Authentication terminal, authentication record management device, system, method, and program
The authentication terminal and management system track authentication history using data size information of biometric data, addressing the challenge of legal restrictions on personal information retention by ensuring accurate authentication history tracking without using personal data.
Patent Information
- Application Number
- JP2024002918
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-12
- Publication Date
- 2025-07-25
AI Technical Summary
Service providers face challenges in tracking the authentication history of users in one-to-one biometric authentication due to legal restrictions on retaining personal information, which hinders accurate tracking of authentication records.
An authentication terminal and management system that associates authentication results with data size information of master biometric information in a history database, allowing tracking without using personal information.
Ensures accurate tracking of authentication history by using anonymized data size information, reducing the need for personal information and shortening service provision time.
Smart Images

Figure 2025109218000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an authentication terminal, as well as an authentication history management device, a system, a method, and a program.
Background Art
[0002] Patent Document 1 discloses a technique related to face authentication using a face image stored in an IC (Integrated Circuit) chip. The license application automatic acceptance device according to Patent Document 1 reads a face image stored in the IC chip of a license. Then, the user captures a face image using the camera of the license application automatic acceptance device. Thereafter, the license application automatic acceptance device collates the read face image with the face image captured by the camera and outputs the collation result.
[0003] As described above, an operator (service provider) providing a certain service may provide the service when personal identification can be made by so-called "one-to-one biometric authentication" as in Patent Document 1 above.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] Here, in order for the above-described service provider to track the past authentication history of a specific user or a group of users with common attributes, the service provider needs to record the user's identification information itself or personal information in the authentication history. However, due to requirements such as personal information protection, it may be difficult for the service provider to retain the user's identification information itself or personal information for the purpose of the history. Therefore, there has been a problem that the tracking of the authentication history in one-to-one biometric authentication cannot be sufficiently performed.
[0006] An object of the present disclosure is to provide an authentication terminal, an authentication history management device, a system, a method, and a program for ensuring the tracking accuracy of authentication history in one-to-one biometric authentication without using personal information, in view of the above-described problems.
Means for Solving the Problems
[0007] The authentication terminal according to the present disclosure includes an acquisition unit that acquires the master biometric information from a storage medium in which the master biometric information of the user is stored, and a registration unit that registers authentication history information in which an authentication result of biometric authentication based on the query biometric information acquired from the user and the master biometric information and data size information of the master biometric information are associated with each other in a history database. is provided.
[0008] The authentication history management device according to the present disclosure includes an acquisition unit that acquires an authentication result of biometric authentication based on the master biometric information acquired by an authentication terminal from a storage medium in which the master biometric information of the user is stored and the query biometric information acquired from the user by the authentication terminal, and data size information of the master biometric information, and a registration unit that registers authentication history information in which the authentication result and the data size information are associated with each other in a history database. is provided.
[0009] The authentication history management system according to the present disclosure includes an authentication terminal and a history database, wherein the authentication terminal acquires the master biometric information from a storage medium in which the master biometric information of the user is stored, and registers authentication history information in which an authentication result of biometric authentication based on the query biometric information acquired from the user and the master biometric information and data size information of the master biometric information are associated with each other in the history database.
[0010] The authentication history management method according to the present disclosure A computer obtains the master biometric information of the user from a storage medium in which the master biometric information of the user is stored, and registers authentication history information associating an authentication result of biometric authentication based on the query biometric information obtained from the user and the master biometric information, and data size information of the master biometric information in a history database.
[0011] The authentication history management method according to the present disclosure is such that a computer obtains an authentication result of biometric authentication based on the master biometric information obtained by an authentication terminal from a storage medium in which the master biometric information of the user is stored and the query biometric information obtained from the user by the authentication terminal, and data size information of the master biometric information, and registers authentication history information associating the authentication result and the data size information in a history database.
[0012] The authentication history management program according to the present disclosure causes a computer to execute a process of obtaining the master biometric information from a storage medium in which the master biometric information of the user is stored, and a process of registering, in a history database, authentication history information associating an authentication result of biometric authentication based on the query biometric information obtained from the user and the master biometric information, and data size information of the master biometric information.
[0013] The authentication history management program according to the present disclosure causes a computer to execute a process of obtaining an authentication result of biometric authentication based on the master biometric information obtained by an authentication terminal from a storage medium in which the master biometric information of the user is stored and the query biometric information obtained from the user by the authentication terminal, and data size information of the master biometric information, and a process of registering, in a history database, authentication history information associating the authentication result and the data size information.
Advantages of the Invention
[0014] According to the present disclosure, it is possible to provide an authentication terminal, an authentication history management device, a system, a method, and a program for ensuring the tracking accuracy of an authentication history in one-to-one biometric authentication without using personal information.
Brief Description of the Drawings
[0015]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Mode for Carrying Out the Invention
[0016] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In each drawing, the same or corresponding elements are denoted by the same reference numerals, and redundant descriptions are omitted as necessary for clarity of explanation.
[0017] <Embodiment 1> Hereinafter, with reference to FIG. 1, the configuration of an authentication history management system 1000 including an authentication terminal 1 will be described. The authentication history management system 1000 includes an authentication terminal 1 and an authentication history DB (DataBase) 4. Further, the authentication history management system 1000 is, for example, an information system managed or operated by a predetermined service provider. The service provider provides a predetermined service to the user U when the identity of the user U is confirmed by biometric authentication on the authentication terminal 1 (the biometric authentication is successful). Further, the authentication history management system 1000 records the history information of biometric authentication in the authentication history DB 4.
[0018] Here, "biometric authentication" is an information processing that verifies the authenticity of an individual by comparing master biometric information with query biometric information obtained from or input by an individual at the time of authentication, and determining that the degree of match is equal to or greater than a threshold value. Also, "biometric information" is data (feature quantities) calculated from physical characteristics unique to an individual, such as fingerprints, voiceprints, veins, retinas, and iris patterns of the pupils. Further, biometric information may be data indicating a set of feature quantities, such as a plurality of feature points extracted from an image capturing at least a part of the user's body and the distances between the feature points. Additionally, biometric information may be the image data itself. "Master biometric information" is biometric information previously obtained from a user and stored in a predetermined recording medium, and is the biometric information to be compared with query biometric information at the time of the user's biometric authentication. Also, "query biometric information" is biometric information obtained from the user himself / herself at the timing of biometric authentication, and is data to be compared with master biometric information. Note that "authentication" in this specification includes a determination process for verifying the authenticity of an individual. Therefore, "authentication" includes, in addition to biometric authentication processing (such as acquisition processing and comparison processing of master and query biometric information), a process for verifying (determining) the success or failure of authentication included in past authentication results, which will be described later.
[0019] It is assumed that user U carries a storage medium 3 incorporated in his / her personal certificate (not shown). It is assumed that master biometric information 30 capable of uniquely identifying user U is stored in storage medium 3. Also, storage medium 3 enables data transmission and reception with the outside via a short-range wireless communication interface within the personal certificate. Note that storage medium 3 may be able to output at least master biometric information 30 to the outside by other communication methods. Further, storage medium 3 or the personal certificate incorporating storage medium 3 may be incorporated in a mobile terminal or the like possessed by user U.
[0020] The authentication terminal 1 is an information processing device installed at a location where the service provider conducts identity verification for providing a predetermined service. Alternatively, the authentication terminal 1 may be a portable wireless-enabled information terminal carried by the user. The authentication terminal 1 includes an acquisition unit 11 and a registration unit 12. The acquisition unit 11 and the registration unit 12 may be used as means for acquiring information or data and means for registering information or data, respectively.
[0021] The acquisition unit 11 acquires the master biometric information 30 from the storage medium 3 in which the master biometric information 30 of the user U is stored. For example, the acquisition unit 11 may acquire the master biometric information 30 by reading the master biometric information 30 from the storage medium 3 through short-range wireless communication. Incidentally, the acquisition unit 11 may acquire the master biometric information 30 output by another communication method corresponding to the storage medium 3.
[0022] Incidentally, the authentication terminal 1 identifies or calculates the data size information of the acquired master biometric information 30. For example, the authentication terminal 1 may identify the area size allocated when the acquired master biometric information 30 is temporarily stored in the internal memory as the data size information of the master biometric information 30. Alternatively, when the data size information of the master biometric information 30 itself is stored in the storage medium 3, the acquisition unit 11 may acquire the data size information together with the master biometric information 30 from the storage medium 3.
[0023] In addition, the authentication terminal 1 acquires query biometric information from the user U. For example, the acquisition unit 11 may acquire a face image of the user U captured by a camera (not shown) of the authentication terminal 1 as the query biometric information.
[0024] Subsequently, the authentication terminal 1 controls the biometric authentication process of user U. Here, the biometric authentication process of user U may be executed either inside the authentication terminal 1 or by an external authentication device. When the authentication terminal 1 executes the biometric authentication process, the authentication terminal 1 compares the master biometric information with the query biometric information and calculates the degree of match between the master biometric information and the query biometric information. Then, when the degree of match exceeds the threshold value, the authentication terminal 1 includes in the authentication result that the authentication is successful. On the other hand, when the degree of match is below the threshold value, the authentication terminal 1 includes in the authentication result that the authentication has failed.
[0025] Alternatively, when an external authentication device executes the biometric authentication process, the authentication terminal 1 sends an authentication request including the master biometric information and the query biometric information to the authentication device. The authentication device compares the master biometric information and the query biometric information included in the received authentication request and obtains the authentication result in the same manner as above. Then, the authentication terminal 1 acquires the authentication result from the authentication device. In this case, the authentication device may delete the acquired master biometric information and query biometric information. This is for the protection of personal information.
[0026] The registration unit 12 registers authentication history information 40 in which the authentication result 41 of the biometric authentication of user U is associated with the data size information 42 of the master biometric information 30 in the authentication history DB4. Here, the authentication history DB4 may be included in a predetermined information system (for example, a DB server) connected to the authentication terminal 1. In this case, the registration unit 12 may register the authentication history information 40 in the authentication history DB4 by sending a registration request including the authentication history information 40 to the information system. Note that the predetermined information system may also serve as the above-described authentication device.
[0027] Alternatively, the registration unit 12 may perform registration by sending the authentication result 41, the data size information 42, and a registration instruction to the DB server. In this case, it is assumed that the registration instruction includes an instruction to register the authentication result and the data size information in association with each other. In response to this, the DB server generates authentication history information 40 by associating the authentication result 41 and the data size information 42 according to the registration instruction, and registers the authentication history information 40 in the authentication history DB4.
[0028] Alternatively, the authentication history DB4 may be a database in a storage device connected to the authentication terminal 1. Alternatively, the authentication history DB4 may be built into the authentication terminal 1. It is assumed that the authentication history DB4 is at least accessible from the authentication terminal 1. Furthermore, the authentication history DB4 may be accessible from other authentication terminals or other information systems other than the authentication terminal 1. In these cases, the registration unit 12 may generate the authentication history information 40 by associating the authentication result 41 and the data size information 42. Then, the registration unit 12 may register the authentication history information 40 in the authentication history DB4 by issuing a registration command or the like for the authentication history information 40 to the authentication history DB4. In addition, the registration unit 12 can register the authentication history information 40 in which the authentication result 41 and the data size information 42 are associated with each other in the authentication history DB4 by various methods.
[0029] Subsequently, the flow of the authentication history management process will be described with reference to FIG. 2. First, the acquisition unit 11 acquires the master biometric information 30 from the storage medium 3 in which the master biometric information 30 of the user U is stored (S11). Next, the registration unit 12 registers the authentication history information 40 in which the authentication result 41 of the biometric authentication based on the query biometric information acquired from the user U and the master biometric information 30 and the data size information 42 of the master biometric information 30 are associated with each other in the authentication history DB4 (S12). Note that the authentication terminal 1 may delete the acquired master biometric information 30 and query biometric information for the purpose of personal information protection.
[0030] In recent years, due to demands such as personal information protection, there has been an increasing need for service providers to adopt a method of not retaining master biometric information or personal information. In particular, in some countries and regions, businesses may not be permitted to retain personal information (data). Therefore, in the present disclosure, the authentication history information 40 registered in the authentication history DB4 does not include personal information, and the data size information 42 is used. Here, the data size information 42 of the master biometric information 30 does not have the same personal identification ability as the master biometric information 30, but it can be said that it has some personal identification ability in a user group of a certain scale. On the other hand, since the data size information 42 corresponds to anonymized information, it does not fall under personal information.
[0031] Therefore, later, by referring to the authentication history DB4, the authentication history information 40 including specific data size information 42 can be retrieved. Furthermore, after a plurality of pieces of authentication history information 40 are stored in the authentication history DB4, the authentication history information 40 including specific data size information 42 can also be retrieved. Then, although an individual cannot be identified, by checking the authentication result 41 included in the authentication history information 40 retrieved from the authentication history DB4, the authentication history of the user corresponding to the master biometric information 30 of the specific data size information 42 can be traced. In other words, by checking the authentication result 41 associated with the data size information 42, the authentication history of any user can be traced.
[0032] Furthermore, when the user U performs identity verification by one-to-one biometric authentication using the authentication terminal 1 or other authentication terminals, each time, instead of the personal information of the user U, the data size information 42 is associated with the authentication result 41 and registered in the authentication history DB4. Therefore, by retrieving the authentication result 41 associated with the specific data size information 42 from the authentication history DB4, the authentication history of a specific (any) user can be substantially traced. Alternatively, the authentication terminal 1 or other authentication terminals may search the authentication history DB4 using the data size information 42 of the user U as a search key before performing the biometric authentication of the user U. And when the authentication result 41 included in the search result indicates authentication success, the authentication terminal 1 or the like may regard it as having been able to verify the identity of the user U without performing biometric authentication. Thus, in the present disclosure, since the data size information of the master biometric information is included in the authentication history information without using personal information, it is possible to reduce the load of the biometric authentication process in the authentication terminal 1 or the like and shorten the service provision time.
[0033] From the above, according to the present disclosure, it is possible to ensure the tracking accuracy of the authentication history in one-to-one biometric authentication without using personal information.
[0034] The authentication terminal 1 is provided with a processor, a memory, and a storage device as a configuration not shown in the figure. Further, the storage device stores a computer program in which, for example, the authentication history management process of FIG. 2 is implemented. Then, the processor causes the memory to read a computer program or the like from the storage device and executes the computer program. Thereby, the processor realizes the functions of the acquisition unit 11 and the registration unit 12.
[0035] Alternatively, each component of the authentication terminal 1 may be realized by dedicated hardware. Also, some or all of the components of each device may be realized by general-purpose or dedicated circuitry, processors, etc. or combinations thereof. These may be configured by a single chip or by a plurality of chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-described circuitry or the like and a program. Also, as the processor, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (Field-Programmable Gate Array), a quantum processor (quantum computer control chip), etc. can be used.
[0036] Also, when some or all of the components of the authentication terminal 1 are realized by a plurality of information processing devices, circuits, etc., the plurality of information processing devices, circuits, etc. may be centrally arranged or distributed. For example, the information processing devices, circuits, etc. may be realized in a form in which each is connected via a communication network, such as a client-server system or a cloud computing system. Also, the function of the authentication terminal 1 may be provided in the form of SaaS (Software as a Service).
[0037] <Embodiment 2> Next, with reference to FIG. 3, the configuration of the authentication history management system 2000 including the authentication history management device 2 will be described. The authentication history management system 2000 includes an authentication terminal 1 and an authentication history management device 2. Also, the authentication history management system 2000 is an information system managed or operated by a predetermined service provider, similar to the above-described authentication history management system 1000. Note that the authentication terminal 1 in FIG. 3 may have the same functions as the authentication terminal 1 in FIG. 1 above. Alternatively, the authentication terminal 1 in FIG. 3 is at least configured to acquire master biometric information 30 from the storage medium 3 and acquire query biometric information from the user U. Further, the authentication terminal 1 in FIG. 3 may transmit the authentication result 41, the data size information 42, and the registration instruction to the authentication history management device 2. Alternatively, the authentication terminal 1 in FIG. 3 may transmit an authentication request including the master biometric information 30 and the query biometric information to the authentication history management device 2.
[0038] The authentication history management device 2 is an information processing device for a service provider to manage the authentication history DB 4. The authentication history management device 2 includes an acquisition unit 21, a registration unit 22, and an authentication history DB 4. The acquisition unit 21 and the registration unit 22 may be used as means for acquiring information or data and means for registering information or data, respectively. Note that the authentication history DB 4 may be external to the authentication history management device 2. In that case, the authentication history DB 4 may be a database in a storage device connected to the authentication history management device 2 or in a predetermined information system (for example, a DB server). The authentication history DB 4 is assumed to be at least accessible from the authentication history management device 2. Further, the authentication history DB 4 may also be accessible from the authentication terminal 1 and other authentication terminals.
[0039] The acquisition unit 21 acquires the authentication result 41 of the biometric authentication of the user U and the data size information 42 of the master biometric information 30 stored in the storage medium 3. Here, the authentication result 41 is the authentication result of the biometric authentication based on the master biometric information 30 of the user U and the query biometric information acquired from the user U by the authentication terminal 1. And the master biometric information 30 is information acquired from the storage medium 3 by the authentication terminal 1.
[0040] Here, the biometric authentication process for the user U may be executed either inside the authentication terminal 1, inside the authentication history management device 2, or an external authentication device. When the authentication terminal 1 executes the biometric authentication process, as described above, the authentication terminal 1 executes biometric authentication and obtains an authentication result. Alternatively, the authentication terminal 1 may cause an external authentication device to execute biometric authentication and obtain the authentication result. In these cases, the acquisition unit 21 of the authentication history management device 2 obtains the authentication result 41 from the authentication terminal 1.
[0041] Alternatively, when the authentication history management device 2 executes the biometric authentication process, the authentication history management device 2 receives an authentication request including master biometric information and query biometric information from the authentication terminal 1. Then, the authentication history management device 2 collates the master biometric information and the query biometric information included in the received authentication request, and obtains an authentication result in the same manner as above. Thereby, the acquisition unit 21 obtains the authentication result.
[0042] Alternatively, when an external authentication device executes the biometric authentication process, the authentication history management device 2 transmits the authentication request received from the authentication terminal 1 to the authentication device. The authentication device executes the biometric authentication process in the same manner as above and returns the authentication result to the authentication history management device 2. Thereby, the acquisition unit 21 obtains the authentication result. In this case, the authentication device may delete the acquired master biometric information and query biometric information. This is for personal information protection.
[0043] In addition, the acquisition unit 21 may obtain the data size information 42 itself from the authentication terminal 1. Alternatively, the acquisition unit 21 may obtain the master biometric information 30 from the authentication terminal 1, and specify or calculate the data size information of the acquired master biometric information 30 as described above.
[0044] The registration unit 22 registers the authentication history information 40 in which the authentication result 41 and the data size information 42 are associated in the authentication history DB 4. For example, when the acquisition unit 21 receives the authentication result 41, the data size information 42, and the registration instruction from the authentication terminal 1, the registration unit 22 generates the authentication history information 40 by associating the authentication result 41 and the data size information 42 according to the registration instruction. Alternatively, the registration unit 22 may generate the authentication history information 40 by associating the acquired authentication result 41 and the specifically determined or calculated data size information 42 in response to the authentication request received from the authentication terminal 1. In these cases, the registration unit 22 registers the generated authentication history information 40 in the authentication history DB 4. When the authentication history DB 4 is included in the information system connected to the authentication history management device 2, the registration unit 22 may register the authentication history information 40 in the authentication history DB 4 by transmitting a registration request including the authentication history information 40 to the information system.
[0045] Subsequently, the flow of the authentication history management process will be described with reference to FIG. 4. First, the acquisition unit 21 acquires the authentication result 41 of the user U and the data size information 42 of the master biometric information 30 (S21). Next, the registration unit 22 registers the authentication history information 40 in which the authentication result 41 and the data size information 4 are associated in the authentication history DB 4 (S22).
[0046] From the above, also in the second embodiment, similar to the first embodiment described above, it is possible to ensure the tracking accuracy of the authentication history in one-to-one biometric authentication without using personal information. In addition, the second embodiment can achieve the same effects as the first embodiment by performing the search process before and after biometric authentication in the same manner as the first embodiment.
[0047] The authentication history management device 2 includes a processor, a memory, and a storage device as a configuration not shown in the figure. In addition, for example, a computer program in which the authentication history management process of FIG. 4 is implemented is stored in the storage device. Then, the processor causes the memory to read the computer program or the like from the storage device and executes the computer program. Thereby, the processor realizes the functions of the acquisition unit 21 and the registration unit 22.
[0048] Alternatively, each component of the authentication history management device 2 may be realized by dedicated hardware. Also, some or all of the components of each device may be realized by general-purpose or dedicated circuitry, a processor, etc., or a combination thereof. These may be constituted by a single chip or by a plurality of chips connected via a bus. Some or all of the components of each device may be realized by a combination of the circuitry etc. described above and a program. Also, as the processor, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (Field-Programmable Gate Array), a quantum processor (quantum computer control chip), etc. can be used.
[0049] Also, when some or all of the components of the authentication history management device 2 are realized by a plurality of information processing devices, circuitry, etc., the plurality of information processing devices, circuitry, etc. may be centrally arranged or may be distributed. For example, the information processing devices, circuitry, etc. may be realized in a form in which each is connected via a communication network, such as a client-server system, a cloud computing system, etc. Also, the function of the authentication history management device 2 may be provided in the form of SaaS (Software as a Service).
[0050] <Embodiment 3> Next, the configuration of the authentication history management system 3000 will be described with reference to FIG. 5. Note that the authentication history management system 3000 will be described for the case of face authentication as biometric authentication and face images as biometric information, but other biometric authentications and biometric information are also feasible. The authentication history management system 3000 includes authentication terminals 100-1 and 100-2, and an authentication history management device 200 having an authentication history DB 400. Note that the authentication history DB 400 may be external to the authentication history management device 200. Also, the authentication terminals 100-1 and 100-2 are assumed to have equivalent functions. In the following description, the authentication terminals 100-1 and 100-2 may be collectively referred to simply as the "authentication terminal 100". Also, in the following description, the users U1 and U2 may be collectively referred to simply as the "user U". Note that in the present disclosure, at least one authentication terminal 100 is sufficient. That is, the authentication history management system 3000 may include three or more authentication terminals 100. The authentication terminal 100 is a specific example of the authentication terminal 1 in Embodiment 1 or 2. Also, the authentication history management device 200 is a specific example of the authentication history management device 2 in Embodiment 2. The authentication history DB 400 is a specific example of the authentication history DB 4 in Embodiment 1 or 2.
[0051] Each of the authentication terminals 100-1 and 100-2 and the authentication history management device 200 is communicably connected via a network N. Here, the network N is a wired or wireless communication line. Further, the authentication history DB 400 may also be communicably connected to the network N.
[0052] The authentication history management system 3000 is an information system that provides a predetermined service to user U when the user U is authenticated by biometric authentication at each authentication terminal 100 installed at multiple locations within a predetermined area. The "predetermined service" includes, for example, alcohol sales, senior discounts, ladies' day discounts, foreigner discounts, discounts limited to local residents, discounts for the disabled, student discounts, minor discounts, etc., but is not limited to these. And for each of these services, service provision conditions are defined. For example, when the service is alcohol sales, the service provision condition is that the user's age is 20 years or older. Also, when the service is a senior discount (for movie tickets, supermarkets, or drugstores), the service provision condition is that the user's age is 60 years or older, 65 years or older, etc. Also, when the service is a ladies' day discount, the service provision condition is that the user's gender is female. Also, when the service is a foreigner discount, the service provision condition is that the user's nationality is foreign. Also, when the service is a discount limited to local residents, the service provision condition is that the user's address is within a predetermined area. Also, when the service is a discount for the disabled, the service provision condition is that the user's disability level meets the predetermined conditions. Also, when the service is a student discount, the service provision condition is that the user is a student of a predetermined school (has a student status). Also, when the service is a minor discount, the service provision condition is that the user's age is under 18 years old. Note that the services provided at each location may be different, common, or partially common. There may be multiple service providers who manage or operate the authentication history management system 3000. The authentication history management system 3000 may provide services including, for example, some or multiple of airports, commercial facilities, public transportation, theme parks, movie theaters, etc.
[0053] Assume that user U1 is carrying personal certificate 31 and standing in front of authentication terminal 100-1. Personal certificate 31 corresponds to the identity certificate of user U1 and includes an IC chip 310 in which electronic data of personal information is stored. At least master face image 311 and attribute information 312 are stored in IC chip 310. Master face image 311 is image data obtained by photographing an area including the face of user U1. Master face image 311 is an example of the above-described master biometric information 30. Note that IC chip 310 may store face feature information extracted from master face image 311 together with master face image 311 or instead of master face image 311. Attribute information 312 is personal information indicating the attributes of user U1. Examples of attribute information 312 include name, date of birth, gender, nationality, disability level, address, telephone number, school (student status) to which the user belongs, etc. However, attribute information 312 is not limited thereto. Personal certificate 31 may be a physical document, a plastic card, a portable information terminal, etc. incorporating IC chip 310. For example, personal certificate 31 may be an identity certificate with a face photo of user U1. In that case, image data corresponding to the face photo of user U1 is stored in IC chip 310. Also, for example, personal certificate 31 may be a passport, a my number card, a driver's license, an employee ID, a student ID, etc. However, personal certificate 31 is not limited thereto.
[0054] Assume that user U2 is carrying the personal certificate 32 and is in front of the authentication terminal 100-2. If user U2 is the same person as user U1, Fig. 5 shows the state where user U was present in front of the authentication terminal 100-1 and in front of the authentication terminal 100-2 at different time zones. In that case, the personal certificates 31 and 32 are the same. The personal certificate 32 corresponds to the identity certificate of user U2 and includes an IC chip 320 in which electronic data of personal information is stored. At least a master face image 321 and attribute information 322 are stored in the IC chip 320. The master face image 321 is image data obtained by photographing an area including the face of user U2. The master face image 321 is an example of the above-described master biometric information 30. The attribute information 322 is personal information indicating the attributes of user U2. The attribute information 322 is information equivalent to the above-described attribute information 312 for user U2. Also, the personal certificate 32 is information equivalent to the above-described personal certificate 31 for user U2.
[0055] The configuration of the authentication terminal 100 will be described with reference to Fig. 6. The authentication terminal 100 includes an acquisition unit 110, an authentication unit 120, a determination unit 130, a registration unit 140, a search unit 150, and an execution unit 160. Note that the authentication terminal 100 includes a camera and a display as will be described later. Alternatively, the authentication terminal 100 may be connected to either or both of the camera and the display. Also, the authentication terminal 100 may be able to communicate with a non-contact IC chip by short-range wireless communication.
[0056] The acquisition unit 110 is an example of the above-described acquisition unit 11. For example, the acquisition unit 110 acquires the master face image 311 and the attribute information 312 from the IC chip 310 of the personal certificate 31 carried by user U1. In this case, the acquisition unit 110 specifies or calculates numerical information indicating the data size of the master face image 311 as data size information. The numerical information indicating the data size is, for example, the byte value or bit value of the image data. Note that the data size information may be numerical information in other units. Also, the acquisition unit 110 acquires image data (query face image) obtained by photographing the vicinity of the face of user U1 by the above-described camera.
[0057] The authentication unit 120 controls face authentication processing as an example of biometric authentication. Specifically, the authentication unit 120 performs face authentication based on a master face image and a query face image. For example, the authentication unit 120 detects a face region from each face image, extracts a plurality of feature points indicating the features (eyes, nose, mouth, etc.) of the person's face from the detected face region, and calculates the distance between each feature point as a feature quantity. Then, the authentication unit 120 extracts a feature vector including the set of the calculated plurality of feature quantities as face feature information. That is, it can be said that the authentication unit 120 extracts the feature vector calculated from each face image as face feature information. Then, the authentication unit 120 collates the face feature information extracted from the master face image with the face feature information extracted from the query face image, and calculates a collation score indicating the degree of collation as a degree of coincidence. For example, the authentication unit 120 may calculate a higher collation score as the distance between the master and query feature vectors is shorter. Then, when the degree of coincidence is equal to or higher than a threshold value, the authentication unit 120 determines that the face authentication has succeeded, and when the degree of coincidence is less than the threshold value, the authentication unit 120 determines that the face authentication has failed. The authentication unit 120 includes the determination result of the face authentication in the authentication result as the result of the success or failure of the biometric authentication. In addition, the authentication unit 120 includes the execution date and time of the face authentication processing in the authentication result. Furthermore, the authentication unit 120 may include position information capable of specifying the position of the authentication terminal 100 in the authentication result. The position information includes, for example, the terminal ID of the authentication terminal 100, information indicating the installation location, or GPS (Global Positioning System) information, etc., but is not limited thereto.
[0058] The determination unit 130 determines whether the user's attribute information satisfies a predetermined service provision condition. Specifically, the determination unit 130 makes the above determination using the attribute information 312 acquired from the IC chip 310 by the acquisition unit 110. For example, assume that the attribute information is age information such as date of birth, and the service provision condition is a senior discount for users aged 60 or older. In this case, when the user's age information is 60 or older, the determination unit 130 determines that the service provision condition is satisfied, that is, the senior discount can be applied. Then, the determination unit 130 uses the presence or absence of satisfaction of the service provision condition as the attribute determination result. In this example, the determination unit 130 uses the fact that the senior discount can be applied as the attribute determination result. That is, the attribute determination result may include the service content provided when the service provision condition is satisfied.
[0059] The registration unit 140 is an example of the above-described registration unit 12. The registration unit 140 registers authentication history information associating the authentication result, the data size information, and the attribute determination result in the authentication history DB 400. For example, the registration unit 140 transmits a history registration request including the authentication result, the data size information, and the attribute determination result to the authentication history management device 200. In this case, it is assumed that the history registration request includes a registration instruction for associating the authentication result, the data size information, and the attribute determination result. Alternatively, the registration unit 140 may generate authentication history information associating the authentication result, the data size information, and the attribute determination result. In that case, the registration unit 140 may transmit a history registration request including the generated authentication history information to the authentication history management device 200. Note that when the location information of the authentication terminal 100 is included in the authentication result, the data size information and the location information are associated in the authentication history information. Therefore, it can be said that the registration unit 140 further includes location information capable of specifying the location of the authentication terminal 100 and registers it in the authentication history DB 400 as authentication history information.
[0060] The search unit 150 performs a search process on the authentication history DB 400 by including the data size information of the master biometric information acquired by the acquisition unit 110 as a search key. For example, the search unit 150 may transmit a history search request including the data size information to the authentication history management device 200. Then, the search unit 150 receives the search result in the authentication history DB 400 from the authentication history management device 200. That is, the search unit 150 acquires, as a search result, the authentication history information including the data size information included in the search key. Here, the search result includes at least one of the authentication result and the attribute determination result associated with the data size information that is the search key. That is, the search unit 150 can search for the authentication result and the attribute determination result associated with the same data size as the data size of the master face image of the user U existing in front of the authentication terminal 100. Note that, with the authentication history information of a certain user X registered in the authentication history DB 400, it is possible that another user Y whose data size of the master biometric information happens to be the same as that of user X performs biometric authentication or the like using the authentication terminal according to the present disclosure. For example, when the biometric authentication of user Y is performed at a time and place relatively close to the time and place when user X succeeded in biometric authentication, the authentication terminal may determine that user Y has recently succeeded in biometric authentication or that the attribute determination result has recently satisfied the service provision conditions. In that case, the authentication terminal may omit the biometric authentication or the attribute determination for user Y. Therefore, the authentication terminal according to the present disclosure may determine whether the user corresponding to the data size included in the search result is the same as the user to be authenticated or the user to be subjected to attribute determination this time, taking into account the authentication location and the authentication success time information included in the search result. Specifically, the authentication terminal calculates the distance between the authentication location W of the search result and the current authentication location Z by utilizing predetermined map information or the like for the authentication location included in the search result, and also calculates the difference between the authentication time (execution date and time) included in the search result and the current time, and determines the identity of the user in consideration of the distance and the time difference. For example, when it is physically difficult for any user to move from the authentication location W to the authentication location Z between the authentication time TX of the search result and the current time TY, the authentication terminal may determine that users X and Y are different persons.
[0061] Furthermore, the search unit 150 may perform a search process before the determination by the determination unit 130. The search results include at least a part of the past authentication date and time (the execution date and time of biometric authentication), authentication success or failure, authentication location, availability of service provision, provided service content, etc. for users corresponding to specific data size information.
[0062] The execution unit 160 may execute a process of providing the above-described predetermined service when the user U succeeds in biometric authentication. Furthermore, the execution unit 160 may execute a process of providing a predetermined service when the user U succeeds in biometric authentication and satisfies the service provision conditions.
[0063] Furthermore, the execution unit 160 may execute a process according to the search result of the search process by the search unit 150. Specifically, the execution unit 160 may output display information according to the search result to the screen of the authentication terminal 100.
[0064] Also, for example, assume that a search process is performed before the determination by the determination unit 130, and the search result includes the fact of authentication success. In other words, it can be said that the authentication history information included in the search result includes the fact of authentication success. Or it can also be said that when the authentication result associated with the data size information used as the search key indicates the fact of authentication success. In this case, the execution unit 160 executes a process according to the attribute determination result included in the search result. For example, when the attribute determination result indicates that the service provision conditions are satisfied, the execution unit 160 may execute a process of providing the service without performing the determination by the determination unit 130. That is, the execution unit 160 can provide the service according to the authentication result and the attribute determination result associated with the same data size as the data size of the master face image of the target user U. In other words, when the user U in front of the authentication terminal 100 has succeeded in authentication on another authentication terminal 100 in the past and satisfies the service provision conditions, the execution unit 160 may provide the service without performing the attribute determination again. This can reduce the determination processing load of the service provision conditions and the work load of the staff's attribute confirmation.
[0065] Using FIG. 7, the hardware configuration of the authentication terminal 100 will be described. The authentication terminal 100 includes a memory 101, a processor 102, a network interface 103, a display 104, a camera 105, and a short-range wireless communication interface 106.
[0066] The memory 101 is composed of a combination of a volatile memory and a non-volatile memory. The volatile memory is, for example, a volatile storage device such as a RAM (Random Access Memory), and is a storage area for temporarily holding information during the operation of the processor 102. The non-volatile memory is, for example, a non-volatile storage device such as a hard disk or a flash memory. The memory 101 stores at least a computer program in which the authentication history management process of the authentication terminal 100 according to the present disclosure is implemented. Note that the memory 101 may include a storage disposed separately from the processor 102. In this case, the processor 102 may access the memory 101 via an I / O (Input / Output) interface (not shown).
[0067] The processor 102 is a control device that controls each component of the authentication terminal 100. The processor 102 reads and executes software (computer program) from the memory 101. Thereby, the processor 102 realizes the functions of the acquisition unit 110, the authentication unit 120, the determination unit 130, the registration unit 140, the search unit 150, and the execution unit 160. That is, the processor 102 performs the authentication history management process according to the present disclosure. The processor 102 may be, for example, a microprocessor, an MPU (Multi Processing Unit), or a CPU (Central Processing Unit). Also, the processor 102 may include a plurality of processors.
[0068] The network interface 103 may be used to communicate with a network node. The network interface 103 may include, for example, a network interface card (NIC) compliant with the IEEE 802.3 series. IEEE represents the Institute of Electrical and Electronics Engineers.
[0069] The display 104 is a display device that displays information instructed by the processor 102. The display 104 is, for example, a screen such as a liquid crystal display or an organic electro-luminescence (EL) display.
[0070] The camera 105 captures an image of the face of the user U or the like in response to an operation by the user U or a staff member or an instruction from the processor 102, and outputs the captured image to the processor 102. The camera 105 is, for example, a charge-coupled device (CCD) image sensor or a complementary metal oxide semiconductor (CMOS) sensor. The camera 105 is one or more imaging devices.
[0071] The short-range wireless communication interface 106 establishes a connection and communicates with an interface of another device (such as a personal certificate equipped with an IC chip) of the same type within a predetermined range by short-range wireless communication of a predetermined method. The predetermined method may correspond to, for example, but is not limited to, standards and methods such as Bluetooth (registered trademark) and Bluetooth Low Energy (BLE).
[0072] The configuration of the authentication history management device 200 and the authentication history DB 400 will be described with reference to FIG. 8. The authentication history management device 200 includes an acquisition unit 210, a registration unit 240, a search unit 250, and an authentication history DB 400.
[0073] The acquisition unit 210 is an example of the acquisition unit 21 described above. The acquisition unit 210 acquires a history registration request including an authentication result, data size information, and an attribute determination result from the authentication terminal 100. Alternatively, the acquisition unit 210 may acquire a history registration request including authentication history information from the authentication terminal 100. Here, the authentication result may include the location information of the authentication terminal 100. That is, the acquisition unit 210 may acquire location information capable of specifying the location of the authentication terminal 100. The location information may be information indicating a terminal ID or an installation location as described above. For example, when the terminal ID of the authentication terminal 100 is managed in association with the installation location in an arbitrary database, the authentication history management device 200 can specify the installation location from the terminal ID by referring to the database. Therefore, the terminal ID can also be said to be location information capable of specifying the location of the authentication terminal 100.
[0074] The registration unit 240 is an example of the registration unit 22 described above. When a registration instruction is included in the history registration request, the registration unit 240 generates authentication history information by associating the authentication result, data size information, and attribute determination result included in the history registration request. Then, the registration unit 240 registers the generated authentication history information in the authentication history DB 400. Alternatively, when the history registration request includes authentication history information, the registration unit 240 registers the authentication history information included in the history registration request in the authentication history DB 400.
[0075] In response to a history search request received from the authentication terminal 100, the search unit 250 performs a search process on the authentication history DB 400 and returns the search result to the authentication terminal 100. Specifically, the search unit 250 executes a search process on the authentication history DB 400 including the data size information included in the history search request as a search key. When the search hits, the search unit 250 uses the authentication history information including the data size information of the search key from the authentication history DB 400 as the search result. In this case, the search result will include the authentication result and attribute determination result associated with the data size information that is the search key. On the other hand, when the search does not hit, the search unit 250 uses the fact of a search miss as the search result.
[0076] The authentication history DB400 is a database for managing the authentication history information of biometric authentication in one or more authentication terminals 100. For example, in the authentication history DB400, authentication history information 410, 420, ··· 4n0 (n is a natural number of 1 or more) is registered. For example, the authentication history information 410 is information in which an authentication result 411, data size information 412, and an attribute determination result 413 are associated. Note that the authentication history information 410 only needs to be information in which at least the authentication result 411 and the data size information 412 are associated. Also, other information may be associated with the data size information 412 in the authentication history information 410. The authentication result 411 is a specific example of the authentication result 41 in Embodiment 1 or 2. The authentication result 411 preferably includes information indicating the success or failure of face authentication, the execution date and time of face authentication processing, and the authentication location, etc. Note that the authentication location may be the position information of the above-described authentication terminal 100. The data size information 412 is a specific example of the data size information 42 in Embodiment 1 or 2. The data size information 412 is numerical information indicating the data size of the master face image. The attribute determination result 413 is the result of determining whether the user's attribute information satisfies predetermined service provision conditions. For example, the attribute determination result 413 may be information indicating whether a predetermined service content has been provided. Specifically, the attribute determination result 413 includes, but is not limited to, the availability of alcohol sales, the availability of senior discounts, the availability of ladies' day discounts, the availability of foreigner discounts, the availability of area resident-only discounts, the availability of discounts for disabled persons according to the disability level, the availability of student discounts, discounts for minors, etc. In other words, the attribute determination result 413 does not include the user's attribute information itself or personal information that is the subject of determination. Also, since the authentication history information 420 to 4n0 has the same configuration as the authentication history information 410, detailed description thereof is omitted.
[0077] The hardware configuration of the authentication history management apparatus 200 will be described with reference to FIG. 9. The authentication history management apparatus 200 includes a memory 201, a processor 202, and a network interface 203.
[0078] The memory 201 stores at least a computer program in which the authentication history management process of the authentication history management device 200 according to the present disclosure is implemented. Note that the memory 201 may store database management software. Other configurations of the memory 201 are the same as those of the memory 101 described above. The processor 202 is a control device that controls each component of the authentication history management device 200. The processor 202 reads and executes software (computer program) from the memory 201. Thereby, the processor 202 realizes the functions of the acquisition unit 210, the registration unit 240, and the search unit 250. That is, the processor 202 performs the authentication history management process according to the present disclosure. Other configurations of the processor 202 are the same as those of the processor 102 described above. The network interface 203 has the same configuration as the network interface 103 described above.
[0079] Subsequently, with reference to FIG. 10, the flow of service provision and authentication history registration processing will be described. In the following description, the flow of an example of service provision and authentication history registration processing will be described with reference to FIG. 11 as appropriate.
[0080] First, it is assumed that the user U1 exists in front of the authentication terminal 100-1 while carrying the personal certificate 31 in order to receive the provision of a predetermined service. Then, the authentication terminal 100-1 acquires the master face image 311 from the personal certificate 31 (S101, S121). For example, the authentication terminal 100-1 may establish communication with the IC chip 310 in the personal certificate 31 by short-range wireless communication of a predetermined method and issue a master face image acquisition command. In response to this, the IC chip 310 reads the master face image 311 from the storage area and returns the master face image 311 to the authentication terminal 100-1 by short-range wireless communication. Note that the method for acquiring the master face image stored in the IC chip is not limited to this.
[0081] Subsequently, the authentication terminal 100-1 identifies the data size information of the acquired master face image 311 (S102, S122). For example, the authentication terminal 100-1 may identify or calculate the data size of the master face image 311 from the address information assigned when the master face image 311 is stored in the memory 101. Note that the method of identifying the data size is not limited to this.
[0082] In parallel with, or before or after steps S101 and S102, the authentication terminal 100-1 captures the face of the user U1 and acquires a query face image (S103, S123). At least after steps S101 and S103, the authentication terminal 100-1 collates the master face image and the query face image to perform face authentication (S104). Then, the authentication terminal 100-1 determines whether the face authentication has succeeded (S105).
[0083] For example, when the face authentication is successful (YES in S105, S124), the authentication terminal 100-1 acquires the attribute information 312 from the personal certificate 31 (S106, S125). For example, the authentication terminal 100-1 may issue a command to acquire attribute information by short-range wireless communication of a predetermined method. In response, the IC chip 310 reads out the attribute information 312 from the storage area and returns the attribute information 312 to the authentication terminal 100-1 by short-range wireless communication. Note that the method of acquiring the attribute information stored in the IC chip is not limited to this. For example, when the attribute information 312 is not stored in the IC chip 310 but is stored in the IC chip of another personal certificate, the authentication terminal 100-1 may acquire the attribute information from the other personal certificate. Or, when the staff near the authentication terminal 100 can visually confirm the user's attributes with another personal certificate or the like, the authentication terminal 100-1 may acquire the user's attribute information based on the input from the staff.
[0084] Thereafter, the authentication terminal 100-1 determines whether the attribute information satisfies the service provision conditions (S107). If the service provision conditions are satisfied (YES in S107, S126), the authentication terminal 100-1 displays display information regarding service provision (S108, S127). For example, the authentication terminal 100-1 may display on the screen that identity verification can be performed by face authentication, that the service provision conditions are satisfied, the service content to be provided, and the like. Then, the authentication terminal 100-1 performs service provision processing for the user U1 (S109, S128). For example, the authentication terminal 100-1 may output a control signal for unlocking the entrance gate. Alternatively, the authentication terminal 100-1 may perform settlement processing with an amount obtained by discounting a predetermined amount from the settlement amount of the user U. Note that the services provided are not limited to these.
[0085] On the other hand, if face authentication fails in step S105 (NO in S105), or if the service provision conditions are not satisfied in step S107 (NO in S107), the authentication terminal 100-1 displays a message indicating that service provision is not possible (S110).
[0086] After step 109 or S110, the authentication terminal 100-1 transmits a history registration request including the authentication result, data size information, and attribute determination result to the authentication history management device 200 (S111, S129). Thereafter, the authentication terminal 100-1 deletes the master face image acquired in step S101, the query face image acquired in step S103, and the attribute information acquired in step S106 (S112, S130).
[0087] In response to step S129, the authentication history management device 200 receives the history registration request from the authentication terminal 100-1. Subsequently, the authentication history management device 200 generates authentication history information by associating the authentication result, data size information, and attribute determination result included in the received history registration request (S131). Then, the authentication history management device 200 registers the generated authentication history information in the authentication history DB400 (S132).
[0088] FIG. 12 is a diagram showing an example of authentication history information registered in the authentication history DB 400. In this example, the authentication history DB 400 is defined with an execution date and time 4011, an authentication location 4012, an authentication success or failure 4013, a data size 402, and an attribute determination result 403 as table attributes. The execution date and time 4011, the authentication location 4012, and the authentication success or failure 4013 are included in the authentication result 401. Also, in the example of FIG. 12, an example in which authentication history information 420 to 470 is registered as records in the table of the authentication history DB 400 is shown. Note that the table attributes of the authentication history DB 400 are not limited to these. For example, the authentication history DB 400 may be defined with a history ID for uniquely identifying authentication history information as a record in the table as a table attribute.
[0089] The execution date and time 4011 is an attribute in which date and time information (time information) when biometric authentication processing, for example, collation processing of a face image or face feature information or authentication determination processing, is executed is stored regardless of the success or failure of biometric authentication. In this example, the information stored in the execution date and time 4011 includes year, month, day, hour, minute, second, and millisecond. It is desirable that the information stored in the execution date and time 4011 includes year, month, and day, and hour, minute, and second. Further, the information stored in the execution date and time 4011 may include milliseconds or even more detailed units of seconds. Or, when the authentication history information is in units of days, the information stored in the execution date and time 4011 may omit the year and month.
[0090] The authentication location 4012 is an example of an attribute in which location information capable of specifying the position of the authentication terminal 100 is stored. The location information stored in the authentication location 4012 is, for example, identification information capable of specifying the installation location of the authentication terminal 100 such as "location A" to "location C". Note that the location information stored in the authentication location 4012 may be other location information such as GPS information as described above.
[0091] The authentication success or failure 4013 is an example of an attribute in which information indicating "success" or "failure" of biometric authentication is stored. Note that the information stored in the authentication success or failure 4013 may indicate success or failure as "OK" and "NG", "0" and "1", other numerical values, flags, symbols, or character information.
[0092] The information stored in data size 402 is information representing, in byte units, a numerical value indicating the data size of master biometric information, for example, a master face image. Note that the unit of the numerical value indicating the data size is not limited to bytes.
[0093] The attribute determination result 403 is an example of an attribute in which information indicating whether service provision conditions are satisfied is stored. The information stored in the attribute determination result 403 is an example combining information indicating the type of service provision conditions and information indicating the presence or absence of satisfaction (such as applicability). Specifically, the authentication history information 420 and 430 "failed" in the authentication with the authentication success / failure 4013. Therefore, it indicates that information indicating "−", that is, undetermined, is stored in the attribute determination result 403. On the other hand, in the attribute determination result 403 of the authentication history information 440, it indicates that information indicating "senior discount" as the type of service provision condition and "applicable" as the applicability is stored. Also, in the attribute determination result 403 of the authentication history information 450, it indicates that information indicating "foreigner discount" as the type of service provision condition and "applicable" as the applicability is stored. Further, in the attribute determination result 403 of the authentication history information 460, it indicates that information indicating "alcohol sales" as the type of service provision condition and "(sales, applicable) yes" as the applicability is stored. On the other hand, in the attribute determination result 403 of the authentication history information 470, it indicates that information indicating "alcohol sales" as the type of service provision condition and "(sales, applicable) no" as the applicability is stored.
[0094] In this example, since the data sizes 402 of the authentication history information 420, 430, and 440 are the same at "984,567" bytes, it can be estimated that they are the authentication history information of the same user. Also, in the analysis process described later, from the execution dates and times 4011 and authentication locations 4012 of the authentication history information 420, 430, and 440, for the user whose data size 402 of the master face image is "984,567" bytes, it can be analyzed that the face authentication failed twice in a row in a short time at location A and succeeded on the third try. That is, it can be said that the action history of a specific user (although the specific individual is unknown) can be analyzed using an arbitrary information processing device based on the authentication history information including the data size information without including personal information.
[0095] Also, the authentication history information 440 indicates that for the user whose data size 402 of the master face image is "984,567" bytes, at location A (although personal information is unknown), it was determined that the senior discount is applicable. Also, the authentication history information 460 indicates that for the same user as the authentication history information 440, about two hours later, the purchase of alcohol was permitted at location C. On the other hand, since the data size 402 of the authentication history information 470 is different from the data size 402 of the authentication history information 460, etc., it indicates that it is a different user. And the authentication history information 470 indicates that for the user whose data size 402 of the master face image is "978,542" bytes, at location C (although personal information is unknown), the purchase of alcohol was not permitted. That is, the user corresponding to the authentication history information 470 indicates that the user was under 20 years old at the time of authentication.
[0096] Note that the acquisition process of the attribute information 312 from the IC chip 310 is not limited to the timings of steps S106 and S125 described above. Specifically, when the attribute information 312 is stored in the IC chip 310, the authentication terminal 100-1 may execute the acquisition process of the attribute information 312 from the IC chip 310 in conjunction with steps S101 and S121.
[0097] Furthermore, the specific process for identifying the data size information is not limited to the timings of steps S102 and S122 described above. Specifically, the authentication terminal 100-1 may execute the specific process for identifying the data size information at least before the transmission process of the history registration requests in steps S111 and S129.
[0098] Furthermore, the deletion processes for the master face image, query face image, and attribute information are not limited to the timings of steps S112 and S130 described above. Specifically, the authentication terminal 100-1 may delete the master face image and query face image after extracting the face feature amounts from each of the master face image and query face image in step S104. Additionally, the authentication terminal 100-1 may delete the face feature amounts after face authentication. Also, the authentication terminal 100-1 may delete the attribute information after the determination process in step S107.
[0099] The flow of an example of the authentication history search process will be described with reference to FIG. 13. First, assume that user U2 exists in front of the authentication terminal 100-2 while carrying the personal certificate 32 in order to receive the provision of a predetermined service. Also, assume that user U2 has received the service provision because of successful face authentication and satisfaction of the service provision conditions at other authentication terminals such as the authentication terminal 100-1 in the past. Therefore, assume that authentication history information in which the authentication result indicating successful face authentication, the data size information of the master face image 321, and the attribute determination result indicating satisfaction of the service provision conditions are associated has been registered in the authentication history DB 400.
[0100] On this premise, the authentication terminal 100-2 acquires the master face image 321 from the personal certificate 32 (S121). Subsequently, the authentication terminal 100-2 identifies the data size of the acquired master face image 321 (S122). Also, the authentication terminal 100-2 captures the face of user U2 and acquires a query face image (S123). Then, the authentication terminal 100-2 performs face authentication and assumes that the face authentication is successful (S124).
[0101] Here, the authentication terminal 100-2 transmits a history search request including the data size information specified in step S122 to the authentication history management device 200 (S141). In response to this, the authentication history management device 200 receives the history search request from the authentication terminal 100-2. Subsequently, the authentication history management device 200 executes a search process on the authentication history DB 400 by including the data size information included in the received history search request as a search key (S142). Here, the description continues assuming a hit in the search. The authentication history management device 200 returns a search result including the authentication result and the attribute determination result associated with the data size information of the search key to the authentication terminal 100-2 (S143).
[0102] In response to this, the authentication terminal 100-2 receives the search result from the authentication history management device 200. Then, the authentication terminal 100-2 determines whether the user U2 satisfies the service provision conditions based on the attribute determination result included in the received search result (S126a). Here, the description continues assuming that the attribute determination result indicates fulfillment of the service provision conditions, that is, the user U2 satisfies the service provision conditions. Therefore, the authentication terminal 100-2 displays display information regarding service provision (S127). Thereafter, the authentication terminal 100-2 and the authentication history management device 200 execute steps S128 to S132 in the same manner as in FIG. 11 above. Note that the authentication terminal 100 may perform a search process on the authentication history DB 400 by including the data size information as a search key after step S122. And when the search result includes a message indicating successful authentication, the face authentication processes in steps S123 and S124 can also be omitted. Details will be described later.
[0103] Using FIG. 14, an example of the display information 51 displayed on the screen of the authentication terminal 100-2 when the service is provided because the user U2 was determined to be serviceable in the previous authentication is shown. The display information 51 indicates that a senior discount was applied in the face authentication and the provision of the payment service by the user U2 in the previous authentication terminal 100. Also, the display information 51 indicates that a senior discount will also be applied in the face authentication and the provision of the payment service by the user U2 in the current authentication terminal 100-2. For example, while the normal price for one adult for Movie A is 2,000 yen, it shows that the senior discount is 700 yen and the price becomes 1,300 yen. Note that the type, content, discount amount, etc. of the service are merely examples and are not limited thereto. For example, the display information 51 may be information that includes the authentication history (the execution date and time of authentication, authentication location, authentication success or failure, attribute determination result, service usage details, etc.) of the user U2 in the immediately previous one time or several times from the immediate past. Thereby, the user U2 can visually confirm when and where they have successfully performed biometric authentication. Therefore, the user U2 can also grasp whether they have been erroneously authenticated or paid as someone else.
[0104] Note that when it is shown in step S126a that the attribute determination result does not satisfy the service provision condition, the authentication terminal 100-2 may display a message indicating that the service cannot be provided, as in step S110 of FIG. 10 above. Alternatively, in this case, the authentication terminal 100-2 may determine the service provision condition for the attribute information of the user U2 again. For example, the authentication terminal 100-2 may obtain the attribute information 322 from the personal certificate 32 of the user U2 in step S125 of FIG. 11 above and perform the determination in step S126.
[0105] Still, in step S126a, even if user U2 has satisfied the service provision conditions in the past, if a certain period of time or more has elapsed since the authentication success date and time of the authentication result included in the received search results, the authentication terminal 100-2 may determine the service provision conditions again. This is because even for the same user, the attribute information may cease to satisfy the service provision conditions after a certain period of time has elapsed. For example, if the service is a student discount, the user had a student status at the time of the previous determination, but may have graduated from school and no longer have a student status at the time of the current determination. Also, if the service is a minor discount, the user's age was 17 years old and satisfied the service provision conditions at the time of the previous determination, but may be 18 years old at the time of the current determination, making the minor discount inapplicable.
[0106] Also, in FIG. 12, for a user whose data size 402 is "984,567" bytes, it can be said that from the authentication history information 440, the user has already "succeeded in face authentication" at "10:05:35", and "confirmed that the age is 60 or above (for which senior discount is applicable)". Therefore, when the user attempts to purchase alcohol around "13:21", the authentication terminal specifies the authentication history information 440 from the authentication history DB 400 using the data size "984,567" bytes of the user's master face image as a search key, and can determine that the user has been confirmed to be 60 years or above within the most recent two and a half hours. Thus, without obtaining the age information from the user's personal certificate or the like, the authentication terminal can determine that the alcohol sales conditions are met because the user is 20 years or above. That is, when a user with a specific data size has "succeeded in face authentication" within a predetermined time and has a specific "attribute determined", the authentication terminal can omit the normal attribute determination process. In other words, in this case, the authentication terminal may "deem it permitted" to sell alcohol for the corresponding user. At that time, the authentication terminal may register this fact as the authentication history information 460 in the authentication history DB 400. For example, the authentication terminal may register "Alcohol sales: deemed permitted" or the like in the attribute determination result 403 of the authentication history information 460 in FIG. 12. That is, the recorded content of the authentication history information may be distinguishable between the case where the authentication terminal omits or deems permitted the attribute determination process based on the search result in response to the history search request and the case where the authentication terminal performs the normal attribute determination process. Also, in this case, the authentication terminal may register the date and time when it was determined to "deem it permitted" to sell alcohol based on the authentication history information 440 in the execution date and time 4011 of the authentication history information 460 in FIG. 12. Further, in step S126a in FIG. 13, when the attribute determination result included in the search result is "deemed permitted" or "deemed applicable" in addition to "permitted" or "applied", the authentication terminal may similarly determine that the user meets the service provision conditions.
[0107] Here, an example of the present disclosure can be said to record the image data size of a face photo stored in an IC chip of a personal certificate carried by a specific user as unique information of the user in the authentication history of biometric authentication. Further, instead of the image data size of the face photo, data size information of other master biometric information may be used. That is, the authentication history management system according to the present disclosure includes data size information of the user's master biometric information in the records of the authentication history DB, so that any user can be substantially tracked from the authentication history without issuing a new user ID for biometric authentication. For example, a service provider can track the authentication history (authentication result) of any user (even if an individual cannot be identified) and substantially grasp the action history by analyzing the search results using specific data size information as a search key from the authentication history. Therefore, the tracking accuracy of the authentication history and the like can be ensured without using personal information.
[0108] In addition, the authentication history management system according to the present disclosure registers an attribute determination result in association with the data size information in the authentication history DB. Therefore, in the authentication history search process, it is also possible to search the authentication history DB for the attribute determination result associated with the data size information. Therefore, the authentication terminal can determine whether the current user is a service target without using personal information itself such as attribute information, but using the result determined to be service-providable in the past.
[0109] In addition, in order to provide services using an authentication terminal, it was necessary for the staff of the service provider to determine attributes and the like every time when verifying the identity of the user. In particular, the staff had to prompt the user to hold a card or the like storing attribute information in front of the authentication terminal, or visually check a document on which the attribute information was described and input the fact to the authentication terminal. Therefore, the burden on the staff was heavy. On the other hand, the authentication terminal according to the present disclosure may be able to omit acquiring attribute information every time service is provided by referring to the attribute determination result associated with the data size information of the user's master biometric information from the authentication history DB. Therefore, labor saving for the staff and reduction of the burden on the user can be achieved. In addition, by determining fulfillment of service provision conditions using past attribute determination results, the authentication terminal 100 can omit the acquisition process of attribute information for the second and subsequent times and the determination process of service provision conditions based on the attribute information. Therefore, the processing load on the authentication terminal can be reduced, and the processing speed and service provision speed can be improved.
[0110] In addition, in one-to-one or one-to-N biometric authentication, it was usually impossible to identify the user at the time of authentication failure. This is because biometric authentication itself is a process of verifying the identity of the user, that is, identifying the user. Therefore, it was difficult to analyze the cause of the authentication failure and so on. On the other hand, the authentication history management system according to the present disclosure can register data size information in the authentication history DB in association with the fact of authentication failure and the date and time of authentication failure, among the authentication results. Thereby, based on the data size information, it is possible to analyze whether or not the authentication failure is caused by a person who is considered to be the same user with a certain degree of accuracy. Along with this, it is also possible to analyze whether the cause of the authentication failure is due to the installation location of the authentication terminal or a specific person. For example, assume that a plurality of authentication history information including the same data size information is registered in the authentication history DB. In this case, if the authentication failure times included in the authentication history information are consecutive in a short period and then the authentication is successful, it can be analyzed that the cause of the authentication failure is due to the user corresponding to the master face image corresponding to the data size information. On the other hand, if the authentication failures are included in a plurality of authentication history information including different data size information and the terminal IDs and the like included in these authentication history information are common, it can be analyzed that the cause of the authentication failure is not due to the user but due to the installation location. For example, from the time zone of the authentication failure of a specific authentication terminal, it can be specified that the sunlight exposure to the camera is the cause of the decrease in authentication accuracy, which can contribute to considering the improvement of the installation location of the authentication terminal (such as avoiding direct sunlight).
[0111] In addition, in the present embodiment, an example in which the data size itself is used as the data size information has been described. Thereby, it is possible to simply realize while meeting the requirements for personal information protection, and to obtain appropriate analysis results.
[0112] Furthermore, by using the authentication result in the authentication history information of the authentication history DB of the present disclosure, it is also possible to omit the biometric authentication after the second time. For example, the search unit of the authentication terminal or the authentication history management device performs a search process before the biometric authentication is performed. And when the execution unit includes the fact that the authentication is successful in the search result, it may execute the process according to the search result. Thereby, after the identity confirmation by biometric authentication is once performed on the authentication terminal in a predetermined area, the biometric authentication process can be omitted again on other authentication terminals. Therefore, it contributes to reducing the processing load, communication load, and processing time of the authentication terminal or the authentication history management device. Furthermore, it can also contribute to shortening the service provision time. Furthermore, when the authentication success date and time included in the search result are within a predetermined period, the execution unit may execute the service provision process without performing biometric authentication on the user. That is, only within a certain period, the success of past biometric authentication is made valid. By providing an expiration date for the identity confirmation by biometric authentication, security can be ensured.
[0113] <Embodiment 4> Since the authentication history management system according to Embodiment 4 is equivalent to FIG. 5 above, the illustration is omitted. However, for convenience of explanation, the reference numerals of the authentication terminals are replaced from "100(100-1, 100-2)" to "100a(100a-1, 100a-2)" for explanation. Similarly, the reference numeral of the authentication history management device is replaced from "200" to "200a" for explanation.
[0114] Therefore, the authentication history management system according to Embodiment 4 includes authentication terminals 100a-1 and 100a-2, and an authentication history management device 200a having an authentication history DB 400. The illustration of the authentication history management system according to Embodiment 4 is omitted. The authentication terminal 100a is a specific example of the authentication terminal 1 in Embodiment 1 or 2. The authentication history management device 200a is a specific example of the authentication history management device 2 in Embodiment 2.
[0115] The authentication terminal 100a only needs to have at least some of the configurations and functions of the authentication terminal 100 in Embodiment 3. Therefore, the illustration of the authentication terminal 100a according to Embodiment 4 is omitted. The authentication terminal 100a may include an acquisition unit 110, an authentication unit 120, a determination unit 130, a registration unit 140, a search unit 150, and an execution unit 160. However, for the authentication terminal 100a, some of the functions of these configurations are as described below.
[0116] The acquisition unit 110 according to Embodiment 4 may have the same function as that in Embodiment 3. However, the acquisition unit 110 according to Embodiment 4 does not necessarily need to specify or calculate the data size information of the master face image obtained from the personal certificate.
[0117] The authentication unit 120 according to Embodiment 4 transmits a face authentication request including the master face image and the query face image to the authentication history management device 200a or an external authentication device. Then, the authentication unit 120 acquires the authentication result from the device that is the transmission destination of the face authentication request.
[0118] The determination unit 130 according to Embodiment 4 transmits a determination request including the attribute information of the user U to the authentication history management device 200a and receives the attribute determination result from the authentication history management device 200a. Further, the determination unit 130 determines whether or not the service provision conditions are satisfied based on the attribute determination result received from the authentication history management device 200a.
[0119] The registration unit 140 according to Embodiment 4 may send a history registration request including the authentication result, data size information, and attribute determination result to the authentication history management device 200a. However, when the authentication history management device 200a regards the face authentication request from the authentication unit 120 and the determination request from the determination unit 130 as a history registration request, the registration unit 140 may not send the history registration request. Alternatively, the registration unit 140 may send a face authentication request instead of the authentication unit 120. Also, the registration unit 140 may send a determination request instead of the determination unit 130. Or, the registration unit 140 may send a history registration request including the master face image, the query face image, and attribute information to the authentication history management device 200a. In this case, the authentication history management device 200a may perform authentication processing, determination processing, and registration processing according to the history registration request.
[0120] The search unit 150 according to Embodiment 4 may send a face authentication request as a search request to the authentication history management device 200a instead of the authentication unit 120. The execution unit 160 according to Embodiment 4 may have the same functions as those in Embodiment 3.
[0121] Subsequently, the configurations of the authentication history management device 200a and the authentication history DB 400 will be described with reference to FIG. 15. Since the authentication history DB 400 is the same as that in Embodiment 3, detailed description thereof will be omitted. The authentication history management device 200a includes an acquisition unit 210a, an authentication unit 220a, a determination unit 230a, a registration unit 240a, a search unit 250a, and an execution unit 260a.
[0122] The acquisition unit 210a is an example of the acquisition unit 21 described above. The acquisition unit 210a acquires a face authentication request including a master face image and a query face image from the authentication terminal 100a. Also, the acquisition unit 210a may acquire position information capable of specifying the position of the authentication terminal 100a. Further, the acquisition unit 210a may acquire a determination request including the attribute information of the user U from the authentication terminal 100a. Or, the acquisition unit 210a may acquire a history registration request including a master face image, a query face image, and attribute information from the authentication terminal 100a.
[0123] In addition, the acquisition unit 210a acquires the authentication result by the authentication unit 220a. Further, the acquisition unit 210a specifies or calculates numerical information indicating the data size of the master biometric information included in the acquired face authentication request or history registration request as data size information. Alternatively, the acquisition unit 210a may acquire the data size itself of the master face image of the user U from the authentication terminal 100a.
[0124] The authentication unit 220a controls face authentication as an example of biometric authentication. The authentication unit 220a performs face authentication based on the master face image and the query face image included in the face authentication request or history registration request acquired by the acquisition unit 210a. In addition, the authentication unit 220a performs face authentication by the same process as the authentication unit 120 of Embodiment 3.
[0125] The determination unit 230a determines whether the attribute information of the user satisfies a predetermined service provision condition. The determination unit 230a performs the above determination using the attribute information included in the determination request or history registration request acquired by the acquisition unit 110. In particular, the determination unit 230a preferably determines the service provision condition corresponding to the requesting authentication terminal. For example, the determination unit 230a preferably specifies the type of service provision condition from the terminal ID included in the determination request or history registration request and performs the determination of the specified type of service provision condition. In addition, the determination unit 230a performs face authentication by the same process as the determination unit 130 of Embodiment 3.
[0126] The registration unit 240a is an example of the above-described registration unit 22. The registration unit 240a generates authentication history information by associating the authentication result and data size information acquired by the acquisition unit 210a and the attribute determination result determined by the determination unit 230a. Then, the registration unit 240a registers the generated authentication history information in the authentication history DB 400. If the position information of the authentication terminal 100a is included in the authentication result, the data size information and the position information will be associated in the authentication history information. Therefore, it can be said that the registration unit 240a further includes position information that can specify the position of the authentication terminal 100a and registers it in the authentication history DB 400 as authentication history information.
[0127] The search unit 250a performs a search process on the authentication history DB 400, including the data size information of the master biometric information acquired by the acquisition unit 210a as a search key. For example, when the authentication result by the authentication unit 220a is a successful authentication, it is preferable that the search unit 250a performs a search process on the authentication history DB 400 including the data size information as a search key. In addition, the search unit 250a performs a search process in the same manner as the search unit 250 in the third embodiment. Further, the search unit 250a may perform a search process before the determination by the determination unit 230a is performed.
[0128] When the execution unit 260a includes a successful authentication in the search result, the execution unit 260a executes a process according to the attribute determination result included in the search result. For example, when the search result includes a successful authentication and satisfaction of service provision conditions, the execution unit 260a may transmit an execution instruction for the service corresponding to the service provision conditions to the authentication terminal 100a. Or, when the search result includes a successful authentication and satisfaction of service provision conditions, and the service content is a discount on the settlement amount, the execution unit 260a may perform a settlement process with an amount obtained by discounting a predetermined amount from the settlement amount of the user U. In addition, the execution unit 260a may transmit an output instruction for display information according to the search result to the authentication terminal 100a.
[0129] Also, for example, assume that a search process is performed before the determination by the determination unit 230a, and the search result includes a successful authentication. In this case, the execution unit 260a executes a process according to the attribute determination result included in the search result. Thereby, similar to the third embodiment, the determination process load of the service provision conditions and the staff's attribute confirmation work load can be reduced.
[0130] FIG. 16 illustrates a flow of an example of the authentication history registration process. First, assume that the user U1 exists in front of the authentication terminal 100a-1 while carrying the personal certificate 31 in order to receive the provision of a predetermined service. Then, the authentication terminal 100a-1 acquires the master face image 311 from the personal certificate 31 (S121). In parallel with, before, or after step S121, the authentication terminal 100a-1 captures the face of the user U1 and acquires a query face image (S123).
[0131] Then, the authentication terminal 100a-1 transmits a face authentication request including the master face image and the query face image to the authentication history management device 200a (S201). In response to this, the authentication history management device 200a receives the face authentication request from the authentication terminal 100a-1. Then, the authentication history management device 200a performs face authentication processing based on the master face image and the query face image included in the received face authentication request (S202). Here, the description will continue assuming successful face authentication. Therefore, the authentication history management device 200a returns an authentication result including the fact of successful authentication to the authentication terminal 100a-1 (S203). In response to this, the authentication terminal 100a-1 receives the authentication result from the authentication history management device 200a. Incidentally, here, the authentication history management device 200a specifies the data size information of the master face image (S205).
[0132] Then, the authentication terminal 100a-1 determines whether the face authentication is successful or not based on the authentication result (S204). Here, the authentication terminal 100a-1 determines that the user U1 has succeeded in face authentication. Therefore, the authentication terminal 100a-1 acquires the attribute information 312 from the personal certificate 31 (S125). Then, the authentication terminal 100a-1 transmits a determination request including the attribute information of the user U1 to the authentication history management device 200a (S206). In response to this, the authentication history management device 200a receives the determination request from the authentication terminal 100a-1. Then, the authentication history management device 200a determines whether the service provision conditions are satisfied or not using the attribute information included in the received determination request (S207). Here, the description will continue assuming that the service provision conditions are satisfied (met). Therefore, the authentication history management device 200a returns an attribute determination result including the fact that the service provision conditions are satisfied to the authentication terminal 100a-1 (S208). In response to this, the authentication terminal 100a-1 receives the attribute determination result from the authentication history management device 200a.
[0133] Then, the authentication terminal 100a-1 determines whether the user U1 satisfies the service provision conditions based on the received attribute determination result (S209). Here, it is assumed that the attribute determination result indicates fulfillment of the service provision conditions, that is, the user U1 satisfies the service provision conditions, and the description continues accordingly. Thereafter, the authentication terminal 100a-1 executes steps S127, S128, and S130 in the same manner as in FIG. 11 above.
[0134] Also, after step S207, the authentication history management device 200a generates authentication history information by associating the authentication result, data size information, and attribute determination result (S131). Then, the authentication history management device 200 registers the generated authentication history information in the authentication history DB 400 (S132). Thereafter, the authentication history management device 200a deletes the master face image and query face image included in the received face authentication request, and the attribute information included in the received determination request (S133).
[0135] Note that the process of acquiring the attribute information 312 from the IC chip 310 is not limited to the timing of step S125 described above. Specifically, when the attribute information 312 is stored in the IC chip 310, the authentication terminal 100a-1 may execute the process of acquiring the attribute information 312 from the IC chip 310 in conjunction with step S121.
[0136] Note that the process of specifying the data size information is not limited to the timing of step S205 described above. Specifically, the authentication history management device 200a may execute the process of specifying the data size information at least before step S131.
[0137] Furthermore, the deletion processes of the master face image, query face image, and attribute information are not limited to the timings of steps S130 and S133 described above. Specifically, after transmitting a face authentication request in step S201, the authentication terminal 100a-1 may delete the master face image and the query face image. Also, after transmitting a determination request in step S206, the authentication terminal 100a-1 may delete the attribute information. Further, after extracting face feature amounts from the master face image and the query face image respectively in step S202, the authentication history management device 200a may delete the master face image and the query face image. Additionally, after face authentication, the authentication history management device 200a may delete the face feature amounts. Also, after the determination process in step S207, the authentication history management device 200a may delete the attribute information. Further, a database managed by an attribute information manager different from this service provider may be installed outside the authentication history management device 200a, and under appropriate management by the attribute information manager, the attribute information manager may store and utilize the attribute information.
[0138] With reference to FIG. 17, the flow of an example of the authentication history search process will be described. First, assume that user U2 exists in front of the authentication terminal 100a-2 while carrying the personal certificate 32 in order to receive a predetermined service. Note that it is assumed that user U2 has received service provision because of successful face authentication and satisfaction of service provision conditions at another authentication terminal such as the authentication terminal 100a-1 in the past. Therefore, it is assumed that authentication history information in which an authentication result indicating successful face authentication, data size information of the master face image 321, and an attribute determination result indicating satisfaction of service provision conditions are associated is already registered in the authentication history DB 400.
[0139] On this premise, the authentication terminal 100a-2 acquires the master face image 321 from the personal certificate 32 (S121). Also, the authentication terminal 100a-2 captures the face of user U2 and acquires a query face image (S123). Then, the authentication terminal 100a-2 sends a face authentication request including the master face image and the query face image to the authentication history management device 200a (S201). Then, the authentication history management device 200a performs face authentication processing (S202) and assumes that the face authentication is successful. The authentication history management device 200a returns an authentication result including the fact of successful authentication to the authentication terminal 100a-2 (S203). The authentication terminal 100a-2 determines the success or failure of face authentication based on the received authentication result (S204) and determines that user U2 has succeeded in face authentication. Here, the authentication history management device 200a specifies the data size information of the master face image (S205).
[0140] Subsequently, the authentication history management device 200a executes a search process on the authentication history DB 400 by including the specified data size information in the search key (S211). Here, the description continues assuming that a hit is found in the search. The authentication history management device 200a determines whether user U2 satisfies the service provision conditions based on the attribute determination result included in the search result (S212). Here, the description continues assuming that the attribute determination result indicates fulfillment of the service provision conditions, that is, user U2 satisfies the service provision conditions. Then, the authentication history management device 200a returns the attribute determination result to the authentication terminal 100a-2 (S208).
[0141] Accordingly, the authentication terminal 100a-2 receives the attribute determination result from the authentication history management device 200a. Then, the authentication terminal 100a-2 determines whether user U2 satisfies the service provision conditions based on the received attribute determination result (S209). Here, it is determined that the attribute determination result indicates fulfillment of the service provision conditions. Thereafter, the authentication terminal 100a-2 executes steps S127, S128, and S130 in the same manner as in FIG. 16 above. Also, after step S212, the authentication history management device 200a executes steps S131 to S133 in the same manner as in FIG. 16 above.
[0142] The determination process of the service provision conditions in the authentication history management device 200a may also be performed on the authentication terminal 100a side. In this case, the determination process request to the authentication history management device 200a can be omitted, and the communication load can be reduced. Also, the processing load of the authentication history management device 200a can be reduced.
[0143] Moreover, when the attribute determination result in step S212 indicates that the service provision conditions are not satisfied, the authentication history management device 200a may return display information indicating that service provision is not possible to the authentication terminal 100a-2. In this case, the authentication terminal 100a-2 displays the received display information on the screen. Or, in this case, the authentication history management device 200a may determine the service provision conditions for the attribute information of the user U2 again. For example, the authentication history management device 200a may send an instruction to re-acquire the attribute information to the authentication terminal 100a-2. Then, the authentication terminal 100a-2 may acquire the attribute information 322 from the personal certificate 32 of the user U2 by step S125 in FIG. 11 above, and send a determination request including the attribute information to the authentication history management device 200a by step S206. Then, the authentication history management device 200a may perform the determination by step S207.
[0144] Moreover, in step S212, even if the user U2 has satisfied the service provision conditions in the past, if a certain period of time or more has elapsed since the authentication success date and time of the authentication result included in the received search result, the authentication history management device 200a may determine the service provision conditions again. This is the same as the reason described above in Embodiment 3.
[0145] From the above, in Embodiment 4, the same effects as those of Embodiment 3 described above can be achieved.
[0146] <Embodiment 5> Next, as Embodiment 5, a method for reducing the processing of the authentication terminal by utilizing the authentication history DB and reducing the burden on users and staff will be described. Since the authentication history management system according to Embodiment 5 is equivalent to FIG. 5 above, the illustration is omitted. However, for convenience of explanation, the reference numerals of the authentication terminals will be described by replacing them from "100(100-1, 100-2)" to "100b(100b-1, 100b-2)".
[0147] Therefore, the authentication history management system according to Embodiment 5 includes authentication terminals 100b-1 and 100b-2, and an authentication history management device 200 having an authentication history DB 400. Note that the illustration of the authentication history management system according to Embodiment 5 is omitted. The authentication terminal 100b is a specific example of the authentication terminal 1 in Embodiment 1 or 2.
[0148] The authentication terminal 100b has at least some of the configurations and functions of the authentication terminal 100 in Embodiment 3. Therefore, the illustration of the authentication terminal 100a according to Embodiment 4 is omitted. The authentication terminal 100b may include an acquisition unit 110, an authentication unit 120, a determination unit 130, a registration unit 140, a search unit 150, and an execution unit 160. However, for some of the functions of these configurations of the authentication terminal 100b, they will be described later.
[0149] The acquisition unit 110 of the authentication terminal 100b is an example of a specifying means, and specifies the first data size information of the first master biometric information stored in the user's storage medium. Further, the search unit 150 of the authentication terminal 100b performs a search process on the history DB including the first data size information as a search key. Here, it can be said that the history DB stores authentication history information in which the authentication result of biometric authentication based on the collation of the second master biometric information and the query biometric information is associated with the second data size information of the second master biometric information. The second master biometric information may be the same as or different from the first master biometric information. Further, the execution unit 160 of the authentication terminal 100b executes a process according to the search result of the search process. Thereby, the same effect as in Embodiment 1 above is achieved.
[0150] Furthermore, the search unit 150 of the authentication terminal 100b may perform a search process before biometric authentication is performed. In this case, when the execution unit 160 of the authentication terminal 100b includes a message indicating successful authentication in the search result, the execution unit 160 may execute the process.
[0151] FIG. 18 is a flowchart showing the flow of service provision, authentication history registration, and authentication history search processing. In the following description, an example flow of service provision, authentication history registration, and authentication history search processing will be described with reference to the sequence diagram of FIG. 19 as appropriate.
[0152] First, assume that user U2 is present in front of the authentication terminal 100b-2 while carrying the personal certificate 32 in order to receive a predetermined service. It is assumed that user U2 has received service provision because face authentication has been successful and service provision conditions have been satisfied at other authentication terminals such as the authentication terminal 100b-1 in the past. Therefore, it is assumed that authentication history information in which the authentication result indicating successful face authentication, the data size information of the master face image 321, and the attribute determination result indicating satisfaction of the service provision conditions are associated has been registered in the authentication history DB 400.
[0153] On this premise, the authentication terminal 100b-2 acquires the master face image 321 from the personal certificate 32 (S101, S121). Subsequently, the authentication terminal 100b-2 specifies the data size of the acquired master face image 321 (S102, S122). Instead of steps S101 and S102, the authentication terminal 100b-2 may specify the data size by acquiring the numerical information of the data size of the master face image 321 itself from the personal certificate 32.
[0154] Subsequently, the authentication terminal 100b-2 executes a search process on the authentication history DB 400 including the data size information as a search key (S501). For example, the authentication terminal 100b-2 transmits a history search request including the data size information specified in step S122 to the authentication history management device 200 (S141). In response to this, the authentication history management device 200 receives the history search request from the authentication terminal 100b-2. Subsequently, the authentication history management device 200 executes a search process on the authentication history DB 400 including the data size information included in the received history search request as a search key (S142). Here, the description continues assuming a hit in the search. The authentication history management device 200 returns a search result including the authentication result and the attribute determination result associated with the data size information of the search key to the authentication terminal 100b-2 (S143).
[0155] In response to this, the authentication terminal 100b-2 receives the search result from the authentication history management device 200. Then, the authentication terminal 100b-2 determines whether it has been authenticated based on the authentication result included in the received search result (S124a). That is, the authentication terminal 100b-2 determines whether the authentication result included in the search result includes a message indicating authentication success (S502). If the authentication result includes a message indicating authentication success (YES in S124a), hereinafter, the authentication terminal 100b-2 executes steps S106 to S110 (S126a and S127 to S130 in FIG. 13 above) in the same manner as in FIG. 10 above. Then, the authentication history management device 200 executes S131 and S132 in the same manner as in FIG. 13 above.
[0156] On the other hand, if the authentication result includes a message indicating authentication failure (NO in S502), the authentication terminal 100b-2 captures the face of the user U2 and acquires a query face image (S103). Subsequently, the authentication terminal 100b-2 executes steps S104 to S110 (S126 to S130 in FIG. 11 above) in the same manner as in FIG. 10 above. Then, the authentication history management device 200 executes S131 and S132 in the same manner as in FIG. 11 above.
[0157] From the above, in Embodiment 5, the same effects as those of Embodiment 3 described above can be achieved. In particular, according to Embodiment 5, after the identity verification by biometric authentication is performed once on an authentication terminal with a predetermined area, the biometric authentication process can be omitted again on other authentication terminals. Therefore, it contributes to reducing the processing load of the authentication terminal or the authentication history management device, reducing the communication load, and shortening the processing time. Furthermore, it can also contribute to shortening the service provision time. Further, when the authentication success date and time included in the search result are within a predetermined period, the execution unit may execute the service provision process without performing biometric authentication on the user. That is, only within a certain period, the success of past biometric authentication is made valid. By setting an expiration date for identity verification by biometric authentication, security can be ensured.
[0158] In the authentication history information 440 of FIG. 12, a user with a data size 402 of "984,567" bytes has "succeeded in face authentication" at "10:05:35". Therefore, if the user attempts to receive service provision by face authentication within several hours from "10:05:35", the authentication terminal may consider that the face authentication has succeeded without capturing the user's face based on the authentication history information 440. Specifically, the authentication terminal identifies the authentication history information 440 from the authentication history DB 400 using the data size "984,567" bytes of the user's master face image as a search key. Then, the authentication terminal may determine that the user with the said data size has already "succeeded in face authentication" based on the authentication result 4013 of the authentication history information 440. That is, if the authentication result 4013 of the information that matches the user's data size information among the past authentication history information indicates "success", the authentication terminal may omit the biometric authentication process for the said user. In other words, in this case, the authentication terminal may consider that the biometric authentication has succeeded and the identity has been confirmed even without actually performing biometric authentication on the said user. At that time, the authentication terminal may register to that effect as the authentication history information 460 in the authentication history DB 400. For example, the authentication terminal may register "deemed successful" etc. in the authentication result 4013 of the authentication history information 460 of FIG. 12. That is, the recorded content of the authentication history information may be distinguishable between the case where the authentication terminal omits or deems successful the biometric authentication process based on the search result in response to the history search request, and the case where the authentication terminal performs the normal biometric authentication process. Furthermore, if the user attempts to purchase alcohol by the authentication terminal within several hours from "10:05:35", the authentication terminal may also omit the attribute determination process in the same manner as above. That is, the authentication terminal may omit the biometric authentication process and the attribute determination process for the said user. At that time, the authentication terminal may register, for example, "deemed successful" in the authentication result 4013 of the authentication history information 460 of FIG. 12, and "alcohol sales: deemed permitted" etc. in the attribute determination result 403. Incidentally, in these cases, the authentication terminal may register in the execution date and time 4011 of the authentication history information 460 of FIG. 12 the date and time when it is determined that the biometric authentication is "deemed successful" or the alcohol sales are "deemed permitted" based on the authentication history information 440.Also, in step S124a of FIG. 19, when the authentication result included in the authentication result is "success" in addition to "deemed success", the authentication terminal may similarly determine that the user has been authenticated (verified).
[0159] <Other Embodiments> In addition, as described above, the personal certificate according to the above embodiment is a passport, a my number card, a driver's license, an employee ID card, a student ID card, etc. that incorporate a storage medium (such as an IC chip) that stores at least master biometric information. Therefore, for example, in step S101 of FIG. 10 and step S121 of FIG. 11, the authentication terminal may read the master biometric information from the passport or the like. Alternatively, the master biometric information read by the authentication terminal may be information pre-registered in a mobile terminal such as a smartphone carried by the user.
[0160] Furthermore, the mobile terminal may previously read the master biometric information from the above personal certificate and perform biometric authentication by one-to-one matching of query biometric information such as a face image captured by the mobile terminal of the user and the master biometric information. In this case, the mobile terminal may store either the query biometric information or the master biometric information that has succeeded in biometric authentication internally as the master biometric information. Then, the authentication terminal may read the master biometric information from the mobile terminal. And these are the same in step S11 of FIG. 2, step S21 of FIG. 4, and steps S121 of FIGS. 13, 16, 17, and 19. Therefore, for example, if the user has previously succeeded in biometric authentication by the authentication terminal, the user can omit the biometric authentication simply by touching the authentication terminal with a storage medium (such as a passport) incorporating an IC chip or the like in which the master biometric information is stored or a mobile terminal. That is, by having the user touch a passport or the like or a smartphone or the like to the authentication terminal, the authentication terminal can obtain the data size of the master biometric information of the user and search the authentication history information using the obtained data size.
[0161] The authentication history information of the authentication history DB 400 according to the above-described Embodiments 3 and 4 includes the attribute determination result 413. Therefore, by performing a search process on the authentication history DB 400 using a specific attribute determination result as a search key, it is also possible to perform behavior analysis on a user group with a specific attribute. In this case, for example, the authentication history management device may further include a second search unit that searches the authentication history DB for authentication history information including the result of determination of service provision conditions that satisfy specific conditions. In this case, the execution unit of the authentication history management device may execute, as processing according to the search result, outputting an analysis result based on the authentication history information searched by the second search unit. Note that the second search unit and the execution unit may be provided in another information processing device connected to the authentication history DB instead of the authentication history management device.
[0162] Here, specific examples of the specific attribute determination result include, but are not limited to, the type of service content and the determination result of whether or not a service can be provided. Further, the analysis result may be, for example, the number of pieces of the searched authentication history information. Alternatively, the analysis result may be, for example, the number of pieces including the same data size information among the searched authentication history information. That is, by aggregating the number of pieces including the same data size information among the searched authentication history information, the number of users who have obtained a specific attribute determination result can be estimated.
[0163] Based on these, it is possible to trace the authentication history of specific attributes and utilize it for analyzing marketing trends. That is to say, the authentication history DB of the present disclosure can also be utilized for analyzing the behaviors of user groups with common attributes. The reason is that in the case of analyzing marketing trends, it is not necessary to strictly identify individuals, and it can be said that it is a sufficiently useful result if the trends of user groups with common attributes can be grasped. Also, it is possible to consider sales improvement plans from multiple analysis results. For example, let analysis result 1 be that at a certain time zone X on weekdays (starting from the authentication success date and time) on authentication terminal A, there are a predetermined number of users (aggregate value of different data sizes) to whom the senior discount for movie tickets is applied (from the attribute determination result). Also, let analysis result 2 be that at time zone Y after time zone X (starting from the authentication success date and time) on authentication terminal B, there are a predetermined number of users (aggregate value of different data sizes) to whom alcohol sales are permitted (from the attribute determination result). From these two analysis results, it becomes possible to conduct a complex marketing analysis such as expecting an effect of increasing sales by installing a store that sells alcoholic beverages preferred by the senior layer near a movie theater.
[0164] In addition, the authentication history DB of the present disclosure may be built into the authentication terminal. In that case, for example, the authentication history management device may collect the authentication history information of each authentication history DB from a plurality of authentication terminals at regular intervals or at a predetermined timing and aggregate it into an integrated authentication history DB. Or, before the determination process, the authentication terminal may execute a search process using the data size information of the master biometric information of the current target user as a search key for each of the authentication history DBs of other multiple authentication terminals.
[0165] Furthermore, the authentication terminal of the present disclosure is not limited to a kiosk terminal or the like installed by a service provider. The authentication terminal of the present disclosure may be, for example, a portable wireless-capable information terminal (user terminal) carried by a user. That is, the storage medium 3 of Embodiment 1 or 2 may be built into the user terminal. In that case, the user terminal shall include the current location information of the user terminal in a history registration request, a face authentication request, or the like. The location information includes, for example, but is not limited to, GPS information. Thereby, even when the authentication terminal is a user terminal, it can contribute to improving the analysis accuracy of the authentication history.
[0166] Furthermore, the data size information of the present disclosure may be an operation result or a conversion result obtained by performing a predetermined operation process, conversion process, encryption process, or the like on the data size (numerical value) of the master biometric information. For example, the data size information may be a hash value or the like. In that case, the authentication terminal or the authentication history management device shall further include a calculation unit that calculates the data size information from the master biometric information acquired by the acquisition unit. Then, the registration unit may register the calculated data size information in the history database including it in the authentication history information. In this case, further, the calculation unit may calculate, as the data size information, a conversion result obtained by performing a predetermined conversion process on the data size of the master biometric information.
[0167] Furthermore, the search results using the data size according to the present disclosure may be considered valid when the execution date and time of authentication are within a predetermined period from the current time. For example, the predetermined period may be limited to the same day or one week. That is, for a service that has recently succeeded in one-to-one biometric authentication or has been permitted by attribute determination, if the use is within the predetermined period, it is preferable to be able to omit biometric authentication and attribute determination. This is because when referring to the authentication history using the data size to omit biometric authentication and attribute determination for identity authentication, the probability of a decrease in authentication accuracy increases when the number of the population increases. In addition, when the number of authentication history information exceeds a predetermined number, the authentication history management device or the like may delete older authentication history information from the authentication history DB so as to maintain the authentication history information within the predetermined number. That is, even if the user has succeeded in biometric authentication or has been permitted by attribute determination in the past, the authentication terminal may display a message requesting biometric authentication and attribute determination.
[0168] Furthermore, in the above-described embodiments, although the hardware configuration has been described, the present disclosure is not limited thereto. The present disclosure can also be realized by causing a CPU to execute a computer program for any process.
[0169] In the above example, when the program is loaded into a computer, it includes a set of instructions (or software code) for causing the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, a computer-readable medium or a tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD), or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray (registered trademark) disc, or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage, or other magnetic storage devices. The program may also be transmitted on a transitory computer-readable medium or a communication medium. By way of example and not limitation, a transitory computer-readable medium or a communication medium includes electrical, optical, acoustic, or other forms of propagated signals.
[0170] As described above, the present disclosure has been described with reference to the embodiments, but the present disclosure is not limited to the above-described embodiments. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. And each embodiment can be combined with other embodiments as appropriate.
[0171] Each drawing is merely an illustration for explaining one or more embodiments. Each drawing is not associated with only one specific embodiment, but may be associated with one or more other embodiments. As can be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, embodiments that are not explicitly illustrated or described. Not all of the features or steps shown in any one drawing for explaining exemplary embodiments are necessarily essential, and some features or steps may be omitted. The order of the steps described in any drawing may be changed as appropriate.
[0172] Some or all of the above embodiments can also be described as follows, but are not limited thereto. (Appendix A1) An acquisition means for acquiring the master biometric information from a storage medium storing the master biometric information of the user, A registration means for registering authentication history information in which the authentication result of biometric authentication based on the query biometric information acquired from the user and the master biometric information is associated with the data size information of the master biometric information in a history database, An authentication terminal comprising the above. (Appendix A2) The authentication result includes the result of success or failure of the biometric authentication The authentication terminal according to Appendix A1. (Appendix A3) A search means for performing a search process on the history database including the data size information of the master biometric information acquired by the acquisition means as a search key, An execution means for executing a process according to the search result of the search process, Further comprising the above The authentication terminal according to Appendix A1 or A2. (Appendix A4) Further comprising a determination means for determining whether or not the attribute information of the user satisfies a predetermined service provision condition, The registration means registers the authentication history information in which the result of the determination is further associated with the data size information in the history database The authentication terminal according to Appendix A3. (Appendix A5) The search means performs the search process before the determination is made, When the search result includes a message indicating successful authentication, the execution means executes a process according to the result of the determination included in the search result The authentication terminal according to Appendix A4. (Appendix A6) The attribute information of the user is further stored in the storage medium, The acquisition means acquires the attribute information from the storage medium, The determination means performs the determination using the attribute information acquired by the acquisition means. The authentication terminal according to Supplementary Note A4 or A5. (Supplementary Note A7) The result of the determination includes the service content provided when the service provision conditions are satisfied. The authentication terminal according to any one of Supplementary Notes A4 to A6. (Supplementary Note A8) The execution means executes, as the process, outputting display information corresponding to the search result. The authentication terminal according to any one of Supplementary Notes A3 to A7. (Supplementary Note A9) The registration means further includes position information capable of specifying the position of the authentication terminal, and registers the authentication history information in the history database as the history data. The authentication terminal according to any one of Supplementary Notes A1 to A8. (Supplementary Note A10) The search means performs the search process before the biometric authentication is performed. When the search result includes a message indicating successful authentication, the execution means executes the process. The authentication terminal according to any one of Supplementary Notes A3 to A8. (Supplementary Note A11) When the authentication success date and time included in the search result is within a predetermined period, the execution means executes the process without performing the biometric authentication on the user. The authentication terminal according to Supplementary Note A10. (Supplementary Note A12) The data size information is numerical information indicating the data size of the master biometric information. The authentication terminal according to any one of Supplementary Notes A1 to A11. (Supplementary Note A13) The acquisition means further includes a calculation means for calculating the data size information from the master biometric information acquired by the acquisition means. The registration means includes the calculated data size information in the authentication history information and registers it in the history database. The authentication terminal according to any one of Supplementary Notes A1 to A11. (Supplementary Note A14) The calculation means calculates, as the data size information, a conversion result obtained by performing a predetermined conversion process on the data size of the master biometric information. The authentication terminal according to Supplementary Note A13. (Supplementary Note A15) The history database is included in a predetermined information system connected to the authentication terminal. The registration means registers the authentication history information in the history database by transmitting a registration request including the authentication history information to the information system. The authentication terminal according to any one of Supplementary Notes A1 to A14. (Supplementary Note B1) An acquisition means for acquiring an authentication result of biometric authentication based on the master biometric information acquired by the authentication terminal from a storage medium storing the master biometric information of the user and the query biometric information acquired from the user by the authentication terminal, and data size information of the master biometric information; A registration means for registering authentication history information associating the authentication result and the data size information in a history database; An authentication history management device comprising the above. (Supplementary Note B2) The authentication result includes a result of success or failure of the biometric authentication. The authentication history management device according to Supplementary Note B1. (Supplementary Note B3) A first search means for performing a search process on the history database including the data size information of the master biometric information acquired by the acquisition means as a search key; An execution means for executing a process according to a search result of the search process; The authentication history management device according to Supplementary Note B1 or B2, further comprising the above. (Supplementary Note B4) The acquisition means further acquires a result of determination as to whether or not the attribute information of the user satisfies a predetermined service provision condition. The registration means registers the authentication history information in which the result of the determination is further associated with the data size information in the history database. The authentication history management device according to appended note B3. (Appended note B5) The apparatus further includes second search means for searching for authentication history information including the result of the determination that satisfies a specific condition from the history database. The execution means executes, as the process, outputting an analysis result based on the authentication history information retrieved by the second search means. The authentication history management device according to appended note B4. (Appended note B6) The first search means performs the search process before the determination is made. When the search result includes a successful authentication, the execution means executes a process according to the result of the determination included in the search result. The authentication history management device according to appended note B4 or B5. (Appended note B7) The storage medium further stores the attribute information of the user. The acquisition means further acquires the attribute information acquired by the authentication terminal from the storage medium. The result of the determination is a result determined using the attribute information acquired by the acquisition means. The authentication history management device according to any one of appended notes B4 to B6. (Appended note B8) The result of the determination includes the service content provided when the service provision condition is satisfied. The authentication history management device according to any one of appended notes B4 to B7. (Appended note B9) The execution means executes, as the process, outputting display information according to the search result. The authentication history management device according to any one of appended notes B3 to B8. (Appended note B10) The registration means registers, in the history database, the authentication history information further including position information capable of specifying the position of the authentication terminal. The authentication history management device according to any one of Appendices B1 to B9. (Appendix B11) The first search means performs the search process before the biometric authentication is performed. When the search result includes a message indicating successful authentication, the execution means executes the process. The authentication history management device according to any one of Appendices B3 to B9. (Appendix B12) When the authentication success date and time included in the search result are within a predetermined period, the execution means executes the process without performing the biometric authentication on the user. The authentication history management device according to Appendix B11. (Appendix B13) The data size information is numerical information indicating the data size of the master biometric information. The authentication history management device according to any one of Appendices B1 to B11. (Appendix B14) The device further includes a calculation means for calculating the data size information from the master biometric information acquired by the acquisition means. The registration means includes the calculated data size information in the authentication history information and registers it in the history database. The authentication history management device according to any one of Appendices B1 to B12. (Appendix B15) The calculation means calculates, as the data size information, a conversion result obtained by performing a predetermined conversion process on the data size of the master biometric information. The authentication history management device according to Appendix B14. (Appendix B16) The history database is included in a predetermined information system connected to the authentication history management device. The registration means registers the authentication history information in the history database by transmitting a registration request including the authentication history information to the information system. The authentication history management device according to any one of Appendices B1 to B15. (Supplementary Note B17) The authentication history management device further includes the history database The authentication history management device according to any one of Supplementary Notes B1 to B15 (Supplementary Note C1) An authentication terminal and a history database are provided The authentication terminal acquires the master biometric information from a storage medium storing the master biometric information of the user registers authentication history information associating the authentication result of biometric authentication based on the query biometric information acquired from the user and the master biometric information, and the data size information of the master biometric information, in the history database An authentication history management system (Supplementary Note D1)(Method of terminal) A computer acquires the master biometric information from a storage medium storing the master biometric information of the user registers authentication history information associating the authentication result of biometric authentication based on the query biometric information acquired from the user and the master biometric information, and the data size information of the master biometric information, in the history database An authentication history management method (Supplementary Note E1)(Method of server) A computer acquires the authentication result of biometric authentication based on the master biometric information acquired by the authentication terminal from a storage medium storing the master biometric information of the user and the query biometric information acquired from the user by the authentication terminal, and the data size information of the master biometric information registers authentication history information associating the authentication result and the data size information in the history database An authentication history management method (Supplementary Note F1)(Program of terminal) A process of acquiring the master biometric information from a storage medium storing the master biometric information of the user, and A process of registering authentication history information associating an authentication result of biometric authentication based on query biometric information acquired from the user and the master biometric information, and data size information of the master biometric information in a history database. An authentication history management program that causes a computer to execute. (Appendix G1) (Server Program) A process of acquiring an authentication result of biometric authentication based on the master biometric information acquired by an authentication terminal from a storage medium storing the master biometric information of the user and query biometric information acquired by the authentication terminal from the user, and data size information of the master biometric information. A process of registering authentication history information associating the authentication result and the data size information in a history database. An authentication history management program that causes a computer to execute. (Appendix H1) Specifying means for specifying first data size information of first master biometric information stored in a storage medium of a user. Search means for performing a search process including the first data size information as a search key on a history database in which authentication history information associating an authentication result of biometric authentication based on collation with second master biometric information and query biometric information and second data size information of the second master biometric information is registered. Execution means for executing a process according to a search result of the search process. An authentication terminal comprising the above. (Appendix H2) The search means performs the search process before the biometric authentication is performed. The execution means executes the process when the search result includes a message indicating successful authentication. The authentication terminal according to Appendix H1. (Appendix I1) A computer Specifies first data size information of first master biometric information stored in a storage medium of a user. For a history database in which authentication history information associating the authentication result of biometric authentication based on the collation of the second master biometric information and the query biometric information with the second data size information of the second master biometric information is registered, a search process including the first data size information as a search key is performed, Execute a process according to the search result of the search process, Biometric authentication history management method. (Appendix J1) A specifying process for specifying the first data size information of the first master biometric information stored in the user's storage medium, For a history database in which authentication history information associating the authentication result of biometric authentication based on the collation of the second master biometric information and the query biometric information with the second data size information of the second master biometric information is registered, a search process including the first data size information as a search key is performed, An execution process for executing a process according to the search result of the search process, A biometric authentication history management program for causing a computer to execute.
[0173] A part or all of the elements (e.g., configurations and functions) described in Appendix A2 to Appendix A15 that are subordinate to Appendix A1 {eg terminal} may also be subordinate to Appendix D1 {eg method} and Appendix F1 {eg program} in the same subordinate relationship as Appendix A2 to Appendix A15. Also, a part or all of the elements (e.g., configurations and functions) described in Appendix B2 to Appendix B17 that are subordinate to Appendix B1 {eg device} may also be subordinate to Appendix E1 {eg method} and Appendix G1 {eg program} in the same subordinate relationship as Appendix B2 to Appendix B17. Also, a part or all of the elements (e.g., configurations and functions) described in Appendix A2 to Appendix A15 that are subordinate to Appendix A1 {eg terminal} may also be subordinate to Appendix H1 {eg terminal}, Appendix I1 {eg method}, and Appendix J1 {eg program} in the same subordinate relationship as Appendix A2 to Appendix A15. In addition, some or all of the elements (e.g., configurations and functions) described in Appendix H2 that are dependent on Appendix H1 {eg, terminal} may also be dependent on Appendix I1 {eg, method} and Appendix J1 {eg, program} in the same dependent relationship as Appendix H2. Some or all of the elements described in any appendix may be applied to various hardware, software, recording means for recording software, systems, and methods. [Explanation of symbols]
[0174] 1000 Certification History Management System U User 1 Authentication terminal 11 Acquisition Department 12 Registration Department 3 Storage medium 30 Master Biometric Information 4 Authentication History DB 40 Authentication History Information 41 Authentication Results 42 Data size information 2000 Certification History Management System 2. Authentication History Management Device 21 Acquisition Department 22 Registration Department 3000 Certification History Management System N Network User U1 User U2 Authentication terminal 100-1 Authentication terminal 100a-1 Personal certificate 31 IC chip 310 Master face image 311 Attribute information 312 Authentication terminal 100-2 Authentication terminal 100a-2 Personal certificate 32 IC chip 320 Master face image 321 Attribute information 322 Authentication terminal 100 Acquisition unit 110 Authentication unit 120 Judgment unit 130 Registration unit 140 Search unit 150 Execution unit 160 Memory 101 Processor 102 Network interface 103 Display 104 Camera 105 Short-range wireless communication interface 106 Authentication history management device 200 Acquisition unit 210 Registration unit 240 Search unit 250 Memory 201 Processor 202 Network interface 203 Authentication history DB 400 Authentication history information 410 Authentication result 411 Data size information 412 Attribute judgment result 413 Authentication history information 420 Authentication history information 430 Authentication history information 440 Authentication history information 450 Authentication history information 460 Authentication history information 470 4n0 Authentication History Information 401 Authentication Result 4011 Execution Date and Time 4012 Authentication Location 4013 Authentication Success / Failure 402 Data Size 403 Attribute Judgment Result 51 Display Information 200a Authentication History Management Device 210a Acquisition Unit 220a Authentication Unit 230a Judgment Unit 240a Registration Unit 250a Search Unit 260a Execution Unit
Claims
1. An acquisition means for acquiring the master biometric information from a storage medium storing the master biometric information of the user; A registration means for registering authentication history information associating an authentication result of biometric authentication based on the query biometric information acquired from the user and the master biometric information, and data size information of the master biometric information in a history database; An authentication terminal comprising the above.
2. The authentication result includes the result of success or failure of the biometric authentication The authentication terminal according to claim 1.
3. A search means for performing a search process on the history database including the data size information of the master biometric information acquired by the acquisition means as a search key; An execution means for executing a process according to the search result of the search process; Further comprising The authentication terminal according to claim 1 or 2.
4. Further comprising a determination means for determining whether or not the attribute information of the user satisfies a predetermined service provision condition, The registration means registers the authentication history information further associating the result of the determination with the data size information in the history database The authentication terminal according to claim 3.
5. The search means performs the search process before the determination is made, When the search result includes a successful authentication, the execution means executes a process according to the result of the determination included in the search result The authentication terminal according to claim 4.
6. The attribute information of the user is further stored in the storage medium, The acquisition means acquires the attribute information from the storage medium, The determination means makes the determination using the attribute information acquired by the acquisition means The authentication terminal according to claim 4.
7. An acquisition means for acquiring an authentication result of biometric authentication based on the master biometric information acquired by an authentication terminal from a storage medium storing the master biometric information of the user and query biometric information acquired from the user by the authentication terminal, and data size information of the master biometric information; A registration means for registering authentication history information associating the authentication result and the data size information in a history database; An authentication history management device comprising the above.
8. Comprising an authentication terminal and a history database, The authentication terminal Acquires the master biometric information from a storage medium storing the master biometric information of the user, Register authentication history information, which associates the authentication result of biometric authentication based on the query biometric information obtained from the user and the master biometric information, with the data size information of the master biometric information, in the history database. An authentication history management system.
9. A computer obtains the master biometric information from a storage medium storing the master biometric information of a user, and registers authentication history information, which associates the authentication result of biometric authentication based on the query biometric information obtained from the user and the master biometric information, with the data size information of the master biometric information, in a history database. An authentication history management method.
10. A process of obtaining the master biometric information from a storage medium storing the master biometric information of a user, and a process of registering authentication history information, which associates the authentication result of biometric authentication based on the query biometric information obtained from the user and the master biometric information, with the data size information of the master biometric information, in a history database, An authentication history management program that causes a computer to execute.
Citation Information
Patent Citations
Application receiving apparatus, application receiving system, method, and program
JP2022169476A
Cited By
Information processing apparatus for verifying biometric authentication scores, information processing method, and non-transitory recording medium
US12645769B2