Server device, method for controlling server device, and program
The server device addresses the challenge of detecting unauthorized entry through tailgating by calculating pedestrian counts and analyzing biometric data to identify and prevent unauthorized access in gateless authentication systems.
Patent Information
- Application Number
- JP2024034473
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-07
- Publication Date
- 2025-09-19
AI Technical Summary
Existing systems struggle to detect unauthorized individuals who enter secure venues by tailgating with authorized persons, particularly in gateless authentication scenarios where physical barriers are absent.
A server device that calculates the number of pedestrians passing through a specified point, extracts biometric information from image data, and performs authentication processing to identify instances of tailgating by comparing the number of individuals to the number of authorized persons.
Effectively detects and prevents unauthorized entry by tailgating, enhancing security in gateless authentication systems by identifying and alerting security personnel to potential tailgating incidents.
Smart Images

Figure 2025136195000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a server device, a method for controlling a server device, and a program. [Background technology]
[0002] Technology exists to detect suspicious intruders.
[0003] For example, Patent Document 1 discloses an intrusion monitoring system that can improve the accuracy of detecting unauthorized entry by tailgating. The intrusion monitoring system of Patent Document 1 determines that an unauthorized person has intruded when an intrusion detection device permits entry into a security area and detects the blocking of light or sound waves equivalent to the number of people. Therefore, even if an intrusion is authenticated, the intrusion monitoring system can detect the number of people passing by based on the blocking of infrared rays and determine that an unauthorized person has intruded into the security area by tailgating. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-233692 Summary of the Invention [Problem to be solved by the invention]
[0005] As disclosed in Patent Document 1, it is necessary to detect unauthorized entrants who enter with others. In recent years, there have been systems that employ gateless authentication, which does not use means to physically restrict people's passage, such as gates or flappers. Even in gateless authentication, it is necessary to detect unauthorized entrants who enter with others.
[0006] A primary object of the present invention is to provide a server device, a method for controlling a server device, and a program that contribute to enabling detection of a person attempting to illegally enter a venue by tailgating. [Means for solving the problem]
[0007] According to a first aspect of the present invention, a server device is provided which includes: a calculation means for calculating the number of pedestrians passing through a specified point during a specified period; an extraction means for extracting biometric information of at least one or more first authenticated persons from image data obtained by photographing pedestrians passing through the specified point; and a first authentication means for performing authentication processing of the at least one or more first authenticated persons using the extracted biometric information, and determining that there is a companion passing through the specified point with an authenticated person among the at least one or more first authenticated persons who has been determined to have been successfully authenticated, if the number of pedestrians is greater than the number of first authenticated persons obtained from the image data.
[0008] According to a second aspect of the present invention, there is provided a control method for a server device, comprising: a calculation step of calculating the number of pedestrians passing through a specified point during a specified period; an extraction step of extracting biometric information of at least one or more first authenticated persons from image data obtained by photographing pedestrians passing through the specified point; and a first authentication step of performing authentication processing of the at least one or more first authenticated persons using the extracted biometric information, and determining that there is a companion passing through the specified point with one of the at least one or more first authenticated persons who has been determined to have been successfully authenticated, if the number of pedestrians is greater than the number of first authenticated persons obtained from the image data.
[0009] According to a third aspect of the present invention, there is provided a program for causing a computer mounted on a server device to execute the following steps: a calculation process for calculating the number of pedestrians passing through a specified point within a specified period of time; an extraction process for extracting biometric information of at least one or more first subjects to be authenticated from image data obtained by photographing pedestrians passing through the specified point; and a first authentication process for performing an authentication process for the at least one or more first subjects to be authenticated using the extracted biometric information, and determining that, if the number of pedestrians is greater than the number of first subjects to be authenticated obtained from the image data, there is a companion passing through the specified point with one of the at least one or more first subjects to be authenticated who has been determined to have been successfully authenticated. [Effects of the Invention]
[0010] According to each aspect of the present invention, a server device, a control method for a server device, and a program are provided that contribute to enabling detection of a person attempting to illegally enter a venue by tailgating. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram for explaining an outline of an embodiment. [Figure 2] FIG. 2 is a flowchart for explaining an outline of the operation of one embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure. [Figure 4] FIG. 4 is a diagram illustrating an example of a building configuration according to an embodiment of the present disclosure. [Figure 5] FIG. 5 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 6] 6A and 6B are diagrams for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 7]FIG. 7 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 8] FIG. 8 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 9] FIG. 9 is a diagram illustrating an example of a processing configuration of a server device according to an embodiment of the present disclosure. [Figure 10] FIG. 10 is a diagram illustrating an example of an employee management database according to an embodiment of the present disclosure. [Figure 11] FIG. 11 is a flowchart illustrating an example of the operation of the first authentication unit according to the embodiment of the present disclosure. [Figure 12] FIG. 12 is a flowchart illustrating an example of the operation of the first authentication unit according to the embodiment of the present disclosure. [Figure 13] FIG. 13 is a flowchart illustrating an example of the operation of the second authentication unit according to the embodiment of the present disclosure. [Figure 14] FIG. 14 is a diagram illustrating an example of a processing configuration of an authentication terminal according to an embodiment of the present disclosure. [Figure 15] FIG. 15 is a sequence diagram illustrating an example of the operation of the information processing system according to an embodiment of the present disclosure. [Figure 16] FIG. 16 is a diagram illustrating an example of a display on a terminal carried by a security guard according to an embodiment of the present disclosure. [Figure 17] FIG. 17 is a diagram illustrating an example of a display on a terminal carried by a security guard according to an embodiment of the present disclosure. [Figure 18] FIG. 18 is a diagram illustrating an example of a hardware configuration of a server device according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0012] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.
[0013] A server device 100 according to one embodiment includes a calculation means 101, an extraction means 102, and a first authentication means 103 (see FIG. 1). The calculation means 101 calculates the number of pedestrians passing through a predetermined point during a predetermined period (step S1 in FIG. 2). The extraction means 102 extracts biometric information of at least one first person to be authenticated from image data obtained by photographing pedestrians passing through the predetermined point (step S2). The first authentication means 103 executes authentication processing for at least one first person to be authenticated using the extracted biometric information (step S3). If the number of pedestrians is greater than the number of first people to be authenticated obtained from the image data, the first authentication means 103 determines that there is a companion passing through the predetermined point with at least one first person to be authenticated who has been determined to have been successfully authenticated (step S4).
[0014] The server device 100 calculates the number of pedestrians passing through a predetermined point set in an entry-restricted area. The server device 100 also extracts a facial image of the person to be authenticated from image data of the pedestrian attempting to pass through the predetermined point and authenticates the person. When the server device 100 successfully authenticates the person to be authenticated, if the number of pedestrians passing through the predetermined point is greater than the number of people to be authenticated, the server device 100 determines that there is a tailgating partner who passed through the predetermined point with the successfully authenticated person. For example, if there is a tailgating partner attempting to pass through the predetermined point by hiding behind the person to be authenticated who has the authority to pass through the predetermined point, the number of pedestrians is "2" and the number of people to be authenticated is "1." The server device 100 focuses on such an imbalance between the number of pedestrians and the number of people to be authenticated and detects tailgating partners attempting to enter a predetermined facility, etc., by tailgating.
[0015] Specific embodiments will be described in more detail below with reference to the drawings.
[0016] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.
[0017] [System Configuration] 3 is a diagram illustrating an example of a schematic configuration of an information processing system (authentication system) according to an embodiment of the present disclosure. As illustrated in FIG. 3, the information processing system includes a server device 10.
[0018] The server device 10 provides authentication services to companies, universities, local governments, etc. In the first embodiment, a case will be described in which the server device 10 provides authentication services to companies. More specifically, in the first embodiment, employees working at a company are set as authentication subjects, and the configuration, operation, etc. of the information processing system will be described.
[0019] The server device 10 may be installed in the building of a company that provides the authentication service, or may be installed on a network (on the cloud).
[0020] 3, employees and the like carry terminals 20. The employees use the terminals 20 to access the server device 10 and the like.
[0021] FIG. 4 is a diagram showing an example of the internal configuration of a building that houses a company office. FIG. 4 shows the internal configuration on the first floor of the building. As shown in FIG. 4, the inside and outside of the building are separated by an automatic door. The opening and closing of the automatic door is not linked to the results of biometric authentication. The automatic door opens automatically when it detects a person, and then closes automatically.
[0022] A camera device 30 is installed outside the building, which can photograph a person to be authenticated who is about to enter the entrance through the automatic door.
[0023] Furthermore, a detection device 31 is installed in front of the camera device 30. The detection device 31 uses an infrared sensor or the like to detect a person crossing in front of the detection device 31 and heading towards the automatic door. Note that in the drawings including FIG. 4, one of the two units that transmit and receive infrared rays is not shown.
[0024] The camera device 30 is installed so as to be able to capture an image of a person passing in front of the detection device 31. For example, the camera device 30 is installed so as to be able to capture an image of a person located in the image capture area shown in FIG.
[0025] An authentication terminal 40 is installed inside the building. The authentication terminal 40 is a terminal that restricts people entering the entrance from entering a predetermined area. For example, the authentication terminal 40 is installed at the entrance to an elevator hall.
[0026] The server device 10 and the devices (camera device 30, detection device 31, authentication terminal 40) installed in the building are configured to be able to communicate with each other via a network. For example, the server device 10 and the camera device 30 are connected by wired or wireless communication means.
[0027] 3 and 4 are merely examples and are not intended to limit the configuration of the information processing system disclosed herein. For example, the information processing system may include multiple server devices 10. The multiple server devices 10 may achieve load balancing and redundancy. Also, FIG. 4 is merely an example and is not intended to limit the configuration within the building or the installation of the authentication terminal 40. For example, the authentication terminal 40 may be installed at the entrance to a conference room, or at the entrance to an office on an upper floor.
[0028] [General operation] Next, the general operation of the information processing system according to the first embodiment will be described.
[0029] <Employee Registration> Employees working at a company are required to register as employees in order to move around the building using biometric authentication.
[0030] The employee operates the terminal 20 to access the employee registration page provided by the server device 10. The employee registers as an employee on the employee registration page.
[0031] The employee inputs into the server device 10 his / her name, sex, date of birth, address, contact information (telephone number, email address), employee number, department, job title, biometric information, etc.
[0032] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, and iris pattern. Alternatively, the user's biometric information may be image data such as a face image or fingerprint image. The user's biometric information may be any information that includes the user's physical characteristics. In the first embodiment, the biometric information is a person's face image or features generated from a face image.
[0033] The server device 10 stores the acquired employee information in an employee management database, the details of which will be described later.
[0034] <Gateless authentication> The server device 10 authenticates a person attempting to enter a building. In this case, since an automatic door cannot restrict the person's entry into the building, the server device 10 performs gateless authentication that does not use a physical means of restricting passage such as a gate.
[0035] A person attempting to enter the building passes in front of the detection device 31 and goes through the automatic door. The detection device 31 detects the person passing in front of the detection device 31. When the detection device 31 detects the person passing in front of the detection device 31, it notifies the server device 10 of the fact.
[0036] Specifically, when the detection device 31 detects a person, it transmits a "detection notification" to the server device 10 (see FIG. 5).
[0037] Upon receiving the detection notification, the server device 10 sets a period for determining the number of pedestrians attempting to pass through the automatic door at the same time (predetermined period). Specifically, the server device 10 sets a "passer number determination period" in response to receiving the detection notification. For example, the server device 10 sets one second from the time of receiving the detection notification as the "passer number determination period."
[0038] In the following description, the passerby number determination period may be simply referred to as the "determination period."
[0039] If the server device 10 receives the next detection notification before the determination period has elapsed, the server device 10 resets the determination period. If the server device 10 receives the next detection notification during the determination period, the server device 10 sets the determination period to a predetermined period (for example, one second) from the time the server device 10 receives the next detection notification. If the server device 10 receives a new detection notification during the determination period, the server device 10 extends the determination period.
[0040] The server device 10 counts the number of pedestrians attempting to pass through the automatic door while setting the determination period. Specifically, the server device 10 increments the number of pedestrians each time it receives a detection notification. When the determination period ends, the number of pedestrians is finalized.
[0041] For example, when two people try to pass through the automatic door in succession (two people in a row), two detection notifications are sent consecutively to the server device 10. In response to receiving the first detection notification, the server device 10 sets a determination period and sets the number of passers-by to "1."
[0042] If the next person passes in front of the detection device 31 before the set decision period has elapsed, the server device 10 receives a second detection notification. In response to receiving the second detection notification, the server device 10 resets the decision period and increments the number of passersby (the number of passersby becomes "2").
[0043] Once the reset decision period has elapsed, the number of pedestrians will be determined. In the example above, the number of pedestrians attempting to pass through the automatic door will be "2."
[0044] The camera device 30 captures an image of a predetermined area in front of the automatic door and transmits the image data obtained by the image capture to the server device 10. The camera device 30 transmits image data of a person walking toward the automatic door to the server device 10.
[0045] The server device 10 sets the person who appears in the image data acquired immediately after receiving the detection notification that triggered the setting of the determination period as the person to be authenticated. For example, if two people appear in the image data, the two people are set as the person to be authenticated.
[0046] Server device 10 performs authentication for each of at least one or more persons to be authenticated.
[0047] Specifically, the server device 10 extracts biometric information (e.g., facial images) of at least one person to be authenticated that appears in the image data, and then performs authentication processing using the extracted biometric information and the biometric information stored in the employee management database.
[0048] For example, if two persons to be authenticated appear in the image data, the server device 10 executes authentication processing for each of the two persons to be authenticated.
[0049] Here, if the number of people passing through the automatic door at the same time is equal to or less than the number of people to be authenticated, server device 10 will use the authentication results of each person to be authenticated as the authentication result as is.
[0050] For example, as shown in Fig. 6A, if two people try to pass through the automatic door at the same time (within one second of time difference), the number of passers-by is set to "2." Furthermore, since the two people appear in the image data, the number of people to be authenticated is also set to "2." In this case, the server device 10 uses the authentication results of each person to be authenticated as the authentication result as is.
[0051] 6B, when two people pass through the automatic door in parallel (side by side), the number of passers-by is set to "1." Furthermore, since the two people appear in the image data, the number of people to be authenticated is set to "2." In this case as well, server device 10 uses the authentication results of each person to be authenticated as the authentication result as is.
[0052] If the number of people passing through the automatic door at the same time is greater than the number of people to be authenticated and the authentication result of the person to be authenticated is unsuccessful, the server device 10 adopts the authentication result of the person to be authenticated as the authentication result as it is.
[0053] On the other hand, if the number of people trying to pass through the automatic door at the same time is greater than the number of people to be authenticated and the authentication result of the person to be authenticated is successful, the server device 10 sets the authentication result of the person to be authenticated to authentication failure.
[0054] For example, as shown in Figure 7, if there is a person hiding behind an employee trying to enter a building, the detection device 31 detects two people. In this case, the number of passersby is set to "2." Furthermore, the image data obtained from the camera device 30 does not capture the person moving behind the employee. Therefore, the number of people to be authenticated is set to "1."
[0055] In this case, even if the server device 10 successfully authenticates the employee walking in front, it sets the authentication result of that employee to "authentication failed." That is, the server device 10 sets the authentication result of an employee who allows another person to enter (enter the building) by tailgating, even if the employee has legitimate authority to enter the building, to "authentication failed."
[0056] If it is determined that the authentication has failed because the authenticated person (the person to be authenticated who has been determined to have been successfully authenticated) allowed another person to tailgate, the server device 10 stores this information in the account of the authenticated person. Specifically, the server device 10 stores the authenticated person (employee) who allowed the tailgate as a "tailgate-allowed person" in the employee management database.
[0057] If the authentication results include an authentication failure, the server device 10 notifies a security guard or the like that a suspicious person may have entered. For example, the server device 10 transmits a message to a terminal held by the security guard that a suspicious person may have entered.
[0058] In particular, if the number of people passing through the automatic door is greater than the number of people to be authenticated obtained from the image data, the server device 10 determines that there is a person accompanying the successfully authenticated person (employee) who is going to pass through the automatic door. In this case, the server device 10 notifies the terminal carried by the security guard of the presence of the person accompanying the person.
[0059] <In-building authentication> A person who passes through the automatic doors and enters the building is also subject to biometric authentication when entering a designated area within the building. For example, in the example of Figure 4, an employee is required to undergo biometric authentication at authentication terminal 40.
[0060] When authentication terminal 40 detects a person to be authenticated in front of it, it transmits an "authentication request" including biometric information of the detected person to server device 10 (see FIG. 8).
[0061] The server device 10 executes authentication processing using the biometric information included in the authentication request and the biometric information stored in the employee management database. At this time, the server device 10 determines that the authentication is successful if the person to be authenticated is qualified to enter the elevator hall. The server device 10 determines that the authentication is unsuccessful if the person to be authenticated is not qualified to enter the elevator hall.
[0062] Furthermore, even if the person to be authenticated is qualified to enter the elevator hall, if the person to be authenticated is set as a "person who allows tailgating," the server device 10 determines that the authentication has failed. That is, if an employee allows another person to be tailgated in authentication performed at the building entrance (gateless authentication), the employee is determined to have failed the authentication even if the employee is qualified to enter the elevator hall.
[0063] The server device 10 transmits the authentication result (authentication success, authentication failure) to the authentication terminal 40. Specifically, if the authentication of the person to be authenticated is successful, the server device 10 transmits a positive response indicating that to the authentication terminal 40. If the authentication of the person to be authenticated is unsuccessful, the server device 10 transmits a negative response indicating that to the authentication terminal 40.
[0064] Upon receiving the positive response (authentication success), the authentication terminal 40 opens the gate and allows the person to be authenticated to pass through.
[0065] Upon receiving a negative response (authentication failure), the authentication terminal 40 closes the gate and denies the person to be authenticated passage.
[0066] An employee (tailgating permitter) who is determined to have failed authentication because he or she allowed another person to tailgate will contact, for example, a person in the human resources department by phone. The person in the human resources department will hear the circumstances from the employee and give the employee a prescribed warning or punishment. The person in the human resources department will access the server device 10 and cancel the tailgating permitter setting for the employee.
[0067] Next, details of each device included in the information processing system according to the first embodiment will be described.
[0068] [Server device] 9 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to the embodiment of the present disclosure. Referring to FIG. 9, the server device 10 includes a communication control unit 201, an employee management unit 202, a first authentication unit 203, a second authentication unit 204, and a storage unit 205.
[0069] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the authentication terminal 40. The communication control unit 201 also transmits data to the authentication terminal 40. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0070] The employee management unit 202 is a means for controlling and managing employees.
[0071] When an employee operates terminal 20 to access the employee registration page, employee management unit 202 acquires information about the employee on that page.
[0072] Specifically, the employee management department 202 displays a GUI (Graphical User Interface) or the like on the terminal 20 and acquires the employee's name, gender, date of birth, address, contact information (telephone number, email address), employee number, department, position, biometric information (e.g., facial image), etc.
[0073] When the employee management unit 202 acquires a facial image, it generates feature quantities from the facial image. The employee management unit 202 can use existing technology for the feature quantity generation process, so a detailed description thereof will be omitted. For example, the employee management unit 202 extracts the eyes, nose, mouth, etc. from the facial image as feature points. The employee management unit 202 then calculates the positions of each feature point and the distances between each feature point as feature quantities (generating a feature vector consisting of multiple feature quantities).
[0074] Once the feature quantities are generated, the employee management unit 202 generates an employee ID to identify the employee. The employee ID may be any information that can uniquely identify an employee. For example, the employee management unit 202 may assign a unique value each time it acquires employee information and use this as the employee ID. Alternatively, the employee management unit 202 may use the employee number as the employee ID.
[0075] When the employee ID is generated, the employee management unit 202 adds a new entry to the employee management database and generates an account. The employee management unit 202 stores the employee ID, name, biometric information (features), etc. in the added entry (see FIG. 10).
[0076] The employee management database shown in Figure 10 is an example and is not intended to limit the items stored. For example, a "face image" may be registered as biometric information in the employee management database. Also, in Figure 10, an employee with a circle in the Tailgating Allowed field indicates an employee who has allowed others to be tailgated during gateless authentication.
[0077] First authentication unit 203 is a means for authenticating a person to be authenticated (first person to be authenticated) who is attempting to enter a building.
[0078] The first authentication unit 203 functions as a calculation unit and an extraction unit. The first authentication unit 203 as a calculation unit calculates the number of pedestrians passing through a predetermined point (e.g., an automatic door) during a predetermined period. The first authentication unit 203 as an extraction unit extracts biometric information of at least one first person to be authenticated from image data obtained by photographing pedestrians passing through the predetermined point. Furthermore, the first authentication unit 203 performs authentication processing for at least one first person to be authenticated using the extracted biometric information. If the number of pedestrians passing through the automatic door is greater than the number of first people to be authenticated obtained from the image data, the first authentication unit 203 determines that there is a tailgating individual passing through the predetermined point with at least one first person to be authenticated who has been determined to have been successfully authenticated.
[0079] 11 and 12 are flowcharts showing an example of the operation of the first authentication unit 203 according to the embodiment of the present disclosure. The operation of the first authentication unit 203 will be described with reference to FIGS.
[0080] When the first authentication unit 203 receives a detection notification from the detecting device 31, it sets a passerby number determination period (setting determination period; step S101).
[0081] In response to receiving the detection notification, the first authentication unit 203 sets the number of passersby to "1" (step S102). That is, in response to receiving the detection notification, the first authentication unit 203 starts counting the number of passersby.
[0082] When receiving a detection notification during the determined period (step S103, branch Yes), the first authentication unit 203 resets the determined period and increments the number of passersby (steps S104 and S105).
[0083] If no new detection notification is received within the determined period (step S103, No branch), the first authentication unit 203 extracts biometric information (face image, face area) from the image data received from the camera device 30 (step S106).
[0084] Specifically, the first authentication unit 203 extracts face images of at least one person appearing in the image data acquired immediately after receiving the detection notification that triggered the setting of the determination period.
[0085] Note that since existing technology can be used for the facial image extraction process by the first authentication unit 203, detailed description thereof will be omitted. For example, the first authentication unit 203 may extract a facial image (facial region) from image data using a learning model trained by a CNN (Convolutional Neural Network). Alternatively, the first authentication unit 203 may extract a facial image using a method such as template matching.
[0086] The number of face images extracted from the image data corresponds to the number of people to be authenticated.
[0087] The first authentication unit 203 executes authentication processing for each of the at least one or more extracted face images (execute authentication processing; step S107).
[0088] Specifically, first authentication unit 203 generates features from the extracted facial image. First authentication unit 203 executes a matching process using the generated features and features stored in the employee management database. More specifically, first authentication unit 203 sets the generated features as the target of matching and performs one-to-N matching between the features and features registered in the employee management database (N is a positive integer, the same applies below).
[0089] The first authentication unit 203 calculates the similarity between the feature to be matched and each of the multiple feature values on the registration side. The similarity can be calculated using a chi-square distance, Euclidean distance, or the like. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0090] The first authentication unit 203 determines that the matching process has failed if there is no feature among the multiple feature amounts registered in the employee management database that has a similarity with the feature amount to be matched that is equal to or greater than a predetermined value.
[0091] The first authentication unit 203 determines that the matching process is successful if, among the multiple feature amounts registered in the employee management database, there is a feature amount whose similarity with the feature amount to be matched is equal to or greater than a predetermined value. If the matching process is successful, the employee corresponding to the entry with the feature amount with the highest similarity is identified as the person to be authenticated who appears in the image data.
[0092] If the matching process is successful, the first authentication unit 203 determines that the authentication of the person to be authenticated has been successful. If the matching process is unsuccessful, the first authentication unit 203 determines that the authentication of the person to be authenticated has been unsuccessful. In this way, the first authentication unit 203 determines that the authentication of the person to be authenticated has been successful if biometric information that is substantially the same as the biometric information of the person to be authenticated is registered in the employee management database.
[0093] The first authentication unit 203 repeats the above authentication process for each face image extracted from the image data.
[0094] The first authentication unit 203 determines whether the number of passers-by determined according to the number of times the detection notification has been received is greater than the number of people to be authenticated.
[0095] If the number of passersby determined according to the number of times the detection notification is received is equal to or less than the number of persons to be authenticated (step S108, No branch), the first authentication unit 203 does not perform any particular process.
[0096] If the number of passersby is greater than the number of persons to be authenticated (step S108, Yes branch), the first authentication unit 203 cancels the successful authentication of the person to be authenticated (step S109). Specifically, if there is a person to be authenticated who is determined to have been successfully authenticated, the first authentication unit 203 sets the authentication result of that person to be successfully authenticated to "authentication failed." Furthermore, the first authentication unit 203 stores the person to be authenticated (employee) who is determined to have been successfully authenticated in the authentication process of step S107 as a "tailgating-approved person" in the employee management database.
[0097] The first authentication unit 203 determines whether or not there is an authentication failure in the authentication result.
[0098] If there is an authentication failure (step S110 in FIG. 12, Yes branch), the first authentication unit 203 notifies a security guard or the like that a suspicious person may have entered (step S110).
[0099] In this case, the first authentication unit 203 may change the content of the notification to the security guard regarding normal authentication failure and authentication failure due to tailgating. In the former case, the first authentication unit 203 may send a facial image (a facial image extracted from image data) of the person who failed the authentication process to a terminal carried by the security guard. In the latter case, the first authentication unit 203 may send a message to the terminal carried by the security guard that a suspicious person has entered the building as a tailgating person.
[0100] If there is no authentication failure (step S110 in FIG. 12, No branch), the first authentication unit 203 does not perform any particular process.
[0101] In this way, if the number of passersby is greater than the number of first authenticated persons obtained from the image data and there is an authenticated person who has been determined to have been successfully authenticated, the first authentication unit 203 sets the authentication result of that authenticated person to authentication failure (cancels the authentication success). Furthermore, the first authentication unit 203 stores the authenticated person whose authentication result has been set to authentication failure in the employee management database as an approved tailgating person. Furthermore, the first authentication unit 203 transmits information about the first authenticated person who has been determined to have been unsuccessful in the authentication process to a terminal carried by the security guard.
[0102] Second authentication unit 204 is a means for authenticating a person to be authenticated (second person to be authenticated) who attempts to enter a predetermined area. Second authentication unit 204 processes an authentication request received from authentication terminal 40.
[0103] Second authentication unit 204 receives biometric information of the second person to be authenticated from authentication terminal 40 installed in a predetermined area (for example, an elevator hall). Second authentication unit 204 authenticates the second person to be authenticated using the received biometric information of the second person to be authenticated and the biometric information stored in the employee management database.
[0104] 13 is a flowchart showing an example of the operation of the second authentication unit 204 according to the embodiment of the present disclosure. The operation of the second authentication unit 204 will be described with reference to FIG.
[0105] Upon receiving an authentication request, the second authentication unit 204 executes a matching process using the biometric information included in the authentication request and the biometric information stored in the employee management database (step S201).
[0106] Note that the matching process performed by the second authentication unit 204 and the matching process performed by the first authentication unit 203 can be the same, so a detailed description of the matching process performed by the second authentication unit 204 will be omitted.
[0107] If the matching process fails (step S202, No branch), the second authentication unit 204 sets the authentication result to authentication failure (step S203).
[0108] If the matching process is successful (step S202, Yes branch), the second authentication unit 204 determines whether the person to be authenticated identified by the matching process is qualified to enter the specified area (determine whether or not the person is qualified to enter; step S204).
[0109] For example, the second authentication unit 204 determines whether the person to be authenticated is qualified to enter based on the department and position of the employee identified by the matching process. For example, in the example of Fig. 4, if the department of the identified employee is on a floor that can be reached by elevator, the employee is determined to be qualified to enter the specified area (elevator hall).
[0110] Alternatively, the second authentication unit 204 may determine that the person to be authenticated (employee) identified by the matching process is qualified to enter the predetermined area if the biometric information is registered in the employee management database.
[0111] If the person to be authenticated does not have the qualification to enter the predetermined area (step S205, No branch), second authentication unit 204 sets the authentication result to authentication failure (step S203).
[0112] If the person to be authenticated is qualified to enter the predetermined area (step S205, Yes branch), the second authentication unit 204 determines whether the person to be authenticated identified by the matching process is a tailgating-allowed person (step S206). The second authentication unit 204 checks the tailgating-allowed person field in the employee management database and determines whether the person to be authenticated is set as a tailgating-allowed person.
[0113] If the person to be authenticated is a tailgating-approved person (step S207, Yes branch), the second authentication unit 204 sets the authentication result to authentication failure (step S203).
[0114] If the person to be authenticated is not a tailgating-approved person (step S207, No branch), the second authentication unit 204 sets the authentication result to authentication success (step S208).
[0115] The second authentication unit 204 transmits the authentication result (authentication success, authentication failure) to the authentication terminal 40 (step S209). If the authentication is successful, the second authentication unit 204 transmits a positive response indicating that to the authentication terminal 40. If the authentication is unsuccessful, the second authentication unit 204 transmits a negative response indicating that to the authentication terminal 40.
[0116] When second authentication unit 204 sets the authentication result of the person to be authenticated who is stored as a person who has accepted tailgating as "authentication failed," second authentication unit 204 may notify authentication terminal 40 that the person to be authenticated is a person who has accepted tailgating. For example, second authentication unit 204 may transmit to authentication terminal 40 a negative response including a message indicating that the person to be authenticated is a person who has accepted tailgating.
[0117] In this way, second authentication unit 204 performs a matching process (authentication process) using the biometric information of the second person to be authenticated received from authentication terminal 40 and the biometric information stored in the employee management database. If the second person to be authenticated identified by the matching process is stored as a person who has been allowed to tailgate, second authentication unit 204 sets the authentication result of the second person to be authenticated who has been stored as a person who has been allowed to tailgate to authentication failure.
[0118] The storage unit 205 is a means for storing information necessary for the operation of the server device 10. The storage unit 205 manages and stores the biometric information of each of a plurality of persons to be authenticated (employees) using an employee management database.
[0119] Furthermore, the employee management database stores biometric information and qualification information (attribute information) of each person to be authenticated in association with each other. The qualification information is information that the server device 10 uses to determine whether each person to be authenticated is qualified to enter a predetermined area (a restricted entry area, for example, an elevator hall). For example, in the above example, the employee's department and job title correspond to the qualification information.
[0120] [Authentication terminal] 14 is a diagram illustrating an example of a processing configuration (processing module) of the authentication terminal 40 according to an embodiment of the present disclosure. Referring to FIG. 14, the authentication terminal 40 includes a communication control unit 301, a biometric information acquisition unit 302, an authentication request unit 303, and a storage unit 304.
[0121] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the server device 10. The communication control unit 301 also transmits data to the server device 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0122] The biometric information acquisition unit 302 is a means for controlling a camera and acquiring biometric information (e.g., a facial image) of a person to be authenticated. The biometric information acquisition unit 302 captures an image in front of the device periodically or at a predetermined timing. The biometric information acquisition unit 302 determines whether or not the acquired image contains a facial image, and if a facial image is included, extracts the facial image from the acquired image data.
[0123] The biometric information acquisition unit 302 passes the extracted face image to the authentication request unit 303 .
[0124] The authentication request unit 303 is a unit that requests authentication of the person to be authenticated from the server device 10. The authentication request unit 303 transmits an authentication request including the biometric information acquired from the biometric information acquisition unit 302 to the server device 10.
[0125] The authentication request unit 303 receives the authentication result (authentication success, authentication failure) from the server device 10.
[0126] If a negative response (authentication failure) is received, authentication request unit 303 closes the gate of authentication terminal 40 to deny passage to the person to be authenticated. In this case, if the person to be authenticated receives a negative response including a message indicating that the person is a person who has permitted tailgating, authentication request unit 303 may notify the person to be authenticated that they cannot pass through the gate because they have allowed another person to enter with them.
[0127] If an affirmative response (authentication success) is received, authentication request unit 303 opens the gate of authentication terminal 40 and allows the person to be authenticated to pass through.
[0128] The storage unit 304 stores information necessary for the operation of the authentication terminal 40 .
[0129] [Detection Device] A detailed description of the configuration and operation of the detection device 31 will be omitted because the configuration of the detection device 31 will be clear to those skilled in the art. The detection device 31 only needs to include a sensor for detecting the presence of an object (person) using infrared rays or the like, and a means for transmitting a detection notification.
[0130] [Camera equipment] The configuration of the camera device 30 will be clear to those skilled in the art, and therefore detailed description thereof will be omitted. The camera device 30 photographs a predetermined area periodically or at a predetermined timing, and transmits the obtained image data to the server device 10.
[0131] [Device] Examples of the terminal 20 include a smartphone, a mobile phone, a game console, a mobile terminal device such as a tablet, and a computer (personal computer, laptop computer). The terminal 20 can be any equipment or device that can accept user operations and communicate with the server device 10, etc. Furthermore, the configuration of the terminal 20 is clear to those skilled in the art, so a detailed description thereof will be omitted.
[0132] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described.
[0133] 15 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment of the present disclosure. The operation relating to gateless authentication of the information processing system according to the embodiment of the present disclosure will be described with reference to FIG.
[0134] The detecting device 31 transmits a detection notification to the server device 10 (step S01).
[0135] In response to receiving the detection notification, the server device 10 starts setting a determination period and counting the number of passersby (steps S02 and S03).
[0136] The camera device 30 transmits the image data to the server device 10 (step S04).
[0137] The server device 10 extracts at least one face image from the image data (step S05).
[0138] Server device 10 uses the extracted face image to perform authentication processing for each person to be authenticated (step S06).
[0139] If there is a successful authenticated person who allowed another person to enter by tailgating, the server device 10 cancels the successful authentication of the successful authenticated person (step S07).
[0140] If the authentication result includes an authentication failure, the server device 10 warns the security guard of the presence of a suspicious person (warning the security guard; step S08).
[0141] In this case, the server device 10 may change the content sent to the security guard's terminal depending on whether it is treating a normal authentication failure (a person without authority to enter the building) as a suspicious person or treating a person who has entered the building by hiding behind an employee or other person as a suspicious person.
[0142] For example, when notifying a security guard of a normal authentication failure as a suspicious person, the server device 10 transmits a facial image of the suspicious person, etc., so that a screen such as that shown in Fig. 16 is displayed on the security guard's terminal. Alternatively, when notifying a security guard that a suspicious person has entered a building with another person, the server device 10 transmits a message, etc., so that a screen such as that shown in Fig. 17 is displayed on the security guard's terminal.
[0143] As described above, in the information processing system according to the first embodiment, the server device 10 calculates the number of pedestrians passing through a predetermined point (automatic door) set in an area where entry is restricted. The server device 10 also extracts a facial image of the person to be authenticated from image data of the person passing through the automatic door, and authenticates the person to be authenticated using biometric information stored in the employee management database. When the server device 10 successfully authenticates the person to be authenticated, if the number of pedestrians passing through the automatic door is greater than the number of the person to be authenticated, the server device 10 determines that there is a tailgating partner who passed through the automatic door together with the person who was successfully authenticated. The server device 10 treats the tailgating partner as a suspicious person and notifies a security guard that the tailgating partner has entered the building (or that there is a possibility that the tailgating partner has entered the building). The security guard who receives the notification then further strengthens security within the building.
[0144] Furthermore, the server device 10 penalizes an employee (a person to be authenticated who has legitimate authority) who allows another person to enter by tailgating. Specifically, the server device 10 sets the employee who allowed the other person to enter as a "tailgating-approved employee." When the tailgating-approved employee undergoes authentication following the gateless authentication (authentication using a gate), the server device 10 sets the authentication result of the tailgating-approved employee to authentication failure. The tailgating-approved employee who is notified of authentication failure cannot pass through the gate. The tailgating-approved employee asks a person in the human resources department or the like to cancel the tailgating-approved employee setting. The person in the human resources department cancels the tailgating-approved employee setting while giving the tailgating-approved employee a warning. Such operation of the information processing system increases employees' awareness of security.
[0145] In addition, since the server device 10 can realize gateless authentication, it is possible to introduce entry / exit management using biometric authentication even in places where it is difficult to install a physical gate device. Furthermore, since employees who allow tailgating are registered as "tailgating-approved individuals" in the employee management database of the server device 10, personnel in charge can easily identify employees who allow tailgating.
[0146] Next, the hardware of each device constituting the information processing system will be described. Fig. 18 is a diagram showing an example of the hardware configuration of the server device 10.
[0147] The server device 10 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 18. For example, the server device 10 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
[0148] 18 is not intended to limit the hardware configuration of the server device 10. The server device 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the server device 10 is not intended to be limited to the example shown in FIG. 18, and for example, the server device 10 may include multiple processors 311.
[0149] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).
[0150] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.
[0151] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a keyboard, a mouse, a touch panel, or the like that accepts user operations.
[0152] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).
[0153] The functions of the server device 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by semiconductor chips.
[0154] The authentication terminal 40 and the like can also be configured by an information processing device, similar to the server device 10, and the basic hardware configuration is the same as that of the server device 10, so a description thereof will be omitted.
[0155] The server device 10 is equipped with a computer, and the computer executes a program to realize the functions of the server device 10. The server device 10 also executes a control method for the server device 10 by the program.
[0156] [Variations] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.
[0157] In the above embodiment, the operation of the information processing system was described with an employee working for a company set as the person to be authenticated. The person to be authenticated may also be an employee of another company visiting the company. In this case, the server device 10 may store biometric information of visitors to the company in a database and authenticate the visitor using the stored biometric information. For example, the server device 10 stores the biometric information of the visitor in a visitor management database. If the first authentication unit 203 or the second authentication unit 204 fails in the authentication process (matching process) using the biometric information stored in the employee management database, it may perform the authentication process using the biometric information stored in the visitor management database.
[0158] In the above embodiment, it has been described that when a suspicious person is detected in a building, the server device 10 notifies a security guard to that effect. However, when a suspicious person is detected, the first authentication unit 203 may notify employees and the like of the detection of the suspicious person by using an internal broadcast or the like.
[0159] In the above embodiment, the case where a pedestrian attempting to pass through an automatic door is detected by the detection device 31 using infrared rays has been described. However, the detection of the pedestrian may also be performed by analyzing image data. For example, a camera may be installed to capture images of the photographed area shown in FIG. 4 from the side or above. The first authentication unit 203 of the server device 10 may use the image data obtained from the camera to calculate the number of pedestrians attempting to pass through the automatic door at the same time.
[0160] In the above embodiment, in gateless authentication, the server device 10 determines that the authentication of the person to be authenticated is successful if the biometric information of the person to be authenticated is stored in the employee management database. However, like the second authentication unit 204, the first authentication unit 203 may also determine that the authentication of the person to be authenticated is successful if the person to be authenticated is qualified to enter the building.
[0161] In the above embodiment, a case has been described in which a facial image is transmitted as biometric information from the authentication terminal 40 to the server device 10. However, feature amounts generated from the facial image may be transmitted as biometric information from the authentication terminal 40 to the server device 10. In this case, the server device 10 can omit the process of generating feature amounts from the facial image.
[0162] In the above embodiment, the employee management database is configured inside the server device 10, but the database may also be configured on an external database server or the like. That is, some of the functions of the server device 10 may be implemented in another device. More specifically, the above-described "first authentication unit (first authentication means)" and the like may be implemented in any of the devices included in the system.
[0163] The form of data transmission and reception between each device (for example, the server device 10, the authentication terminal 40, etc.) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Biometric information and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.
[0164] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.
[0165] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.
[0166] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to information processing systems that realize biometric authentication performed in companies and the like.
[0167] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.
[0168] [Appendix 1] A calculation means for calculating the number of pedestrians passing through a predetermined point during a predetermined period of time; an extraction means for extracting biometric information of at least one first person to be authenticated from image data obtained by photographing a passerby passing through the predetermined point; a first authentication means for executing authentication processing of the at least one or more first authenticated persons using the extracted at least one or more pieces of biometric information, and determining, when the number of passersby is greater than the number of the first authenticated persons obtained from the image data, that there is a companion passing through the predetermined point together with an authenticated person among the at least one or more first authenticated persons who has been determined to have been successfully authenticated; A server device comprising: [Appendix 2] The first authentication means A server device as described in Appendix 1, which, if the number of passersby is greater than the number of first authenticated persons obtained from the image data, sets the authentication result of the at least one or more first authenticated persons who are determined to have been successfully authenticated to authentication failure. [Appendix 3] a storage means for storing biometric information of each of a plurality of subjects to be authenticated using a database; The server device described in Appendix 2, further comprising a second authentication means for receiving biometric information of a second person to be authenticated from an authentication terminal installed in a predetermined area, and authenticating the second person to be authenticated using the received biometric information of the second person to be authenticated and the biometric information stored in the database. [Appendix 4] The server device according to claim 3, wherein the first authentication means stores the successfully authenticated person, whose authentication result has been set to authentication failure, in the database as a tailgating-approved person. [Appendix 5] The second authentication means A server device as described in Appendix 4, which performs a matching process using the received biometric information of the second person to be authenticated and the biometric information stored in the database, and if the second person to be authenticated identified by the matching process is stored as the tailgating approved person, sets the authentication result of the second person to be authenticated who is stored as the tailgating approved person to authentication failure. [Appendix 6] The second authentication means A server device as described in Appendix 5, which notifies the authentication terminal that the second authenticated person is the tailgating approved person when the authentication result of the second authenticated person stored as the tailgating approved person is set to authentication failure. [Appendix 7] The server device according to any one of appendices 1 to 6, wherein the first authentication means transmits information about the first authenticated person who is determined to have failed authentication in the authentication process to a terminal carried by a security guard. [Appendix 8] 7. The server device according to claim 1, wherein the first authentication means notifies a terminal carried by a security guard of the presence of the accompanying person. [Appendix 9] A calculation step of calculating the number of pedestrians passing through a predetermined point during a predetermined period of time; an extraction step of extracting biometric information of at least one first person to be authenticated from image data obtained by photographing a passerby passing through the predetermined point; a first authentication step of performing authentication processing of the at least one or more first authenticated persons using the extracted at least one or more pieces of biometric information, and determining, if the number of passersby is greater than the number of the first authenticated persons obtained from the image data, that there is a companion passing through the predetermined point together with an authenticated person among the at least one or more first authenticated persons who has been determined to have been successfully authenticated; A method for controlling a server device, comprising: [Appendix 10] The first authentication step includes: A control method for a server device described in Appendix 9, wherein, if the number of passersby is greater than the number of first authenticated persons obtained from the image data, the authentication result of the at least one or more first authenticated persons who are determined to have been successfully authenticated is set to failed authentication. [Appendix 11] a storage step of storing biometric information of each of a plurality of authentication subjects using a database; A method for controlling a server device as described in Appendix 10, further comprising a second authentication step of receiving biometric information of a second person to be authenticated from an authentication terminal installed in a predetermined area, and authenticating the second person to be authenticated using the received biometric information of the second person to be authenticated and the biometric information stored in the database. [Appendix 12] The server device control method according to claim 11, wherein the first authentication step stores the successfully authenticated person, whose authentication result is set to authentication failure, in the database as a tailgating-approved person. [Appendix 13] The second authentication step includes: A control method for a server device described in Appendix 12, which performs a matching process using the received biometric information of the second person to be authenticated and the biometric information stored in the database, and if the second person to be authenticated identified by the matching process is stored as the tailgating approved person, sets the authentication result of the second person to be authenticated who is stored as the tailgating approved person to authentication failure. [Appendix 14] The second authentication step includes: A control method for a server device described in Appendix 13, in which if the authentication result of the second authenticated person stored as the tailgating approved person is set to authentication failure, the authentication terminal is notified that the second authenticated person is the tailgating approved person. [Appendix 15] A control method for a server device described in any one of Appendices 9 to 14, wherein the first authentication process sends information about the first authenticated person who is determined to have failed authentication in the authentication process to a terminal carried by a security guard. [Appendix 16] The server device control method according to any one of appendices 9 to 14, wherein the first authentication step notifies a terminal carried by a security guard of the presence of the accompanying person. [Appendix 17] The computer installed in the server device A calculation process for calculating the number of pedestrians passing through a predetermined point during a predetermined period of time; an extraction process for extracting biometric information of at least one first person to be authenticated from image data obtained by photographing a passerby passing through the predetermined point; a first authentication process that executes authentication processing of the at least one or more first authenticated persons using the extracted at least one or more pieces of biometric information, and when the number of passersby is greater than the number of the first authenticated persons obtained from the image data, determines that there is a companion passing through the predetermined point together with an authenticated person among the at least one or more first authenticated persons who has been determined to have been successfully authenticated; A program to execute. [Appendix 18] The first authentication process includes: The program described in Appendix 17, wherein, if the number of passersby is greater than the number of first authenticated persons obtained from the image data, the authentication result of the at least one or more first authenticated persons who are determined to have been successfully authenticated is set to authentication failure. [Appendix 19] a storage process for storing biometric information of each of a plurality of authentication subjects using a database; The program described in Appendix 18, further executing a second authentication process, which receives biometric information of a second person to be authenticated from an authentication terminal installed in a specified area, and authenticates the second person to be authenticated using the received biometric information of the second person to be authenticated and the biometric information stored in the database. [Appendix 20] The program according to claim 19, wherein the first authentication process stores the successfully authenticated person, whose authentication result is set to authentication failure, in the database as a tailgating-approved person. [Appendix 21] The second authentication process includes: A program as described in Appendix 20, which performs a matching process using the received biometric information of the second person to be authenticated and the biometric information stored in the database, and if the second person to be authenticated identified by the matching process is stored as the tailgating approved person, sets the authentication result of the second person to be authenticated who is stored as the tailgating approved person to authentication failure. [Appendix 22] The second authentication process includes: A program as described in Appendix 21, which notifies the authentication terminal that the second authenticated person is the tailgating approved person when the authentication result of the second authenticated person stored as the tailgating approved person is set to authentication failure. [Appendix 23] The program according to any one of appendices 17 to 22, wherein the first authentication process sends information about the first authenticated person who is determined to have failed authentication in the authentication process to a terminal carried by a security guard. [Appendix 24] 23. The program according to any one of appendices 17 to 22, wherein the first authentication process notifies a terminal carried by a security guard of the presence of the accompanying person.
[0169] Furthermore, some or all of the configurations described in Supplementary Notes 2 to 8, which are dependent on Supplementary Note 1, may also be dependent on Supplementary Notes 9 and 17 in the same dependent relationship as Supplementary Notes 2 to 8. Furthermore, not limited to Supplementary Notes 1, 9, and 17, but within the scope of each of the above-mentioned embodiments, some or all of the configurations described as Supplements may also be dependent on various hardware, software, various recording means for recording software, or systems.
[0170] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]
[0171] 10 Server device 20 terminals 30 Camera equipment 31 Detection Device 40 Authentication Terminal 100 Server device 101 Calculation Method 102 Extraction means 103 First authentication method 201 Communication control unit 202 Employee Management Department 203 First Authentication Section 204 Second Authentication Section 205 Storage section 301 Communication Control Unit 302 Biometric information acquisition unit 303 Authentication Request Section 304 Storage section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface
Claims
1. A calculation means for calculating the number of pedestrians passing through a predetermined point during a predetermined period of time; an extraction means for extracting biometric information of at least one first person to be authenticated from image data obtained by photographing a passerby passing through the predetermined point; a first authentication means for executing authentication processing of the at least one or more first authenticated persons using the extracted at least one or more pieces of biometric information, and determining, when the number of passersby is greater than the number of the first authenticated persons obtained from the image data, that there is a companion passing through the predetermined point together with an authenticated person among the at least one or more first authenticated persons who has been determined to have been successfully authenticated; A server device comprising:
2. The first authentication means The server device of claim 1, wherein if the number of passersby is greater than the number of first authenticated persons obtained from the image data, the authentication result of the at least one first authenticated person who is determined to have been successfully authenticated is set to failed authentication.
3. a storage means for storing biometric information of each of a plurality of subjects to be authenticated using a database; 3. The server device according to claim 2, further comprising a second authentication means for receiving biometric information of a second person to be authenticated from an authentication terminal installed in a predetermined area, and authenticating the second person to be authenticated using the received biometric information of the second person to be authenticated and the biometric information stored in the database.
4. 4. The server device according to claim 3, wherein the first authentication means stores the successfully authenticated person, whose authentication result has been set to authentication failure, in the database as a person who has been allowed to tailgate.
5. The second authentication means The server device of claim 4, wherein a matching process is performed using the received biometric information of the second person to be authenticated and the biometric information stored in the database, and if the second person to be authenticated identified by the matching process is stored as the tailgating approved person, the authentication result of the second person to be authenticated stored as the tailgating approved person is set to authentication failure.
6. The second authentication means The server device according to claim 5, wherein when the authentication result of the second person to be authenticated who is stored as the tailgating-approved person is set to authentication failure, the server device notifies the authentication terminal that the second person to be authenticated is the tailgating-approved person.
7. 7. The server device according to claim 1, wherein the first authentication means transmits information about the first authenticated person who has been determined to have failed authentication in the authentication process to a terminal carried by a security guard.
8. 7. The server device according to claim 1, wherein the first authentication means notifies a terminal carried by a security guard of the presence of the accompanying person.
9. A calculation step of calculating the number of pedestrians passing through a predetermined point during a predetermined period of time; an extraction step of extracting biometric information of at least one first person to be authenticated from image data obtained by photographing a passerby passing through the predetermined point; a first authentication step of performing authentication processing of the at least one or more first authenticated persons using the extracted at least one or more pieces of biometric information, and determining, if the number of passersby is greater than the number of the first authenticated persons obtained from the image data, that there is a person accompanying the at least one or more first authenticated persons who has been determined to have been successfully authenticated, passing through the predetermined point; A method for controlling a server device, comprising:
10. The computer installed in the server device A calculation process for calculating the number of pedestrians passing through a predetermined point during a predetermined period of time; an extraction process of extracting biometric information of at least one first person to be authenticated from image data obtained by photographing a passerby passing through the predetermined point; a first authentication process that executes authentication processing of the at least one or more first authenticated persons using the extracted at least one or more pieces of biometric information, and when the number of passersby is greater than the number of the first authenticated persons obtained from the image data, determines that there is a companion passing through the predetermined point together with an authenticated person among the at least one or more first authenticated persons who has been determined to have been successfully authenticated; A program to execute.
Citation Information
Patent Citations
Intrusion monitoring system
JP2007233692A