Face authentication system

The face authentication system enhances attendance and departure management by integrating imaging and management terminals with setting features, improving operational efficiency and reducing costs.

JP2025102156APending Publication Date: 2025-07-08TERAOKA SEIKO CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023219431
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

Existing face recognition systems for attendance and departure management are inefficient and require improvements in operation and management.

Method used

A face authentication system comprising an imaging terminal and a management terminal, with features for setting face registration and authentication machines, and a transmission unit to configure and transmit settings to the imaging terminal, enabling efficient face registration and authentication processes.

Benefits of technology

Facilitates effective management and operation of attendance and departure processes through improved face recognition technology, allowing for seamless integration and cost-effective implementation in companies and organizations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025102156000001_ABST
    Figure 2025102156000001_ABST
Patent Text Reader

Abstract

To appropriately execute the management and operation of attendance / leaving.SOLUTION: A face authentication system including an imaging terminal having an imaging part, and a management terminal to perform face authentication by using a registered face image and a face image to be acquired during the face authentication, includes: face registration machine setting means for setting face registration machine setting information to make the imaging terminal function as a face authentication machine for imaging a face image to be used for registration on the basis of operation of the management terminal; face authentication machine setting means for setting face authentication machine setting information to make the imaging terminal function as a face authentication machine for imaging the face image during face authentication on the basis of operation of the management terminal; and transmission means for transmitting the face registration machine setting information set by the face registration machine setting means or the face authentication machine setting information set by the face authentication machine setting means to the imaging terminal on the basis of operation of the management terminal.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a face recognition system.

Background Art

[0002] A face recognition system using a user's face image is known (see, for example, Patent Document 1). Also, a system for managing the attendance and departure of employees and staff is known.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, there is room for improvement in the management and operation of attendance and departure.

[0005] The present invention has been made in view of such circumstances, and an object thereof is to provide a technology capable of suitably implementing the management and operation of attendance and departure.

Means for Solving the Problems

[0006] One aspect for solving the above-described problems is a face authentication system including an imaging terminal having an imaging unit and a management terminal, and performing face authentication using a registered face image and a face image acquired during face authentication. The face authentication system includes: a face registration machine setting unit configured to set face registration machine setting information for causing the imaging terminal to function as a face registration machine that captures a face image used for registration based on an operation of the management terminal; a face authentication machine setting unit configured to set face authentication machine setting information for causing the imaging terminal to function as a face authentication machine that captures a face image during face authentication based on an operation of the management terminal; and a transmission unit configured to transmit the face registration machine setting information set by the face registration machine setting unit or the face authentication machine setting information set by the face authentication machine setting unit to the imaging terminal based on an operation of the management terminal.

Brief Description of the Drawings

[0007]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Embodiment for Carrying Out the Invention

[0008] FIG. 1 is a conceptual diagram of a network for explaining the arrival / departure management system 1 of the present embodiment. As shown in FIG. 1, the arrival / departure management system 1 includes a management terminal 10, a store terminal 20, a mobile terminal 30, a Web server 100, a face recognition server 200, and a mail server 300.

[0009] The arrival / departure management system 1 manages arrival / departure (attendance), and is introduced into, for example, companies, institutions, groups, and organizations. The arrival / departure management system 1 is suitable for introduction into companies and the like having a plurality of workplaces (main offices, branch offices, stores, offices, research institutes, etc.). The arrival / departure management system 1 manages arrival / departure by face recognition. That is, in the arrival / departure management system 1, when storing the arrival time and departure time, a face is imaged to identify the person arriving / departing.

[0010] (Overview of Each Device) The management terminal 10 is installed, for example, in the headquarters (the management department of the head office) H. The management terminal 10 is, for example, a personal computer connectable to the Internet. Although not shown, the management terminal 10 includes a CPU 11, a storage unit (ROM, RAM, HDD, SDD, etc.) 12, an operation unit (mouse, keyboard, etc.) 13, a display unit 14, and a communication unit 16. Note that the display unit 14 may be a touch display having a touch panel.

[0011] The store terminal 20 is installed, for example, at each place of work (workplaces K-1, K-2, …). Note that a plurality of store terminals 20 may be installed within the same place of work (for example, a building). For example, a store terminal 20 for Department A may be installed on the floor of Part A on the first floor of the head office building, and a store terminal 20 for Department B may be installed on the floor of Part B on the second floor of the head office building. The store terminal 20 is, for example, a tablet terminal connectable to the Internet. Although illustration is omitted, the store terminal 20 includes a CPU 21, a storage unit (ROM, RAM, HDD, SDD, etc.) 22, a display unit (touch display) 24, an imaging unit (camera) 25, and a communication unit 26.

[0012] The mobile terminal 30 is carried by, for example, an individual subject to commuting management. The mobile terminal 30 is, for example, a smartphone connectable to the Internet. Although illustration is omitted, the mobile terminal 30 includes a CPU 31, a storage unit (ROM, RAM, SDD, etc.) 32, a display unit (touch display) 34, an imaging unit (camera) 35, and a communication unit 36. The mobile terminal 30 may include a position measurement unit (GPS, etc.) and a motion detection unit (acceleration sensor, gyro sensor, etc.). The mobile terminal 30 may be a tablet terminal.

[0013] Although the mobile terminal 30 is mainly assumed to be used outside the office, when a movement at a speed equal to or higher than that of the motion detection unit is detected, the operation may be restricted (for example, the operation to the face registration screen in Fig. 16(A) and the commuting screen in Fig. 16(B) is restricted). For example, a threshold of about 10 km / h is set, and when the mobile terminal 30 detects a movement speed equal to or higher than the threshold, since there is a possibility of driving a vehicle or a bicycle (a "vehicle" under the Road Traffic Law) whose legal speed is defined, including an electric kick scooter, the operation may be restricted. This serves as a measure for accident prevention such as preventing distracted driving. The restriction may be performed using the position measurement unit instead of or in addition to the motion detection unit.

[0014] The commuting management system 1 uses the web service provided by the web server 100 (the commuting service to be described later). Therefore, if the company has a personal computer (management terminal 10), a tablet terminal (store terminal 20), and a smartphone (mobile terminal 30), it can introduce the commuting management system 1. Accordingly, the company can introduce the commuting management system 1 in a short period and at low cost, and operate the commuting management system 1 at low cost.

[0015] The web server 100 is installed in, for example, a data center connectable to the Internet. Although not shown, the web server 100 includes a CPU 111, a storage unit (ROM, RAM, HDD, SDD, etc.) 112, and a communication unit 116. The face authentication server 200 is installed in, for example, a data center connectable to the Internet. Although not shown, the face authentication server 200 includes a CPU 211, a storage unit (ROM, RAM, HDD, SDD, etc.) 212, and a communication unit 216. The mail server 300 is installed in, for example, a data center connectable to the Internet. Although not shown, the mail server 300 includes a CPU 311, a storage unit (ROM, RAM, HDD, SDD, etc.) 312, and a communication unit 316.

[0016] (Functions of the web server 100) The web server 100 provides a web service related to commuting (hereinafter referred to as the commuting service). For example, the web server 100 includes a web page (web screen) and a web application (server-side program), and provides the commuting service through the web page and the web application. Specifically, the web server 100 provides a commuting screen (see, for example, FIG. 2) to the terminal in response to an access from the terminal (store terminal 20, mobile terminal 30) (access by a web browser), and executes various processes based on the information from the terminal (store terminal 20, mobile terminal 30).

[0017] For example, when the Web server 100 has previously acquired a face image (a captured image of an employee's face) as preparation for face authentication at the time of clocking in and out from terminals (store terminal 20, mobile terminal 30), the Web server 100 transmits the face image to the face authentication server 200 and stores it in a face authentication master (described later). Also, when the Web server 100 acquires a face image at the time of clocking in and out from terminals (store terminal 20, mobile terminal 30), the Web server 100 transmits the face image to the face authentication server 200 and causes the face authentication server 200 to perform face authentication at the time of clocking in and out. Further, when the authentication is successful, the Web server 100 stores the attendance and departure record information (punching information) of the employee identified from the face image in an attendance and departure record file (described later).

[0018] Hereinafter, a face image that the Web server 100 acquires and manages in advance as preparation for face authentication at the time of clocking in and out (specifically, the face image stored in the face authentication master) is referred to as a pre-registered face image, and a face image that the Web server 100 acquires when punching may be referred to as a face image for punching.

[0019] The Web server 100 can provide attendance and departure services according to each person's affiliation (e.g., workplace, department). That is, the Web server 100 can provide attendance and departure services with different contents for each affiliation.

[0020] For example, the Web server 100 may make the attendance and departure screens different between the ○ branch and the × branch. As an example, the Web server 100 may display buttons with different functions on the attendance and departure screen for the ○ branch and the attendance and departure screen for the × branch. That is, the Web server 100 may provide an attendance and departure screen with button a for function A arranged as the attendance and departure screen for the ○ branch, and an attendance and departure screen with button b for function B different from function A arranged as the attendance and departure screen for the × branch. In other words, the terminals for the ○ branch (store terminal 20 installed in the ○ branch, mobile terminal 30 of an individual belonging to the ○ branch) may display an attendance and departure screen that can execute function A by operating button a, and the terminals for the × branch (store terminal 20 installed in the × branch, mobile terminal 30 of an individual belonging to the × branch) may display an attendance and departure screen that can execute function B by operating button b.

[0021] The Web server 100 has been described as providing the check-in / check-out screen to the store terminal 20 and the mobile terminal 30, but there are conditions for providing the check-in / check-out screen. That is, the Web server 100 provides the check-in / check-out screen to the store terminal 20 and the mobile terminal 30 when the conditions are met. Specifically, the Web server 100 provides the check-in / check-out screen to the store terminal 20 and the mobile terminal 30 when it obtains the certificate information (password) from the store terminal 20 and the mobile terminal 30. For example, the Web server 100 provides the check-in / check-out screen when it obtains the certificate information when accessed from the store terminal 20 and the mobile terminal 30. Note that the store terminal 20 and the mobile terminal 30 may store the certificate information in the web browser in association with the access destination (URL) to the Web server 100 as a cookie and transmit the certificate information to the Web server 100 when accessing the Web server 100.

[0022] The Web server 100 generates and stores (manages) the certificate information for each affiliation. For example, the Web server 100 generates the certificate information for ○ branch, stores it as the certificate information for ○ branch, generates the certificate information for × branch, and stores it as the certificate information for × branch. For example, the Web server 100 may store the certificate information for each department (each affiliation) in the department master (described later).

[0023] As described above, the certificate information differs for each affiliation, but the URL of the check-in / check-out screen may differ for each affiliation or may be common to all affiliations.

[0024] When the URL of the attendance screen is different for each department, access may be controlled as follows. When the Web server 100 receives access from a terminal of a certain department (for example, the store terminal 20 installed in a certain branch or the mobile terminal 30 of an individual belonging to a certain branch) to the URL for that department, it determines whether the certificate information obtained from the terminal at the time of the access matches the certificate information of that department stored by itself. If the Web server 100 determines that the certificate information obtained from a terminal of a certain department matches the certificate information of that department stored by itself, it provides the attendance screen for that department to the terminal. If the Web server 100 determines that the certificate information obtained from a terminal of a certain department does not match the certificate information of that department stored by itself, it provides a screen for requesting certificate information to the terminal. Note that the Web server 100 also provides a screen for requesting certificate information to the terminal even when it has not obtained the certificate information when there is access from a terminal of a certain department to the URL for that department.

[0025] When the URL of the attendance screen is the same for all departments, access may be controlled as follows. When the Web server 100 receives access from a terminal of a certain department (for example, the store terminal 20 installed in a certain branch or the mobile terminal 30 of an individual belonging to a certain branch) to the URL common to all departments, it determines whether the certificate information obtained from the terminal at the time of the access matches the certificate information of any department stored by itself. If the Web server 100 determines that the certificate information obtained from a terminal of a certain department matches the certificate information of any department stored by itself, it provides the attendance screen for the department for which it is determined that the certificate information matches to the terminal. If the Web server 100 determines that the certificate information obtained from a terminal of a certain department does not match the certificate information of any department stored by itself, it provides a screen for requesting certificate information to the terminal. Note that the Web server 100 also provides a screen for requesting certificate information to the terminal even when it has not obtained the certificate information when there is access from a terminal of a certain department to the URL common to all departments.

[0026] That is, when each terminal belonging to a particular department accesses the check-in / check-out screen for that department (access to the URL specific to that department or access to a URL common to all departments), it attaches the certificate information belonging to that department (certificate information stored as a cookie) for access. As a result, each terminal belonging to a particular department can display the check-in / check-out screen for that department. Hereinafter, it is assumed that the URLs of the check-in / check-out screens are different for each department.

[0027] The web server 100 stores various information. For example, the web server 100 stores an employee master. The employee master is a file that stores, for example, an employee code (identification information for uniquely identifying an employee), name, department, employment category (regular employee, dispatched employee, contract employee, part-time, temporary worker, etc.), job title, phone number of the mobile terminal, email address of the mobile terminal, home phone number, address, face authentication permission / denial setting information, personal time recorder setting information, etc. The face authentication permission / denial setting information is information that sets permission / denial for punching in / out by face authentication. The personal time recorder setting information is information regarding the use of a personal time recorder (described later), which includes information that sets permission / denial for the use of the personal time recorder and information indicating whether a page (described later) regarding the personal time recorder has been distributed.

[0028] In addition, the web server 100 stores a company master regarding the entire company. The company master is a file that stores setting information regarding the entire company (all departments). For example, the company master stores, for example, the upper limit number of employees (persons) who are the subjects of face authentication by the departmental time recorder (described later) for the entire company, and the setting information (basic settings) of the screen (check-in / check-out screen) of the departmental time recorder for the entire company.

[0029] If the usage fee for the check-in / check-out service is a fee related to the number of face authentication subjects (for example, a fee system where it is X yen per month for up to 〇 persons and Y yen per month for up to △ persons), setting the upper limit of the subjects for the entire company will prevent the fee from exceeding the planned amount, so the introducing company can also feel at ease.

[0030] In addition, the Web server 100 stores a department master (affiliation master) related to departments. The department master is a file that stores setting information regarding individual affiliations. The department master stores, for example, the upper limit of the number of subjects for face authentication by the time recorders for individual affiliations, and the setting information (individual settings) of the screens of the time recorders for individual affiliations. The department master stores the email address of the device that functions as the time recorder for individual affiliations in each affiliation, and the email address of the terminal used by the person in charge of each affiliation. The department master may store the certificate information of each affiliation. The department master may store the work location, working hours, core time, etc.

[0031] As described above, when the usage fee of the attendance and departure service is a fee related to the number of subjects for face authentication, if the upper limit of the number of subjects for each affiliation is set, for example, an unexpected situation where the number of subjects in a certain affiliation has reached an unexpected number (it has become difficult to increase the number of subjects in other affiliations) can be prevented.

[0032] In addition, the Web server 100 stores an administrator master related to the administrator of the attendance and departure service. The administrator master is a file that stores, for example, the classification of the administrator (full authority administrator, general administrator), login ID, email address, etc.

[0033] In addition, the Web server 100 stores an attendance and departure performance file related to the attendance and departure performance. The attendance and departure performance file is a file that stores attendance and departure performance information. The attendance and departure performance information includes, for example, the employee code, arrival time, departure time, and face image for punching in the case of punching in by face authentication. The attendance and departure performance information includes, for example, the employee code, arrival time, departure time, and information indicating that it was the employee code in the case of punching in by the employee code.

[0034] The information stored in the Web server 100 can be referenced by the management terminal 10. The Web server 100 provides, for example, a management screen that can reference various masters (employee master, company master, department master, administrator master) and the attendance and departure record information stored in the attendance and departure record file to the management terminal 10. The Web server 100 provides a management screen to the management terminal 10 in response to an access from the management terminal 10 (access by a Web browser).

[0035] The information stored in the Web server 100 can be edited (changed) by the management terminal 10. The Web server 100 may, for example, accept edits to the various masters and the attendance and departure record information stored in the attendance and departure record file via the above management screen.

[0036] Note that the Web server 100 stores the employee master, but in addition to the Web server 100, other devices may also store the employee master. The information (information on some or all items) of the employee masters (the employee master stored in the Web server 100 and the employee master stored in other devices) is synchronized as appropriate. The same applies to other masters.

[0037] The content of the attendance and departure service provided by the Web server 100 is managed (set, changed) by the management terminal 10. For example, the content of the attendance and departure screen can be set / changed by the management terminal 10. Also, the information (for example, setting values, control parameters, etc.) referenced by the Web application of the Web server 100 can be set / changed by the management terminal 10.

[0038] The Web server 100 provides a management screen to the management terminal 10 that can set / change the content of the attendance and departure service. The Web server 100 provides a management screen to the management terminal 10 in response to an access from the management terminal 10 (access by a Web browser).

[0039] (Functions of the face authentication server 200) The face authentication server 200 stores a face authentication master and performs face authentication. The face authentication master stores, for example, an employee code, one or more pre-registered face images (pre-registered face images of the employee with the corresponding employee code), the imaging date and time, etc. The face authentication server 200 acquires a face image for punching from the web server 100 and identifies one employee by referring to the face authentication master. Specifically, the face authentication server 200 compares the face image for punching acquired from the web server 100 with each pre-registered face image in the face authentication master (determines whether the faces match) and identifies the employee determined to be the same person.

[0040] Although it has been described that the face authentication server 200 stores pre-registered face images in the face authentication master, the face authentication server 200 acquires a face image (hereinafter sometimes referred to as a "pre-registration candidate face image" or a "face image for pre-registration") that becomes a pre-registered face image from the web server 100, and stores the pre-registration candidate face image acquired from the web server 100 in the face authentication master as a pre-registered face image. As described above, the web server 100 acquires a face image (pre-registration candidate face image) in advance as a preparation for face authentication from the terminal (store terminal 20, mobile terminal 30) and transmits it to the face authentication server 200. However, the web server 100 provides a face registration screen (for example, FIGS. 4 and 16(A)) capable of acquiring an employee code and a pre-registration candidate face image to the terminal, acquires a pre-registration candidate face image from the terminal via the face registration screen, and transmits the pre-registration candidate face image acquired from the terminal to the face authentication server 200. The web server 100 provides a face registration screen to the terminal in response to an access from the terminal (store terminal 20, mobile terminal 30) (access by a web browser).

[0041] The information stored by the face authentication server 200 can be referred to by the management terminal 10. The web server 100 provides, for example, a management screen that can refer to information based on the face authentication master stored by the face authentication server 200 to the management terminal 10. The web server 100 provides the management screen to the management terminal 10 in response to an access from the management terminal 10 (access by a web browser).

[0042] The information stored in the face authentication server 200 can be edited (changed) by the management terminal 10. The web server 100 may accept editing of the information stored in the face authentication master, for example, via the above-described management screen.

[0043] (Function of the management terminal 10) The management terminal 10 manages (configures, changes) the content of the attendance service provided by the web server 100. For example, the management terminal 10 manages the content of the attendance service via the above-described management screen. The management terminal 10 is used by an administrator who manages the attendance service.

[0044] The management terminal 10 displays the information stored in the web server 100 in an editable manner. For example, the management terminal 10 accesses the URL of the management screen using a web browser and displays the information stored in various masters and the attendance record file in an editable manner on the management screen.

[0045] The management terminal 10 displays the information stored in the face authentication server 200 in an editable manner. For example, the management terminal 10 accesses the URL of the management screen using a web browser and displays the information based on the face authentication master in an editable manner on the management screen.

[0046] The management screen that the management terminal 10 accesses and displays on the web server 100 has, for example, the following functions (1) to (5).

[0047] (1) Display of log list Displays the attendance record information stored in the attendance record file as the attendance log of employees. Also, stores and displays the operation information by the administrator and the operation of the system (such as synchronization of masters) as the log of the administrator / system.

[0048] (2) Employee settings Displays and sets (registers, edits) information related to employees.

[0049] (3) Page distribution Distribute pages related to the departmental time recorder, personal time recorder, and face registration. The departmental time recorder is a time recorder realized by the store terminal 20. The personal time recorder is a time recorder realized by the mobile terminal 30. Distributing the page related to the personal time recorder means distributing information (such as an email) related to the personal time recorder. The same applies to distributing the page related to the personal time recorder and the page related to face registration. That is, the function of distributing a page related to XX (such as the personal time recorder) is the function of distributing information related to XX.

[0050] (4) Administrator Settings Display and set (register and edit) information related to the administrator of the attendance service (full authority administrator, general administrator).

[0051] (5) Company Information Display and set (register and edit) information related to the company introducing the attendance service (such as information common to all departments, information for each department).

[0052] (Functions of the Store Terminal 20) The store terminal 20 functions as a departmental time recorder (departmental face recognition device). The departmental time recorder is a time recorder installed at workplaces such as main branches and used by multiple employees during attendance and departure. The store terminal 20, as a departmental time recorder, captures the faces of employees (acquires face images for punching) during attendance and departure and transmits them to the Web server 100. Thereby, the attendance and departure performance information of employees is stored in the attendance and departure performance file.

[0053] The store terminal 20 receives the page related to the departmental time recorder distributed from the Web server 100 and functions as a departmental time recorder after the procedure for activating the face recognition device (time recorder) indicated by the page (the procedure by the workplace administrator). The above procedure will be described later.

[0054] In addition, the store terminal 20 functions as a face registration device for registering the pre-acquired face images. As a face registration device, the store terminal 20 captures the face of an employee (acquires a pre-registration candidate face image) and transmits it to the Web server 100. Thereby, the pre-registered face image of the employee is stored in the face authentication master.

[0055] The store terminal 20 functions as a face registration device after the procedure for activating the face authentication device. That is, the store terminal 20 that functions as a face authentication device also functions as a face registration device.

[0056] (Function of the mobile terminal 30) The mobile terminal 30 functions as a personal time recorder (personal face authentication device). A personal time recorder is a time recorder carried by individual employees and used by individual employees when clocking in and out. As a personal time recorder, the mobile terminal 30 captures the face of an employee (acquires a clock-in / out face image) when clocking in and out and transmits it to the Web server 100. Thereby, the clock-in / out performance information of the employee is stored in the clock-in / out performance file.

[0057] The mobile terminal 30 receives a page related to the personal time recorder distributed from the Web server 100 and functions as a personal time recorder after the procedure for activating the face authentication device (procedure by an individual) indicated by the page.

[0058] In addition, the mobile terminal 30 functions as a face registration device for registering the pre-acquired face images. As a face registration device, the mobile terminal 30 captures the face of an employee (acquires a pre-registration candidate face image) and transmits it to the Web server 100. Thereby, the pre-registered face image of the employee is stored in the face authentication master).

[0059] The mobile terminal 30 receives a page related to face registration distributed from the Web server 100 and functions as a face registration device after the procedure for activating the face registration device (procedure by an individual) indicated by the page. The above procedure will be described later.

[0060] Figures 2 to 4 are display examples of the store terminal 20. The store terminal 20, as an affiliated time recorder (affiliated face recognition device), displays a commuting screen (also referred to as an affiliated time recorder screen) as shown in Figure 2. Specifically, the store terminal 20 accesses the Web server 100 and displays a commuting screen as shown in Figure 2. That is, the Web server 100 transmits the commuting screen of Figure 2 to the store terminal 20 based on the above access.

[0061] Note that the access destination (URL) of the commuting screen to the Web server 100 may be different for each affiliation as described above, or may be common to all affiliations. In this example, however, it is assumed to be different for each affiliation. Specifically, in the URL (xxx.xxx.jp / … / s-rec / ho / ) of the commuting screen in Figure 2, the part "ho" indicates the head office of the relevant affiliation. Note that "s-rec" indicates an affiliated time recorder.

[0062] The commuting screen in Figure 2 displays the current time (the year, month, and day may also be displayed). On the commuting screen in Figure 2, there are arranged a punch-in button BT201, a punch-out button BT202, a break-in button BT203, a break-return button BT204, a time card button BT210, and a face registration button BT211, and an attendance status list area AR220 is provided. Information based on the commuting record information is displayed in the attendance status list area AR220. Each button may be made easy to operate by color coding (easy to find the desired button, difficult to misoperate). For example, the punch-in button BT201 may be displayed in a more prominent color than other buttons during the punch-in time zone (e.g., until 11:00), and the punch-in button BT201 may be displayed in a more prominent color than other buttons during the punch-out time zone (e.g., after 15:00).

[0063] The attendance button BT201 is a button to be operated at the time of attendance. The leaving work button BT202 is a button to be operated at the time of leaving work. The break-in button BT203 is a button to be operated at the start of personal break (break during working hours). The break-return button BT204 is a button to be operated at the end of personal break. The time card button BT210 is a button (link button to the management screen) for displaying the management screen. The face registration button BT211 is a button (link button to the face registration screen) for displaying the face registration screen (for example, FIG. 4). The management screen displayed by operating the time card button BT210 may display some of the information displayed on the management screen (for example, FIG. 5) displayed by the management terminal 10.

[0064] When an employee arrives at work, the employee operates the attendance button BT201 and takes an image of his / her face. If face authentication is successful, the attendance time and other information are displayed in the attendance status list area AR220. That is, when the attendance button BT201 is operated, the store terminal 20 activates the camera as a face authentication device and takes an image of the employee's face (obtains a face image for punching). Subsequently, the store terminal 20 transmits the face image for punching to the web server 100 (that is, requests face authentication from the face authentication server 200), face authentication is performed in the face authentication server 200 (the employee is identified), and the attendance time and other information are displayed in the attendance status list area AR220. The same applies when leaving work, at the start of personal break, and at the end of personal break.

[0065] In the attendance status list area AR220, the face image (face image for punching) and name of the employee are displayed. As a result, for example, although it is not immediately easy to understand simply from the character information (name) alone, since there is also image information (face image), information about the status of other employees, such as "this person is present", is more likely to be obtained. Also, since the face and name are shown as a set, they can be remembered as a set and can also be used as a kind of communication tool (a tool for fixing a person and their face). Note that a pre-registered face image may be displayed instead of the face image for punching. However, while the face image for punching obtained each time basically has variations, the pre-registered face image basically has no variations, and since the pre-registered face image is a face image confirmed by the person himself / herself, it can also be said to be suitable in terms of grasping the status of other employees and using it as a communication tool.

[0066] In the column (item) of "authentication information" in the attendance status list area AR220 of FIG. 2, a face image is displayed in the case where face authentication has been performed. However, in the case where punching is performed using the employee code, information indicating that punching has been performed using the employee code (for example, words such as "code", "code punching", "code input", etc.) is displayed. Therefore, by looking at the attendance status list area AR220, it is possible to easily recognize whether each employee has punched in by face authentication or by employee code.

[0067] When an employee starts face registration, the employee operates the face registration button BT211 to capture his / her own face. The captured face image is registered. That is, when there is an operation of the face registration button BT211, the store terminal 20 operates as a face registration machine, activates the camera as a face registration machine, and captures the face of the employee (obtains a pre-registered candidate face image). Subsequently, the store terminal 20 transmits the pre-registered candidate face image to the web server 100. The pre-registered candidate face image transmitted by the store terminal 20 is stored as a pre-registered face image in the face authentication master of the face authentication server 200.

[0068] When there is an operation on the attendance button BT201 of the attendance / check - out screen on the store terminal 20, the camera is activated, and a small screen (pop - up screen) SG2000 as shown in Fig. 3(A) is pop - up displayed in front of the attendance / check - out screen. That is, the Web server 100 transmits the small screen SG2000 in Fig. 3(A) to the store terminal 20 based on the operation of the attendance button BT201.

[0069] At the upper part of the small screen SG2000 in Fig. 3(A), a message indicating the start of face authentication (in this example, "Start face authentication") is displayed. Also, on the small screen SG2000, an imaging area AR2100 is provided, and an attendance button BT2101 and a code - stamping button BT2102 are arranged. When an employee performs face authentication, on the small screen SG2000, the employee adjusts the position of the face so that the face is imaged in the imaging area AR2100 and operates the attendance button BT2101. When an employee performs code - stamping, the employee operates the code - stamping button BT2102.

[0070] When there is an operation on the attendance button BT2101 of the small screen SG2000 on the store terminal 20, the face is imaged (a face image for stamping is acquired), the face image for stamping is transmitted to the Web server 100, and a small screen SG2001 as shown in Fig. 3(B) is pop - up displayed in front of the attendance / check - out screen instead of the small screen SG2000. That is, the Web server 100 transmits the small screen SG2001 in Fig. 3(B) to the store terminal 20 based on the operation of the attendance button BT2101. Note that between the small screen SG2000 in Fig. 3(A) and the small screen SG2001 in Fig. 3(B), there is a scene after adjusting the position of the face and before operating the attendance button BT2101 (a scene corresponding to the small screen SG2014 in Fig. 4(F) between the small screen SG2014 in Fig. 4(E) and the small screen SG2015 in Fig. 4(G)), but the illustration of the intermediate scene is omitted in the transition from Fig. 3(A) to Fig. 3(B).

[0071] The case of an operation on the code - stamping button BT2102 of the small screen SG2000 will be described later.

[0072] At the upper part of the small screen SG2001 in FIG. 3(B), a message indicating that face authentication is in progress (in this example, "Face authentication in progress...") is displayed. Also, in the imaging area AR2100 of the small screen SG2001, a face image for stamping is displayed.

[0073] (Face authentication) In addition, the Web server 100 transmits the face image for stamping obtained from the store terminal 20 to the face authentication server 200 together with an instruction (request) for face authentication based on the operation of the attendance button BT2101.

[0074] The face authentication server 200 that has obtained (received) the face image for stamping together with the instruction for face authentication from the Web server 100 (that is, the face authentication server 200 requested for face authentication by the Web server 100) performs face authentication. Specifically, the face authentication server 200 determines that the face authentication is successful if a pre-registered face image that matches the face image for stamping obtained from the Web server 100 is stored in the face authentication master, and determines that the face authentication has failed if a pre-registered face image that matches the face image for stamping obtained from the Web server 100 is not stored in the face authentication master. The face recognition algorithm is not particularly limited, and may be, for example, eigenface using principal component analysis, linear discriminant analysis, elastic bunch graph matching, hidden Markov model, dynamic link matching by neuron motivation, etc.

[0075] (When face authentication is successful) When the face authentication is successful (when a pre-registered face image that matches the face image for stamping is stored in the face authentication master), the face authentication server 200 transmits the employee code of the employee whose pre-registered face image matches the face image for stamping (the employee whose face image matches) to the Web server 100. In other words, when the face authentication server 200 can identify the employee based on the face image for stamping and the face authentication master (the pre-registered face image in the face authentication master), it transmits the employee code of the said employee to the Web server 100.

[0076] That is, when face authentication by the face authentication server 200 is successful (when an employee whose face image matches is identified by the face authentication server 200), the Web server 100 acquires (receives) the employee code of the employee for whom face authentication has been successful from the face authentication server 200. The Web server 100 that has acquired the employee code stores the attendance and departure record information of the employee (the employee code, attendance time, and face image for punching of the employee) in the attendance and departure record file, and reflects (displays) information based on the attendance and departure record information on the attendance status list area AR220 of the attendance and departure screen, and transmits to the store terminal 20 a small screen SG2002 as shown in FIG. 3(C).

[0077] In other words, when face authentication is successful, the store terminal 20 pops up and displays the small screen SG2002 in FIG. 3(C) in front of the attendance and departure screen instead of the small screen SG2001 in FIG. 13(B). Further, the store terminal 20 displays the attendance time of the employee who has succeeded in face authentication in the attendance status list area AR220 of the attendance and departure screen on the back of the small screen SG2002.

[0078] At the upper part of the small screen SG2002 in FIG. 3(C), a message indicating that face authentication has been completed (in this example, "Authenticated!") is displayed. In the imaging area AR2100 of the small screen SG2002, an image (in this example, a mascot image) is displayed instead of the face image for punching, and the attendance time and employee name are displayed at the lower part of the imaging area AR2100. Further, a continuous attendance button BT2103 and a return button BT2104 are arranged on the small screen SG2002.

[0079] When the continuous attendance button BT2103 of the small screen SG2002 is operated on the store terminal 20, the store terminal 20 pops up and displays the small screen SG2000 in FIG. 3(A) in front of the attendance and departure screen instead of the small screen SG2002. That is, the Web server 100 transmits the small screen SG2000 in FIG. 3(A) to the store terminal 20 based on the operation of the continuous attendance button BT2103 of the small screen SG2002. For example, another employee (the next employee) operates the continuous attendance button BT2103 of the small screen SG2002 in FIG. 3(C) and starts face authentication from the small screen SG2000 in FIG. 3(A) that is displayed again after the operation.

[0080] When there is an operation on the back button BT2104 of the small screen SG2002, the store terminal 20 deletes the small screen SG2002. In addition, when there is no operation on either the consecutive attendance button BT2103 or the back button BT2104 on the small screen SG2002 and a predetermined time (10 seconds in this example) has elapsed since the start of the small screen SG2002, the store terminal 20 also deletes the small screen SG2002. In addition, the store terminal 20 may notify the Web server 100 that the small screen SG2002 has been deleted.

[0081] (When face authentication fails) When face authentication fails (when the pre-registered face image that matches the face image for punching is not stored in the face authentication master), the face authentication server 200 transmits information indicating that face authentication has failed to the Web server 100. In other words, when the face authentication server 200 cannot identify an employee based on the face image for punching and the face authentication master (pre-registered face image), the face authentication server 200 transmits information indicating that face authentication has failed to the Web server 100.

[0082] That is, when face authentication by the face authentication server 200 fails (when an employee whose face image matches cannot be identified by the face authentication server 200), the Web server 100 obtains (receives) information indicating that face authentication has failed from the face authentication server 200. The Web server 100 that has obtained information indicating that face authentication has failed transmits a small screen SG2003 as shown in FIG. 3(D) to the store terminal 20.

[0083] In other words, when face authentication fails, the store terminal 20 pops up and displays the small screen SG2003 in FIG. 3(D) in front of the attendance / punching screen instead of the small screen SG2001 in FIG. 3(B).

[0084] At the upper part of the small screen SG2003 in Fig. 3(D), a message indicating that face authentication has failed (in this example, "Authentication failed") is displayed. Also, in the imaging area AR2100 of the small screen SG2003, the face image for stamping is displayed, and the re-authentication button BT2105 and the code stamping button BT2102 are arranged. In addition, a caution message (in this example, "Please check if your face, hair, shadow, etc. are not hidden") is displayed.

[0085] When the re-authentication button BT2105 on the small screen SG2003 of the store terminal 20 is operated, the small screen SG2000 in Fig. 3(A) is pop-up displayed in front of the attendance / leaving work screen instead of the small screen SG2003. That is, the Web server 100 transmits the small screen SG2000 in Fig. 3(A) to the store terminal 20 based on the operation of the re-authentication button BT2105. For example, an employee who has failed face authentication operates the re-authentication button BT2105 on the small screen SG2003 in Fig. 3(D), and starts face authentication again from the small screen SG2000 in Fig. 3(A) that is displayed again after the operation.

[0086] When face authentication is successful, as shown in Fig. 3(C), the store terminal 20 displays an image (mascot image) without displaying the face image for stamping that was displayed on the small screen SG2001 in Fig. 3(B). On the other hand, when face authentication fails, as shown in Fig. 3(D), the face image for stamping that was displayed on the small screen SG2001 in Fig. 3(B) is displayed together with the caution message. That is, when face authentication is successful, it can be said that the store terminal 20 omits the display of the face image for stamping (the face image for stamping in Fig. 3(B)) that is displayed when face authentication fails, and displays an image.

[0087] When face authentication is successful, if the face image for punching (the face image for punching at the time of success) is displayed, there may be a situation where others (for example, the next employee) can see the face image for punching (that is, one's own face photo. A face photo that may not look good even though face authentication is successful). Due to the feeling of not wanting others to see the face image for punching in such a situation, there is a possibility of not leaving the scene until the face image for punching is deleted. Also, even if one doesn't wait until the face image for punching is deleted, there may be a situation where one checks the face image for punching, for example, by looking at a mirror. On the other hand, if the face image for punching is not displayed (if an image is displayed) when face authentication is successful, the above-mentioned situation does not occur, so one will leave the scene immediately after face authentication is successful. That is, if an image is displayed instead of the face image for punching when face authentication is successful, the punching of the next employee will start smoothly (the rotation of the person during punching will speed up), and it will be difficult for congestion to occur during punching at the store terminal 20. Also, if a common (identical) image is displayed immediately when face authentication is successful, the feeling of "image = face authentication successful" will be established, and it will be possible to immediately recognize that face authentication is successful based on the display of the image. Therefore, in addition to the above-mentioned elimination of congestion, it also leads to a reduction in the confirmation work of whether it was successful or not.

[0088] On the other hand, when face authentication fails, by properly showing the face image for punching to the person along with a caution message, it is possible to understand what was the cause of the failure. That is, the store terminal 20 does not show the face image for punching to the person for the reasons described above when face authentication is successful, while when face authentication fails, it shows a caution message + the actual face image for punching at the time of failure to allow the person to confirm what was the cause of the failure, making it easier for face authentication to be successful again after the operation of the re-authentication button BT2105.

[0089] (Punching by employee code) When an operation is performed on the code stamping button BT2102 of the small screen SG2000 in Fig. 3(A) (the same applies when an operation is performed on the code stamping button BT2102 of the small screen SG2003 in Fig. 3(D)), the store terminal 20 pops up and displays a small screen SG2004 (not shown) instead of the small screen SG2000 (small screen SG2003). That is, the web server 100 transmits the small screen SG2004 (not shown) to the store terminal 20 based on the operation of the code stamping button BT2102.

[0090] At the upper part of the small screen SG2004 (not shown), a message indicating that it is stamping by the employee code (for example, "Employee code stamping") is displayed. Also, on the small screen SG2004, an employee code input area AR2100 for inputting the employee code is provided, and a re - authentication button BT2111 (not shown) and an attendance button BT2112 (not shown) are arranged. The employee inputs the employee code into the employee code input area AR2100 of the small screen SG2004 and operates the attendance button BT2112. Input keys such as a numeric keypad used for inputting the employee code into the employee code input area AR2100 may be arranged on the small screen SG2004 (not shown), or when the small screen SG2004 (not shown) is displayed (when an operation is performed on the code stamping button BT2102), a small screen (not shown) with the above - mentioned input keys arranged together with the small screen SG2004 (not shown) may be displayed. In addition, when the employee performs face authentication, the employee operates the re - authentication button BT2111.

[0091] When there is an operation on the attendance button BT2112 of the small screen SG2004 (not shown) on the store terminal 20, the employee code entered in the employee code input area AR2100 is sent to the web server 100, and a small screen SG2005 (not shown) is pop-up displayed instead of the small screen SG2004. That is, the web server 100 that has acquired (received) the employee code confirms that the employee code acquired from the store terminal 20 matches any of the employee codes stored in the employee master, and also confirms that the attendance time has not yet been stored in the attendance and departure record file in association with the employee code acquired from the store terminal 20. The attendance and departure record information of the employee (the employee code of the employee, the attendance time, and the information indicating that the punching was performed using the employee code) is stored in the attendance and departure record file, and an attendance status screen that reflects (displays) the information based on the attendance and departure record information in the attendance status list area AR220, and the small screen SG2005 (not shown) are sent to the store terminal 20. When there is an operation on the re-authentication button BT2111 of the small screen SG2004, the store terminal 20 displays the small screen SG2000 in Fig. 3(A).

[0092] At the upper part of the small screen SG2005 (not shown), a message indicating that it is punching by the employee code (for example, "Employee code punching") is displayed. Also, on the small screen SG2005, the attendance time and the employee name are displayed, and a continuous attendance button BT2113 (not shown) and a return button BT2114 (not shown) are arranged.

[0093] When there is an operation on the continuous attendance button BT2113 of the small screen SG2005 (not shown) on the store terminal 20, the small screen SG2000 in Fig. 3(A) is pop-up displayed in front of the attendance and departure screen instead of the small screen SG2005. That is, the web server 100 transmits the small screen SG2000 in Fig. 3(A) to the store terminal 20 based on the operation of the continuous attendance button BT2113 of the small screen SG2005. For example, another employee (the next employee) operates the continuous attendance button BT2113 of the small screen SG2005 and starts face authentication from the small screen SG2000 in Fig. 3(A) that is redisplayed after the operation. Note that when there is an operation on the continuous attendance button BT2113 of the small screen SG2005, the store terminal 20 may pop-up display the small screen SG2004 (not shown) in front of the attendance and departure screen instead of the small screen SG2005. That is, the web server 100 may transmit the small screen SG2004 to the store terminal 20 based on the operation of the continuous attendance button BT2113 of the small screen SG2005. For example, another employee (the next employee) operates the continuous attendance button BT2113 of the small screen SG2005 and starts punching in with the employee code from the small screen SG2004 that is redisplayed after the operation.

[0094] When there is an operation on the back button BT2114 of the small screen SG2005 (not shown) on the store terminal 20, the small screen SG2005 is erased. Note that the store terminal 20 also erases the small screen SG2005 when there is no operation on either the continuous attendance button BT2113 or the back button BT2114 on the small screen SG2005 and a predetermined time (10 seconds in this example) has elapsed since the start of the small screen SG2005.

[0095] The above is the operation when punching in with the employee code is successful (the employee code transmitted from the store terminal 20 to the web server 100 matches any of the employee codes stored in the employee master, and the attendance time is not stored in the attendance and departure record file associated with the employee code). However, when punching in with the employee code is not successful, for example, the following operations will occur.

[0096] For example, if the employee code obtained by the Web server 100 does not match any of the employee codes stored in the employee master that were obtained from the store terminal 20, the Web server 100 does not store the attendance and departure record information of the employee in the attendance and departure record file. Instead, it simply displays an error message (an error message indicating that the employee codes do not match) and sends a small screen SG2006 (not shown) that requests re-entry of the employee code to the store terminal 20. That is, the store terminal 20 pops up and displays the small screen SG2006 (not shown) instead of the small screen SG2004.

[0097] Also, if the Web server 100 that has obtained the employee code already has an attendance time stored in the attendance and departure record file associated with the employee code, the Web server 100 does not store the attendance and departure record information of the employee in the attendance and departure record file. Instead, it simply displays an error message (an error message indicating that the employee has already checked in) and sends a small screen SG2007 (not shown) that requests re-entry of the employee code to the store terminal 20. That is, the store terminal 20 pops up and displays the small screen SG2007 (not shown) instead of the small screen SG2004. The same control may be applied in the case of clock-in by face authentication.

[0098] Note that by referring to the employee master, the affiliation of the employee is specified from the employee code. If the specified affiliation matches the affiliation related to the store terminal 20, clock-in by the employee code is permitted (resulting in the display of the small screen SG2005), and if the specified affiliation does not match the affiliation related to the store terminal 20, clock-in by the employee code is prohibited (an error message indicating that the affiliations do not match is displayed, and a small screen with a return button is displayed). The same control may be applied in the case of clock-in by face authentication.

[0099] Although the small screens SG2000 to SG2005 (not shown) have been described as the screens displayed after the operation of the attendance button BT201 on the attendance and departure screen (Figure 2), the same applies to the screens displayed after the operation of the departure button BT202, the leave-in button BT203, or the leave-return button BT204 on the attendance and departure screen (Figure 2).

[0100] For example, after the operation of the attendance button BT201, the store terminal 20 displays a small screen SG2000 (Fig. 3(A)) in which an attendance button BT2101 and a code stamping button BT2102 are arranged. After the operation of the leaving work button BT202, a small screen (not shown) in which a leaving work button (not shown) is arranged instead of the attendance button BT2101 is displayed. After the operation of the rest-in button BT203, a small screen (not shown) in which a rest-in button (not shown) is arranged instead of the attendance button BT2101 is displayed. After the operation of the rest-return button BT204, a small screen (not shown) in which a rest-return button (not shown) is arranged instead of the attendance button BT2101 is displayed.

[0101] Since the small screens SG2000 to SG2003 are screens for stamping by face authentication, they may also be referred to as face authentication stamping screens. Since the small screen SG2004 (not shown) and the small screen SG2005 (not shown) are screens for stamping by employee code, they may also be referred to as employee code stamping screens.

[0102] The face authentication stamping screen does not have to be a pop-up screen displayed in front of the attendance / leaving work screen. For example, the display content (imaging area AR2100 and various buttons) of the face authentication stamping screen may be displayed in a partial area of the attendance / leaving work screen. That is, the store terminal 20 may display the display content of the face authentication stamping screen in a partial area of the attendance / leaving work screen based on the operation of the attendance button BT201 or the like. Also, for example, the face authentication stamping screen may be displayed instead of the attendance / leaving work screen. That is, the store terminal 20 may display the face authentication stamping screen instead of the attendance / leaving work screen based on the operation of the attendance button BT201 or the like. The same applies to the employee code stamping screen.

[0103] In the mode of displaying the face authentication punching screen on the entire screen (full screen) (the mode of displaying the face authentication punching screen instead of the attendance and departure screen), since the face authentication punching screen is displayed large and is likely to be seen by others (for example, the next employee) (or is likely to be clearly seen), the mode of displaying the face authentication punching screen as a pop-up screen or the mode of displaying the face authentication punching screen in a partial area of the attendance and departure screen is preferable. Also, between the mode of displaying the face authentication punching screen as a pop-up screen and the mode of displaying the face authentication punching screen in a partial area of the attendance and departure screen, in the former mode, since it only needs to be popped up at a position suitable for shooting (without considering the layout such as the arrangement of each area within the attendance and departure screen), in this regard, it is more advantageous than the latter mode.

[0104] (Face registration) When an operation is performed on the face registration button BT211 of the attendance and departure screen on the store terminal 20, a small screen SG2010 as shown in Fig. 4(A) is pop-up displayed in front of the attendance and departure screen. That is, the web server 100 transmits the small screen SG2010 in Fig. 4(A) to the store terminal 20 based on the operation of the face registration button BT211.

[0105] In the small screen SG2010 of Fig. 4(A), an employee code input area AR2200 for inputting the employee code is provided, and a back button BT2201 and a next button BT2202 are arranged. The employee inputs the employee code in the employee code input area AR2200 of the small screen SG2010 and operates the next button BT2202. In addition, when the employee stops face registration, the back button BT2201 is operated (the small screen SG20 is erased by the operation of the back button BT2201). Input keys such as a numeric keypad used for inputting the employee code into the employee code input area AR2200 may be arranged on the small screen SG2010, or when the small screen SG2010 is displayed (when an operation is performed on the face registration button BT211), a small screen (not shown) with the above-mentioned input keys arranged together with the small screen SG2010 may be displayed.

[0106] When there is an operation on the Next button BT2202 of the small screen SG2010 on the store terminal 20, the store terminal 20 temporarily stores the employee code entered in the employee code input area AR2200 and sends it to the web server 100, and pops up and displays a small screen SG2011 as shown in FIG. 4(B) instead of the small screen SG2010. That is, the web server 100 that has acquired (received) the employee code refers to the employee master and sends the small screen SG2011 with the name of the employee specified by the employee code displayed thereon to the store terminal 20.

[0107] On the small screen SG2011 in FIG. 4(B), the name of the employee is displayed, and the Back button BT2201 and the Next button BT2202 are arranged. The employee checks the name and operates the Next button BT2202. In addition, for example, when the name is incorrect (that is, when the entered employee code is incorrect), the employee operates the Back button BT2201 (by operating the Back button BT2201, the small screen SG2010 is displayed instead of the small screen SG2011).

[0108] When there is an operation on the Next button BT2202 of the small screen SG2011 on the store terminal 20, the store terminal 20 pops up and displays a small screen SG2012 as shown in FIG. 4(C) instead of the small screen SG2011. That is, the web server 100 sends the small screen SG2012 in FIG. 4(C) to the store terminal 20 based on the operation on the Next button BT2202 of the small screen SG2011.

[0109] On the small screen SG2012 in FIG. 4(C), the precautions at the time of registration are displayed, and the Back button BT2201 and the Next button BT2202 are arranged. The employee checks the precautions and operates the Next button BT2202.

[0110] When an operation is performed on the Next button BT2202 of the small screen SG2012 on the store terminal 20, a small screen SG2013 as shown in FIG. 4(D) is pop-up displayed in place of the small screen SG2012. That is, the web server 100 transmits the small screen SG2013 in FIG. 4(D) to the store terminal 20 based on the operation of the Next button BT2202 of the small screen SG2012.

[0111] On the small screen SG2013 in FIG. 4(D), the precautions at the time of registration are displayed, and a Back button BT2201 and a Next button BT2202 are arranged. The employee checks the precautions and operates the Next button BT2202.

[0112] When an operation is performed on the Next button BT2202 of the small screen SG2013 on the store terminal 20, the camera is activated, and a small screen SG2014 as shown in FIG. 4(E) is pop-up displayed in place of the small screen SG2013. That is, the web server 100 transmits the small screen SG2014 in FIG. 4(E) to the store terminal 20 based on the operation of the Next button BT2202 of the small screen SG2013.

[0113] On the small screen SG2014 in FIG. 4(E), an imaging area AR2210 is provided, and a Back button BT2201 and a Shooting button BT2203 are arranged. The employee adjusts the position of the face so that the face is imaged in the imaging area AR2210 and operates the Shooting button BT2203.

[0114] FIG. 4(F) shows a scene where the position of the face before the operation of the Shooting button BT2203 is adjusted. A through image (view image) is displayed in the imaging area AR2210 of the small screen SG2014 in FIG. 4(F).

[0115] When there is an operation on the shooting button BT2203 of the small screen SG2014 on the store terminal 20, the face is imaged (the pre-registered candidate face image is acquired), the pre-registered face image is sent to the web server 100, and a small screen SG2015 as shown in Fig. 4(G) is pop-up displayed instead of the small screen SG2014. That is, the web server 100 sends the small screen SG2015 in which the pre-registered candidate face image acquired from the store terminal 20 is reflected (displayed) in the imaging area AR2210 to the store terminal 20 based on the operation of the shooting button BT2203.

[0116] In the imaging area AR2210 of the small screen SG2015 in Fig. 4(G), the pre-registered candidate face image is displayed, and the retake button BT2204 and the registration button BT2205 are arranged. When the employee needs to retake the photo, the retake button BT2204 is operated, and when registering, the registration button BT2205 is operated.

[0117] When there is an operation on the retake button BT2204 of the small screen SG2015 on the store terminal 20, the small screen SG2014 in Fig. 4(E) is pop-up displayed instead of the small screen SG2015. That is, the web server 100 sends the small screen SG2014 to the store terminal 20 based on the operation of the retake button BT2204.

[0118] When there is an operation on the registration button BT2205 of the small screen SG2015 on the store terminal 20, the pre-registered candidate face image and the employee code temporarily stored (the employee code input in the employee code input area AR2200 of the small screen SG2010) are sent to the web server 100, and a small screen SG2016 as shown in Fig. 4(H) is pop-up displayed instead of the small screen SG2015. That is, the web server 100 sends the small screen SG2016 in which the pre-registered candidate face image (which is also the pre-registered face image stored in the face authentication master as described later) acquired from the store terminal 20 is reflected (displayed) in the imaging area AR2210 to the store terminal 20 based on the operation of the registration button BT2205. Note that after the store terminal 20 sends the employee code to the web server 100, the temporarily stored employee code is erased.

[0119] Also, based on the operation of the registration button BT2205, the Web server 100 transmits the employee code and the pre-registered candidate face image obtained from the store terminal 20 to the face authentication server 200 together with an instruction (request) for face registration.

[0120] The face authentication server 200 that has acquired (received) the employee code and the pre-registered candidate face image from the Web server 100 together with the instruction for face registration (that is, the face authentication server 200 requested by the Web server 100 for face registration) executes face registration. Specifically, the face authentication server 200 stores the pre-registered candidate face image obtained from the Web server 100 as a pre-registered face image in the face authentication master in association with the employee code obtained from the Web server 100.

[0121] In the imaging area AR2210 of the small screen SG2016 in FIG. 4(H), the pre-registered face image is displayed, and the additional registration button BT2206 and the registration end button BT2207 are arranged. When an employee wants to additionally register another image (pre-registered face image), the employee operates the additional registration button BT2206, and when the registration is completed, the employee operates the registration end button BT2207.

[0122] When there is an operation of the additional registration button BT2206 on the small screen SG2016 of the store terminal 20, the store terminal 20 pops up and displays the small screen SG2014 in FIG. 4(E) instead of the small screen SG2016. That is, based on the operation of the additional registration button BT2206, the Web server 100 transmits the small screen SG2014 to the store terminal 20.

[0123] When there is an operation of the registration end button BT2207 on the small screen SG2016 of the store terminal 20, the store terminal 20 deletes the small screen SG2016. Note that the store terminal 20 may notify the Web server 100 that the small screen SG2016 has been deleted.

[0124] Note that since the small screens SG2010 to SG2016 are for face registration, they may also be referred to as face registration screens. The face registration screen does not have to be a pop-up screen, similar to the face authentication engraving screen and the employee code engraving screen. However, for the same reason as the face authentication engraving screen, it is preferable that the face registration screen is a pop-up screen.

[0125] By operating the registration button BT2205 of the small screen SG2015 in FIG. 4(G), the pre-registered candidate face image will be stored in the face authentication master as a pre-registered face image. When taking a photo, attention points during registration are displayed on the small screen SG2012 in FIG. 4(C) and the small screen SG2013 in FIG. 4(D) so that a pre-registered face image suitable for face authentication (for example, one in which feature points such as eyes, nose, and mouth are exposed, leading to accurate and fast face authentication) is stored.

[0126] FIGS. 5 to 8 are display examples of the management terminal 10. The management terminal 10 displays a management screen as shown in FIG. 5. Specifically, when the management terminal 10 accesses the web server 100 when the web browser is launched and a predetermined ID and PW are input on the login screen (not shown) displayed after the access, the management screen as shown in FIG. 5 is displayed. That is, the web server 100 transmits the login screen to the management terminal 10 based on the above access, and transmits the management screen of FIG. 5 to the management terminal 10 based on the input of the predetermined ID and PW on the login screen.

[0127] Note that the management screen in FIG. 5 is the management screen after operating the all button BT111 (described later) and then the display button BT116 (described later) after logging in, so information (logs) is displayed in the list display area AR117 (described later), but no information is displayed in the list display area AR117 of the management screen immediately after logging in. For example, information may be initially set (designated) in the display content designation area AR110 (described later) of the management screen immediately after logging in, and information based on the initial setting may be displayed in the list display area AR117 of the management screen immediately after logging in.

[0128] On the management screen of Fig. 5 (the same applies to the management screens of Figs. 6, 7, 12 to 14), as selection buttons, a log list button BT101, an employee setting button BT102, a page distribution button BT103, an administrator setting button BT104, and a company information button BT105 are arranged.

[0129] The log list button BT101 is a button to be operated (selected) when displaying a list of logs. The employee setting button BT102 is a button to be operated when setting for employees. The page distribution button BT103 is a button to be operated when distributing various pages (pages related to the affiliated time recorder, pages related to the personal time recorder, pages related to face registration). The administrator setting button BT104 is a button to be operated when setting for the administrator of the attendance service. The company information button BT105 is a button to be operated when displaying and setting information related to the entire company.

[0130] (Log List) Fig. 5 is the management screen after the operation of the log list button BT101. On the management screen of Fig. 5, a display content specification area AR110 and a list display area AR117 are provided. The display content specification area AR110 is an area that accepts operations for specifying the display content in the list display area AR117 and operations for instructing the display of information (logs) to the list display area AR117. The list display area AR117 is an area that displays a list of information according to the specified content in the display content specification area AR110. Also, on the management screen of Fig. 5, a CSV output button BT118 is arranged.

[0131] In the display content specification area AR110, as selection buttons (specification buttons), an all button BT111, an attendance log button BT112, and an administrator system log button BT113 are arranged, and an operation content selection area AR114 and a period specification area AR115 are provided. Also, in the display content specification area AR110, a display button BT116 is arranged.

[0132] The All Button BT111 is a button for specifying all (employee clock-in / out logs, administrator / system logs) as the logs to be displayed in the list display area AR117. The Clock-in / out Log Button BT112 is a button for specifying the employee clock-in / out logs as the logs to be displayed in the list display area AR117. The Administrator System Log Button BT113 is a button for specifying the administrator / system logs as the logs to be displayed in the list display area AR117.

[0133] The Operation Content Selection Area AR114 is an area for selecting the operation content when narrowing down the logs to be displayed in the list display area AR117 by the operation content (operation items). For example, when the Clock-in / out Log Button BT112 (or the All Button BT111) is selected, in the Operation Content Selection Area AR114, regarding clock-in, face authentication clock-in (clock-in by face authentication) and code clock-in (clock-in by employee code) can be selected. Also, for example, when the Administrator System Log Button BT113 (or the All Button BT111) is selected, in the Operation Content Selection Area AR114, login, logout, password reset, master synchronization, logout, registration (setting) of face authentication targets, exclusion (deletion) of face authentication targets, addition of pre-registered face images, deletion of pre-registered face images, distribution of pages (pages related to the department time recorder, personal time recorder, face registration), etc. can be selected. The Period Specifying Area AR115 is an area for specifying the period when narrowing down the logs to be displayed in the list display area AR117 by the period.

[0134] The Display Button BT116 is a button to be operated when instructing the display of information (logs) in the list display area AR117. The Display Button BT116 is operated after specifying the information to be displayed in the list display area AR117. The scene in Figure 5 is a scene where the administrator operates the All Button BT111 and then operates the Display Button BT116, and the employee clock-in / out logs and the administrator / system logs are displayed in the list display area AR117. The CSV Output Button BT118 is a button to be operated when outputting the information displayed in the list display area AR117 as CSV.

[0135] (Employee Settings) FIG. 6 shows the management screen after the operation of the employee setting button BT102. When there is an operation of the employee setting button BT102, the management terminal 10 displays the management screen as shown in FIG. 6. That is, the web server 100 transmits the management screen as shown in FIG. 6 to the management terminal 10 based on the operation of the employee setting button BT102.

[0136] Note that the management screen in FIG. 6 is the management screen after selecting the department, etc. in the department selection area AR121 (described later) and further operating the display button BT126 (described later) after the operation of the employee setting button BT102. Therefore, information (employee setting information) is displayed in the employee setting content display area AR127 (described later), but no information is displayed in the employee setting content display area AR127 of the management screen immediately after the operation of the employee setting button BT102. For example, information may be initially set (selected, specified) in the display content specification area AR120 (described later) of the management screen immediately after the operation of the employee setting button BT102, and information based on the initial setting may be displayed in the employee setting content display area AR127 of the management screen immediately after the operation of the employee setting button BT102.

[0137] The management screen in FIG. 6 is provided with a display content specification area AR120 and an employee setting content display area AR127. The display content specification area AR120 is an area that accepts operations for specifying the display content in the employee setting content display area AR127 and operations for instructing the display of information (employee setting information) in the employee setting content display area AR127. The employee setting content display area AR127 is an area that displays a list of information corresponding to the specified content in the display content specification area AR120. Also, an edit button BT128 and a master synchronization button BT129 are arranged on the management screen in FIG. 6.

[0138] The display content specification area AR120 is provided with a department selection area AR121, an employment category selection area AR122, an employee code input area AR123, a name input area AR124, and a retiree necessity selection area AR125. Also, a display button BT126 is arranged in the setting target selection area AR120.

[0139] The affiliated selection area AR121 is an area for selecting the affiliation of employees. The employment classification selection area AR122 is an area for selecting the employment classification of employees. The employee code input area AR123 is an area for inputting the employee code of employees. The name input area AR124 is an area for inputting the name of employees. The separated employee necessity selection area AR125 is an area for designating the necessity of information on separated employees (whether to include separated employees or not).

[0140] The display button BT126 is a button to be operated when instructing the display of information to the employee setting content display area AR127. The display button BT126 is operated after specifying the information to be displayed in the employee setting content display area AR127. The scene in FIG. 6 is a scene where all affiliations, all employment classifications, and no separated employees are selected and the display button BT126 is operated, and in the employee setting content display area AR127, employee setting information corresponding to all affiliations and all employment classifications excluding separated employees is displayed.

[0141] In the "face registration" column (item) of the employee setting content display area AR127, the status regarding the face registration of the corresponding employee is displayed. For example, when punching by face authentication of the corresponding employee is permitted (permission is set for punching by face authentication of the corresponding employee in the face authentication permission / denial setting information), and the face registration of the corresponding employee is completed (when the pre-registered face image of the corresponding employee is stored in the face authentication master), the column of "face registration" is displayed as "registered". When punching by face authentication of the corresponding employee is permitted, but the face registration of the corresponding employee is not completed (when the pre-registered face image of the corresponding employee is not stored in the face authentication master), the column of "face registration" is displayed as "not registered". When punching by face authentication of the corresponding employee is not permitted (when non-permission is set for punching by face authentication of the corresponding employee in the face authentication permission / denial setting information), the column of "face registration" is displayed as "not applicable".

[0142] Note that a sorting section (the black triangle part under the name of each item) is provided in the "Face Registration" item. By operating the sorting section, it is possible to sort based on the status regarding face registration for each employee (organize by status regarding face registration) and display the information in the employee setting content display area AR127.

[0143] In the column (item) of "Personal Screen" in the employee setting content display area AR127, the status regarding the personal time recorder of the employee is displayed. For example, when the use of the employee's personal time recorder is permitted (permission for the use of the employee's personal time recorder is set in the personal time recorder setting information), and a page regarding the personal time recorder has already been distributed to the employee's mobile terminal 30 (information indicating that a page regarding the personal time recorder has been distributed to the employee is stored in the personal time recorder setting information), the column of "Personal Screen" is displayed as "OK". When the use of the employee's personal time recorder is permitted, but a page regarding the personal time recorder has not yet been distributed to the employee's mobile terminal 30 (information indicating that a page regarding the personal time recorder has been distributed to the employee is not stored in the personal time recorder setting information), the column of "Personal Screen" is displayed as "NG". Note that even when the use of the employee's personal time recorder is not permitted (when non - permission for the use of the employee's personal time recorder is set in the personal time recorder setting information), the column of "Personal Screen" is also displayed as "NG".

[0144] Note that a sorting section is provided in the "Personal Screen" item. By operating the sorting section, it is possible to sort based on the status regarding the personal time recorder for each employee (organize by status regarding the personal time recorder) and display the information in the employee setting content display area AR127.

[0145] In addition, a sorting section may be provided for other items in the employee setting content display area AR127, and the information in the employee setting content display area AR127 may be organized by information for each item so that it can be confirmed.

[0146] The edit button BT128 is a button to be operated when editing the information displayed in the employee setting content display area AR127. For example, when there is an operation of the edit button BT128, the management device 10 displays an edit screen (not shown) on which the employee setting content (employee setting information) can be edited (pop-up displayed in front of the management screen in FIG. 6). That is, the Web server 100 transmits an edit screen (not shown) to the management device 10 based on the operation of the edit button BT128.

[0147] In the edit screen (not shown), the information stored in the employee master can be edited (changed, added, deleted). As an example, in the edit screen (not shown), the face authentication permission setting information can be edited (that is, changed from not permitted to permitted for punching by face authentication, or changed from permitted to not permitted for punching by face authentication). Also, in the edit screen (not shown), the personal time recorder setting information can be edited (that is, changed from not permitted to permitted for use of the personal time recorder, or changed from permitted to not permitted for use of the personal time recorder).

[0148] The master synchronization button BT129 is a button to be operated when synchronizing the employee master. By operating the master synchronization button BT129, for example, the information (information on some or all items) of another employee master (employee master as an employee roster within the company, etc.) is synchronized (imported) to the employee master as the latest information.

[0149] (Page distribution / Time recorder for department) Figure 7 shows the management screen after the operation of the page distribution button BT103. When there is an operation on the page distribution button BT103, the management terminal 10 displays a management screen as shown in Figure 7. That is, the Web server 100 transmits a management screen as shown in Figure 7 to the management terminal 10 based on the operation of the page distribution button BT103.

[0150] Note that the management screen in Figure 7 is the management screen after the operation of the page distribution button BT103, after operating the affiliated time recorder button BT131 (described later) to specify the page to be distributed, and then selecting the affiliation in the affiliation selection area AR134 (described later) to specify the affiliation of the distribution target. Therefore, the certificate display button BT138 (described later) is arranged in the distribution content confirmation area AR137 (described later), and information (the template of the distributed page) is displayed. However, in the management screen immediately after the operation of the page distribution button BT103, since the page and affiliation of the distribution target are not specified, the certificate display button BT138 is not arranged in the distribution content confirmation area AR137, and no information is displayed.

[0151] In the management screen of Figure 7, a distribution content specification area AR130 and a distribution content confirmation area AR137 are provided. The distribution content specification area AR130 is an area that accepts operations to specify the distribution page, distribution destination, and operations to instruct distribution. The distribution content confirmation area AR137 is an area for confirming the content of the distributed page.

[0152] In the distribution content specification area AR130, as step 1 (the first of the operations), the distribution page is selected (specified). In the distribution content specification area AR130, as the selection button (specification button) related to step 1, the affiliated time recorder button BT131, the personal time recorder button BT132, and the face registration button BT133 are arranged.

[0153] The department time recorder button BT131 is a button to be operated when selecting a page related to the department time recorder as the page to be distributed. The personal time recorder button BT132 is a button to be operated when selecting a page related to the personal time recorder as the page to be distributed. The face registration button BT133 is a button to be operated when selecting a page related to face registration as the page to be distributed. In FIG. 7, the administrator is operating the department time recorder button BT131.

[0154] In the distribution content specification area AR130, as step 2, select (specify) the department to be distributed. In the distribution content specification area AR130, there is provided a department selection area AR134 for selecting the department to be distributed as a selection area related to step 2. In FIG. 7, the administrator has selected "AA Branch".

[0155] In the distribution content specification area AR130, as step 3, set the distribution destination. In the distribution content specification area AR130, there is provided a distribution destination setting area AR135 for setting (inputting) the email address of the terminal that will be the store terminal 20 as a setting area related to step 3. In the distribution destination setting area AR135, input the email address of the device that functions as the department time recorder in the department to be distributed (that is, the device that will be the store terminal 20 in the department to be distributed, the terminal used as the department time recorder). In the distribution destination setting area AR135, the email address of the person in charge of the department to be distributed (the terminal used by the person in charge) may also be input. Note that in the department master, the email address of the device that functions as the department time recorder in each department and the email address of the terminal used by the person in charge of each department are stored.

[0156] When an email address is entered in the distribution destination setting area AR135, the consistency between the affiliation selected in the distribution content specification area AR130 and the email address entered in the distribution destination setting area AR135 may be checked. For example, when an email address is entered in the distribution destination setting area AR135, the management terminal 10 transmits the affiliation selected in the distribution content specification area AR130 and the email address entered in the distribution destination setting area AR135 to the web server 100. The web server 100 refers to the department master and checks the consistency between the affiliation received from the management terminal 10 (the affiliation selected in the distribution content specification area AR130) and the email address received from the management device 10 (the email address entered in the distribution destination setting area AR135), and may transmit the check result to the management terminal 10. Note that the web server 100 determines that they are consistent when the email address received from the management device 10 matches the email address of the corresponding affiliation (the affiliation received from the management terminal 10) stored in the department master (the email address of the device that functions as the time recorder for the affiliation or the email address of the terminal used by the person in charge of the affiliation), and determines that they are inconsistent when they do not match. Thereby, input errors can be discovered and corrected to the correct email address.

[0157] When there is a selection of the department in the distribution content specification area AR130, the email address corresponding to the department may be automatically entered in the distribution destination setting area AR135. For example, when there is a selection of the department in the distribution content specification area AR130, the management terminal 10 transmits the department selected in the distribution content specification area AR130 to the web server 100. The web server 100 may refer to the department master and transmit the email address corresponding to the department (the department selected in the distribution content specification area AR130) received from the management terminal 10 to the management terminal 10. Note that the web server 100 transmits the email address (the email address of the device that functions as the department time recorder in the department or the email address of the terminal used by the person in charge of the department) of the department (the department received from the management terminal 10) stored in the department master to the management terminal 10. When there are two or more email addresses corresponding to the department, the two or more email addresses may be displayed in the distribution destination setting area AR135 so that they can be selected. That is, when there are two or more email addresses of the department stored in the department master, the web server 100 transmits the two or more email addresses to the management terminal 10, and the management device 10 may display the two or more email addresses in the distribution destination setting area AR135 so that they can be selected. Since it is not a request for input by the administrator but automatic input or selection, the work burden on the administrator is reduced. In addition, since input keys such as numeric keys do not need to be arranged, an area such as the distribution content confirmation area AR137 can be secured (or secured with a sufficient size).

[0158] As step 3, if the email address is automatically entered in the distribution destination setting area AR135 or the email address to be entered in the distribution destination setting area AR135 is selected, the work is simplified such as eliminating the need for manual input, and the burden on the administrator is reduced. In addition, while proceeding with the work from step 1 to step 3, the template of the page to be distributed can be confirmed at the same time, so the work is made more efficient.

[0159] (Template of the page related to the department time recorder, display of certificate information) When there is a selection of the affiliation in Step 2 in the distribution content specification area AR130, the management terminal 10 displays a page prototype (standard text of an email regarding the time recorder for affiliation) regarding the time recorder for affiliation in the distribution content confirmation area AR137, and arranges the certificate display button BT138 in the distribution content confirmation area AR137. That is, when there is a selection of the affiliation in Step 2, the web server 100 displays the page prototype regarding the time recorder for affiliation in the distribution content confirmation area AR137, and transmits a management screen in which the certificate display button BT138 is arranged in the distribution content confirmation area AR137 to the management terminal 10. The web server 100 stores, for example, as text data, page prototypes regarding the time recorder for affiliation (similarly, page prototypes regarding the personal time recorder and page prototypes regarding face registration) in the storage unit 112, and may display the page prototype regarding the time recorder for affiliation stored in the storage unit 112 in the distribution content confirmation area AR137 when there is a selection of the affiliation in Step 2.

[0160] Note that since the certificate information displayed by operating the certificate display button BT138 is different for each affiliation, after the affiliation is specified by selecting the affiliation, the page prototype regarding the time recorder for affiliation is displayed in the distribution content confirmation area AR137 and the certificate display button BT138 is arranged in the distribution content confirmation area AR137.

[0161] As shown in the distribution content confirmation area AR137, the page regarding the time recorder for affiliation is an email that guides the procedure for enabling the face authentication device and provides two pieces of information (URL of the certificate information (URL of the screen for the recipient of this email to refer to the certificate information), URL of the time recorder for affiliation (URL of the attendance and departure screen)) required in the procedure for enabling the face authentication device.

[0162] On the page related to the time recorder for the department, a caution message regarding the expiration date of the URL of the certificate information (in this example, "The expiration date of the linked destination is 72 hours from the sending of this email") is displayed. Note that the expiration date may be changeable on the said management screen (the management screen in Fig. 7) or other management screens (for example, the management screen in Fig. 12).

[0163] The certificate display button BT138 is a button that receives an instruction to display the certificate information for the department. The certificate display button BT138 is associated with the URL of the screen (certificate information confirmation screen) for the administrator to check the certificate information of the department, etc., and displays the certificate information confirmation screen (see Fig. 8) of the department based on the administrator's operation.

[0164] Note that when the selected certificate information for the department does not exist (for example, when it is a department newly applying the attendance service and the certificate information for the department has not been generated), after generating the certificate information for the department, the Web server 100 displays the template of the page related to the time recorder for the department in the distribution content confirmation area AR137, and transmits to the management terminal 10 a management screen in which the certificate display button BT138 that receives an instruction to display the certificate information for the department is arranged in the distribution content confirmation area AR137.

[0165] Further, when there is an operation on the belonging time recorder button BT131 in Step 1, the management terminal 10 may display the page prototype related to the belonging time recorder in the distribution content confirmation area AR137, and when there is a selection of belonging in Step 2, the certificate display button BT138 may be arranged in the distribution content confirmation area AR137. That is, since the certificate information displayed by the operation of the certificate display button BT138 is different for each belonging, the certificate display button BT138 is arranged in the distribution content confirmation area AR137 after the belonging is specified by the selection of belonging. However, since the page prototype related to the belonging time recorder is common regardless of the belonging, for the page prototype related to the belonging time recorder, after the belonging time recorder button BT131 is operated and it is specified that the page to be distributed is the page related to the belonging time recorder (before the belonging is specified), it may be displayed in the distribution content confirmation area AR137.

[0166] Also, the timing for the management terminal 10 to obtain the page prototype related to the belonging time recorder from the Web server 100 does not have to be immediately before displaying the page prototype in the distribution content confirmation area AR137. For example, based on the operation of the page distribution button BT103, the management terminal 10 may obtain the page prototypes of all pages (the page prototype related to the belonging time recorder, the page prototype related to the personal time recorder, the page prototype related to face registration) from the Web server 100. That is, when there is a selection of belonging as Step 2 (or when there is an operation on the belonging time recorder button BT131 as Step 1), the management terminal 10 may read out the corresponding page prototype (the page prototype related to the belonging time recorder) among the page prototypes already stored and display it in the distribution content confirmation area AR137.

[0167] When there is an operation on the certificate display button BT138, the management terminal 10 pops up and displays a small screen (pop-up screen) SG1000 as shown in FIG. 8 in front of the management screen. That is, based on the operation of the certificate display button BT138, the Web server 100 transmits to the management terminal 10 a small screen SG1000 that displays the certificate information for the relevant affiliation (the affiliation selected in step 2) in the certificate information display area AR1002 (described later) as shown in FIG. 8.

[0168] The small screen SG1000 in FIG. 8 is a screen (certificate information confirmation screen) for the administrator to check the certificate information, etc. A close button BT1001 is arranged at the upper part of the small screen SG1000 in FIG. 8. Further, the small screen SG1000 is provided with a certificate information display area AR1002 and a certificate information update instruction area AR1003. The certificate information display area AR1002 is an area for displaying the certificate information. The certificate information update instruction area AR1003 is an area for instructing the update of the certificate information. The administrator checks the certificate information in the certificate information display area AR1002 and operates the close button BT1001.

[0169] (Update of Certificate Information) In the certificate information update instruction area AR1003, precautions for updating the certificate information are displayed, and all check boxes (reference signs a, b, and c in the figure) for the precautions are provided. Also, an update button BT1004 is arranged in the certificate information update instruction area AR1003. When updating the certificate information, the administrator checks the precautions, checks all the check boxes, and operates the update button BT1004. The administrator updates the certificate information as appropriate, for example, to deal with unauthorized access from a retiree. As shown in the precautions of the check box, if the certificate information is not activated at the store terminal 20 after the update, it cannot be used as a face recognition machine (for example, because punching cannot be performed), so check boxes are provided to thoroughly check the precautions. The operation of the update button BT1004 is not valid unless all the check boxes are checked, but the update button BT1004 may be displayed after checking all the check boxes without displaying the update button BT1004 before checking all the check boxes.

[0170] When there is an operation of the update button BT1004, the management terminal 10 redisplay the small screen SG1000 that displays the updated certificate information in the certificate information display area AR1002. That is, based on the operation of the update button BT1004, the web server 100 generates and stores the certificate information for the relevant department (the department selected in step 2), and transmits the small screen SG1000 that displays the generated certificate information in the certificate information display area AR1002 to the management terminal 10.

[0171] In addition, when there is an operation on the update button BT1004, the management terminal 10 may display a confirmation screen (a screen with an update execution button and a return button, not shown in the figure) for confirming whether to update the certificate information. When there is an operation on the update execution button, the small screen SG1000 that displays the updated certificate information in the certificate information display area AR1002 may be redisplayed. That is, the Web server 100 may transmit the above confirmation screen to the management terminal 10 based on the operation of the update button BT1004, and based on the operation of the update execution button on the above confirmation screen, generate and store the certificate information for the relevant department (the department selected in step 2), and transmit the small screen SG1000 that displays the generated certificate information in the certificate information display area AR1002 to the management terminal 10.

[0172] The administrator checks the template of the page related to the departmental time recorder displayed in the distribution content confirmation area AR137 (and further checks the certificate information on the small screen SG1000 if necessary), and instructs the distribution of the page related to the departmental time recorder.

[0173] In the distribution content specification area AR130, finally, an operation instruction for distribution is received. In the distribution content specification area AR130, a transmission button BT136 for instructing distribution is arranged.

[0174] When there is an operation on the transmission button BT136, the management terminal 10 transmits the page related to the departmental time recorder (a page with two pieces of information required in the procedure for enabling the face recognition machine added to the template of the page related to the departmental time recorder) to the distribution destination set in step 3. That is, the Web server 100 transmits an e-mail (Figure 9) related to the departmental time recorder with two pieces of information (the URL of the certificate information and the URL of the departmental time recorder) added to the distribution destination set in step 3 via the mail server 300 based on the operation of the transmission button BT136.

[0175] Figures 9 to 11 are display examples of a terminal that becomes the store terminal 20 (a terminal that functions as the store terminal 20 by being activated as a face recognition device. Hereinafter, it may be referred to as "terminal A"). Based on the above operation on the management terminal 10 (the operation of the transmission button BT136 on the management screen in FIG. 7), the distribution destination terminal (terminal A) receives an email regarding the affiliated time recorder as shown in FIG. 9.

[0176] In the email in FIG. 9, the procedure for activating the face recognition device is guided, and the information required in the procedure for activating the face recognition device (the URL of the certificate information, the URL of the affiliated time recorder) is shown.

[0177] When there is an operation (for example, touch) on the URL of the certificate information, terminal A displays a screen (certificate information reference screen) as shown in FIG. 10. That is, the web server 100 transmits a certificate information reference screen as shown in FIG. 10 to terminal A based on the access to the above URL. In the certificate information reference screen of FIG. 10, a certificate information display area AR230 for displaying certificate information is provided, and a copy button BT231 for receiving an instruction to temporarily copy (copy to the clipboard) the certificate information is arranged.

[0178] When there is an operation on the URL of the affiliated time recorder, terminal A displays a screen (certificate information input screen) as shown in FIG. 11. That is, the web server 100 displays a certificate input screen as shown in FIG. 11 based on the access to the above URL (access without certificate information added). In the certificate information input screen of FIG. 11, a certificate information input area AR240 for inputting certificate information is provided, and an OK button BT241 for receiving an OK operation is arranged.

[0179] The operator of terminal A copies the certificate information displayed in the certificate information display area AR230 of the certificate information reference screen (Figure 10) according to the operation guide for e-mail (the procedures in Steps 1 and 2) (procedure in Step 1), enters the copied certificate information into the certificate information input area AR240 of the certificate information input screen (Figure 11) (procedure in Step 2), and finally operates the OK button BT241 on the certificate information input screen (Figure 11).

[0180] When there is an operation on the OK button BT241, terminal A stores the certificate information as a cookie and displays the attendance / leaving screen. That is, based on the operation of the OK button BT241 on the certificate information input screen (Figure 11), web server 100 confirms that the certificate information entered in the certificate information input area AR240 of the certificate information input screen matches the certificate information of the relevant department (for example, by referring to the department master), and transmits the attendance / leaving screen to terminal A instead of the certificate information input screen. In this way, terminal A becomes the store terminal 20 (a terminal capable of displaying the attendance / leaving screen). Note that the two pieces of information distributed to terminal A are information corresponding to the department, and terminal A is activated using the information corresponding to the department (two pieces of information) and is made to be used as the store terminal 20. That is, in the attendance / leaving management system 1, it is possible to know which department's store terminal 20 each activated and operated store terminal 20 belongs to (where it is operated).

[0181] When the terminal A that has become the store terminal 20 accesses the URL of the departmental time recorder after the next time, since the certificate information stored as a cookie is transmitted to the web server 100, the terminal A that has become the store terminal 20 directly displays the attendance / leaving screen without displaying the certificate information input screen.

[0182] Figures 12 and 13 are display examples of the management terminal 10. Specifically, Figure 12 is the management screen after the operation of the company information button BT105. Figure 13 is the management screen after the operation of the setting button BT152 in Figure 12.

[0183] (Company Information) When there is an operation on the enterprise information button BT105, the management terminal 10 displays a management screen as shown in FIG. 12. That is, the Web server 100 transmits a management screen as shown in FIG. 12 to the management terminal 10 based on the operation of the enterprise information button BT105.

[0184] The management screen of FIG. 12 is provided with a face registration punching number display area AR150, a time recorder setting area AR151, and an affiliation-based setting area AR153.

[0185] The face registration punching number display area AR150 is an area for displaying the number of face authentication punches in the current month (the number of employees who punched in by face authentication) and the number of face authentication punches in the previous month. In the face registration punching number display area AR150, operations for instructing CSV output for each of the number of face authentication punches in the current month and the number of face authentication punches in the previous month can be accepted. Also, in the face registration punching number display area AR150, the upper limit of face authentication targets (the overall upper limit for all affiliations) can be set.

[0186] The time recorder setting area AR151 is an area for setting time recorders for all affiliations. A setting button BT152 is arranged in the time recorder setting area AR151. The affiliation-based setting area AR153 is an area for setting time recorders for individual affiliations. An affiliation-based setting button BT154 is arranged in the affiliation-based setting area AR153.

[0187] When the administrator performs settings (basic settings) common to all affiliations for the time recorder, the administrator operates the setting button BT152 in the time recorder setting area AR151. When performing settings (individual settings) for each affiliation, the administrator operates the affiliation-based setting button BT154 in the affiliation-based setting area AR153. In addition, when there are items (inconsistent items) where the settings common to all affiliations and the settings for each affiliation conflict, the individual settings may be applied. Also, in the settings common to all affiliations and the settings for each affiliation, it may be possible to separately set (by type) the affiliation time recorder / personal time recorder. That is, it may be possible to set different screens and the like for the store terminal 20 and the mobile terminal 30.

[0188] When there is an operation on the setting button BT152, the management terminal 10 displays a management screen as shown in FIG. 13. That is, the Web server 100 transmits a management screen as shown in FIG. 13 to the management terminal 10 based on the operation of the setting button BT152.

[0189] The management screen of FIG. 13 is provided with a display setting area AR155, a network setting area AR156, and the like.

[0190] In the area on the left side of the display setting area AR155, it is possible to set the display / non-display of numbers corresponding to the punching types (attendance / leaving, break start / break end, going out start / going out end) in the attendance / leaving work screen (FIG. 2) of the attendance / leaving work performance information (punching information).

[0191] In the area on the right side of the display setting area AR155, it is possible to set the display / non-display of the time card button BT210 in the attendance / leaving work screen (FIG. 2), the display / non-display of the attendance / leaving work performance information (punching information) in the attendance / leaving work screen, the display / non-display of the face registration button BT221 in the attendance / leaving work screen, the use or non-use of code punching (punching by employee code), and the use or non-use of the face authentication auto mode (auto detect). When the face authentication auto mode is off (invalid), it starts from the small screen SG2000 of "Start face authentication" in FIG. 3(A), but when the face authentication auto mode is on (valid), it starts from the small screen SG2000 of "Face authentication in progress..." in FIG. 3(B) (the first code punching is not used).

[0192] Although not shown, it is also possible to set whether to display another image (pre-registered face image of the employee or image such as a mascot image) instead of the actual captured image (face image for punching) as the image displayed in the attendance status list area AR220, whether to display an image (face image for punching, image) in the attendance status list area AR220, and whether to display the attendance status list area AR220 itself.

[0193] The operation contents (setting contents) in the management screens of FIGS. 12 and 13 are stored in, for example, the company master or department master.

[0194] (Administrator Settings) When there is an operation on the administrator setting button BT104 of the management terminal 10, a management screen (not shown) for setting the administrator of the commuting service is displayed. That is, the web server 100 transmits a management screen for setting the administrator of the commuting service to the management terminal 10 based on the operation of the administrator setting button BT104. In the management screen, settings for administrators (full administrators, general administrators), sending of account notification emails, etc. are possible. The operation content (setting content) in the management screen is stored in, for example, the administrator master. Note that only full administrators can access (display) the management screen.

[0195] (Page Distribution / Face Registration) FIG. 14 is an example display of the management terminal 10. Specifically, FIG. 14 is a management screen after the operation of the page distribution button BT103, similar to the management screen in FIG. 7. Since the management screen in FIG. 14 is the management screen after the operation of the page distribution button BT103, similar to the management screen in FIG. 7, some or all of the content described in FIG. 7 will be omitted from the explanation.

[0196] Note that the management screen in FIG. 14 is the management screen after operating the face registration button BT133 (identifying the page to be distributed) after the operation of the page distribution button BT103, and further selecting the affiliation in the affiliation selection area AR134 (identifying the affiliation of the distribution target). Therefore, information (template of the distributed page) is displayed in the distribution content confirmation area AR137. However, in the management screen immediately after the operation of the page distribution button BT103, since the page to be distributed and the affiliation are not specified, no information is displayed in the distribution content confirmation area AR137.

[0197] On the management screen of FIG. 7, the administrator selects the affiliated time recorder as the selection of the page of Step 1 in the distribution content specification area AR130 (operates the affiliated time recorder button BT131), and selects "AA Branch" as the selection of the affiliation in Step 2. However, on the management screen of FIG. 14, the administrator selects the face registration page as the selection of the page of Step 1 (operates the face registration button BT133), and selects "Head Office" as the selection of the affiliation in Step 2.

[0198] On the management screen of FIG. 7, the administrator inputs the email address of the terminal (Terminal A) that becomes the store terminal 20 as the setting of the distribution destination in Step 3. However, on the management screen of FIG. 14, the administrator selects the email address of the employee (the mobile terminal of the employee (the terminal (Terminal B) that becomes the mobile terminal 30)) as the setting of the distribution destination in Step 3.

[0199] The management terminal 10 can display the employees of the distribution destination in the distribution destination setting area AR135 as Step 3. More specifically, the management terminal 10 displays, in the distribution destination setting area AR135, information (face registration, name, email address) about the employees who are the employees corresponding to the selection result (selected affiliation) of Step 2 (employees belonging to the selected affiliation) and whose punching is permitted by face authentication (employees who are permitted for punching by face authentication in the face authentication permission / denial setting information) in a selectable list. That is, based on the selection of the affiliation in Step 2, as shown in FIG. 14, the Web server 100 transmits to the management terminal 10 a management screen in which a list of information of the employees who are the targets of punching by face authentication in the said affiliation is displayed in a selectable list in the distribution destination setting area AR135.

[0200] In the "Face Registration" column (item) of the distribution destination setting area AR135, similar to the "Face Registration" column in the employee setting content display area AR127 of the management screen in Fig. 7, the status regarding the face registration of the employee is displayed. However, as described above, since the employees who are permitted to clock in by face authentication are the selection targets, "Registered" or "Unregistered" is displayed, but "Excluded" is not displayed. That is, the management terminal extracts and displays the "Registered" or "Unregistered" employees. In the "Name" column (item) of the distribution destination setting area AR135, the name of the employee is displayed, and in the "Email Address" column, the email address of the employee's mobile terminal is displayed.

[0201] Note that in the "Face Registration" column of the distribution destination setting area AR135, as described above, "Registered" or "Unregistered" is displayed, but only the "Unregistered" employees may be displayed. That is, the management terminal may extract and display only the "Unregistered" employees. Specifically, the management terminal may display only the "Unregistered" employees from the beginning (even without side chains), or may provide a function to extract only the "Unregistered" employees (such as a button for extracting and displaying only the "Unregistered" employees).

[0202] The check box for each employee (each row) is a check box for selecting each employee. The check box in the upper part (title part) is a check box for collectively selecting all selectable employees. Note that the check box in the upper part collectively selects all selectable employees including the "Registered" employees, but may also collectively select the "Unregistered" employees. Also, a check box for collectively selecting all employees, a check box for collectively selecting the "Unregistered" employees, and a check box for collectively selecting the "Registered" employees may be provided separately.

[0203] Note that a sorting section (the black triangle part below the name of each item) is provided in the "Face Registration" item. By operating the sorting section, it is possible to sort based on the status regarding face registration for each employee (organize by status regarding face registration) and display the information in the distribution destination setting area AR135. For example, the selection work can be made more efficient by placing employees with "not registered" at the top.

[0204] After selecting the employee as the distribution destination in step 3, the administrator operates the send button BT136.

[0205] (Display of the prototype of the page regarding face registration) When there is a selection of the department in step 2 of the distribution content specification area AR130, the management terminal 10 displays a prototype of the page regarding face registration (a fixed text of an email regarding face registration) in the distribution content confirmation area AR137. That is, when there is a selection of the department in step 2, the web server 100 transmits a management screen in which a prototype of the page regarding face registration is displayed in the distribution content confirmation area AR137 to the management terminal 10. Note that the management terminal 10 may display a prototype of the page regarding face registration in the distribution content confirmation area AR137 when the face registration button BT133 in step 1 is operated.

[0206] As shown in the distribution content confirmation area AR137, the page regarding face registration is an email that guides the procedure for activating the face registration machine and provides two pieces of information (the employee code of the person himself / herself, the URL of the face registration machine (the URL of the face registration screen)) required in the procedure for activating the face registration machine. Note that the employee code of the person himself / herself is the employee code of each employee selected as the distribution destination in step 3. That is, an employee code corresponding to the distribution destination (employee) is provided for each distribution destination (for each email).

[0207] In step 3, since it is only necessary to select the employees to be distributed to, the burden on the administrator is reduced. Also, while proceeding with the work from step 1 to step 3, the prototype of the page to be distributed can be confirmed simultaneously, so the work is made more efficient.

[0208] Note that the timing at which the management terminal 10 obtains the page template related to face registration from the Web server 100 does not have to be immediately before the page template is displayed in the distribution content confirmation area AR137. For example, the management terminal 10 may obtain the page templates of all pages from the Web server 100 based on the operation of the page distribution button BT103. That is, when there is a selection of the department as step 2 (or when there is an operation of the face registration button BT133 as step 1), the management terminal 10 may read out the corresponding page template (the page template related to face registration) among the page templates already stored and display it in the distribution content confirmation area AR137.

[0209] When there is an operation of the send button BT136, the management terminal 10 sends the page related to face registration (the page obtained by adding two pieces of information required in the procedure for activating the face registration machine to the page template related to face registration) to the distribution destination selected in step 3. That is, based on the operation of the send button BT136, the Web server 100 sends an e-mail related to face registration (Fig. 15) added with two pieces of information (the employee code of the person himself / herself and the URL of the face registration machine) to the distribution destination selected in step 3 via the mail server 300. Note that the Web server 100 identifies the employee code of each employee by referring to, for example, the employee master (for example, identifies the employee code from the e-mail address).

[0210] Fig. 15 is a display example of the terminal that becomes the mobile terminal 30 (the terminal that is activated as a face registration machine and functions as the mobile terminal 30. Hereinafter, it may be referred to as "terminal B"). Fig. 16 is a display example of the mobile terminal 30. Based on the above operation on the management terminal 10 (the operation of the send button BT136 on the management screen in Fig. 14), the distribution destination terminal (terminal B) receives an e-mail related to face registration as shown in Fig. 15.

[0211] In the e-mail of Fig. 15, the procedure for activating the face registration machine of the face registration machine is guided, and the information (employee code, URL of the face registration machine) required in the procedure for activating the face registration machine is shown. Note that the e-mail in Fig. 15 is a display example when terminal B is placed horizontally.

[0212] When there is an operation (e.g., touch) on the URL of the face registration device at the terminal B, a screen for inputting an employee code (employee code input screen, not shown) is displayed. That is, based on the access to the above URL, the web server 100 transmits an employee code input screen (not shown) to the terminal B. On the employee code input screen, for example, an input field for the employee code is provided, and an OK button is arranged.

[0213] The operator of the terminal B inputs the employee code (the operator's own employee code displayed in the email) into the input field for the employee code on the employee code input screen (not shown), and operates the OK button on the employee code input screen.

[0214] When there is an operation on the OK button of the employee code input screen (not shown) at the terminal B, as shown in FIG. 16(A), a face registration screen (a screen corresponding to the small screen SG2011 in FIG. 4(B)) is displayed. That is, based on the operation of the OK button on the employee code input screen, the web server 100 acquires the employee code (the employee code input on the employee code input screen), checks the employee (for example, checks whether the employee code exists in the employee master), and if it is OK, transmits a face registration screen as shown in FIG. 16(A) to the terminal B (mobile terminal 30).

[0215] That is, the terminal B functions as a face registration device (a face registration device that accesses the URL of the face registration device among the two pieces of information and acquires a pre-registered candidate face image) used for face registration of the employee (the employee of the employee code among the two pieces of information) who uses the terminal B according to the two pieces of information (the employee's own employee code and the URL of the face registration device) indicated in the email.

[0216] Hereinafter, based on an operation by the employee or the like, the mobile terminal 30 displays screens corresponding to the small screens SG2012 in FIG. 4(C) to SG2016 in FIG. 4(H) from the face registration screen in FIG. 16(A).

[0217] The face registration screen in Fig. 16(A) is a face registration screen (the face registration screen after employee code input) corresponding to the small screen SG2011 in Fig. 4(B). That is, the mobile terminal 30 does not display a face registration screen (a face registration screen capable of inputting an employee code) corresponding to the small screen SG2010 in Fig. 4(A). In this regard, the mobile terminal 30 temporarily stores the employee code input on the employee code input screen (not shown) (for example, stores it as a cookie of the URL of the face registration machine), and may send the temporarily stored employee code together with the pre-registered candidate face image to the web server 100.

[0218] (Page distribution / Personal time recorder) Note that the flow of distributing a page (an email regarding the personal time recorder) regarding the personal time recorder is the same as the flow of distributing a page (an email regarding the department time recorder) regarding the department time recorder. That is, the administrator operates the personal time recorder button BT132, selects the department and the distribution destination, and operates the send button BT136, whereby the mobile terminal at the distribution destination receives a page (an email regarding the personal time recorder). According to the procedure for activating the face recognition machine guided on the page, the mobile terminal 30 displays a check-in / check-out screen as shown in Fig. 16(B).

[0219] In the page distribution of the personal time recorder, when the department is selected in Step 2, in Step 3, employees who are permitted to use the personal time recorder (employees for whom permission to use the personal time recorder is set in the personal time recorder setting information) are displayed as selectable. Also, in the page distribution of the department time recorder, similar to the case where the template of the page related to the department time recorder (standard text of the email related to the department time recorder) and the certificate display button BT138 are displayed as operable, in the page distribution of the personal time recorder, the template of the page related to the personal time recorder (standard text of the email related to the personal time recorder) and the certificate display button BT138 are displayed as operable. Therefore, similar to other page distribution cases, the burden on the administrator is reduced and the work is streamlined.

[0220] In the attendance and departure screen of Fig. 16(B), the time card button BT210 is not arranged. Also, in the attendance and departure screen of Fig. 16(B), the attendance status list area AR220 is not provided. That is, the Web server 100 transmits the attendance and departure screen corresponding to the distribution destination (department), but when different screen settings are made between the store terminal 20 and the mobile terminal 30, the face registration screen for the mobile terminal of the said department is transmitted. Also, in the attendance and departure screen of the mobile terminal 30, the name of the employee may be displayed.

[0221] (Control of the screen) In the above, when transitioning from one screen to the next screen, an example of accessing the Web server 100 each time to transition from one screen to the next screen has been described. However, by acquiring (for example, prefetching and caching) a plurality of screens (screen information) together, it is also possible to transition from one screen to the next without accessing the Web server 100 each time.

[0222] For example, when there is an operation on the attendance button BT201 of the attendance and departure screen in Fig. 2 (when displaying the small screen SG2000 in Fig. 3(A)), in addition to the screen information of the small screen SG2000 in Fig. 3(A), the store terminal 20 acquires the screen information of the small screen SG2001 in Fig. 3(B) after the operation of the attendance button BT2101 on the small screen SG2000 from the Web server 100 and displays the small screen SG2000. When there is an operation on the attendance button BT2101 of the small screen SG2000, the store terminal 20 may also display the small screen SG2001 for which the screen information has already been acquired without accessing the Web server 100. Alternatively, when there is an operation on the attendance button BT201 of the attendance and departure screen in Fig. 2, in addition to the screen information of the small screen SG2000 in Fig. 3(A) and the screen information of the small screen SG2001 in Fig. 3(B), the store terminal 20 acquires the screen information of the small screen SG2004 (not shown) after the operation of the code stamping button BT2102 on the small screen SG2000 from the Web server 100 and displays the small screen SG2000. When there is an operation on the attendance button BT2101 of the small screen SG2000, the store terminal 20 may display the small screen SG2001 for which the screen information has already been acquired without accessing the Web server 100. When there is an operation on the code stamping button BT2102 of the small screen SG2000, the store terminal 20 may display the small screen SG2004 for which the screen information has already been acquired without accessing the Web server 100. In other words, the Web server 100 may send the screen information of two or more small screens to the store terminal 20 together.

[0223] Note that, in order to display the name of the employee (surname) who has attended work, the small screen SG2002 in Fig. 3(C) requires communication with the Web server 100. However, the necessary information is acquired from the Web server 100, and the screen information of the small screen SG2002 may be acquired in advance (for example, when operating the attendance button BT201 on the attendance and departure screen, or when operating the attendance button BT2101 on the small screen SG2000). The same applies to the small screen SG2005 (not shown).

[0224] The same applies to the attendance and departure screen of the mobile terminal 30 (for example, the screen that transitions from Fig. 16(B)).

[0225] For example, when an operation is performed on the next button BT2202 of the small screen SG2010 in Fig. 4(A) (when displaying the small screen SG2011 in Fig. 4(B)), in addition to the screen information of the small screen SG2011 in Fig. 4(B), the store terminal 20 acquires the screen information of the small screens SG2012 in Fig. 4(C) to SG2015 in Fig. 4(G) from the Web server 100, and when an operation is performed on the next button BT2202 or the shooting button BT2003, the next small screen may be displayed without accessing the Web server 100. Alternatively, when an operation is performed on the face registration button BT211 of the attendance screen in Fig. 2 (when displaying the small screen SG2010 in Fig. 4(A)), in addition to the screen information of the small screen SG2010 in Fig. 4(A), the store terminal 20 acquires the screen information of the small screens SG2011 in Fig. 4(B) to SG2015 in Fig. 4(G) from the Web server 100, and when an operation is performed on the next button BT2202 or the shooting button BT2003, the next small screen may be displayed without accessing the Web server 100.

[0226] The same applies to face registration by the mobile terminal 30 (for example, the screen transition from Fig. 16(A)).

[0227] For example, when the management terminal 10 accesses the management screen, in addition to the screen information of the management screen in Fig. 5, the management terminal 10 acquires the screen information of the management screens in Figs. 6, 7, 12 to 14 from the Web server 100, and when an operation for switching the display content (operations of the log list button BT101, employee setting button BT102, page distribution button BT103, administrator setting button BT104, enterprise information button BT105) is performed, another management screen may be displayed without accessing the Web server 100.

[0228] Fig. 17 is a sequence diagram showing an overview of the operations of each device when the store terminal 20 is enabled as a face authentication device. In Fig. 17, the left side shows the operation of the management terminal 10, the middle shows the operation of the store terminal 20, and the right side shows the operation of the Web server 100. At the time of disclosure of step S1, it is assumed that the management terminal 10 is displaying the management screen after the operation of the page distribution button BT103.

[0229] Note that in FIG. 17, for the sake of convenience, the operations related to the screen update (request, transmission) between the management terminal 10 and the Web server 100 and the operations of the mail server 200 are omitted. Also, in FIG. 17, the middle part was described as the operation of the store terminal 20. However, after being activated as a face recognition device (after step S21 and later), it is the operation of the store terminal 20, and before being activated as a face recognition device (until step S17), it is the operation of the terminal (terminal A) that becomes the store terminal 20.

[0230] Step S1: The management terminal 10 receives a selection of a page related to the belonging time recorder as a distribution page. That is, the management terminal 10 receives an operation of the belonging time recorder button BT131. Step S2: The management terminal 10 receives a selection of the belonging to which the page related to the belonging time recorder is to be distributed in the belonging selection area AR134. Step S3: The management terminal 10 displays a template of the distribution page (a fixed form of an email). For example, the management terminal 10 displays a template of the page related to the belonging time recorder (a fixed form of an email related to the belonging time recorder) as shown in the distribution content confirmation area AR137 of the management screen in FIG. 7. Step S4: The management terminal 10 receives a selection of the email address of the distribution destination in the distribution destination setting area AR135. Step S5: The management terminal 10 receives an instruction to distribute the page related to the belonging time recorder. That is, the management terminal 10 receives an operation of the send button BT136.

[0231] Step S6: Based on the operation of the send button BT136, the Web server 100 sends an email including the URL of the certificate information and the URL of the belonging time recorder to the email address entered as the distribution destination. For example, the Web server 100 sends an email as shown in FIG. 9. Step S7: The store terminal 20 receives an email including the URL of the certificate information and the URL of the belonging time recorder. Step S8: The store terminal 20 requests the certificate information based on the operation of the URL of the certificate information. Step S9: The web server 100 receives the request for the certificate information. Step S10: The web server 100 transmits a certificate information reference screen. For example, the web server 100 transmits a certificate information reference screen as shown in FIG. 10. Step S11: The store terminal 20 receives and displays the certificate information reference screen. Step S12: The store terminal 20 requests the attendance / leaving screen based on the operation of the URL of the affiliated time recorder. This request is a request without certificate information. Step S13: The web server 100 receives the request for the attendance / leaving screen (without certificate information). Step S14: The web server 100 transmits a certificate information input screen. For example, the web server 100 transmits a certificate information input screen as shown in FIG. 11. Step S15: The store terminal 20 receives and displays the certificate information input screen. Step S16: The store terminal 20 accepts the input of the certificate information on the certificate information input screen.

[0232] Step S17: The store terminal 20 transmits the certificate information based on the operation of the OK button BT241. Step S18: The web server 100 receives the certificate information. Step S19: The web server 100 confirms the match with the certificate information of the said affiliation. Step S20: The web server 100 transmits the attendance / leaving screen of the said affiliation. Step S21: The store terminal 20 receives and displays the attendance / leaving screen. Step S22: The store terminal 20 stores the certificate information as a cookie in association with the attendance / leaving screen (the URL of the said attendance / leaving screen).

[0233] FIG. 18 is a sequence diagram showing an overview of the operations of each device when activating the mobile terminal as a face registration device. In FIG. 18, the leftmost shows the operation of the management terminal 10, the second from the left shows the operation of the mobile terminal 30, the third from the left shows the operation of the web server 100, and the rightmost shows the operation of the face authentication server 200. When disclosing step S31, it is assumed that the management terminal 10 is displaying the management screen after the operation of the page distribution button BT103.

[0234] Note that in FIG. 18, for the sake of convenience, the operations related to the screen update (request, transmission) between the management terminal 10 and the web server 100 and the operation of the mail server 200 are omitted. Also, although it was explained that the second from the left in FIG. 18 is the operation of the mobile terminal 30, the operation after being activated as a face registration device (after step S47) is the operation of the mobile terminal 30, and before being activated as a face registration device (until step S43) is the operation of the terminal (terminal B) that becomes the mobile terminal 30.

[0235] Step S31: The management terminal 10 receives a selection of a page related to face registration as a distribution page. That is, the management terminal 10 receives an operation of the face registration button BT133. Step S32: The management terminal 10 receives a selection of the affiliation to which the page related to face registration is to be distributed in the affiliation selection area AR134. Step S33: The management terminal 10 displays a template of the distribution page (standard text of an email). For example, the management terminal 10 displays a template of the page related to face registration (standard text of an email related to face registration) as shown in the distribution content confirmation area AR137 of the management screen in FIG. 14. Step S34: The management terminal 10 receives a selection of the destination employee in the distribution destination setting area AR135. Step S35: The management terminal 10 receives an instruction to distribute the page related to face registration. That is, the management terminal 10 receives an operation of the send button BT136.

[0236] Step S36: Based on the operation of the send button BT136, the Web server 100 sends an email containing the employee code and the URL of the face registration screen to the mobile terminal 30 of the employee selected as the distribution destination. For example, the Web server 100 sends an email as shown in FIG. 15. Step S37: The mobile terminal 30 receives an email containing the employee code and the URL of the face registration screen. Step S38: Based on the operation of the URL of the face registration screen, the mobile terminal 30 requests the face registration screen. Step S39: The Web server 100 receives the request for the face registration screen. Step S40: The Web server 100 sends the employee code input screen. Step S41: The mobile terminal 30 receives and displays the employee code input screen. Step S42: The mobile terminal 30 accepts the input of the employee code. Step S43: Based on the operation of the OK button, the mobile terminal 30 sends the employee code. Step S44: The Web server 100 receives the employee code. Step S45: The Web server 100 refers to the employee master to identify the employee.

[0237] Step S46: The Web server 100 sends the face registration screen. For example, the Web server 100 sends a face registration screen as shown in FIG. 16(A) (a face registration screen corresponding to the small screen SG2011 in FIG. 4(B)). Step S47: The mobile terminal 30 receives and displays the face registration screen. Also, the mobile terminal 30 activates the camera. Step S48: The mobile terminal 30 displays a guide (a face registration screen corresponding to the small screen SG2012 in FIG. 4(C) to a face registration screen corresponding to the small screen SG2014 in FIG. 4(D)), and captures an image of the face based on the operation of the capture button BT2203. Step S49: Based on the operation of the registration button BT2205, the mobile terminal 30 sends the employee code and the captured image (pre-registered candidate face image). Step S50: The Web server 100 receives the employee code and the pre-registered candidate face image, and transmits the received employee code and pre-registered candidate face image.

[0238] Step S51: The face authentication server 200 receives the employee code and the pre-registered candidate face image. Step S52: The face authentication server 200 registers (stores the pre-registered candidate face image as a pre-registered face image in association with the employee code) in the face authentication master.

[0239] FIG. 19 is a sequence diagram showing an overview of the operations of each device at the time of attendance. In FIG. 19, the left side shows the operation of the store terminal 20, the middle shows the operation of the Web server 100, and the right side shows the operation of the face authentication server 200. At the time of disclosure of step S61, it is assumed that the store terminal 20 is displaying the attendance / departure screen.

[0240] Note that in FIG. 19, the example of clocking in at the time of attendance is shown, but the same applies to clocking in at the time of leaving work and the like. Also, in FIG. 19, the example of clocking in by the store terminal 20 which is a face authentication device is shown, but the same applies to clocking in by the mobile terminal 30 which is a face authentication device.

[0241] Step S61: The store terminal 20 receives an operation of the attendance button BT201. Step S62: The store terminal 20 requests a face authentication clocking screen. For example, the store terminal 20 requests the small screen SG2000 of FIG. 3(A). Step S63: The Web server 100 receives a request for a face authentication clocking screen. Step S64: The Web server 100 transmits a face authentication clocking screen. For example, the Web server 100 transmits, in addition to the screen information of the small screen SG2000 of FIG. 3(A), the screen information of the small screen SG2001 of FIG. 3(B) after the operation of the attendance button BT2101 of the small screen SG2000. Step S65: The store terminal 20 receives and displays the face authentication clocking screen. Also, the store terminal 20 activates the camera. For example, the store terminal 20 displays the small screen SG2000 of FIG. 3(A) and activates the camera. Step S66: The store terminal 20 captures an image of the face based on the operation of the attendance button BT2101. Step S67: The store terminal 20 that has captured the face image transmits time information (current time) and the captured image (face image for time stamping).

[0242] Step S68: The web server 100 receives the time information and the face image for time stamping. Step S69: The web server 100 transmits the face image for time stamping.

[0243] Step S70: The face authentication server 200 receives the face image for time stamping. Step S71: The face authentication server 200 refers to the face authentication master and authenticates the employee. That is, the face authentication server 200 refers to the face authentication master and identifies the employee (employee code) from the face image for time stamping. Step S72: The face authentication server 200 transmits the employee code of the authenticated employee. That is, the face authentication server 200 transmits the employee code of the employee identified from the face image for time stamping.

[0244] Step S73: The web server 100 receives the employee code. Step S74: The web server 100 stores the time stamping information in the attendance record file. For example, the web server 100 stores the employee code, attendance time, and face image for time stamping in the attendance record file as the time stamping information. Step S74: The web server 100 stores the time stamping information in the attendance record file. For example, the web server 100 stores the employee code, attendance time (time information received from the store terminal 20), and face image for time stamping in the attendance record file as the time stamping information. Step S75: The web server 100 transmits the updated (after adding the time stamping information) attendance and departure screen, etc. For example, the web server 100 transmits the attendance and departure screen in which the information based on the updated attendance record file (attendance and departure record information) is reflected in the attendance status list area AR220, and the small screen SG2002 (Fig. 3(C)). Step S76: The store terminal 20 receives and displays the updated attendance and departure screen, etc.

[0245] In the sequence diagram of FIG. 19, time information is acquired at the timing of step S67 (the timing when the face is photographed) (that is, the timing when the face is photographed is regarded as the arrival time), but time information may be acquired at other timings. For example, time information may be acquired at step S61 (the timing when the attendance button BT201 is operated). Also, time information may be acquired at the timing on the server side (the timing when the face authentication server 200 transmits the employee code in step S72, the timing when the web server 100 receives the employee code in step S73). The same applies to other time punches (such as leaving work).

[0246] (Anti-fraud measures) To prevent impersonation (substitution), multiple face images (for example, two) may be captured at different times during authentication. That is, the authentication device (store terminal 20, mobile terminal 30) may acquire a plurality of face images for time punching based on a single operation of the photographing button BT2203. For example, when taking a face photo, since the edge of the face photo may be reflected, fraud can be detected from the attendance and departure record file (log). Note that some of the captured images (for example, one when two are captured, one or two when three are captured) may be used for face authentication, or all of the captured images (for example, two when two are captured, three when three are captured) may be used for face authentication. Also, all of the captured images may be stored (saved) as log information (information for future verification), or a specific image among the captured images (for example, an image suspected of fraud by AI determination) may be stored as log information.

[0247] (Evaluation of pre-registered candidate face images) Evaluate whether the pre-registered candidate face images acquired (captured) by the store terminal 20 or the mobile terminal 30 are suitable for the pre-registered face images (for example, determine the suitability by AI judgment), and for pre-registered candidate face images that are not suitable for the pre-registered face images, they may not be stored in the face authentication master as pre-registered face images. When a pre-registered candidate face image is acquired, the above control may always be performed, or it may be switchable to a face image evaluation mode (face image test mode). When a pre-registered candidate face image is acquired in the face image evaluation mode, the above control may also be performed.

[0248] (Evaluation of the environment) In the case of a wireless communication terminal (for example, the terminal that becomes the store terminal 20), depending on the installation location, problems such as slow communication with the web server 100 may occur. Therefore, there may be an environment evaluation mode (environment test mode) for evaluating the pros and cons of the installation location (whether the communication speed meets a predetermined reference speed). For example, in the environment evaluation mode, a face image for punching is acquired as a dummy and transmitted to the web server 100. Also, in the environment evaluation mode, the test result (whether the communication speed meets the reference speed) may be notified in characters (messages) (for example, display or voice output of "qualified" or "unqualified", etc.), or the display mode (for example, the background color and text color of the screen) may be made different according to the test result (when the communication speed meets the reference speed and when it does not). Also, even after the wireless communication terminal operates as the store terminal 20 (after the wireless communication terminal is activated as a face authentication device), it may be operated in the environment evaluation mode. That is, since the communication environment may change after activation, the communication speed may be checked in the environment evaluation mode as appropriate, and countermeasures (such as moving the installation location or reviewing the communication environment) may be taken as necessary.

[0249] (Location information of the mobile terminal 30) Punching by the mobile terminal 30 (face authentication device) is possible regardless of the location. For example, in addition to when going straight or returning straight, it is also convenient to be able to punch during telework at home or in a rented meeting room, etc. (it is not necessary to correct going to and leaving work during closing).

[0250] Since it is possible to freely punch in regardless of the side or location, there is a risk of unauthorized punching. If the mobile terminal 30 transmits the location information to the Web server 100 when transmitting the face image for punching and stores the location information in the attendance record file (log), it is possible to detect fraud from the attendance record file.

[0251] As described above, the embodiments have been explained. According to the embodiments, the management and operation of attendance can be suitably carried out.

[0252] For example, by operating the management terminal 10, it is possible to simply make a general-purpose terminal (for example, a tablet terminal) at the workplace (work location) function as the store terminal 20 (face authentication machine, face registration machine), or make a personal terminal (for example, a smartphone, tablet terminal) function as the mobile terminal 30 (face registration machine, face authentication machine). That is, conventionally, the burden on the administrator (operator) (burden of new introduction, expansion to other bases, equipment addition, face image registration, etc.) was large, but since the administrator only needs to operate the management terminal 10, the burden on the administrator is significantly reduced.

[0253] In the operation of activating the face authentication machine, since a password (certificate information) is required, the users of the face authentication machine can be restricted to the original users, preventing unauthorized use. Since the operation of activating the face authentication machine itself is a simple operation such as following the guidance, the burden on the site or individual when functioning as a face authentication machine is very small.

[0254] The operation of activating the face registration machine only requires the input of the employee code, so the burden on the individual when functioning as a face registration machine is very small.

[0255] Also, in terms of operation, for example, when part-time employee A of store a goes to help at another store b, usually, they clock in at the store terminal 20 of store a, but when helping, they can clock in at the store terminal 20 of store b (or on the mobile terminal 30 of the part-time employee). When clocking in at the store terminal 20 of a store different from the affiliated store, log information (for example, information indicating clocking in at a store different from the affiliated store, identification information of the store different from the affiliated store where the clocking in occurred) may be stored so that this can be known. For example, although the affiliated store of part-time employee A is store a (store a is stored as the affiliation of part-time employee A in the employee master), when clocking in at the store terminal 20 of store b, information indicating that part-time employee A clocked in at a store different from the affiliated store a, and information indicating that part-time employee A clocked in at store b, which is different from the affiliated store a, may be stored as log information. Also, for example, when a salesperson in branch c returns directly from a customer's place, they can clock in on their mobile terminal 30 when returning directly. The same applies when going directly. In the case of going directly or returning directly, log information (for example, information indicating going directly or returning directly, location information of the location where going directly or returning directly occurred) may be stored so that this can be known. Also, when the terminals are different for clocking in and clocking out, this may be left in the log so that this can be known.

[0256] In the commuting management system 1, attendance and departure can be managed by face authentication or employee code using the store terminal 20 and the mobile terminal 30. Depending on the job content and employment classification of employees, attendance and departure can be managed in a suitable way for each. For example, for employees mainly engaged in off-site work such as sales and maintenance service positions, allowing clock-in by face authentication using the mobile terminal 30 enables flexible response to work systems such as going straight to and returning from work immediately. In workplaces with a lot of people coming and going, including part-time jobs in restaurants, etc., smooth attendance and departure management can be achieved by using both face authentication for clock-in and employee code for clock-in. Also, for example, if IC cards are issued for attendance and departure management to part-time employees who are relatively frequently replaced, it will cost that much (cost, labor). However, since the commuting management system 1 does not use IC cards, the cost can be cut. Also, since equipment capable of reading IC cards is not required, that much cost can also be cut. In office and staff positions with little off-site work, by only allowing clock-in by employee code without allowing clock-in by face authentication, if the usage fee for the attendance and departure service is related to the number of people subject to face authentication, the usage fee can be reduced.

[0257] In addition, in the commuting management system 1, since face image registration (storing pre-registered face images) can be performed using smartphones that are substantially owned by everyone (almost 100% in the active generation), employees do not need to go to the branch office or headquarters for registration, and time-consuming and cumbersome tasks (for example, a series of tasks such as capturing a face image, creating a predetermined email including the destination, selecting the captured face image from a predetermined folder, attaching it to the created email, and sending the email) are unnecessary. Simply following the guidance (distributed pages), employees can intuitively operate and easily register face images. Since the administrator can proceed with the work by selection rather than input of information on the management terminal 10 (for example, in step 3), the work is simplified, and by reducing the amount of information, intuitive operation becomes possible. Also, by entrusting the face registration work itself to employees, the work burden on the administrator is reduced, and the registration status of face registration is also displayed by icons ("not registered", "registered"), so it can be grasped intuitively.

[0258] (Modification examples, etc.) As described above for each embodiment, the configuration of the device, the configuration of the data, the processing flow, the display and output modes, etc. can be appropriately changed as shown in, for example, the following (1) to (19). Also, the following (1) to (19) may be appropriately combined with each other.

[0259] (1) In the above embodiment, when the stamping by face authentication is continuously successful, the small screen SG2000 in Fig. 3(A) → adjusting the position of the face on the small screen SG2000 in Fig. 3(A) → operating the attendance button BT2101 on the small screen SG2000 in Fig. 3(A) → the small screen SG2001 in Fig. 3(B) → the small screen SG2002 in Fig. 3(C) → operating the continuous attendance button BT2103 on the small screen SG2002 in Fig. 3(C) → the small screen SG2000 in Fig. 3(A) → adjusting the position of the face on the small screen SG2000 in Fig. 3(A) → operating the attendance button BT2101 on the small screen SG2000 in Fig. 3(A) → the small screen SG2001 in Fig. 3(B) → the small screen SG2002 in Fig. 3(C) → operating the continuous attendance button BT2103 on the small screen SG2002 in Fig. 3(C) → the small screen SG2000 in Fig. 3(A) →... Such an example of screen transition (switching) was described. However, the screen may also transition as follows: the small screen SG2000 in Fig. 3(A) → adjusting the position of the face on the small screen SG2000 in Fig. 3(A) → operating the attendance button BT2101 on the small screen SG2000 in Fig. 3(A) → the small screen SG2001 in Fig. 3(B) → the small screen SG2002 in Fig. 3(C) → the small screen SG2000 in Fig. 3(A) → adjusting the position of the face on the small screen SG2000 in Fig. 3(A) → the small screen SG2001 in Fig. 3(B) → the small screen SG2002 in Fig. 3(C) → the small screen SG2000 in Fig. 3(A) →... That is, when the stamping by face authentication is continuously successful, even without the operation of the attendance button BT2101 in Fig. 3(A) or the continuous attendance button BT2103 in Fig. 3(C), the screen may transition over time. That is, after the operation of the first attendance button BT2101, as long as the authentication is successful, continuous stamping by face authentication may be possible without operation.

[0260] (2) In the above embodiment, an example in which punching can be performed by face authentication and by employee code has been described (Fig. 3(A)). However, if the person to be face-authenticated (an "already registered" employee) continues to punch using the employee code instead of punching by face authentication for a predetermined period, the employee or the administrator may be notified. Even when punching is performed using the employee code instead of punching by face authentication continuously for a predetermined number of times, the employee or the administrator may be notified. For the employee, an announcement may be made on the screen (a small screen or the like) after punching using the employee code, or an announcement may be made by e-mail. For the administrator, an announcement may be made by the management device 10, or an announcement may be made by e-mail. For example, the Web server 100 may store (manage) the predetermined number of times and count (manage) the number of times of punching using the employee code.

[0261] (3) In the above embodiment, in addition to punching by face authentication, punching using an employee code (punching in which an employee code, which is identification information capable of uniquely identifying an employee, is input) has been described. However, instead of the employee code, a password may be input. The password is set in advance by each employee and is stored, for example, in the employee master. Basically, the password is an arbitrary character string. However, since it is necessary to identify each individual employee with the password alone, duplication of passwords with other employees is not allowed. Therefore, for example, when setting the password, the Web server 100 checks whether it overlaps (duplicates) with the passwords of other employees. Also, in view of the laboriousness at the time of input (i.e., at the time of punching), depending on the number of persons targeted, the password may be a number within 5 or 6 digits.

[0262] (4) In the above embodiment, when face authentication fails, a screen for notifying the face image at the time of failure (the face image for stamping) (the small screen SG2003 in Fig. 3(D)) is displayed to guide stamping by re-face authentication or stamping by employee code (that is, an example of guiding re-challenge of stamping by face authentication or stamping by employee code and finally completing stamping) has been described. However, the processing after stamping completion may be varied according to the situation of face authentication failure. For example, when face authentication fails continuously for a predetermined number of times, or when face authentication fails a predetermined number of times (or accumulatively a predetermined number of times) within a predetermined period, since there is a possibility that the pre-registered face image and the current appearance are significantly different, additional face registration (addition of pre-registered face image) may be guided. For example, the Web server 100 may store (manage) a predetermined number of times which is a reference number of times, and count (manage) the number of failure times.

[0263] The mode of guiding additional face registration may be to display a guiding message on a screen (small screen, etc.) after stamping completion or after authentication failure, or to send a page related to face registration (an e-mail related to face registration) to the employee.

[0264] Also, when face authentication fails continuously for a predetermined number of times, the possibility of successful stamping by face authentication is low and there may be a risk of congestion. Therefore, only stamping by employee code may be guided (the re-authentication button BT2105 may be made invisible). The predetermined number of times (continuous failure times) when only guiding stamping by employee code and the predetermined number of times (continuous failure times) when guiding additional face registration may be the same or different.

[0265] (5) In the above (4), a predetermined number of times is used as a condition, but the predetermined number of times may be 1 time. That is, when stamping by face authentication fails and stamping by employee code is performed, even for the first time, for example, a page related to face registration may be sent to the employee. Each time stamping by face authentication fails, a page related to face registration may be sent to the employee.

[0266] (6) In the above embodiment, a deadline (for example, "72 hours") is set for the operation of activating the face recognition device, but a deadline may also be set for face registration. For example, when a predetermined time has elapsed since the transmission of a page related to face registration (an email related to face registration), the face registration screen may not be displayed.

[0267] (7) Without setting a deadline for face registration, when a predetermined time has elapsed without face registration after the transmission of a page related to face registration (an email related to face registration), the page related to face registration may be automatically transmitted again. Before automatically transmitting the page related to face registration, for example, an announcement (an announcement of a notice of automatic transmission including the target person and the scheduled transmission time) may be made to the administrator using the management terminal 10 (or an email). Or, after automatically transmitting the page related to face registration, for example, an announcement (an announcement of the result of automatic transmission including the target person and the transmission time) may be made to the administrator using the management terminal 10 (or an email). The history of automatic transmission may be stored (for example, stored in the web server 100). Note that when a predetermined time has elapsed without face registration after the transmission of the page related to face registration, instead of automatic transmission, an announcement may be made to the administrator using the management terminal 10 (or an email) to the effect that a predetermined time has elapsed without face registration after the transmission of the page related to face registration (that is, the administrator who has received the announcement operates the management terminal 10 to instruct the transmission of the page related to face registration).

[0268] (8) In the above embodiment, the face authentication server 200 determines whether it matches the face image for punching (identifying the employee) by comparing it with all the pre-registered face images in the face authentication master, but it may also be determined by comparing it with the pre-registered face images within the scope of the department. This is effective (for example, improving speed and accuracy) in face authentication using a terminal (store terminal 20) whose department can be identified from the installation location.

[0269] (9) In the above embodiment, an example of selecting one distribution page (one of the pages related to the department time recorder, the personal time recorder, and the face registration page) at the time of page distribution was described. However, two distribution pages may be selected together. Specifically, the two pages related to the personal time recorder and the face registration page may be selected together. Since the destinations for setting (selecting, etc.) the above two distribution pages in step 3 are both employees and common, they can be selected and distributed together. Note that since the destination of the page related to the department time recorder is not an employee (it is a device, etc.), it cannot be selected and distributed together with other pages.

[0270] (10) In the above embodiment, the store terminal 20 was described as a tablet terminal. However, it may be a terminal installed at the workplace (work location) and used by a plurality of employees. For example, the store terminal 20 may be a personal computer (desktop type, notebook computer) with a built-in (or externally attached) camera. When a personal computer is used as the store terminal 20, it may be operated by a mouse or keyboard instead of a touch operation on a touch display. When the store terminal 20 is a tablet terminal (similarly for a personal computer) and has both an inward-facing camera (facing the display unit side for imaging) and an outward-facing camera built in, the inward-facing camera is activated. When attaching a camera externally to the personal computer used as the store terminal 20, it is attached in the direction of imaging the display unit side.

[0271] (11) In the above-described embodiment, the mobile terminal 30 was described as a smartphone or a tablet terminal, but any portable type terminal (a mobile terminal suitable for carrying around) may be used. For example, the mobile terminal 30 may be a notebook personal computer with a built-in (or externally attached) camera. When using a notebook personal computer as the mobile terminal 30, it may be operated using a mouse or a keyboard instead of a touch operation on a touch display. When the smartphone used as the mobile terminal 30 (similarly for a tablet terminal or a notebook personal computer) has both an inward-facing camera and an outward-facing camera built therein, the inward-facing camera is activated. When attaching a camera externally to the notebook personal computer used as the mobile terminal 30, it is attached in a direction for imaging the display unit side.

[0272] (12) In the above-described embodiment, the personal time recorder was described as the mobile terminal 30 (a smartphone or a tablet terminal), but the personal time recorder may be any personal terminal and does not necessarily have to be a portable type terminal. For example, the personal time recorder may be an installed type personal computer with a built-in (or externally attached) camera. When using an installed type personal computer as the personal time recorder, it may be operated using a mouse or a keyboard. The installation location may be a desk at the workplace or at home. When the smartphone used as the personal time recorder (similarly for a tablet terminal or a personal computer) has both an inward-facing camera and an outward-facing camera built therein, the inward-facing camera is activated. When attaching a camera externally to the personal computer used as the personal time recorder, it is attached in a direction for imaging the display unit side.

[0273] (13) In the above-described embodiment, it was described that the Web server 100 stores the employee master, but other devices may store the employee master. For example, a file server (a server accessible by the Web server 100, not shown) may store the employee master. The same applies to the company master, the administrator master, the department master (affiliation master), and the attendance record file. Also, various masters and attendance record files may be distributed and stored in a plurality of devices.

[0274] (14) In the above embodiment, it has been described that the face authentication server 200 stores the face authentication master, but other devices may store the face authentication master. For example, the Web server 100 may store the face authentication master (that is, the face authentication server 200 may perform face authentication by referring to the face authentication master stored by the Web server 100), or a file server (a server accessible by the face authentication server 200, not shown) may store the face authentication master.

[0275] (15) In the above embodiment, the Web server 100, the face authentication server 200, and the mail server 300 have been described separately, but the Web server 100 and the face authentication server 200 may be integrated (the Web server 100 may also have the functions of the face authentication server 200). The Web server 100 and the mail server 300 may be integrated. The face authentication server 200 and the mail server 300 may be integrated. The Web server 100, the face authentication server 200, and the mail server 300 may be integrated.

[0276] (16) In the above embodiment, it has been described that the attendance management system 1 uses the Web service provided by the Web server 100, but it may not use the Web service. That is, it may be by an application (an application other than the Web) operating on one or both of the server side and the terminal side. For example, the screen displayed on the terminal such as the attendance screen may be displayed by an application operating on the terminal side. Also, the face authentication function (system) may be on the server side or may be a program (algorithm) of an application operating on the terminal side.

[0277] (17) In the above embodiment, an example of adopting face authentication as the authentication using the imaging unit (camera) has been described, but instead of or in addition to face authentication, authentication by iris or fingerprint may be adopted.

[0278] (18) In the above embodiment, an example of using face registration / face authentication in a system related to going to and coming from work (commute management system 1) has been described. However, the face registration / face authentication technology shown in the above embodiment may be applied to a system that performs face authentication using a pre-registered face image and a face image acquired at the time of face authentication. For example, it may be applied to a system related to events or entry (or exit).

[0279] (19) Some or all of the functions (input / output, storage, processing (including judgment)) in each device (management terminal 10, store terminal 20, mobile terminal 30, Web server 100, face authentication server 200, mail server 300) may be realized in another device different from the device described as the execution entity of the function.

[0280] <Summary of the Embodiment> [Technical Field] The present invention relates to a face authentication system. [Background Art] A face authentication system using a user's face image is known (for example, see Patent Document 1). Also, a system for managing the going to and coming from work of employees and staff is known. [Prior Art Documents] [Patent Documents] [Patent Document 1] Japanese Patent Application Laid-Open No. 2020-126342 [Summary of the Invention] [Problems to be Solved by the Invention] However, there is room for improvement in the management and operation of going to and coming from work. The present invention has been made in view of such circumstances, and an object thereof is to provide a technology capable of suitably implementing the management and operation of going to and coming from work. [Means for Solving the Problems]

[0281] (1) One aspect for solving the above-described problems is a face authentication system (e.g., the attendance management system 1) that includes an imaging terminal (e.g., the store terminal 20, the mobile terminal 30) having an imaging unit and a management terminal (e.g., the management terminal 10), and performs face authentication using a registered face image (e.g., a pre-registered face image) and a face image acquired during face authentication (e.g., a face image for punching). The face registration machine setting means for setting face registration machine setting information (e.g., information regarding the distribution of pages related to the affiliated time recorder, information regarding the distribution of pages related to face registration) for causing the imaging terminal to function as a face registration machine for imaging a face image used for registration based on an operation of the management terminal, the face authentication machine setting means for setting face authentication machine setting information for causing the imaging terminal to function as a face authentication machine for imaging a face image during face authentication based on an operation of the management terminal (e.g., information regarding the distribution of pages related to the affiliated time recorder, information regarding the distribution of pages related to the personal time recorder), and transmission means for transmitting the face registration machine setting information set by the face registration machine setting means or the face authentication machine setting information set by the face authentication machine setting means to the imaging terminal based on an operation of the management terminal. (1) According to the face authentication system of (1), the management and operation of attendance can be suitably carried out.

[0282] (2) The face authentication system according to (1) further includes setting screen display control means for displaying a setting screen (e.g., a management screen) for setting the face registration machine setting information and the face authentication machine setting information. The setting screen display control means displays information for setting the face registration machine setting information or the face authentication machine setting information in a selectable manner in a plurality of stages (e.g., step 1, step 2, step 3) in a first display area (e.g., the left area of the management screen in FIGS. 7 and 14), and when a predetermined operation is performed in the first display area, displays information (e.g., a template of a distribution page) corresponding to the information selected in the first stage among the plurality of stages in a second display area (e.g., the right area of the management screen). (2) According to the face authentication system of (2), the management and operation of attendance can be suitably carried out.

[0283] (3) It is provided with face authentication operation control means for making the imaging terminal function as the face authentication machine based on the face authentication machine setting information. The face authentication machine can accept an operation for identifying an operator by code authentication (for example, operation of the code engraving button BT2102) in addition to an operation for identifying an operator by face authentication. When the operator is identified by face authentication, the face authentication operation control means displays first authentication information indicating that the operator has been identified by face authentication (for example, displays a face image in the authentication information column of the attendance status list area AR220 on the attendance and departure screen in FIG. 2). When the operator is identified by code authentication, it displays second authentication information indicating that the operator has been identified by code authentication (for example, displays "code" or the like in the authentication information column of the attendance status list area AR220 on the attendance and departure screen in FIG. 2). It is the face authentication system according to (1) or (2). According to the face authentication system of (3), the management and operation of attendance and departure can be suitably carried out.

[0284] (4) It is provided with face authentication operation control means for making the imaging terminal function as the face authentication machine based on the face authentication machine setting information. When the operator is identified by face authentication, the face authentication operation control means displays an image different from the captured image by the imaging terminal (for example, an image such as a mascot image, an image for engraving) and displays a button (for example, the continuous attendance button BT2103) for starting the next face authentication. When the operator is not identified by face authentication, it displays the captured image by the imaging terminal (for example, the face image for engraving) and displays buttons (for example, the re-authentication button BT2105, the code engraving button BT2102) for continuing the identification of the operator. It is the face authentication system according to (1) or (2). According to the face authentication system of (4), the management and operation of attendance and departure can be suitably carried out.

[0285] (5) One aspect for solving the above problems is a face authentication system (for example, the attendance management system 1) that includes an imaging terminal (for example, the store terminal 20, the mobile terminal 30) having an imaging unit, a management terminal (for example, the management terminal 10), and a server (for example, the Web server 100), and performs face authentication using a registered face image and a face image obtained during face authentication. The management terminal includes a face registration machine setting means for setting face registration machine setting information for causing the imaging terminal to function as a face registration machine that captures a face image used for registration based on an operation on a setting screen (for example, a management screen) provided by the server, a face authentication machine setting means for setting face authentication machine setting information for causing the imaging terminal to function as a face authentication machine that captures a face image during face authentication based on an operation on a setting screen provided by the server, and a transmission means for transmitting the face registration machine setting information set by the face registration machine setting means or the face authentication machine setting information set by the face authentication machine setting means to the imaging terminal based on an operation on a setting screen provided by the server. (5) According to the face authentication system of (5), the management and operation of attendance can be suitably carried out.

[0286] (6) One aspect for solving the above problems is a management terminal (for example, the management terminal 10) that manages a face authentication system (for example, the attendance management system 1) that performs face authentication using a pre-registered face image (for example, a pre-registered face image) and a face image obtained during face authentication (for example, a face image for stamping). The management terminal includes a face authentication machine setting means for setting face authentication terminal setting information for causing the terminal to function as a face authentication machine that captures a face image during face authentication. The face authentication machine displays a face authentication machine screen (for example, the attendance screen in FIGS. 2 and 16(B)) provided by a server (for example, the Web server 100) using a browser. The face authentication machine setting means is a management terminal that sets distribution of guidance information (for example, the e-mail in FIG. 9) including the URL of the screen (the certificate information reference screen in FIG. 10) that displays the URL of the face authentication machine screen and the password (for example, certificate information) to the terminal that functions as the face authentication machine. (6) According to the management terminal of (6), the management and operation of attendance can be suitably carried out.

[0287] It includes face registration machine setting means for setting face registration machine setting information for causing a terminal to function as a face registration machine that captures a face image (for example, a pre-registration candidate face image) used for pre-registration. The face registration machine displays a screen for the face registration machine provided by the server (for example, the face registration screen in FIG. 16(A)) on a browser, and the face registration machine setting means distributes guidance information (for example, the e-mail in FIG. 15) including the URL and ID (for example, employee code) of the screen for the face registration machine to the terminal that functions as the face registration machine. It is the management terminal described in (6). According to the management terminal in (7), the management and operation of going to and leaving work can be suitably carried out.

[0288] Note that, a program for realizing the functions of each of the devices (management terminal 10, store terminal 20, mobile terminal 30, Web server 100, face authentication server 200, mail server 300) described above may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read into a computer system and executed to perform the processing of each of the above devices. Here, "reading the program recorded on the recording medium into a computer system and executing it" includes installing the program in the computer system. The "computer system" as used herein shall include hardware such as an OS and peripheral devices. Also, the "computer system" may include a plurality of computer devices connected via a network including a communication line such as the Internet, WAN, LAN, or dedicated line. Further, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, magneto-optical disk, ROM, CD-ROM, or a storage device such as a hard disk built into a computer system. Thus, the recording medium storing the program may be a non-transitory recording medium such as a CD-ROM. Also, the recording medium includes an internal or external recording medium provided so as to be accessible from a distribution server for distributing the program. The code of the program stored in the recording medium of the distribution server may be different from the code of the program in a form executable by the terminal device. That is, as long as it can be downloaded from the distribution server and installed in a form executable by the terminal device, the form stored in the distribution server does not matter. Note that, the program may be divided into a plurality of parts, downloaded at different timings, and then combined in the terminal device, or the distribution servers for distributing each of the divided programs may be different. Furthermore, the "computer-readable recording medium" shall also include a volatile memory (RAM) inside a computer system that becomes a server or a client when a program is transmitted via a network, and that holds the program for a certain period of time. Also, the above program may be for realizing a part of the functions described above.Furthermore, it may be a so-called difference file (difference program) that can be realized in combination with a program already recorded in the computer system for the above-described functions.

Explanation of Signs

[0289] 1…Attendance management system 10…Management terminal 20…Store terminal 30…Mobile terminal 100…Web server 200…Face authentication server 300…Mail server

Claims

1. A face recognition system comprising an imaging terminal having an imaging unit and a management terminal, and performing face recognition using a registered face image and a face image acquired during face authentication, a face registration machine setting means for setting face registration machine setting information for causing the imaging terminal to function as a face registration machine that captures a face image used for registration based on an operation of the management terminal, a face authentication machine setting means for setting face authentication machine setting information for causing the imaging terminal to function as a face authentication machine that captures a face image during face authentication based on an operation of the management terminal, a transmission means for transmitting the face registration machine setting information set by the face registration machine setting means or the face authentication machine setting information set by the face authentication machine setting means to the imaging terminal based on an operation of the management terminal, A face recognition system comprising the above.

2. Comprising a setting screen display control means for displaying a setting screen for setting the face registration machine setting information and the face authentication machine setting information, The setting screen display control means, In a first display area, information for setting the face registration machine setting information or the face authentication machine setting information is displayed so as to be selectable in multiple stages, In a second display area, when a predetermined operation is performed in the first display area, information corresponding to the information selected in the first stage of the multiple stages is displayed The face recognition system according to claim 1.

3. Comprising a face authentication operation control means for causing the imaging terminal to function as the face authentication machine based on the face authentication machine setting information, The face authentication machine can receive an operation for identifying an operator by code authentication in addition to an operation for identifying an operator by face authentication, The face authentication operation control means, When an operator is identified by face authentication, display first authentication information indicating that the operator has been identified by face authentication, When an operator is identified by code authentication, display second authentication information indicating that the operator has been identified by code authentication The face recognition system according to claim 1 or claim 2.

4. Comprising a face authentication operation control means for causing the imaging terminal to function as the face authentication machine based on the face authentication machine setting information, The face authentication operation control means, When an operator is identified by face authentication, display an image different from the captured image by the imaging terminal and display a button for starting the next face authentication, while When the operator cannot be identified by face authentication, the imaging terminal displays the captured image and also displays a button for continuing to identify the operator. The face authentication system according to claim 1 or claim 2.

5. A face authentication system comprising an imaging terminal having an imaging unit, a management terminal, and a server, and performing face authentication using a registered face image and a face image acquired during face authentication, The management terminal, face registration machine setting means for setting face registration machine setting information for causing the imaging terminal to function as a face registration machine that captures a face image used for registration based on an operation on a setting screen provided by the server; face authentication machine setting means for setting face authentication machine setting information for causing the imaging terminal to function as a face authentication machine that captures a face image during face authentication based on an operation on a setting screen provided by the server; transmission means for transmitting the face registration machine setting information set by the face registration machine setting means or the face authentication machine setting information set by the face authentication machine setting means to the imaging terminal based on an operation on a setting screen provided by the server; A face authentication system comprising the above.

Citation Information

Patent Citations

  • Face authentication system, face authentication management device, face authentication management method, and face authentication management program

    JP2020126342A