User usage registration management system, terminal device, user usage registration management method, and program
The user registration management system addresses the high costs of managing public identification information by separating its management, allowing seamless input and authentication, thus reducing burdens on service providers and enhancing user registration convenience.
Patent Information
- Application Number
- JP2024030250
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-29
- Publication Date
- 2025-09-10
AI Technical Summary
Existing systems that use public identification information such as My Number for identity verification incur high financial and labor burdens due to the need for specialized management systems, limiting user registration for network services.
A user registration management system that separates the management of public identification information into a dedicated system, allowing seamless input and authentication of user-related information, including public identification information like My Number, without requiring service providers to build additional management systems.
Reduces financial and labor burdens on service providers by enabling robust personal authentication based on public identification information, facilitating wider user registration for network services.
Smart Images

Figure 2025132584000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a user registration management system, a terminal device, a user registration management method, a program, and the like. [Background technology]
[0002] 2. Description of the Related Art Conventionally, network services such as internet banking or mail order sites have been provided via communication networks.
[0003] Recently, it has become common practice to verify the identity of individuals when registering to use such network services, and this is often done using individual identification information for citizens, such as My Number cards or social security numbers, or identification documents such as driver's licenses.
[0004] For example, as a system for verifying an individual's identity using such identification information or identification card, a system that uses electronic identification information or identification card is known.
[0005] In particular, such a system is configured to verify the identity of a user who has legitimate authority using information (including personal identification information), a facial image of the user, an IC card on which the identification information is digitized, and a facial image generated by capturing the face of the person seeking identification (e.g., Patent Document 1). [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Publication No. 2019-050014 Summary of the Invention [Problem to be solved by the invention]
[0007] However, in a system such as that described in Patent Document 1, if personal identification information is public identification information such as My Number, which requires special management with strict regulations, a system for performing the special management must be prepared, and building such a system (i.e., just for managing the personal identification information) is expected to incur additional high costs.
[0008] The present invention has been made to solve the above-mentioned problems, and its purpose is to provide an authentication system etc. that reduces the financial and labor burden on service providers by managing personal identification information in a separate, dedicated system, and that enables a wide range of users to register for network services by realizing robust personal authentication based on public identification information. [Means for solving the problem]
[0009] (1) In order to solve the above problems, the present invention provides: A user registration management system that works in conjunction with a terminal device to which information about a user is input as user-related information, and manages the user's registration for a given service based on the user-related information, When the user wishes to register for use of the service, the user-related information transmitted from the terminal device is user information of the user who wishes to register for use of the service. a reception processing means for executing a reception process for receiving registration information and identity verification information for verifying the identity of the user wishing to register; a determination processing means for executing a determination process to determine whether the type of the received personal identification information is information that requires a given special management; a providing means for executing a first provision control process of associating the received user registration information with a service identification information for the user when using the service and providing the information to a service system that provides the given service, and a second provision control process of providing the received personal identification information together with the service identification information of the user to a management system that performs the given special management when the type of the received personal identification information is determined to be information that requires the given special management by the determining process; The system is configured to include a management means for registering and managing the user registration information in a given database in association with the service identification information or in conjunction with the personal identification information provided to the management system, when the system receives a notification sent from the service system or the management system indicating that personal identification has been successful based on the provided user registration information and personal identification information, on the assumption that the personal identification information will be registered in the management system.
[0010] With this configuration, when the present invention is used to register a user to use a network service and the personal identification information used is, for example, public identification information such as My Number, which is strictly regulated and requires special management, the personal identification information can be managed separately in a management system that meets special requirements such as legal requirements, different from the database used to register users of the service.
[0011] Therefore, the present invention can accept public identification information as personal identification information without requiring the service provider to prepare a management system such as a database that meets legal requirements, thereby reducing the financial and labor burden on the service provider and enabling a wide range of users to register for network services by realizing robust personal authentication based on public identification information.
[0012] The "user registration information" includes attribute information related to the user's attributes, such as the user's name, address or residence, contact information, age, family structure, and annual income. However, in addition to the attribute information, the user registration information may also include a facial image of the user or an upper body image including the facial image (a so-called selfie image), and an image of personal identification information.
[0013] "Personal identification information" includes not only official identification information issued by the country or government, such as My Number or Social Security Number, but also information regarding certificates issued by public institutions that certify each user's unique information, such as a driver's license, passport, health insurance card, or employee ID card.
[0014] In addition, "information requiring special management" includes information regarding public identification information (i.e., national identification numbers) issued by the country or government, such as My Number or Social Security Number, that requires legal management.
[0015] "Special management" refers to management based on legal requirements or equivalent requirements, such as usage restrictions (including restrictions on data (file) creation), safety control measures (including management by contractors), and provision restrictions.
[0016] Furthermore, "identification has been successful" indicates that, for example, the attribute information such as the name in the user registration information and the attribute information indicated by the identity verification information are the same or are deemed to be the same. In particular, cases where a person is deemed to be the same include cases where at least important information that must be the same, such as name, matches, but non-important information such as part of the contact information (for example, phone number) does not match, or where there is a possible input error, such as a difference in part of the email address.
[0017] (2) The present invention also provides The providing means If it is determined that the type of the received personal identification information does not require special management, the personal identification information is provided to the service system together with the user registration information; The management means: When a notification indicating that the identity verification has been successful is received from the service system, the user registration information and identity verification information are registered in the database in association with each other and managed.
[0018] With this configuration, the present invention can use as personal identification information not only information that requires special management, but also a mixture of information other than information that requires special management, such as a driver's license or passport, thereby improving the convenience of users in registering for services.
[0019] (3) In order to solve the above problems, the present invention provides: A user registration management system that works in conjunction with a terminal device to which information about a user is input as user-related information, and manages the user's registration for a given service based on the user-related information, a reception processing means for executing a reception process for receiving user-related information transmitted from the terminal device when the user wishes to register for use of the service, the user-related information including user registration information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register; a determination processing means for executing a determination process to determine whether the type of the received personal identification information is information that requires a given special management; providing means for providing the personal identification information together with the service identification information of the user to a management system that performs the special management when the personal identification is successfully authenticated based on the received user registration information and personal identification information and the type of the received personal identification information is determined to be information that requires the given special management by the determination process; a management means for registering and managing the user registration information in a given database by associating the received user registration information with service identification information for the user when using the service and linking the received user registration information with the identity verification information registered in the management system, when identity authentication based on the received user registration information and identity verification information is successful, on the premise that the identity verification information will be registered in the management system; The configuration includes:
[0020] With this configuration, when the present invention is used to register a user to use a network service, for example, when public identification information such as My Number, which requires special management with strict management regulations, is used as personal identification information, the personal identification information can be managed separately in a management system that meets special requirements such as legal requirements, different from the database used to register users of the service.
[0021] Therefore, the present invention allows a service provider to accept public identification information as personal identification information without having to prepare a management system such as a database that meets legal requirements. This reduces the financial and labor burden on the service provider, and by realizing robust personal authentication based on public identification information, it is possible to allow a wide range of users to register as users for network services.
[0022] (4) The present invention also provides The providing means If it is determined that the type of the received personal identification information does not require special management, the personal identification information is registered in the database together with the user registration information; The management means: If the user is successfully authenticated based on the received user registration information and personal identification information, the user registration information and personal identification information are associated with each other and registered in the database for management.
[0023] With this configuration, the present invention can use as personal identification information not only information that requires special management, but also a mixture of information other than information that requires special management, such as a driver's license or passport, thereby improving the convenience of users in registering for services.
[0024] (5) The present invention also provides The reception processing means performs the reception processing as follows: executes an input support process in cooperation with the terminal device to prompt seamless input of both the user-related information and the personal identification information; The terminal device is configured to accept the user registration information and the personal identification information that are input to the terminal device based on the input support process and transmitted directly from the terminal device.
[0025] With this configuration, when inputting personal identification information that requires special management, the present invention can accept, for example, all information required for input, including user-related information, via a communication line only with the relevant terminal device without the intervention of other devices.
[0026] Therefore, the present invention can reduce the rate at which users stop inputting information for user registration (dropout rate) compared to when user registration information and personal identification information are obtained by the intervention of other devices or by exchanging information with other devices.
[0027] In other words, since the present invention can collect user registration information and personal identification information using the same application, there is no non-coordination of the user interface for inputting user registration information and personal identification information, nor is there any confusion regarding the input of user identification information, compared to when the user is guided to input personal identification information and the input is carried out by changing the application through which the information is input or by changing the system through which the information is input, separate from the user registration information.
[0028] As a result, the present invention allows users to seamlessly input user-related information and personal identification information, thereby avoiding confusion regarding user input and procedures that may arise when switching between management systems to manage tasks such as registering personal identification information, and reducing the dropout rate when registering users.
[0029] (6) The present invention also provides In the user registration management system according to claim 1 or 3, The personal identification information includes image information in which the personal identification information is visualized.
[0030] With this configuration, the present invention not only ensures that the personal identification information is actually in the user's hands when registering for use, but also allows the imaged personal identification information to include an image of the person's face or upper body, which significantly improves the authenticity of the person and enables the personal identification information to be managed appropriately.
[0031] (7) In order to solve the above problems, the present invention provides: A program that works in conjunction with a terminal device to which information about a user is input as user-related information, and manages the user's registration for a given service based on the user-related information, a reception processing means for executing a reception process for receiving user-related information transmitted from the terminal device when the user wishes to register for use of the service, the user-related information including user registration information of the user who wishes to register and use the service, and personal identification information for performing personal identification of the user who wishes to register; a determination processing means for executing a determination process to determine whether the type of the received personal identification information is information that requires a given special management; a first provision control process for associating the received user registration information with service identification information for the user when using the service and providing the information to a service system that provides the given service; and a provision means for executing a second provision control process for providing the received personal identification information, together with the service identification information of the user, to a management system that performs the given special management when the type of the received personal identification information is determined to be information that requires the given special management by the determination process; a management means for registering and managing the user registration information in a given database in association with the service identification information or in association with the identity verification information provided to the management system, on the assumption that the identity verification information will be registered in the management system, when receiving a notification transmitted from the service system or the management system indicating that identity verification has been successful based on the provided user registration information and identity verification information; The computer has a configuration that causes the computer to function as a
[0032] With this configuration, when the present invention is used to register a user to use a network service and the personal identification information used is, for example, public identification information such as My Number, which is strictly regulated and requires special management, the personal identification information can be managed separately in a management system that meets special requirements such as legal requirements, different from the database used to register users of the service.
[0033] Therefore, the present invention can accept public identification information as personal identification information without requiring the service provider to prepare a management system such as a database that meets legal requirements, thereby reducing the financial and labor burden on the service provider and enabling a wide range of users to register for network services by realizing robust personal authentication based on public identification information.
[0034] (8) In order to solve the above problems, the present invention provides: A program that works in conjunction with a terminal device to which information about a user is input as user-related information, and manages the user's registration for a given service based on the user-related information, a reception processing means for executing a reception process for receiving user-related information transmitted from the terminal device when the user wishes to register for use of the service, the user-related information including user registration information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register; The type of the received personal identification information is information that requires special management. a determination processing means for executing a determination process for determining whether or not providing means for providing the personal identification information together with the service identification information of the user to a management system that performs the special management when the personal identification is successfully authenticated based on the received user registration information and personal identification information and the type of the received personal identification information is determined to be information that requires the given special management by the determination process; a management means for registering and managing the user registration information in a given database by associating the received user registration information with service identification information for the user when using the service and linking the received user registration information with the identity verification information registered in the management system, when identity authentication based on the received user registration information and identity verification information is successful, on the premise that the identity verification information will be registered in the management system; The configuration includes:
[0035] With this configuration, when the present invention is used to register a user to use a network service and the personal identification information used is, for example, public identification information such as My Number, which is strictly regulated and requires special management, the personal identification information can be managed separately in a management system that meets special requirements such as legal requirements, different from the database used to register users of the service.
[0036] Therefore, the present invention can accept public identification information as personal identification information without requiring the service provider to prepare a management system such as a database that meets legal requirements, thereby reducing the financial and labor burden on the service provider and enabling a wide range of users to register for network services by realizing robust personal authentication based on public identification information.
[0037] (9) In order to solve the above problems, the present invention provides: A user registration management method that operates in conjunction with a terminal device to which information about a user is input as user-related information, and manages the user's registration for a given service based on the user-related information, comprising: When the user wishes to register for use of the service, a reception process is executed to receive user-related information transmitted from the terminal device, the user registration information of the user who wishes to register and use the service, and personal identification information for performing personal identification of the user who wishes to register; execute a determination process to determine whether the type of the received personal identification information is information that requires a given special management; a first provision control process for associating the received user registration information with service identification information for the user when using the service and providing the information to a service system that provides the given service; and a second provision control process for providing the received personal identification information, together with the service identification information of the user, to a management system that performs the given special management when the type of the received personal identification information is determined to be information that requires the given special management by the determination process, When receiving a notification transmitted from the service system or the management system indicating that identity verification has been successful based on the provided user registration information and identity verification information, registering and managing the user registration information in a given database in association with the service identification information or in association with the identity verification information provided to the management system, on the premise that the identity verification information will be registered in the management system. The present invention has a configuration including the above.
[0038] With this configuration, the present invention is applicable to a case where user registration for using a network service is performed, and the user uses, for example, a public identification number such as a My Number as personal identification information. When using information that requires special management with strict management regulations, the personal identification information can be managed separately in a management system that meets special requirements such as legal requirements, different from the database used to register users of the service.
[0039] Therefore, the present invention can accept public identification information as personal identification information without requiring the service provider to prepare a management system such as a database that meets legal requirements, thereby reducing the financial and labor burden on the service provider and enabling a wide range of users to register for network services by realizing robust personal authentication based on public identification information.
[0040] (10) In order to solve the above problems, the present invention provides: A terminal device that performs a process related to a user's registration for a given service based on user-related information indicating information about the user, an operation input means used to input, when the user wishes to register for use of the service, user-related information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register, as the user-related information; a determination processing means for executing a determination process to determine whether the type of the input personal identification information is information that requires a given special management; an output control means for executing a first output control process for associating the input user registration information with service identification information for the user when using the service, and outputting the information to a service system that provides the given service or a user registration management system that manages registration of the user; and a second output control process for outputting the personal identification information, together with the service identification information of the user, to a management system that manages the special management when the type of the personal identification information received by the determination process is determined to be information that requires the special management; a notification control means for notifying the user that registration for a given service has been completed when a notification is received from the service system, the user registration management system, or the management system indicating that identity verification has been successful based on the provided user registration information and identity verification information; and The configuration includes:
[0041] With this configuration, when performing user registration to use a network service, and when using public identification information such as My Number, which is information that requires strict management regulations and special management, as personal identification information, the personal identification information can be managed separately in a management system that meets special requirements such as legal requirements, different from the database where service user registration is performed.
[0042] Therefore, the present invention can accept public identification information as personal identification information without requiring the service provider to prepare a management system such as a database that meets legal requirements, thereby reducing the financial and labor burden on the service provider and enabling a wide range of users to register for network services by realizing robust personal authentication based on public identification information.
[0043] (11) In order to solve the above problems, the present invention provides: A program for performing a process related to a user's registration for a given service based on user-related information indicating information about the user, When the user wishes to register for use of the service, an operation input is used to input user-related information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register, as the user-related information. force means, a determination processing means for executing a determination process to determine whether the type of the input personal identification information is information that requires a given special management; a first output control process for associating the input user registration information with service identification information for the user when using the service, and outputting the information to a service system that provides the given service or a user registration management system that manages the registration of the user; and an output control means for executing a second output control process for, when it is determined that the type of the personal identification information received by the determination process is information that requires the given special management, outputting the personal identification information together with the service identification information of the user to a management system that performs the special management; a notification control means for notifying the user that registration for a given service has been completed when a notification is received from the service system, the user registration management system, or the management system indicating that identity verification has been successful based on the provided user registration information and identity verification information; The computer has a configuration that causes the computer to function as a
[0044] With this configuration, when performing user registration to use a network service, and when using public identification information such as My Number, which is information that requires strict management regulations and special management, as personal identification information, the personal identification information can be managed separately in a management system that meets special requirements such as legal requirements, different from the database where service user registration is performed.
[0045] Therefore, the present invention can accept public identification information as personal identification information without requiring the service provider to prepare a management system such as a database that meets legal requirements, thereby reducing the financial and labor burden on the service provider and enabling a wide range of users to register for network services by realizing robust personal authentication based on public identification information. [Brief explanation of the drawings]
[0046] [Figure 1] 1 is a system configuration diagram showing a configuration of an authentication management communication system according to an embodiment. [Figure 2] FIG. 2 is a functional block diagram illustrating a configuration of an authentication server device according to an embodiment. [Figure 3] FIG. 2 is a functional block diagram illustrating an example of a configuration of a terminal device according to an embodiment. [Figure 4] FIG. 10 is a diagram illustrating a user registration process executed by the authentication server device according to the embodiment. [Figure 5] 10A and 10B are diagrams for explaining the reception process executed by the authentication server device according to one embodiment, and are diagrams for explaining screen transitions in the user registration process displayed on the terminal device. [Figure 6] FIG. 10 is an example of a functional block diagram showing a configuration of a service server device according to a first modified example of one embodiment. [Figure 7] FIG. 10 is a functional block diagram illustrating an example of the configuration of a terminal device according to a second modification of the embodiment. [Figure 8] 10 is a flowchart illustrating an operation of a user registration process executed by the authentication server device according to one embodiment. [Figure 9] 10 is a flowchart illustrating an operation of a user registration process executed by the authentication server device according to one embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0047] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0048] The embodiment described below is an embodiment in which the user usage registration management system of the present application is applied to part (including a combination of server devices) or all of the configuration of a network service management system that has a terminal device used by a user, a usage registration management server device that executes processing related to user usage registration for a given network service, a network service server device that provides the network service, and a personal identification information management server device that registers and manages personal identification information.
[0049] [1] Network Service Management System First, an overview of the network service management system S of this embodiment will be described with reference to FIG.
[0050] FIG. 1 is a system configuration diagram showing the configuration of a network service management system S in this embodiment.
[0051] In addition, to prevent the diagram from becoming too complicated, Figure 1 only shows terminal devices 20 owned by some users and a network service server device (hereinafter also referred to as a "service server device") 30 that provides network services.
[0052] That is, in the actual network service management system S, there are many more terminal devices 20 and service server devices 30 than are shown in FIG.
[0053] The network service management system S of this embodiment is a system that executes various processes related to the registration of a user who wishes to register for use of a given network service (hereinafter referred to as a "registration-desiring user").
[0054] In particular, the network service management system S of this embodiment is configured to acquire information about a user wishing to register as user-related information, as well as acquire identity verification information (hereinafter referred to as "identity verification information") that proves the identity of the user wishing to register, and if identity verification is successful based on the user-related information and identity verification information, to register the user wishing to register as a registered user.
[0055] Furthermore, the network service management system S of this embodiment is configured to perform special management of the personal identification information together with the service identification information of the user in question when registering as a registered user if the type of personal identification information is information that requires special management.
[0056] In other words, when public identification information such as My Number or Social Security Number, which is information whose management is strictly regulated and requires special management, is used as personal identification information, the network service management system S of this embodiment is configured to perform special management of the personal identification information in accordance with legal requirements, etc., in order to reduce the financial and labor burden on the service provider of the network service and to allow a wide range of users to register as users for the network service by realizing robust personal authentication based on the public identification information.
[0057] Specifically, as shown in FIG. 1, the network service management system S of this embodiment includes an authentication server device 10 that manages user registration, terminal devices 20 (e.g., terminal devices 20A, 20B, and 20C) that are connected to a network such as the Internet and on which users perform various operations related to user registration, a service server device 30 that provides predetermined network services, and information about each user such as a personal management number (e.g., My Number). The personal identification information management server device 40 manages (information management) personal identification information for performing personal identification, including user-specific identification information, in accordance with legal requirements, and provides and manages personal identification services.
[0058] The authentication server device 10 is an information processing device that uses, for example, an API (Application Programming Interface) or a predetermined platform to perform various processes related to user registration, including the collection of user registration information and personal identification information when registering for a network service (hereinafter referred to as "user registration process"), and authentication for using the service after the user registration (hereinafter simply referred to as "authentication process").
[0059] In particular, when performing processing related to user registration to a network service (hereinafter referred to as "user registration processing"), the authentication server device 10 is configured to perform processing to link the corresponding terminal device 20 with the personal identification information management server device 40.
[0060] The authentication server device 10 is configured to register a user who wishes to register as a user who provides network services (i.e., a registered user) when the user's identity is confirmed through a process (hereinafter referred to as "identity confirmation process") to confirm whether the user is the person in question when the user registration process is executed (i.e., when the identity confirmation authentication is successful).
[0061] The authentication server device 10 may be configured as one (device, processor) or as multiple (devices, processors).
[0062] The authentication server device 10 also has various databases (broadly speaking, storage devices, memories) that store various information used in the user registration process and authentication process of registered users. However, the authentication server device 10 of this embodiment may also access databases (broadly speaking, storage devices, memories) connected via a network (intranet or the Internet).
[0063] The terminal device 20 is a communication terminal device that is used by a user and is configured by an information processing device such as a PC (personal computer), a tablet-type information communication terminal device, a smartphone, a mobile phone, a game device, or an HMD.
[0064] In addition, the terminal device 20 is a device that can be connected to the authentication server device 10 via a network such as the Internet (WAN) or LAN, and is configured to establish a communication line with the authentication server device 10 via wired or wireless means to exchange various data.
[0065] In addition, the terminal device 20 has a configuration that includes a function for acquiring information input by the user (e.g., user registration information and personal identification information), a communication control function for communicating with the authentication server device 10 or the service server device 30, and a display function for performing display control using data received from the authentication server device 10 or the service server device 30.
[0066] The service server device 30 is a server device for providing various network services, including banking services that provide financial institution-related services, reservation services for restaurants, inns, transportation, etc., product sales services, SNS services, content provision services such as games, music, and videos, cloud services such as various applications such as email, and information provision services such as search and advertisements.
[0067] Specifically, when the authentication of a registered user who has been registered by the authentication server device 10 is successful, the service server device 30 assigns the network service to be provided. The system is configured to allow the user to log in and execute various processes to provide the corresponding services to the user.
[0068] In addition, when a user registration process is executed, the service server device 30 is configured to, in conjunction with the personal identification information management server device 40 or independently, use the user registration information and personal identification information to perform a process of determining whether or not user registration, including personal identification processing, is possible (hereinafter referred to as the "registration determination process"), or a process related to the personal identification process (hereinafter referred to as the "personal identification-related process").
[0069] In particular, the service server device 30 is configured to execute a process as part of identity verification-related processing, in which if identity verification authentication is successful through identity verification processing or the like, a notification indicating this (a notification indicating that identity verification has been successful) is provided to the authentication server device 10.
[0070] In addition, the service server device 30 may perform identity verification processing by automatically matching identity verification information with user registration information, or may perform identity verification-related processing by providing user registration information to the identity verification information management server device 40, causing it to perform identity verification processing and obtaining the results.
[0071] Then, the service server device 30 may present the user registration information and the personal identification information to the administrator (by manually comparing them), and obtain the result of the personal identification based on an instruction from the administrator.
[0072] The personal identification information management server device 40 is an information processing device that works in conjunction with the authentication server device 10 and manages personal identification information.
[0073] In particular, the personal identification information management server device 40 is an information processing device that performs special management (information management) based on legal requirements for information such as My Number or Social Security Number, whose management is strictly regulated and requires special management.
[0074] Furthermore, the personal verification information management server device 40 may be configured as one (device, processor) or as multiple (devices, processors).
[0075] Specifically, similar to the authentication server device 10, the personal identification information management server device 40 has a configuration that performs authentication based on personal identification information (i.e., personal identification processing) by coordinating with the authentication server device 10 or the terminal device 20, or independently, using, for example, an API (application programming interface) or a predetermined platform.
[0076] Furthermore, the personal identification information management server device 40 has various databases (broadly speaking, storage devices, memories) that store personal identification information of each specific user and various information used in authentication processing related to personal identification. However, the personal identification information management server device 40 of this embodiment may also access databases (broadly speaking, storage devices, memories) connected via a network (an intranet or the Internet).
[0077] In addition, when the personal identification information management server device 40 performs the personal identification process instead of the service server device 30, it may present the user registration information and personal identification information to an administrator and obtain the success or failure of the personal identification based on the administrator's instructions.
[0078] [2] Authentication server device Next, the authentication server device 10 of this embodiment will be described with reference to Fig. 2. Fig. 2 is an example of a functional block diagram showing the configuration of the authentication server device 10 of this embodiment.
[0079] As shown in FIG. 2, the authentication server device 10 of this embodiment includes a processing unit 100, a database 140, a storage unit 170, an information storage medium 180, and a communication unit 196.
[0080] The authentication server device 10 does not need to include all of the components shown in FIG. 2, and may have a configuration in which some of them are omitted.
[0081] The storage unit 170 serves as a work area for the processing unit 100 and the like, and its function can be realized by hardware such as RAM (VRAM). In particular, the storage unit 170 functions as a work area used when various processes are executed.
[0082] The information storage medium 180 is computer-readable, and stores programs, data, etc. In other words, the information storage medium 180 stores programs for causing a computer to function as each unit of this embodiment (programs for causing a computer to execute the processing of each unit).
[0083] The processing unit 100 can perform various processes of this embodiment based on data read from a program (data) stored in this information storage medium 180.
[0084] For example, the information storage medium 180 is an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.
[0085] The database 140 is formed by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.
[0086] In addition, database 140 is a database in which user registration information (including information about each user for performing authentication processing when logging in to the network service) registered when a user registers for the network service provided by each service server device 30 is registered.
[0087] In particular, the database 140 stores, for each user, the following information in association with each user ID: (A1) User name, (A2) Password, (A3) Network identification information (hereinafter referred to as "specific key information"), and (A4) User-related information of the user (e.g., name, credit card number, contact information such as email address and mobile phone number), User registration information such as the above is stored.
[0088] The communication unit 196 performs various controls for communicating with the outside (for example, the terminal device 20 or the service server device 30), and its functions are configured by hardware such as various processors or communication ASICs, programs, etc.
[0089] The processing unit 100 performs various processes of this embodiment based on programs (data) stored in the storage unit 170. Note that the processing unit 100 of this embodiment may read out programs and data stored in the information storage medium 180, temporarily store the read out programs and data in the storage unit 170, and perform processing based on the programs and data.
[0090] The processing unit 100 (processor) performs various processes using the main memory in the memory unit 170 as a work area. The functions of the processing unit 100 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.
[0091] Specifically, the processing unit 100 includes a communication control unit 101, an information management unit 102, an information type determination processing unit 103, an information linkage processing unit 104, an authentication processing unit 105, a registration control unit 106, a timer management unit 110, and an information provision unit 111.
[0092] The communication control unit 101 establishes a communication line with the terminal device 20, the service server device 30, etc. via the network, and communicates with them.
[0093] The information management unit 102 executes a reception process for receiving the user registration information and personal identification information input via each terminal device 20 for each terminal device 20 .
[0094] The information type determination processing unit 103 executes a determination process to determine whether the type of the received personal verification information is information that requires a given special management (for example, whether it is a My Number).
[0095] For user registration, the information linking processing unit 104 performs various processes to provide user registration information and personal identification information to the service server device 30 or personal identification information management server device 40 that provides the service for which the user wishes to register.
[0096] The authentication processing unit 105 receives authentication information (hereinafter referred to as "authentication information") input via each terminal device 20 for each terminal device 20, and performs authentication processing for each user based on the received authentication information (specifically, a user name or user ID and password, etc.) and the authentication information of the corresponding user already registered in the database 140 (i.e., a user name or user ID and password).
[0097] The registration control unit 106 registers the user registration information, or the user registration information and personal identification information, in the database 140 when executing the user registration process.
[0098] The timer management unit 110 has a function of measuring the current date and time and from a predetermined timing, and outputs the current time and the measurement result when the predetermined timing arrives.
[0099] The information providing unit 111 provides the input information such as the user registration information and personal identification information to the authentication server device 10 or the service server device 30.
[0100] [3] Terminal device Next, the functions of the terminal device 20 will be described with reference to Fig. 3. Fig. 3 is a functional block diagram showing an example of the configuration of the terminal device 20 of this embodiment.
[0101] As shown in FIG. 3, the terminal device 20 of this embodiment has a processing unit 200, a card reader / writer 240, an imaging unit 250, an operation input unit 260 consisting of a touch panel or the like, a memory unit 270, an information storage medium 280, a display unit 290 consisting of a display element such as a liquid crystal panel, a communication unit 296, and a sound output unit 292.
[0102] The card reader / writer 240 reads and writes information from and to an IC card (not shown) held by the user.
[0103] For example, the card reader / writer 240 of this embodiment may be an IC card (not shown). The personal identification information including the personal management number is read from the
[0104] The card reader / writer 240 can be realized by, for example, a card reader for NFC (Near Field Communication).
[0105] The imaging unit 250 is made up of an imaging camera having a predetermined imaging angle and focal length and a predetermined imaging element such as a CCD, and an image generating unit that converts the output of the imaging camera into an image.
[0106] In addition, the imaging unit 250 works in conjunction with the processing unit 200, and when performing user registration processing, for example, it captures the user's face and transmits image information, which is a digitalized image of the face or an image of the upper body including the face, to the authentication server device 10.
[0107] The operation input unit 260 is a device for inputting input information from the player, and outputs the input information from the player to the processing unit 200 .
[0108] The operation input unit 260 of this embodiment has a configuration for detecting input information (input signals) from the user, and is composed of, for example, a lever, a button, a microphone, a touch panel display, a keyboard, a mouse, and the like.
[0109] The storage unit 270 serves as a work area for the processing unit 200 and the like, and its function can be realized by hardware such as RAM (VRAM).
[0110] The storage unit 270 of this embodiment includes a main storage unit 271 used as a work area, an image buffer 272 in which display images and the like to be displayed during user registration processing are stored, and a user-related information storage unit 273 in which user-related information including part or all of the user registration information is stored. Note that some of these may be omitted.
[0111] The information storage medium 280 is computer-readable, and stores various applications, an OS (operating system), and, in particular, in this embodiment, various data including the user ID of the user corresponding to the terminal device 20.
[0112] That is, the information storage medium 280 stores applications for causing a computer to function as each unit of this embodiment (applications for causing a computer to execute the processing of each unit) and a user ID.
[0113] For example, the information storage medium 280 is an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk drive, a flash memory, a magnetic tape, a memory (ROM), a memory card, or the like.
[0114] The communication unit 296 performs various controls for communicating with the outside (e.g., other terminal devices 20, authentication server device 10, and service server device 30), and its functions are configured by hardware such as various processors or communication ASICs, programs, etc.
[0115] The processing unit 200 can perform various processes of this embodiment by reading and executing the applications stored in this information storage medium 280. Note that the types of applications stored in the information storage medium 280 are arbitrary.
[0116] The processing unit 200 performs various processes of this embodiment based on the application stored in the information storage medium 280. Note that the processing unit 200 of this embodiment may read out programs and data stored in the information storage medium 280, temporarily store the read out programs and data in the storage unit 270, and perform processing based on the programs and data.
[0117] The processing unit 200 (processor) performs various processes using the main memory in the memory unit 270 as a work area. The functions of the processing unit 200 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.
[0118] The processing unit 200 includes a communication control unit 210, a web browser 211, an imaging control unit 212, a display control unit 213, an input reception processing unit 214, a reading control unit 215, a drawing unit 220, and a sound processing unit 230. Note that some of these units may be omitted.
[0119] The communication control unit 210 performs processing to send and receive data to and from the authentication server device 10 or the service server device 30 .
[0120] In addition, the communication control unit 210 receives data transmitted from the authentication server device 10 or the service server device 30, and performs processes such as storing the received data in the memory unit 270, analyzing the received data, and controlling other processes related to the transmission and reception of data.
[0121] The communication control unit 210 may store the destination information (IP address, port number) of the authentication server device 10 or the service server device 30 in the information storage medium 280 and perform processing for managing it.
[0122] Then, the communication control unit 210 may communicate with the authentication server device 10 or the service server device 30 when receiving input information from the user to start communication.
[0123] The communication control unit 210 may also communicate with the service server device 30 via the authentication server device 10.
[0124] In addition, the communication control unit 210 may send and receive data with the authentication server device 10 or the service server device 30 at a predetermined interval, or may send and receive data with the authentication server device 10 or the service server device 30 when input information is received from the operation input unit 260.
[0125] The web browser 211 is an application program for viewing web pages (authentication screen, user registration processing screen, or service enjoyment screen), and downloads HTML files, image files, etc. from the web server (authentication server device 10 or service server device 30), analyzes the layout, and controls the display.
[0126] Furthermore, the Web browser 211 transmits data to the Web server (the authentication server device 10 or the service server device 30) using an input form (links, buttons, text boxes, etc.).
[0127] The terminal device 20 can use the Web browser 211 to display information from a Web server (for example, the service server device 30) specified by a URL via the Internet.
[0128] For example, the terminal device 20 displays each content (data such as HTML) received from the authentication server device 10 or the service server device 30 on the web browser 211. It is possible.
[0129] When the imaging control unit 212 works in conjunction with the authentication server device 10 to perform user registration processing including identity verification processing, it causes the imaging unit 250 to capture an image of the user's face and generate facial image information (hereinafter referred to as "captured facial image information" or "captured image information").
[0130] The display control unit 213 performs processing for displaying on the display unit 290. For example, the display control unit 213 may use the web browser 211 for display.
[0131] The input reception processing unit 214 recognizes input information (specifically, user registration information and personal identification information) input by the user from the operation input unit 260, and receives the recognized information.
[0132] The reading control unit 215 controls a card reader / writer 240 that reads personal identification information from an IC card (not shown) or the like.
[0133] That is, the reading control unit 215 can also acquire personal identification information from an IC card (not shown) instead of the operation input unit 260.
[0134] The drawing unit 220 performs drawing processing based on various processes performed by the processing unit 200, thereby generating an image, which is output to the display unit 290 by the display control unit 213.
[0135] The sound processing unit 230 performs sound processing based on the results of various processes performed by the processing unit 200 , generates background music, sound effects, voice, or the like, and outputs them to the sound output unit 292 .
[0136] [4] Method of this embodiment [4.1] Overview Next, the user registration process executed by the authentication server device 10 of this embodiment will be described with reference to FIG.
[0137] FIG. 4 is a diagram for explaining the user registration process executed by the authentication server device 10 of this embodiment.
[0138] The authentication server device 10 of this embodiment is a device that works in conjunction with a terminal device 20 to which information about a user is input as user-related information, and manages the user's registration for use of a given service (i.e., user registration management) based on the user-related information.
[0139] In particular, the authentication server device 10 of this embodiment is configured to collect information necessary for registration (i.e., user registration information) and identity verification information for verifying that the user is a real person from a user who wishes to register to enjoy a given network service provided by the service server device 30.
[0140] In addition, the authentication server device 10 of this embodiment is configured to work in conjunction with the service server device 30 and the identity verification information management server device 40 to manage the various types of collected information when identity verification is successful based on the user registration information and identity verification information.
[0141] Specifically, as shown in FIG. 4, the authentication server device 10: (A1) When a user wishes to register for use of a service, user-related information transmitted from the terminal device 20 is received, including user registration information of the user who wishes to register and use the service, and personal identification information for verifying the identity of the user who wishes to register. Reception processing, (A2) A determination process for determining whether the type of the received personal identification information is information that requires a given special management; (A3) An information linking process in which the accepted user registration information is associated with service identification information for use by the corresponding user when using the service, and is provided to a service server device 30 that provides a given service, and when the type of the accepted personal identification information is determined by the determination process to be information requiring given special management, the personal identification information is provided to a management system that performs the special management together with the service identification information of the corresponding user; and (A4) A registration control process in which, when a notification transmitted from the service server device 30 or the personal identification information management server device 40 indicating that personal identification has been successful based on the provided user registration information and personal identification information is received, the registration control process registers and manages the user registration information in the database 140 in association with the service identification information and in conjunction with the personal identification information provided to the personal identification information management server device 40, on the premise that the personal identification information will be registered in the personal identification information management server device 40; The system has a configuration for executing the above.
[0142] In addition to the above, Figure 4 also shows that if the personal identification information is publicly managed identification information, the personal identification information is registered in the personal identification information management server device 40, and if the personal identification information is not publicly managed identification information (if it is non-publicly managed identification information), the personal identification information is registered in the authentication server device 10 (specifically, database 140) together with the user registration information, and that the service server device 30 and the personal identification information management server device 40 work together for personal identification processing, etc., and shows an example of authentication processing for a user by the terminal device 20, the authentication server device 10, and the service server device 30.
[0143] With this configuration, when the authentication server device 10 of this embodiment performs user registration for using a network service and uses public management identification information such as My Number as personal identification information, the personal identification information can be managed separately in the personal identification information management server device 40, which has special requirements such as legal requirements, different from the database 140 that performs service usage registration.
[0144] Therefore, the authentication server device 10 of this embodiment can accept public identification information as personal identification information without requiring the service provider to prepare a personal identification information management server device 40 such as a database that meets legal requirements, thereby reducing the financial and labor burden on the service provider and enabling a wide range of users to register as users for network services by realizing robust personal authentication based on public identification information.
[0145] In this embodiment, the user registration information and personal identification information include, for example, image information of a face image or an upper body image including a face image, but may also be image information of a body part that can be distinguished from other people, such as a fingerprint or retina. However, basically, an image that includes a face image that can be easily distinguished visually is preferable, and in this embodiment, a face image will be used as image information included in personal identification information, etc.
[0146] [4.2] Reception process Next, the reception process executed by the authentication server device 10 of this embodiment will be described as shown in FIG.
[0147] 5 shows the reception process executed by the authentication server device 10 of this embodiment. 10 is a diagram for explaining the screen transition of the user registration process displayed on the terminal device 20. FIG.
[0148] The information management unit 102 works in conjunction with the communication control unit 101 to connect a communication line to the terminal device 20 via the communication unit 196 and executes a reception process to acquire user registration information and personal identification information sent from the terminal device 20.
[0149] In particular, the information management unit 102 works in conjunction with the terminal device 20 operated by a user who wishes to register as a user, and performs input support processing to prompt the user to seamlessly input both user-related information and personal identification information.
[0150] The information management unit 102 then receives the user registration information and personal identification information that are input to the terminal device 20 based on the input support process and transmitted directly from the terminal device 20 .
[0151] The information management unit 102 also accepts the attribute information of the person and image information relating to the person as user registration information, and also accepts information relating to the personal identification document as personal identification information.
[0152] Specifically, the information management unit 102 stores the following as user registration information: (A1) User's name, (A2) Address or residence, (A3) Contact information (phone number, email address, or designated app ID, etc.), (A4) Age, (A5) Family structure, (A6) Annual income, and (A7) Image information of the user's face image or an upper body image including the face image (so-called selfie image), The attribute information regarding the user's attributes such as the above is accepted.
[0153] In addition, the information management unit 102 stores the following as personal identification information: (B1) Officially managed identification information such as My Number or Social Security Number, or text information contained in a certificate issued by a public institution that certifies each user's unique information, such as a driver's license, passport, health insurance card, or employee ID card; (B2) the official control identification information or image information of the certificate; and (B3) Type of identity verification information; Accept.
[0154] In particular, the information management unit 102 may accept as type information the type indicated by the user from among multiple types presented to the user when accepting the personal identification information, or may identify the type by recognizing the layout of the certificate or the text of the certificate from the image shown by the image information, and accept the identified type as type information.
[0155] In addition, when accepting user registration information and personal identification information, the information management unit 102 works in conjunction with the service server device 30 or in accordance with an application to issue identification information (i.e., service identification information) for each user and for each network service for which registration is desired.
[0156] Then, the information management unit 102 associates the issued service identification information with the received user registration information and personal identification information, and sends the service identification information to the corresponding terminal device 20. Provide identification information.
[0157] For example, as shown in FIG. 5, the information management unit 102 executes control for reception processing, such as initiating an application for user registration (opening an account in an online banking service), agreeing to terms and conditions, authenticating an email address, etc., selecting an identity verification / number verification document (an example in FIG. 5 shows a driver's license being selected), a liveness check (checking whether the user is alive or dead), taking a facial image, taking a photo of an identity verification document, entering personal identification information, and displaying various images related to the completion of the application, and based on this, accepts various pieces of information input to the terminal device 20.
[0158] [4.3] Judgment process Next, the determination process executed by the authentication server device 10 of this embodiment will be described.
[0159] The information type determination processing unit 103 executes a determination process to determine whether the type of personal verification information received in the reception process is information that requires a given special management.
[0160] In particular, the information type determination processing unit 103 determines whether the type of the received personal identification information is information regarding public identification information (i.e., national identification number) such as a My Number or a Social Security Number, and is information that requires legal management.
[0161] In particular, the information type determination processing unit 103 determines whether the type of the received personal identification information is information related to official identification information in order to perform legal management of the relevant personal identification information.
[0162] Specifically, the information type determination processing unit 103 identifies the type of the accepted personal identification information based on type information obtained by having the user wishing to register identify the type of personal identification information when the personal identification information is input by the information management unit 102.
[0163] [4.4] Information linkage processing Next, the information linking process executed by the authentication server device 10 of this embodiment will be described.
[0164] The information linking processing unit 104 cooperates with the communication control unit 101 and the information providing unit 111 to perform a process of associating the received user registration information with the service identification information of the corresponding user and providing it to the service server device 30 that provides the corresponding service (hereinafter referred to as the "user registration information providing process (first providing control process)").
[0165] In particular, since the service server device 30 performs user registration processing including identity verification processing, the information linking processing unit 104 provides the accepted user registration information to the service server device 30 in association with the service identification information.
[0166] On the other hand, the information linking processor 104 provides the received personal identification information to the personal identification information management server device 40 and registers it in the database 140 depending on the result of the determination process for determining the type of personal identification information.
[0167] In particular, when the information linking processing unit 104 determines that the type of the received personal identification information is information related to public identification information (i.e., publicly managed identification information) through the determination processing, the information linking processing unit 104 links with the communication control unit 101 and the information providing unit 111 to associate the received personal identification information with the service identification information of the corresponding user, and (hereinafter referred to as "special personal identification information provision process (second provision control process)").
[0168] In other words, if the type of personal identification information accepted by the determination process is determined to be publicly managed identification information, the information linking processing unit 104 provides the personal identification information to the personal identification information management server device 40 so that the personal identification information can be appropriately managed by the personal identification information management server device 40, which meets legal requirements.
[0169] In this case, the personal authentication process is performed by the service server device 30, and the personal identification information is provided to the service server device 30 via the personal identification information management server device 40.
[0170] Furthermore, if the type of personal identification information received through the judgment process is determined to not be information related to publicly managed identification information, the personal identification information is registered in database 140 without being provided to personal identification information management server device 40, as described below.
[0171] On the other hand, if the information linkage processing unit 104 determines in the determination process for determining the type of personal identification information that the type of the received personal identification information is not publicly managed identification information, it provides the received personal identification information together with the user registration information to the service server device 30.
[0172] In other words, in this case, as described above, the service server device 30 executes the user registration process including the identity verification process, but since the identity verification information management server device 40 does not manage the identity verification information, the identity verification information is provided to the service server device 30 via the identity verification information management server device 40.
[0173] [4.5] Registration control process Next, a registration control process executed by the authentication server device 10 of this embodiment will be described.
[0174] When the service server device 30 executes a user registration process including identity verification processing and receives a notification indicating that identity verification has been successful based on the user registration information and identity verification information, the registration control unit 106 registers the user registration information or the user registration information and identity verification information in the database 140.
[0175] In particular, when personal identification information is registered in the personal identification information management server device 40, the registration control unit 106 registers and manages the user registration information in the database 140 by associating it with the service identification information or by linking it with the personal identification information provided to the personal identification information management server device 40.
[0176] For example, when personal identification information provided to the personal identification information management server device 40 is linked to user registration information registered in the database 140, the registration control unit 106 specifies the personal identification information associated with the corresponding user registration information, and It is sufficient that the personal identification information can be read.
[0177] That is, in this case, the registration control unit 106 registers the user registration information in the database 140 together with specific information such as an ID or address when the personal identification information is registered in the personal identification information management server device 40 .
[0178] On the other hand, the registration control unit 106 controls the personal identification information to be registered in the personal identification information management server device 40. If not, the user registration information and personal identification information are registered in the database 140 in association with the service identification information and managed.
[0179] That is, when the registration control unit 106 receives a notification from the service server device 30 indicating that the identity verification has been successful, it registers the user registration information and identity verification information in the database 140 in association with each other and manages them.
[0180] [4.6] Authentication process (login to network services) Next, the authentication process executed by the authentication server device 10 of this embodiment will be described.
[0181] The authentication processing unit 105 receives authentication information (specifically, a user name or a user ID and a password, etc.) input via each terminal device 20, and performs authentication processing for each user based on the received authentication information and the user registration information (i.e., a user name or a user ID and a password) of the corresponding user that has already been registered in the database 140.
[0182] If the received authentication information matches the user registration information, the authentication processing unit 105 determines that the authentication process is successful, establishes a communication line between the relevant terminal device 20 and a specific service server device 30, and executes login to the network service provided by the service server device 30 (i.e., login to the specific network service).
[0183] [4.7] Variations [4.7.1] Variation 1 Next, a first modification of this embodiment will be described with reference to Fig. 6. Fig. 6 is an example of a functional block diagram showing the configuration of the service server device 31 of this modification.
[0184] (Features of the modified example) This modification is characterized in that the functions of the authentication server device 10 that executes various processes related to the user registration process are realized by the service server device 31.
[0185] That is, the service server device 30 of this modified example has a configuration for executing various processes related to the user registration process.
[0186] In this modification, the same components as those in the above embodiment are denoted by the same reference numerals and their description will be omitted.
[0187] In this case, the service server device 31 is configured to work in conjunction with the terminal device 20 that has been input as user-related information, and to manage the user's registration for a given service based on the user-related information.
[0188] (Summary configuration) As shown in FIG. 6, the service server device 31 of this modified example: (A1) A reception process for receiving user-related information transmitted from the terminal device 20 when a user wishes to register for use of a service, the user-related information including user registration information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register; (A2) A determination process for determining whether the type of the received personal identification information is information that requires a given special management; (A3) User authentication is successful based on the accepted user registration information and personal identification information. and a providing process for providing the personal identification information, together with the service identification information of the corresponding user, to a personal identification information management server device 40 that performs the special management when the type of the personal identification information received by the determining process is determined to be information that requires a given special management; and (A4) A registration control process in which, if identity authentication is successful based on the accepted user registration information and identity verification information, the accepted user registration information is associated with service identification information for use when the user uses a service, and linked to the identity verification information registered in the identity verification information management server device 40, and the user registration information is registered in a given database and managed, on the premise that the identity verification information is registered in the management system; The system has a configuration for executing the above.
[0189] In addition, the service server device 31 (B1) If it is determined by the determination process that the type of the received personal identification information is not information requiring a given special management, the personal identification information is registered in the database 340 together with the user registration information; (B2) If personal authentication is successful based on the received user registration information and personal identification information, the user registration information and personal identification information may be associated with each other and registered in database 340 for management.
[0190] (Specific configuration) The storage unit 370 serves as a work area for the processing unit 300 and the like, and its function can be realized by hardware such as RAM (VRAM). In particular, the storage unit 370 functions as a work area used when various processes are executed.
[0191] The information storage medium 380 is computer-readable, and stores programs, data, etc. In other words, the information storage medium 180 stores programs for causing a computer to function as each unit of the present embodiment (programs for causing a computer to execute the processing of each unit).
[0192] The processing unit 300 can perform various processes of this embodiment based on data read from the program (data) stored in this information storage medium 380.
[0193] For example, the information storage medium 380 is an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.
[0194] The database 340 is formed by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.
[0195] In addition, database 340 is a database in which user registration information (including information about each user for performing authentication processing when logging in to the network service) registered when a user registers for a network service is registered.
[0196] In particular, the database 340 stores, for each user, the following information in association with each user ID: (C1) User name, (C2) Password, (C3) Network identification information (hereinafter referred to as "specific key information"), and (C4) User-related information of the user (e.g., name, credit card number, contact information such as email address and mobile phone number), User registration information such as the above is stored.
[0197] The communication unit 396 performs various controls for communicating with the outside (for example, the terminal device 20 or the service server device 30), and its functions are configured by hardware such as various processors or communication ASICs, programs, etc.
[0198] The processing unit 300 performs various processes of this embodiment based on the programs (data) stored in the storage unit 170. Note that the processing unit 300 of this embodiment may read out the programs and data stored in the information storage medium 180, temporarily store the read out programs and data in the storage unit 170, and perform processing based on the programs and data.
[0199] The processing unit 300 (processor) performs various processes using the main memory in the memory unit 370 as a work area. The functions of the processing unit 300 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.
[0200] Specifically, the processing unit 300 includes a communication control unit 301, an information management unit 302, an information type determination processing unit 303, an information linkage processing unit 304, an authentication processing unit 305, a registration control unit 306, a network service provision control unit 307, a timer management unit 310, and an information provision unit 311.
[0201] The communication control unit 301 establishes a communication line with the terminal device 20 and the like via the network, and performs mutual communication.
[0202] The information management unit 302 receives, for each terminal device 20, user registration information and personal identification information entered via each terminal device 20, registers the corresponding information in the database 140, and performs various processes to provide the corresponding personal identification information to the personal identification information management server device 40.
[0203] The information type determination processing unit 303 executes a determination process to determine whether the type of the received personal verification information is information that requires a given special management.
[0204] The information linking processing unit 304 provides personal identification information to the personal identification information management server device 40 for user registration.
[0205] The authentication processing unit 305 receives, for each terminal device 20, authentication information input via each terminal device 20, and performs authentication processing for each user based on the received authentication information.
[0206] The registration control unit 306 registers the user registration information in the database 340 when the user registration process is executed.
[0207] The network service provision control unit 307 works in conjunction with the corresponding terminal device 20 (specifically, the Web browser 211) to execute various processes for allowing the user to enjoy a given network service.
[0208] The timer management unit 310 has a function of measuring the current date and time and from a predetermined timing, and outputs the current time and the measurement result when the predetermined timing arrives.
[0209] The information providing unit 311 provides the authentication server device 10 with information such as the input personal identification information.
[0210] [4.7.2] Variation 2 Next, a second modification of this embodiment will be described with reference to Fig. 7. Fig. 7 shows the second modification. 1 is an example of a functional block diagram showing the configuration of a terminal device 21. FIG.
[0211] (Features of the modified example) This modification is characterized in that the functions of the authentication server device 10 that executes various processes related to user registration processing are executed by the terminal device 21.
[0212] That is, the terminal device 21 of this modified example has a configuration that executes the above-mentioned determination process and also executes, as information linkage processing, output control for providing user registration information and personal identification information.
[0213] In this case, the terminal device 21 is a terminal device that performs processing related to the user's registration for a given service based on user-related information that indicates information about the user.
[0214] In this case, the terminal device 21 (A1) When a user wishes to register for use of the service, an input process is executed in which user-related information of the user who wishes to register and use the service and personal identification information for identifying the user who wishes to register are input as user-related information; (A2) Execute a determination process to determine whether the type of the input personal identification information is information that requires a given special management; (A3) A first output control process is executed to associate the input user registration information with service identification information for use by the corresponding user when using the service, and output the information to a service server device 30 that provides a given service or an authentication server device 10 that manages user registration; and a second output control process is executed to output the personal identification information, together with the service identification information of the corresponding user, to a personal identification information management server device 40 that manages the special management when the type of the personal identification information received by the determination process is determined to be information that requires the special management. (A4) When a notification is received from the service server device 30, the authentication server device 10, or the personal identification information management server device 40 indicating that personal identification has been successfully completed based on the provided user registration information and personal identification information, notify the user that registration for a given service has been completed. It has the following structure.
[0215] (Specific configuration of Modification 2) As shown in FIG. 7, the terminal device 21 of this embodiment has a processing unit 200, a card reader / writer 240, an imaging unit 250, an operation input unit 260 consisting of a touch panel or the like, a memory unit 270, an information storage medium 280, a display unit 290 consisting of a display element such as a liquid crystal panel, a communication unit 296, and a sound output unit 292.
[0216] In particular, the processing unit 200 includes a communication control unit 210, a web browser 211, an imaging control unit 212, a display control unit 213, an input reception processing unit 214, a reading control unit 215, an information type determination processing unit 216, an output control unit 217, a drawing unit 220, and a sound processing unit 230. Note that some of these may be omitted.
[0217] In addition, the information type determination processing unit 216, similar to the information type determination processing unit 103 of the authentication server device 10 in the above embodiment, performs a determination process to determine whether the type of the received personal identification information is information that requires special management.
[0218] Then, the output control unit 217, like the information linking processing unit 104 of the authentication server device 10 in the above embodiment, provides user registration information to the authentication server device 10 or the service server device 30 for user registration, and provides personal identification information to the personal identification information management server device 40. do.
[0219] [5] Operation in this embodiment Next, the operation of the authentication server device 10 of this embodiment when executing the user registration process will be described with reference to FIGS.
[0220] 8 and 9 are flowcharts showing the operation of the authentication server device 10 of this embodiment when executing the user registration process.
[0221] This operation is executed every time a user desiring to register requests user registration for a given network service.
[0222] In this operation, it is assumed that the personal identification information of the user and the user registration information of the given network service have not yet been registered in the database 140 or the like.
[0223] First, the information management unit 102 executes a reception process and acquires the user registration information and personal identification information sent from the terminal device 20 (step S101), and then issues service identification information and provides it to the terminal device 20 and the service server device 30 (step S102).
[0224] Next, the information type determination processing unit 103 executes a determination process to determine whether or not the received personal identification information is information requiring special management (official management identification information) (step S103).
[0225] At this time, if the information type determination processing unit 103 determines that the received personal identification information is information that requires special management, it provides the personal identification information to the personal identification information management server device 40 in association with the issued service identification information, and proceeds to processing of step S105 (step S104).
[0226] Next, the information type determination processing unit 103 associates the user registration information with the issued service identification information and provides it to the service server device 30 (step S105).
[0227] On the other hand, if the information management unit 102 determines that the received personal identification information does not require special management, it provides both the user registration information and the personal identification information to the service server device 30, together with the issued service identification information (step S106).
[0228] Next, when the information linking processing unit 104 receives a notification regarding identity verification sent from the service server device 30 or the identity verification information management server device 40 (step S107), it determines whether the received notification indicates that identity verification has been successful (step S108).
[0229] At this time, if the information linkage processing unit 104 determines that the received notification is not a notification indicating that identity verification has been successful, it executes control to cause the corresponding terminal device 20 to display a message indicating that identity verification has not been successful (step S109), and terminates this operation.
[0230] On the other hand, if the information linking processing unit 104 determines that the received notification is a notification indicating that identity verification has been successful, it executes control to cause the corresponding terminal device 20 to display a message indicating that identity verification has been successful (step S110).
[0231] Next, the registration control unit 106 determines whether or not the personal identification information is officially managed identification information based on the determination result in the process of step S103 (step S111).
[0232] At this time, if the registration control unit 106 determines that the personal identification information is information to be registered in the personal identification information management server device 40, it registers the user registration information together with the service identification information in the database 140 while linking it with the personal identification information to be registered in the personal identification information management server device 40 (step S112), and terminates this operation.
[0233] In addition, if the registration control unit 106 determines that the personal identification information is not information to be registered in the personal identification information management server device 40, it registers the personal identification information and user registration information together with the service identification information in the database 140 (step S113), and terminates this operation.
[0234] [6] Other The present invention is not limited to the above-described embodiments, and various modifications are possible. For example, terms cited in the specification or drawings as broadly defined or synonymous terms can be replaced with broadly defined or synonymous terms in other descriptions in the specification or drawings.
[0235] The present invention includes configurations that are substantially the same as the configurations described in the embodiments (for example, configurations with the same functions, methods, and results, or configurations with the same purpose and effects). The present invention also includes configurations in which non-essential parts of the configurations described in the embodiments are replaced. The present invention also includes configurations that achieve the same effects as the configurations described in the embodiments or that can achieve the same purpose. The present invention also includes configurations in which publicly known technology is added to the configurations described in the embodiments.
[0236] Although the embodiments of the present invention have been described in detail as above, it will be readily apparent to those skilled in the art that many modifications can be made without substantially departing from the novel features and effects of the present invention. Therefore, all such modifications are intended to be included within the scope of the present invention. [Explanation of symbols]
[0237] S: Network Service Management System 10: Authentication server device 20, 21: Terminal device 30, 31: Service server device 40: Personal identification information management server device 100: Processing section 101: Communication control unit 102: Information Management Department 103: Information type determination processing unit 104: Information Linkage Processing Unit 105: Authentication processing unit 106: Registration control unit 110: Timer management unit 111: Information provision department 140: Database 170: Storage section 180: Information storage medium 196: Communications Department 200: Processing section 210: Communication control unit 211: Web browser 212: Imaging control unit 213: Display control unit 214: Input reception processing unit 215: Reading control unit 216: Information type determination processing unit 217: Output control section 220: Drawing section 230: Sound processing unit 240: Writer 250: Imaging unit 260: Operation input section 270: Storage section 271: Main memory 272: Image buffer 273: User-related information storage unit 280: Information storage medium 290:Display section 292: Sound output unit 296: Communications Department 300: Processing section 301: Communication control section 302: Information Management Department 303: Information type determination processing unit 304: Information Linkage Processing Unit 305: Authentication processing section 306: Registration control section 307: Network service provision control unit 310: Timer management unit 311: Information provision department 340: Database 370: Storage section 380: Information storage medium 396: Communications Department
Claims
1. A user registration management system that works in conjunction with a terminal device to which information about a user is input as user-related information, and manages the user's registration for a given service based on the user-related information, a reception processing means for executing a reception process for receiving user-related information transmitted from the terminal device when the user wishes to register for use of the service, the user-related information including user registration information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register; a determination processing means for executing a determination process to determine whether the type of the received personal identification information is information that requires a given special management; a providing means for executing a first provision control process of associating the received user registration information with a service identification information for the user when using the service, and providing the information to a service system that provides the given service; and a second provision control process of providing the received personal identification information, together with the service identification information of the user, to a management system that performs the given special management when the type of the received personal identification information is determined to be information that requires the given special management by the determining process, a management means for registering and managing the user registration information in a given database in association with the service identification information or in conjunction with the identity verification information provided to the management system, on the assumption that the identity verification information will be registered in the management system, when receiving a notification sent from the service system or the management system indicating that identity verification has been successful based on the provided user registration information and identity verification information.
2. 2. The user registration management system according to claim 1, The providing means If it is determined that the type of the received personal identification information does not require special management, the personal identification information is provided to the service system together with the user registration information; The management means: A user registration management system that, when receiving a notification from the service system indicating that the identity verification has been successful, registers and manages the user registration information and identity verification information in the database in association with each other.
3. A user registration management system that works in conjunction with a terminal device to which information about a user is input as user-related information, and manages the user's registration for a given service based on the user-related information, a reception processing means for executing a reception process for receiving user-related information transmitted from the terminal device when the user wishes to register for use of the service, the user-related information including user registration information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register; a determination processing means for executing a determination process to determine whether the type of the received personal identification information is information that requires a given special management; providing means for providing the personal identification information together with the service identification information of the user to a management system that performs the special management when the personal identification is successfully authenticated based on the received user registration information and personal identification information and the type of the received personal identification information is determined to be information that requires the given special management by the determination process; If the user authentication is successful based on the received user registration information and personal identification information, the received user registration information and personal identification information are registered in the management system. a management means for registering and managing the received user registration information in a given database by associating the received user registration information with service identification information for the user when using the service and by linking the received user registration information with personal identification information registered in the management system; A user registration management system comprising:
4. 4. The user registration management system according to claim 3, The providing means If it is determined that the type of the received personal identification information does not require special management, the personal identification information is registered in the database together with the user registration information; The management means: If the user is successfully authenticated based on the received user registration information and personal identification information, the user registration information and personal identification information are associated with each other and registered in the database for management purposes.
5. 4. The user registration management system according to claim 1, The reception processing means performs the reception processing as follows: executes an input support process in cooperation with the terminal device to prompt seamless input of both the user-related information and the personal identification information; a user registration management system that accepts the user registration information and the personal identification information that are input to the terminal device based on the input support process and transmitted directly from the terminal device;
6. 4. The user registration management system according to claim 1, A user registration management system, wherein the personal identification information includes image information in which the personal identification information is visualized.
7. A program that works in conjunction with a terminal device to which information about a user is input as user-related information, and manages the user's registration for a given service based on the user-related information, a reception processing means for executing a reception process for receiving user-related information transmitted from the terminal device when the user wishes to register for use of the service, the user-related information including user registration information of the user who wishes to register and use the service, and personal identification information for performing personal identification of the user who wishes to register; a determination processing means for executing a determination process to determine whether the type of the received personal identification information is information that requires a given special management; a first provision control process for associating the received user registration information with service identification information for the user when using the service, and providing the information to a service system that provides the given service; and a provision means for executing a second provision control process for, when it is determined by the determination process that the type of the personal identification information received is information that requires the given special management, providing the personal identification information together with the service identification information of the user to a management system that performs the special management; a management means for registering and managing the user registration information in a given database in association with the service identification information or in association with the identity verification information provided to the management system, on the assumption that the identity verification information will be registered in the management system, when receiving a notification transmitted from the service system or the management system indicating that identity verification has been successful based on the provided user registration information and identity verification information; A program that causes a computer to function as a
8. The information about the user is linked to the terminal device into which the information about the user is input as user-related information, and the user A program for managing a user's registration for a given service based on related information, a reception processing means for executing a reception process for receiving user-related information transmitted from the terminal device when the user wishes to register for use of the service, the user-related information including user registration information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register; a determination processing means for executing a determination process to determine whether the type of the received personal identification information is information that requires a given special management; providing means for providing the personal identification information together with the service identification information of the user to a management system that performs the special management when the personal identification is successfully authenticated based on the received user registration information and personal identification information and the type of the received personal identification information is determined to be information that requires the given special management by the determination process; a management means for registering and managing the user registration information in a given database by associating the received user registration information with service identification information for the user when using the service and linking the received user registration information with the identity verification information registered in the management system, when identity authentication based on the received user registration information and identity verification information is successful, on the premise that the identity verification information will be registered in the management system; A program comprising:
9. A user registration management method that operates in conjunction with a terminal device to which information about a user is input as user-related information, and manages the user's registration for a given service based on the user-related information, comprising: When the user wishes to register for use of the service, a reception process is executed to receive user-related information transmitted from the terminal device, the user registration information of the user who wishes to register and use the service, and personal identification information for performing personal identification of the user who wishes to register; execute a determination process to determine whether the type of the received personal identification information is information that requires a given special management; a first provision control process for associating the received user registration information with service identification information for the user when using the service and providing the information to a service system that provides the given service; and a second provision control process for providing the received personal identification information, together with the service identification information of the user, to a management system that performs the given special management when the type of the received personal identification information is determined to be information that requires the given special management by the determination process, When receiving a notification transmitted from the service system or the management system indicating that identity verification has been successful based on the provided user registration information and identity verification information, registering and managing the user registration information in a given database in association with the service identification information or in association with the identity verification information provided to the management system, on the premise that the identity verification information will be registered in the management system. A user registration management method comprising:
10. A terminal device that performs a process related to a user's registration for a given service based on user-related information indicating information about the user, an operation input means used to input, when the user wishes to register for use of the service, user-related information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register, as the user-related information; a determination processing means for executing a determination process to determine whether the type of the input personal identification information is information that requires a given special management; an output control means for executing a first output control process for associating the input user registration information with service identification information for the user when using the service, and outputting the information to a service system that provides the given service or a user registration management system that manages registration of the user; and a second output control process for outputting the personal identification information, together with the service identification information of the user, to a management system that manages the special management when the type of the personal identification information received by the determination process is determined to be information that requires the special management; a notification control means for notifying the user that registration for a given service has been completed when a notification is received from the service system, the user registration management system, or the management system indicating that identity verification has been successful based on the provided user registration information and identity verification information; and A terminal device comprising:
11. A program for performing a process related to a user's registration for a given service based on user-related information indicating information about the user, an operation input means used to input, when the user wishes to register for use of the service, user-related information of the user who wishes to register and use the service, and personal identification information for identifying the user who wishes to register; a determination processing means for executing a determination process to determine whether the type of the input personal identification information is information that requires a given special management; a first output control process for associating the input user registration information with service identification information for the user when using the service, and outputting the information to a service system that provides the given service or a user registration management system that manages the registration of the user; and an output control means for executing a second output control process for, when it is determined that the type of the personal identification information received by the determination process is information that requires the given special management, outputting the personal identification information together with the service identification information of the user to a management system that manages the special management; a notification control means for notifying the user that registration for a given service has been completed when a notification is received from the service system, the user registration management system, or the management system indicating that identity verification has been successful based on the provided user registration information and identity verification information; A program that causes a computer to function as a
Citation Information
Patent Citations
Account opening system, account opening method, and program
JP2019050014A