Terminal, Terminal Control Method, and Program
Patent Information
- Application Number
- JP2022180719
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-11-11
- Publication Date
- 2025-07-24
AI Technical Summary
Users are burdened with the repetitive task of registering their biometric information for multiple biometric authentication services provided by different service providers, leading to inefficiency and inconvenience.
A system where a user's original biometric information is stored on a terminal and transmitted to a management server, which then distributes it to selected service providers to generate authentication information, reducing the need for repeated registrations.
This approach significantly reduces the burden on users by allowing them to register their biometric information once, enabling seamless access to multiple services without repeated registrations, while also minimizing the risk of information leakage and service provider dependency on specific authentication technologies.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a system, a terminal, a control method for a terminal, and a storage medium. [Background technology]
[0002] In recent years, services using biometric authentication have started to become widespread.
[0003] Patent Document 1 states that the device achieves both safety and convenience in electronic money payment for purchasing goods and services. The biometric authentication device described in Patent Document 1 acquires a CID and a facial image that identifies a user. The biometric authentication device downloads facial images of shop attendants in advance, and authenticates the user by comparing the acquired facial image with the facial images. If the authentication is successful, the biometric authentication device requests the payment device to settle the price of the goods to be purchased by the user, and permits the purchase of the goods when the payment device permits the payment. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2019-067075 A Summary of the Invention [Problem to be solved by the invention]
[0005] As described above, various services using biometric authentication have begun to be provided. In a system using biometric authentication, a terminal for biometric authentication is installed in a retail store or the like, and biometric information is transmitted from the terminal to a server. The server executes a matching process using the acquired biometric information and biometric information stored in a database to identify the user.
[0006] Before receiving a service using biometric authentication, a user must register his / her biometric information (e.g., a facial image) on a server. In order to receive services from multiple service providers (e.g., retailers, transportation companies), the user must register his / her biometric information for each service provider.
[0007] Specifically, every time a user desires to receive a service from a service provider, the user must obtain biometric information (e.g., a face image) by, for example, taking a selfie, and register the obtained biometric information in a server. Such repeated registration procedures are a heavy burden on the user.
[0008] A primary object of the present invention is to provide a system, a terminal, a control method for a terminal, and a storage medium that contribute to reducing the burden on a user who uses multiple biometric authentication services. [Means for solving the problem]
[0009] According to a first aspect of the present invention, there is provided a system including a plurality of first servers operated by a plurality of service providers each providing a service using biometric authentication, a second server managing the biometric authentication of each of the plurality of service providers, and a terminal storing original biometric information that is the original of authentication information used for the biometric authentication, wherein the terminal transmits the original biometric information to the second server in response to a request from the second server, the second server transmits the original biometric information to the first server of a service provider selected by a user from among the plurality of service providers, and the first server generates authentication information for registration from the original biometric information.
[0010] According to a second aspect of the present invention, there is provided a terminal including: a memory unit that stores original biometric information that is the original of authentication information used for biometric authentication; and a transmission unit that transmits the original biometric information to a management server in response to a request from the management server that provides services using biometric authentication and manages the biometric authentication of each of a plurality of service providers.
[0011] According to a third aspect of the present invention, there is provided a method for controlling a terminal, which stores original biometric information serving as an original of authentication information used for biometric authentication in a terminal, provides a service using biometric authentication, manages the biometric authentication of each of a plurality of service providers, and transmits the original biometric information to a management server in response to a request from the management server.
[0012] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on a terminal to execute a process of storing original biometric information that serves as the original of authentication information used for biometric authentication, and a process of transmitting the original biometric information to a management server in response to a request from the management server, which manages the biometric authentication of each of a plurality of service providers that provide services using biometric authentication. Effect of the Invention
[0013] According to each aspect of the present invention, a system, a terminal, a control method for a terminal, and a storage medium are provided that contribute to reducing the burden on a user who uses multiple biometric authentication services. Note that the effects of the present invention are not limited to the above. The present invention may achieve other effects instead of or in addition to the effects. [Brief description of the drawings]
[0014] [Figure 1] FIG. 1 is a diagram for explaining an overview of an embodiment. [Diagram 2] FIG. 2 is a flowchart illustrating an example of the operation of an embodiment. [Diagram 3] FIG. 3 is a diagram illustrating an example of a schematic configuration of an authentication system according to the first embodiment. [Figure 4] FIG. 4 is a diagram for explaining the operation of the authentication system according to the first embodiment. [Diagram 5] FIG. 5 is a diagram showing an example of a display on the terminal according to the first embodiment. [Figure 6]FIG. 6 is a diagram for explaining the operation of the authentication system according to the first embodiment. [Figure 7] FIG. 7 is a diagram showing an example of a display on the terminal according to the first embodiment. [Figure 8] FIG. 8 is a diagram for explaining the operation of the authentication system according to the first embodiment. [Figure 9] FIG. 9 is a diagram illustrating an example of a processing configuration of the management server according to the first embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of the account management database according to the first embodiment. [Figure 11] FIG. 11 is a flowchart illustrating an example of the operation of the management server according to the first embodiment. [Figure 12] FIG. 12 is a diagram illustrating an example of a processing configuration of the service server according to the first embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of the user management database according to the first embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of a processing configuration of the authentication terminal according to the first embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment. [Figure 16] FIG. 16 is a diagram showing an example of a display on the terminal according to the first embodiment. [Figure 17] FIG. 17 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment. [Figure 18] FIG. 18 is a diagram showing an example of a display on a terminal according to a modification of the first embodiment. [Figure 19] FIG. 19 is a diagram showing an example of a display on a terminal according to a modification of the first embodiment. [Figure 20] FIG. 20 is a diagram illustrating an example of a hardware configuration of a management server according to the present disclosure. [Figure 21] FIG. 21 is a diagram illustrating an example of a processing configuration of a management server according to a modification of the present disclosure. [Figure 22]FIG. 22 is a diagram showing an example of a display on a terminal according to a modification of the present disclosure. [Diagram 23] FIG. 23 is a diagram showing an example of a display on a terminal according to a modification of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0015] First, an outline of one embodiment will be described. The reference numerals in the drawings are added to each element for convenience as an example to aid in understanding, and the description of the outline is not intended to be limiting. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units rather than hardware units. The connection lines between the blocks in each drawing include both bidirectional and unidirectional. The unidirectional arrows are used to diagrammatically indicate the flow of the main signal (data) and do not exclude bidirectionality. In this specification and the drawings, elements that can be similarly described may be given the same reference numerals to avoid redundant description.
[0016] The system according to an embodiment includes a plurality of first servers 101, a second server 102, and a terminal 103 (see FIG. 1). The plurality of first servers 101 are operated by a plurality of service providers that provide services using biometric authentication. The second server 102 manages the biometric authentication of each of the plurality of service providers. The terminal 103 stores original biometric information that is the original of authentication information used for biometric authentication. The terminal 103 transmits the original biometric information to the second server 102 in response to a request from the second server 102 (step S1 in FIG. 2). The second server 102 transmits the original biometric information to the first server 101 of the service provider selected by the user from among the plurality of service providers (step S2). The first server 101 generates authentication information for registration from the original biometric information (step S3).
[0017] In the above system, the biometric information of the user (biometric information serving as the original of authentication information) is stored in the terminal 103 of the user. When the user desires to receive a biometric authentication service and selects a service provider, the original biometric information is provided from the terminal 103 via the second server 102 to the first server 101 of the service provider that requires the original biometric information. That is, if the user registers the original biometric information (e.g., a face image) in the terminal 103, the user does not need to obtain the original biometric information every time the user selects (adds) a biometric authentication service. In addition, the original biometric information (e.g., a face image) is transmitted from the second server 102 to the first server 101, and the first server 101 generates authentication information (feature amount), so that there are cases where consent does not need to be obtained every time authentication is performed when the user uses a service. As a result, the burden on the user who uses multiple biometric authentication services is reduced.
[0018] Specific embodiments will be described in more detail below with reference to the drawings.
[0019] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.
[0020] [System configuration] Fig. 3 is a diagram showing an example of a schematic configuration of an authentication system (information processing system) according to the first embodiment. As shown in Fig. 3, the authentication system includes a plurality of service providers A to C and a management center.
[0021] A service provider is a business entity that provides a service to a user using biometric authentication. The authentication system according to the present disclosure is premised on service providers belonging to various business types and industries providing services using biometric authentication.
[0022] Examples of service providers include operators of transportation such as railways and airplanes, operators providing accommodation services, operators of retail stores, operators providing events such as concerts, operators providing financial services, educational operators, operators where users work, etc. In addition, service providers are not limited to private operators such as retail stores. Public institutions such as local governments may also be service providers.
[0023] The management center manages the biometric authentication of each of the multiple service providers. Businesses (service providers) that wish to provide services using biometric authentication must enter into a contract with the company or organization that operates the management center.
[0024] The management center includes a management server 10. The management server 10 realizes the main functions of the management center. The management server 10 may be installed in the building of the management center, or may be a server installed on a network (cloud).
[0025] As described above, a service provider provides a user with a service that uses biometric authentication. For example, a payment procedure at a retail store or the like is performed using biometric authentication. Other examples of services that use biometric authentication include ticket confirmation at an event venue, check-in procedures at a hotel, attendance management at an office, and immigration procedures at an airport.
[0026] 3, each service provider includes a service server 20 and at least one authentication terminal 30. The devices included in the service provider (service server 20, authentication terminal 30) are connected to each other so that they can communicate with each other. Specifically, the service server 20 and the authentication terminal 30 are connected by a wired or wireless communication means.
[0027] The service server 20 is connected to the management server 10 via a network. The service server 20 may be installed in the premises of the service provider, or may be installed on the cloud.
[0028] The service server 20 stores information required when providing a service to a user. Specifically, the service server 20 stores business information required when each service provider provides a service using biometric authentication, and information required for biometric authentication. The service server 20 uses a user management database to store business information including the user's name, date of birth, etc., and information required for biometric authentication. The user management database will be described in detail later.
[0029] For example, the service server 20 of a retailer stores account information required for payment. The service server 20 of a business hosting an event stores ticket information regarding tickets purchased by users. Or the service server 20 of a transportation business stores information regarding users' commuter passes (for example, an ID for identifying the commuter pass). Or the service server 20 that manages employee attendance stores employee numbers, etc.
[0030] The information necessary for biometric authentication stored in the service server 20 will be described in detail later.
[0031] The authentication terminal 30 is a device that serves as an interface for users who receive services. The authentication terminal 30 is installed at the service providing location of each service provider. More specifically, the authentication terminal 30 is installed in a store or the like that the user actually visits.
[0032] The authentication terminal 30 has functions and forms according to the type of business of the service provider. For example, a tablet-type terminal can be used as the authentication terminal 30 installed at a service provider that provides a payment service. Alternatively, the authentication terminal 30 installed at an event venue can be a gate device equipped with a gate that restricts the passage of users.
[0033] 3 is merely an example and is not intended to limit the configuration of the authentication system disclosed herein. For example, the management center may include two or more management servers 10. Also, the service provider may include at least one or more service servers 20 and at least one or more authentication terminals 30.
[0034] [General operation] Next, the general operation of the authentication system according to the first embodiment will be described.
[0035] <Create account> A user who wishes to receive a service from a service provider included in the authentication system must create an account in the system. Specifically, the user operates a terminal 40 owned by the user to access the management server 10 (see FIG. 4).
[0036] The user inputs login information (e.g., login ID, password), name, date of birth, etc., on a WEB page provided by the management server 10. When the management server 10 acquires the login information, etc., it generates a user ID for identifying the user. The management server 10 associates the generated user ID with the login information, etc., and stores them in an account management database. The account management database will be described in detail later.
[0037] <Biometric information registration> A user who wishes to receive services using biometric authentication needs to register his / her own biometric information in the terminal 40 .
[0038] Here, to perform biometric authentication, it is necessary to pre-register authentication information generated from biometric information. For example, when performing face authentication, it is necessary to pre-register features (feature vectors) generated from a face image as authentication information. Or, when performing fingerprint authentication, it is necessary to pre-register features generated from a fingerprint image as authentication information.
[0039] In the following description, original (basic) information for generating authentication information, such as a face image or a fingerprint image, is referred to as "original biometric information." Also, features generated from the original biometric information and registered in advance are referred to as "registered authentication information."
[0040] After completing user registration, the user must register original biometric information (e.g., a facial image) in the terminal 40 that the user possesses. The terminal 40 acquires the original biometric information using a GUI (Graphical User Interface) or the like. The terminal 40 stores the acquired original biometric information (e.g., a facial image) internally. In this manner, the terminal 40 stores the original biometric information that serves as the original of authentication information used for biometric authentication.
[0041] <Select a service> A user who has completed system registration (account creation) and registration of original biometric information selects, on a portal site provided by the management server 10, a service provider from which the user wishes to receive biometric authentication services.
[0042] Here, the management server 10 stores information on the service providers participating in the authentication system. For example, the management server 10 stores the name, type of business, location, etc. of the service provider. The management server 10 holds information on each of a plurality of service providers and enables the user to select a service provider.
[0043] When a user operates terminal 40 to perform a predetermined operation on the portal site, management server 10 displays on terminal 40 a GUI or the like that enables the user to select a desired service (service provider).
[0044] For example, the management server 10 acquires a service (biometric authentication service) desired by the user using a GUI as shown in FIG.
[0045] <User registration> When the service provider selected by the user is acquired, the management server 10 requests the original biometric information to be provided from the terminal 40. Specifically, the management server 10 transmits an original provision request to the terminal 40 (see step S01 in FIG. 6).
[0046] When receiving the original provision request, the terminal 40 obtains consent to provide the user's original biometric information (e.g., a facial image) to the service provider. For example, the terminal 40 obtains the user's prior consent (opt-in) to provide the original biometric information (e.g., a facial image) using a GUI as shown in Fig. 7. That is, the consent by the user is prior consent (opt-in) to providing the user's original biometric information (e.g., a facial image) to a business providing the desired service when applying for the desired service.
[0047] When the consent of the user is obtained, the terminal 40 transmits the original biometric information (for example, a face image) of the user to the management server 10 (step S02 in FIG. 6).
[0048] The management server 10 notifies the service provider corresponding to the service selected by the user of the acquired original biometric information, personal identification information, etc. The personal identification information is information for identifying the user. Examples of the personal identification information include the user's name, or a combination of the user's name and date of birth.
[0049] The management server 10 transmits a "user registration request" including the original biometric information and the individual identification information to the service server 20 of the service provider selected by the user (step S03).
[0050] In this way, the user provides the original biometric information (master data of the biometric information) stored in the terminal 40 such as a smartphone to the service provider via the management server 10 in the management center. At that time, the terminal 40 continues to internally hold the original biometric information (master data) of the user.
[0051] The management server 10 deletes the original biometric information (for example, a face image) when the management server 10 transmits a user registration request to the service server 20 or when the management server 10 receives a response to the request.
[0052] When receiving the user registration request, the service server 20 identifies the user who wishes to receive the biometric authentication service. The service server 20 searches the user management database using the acquired personal identification information (e.g., name, etc.) as a key, and identifies the corresponding entry (user).
[0053] When the user is identified, the service server 20 generates registered authentication information from the acquired original biometric information. For example, when the service server 20 acquires a face image as the original biometric information, the service server 20 generates a feature amount (feature vector) corresponding to a face recognition algorithm adopted by the service server 20 as registered authentication information.
[0054] In this way, the service server 20 of each service provider calculates registration authentication information from the user's original biometric information (e.g., face image) using a face recognition algorithm (face recognition engine, face recognition program) adopted by each service provider.
[0055] When the registered authentication information is generated, the service server 20 stores the generated registered authentication information (for example, feature amounts) in the user management database.
[0056] When the service server 20 generates the registered authentication information (eg, feature amount), the service server 20 deletes the original biometric information acquired from the management server 10.
[0057] When the user registration is normally completed, the service server 20 transmits an affirmative response indicating that to the management server 10 (step S04).
[0058] In this way, the authentication system includes a plurality of service servers 20 (first servers) operated by a plurality of service providers that provide services using biometric authentication. Furthermore, the authentication system includes a management server 10 (second server) that manages the biometric authentication of each of the plurality of service providers. A terminal 40 carried by a user transmits original biometric information to the management server 10 in response to a request from the management server 10. The management server 10 transmits the acquired original biometric information to a service server 20 of a service provider selected by the user from among the plurality of service providers. The service server 20 generates authentication information for registration (registration authentication information) from the original biometric information.
[0059] <Provision of services> After completing the selection of the service, the user visits the service provider to receive the service. For example, the user visits a facility, store, etc., such as a retail store or an event venue, where the user can receive the service he or she selected.
[0060] The authentication terminal 30 acquires biometric information of a user (person to be authenticated) who receives the service. For example, the authentication terminal 30 photographs the person to be authenticated and acquires biometric information (facial image) corresponding to the original biometric information. The authentication terminal 30 transmits an authentication request including the acquired facial image to the service server 20 (see FIG. 8). If necessary, the authentication terminal 30 transmits other information (e.g., payment information such as the price of a purchased item) together with the biometric information to the service server 20.
[0061] The service server 20 generates authentication information for matching from the acquired face image. For example, the service server 20 generates features from the face image for matching. The service server 20 executes a matching process (1:N matching; N is a positive integer, the same applies below) using the generated authentication information for matching (hereinafter, referred to as matching authentication information) and registered authentication information registered in the user management database.
[0062] The service server 20 identifies the user (person to be authenticated) registered in the user management database through a matching process.
[0063] The service server 20 authenticates the identified user using the business information of the user. For example, the service server 20 determines that the authentication is successful if the payment is successfully made using the account information of the identified user. Alternatively, the service server 20 determines that the authentication is successful if the ticket associated with the identified user is valid.
[0064] The service server 20 transmits the authentication result (authentication success, authentication failure) to the authentication terminal 30.
[0065] The authentication terminal 30 executes a process according to the authentication result. For example, when the authentication success is received, the authentication terminal 30 installed in a retail store notifies the authenticated person that the payment for the product has been completed. Alternatively, when the authentication success is received, the authentication terminal 30 installed in an event venue allows the authenticated person to pass through the gate.
[0066] In this way, among the multiple authentication terminals 30 included in the authentication system, the authentication terminal 30 installed at the service provision location visited by the person to be authenticated transmits an authentication request including the biometric information of the person to be authenticated to the service server 20 corresponding to the service provision location visited by the person to be authenticated. The service server 20 that receives the authentication request generates authentication information for matching from the biometric information included in the authentication request, and performs authentication processing using the generated authentication information for matching and authentication information for registration. More specifically, the service server 20 that receives the authentication request determines that the authentication is successful when the business information of the person to be authenticated identified by the matching processing using the authentication information for registration and authentication information for matching is valid.
[0067] Next, each device included in the authentication system according to the first embodiment will be described in detail.
[0068] [Management Server] Fig. 9 is a diagram showing an example of a processing configuration (processing module) of the management server 10 according to the first embodiment. Referring to Fig. 9, the management server 10 includes a communication control unit 201, an account management unit 202, a business operator management unit 203, a service selection control unit 204, and a storage unit 205.
[0069] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the service server 20. The communication control unit 201 also transmits data to the service server 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, the other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0070] The account management unit 202 is a means for managing a user's account. When a user operates the terminal 40 to access a specific homepage or the like, the account management unit 202 acquires information necessary to create an account for the user.
[0071] Specifically, the account management unit 202 acquires personal information such as login information, name, and date of birth. Upon acquiring the login information, the account management unit 202 generates a user ID for identifying the user. The user ID may be any information that can uniquely identify the user. For example, the account management unit 202 may assign a unique value each time an account is generated, and use this as the user ID.
[0072] The account management unit 202 stores the generated user ID, login information, name, etc. in an account management database in association with each other (see FIG. 10). Note that the account management database shown in FIG. 10 is merely an example, and is not intended to limit the items to be stored. For example, the account generation date and time, etc. may be stored in the account management database.
[0073] The account management unit 202 acquires login information for logging in to a predetermined portal site from the user's terminal 40. The account management unit 202 performs authentication using the login information.
[0074] The business management unit 203 is a means for managing service providers (service businesses) participating in the authentication system. The business management unit 203 acquires business information (service provider name, business type, location, address of service server 20, etc.) to be registered in the system from staff of each service provider.
[0075] For example, the business management unit 203 may provide each service provider with an interface for inputting business information, etc. Alternatively, each service provider may send a USB (Universal Serial Bus) memory or the like in which the business information, etc. is stored to the management center. The business management unit 203 may acquire the business information, etc. from staff, etc. of the management center.
[0076] The business management unit 203 generates an ID (business ID) for the service provider from which the business information, etc. have been acquired. The business management unit 203 stores the generated business ID and the acquired business information, etc. in association with each other.
[0077] The service selection control unit 204 is a means for controlling the selection of a biometric authentication service (service provider) by a user.
[0078] When a user operates terminal 40 to log in to a portal site and performs a predetermined operation on the portal site, service selection control unit 204 displays a GUI or the like that enables the user to select a desired service on terminal 40. For example, service selection control unit 204 displays a GUI such as that shown in FIG.
[0079] The service selection control unit 204 uses the business information acquired by the business management unit 203 to display a GUI such as that shown in Fig. 5. The service selection control unit 204 refers to the business information and displays on the terminal 40 information on service providers who have concluded contracts with the management center (a list of service providers).
[0080] When providing the user with information about service providers, the service selection control unit 204 may also provide the user with more detailed information about each service provider (for example, type of business, services provided, store location, etc.).
[0081] When the user acquires the service provider selected by the user, the service selection control unit 204 transmits an “original provision request” to the terminal 40 carried by the user. The service selection control unit 204 receives the original biometric information (e.g., a face image) of the user from the terminal 40.
[0082] The service selection control unit 204 transmits a user registration request including the user's user ID, the acquired original biometric information, the individual identification information, and the like, to the service server 20 of the service provider corresponding to the service selected by the user.
[0083] The service selection control unit 204 receives a response (positive response, negative response) to the user registration request.
[0084] If an affirmative response (user registration successful) is received, the service selection control unit 204 registers the business ID of the service provider selected by the user in the account management database. That is, the service selection control unit 204 reflects the service selection by the user in the account management database. Also, if an affirmative response is received, the service selection control unit 204 notifies the user that the user registration was successful.
[0085] If a negative response (user registration failure) is received, the service selection control unit 204 notifies the user accordingly.
[0086] The storage unit 205 is a means for storing information necessary for the operation of the management server 10 .
[0087] The above-described operation of the management server 10 regarding user registration can be summarized as shown in the flowchart of FIG.
[0088] The management server 10 acquires the biometric authentication service (service provider) that the user desires to receive (acquire selected service; step S101).
[0089] The management server 10 acquires the original biometric information by transmitting an "original provision request" to the terminal 40 held by the user (step S102). At that time, the terminal 40 acquires the consent of the user (consent to the original biometric information being provided to the service provider).
[0090] The management server 10 transmits a user registration request including the acquired original biometric information (for example, a face image) and individual identification information (for example, a name) to the service server 20 (step S103).
[0091] The management server 10 receives a response to the user registration request from the service server 20 (step S104).
[0092] The management server 10 notifies the user of the success or failure of the user registration (step S105).
[0093] [Service Server] Fig. 12 is a diagram showing an example of a processing configuration (processing module) of the service server 20 according to the first embodiment. Referring to Fig. 12, the service server 20 includes a communication control unit 301, a business information management unit 302, a user registration control unit 303, an authentication unit 304, and a storage unit 305.
[0094] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the management server 10. The communication control unit 301 also transmits data to the management server 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, the other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0095] The business information management unit 302 is a means for managing and controlling business information required by the service provider to provide the service.
[0096] The business information management unit 302 acquires business information necessary for the provision of its services by using any means. For example, the business information management unit 302 acquires information specific to the provision of its services, in addition to information such as the user's name and date of birth. For example, the business information management unit 302 of a retailer acquires credit card information and account information such as a bank account. The business information management unit 302 of an event organizer acquires information on tickets purchased by users (ticket number, event date, event location, etc.).
[0097] The business information management unit 302 may acquire the business information from staff of the service provider, or may acquire the information directly from the user using a means such as a homepage. That is, the user may operate the terminal 40 to individually access the service server 20 of each service provider and register the business information required for the service provider to provide the service in the service server 20. The business information management unit 302 also acquires information required for the service provision depending on the time of service provision. For example, during an infectious disease epidemic, the business information management unit 302 may acquire a vaccination certificate or a negative test certificate related to the infectious disease as business information.
[0098] The business information management unit 302 manages the acquired business information using a user management database.
[0099] A detailed description of the business information management unit 302 will be omitted here because details of business information for individual services and the method of acquiring the same are different from the gist of the disclosure of this application.
[0100] The user registration control unit 303 is a unit for controlling the registration of users who are to be provided with a biometric authentication service by a service provider. The user registration control unit 303 processes a user registration request received from the management server 10.
[0101] When a user registration request is received, the user registration control unit 303 searches the user management database using the individual identification information (for example, name) included in the user registration request as a key, and identifies the corresponding user (entry).
[0102] If the corresponding user is registered in the user management database, the user registration control unit 303 generates registration authentication information from the acquired original biometric information (e.g., a face image). For example, when a face image is acquired, the user registration control unit 303 generates a feature amount (feature vector) corresponding to a face recognition algorithm adopted by the company as the registration authentication information.
[0103] Since existing technology can be used for the process of generating the feature amounts, detailed description thereof will be omitted. For example, the user registration control unit 303 extracts the eyes, nose, mouth, etc. as feature points from the face image. After that, the user registration control unit 303 calculates the position of each feature point and the distance between each feature point as feature amounts, and generates a feature vector (vector information that characterizes the face image) consisting of multiple feature amounts.
[0104] When the registered authentication information (e.g., features) is generated, the user registration control unit 303 stores the user's user ID, the generated registered authentication information (features), and the business information in association with each other in the user management database (see FIG. 13).
[0105] It should be noted that the user management database shown in FIG. 13 is an example and is not intended to limit the items to be stored. For example, the date and time of user registration may be registered in the user management database. The user ID shown in FIG. 13 is an ID generated by the management server 10. The business information management unit 302 may generate an ID for managing users independently in-house and store the generated ID in the user management database.
[0106] When the user registration is completed normally, the user registration control unit 303 transmits an affirmative response to the management server 10 indicating that the user registration was successful.
[0107] If the user registration is not normally completed, the user registration control unit 303 transmits a negative response indicating that the user registration has failed to the management server 10. For example, a negative response is transmitted to the management server 10 when the personal identification information (e.g., name) received from the management server 10 is not registered in the user management database or when valid registration authentication information cannot be generated from the original biometric information.
[0108] The authentication unit 304 is a means for performing biometric authentication of the person to be authenticated. The authentication unit 304 receives an authentication request from the authentication terminal 30. The authentication unit 304 extracts biometric information (for example, a face image) from the authentication request.
[0109] The authentication unit 304 generates matching authentication information from the acquired biometric information. For example, when a face image is acquired, the authentication unit 304 generates features corresponding to the face recognition algorithm adopted by the company. The authentication unit 304 executes matching processing using the generated matching authentication information (feature) and registered authentication information (feature) registered in the user management database.
[0110] Specifically, the authentication unit 304 calculates the similarity between the feature amount (feature vector) to be matched and each of the multiple feature amounts on the registration side. The similarity can be calculated using a chi-square distance, Euclidean distance, or the like. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0111] If there is no feature whose similarity is equal to or greater than a predetermined value, the authentication unit 304 sets the authentication result to "authentication failure."
[0112] If there is a feature whose similarity is equal to or greater than a predetermined value, the authentication unit 304 identifies an entry (user) having the most similar feature (registered authentication information) from among multiple entries registered in the user management database. The authentication unit 304 authenticates the person to be authenticated using the business information of the identified user.
[0113] For example, the authentication unit 304 of the retailer determines that the authentication is successful if the payment for the product is successfully made using the payment information acquired from the authentication terminal 30 and the account information registered in the user management database. On the other hand, the authentication unit 304 determines that the authentication is unsuccessful if the payment for the product fails.
[0114] Alternatively, the authentication unit 304 of the event organizer determines that the authentication was successful if the ticket information of the person to be authenticated registered in the user management database is valid. On the other hand, the authentication unit 304 determines that the authentication was unsuccessful if the ticket information of the person to be authenticated registered in the user management database is invalid.
[0115] Note that detailed explanations regarding authentication processing using business information in each service provider will be omitted, since processing specific to each service provider is outside the scope of the present disclosure.
[0116] The authentication unit 304 transmits the authentication result (authentication success, authentication failure) to the authentication terminal 30.
[0117] The storage unit 305 is a means for storing information necessary for the operation of the service server 20 .
[0118] [Authentication device] Fig. 14 is a diagram showing an example of a processing configuration (processing module) of the authentication terminal 30 according to the first embodiment. Referring to Fig. 14, the authentication terminal 30 includes a communication control unit 401, a biometric information acquisition unit 402, an authentication request unit 403, a function realization unit 404, and a storage unit 405.
[0119] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the service server 20. The communication control unit 401 also transmits data to the service server 20. The communication control unit 401 passes the data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, the other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0120] The biometric information acquisition unit 402 is a means for controlling a camera and acquiring biometric information (e.g., a face image) of a person to be authenticated. The biometric information acquisition unit 402 captures an image in front of the device periodically or at a predetermined timing. The biometric information acquisition unit 402 determines whether or not the acquired image contains a human face image, and if a face image is included, extracts the face image from the acquired image data.
[0121] Since existing technologies can be used for the facial image detection process and facial image extraction process by the biometric information acquisition unit 402, detailed explanations will be omitted. For example, the biometric information acquisition unit 402 may extract a facial image (face region) from image data using a learning model learned by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 402 may extract a facial image using a method such as template matching.
[0122] The biometric information acquisition unit 402 passes the extracted face image to the authentication request unit 403 .
[0123] The authentication request unit 403 is a means for requesting authentication of the person to be authenticated to the service server 20. When authentication of the person to be authenticated becomes necessary, the authentication request unit 403 transmits an authentication request including biometric information of the person to be authenticated (the user in front of the authentication terminal 30) to the service server 20.
[0124] The authentication request unit 403 receives an authentication result (authentication success, authentication failure) from the service server 20. The authentication request unit 403 passes the received authentication result to the function realization unit 404.
[0125] The function realization unit 404 is a means for realizing the functions assigned to the authentication terminal 30. For example, when the function realization unit 404 of the authentication terminal 30 installed at a retailer receives a notification of successful authentication, it notifies the person to be authenticated that payment has been completed. Alternatively, when the function realization unit 404 of the authentication terminal 30 installed at an event venue receives a notification of successful authentication, it opens the gate and allows the person to be authenticated to enter.
[0126] A detailed description of the function realization unit 404 included in the authentication terminal 30 of each service provider will be omitted because the realization of the functions of the authentication terminal 30 by the function realization unit 404 is different from the gist of the disclosure of this application.
[0127] The storage unit 405 is a means for storing information necessary for the operation of the authentication terminal 30 .
[0128] [Device] Fig. 15 is a diagram showing an example of a processing configuration (processing module) of the terminal 40 according to the first embodiment. Referring to Fig. 15, the terminal 40 includes a communication control unit 501, an account creation control unit 502, an original information acquisition unit 503, a service selection unit 504, and a storage unit 505.
[0129] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the management server 10. The communication control unit 501 also transmits data to the management server 10. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, the other processing modules transmit and receive data to and from other devices via the communication control unit 501. The communication control unit 501 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0130] The account creation control unit 502 is a means for controlling the creation of an account by a user. The account creation control unit 502 accesses a predetermined web page or the like provided by the management server 10 in response to an operation by the user.
[0131] The account creation control unit 502 inputs login information, name, date of birth, etc., into the web page in response to a user's operation.
[0132] The original information acquiring unit 503 is a means for acquiring biometric information of a user (original biometric information). The original information acquiring unit 503 displays a GUI or the like for acquiring original biometric information (e.g., a face image) in response to an operation by a user. For example, the original information acquiring unit 503 acquires the original biometric information using a GUI as shown in FIG. 16.
[0133] The original information acquiring unit 503 stores the acquired original biometric information (e.g., a face image) in the storage unit 505. At this time, the original information acquiring unit 503 may encrypt, code, or the like the acquired original biometric information, and store the encrypted original biometric information in the storage unit 505. That is, the terminal 40 held by the user may hold the encrypted original biometric information. The encrypted original biometric information may be decrypted when the original biometric information is transmitted to the management server 10. Alternatively, information for decrypting the encrypted original biometric information (e.g., a common key) may be shared between the terminal 40 and the management server 10, and the management server 10 may decrypt the encrypted original biometric information.
[0134] In principle, the terminal 40 does not delete (discard) the original biometric information (e.g., face image) of the user. That is, the terminal 40 does not delete the original biometric information stored in the storage unit 505 unless there is a clear instruction from the user.
[0135] The service selection unit 504 is a means for enabling a user to select a biometric authentication service. The service selection unit 504 logs in to a portal site provided by the management server 10 in response to an operation by the user. The service selection unit 504 transmits information on a service provider selected by the user using a GUI provided by the management server 10 to the management server 10.
[0136] The service selection unit 504 receives an original provision request from the management server 10. Upon receiving the request, the service selection unit 504 acquires the user's consent to providing the original biometric information (e.g., a facial image) stored in the own device to the service provider. For example, the service selection unit 504 acquires whether or not the original biometric information (e.g., a facial image) can be provided using a GUI as shown in FIG. 7.
[0137] When the consent of the user is obtained, the service selection unit 504 transmits the original biometric information to the management server 10 .
[0138] The storage unit 505 is a means for storing information necessary for the operation of the terminal 40 .
[0139] [System Operation] Next, the operation of the authentication system according to the first embodiment will be described. Note that the description of the operation related to the account generation etc. will be omitted. Fig. 17 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment.
[0140] The terminal 40 transmits information about the service selected by the user (information about the service provider from which the user wishes to receive biometric authentication service) to the management server 10 (transmitting service information; step S10).
[0141] When the user selects a service that he / she wishes to receive, the management server 10 transmits an original provision request to the terminal 40 of the user (step S11). That is, after the user selects a service provider, the management server 10 requests the terminal 40 possessed by the user to provide the original biometric information.
[0142] The terminal 40 that has received the request to provide the original obtains consent from the user before providing the original biometric information (step S12).
[0143] When consent of the user is obtained, the terminal 40 transmits the original biometric information (e.g., a face image) to the management server 10 (step S13). That is, when consent of the user to the provision of the original biometric information to the service provider is obtained, the terminal 40 carried by the user transmits the original biometric information to the management server 10.
[0144] The management server 10 transmits a user registration request including the acquired original biometric information, the user's user ID, individual identification information, and the like, to the service server 20 of the service provider selected by the user (step S14).
[0145] The service server 20 generates authentication information for registration (registration authentication information) from the acquired original biometric information (step S15). The generated registration authentication information is registered in the user management database.
[0146] Next, a modification of the first embodiment will be described.
[0147] <Variation 1> The service server 20 may acquire information necessary for authenticating an authenticated person from the terminal 40 of the authenticated person. For example, if confirmation of an attendee's health information (whether or not they have been vaccinated against infectious diseases, proof of negative test) is required when entering an event venue, the service server 20 may acquire the health information from the terminal 40 via the authentication terminal 30. Alternatively, the service server 20 may acquire ticket information and business information necessary for product payment via the authentication terminal 30, or may acquire such business information via the terminal 40 and the management server 10.
[0148] In this case, the authentication terminal 30 transmits a "request for providing associated information" to the terminal 40. In response to receiving the request for providing associated information, the terminal 40 transmits information specified by the authentication terminal 30 (for example, a vaccination certificate or a negative test certificate) to the authentication terminal 30.
[0149] The authentication terminal 30 transmits the acquired vaccination certificate and the like to the service server 20 together with the biometric information of the person to be authenticated.
[0150] The service server 20 authenticates the person to be authenticated using the person's business information (e.g., ticket information) and the acquired vaccination certificate, etc. For example, the service server 20 determines that the authentication is successful when the person to be authenticated has purchased a valid ticket and the vaccination certificate is valid.
[0151] In this manner, service server 20 may authenticate the person to be authenticated using associated information acquired from terminal 40 of the person to be authenticated.
[0152] <Variation 2> The service provider (service server 20) may store the registration authentication information temporarily or permanently if explicit consent is obtained from the user.
[0153] For example, when selecting a service, the user may instruct the service provider on how the service provider should handle the registered authentication information, etc. Specifically, when the user selects a service provider, the terminal 40 may display a GUI or the like inquiring about "whether or not to retain the registered authentication information" (see FIG. 18). Alternatively, the terminal 40 may display a GUI or the like inquiring about the period or deadline for which the service provider can retain the registered authentication information.
[0154] An instruction regarding the handling of the user's authentication information is sent together with the user registration request to the service server 20. The service server 20 determines how to handle the registered authentication information according to the instruction.
[0155] Furthermore, the terminal 40 may make suggestions regarding the handling of the registered authentication information, etc., for the convenience of the user. For example, for procedures such as hotel check-in procedures, entry to an event venue, and boarding procedures for an airplane, in which the business information is no longer necessary once the procedure is completed, the terminal 40 suggests to the user that the registered authentication information be deleted. In contrast, for office attendance management, the same business information is used repeatedly. In this case, the terminal 40 suggests to the user that at least the registered authentication information be left in the service server 20.
[0156] In this way, depending on the type and business condition of the service provider, the registered authentication information may be retained in the service server 20, or may be deleted upon completion of the authentication process. In other words, it may be determined for each service provider whether the registered authentication information (feature amount) is to be retained permanently (whether it is to be deleted when the use of the registered authentication information is finished (when authentication is successful)).
[0157] <Variation 3> As described above, the management center (management server 10) and the service provider (service server 20) will, in principle, delete the original biometric information (e.g., face image) of the user. However, the management server 10 and the service server 20 may temporarily or permanently store the original biometric information (e.g., face image) if explicit consent is obtained from the user.
[0158] Furthermore, when the original biometric information is stored, the management server 10 may provide the original biometric information to a service provider selected by the user in response to a request from the service provider.
[0159] For example, consider a case where the service provider does not store the original biometric information and changes the authentication algorithm adopted by the service provider. In this case, the service provider (service server 20) transmits the original biometric information including the user ID of the user to the management server 10. The management server 10 transmits the original biometric information corresponding to the acquired user ID to the service server 20.
[0160] The service server 20 generates registration authentication information that is compatible with the newly adopted authentication algorithm using the acquired original biometric information.
[0161] The management server 10 may obtain consent from the user regarding the provision of the original biometric information before providing the original biometric information to the service server 20. The management server 10 transmits the original biometric information to the service server 20 only when consent is obtained from the user.
[0162] Furthermore, if the service server 20 holds original biometric information, when the authentication algorithm adopted by the company is changed, the service server 20 may use the held original biometric information to generate registered authentication information (feature amount) for the newly adopted authentication algorithm. In this manner, the service server 20, in principle, deletes the original biometric information (face image) after calculating the registered authentication information (feature amount). However, the service server 20 may hold the original biometric information (face image) with the user's consent.
[0163] When the management server 10 does not hold original biometric information (e.g., a facial image) and receives a request for providing the original biometric information from the service server 20 due to a change in the authentication algorithm adopted by the service provider, the management server 10 may request the provision of the original biometric information from the terminal 40. In other words, when the management server 10 does not hold a facial image, the management server 10 may inquire of the user's terminal 40 to acquire a facial image and transmit the acquired facial image to the service server 20 every time a request is received from the service server 20.
[0164] <Modification 4> When a user selects a service provider, the authentication system disclosed in the present application may obtain business information required by the selected service provider. For example, when a user desires to select a service from a retailer, the terminal 40 may obtain business information (e.g., credit card information) to be provided to the retailer. In this case, the terminal 40 obtains the credit card information using a GUI such as that shown in FIG. 19.
[0165] The terminal 40 transmits to the management server 10 the acquired transaction information (for example, credit card information) together with the original biometric information of the user.
[0166] Alternatively, if the user selects an event organizer, the terminal 40 may connect to a ticket sales site provided by the event organizer. When the user purchases a ticket, the terminal 40 obtains ticket information of the ticket purchased by the user from the ticket sales site.
[0167] The terminal 40 transmits the acquired ticket information together with the user's original biometric information to the management server 10. The management server 10 transmits a user registration request including the user's original biometric information, ticket information, etc. to the service server 20.
[0168] In this manner, the terminal 40 may acquire business information related to the service provider selected by the user, and transmit the acquired business information to the management server 10 together with the original biometric information.
[0169] As described above, in the authentication system according to the first embodiment, original biometric information (e.g., face image) required for biometric authentication is stored in the terminal 40 of the user. When a user wishes to receive a biometric authentication service, the user selects a service provider, and then the original biometric information stored in the terminal 40 is provided to the selected service provider (a service provider that requires registered authentication information). Once the user registers his / her own biometric information (e.g., face image) in the terminal 40, the user can receive each service without registering biometric information in each service (various service providing locations). That is, once the user photographs his / her face, the user can use the face authentication service in various locations (services) using the face image without registering the face again. In other words, once biometric information is registered, the biometric information can be applied to various solutions using biometric authentication.
[0170] In addition, the above configuration solves various problems that arise when a service provider provides a biometric authentication service. In existing systems, the service provider needs to have the user register a face image for each service provision location (service). However, in the system according to the first embodiment, the user only needs to register the face once, and the burden of inducing the user to register the face is significantly reduced. In addition, the service provider does not need to hold the original biometric information (face image), and the burden on the service provider against information leakage, etc. is reduced. In particular, when the same service provider employs multiple face recognition algorithms, it is no longer necessary to possess face images corresponding to each face recognition algorithm, and the business risk of the service provider is reduced. In addition, with the consent of the user, the management center stores the original biometric information, and the service provider can change the face recognition engine employed in the company or newly adopt a face recognition engine suitable for the service provided. In other words, the service provider is not limited to a face recognition engine of a specific vendor, and can adopt face recognition engines of various vendors suitable for the purpose. As a result, the service provider can avoid the business risk of being overly dependent on one vendor (one face recognition engine). In other words, service providers who participate in the authentication system disclosed in this application can easily support multiple vendors.
[0171] From the user's point of view, since there is no need to register a face image multiple times even for the same service (same service provider), the user's convenience is improved. Furthermore, the original biometric information (face image) is stored in the user's own terminal 40, and the user's face image is not held by an external company, etc., so anxiety about information leakage, etc. is reduced. In other words, the user can enjoy the biometric authentication service with peace of mind.
[0172] Next, the hardware of each device constituting the authentication system will be described.
[0173] The management server 10 can be configured by an information processing device (so-called a computer), and has the configuration exemplified in Fig. 20. For example, the management server 10 has a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
[0174] However, the configuration shown in Fig. 20 is not intended to limit the hardware configuration of the management server 10. The management server 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the management server 10 is not intended to be limited to the example shown in Fig. 20, and for example, the management server 10 may include multiple processors 311.
[0175] The processor 311 is, for example, a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA), or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).
[0176] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.
[0177] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a keyboard, a mouse, etc. that accepts user operations.
[0178] The communication interface 314 is a circuit, a module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).
[0179] The functions of the management server 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The programs can be recorded in a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The programs can be downloaded via a network, or updated using a storage medium storing the programs. The processing modules can also be realized by a semiconductor chip.
[0180] The service server 20, authentication terminal 30, terminal 40, etc. can also be configured by information processing devices like the management server 10, and their basic hardware configurations are not described here because they are no different from the management server 10. For example, the authentication terminal 30 may be provided with a camera device for photographing the person to be authenticated.
[0181] The management server 10, which is an information processing device, is equipped with a computer, and can realize the functions of the management server 10 by having the computer execute a program. The management server 10 also executes a control method for the management server 10 by the program. Similarly, the terminal 40, which is an information processing device, is equipped with a computer, and can realize the functions of the terminal 40 by having the computer execute a program. The terminal 40 also executes the control method for the terminal 40 by the program.
[0182] [Variations] The configuration, operation, and the like of the authentication system described in the above embodiment are merely examples, and are not intended to limit the system configuration, and the like.
[0183] In the above embodiment, the operation of the authentication system has been described using a person's "face" as an example of biometric information. However, the authentication system disclosed in the present application can also use other types of biometric information. For example, data including physical characteristics unique to an individual, such as a fingerprint, voiceprint, vein, retina, or iris pattern, may be used. In other words, the biometric information of a user may be any information that includes the user's physical characteristics.
[0184] The service server 20 may provide the management server 10 with data obtained by authenticating the user. Specifically, the service server 20 transmits the user's user ID and behavioral information obtained from biometric authentication (for example, the date and time of successful authentication, the place where authentication was successful, purchased products, etc.) to the management server 10. The management server 10 may integrate the behavioral information obtained from each service provider based on the user's user ID to generate a behavioral history of the user. The generated behavioral history may be utilized by the management server 10, or may be sold to other businesses after being anonymized. The operator of the management center or other businesses can analyze the behavioral history of the user that cannot be obtained by their own company alone, and provide information (information distribution) taking into account the user's preferences, location, time, etc. That is, the behavioral history of the user may be utilized for advertising business.
[0185] The management center can receive a service fee for the authentication system from the service provider. The service fee may be determined according to the number of users registered with the service provider. Alternatively, the service fee may be determined according to the number of authentications performed by the service provider.
[0186] In the above embodiment, it has been described that the terminal 40 continues to hold the original biometric information (e.g., a face image) of the user unless there is a clear instruction from the user. However, the terminal 40 may request (instruct) the user to update the held original biometric information periodically or at a predetermined timing. That is, a person's face (physiognomy) changes over time, which is noticeable in children and the like. The terminal 40 requests the user to update the registered biometric information periodically or at a predetermined timing, taking into account the change in the face.
[0187] Alternatively, the terminal 40 may compare a face image taken by the user for a social networking service (SNS) or the like with the original biometric information (face image) for registration in a biometric authentication service, and if the similarity between the two face images has decreased, may request an update of the registered face image. In this case, the terminal 40 may calculate the similarity between the two face images, and request (instruct) an update of the original biometric information according to the result of threshold processing on the calculated similarity.
[0188] The management server 10 may have a function of verifying the quality of the original biometric information (e.g., face image) provided from the terminal 40 (see FIG. 21). For example, the quality verification unit 206 shown in FIG. 21 checks the quality of a face image that the user is about to provide to the service provider. For example, the quality verification unit 206 verifies the quality of the face image based on the brightness of the face image and whether or not feature points (e.g., eyes, nose, etc.) necessary for generating feature amounts are included. If the quality of the acquired face image does not meet a predetermined standard, the quality verification unit 206 requests the terminal 40 to resend the face image. The terminal 40 that receives the request requests the user to reacquire the face image. If the quality of the acquired face image meets a predetermined standard, the quality verification unit 206 transmits the face image (original biometric information) to the service server 20 of the service provider. With this configuration, it is possible to reduce the possibility that the service server 20 downstream of the management server 10 will fail the registration process (the process of generating feature amounts).
[0189] The user's terminal 40 may display list information that allows the user to immediately understand how each service provider handles the original biometric information and registered authentication information (e.g., retain permanently, retain for a specified period, delete immediately). For example, the terminal 40 may display a list of how each business (e.g., management center, service provider) handles the original biometric information as shown in Fig. 22. Alternatively, the terminal 40 may display a list of how each service provider handles the registered authentication information (e.g., feature amount) as shown in Fig. 23.
[0190] In the above embodiment, the case where the account management database is configured inside the management server 10 has been described, but the database may be constructed in an external database server or the like. That is, some of the functions of the management server 10 may be implemented in another server. More specifically, the above-described "service selection control unit (service selection control means)" and the like may be implemented in any of the devices included in the system.
[0191] The management server 10 may verify the identity of the user when creating an account. Specifically, the management server 10 acquires the user's login information and other information, such as an identification document (e.g., a passport, a driver's license, etc.) bearing biometric information and the biometric information. The management server 10 performs one-to-one matching using the biometric information on the identification document and the biometric information acquired from the user. If the matching is successful, the management server 10 may perform user registration (system registration) of the user whose identity has been successfully verified.
[0192] Although the format of data transmission between each device (management server 10, service server 20, authentication terminal 30) is not particularly limited, data transmitted between these devices may be encrypted. Biometric information and the like is transmitted between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.
[0193] In the flow charts (flow charts, sequence diagrams) used in the above description, multiple steps (processes) are described in order, but the order of execution of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the steps shown in the figures can be changed to a degree that does not interfere with the content, such as executing each process in parallel.
[0194] The above-mentioned embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the configurations described above are necessary. In addition, when a plurality of embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace a part of the configuration of an embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of an embodiment. Furthermore, it is possible to add, delete, or replace a part of the configuration of an embodiment with another configuration.
[0195] From the above explanation, the industrial applicability of the present invention is clear, and the present invention can be suitably applied to an information processing system that provides a biometric authentication service.
[0196] A part or all of the above-described embodiments can be described as, but is not limited to, the following supplementary notes. [Appendix 1] A plurality of first servers operated by a plurality of service providers each providing a service using biometric authentication; A second server that manages biometric authentication for each of the plurality of service providers; A terminal that stores original biometric information that is an original of authentication information used for biometric authentication; Including, The terminal transmits the original biometric information to the second server in response to a request from the second server; The second server transmits the original biometric information to the first server of a service provider selected by the user from among the plurality of service providers; The first server generates authentication information for enrollment from the original biometric information. [Appendix 2] 2. The system described in claim 1, wherein the second server holds information on each of the plurality of service providers and enables the user to select the service provider. [Appendix 3] The system described in Appendix 2, wherein the second server requests the terminal to provide the original biometric information after the user selects the service provider. [Appendix 4] The system described in Appendix 3, wherein the terminal transmits the original biometric information to the second server when the user's consent to the original biometric information being provided to the service provider is obtained. [Appendix 5] The system further includes a plurality of authentication terminals installed at respective service providing locations of the plurality of service providers, The system described in Appendix 4, wherein an authentication terminal among the multiple authentication terminals installed at a service provision location visited by the person to be authenticated transmits an authentication request including biometric information of the person to be authenticated to the first server corresponding to the service provision location visited by the person to be authenticated. [Appendix 6] The system described in Appendix 5, wherein the first server that receives the authentication request generates authentication information for matching from the biometric information included in the authentication request, and performs authentication processing using the generated authentication information for matching and the authentication information for registration. [Appendix 7] The system described in Appendix 6, wherein each of the multiple first servers stores, in association with each other, business information required when each service provider provides a service using the biometric authentication and the authentication information for registration. [Appendix 8] The system described in Appendix 7, wherein the first server that receives the authentication request determines that the authentication is successful if the business information of the person to be authenticated identified by a matching process using the authentication information for registration and the authentication information for matching is valid. [Appendix 9] 9. The system according to any one of claims 1 to 8, wherein the biometric information is a facial image of a person. [Appendix 10] 10. The system of claim 9, wherein the terminal does not delete the stored original biometric information unless instructed by the user. [Appendix 11] The system described in Appendix 10, wherein the plurality of first servers and the second server delete the received original biometric information unless instructed by the user. [Appendix 12] a storage unit that stores original biometric information that is an original of authentication information used for biometric authentication; a transmission unit that transmits the original biometric information to a management server in response to a request from the management server, the management server managing the biometric authentication of each of a plurality of service providers that provide services using biometric authentication; A terminal comprising: [Appendix 13] On the terminal, storing original biometric information that is the original of authentication information used for biometric authentication; A method for controlling a terminal, which provides a service using biometric authentication, manages biometric authentication for each of a plurality of service providers, and transmits the original biometric information to a management server in response to a request from the management server. [Appendix 14] The computer installed in the terminal A process of storing original biometric information that serves as an original of authentication information used for biometric authentication; a process of transmitting the original biometric information to a management server in response to a request from the management server, the management server managing the biometric authentication of each of a plurality of service providers that provide services using biometric authentication; A computer-readable storage medium that stores a program for executing the above.
[0197] The disclosures of the above cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. It will be understood by those skilled in the art that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and amendments that a person skilled in the art can make in accordance with the entire disclosure, including the scope of the claims, and the technical ideas. [Explanation of symbols]
[0198] 10 Management Server 20 Service Server 30 Authentication terminal 40 Terminals 101 First Server 102 Second Server 103 Terminal 201 Communication control section 202 Account Management Department 203 Business Management Department 204 Service selection control unit 205 Storage section 206 Quality Inspection Department 301 Communication Control Unit 302 Business Information Management Department 303 User registration control unit 304 Authentication Department 305 Storage section 311 Processor 312 Memory 313 Input / Output Interface 314 Communication Interface 401 Communication control section 402 Biometric information acquisition unit 403 Authentication Request Section 404 Functionality Realization Department 405 Storage section 501 Communication control section 502 Account creation control unit 503 Original information acquisition department 504 Service Selection Department 505 Storage section
Claims
1. A memory unit that stores original biometric information which is the original of authentication information used for biometric authentication; An agreement acquisition unit that acquires, from a user corresponding to the original biometric information, an agreement to transmit the original biometric information to a management server in response to a request from the management server that manages biometric authentication for each of a plurality of service providers that provide services using biometric authentication; A transmission unit that transmits the original biometric information to the management server when the user agrees to transmit the original biometric information to the management server; A terminal comprising the above.
2. The terminal according to Claim 1, further comprising a re-acquisition unit that re-acquires the original biometric information from the user corresponding to the original biometric information when a re-transmission of the original biometric information is requested from the management server, and the transmission unit transmits the re-acquired original biometric information to the management server.
3. In a terminal, a method for controlling a terminal, comprising: storing original biometric information which is the original of authentication information used for biometric authentication; acquiring, from a user corresponding to the original biometric information, an agreement to transmit the original biometric information to a management server in response to a request from the management server that manages biometric authentication for each of a plurality of service providers that provide services using biometric authentication; and transmitting the original biometric information to the management server when the user agrees to transmit the original biometric information to the management server.
4. A program for causing a computer mounted on a terminal to execute: a process of storing original biometric information which is the original of authentication information used for biometric authentication; a process of acquiring, from a user corresponding to the original biometric information, an agreement to transmit the original biometric information to a management server in response to a request from the management server that manages biometric authentication for each of a plurality of service providers that provide services using biometric authentication; and a process of transmitting the original biometric information to the management server when the user agrees to transmit the original biometric information to the management server.