Information processing apparatus, control method for information processing apparatus, and program
The information processing device enhances system throughput and security by implementing real-time spoofing detection and suspiciousness assessment, reducing computational resources and user inconvenience.
Patent Information
- Application Number
- JP2024016552
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-06
- Publication Date
- 2025-08-19
AI Technical Summary
Existing spoofing detection technologies in biometric authentication systems reduce system throughput and increase computational resources, leading to decreased efficiency and increased user inconvenience.
An information processing device with a first acquisition unit for data collection, an authentication unit for identity verification, a first determination unit for spoofing detection, and a second determination unit for suspiciousness assessment, allowing immediate entry while monitoring behavior to confirm authenticity.
Improves system throughput by allowing immediate entry while reducing computational resources and enhancing security through real-time suspiciousness determination.
Smart Images

Figure 2025121230000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a process for detecting fraudulent authentication and a process for determining whether a person is suspicious. [Background technology]
[0002] In the past, there have been attacks on biometric authentication in which an artificial object that resembles a living body is presented in an attempt to fraudulently authenticate. For example, in the case of facial authentication, an attacker could present a printed photograph of a face to impersonate another person and attempt to authenticate. Spoofing detection technology is a technology that can detect such attacks.
[0003] Patent Document 1 describes setting security strength according to the number of successful spoofing detections, and performing authentication based on the number of times that takes into account the trade-off between that strength and processing load. Patent Document 2 also describes performing fraud detection after the e-learning lesson is completed, based on the authentication results of the learner during the e-learning lesson, in order to prevent spoofing in the e-learning lesson. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 6202983 [Patent Document 2] Japanese Patent Application Laid-Open No. 2013-149181 Summary of the Invention [Problem to be solved by the invention]
[0005] However, the introduction of spoofing detection poses a problem of reduced system throughput. For example, if Patent Document 1 is applied to gate authentication, the user will be stopped at the gate every time a spoofing is detected. As a result, security improves but throughput decreases compared to when spoofing detection is not implemented. Furthermore, Patent Document 2 performs fraud detection after the e-learning program is completed, which necessitates monitoring all users for fraud detection, resulting in the problem of increased computational resources.
[0006] The present invention has been made in view of the above problems, and an object of the present invention is to provide an information processing device that can improve throughput while reducing computational resources. [Means for solving the problem]
[0007] In order to achieve the above-mentioned object, an information processing device as one aspect of the present invention has a first acquisition means for acquiring first data, an authentication means for authenticating a person based on the first data, a first determination means for determining whether the person to be authenticated by the authentication means is attempting fraudulent authentication, and a second determination means for determining whether the person to be authenticated is a suspicious person when the first determination means determines that fraudulent authentication is being attempted. [Effects of the Invention]
[0008] According to the present invention, it is possible to improve throughput while reducing computational resources. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a hardware configuration diagram of a computer device according to an embodiment. [Figure 2] FIG. 1 is a functional block diagram of an information processing device according to an embodiment. [Figure 3] FIG. 2 is an explanatory diagram showing a state of processing performed by an information processing apparatus according to an embodiment. [Figure 4]10 is a flowchart showing the flow of a service control process in the embodiment. [Figure 5] FIG. 10 is a block diagram illustrating the configuration of an information processing device according to another embodiment. [Figure 6] 10 is a flowchart showing the flow of a service control process in another embodiment. [Figure 7] FIG. 10 is a block diagram illustrating the configuration of an information processing device according to another embodiment. [Figure 8] 10 is a flowchart showing the flow of a service control process in another embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] Preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Note that the configurations shown in the following embodiments are merely examples, and the present invention is not limited to the illustrated configurations.
[0011] <Embodiment 1> The hardware configuration of a computer device 100 of this embodiment will be described below with reference to Fig. 1. Fig. 1 is a block diagram illustrating the hardware configuration of the computer device 100 of this embodiment. The computer device 100 of this embodiment has a CPU 101, a ROM 102, a RAM 103, an external storage device 104, an input device interface 105, an output device interface, and a communication interface. The computer device 100 of this embodiment also functions as an information processing device.
[0012] The CPU (processor) 101 is a central processing unit that controls the entire computer device 100. The CPU 101 executes control programs stored in the ROM 102 and RAM 103 to comprehensively control each component of the computer device 100. The CPU 101 is an acronym for Central Processing Unit. The ROM 102 is a non-volatile memory that stores (memorizes), for example, control programs and various parameters that do not require modification. The ROM 102 is an acronym for Read Only Memory.
[0013] RAM 103 is a volatile memory that temporarily stores programs and data supplied from an external device, etc. RAM 103 is an acronym for Random Access Memory. External storage device 104 is a storage device such as a hard disk or memory card that is fixedly installed in computer device 100. Note that external storage device 104 may also include optical disks such as flexible disks (FDs) and compact disks (CDs) that are detachable from computer device 100, magnetic or optical cards, IC cards, memory cards, etc.
[0014] The input device interface (input device I / F) 105 is an interface with an input device 109 such as a pointing device, mouse, or keyboard that receives user operations and inputs data. The output device interface (output device I / F) 106 is an interface with a monitor (display) 110 that displays various data such as data held by the computer device 100 and data supplied thereto.
[0015] The communication interface 107 is a communication interface for connecting to a network line 111 such as the Internet. In this embodiment, the communication interface 107 is connected to an NW camera (network camera) 112 via the network line 111. The NW camera 112 is an imaging device that captures videos and images. In FIG. 1, one NW camera 112 is connected to the computer device 100 via the network line 111. However, this is not limiting, and a plurality of NW cameras 112 may be connected to the computer device 100 via the network line 111. The system bus 108 is a transmission path that communicatively connects each unit from the CPU 101 to the communication interface 107. Each process in FIGS. 4, 6, and 7, which will be described later, functions as a process when the CPU 101 executes a program stored in a computer-readable storage medium such as the ROM 102.
[0016] A situation in which this embodiment is applied will be described below with reference to Fig. 3. Fig. 3 is an explanatory diagram showing a situation in which a computer device 100 performs processing. Fig. 3(A) is an explanatory diagram showing a situation in which a computer device 100 performs processing in embodiment 1. Fig. 3(B) is an explanatory diagram showing a situation in which a computer device 100 performs processing in embodiment 2. Therefore, details of Fig. 3(B) will be described later.
[0017] In this embodiment, a face authentication system is assumed to be installed in an event venue 300a. An entrance gate 301a is installed at the entrance to the event venue 300a. The entrance gate 301a is an authentication device with an automatic gate function that physically permits or restricts entry, and is equipped with an imaging device such as a camera. The camera installed at the entrance gate 301 is positioned and positioned so that a person's face can be captured at an angle of view. Here, a person who has been registered in advance has their face photographed by the camera installed at the entrance gate 301a. After a predetermined authentication process is performed, entry is permitted, and the gate opens, allowing the person to enter the event venue 300a. Although not shown, an exit gate is also installed at the event venue 300a. The exit gate may be an authentication device with an automatic gate function, similar to the entrance gate 301a. Alternatively, an attendant may be stationed at the exit gate, allowing free exit but not entry, without the automatic gate function.
[0018] Event venue 300a includes booths 310a, 311a, 312a, 313a, 314a, 315a, 316a, 317a, and 318a, each selling merchandise, food, and beverages. Each booth is equipped with a facial recognition information terminal (a facial recognition terminal), which can be used to make payments at the booths. Payments are made by deducting the fee from a deposit made in advance when registering for the event. Alternatively, a credit card or other payment method may be registered and the fee deducted from that account, or electronic money may be used to pay the fee. Some booths are staffed, while others are unmanned, such as vending machines. Network cameras 320a, 321a, 322a, and 323a are also installed at the event venue. When the NW cameras 320a, 321a, 322a, and 323a are installed in the event venue 300a as shown in FIG. 3(A), they are preferably installed at different positions.
[0019] The computer device 100, the NW cameras 320a to 323a, the entrance gate 301a, and the face authentication terminal are connected via a network line 111a or the like, and are configured to enable control and communication between them.
[0020] Even if the computer device 100 of this embodiment detects impersonation during authentication processing, it unlocks the entrance gate 301a (first service) to allow entry, but performs processing to lock the payment account of the user suspected of impersonation (second service). The behavior of the user within the event venue 300a is then monitored by NW cameras 320a-323a, and if suspicion of impersonation is cleared, processing to activate the payment account of the user (third service) is performed. On the other hand, if suspicion of impersonation persists, the user is determined to be a suspicious person, and a prescribed notification is made to a security guard or the like.
[0021] The functional configuration of the computer device 100 of this embodiment will be described with reference to Fig. 2. Fig. 2 is a diagram showing the functional block configuration of the computer device 100 in embodiment 1. The computer device 100 of embodiment 1 has a first acquisition unit 201, an authentication unit 202, a first suspiciousness determination unit 203, a second acquisition unit 204, a second suspiciousness determination unit 205, and a notification unit 206. It also has a first service unit 207, a second service unit 208, a first execution control unit 209, and a second execution control unit 210.
[0022] The first acquisition unit 201 acquires video data (first data) from a camera installed in the entrance gate 301a. If a separate camera is installed near the entrance gate 301a, the video data may be acquired from the camera installed near the entrance gate 301a instead of the camera installed in the entrance gate 301a. When installing a camera near the entrance gate 301a, the camera is installed so that the angle of view captures at least the face of a person attempting to enter through the entrance gate 301a. Furthermore, if a camera is installed near the entrance gate 301a, the first acquisition unit 201 may acquire video data (first data) from both the camera installed in the entrance gate 301a and the camera installed near the entrance gate 301a.
[0023] The authentication unit 202 authenticates people appearing in the video data acquired by the first acquisition unit 201. Specifically, it uses face detection technology to detect that a person appears in the acquired video data, and uses face recognition technology to identify the identity of that person. Specifically, a registration database is created in which users' facial images are registered in advance, such as when signing up for an event. Then, it uses face detection technology to detect that a face appears in the video data. A method such as RetinaFace can be used as the face detection technology. After that, it calculates the similarity between the detected face and faces registered in the registration database, and if there is a registered person whose similarity exceeds a predetermined level, it identifies the person in the video as a registered person. A method such as ArcFace can be used to calculate the similarity between two facial images. The registration database also stores information such as the account ID of registered people for linking with other services.
[0024] The first suspiciousness determination unit 203 determines whether a person (user) is attempting fraudulent authentication in the authentication unit 202. For example, it determines whether the person is attempting to fraudulently impersonate another person for authentication by presenting a printed photograph of their face or a smartphone or tablet displaying their face photograph. Specifically, it acquires video data from the first acquisition unit 201 and determines whether the face used by the authentication unit 202 for authentication is a fake photograph or the like. As a determination method, there is a spoofing detection technology that determines whether a subject is living or non-living from a facial image, and any known method may be used. In this embodiment, the first suspiciousness determination unit 203 uses a method of determining whether a subject is living or non-living from an image. However, it may also be possible to use a method of detecting spoofing by detecting an action such as the subject holding a photograph in front of their face.
[0025] The second acquisition unit 204 acquires video data (second data) from each of the NW cameras 320a to 323a.
[0026] The second suspiciousness determination unit 205 determines whether a person determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication (a person determined to be suspicious) is a suspicious person (determines suspiciousness) using video data obtained from the second acquisition unit 204. Specifically, when the first suspiciousness determination unit 203 determines that a person is attempting fraudulent authentication, the first suspiciousness determination unit 203 identifies the person using video data (first data) from the NW camera 320a that captures the entrance gate 301a. Thereafter, the first suspiciousness determination unit 205 tracks the person determined to be attempting fraudulent authentication through multiple NW cameras (NW cameras 320a to 323a) in the event venue 300a using tracking technology or the like, and monitors the person's behavior. Then, the second suspiciousness determination unit 205 determines whether the person determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication is a suspicious person based on the monitoring results (video data from the multiple NW cameras).
[0027] An example of suspicious behavior is, for example, a person's face changing from the face at the time of entry. In this case, even if a person passes through the entrance gate by holding up a photo or the like, if they stop holding up a photo after entering, their face will change from the face at the time of entry. When such suspicious behavior is detected from the monitoring results, the second suspiciousness determination unit 205 can determine that the person determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication is a suspicious person. In this way, the second suspiciousness determination unit 205 determines whether the person determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication is a suspicious person based on the behavior of the person.
[0028] Alternatively, if the monitoring results detect an action of lowering a photo being held up or removing a headgear such as a costume mask, the second suspiciousness determination unit 205 may determine that the person determined to be attempting fraudulent authentication is a suspicious person.
[0029] Furthermore, when the monitoring results detect behaviors that are typical of people with high stress or behaviors that intentionally escape from the surveillance camera, the second suspiciousness determination unit 205 may determine that the person determined to be attempting fraudulent authentication is a suspicious person. Furthermore, when the monitoring results detect behaviors that continue to track a person from the entrance gate and put away the photo that they are holding up, the second suspiciousness determination unit 205 may determine that the person determined to be attempting fraudulent authentication is a suspicious person. Furthermore, when the monitoring results detect behaviors that pass through a public place without removing an impersonation accessory such as a headgear, the second suspiciousness determination unit 205 may determine that the person determined to be attempting fraudulent authentication is a suspicious person.
[0030] In this way, holding a photo in front of one's face or wearing a headgear clearly looks suspicious, so if one passes through a crowded place in such a state, one will stand out as a suspicious person. Therefore, if such behavior is not observed before passing through a crowded place, it can be determined that the person is not a suspicious person. Note that the suspicious behaviors described above are only examples, and the method of determining whether a person is a suspicious person is not limited to these.
[0031] The notification unit 206 notifies a security guard or the like when a person who is determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication is determined by the second suspiciousness determination unit 205 to be a suspicious person. Specifically, a monitor 110a or the like is placed in a security room or the like, and the suspicious person is displayed and notified to the security guard. Alternatively, a sound may be emitted from a speaker or the like. Alternatively, a current NW camera image showing the suspicious person, the position of the NW camera, and the position of the suspicious person may be displayed on the monitor 110a. In addition, the monitor 110a may also display an image when the first suspiciousness determination unit 203 determined the suspicious person to be suspicious. Alternatively, the monitor 110a may display a registered person authenticated by the authentication unit 202, and display which registered person the person has impersonated. Note that the above notification methods and notification contents are merely examples and are not limited to these.
[0032] The first service unit 207 controls the locking and unlocking (opening and closing) of the entrance gate 301a, and permits or restricts entry to the event venue 300a.
[0033] The second service unit 208 controls payments for merchandise sales and the like at each booth in the event venue 300a. A face recognition terminal installed at each booth identifies the person to whom payment is to be made from a registration database, and makes the payment using the payment method associated with the registered person. For example, the fee is deducted from a prepaid deposit. Alternatively, the payment may be made by credit card. In addition, the payment service provided by the second service unit 208 can lock an account, and payments will fail while the account is locked. This prevents the person from making payments at the booth.
[0034] The first execution control unit 209 controls the first service unit 207 to execute the first service. Furthermore, it controls the second service unit 208 to execute the second service. Specifically, if the authentication unit 202 is successful in authentication, it controls the first service unit 207 to unlock the entrance gate 301a. In addition, if the first suspiciousness determination unit 203 determines that fraudulent authentication is being attempted, it controls the second service unit 208 to lock the payment account of the person authenticated by the authentication unit 202. In this way, the first execution control unit 209 controls the first service unit 207 to unlock the entrance gate 301a as the first service. Furthermore, the first execution control unit 209 controls the second service unit 208 to lock the payment account of the person authenticated by the authentication unit 202 as the second service.
[0035] The second execution control unit 210 controls the second service unit 208 to execute a third service that unlocks the second service. Specifically, when the second suspiciousness determination unit 205 determines that a person who has been determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication is not a suspicious person, the second execution control unit 210 controls the second service unit 208 to unlock the payment account of the person. This activates the account of the person, allowing the person to make payments at the booth. In this way, the second execution control unit 210 unlocks the payment account of a person whose payment account has been locked, as a third service.
[0036] 2, for the functions that are realized by software, a program for providing the function of each functional block is stored in a memory such as ROM 102. The program is then read into RAM 102 and executed by CPU 101, thereby realizing the function.
[0037] For functions implemented by hardware, for example, a specific compiler can be used to automatically generate a dedicated circuit on an FPGA from a program for implementing the function of each functional block. FPGA is an acronym for Field Programmable Gate Array. Alternatively, a gate array circuit may be formed in the same manner as an FPGA and implemented as hardware. Alternatively, the function may be implemented using an ASIC (Application Specific Integrated Circuit). Note that the functional block configuration shown in FIG. 2 is an example; multiple functional blocks may constitute one functional block, or any functional block may be divided into blocks that perform multiple functions.
[0038] Next, the service control processing flow in this embodiment will be described with reference to the flowchart in Fig. 4. Fig. 4 is a flowchart showing the flow of the service control processing in this embodiment. Each process (step) is represented by adding an S to the beginning, thereby abbreviating the notation of the process (step).
[0039] In S401, the authentication unit 202 searches the registration database for a person (user) visiting the entrance gate 301a and performs authentication processing for the person. In the authentication processing for the person, the person visiting the entrance gate 301a is captured by a camera installed in the entrance gate 301a. Next, the first acquisition unit 201 acquires video data (first data) captured by the camera. Next, the authentication unit 202 detects a person from the acquired video data (first data) using face detection technology and identifies the person. Specifically, the authentication unit 202 calculates the similarity between the face of the detected person and a face registered in the registration database, and if there is a registered person whose similarity exceeds a predetermined level, it identifies the person in the video data (first data) as a registered person. That is, it determines that authentication of the person attempting to enter through the entrance gate 301a has been successful. On the other hand, if there is no registered person whose similarity exceeds the predetermined level, it does not identify the person in the video data (first data) as a registered person. That is, it determines that authentication of the person attempting to enter through the entrance gate 301a has failed. By performing the processing in S401, it is possible to identify the person who has come to the entrance gate 301a and is attempting to enter the event venue 300a.
[0040] In S402, the first suspiciousness determination unit 203 determines whether or not the person who was authenticated by the authentication unit 202 in S401 has attempted fraudulent authentication. Specifically, the first suspiciousness determination unit 203 determines whether or not the person is attempting impersonation by holding up a photo in front of a camera, etc. (is committing impersonation).
[0041] In S403, the first suspiciousness determination unit 203 determines whether or not the person who was authenticated by the authentication unit 202 in S401 was successfully authenticated. If the authentication was successful, the process proceeds to S404. On the other hand, if the authentication was unsuccessful, the process ends. In other words, if the authentication was unsuccessful in S401, the entrance gate 301a will not be unlocked, and the person who was authenticated by the authentication unit 202 in S401 will not be able to enter the event venue 300a.
[0042] In S404, the first execution control unit 209 controls the first service unit 207 to unlock the entrance gate 301a and permit the person who was the target of authentication in S401 to enter the event venue 300a (execution of the first service). In other words, the first execution control unit 209 controls the first service unit 207 to execute the first service, regardless of the determination result by the first suspiciousness determination unit 203 (whether or not the person who was authenticated by the authentication unit 202 in S401 attempted fraudulent authentication).
[0043] It is assumed that entrance gate 301a is not an authentication device with an automatic gate function, but is a gate where, for example, an attendant or other relevant person is stationed and decides whether to permit or deny entry at the discretion of the attendant. In this case, a notification that entry is permitted may be sent to an electronic device such as a tablet or smartphone carried by the attendant, and based on that notification, the attendant may permit the entry of the person and allow them into event venue 300a. If entry is denied, the attendant will inform the person attempting to enter of this fact and will not permit entry to the person.
[0044] In S405, the first suspiciousness determination unit 203 determines whether or not fraudulent authentication was attempted in S402 (whether or not it was spoofing). If the determination result in S402 is spoofing, the process proceeds to S406. On the other hand, if the determination result in S402 is not spoofing, the process proceeds to S410.
[0045] In S406, the first execution control unit 209 locks the payment account of the registered person identified in S401 (executing the second service). Specifically, the account ID of the second service unit 208 associated with the registered person is obtained. The first execution control unit 209 then notifies the second service unit 208 to lock the account. After that, the second service unit 208, having received the notification to lock the account from the first execution control unit 209, locks the account and prohibits payments. In this way, the first execution control unit 209 executes payment control as a second service in accordance with the determination result of the first suspiciousness determination unit 203. That is, when the first suspiciousness determination unit 203 determines that fraudulent authentication is being attempted, the first execution control unit 209 controls the second service unit 208 to execute the second service to lock the payment account for that person.
[0046] In S407, the second suspiciousness determination unit 205 monitors the person determined in S402 to be attempting fraudulent authentication using the NW cameras 320a to 323a installed in the event venue 300a. During the monitoring, the second acquisition unit 204 acquires video data (second data) as the monitoring results from the NW cameras 320a to 323a. It is preferable that the second acquisition unit 204 acquires video data (second data) as the monitoring results from each of the installed NW cameras. However, this is not limiting, and the second data may be acquired from at least one NW camera that can capture an image of the person determined in S402 to be attempting fraudulent authentication.
[0047] In S408, the second suspiciousness determination unit 205 determines whether the person determined to be attempting fraudulent authentication in S402 is a suspicious person, based on the video data (second data) that is the monitoring result acquired by the second acquisition unit 204 in S407. If the person determined to be attempting fraudulent authentication in S402 is determined to be a suspicious person, the process proceeds to S409. On the other hand, if the person determined to be attempting fraudulent authentication in S402 is not determined to be a suspicious person, the process proceeds to S410. Note that if the person is not determined to be a suspicious person in S408, the first suspiciousness determination unit 203 erroneously determined that the person to be authenticated is a person attempting fraudulent authentication, but the second suspiciousness determination unit 205 corrected the determination by determining that the person is not suspicious (not a suspicious person).
[0048] In S409, the notification unit 206 notifies relevant parties such as security guards of the presence of a suspicious person (the person determined to be suspicious in S408). That is, this notification is made when the person determined to be suspicious in S402 by the second suspiciousness determination unit 205 is determined to be a suspicious person. Note that the notification may be made, for example, by placing a monitor 110a or the like in a security room or the like and displaying the suspicious person to notify the security guards, or by displaying the information on the monitor of an information terminal such as a tablet or smartphone carried by the security guards.
[0049] In S410, the second execution control unit 210 activates the payment account of the registered person identified in S401 (executing the third service). Specifically, the account ID of the second service unit 208 associated with the registered person is obtained. Then, the second service unit 208 is notified to activate the account. Thereafter, the second service unit 208 makes the account available for payment. If the payment account was locked in S406, the second execution control unit 210 unlocks the account and activates it. That is, the second execution control unit 210 controls the second service unit 208 to execute a third service that cancels the second service that locked the account and prohibited payment. In this way, if the first suspiciousness determination unit 203 determines that fraudulent authentication is being attempted but the second suspiciousness determination unit 205 does not determine that the person is a suspicious person, the second execution control unit 210 controls the second service unit 208 to execute the third service.
[0050] In the above-described embodiment, the spoofing determination process S402 is executed immediately after S401 in Fig. 4. However, this is not a limitation, and the spoofing determination process may be executed by S405. For example, the spoofing determination process may be executed immediately after a YES determination is made in S403 or immediately after the process of S404. Alternatively, the spoofing determination process may be executed immediately before S401. In other words, the process may be executed between any of S401 to S404, or may be executed in parallel with any of the processes of S401 to S404, as long as it is executed before the start of execution of S405.
[0051] In the above-described embodiment, the entrance gate 301a is photographed by the NW camera 320a. However, the NW camera 320a does not necessarily photograph the entrance gate 301a. In this case, to track a suspicious person identified by the first suspiciousness determination unit 203 at the entrance gate 301a, the camera's angle of view is set so that the camera at the entrance gate 301a can capture the suspicious person's entire body. Then, based on the image of the entire body, images of the suspicious person are identified from the other NW cameras, and the second suspiciousness determination unit 205 monitors their behavior. In this case, to obtain the entire body of the person identified as suspicious, the second suspiciousness determination unit 205 also obtains video data from the first acquisition unit 201. This reduces restrictions on camera installation and the number of cameras.
[0052] In the above-described embodiment, the second acquisition unit 204 acquires video data (second data) from the NW cameras 320a to 323a. However, the video data (second data) may be acquired from a face recognition terminal in at least one of the booths 310a to 318a. For example, when a person to be monitored appears at the face recognition terminal, the second suspiciousness determination unit 205 may use video data from a predetermined time point back in time to determine that the person is suspicious based on behavior such as holding a photo or smartphone over the camera. Furthermore, the second suspiciousness determination unit 205 may determine that the person is suspicious based on whether the person's face changes before and after holding the smartphone over the camera. This eliminates the need to install a NW camera in the event venue 300a, thereby reducing costs.
[0053] In the above embodiment, the second suspiciousness determination unit 205 determines the suspiciousness of a person who has been determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication (whether the person is a suspicious person) based on the behavior of the person. However, suspiciousness may be determined by other methods. For example, the second acquisition unit 204 may be configured to acquire video data (second data) from a face recognition terminal in at least one of the booths 310a to 318a. Then, at the time of authentication for payment, it may be determined whether or not impersonation is being attempted using spoofing detection technology, such as that used by the first suspiciousness determination unit 203.
[0054] Furthermore, some impersonation detection technologies use only a single still image, while others use multiple frames of video. Using multiple frames makes it possible to determine whether an actual three-dimensional face is present, rather than whether a flat object such as a photograph is being held up. Therefore, the latter is generally more accurate. However, it has the problem of reduced throughput. Therefore, the first suspiciousness determination unit 203 may use a still-image-based technology to improve the throughput of the entrance gate. The second suspiciousness determination unit 205 may also be configured to use a video-based technology to improve accuracy.
[0055] This increases throughput at the entrance gate while enabling highly accurate judgments when making payments at booths, etc. Furthermore, when making payments at booths, the second suspiciousness judgment unit 205 only processes people who are judged to be suspicious by the first suspiciousness judgment unit 203, so the decrease in throughput when making payments is limited. Additionally, the second suspiciousness judgment unit 205 may use active spoofing detection, which instructs the user to look to the side, blink, etc., and determines whether the user moves as instructed. Such technology requires more time for judgment, but is highly accurate. This allows for even greater accuracy.
[0056] In the above embodiment, payment is prevented by locking the account. However, this is not a limitation, and other methods may be used to lower the service level. For example, a restriction may be imposed such that payment is not possible at unmanned booths but is possible at manned booths. Alternatively, event participants may be divided into free users and paid users, and paid users may be further divided into ranks based on participation fees, etc. The service level provided at the event may be changed according to such user classification. Therefore, rather than locking the account, the service level may be restricted by changing such user classification.
[0057] The above-described embodiment assumes a situation in which a payment for merchandise or the like is made within the event venue 300a. However, the present invention may also be applied to a situation in which no payment is made within the event venue 300a and only the entrance gate 301a is present. In this case, control of the payment account is unnecessary, and therefore the processes of S406 and S410 in the flowchart of FIG. 4 are unnecessary. In this case, the second execution control unit 210 and the second service unit 208 may be omitted from the configuration of the computer device 100. As a result, even if the first suspiciousness determination unit 203 determines that a person is attempting fraudulent authentication (determined as suspicious), the person can pass through the entrance gate 301a. This prevents the user from being stopped at the entrance gate due to an erroneous determination by the first suspiciousness determination unit 203, thereby reducing user stress. In addition, it prevents people from accusing others, improving throughput. Even if the result of the authentication determination by the first suspiciousness determination unit 203 is correct, if the second suspiciousness determination unit 205 determines that the person is suspicious, a security guard is notified, and the suspicious person can be expelled from the event venue. Therefore, the service operator can continue business without any loss. The entrance gate 301a may also function as an exit gate, and an exit gate may be provided separately.
[0058] In the above-described embodiment, the computer device (information processing device) 100 has been described as performing service control. However, the computer device 100 may be configured as a device that only performs suspiciousness determination (determining whether fraudulent authentication is being attempted and whether the person is suspicious). In that case, the computer device 100 has only the first acquisition unit 201, authentication unit 202, first suspiciousness determination unit 203, second acquisition unit 204, and second suspiciousness determination unit 205 as components, and outputs the results of the first suspiciousness determination unit 203 and the second suspiciousness determination unit 205. Alternatively, the computer device 100 may be configured to output the results of the second suspiciousness determination unit 205. The output results may be stored in the RAM 103 or the external storage device 104, for example.
[0059] This allows for increased accuracy in suspiciousness determination, since the second suspiciousness determination unit 205 further checks cases where the first suspiciousness determination unit 203 erroneously determines that fraudulent authentication is being attempted (determines it as suspicious). In particular, the first suspiciousness determination unit 203 makes a determination based on impersonation detection, and the second suspiciousness determination unit 205 makes a determination based on behavior, thereby determining whether a person is suspicious based on different criteria, thereby allowing for increased accuracy.
[0060] Furthermore, the computer device 100 may be configured without the second acquisition unit 204. In this case, the second suspiciousness determination unit 205 may acquire video data from the first acquisition unit 201. For example, instead of using the camera installed in the entrance gate 301a, only one network camera capturing the entrance gate is used. When a person approaches the entrance gate 301a, facial authentication is performed using the network camera, and if the authentication is successful, the entrance gate 301a is unlocked. Furthermore, if the first suspiciousness determination unit 203 suspects that the person at the time of authentication is suspicious (if the person is determined to be attempting fraudulent authentication), the second suspiciousness determination unit 205 monitors the person's subsequent behavior. For example, if a person who has been successfully authenticated is tracked and a change in the person's facial image is detected, it is suspected that the person has taken down something that was previously being held up, such as a photograph, and the person can be determined to be suspicious. In this way, a configuration using only one camera may be adopted.
[0061] In the above-described embodiment, the first suspiciousness determination unit 203 performs processing only on video data acquired by the camera at the entrance gate 301a. However, this processing may be performed at multiple locations, not just the entrance gate 301a. For example, it may also be performed at the face recognition terminals at the booths 310a to 318a. That is, when authentication is attempted using a face recognition terminal, the first suspiciousness determination unit 203 determines whether fraudulent authentication is being attempted (determines suspiciousness). If it is determined that fraudulent authentication is being attempted, the second suspiciousness determination unit 205 may monitor each network camera. Alternatively, if there is a sub-gate or the like that further divides the event venue 300a instead of a face recognition terminal, the first suspiciousness determination unit 203 may perform processing using the video data from that gate.
[0062] As a result, even if a person passes through the entrance gate 301a, if the person is suspected to be a suspicious person, the payment account can be locked. Also, even if the second suspiciousness determination unit 205 mistakenly releases the lock, the first suspiciousness determination unit 203 processes the account again at multiple locations, so the account can be locked again. Also, if locking and unlocking are repeated, the locked state may be maintained. This allows the locked state to be maintained even if the second suspiciousness determination unit 205 does not mistakenly determine the person to be a suspicious person, thereby further improving security.
[0063] In the above embodiment, the first service is unlocking the entrance gate 301a of the event venue 300a, and the second service is restricting payment services within the event venue 300a. However, the present invention is not limited to these, and may be applied to other services. For example, the present invention may be applied to unlocking a car or starting an engine.
[0064] That is, the first service is assumed to be a service that controls the unlocking and locking of car doors. The second service is assumed to be a service that controls post-boarding operations such as starting the engine and controlling the air conditioner. Even if the first suspiciousness determination unit 203 determines that fraudulent authentication is being attempted (determines the user as suspicious), the first execution control unit 209 unlocks the doors and allows the user to board. In addition, the first execution control unit 209 sets the vehicle in a locked state to temporarily prohibit the execution of the second service. Thereafter, when the second suspiciousness determination unit 205 determines from the video of the user after boarding that the user is not a suspicious person, the second execution control unit 210 allows the execution of the second service. This increases the probability that the user can board the vehicle smoothly while preventing highly important operations such as starting the engine by a suspicious person.
[0065] Alternatively, the present invention may be applied to unlocking a smartphone or launching an application. That is, a service that controls unlocking a smartphone, etc., is assumed as the first service. A service that controls the execution of applications on the smartphone is assumed as the second service. Even if the first suspiciousness determination unit 203 determines that an unauthorized authentication attempt is being made (determines the user as suspicious), the smartphone is unlocked. In addition, the second execution control unit 210 temporarily prohibits the execution of the second service. Thereafter, if the second suspiciousness determination unit 205 determines that the user is not a suspicious person based on the video viewed by the user on the screen while the smartphone is unlocked, the second execution control unit 210 permits the execution of the second service. This increases the probability that the smartphone can be unlocked smoothly, while preventing highly important control, such as the execution of applications, by a suspicious person.
[0066] Alternatively, instead of prohibiting the execution of an application, the range of applications that can be executed may be limited. For example, this may be achieved by changing the authority of the account. The above is just an example, and the present invention is not limited to this.
[0067] In the above embodiment, the computer device 100 (information processing device) is configured as a single device. However, this is not limiting, and the computer device may be configured as multiple separate devices. For example, the first service unit 207 and the second service unit 208 may be configured as separate devices (information processing devices). Furthermore, the first acquisition unit 201, the authentication unit 202, the first suspiciousness determination unit 203, and the first execution control unit 209 may be configured as one device, and the second acquisition unit 204, the second suspiciousness determination unit 205, the notification unit 206, and the second execution control unit 210 may be configured as another device. Note that the above combination is just an example, and when configured as multiple separate computers, the combination can be set as desired.
[0068] In the above embodiment, the first acquisition unit 201 and the second acquisition unit 204 acquire video data from an imaging device such as a camera. However, this is not limited to this, and other data such as sensor data may be acquired. For example, the first suspiciousness determination unit 203 detects impersonation based on video data (first data). However, a vital sensor may be installed to estimate the user's stress level from vital data such as temperature, sweating, and heart rate, and if the stress level is high, it may be determined that fraudulent authentication is being attempted (determined as suspicious). Similarly, the second suspiciousness determination unit 205 may also use vital data to determine whether or not a person is suspicious. Furthermore, a user may be identified using an NFC (Near Field Communication) card without using face recognition for authentication. In this case, vital data serves as the first and second data. In this way, a configuration using other data without using video data can be implemented.
[0069] Assume that there is an exit gate with the same function as the entrance gate 301a. In this case, a camera installed at the exit gate may capture an image of a person exiting, and if the person is determined to be suspicious, the exit gate may be controlled not to be unlocked (second service). Also, the entrance gate 301a may be used as an exit gate as well.
[0070] As described above, according to the computer device 100 of this embodiment, even if the first suspiciousness determination unit 203 at the entrance gate 301a determines that a person is attempting fraudulent authentication (determined to be suspicious), the person is not stopped at the entrance gate 301a. This improves the throughput at the entrance gate 301a. Furthermore, only those persons determined to be attempting fraudulent authentication by the first suspiciousness determination unit 203 are monitored (tracked), and the second suspiciousness determination unit 205 determines whether or not they are truly suspicious. This eliminates the need to track all users who enter, and allows suspicious individuals to be identified by allocating computational resources only to those suspected of being suspicious. This improves throughput while reducing computational resources. Furthermore, if a person is ultimately determined to be suspicious, a security guard or the like is notified, allowing measures such as excluding the suspicious individual to be taken. This also prevents a decrease in the security level.
[0071] <Embodiment 2> In the first embodiment, an example was described in which a payment account is locked when it is determined that a fraudulent authentication attempt is being made (suspected), and the locked state of the payment account is unlocked when the suspicion of the suspicious person is cleared. In this embodiment, a form is described in which payment of the fee is put on hold when it is determined that a fraudulent authentication attempt is being made (suspected), and payment is carried out when the suspicion of the fraudulent person is cleared. Note that the computer device 100 of the second embodiment has the same configuration as the computer device 100 of the first embodiment. Therefore, a detailed description of the same configuration and processing as in the first embodiment will be omitted.
[0072] A situation in which this embodiment is applied will be described using Fig. 3(B). In this embodiment, a situation is assumed in which a ticket is purchased from a ticket vending machine that allows payment by facial recognition, and then the ticket is used to enter a facility such as a zoo or an aquarium. A camera is attached to the ticket vending machine (ticket issuing device) 302b, which is a device for obtaining a means of admission (ticket), and a user who has a payment account that uses facial recognition can purchase a ticket if their face is successfully authenticated.
[0073] When entrance gate 301b accepts the ticket, it unlocks entrance gate 301b and permits entry to facility 300b. NW camera 320b and NW camera 321b are installed inside facility 300b. NW camera 322b is installed outside facility 300b. As shown in FIG. 3(B), when NW camera 320b and NW camera 321b are installed inside facility 300b, it is preferable to install (place) them at different positions.
[0074] The computer device 100 of this embodiment, functioning as an information processing device, issues a ticket even if a person is suspected of being suspicious when purchasing a ticket using facial recognition, but does not process the payment. The user then uses the ticket to enter the facility, but monitors the person suspected of being suspicious, and once the suspicion is cleared, the payment that should have been made earlier is delayed. If the suspicion persists, a security guard or other person is notified that the person is a suspicious person.
[0075] The functional configuration of the computer device 100 of this embodiment will be described with reference to Fig. 5. Fig. 5 is a diagram showing the functional block configuration of the computer device 100 in embodiment 2. Note that components in Fig. 5 that have the same numbers as those in Fig. 2 of embodiment 1 have the same configuration as those in embodiment 1, and therefore their description will be omitted. The computer device 100 of embodiment 2 has a first acquisition unit 501, an authentication unit 502, a first suspiciousness determination unit 203, a second acquisition unit 504, a second suspiciousness determination unit 205, and a notification unit 206. It also has a first service unit 507, a second service unit 508, a first execution control unit 509, and a second execution control unit 510.
[0076] The first acquisition unit 501 acquires video data (first data) from a camera attached to the ticket vending machine 302b. The authentication unit 502 authenticates the person (the person making a payment at the ticket vending machine 302b) who appears in the video data acquired by the first acquisition unit 501. Specifically, as in the first embodiment, the authentication unit 502 identifies which payment account the person making a payment at the ticket vending machine 302b is a user of based on the registration database and the acquired video data (first data). The registration database of this embodiment stores information about people who hold payment accounts.
[0077] The second acquisition unit 504 acquires video data (second data) from each NW camera (NW cameras 320b to 322b). The first service unit 507 controls the ticket vending machine 302b to issue tickets (first service). The second service unit 508 controls the payment service to perform a second service such as withdrawing fees.
[0078] When the authentication unit 502 is successful in authentication, the first execution control unit 509 controls the first service unit 507 to issue a ticket as a first service. When the second suspiciousness determination unit 205 determines that a person who has been determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication is not a suspicious person, the second execution control unit 510 controls the second service unit 508 to execute payment processing for the person as a second service.
[0079] Next, the service control processing flow in this embodiment will be described with reference to the flowchart in Fig. 6. Fig. 6 is a flowchart showing the flow of the service control processing in embodiment 2. Furthermore, by adding an S to the beginning of each process (step), the process (step) is omitted from the description.
[0080] In S601, the authentication unit 502 searches the registration database for a person who is trying to purchase a ticket from the ticket vending machine 302b, and performs authentication processing for the person. Note that the authentication processing for the person in S601 can be the same as in the first embodiment, and therefore a description thereof will be omitted.
[0081] In S602, the first suspiciousness determination unit 203 determines whether or not the person who was authenticated by the authentication unit 502 in S601 is attempting fraudulent authentication. Specifically, the first suspiciousness determination unit 203 determines whether or not the person is attempting impersonation by holding up a photo in front of the camera, etc. (is committing impersonation).
[0082] In S603, the first suspiciousness determination unit 203 determines whether or not the person who was authenticated by the authentication unit 502 in S601 was successfully authenticated. If the authentication was successful, the process proceeds to S604. On the other hand, if the authentication was unsuccessful, the process ends. In other words, if the authentication was unsuccessful, the ticket cannot be purchased.
[0083] In S604, the first execution control unit 509 controls the first service unit 507 to issue a ticket from the ticket vending machine 302b (execution of the first service). In other words, the first execution control unit 509 controls the first service unit 507 to execute the first service, regardless of the determination result by the first suspiciousness determination unit 203 (whether or not the person who was authenticated by the authentication unit 502 in S601 attempted fraudulent authentication).
[0084] In S605, the first suspiciousness determination unit 203 determines whether fraudulent authentication was attempted (whether it was spoofing) in S602. If the determination result in S602 is spoofing, the process proceeds to S606. On the other hand, if the determination result in S602 is not spoofing, the process proceeds to S609.
[0085] In S606, the second suspiciousness determination unit 205 monitors the person determined to be attempting fraudulent authentication in S602 (the person determined to be suspicious) using the NW cameras 320b to 322b. During the monitoring, the second acquisition unit 504 acquires video data (second data) that is the monitoring result from the NW cameras 320b to 322b.
[0086] In S607, the second suspiciousness determination unit 205 determines whether the person determined to be attempting fraudulent authentication in S602 is a suspicious person, based on the video data (second data) that is the monitoring result acquired by the second acquisition unit 204 in S606. If the person determined to be attempting fraudulent authentication in S602 is determined to be a suspicious person, the process proceeds to S608. On the other hand, if the person determined to be attempting fraudulent authentication in S602 is not determined to be a suspicious person, the process proceeds to S609. Note that if the person is not determined to be a suspicious person in S607, the first suspiciousness determination unit 203 erroneously determined that the person to be authenticated is a person attempting fraudulent authentication, but the second suspiciousness determination unit 205 corrected the determination by determining that the person is not suspicious (not a suspicious person).
[0087] In S608, the notification unit 206 notifies relevant personnel such as security guards of the presence of a suspicious person (a person determined to be a suspicious person in S607).
[0088] In S609, the second execution control unit 510 controls the second service unit 508 to debit the ticket fee from the payment account of the registered person identified in S601 (execution of the second service).
[0089] In the above embodiment, the payment process in S609 may be different depending on whether it is determined in S605 that the person is not attempting fraudulent authentication (is not suspicious) or whether it is determined in S607 that the person is not suspicious. For example, if the process reaches S609 via S607, the amount charged may be reduced in consideration of the possibility of an erroneous judgment by the first suspiciousness judgment unit 203. Alternatively, the upper limit allowed by the payment service may be lowered, and if the upper limit is exceeded, the payment may not be made. Alternatively, the same amount may be paid, but a history may be kept on the payment service side so that a refund request can be made. This reduces the impact of an erroneous judgment.
[0090] In the above embodiment, an example of prepayment in the form of ticket issuance was given, but it may also be applied to a postpayment format. In the case of postpayment, if it is determined that a person is attempting fraudulent authentication, the amount charged may be increased. For example, when visiting a medical institution, a patient is examined after reception, and payment is made at the end, in a postpayment format. Below, a format applied to a medical institution will be described.
[0091] In this format, reception is processed at a reception terminal using the My Number card, and the user receives a medical examination ticket that lists the reception number, examination room, etc. The user then proceeds to the examination room to receive treatment, and after the treatment, the payment is processed at an accounting terminal. The reception terminal is equipped with a camera that determines whether the person captured by the camera is the same person associated with the My Number card, and if facial recognition is successful, the medical examination ticket is issued. The accounting terminal reads the medical examination ticket, calculates the medical expenses to be claimed, and bills the user, who then pays in cash or by credit card.
[0092] In this configuration, the first service is the issuance of a medical examination ticket at the reception terminal. Additionally, the second service is the settlement of medical expenses at the accounting terminal. Even if the first suspiciousness determination unit 203 determines that the user is suspicious, the first execution control unit 209 issues a medical examination ticket. Thereafter, when the second suspiciousness determination unit 205 determines that the user is not a suspicious person based on video of the user in the hospital, the second execution control unit 210 controls the system to charge the normal amount at the accounting terminal. On the other hand, if the second suspiciousness determination unit 205 determines that the user is a suspicious person, a warning may be displayed to the user and an increased amount may be charged. While medical expenses are usually 30% of the total, for example, the increased amount may be requested, with the user paying 100%. If a staff member or other person confirms that the medical examination was an error at the time of billing, the billed amount may be returned to the user who was confirmed to have been an error, and payment may be made normally. This allows for smooth reception while implementing different payments depending on the degree of suspiciousness.
[0093] As described above, according to the computer device 100 of this embodiment, even if the first suspiciousness determination unit 203 determines that the ticket vending machine 302b is suspicious, the ticket vending machine 302b still issues a ticket, thereby preventing queues from forming at the ticket vending machine 302b. Furthermore, instead of monitoring everyone, only those determined to be attempting fraudulent authentication (those suspected of being suspicious) are monitored, which also reduces computational resources. In addition, it is possible to prevent erroneous charging of a person who has been impersonated.
[0094] <Embodiment 3> In this embodiment, the present invention is applied to e-learning, which is a type of online learning, and describes a form in which a student is monitored only when impersonation is suspected, and it is determined whether the student is actually taking the course. The computer device 100 of the third embodiment has the same configuration as the computer device 100 of the first embodiment. Therefore, detailed descriptions of the same configuration and processing as those of the first embodiment will be omitted.
[0095] A situation in which this embodiment is applied will be described. In this embodiment, a student takes e-learning courses at home using an information processing device such as a laptop PC. Then, the student logs in to the e-learning class using facial recognition and takes the e-learning course. A camera mounted on the laptop PC is used for facial recognition. The student's appearance during the course is also monitored using the same camera. Note that the configuration does not have to be a laptop PC, and a desktop PC and USB camera may also be used. Furthermore, a laptop PC may also be configured to perform facial recognition using a camera such as a USB camera.
[0096] The functional configuration of the computer device 100 of this embodiment will be described with reference to Fig. 7. Fig. 7 is a diagram showing the functional block configuration of the computer device 100 in embodiment 3. Note that components in Fig. 7 that have the same numbers as those in Fig. 2 of embodiment 1 have the same configuration as those in embodiment 1, and therefore their description will be omitted. The computer device 100 of embodiment 3 has a first acquisition unit 701, an authentication unit 702, a first suspiciousness determination unit 203, a second acquisition unit 704, and a second suspiciousness determination unit 705. It also has a first service unit 707, a second service unit 708, a first execution control unit 709, and a second execution control unit 710.
[0097] The first acquisition unit 701 acquires video data (first data) from the camera of the notebook PC. The second acquisition unit 704 acquires video data (second data) from the camera of the notebook PC.
[0098] The authentication unit 702 authenticates the person (person making payment) appearing in the video data acquired by the first acquisition unit 701. Specifically, as in the first embodiment, it identifies which student is attending the class based on the registration database and the video data (first data). The registration database of this embodiment stores information about the students. Then, it searches the registration database for the person appearing in the video data acquired by the first acquisition unit 701 to identify which student they are.
[0099] The second suspiciousness determination unit 705 determines whether a person taking the class is suspicious (whether the class is being attended suspiciously) based on the video data (second data) of the class. In particular, it determines whether a different person is taking the class, assuming that a substitute is taking the class. For example, if the face of a person authenticated by the authentication unit 702 is not present in the video and the face of a person different from the authenticated face is recognized a certain number of times, it determines that the class is being attended suspiciously. Alternatively, if the face of a different person is recognized for more than a certain period of time, it determines that the class is being attended suspiciously. Alternatively, in order to detect if a person has left the class without attending, it determines that the person is attending suspiciously when a certain period of time continues in which no person is recognized in the video. Note that these are merely examples, and the method of determining whether a person is a suspicious person is not limited to these.
[0100] The first service unit 707 is an e-learning service that starts e-learning (first service). The second service unit 708 is a service that records the course history, and records information such as whether the person has taken the course (second service). The second service unit 708 may also record the course status, such as whether the course is in progress or completed, and the course time.
[0101] When the authentication unit 702 is successful in authentication, the first execution control unit 709 controls the first service unit 707 to start e-learning (start online learning) as a first service. When the second suspiciousness determination unit 705 determines that a person who is determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication is not a suspicious person, the second execution control unit 710 controls the second service unit 708 to perform recording processing as a normal attendance. Furthermore, when the second suspiciousness determination unit 705 determines that a person who is determined by the first suspiciousness determination unit 203 to be attempting fraudulent authentication is a suspicious person, the second execution control unit 710 performs recording processing as a suspicious attendance. In this way, the second suspiciousness determination unit 705 records attendance based on the determination result of the second suspiciousness determination unit 705 as a second service.
[0102] Next, the service control processing flow in this embodiment will be described with reference to the flowchart in Fig. 8. Fig. 8 is a flowchart showing the flow of the service control processing in embodiment 3. Furthermore, by adding an S to the beginning of each process (step), the process (step) is omitted from the description.
[0103] In S801, the authentication unit 702 determines whether a control signal related to taking e-learning courses has been received. If it is determined that a control signal (control command) related to taking e-learning courses has been received, the process proceeds to S802. On the other hand, if it is determined that a control signal related to taking e-learning courses has not been received, the process waits until a control signal related to taking e-learning courses is received. Note that the control signal related to taking e-learning courses may be, for example, a control signal that identifies the e-learning course to be taken or a control signal indicating that the user wishes to log in to an e-learning class. To select e-learning courses, the user who plans to take the course uses the input device 109 or the like to select the e-learning course to be taken on an e-learning site or the like.
[0104] In S802, the authentication unit 702 searches the registration database for a person who is going to take the e-learning course and performs authentication processing for the person. The authentication processing for the person in S802 can be the same as in the first embodiment, and therefore a description thereof will be omitted.
[0105] In S803, the first suspiciousness determination unit 203 determines whether or not the person who was authenticated by the authentication unit 702 in S802 is attempting fraudulent authentication. Specifically, the first suspiciousness determination unit 203 determines whether or not the person is attempting impersonation (performing impersonation) by holding up a photo in front of the camera, for example.
[0106] In S804, the first suspiciousness determination unit 203 determines whether the person who was authenticated by the authentication unit 702 in S802 is attempting fraudulent authentication. If the authentication is successful, the process proceeds to S805. On the other hand, if the authentication is unsuccessful, the process ends. In other words, in this case, the person cannot take the e-learning course.
[0107] In S805, the first execution control unit 709 controls the first service unit 707 to start e-learning (execution of the first service). In other words, the first execution control unit 709 controls the first service unit 707 to execute the first service, regardless of the determination result by the first suspiciousness determination unit 203 (whether or not the person who was authenticated by the authentication unit 702 in S802 attempted fraudulent authentication).
[0108] In S806, the first suspiciousness determination unit 203 determines whether fraudulent authentication was attempted (whether it was spoofing) in S803. If the determination result in S803 is spoofing, the process proceeds to S807. On the other hand, if the determination result in S803 is not spoofing, the process proceeds to S810.
[0109] In S807, the second suspiciousness determination unit 705 monitors the person determined to be attempting fraudulent authentication in S803 (the person determined to be suspicious) using the camera of the notebook PC. During monitoring, the second acquisition unit 704 acquires video data (second data) that is the monitoring result from the notebook PC.
[0110] In S808, the second suspiciousness determination unit 705 determines whether the person determined to be attempting fraudulent authentication in S803 is a suspicious person, based on the video data (second data) that is the monitoring result acquired by the second acquisition unit 704 in S807. If the person determined to be attempting fraudulent authentication in S803 is determined to be a suspicious person, the process proceeds to S809. On the other hand, if the person determined to be attempting fraudulent authentication in S803 is not determined to be a suspicious person, the process proceeds to S810. Note that if the person is not determined to be a suspicious person in S808, the first suspiciousness determination unit 203 erroneously determined that the person to be authenticated is a person attempting fraudulent authentication, but the second suspiciousness determination unit 705 corrected the determination by determining that the person is not suspicious (not a suspicious person).
[0111] In S809, the second execution control unit 710 controls the second service unit 708 to record that the attendance history of the person identified in S802 was "suspicious" (execution of the second service).
[0112] In S810, the second execution control unit 710 controls the second service unit 708 to record that the attendance history of the person identified in S802 was "normal attendance" (execution of the second service).
[0113] In the above embodiment, the example of taking an e-learning course has been described, but the present invention may also be applied to "taking a qualification exam." For example, there are places such as test centers where multiple PCs are prepared and exams are taken all at once. In such places, network cameras may be installed and used by the second suspiciousness determination unit 705.
[0114] Although the computer device 100 of the third embodiment is configured without the notification unit 206, it may be configured to include the notification unit 206. In that case, when the second suspiciousness determination unit 705 determines that fraudulent authentication is being attempted, it may notify, for example, a person supervising the examination.
[0115] This embodiment can also be applied to taking attendance at classes. For example, a face recognition tablet or the like can be passed around among students to take attendance. Furthermore, a configuration is possible in which students are photographed with a network camera. Then, during tablet authentication, a person suspected of impersonation can be monitored with the network camera, and if the suspicion persists (if the person is determined to be a suspicious person), the person can be recorded as having suspicious attendance.
[0116] As described above, the computer device 100 in this embodiment monitors participants only when impersonation is suspected. This eliminates the need to monitor everyone, and allows computing resources to be allocated only to those suspected of being suspicious, enabling efficient processing.
[0117] Although the embodiments have been described in detail above, the present invention is not limited to the above-described embodiments, and various modifications can be made without departing from the spirit of the present invention.
[0118] The present invention can be embodied as, for example, a system, an apparatus, a method, a program, or a storage medium, etc. Specifically, the present invention may be applied to a system consisting of multiple devices, or may be applied to an apparatus consisting of a single device.
[0119] The present invention can also be realized by executing the following process: software (programs) that realize the functions of the above-described embodiments are supplied to a system or device via a network or various storage media, and the computer (or CPU, MPU, etc.) of the system or device reads and executes the programs.
[0120] The disclosure of this embodiment includes the following configuration, method, and program.
[0121] (Configuration 1) a first acquiring means for acquiring first data; authentication means for authenticating a person based on the first data; a first determination means for determining whether or not a person who has been authenticated by the authentication means is attempting fraudulent authentication; and a second determination means for determining whether the person to be authenticated is a suspicious person when the first determination means determines that the person is attempting fraudulent authentication. 1. An information processing device comprising:
[0122] (Configuration 2) The method further includes a monitoring means for monitoring a person who is determined by the first determination means to be attempting the fraudulent authentication, The information processing device described in configuration 1, characterized in that the second determination means determines whether the person determined by the first determination means to be attempting the fraudulent authentication is a suspicious person based on the monitoring results of the monitoring means.
[0123] (Configuration 3) further comprising a second acquisition means for acquiring second data; The information processing device described in configuration 1 or 2, characterized in that the second determination means determines, based on the second data, whether the person determined by the first determination means to be attempting the fraudulent authentication is a suspicious person.
[0124] (Configuration 4) 4. The information processing apparatus according to configuration 3, wherein the second acquisition means acquires video data as the second data from at least one imaging means.
[0125] (Configuration 5) 5. The information processing apparatus according to any one of configurations 1 to 4, wherein the first acquisition means acquires video data as the first data from an imaging means capable of capturing an image of at least the face of the person.
[0126] (Configuration 6) The information processing device described in any one of configurations 1 to 5, characterized in that the second determination means determines whether the person determined to be attempting fraudulent authentication is a suspicious person based on the behavior of the person determined to be attempting fraudulent authentication.
[0127] (Configuration 7) The information processing device described in any one of configurations 1 to 6, further comprising a notification means for issuing a predetermined notification when the person determined by the second determination means to be attempting the fraudulent authentication is determined to be a suspicious person.
[0128] (Configuration 8) 8. The information processing apparatus according to any one of configurations 1 to 7, further comprising a first execution control means for controlling to execute a first service regardless of the determination result of the first determination means.
[0129] (Configuration 9) 9. The information processing device according to configuration 8, wherein the first service is at least one of opening and closing a gate, issuing a ticket for a means of entry, and starting online learning.
[0130] (Configuration 10) 10. The information processing device according to configuration 8 or 9, wherein the first execution control means controls to execute a second service depending on the determination result of the first determination means.
[0131] (Configuration 11) The information processing device described in any one of configurations 8 to 10, characterized in that the first execution control means controls to execute payment control as a second service when the first determination means determines that fraudulent authentication is being attempted.
[0132] (Configuration 12) a second execution control means for executing a third service that cancels the second service; The information processing device described in configuration 10, characterized in that the second execution control means controls to execute the third service when the first judgment means determines that the person is attempting fraudulent authentication but the second judgment means does not determine that the person is a suspicious person.
[0133] (Configuration 13) a first execution control means for controlling execution of a first service regardless of the determination result of the first determination means; and second execution control means for controlling payment as a second service depending on the determination result of the first determination means or the second determination means. 8. The information processing device according to any one of configurations 1 to 7.
[0134] (Configuration 14) The information processing device according to any one of configurations 8 to 10, further comprising a second execution control means for recording attendance based on the second determination means as a second service when the first service is the start of online learning.
[0135] (Configuration 15) A control method for an information processing device, comprising: a first acquisition step of acquiring first data; an authentication step of authenticating a person based on the first data; a first determination step of determining whether or not a person who has been the subject of authentication in the authentication step is attempting fraudulent authentication; a second determination step of determining whether the person to be authenticated is a suspicious person when it is determined in the first determination step that fraudulent authentication is being attempted, 2. A method for controlling an information processing apparatus comprising:
[0136] (Configuration 16) A program for causing a computer to function as each means of the information processing device according to any one of configurations 1 to 14. [Explanation of symbols]
[0137] 201 First Acquisition Department 202 Authentication Department 203 First Suspiciousness Judgment Department 205 Second Suspiciousness Judgment Department
Claims
1. a first acquiring means for acquiring first data; authentication means for authenticating a person based on the first data; a first determination means for determining whether or not a person who has been authenticated by the authentication means is attempting fraudulent authentication; and a second determination means for determining whether the person to be authenticated is a suspicious person when the first determination means determines that the person is attempting fraudulent authentication.
1. An information processing device comprising:
2. The method further includes a monitoring means for monitoring a person who is determined by the first determination means to be attempting the fraudulent authentication, The information processing device according to claim 1, characterized in that the second determination means determines whether the person determined by the first determination means to be attempting the fraudulent authentication is a suspicious person based on the monitoring results of the monitoring means.
3. further comprising a second acquisition means for acquiring second data; The information processing device according to claim 1, characterized in that the second determination means determines, based on the second data, whether the person determined by the first determination means to be attempting the fraudulent authentication is a suspicious person.
4. 4. The information processing apparatus according to claim 3, wherein the second acquisition means acquires video data as the second data from at least one imaging means.
5. 2. The information processing apparatus according to claim 1, wherein the first acquisition means acquires video data as the first data from an image capture means capable of capturing an image of at least the face of the person.
6. The information processing device according to claim 1, characterized in that the second determination means determines whether the person determined to be attempting fraudulent authentication is a suspicious person based on the behavior of the person determined to be attempting fraudulent authentication.
7. 2. The information processing apparatus according to claim 1, further comprising a notification means for issuing a predetermined notification when the person determined by the second determination means to be attempting the fraudulent authentication is determined to be a suspicious person.
8. 2. The information processing apparatus according to claim 1, further comprising a first execution control means for controlling execution of a first service regardless of the result of the determination by said first determination means.
9. 9. The information processing apparatus according to claim 8, wherein the first service is at least one of opening and closing a gate, issuing a ticket for a means of entry, and starting online learning.
10. 9. The information processing apparatus according to claim 8, wherein the first execution control means controls to execute a second service in accordance with the result of the determination by the first determination means.
11. The information processing device according to claim 8, characterized in that the first execution control means controls to execute payment control as a second service when the first determination means determines that fraudulent authentication is being attempted.
12. a second execution control means for executing a third service that cancels the second service; The information processing device according to claim 10, characterized in that the second execution control means controls the execution of the third service when the first judgment means determines that the person is attempting fraudulent authentication but the second judgment means does not determine that the person is a suspicious person.
13. a first execution control means for controlling execution of a first service regardless of the determination result of the first determination means; and second execution control means for controlling payment as a second service depending on the determination result of the first determination means or the second determination means.
2. The information processing apparatus according to claim 1, wherein:
14. 9. The information processing device according to claim 8, further comprising a second execution control means for recording attendance based on the second determination means as a second service when the first service is the start of online learning.
15. A control method for an information processing device, comprising: a first acquisition step of acquiring first data; an authentication step of authenticating a person based on the first data; a first determination step of determining whether or not a person who has been the subject of authentication in the authentication step is attempting fraudulent authentication; a second determination step of determining whether the person to be authenticated is a suspicious person when it is determined in the first determination step that fraudulent authentication is being attempted, 2. A method for controlling an information processing apparatus comprising:
16. A program for causing a computer to function as each of the means of the information processing apparatus according to any one of claims 1 to 14.
Citation Information
Patent Citations
Liquid type moving apparatus
JP1987002983A
Authentication program, authentication device, and authentication system
JP2013149181A