Information processing system, information processing method, and information processing device
The system improves biometric authentication accuracy by processing self-attribute information and calculating fitness for feature subsets, addressing errors due to time and environmental changes.
Patent Information
- Application Number
- JP2024001685
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-10
- Publication Date
- 2025-07-23
AI Technical Summary
Existing biometric authentication systems fail to consider various error factors such as changes in biometric information over time and environmental conditions, leading to insufficient authentication accuracy.
An information processing system that includes a client terminal and a server, which acquires and processes self-attribute information along with biometric data, creating feature subsets and calculating fitness based on similarity and mutual attribute information to update registered feature amounts, thereby improving authentication accuracy.
This approach enables highly accurate biometric authentication by considering error factors, enhancing registration accuracy and stability across varying conditions.
Smart Images

Figure 2025108055000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing system, an information processing method, and an information processing apparatus.
Background Art
[0002] Personal authentication is a process of confirming that the user is the person who has registered in advance, and is performed in various IT (Information Technology) systems. Among personal authentications, biometric authentication that confirms the identity based on the physical and behavioral characteristics of an individual is highly convenient because it does not require memorization of passwords or carrying items such as IC (Integrated Circuit) cards, and has attracted attention as a reliable means of personal identification.
[0003] Examples of features used in biometric authentication include fingerprints, faces, irises, veins, and palm prints. In biometric authentication, if the error between the biometric information acquired at the time of registration and the time of authentication is less than a certain level, the biometric information at the time of registration and the biometric information at the time of authentication are considered to be of the same person, and the authentication is determined to be successful. Therefore, in biometric authentication, if the error is equal to or greater than a certain level, even if the biometric information at the time of registration and the biometric information at the time of authentication are of the same person, they are considered to be of another person and the authentication is determined to be a failure.
[0004] As a method for suppressing this error and improving the authentication accuracy, a method of registering a plurality of biometric information to improve the authentication accuracy is known.
[0005] Japanese Patent Application Laid-Open No. 2006-72540 (Patent Document 1) describes a personal authentication system that performs personal authentication using a plurality of registered biometric information, and updates and registers the data in the storage medium while leaving the data with a low degree of matching between the data based on the newly authenticated biometric information and the data based on the plurality of biometric information registered in the storage medium.
Prior Art Documents
Patent Documents
[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-72540 [Summary of the Invention] [Problems to be Solved by the Invention]
[0007] However, the technology described in Patent Document 1 determines biometric information to be registered by referring only to the degree of matching, and does not directly consider various error factors. For example, since a person's biometric information changes over time, an error occurs depending on the acquisition date and time of the biometric information. Therefore, when registering biometric information, it is desirable to perform the registration considering error factors such as the acquisition date and time of the biometric information. However, in the technology described in Patent Document 1, only the degree of matching is referred to in the registration of biometric information, so there is a possibility that sufficient authentication accuracy cannot be obtained. [Means for Solving the Problems]
[0008] To solve the above problems, one aspect of the present invention adopts the following configuration. An information processing system includes a client terminal and a server. The client terminal holds authentication biometric information and an authentication feature amount extracted from the authentication biometric information, and acquires self-attribute information corresponding to the authentication biometric information by receiving an input to an input device and / or by calculating from the authentication biometric information or the authentication feature amount. The client terminal then transmits the authentication feature amount and the self-attribute information corresponding to the authentication biometric information to the server. The server holds a registered feature amount extracted from registered biometric information and self-attribute information corresponding to the registered biometric information, receives the authentication feature amount and the self-attribute information corresponding to the authentication biometric information from the server, creates a plurality of feature subsets from a feature set including the registered feature amount and the authentication feature amount, calculates a similarity for each combination of features included in the feature set, calculates a fitness indicating authentication accuracy for each of the plurality of feature subsets based on the similarity of the combination of features included in the feature subset and the self-attribute information corresponding to the features included in the feature subset, updates the registered feature amount based on the calculated fitness, and the self-attribute information is attribute information extracted from single biometric information or a single feature amount and affecting the authentication accuracy.
Advantages of the Invention
[0009] According to one aspect of the present invention, highly accurate biometric authentication can be realized regardless of error factors.
[0010] Problems, configurations, and effects other than those described above will be clarified by the description of the following embodiments.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Mode for Carrying Out the Invention
[0012] Hereinafter, the biometric authentication system according to the embodiment of the present invention will be described in detail with reference to the drawings. In the present embodiment, the same components are basically denoted by the same reference numerals, and repeated descriptions are omitted. It should be noted that the present embodiment is merely an example for realizing the present invention and does not limit the technical scope of the present invention.
[0013] In order to improve the authentication accuracy, the biometric authentication system of the present embodiment performs registration of biometric information in consideration of error factors such as the acquisition date and time of biometric information (self-attribute information described later). Also, for example, in fingerprint authentication, the position where the finger is placed on the sensor surface has a great influence on the authentication accuracy. For example, if the upper half of the finger is placed on the sensor surface for registration and the lower half of the finger is placed on the sensor surface for authentication, the common area of the acquired fingerprints is small, so authentication is likely to fail. Therefore, it is desirable for the biometric authentication system to register fingerprints at various positions on the upper, lower, left, and right of the finger.
[0014] Furthermore, in the case of face authentication as well, if the face at the time of registration and the face at the time of authentication are facing different directions, it is likely to fail authentication. Therefore, it is desirable for the biometric authentication system to register faces facing various directions, including up, down, left, and right. Similarly, in finger vein authentication, factors such as the position where the finger is placed and the rotation angle of the finger cause errors. By registering biometric information with various positions and rotation angles, the authentication accuracy can be improved. In the present embodiment, the biometric authentication system registers biometric information in consideration of the mutual attribute information described later in order to register biometric information with various positions and rotation angles in this way.
[0015] <First Embodiment> FIG. 1 is a block diagram showing a configuration example of a biometric authentication system. The biometric authentication system includes, for example, a client terminal 1000 and a server 1100 which is an example of an information processing device. The client terminal 1000 and the server 1100 are connected to each other via a network such as the Internet.
[0016] The client terminal 1000 includes, for example, a user ID input unit 1010, a biometric information acquisition unit 1020, a self-attribute information acquisition unit 1030, a feature extraction unit 1040, and an additional authentication data acquisition unit 1050, all of which are functional units.
[0017] The user ID input unit 1010 receives and acquires an input of a user ID for identifying a user via a keyboard, a card reader, or a memory on the client terminal 1000. The user ID is, for example, a character string composed of alphanumeric characters. The biometric information acquisition unit 1020 acquires biometric information. The biometric information can include fingerprints, faces, veins, and the like. The biometric information acquisition unit 1020 acquires fingerprint images, face images, vein images, and the like via, for example, a sensor or a camera connected to the client terminal 1000.
[0018] The self-attribute information acquisition unit 1030 acquires self-attribute information associated with the biological information acquired by the biological information acquisition unit 1020. The self-attribute information is information associated with each piece of biological information, or information associated with each feature amount obtained from the biological information, that is, information obtained from a single piece of biological information or a single feature amount. Also, the attribute information including the self-attribute information and the mutual attribute information described later is information that can affect the authentication accuracy.
[0019] The self-attribute information is classified, according to its acquisition method, into, for example, external sensor information, authentication biological information additional information, and authentication biological information analysis information. The external sensor information is information acquired using sensors other than the sensors that acquire the biological information used for authentication. The external sensor information includes, for example, the illuminance, temperature, humidity at the time of acquiring the biological information, the acquisition date and time of the biological information (when the date and time are not acquired by a camera or the like that acquires the biological information), and the blood pressure of the user at the time of acquiring the biological information.
[0020] The authentication biological information additional information is information acquired as additional information together with the biological information when the biological information used for authentication is acquired. The authentication biological information additional information includes, for example, the acquisition date and time of the biological information (when the date and time are acquired by a camera or the like that acquires the biological information), as well as the brightness and contrast of the image including the biological information, the presence or absence of wearing accessories of the user at the time of acquiring the biological information (for example, glasses, earrings, and masks when the face is used as the biological information), and the presence or absence of injuries of the user (for example, facial injuries when the face is used as the biological information, and finger or hand injuries when fingerprints or veins are used as the biological information).
[0021] The biological information analysis additional information is information calculated from the biological information used for authentication and is additional information different from the feature amounts used for authentication. The authentication biological information analysis additional information includes, for example, information obtained by calculating statistical information of an arbitrary pattern such as the number of feature points. The statistical information of the pattern has errors due to factors appearing inside the biological information and is an example of the attribute information due to internal factors.
[0022] In addition, the self-attribute information is classified into external factors and human factors depending on whether the error factor is due to the authentication environment or the person being authenticated. The self-attribute information included in the external factors is, for example, information on the environment at the time of biometric information acquisition, including the illuminance, temperature, and humidity at the time of biometric information acquisition, and the acquisition date and time of the biometric information. The self-attribute information included in the human factors is information related to the living body at the time of biometric information acquisition, and includes, for example, the user's blood pressure at the time of biometric information acquisition, the presence or absence of wearing accessories by the user, and the presence or absence of injuries to the user.
[0023] The feature extraction unit 1040 extracts feature quantities from the biometric information acquired by the biometric information acquisition unit 1020. The feature quantity is information necessary for authentication extracted from the acquired biometric information. For example, in fingerprint authentication, feature points extracted from a fingerprint image, etc., and in finger vein authentication, vein patterns extracted from a finger vein image, etc., correspond to the feature quantities. The additional authentication data acquisition unit 1050 acquires additional authentication data for authentication by another modality or another authentication means when biometric authentication fails.
[0024] The server 1100 includes, for example, a feature matching unit 1110, an additional authentication unit 1120, an inter-attribute information calculation unit 1130, a fitness calculation unit 1140, a feature quantity registration unit 1150, a self-attribute information acquisition unit 1160, and a learning processing unit 1170, all of which are functional units. In addition, the server 1100 includes a storage unit for storing information, namely, an authentication feature quantity storage unit 1190, a fitness storage unit 1191, a registered feature quantity storage unit 1192, a parameter storage unit 1193, and a learning data storage unit 1194.
[0025] The feature matching unit 1110 matches feature quantities with each other and evaluates the similarity of the matched feature quantities. The similarity between feature quantities is an index for evaluating whether the users corresponding to the feature quantities are the same user (whether the biometric information corresponding to the feature quantities is obtained from the same living body). Although various types of errors may occur when acquiring biometric information, the similarity is an index for evaluating the identity of the user including these errors. The method for calculating the similarity of feature quantities is, for example, determined in advance according to the type of feature quantity. For example, the distance between feature quantities and the cosine similarity are examples of the similarity between feature quantities.
[0026] The additional authentication unit 1120 performs additional authentication when biometric authentication fails. The mutual attribute information calculation unit 1130 calculates the mutual attribute information of the matched feature quantities when the feature matching unit 1110 matches feature quantities with each other.
[0027] The mutual attribute information is information obtained when feature quantities are matched with each other or when biometric information is matched with each other. That is, the mutual attribute information is information obtained as a comparison result of a plurality of feature quantities or a comparison result of a plurality of biometric information. The mutual attribute information can include, for example, the difference in the position, the difference in the angle, and the difference in the size of the living body to be authenticated, but is not limited thereto.
[0028] For example, in the case of fingerprint authentication or vein authentication, since it is possible to grasp how much the position of the finger placed on the sensor is deviated during matching, the difference in the position can be used as mutual attribute information. In the case of face authentication, since the orientation of the face can be estimated from the image, the difference in the angle can be used as mutual attribute information.
[0029] In this way, the mutual attribute information is calculated for a pair of a plurality of biometric information of the same modality (which may be a combination of three or more) or for a pair of the same type of feature quantities obtained from each of a plurality of biometric information of the same modality (which may be a combination of three or more).
[0030] The fitness calculation unit 1140 calculates the fitness for a set of feature quantities based on a model that calculates the fitness defined by the similarity between feature quantities, self-attribute information, mutual-attribute information, and the parameters stored in the parameter storage unit 1193.
[0031] The fitness for a set of feature quantities is, for example, an index indicating how suitable the set of feature quantities is for registered feature quantities (feature quantities already registered in the registered feature quantity storage unit 1192), and the authentication accuracy (estimated value) when the set of feature quantities is a registered feature quantity can be used as the fitness. Information indicating the authentication accuracy, such as the genuine acceptance rate, which is the probability that the genuine person is correctly accepted, the genuine rejection rate, which is the probability that the genuine person is erroneously rejected, and the impostor acceptance rate, which is the probability that an impostor is erroneously accepted, are all examples of fitness.
[0032] The feature quantity registration unit 1150 registers the feature quantity to be registered and the self-attribute information corresponding to the feature quantity in the registered feature quantity storage unit 1192. The self-attribute information acquisition unit 1160 acquires self-attribute information from the feature quantity. The learning processing unit 1170 learns the parameters of the model for calculating the fitness.
[0033] The authentication feature quantity storage unit 1190 stores the authentication feature quantity, which is the feature quantity acquired for authentication. The fitness storage unit 1191 stores the fitness calculated by the fitness calculation unit 1140. The registered feature quantity storage unit 1192 stores the registered feature quantity used for biometric authentication and the self-attribute information corresponding to the registered feature quantity.
[0034] The parameter storage unit 1193 stores the parameters of the model used by the fitness calculation unit 1140 when calculating the fitness. The learning data storage unit 1194 stores the learning data used for pre-learning processing. The learning data includes feature quantities extracted from biometric information such as fingerprints, faces, and veins acquired in advance, information indicating the types of feature quantities (for example, the types of the feature quantities themselves and the modalities of the biometric information from which the feature quantities are calculated), and the user ID corresponding to the feature quantity.
[0035] Note that some or all of the above-described functions performed by the client terminal 1000 may be executed by the server 1100, or some or all of the above-described functions performed by the server 1100 may be executed by the client terminal 1000. That is, a part of the above-described functional units included in the client terminal 1000 may be provided in the server 1100, or a part of the above-described functional units included in the server 1100 may be provided in the client terminal 1000. For example, the server 1100 may have the feature extraction unit 1040 or the like. Also, a part or all of the above-described storage unit included in the server 1100 may be provided in the client terminal 1000.
[0036] Further, the client terminal 1000 and the server 1100 may be integrated. In this case, communication between the client terminal 1000 and the server 1100 is omitted.
[0037] FIG. 2 is a block diagram showing an example of the hardware configuration of each of the client terminal 1000 and the server 1100. Each of the client terminal 1000 and the server 1100 is configured by a computer having a CPU (Central Processing Unit) 7010, a main storage device 7020, an auxiliary storage device 7030, an input device 7040, an output device 7050, and a communication device 7060.
[0038] The CPU 7010 includes a processor and executes programs stored in the main storage device 7020. The main storage device 7020 is a device corresponding to the memory of the computer and includes a ROM (Read Only Memory), which is a non-volatile memory element, and a RAM (Random Access Memory), which is a volatile memory element. The ROM stores unchanging programs (for example, BIOS (Basic Input / Output System)) and the like. The RAM is a high-speed and volatile memory element such as a DRAM (Dynamic Random Access Memory) and temporarily stores programs executed by the CPU 7010 and data used during program execution.
[0039] The auxiliary storage device 7030 is a large-capacity and non-volatile storage device such as a magnetic storage device (HDD (Hard Disk Drive)) or a flash memory (SSD (Solid State Drive)), and stores programs executed by the CPU 7010 and data used during program execution. That is, the program is read from the auxiliary storage device 7030, loaded into the main storage device 7020, and executed by the CPU 7010.
[0040] The input device 7040 is a device that receives input from an operator such as a keyboard, mouse, biometric sensor, touch panel, smart device, scanner, and camera. The input device 7040 is used to read information in the user ID input unit 1010, biometric information acquisition unit 1020, and self-attribute information acquisition unit 1030. The output device 7050 is a device that outputs the execution result of a program in a form visible to the operator, such as a display device or a printer.
[0041] The communication device 7060 is a network interface device that controls communication with other devices according to a predetermined protocol. Further, the communication device 7060 includes a serial interface such as USB (Universal Serial Bus), for example.
[0042] Part or all of the program executed by the CPU 7010 may be provided to the computer via a network from a removable medium (such as a CD-ROM or flash memory), which is a non-transitory storage medium, or an external computer equipped with a non-transitory storage device, and stored in the non-volatile auxiliary storage device 7030, which is a non-transitory storage medium. Therefore, the computers constituting the client terminal 1000 and the server 1100 respectively may have an interface for reading data from the removable medium.
[0043] Each of the client terminal 1000 and the server 1100 is a computer system configured physically on one computer or on a plurality of computers configured logically or physically, and may operate in separate threads on the same computer or may operate on a virtual computer built on a plurality of physical computer resources.
[0044] The CPU 7010 of the computer constituting the client terminal 1000 includes each functional unit of the client terminal 1000 shown in FIG. 1. The CPU 7010 of the computer constituting the server 1100 includes each functional unit of the server 1100 shown in FIG. 1.
[0045] For example, the CPU 7010 of the computer constituting the client terminal 1000 functions as the user ID input unit 1010 by operating according to the user ID input program loaded in the main storage device 7020 of the computer, and functions as the biological information acquisition unit 1020 by operating according to the biological information acquisition program loaded in the main storage device 7020 of the computer. The relationship between the program and the CPU 7010 and the main storage device 7020 of the computer constituting the client terminal 1000 is the same for other functional units included in the client terminal 1000. Also, for the functional units included in the server 1100, the relationship between the program and the CPU 7010 and the main storage device 7020 of the computer constituting the server 1100 is the same.
[0046] Note that some or all of the functions of the functional units included in the client terminal 1000 and the functions of the functional units included in the server 1100 may be realized by hardware such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array).
[0047] The auxiliary storage device 7030 of the computer constituting the server 1100 includes each storage unit shown in FIG. 1. That is, the data stored in each storage unit is accumulated as data on the auxiliary storage device 7030. Note that part or all of the data stored in each storage unit shown in FIG. 1 may be stored in the main storage device 7020 or may be stored in an external database.
[0048] Note that in the present embodiment, the information used by the authentication system may be expressed in any data structure regardless of the data structure. For example, a data structure appropriately selected from a table, a list, a database, or a queue can store the information.
[0049] FIG. 3 is a flowchart showing an example of pre-learning processing. First, the learning processing unit 1170 of the server 1100 acquires learning data from the learning data storage unit 1194 (S2010).
[0050] The self-attribute information acquisition unit 1160 acquires self-attribute information corresponding to each feature amount included in the learning data acquired in step S2010 (S2020). For example, among the self-attribute information, for the external sensor information and the authentication biometric information additional information, the self-attribute information acquisition unit 1160 acquires them via an input from an external sensor or the input device 7040, and for the authentication biometric information analysis information, the self-attribute information acquisition unit 1160 calculates it. Note that the types of self-attribute information acquired in step S2020 are determined in advance according to, for example, the types of feature amounts and the modalities of the biometric information corresponding to the feature amounts.
[0051] The mutual attribute information calculation unit 1130 calculates mutual attribute information corresponding to each pair of the same type of feature amounts included in the learning data acquired in step S2010 (S2030).
[0052] In addition, when the fitness used in this embodiment includes the false rejection rate or the true acceptance rate of the user, the mutual attribute information calculation unit 1130 calculates the mutual attribute information corresponding to each pair of feature amounts of the same type included in the learning data acquired in step S2010 and having the same user ID among the pairs of feature amounts of the same type. Further, when the fitness used in this embodiment includes the false acceptance rate of others, the mutual attribute information calculation unit 1130 calculates the mutual attribute information corresponding to each pair of feature amounts of different user IDs among the pairs of feature amounts of the same type included in the learning data acquired in step S2010. Further, the types of mutual attribute information calculated in step S2030 are determined in advance according to, for example, the types of feature amounts and the modalities of biometric information corresponding to the feature amounts.
[0053] The feature matching unit 1110 calculates the similarity corresponding to each pair of feature amounts of the same type included in the learning data acquired in step S2010 (S2040).
[0054] In addition, when the fitness used in this embodiment includes the false rejection rate or the true acceptance rate of the user, the feature matching unit 1110 calculates the similarity corresponding to each pair of feature amounts of the same type included in the learning data acquired in step S2010 and having the same user ID among the pairs of feature amounts of the same type. Further, when the fitness used in this embodiment includes the false acceptance rate of others, the feature matching unit 1110 calculates the feature amounts corresponding to each pair of feature amounts of different user IDs among the pairs of feature amounts of the same type included in the learning data acquired in step S2010. Further, the types of similarity calculated in step S2040 are determined in advance according to, for example, the types of feature amounts and the modalities of biometric information corresponding to the feature amounts.
[0055] The learning processing unit 1170 learns the parameters of a model that outputs the fitness using the self-attribute information of the feature amounts, the mutual attribute information between the feature amounts, and the similarity between the feature amounts as inputs (S2050). The model that outputs the fitness is generated for each type of feature amount.
[0056] When the learning processing unit 1170 learns the parameters of a model that outputs the false acceptance rate or the true acceptance rate as the fitness for each type of feature quantity, for each combination of the same user ID, the self-attribute information of the feature quantity of that type, the mutual-attribute information between the feature quantities of that type, and the similarity between the feature quantities of that type are used as explanatory variables, and the fitness is used as the objective variable to learn the parameters.
[0057] Also, when the learning processing unit 1170 learns the parameters of a model that outputs the false acceptance rate of others as the fitness for each type of feature quantity, for each combination of different user IDs, the self-attribute information of the feature quantity of that type, the mutual-attribute information between the feature quantities of that type, and the combination of the similarity between the feature quantities of that type are used as explanatory variables, and the fitness is used as the objective variable to learn the parameters.
[0058] Note that the correct label of the fitness is measured from the learning data, for example. When the fitness is the false acceptance rate or the true acceptance rate, the correct label of the fitness corresponding to the feature quantity is given by, for example, the false acceptance rate or the true acceptance rate when authentication is performed for each of the other feature quantities of the same type of the same person included in the learning data assuming that the feature quantity is registered. Also, when the fitness is the false acceptance rate of others, the correct label of the fitness corresponding to the feature quantity is given by, for example, the false acceptance rate of others when authentication is performed for each of the other feature quantities of the same type of other persons included in the learning data assuming that the feature quantity is registered.
[0059] As an estimation method for learning the parameters, a linear model using a polynomial, a generalized linear model using a non-linear function, or a generalized linear mixed model considering the difference in the quality of each feature quantity can be used, but it is not limited to this, and any regression model, neural network, etc. can be applied. Also, the parameters of the model are the regression parameters used in each estimation method. For example, when a linear model is used, the coefficients for each explanatory variable are the parameters to be learned.
[0060] Also, in step S2050, the learning processing unit 1170 associates the learned parameters with the type of feature amount (and the modality of the biological information which is the extraction source of the feature amount) and the type of fitness (false rejection rate, true acceptance rate, or false acceptance rate of others), and stores them in the parameter storage unit 1193.
[0061] As described above, the pre-learning is completed, and the server 1100 can calculate the fitness for the combination of feature amounts using the parameters.
[0062] FIG. 4 is a sequence diagram showing an example of the biometric authentication process and the feature amount registration process. In the first embodiment, the server 1100 executes the authentication process, selects a feature amount based on the fitness for the combination of feature amounts, and registers the selected feature amount.
[0063] First, the user ID input unit 1010 of the client terminal 1000 acquires a user ID (S3010). The user ID input unit 1010 acquires the user ID via keyboard input, two-dimensional code reading, IC card reading, or wireless communication with a smart device, etc. Note that when 1:N authentication for identifying all users without inputting a user ID is executed, the process of step S3010 is omitted.
[0064] The biological information acquisition unit 1020 acquires one or more pieces of biological information of the user (S3020). Also, the biological information acquisition unit 1020 may acquire biological information of a plurality of modalities. For example, in the case of executing multi-modal biometric authentication using the face and vein for authentication, the biological information acquisition unit 1020 acquires biological information of both the face and the vein.
[0065] The self-attribute information acquisition unit 1030 acquires self-attribute information corresponding to the biological information acquired in step S3020 (S3030). The type and acquisition method of the self-attribute information are the same as in step S2020 (that is, the same type of self-attribute information as during learning is acquired by the same method).
[0066] The feature extraction unit 1040 extracts authentication feature quantities from the biometric information acquired in step S3020 (S3040). The types of authentication feature quantities extracted by the feature extraction unit 1040 are, for example, predetermined according to the modality of the biometric information and are the same as the types of feature quantities in the learning data. For example, if the modality of the biometric information is a fingerprint, feature points called minutiae are extracted; if it is a face, an embedding vector obtained as the output of a neural network is extracted; if it is a vein, a pattern image obtained by extracting the vein region from an image is extracted as the authentication feature quantity, respectively.
[0067] The feature extraction unit 1040 transmits the user ID acquired in step S3010, the authentication feature quantity acquired in step S3040, and the self-attribute information acquired in step S3030 to the server 1100 (S3050). However, when the process of step S3010 is omitted (i.e., when 1:N authentication is performed), the user ID is not transmitted by the feature extraction unit 1040 in step S3050.
[0068] In addition, when the mutual attribute information calculated by the server 1100 in step S3270 described later is information that cannot be calculated from the feature quantity itself, the client terminal 1000 acquires information necessary for calculating the mutual attribute information from the biometric information and also transmits the necessary information to the server 1100 in step S3200. The server 1100 needs to store the necessary information corresponding to the registered feature quantity stored in the registered feature quantity storage unit 1192 and the authentication feature quantity stored in the authentication feature quantity storage unit 1190.
[0069] For example, when the difference in the angle of the living body, which is an example of mutual information, cannot be calculated from the feature quantity itself, information indicating the angle of the living body is acquired from the biometric information by the client terminal 1000 and transmitted to the server 1100. Information to be compared for calculating mutual attribute information such as the angle of the living body in this case is also called comparison information. When it is possible to calculate from the biometric information from the feature quantity itself, the feature quantity itself is the comparison information.
[0070] At server 1100, the user ID, authentication feature amount, and self-attribute information transmitted in step S3050 are received (S3200). However, when the process of step S3010 is omitted (i.e., when 1:N authentication is performed), the server 1100 does not receive the user ID in step S3200.
[0071] The feature matching unit 1110 of server 1100 reads out the registered feature amount corresponding to the user ID received in step S3200 from the registered feature amount storage unit 1192, and collates the read registered feature amount with the authentication feature amount received in step S3200 to calculate the similarity (S3210).
[0072] In addition, when a plurality of (same type) registered feature amounts corresponding to the user ID are stored in the registered feature amount storage unit 1192, the feature matching unit 1110 collates the authentication feature amount received in step S3200 with each of the plurality of registered feature amounts to calculate a plurality of similarities. Also, for example, when a plurality of modalities (i.e., a plurality of types of feature amounts) corresponding to the user ID, such as a face and a vein, are registered in the registered feature amount storage unit 1192, the feature matching unit 1110 collates the authentication feature amount received in step S3200 with the read registered feature amount for each type of feature amount to calculate the similarity.
[0073] In addition, when the process of step S3010 is omitted (i.e., when 1:N authentication is performed), since the server 1100 does not receive the user ID, in step S3210, the feature matching unit 1110 reads out the registered feature amounts of all users, and collates the authentication feature amount received in step S3200 with each of the registered feature amounts of all users to calculate the similarity.
[0074] In addition, when a plurality of registered feature amounts of the same user (of the same type) are stored in the registered feature amount storage unit 1192, the feature matching unit 1110 may select a registered feature amount from the plurality of registered feature amounts and calculate the similarity by matching the authentication feature amount received in step S3200 with each of the selected registered feature amounts. By doing so, the amount of calculation required for authentication becomes constant regardless of the number of registered feature amounts, and it is possible to keep constant the acceptance rate of others that increases with the number of registered feature amounts.
[0075] The feature matching unit 1110 can use the self-attribute information corresponding to the authentication feature amount received in step S3200 and the self-attribute information corresponding to the registered feature amount stored in the registered feature amount storage unit 1192 for the selection of the registered feature amount described above. For example, when the direction in which the face is facing is used as self-attribute information in face authentication, the feature matching unit 1110 compares the direction of the face (self-attribute information) received in step S3200 with the direction of the face corresponding to each registered feature amount, and selects the registered feature amount corresponding to the direction closest to that received in step S3200. Thereby, it can be expected that authentication can be performed with high accuracy.
[0076] In addition, when the feature matching unit 1110 determines that the registered feature amount corresponding to the user ID received in step S3200 is not included in the registered feature amount storage unit 1192 (that is, at the time of first registration), the processing after step S3210 may be omitted, and the user ID, authentication feature amount, and self-attribute information received in step S3200 may be associated and registered in the registered feature amount storage unit 1192.
[0077] The feature matching unit 1110 obtains an authentication result by performing threshold processing or the like on the obtained similarity (S3220). In biometric authentication, for example, if the similarity between the registered feature amount and the authentication feature amount is equal to or greater than a predetermined threshold, the biometric information corresponding to those feature amounts is regarded as that of the same person and the authentication is successful, and if the error is less than the predetermined threshold, the authentication fails. The process for obtaining such an authentication result is called threshold processing.
[0078] Incidentally, the predetermined threshold value may be described, for example, in a program that implements the feature matching unit 1110, or may be stored in advance in the main storage device 7020 or the auxiliary storage device 7030 that constitutes the computer that implements the server 1100.
[0079] Incidentally, when the feature matching unit 1110 calculates a plurality of similarity degrees, for example, by performing a predetermined statistical operation, a representative value such as the maximum value, minimum value, average value, or median value of the plurality of similarity degrees is calculated, and an authentication result can be obtained by performing threshold processing on the representative value.
[0080] Incidentally, when performing authentication using a plurality of modalities such as face and vein, if the feature matching unit 1110 determines that authentication is successful in at least one modality, the system may determine that authentication is successful. By doing so, it becomes possible to stably perform authentication even if the quality of the biometric information of one modality is low at the time of authentication. Furthermore, since it is possible to register an authentication feature amount for which an error is large and single modality authentication fails when performing additional registration of feature amounts thereafter, it is possible to enhance the effect of additional registration.
[0081] When the feature matching unit 1110 determines in step S3220 that the similarity degree is less than the threshold value, it notifies the client terminal 1000 of an authentication result indicating that authentication has failed. The additional authentication data acquisition unit 1050 of the client terminal 1000 acquires additional authentication data (S3060) and transmits the acquired additional authentication data to the server 1100 (S3070).
[0082] The additional authentication data is data acquired from the user when authentication fails once. The additional authentication data acquisition unit 1050 may acquire biometric information in the same manner as in steps S3020 and S3040 and extract feature amounts from the acquired biometric information.
[0083] In addition, the additional authentication data acquisition unit 1050 may acquire, as additional authentication data, authentication data for memory authentication such as password authentication or authentication data for possession authentication such as IC card authentication, in addition to biometric information. When additional authentication other than biometric authentication is performed, registration data for comparison with the authentication data in the additional authentication is stored in advance, for example, in the auxiliary storage device 7030 of the computer constituting the server 1100.
[0084] The server 1100 receives the additional authentication data transmitted in step S3070 (S3230), and the additional authentication unit 1120 performs additional authentication using the received additional authentication data (S3240). If the additional authentication unit 1120 determines that the additional authentication has failed, the process ends as if the entire authentication process has failed.
[0085] When the feature matching unit 1110 determines that authentication has succeeded in step S3220 (that is, when it is determined that the similarity is equal to or greater than the threshold value), or when the additional authentication unit 1120 determines that additional authentication has succeeded in step S3250, for each arbitrary feature amount pair that can be generated from the feature amount set including the registered feature amount read from the registered feature amount storage unit 1192 in step S3210 and the authentication feature amount received in step S3200, the feature matching unit 1110 calculates the similarity, and the mutual attribute information calculation unit 1130 calculates the mutual attribute information (S3270).
[0086] Note that the type and calculation method of the similarity are the same as in step S2040 (that is, the same type of similarity as during learning is obtained by the same method), and the type and calculation method of the mutual attribute information are the same as in step S2050 (that is, the same type of mutual attribute information as during learning is calculated by the same method).
[0087] The fitness calculation unit 1140 acquires a model corresponding to the parameters stored in the parameter storage unit 1193 (and corresponding to the type of feature amount received in step S3200), generates a subset (hereinafter also referred to as a feature amount subset) from the set of feature amounts, and for each feature amount subset, uses, as explanatory variables, the similarity of each pair of feature amounts included in the feature amount subset, the self-attribute information of each feature amount included in the feature amount subset, and the mutual-attribute information of each pair of feature amounts included in the feature amount subset, and inputs them to the acquired model to calculate the fitness (S3280).
[0088] Note that, as an example, the fitness is calculated using three types of explanatory variables, i.e., similarity, self-attribute information, and mutual-attribute information, as the explanatory variables of the model. However, it is also possible to calculate the fitness using a part of similarity, self-attribute information, and mutual-attribute information. When the fitness is calculated using a part of them, parameter learning using the part is performed in step S2050.
[0089] For example, when self-attribute information is included in the explanatory variables of the model for calculating the fitness, it becomes possible to register feature amounts in consideration of the date and time at the time of acquisition of biological information, the external environment, and the brightness, contrast, etc. of the image, which are image features.
[0090] Also, for example, when mutual-attribute information is included in the explanatory variables of the model for calculating the fitness, it becomes possible to register feature amounts with different displacements in the position or angle of the image, and it becomes possible to widely cover variations in position and angle in the registered feature amounts.
[0091] Also, for example, when both self-attribute information and mutual-attribute information are included in the explanatory variables of the model for calculating the fitness, a feature amount obtained from biometric information that is new in acquisition date and time and has no deviation in the position of other biometric information and the image, such that the registration priority is high when only self-attribute information is considered but low when only mutual-attribute information is considered, and a feature amount obtained from biometric information that is old in acquisition date and time and has a different position from other biometric information, such that the registration priority is low when only self-attribute information is considered but high when only mutual-attribute information is considered, it is possible to compare which one should be registered, etc.
[0092] Among the feature amounts included in the above-described feature amount set, when the number of registered feature amounts stored in the registered feature amount storage unit 1192 is a, the number of authentication feature amounts received in step S3200 among the feature amounts included in the feature amount set is 1, and the maximum number of registered feature amounts in the registered feature amount storage unit 1192 is m, the number of feature amounts to be registered (the number of updated registered feature amounts) in step S3290 described later is 1 or more and min(a + 1, m) or less.
[0093] In step S3280, the subset of feature amounts to be the object of fitness calculation may be all subsets that can be generated from the feature amount set consisting of a + 1 feature amounts and are subsets consisting of min(a + 1, m) feature amounts which is the maximum value of the possible number (as the number of elements of the subset of feature amounts). In this case, in step S3290 described later, the maximum number of feature amounts that can be registered will always be registered.
[0094] Also, the subset of feature amounts to be the object of fitness calculation may be all subsets that can be generated from the feature amount set consisting of a + 1 feature amounts and are subsets consisting of 1 or more and min(a + 1, m) or less feature amounts. In this case, the number of feature amounts to be registered in step S3290 described later is variable and is 1 or more and min(a + 1, m) or less. Note that the number of registered feature amounts and the number of feature amounts included in the subset of feature amounts to be the object of fitness calculation can be preset, for example, by an administrator of the biometric authentication system or the like.
[0095] Also, one type of fitness may be calculated, or two or more types of fitness may be calculated (that is, there may be only one model for calculating fitness, or there may be two or more). The type and number of types of fitness calculated can be preset, for example, by the administrator of the biometric authentication system or the like.
[0096] When one type of fitness is calculated, for example, the false rejection rate, which is the probability that the person cannot be correctly authenticated when biometric authentication is performed, or the true acceptance rate, which is the probability that the person can be correctly authenticated, can be used as the fitness. In this case, the feature registration unit 1150 selects and registers the feature subset with the lowest false rejection rate or the highest true acceptance rate among the feature subsets for which the fitness has been calculated, thereby improving the authentication accuracy.
[0097] Also, when two or more types of fitness are calculated, for example, two of them, the false rejection rate, which is the probability that the person cannot be correctly authenticated, and the false acceptance rate, which is the probability that another person is incorrectly authenticated, can be used as the fitness. The false rejection rate and the false acceptance rate are in a trade-off relationship. Generally, as the number of registered features increases, the false rejection rate decreases, but the false acceptance rate increases.
[0098] To meet the security requirements, for the false acceptance rate, for example, when the performance (security requirement) of the biometric authentication system claims a false acceptance rate of 1 in 1 million, it is not allowed for the false acceptance rate to exceed this value. Therefore, it is preferable to use the false acceptance rate as a constraint condition. Specifically, for example, the feature registration unit 1150 can adopt a strategy of registering only the feature subsets for which the estimated false acceptance rate meets the security requirements as registration candidates, and registering the feature subset with the lowest false rejection rate among those candidates. By doing so, it becomes possible to improve the authentication accuracy while always meeting the security requirements.
[0099] The above is a method for improving authentication accuracy while meeting security requirements on the premise that the threshold value used for authentication is a fixed and common value independent of the user (hereinafter, the fixed threshold value independent of the user is also referred to as the common threshold value).
[0100] When it is possible to operate using a variable and individual threshold value for each user (hereinafter, the threshold value for each user is also referred to as the individual threshold value), the fitness calculation unit 1140 estimates an other distribution, which is a probability distribution followed by the similarity between features of others with respect to the feature subset, from the similarity between feature amounts, the self-attribute information of the feature amount, and the mutual-attribute information between feature amounts, obtains an individual threshold value that satisfies the security requirement (the acceptance rate of others for the entire biometric authentication system) based on the estimated other distribution, and can also obtain the false rejection rate of the legitimate user when the individual threshold value is used as the fitness. In this case, the individual threshold value is always optimized for the security requirement, and a feature subset with high authentication accuracy at the individual threshold value will be registered.
[0101] The fitness calculation unit 1140 refers to the parameters stored in the parameter storage unit 1193 in the calculation of the fitness. The fitness calculation unit 1140 stores the calculated fitness in the fitness storage unit 1191.
[0102] Note that the fitness calculation unit 1140 may store the calculated fitness in the fitness storage unit 1191 in association with the user ID corresponding to the fitness and the information indicating the feature subset corresponding to the fitness. Thereby, in the process of step S3280 after the next time, the process of calculating the fitness for a part of the feature subsets of the user ID can be omitted.
[0103] Further, the fitness calculation unit 1140 may store the calculated fitness in the fitness storage unit 1191 in association with the user ID corresponding to the fitness, the similarity used for calculating the fitness, the self-attribute information, and the mutual-attribute information, and information indicating the feature amounts corresponding to the similarity, the self-attribute information, and the inheritance information. Thereby, in the process of step S3280 after the next time, for a pair of some feature amounts of the user ID, the process of calculating the similarity and the mutual-attribute information can be omitted, and when the server 1100 acquires the self-attribute information, the process of acquiring the self-attribute information for some feature amounts of the user ID can be omitted.
[0104] Note that when the fitness calculation unit 1140 uses the mutual-attribute information for estimation in the calculation of the fitness, it is necessary to substitute, as explanatory variables, the mutual-attribute information between each of the feature amounts included in the above-described feature amount subset and the feature amounts to be acquired at the time of future authentication, into the model. Since the feature amounts to be acquired at the time of future authentication are unknown, the fitness calculation unit 1140 estimates the mutual-attribute information with the feature amounts to be acquired at the time of future authentication as a probability distribution assuming a prior distribution. The fitness calculation unit 1140 can estimate the fitness for future authentication by performing marginalization using the probability distribution.
[0105] For example, as the mutual-attribute information, when the difference in the position of the living body to be collated is calculated, and the position cannot be specified from the feature amount itself but can be specified from the biometric information, it is preferable that a prior distribution of the biometric information or a prior distribution of the position of the living body is generated in advance. Also, when the mutual-attribute information can be calculated from the feature amount itself, a prior distribution of the feature amount may be generated in advance.
[0106] Note that when the fitness calculation unit 1140 uses the self-attribute information in the calculation of the fitness, similarly, the self-attribute information of the unknown feature amounts to be acquired at the time of future authentication may be estimated as a probability distribution assuming a prior distribution, and the estimated self-attribute information may be substituted into the model.
[0107] Note that when the learning processing unit 1170 learns the prior distribution used for fitness calculation during parameter learning in step S2050, the fitness calculation unit 1140 can use a prior distribution common to all users. Further, the learning processing unit 1170 may learn the prior distribution using the attribute information obtained during operation for each user. In this case, the fitness calculation unit 1140 uses a different prior distribution for each user. The learning processing unit 1170 may store the learned prior distribution (the prior distribution associated with the user ID when using different prior distributions for each user), for example, in the parameter storage unit 1193.
[0108] The feature quantity registration unit 1150 selects a feature quantity subset according to the magnitude of the fitness, and registers all the feature quantities included in the selected feature quantity subset as new registered feature quantities in the registered feature quantity storage unit 1192, thereby updating the registered feature quantities stored in the registered feature quantity storage unit 1192 (S3290). Further, the feature quantity registration unit 1150 registers the self-attribute information corresponding to each of the new registered feature quantities in the registered feature quantity storage unit 1192.
[0109] When different individual thresholds are adopted for each user in step S3280, the feature quantity registration unit 1150 also registers the individual thresholds in the registered feature quantity storage unit 1192, and the individual thresholds may be used during authentication. Since the feature quantities included in the feature quantity subset with the maximum or minimum (i.e., the best) fitness are a set of feature quantities expected to achieve the highest subsequent authentication accuracy when the feature quantities included in the feature quantity subset are registered, the authentication accuracy of the biometric authentication system can be improved thereby.
[0110] As described above, the biometric authentication system according to the first embodiment utilizes the biometric information acquired at the time of authentication, and selects and registers a set of feature quantities that are considered optimal for registration from the perspective of attribute information, that is, a set of feature quantities expected to achieve high authentication accuracy, thereby optimizing the authentication accuracy.
[0111] In the above example, when authentication is successful in step S3220 or when it is determined that additional authentication is successful in step S3250, the processes in steps S3270 to S3290 are always executed, but there may be cases where some or all of these processes are omitted.
[0112] Specifically, for example, when authentication is successful in step S3220 or when it is determined that additional authentication is successful in step S3250, the fitness calculation unit 1140 obtains, from the fitness storage unit 1191, the fitness corresponding to the current registered feature amount of the user ID (or all registered feature amounts in the case of 1:N authentication).
[0113] The fitness calculation unit 1140 determines whether the processes in steps S3270 to S3290 are to be executed based on the comparison result of comparing the obtained fitness with a predetermined value (i.e., the expected authentication accuracy based on the current registered feature amount). Specifically, for example, when the fitness includes the false rejection rate of the user, the fitness calculation unit 1140 determines that the processes in steps S3270 to S3290 are to be executed when the false rejection rate indicated by the obtained fitness is equal to or higher than the predetermined value (i.e., the expected authentication accuracy based on the current registered feature amount is low), and determines that the processes in steps S3270 to S3290 are not to be executed when the false rejection rate indicated by the obtained fitness is less than the predetermined value (i.e., the expected authentication accuracy based on the current registered feature amount is high).
[0114] Further, after the fitness calculation unit 1140 obtains the fitness corresponding to the current registered feature amount, and executes the processes of step S3270 and step S3280, based on the comparison result between the fitness corresponding to the current registered feature amount and the fitness calculated in step S3280 (the difference between the authentication accuracy based on the current registered feature amount and the authentication accuracy when the registered feature amount is updated), it may be determined whether the process of step S3290 is to be executed. Specifically, for example, when the difference between the fitness of the current registered feature amount and the fitness calculated in step S3280 is equal to or greater than a predetermined value (i.e., an improvement in authentication accuracy is expected due to the registration of the feature amount), it is determined that the process of step S3290 is to be executed, and when the difference is less than the predetermined value (i.e., an improvement in authentication accuracy is not expected due to the registration of the feature amount), it is determined that the process of step S3290 is not to be executed.
[0115] Also, the processes of step S3270 and step S3280 may be executed only when the false rejection rate indicated by the fitness corresponding to the current registered feature amount is equal to or greater than a predetermined value, and further, the process of step S3290 may be executed only when the difference between the fitness corresponding to the current registered feature amount and the fitness calculated in step S3280 is equal to or greater than a predetermined value.
[0116] Thereby, the biometric authentication system can omit the update process of the registered feature amount when the expected authentication accuracy by the current registered feature amount is high or when an improvement in authentication accuracy is not expected due to the registration of the feature amount, so that both high authentication accuracy and reduction in calculation amount can be achieved.
[0117] <Second Embodiment> The biometric authentication system of the first embodiment evaluates the authentication feature amount acquired at the time of authentication on the spot, and automatically updates the registered feature amount when it is better to update. However, since the update of the feature amount may sometimes cause a deterioration in accuracy, there may be cases where an administrator wants to be involved in the update of the feature amount.
[0118] In addition, when the biometric authentication system does not include the authentication feature amount obtained at the time of authentication in the new registration feature amount, instead of deleting the authentication feature amount, the authentication feature amount is accumulated, and then registration processing is performed as a batch process, so that there is a possibility of obtaining a registration feature amount with higher expected authentication accuracy.
[0119] Under such a background, the biometric authentication system according to the second embodiment accumulates the authentication feature amounts obtained at the time of authentication, and when there is an instruction from the administrator, selects the optimal feature amount from the accumulated authentication feature amounts and the registration feature amounts, and updates it as a new registration feature amount.
[0120] Hereinafter, the differences from the first embodiment will be mainly described. In the second embodiment, instead of the processing in FIG. 4, the processing in FIGS. 5 and 6 is executed.
[0121] FIG. 5 is a sequence diagram showing an example of biometric authentication processing and feature amount storage processing. Since steps S3010 to S3250 are the same procedures as in FIG. 3, the description thereof is omitted. In FIG. 5, instead of steps S3270 to S3290, the processing of step S4260 is executed. That is, in the second embodiment, at the time of authentication, the calculation of the similarity and mutual attribute information and the update processing of the registration feature amount are not executed. In step S4260, the feature amount registration unit 1150 associates the user ID, authentication feature amount, and self-attribute information obtained in step S3200, stores them in the authentication feature amount storage unit 1190, and ends the processing.
[0122] FIG. 6 is a flowchart showing an example of feature amount update processing. The feature amount registration unit 1150 displays the administrator login screen of the biometric authentication system on the output device 7050 of the computer constituting the server 1100, logs in as an administrator according to the information input to the input device 7040 of the computer, and displays the administrator menu screen (S5110). The details of the administrator menu screen will be described later with reference to FIG. 7.
[0123] Generate a feature set including the authentication feature stored in the authentication feature storage unit 1190 and the registered feature stored in the registered feature storage unit 1192, and for each arbitrary feature pair that can be generated from the feature set, the feature matching unit 1110 calculates the similarity, and the mutual attribute information calculation unit 1130 executes the process of calculating the mutual attribute information for each user ID (S5120).
[0124] The fitness calculation unit 1140 acquires a model corresponding to the parameter stored in the parameter storage unit 1193 (and corresponding to the type of feature received in step S3200), generates a feature subset from the feature set, and for each feature subset, uses the similarity of each pair of features included in the feature subset, the self-attribute information of each feature included in the feature subset, and the mutual attribute information of each pair of features included in the feature subset as explanatory variables, and inputs them into the acquired model to calculate the fitness for each user ID (S5130).
[0125] The feature registration unit 1150 displays the fitness calculated in step S5130 on the management menu screen (S5150). The feature registration unit 1150 receives an update instruction for the registered feature via the input device 7040 of the computer constituting the server 1100 (S5160). The update instruction includes the user ID of the update target of the registered feature.
[0126] For the user ID indicated by the update instruction, the feature registration unit 1150 selects a feature subset according to the magnitude of the fitness calculated in step S5130 in the same manner as in step S3290, and registers all the features included in the selected feature subset as new registered features in the registered feature storage unit 1192, thereby updating the registered features stored in the registered feature storage unit 1192 (S5170). In addition, the feature registration unit 1150 registers the self-attribute information corresponding to each of the new registered features in the registered feature storage unit 1192.
[0127] FIG. 7 is a diagram showing an example of the screen configuration of the administrator menu screen 6000. The administrator menu screen 6000 is a screen for an administrator of the biometric authentication system to check the operation status of the biometric authentication system and instruct the update of registered feature amounts as necessary.
[0128] The administrator menu screen 6000 includes, for example, a user ID display area 6010, an accumulation number display area 6020, a registration number display area 6030, a current estimated accuracy display area 6040, an updated estimated accuracy display area 6050, and an update button display area 6060.
[0129] In the user ID display area 6010, the user ID of the user whose registered feature amounts are stored in the registered feature amount storage unit 1192 is displayed. In the accumulation number display area 6020, the accumulation number of the authentication feature amounts stored in the authentication feature amount storage unit 1190 is displayed for each user ID. In the registration number display area 6030, the number of the registered feature amounts stored in the registered feature amount storage unit 1192 is displayed for each user ID.
[0130] In the current estimated accuracy display area 6040, the fitness stored in the fitness storage unit 1191, that is, the fitness corresponding to the registered feature amounts currently stored in the registered feature amount storage unit 1192, is displayed for each user ID. In the updated estimated accuracy display area 6050, the maximum or minimum (i.e., the best) fitness among the fitnesses calculated in step S5130 is displayed for each user ID.
[0131] In the current estimated accuracy display area 6040 and the updated estimated accuracy display area 6050, the displayed estimated accuracy (fitness) indicates the probability of successful authentication. That is, the current estimated accuracy display area 6040 indicates the estimated value of the current authentication accuracy, and the updated estimated accuracy display area 6050 indicates the estimated value of the authentication accuracy after the update of the registered feature amounts is performed. By the display of the current estimated accuracy display area 6040 and the updated estimated accuracy display area 6050, an administrator can grasp in advance how much effect (how much the estimated accuracy is improved) there is when the registered feature amounts are updated, and can support the determination of the necessity of updating the registered feature amounts.
[0132] In the update button display area 6060, an update button for each user ID is displayed. When an update button is selected, the processing after step S5160 is executed for the user corresponding to the selected update button.
[0133] As described above, the biometric authentication system according to the second embodiment can find an optimal feature amount subset from the set of feature amounts including the authentication feature amounts stored in the authentication feature amount storage unit 1190 and the registered feature amounts stored in the registered feature amount storage unit 1192 based on an instruction from the administrator, and update the registered feature amounts registered in the registered feature amount storage unit 1192.
[0134] Note that the present invention is not limited to the above-described embodiments, and includes various modifications. For example, the above-described embodiments have been described in detail for easy understanding of the present invention, and are not necessarily limited to those having all the configurations described. Also, it is possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add the configuration of another embodiment to the configuration of one embodiment. Further, it is possible to add, delete, or replace a part of the configuration of each embodiment with another configuration.
[0135] Also, each of the above configurations, functions, processing units, processing means, etc. may be realized in hardware by designing part or all of them, for example, by an integrated circuit. Further, each of the above configurations, functions, etc. may be realized in software by a processor interpreting and executing a program for realizing each function. Information such as a program, table, file, etc. for realizing each function can be placed in a memory, a recording device such as a hard disk, an SSD (Solid State Drive), or a recording medium such as an IC card, an SD card, or a DVD.
[0136] Also, control lines and information lines show those considered necessary for explanation, and not necessarily all control lines and information lines are shown on the product. In practice, it may be considered that almost all configurations are interconnected.
Explanation of Reference Numerals
[0137] 1000 client terminals, 1010 user ID input section, 1020 biometric information acquisition section, 1030 self-attribute information acquisition section, 1040 feature extraction section, 1050 additional authentication data acquisition section, 1100 server, 1110 feature matching section, 1120 additional authentication section, 1130 mutual attribute information calculation section, 1140 fitness calculation section, 1150 feature amount registration section, 1160 self-attribute information acquisition section, 1170 learning processing section, 1190 authentication feature amount storage section, 1191 fitness storage section, 1192 registered feature amount storage section, 1193 parameter storage section, 1194 learning data storage section, 7010 CPU, 7020 main memory device, 7030 auxiliary storage device, 7040 input device, 7050 output device, 7060 communication device
Claims
1. An information processing system comprising a client terminal and a server, wherein the client terminal holds authentication biometric information and an authentication feature amount extracted from the authentication biometric information, acquires self-attribute information corresponding to the authentication biometric information by receiving an input to an input device and / or by calculating from the authentication biometric information or the authentication feature amount, transmits the authentication feature amount and the self-attribute information corresponding to the authentication biometric information to the server, wherein the server holds a registered feature amount extracted from registered biometric information and self-attribute information corresponding to the registered biometric information, receives the authentication feature amount and the self-attribute information corresponding to the authentication biometric information from the server, creates a plurality of feature subsets from a set of features including the registered feature amount and the authentication feature amount, calculates the similarity for each combination of features included in the set of features, for each of the plurality of feature subsets, calculates a fitness indicating authentication accuracy based on the similarity of the combination of features included in the feature subset and the self-attribute information corresponding to the features included in the feature subset, updates the registered feature amount based on the calculated fitness, wherein the self-attribute information is attribute information extracted from single biometric information or a single feature amount and affecting the authentication accuracy, the information processing system.
2. The information processing system according to claim 1, wherein the self-attribute information includes at least one of the date and time when the biometric information was acquired, the temperature when the biometric information was acquired, the humidity when the biometric information was acquired, and the illuminance when the biometric information was acquired, the information processing system.
3. The information processing system according to claim 1, wherein the server calculates mutual attribute information corresponding to each combination including the features included in the set of features, for each of the plurality of feature subsets, calculates the fitness based on the similarity of the combination of features included in the feature subset, the self-attribute information corresponding to the features included in the feature subset, and the mutual attribute information of the combination including the features included in the feature subset, wherein the mutual attribute information is attribute information indicating a comparison result of a plurality of feature amounts or a comparison result of biometric information corresponding to each of the plurality of feature amounts, the information processing system.
4. The information processing system according to claim 3, The information processing system, wherein the mutual attribute information includes at least one of a difference in position and a difference in angle of biometric information. **Claim 5** The information processing system according to claim 3, wherein the server holds a prior distribution of unknown feature amounts, infers the unknown feature amounts from the prior distribution, and calculates the mutual attribute information corresponding to each combination of the feature amounts included in the feature amount set and the unknown feature amounts. **Claim 6** The information processing system according to claim 1 or 3, wherein the fitness includes at least one of a false rejection rate and a false acceptance rate. **Claim 7** The biometric authentication system according to claim 6, wherein the fitness includes the false rejection rate and the false acceptance rate, and the server selects a subset of feature amounts based on the false rejection rate from a subset of feature amounts that satisfy a predetermined constraint condition of the false acceptance rate, and updates the registered feature amounts using the selected subset of feature amounts. **Claim 8** The information processing system according to claim 6, wherein the fitness includes the false acceptance rate, and the server determines an authentication result based on a comparison result of comparing the registered feature amounts and the authentication feature amounts and an individual threshold value for each user, and determines the individual threshold value based on the false acceptance rate corresponding to the registered feature amounts. **Claim 9** The information processing system according to claim 1 or 3, wherein the server holds a learned model including the attribute information as an explanatory variable and the fitness as an objective variable, and in calculating the fitness, for each of the plurality of subsets of feature amounts, substitutes the attribute information corresponding to the feature amounts included in the subset of feature amounts into the learned model, and the learned model is generated based on learning feature amounts and the attribute information corresponding to the learning feature amounts. **Claim 10** The information processing system according to claim 1 or 3, wherein the server holds additional authentication registration data, executes at least one of an authentication process and an additional authentication process between the client terminal and the server, and updates the registered feature amounts when authentication is successful in at least one of the authentication process and the additional authentication process, and in the authentication process, the server compares the registered feature amounts and the authentication feature amounts to determine an authentication result. In the additional authentication process, the client terminal acquires additional authentication data, transmits the additional authentication data to the server, and the server compares the additional authentication registration data with the additional authentication data to determine an authentication result, an information processing system.
11. The information processing system according to claim 1 or 3, wherein the client terminal holds a plurality of authentication biometric information and a plurality of the authentication feature amounts extracted from the plurality of authentication biometric information, acquires self-attribute information corresponding to each of the plurality of authentication biometric information by receiving an input to the input device and / or by calculating from the plurality of authentication biometric information or the plurality of authentication feature amounts, transmits the plurality of authentication feature amounts and the self-attribute information corresponding to each of the plurality of authentication biometric information to the server, the server receives and accumulates the plurality of authentication feature amounts and the self-attribute information corresponding to each of the plurality of authentication biometric information from the server, the feature amount set includes the registered feature amount and the plurality of accumulated authentication feature amounts, and the server updates the registered feature amount based on the calculated fitness when receiving an update instruction for the registered feature amount, an information processing system.
12. An information processing method by an information processing system having a client terminal and a server, wherein the client terminal holds authentication biometric information and an authentication feature amount extracted from the authentication biometric information, the server holds a registered feature amount extracted from registered biometric information and self-attribute information corresponding to the registered biometric information, the information processing method includes the client terminal acquiring self-attribute information corresponding to the authentication biometric information by receiving an input to the input device and / or by calculating from the authentication biometric information or the authentication feature amount, the client terminal transmitting the authentication feature amount and the self-attribute information corresponding to the authentication biometric information to the server, the server receiving the authentication feature amount and the self-attribute information corresponding to the authentication biometric information from the server, the server creating a plurality of feature amount subsets from a feature amount set including the registered feature amount and the authentication feature amount, and the server calculating a similarity for each combination of feature amounts included in the feature amount set. The server calculates a fitness indicating authentication accuracy for each of the plurality of feature subsets based on the similarity of the combination of features included in the feature subset and the self-attribute information corresponding to the features included in the feature subset. The server updates the registered features based on the calculated fitness. The self-attribute information is information extracted from single biometric information or a single feature, and is attribute information that affects the authentication accuracy. An information processing method.
13. The information processing method according to claim 12, The server calculates mutual attribute information corresponding to each combination including the features included in the feature set. The server calculates the fitness based on the similarity of the combination of features included in each of the plurality of feature subsets, the self-attribute information corresponding to the features included in the feature subset, and the mutual attribute information of the combination including the features included in the feature subset. The mutual attribute information is attribute information indicating a comparison result of a plurality of features or a comparison result of biometric information corresponding to each of the plurality of features. An information processing method.
14. An information processing apparatus, Comprising a processor and a memory, The memory holds authentication features extracted from authentication biometric information, self-attribute information corresponding to the authentication biometric information, registered features extracted from registered biometric information, and self-attribute information corresponding to the registered biometric information. The processor, Creates a plurality of feature subsets from a feature set including the registered features and the authentication features. Calculates the similarity for each combination of features included in the feature set. For each of the plurality of feature subsets, calculates a fitness indicating authentication accuracy based on the similarity of the combination of features included in the feature subset and the self-attribute information corresponding to the features included in the feature subset. Updates the registered features based on the calculated fitness. The self-attribute information is information extracted from single biometric information or a single feature, and is attribute information that affects the authentication accuracy. An information processing apparatus.
15. The information processing apparatus according to claim 14, The processor, Calculates mutual attribute information corresponding to each combination including the features included in the feature set. For each of the plurality of feature subsets, calculate the fitness based on the similarity of the combination of features included in the feature subset, the self-attribute information corresponding to the features included in the feature subset, and the mutual-attribute information of the combination including the features included in the feature subset. The information processing apparatus, wherein the mutual-attribute information is attribute information indicating a comparison result of a plurality of features or a comparison result of biometric information corresponding to each of the plurality of features.
Citation Information
Patent Citations
Personal authentication system
JP2006072540A