Information processing system, terminal device, information processing method, and program

The information processing system enhances user authentication in financial systems by using biometric data and location/time-based permissions to prevent fraud, ensuring reliable execution of specific processes.

JP2025119198APending Publication Date: 2025-08-14THE JAPAN RES INST
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024013941
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-01
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Existing user authentication systems, particularly in large-scale financial systems, face challenges in enhancing security against fraudulent activities like user impersonation without requiring significant capital investment.

Method used

An information processing system that includes a terminal device with a first acquisition unit for processing information, an authentication unit for user verification using biometric data, a post-authentication information output unit, and a judgment unit to determine permission conditions, which can also utilize location and time information to enhance authentication reliability.

Benefits of technology

The system enables easy and reliable user authentication, preventing fraud by allowing specific processes only when permission conditions are met, including location and time constraints.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025119198000001_ABST
    Figure 2025119198000001_ABST
Patent Text Reader

Abstract

To take measures against a fraud, such as impersonation of a user.SOLUTION: An information processing system 1 includes: a first acquisition unit 643 which acquires processing information for use in identification processing; an authentication unit 651 which performs authentication of a user who requests execution of the identification processing, from biometric information acquired from the user; a post-authentication information output unit 655 which outputs post-authentication information including the processing information acquired by the first acquisition unit 643, after the authentication of the authentication unit 651; a second acquisition unit 143 which acquires the post-authentication information; a determination unit 151 which determines whether the post-authentication information satisfies a predetermined permission condition; and a permission information output unit 155 which outputs, when the determination unit 151 determines that the permission condition is satisfied, permission information for permitting execution of the identification processing to an identification processing apparatus 910. The information processing system 1 enables easy and reliable authentication of a specific user and enables execution of identification processing related to the user.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system, a terminal device, an information processing method, and a program capable of authenticating a user. [Background technology]

[0002] BACKGROUND ART Conventionally, there is an information processing system configured to authenticate a user that uses biometric information of the user (for example, see Patent Document 1 below). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent No. 6617086 Summary of the Invention [Problem to be solved by the invention]

[0004] In systems that perform specific processing using user information, it is becoming increasingly important to develop countermeasures against fraudulent activities such as user impersonation. The user authentication system described in Patent Document 1 performs first-stage authentication using a location identifier and second-stage authentication using the user's biometric information. However, there are cases where it is difficult to introduce such a user authentication system into existing systems that use devices that have been in use up until now. In particular, in relatively large-scale systems that use specific processing devices that perform specific processing related to financial institutions, for example, it is extremely important to take measures to enhance the security of user authentication, but there is a problem in that this requires a large amount of capital investment.

[0005] Therefore, an object of the present invention is to provide an information processing system, a terminal device, an information processing method, and a program that can easily and reliably authenticate a specific user and then execute specific processing related to that user. [Means for solving the problem]

[0006] The information processing system of the first invention is an information processing system that includes a terminal device and an information processing device, and is capable of outputting information to a specific processing device that executes a specific processing, and is equipped with: a first acquisition unit that is provided in the terminal device and acquires processing information to be used for the specific processing; an authentication unit that is provided in the terminal device and authenticates a user who instructs the execution of the specific processing using biometric information acquired from the user; a post-authentication information output unit that is provided in the terminal device and outputs post-authentication information including the processing information acquired by the first acquisition unit after authentication is performed by the authentication unit; a second acquisition unit that is provided in the information processing device and acquires the post-authentication information; a judgment unit that is provided in the information processing device and judges whether the post-authentication information satisfies specified permission conditions; and a permission information output unit that is provided in the information processing device and, when the judgment unit judges that the permission conditions are satisfied, outputs permission information to the specific processing device to permit the execution of the specific processing.

[0007] With this configuration, it is possible to easily and reliably authenticate a specific user and then execute a specific process related to that user.

[0008] In addition, the information processing system of the second invention, compared to the first invention, is an information processing system that is provided in a terminal device and includes a location information acquisition unit that acquires location information regarding the location of the terminal device, and a post-authentication information output unit that outputs post-authentication information including the location information.

[0009] With this configuration, the location of the terminal device can be used to make decisions regarding the permission conditions.

[0010] Furthermore, the information processing system of the third invention is an information processing system in which, compared to the second invention, the permission conditions include at least one of the following conditions: the location information is within an area associated with the terminal device, the area associated with the processing information, and the area associated with an external device used to instruct the specific processing.

[0011] With this configuration, it is possible to perform specific processing after more reliably authenticating the user in order to prevent fraud such as impersonation.

[0012] Furthermore, the information processing system of the fourth invention is an information processing system in which, compared to any of the first to third inventions, the permission information output unit obtains time information regarding the time during which execution of a specific process is permitted based on the judgment result of the judgment unit, and outputs the permission information based on the time information.

[0013] With this configuration, the time during which execution of the specific process is permitted can be set based on the determination result of the determination unit.

[0014] Furthermore, the information processing system of the fifth invention is an information processing system in which, compared to any of the first to fourth inventions, the permission information output unit transmits second permission information to an external device other than the specific processing device to permit the external device to execute a second specific processing when the processing information acquired by the first acquisition unit satisfies a predetermined processing condition.

[0015] With this configuration, it is possible to easily and reliably authenticate a specific user, and then cause the external device to execute a second specific process that is different from the specific process.

[0016] Furthermore, the terminal device of the sixth invention is a terminal device that, together with an information processing device, constitutes an information processing system capable of outputting information to a specific processing device that executes a specific processing, and is equipped with a first acquisition unit that acquires processing information to be used for the specific processing, an authentication unit that authenticates a user who instructs the execution of the specific processing using biometric information acquired from the user, and a post-authentication information output unit that outputs post-authentication information including the processing information acquired by the first acquisition unit after authentication is performed by the authentication unit, and the information processing device is a terminal device that is equipped with a second acquisition unit that acquires the post-authentication information, a judgment unit that judges whether the post-authentication information satisfies specified permission conditions, and a permission information output unit that outputs permission information to the specific processing device to permit the execution of the specific processing when the judgment unit judges that the permission conditions are satisfied.

[0017] With this configuration, it is possible to easily and reliably authenticate a specific user and then execute a specific process related to that user. [Effects of the Invention]

[0018] According to the present invention, it is possible to easily and reliably authenticate a specific user and then execute a specific process related to that user. [Brief explanation of the drawings]

[0019] [Figure 1] FIG. 1 is a diagram showing an overview of an information processing system according to an embodiment of the present invention. [Figure 2] FIG. 1 is a block diagram showing an example of the configuration of an information processing device and a terminal device of the information processing system. [Figure 3] FIG. 10 is a diagram showing an example of pre-registration information used in the information processing device; [Figure 4] FIG. 10 is a diagram showing an example of destination information used in the information processing apparatus; [Figure 5] A flowchart showing an example of the operation of the terminal device [Figure 6] A flowchart showing an example of the operation of the information processing device [Figure 7] FIG. 10 is a diagram illustrating a specific example of the operation of the information processing system. [Figure 8] FIG. 10 is a diagram illustrating a specific example of user authentication performed using the terminal device. [Figure 9] FIG. 10 is a diagram illustrating a specific example of the operation of an information processing system according to a modified example of the present embodiment. [Figure 10] Overview of the computer system in the above embodiment [Figure 11] Block diagram of the computer system DETAILED DESCRIPTION OF THE INVENTION

[0020] Hereinafter, an embodiment of an information processing system and the like will be described with reference to the drawings.

[0021] The terms used below are generally defined as follows: The meanings of these terms should not always be interpreted as shown here, but rather, when they are individually explained below, they should be interpreted in light of that explanation.

[0022] An identifier for a certain item is a character or code that uniquely identifies that item. An identifier could be, for example, an ID, but any type of information can be used as long as it can identify the corresponding item. In other words, an identifier could be the name of the thing it represents, or a combination of codes that uniquely identify the thing.

[0023] "Acquisition" may include acquiring information entered by a user or the like, or acquiring information stored in another device. "Acquisition" of information stored in another device may include acquiring information stored in another device via an API or the like, or acquiring the contents of a document file (including the contents of a web page) provided by another device by scraping or the like. It may also include acquiring information in a format different from the original information, such as acquiring information by performing optical character reading on an image file.

[0024] Outputting information is a concept that includes displaying on a display, projecting using a projector, printing on a printer, outputting sound, transmitting to an external device, storing on a recording medium, transferring the processing results to another processing device or another program, etc. Specifically, it includes, for example, making it possible to display information on a web page, transmitting as e-mail, etc., and outputting information for printing.

[0025] The concept of accepting information includes accepting information entered from input devices such as a keyboard, mouse, or touch panel, receiving information transmitted from other devices via wired or wireless communication lines, and accepting information read from recording media such as optical disks, magnetic disks, and semiconductor memories.

[0026] (Embodiment)

[0027] An overview of this embodiment is as follows: An information processing system is capable of outputting information to a specific processing device that executes a specific process. The information processing system authenticates a user who instructs the execution of a specific process using biometric information acquired from the user. After authentication, the information processing system outputs predetermined post-authentication information including processing information to be used for the specific process, determines whether the post-authentication information satisfies predetermined permission conditions, and outputs permission information for permitting the execution of the specific process if it is determined that the permission conditions are satisfied. In this embodiment, for example, user authentication and output of post-authentication information are performed on a terminal device used by the user, and determination of whether the post-authentication information satisfies the permission conditions and output of permission information are performed on the information processing device.

[0028] The terminal device may acquire location information and output the information after authentication. The permission condition may include at least one of the following: the location information is within an area associated with the terminal or the processing information; and the location information is within an area associated with an external device used to instruct the specific process. Furthermore, a time period for permitting execution of the specific process may be set based on a determination result of whether the post-authentication information satisfies a predetermined permission condition. Furthermore, the information processing system may be capable of transmitting permission information to an external device different from the specific processing device when it determines that the processing information satisfies a predetermined processing condition.

[0029] The information processing system configured in this manner will be described below.

[0030] FIG. 1 is a diagram showing an overview of an information processing system 1 according to an embodiment of the present invention.

[0031] The information processing system 1 includes an information processing device 100 and a terminal device 600. The information processing device 100 and the terminal device 600 can communicate with each other via a network such as the Internet. However, the configuration of the information processing system 1 is not limited to this. The number of devices included in the information processing system 1 is not important, and other devices may also be included in the information processing system 1.

[0032] A user of the information processing system 1 can use the information processing system 1 by using a terminal device 600. Although a mobile information terminal device such as a smartphone is shown as the terminal device 600 in FIG. 1, the terminal device 600 is not limited to such a mobile information terminal device. The terminal device 600 may be, for example, a personal computer (PC) such as a laptop computer, or other devices such as a tablet-type information terminal device. In the following example, the description will be given assuming that a mobile information terminal device such as a smartphone is used as the terminal device 600.

[0033] In this embodiment, the information processing system 1 is used together with a specific processing device 910 that performs specific processing. The information processing system 1 can also be used together with a second external device 950.

[0034] The specific processing is, for example, a predetermined processing performed for each user. In other words, the specific processing is processing performed after identifying the user involved in the processing. The specific processing may be, for example, processing performed when providing a service unique to each of two or more predetermined users. The specific processing is, for example, processing related to finance or payment, but may also be processing related to a predetermined application process or management of specific user information. More specifically, for example, the specific processing is processing related to bank transfers, online banking, payments using credit cards, etc., but is not limited to these, and may also be processing related to online application procedures performed for predetermined institutions, processing performed when using various web services, etc.

[0035] The specific processing device 910 is a device that performs specific processing. The specific processing device 910 is, for example, a server device, but is not limited to this. For example, when an instruction based on a user operation is received, the specific processing device 910 can execute specific processing in accordance with the instruction. The specific processing device 910 is a device having a known configuration for performing specific processing.

[0036] A specific external device 920, which is an external device, may be used to execute the specific process in the specific processing device 910. The specific external device 920 is, for example, a device that receives input of information related to a user and issues instructions to cause the specific external device 920 to execute the specific process based on the received information. In other words, the specific external device 920 can be said to be an external device used to issue instructions for the specific process. The specific external device 920 can transmit information to the specific processing device 910 via a network such as the Internet or a local area network, but is not limited to this.

[0037] In this embodiment, for example, when a process related to a bank transfer or online banking is performed as the specific process, the specific processing device 910 can be a server device belonging to an administrative center or the like participating in a nationwide bank data communication system. In this case, the specific external device 920 can be, for example, an automated teller machine or a terminal for using online banking. Furthermore, for example, when a process related to a payment using a credit card is performed as the specific process, the specific processing device 910 can be a server device of a payment service provider. In this case, the specific external device 920 can be, for example, a credit card payment terminal or a terminal for reading credit card information or the like to make an online payment.

[0038] The specific processing device 910 may be the same device as the information processing device 100. That is, one device may have both the function of the specific processing device 910 and the function of the information processing device 100. Furthermore, the specific external device 920 may be the same device as the terminal device 600. One device may have both the function of the specific external device 920 and the function of the terminal device 600.

[0039] The second external device 950 is a device that performs a process different from the specific process (hereinafter, sometimes referred to as the second specific process). The second specific process is a process that is performed after identifying a user involved in the process, similar to the specific process, and may be a process that is not performed by the specific processing device 910. For example, when an instruction based on a user's operation is received, the second external device 950 can execute the second specific process in accordance with the instruction. The second external device 950 is a device having a known configuration for performing the second specific process. For example, assume that the specific processing device 910 is a server that manages an account at a specific first bank, and the specific process involves a withdrawal from the account at the first bank. In such a case, the second external device 950 may be a server that manages an account at a specific second bank different from the first bank, and the second specific process involves a withdrawal from the account at the second bank. Furthermore, in the above case, the second external device 950 may be a server that performs a payment process using a specific credit card, and the second specific process involves a payment process using the credit card.

[0040] In this embodiment, the specific processing device 910 is configured to receive instructions for executing a specific process using the specific external device 920, and also to be able to execute the specific process when permission information output from the information processing system 1 is acquired as described below. The permission information can be said to be information for permitting the execution of the specific process. The permission information includes information corresponding to a target user, and accordingly, the specific process corresponding to the user can be executed.

[0041] Furthermore, the second external device 950 is configured to receive instructions for executing a second specified process using a device similar to the specified external device 920, and is also configured to be able to execute the second specified process when it acquires second permission information output from the information processing system 1, as described below. The second permission information may be said to be information for permitting the execution of the second specified process. The second permission information includes information corresponding to a target user, and accordingly, the second specified process corresponding to the user can be executed.

[0042] The information processing system 1 is communicably connected directly or through a network or the like so that information can be transmitted to the specific processing device 910 and the second external device 950. The connection method is not important.

[0043] FIG. 2 is a block diagram showing an example of the configuration of the information processing device 100 and the terminal device 600 of the information processing system 1. As shown in FIG.

[0044] The information processing device 100 includes a storage unit 110, a receiving unit 120, a reception unit 130, a processing unit 140, and a transmission unit 170. The information processing device 100 is, for example, a server device.

[0045] The terminal device 600 includes a terminal storage unit 610, a terminal receiving unit 620, a terminal acceptance unit 630, a terminal processing unit 640, a terminal output unit 660, a terminal transmission unit 670, and a sensor unit 680. The terminal output unit 660 includes a display unit 661 such as a liquid crystal display.

[0046] The storage unit 110 and the terminal storage unit 610 are preferably non-volatile recording media, but can also be realized as volatile recording media. Information acquired by each device is stored in these, but the process by which the information is stored is not limited to this. For example, information may be stored via a recording medium, information transmitted via a communication line, or information input via an input device.

[0047] The processing unit 140 and the device processing unit 640 can usually be realized by an MPU, memory, etc. The processing procedures of the processing unit 140 and the device processing unit 640 are usually realized by software, and the software is recorded on a recording medium such as a ROM. However, they may also be realized by hardware (dedicated circuitry).

[0048] The input means that can be used to input information that can be accepted by acceptance unit 130 and terminal acceptance unit 630 may be any means, such as a numeric keypad, keyboard, mouse, menu screen, etc. Acceptance unit 130 and terminal acceptance unit 630 can be realized by a device driver for an input means such as a numeric keypad or keyboard, or control software for a menu screen.

[0049] The receiving unit 120 and the terminal receiving unit 620 are usually realized by wireless or wired communication means, but may also be realized by means for receiving broadcasts.

[0050] The transmitting unit 170 and the terminal transmitting unit 670 are usually realized by wireless or wired communication means, but may also be realized by broadcasting means.

[0051] The terminal device 600 is configured to be able to display various information on the display unit 661 and to accept operations by a user. The terminal device 600 is configured to be able to receive information transmitted from an external device such as the information processing device 100 via a network such as the Internet. The terminal device 600 is also configured to be able to transmit information to an external device via the network in response to, for example, a user operation or the operation of predetermined software or the like.

[0052] In this embodiment, the components of the information processing device 100 and the terminal device 600 are configured as follows, for example.

[0053] The terminal storage unit 610 stores programs that can be executed by the computer of the terminal device 600, and information that is used when the terminal device 600 operates. In this embodiment, the terminal storage unit 610 is provided with an authentication information storage unit 611 and a terminal identifier storage unit 613.

[0054] The authentication information storage unit 611 stores, for example, information used to authenticate a user. In this embodiment, biometric authentication information may be used to authenticate a user using the user's biometric information. Examples of biometric authentication information include the user's fingerprint, blood vessel pattern, and facial recognition data. These are used to verify an individual's biometric characteristics and perform authentication. The biometric authentication information may be, for example, information acquired in advance from the user himself / herself. Note that information such as a password and answers to predetermined questions may also be stored as information used to authenticate a user.

[0055] A terminal identifier is stored in the terminal identifier storage unit 613. The terminal identifier is information that can identify the terminal device 600, but is not limited to this. It is also possible that other information cannot be written to the terminal identifier storage unit 613.

[0056] The terminal identifier can be said to be information that identifies the terminal device 600 that the user normally uses. In this embodiment, the terminal identifier is used to determine whether or not to permit a specific process, as will be described later.

[0057] In addition to the above information, the terminal storage unit 610 may store, for example, user information. The user information is information about a user who uses the terminal device 600. The user information may include various types of information. For example, the user information may be information about the user received from the information processing device 100, or information about the user acquired by the terminal device 600 as described below.

[0058] The user information is information that can be associated with a user identifier that identifies a user who uses the terminal device 600. The user information may be associated with a terminal identifier. Note that the terminal identifier may be used as the user identifier.

[0059] In this embodiment, user information such as the user's current location is stored in the terminal storage unit 610. The user's current location is, for example, location information identified using the detection result of the sensor unit 680, but may also be location information identified by other methods.

[0060] The terminal receiving unit 620 receives information transmitted from the information processing device 100 or other devices via a network. The terminal receiving unit 620 stores the received information in, for example, the terminal storage unit 610 so that the device processing unit 640 and the like can acquire the information.

[0061] The terminal reception unit 630 receives various input operations for the terminal device 600 by a user of the terminal device 600. The operations are performed, for example, using a touch panel provided on the display unit 661, but may also be performed using other input devices (not shown). The terminal reception unit 630 may also receive input operations using voice input through a microphone, for example.

[0062] It may be considered that the terminal accepting unit 630 accepts the information received by the terminal receiving unit 620 as information input to the terminal device 600. In other words, input of information to the terminal device 600 may be interpreted as meaning that the information is indirectly input to the terminal device 600 by the user via the information processing device 100 or the like, or may be interpreted as meaning that the information is directly input to the terminal device 600 by the user using an input means. Also, input of information to the terminal device 600 may be considered as the user providing information to the terminal device 600 by executing a program that automatically generates information or by providing various information to a program to make it function.

[0063] The terminal processing unit 640 performs various information processing operations using each unit of the terminal device 600. In this embodiment, the terminal processing unit 640 includes a first acquisition unit 643, a position information acquisition unit 645, an authentication unit 651, and a post-authentication information output unit 655.

[0064] The first acquisition unit 643 acquires processing information to be used for the specific process. In this embodiment, the processing information is, for example, information that identifies information about a user related to the specific process to be executed by the specific processing device 910. More specifically, it can be, for example, information that identifies the means used by the user for payment. For example, the processing information may be information that identifies the user's bank account, other information used to make a payment to the bank account, or information for making a payment using the user's credit card, electronic money, or the like. In other words, the processing information can be information corresponding to a processing medium, such as a cash card or passbook, used when transferring money from a bank account or withdrawing cash. Furthermore, for example, when making a payment using a credit card, the processing information can be information corresponding to the credit card, or the like. In these cases, the processing information can be, for example, an identifier that identifies the processing medium, or information identified by or recorded on the processing medium.

[0065] The first acquisition unit 643 may also acquire, as processing information, information used in the second specified process to be executed by the specified external device 920.

[0066] The acquisition of the processing information is performed, for example, by acquiring information from a processing medium using a sensor unit 680 provided in the terminal device 600. However, without being limited to this, the first acquisition unit 643 may acquire information read by another device or information stored in another device that can communicate with the terminal device 600.

[0067] Furthermore, for example, the processing information may be stored in advance as user information in the terminal storage unit 610. In this case, the first acquisition unit 643 can acquire the stored information.

[0068] The location information acquisition unit 645 acquires location information relating to the location of the terminal device 600. The location information is acquired using the sensor unit 680, for example.

[0069] The authentication unit 651 is configured to authenticate a user who instructs the execution of a specific process by using biometric information acquired from the user. The authentication unit 651 is configured, for example, to acquire biometric information from the user using the sensor unit 680, and to perform authentication by comparing the acquired information with biometric authentication information stored in the authentication information storage unit 611. This comparison process may be performed by a known method.

[0070] When the authentication unit 651 authenticates the user (when the authentication is successful), the post-authentication information output unit 655 outputs the post-authentication information. The post-authentication information is information including the processing information acquired by the first acquisition unit 643. In this embodiment, the post-authentication information may include, for example, a terminal identifier together with the processing information. Instead of the terminal identifier, a user identifier or the like for identifying the user may be included. Furthermore, information such as a passphrase entered by the user may be included in the post-authentication information. This information, together with the information acquired by the first acquisition unit 643, may be referred to as processing information. The post-authentication information may be information acquired by performing encoding or the like based on the processing information or the like.

[0071] In this embodiment, the post-authentication information output unit 655 may output post-authentication information including location information. For example, the location information may be information detected by the sensor unit 680 when authentication is performed.

[0072] The post-authentication information output unit 655 outputs the post-authentication information, for example, by transmitting the post-authentication information to the information processing device 100 using the terminal transmission unit 670. Note that the method for outputting the post-authentication information is not limited to this, and the post-authentication information may be stored in the terminal storage unit 610 or the like, or displayed on the display unit 661. The post-authentication information output unit 655 may output the post-authentication information so that the information processing device 100 can acquire it.

[0073] The terminal output unit 660 has a display unit 661. The terminal output unit 660 outputs information, for example, by displaying a screen on the display unit 661. Note that the method of outputting information is not limited to this, and the information may be output by outputting sound or the like from a speaker or the like.

[0074] The terminal transmitting unit 670 transmits information acquired by, for example, the terminal processing unit 640 via the network.

[0075] The sensor unit 680 has, for example, an illuminance sensor, a camera, a position information sensor capable of identifying a position using a GPS, etc. The sensor unit 680 can detect information related to the surrounding situation and output the detection results. Note that the types of the sensor unit 680 are not limited to these, and a microphone, an acceleration sensor, an air pressure sensor, etc. may also be provided.

[0076] In this embodiment, the sensor unit 680 has a sensor for acquiring specific biometric information of the user who is the subject of authentication, such as a fingerprint scanner, a face recognition camera, a blood vessel pattern reader, etc. That is, when authenticating a user, the user can use the sensor unit 680 to have the processing unit 140 acquire his / her own biometric information and execute authentication.

[0077] Furthermore, in this embodiment, the sensor unit 680 may have, for example, a sensor for acquiring the processing information from a processing medium (such as a credit card) owned by the user. For example, an RFID chip or the like on which the processing information is recorded may be embedded in the processing medium, and the sensor unit 680 may have a module for reading it. In this case, the first acquisition unit 643 can acquire the processing information using the sensor unit 680.

[0078] The information processing device 100 is configured to be capable of communicating with, for example, a terminal device 600 or an external device (not shown), and to perform information processing using information transmitted from the terminal device 600 or the external device, and to transmit information to the terminal device 600 or the external device.

[0079] The storage unit 110 stores various types of information used by the information processing device 100. For example, information acquired by the information processing device 100, information output by the information processing device 100, etc. may be stored. In addition, programs executed by the information processing device 100, etc. may also be stored.

[0080] In this embodiment, storage unit 110 includes pre-registration information storage unit 115 and destination information storage unit 117 .

[0081] The pre-registration information storage unit 115 stores pre-registration information related to each of two or more users who use the information processing system 1. The pre-registration information includes, for example, the terminal identifier of the terminal device 600 used by the user. The pre-registration information may also include information related to the processing information used by the user. For example, the pre-registration information may include information related to a bank account number or credit card information used to execute a specific process performed using the information processing system 1. The pre-registration information is stored in association with, for example, a user identifier that identifies each user, but is not limited to this. The terminal identifier of each user may be used as the user identifier that identifies each user. It may also be interpreted that the account number, information related to the credit card, etc. are used as the user identifier for each specific process.

[0082] FIG. 3 is a diagram showing an example of pre-registration information used in the information processing device 100. As shown in FIG.

[0083] In the example shown in the figure, the pre-registration information includes, for example, a terminal identifier (terminal ID) and processing information associated with a user identifier (user ID). Note that information relating to two or more different specific processes may be stored as the processing information.

[0084] 2, the destination information storage unit 117 stores destination information used for transmitting the permission information or the second permission information to the specified processing device 910 or the second external device 950. For example, the destination information storage unit 117 stores information indicating an end point for accepting the permission information or the like in the specified processing device 910 or the like, and an address of the specified processing device 910 or the like. The information processing device 100 can use this information to transmit the permission information or the like to the specified processing device 910 or the like.

[0085] In this embodiment, the destination information is stored in association with, for example, matching information related to the processing information. That is, when the processing information corresponds to matching information, it is possible to identify the destination information corresponding to the matching information. This makes it possible to transmit permission information, etc. to the specified processing device 910 or the second external device 950, which is a predetermined destination, according to the processing information.

[0086] FIG. 4 is a diagram showing an example of destination information used in the information processing device 100. As shown in FIG.

[0087] In the example shown in the figure, the destination information is, for example, endpoint information for the specific processing device 910 and the second external device 950, and is shown in association with matching information. The matching information can be, for example, various types of information that can be used to determine whether or not the information matches the processing information. The matching information can also be considered a condition for determining the destination.

[0088] Returning to FIG. 2, the receiving unit 120 receives information transmitted from another device. The receiving unit 120 stores the received information in, for example, the storage unit 110. The receiving unit 120 can store each piece of transmitted information in the storage unit 110 in association with a user identifier. When receiving this information from the terminal device 600, the receiving unit 120 can identify the user identifier of the user involved in the transmission based on the transmitted information.

[0089] The reception unit 130 receives information input using an input means (not shown) connected to the information processing device 100. The reception unit 130 stores the received information in the storage unit 110, for example. The input means may be any means, such as a numeric keypad, keyboard, mouse, or menu screen. The reception unit 130 may also receive information input by an input operation (including, for example, information read by a device) performed using a reading device (for example, a code reader) connected to the information processing device 100.

[0090] Note that the accepting unit 130 may be considered to accept the information received by the receiving unit 120 as information input to the information processing device 100. In other words, inputting information to the information processing device 100 may be interpreted as meaning that the information is indirectly input to the information processing device 100 by the user via the terminal device 600 or the like, or may be interpreted as meaning that the information is directly input to the information processing device 100 by the user using an input means. Furthermore, inputting information to the information processing device 100 may be considered to mean that the user provides information to the information processing device 100 by executing a program that automatically generates information or by providing various information to a program to make it function.

[0091] The processing unit 140 has a second acquisition unit 143, a determination unit 151, and a permission information output unit 155. The processing unit 140 performs various types of processing. The various types of processing are, for example, processing performed by each unit of the processing unit 140 as follows.

[0092] The second acquiring unit 143 acquires the post-authentication information transmitted from the terminal device 600 and received by the receiving unit 120 .

[0093] The determination unit 151 determines whether the post-authentication information satisfies a predetermined permission condition. The predetermined permission condition may be, for example, that a combination of a terminal identifier and processing information that matches pre-registered pre-registration information has been transmitted. In this case, the determination unit 151 determines, for example, whether the combination of a terminal identifier and processing information included in the post-authentication information matches the combination of a terminal identifier and processing information stored in the pre-registration information storage unit 115. If they match, it can be determined that the predetermined permission condition is satisfied.

[0094] The permission conditions are not limited to this, and may include, for example, a condition related to the location information included in the post-authentication information.

[0095] That is, for example, the permission condition may be that the location is within an area associated with the terminal device 600. For example, the user of the terminal device 600 may register in advance a location where the user is often present, and when the location information corresponds to an area within a predetermined range from the location, it may be determined that the condition related to the location information is satisfied. More specifically, for example, the user of the terminal device 600 may register in advance the location of his or her home, and when the post-authentication information includes location information indicating the home, it may be determined that the permission condition related to the location information is satisfied.

[0096] Furthermore, for example, the permission condition may be that the location information is within an area associated with the processing information. For example, if the processing information is information about a specific bank, and it is possible to determine that the location information is in a location corresponding to the location of the bank's head office or branch office, it may be determined that the condition regarding the location information is satisfied.

[0097] Furthermore, for example, the permission condition may be that the device is within an area associated with the specific external device 920 used to instruct the specific process. For example, if it can be determined that the device is in a position corresponding to the position of a pre-specified specific external device 920 or the position of a specific external device 920 that can be identified using processing information, it may be determined that the condition related to the location information is met. More specifically, for example, if user authentication using the terminal authentication 600 is performed near a specific station (the position can be identified based on location information), and an instruction for the specific process is given using a specific external device 920 that is near the specific station, it may be determined that the permission condition related to the location information is met.

[0098] When the determination unit 151 determines that the permission conditions are satisfied, the permission information output unit 155 outputs permission information for permitting the execution of the specified process. The permission information is output to the specified processing device 910. Here, the permission information output unit 155 can output the permission information using the destination information stored in the destination information storage unit 117. For example, the permission information output unit 155 identifies matching information stored in the destination information storage unit 117 that corresponds to the processing information included in the post-authentication information. Then, the permission information output unit 155 outputs the permission information using the destination information corresponding to the identified matching information. For example, assume that the specified processing device 910 is associated with the first matching information and the second matching information is associated with the second external device 950. In this case, if the processing information corresponds to the first matching information, the permission information is output to the specified processing device 910, and if it corresponds to the second matching information, the permission information (which can be considered second permission information in this case) is output to the second external device 950. In other words, in the latter case, when the processing information satisfies a predetermined processing condition, the permission information output unit 155 transmits the second permission information to a second external device 950 different from the specified processing device 910. In this case, the predetermined processing condition is that the processing information corresponds to the second matching information.

[0099] The transmitting unit 170 transmits the information via the network to other devices constituting the information processing system 1. The transmitting unit 170 transmits the information to, for example, the terminal device 600. In other words, the transmitting unit 170 outputs the information to, for example, the terminal device 600.

[0100] Next, an example of the operation of the information processing device 100 performed when a user uses the information processing system 1 according to this embodiment will be described. In this embodiment, a user who intends to execute a specific process can, for example, use the terminal device 600 to run a specific application or access the information processing device 100, and then perform other operations necessary for the specific process, thereby causing the specific processing device 910 or the like to execute the specific process. Note that the specific application may be, for example, a dedicated application that operates using information transmitted from the information processing device 100, or a web browser or the like that displays web applications provided in the information processing device 100 in a usable manner.

[0101] In this embodiment, the information processing system 1 is typically used as follows. That is, a user uses the terminal device 600 to read processing information and perform user authentication operations with the aim of performing a specific process. Then, post-authentication information is transmitted from the terminal device 600 to the information processing device 100. The information processing device 100 uses the post-authentication information to output permission information. This makes it possible for the user to perform a required operation, etc., to execute the specific process.

[0102] When the information processing system 1 operates in this manner, the terminal device 600 and the information processing device 100 perform various operations, for example, as follows. These operations are performed by the device processing unit 640 and the processing unit 140 executing control operations and the like using each unit. Note that the user has previously registered in the information processing device 100 a combination of the terminal identifier of his / her own terminal device 600 and processing information to be used for a specific process.

[0103] FIG. 5 is a flowchart showing an example of the operation of the terminal device 600.

[0104] For example, when a user issues an instruction to start an operation for executing a specific process by running a predetermined application on the terminal device 600, the following process is performed.

[0105] (Step S11) The terminal processing unit 640 acquires processing information.

[0106] (Step S12) The terminal processing unit 640 acquires the location information of the terminal device 600.

[0107] (Step S13) The device processing unit 640 performs user authentication. For example, the device processing unit 640 acquires biometric information of the user and compares it with the biometric authentication information stored in the authentication information storage unit 611 to perform authentication.

[0108] (Step S14) The terminal processing unit 640 determines whether or not the user authentication has been successful. If it is determined that the user authentication has been successful, the process proceeds to step S15; if not, the process ends.

[0109] (Step S15) The terminal processing unit 640 outputs the post-authentication information. The post-authentication information is transmitted to the information processing device 100.

[0110] FIG. 6 is a flowchart showing an example of the operation of the information processing device 100.

[0111] (Step S31) The processing unit 140 determines whether or not post-authentication information has been received from the terminal device 600. If it is determined that post-authentication information has been received, the processing proceeds to step S32; if not, the processing of step S31 is executed again.

[0112] (Step S32) Processing unit 140 uses the received post-authentication information to determine whether the permission conditions are met. If it is determined that the permission conditions are met, the process proceeds to step S34; if not, the process proceeds to step S33.

[0113] (Step S33) The processing unit 140 outputs error information. The error information may include information that the permission conditions were not met, that the permission information was not sent, that the user is in a state where the specific process cannot be executed, or that user authentication or the like should be performed again so that the permission conditions are met. The error information may be transmitted to the terminal device 600, for example, and output to the display unit 661 or the like in the terminal device 600 so that the user can be made aware of the error information. Once the error information has been output, the process returns to step S31.

[0114] (Step S34) The processing unit 140 identifies the destination information by using the post-authentication information. That is, by identifying matching information corresponding to the processing information from the information stored in the destination information storage unit 117, it is possible to identify the destination information associated with the matching information.

[0115] (Step S35) The processing unit 140 uses the destination information to transmit the permission information, thereby transmitting the permission information to an appropriate external device.

[0116] When the process of step S35 is completed, the series of operations ends.

[0117] Next, a specific example of the operation of the information processing system 1 according to this embodiment will be described.

[0118] In the following specific example, it is assumed that a user uses his / her own cash card at an automated teller machine to execute a specific process such as withdrawing money from his / her own bank account.

[0119] FIG. 7 is a diagram illustrating a specific example of the operation of the information processing system 1. In FIG.

[0120] 7, an automated teller machine is shown as the specific external device 920, and a host device that manages each bank account is shown as the specific processing device 910. A user can use the information processing system 1 and the automated teller machine as follows, using a processing medium C (card C), for example, a cash card.

[0121] (Step S1) First, before carrying out a transaction using the specific external device 920, the user operates the terminal device 600 to perform user authentication.

[0122] FIG. 8 is a diagram for explaining a specific example of user authentication performed using the terminal device 600. In FIG.

[0123] As shown in the figure, first, the user performs a predetermined operation to start the execution of a specific process, for example, using the terminal device 600 (step S101). More specifically, for example, the user performs an operation to select a menu item for performing the specific process from a menu screen of an application for internet banking.

[0124] Next, the user acquires processing information by reading card C using terminal device 600 (step S102). Here, for example, an operation is performed to read the IC chip embedded in card C by contactless communication.

[0125] Next, the user uses the terminal device 600 to read biometric information for biometric authentication (step S103). Here, for example, an operation for reading the user's fingerprint is performed. Guidance information for reading the biometric information is output from the terminal device 600 to the user, and the user follows the guidance to read the biometric information.

[0126] Once the processing information has been acquired and the biometric information has been read in this way, biometric authentication is performed using the read biometric information. Returning to FIG.

[0127] (Step S2) When user authentication using the terminal device 600 is successful, post-authentication information is transmitted from the terminal device 600 to the information processing device 100. The post-authentication information includes a terminal identifier and processing information. For example, the post-authentication information may also include location information. Note that in addition to or instead of the location information, the user's identity or other unique information relating to the user's current status may be transmitted. This can further enhance the effectiveness of preventing impersonation.

[0128] (Step S3) When the post-authentication information is transmitted in this manner, the information processing device 100 determines whether the permission conditions are met or not. Then, permission information is transmitted to the specified processing device 910 according to the determination result.

[0129] When the specific processing device 910 receives the permission information, it becomes capable of executing specific processing related to the user.

[0130] (Step S4) When the operation (preliminary operation) using the terminal device 600 is completed in this way, the user uses the card C to perform an operation such as withdrawal to the specific external device 920.

[0131] (Step S5) When the specific external device 920 accepts the operation performed by the user, it transmits corresponding information to the specific processing device 910. For example, account information obtained by reading card C by the specific external device 920 and the result of acquiring the PIN number by the specific external device 920 are transmitted to the specific processing device 910.

[0132] When the account information, PIN number, etc. are transmitted in this manner, the specific processing device 910 uses the information to execute specific processing.

[0133] As described above, according to this embodiment, it is possible to authenticate a user and then accept an operation related to a specific process performed by that user. Therefore, it is possible to reliably authenticate a specific user and then execute a specific process related to that user. There is no need to use a complex separate device to authenticate the user, and the result of authentication using the terminal device 600 owned by the user himself / herself can be used. Therefore, it can be easily introduced in a wide range and at low cost. Because location information is used to determine whether or not processing can be performed in the specific processing device 910, it is possible to more reliably prevent the occurrence of fraud such as impersonation.

[0134] The processing in this embodiment may be implemented by software. This software may be distributed by software download or the like. Furthermore, this software may be recorded on a recording medium such as an optical disc and distributed. The software implementing the information processing system 1 in this embodiment is the following program. That is, this program is executed on one or more computers of the information processing system 1, and causes the computers to function as: a first acquisition unit that acquires processing information to be used in a specific process; an authentication unit that authenticates a user who instructs the execution of the specific process using biometric information acquired from the user; a post-authentication information output unit that outputs post-authentication information including the processing information acquired by the first acquisition unit after authentication by the authentication unit; a second acquisition unit that acquires the output post-authentication information; a determination unit that determines whether the post-authentication information satisfies the permission condition; and a permission information output unit that outputs permission information to permit the execution of the specific process to the specific processing device when the determination unit determines that the permission condition is satisfied.

[0135] In the above-described embodiment, the terminal device 600 of the user that performs user authentication may be different from the terminal device 600 that acquires the processing information. For example, a user that instructs the execution of a specific process (here, referred to as a first user U1) and a second user U2 that acts with the permission of the first user U1 may use different terminal devices 600 to use the information processing system 1 together.

[0136] FIG. 9 is a diagram illustrating a specific example of the operation of the information processing system 1 according to a modification of the present embodiment.

[0137] In this case, the information processing system 1 may include two terminal devices 600: a first terminal device 601 used by a first user U1 and a second terminal device 602 used by a second user U2. The first terminal device 601 and the second terminal device 602 may each have the same configuration as the above-described terminal device 600, but are not limited to this. The first terminal device 601 may include an authentication unit 651 and a post-authentication information output unit 655, and the second terminal device 602 may include a first acquisition unit 643.

[0138] In this modified example, the operation before a transaction using the specified external device 920 is slightly different from that of the above-described embodiment. That is, first, the second user U2 uses the second terminal device 602 to read the processing medium C (step S1A). This results in the acquisition of processing information. The terminal processing unit 640 of the second terminal device 602 transmits the processing information to the information processing device 100 (step SS1B). In this case, the terminal identifier and location information of the second terminal device 602 may be transmitted together with the processing information.

[0139] When the information processing device 100 receives the processing information, it transmits a notification requesting user authentication to the first terminal device 601 corresponding to the terminal identifier of the sender (step S1C). As a result, the first terminal device 601 receives the notification and outputs it so that the first user U1 can recognize it. Note that it is sufficient if information indicating the correspondence relationship between the first terminal device 601 and the second terminal device 602 is stored in the information processing device 100 in advance. Furthermore, the information processing device 100 may be configured to identify the first terminal device 601 corresponding to the processing information and transmit the notification.

[0140] Next, the first user U1 performs biometric authentication using the first terminal device 601. If the user authentication is successful, post-authentication information is output from the first terminal device 601 (step S2). Note that the post-authentication information may include a terminal identifier of the first terminal device 601, but is not limited to this.

[0141] Thereafter, the information processing device 100 determines whether the permission conditions are satisfied using the post-authentication information, and the operations from step S3 onward can be performed, as in the above-described embodiment. That is, the specific process can be executed when the second user U2 performs an action of operating the specific external device 920 using the processing medium C. In this modified example, it is possible to execute a specific process in accordance with the action of another user, the second user U2, on the condition that user authentication of the first user U1 has been performed, i.e., that post-authentication information has been acquired. Therefore, it is possible to ensure that the specific process is performed with the permission of the first user U1.

[0142] In this variant, the information processing system 1 can be said to include a first acquisition unit that acquires processing information to be used for a specific process, an authentication unit that authenticates a user who instructs the execution of a specific process using biometric information acquired from the user, a post-authentication information output unit that outputs post-authentication information after authentication is performed by the authentication unit, a second acquisition unit that receives the processing information and post-authentication information acquired by the first acquisition unit, a judgment unit that judges whether the post-authentication information satisfies specified permission conditions, and a permission information output unit that outputs permission information to the specific processing device to permit the execution of the specific process when the judgment unit judges that the permission conditions are satisfied.

[0143] (others)

[0144] Fig. 10 is a schematic diagram of a computer system 800 according to the embodiment, and Fig. 11 is a block diagram of the same computer system 800.

[0145] These figures show examples of computer configurations that execute the programs described in this specification to realize the information processing systems, etc., of the above-described embodiments. The above-described embodiments can be realized by computer hardware and computer programs executed thereon.

[0146] Computer system 800 includes a computer 801 that includes an optical disk drive, a keyboard 802, a mouse 803, and a monitor 804.

[0147] In addition to an optical disk drive (ODD) 8012, the computer 801 includes an MPU 8013, a bus 8014 connected to the optical disk drive 8012 etc., a ROM 8015 for storing programs such as a boot-up program, a RAM 8016 connected to the MPU 8013 for temporarily storing instructions of application programs and providing temporary storage space, and a hard disk (HDD) 8017 for storing application programs, system programs, and data. Although not shown here, the computer 801 may further include a network card for providing connection to a LAN.

[0148] A program that causes the computer system 800 to execute the functions of the information processing device or the like of the above-described embodiments may be stored on an optical disk 8101, inserted into the optical disk drive 8012, and then transferred to the hard disk 8017. Alternatively, the program may be transmitted to the computer 801 via a network (not shown) and stored on the hard disk 8017. The program is loaded into the RAM 8016 when executed. The program may also be loaded directly from the optical disk 8101 or the network.

[0149] The program does not necessarily include an operating system (OS) or a third-party program that causes the computer 801 to execute the functions of the information processing device of the above-described embodiment. The program only needs to include instructions that call appropriate functions (modules) in a controlled manner to achieve desired results. How the computer system 800 operates is well known, and a detailed description thereof will be omitted.

[0150] In addition, in the above program, the sending step of sending information and the receiving step of receiving information do not include processing performed by hardware, such as processing performed by a modem or interface card in the sending step (processing that can only be performed by hardware).

[0151] The computer that executes the program may be a single computer or a plurality of computers, that is, it may perform centralized processing or distributed processing.

[0152] Furthermore, in the above-described embodiments, two or more components present in one device may be physically realized on one medium.

[0153] In the above embodiments, each component may be configured with dedicated hardware, or, for components that can be realized by software, may be realized by executing a program. For example, each component may be realized by a program execution unit such as a CPU reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. During execution, the program execution unit may execute the program while accessing a storage unit or recording medium. The program may also be executed by being downloaded from a server or the like, or by being read from a predetermined recording medium (e.g., an optical disk, a magnetic disk, a semiconductor memory, etc.). The program may also be used as a program constituting a program product. The program may be executed by a single computer or multiple computers. That is, centralized processing or distributed processing may be performed.

[0154] Furthermore, in the above embodiments, each process (each function) may be realized by centralized processing by a single device (system), or may be realized by distributed processing by multiple devices (in this case, the entire system consisting of multiple devices performing distributed processing can be understood as a single "device").

[0155] Furthermore, in the above embodiments, the transfer of information between components may be performed, for example, by one component outputting information and the other component receiving information if the two components transferring the information are physically different, or by moving from a processing phase corresponding to one component to a processing phase corresponding to the other component if the two components transferring the information are physically the same.

[0156] Furthermore, in the above-described embodiments, information related to the processing performed by each component, such as information accepted, acquired, selected, generated, transmitted, or received by each component, and information such as thresholds, formulas, and addresses used in processing by each component, may be temporarily or long-term stored in a recording medium (not shown), even if not explicitly stated in the above description. Furthermore, the storage of information in the recording medium (not shown) may be performed by each component or a storage unit (not shown). Furthermore, the reading of information from the recording medium (not shown) may be performed by each component or a reading unit (not shown).

[0157] Furthermore, in the above-described embodiments, if the information used by each component, such as thresholds, addresses, and various setting values used by each component in processing, may be changed by the user, the user may or may not be able to change the information as appropriate, even if not explicitly stated in the above description. If the information is changeable by the user, the change may be realized, for example, by a receiving unit (not shown) that receives a change instruction from the user and a changing unit (not shown) that changes the information in accordance with the change instruction. The change instruction may be received by the receiving unit (not shown), for example, from an input device, by receiving information transmitted via a communication line, or by receiving information read from a predetermined recording medium.

[0158] The present invention is not limited to the above-described embodiment, and various modifications are possible, and these modifications are also included within the scope of the present invention.

[0159] The components of the above-described embodiments and modifications may be combined as appropriate to form an embodiment. Also, some of the components or functions of the above-described embodiments and modifications may be omitted.

[0160] When permission information is transmitted from the information processing device to the specific external device, the time during which the specific process can be executed in the specific external device, i.e., the time during which execution of the specific process is permitted, may be limited to a predetermined time. For example, the specific external device may be made unable to execute the specific process after a preset time has elapsed. This allows the system using the specific processing device to be used more securely, so that only the user can execute the specific process.

[0161] In the above case, for example, the permission information output unit may be configured to output permission information including information specifying a time period during which the specific process is permissible, and the specific external device may set the permissible time period in accordance with the permission information. In this case, the permission information output unit may obtain time information regarding a time period during which execution of the specific process is permissible based on the determination result of the determination unit, and output the permission information based on the time information.

[0162] The time information may be acquired, for example, according to location information included in the post-authentication information. For example, time information may be set in advance in association with a predetermined area such as the user's home, workplace, or other location, and the time information may be specified according to the location information. By limiting the time during which execution of a specific process is permitted according to the time information in this way, the system using the specific processing device can be maintained more secure. [Industrial Applicability]

[0163] As described above, the information processing system according to the present invention has the effect of being able to easily and reliably authenticate a specific user and then execute specific processing related to that user, and is useful as an information processing system, etc. [Explanation of symbols]

[0164] 1. Information Processing Systems 100 Information processing device 110 Storage area 115 Pre-registration information storage section 117 Destination information storage section 120 Receiver 130 Reception 140 Processing section 143 Second Acquisition Department 145 Location information acquisition unit 151 Judgment Department 155 Permission information output unit 170 Transmitter 600 Terminal Equipment 610 Terminal storage section 611 Authentication information storage section 613 Terminal identifier storage unit 615 Lifestyle Information Storage Unit 620 Terminal receiving unit 630 Terminal Reception 640 Terminal Processing Unit 643 First Acquisition Department 651 Authentication Department 655 Post-authentication information output unit 660 Terminal Output Unit 661 Display section 670 Terminal Transmitter 680 Sensor unit 910 Specific processing equipment 920 Specific external device 950 Second external device

Claims

1. An information processing system including a terminal device and an information processing device, capable of outputting information to a specific processing device that executes a specific process, a first acquisition unit provided in the terminal device and configured to acquire processing information to be used in the specific process; an authentication unit provided in the terminal device, which authenticates a user who instructs execution of the specific process by using biometric information acquired from the user; a post-authentication information output unit that is provided in the terminal device and outputs post-authentication information including the processing information acquired by the first acquisition unit after authentication is performed by the authentication unit; a second acquisition unit provided in the information processing device and configured to acquire the post-authentication information; a determination unit provided in the information processing device and determining whether the authenticated information satisfies a predetermined permission condition; an information processing system including a permission information output unit provided in the information processing device and configured to output permission information to the specific processing device for permitting execution of the specific processing when the judgment unit determines that the permission conditions are satisfied.

2. a location information acquisition unit provided in the terminal device and acquiring location information relating to a location of the terminal device; The information processing system according to claim 1 , wherein the post-authentication information output unit outputs the post-authentication information including the location information.

3. The information processing system of claim 2, wherein the permission conditions include at least one of the following conditions: the location information is within an area associated with the terminal device, the location information is within an area associated with the processing information, and the location information is within an area associated with an external device used to instruct the specific processing.

4. The information processing system according to claim 1 , wherein the permission information output unit acquires time information relating to a time period during which execution of the specific process is permitted based on a determination result of the determination unit, and outputs the permission information based on the time information.

5. The information processing system of claim 1, wherein the permission information output unit transmits second permission information to an external device other than the specific processing device to permit the external device to perform a second specific processing when the processing information acquired by the first acquisition unit satisfies specified processing conditions.

6. A terminal device constituting an information processing system that can output information to a specific processing device that executes a specific process together with an information processing device, a first acquisition unit that acquires processing information to be used in the specific processing; an authentication unit that authenticates a user who instructs execution of the specific process using biometric information acquired from the user; a post-authentication information output unit that outputs post-authentication information including the processing information acquired by the first acquisition unit after authentication is performed by the authentication unit, The information processing device includes: a second acquisition unit that acquires the post-authentication information; a determination unit that determines whether the post-authentication information satisfies a predetermined permission condition; a permission information output unit that outputs permission information for permitting execution of the specific processing to the specific processing device when the determination unit determines that the permission condition is satisfied.

7. An information processing method that is performed using a first acquisition unit, an authentication unit, a post-authentication information output unit, a determination unit, and a permission information output unit, and outputs information to a specific processing device that executes a specific process, a first acquisition step in which the first acquisition unit acquires processing information to be used for the specific process; an authentication step in which the authentication unit authenticates a user who instructs execution of the specific process using biometric information acquired from the user; a post-authentication information output step in which the post-authentication information output unit outputs post-authentication information including the processing information acquired in the first acquisition step after authentication is performed in the authentication step; a determination step in which the determination unit determines whether the post-authentication information satisfies a predetermined permission condition; an authorization information output step in which the authorization information output unit outputs authorization information for permitting execution of the specific processing to the specific processing device when the determination step determines that the authorization condition is satisfied.

8. A program executed by a computer of a terminal device constituting an information processing system that can output information to a specific processing device that executes a specific process together with an information processing device, The information processing device includes: a second acquisition unit that acquires post-authentication information output from the terminal device; a determination unit that determines whether the post-authentication information satisfies a permission condition; a permission information output unit that outputs permission information for permitting execution of the specific processing to the specific processing device when the determination unit determines that the permission condition is satisfied, The computer of the terminal device, a first acquisition unit that acquires processing information to be used in the specific processing; an authentication unit that authenticates a user who instructs execution of the specific process using biometric information acquired from the user; a post-authentication information output unit that outputs the post-authentication information including the processing information acquired by the first acquisition unit after authentication is performed by the authentication unit.

Citation Information

Patent Citations

  • User authentication system, user authentication method and program

    JP6617086B2