Information collection system, data generation system, information collection method, data generation method, terminal device, and program
A customizable information collection system generates tailored application data for identity verification, addressing inefficiencies by allowing a single application to meet multiple service providers' needs, thus reducing provider effort and preventing device overload.
Patent Information
- Application Number
- JP2024030251
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-29
- Publication Date
- 2025-09-10
- Estimated Expiration
- 2044-02-29
AI Technical Summary
Existing systems lack the ability to customize authentication processes for identity verification according to the specific requirements of each network service provider, leading to inefficiencies and potential memory or CPU issues due to multiple applications being used simultaneously.
A customizable information collection system that generates application data based on base data and customization data, allowing a single application to perform identity verification processes tailored to each provider's needs, eliminating the need for individual setup and reducing application overload.
This solution saves time and effort for providers by allowing a single application to handle identity verification for multiple services, reducing the burden on users and preventing memory or CPU malfunctions.
Smart Images

Figure 2025132585000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information collection system, a data generation system, an information collection method, a data generation method, a terminal device, a program, and the like. [Background technology]
[0002] 2. Description of the Related Art Conventionally, network services such as Internet banking or mail order sites have been provided to customers via communication networks.
[0003] Recently, portable mobile information terminal devices such as smartphones are often used not only for using such network services but also for initial registration, including identity verification, and in such cases, it has become common to have users use applications for such mobile information terminal devices.
[0004] For example, a known example of such an information terminal device or a system that uses it for identity verification is one that acquires personal information and facial image data from an IC card and performs authentication processing for identity verification based on the acquired information (e.g., Patent Document 1). [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Publication No. 2019-050014 Summary of the Invention [Problem to be solved by the invention]
[0006] However, with the system and terminal device described in Patent Document 1, it is not possible to customize the steps for performing authentication processes such as identity verification and the design for doing so according to the wishes of each service provider, such as whether or not to acquire facial image data of the user wishing to register, the method for acquiring identity verification information, or the image data (e.g., web design) used to acquire identity verification information.
[0007] The present invention has been made to solve the above-mentioned problems, and its purpose is to provide a terminal device or the like that can collect personal identification information and perform authentication processing for verifying the identity of a network service provider in accordance with the requirements of each provider by using a single customizable application, thereby reducing the burden on the provider and eliminating complexity for the user, and preventing memory shortages or CPU malfunctions that may occur due to the coexistence of many applications. [Means for solving the problem]
[0008] (1) In order to solve the above problems, the present invention provides: An information collection system that executes an information collection process that is a process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, a management means for managing base data, which is stored in a storage means and defines the content of each process, and customization data, which is stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the process, and which customizes the base data; application data based on the base data and the customization data A generating means for executing a generating process; an application execution processing means for executing the information collection process based on the generated application data; a presentation means for presenting the personal identification information to be input to the user during the execution of the information collection process; a reception processing means for executing a reception process for receiving an operation by the user to input the presented personal identification information; an output control means for outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; Equipped with The generation means performs the generation process as follows: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; The application data is generated based on the customized data and the base data that are stored in the storage means in association with the acquired instruction information.
[0009] With this configuration, the present invention eliminates the need to prepare an authentication process for identity verification for each network service provider and to set up the application individually on the terminal device, and can collect identity verification information and perform authentication processing for identity verification in accordance with the needs of each provider using a single application data.
[0010] Therefore, the present invention can save the provider time and effort, and also eliminate the user's trouble of having to download and install the software individually on the terminal device.
[0011] Furthermore, the present invention provides authentication processing for verifying identity, which is an important process in processing related to network services but is used relatively infrequently, using a single application, thereby reducing the number of applications, thereby preventing memory shortages or CPU malfunctions in the terminal device that can occur when many applications are mixed together.
[0012] The "given network service" refers to a service that uses a network, such as a network banking service, a product sales service, or a membership service.
[0013] An "authentication server system" refers to a server system that can not only authenticate an individual using an ID and password, but also electronically verify an individual's identity using identification documents such as a driver's license, passport, or My Number card.
[0014] In addition, "authentication processing for identity verification" refers to authentication processing (hereinafter also referred to as "identity verification processing") for determining whether or not the user wishing to verify their identity is a legitimate user (a legitimate user already registered in the identity verification service) (whether or not they are the actual user).
[0015] In particular, "authentication processing for identity verification" includes, for example, (A1) The entered key information (key code), such as a PIN code, matches the pre-stored key information. (A2) The biometric information or personal identification information obtained from a facial image or ID such as a My Number card is the same as or is deemed to be the same as the stored biometric information or personal identification information for personal identification, and (A3) Entered personal identification information such as address or phone number and already stored user The information is identical to related information (information stored in other devices such as a server device). These include:
[0016] Furthermore, the "one or more steps" include an explanation of the authentication process for identity verification, viewing of terms of use, taking a facial image, instructions on how to obtain identity verification information from a storage medium such as an IC card on which the identity verification information is stored, inputting key information (key code) such as a PIN, confirming the identity verification information to be input, and presenting the results of the identity authentication process.
[0017] "Application data" refers to data that guides the user to input personal identification information and defines each step of the information collection process.
[0018] For example, application data includes data for presenting content to a user, such as data for displaying images including text, or data for outputting sounds including background music and voice, and data for prompting a user to enter personal identification information.
[0019] In addition to the above, "instruction information" refers to information input by, for example, user operation, and is defined by reading a two-dimensional barcode such as a QR code (registered trademark) or by inputting specific information such as a URL (Uniform Resource Locator).
[0020] In particular, "identification information" is identification information given to each provider that provides a network service, and "setting information" is information for specifying the customization content of each process.
[0021] Furthermore, "presenting to the user" refers to allowing the user to view or be notified of content such as image display and sound output.
[0022] (2) The present invention also provides the customization data is data that specifies whether each of a plurality of steps included in the information collection process is executable, The generating means The application data, in which whether or not each process is executable is defined, is generated based on the customized data stored in association with the instruction information and the base data.
[0023] With this configuration, the present invention can perform authentication processing for identity verification for each provider, including whether or not each step can be performed, thereby eliminating the hassle for the provider of generating and preparing applications, and also eliminating the hassle for the user of having to download them individually and install them on the terminal device.
[0024] (3) The present invention also provides the customization data is data defining content to be incorporated into the base data, The generating means The application data is generated by incorporating the customization data, which is stored in association with the instruction information, into the base data.
[0025] With this configuration, the present invention can provide the user with a design for each provider, including the design that is to be visually recognized by the user. Since it is possible to set the identity verification information to be guided or collected, it is possible to realize authentication processing for identity verification according to the wishes of each provider while realizing it with a single application data.
[0026] (4) The present invention also provides The customization data specifies an information management server system to be linked when performing the authentication process for the identity verification from among a plurality of information management server systems that perform the authentication process using the legitimate identity verification information, The generating means The application data is generated based on the customized data stored in association with the instruction information and the base data, and includes data communication with an information management server system that is linked when performing authentication processing for identity verification.
[0027] With this configuration, the present invention allows each provider to use the information management server system of their choice from among multiple information management server systems that perform authentication processing using legitimate personal identification information, thereby enabling authentication processing for personal identification that meets the needs of each provider while being realized using a single application.
[0028] In particular, the present invention allows providers to select an information management server system according to their wishes that manages (information management) personal identification information for identity verification, including each user's unique identification information such as a personal management number (e.g., My Number), in accordance with legal requirements.
[0029] An "information management server system" is a server system that manages (manages information about) personal identification information for personal identification purposes in accordance with legal requirements, and works in conjunction with a public authentication management server system that is required to query personal identification information when performing authentication processing for personal identification.
[0030] (5) The present invention also provides further comprising imaging control means for controlling the imaging means; The customization data specifies whether or not a process using image information captured and generated by the imaging means is to be executed, The generating means The configuration is such that the application data is generated based on the customized data stored in association with the instruction information and the base data, and the application data specifies whether or not to use the image information generated by the imaging means.
[0031] With this configuration, the present invention can set the identity verification information to be collected for each provider, so that authentication processing for identity verification that meets the needs of each provider can be realized while using a single application data.
[0032] It should be noted that "image information" includes, for example, information on the image of the face of a storage medium such as an IC card on which the My Number is stored, in addition to information on the user's facial image.
[0033] (6) Furthermore, in order to solve the above problems, the present invention provides: A program for executing an information collection process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, The data stored in the storage means is base data that defines the content of each process, and for each provider that provides the network service, the identification information of each provider or the content of the process. a management unit for managing customization data that customizes the base data and is stored in the storage unit in association with setting information that defines the above; a generation means for executing a generation process for generating application data based on the base data and the customized data; an application execution processing means for executing the information collection process based on the generated application data; a presentation means for presenting the personal identification information to be input to the user during the execution of the information collection process; a reception processing means for executing a reception process for receiving an operation by the user to input the presented personal identification information; and an output control means for outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; Make the computer function as The generation means performs the generation process as follows: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; The application data is generated based on the customized data and the base data that are stored in the storage means in association with the acquired instruction information.
[0034] With this configuration, the present invention eliminates the need to prepare an authentication process for identity verification for each network service provider and to set up the application individually on the terminal device, and can collect identity verification information and perform authentication processing for identity verification in accordance with the needs of each provider using a single application data.
[0035] Therefore, the present invention can save the provider time and effort, and also eliminate the user's trouble of having to download and install the software individually on the terminal device.
[0036] Furthermore, the present invention provides authentication processing for verifying identity, which is an important process in processing related to network services but is used relatively infrequently, using a single application, thereby reducing the number of applications, thereby preventing memory shortages or CPU malfunctions in the terminal device that can occur when many applications are mixed together.
[0037] (7) In order to solve the above problems, the present invention provides: An information collection method for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, and being executed by a computer, comprising: managing base data that is stored in a storage means and defines the content of each step, and customization data that is stored in the storage means in association with identification information of each provider or setting information that defines the content of the step for each provider of the network service, and that customizes the base data; executes a generation process for generating application data based on the base data and the customization data; Execute the information collection process based on the generated application data; During the information collection process, present the user with the personal identification information to be input; executes a reception process for receiving an operation by the user to input the presented personal identification information; outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; This includes: The generation process includes: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; The application data is generated based on the customized data and the base data that are stored in the storage means in association with the acquired instruction information.
[0038] With this configuration, the present invention eliminates the need to prepare an authentication process for identity verification for each network service provider and to set up the application individually on the terminal device, and can collect identity verification information and perform authentication processing for identity verification in accordance with the needs of each provider using a single application data.
[0039] Therefore, the present invention can save the provider time and effort, and also eliminate the user's trouble of having to download and install the software individually on the terminal device.
[0040] Furthermore, the present invention provides authentication processing for verifying identity, which is an important process in processing related to network services but is used relatively infrequently, using a single application, thereby reducing the number of applications, thereby preventing memory shortages or CPU malfunctions in the terminal device that can occur when many applications are mixed together.
[0041] (8) In order to solve the above problems, the present invention provides: A terminal device that executes an information collection process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, an acquisition means for executing an acquisition process for acquiring the generated application data based on base data, which is data stored in a storage means and defines the content of each step, and customization data, which is data stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the step, and customizes the base data; an application execution processing means for executing the information collection process based on the acquired application data; a presentation means for presenting the personal identification information to be input to the user during the execution of the information collection process; a reception processing means for executing a reception process for receiving an operation by the user to input the presented personal identification information; an output control means for outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; Equipped with The application data is The information is acquired when the user requests the execution of an authentication process for identity verification for a network service provided by a specific provider, and is configured to be generated based on instruction information of at least one of the identification information of the specific provider and the setting information.
[0042] With this configuration, the present invention provides a network service provider that performs authentication processing for identity verification. It is not necessary to prepare for each provider and to set up the application for each terminal device, and it is possible to collect personal identification information in accordance with the requirements of each provider.
[0043] Therefore, the present invention can save the provider time and effort, and also eliminate the user's trouble of having to download and install the software individually on the terminal device.
[0044] Furthermore, the present invention provides authentication processing for verifying identity, which is an important process in processing related to network services but is used relatively infrequently, using a single application, thereby reducing the number of applications, thereby preventing memory shortages or CPU malfunctions in the terminal device that can occur when many applications are mixed together.
[0045] (9) In order to solve the above problems, the present invention provides: A program for executing an information collection process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, an acquisition means for executing an acquisition process for acquiring the generated application data based on base data, which is data stored in a storage means and defines the content of each step, and customization data, which is data stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the step, and customizes the base data; an application execution processing means for executing the information collection process based on the acquired application data; a presentation means for presenting the personal identification information to be input to the user during the execution of the information collection process; a reception processing means for executing a reception process for receiving an operation by the user to input the presented personal identification information; and an output control means for outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; Make the computer function as The application data is The information is acquired when the user requests the execution of an authentication process for identity verification for a network service provided by a specific provider, and is configured to be generated based on instruction information of at least one of the identification information of the specific provider and the setting information.
[0046] With this configuration, the present invention eliminates the need to prepare authentication processing for identity verification for each network service provider and to set up the application individually on each terminal device, and can collect identity verification information in accordance with the needs of each provider.
[0047] Therefore, the present invention can save the provider time and effort, and also eliminate the user's trouble of having to download and install the software individually on the terminal device.
[0048] Furthermore, the present invention provides authentication processing for verifying identity, which is an important process in processing related to network services but is used relatively infrequently, using a single application, thereby reducing the number of applications, thereby preventing memory shortages or CPU malfunctions in the terminal device that can occur when many applications are mixed together.
[0049] (10) In order to solve the above problems, the present invention provides: An information collection method for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, and being executed by a computer, comprising: executes an acquisition process for acquiring the generated application data based on base data, which is data stored in a storage means and defines the content of each step, and customization data, which is data stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the step, and customizes the base data; Execute the information collection process based on the acquired application data; During the information collection process, present the user with the personal identification information to be input; executes a reception process for receiving an operation by the user to input the presented personal identification information; outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; This includes: The application data is The information is acquired when the user requests the execution of an authentication process for identity verification for a network service provided by a specific provider, and is configured to be generated based on instruction information of at least one of the identification information of the specific provider and the setting information.
[0050] With this configuration, the present invention eliminates the need to prepare authentication processing for identity verification for each network service provider and to set up the application individually on each terminal device, and can collect identity verification information in accordance with the needs of each provider.
[0051] Therefore, the present invention can save the provider time and effort, and also eliminate the user's trouble of having to download and install the software individually on the terminal device.
[0052] Furthermore, the present invention provides authentication processing for verifying identity, which is an important process in processing related to network services but is used relatively infrequently, using a single application, thereby reducing the number of applications, thereby preventing memory shortages or CPU malfunctions in the terminal device that can occur when many applications are mixed together.
[0053] (11) In order to solve the above problems, the present invention provides: A data generation system that generates application data for executing an information collection process that is made up of one or more steps and is used to collect information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the data generation system comprising: a management means for managing base data, which is stored in a storage means and defines the content of each process, and customization data, which is stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the process, and which customizes the base data; a generation unit that executes a generation process for generating application data based on the base data and the customized data; providing means for providing the generated application data to a terminal device; an acquisition means for acquiring information input by the user's operation based on the application data as personal identification information; Equipped with The generation means performs the generation process as follows: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; The application data is generated based on the customized data and the base data that are stored in the storage means in association with the acquired instruction information.
[0054] With this configuration, the present invention eliminates the need to prepare an authentication process for identity verification for each network service provider and to set up the application individually on the terminal device, and can collect identity verification information and perform authentication processing for identity verification in accordance with the needs of each provider using a single application data.
[0055] Therefore, the present invention can save the provider time and effort, and also eliminate the user's trouble of having to download and install the software individually on the terminal device.
[0056] Furthermore, the present invention provides authentication processing for verifying identity, which is an important process in processing related to network services but is used relatively infrequently, using a single application, thereby reducing the number of applications, thereby preventing memory shortages or CPU malfunctions in the terminal device that can occur when many applications are mixed together.
[0057] (12) In order to solve the above problems, the present invention provides: A program for generating application data for executing an information collection process that is a process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, a management means for managing base data, which is stored in a storage means and defines the content of each process, and customization data, which is stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the process, and which customizes the base data; a generation means for executing a generation process for generating application data based on the base data and the customized data; providing means for providing the generated application data to a terminal device; and an acquisition means for acquiring information input based on the user's operation as personal identification information based on the application data; Make the computer function as The generation means performs the generation process as follows: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; The application data is generated based on the customized data and the base data that are stored in the storage means in association with the acquired instruction information.
[0058] With this configuration, the present invention eliminates the need to prepare an authentication process for identity verification for each network service provider and to set up the application individually on the terminal device, and can collect identity verification information and perform authentication processing for identity verification in accordance with the needs of each provider using a single application data.
[0059] Therefore, the present invention can save the provider time and effort, and also eliminate the user's trouble of having to download and install the software individually on the terminal device.
[0060] Furthermore, the present invention provides authentication processing for verifying identity, which is an important process in processing related to network services but is used relatively infrequently, using a single application, thereby reducing the number of applications, thereby preventing memory shortages or CPU malfunctions in the terminal device that can occur when many applications are mixed together.
[0061] (13) In order to solve the above problems, the present invention provides: A data generation method for generating, by a computer, application data for executing an information collection process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, comprising: managing base data that is stored in a storage means and defines the content of each step, and customization data that is stored in the storage means in association with identification information of each provider or setting information that defines the content of the step for each provider of the network service, and that customizes the base data; executes a generation process for generating application data based on the base data and the customization data; providing the generated application data to a terminal device; acquiring information input based on the user's operation as personal identification information based on the application data; This includes: The generation process includes: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; The application data is generated based on the customized data and the base data that are stored in the storage means in association with the acquired instruction information.
[0062] With this configuration, the present invention eliminates the need to prepare an authentication process for identity verification for each network service provider and to set up the application individually on the terminal device, and can collect identity verification information and perform authentication processing for identity verification in accordance with the needs of each provider using a single application data.
[0063] Therefore, the present invention can save the provider time and effort, and also eliminate the user's trouble of having to download and install the software individually on the terminal device.
[0064] Furthermore, the present invention provides authentication processing for verifying identity, which is an important process in processing related to network services but is used relatively infrequently, using a single application, thereby reducing the number of applications, thereby preventing memory shortages or CPU malfunctions in the terminal device that can occur when many applications are mixed together. [Brief explanation of the drawings]
[0065] [Figure 1] 1 is a system configuration diagram showing a configuration of an authentication management communication system according to an embodiment. [Figure 2] FIG. 2 is a functional block diagram illustrating a configuration of an authentication server device according to an embodiment. [Figure 3] FIG. 2 is a functional block diagram illustrating an example of a configuration of a terminal device according to an embodiment. [Figure 4] 10A and 10B are diagrams for explaining a process of collecting personal verification information including an application data generation process in a terminal device according to an embodiment; [Figure 5] FIG. 2 is a diagram illustrating an example of personal identification information stored in an IC card according to one embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of base data and customized data according to an embodiment. [Figure 7] FIG. 10 is a diagram illustrating an example of application data according to an embodiment. [Figure 8] FIG. 10 is a diagram illustrating an information collection process executed by a terminal device according to an embodiment. [Figure 9] FIG. 10 is a diagram illustrating an information collection process executed by a terminal device according to an embodiment. [Figure 10] 10 is a flowchart showing operations of a process for collecting personal identification information including an application data generation process executed in one terminal device, and a process for personal identification based on the information collection process; [Figure 11] 10 is a flowchart showing operations of a process for collecting personal identification information including an application data generation process executed in one terminal device, and a process for personal identification based on the information collection process; DETAILED DESCRIPTION OF THE INVENTION
[0066] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0067] The embodiment described below is an embodiment in which the information collection system, data generation system, and terminal device of the present application are applied to an authentication management communication system that uses a storage medium having a terminal device used by a user, an authentication server device that controls various authentication processes, a network service server device that provides network services, an information management server device that manages authentication processes related to identity verification, and a public authentication management server device that manages identity verification information.
[0068] In addition, in this embodiment, an IC card is used as the storage medium. However, the storage medium may be, in addition to an IC card, a storage medium in which given information is stored in an IC chip, such as an IC tag, or a physical storage medium in which information is stored optically or magnetically. The storage medium may be stored in a portable information terminal device such as a smartphone.
[0069] Furthermore, in this embodiment, a user with the right to use refers to a user who owns a storage medium such as an IC card, as well as a user who is permitted to use the storage medium (i.e., a user who has been loaned the storage medium), and refers to a user who has the right to use the storage medium.
[0070] [1] Authentication management communication system First, an overview of an authentication management communication system 1 according to this embodiment will be described with reference to FIG.
[0071] FIG. 1 is a system configuration diagram showing the configuration of an authentication management communication system 1 according to this embodiment.
[0072] In addition, to prevent the diagram from becoming too complicated, Figure 1 only shows IC cards 60 and terminal devices 20 used by some users, as well as some network service server devices (hereinafter also referred to as "service server devices") 30.
[0073] That is, in the actual authentication management communication system 1, there are many more than those shown in FIG. There are an IC card 60, a terminal device 20, and a service server device 30.
[0074] The authentication management communication system 1 of this embodiment is a system that performs authentication processing for a pre-registered user, and if the user authentication is successful, provides various network services to the authenticated user via the network.
[0075] In particular, the authentication management communication system 1 of this embodiment is configured with a mechanism that ensures that identity verification using the IC card 60 is performed by a user who has the authority to use the IC card 60 when performing electronic authentication processing related to identity verification, including authentication processing for verifying identity using an IC card 60, which is a storage medium (hereinafter referred to as ``identity verification processing'').
[0076] That is, the authentication management communication system 1 of this embodiment is configured to execute processing to determine whether a user who wishes to be identified using an IC card 60 (i.e., a user who wishes to use a network service and register with the service, hereinafter referred to as a "registering user") is already a legitimate user who can be identified (for example, a user who has already registered with an identity verification service) (whether the user is the actual user).
[0077] Specifically, as shown in FIG. 1, the authentication management communication system 1 of this embodiment includes an authentication server device 10 that manages authentication processes related to identity verification or various authentication processes such as logging in to network services, and a terminal device 20 (e.g., terminal devices 20A, 20B, 20C) that is connected to the authentication server device 10 via a network such as the Internet and that executes authentication processes including identity verification processes in conjunction with the authentication server device 10.
[0078] As shown in FIG. 1, the authentication management communication system 1 of this embodiment includes a service server device 30 that provides a predetermined network service on the premise that user registration has been performed in advance for an identity verification service (a network service different from the network service for which the user wishes to register), an information management server device 40 that manages (information management) identity verification information for identity verification, including identification information unique to each user such as a personal management number (e.g., My Number), in accordance with legal requirements, and provides and manages identity verification services, and a public authentication management server device 50 that manages identity verification information used when performing identity verification, including the personal management number.
[0079] The authentication server device 10 is an information processing device that uses, for example, an API (Application Programming Interface) or a predetermined platform to execute various processes related to identity verification at the time of registration to a network service and authentication processing after the registration.
[0080] In particular, the authentication server device 10 is a server system that can not only perform identity authentication such as logging in using an ID and password, but also electronically perform identity verification as an identity verification process using identity verification documents such as a driver's license, passport, or My Number card.
[0081] Furthermore, the authentication server device 10 may be configured as one (device, processor) or as multiple (devices, processors).
[0082] The authentication server device 10 has various databases (broadly speaking, storage devices, memories) in which various information used for identity verification processing or authentication processing is stored. However, the authentication server device 10 of this embodiment is not connected to a network (intranet or internet). The database (broadly speaking, a storage device or memory) connected via the
[0083] Furthermore, the authentication server device 10 is configured to work in conjunction with each terminal device 20 and to manage the identity verification process of the user who owns each terminal device 20 and to perform authentication processing.
[0084] The terminal device 20 is a communication terminal device that is used by a user and is configured by an information processing device such as a PC (personal computer), a tablet-type information communication terminal device, a smartphone, a mobile phone, a game device, or an HMD.
[0085] In addition, the terminal device 20 is a device that can be connected to the authentication server device 10 via a network such as the Internet (WAN) or LAN, and is configured to establish a communication line with the authentication server device 10 via wired or wireless means to exchange various data.
[0086] Furthermore, the terminal device 20 has a configuration that includes a communication control function for communicating with the authentication server device 10, such as input information entered by the user, and a display function for performing display control using data received from the authentication server device 10 and the service server device 30.
[0087] The service server device 30 is a server device for providing various network services, including banking services that provide financial institution-related services, reservation services for restaurants, inns, transportation, etc., product sales services, SNS services, content provision services such as games, music, and videos, cloud services such as various applications such as email, and information provision services such as search and advertisements.
[0088] In particular, when a user registers for a network service, the service server device 30 is configured to register the user who wishes to register as a user who provides the network service (i.e., a registered user) once the user's identity is confirmed through an authentication process related to identity verification processing (i.e., when identity verification authentication is successful).
[0089] In addition, when the authentication server device 10 successfully authenticates a registered user, the service server device 30 is configured to log in the authenticated terminal device 20 to the network service it provides and execute various processes to provide the corresponding service to the user.
[0090] The service server device 30 may have various functions relating to authentication, such as the authentication process of the authentication server device 10.
[0091] The information management server device 40 is an information processing device for linking the corresponding terminal device 20 with the official authentication management server device 50 when executing processes related to identity verification, including identity verification processing.
[0092] Furthermore, the information management server device 40 may be configured as one (device, processor) or may be configured as multiple (devices, processors).
[0093] Specifically, similar to the authentication server device 10, the information management server device 40 has a configuration in which each terminal device 20 is linked with the public authentication management server device 50 using, for example, an API (application programming interface) or a predetermined platform, etc., to perform authentication based on personal identification information.
[0094] The public authentication management server device 50 is an information processing device that manages (information management) personal identification information for identity verification, including each user's unique identification information (i.e., personal management number), such as My Number, Social Security Number, or driver's license number, in accordance with legal requirements.
[0095] Furthermore, the official authentication management server device 50 may be configured as one (device, processor) or as multiple (devices, processors).
[0096] The public authentication management server device 50 has various databases (broadly speaking, storage devices, memories) that store the identity verification information of each user and various information used in authentication processing related to identity verification. However, the public authentication management server device 50 of this embodiment may also access databases (broadly speaking, storage devices, memories) connected via a network (intranet or the Internet).
[0097] Specifically, the public authentication management server device 50, like the authentication server device 10, manages each user's personal identification information using, for example, an API (application programming interface) or a predetermined platform, and when performing authentication processing related to personal identification, it works in conjunction with the information management server device 40 to make inquiries about personal identification information and perform other authentication-related processing.
[0098] [2] Authentication server device Next, the authentication server device 10 of this embodiment will be described with reference to FIG.
[0099] FIG. 2 is an example of a functional block diagram showing the configuration of the authentication server device 10 of this embodiment.
[0100] As shown in FIG. 2, the authentication server device 10 of this embodiment includes a processing unit 100, a database 140, a storage unit 170, an information storage medium 180, and a communication unit 196.
[0101] The authentication server device 10 does not need to include all of the components shown in FIG. 2, and may have a configuration in which some of them are omitted.
[0102] The storage unit 170 serves as a work area for the processing unit 100 and the like, and its function can be realized by hardware such as RAM (VRAM). In particular, the storage unit 170 functions as a work area used when various processes are executed.
[0103] The information storage medium 180 is computer-readable, and stores programs, data, etc. In other words, the information storage medium 180 stores programs for causing a computer to function as each unit of this embodiment (programs for causing a computer to execute the processing of each unit).
[0104] The processing unit 100 can perform various processes of this embodiment based on data read from a program (data) stored in this information storage medium 180.
[0105] For example, the information storage medium 180 is an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.
[0106] The database 140 includes optical disks (CD, DVD), magneto-optical disks (MO), magnetic It is formed by a disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.
[0107] The database 140 is a database in which information about each user for performing authentication processing when logging in to each service server device 30 is registered as user authentication information.
[0108] In particular, database 140 stores, for each user, a user name, a password, and user-related information for authentication (e.g., name, credit card number, contact information such as email address and mobile phone number), as well as user authentication information for identifying the user when performing authentication processing, such as design information, in association with each user ID.
[0109] The database 140 may also store base data and customized data used when generating an application for collecting personal identification information in the terminal device 20.
[0110] The communication unit 196 performs various controls for communicating with the outside (for example, the terminal device 20 or the service server device 30), and its functions are configured by hardware such as various processors or communication ASICs, programs, etc.
[0111] The processing unit 100 performs various processes of this embodiment based on programs (data) stored in the storage unit 170. Note that the processing unit 100 of this embodiment may read out programs and data stored in the information storage medium 180, temporarily store the read out programs and data in the storage unit 170, and perform processing based on the programs and data.
[0112] The processing unit 100 (processor) performs various processes using the main memory in the memory unit 170 as a work area. The functions of the processing unit 100 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.
[0113] Specifically, the processing unit 100 includes a communication control unit 101 , a DB management control unit 102 , an authentication processing unit 103 , a personal identification processing management unit 104 , an information collection management control unit 105 , and a timer management unit 107 .
[0114] The communication control unit 101 establishes a communication line with the terminal device 20, the service server device 30, etc. via the network, and communicates with them.
[0115] The DB management control unit 102 executes processes such as reading, writing, deleting, and updating of each piece of data in the database 140 .
[0116] The authentication processing unit 103 receives input information entered via each terminal device 20 for each terminal device 20, and performs authentication processing for each user based on the received input information (specifically, a user name or user ID and a password) and authentication information for the user already registered in the database 140 (i.e., a user name or user ID and a password).
[0117] The personal identification process management unit 104 works in conjunction with the terminal device 20 to execute personal identification process or process related to the personal identification process.
[0118] The information collection management control unit 105 works in conjunction with the terminal device 20 to execute processing related to the collection of personal verification information.
[0119] The timer management unit 107 has a function of measuring the current date and time and from a predetermined timing, and outputs the current time and the measurement result when the predetermined timing arrives.
[0120] [3] Terminal device Next, the functions of the terminal device 20 will be described with reference to Fig. 3. Fig. 3 is a functional block diagram showing an example of the configuration of the terminal device 20 of this embodiment.
[0121] As shown in FIG. 3, the terminal device 20 of this embodiment has a processing unit 200, a card reader / writer 240, an imaging unit 250, an operation input unit 260 consisting of a touch panel or the like, a memory unit 270, an information storage medium 280, a display unit 290 consisting of a display element such as a liquid crystal panel, a communication unit 296, and a sound output unit 292.
[0122] The card reader / writer 240 reads and writes information from and to the IC card 60 held by the user.
[0123] For example, the card reader / writer 240 of this embodiment reads out personal identification information including a personal control number from the IC card 60 .
[0124] The card reader / writer 240 can be realized by, for example, a card reader for NFC (Near Field Communication).
[0125] The imaging unit 250 is made up of an imaging camera having a predetermined imaging angle and focal length and a predetermined imaging element such as a CCD, and an image generating unit that converts the output of the imaging camera into an image.
[0126] Furthermore, the imaging unit 250 works in conjunction with the processing unit 200 to acquire biometric information, such as facial image information obtained by capturing an image of the user's face and digitizing the facial image, when performing identity verification processing.
[0127] The operation input unit 260 is a device for inputting input information from the player, and outputs the input information from the player to the processing unit 200 .
[0128] The operation input unit 260 of this embodiment has a configuration for detecting input information (input signals) from the user, and is composed of, for example, a lever, a button, a microphone, a touch panel display, a keyboard, a mouse, and the like.
[0129] The storage unit 270 serves as a work area for the processing unit 200 and the like, and its function can be realized by hardware such as RAM (VRAM).
[0130] The storage unit 270 of this embodiment includes a main storage unit 271 used as a work area, an image buffer 272 in which display images and the like to be displayed during identity verification processing are stored, a user information storage unit 273 in which user information including part or all of the authentication user-related information is stored, and a data storage unit 274 in which various data for generating application data is stored. Note that some of these may be omitted.
[0131] In particular, the data storage unit 274 stores base data that specifies the content of each step defined in the information collection process, and customization data that customizes the base data, which is data associated with each provider of network services, such as the provider's identification information or setting information that specifies the content of the step.
[0132] The information storage medium 280 is computer readable. In addition to various applications and an OS (operating system), in the present embodiment, various data including the user ID of the user corresponding to the terminal device 20 is stored in the storage device 80.
[0133] That is, the information storage medium 280 stores applications for causing a computer to function as each unit of this embodiment (applications for causing a computer to execute the processing of each unit) and a user ID.
[0134] For example, the information storage medium 280 is an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk drive, a flash memory, a magnetic tape, a memory (ROM), a memory card, or the like.
[0135] The communication unit 296 performs various controls for communicating with the outside (e.g., other terminal devices 20, authentication server device 10, and service server device 30), and its functions are configured by hardware such as various processors or communication ASICs, programs, etc.
[0136] The processing unit 200 can perform various processes of this embodiment by reading and executing the applications stored in this information storage medium 280. Note that the types of applications stored in the information storage medium 280 are arbitrary.
[0137] The processing unit 200 performs various processes of this embodiment based on the application stored in the information storage medium 280. Note that the processing unit 200 of this embodiment may read out programs and data stored in the information storage medium 280, temporarily store the read out programs and data in the storage unit 270, and perform processing based on the programs and data.
[0138] The processing unit 200 (processor) performs various processes using the main memory in the memory unit 270 as a work area. The functions of the processing unit 200 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.
[0139] The processing unit 200 includes a communication control unit 210, a web browser 211, an imaging control unit 212, a display control unit 213, an input reception processing unit 214, a reading control unit 215, an application data generation unit 216, an information collection and management unit 217, an identity verification processing unit 218, a drawing unit 220, and a sound processing unit 230. Note that some of these units may be omitted.
[0140] The communication control unit 210 performs processing to send and receive data to and from the authentication server device 10, the service server device 30, or the information management server device 40.
[0141] In addition, the communication control unit 210 receives data transmitted from the authentication server device 10, the service server device 30, or the information management server device 40, and performs processes such as storing the received data in the memory unit 270, analyzing the received data, and controlling the transmission and reception of other data.
[0142] The communication control unit 210 may store and manage the destination information (IP address, port number) of the authentication server device 10, the service server device 30, or the information management server device 40 in the information storage medium 280.
[0143] Then, the communication control unit 210 may communicate with the authentication server device 10, the service server device 30, or the information management server device 40 when receiving input information from the user to start communication.
[0144] The communication control unit 210 may also communicate with the information management server device 40 via the authentication server device 10.
[0145] In addition, the communication control unit 210 may send and receive data with the authentication server device 10, the service server device 30, or the information management server device 40 at a predetermined interval, or may send and receive data with the authentication server device 10, the service server device 30, or the information management server device 40 when input information is received from the operation input unit 260.
[0146] The web browser 211 is an application program for viewing web pages (authentication screen, identity verification processing screen, or service reception screen), and downloads HTML files, image files, etc. from a web server (authentication server device 10, service server device 30, or information management server device 40), analyzes the layout, and controls the display.
[0147] Furthermore, the Web browser 211 transmits data to the Web server (authentication server device 10, service server device 30 or information management server device 40) using an input form (links, buttons, text boxes, etc.).
[0148] The terminal device 20 can use the Web browser 211 to display information from a Web server (for example, the service server device 30) specified by a URL via the Internet.
[0149] For example, the terminal device 20 can display, by the Web browser 211, each content (data such as HTML) received from the authentication server device 10, the service server device 30, or the information management server device 40.
[0150] When the imaging control unit 212 performs identity verification processing in conjunction with the authentication server device 10, it causes the imaging unit 250 to capture an image of the user's face and generate facial image information (hereinafter referred to as "captured facial image information" or "captured image information").
[0151] The display control unit 213 performs processing for displaying on the display unit 290. For example, the display control unit 213 may use the web browser 211 for display.
[0152] The input reception processing unit 214 recognizes input information input by the user from the operation input unit 260, and receives the recognized information.
[0153] The reading control unit 215 controls the card reader / writer 240 that reads the personal identification information from the IC card 60 .
[0154] The application data generation unit 216 generates application data that defines an information collection process for collecting personal identification information.
[0155] The information collection management unit 217 works in conjunction with the web browser 211 and executes information collection processing using the application data generated by the application data generation unit 216 .
[0156] The identity verification processing unit 218 works in conjunction with the authentication server device 10, the information management server device 40, and the public authentication management server device 50 using the identity verification information collected by the information collection process to perform authentication processing (i.e., identity verification processing) to verify the identity of the user.
[0157] The drawing unit 220 performs drawing processing based on various processes performed by the processing unit 200, thereby generating an image, which is output to the display unit 290 by the display control unit 213.
[0158] The sound processing unit 230 performs sound processing based on the results of various processes performed by the processing unit 200 , generates background music, sound effects, voice, or the like, and outputs them to the sound output unit 292 .
[0159] [4] Method of this embodiment [4.1] Overview Next, the process of collecting personal verification information, including the process of generating application data, in the authentication management communication system 1 of this embodiment will be described with reference to FIG.
[0160] FIG. 4 is a diagram for explaining the process of collecting personal verification information including the process of generating application data in the terminal device 20 of this embodiment.
[0161] The authentication management communication system 1 of this embodiment is configured to execute an information collection process consisting of one or more steps, which is a process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed using a terminal device 20.
[0162] In particular, the terminal device 20 is configured to prepare authentication processing for identity verification for each network service provider, and to collect identity verification information in accordance with the requirements of each provider without setting the application data individually.
[0163] In addition, the terminal device 20 is configured to execute an information collection process to collect personal identification information stored in an IC card 60 such as a My Number card, personal identification information input by a user's operation input, personal identification information which is information on a facial image obtained by capturing an image of the face of a user wishing to register, or two or more of these pieces of personal identification information.
[0164] Specifically, as shown in FIG. 4, the terminal device 20 (A1) Manage base data that is stored in the storage unit 270 or the database 140 of the authentication server device 10 and defines the content of each process, and customize data that is stored in the database 140 for each provider of network services (i.e., service operator) in association with the identification information of each provider or setting information that defines the content of each process, and customizes the base data; (A2) performing a generation process to generate application data based on the base data and the customization data; (A3) Execute an information collection process based on the generated application data; (A4) During the information collection process, the user is presented with the identity verification information to be entered; (A5) performing a reception process to receive an operation input of the user based on the presented personal identification information; (A6) The information input by the user is output as personal identification information to the authentication server device 10 that executes the authentication process. It has the following structure.
[0165] Then, as a generation process, the terminal device 20 performs the following as shown in FIG. (A2-1) When a user issues an instruction to request execution of authentication processing for identity verification for a network service provided by a specific provider, the method acquires instruction information of at least one of identification information and setting information of the specific provider, (A2-2) generating application data based on the customized data and the base data stored in the storage unit 270 in association with the acquired instruction information; It has the following structure.
[0166] FIG. 4 shows an example of information collection processing for personal identification information, including application data generation processing, based on instruction information entered by a user wishing to register, such as a two-dimensional barcode, or entered from a web page for initial registration of a given network service provided by the authentication server device 10 in conjunction with the service server device 30, such as a URL.
[0167] In particular, Figure 4 shows an example in which, when instruction information is acquired, application data is generated based on base data and customized data provided by the memory unit 270 or the authentication server device 10, and personal identification information is presented and accepted based on the application data, and the accepted personal identification information is output to the authentication server device 10.
[0168] FIG. 4 also shows an example in which the authentication server device 10 cooperates with the information management server device 40 and the public authentication management server device 50 to perform identity verification processing using the output identity verification information.
[0169] By having such a configuration, in this embodiment, it is possible to eliminate the trouble for the provider of generating and preparing an application for each provider, and to eliminate the hassle for the user of downloading and installing the applications individually on the terminal device 20, and it is also possible to prevent memory shortages or CPU malfunctions that occur when many applications are mixed together.
[0170] [4.2] Personal Identification Information Next, the personal identification information of this embodiment will be described with reference to FIG.
[0171] FIG. 5 is a diagram showing an example of personal identification information stored in the IC card 60 of this embodiment.
[0172] The IC card 60 is a storage medium that stores personal identification information such as user-related information about a user who has the right of use, and also functions as an identification card with a photograph of the user printed on it.
[0173] For example, as shown in FIG. 5, the IC card 60 stores a personal management number already assigned to a user (i.e., a user with the right to use), user-related information about the user such as the user's name and a data file of an electronic certificate, and identity verification image information showing an image of the user's physical characteristics such as the face, all of which are associated with key information (i.e., a key code such as a PIN) for authenticating whether the user has legitimate authority as identity verification information.
[0174] In particular, the personal identification information is stored with reading locked based on a key code for authenticating whether the user has legitimate authority, which is predetermined when the personal identification information is registered by the user or the like.
[0175] Specifically, a personal management number is a number issued by a public institution such as a government agency to a user who wishes to use it, or is issued compulsorily to identify an individual, and is identification information such as a My Number, Social Security Number, or driver's license number.
[0176] User-related information includes the user's name, address, date of birth, and gender, as well as four other basic pieces of information. The digital certificate data file, the non-removable private key, and the public key for decrypting data encrypted with the private key are stored.
[0177] In addition, user-related information may include contact information such as a telephone number and the user's nickname, or, if rewritable data is stored, information on electronic money, digital legal tender, points or specific currencies that have monetary value in a specific commercial area, and information such as their usage history.
[0178] The personal identification face image information may basically be information on the image of the printed surface (card face) of the IC card 60 on which the face image is printed, or may simply be information on the face image.
[0179] The data file of the digital certificate includes, for example, private key information for signature, private key information for user authentication, public key information, and information on the certification authority that issued the digital certificate.
[0180] When the IC card 60 is issued, the personal identification information is stored in the official authentication management server device 50 (specifically, in a database not shown) in association with a personal management number, etc.
[0181] [4.3] Base Data, Customization Data, and Application Data Next, the base data, customized data, and application data of this embodiment will be described with reference to FIGS.
[0182] FIG. 6 is a diagram showing an example of base data and customized data according to this embodiment, and FIG. 7 is a diagram showing an example of application data according to this embodiment.
[0183] (base data) As shown in Figure 6(A), base data is data used to generate application data, and is data that specifies the basic content of each component that makes up the information collection process for collecting personal identification information, for example, by allowing the user to view or be notified via a web browser, etc.
[0184] In addition, the base data is stored in the data storage unit 274 (or the database 140 of the authentication server device 10) and is data that defines each process, including the order in which the corresponding processes are to be executed, and is composed of part data that defines each element to be visually recognized or notified to the user when executing each process, and configuration data for configuring the arrangement of each part data, etc.
[0185] For example, the parts data is data such as images (still images and moving images) to be visually recognized by the user, background music, decorations, and control data for performing effects.
[0186] The configuration data is data that defines the location of each part data, as well as the location at which customizable part data is incorporated and the configuration parts that can be changed, such as the location.
[0187] Furthermore, for example, the base data specifies various processes such as a process for viewing or notifying the user of an explanation (to specify the information to be provided, etc.) including consent to the authentication process for identity verification, a process for obtaining legally required consent from the user such as viewing the terms of use, a process for providing operating instructions for capturing an image of the user's face or a process for capturing said image, a process for inputting a key code, a process for inputting input information, and a process for presenting the results of the authentication process.
[0188] 6A shows the display format of the configuration data when it is displayed on the terminal device 20. An example of base data is shown.
[0189] (Customized data) As shown in Figure 6(B), the customization data is stored in the data storage unit 274 for each provider of network services, in association with instruction information including identification information of each provider and setting information specifying the content of each process.
[0190] In particular, the identification information, which is one of the instruction information, is an ID that is assigned in advance, for example, by the authentication server device 10, to each provider of a network service, and is information that is identified when the terminal device 20 executes an application for identity verification processing.
[0191] Furthermore, the setting information, which is one type of instruction information, is information that can be obtained, for example, by a URL or by reading a two-dimensional barcode such as a QR code (registered trademark), and is information that is identified when the terminal device 20 executes an application for identity verification processing.
[0192] The customization data is composed of, for example, supplementary part data to be incorporated into the above-mentioned part data such as images, sounds or text, replacement part data to replace the above-mentioned part data such as images, sounds or text, and configuration change data to change the configuration data such as the placement position of the above-mentioned part data or effect processing.
[0193] FIG. 6B shows an example of customization data related to a display design registered in association with identification information "001."
[0194] On the other hand, the customization data defines whether each of a plurality of steps included in the information collection process can be executed.
[0195] That is, the customization data includes control data that defines whether or not each process can be performed for each provider, including the order.
[0196] The customization data is used as data that defines content such as images, sounds, or text to be incorporated into the base data.
[0197] In other words, the customized data includes data representing images, sounds, text, etc. that the user can view or be notified of when entering personal identification information, or that guide the user to enter personal identification information.
[0198] The customization data includes, for each provider, supplemental part data to be incorporated into the above-mentioned part data such as images, sounds or texts, and replacement part data to replace the above-mentioned part data such as images, sounds or texts.
[0199] Furthermore, the customization data is data that specifies an information management server device 40 determined for each provider when an information management server device 40 to be linked with is selected from multiple information management server devices 40 when performing authentication processing for identity verification.
[0200] That is, in this embodiment, when there are multiple information management server devices 40 to be used in conjunction with the public authentication management server device 50 required to inquire about personal identification information when executing personal identification processing, data is stored that specifies the information management server device 40 to be linked from among the multiple information management server devices 40.
[0201] In addition to the above, the customization data may also define whether or not a process using image information captured and generated by the imaging unit 250 is executable.
[0202] (application data) For example, as shown in FIG. 7, the application data is generated based on the above-mentioned base data and customized data each time an authentication process for verifying the identity of a user is executed, and is used when executing the information collection process.
[0203] In particular, the application data of this embodiment is data for guiding the user to input personal identification information, and defines each step.
[0204] For example, the application data of this embodiment includes data for presenting content to the user, such as data for displaying images including text, or data for outputting sounds including background music and voice, and data for prompting the user to enter personal identification information.
[0205] FIG. 7 shows an example in which the customization data shown in FIG. 6(B) is incorporated into the base data shown in FIG. 6(A).
[0206] [4.4] Generation process Next, the generation process executed by the terminal device 20 of this embodiment will be described.
[0207] (Overview of the generation process) The application data generation unit 216 executes a generation process for generating application data based on the base data and the customized data.
[0208] In particular, when a user requests the execution of an authentication process for identity verification for a network service provided by a specific provider (hereinafter referred to as a "request to execute identity verification process"), the application data generation unit 216 acquires instruction information for at least one of the identification information and setting information of the specific provider.
[0209] Then, the application data generating unit 216 executes a generating process to generate application data based on the customized data and the base data stored in the storage unit 270 in association with the acquired instruction information.
[0210] That is, the application data generation unit 216 acquires, as instruction information, the identification information of the network service provider that will execute the identity verification process, setting information such as a URL, or both, which are sent together with the request to execute the identity verification process, acquires customized data based on the acquired instruction information, and generates application data together with the base data.
[0211] Specifically, the application data generation unit 216 mainly performs the following operations based on the acquired customization data: (A1) Setting whether each process can be executed or not, (A2) Addition, modification or deletion of content; (A3) Selection of an information management server device to be linked, and (A4) Addition of a process for acquiring image information, Generate application data for executing the above.
[0212] (Generation process 1: Setting whether each process can be executed) The application data generating unit 216 generates the catalog data stored in association with the instruction information. Based on the customized data and the base data, application data is generated that specifies whether each process can be executed.
[0213] That is, the application data generation unit 216 modifies the base data for each provider, including whether each process can be performed, and generates application data that can perform authentication processing for identity verification.
[0214] (Generation process 2: Adding, changing, or deleting content) The application data generating unit 216 generates application data by incorporating the customized data stored in association with the instruction information into the base data.
[0215] That is, the application data generation unit 216 generates application data for setting the identity verification information to be guided or collected by the user for each provider, including a design that is visible to the user, in order to realize authentication processing for identity verification that meets the wishes of each provider.
[0216] Specifically, the application data generating unit 216 adds, modifies, and deletes content from the base data based on the customized data stored in association with the instruction information.
[0217] (Generation process 3: Setting of information management server device that is linked when executing identity verification process) The application data generation unit 216 generates application data based on the customized data and base data stored in association with the instruction information, including data communication with the information management server device 40 that is linked when performing identity verification processing.
[0218] That is, when performing identity verification processing using identity verification information, the application data generation unit 216 generates application data for identifying the desired information management server device 40 for each provider from among multiple information management server devices 40 that cooperate with the public authentication management server device 50 required to query the identity verification information.
[0219] (Generation process 4: Collection of personal identification information from IC card) The application data generation unit 216 generates application data that specifies whether or not to collect identity verification information from an IC card 60 that stores given information for verifying the identity of a user who has the right to use the application, based on the customized data and base data stored in correspondence with the instruction information.
[0220] That is, the application data generation unit 216 generates application data that specifies whether or not to perform identity verification processing using an IC card 60 that stores identity verification information including unique identification information (i.e., a personal management number) for identifying the user.
[0221] (Generation process 5: Collection of image information) The application data generating unit 216 generates application data that specifies whether or not to use the image information generated by the imaging unit 250, based on the customized data and base data stored in association with the instruction information.
[0222] In particular, the application data generation unit 216 sets the personal identification information to be collected for each provider, and therefore, in addition to a face image or an upper body image of the user including a face image, it is regulated to acquire an image of the face of the IC card 60 that stores personal identification information and functions as an identification card. Generate the specified application data.
[0223] [4.5] Information collection and processing [4.5.1] Overview of information collection and processing Next, an overview of the information collection process executed by the terminal device 20 of this embodiment will be described with reference to FIGS.
[0224] 8 and 9 are diagrams for explaining the information collection process executed by the terminal device 20 of this embodiment.
[0225] The information collection management unit 217 executes information collection processing using the application data generated by the application data generation unit 216 .
[0226] In particular, the information collection management unit 217 presents personal identification information to be entered by the user based on the generated application data, and performs a reception process to accept input of the presented personal identification information, including information on the user's facial image (i.e., facial image information).
[0227] Specifically, as shown in Figures 8 and 9, the information collection management unit 217 creates content based on application data to make the user aware that the provider of the network service is collecting personal identification information, and performs a process (hereinafter also referred to as "input information presentation process") to present information to guide the user to input the personal identification information requested by each provider.
[0228] Then, as shown in Figures 8 and 9, the information collection management unit 217 performs a reception process to accept the input of personal identification information by user operation input in accordance with the application data, or to accept image information captured and generated by the imaging unit 250 as personal identification information.
[0229] In addition, in Figure 8, (A1) a service explanation step in which a user desiring to register is given an explanation regarding identity verification processing for a network service for which the user desiring to register; (A2) A process for explaining and consenting to the terms of use for the identity verification process of the service; (A3) a face image capturing step (input information presenting process) of presenting input information, which is information on a face image of a user desiring to register; (A4) A captured face image confirmation step (reception process) of accepting the face image information as personal identification information; (A5) an operation explanation step (input information presentation process) for explaining how to obtain personal identification information from the IC card 60; (A6) a key code input process (acceptance process) for accepting input of a key code (PIN) for reading personal identification information from the IC card 60; (A7) a personal identification information reading step (acceptance process) of reading personal identification information from the IC card 60 by placing the IC card 60 near the card reader / writer 240; (A8) an identity verification processing step of outputting identity verification information and executing identity verification processing; and (A9) Identity verification completion confirmation process 1 shows an example of an information collection process including an identity verification process.
[0230] FIG. 9 shows an example of information collection processing based on application data generated by the same base data provided by a different provider from that shown in FIG. 8, and shows the above (A3) and (A4). An example of an information gathering process without steps is shown.
[0231] [4.5.2] Input information presentation process Next, an input information presentation process executed by the terminal device 20 of this embodiment will be described.
[0232] Under the direction of the information collection management unit 217, the web browser 211 presents the user with personal identification information to be entered during the execution of the information collection process.
[0233] In particular, the web browser 211 generates web pages (authentication screen, identity verification processing screen, or service reception screen) for each step of the identity verification process based on application data generated for each network service provider, and allows the user to view the generated web pages or plays video or sound embedded in the web pages.
[0234] At this time, the web browser 211 may generate a web page in cooperation with the authentication server device 10 or the information management server device 40 based on the application data under the instructions of the information collection management unit 217, or may generate a web page using data stored in the memory unit 270.
[0235] For example, the web browser 211 constructs a layout based on application data generated for each network service provider, while acquiring image data, sound data, text data, etc. from the memory unit 270 or the authentication server device 10, etc., constructs a layout specified by the application, and performs display control and sound output control.
[0236] In addition, the web browser 211 generates an input form (links, buttons, text boxes, etc.) based on application data generated for each network service provider, and presents or notifies the user of information to be accepted as personal identification information using the input form.
[0237] [4.5.3] Reception process Next, the reception process executed by the terminal device 20 of this embodiment will be described.
[0238] (Overview of reception process) Under the instruction of the information collection and management unit 217, the input reception processing unit 214 executes reception processing for receiving input of the personal identification information presented in the input information presentation processing.
[0239] That is, under the direction of the information collection management unit 217, the input reception processing unit 214 executes a reception process to receive the user's operational input entered based on the personal identification information that is presented by the input information presentation process and that the user is prompted to enter.
[0240] Specifically, the input reception processing unit 214 receives, as the personal identification information to be input, personal identification information stored in the IC card 60, or personal identification information input from the operation input unit 260 such as a keyboard.
[0241] In addition, when an input process for image information is set based on application data, the input reception processing unit 214 may work in conjunction with the imaging unit 250 to accept image information such as a facial image or an image of the face of the IC card 60 as personal identification information.
[0242] For example, the input reception processing unit 214 reads out the personal identification information stored in the IC card 60. If so, it will be executed based on the key code.
[0243] (Acceptance process of personal identification information based on operation of operation input unit) When a process of acquiring personal identification information from an operation input unit 260 such as a keyboard based on application data is set under the direction of the information collection management unit 217, the input reception processing unit 214 executes a reception process to accept personal identification information from the operation input unit entered by a user who wishes to register for a network service when the personal identification information to be entered is presented by the input information presentation process during the execution of the information collection process.
[0244] Then, the input reception processing unit 214 provides the received personal identification information to the information collection and management unit 217 .
[0245] (Acceptance of personal identification information for key code entry) When a process of acquiring personal identification information from the IC card 60 based on a key code is set under the instruction of the information collection management unit 217 based on application data, the input reception processing unit 214 executes a reception process to accept, for example, a key code entered by a user who wishes to register for a network service when the personal identification information to be entered is presented by the input information presentation process during the execution of the information collection process.
[0246] Specifically, when the information collection management unit 217 starts executing the identity verification process in accordance with the instructions of the user wishing to register under the instructions of the information collection management unit 217, the web browser 211 works in conjunction with the display control unit 213 to display a given key button on the display unit 290 and an image prompting the user to enter a key code (hereinafter referred to as the "input key code").
[0247] At this time, the input reception processing unit 214, under the instruction of the information collection management unit 217, works in conjunction with the operation input unit 260 to execute a reception process in which the key information input by the user from the operation input unit 260 is recognized and accepted as an input key code.
[0248] In particular, when the display unit 290 displays numeric keys or various QWERTY key buttons that prompt the user to enter an input key code such as a PIN, the input reception processing unit 214 recognizes multiple pressing operations (i.e., touch operations) on the key buttons by the user wishing to register using the operation input unit 260, and performs a reception process to recognize and accept the recognized key buttons as an input key code.
[0249] Then, the input reception processing unit 214 provides the received input key code to the information collection management unit 217 .
[0250] On the other hand, the reading control unit 215 controls the card reader / writer 240 to read the personal identification information from the IC card 60 based on the provided key code, assuming that the IC card 60 is in the vicinity of the card reader / writer 240.
[0251] In particular, under the instruction of the personal identification processing unit 218, the reading control unit 215 reads out a key code such as a PIN stored in the IC card 60 (hereinafter referred to as a “stored key code”) using the card reader / writer 240.
[0252] Then, under the direction of the identity verification processing unit 218, if it is determined that the input key code matches the stored key code, the reading control unit 215 reads out the identity verification information and provides the read identity verification information to the information collection and management unit 217.
[0253] That is, the reading control unit 215 receives the key code and checks whether it is an input key code or not. If the stored key code matches, the IC card 60 is detected to be placed close to or in contact with the card reader / writer 240, and an image of the physical features of the user wishing to register, such as the face, is captured, an instruction to read the identity verification information is received from the identity verification processing unit 218.
[0254] When the reading control unit 215 receives an instruction to read the personal identification information, if the IC card 60 is maintained in close proximity to or in contact with the card reader / writer 240, the reading control unit 215 reads the personal identification information stored in the IC card 60 using the card reader / writer 240, and provides the read personal identification information to the information collection and management unit 217.
[0255] In addition, even if the reading control unit 215 receives an instruction to read the personal identification information, if the IC card 60 is not maintained in close proximity to or in contact with the card reader / writer 240, the reading control unit 215 will provide a reading error for the personal identification information to the information collection management unit 217.
[0256] (Acceptance process for input of imaging instructions) When a process is set in which, under the direction of the information collection management unit 217, facial image information of a user wishing to register for a network service is acquired as personal identification information using the imaging unit 250 based on application data, the input reception processing unit 214 executes a reception process to accept an imaging instruction entered by the user wishing to register, when the personal identification information to be entered is presented by the input information presentation process during the execution of the information collection process.
[0257] Specifically, the input reception processing unit 214 works in conjunction with the display control unit 213 to display on the display unit 290 a display encouraging the user wishing to register to capture an image of their physical characteristics, while also performing a reception process to accept input of an image capture instruction when capturing an image using the image capture unit 250.
[0258] At this time, the input reception processing unit 214 displays an imaging area image that specifies the imaging range on the display unit 290, and receives input of an imaging instruction by detecting a press operation (i.e., a touch operation) of the imaging button displayed together with the imaging area image.
[0259] Then, the input reception processing unit 214 provides the received imaging instruction to the information collection management unit 217 .
[0260] On the other hand, under the instruction of the information collection management unit 217, the imaging control unit 212 executes an imaging control process to control the imaging unit 250 to capture physical features such as the face of the user wishing to register and generate captured image information based on the imaging instruction of the user wishing to register.
[0261] Specifically, under the instruction of the identity verification processing unit 218, the imaging control unit 212 works in conjunction with the display control unit 213 to display on the display unit 290 an imaging area image that specifies the imaging range and an imaging button that performs imaging in conjunction with the operation input unit 260.
[0262] Then, when the imaging control unit 212 recognizes a pressing operation (i.e., a touch operation) on the imaging button by the user wishing to register using the operation input unit 260, it images the imaging area (e.g., the facial area) captured by the imaging unit 250 to generate captured image information, and provides the generated captured image information to the information collection management unit 217.
[0263] The imaging control unit 212 may change the imaging range and control the imaging direction of the imaging unit 250 based on an operation input via the operation input unit 260 by the user desiring to be registered.
[0264] The imaging control unit 212 also executes similar processing when acquiring image information obtained by imaging the face of the IC card 60 as personal identification information instead of a facial image.
[0265] [4.6] Identity Verification Processing Next, the personal identification process of this embodiment will be described.
[0266] The identity verification processing unit 218 works in conjunction with the authentication server device 10, the information management server device 40, and the public authentication management server device 50 using the identity verification information collected by the information collection process to perform authentication processing (i.e., identity verification processing) to verify the identity of the user.
[0267] In particular, the personal identification processing unit 218 provides the information input by the user as personal identification information to the information management server device 40 that executes the personal identification process, as described above.
[0268] Specifically, the identity verification processing unit 218 works in conjunction with the authentication server device 10, the information management server device 40, and the public authentication management server device 50 to perform identity verification of the user wishing to register, based on the identity verification information input by the operation input unit 260, the identity verification information read from the IC card 60, and the captured face image information as identity verification information or the face image information of the IC card 60.
[0269] Then, when the identity of the person is confirmed based on the provided identity verification information (i.e., when identity authentication is performed), the identity verification processing unit 218 obtains this information and performs registration of the corresponding user (i.e., user registration).
[0270] The personal identification processing unit 218 works in conjunction with the service server device 30 to register the user as a registered user who receives the network services provided by the service server device 30.
[0271] Furthermore, when the identity verification of the user desiring to register is completed, the identity verification processing unit 218 notifies the corresponding terminal device 20 of this fact.
[0272] Furthermore, the identity verification process of this embodiment may be executed at a timing different from the timing of collecting identity verification information, or may be executed when identity verification information is acquired at the timing of collecting identity verification information, as shown in Figure 8 or Figure 9.
[0273] [4.7] Registering and logging in to network services Next, registration to a network service provided by the service server device 30 of this embodiment will be described.
[0274] When the identity verification process for the user wishing to register is completed and the identity authentication of the user wishing to register is completed, the service server device 30, under the management of the authentication server device 10, works in conjunction with the corresponding terminal device 20 to register the user wishing to register as a registered user who will enjoy the corresponding network service.
[0275] Specifically, the service server device 30 works in conjunction with the authentication server device 10 to register user information such as a user name or a user ID and a password in the database 140 .
[0276] When a login is performed by a registered user, the service server device 30 works in conjunction with the authentication server device 10 and performs authentication processing for the registered user based on the input information (specifically, the user name or user ID and password) entered via the terminal device 20 and the information stored in the database 140.
[0277] If the authentication of the registered user is successful, the authentication processing unit 103 allows the registered user to log in to the network service provided by the service server device 30.
[0278] [4.8] Variations Next, a modification of this embodiment will be described.
[0279] (Application data generation process by authentication server device) In the above embodiment, the application data generation process is executed by the terminal device 20, but the application data generation process may be executed in the authentication server device 10.
[0280] That is, the authentication server device 10 may work in conjunction with the terminal device 20 of the user who wishes to be registered and who wishes to be identified, and may execute the application data generation process based on the base data and customized data.
[0281] In this case, the authentication server device 10 includes an information collection management control unit 105 that has some or all of the functions of the application data generation unit 216 of the terminal device 20 .
[0282] The authentication server device 10 is configured to have the corresponding terminal device 20 collect personal identification information based on the generated application data, and to execute personal identification processing based on the collected personal identification information.
[0283] Specifically, the information collection management control unit 105 generates application data for executing an information collection process consisting of one or more steps, which is a process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed.
[0284] In addition, the information collection management control unit 105 (A1) Manage base data that is stored in a database 140 and defines the content of each process, and customize data that is stored in the database for each provider of network services in association with the provider's identification information or setting information that defines the content of the process, and customizes the base data; (A2) performing a generation process to generate application data based on the base data and the customization data; (A3) Providing the generated application data to the terminal device 20; (A4) Acquire information entered based on user operation as personal identification information based on application data; It has the following structure.
[0285] In particular, the information collection management control unit 105 performs the following generation process: (A2-1) When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; (A2-2) generating application data based on the customized data and the base data stored in the database 140 in association with the acquired instruction information; It has the following structure.
[0286] In this case, the personal identification process management unit 104 is linked to the information management server device 40. Then, each step of the authentication process related to the personal identification process is executed.
[0287] On the other hand, in this case, the terminal device 20 executes an information collection process for collecting personal verification information based on the application data generated as described above.
[0288] Specifically, in this case, the terminal device 20 is a terminal device that executes an information collection process consisting of one or more steps, which is a process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed.
[0289] In this case, the terminal device 20 (B1) executes an acquisition process to acquire the generated application data based on base data, which is data stored in the database 140 and defines the content of each process, and customization data, which is data stored in the database 140 for each provider of network services in association with the identification information of each provider or the setting information defining the content of the process, and customizes the base data; (B2) Performing an information collection process based on the acquired application data; (B3) during the execution of the information collection process, presenting the user with the identity verification information to be input; (B4) Execute a reception process to receive a user's operation for inputting the presented personal identification information; (B5) Based on the user's operation, the input information is output as personal identification information to the authentication server device 10 that executes the authentication process. It has the following structure.
[0290] As described above, the application data is information obtained when the user requests the execution of an authentication process for identity verification for a network service provided by a specific provider, and is generated based on instruction information of at least one of the identification information of the specific provider and the setting information.
[0291] In this modification, each step of the authentication process relating to the personal identification process may be executed by the information management server device 40 instead of the authentication server device 10.
[0292] (Other Examples of Authentication Server Device and Service Server Device) In this embodiment, the authentication server device 10 may have the functions of the information management server device 40 .
[0293] In this embodiment, the service server device 30 may also have the functions of the authentication server device 10.
[0294] (Key information obtained via a network, etc.) In this embodiment, an example is described in which the key code is directly input by the user wishing to register via the operation input unit 260, but the key code may also be obtained via a network, or may be stored in advance in the terminal device 20 and obtained by reading it out at the instruction of the user wishing to register.
[0295] [5] Operation in this embodiment Next, with reference to FIGS. 10 and 11, a process of collecting personal identification information including an application data generation process executed in the terminal device 20 of this embodiment and a process of personal identification based on the information collection process will be described.
[0296] 10 and 11 are flowcharts showing the operation of the information collection process for personal identification information, including the application data generation process, executed in the terminal device 20 of this embodiment, and the personal identification process based on the information collection process.
[0297] In this operation, it is assumed that a personal management number has already been issued and an IC card 60 has already been issued.
[0298] This operation will be explained using the collection of personal identification information when initially registering for a given network service and the personal identification process based on the personal identification information.
[0299] Furthermore, a case will be described in which both the identification information of the provider of a given network service and the setting information relating to the steps of the identity verification process are acquired as instruction information.
[0300] First, when the web browser 211 detects a request to execute identity verification processing together with instruction information including both the identification information and setting information of the network service provider (step S101), the application data generation unit 216 reads out the customized data stored in the memory unit 270 based on the identification information and setting information included in the instruction information (step S102).
[0301] Next, the application data generating unit 216 generates application data based on the read customized data and the base data stored in the storage unit 270 (step S103).
[0302] Next, the information collection management unit 217 starts to collect information based on the generated application data (step S104).
[0303] First, the information collection and management unit 217 works in conjunction with the Web browser 211 and the display control unit 213 to display information to be presented to the user regarding the first step on the display unit 290 based on the application data (step S105).
[0304] Next, the information collection management unit 217 determines whether or not there is an operation input from the user (step S106).
[0305] At this time, if the information collection management unit 217 determines that there are no items for user input, it proceeds to processing of step S107, and if it determines that there are items for user input, it proceeds to processing of step S111.
[0306] Then, if the information collection and management unit 217 determines in the processing of step S106 that there is no item for user operation input, or if it acquires personal identification information in the previous step, it determines whether there is a next step (step S107).
[0307] If the information collection management unit 217 determines that there is no next step, it proceeds to processing in step S121; if it determines that there is a next step, it works in conjunction with the web browser 211 and the display control unit 213 to display information to be presented to the user regarding the next step on the display unit 290 based on the application data (step S108), and proceeds to processing in step S106.
[0308] On the other hand, if the information collection and management unit 217 determines that there is an item for user operation input, it executes a reception process for receiving operation input from the user who wishes to register (step 111).
[0309] Next, the information collection and management unit 217 acquires personal identification information based on the accepted operation (step S112), and proceeds to the processing of step S107.
[0310] At this time, the information collection and management unit 217 acquires, as personal identification information, information directly input by the operation input unit 260 or information on checked items, information read from the IC card 60 by the card reader / writer 240, and image information captured and generated by the imaging unit 250.
[0311] On the other hand, if the identity verification processing unit 218 determines in the processing of step S107 that there is no next step in the information collection processing, it terminates the information collection processing and outputs the acquired identity verification information to the authentication server device 10, the information management server device 40 or the public authentication management server device 50 (step S121), and executes the identity verification processing (step S122).
[0312] Finally, the personal identification processing unit 218 displays the result of the personal identification processing (whether or not authentication was successful) on the display unit 290 (step S123), and ends this operation.
[0313] The personal identification processing unit 218 will provide the authentication result of the personal identification processing to the corresponding terminal device 20 at a later date.
[0314] [6] Other The present invention is not limited to the above-described embodiments, and various modifications are possible. For example, terms cited in the specification or drawings as broadly defined or synonymous terms can be replaced with broadly defined or synonymous terms in other descriptions in the specification or drawings.
[0315] The present invention includes configurations that are substantially the same as the configurations described in the embodiments (for example, configurations with the same functions, methods, and results, or configurations with the same purpose and effects). The present invention also includes configurations in which non-essential parts of the configurations described in the embodiments are replaced. The present invention also includes configurations that achieve the same effects as the configurations described in the embodiments or that can achieve the same purpose. The present invention also includes configurations in which publicly known technology is added to the configurations described in the embodiments.
[0316] Although the embodiments of the present invention have been described in detail as above, it will be readily apparent to those skilled in the art that many modifications can be made without substantially departing from the novel features and effects of the present invention. Therefore, all such modifications are intended to be included within the scope of the present invention. [Explanation of symbols]
[0317] 1: Authentication management communication system 10: Authentication server device 20: Terminal device 20A: Terminal equipment 20B: Terminal device 20C: Terminal equipment 30: Service server device 40: Information management server device 50: Public authentication management server device 60: IC card 100: Processing section 101: Communication control unit 102: DB management control unit 103: Authentication processing unit 104: Identity Verification Processing Management Department 105: Information collection management control unit 107: Timer management unit 111: Step 140: Database 170: Storage section 180: Information storage medium 196: Communications Department 200: Processing section 210: Communication control unit 211: Web browser 212: Imaging control unit 213: Display control unit 214: Input reception processing unit 215: Reading control unit 216: Application data generation unit 217: Information Collection and Management Department 218: Identity verification processing unit 220: Drawing section 230: Sound processing unit 240: Writer 250: Imaging unit 260: Operation input section 270: Storage section 271: Main memory 272: Image buffer 273: User information storage unit 274: Data storage unit 280: Information storage medium 290: Display section 292: Sound output unit 296: Communications Department
Claims
1. 1. An information collection system that executes an information collection process that is a process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, a management means for managing base data, which is stored in a storage means and defines the content of each process, and customization data, which is stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the process, and which customizes the base data; a generation unit that executes a generation process for generating application data based on the base data and the customized data; an application execution processing means for executing the information collection process based on the generated application data; a presentation means for presenting the personal identification information to be input to the user during the execution of the information collection process; a reception processing means for executing a reception process for receiving an operation by the user to input the presented personal identification information; an output control means for outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; Equipped with The generation means performs the generation process as follows: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; An information collection system characterized in that the application data is generated based on the customized data and the base data stored in the storage means in association with the acquired instruction information.
2. 2. The information collection system according to claim 1, the customization data is data that specifies whether each of a plurality of steps included in the information collection process is executable, The generating means The information collection system generates the application data in which whether each process can be executed is defined based on the customized data stored in association with the instruction information and the base data.
3. 2. The information collection system according to claim 1, the customization data is data that defines content to be incorporated into the base data, The generating means An information collection system that generates the application data by incorporating the customization data, which is stored in association with the instruction information, into the base data.
4. 2. The information collection system according to claim 1, The customization data specifies an information management server system to be linked when performing the authentication process for the identity verification from among a plurality of information management server systems that perform the authentication process using the legitimate identity verification information, The generating means The customized data and the base data stored in association with the instruction information are and generating the application data based on the data, the application data including performing data communication with an information management server system that cooperates when performing authentication processing for the identity verification.
5. 2. The information collection system according to claim 1, further comprising imaging control means for controlling the imaging means; The customization data specifies whether or not a process using image information captured and generated by the imaging means is to be executed, The generating means An information collection system that generates the application data, which specifies whether or not to use the image information generated by the imaging means, based on the customization data stored in correspondence with the instruction information and the base data.
6. A program for executing an information collection process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, a management means for managing base data, which is stored in a storage means and defines the content of each process, and customization data, which is stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the process, and which customizes the base data; a generation means for executing a generation process for generating application data based on the base data and the customized data; an application execution processing means for executing the information collection process based on the generated application data; a presentation means for presenting the personal identification information to be input to the user during the execution of the information collection process; a reception processing means for executing a reception process for receiving an operation by the user to input the presented personal identification information; and an output control means for outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; Make the computer function as The generation means performs the generation process as follows: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; a program for generating the application data based on the customized data and the base data stored in the storage means in association with the acquired instruction information;
7. An information collection method for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, and being executed by a computer, comprising: managing base data that is stored in a storage means and defines the content of each step, and customization data that is stored in the storage means in association with identification information of each provider or setting information that defines the content of the step for each provider of the network service, and that customizes the base data; executes a generation process for generating application data based on the base data and the customization data; Execute the information collection process based on the generated application data; During the information collection process, present the user with the personal identification information to be input; executes a reception process for receiving an operation by the user to input the presented personal identification information; outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; This includes: The generation process includes: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; An information collection method characterized by generating the application data based on the customized data and the base data stored in the storage means in association with the acquired instruction information.
8. A terminal device that executes an information collection process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, an acquisition means for executing an acquisition process for acquiring the generated application data based on base data, which is data stored in a storage means and defines the content of each step, and customization data, which is data stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the step, and customizes the base data; an application execution processing means for executing the information collection process based on the acquired application data; a presentation means for presenting the personal identification information to be input to the user during the execution of the information collection process; a reception processing means for executing a reception process for receiving an operation by the user to input the presented personal identification information; an output control means for outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; Equipped with The application data is A terminal device characterized in that the information acquired when the user requests the execution of an authentication process for identity verification for a network service provided by a specific provider is generated based on instruction information of at least one of the identification information of the specific provider and the setting information.
9. A program for executing an information collection process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, an acquisition means for executing an acquisition process for acquiring the generated application data based on base data, which is data stored in a storage means and defines the content of each step, and customization data, which is data stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the step, and customizes the base data; an application execution processing means for executing the information collection process based on the acquired application data; a presentation means for presenting the personal identification information to be input to the user during the execution of the information collection process; A reception process for receiving an operation by the user to input the presented personal identification information. A reception processing means for executing the above; an output control means for outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; Make the computer function as The application data is A program characterized in that the information obtained when the user requests the execution of an authentication process for identity verification for a network service provided by a specific provider is generated based on instruction information of at least one of the identification information of the specific provider and the setting information.
10. An information collection method for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, and being executed by a computer, comprising: executes an acquisition process for acquiring the generated application data based on base data, which is data stored in a storage means and defines the content of each step, and customization data, which is data stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the step, and customizes the base data; Execute the information collection process based on the acquired application data; During the information collection process, present the user with the personal identification information to be input; executes a reception process for receiving an operation by the user to input the presented personal identification information; outputting the input information as personal identification information to an authentication server system that executes the authentication process based on the user's operation; This includes: The application data is An information collection method characterized in that the information is acquired when the user requests the execution of an authentication process for identity verification for a network service provided by a specific provider, and is generated based on instruction information of at least one of the identification information of the specific provider and the setting information.
11. A data generation system that generates application data for executing an information collection process that is a process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, a management means for managing base data, which is stored in a storage means and defines the content of each process, and customization data, which is stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the process, and which customizes the base data; a generation unit that executes a generation process for generating application data based on the base data and the customized data; providing means for providing the generated application data to a terminal device; an acquisition means for acquiring information input by the user's operation based on the application data as personal identification information; Equipped with The generation means performs the generation process as follows: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; A data generation system characterized in that the application data is generated based on the customized data and the base data stored in the storage means in association with the acquired instruction information.
12. A program for generating application data for executing an information collection process that is a process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, a management means for managing base data, which is stored in a storage means and defines the content of each process, and customization data, which is stored in the storage means for each provider of the network service in association with identification information of each provider or setting information defining the content of the process, and which customizes the base data; a generation means for executing a generation process for generating application data based on the base data and the customized data; providing means for providing the generated application data to a terminal device; and an acquisition means for acquiring information input based on the user's operation as personal identification information based on the application data; Make the computer function as The generation means performs the generation process as follows: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; a program for generating the application data based on the customized data and the base data stored in the storage means in association with the acquired instruction information;
13. A data generation method for generating, by a computer, application data for executing an information collection process for collecting information for identity verification as identity verification information when an authentication process for verifying the identity of a user for a given network service is executed, the information collection process being composed of one or more steps, comprising: managing base data that is stored in a storage means and defines the content of each step, and customization data that is stored in the storage means in association with identification information of each provider or setting information that defines the content of the step for each provider of the network service, and that customizes the base data; executes a generation process for generating application data based on the base data and the customization data; providing the generated application data to a terminal device; acquiring information input based on the user's operation as personal identification information based on the application data; This includes: The generation process includes: When a request for execution of authentication processing for identity verification for a network service provided by a specific provider is instructed by the user, instruction information of at least one of identification information of the specific provider and the setting information is acquired; A data generation method characterized by generating the application data based on the customized data and the base data stored in the storage means in association with the acquired instruction information.
Citation Information
Patent Citations
Account opening system, account opening method, and program
JP2019050014A