Authentication system, authentication method, authentication device, and facility device
The authentication system addresses server load and network congestion by local storage and scheduled feature transmission, effectively reducing misrecognition of individuals with similar facial features.
Patent Information
- Application Number
- JP2024037675
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-11
- Publication Date
- 2025-09-25
AI Technical Summary
Conventional authentication systems face increased server load and communication bandwidth congestion due to biometric information matching, particularly for identical twins with similar facial features, leading to misrecognition issues.
An authentication system where biometric information is extracted and stored locally on an authentication device, with the server transmitting features only when scheduled, reducing the need for real-time network communication and server-side matching.
This approach reduces server load, prevents network congestion, and minimizes erroneous authentication of individuals with similar facial features, such as identical twins.
Smart Images

Figure 2025138526000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an authentication system, an authentication method, an authentication device, and a facility device for authenticating a user. [Background technology]
[0002] In recent years, authentication technologies using people's biometric information have been applied to various systems. For example, such authentication technologies are applied to entrance / exit authentication systems that authenticate people's entry / exit qualifications for buildings, personal authentication systems that authenticate individuals in banking transactions, and pass authentication systems that authenticate users' qualifications to pass through ticket gates at train stations. These authentication systems are equipped with a server that manages users' biometric information, and the server authenticates the users' qualifications to use the system.
[0003] Patent Document 1 describes a key management system that controls and manages the locking and unlocking of doors installed in various facilities such as homes and hotels. The key management system includes a key device (client) installed at the door of the facility and an information processing device (server) that can communicate with the key device via a network. The key device takes a picture of the visitor's face to generate a facial image and transmits the facial image to the information processing device. The visitor's facial image (registered facial image) is pre-registered in the memory of the information processing device, and the information processing device authenticates the visitor by comparing the facial image received from the key device with the registered facial image. The key device locks and unlocks the door based on the authentication result by the information processing device. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent Publication No. 2021-47766 Summary of the Invention [Problem to be solved by the invention]
[0005] As described above, in conventional authentication systems, the server collectively manages users' biometric information (registered biometric information) and performs biometric information matching processing on the server side. Therefore, the load required for the matching processing increases in proportion to the number of users (number of registered biometric information).
[0006] Furthermore, since biometric information is sent from the client to the server prior to the matching process on the server side, if the frequency of person authentication increases, the number of queries to the server increases, which increases the amount of communication and puts a strain on the communication bandwidth.
[0007] Furthermore, because identical twins have similar facial features, the registered facial images used in face recognition have a high degree of similarity. Therefore, when matching facial images, there is a risk of misrecognizing one twin as the other twin, or misrecognizing the other twin as one twin. Note that this problem is not limited to identical twins, but also occurs between people who have a high degree of similarity in facial features.
[0008] Therefore, an object of the present invention is to provide an authentication system, an authentication method, an authentication device, and a facility device that reduce the matching load on the server, prevent congestion on the communication bandwidth, and / or reduce erroneous authentication of people who have a high degree of commonality in facial features, such as identical twins. [Means for solving the problem]
[0009] In order to achieve the above object, the present invention provides an authentication system for authenticating a user who uses equipment, comprising: a server; and an authentication device capable of communicating with the server and arranged in correspondence with the equipment, wherein the server comprises: a memory unit for storing biometric information of the user; an extraction unit for extracting the biometric information of the user from the memory unit prior to using the equipment; and a transmission unit for transmitting the extracted biometric information, and the authentication device comprises: a receiving unit for receiving the extracted biometric information; an acquisition unit for acquiring the biometric information of the user when using the equipment; and a matching unit for matching the received biometric information with the acquired biometric information.
[0010] In the above authentication system, the authentication device includes a storage unit that stores the received biometric information until a usage time of the facility set for the user has elapsed.
[0011] In the above authentication system, the authentication device is characterized by having a control unit that invalidates the user's biometric information stored in the memory unit when the usage time of the equipment specified for the user has elapsed.
[0012] The above authentication system is characterized in that it includes a facility device that is installed in a facility having the equipment and is capable of communicating with the server, the server extracts the biometric information based on a request from the facility device and transmits the extracted biometric information to the facility device, and the facility device transmits the biometric information received from the server to the authentication device.
[0013] In the above authentication system, the facility device makes the request based on a schedule for the user to use the facility.
[0014] In order to achieve the above object, the present invention provides an authentication method for authenticating a user who uses equipment, comprising: a storage step in which a server stores biometric information of the user; an extraction step in which, prior to using the equipment, the biometric information of the user is extracted from the storage unit; and a transmission step in which the extracted biometric information is transmitted; and the method further comprises: a reception step in which an authentication device capable of communicating with the server and arranged corresponding to the equipment receives the extracted biometric information; an acquisition step in which the biometric information of the user is acquired when using the equipment; and a comparison step in which the received biometric information is compared with the acquired biometric information.
[0015] In order to achieve the above object, an authentication device of the present invention is characterized by being an authentication device used in the above authentication system.
[0016] In order to achieve the above object, a facility device of the present invention is characterized by being a facility device used in the above authentication system. [Effects of the Invention]
[0017] The present invention can reduce the matching load on the server, prevent congestion on the communication bandwidth, and / or reduce false recognition of people who have a high degree of commonality in facial features, such as identical twins. [Brief explanation of the drawings]
[0018] [Figure 1] A floor map of a facility in which a service providing system including an authentication system according to the first embodiment has been installed. [Figure 2] (a) Front view of the automatic doors installed at the entrances and exits of each area, (b) Front view of the doors installed in the completely private rooms [Figure 3] Block diagram of the above service provision system [Figure 4] (a) A table showing the correspondence between various facilities and facility IDs, (b) a customer table, (c) a schedule table, [Figure 5] A diagram showing the flow of information during the registration process [Figure 6] Diagram showing the flow of information in the reservation process [Figure 7] Authentication device hardware configuration diagram [Figure 8] Diagram showing the flow of information in the authentication system [Figure 9] Authentication control computer processing flow diagram [Figure 10] Authentication device processing flow diagram [Figure 11] FIG. 10 is a diagram showing the flow of information in an authentication system according to a second embodiment. [Figure 12] FIG. 10 is a diagram showing the flow of information in an authentication system according to a third embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0019] [First embodiment]
[0020] An authentication system according to a first embodiment of the present invention will be described below, taking as an example a service providing system introduced in a plurality of stores.
[0021] <Store Overview> The multiple stores where the service provision system has been introduced are affiliated stores that provide services such as manga cafes and internet cafes. Each store offers customers access to books, computer use, and entertainment services such as karaoke, darts, and / or billiards for a fee.
[0022] As shown in FIG. 1, the store is divided into a front area and a service area other than the front area. The front area is located near the store entrance and is used for checking in customers and settling fees. The service area is an area where various services are provided based on the customer's purpose of use, and an automatic door 432 shown in FIG. 2(a) is installed at the entrance / exit E1. The service area is further divided into multiple areas according to the type of service. Specifically, the service area is divided into a book area A, a fully private area B, a semi-private area C, and amusement area D, and an automatic door 432 shown in FIG. 2(a) is installed at the entrances E2, E3, E4, and E5 of each of areas A, B, C, and D.
[0023] The book area A has a plurality of shelves, each displaying books such as manga and magazines. The book area A functions as a facility that provides a book browsing service.
[0024] Fully private room area B is provided with multiple fully private rooms, each equipped with a table, chairs, and a computer connected to the Internet. Each fully private room is assigned unique identification information to identify it. As shown in FIG. 2(b), each fully private room has a door with an electric lock 433 at the entrance. The fully private rooms function as facilities that provide exclusive spaces.
[0025] Semi-private area C is equipped with multiple semi-private rooms, each equipped with a table, chairs, and a computer connected to the internet. Each semi-private room is assigned a unique identification code to identify it. Semi-private rooms differ from fully private rooms in that they do not have doors at the entrance and exit. These semi-private rooms function as facilities that provide a private space.
[0026] The game area D is equipped with game equipment such as darts machines and billiards equipment. Each piece of game equipment is assigned unique identification information to identify the game equipment. The game area functions as a facility that provides game equipment usage services.
[0027] As shown in FIG. 4(a), the store's facilities, i.e., book area A, private room area B, semi-private room area C, and play area D, as well as each private room, semi-private room, and play equipment, are assigned identification information (hereinafter referred to as "facility IDs") to identify each other. Specifically, symbols such as "S," "A," "B," "C," and "D" (hereinafter referred to as "area symbols") are assigned as facility IDs for the service area, book area A, private room area B, semi-private room area C, and play area D. Furthermore, the facility ID for each private room, semi-private room, and play equipment is assigned an identification number following the area symbol of the area in which the facility is located.
[0028] <Service provision system 1> As shown in FIG. 3, a service provision system 1 has been introduced into the store. The service provision system 1 is a system used when using the store, i.e., when providing services using facilities within the store. The service provision system 1 will be described below using as an example a scene in which a customer uses their own customer terminal 10 to apply for use of the store and then settles their bill using their own customer terminal 10. The service provision system 1 is a system capable of communicating with the customer terminal 10 via an internet communication line, and includes a web server 20, a customer management server 30, and store systems 40A, 40B, and 40C.
[0029] <Customer terminal 10> The customer terminal 10 is a smart device such as a smartphone or tablet terminal owned by a customer who uses a store. An application for using the service providing system 1 is installed on the customer terminal 10. The CPU of the customer terminal 10 executes the application to perform the registration process (FIG. 5), reservation process (FIG. 6), and payment process described below.
[0030] <webサーバ20> The web server 20 is an information processing device that executes processing in response to requests from the customer terminal 10. The web server 20 includes a network module, memory, and a CPU. The network module functions as a communication unit that communicates with the customer terminal 10, the store systems 40A, 40B, and 40C of each store, and the customer management server 30 via an Internet communication line. Programs are stored in the memory, and the CPU executes the programs to perform registration processing (FIG. 5), reservation processing (FIG. 6), and payment processing.
[0031] <Customer management server 30> The customer management server 30 is an information processing device that cooperates with the web server 20 and the store systems 40A, 40B, and 40C. It includes a network module, a CPU, memory, and a database 31. The network module functions as a communication unit that communicates with the web server 20 and the store systems 40A, 40B, and 40C of each store via an Internet communication line. The database 31 includes a customer table, as shown in FIG. 4(b). The customer table functions as a customer information storage unit that stores customer information. The customer information includes identification information for identifying the customer (hereinafter referred to as "customer ID") and personal information associated with the customer ID. The personal information includes basic information and biometric information. The basic information includes the customer's name, telephone number, address, date of birth, and other information. The biometric information is a feature extracted from a customer's facial image, such as information indicating features related to the shape of the facial contours, and the shape and position of the eyes, nose, and mouth. Note that the biometric information is not limited to facial feature information and may be the customer's facial image itself. The CPU executes the programs stored in the memory to perform the registration process (FIG. 5) and reservation process (FIG. 6) described below.
[0032] <Store Systems 40A, 40B, 40C> Store systems 40A, 40B, and 40C manage store sales and equipment usage schedules, and operate each piece of equipment based on those usage schedules. Because the store systems 40A, 40B, and 40C installed in each store are identical, only the store system 40A installed in store A will be described, and descriptions of the store systems 40B and 40C installed in stores B and C will be omitted. Store system 40A in store A includes a POS system 410 and a store-side authentication system 420.
[0033] The POS system 410 manages store sales and equipment usage schedules. It includes a reception device 411 that accepts customers who visit the store, a payment settlement device 412 that settles payments for customers who leave, and a store management computer 413. As described above, this embodiment focuses on facility usage based on a customer's request for use via the customer terminal 10. Therefore, the reception process by the reception device 411 and the payment settlement process by the payment settlement device 412 are omitted. The store management computer 413 is an information processing device that manages store sales and equipment usage schedules. It includes a network module, a CPU, memory, and a database 414 (see FIGS. 6 and 8). The network module functions as a communication unit that establishes communication with the web server 20 via an Internet communication line and with the store-side authentication system 420 via the network within store A. The memory stores programs related to the management described above. The database 414 includes a schedule table and a sales management table. As shown in Figure 4(c), the schedule table has a customer ID field, a usage date field, a usage time field, and a facility ID field. The customer ID field registers the customer ID of the customer who will use the facility. The usage date field registers the date of facility use. The usage time field registers the facility use time. The facility ID field registers the facility ID of the facility being used. The sales management table functions as a sales storage unit that stores sales for each customer, and registers usage fees, settlement times, etc. in association with customer IDs. The CPU executes the management program stored in memory to perform the reservation processing (Figure 6) described below.
[0034] The store-side authentication system 420 is a system that controls each piece of equipment based on the equipment usage schedule, and is equipped with an authentication control computer 421. The authentication control computer 421 is an information processing device that exchanges customer information with the customer management server 30 and the store management computer 413, and is equipped with a network module, memory, and a CPU. The network module functions as a communication unit that establishes communication with the customer management server 30 via an Internet communication line and with the store management computer 413 via an in-store network. A program is stored in the memory, and the CPU executes the program to perform the reservation process (FIG. 6) described below.
[0035] Next, the registration process (FIG. 5), reservation process (FIG. 6), and payment process performed by the service providing system 1 will be described.
[0036] <Registration process> The registration process is a process for registering customer information of a new customer, and as shown in Figure 5, is initiated by a registration request from the customer terminal 10 and is executed by the customer terminal 10, the web server 20, and the customer management server 30 working together. The registration request is information requesting new customer registration, and is sent from the customer terminal 10 to the web server 20.
[0037] When the web server 20 receives a registration request, it transmits an input form for inputting the customer's basic information and facial image to the requesting customer terminal 10. The customer terminal 10 transmits the basic information input by the customer and the facial image captured by the camera of the customer terminal 10 (hereinafter, information including the basic information and facial image will be referred to as "registration information") to the web server 20. The web server 20 transmits the registration information received from the customer terminal 10 to the customer management server 30.
[0038] Upon receiving the registration information, the customer management server 30 adds a record to the customer table and registers the newly issued customer ID and basic information in the record. The customer management server 30 also extracts features from the facial image and registers the extracted features in the record. The customer management server 30 transmits the registration result to the web server 20. The web server 20 transmits the registration result received from the customer management server 30 to the customer terminal 10.
[0039] <Reservation processing> 6, the reservation process is a process for reserving use of a facility, and is executed starting from a reservation request from a customer terminal 10 through cooperation between the customer terminal 10, web server 20, POS system 410 (store management computer 413), store-side authentication system 420 (authentication control computer 421), and customer management server 30. The reservation request is information requesting a reservation for use of a facility, and is sent from the customer terminal 10 to the web server 20.
[0040] When the web server 20 receives a reservation request, it transmits an input form for inputting reservation information to the requesting customer terminal 10. The input form includes a store list box (store selection section) for selecting a store to use from a store list, an equipment list box (equipment selection section) for selecting a facility to use from a facility list, a usage date list box (usage date selection section) for selecting a usage date, a usage time list box (usage time selection section) for selecting a usage time, and a facial image input box (facial image input section) for inputting a facial image of the customer. The customer terminal 10 transmits reservation information to the web server 20, including the store ID corresponding to the store selected by the customer, the facility type ID corresponding to the selected facility, the usage date, the usage time, and the input facial image in the input form. The web server 20 identifies the store management computer 413 of the store to which the reservation information should be sent based on the store ID included in the received reservation information, and transmits the reservation information (facility type ID, usage date, usage time, and facial image) to the identified store management computer 413.
[0041] When the store management computer 413 receives the reservation information, it sends the facial image included in the reservation information to the authentication control computer 421. The authentication control computer 421 sends the received facial image to the customer management server 30. The customer management server 30 extracts features from the received facial image, extracts customer information corresponding to the features from the customer table, and sends the extracted customer information to the authentication control computer 421. The authentication control computer 421 sends the received customer information to the store management computer 413. The store management computer 413 registers the received customer information (especially the customer ID) in a new record in the schedule table. The store management computer 413 also identifies equipment that is available on the date and time of use from the equipment corresponding to the equipment type ID, and registers the equipment ID, date of use, and time of use of the identified equipment in the new record. This registers a new reservation in the schedule table. The store management computer 413 sends the reservation registration result to the web server 20, and the web server 20 sends the result to the customer terminal 10.
[0042] As described above, the service providing system 1 according to this embodiment registers new customers and executes reservations for use. The customer terminal 10 and the web server 20 execute settlement processing for facility usage fees using a known payment method.
[0043] As shown in FIG. 3, in the service providing system 1 of this embodiment, the store-side authentication system 420 includes a plurality of authentication devices 422, and the store system 40A includes a door system 430.
[0044] <Authentication Device 422> The authentication device 422 authenticates customers entering each area and each private room. As shown in FIG. 2, it is installed on the wall surrounding the entrance to each area and on the wall surrounding the entrance to each private room. As shown in FIG. 7, the authentication device 422 includes a camera 4221, a touch panel display 4222, a network module 4223, a memory 4224, and a CPU 4225. The camera 4221 functions as an imaging unit that captures an image of a customer's face located in front of the authentication device 422 and generates a facial image. The touch panel display 4222 functions as a display unit that displays a predetermined screen based on a video signal input from the CPU 4225, and as an input unit that detects touch operations on the screen and inputs information related to the touch operations to the CPU 4225. The network module 4223 functions as a communication unit that communicates with the authentication control computer 421 and the control device 431 (described below) via the facility network. The memory 4224 stores an authentication program. The authentication program defines the equipment ID of the equipment on which each authentication device 422 is installed, according to the correspondence table in Fig. 4(a). The CPU 4225 executes the authentication program to perform the authentication process described below. The authentication device 422 is typically a smart device such as a tablet terminal, but is not limited to a smart device and may be any device having the above configuration.
[0045] <Door System 430> Door system 430 is a system that controls the opening and closing of doors within store A, and is equipped with multiple automatic doors 432 installed at entrances E1, E2, E3, E4, and E5 of each area, multiple electric locks 433 installed on the doors of each private room, and a control device 431 that controls the multiple automatic doors 432 and multiple electric locks 433.
[0046] The automatic door 432 (FIG. 2(a)) comprises a human presence sensor and an automatic door main body. The human presence sensor is installed on the wall inside the area and functions as a detection unit that detects customers exiting the area. When the human presence sensor detects a customer, it inputs a detection signal to the automatic door main body. The automatic door main body comprises a sliding door, a drive device that slides the sliding door, and a microcomputer that controls the drive device. The microcomputer is capable of communicating with the human presence sensor and the control device 431, and controls the drive device based on the detection signal input from the human presence sensor and the control information input from the control device 431. Here, the program of the microcomputer of each automatic door 432 stores a facility ID corresponding to the area in which each automatic door 432 is installed, according to the correspondence table in FIG. 4(a).
[0047] The electric lock 433 (Fig. 2(b)) has a key case built into the door. The key case has a deadbolt, a drive unit that drives the deadbolt to extend and retract, a microcomputer that controls the drive unit, and a thumb turn that is located on the interior side of the room and extends and retracts the deadbolt. The microcomputer can communicate with the control device 431 and controls the drive unit based on control information input from the control device 431. Here, the program of the microcomputer of each electric lock 433 stores an equipment ID corresponding to the equipment in which each electric lock 433 is installed, according to the correspondence table in Fig. 4(a).
[0048] The control device 431 is a device that controls the multiple automatic doors 432 and multiple electric locks 433 based on the authentication results from the authentication device 422, and includes a network module, memory, and a CPU. The network module is a module that functions as a communication unit that communicates with the multiple authentication devices 422. A control program is stored in the memory, and the CPU executes the control program to perform the processing described below.
[0049] <Authentication System 100>
[0050] In the service providing system 1 configured as described above, as shown in Fig. 8, an authentication system 100 is configured by a customer management server 30, an authentication control computer 421 (facility device), and multiple authentication devices 422. The authentication system 100 is a system that authenticates a customer's use authority for each facility within store A when the customer uses the facility. The authentication process performed by the authentication system 100 is as follows: the authentication control computer 421 receives customer features from the customer management server 30 based on a usage schedule, distributes the received customer features to multiple authentication devices 422, and each authentication device 422 authenticates the customer using the facility by comparing the received features with a captured facial image. Then, based on the authentication result of the authentication system 100, a door system 430 executes locking / unlocking processing.
[0051] Specifically, the store management computer 413 transmits the usage schedule to the authentication control computer 421. The timing of this transmission is not particularly limited, but typically occurs when the date changes or when a change occurs in the usage schedule for that day. When transmitting when the date changes, the CPU of the store management computer 413 extracts records for that day from the schedule table. The records are extracted by searching for the value of the usage date field. When transmitting when a change occurs in the usage schedule for that day, the record containing the change is extracted. In this way, the CPU of the store management computer 413 functions as a schedule extraction unit that extracts the usage schedule. Furthermore, the network module of the store management computer 413 functions as a communication unit that transmits the extracted usage schedule.
[0052] As shown in FIGS. 8 and 9, when the CPU of the authentication control computer 421 receives a usage schedule (s10: yes), it stores the received usage schedule in memory (s11). The CPU also extracts the customer ID from the usage schedule stored in memory (s12), generates a feature request including the extracted customer ID, and transmits the feature request to the customer management server 30 (s13). This series of processes is executed after the usage schedule is received and before the customer begins using the service. In this way, the network module of the authentication control computer 421 functions as a communication unit that receives the usage schedule and transmits the feature request. The memory of the authentication control computer 421 also functions as a storage unit that stores the usage schedule. The CPU of the authentication control computer 421 also functions as a request generation unit that extracts the customer ID and generates a feature request.
[0053] When the CPU of the customer management server 30 receives a feature request, it extracts the feature corresponding to the customer ID from the customer table, associates the extracted feature with the customer ID, and transmits the result to the authentication control computer 421 that sent the request. In this way, the CPU of the customer management server 30 functions as an extraction unit that extracts the feature. In addition, the network module of the customer management server 30 functions as a communication unit (transmission unit) that transmits the feature.
[0054] When the CPU of the authentication control computer 421 receives the feature and the customer ID (s20: yes), it adds the received feature to the usage schedule stored in the memory (storage unit) (s21). Specifically, the CPU searches for a record based on the received customer ID and adds the feature to the corresponding record.
[0055] The CPU of the authentication control computer 421 extracts the values of the start time field and the end time field included in the usage schedule and compares the current time with the start time and the end time. If the current time is the start time (s30: yes), the CPU extracts the facility ID and feature value corresponding to the start time from the usage schedule (s31) and distributes an authentication start command including the extracted facility ID and feature value to the multiple authentication devices 422 (s32). On the other hand, if the current time is the end time (s40: yes), the CPU extracts the facility ID and feature value corresponding to the end time from the usage schedule (s41) and distributes an authentication end command including the extracted facility ID and feature value to the multiple authentication devices 422 (s42). In this way, the CPU of the authentication control computer 421 functions as a command generation unit that generates an authentication start command or an authentication end command based on the usage schedule. The network module of the authentication control computer 421 also functions as a communication unit that distributes the authentication start command or the authentication end command.
[0056] As shown in FIGS. 8 and 10, when the CPU 4225 of the authentication device 422 receives an authentication start command (facility ID and feature amount) (s50: yes), it compares the received facility ID with its own facility ID (s51). The authentication device 422 installed in association with each area (automatic door 432 in each area) compares the area symbol of the received facility ID with its own facility ID. If the matching results in a match (s51: yes), the CPU 4225 stores the received feature amount in the memory 4224 as authentication information (s52). On the other hand, if the facility IDs do not match (s51: no), the CPU 4225 discards the received feature amount. The CPU 4225 of the authentication device 422 installed at the entrance of the service area does not compare the facility ID and instead stores all received feature amounts in the memory 4224. In this way, the memory 4224 of the authentication device 422 functions as a storage unit for storing received feature amounts.
[0057] When the CPU 4225 of the authentication device 422 receives an authentication end command (facility ID and feature amount) (s60: yes), it compares the received facility ID with its own facility ID (s61). Note that the authentication device 422 installed in association with each area (automatic door 432 in each area) compares the area symbol of the received facility ID with its own facility ID. If the comparison results in a match between the facility IDs (s61: yes), the CPU 4225 compares the received feature amount with the authentication feature amount stored in memory, and if they match, deletes the authentication feature amount (s62). On the other hand, if the facility IDs do not match or the feature amount does not match (s61: no), the above deletion process is not performed. In this way, the CPU 4225 of the authentication device 422 functions as a control unit that invalidates the feature amount stored in the memory 4224.
[0058] Here, when a customer performs a touch input on the authentication device 422 of the facility when using the facility (s70: yes), the CPU 4225 of the authentication device 422 activates the camera 4221 to capture an image of the customer and generate a facial image of the customer (s71). The CPU 4225 then analyzes the facial image acquired from the camera 4221 to detect features (s72). The CPU 4225 compares the detected features with features for authentication stored in memory (s73). If the comparison results in a match or similarity between the features, the CPU 4225 determines that authentication has been successful (s74: yes) and transmits an unlock command including the facility ID assigned to the authentication device 422 to the control device 431 (s75). On the other hand, if the features do not match or similarity, the CPU 4225 determines that authentication has failed (s74: no) and does not execute the transmission process. In this way, the CPU of the authentication device 422 functions as an acquisition unit that acquires feature amounts from a facial image, a detection unit that detects feature amounts from the facial image, and a matching unit that matches the feature amounts. Also, the network module of the authentication device 422 functions as a communication unit that transmits an unlock command.
[0059] When the CPU of the control device 431 receives an unlock command from the authentication device 422, it executes control processing. As shown in FIG. 8, the CPU of the control device 431 inputs the unlock command to multiple automatic doors 432 and multiple electric locks 433. The microcomputer of each automatic door 432 and the microcomputer of each electric lock 433 compares the facility ID included in the unlock command with its own facility ID. If the facility IDs match, the microcomputer of the automatic door 432 drives the drive device to open or close the sliding door. If the facility IDs match, the microcomputer of the electric lock 433 drives the drive device to extend or retract the deadbolt. On the other hand, if the facility IDs do not match, the microcomputer of the automatic door 432 and the microcomputer of the electric lock 433 discard the unlock command. In this way, the CPU of the control device 431 functions as a control unit that controls the automatic doors 432 and the electric locks 433.
[0060] As described above, in the authentication system 100 of this embodiment, customer features are delivered to the authentication devices 422 based on the usage schedule, and authentication processing is performed in each authentication device 422. Therefore, there is no need for the customer management server 30 to perform matching processing based on a facial image, which reduces the matching load on the server. Also, there is no need to transmit a facial image to the network each time authentication is performed, which prevents congestion on the network communication bandwidth. Furthermore, only the features of a specific customer delivered based on the usage schedule are stored in the authentication device 422 as information for authentication. In other words, the information (features) to be compared is limited, which reduces the matching load and also reduces erroneous authentication of people who have a high degree of commonality in facial features, such as identical twins.
[0061] Furthermore, in the authentication system 100 of this embodiment, the feature amount, which is information for authentication, is managed based on the usage schedule, so that usage outside of business hours can be appropriately restricted.
[0062] [Second embodiment]
[0063] 11, the authentication system 200 in the service providing system according to the second embodiment does not include the authentication control computer 421 of the first embodiment, but rather the functions of the authentication control computer 421 are provided in a store management computer 413, so that the store management computer 413 functions as a facility device, and multiple authentication devices 422 are provided so as to be able to communicate with the store management computer 413. Note that the rest of the hardware configuration is the same as in the first embodiment, so a description thereof will be omitted.
[0064] In this embodiment, the store management computer 413 transmits a feature request to the customer management server 30 based on the usage schedule stored in the database 414. The timing for transmitting the feature request is typically when the date changes or when a change occurs in the usage schedule for that day. When transmitting the feature request when the date changes, the CPU of the store management computer 413 extracts records for that day from the schedule table and includes the customer ID contained in the extracted record in the feature request before transmitting it. When transmitting the feature request when a change occurs in the usage schedule for that day, the CPU extracts the customer ID contained in the record that has changed and includes the extracted customer ID in the feature request before transmitting it.
[0065] When the CPU of the store management computer 413 receives a feature from the customer management server 30, it associates the received feature with the corresponding customer ID and registers it in the usage schedule. The CPU of the store management computer 413 then references the value in the start time field of the schedule table, extracts the feature and equipment ID from the record whose start time matches the current time, generates an authentication start command, and distributes this authentication start command to the multiple authentication devices 422. The CPU of the store management computer 413 also references the value in the end time field of the schedule table, extracts the feature and equipment ID from the record whose end time matches the current time, generates an authentication end command, and distributes this authentication end command to the multiple authentication devices 422.
[0066] The authentication device 422 of this embodiment stores feature amounts based on an authentication start command and deletes feature amounts based on an authentication end command, similar to the first embodiment. When a touch input is detected, the authentication device 422 executes authentication processing similar to the first embodiment.
[0067] [Third embodiment]
[0068] As shown in FIG. 12, the authentication system 300 in the service provision system according to the third embodiment is a further modification of the authentication system 200 of the second embodiment, and differs from the second embodiment in that a store management computer 413 distributes a usage schedule to multiple authentication devices 422, i.e., there are no facility terminals in this embodiment, and that the multiple authentication devices 422 are configured to be able to communicate with the customer management server 30 and receive features from the customer management server based on the usage schedule.
[0069] The store management computer 413 of this embodiment distributes the usage schedule to a plurality of authentication devices 422 at the same timing as in the first embodiment.
[0070] When the CPU 4225 of each authentication device 422 receives the usage schedule, it stores the received usage schedule in the memory 4224. At this time, it is desirable that the CPU 4225 compares its own facility ID with each facility ID included in the usage schedule, and stores only records in the usage schedule that have a matching facility ID.
[0071] The CPU of the authentication device 422 references the value of the start time field of the usage schedule stored in the memory 4224, extracts the customer ID from the record whose start time matches the current time, generates a feature request, and sends the feature request to the customer management server 30. When the CPU of the authentication device 422 receives the feature from the customer management server 30, the CPU stores the feature as authentication information in association with the customer ID. In this way, in this embodiment, the authentication device 422 itself acquires the feature at the start time and performs authentication based on the acquired feature.
[0072] Furthermore, the CPU of the authentication device 422 references the value of the end time field of the usage schedule stored in the memory 4224, and deletes the feature stored in the record whose end time matches the current time. In this way, in this embodiment, the authentication device 422 deletes the feature by itself when the end time arrives.
[0073] Although the embodiment of the present invention has been described above, the present invention is not limited to the above embodiment, and may be modified as follows.
[0074] <Variation 1> In the above embodiment, the explanation of the reception device 411, the settlement device 412, and the registration device 415 is omitted, but these devices 411, 412, and 415 may also be used.
[0075] The registration device 415 is a device for registering customer information of new customers, and is typically a tablet terminal on which a registration application is installed. The registration device 415 executes the same process as the customer terminal 10 shown in Fig. 5 to register the customer information of new customers.
[0076] The reception device 411 is a device that accepts applications for use from customers who visit the store, and is typically a tablet terminal or the like on which a reception application is installed. The reception device 411 executes the same process as the customer terminal 10 shown in Fig. 6 to register the customer for use. The reception device 411 may be operated by the customer or by store staff.
[0077] The settlement device 412 settles the fees of customers leaving the store. The settlement device 412 is equipped with a tablet terminal on which a settlement application is installed and a cashier capable of communicating with the tablet terminal. The tablet terminal captures the face of the customer leaving the store with its camera and sends the customer's facial image to the store management computer 413. The store management computer 413 then sends the facial image to the customer management server 30 via the authentication control computer 421. The customer management server 30 extracts the customer ID corresponding to the received facial image and sends the customer ID to the store management computer 413 via the authentication control computer 421. The store management computer 413 identifies the facility and usage time corresponding to the received customer ID and calculates the fee. The store management computer 413 then sends transaction information including the facility, usage time, and fee to the settlement device 412, which then performs well-known settlement processing based on the received transaction information.
[0078] <Variation 2> In the above embodiment, an electric lock is provided on the door of the private room, but the invention is not limited to an electric lock, and an electronic lock controlled by the control device 431 may be provided. Also, a retrofit type locking / unlocking device that locks and unlocks a thumb turn provided on an existing door may be provided, and the locking / unlocking device may be controlled by the control device 431.
[0079] <Variation 3> In the above embodiment, the authentication device 422 selects and rejects the distributed feature values based on its own equipment ID, but this is not limited to this embodiment, and the authentication control computer 421 may transmit feature values only to the authentication device 422 that corresponds to the customer's purpose of use.
[0080] <Variation 4> In the above embodiment, the feature values detected based on a facial image are used as the target of matching, but the facial image itself may also be used as the target of matching. In this embodiment, the customer management server 30 stores facial images in its database 31 instead of feature values and transmits the facial images in response to a request from the authentication control computer 421. The authentication control computer 421 distributes the received facial images to each authentication device 422. The authentication device 422 performs authentication by comparing the facial images with facial images generated by the camera 4221.
[0081] <Variation 5> In the above embodiment, facial features are used as biometric information, but the biometric information may be, for example, information such as fingerprints, irises, and voiceprints. A composite authentication method using multiple types of biometric information may also be used. The type of biometric information may also be changed depending on the equipment. Furthermore, authentication may also be performed using a password in addition to biometric information.
[0082] <Variation 6> In the above embodiment, the store system 40A may also include an alarm system. The alarm system may include, for example, multiple indicator lights installed on the entrance wall of each semi-private room and a control device that controls the multiple indicators. The control device is capable of communicating with multiple authentication devices 422, determines which indicator lights to turn on based on the authentication results and equipment IDs received from the authentication devices 422, and controls the lighting of the indicator lights. For example, if the control device receives a successful authentication result, it turns on the indicator light corresponding to the equipment ID in green, and if the control device receives a failed authentication result, it turns on the indicator light corresponding to the equipment ID in red. Note that the alarm device is not limited to indicator lights, and any alarm device that can notify users, such as a speaker that outputs audio, may be used.
[0083] <Variation 7> The facility in which the service providing system is introduced is not limited to a manga cafe or an internet cafe, but may also be, for example, a hotel. When the service providing system is introduced in a hotel, a plurality of electric locks 433 are provided on the door of each room, and an authentication device 422 is installed on the wall of the door. Furthermore, the authentication devices 422 may be installed in correspondence with various facilities in the hotel (laundry, lounge, pool, gym, restaurant), and the notification devices may be installed in correspondence with these facilities, and the authentication results by the authentication device 422 may be notified by the notification devices.
[0084] <Variation 8> Alternatively, the service providing system may be introduced into a super public bathhouse. When introduced into a super public bathhouse, automatic doors 432 are installed at the entrances to the men's bathhouse and the women's bathhouse, and authentication devices 422 are installed on the walls of the entrances. Furthermore, electric locks 433 or electronic locks are installed on each locker in each changing room, and authentication devices 422 are installed on the doors of each locker.
[0085] <Variation 9> Alternatively, the service providing system may be introduced into an amusement park. When introduced into an amusement park, an authentication device 422 is provided at the entrance of each attraction. An open / close gate device is also provided at the entrance of each attraction, and this gate device is controlled by a control device. When the authentication device 422 has successfully authenticated the customer, it sends an open command to the control device, and the control device opens the gate device corresponding to the open command. [Explanation of symbols]
[0086] 1. Service provision system 10 Customer terminal 20 web server 30 Customer Management Server (Server) 40 Store System 410 POS system 420 Store-side authentication system 421 Authentication Control Computer (Facility Equipment) 422 Authentication Device 430 Door System 100 Authentication System 200 Authentication System 300 Authentication System
Claims
1. An authentication system for authenticating a user who uses a facility, A server; an authentication device capable of communicating with the server and disposed in correspondence with the facility; Equipped with The server a storage unit that stores biometric information of the user; an extraction unit that extracts biometric information of a user who will use the facility from the storage unit prior to the use of the facility; a transmitting unit that transmits the extracted biometric information; Equipped with The authentication device a receiving unit that receives the extracted biometric information; an acquisition unit that acquires biometric information of the user when using the facility; a matching unit that matches the received biometric information with the acquired biometric information; An authentication system comprising:
2. The authentication system according to claim 1 , wherein the authentication device includes a storage unit that stores the received biometric information until a usage time of the facility set for the user has elapsed.
3. 3. The authentication system according to claim 2, wherein the authentication device includes a control unit that invalidates the biometric information of the user stored in the storage unit when a usage time of the equipment specified for the user has elapsed.
4. a facility device provided in the facility having the equipment and capable of communicating with the server; the server extracts the biometric information based on a request from the facility device and transmits the extracted biometric information to the facility device; The authentication system according to claim 1 , wherein the facility device transmits the biometric information received from the server to the authentication device.
5. The authentication system according to claim 4 , wherein the facility device makes the request based on a schedule for the user to use the facility.
6. An authentication method for authenticating a user who uses equipment, comprising: The server a storage step of storing the biometric information of the user; an extraction step of extracting biometric information of the user who will use the facility from the storage unit prior to the use of the facility; a transmitting step of transmitting the extracted biometric information; Including, an authentication device that can communicate with the server and is arranged corresponding to the facility, a receiving step of receiving the extracted biometric information; an acquisition step of acquiring biometric information of the user when using the facility; a matching step of matching the received biometric information with the acquired biometric information; authentication methods, including
7. An authentication device provided in the authentication system according to any one of claims 1 to 5.
8. A facility device provided in the authentication system according to claim 4 or 5.
Citation Information
Patent Citations
Key management method and key management system
JP2021047766A