illustration of card C issued by the issuer has 10 variations, the registration information could also indicate one of those variations. In this case, the learning model is a model that labels the input image among the 10 illustrations.

[0202] The authentication system S inputs an input image to a learning model and obtains a label output from the learning model. The card database DB2 stores illustrated novels depicting the background of the user's card C as registration information. The authentication system S determines whether the label output from the learning model matches the label represented by the registration information. If they match, authentication succeeds. If they do not match, authentication fails. This comparison can be performed by the operator server 10 as in the first embodiment, or as in the second embodiment.

[0203] Additionally, card C could be, for example, an insurance card, driver's license, membership card, or student ID. The card C used in authentication may not be a physical card C, but an electronic card C (virtual card C). Furthermore, for example, if the similarity between the input image and the registration image is less than a threshold, the administrator can make a manual judgment. Additionally, for example, if authentication for a card number fails a predetermined number of times, that card number can be restricted to prevent further authentication. In this case, restrictions are placed on registering that card number in the application without the administrator's permission.

[0204] Furthermore, for example, an example of authentication is given when card C is registered in an application, but authentication system S can be applied to authentication in various scenarios. For example, authentication system S can also be applied to scenarios where payment is made using card C. In this case, a user enters the card C used for payment in an e-commerce service and takes a picture of the card C. Authentication system S performs authentication in the same way as in the first or second embodiment. Payment can be made using card C if authentication is successful, and not if authentication fails. In addition, authentication system S can also be applied, for example, to scenarios where card C, equivalent to a certificate such as an ID card, is being authenticated. Authentication system S can also be applied to scenarios where card C, equivalent to an admission ticket in an online exam, is being authenticated.

[0205] Furthermore, for example, the main functions are described as being shared by the operator server 10 and the issuer server 20, but each function can also be implemented by a single computer. Additionally, for example, functions described as being implemented by the operator server 10 can also be implemented by the issuer server 20. Conversely, functions described as being implemented by the issuer server 20 can also be implemented by the operator server 10. Furthermore, for example, each function can also be shared by three or more computers.

Claims

1. An authentication system comprising: an input information acquisition unit that acquires input information input from a user terminal, the input information being related to a feature of a design of a background and a design of a foreground, that is, an appearance, of a card held by a user, in the card; an identification information acquisition unit that acquires identification information that can identify the card; a registration information acquisition unit that acquires registration information related to the feature of the appearance, the registration information being registered in advance in association with the identification information in a server; an authentication unit that performs authentication based on the input information and the registration information, the input information being an input image representing the card, the registration information being a registration image representing the card, the authentication being performed based on a similarity determination with respect to the design of the background and the design of the foreground in the input image and the design of the background and the design of the foreground in the registration image, the similarity determination being implemented by calculating a feature amount of the input image and the registration image based on a learning model. 2.The authentication system according to claim 1, wherein the background is an illustration or a photograph in the card, the authentication unit performs the authentication based on the design of the illustration or the photograph represented by the input information and the design of the illustration or the photograph represented by the registration information. 3.The authentication system according to claim 1, wherein there are multiple kinds of designs of the background in the card of the same kind, the authentication unit performs the authentication based on a kind of the design of the background represented by the input information and a kind of the design of the background represented by the registration information. 4.The authentication system according to claim 1, wherein there are multiple kinds of the design of the foreground in the card of the same kind, the authentication unit performs the authentication based on a kind of the design of the foreground represented by the input information and a kind of the design of the foreground represented by the registration information. 5.The authentication system according to claim 1, wherein the feature of the appearance is a position of the foreground in the card, the authentication unit performs the authentication based on the position of the foreground represented by the input information and the position of the foreground represented by the registration information. 6.The authentication system according to claim 1, wherein the authentication system further comprises a formation determination unit that determines whether paper on which an image of the card is formed is displayed in the input image, the authentication unit further performs the authentication based on a determination result of the formation determination unit. 7.The authentication system according to claim 1, wherein the authentication system further comprises a photographing determination unit that determines whether the input image is generated by a photographing unit of the user terminal, the authentication unit further performs the authentication based on a determination result of the photographing determination unit. 8.The authentication system according to claim 1, wherein the background in the card is any one of multiple kinds of designs, the authentication system further comprises a display control unit that causes the user terminal to display a selection screen for selecting any one of the multiple kinds of designs, ​ The input information indicates a kind of design selected in the selection screen, The registration information indicates any one of the plurality of kinds of design, The authentication unit performs the authentication based on the kind of design indicated by the input information and the kind of design indicated by the registration information.

9. The authentication system according to claim 1, wherein The authentication system includes an operator server corresponding to an operator that provides a service using the card, and an issuer server corresponding to an issuer that issues the card, The operator server includes the authentication unit, The issuer server includes the input information acquisition section, the identification information acquisition unit, the registration information acquisition unit, and a comparison unit that compares the input information and the registration information, The authentication unit of the operator server performs the authentication based on a comparison result of the comparison unit acquired from the operator server.

10. The authentication system according to claim 1, wherein The authentication system includes an operator server corresponding to an operator that provides a service using the card, and an issuer server corresponding to an issuer that issues the card, The registration information is registered in the issuer server, The operator server includes the input information acquisition section, the identification information acquisition unit, the registration information acquisition unit, and the authentication unit, The registration information acquisition unit of the operator server acquires the registration information from the issuer server.

11. The authentication system according to claim 1, wherein The authentication system further includes a registration unit that performs a registration process on the card corresponding to the identification information based on a result of the execution of the authentication.

12. An authentication method comprising: an input information acquisition step of acquiring input information input from a user terminal, the input information being related to a design of a background and a design of a foreground, i.e., a feature of an appearance, of a card held by a user in the card; an identification information acquisition step of acquiring identification information capable of identifying the card; a registration information acquisition step of acquiring registration information related to the feature of the appearance, the registration information being registered in advance in a server in association with the identification information; and an authentication step of performing authentication based on the input information and the registration information, The input information is an input image indicating the card, and the registration information is a registration image indicating the card, The authentication is performed based on a similarity determination with respect to the design of the background and the design of the foreground in the input image and the design of the background and the design of the foreground in the registration image, The similarity determination is realized by calculating a feature amount of the input image and the registration image based on a learning model.

13. A computer-readable recording medium storing a program that causes a computer to function as the following units: an input information acquisition unit that acquires input information input from a user terminal, the input information being related to a design of a background and a design of a foreground, i.e., a feature of an appearance, of a card held by a user in the card; an identification information acquisition unit that acquires identification information capable of identifying the card; a registration information acquisition unit that acquires registration information related to the feature of the appearance, which is registered in advance in a server in association with the identification information; and an authentication unit that performs authentication based on the input information and the registration information, the input information being an input image of the card, and the registration information being a registration image of the card, the authentication being performed based on a similarity determination regarding the design of the background and the design of the foreground in the input image and the design of the background and the design of the foreground in the registration image, the similarity determination being implemented by calculating a feature amount of the input image and the registration image based on a learning model.

Citation Information

Patent Citations

  • IC card authenticity determination system and IC card used in said system

    WO2014016883A1

  • Authentication method and authentication system for logging in to online banks

    CN101795196A

  • Method, device and system for utilizing card characteristics to perform identity verification

    CN105450411A

  • Remote identity authentication system based on audio and video

    CN107995207A

  • Image forming apparatus

    CN109587366A