Authentication program, authentication system and authentication method
The authentication system addresses the inflexibility of existing systems by dynamically providing authentication method information based on user history, enabling secure and adaptable authentication in face-to-face services.
Patent Information
- Application Number
- JP2023208755
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-11
- Publication Date
- 2025-06-23
- Estimated Expiration
- 2043-12-11
AI Technical Summary
Existing authentication systems lack the ability to flexibly set authentication methods according to individual user preferences, limiting their adaptability in face-to-face services.
An authentication program and system that dynamically provide authentication method information to both provider and user devices based on user authentication history and pre-registered information, enabling flexible authentication methods and a two-step authentication process.
Enables secure and flexible user authentication in face-to-face services by allowing users to choose authentication methods based on their history, enhancing security and convenience.
Smart Images

Figure 2025093176000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication program, an authentication system, and an authentication method.
Background Art
[0002] Conventionally, in order to more easily realize user authentication when a user uses a service, techniques related to a plurality of authentication methods are known.
[0003] For example, in the system described in Patent Document 1, user authentication is performed on the condition that biometric information data generated based on biometric information of a user acquired from the user and information acquired from the user's personal terminal match the information previously registered by the user, and data for performing processing related to user settlement at a franchise store is generated.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, the system described in Patent Document 1 only performs authentication by a fixed authentication method, and does not perform authentication by an authentication method that is flexibly set according to the user.
[0006] Therefore, an object of the present invention is to provide an authentication program, an authentication system, and an authentication method capable of performing authentication by an authentication method that is flexibly set according to the user in a face-to-face service that provides a service to the user face-to-face.
Means for Solving the Problems
[0007] An authentication program according to an aspect of the present invention causes a computer to, in a face-to-face service that provides a service to a user face-to-face, based on authentication history information regarding the user's authentication history and at least one piece of user authentication information pre-registered by the user as an element of at least one authentication method for authenticating the user when providing the face-to-face service, provide at least one piece of authentication method information regarding at least one authentication method to at least one of a provider device used by a service provider and a user device of the user; a first authentication unit that performs a first authentication of a user who receives the service based on the at least one piece of authentication method information and at least one piece of user authentication information corresponding to the at least one piece of authentication method information, which is acquired from at least one of the provider device and the user device; a first authentication result providing unit that provides first authentication result information regarding the result of the first authentication to at least one of the provider device and the user device; and a second authentication unit that performs a second authentication of the user based on an operation of the user on at least one of the provider device and the user device according to the first authentication result information.
[0008] An authentication system according to an aspect of the present invention includes: an authentication method providing unit that provides at least one piece of authentication method information regarding at least one authentication method to at least one of a provider device used by a service provider and a user device of the user, based on authentication history information regarding the user's authentication history and at least one piece of user authentication information pre-registered by the user as an element of at least one authentication method for authenticating the user when providing a face-to-face service that provides a service to the user face-to-face; a first authentication unit that performs a first authentication of a user who receives the service based on the at least one piece of authentication method information and at least one piece of user authentication information corresponding to the at least one piece of authentication method information, which is acquired from at least one of the provider device and the user device; a first authentication result providing unit that provides first authentication result information regarding the result of the first authentication to at least one of the provider device and the user device; and a second authentication unit that performs a second authentication of the user based on an operation of the user on at least one of the provider device and the user device according to the first authentication result information.
[0009] In an authentication method according to an aspect of the present invention, in a face-to-face service in which a computer provides a service to a user face-to-face, at least one authentication method information regarding at least one authentication method is provided to at least one of a provider device used by a service provider and a user device of the user based on at least one user authentication information pre-registered by the user as authentication history information regarding the user's authentication history and as an element of at least one authentication method for authenticating the user when providing the face-to-face service. A first authentication of a user receiving the service is performed based on the at least one authentication method information and at least one user authentication information corresponding to the at least one authentication method information acquired from at least one of the provider device and the user device. First authentication result information regarding the result of the first authentication is provided to at least one of the provider device and the user device, and a second authentication of the user is performed based on an operation of the user on at least one of the provider device and the user device according to the first authentication result information.
[0010] In the present invention, the term "unit" does not simply mean a physical means, but also includes a case where the function of the "unit" is realized by software. Further, even if the function of one "unit" or device is realized by two or more physical means or devices, or the functions of two or more "units" or devices are realized by one physical means or device, it is also acceptable.
Advantages of the Invention
[0011] According to the present invention, it is possible to provide an authentication program, an authentication system, and an authentication method that can authenticate using an authentication method flexibly set according to a user in a face-to-face service that provides a service to a user face-to-face.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Embodiments for Carrying Out the Invention
[0013] The present invention relates to an authentication program, an authentication system, and an authentication method for authenticating a user who is executed when a user uses a predetermined service. Here, the predetermined service is a face-to-face service that provides a service to a user in person. For example, it includes settlement at a franchise store, management of entry and exit to a predetermined building or area, and a service that provides a predetermined benefit to the user. That is, according to the present invention, a user who makes a settlement at the time of settlement of a predetermined product in a store may be authenticated, and when managing entry and exit to a predetermined building or area, a user who can enter and exit the building or room may be authenticated. Further, a predetermined benefit may be provided to the user authenticated by the present invention.
[0014] Hereinafter, an embodiment in which the present invention is applied to an authentication system that authenticates a user who makes a settlement at the time of settlement in a franchise store (that is, a service provider) will be described.
[0015] A preferred embodiment of the present invention will be described with reference to the accompanying drawings. FIG. 1 is a diagram showing an outline of the authentication process in an authentication system 100 which is an embodiment of the present invention.
[0016] An authentication system 100 according to an embodiment of the present invention is an information processing system realized by an authentication program and is an information processing system for authenticating a user's payment at a franchise store. The authentication system 100 authenticates a user's payment at a franchise store based on information necessary for authenticating the user's payment at the franchise store, which is obtained directly or indirectly from the franchise store and the user.
[0017] First, the user provides user authentication information for authenticating the user to the authentication system 100 through the user device 300 and registers it as an element of at least one authentication method (S101). The franchise store (provider) receives a payment application from the user (S102), and the authentication system 100 receives an authentication request for the user from the franchise store (S103). The authentication system 100 generates authentication method information regarding an authentication method for authenticating a user who makes a payment at the franchise store based on the authentication history information and the user authentication information pre-registered by the user, and provides it to the provider device 200 described later (S104).
[0018] When the user makes a payment at the franchise store, the franchise store requests the user to provide user authentication information corresponding to the authentication method information, and the user provides the corresponding user authentication information to the provider device 200 (S105). The franchise store provides the acquired user authentication information to the authentication system 100 (S106). The authentication system 100 performs a first authentication on the user who makes a payment at the franchise store based on the authentication method information and the user authentication information acquired from the provider device 200, and provides first authentication result information to the provider device 200 (S107).
[0019] Subsequently, the user performs an operation on the provider device 200 according to the first authentication result information (S108). The provider device 200 provides operation information regarding the user's operation to the authentication system 100 (S109). The authentication system 100 performs a second authentication based on the operation information (S110).
[0020] Then, the user's payment at the franchise store is completed (S111).
[0021] In addition, in S104, the authentication system 100 may provide authentication method information to the user device 300 (not shown) described later. In this case, the authentication system 100 may authenticate a user who makes a payment at the franchise store based on the authentication method information provided to the user device 300 and the user authentication information obtained from the user device 300, and provide the authentication result to the provider device 200.
[0022] Also, in S107, the authentication system 100 may directly provide the first authentication result information to the user device 300 (not shown), or may provide the first authentication result information to the provider device 200, and the provider device 200 may provide the first authentication result information to the user device 300 (not shown). In this case, the authentication system 100 may obtain operation information from the user device 300 (not shown).
[0023] Here, the authentication method is a method by which the authentication system 100 authenticates a user who makes a payment at the franchise store. The authentication method may be, for example, an authentication method based on at least one of possession information regarding a possession (e.g., an information terminal such as the user device 300) possessed by the user, biometric information regarding the user's biometrics, and stored information stored by the user.
[0024] Specifically, the possession information may be, for example, device identification information for identifying a device (e.g., an information terminal such as a smartphone) that is a possession of the user, or position information indicating the position of the possession (e.g., distance information indicating the distance between the possession and the provider device 200, or information indicating GPS coordinates measured by a GPS system using a GPS device). Further, the possession that the user has may provide the possession information to at least one of the authentication system 100 and the provider device 200 directly, or indirectly via a cloud or the like as necessary, by communication based on a communication standard such as BLE (Bluetooth Low Energy), UWB (Ultra Wide Band), Wi-Fi (registered trademark), short-range wireless communication (e.g., RFID (Radio Frequency IDentification) or NFC (Near Field Communication)), or may be provided to at least one of the authentication system 100 and the provider device 200 by other methods.
[0025] Further, the biometric information may be, for example, information related to the user's biometrics such as the user's appearance, fingerprint, palmprint, voiceprint, iris, etc. The user may provide the user's biometric information to the provider device 200, for example, through the provider terminal 220 described later. Also, the user may provide the user's biometric information to the provider device 200 through the user device 300.
[0026] Further, the memory information may be, for example, information for identifying the user in the authentication system 100, the number of a card used for settlement, an account name such as an account number, a telephone number, an email address, a password, a signature or figure input or selected by the user, an answer in a free input format or a choice format for a predetermined question, or other information that the user remembers and can be obtained by the provider device 200. The user inputs or selects the memory information, for example, through an input device provided in the provider terminal 220 installed in the franchise store, and provides the memory information to the provider device 200.
[0027] The authentication method may be an authentication method including at least any one of possession information, biometric information, and memory information as elements. That is, the authentication method may be an authentication method having only any one of possession information, biometric information, and memory information as an element, or may be an authentication method including two or more pieces of information among possession information, biometric information, and memory information as elements. That is, when the authentication method is an authentication method including possession information and biometric information as elements, the authentication system 100 authenticates a user who makes a payment at a franchise based on the possession information and the biometric information. Further, the authentication method may be an authentication method including information other than possession information, biometric information, and memory information as an element.
[0028] Thus, for example, in the case of an authentication method having at least any one of possession information, biometric information, and memory information as an element, the user can make a payment by a so-called cashless payment in which the user can make a payment without possessing or presenting cash or a payment card used for payment (or by possessing or presenting it without any special trouble for the user). Here, the cashless payment includes not only a state where the user makes a payment without wearing anything but also a payment in a state where the user wears only an object that the user usually wears (for example, a smartphone) (that is, a state similar to being empty-handed).
[0029] FIG. 2 is a diagram showing the configuration of an authentication system 100 which is an embodiment of the present invention. The authentication system 100 is a system communicably connected via a network such as the Internet to a provider device 200, a user device 300, and an action history management system 400. Details of the authentication system 100 will be described later.
[0030] The provider device 200 is a device used by franchise stores. The provider device 200 includes a provider information processing system 210, which is an information processing system used by franchise stores and is communicably connected via a network such as the Internet, and a provider terminal 220 installed in the franchise store. In FIG. 2, only one provider device 200 is shown, but if there are multiple franchise stores, a provider device 200 is provided for each franchise store. Also, multiple provider devices 200 may be provided in one franchise store.
[0031] The provider information processing system 210 may be, for example, any information processing system that is communicably connected to the authentication system 100 and the provider terminal 220, and may be any information processing system capable of transmitting and receiving various types of information to and from the authentication system 100 and the provider terminal 220.
[0032] The provider terminal 220 may be, for example, any terminal installed in a franchise store for performing settlement-related processing. For example, when settling accounts, it may include a terminal for registering information related to products (such as information on product numbers and prices) (such as barcode information or tag information attached to the product) and information that is an element of a predetermined authentication method (such as possession information, biometric information, and memory information), and displaying the first authentication result information. That is, the provider terminal 220 may be equipped with a reading device for reading barcode information or tag information of products, a detection device for detecting the user's possessions, a detection device for detecting the user's biometric information, an input device for the user to input memory information, etc., a display device for displaying the first authentication result information, and an operation reception device for receiving the user's operation according to the first authentication result information.
[0033] The franchise store obtains authentication method information indicating an authentication method for authenticating the user's payment from the authentication system 100 through the provider device 200 (for example, the provider information processing system 210). Also, when the user makes a payment at the franchise store, the franchise store may obtain user authentication information from the user or the user device 300 described later through, for example, the provider terminal 220, and provide the obtained user authentication information to the provider information processing system 210. Further, the user authentication information may be provided to the authentication system 100 through the provider information processing system 210.
[0034] Then, the franchise store obtains first authentication result information from the authentication system 100 through, for example, the provider information processing system 210, displays the first authentication result information to the user through the provider terminal 220, obtains the user's operation information through the provider terminal 220, and may provide the operation information to the authentication system 100 through the provider information processing system 210.
[0035] Note that the franchise store may be a so-called unmanned store where payment is made without the operation of a person in charge (for example, an operator who operates the provider terminal 220) installed at the franchise store.
[0036] The user device 300 is a device used by the user, such as a smartphone, a tablet terminal, a personal computer, etc. The user accesses the authentication system 100 through the user device 300 and registers user authentication information for authenticating the user in a predetermined authentication method as an element of the authentication method. That is, the user can register user authentication information such as the user's possession information, the user's biometric information, and the user's memory information as an element of the authentication method through the user device 300.
[0037] Also, when making a payment at the franchise store, the user can provide user authentication information to at least one of the provider device 200 (for example, the provider terminal 220) and the authentication system 100 through the user device 300.
[0038] In addition, the user operates the provider device 200 (for example, the provider terminal 220) and the user device 300 according to the first authentication result information.
[0039] In FIG. 2, only one user device 300 is shown. However, when there are a plurality of users, a user device 300 is provided for each user. Also, one user may hold a plurality of user devices 300.
[0040] The behavior history management system 400 is an information processing system that manages user behavior history information regarding the behavior history of a user. Here, the behavior history of a user includes, for example, the operation history of the user device 300 by the user (for example, application usage history, Internet search history), the location information history of the user device 300, the transaction history through an e-commerce site, the usage history of an SNS (social networking service), and the history of abuse or trouble regarding the user device 300 or the settlement card used by the user.
[0041] The behavior history management system 400 may be any information processing system corresponding to each piece of user behavior history information. That is, the behavior history management system 400 may be, for example, an information processing system that manages and operates applications within the user device 300, an information processing system that operates an e-commerce site, or an information processing system that provides an SNS.
[0042] The behavior history management system 400 can provide the user behavior history information to the authentication system 100. At this time, the behavior history management system 400 may provide the information itself indicating the behavior history of the user, or may provide the information indicating the result of evaluating the behavior history of the user generated based on the information itself indicating the behavior history of the user.
[0043] In FIG. 2, only one behavior history management system 400 is shown. However, a plurality of information processing systems corresponding to each of the plurality of pieces of user behavior history information may be provided.
[0044] Next, the details of the authentication system 100 will be described. The authentication system 100 includes a user registration unit 111, a user information storage unit 112, an authentication history storage unit 121, a behavior history acquisition unit 122, an authentication method generation unit 131, an authentication method storage unit 132, an authentication method provision unit 133, a user authentication information acquisition unit 141, a first authentication unit 142, a first authentication result provision unit 143, an operation acquisition unit 151, and a second authentication unit 152. The computer constituting the authentication system 100 includes a processor and a storage area. Each unit shown in FIG. 2 can be realized, for example, by using the storage area or by the processor executing an authentication program stored in the storage area.
[0045] The user registration unit 111 receives and registers user information including at least one piece of user authentication information from the user device 300 as an element of at least one authentication method for authenticating the user when providing the face-to-face service, and stores it in the user information storage unit 112.
[0046] Here, the user authentication information is information that is an element of at least one authentication method for authenticating the user when providing the face-to-face service, and is information for authenticating the user in the at least one authentication method. The user authentication information includes, for example, possession information, biometric information, and memory information.
[0047] That is, the user registers the user authentication information as an element of at least one authentication method. Specifically, for example, the user registers his / her own biometric information (e.g., fingerprint information) as user authentication information to be used for authentication by an authentication method having biometric information as an element (e.g., an authentication method having only biometric information as an element or an authentication method having biometric information and memory information as elements). Note that the user registration unit 111 may also acquire consent information indicating that the user agrees to use the registered user authentication information as an element of the authentication method when registering the user authentication information, and accept the registration of the user authentication information.
[0048] User information may further include information about the user in addition to user authentication information. Here, the information about the user may be, for example, the user's personal information (e.g., name, address, phone number, email address, password), information about cards or devices (e.g., user device 300) used by the user for settlement (e.g., card number, device number).
[0049] Note that the user may register all the user authentication information that can be registered in the authentication system 100, or may register only the user authentication information that the user himself / herself wishes to register. Thereby, the user can arbitrarily select the user authentication information to be registered, and it is possible to realize an authentication process that balances the user's security awareness and convenience in the authentication process of settlement.
[0050] Also, the user may register a plurality of user authentication information corresponding to the same element among the elements of the authentication method as the user authentication information. That is, the user may register, for example, biometric information related to fingerprints and biometric information related to voiceprints as biometric information that is the same element, or may register biometric information related to fingerprints of a plurality of different fingers.
[0051] FIG. 3 is a diagram showing an example of information stored in the user information storage unit 112. The information stored in the user information storage unit 112 includes, for example, a user ID and user authentication information, and the user authentication information includes, for example, possession information, biometric information, and memory information. Here, the user ID is information for identifying the user who uses the authentication system 100.
[0052] The user information storage unit 112 may store all the user authentication information for each user ID, or may store only a part of the user authentication information. Also, the user may register a plurality of user authentication information corresponding to the same element among the elements of a predetermined authentication method as the user authentication information. That is, the user may register, for example, biometric information related to fingerprints and biometric information related to voiceprints as biometric information that is the same element, or may register biometric information related to fingerprints of a plurality of different fingers.
[0053] The authentication system 100 stores, as authentication history information, the result authenticated by the first authentication unit 142 described later in the authentication history storage unit 121. FIG. 4 is a diagram showing an example of information stored in the authentication history storage unit 121. The information stored in the authentication history storage unit 121 includes, for example, an authentication history ID, authentication date information, and authentication content information.
[0054] The authentication history ID is authentication history identification information for identifying the authentication history. The authentication date information is information indicating the date of authentication. The authentication content information is information indicating the content of authentication. Note that the authentication date information may include information indicating the time of authentication. Also, when the authentication system 100 authenticates the user's payment at the franchise store, the authentication content information may be information indicating the authentication amount.
[0055] Note that the authentication history storage unit 121 may store authentication history information acquired from an external information processing system. In this case, the authentication history storage unit 121 may store the authentication history information itself, or may store, for example, information indicating a link to the authentication history information.
[0056] The behavior history acquisition unit 122 acquires user behavior history information from the behavior history management system 400.
[0057] Here, the user behavior history information may be any information related to the history of the user's behavior. For example, it may include information related to the operation history of the user device 300 by the user (e.g., application usage history, Internet search history), information related to the location information history of the user device 300, information related to the transaction history through the e-commerce site, information related to the usage history of SNS, and information related to the history of abuse or trouble related to the user device 300 or the payment card used by the user. Also, the user behavior history information managed in the behavior history management system 400 may be information indicating the user's behavior history itself, or may be information indicating the result of evaluating the user's behavior history generated based on the information indicating the user's behavior history itself.
[0058] Note that the action history acquisition unit 122 may acquire the information itself indicating the user's action history, or may acquire the information indicating the result of evaluating the user's action history generated based on the information itself indicating the user's action history. Further, the action history acquisition unit 122 may acquire the user action history information itself acquired from the action history management system 400, or may acquire the information indicating the link of the user action history information.
[0059] Based on the authentication history information and at least one piece of user authentication information pre-registered by the user as an element of at least one authentication method for authenticating the user when providing the face-to-face service, the authentication method generation unit 131 generates at least one piece of authentication method information regarding at least one authentication method and stores it in the authentication method storage unit 132.
[0060] Here, the authentication method information is information regarding at least one authentication method executed by the authentication system 100, and may be information indicating the authentication method itself, or may be information indicating elements of the authentication method that can be processed in the authentication system 100 (for example, possession information, biometric information, memory information). The authentication method information only needs to be information indicating whether to adopt the authentication method or not. For example, for each authentication method or each element of the authentication method, the information may include "use" indicating adoption as the authentication method or an element of the authentication method, and "not use" indicating non-adoption as the authentication method or an element of the authentication method. Note that the information indicating whether to adopt the authentication method or an element of the authentication method is not limited to "use" and "not use".
[0061] Specifically, the authentication method generation unit 131 generates authentication method information based on the user authentication information pre-registered by the user as an element of at least one authentication method. That is, the authentication method generation unit 131 generates at least one piece of authentication method information regarding at least one authentication method among the authentication methods having the user authentication information registered by the user as an element. Thereby, the user can use the authentication system 100 within the range of the user authentication information registered by the user and the corresponding authentication method.
[0062] In addition, based on the authentication history information, when the same content (for example, a payment amount equal to or less than the same amount) has been authenticated in the past, the authentication method generation unit 131 determines that the risk of authenticating the user with the same content is low, and can generate authentication information corresponding to an authentication method with a lower burden on the user. As a result, the user can be authenticated more simply with an authentication method that is flexibly set according to the user's own authentication history.
[0063] In addition, based on the authentication history information, when the same content has not been authenticated in the past (for example, when a new high-amount payment is made this time or when paying at a franchise store that has not been used in the past), the authentication method generation unit 131 determines that the risk of authenticating the user is high, and considers the security level at the time of authentication to avoid authentication of a user who is impersonating or has no payment ability. It is possible to generate authentication method information corresponding to a highly secure authentication method (for example, an authentication method that combines a plurality of elements). As a result, the franchise store can perform authentication with an authentication method that takes security into consideration while the authentication method is flexibly set according to the user's authentication history.
[0064] In addition, the authentication method generation unit 131 may calculate the number of elements (for example, possession information, biometric information, memory information) in the authentication method when authenticating the user at the franchise store based on the authentication history information, and generate at least one piece of authentication method information including at least the calculated number of elements. Specifically, when the calculated number of elements is 2, the authentication method generation unit 131 may generate, for example, authentication method information regarding an authentication method including 2 or more elements (for example, an authentication method that authenticates using possession information and biometric information).
[0065] In addition, the authentication method generation unit 131 can generate at least one piece of authentication method information based on the user behavior history information as well.
[0066] Further, the authentication method generation unit 131 may calculate the number of elements (e.g., possession information, biometric information, memory information) in the authentication method for authenticating the user at the franchise store based on the user behavior history information, and generate at least one authentication method information including at least the calculated number of elements.
[0067] Specifically, based on the user behavior history information, for example, when it is determined that there is something suspicious in the user's behavior history, the authentication method generation unit 131 determines that the risk of authenticating the user is high, and can generate authentication information corresponding to a highly secure authentication method.
[0068] Further, the authentication method generation unit 131 may generate at least one authentication method information in association with authentication strength information indicating the strength of authentication in the authentication method, and store it in the authentication method storage unit 132.
[0069] Here, the authentication strength information is information indicating the strength of authentication for each authentication method. The strength of authentication may be determined by, for example, the number and type of elements of the authentication method (e.g., any of possession information, biometric information, memory information). For example, the authentication strength information may be information indicating that an authentication method combining a plurality of elements has a high authentication strength and an authentication method based on only one element has a low authentication strength. Also, for example, the authentication strength information may be information indicating that an authentication method having biometric information as an element has a high authentication strength and an authentication method having possession authentication as an element has a low authentication strength. That is, it shows that an authentication method with a higher authentication strength is an authentication method that can avoid authenticating a user's impersonation or a user without payment ability for settlement, and an authentication method with a lower authentication strength is a simpler authentication method for the user.
[0070] Specifically, the authentication method generation unit 131 may store, in the authentication method storage unit 132, at least one piece of authentication method information (for example, the authentication method information with the lowest or highest authentication strength information) among a plurality of pieces of authentication method information generated based on the authentication history information, where the authentication strength information satisfies a predetermined condition. Thereby, the authentication system 100 can authenticate the user with an authentication method that is convenient for the user or has high security considering the provider among the authentication methods flexibly set based on the user's authentication history.
[0071] Further, the authentication method generation unit 131 may generate at least one piece of authentication method information including at least authentication strength information corresponding to the required authentication strength for authenticating the user, according to the required authentication strength for authenticating the user calculated based on at least one of the authentication history information and the user behavior history information. Specifically, for example, when the required authentication strength for authenticating the user calculated based on at least one of the authentication history information and the user behavior history information is "2", the authentication method generation unit 131 can generate authentication method information with the authentication strength information being "2" or higher than "2". Note that the authentication strength information may be indicated by numerical values, symbols (for example, "A", "B"), etc., and the display form of the authentication strength information is not limited to this.
[0072] In addition, the authentication method generation unit 131 may generate authentication method information using, as an input, the authentication history information based on machine learning, or, if necessary, further using the user behavior history information as an input. At this time, the authentication method generation unit 131 may use a machine learning model generated based on the authentication history information of a plurality of other users using the authentication system 100, or, if necessary, further based on the user behavior history information of a plurality of other users using the authentication system 100.
[0073] Moreover, the authentication method generation unit 131 may generate authentication method information in response to an authentication request directly or indirectly obtained from the user (for example, a payment request from the user at a franchise store).
[0074] In addition, the authentication method generation unit 131 may generate authentication method information corresponding to a predetermined condition prior to an authentication request from a user obtained directly or indirectly, and the authentication method providing unit 133 described later may provide the previously generated authentication method information based on an authentication request from a user obtained directly or indirectly. At this time, the authentication method generation unit 131 may generate the authentication method information again according to an authentication request from a user obtained directly or indirectly.
[0075] Specifically, the authentication method generation unit 131 generates authentication method information in association with a predetermined condition (for example, a condition related to the settlement amount) prior to an authentication request from a user. When the authentication request from the user is within the range of the predetermined condition corresponding to the previously generated authentication method information (for example, when it is a settlement request for an amount equal to or less than a predetermined settlement amount), the authentication method providing unit 133 may provide the previously generated authentication method information to at least one of the provider device 200 and the user device 300.
[0076] On the other hand, when the authentication request from the user is not within the range of the predetermined condition corresponding to the previously generated authentication method information (for example, when it is a settlement request for an amount larger than the predetermined settlement amount), the authentication method generation unit 131 may generate the authentication method information again according to the authentication request from the user.
[0077] Thereby, the authentication system 100 can generate the authentication method information in advance within the range of the authentication requests predicted in advance, and can promptly respond to the authentication requests from the users.
[0078] Note that the generation of the authentication method information in advance by the authentication method generation unit 131 may be performed when a predetermined condition is satisfied, such as at a predetermined timing such as system maintenance time, or when the number of authentication times for the user reaches a predetermined number of times.
[0079] FIG. 5 is a diagram showing an example of information stored in the authentication method storage unit 132. The information stored in the authentication method storage unit 132 includes, for example, an authentication method ID, authentication method information, and authentication strength information. The authentication method information includes, for example, possession information, biometric information, and memory information.
[0080] The authentication method information may be information indicating whether to adopt it as an authentication method. For example, for each authentication method or each element of the authentication method, it may include information such as "use" indicating adoption as the authentication method or an element of the authentication method, and "not use" indicating non - adoption as the authentication method or an element of the authentication method. Note that the information indicating whether to adopt the authentication method or an element of the authentication method is not limited to "use" and "not use".
[0081] The authentication strength information is information indicating the strength of authentication for each authentication method. In the diagram shown in FIG. 5, the authentication strength information is shown numerically, but the display format of the authentication strength information is not limited to this, and it may be, for example, "A", "B", etc.
[0082] The authentication method providing unit 133 provides the authentication method information stored in the authentication method storage unit 132 to at least one of the provider device 200 and the user device 300.
[0083] The authentication method providing unit 133 may provide the authentication method information to the provider device 200. In this case, the franchise store may request the user to provide user authentication information based on the authentication method information provided to the provider device 200.
[0084] Also, the authentication method providing unit 133 may provide the authentication method information to the user device 300. In this case, the user may provide user authentication information to the authentication system 100 through the user device 300.
[0085] Also, the authentication method providing unit 133 may provide the authentication method information to both the provider device 200 and the user device 300.
[0086] Further, the authentication method providing unit 133 may provide the authentication method information with the lowest authentication strength among the authentication method information stored in the authentication method storage unit 132. Thereby, the user can be authenticated by a simple authentication method among the authentication methods flexibly set based on the authentication history information.
[0087] Further, the authentication method providing unit 133 may provide the authentication method information with the highest authentication strength among the authentication method information stored in the authentication method storage unit 132. Thereby, the franchise store can perform authentication by a highly secure authentication method among the authentication methods flexibly set based on the authentication history information.
[0088] When authenticating a user who makes a payment at a franchise store, the user authentication information acquisition unit 141 acquires user authentication information from at least one of the provider device 200 and the user device 300.
[0089] The processing of the authentication method providing unit 133 and the user authentication information acquisition unit 141 will be described with specific examples. First, as a first specific example, the processing when the authentication method providing unit 133 provides authentication method information to the provider device 200 will be described.
[0090] When authenticating a user who makes a payment at a franchise store, first, the authentication method providing unit 133 provides authentication method information to the provider device 200. Subsequently, the franchise store requests the user to provide user authentication information corresponding to the authentication method indicated by the provided authentication method information.
[0091] Then, the provider device 200 acquires user authentication information from the user or the user device 300 and provides it to the authentication system 100, and the user authentication information acquisition unit 141 acquires the user authentication information provided from the provider device 200.
[0092] Here, the provider device 200 may detect at least one user device 300 in the vicinity of the provider device 200 (e.g., the provider terminal 220) and provide the authentication system 100 with possession information regarding the detected at least one user device 300. Further, the provider device 200 (e.g., the provider terminal 220) may acquire biometric information or memory information from the user and provide the acquired biometric information or memory information to the authentication system 100.
[0093] In addition, when a franchise store can acquire user authentication information without requesting the user to provide it (for example, when the provider terminal 220 can receive possession information transmitted from the user device 300), the franchise store may acquire the user authentication information without requesting the user to provide the user authentication information. As a result, the user can provide the user authentication information without performing a special operation for providing the user authentication information, and an authentication process with high convenience can be realized.
[0094] Also, a user who has received a request to provide user authentication information from a franchise store may provide the authentication system 100 with the user authentication information through the user device 300. Thereby, the user can receive authentication under simple and high security without providing the user authentication information to the outside (e.g., the provider device 200).
[0095] As a second specific example, regarding the processing of the authentication method providing unit 133 and the user authentication information acquiring unit 141, the processing when the authentication method providing unit 133 provides authentication method information to the user device 300 will be described.
[0096] When authenticating a user who makes a payment at a franchise store, first, the authentication method providing unit 133 provides authentication method information to the user device 300. Subsequently, the user provides user authentication information corresponding to the authentication method indicated by the authentication method information provided by the authentication method providing unit 133 to the authentication system 100 through the user device 300, and the user authentication information acquisition unit 141 acquires the user authentication information provided from the user device 300. Thereby, the user can be authenticated simply and with high security without providing the user authentication information to the outside (for example, the provider device 200).
[0097] As a third specific example, regarding the processing of the authentication method providing unit 133 and the user authentication information acquisition unit 141, the processing when the authentication method providing unit 133 provides authentication method information to both the provider device 200 and the user device 300 will be described.
[0098] When authenticating a user who makes a payment at a franchise store, first, the authentication method providing unit 133 provides authentication method information to both the provider device 200 and the user device 300. The franchise store requests the user to provide user authentication information corresponding to the authentication method indicated by the authentication method information based on the authentication method information provided by the authentication method providing unit 133. Here, the franchise store may request the user to provide only the user authentication information that can be acquired through the provider device 200.
[0099] On the other hand, the user provides user authentication information corresponding to the authentication method indicated by the authentication method information provided by the authentication method providing unit 133 to the authentication system 100 through the user device 300. Here, the user may provide only the user authentication information that can be provided to the authentication system 100 through the user device 300 to the authentication system 100.
[0100] Then, the user authentication information acquisition unit 141 acquires the user authentication information provided from the provider device 200 and the user device 300.
[0101] In addition, when the authentication method providing unit 133 provides the authentication method information to both the provider device 200 and the user device 300, the user authentication information acquisition unit 141 may acquire the user authentication information provided from only one of the provider device 200 and the user device 300. Thereby, even when the franchise store and the user do not provide the user authentication information to the authentication system 100, they can grasp by what authentication method the authentication is performed.
[0102] The first authentication unit 142 performs first authentication of the user's payment at the franchise store based on at least one piece of authentication method information and at least one piece of user authentication information acquired from at least one of the provider device 200 and the user device 300.
[0103] Specifically, for example, in the authentication method indicated by the authentication method information, the first authentication unit 142 performs first authentication of the user's payment at the franchise store when the user authentication information stored in the user information storage unit 112 matches the user authentication information acquired from at least one of the provider device 200 and the user device 300.
[0104] The first authentication result providing unit 143 provides first authentication result information regarding the result of the first authentication to at least one of the provider device 200 and the user device 300.
[0105] Here, the first authentication result information may include display information for displaying image information indicating the user's face, which is included in at least one piece of user authentication information acquired from at least one of the provider device 200 and the user device 300. That is, the first authentication result information may include display information for displaying image information indicating the user's face, which is acquired in the first authentication by the first authentication unit 142. Thereby, at least one of the provider device 200 and the user device 300 that acquires the first authentication result information can display the image information indicating the user's face acquired in the first authentication.
[0106] Further, the first authentication result information may include display information for displaying image information showing the user's face, which is included in at least one piece of user authentication information registered in advance. That is, the first authentication result information may include display information for displaying image information showing the user's face, which was registered in advance as user authentication information in the user registration unit 111. Thereby, at least one of the provider device 200 and the user device 300 that acquires the first authentication result information can display the image information showing the user's face, which was registered in advance as user authentication information.
[0107] Further, the first authentication result information may include display information for displaying image information showing the user's face, which is included in at least one piece of user authentication information acquired from at least one of the provider device 200 and the user device 300, and display information for displaying image information showing the user's face, which is included in at least one piece of user authentication information registered in advance. Thereby, the user can compare the two images and confirm the result of the first authentication.
[0108] Further, the first authentication result information may further include display information for displaying the result of the first authentication, that is, for example, information indicating the user who has undergone the first authentication and the content of the service that has been authenticated (for example, the transaction amount, the transaction content, etc.).
[0109] The first authentication result providing unit 143 may provide the first authentication result information to, for example, either the provider device 200 or the user device 300. In this case, the operation acquisition unit 151, which will be described later, acquires operation information from the device provided by the first authentication result providing unit 143.
[0110] Further, the first authentication result providing unit 143 may provide the first authentication result information to, for example, both the provider device 200 and the user device 300. In this case, the operation acquisition unit 151 described later acquires operation information from at least one of the provider device 200 and the user device 300. Thereby, since the user can select the device for performing the operation from either the provider device 200 or the user device 300, the convenience of the user is improved.
[0111] The operation acquisition unit 151 acquires operation information regarding the user's operation on at least one of the provider device 200 and the user device 300 according to the first authentication result information.
[0112] The operation information may be, for example, information regarding an operation indicating that the result of the first authentication has been confirmed and approved. The operation indicated by the operation information may be, for example, a selection operation (such as a touch operation or a click operation) or an input operation by the user on at least one of the provider device 200 and the user device 300. The selection operation may be, for example, an operation of selecting a predetermined button or area using a finger or a mouse. The input operation may be an operation of inputting text through a keyboard or the like, or an operation of electronically inputting a signature or the like.
[0113] The second authentication unit 152 performs the second authentication of the user based on the operation information. That is, the second authentication unit 152 performs the second authentication of the user based on the user's operation on at least one of the provider device 200 and the user device 300 according to the first authentication result information.
[0114] Here, the second authentication is, for example, a process of determining the result of the first authentication based on the fact that the user has confirmed and approved the result of the first authentication, and finally authenticating the provision of a predetermined service (such as settlement) to the user.
[0115] A case where the first authentication result providing unit 143 provides the first authentication result information to the provider device 200 will be described as an example for a series of second authentication processes.
[0116] First, the provider device 200 that has acquired the first authentication result information displays the first authentication result information to the user. At this time, the provider device 200 displays, for example, at least any one of the image information indicating the user's face acquired in the first authentication by the first authentication unit 142, the image information indicating the user's face pre-registered as user authentication information in the user registration unit 111, and the result of the first authentication. Subsequently, the user refers to the first authentication result information, confirms the result of the first authentication, and performs an operation to approve the result of the first authentication.
[0117] Then, the operation acquisition unit 151 acquires operation information regarding the operation by the user from the provider device 200. The second authentication unit 152 performs a second authentication based on the operation information. As a result, the franchise store and the user confirm the authentication result, and the settlement of the user at the franchise store is completed.
[0118] Here, the case where the first authentication result providing unit 143 provides the first authentication result information to the provider device 200 has been described as an example. However, when the first authentication result providing unit 143 provides the first authentication result information to the user device 300, the provider device 200 may be appropriately replaced with the user device 300.
[0119] In this way, through a series of second authentication processes, the authentication system 100 can grasp that the user has confirmed and approved the authentication result (especially the result of the first authentication). In this regard, particularly when the first authentication is, for example, possession information or biometric information, the first authentication may be completed without the user's active operation and without the user's awareness. In this case, there is a possibility that the first authentication is performed without the intention of the user and the provider. Specifically, for example, a situation may occur where another user who is not a settlement party is erroneously authenticated. Therefore, by performing the second authentication, the authentication system 100 can enhance the reliability of the result of the first authentication and realize an authentication process that balances the user's security awareness and convenience in the authentication process of settlement. Also, even when the first authentication is memory information, the authentication system 100 can enhance the reliability of the result of the first authentication by performing the second authentication.
[0120] FIG. 6 is a diagram showing an example of display information included in the first authentication result information. The display information shown in FIG. 6 shows, for example, an example of a screen displayed on at least one of the provider device 200 and the user device 300 that has acquired the first authentication result information.
[0121] The screen shown in FIG. 6 includes, for example, an area 601 for displaying image information showing the user's face, which is registered in advance, an area 602 for displaying image information showing the user's face, which is acquired in the first authentication by the first authentication unit 142, an area 603 for displaying the result of the first authentication (for example, the user name, service content, etc.), an area 604 for requesting the user to confirm the result of the first authentication, and an area 605 for receiving an operation by the user to approve the result of the first authentication.
[0122] When the user approves the result of the first authentication, for example, the user selects a button displayed in the area 605. In response to the selection by the user, for example, the provider device 200 provides operation information to the authentication system 100, the operation acquisition unit 151 acquires the operation information, and the second authentication unit 152 performs the second authentication based on the operation information.
[0123] Note that the screen shown in FIG. 6 is merely an example, and the screen displayed on at least one of the provider device 200 and the user device 300 is not limited to this.
[0124] FIG. 7 is a flowchart showing an example of processing in the authentication system 100 according to an embodiment of the present invention.
[0125] First, the user device 300 provides user authentication information to the authentication system 100 (S701), and the user registration unit 111 registers the user authentication information (S702).
[0126] The action history management system 400 provides user action history information to the authentication system 100 (S703), and the action history acquisition unit 122 acquires the user action history information. The authentication method generation unit 131 generates authentication method information based on the user action history information and the authentication history information stored in the authentication history storage unit 121 (S704).
[0127] The authentication method providing unit 133 provides the authentication method information to at least one of the provider device 200 and the user device 300 (for example, the provider device 200) (S705). The provider device 200 requests the user or the user device 300 to provide user authentication information corresponding to the authentication method information based on the authentication method information (S706).
[0128] The user or the user device 300 provides the user authentication information to the provider device 200 (S707). The provider device 200 provides the user authentication information to the authentication system 100, and the user authentication information acquisition unit 141 acquires the user authentication information from at least one of the provider device 200 and the user device 300 (for example, the provider device 200) (S708). The first authentication unit 142 performs the first authentication of the user's payment at the franchise store based on the authentication method information and the user authentication information (S709).
[0129] Subsequently, the first authentication result providing unit 143 provides the first authentication result information to, for example, the provider device 200 (S710). The provider device 200 displays the first authentication result (S711). The user performs an operation on the provider device according to the first authentication result information (S712). The operation acquisition unit 151 acquires operation information from the provider device 200 (S713). The second authentication unit 152 performs the second authentication based on the operation information (S714).
[0130] Note that the authentication method providing unit 133 may provide the authentication method information to the user device 300. In this case, the user may provide the user authentication information to the authentication system 100 directly or through the user device 300, and the user authentication information acquisition unit 141 may acquire the user authentication information from the user or the user device 300.
[0131] In addition, the provider device 200 may further provide the first authentication result information to the user device 300, or the first authentication result providing unit 143 may directly provide the first authentication result information to the user device 300. In this case, the operation acquisition unit 151 may acquire operation information from the user device 300.
[0132] As described above, an embodiment of the present invention has been explained. The authentication system 100 provides at least one authentication method information to at least one of the provider device 200 and the user device 300 based on the authentication history information and at least one user authentication information pre-registered by the user as an element of at least one authentication method, and based on the provided at least one authentication method information and the user authentication information acquired from at least one of the provider device 200 and the user device 300, performs the first authentication of the user, provides the first authentication result information regarding the result of the first authentication to at least one of the provider device 200 and the user device 300, and can perform the second authentication of the user based on the user's operation according to the first authentication result information. Thereby, in a face-to-face service that provides a service to the user in person, the user can be authenticated based on an authentication method that is flexibly set according to the user's authentication history.
[0133] In addition, the authentication system 100 provides the first authentication result information including display information for displaying image information showing the user's face included in at least one user authentication information acquired from at least one of the provider device 200 and the user device 300, and can perform the second authentication based on the user's operation on at least one of the provider device 200 and the user device 300 that displays the display information. Thereby, the user can easily confirm the result of the first authentication.
[0134] In addition, the authentication system 100 provides first authentication result information including display information for displaying image information showing the user's face, which is included in at least one piece of user authentication information acquired from at least one of the provider device 200 and the user device 300, and can perform second authentication based on a user operation on at least one of the provider device 200 and the user device 300 that displays the display information. Thereby, the user can easily confirm the result of the first authentication.
[0135] In addition, the authentication system 100 can authenticate a user by using at least one authentication method based on at least one of possession information, biometric information, and memory information.
[0136] In addition, the authentication system 100 can authenticate a user by using an authentication method that authenticates based on distance information indicating the distance between the user's possession and the provider terminal 220. Thereby, the authentication system 100 can easily authenticate a user who is near the provider terminal 220 in the service provider.
Description of Reference Numerals
[0137] 100 Authentication system, 111 User registration unit, 112 User information storage unit, 121 Authentication history storage unit, 122 Behavior history acquisition unit, 131 Authentication method generation unit, 132 Authentication method storage unit, 133 Authentication method providing unit, 141 User authentication information acquisition unit, 142 First authentication unit, 143 First authentication result providing unit, 151 Operation acquisition unit, 152 Second authentication unit, 200 Provider device, 210 Provider information processing system, 220 Provider terminal, 300 User device, 400 Behavior history management system
Claims
1. A computer, in a face-to-face service that provides services to a user face-to-face, based on at least one user authentication information pre-registered by the user, as authentication history information regarding the authentication history of the user and as elements of at least one authentication method for authenticating the user when providing the face-to-face service, at least one authentication method information regarding the at least one authentication method is provided to at least one of a provider device used by a provider of the service and a user device of the user; an authentication method providing unit; a first authentication unit that performs a first authentication of the user who receives the service based on the at least one authentication method information and the at least one user authentication information corresponding to the at least one authentication method information, which is obtained from at least one of the provider device and the user device; a first authentication result providing unit that provides first authentication result information regarding the result of the first authentication to at least one of the provider device and the user device; a second authentication unit that performs a second authentication of the user based on an operation of the user on at least one of the provider device and the user device according to the first authentication result information; An authentication program for realizing the above.
2. The first authentication result information includes display information for displaying image information showing the face of the user, which is included in the at least one user authentication information pre-registered; The second authentication unit performs the second authentication based on an operation of the user on at least one of the provider device and the user device for displaying the display information. The authentication program according to Claim 1.
3. The first authentication result information includes display information for displaying image information showing the face of the user, which is included in the at least one user authentication information pre-registered; The second authentication unit performs the second authentication based on an operation of the user on at least one of the provider device and the user device that displays the display information. The authentication program according to claim 1 or 2.
4. The at least one authentication method includes at least one authentication method based on at least any one of possession information regarding a possession possessed by the user, biometric information regarding the user's living body, and storage information stored by the user. The at least one user authentication information includes at least any one of the possession information, the biometric information, and the storage information. The authentication program according to claim 1 or 2.
5. The authentication program according to claim 4, wherein the possession information includes distance information indicating a distance between the possession and a provider terminal installed by the provider.
6. In a face-to-face service that provides a service to a user face-to-face, as an element of authentication history information regarding the authentication history of the user and at least one authentication method for authenticating the user when providing the face-to-face service, at least one authentication method information regarding the at least one authentication method is provided to at least one of a provider device used by a provider of the service and a user device of the user based on at least one user authentication information pre-registered by the user; A first authentication unit that performs a first authentication of the user who receives the service based on the at least one authentication method information and the at least one user authentication information corresponding to the at least one authentication method information, which is acquired from at least one of the provider device and the user device; A first authentication result providing unit that provides first authentication result information regarding the result of the first authentication to at least one of the provider device and the user device; a second authentication unit configured to perform a second authentication of the user based on an operation of the user on at least one of the provider device and the user device in accordance with the first authentication result information; An authentication system comprising:
7. The computer In a face-to-face service for providing a service to a user in face-to-face, at least one authentication method information relating to the at least one authentication method is provided to at least one of a provider device used by a provider of the service and a user device of the user, based on authentication history information relating to the authentication history of the user and at least one user authentication information registered in advance by the user as an element of at least one authentication method for authenticating the user when the face-to-face service is provided; performing a first authentication of the user who receives the service based on the at least one piece of authentication method information and the at least one piece of user authentication information corresponding to the at least one piece of authentication method information acquired from at least one of the provider device and the user device; providing first authentication result information regarding a result of the first authentication to at least one of the provider device and the user device; performing a second authentication of the user based on an operation of the user on at least one of the provider device and the user device in accordance with the first authentication result information; Authentication method.
Citation Information
Patent Citations
Approval terminal, settlement system, and settlement method
JP2020030669A
Authentication program, authentication system and authentication method
JP2023150067A
Facial recognition identification for in-store payment transactions
US20170323299A1
Electronic settlement system, terminal for individual, terminal for member store, authentication / settlement apparatus, electronic settlement method and electronic settlement program
JP2006190112A