Information processing device, server device, information processing system, information processing method, and program
The information processing device enhances user authentication by locally storing personal information from authentication media, addressing network delays and ensuring consistent service delivery.
Patent Information
- Application Number
- JP2024038184
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-12
- Publication Date
- 2025-09-26
AI Technical Summary
Delays in network communication during user authentication using authentication media, such as IC cards, can reduce user convenience, particularly in frequently used services like delivery locker services and entrance management.
An information processing device that acquires identification information from an authentication medium via near-field communication, requests a server to authenticate the user based on this information, and stores personal information locally for subsequent authentication without relying solely on network access.
Enables efficient and convenient user authentication by reducing the impact of network delays, ensuring seamless service provision.
Smart Images

Figure 2025139321000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing device, a server device, an information processing system, an information processing method, and a program. [Background technology]
[0002] With the realization of near-field wireless communication, also known as contactless communication, various services utilizing this communication technology, such as the settlement of public transportation fares and transactions using electronic money, have been proposed by applying this communication technology to portable communication terminals such as IC cards and smartphones. In recent years, various technologies have also been proposed that apply user authentication based on the results of reading an IC card or the like via near-field wireless communication when unlocking a door upon entry to an entrance of an apartment building or unlocking a delivery locker installed in an apartment building or the like when receiving a delivery. For example, Patent Document 1 discloses an example of a technology that uses the results of reading an IC card via near-field wireless communication when providing a delivery locker service installed in an apartment building or the like. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-568 Summary of the Invention [Problem to be solved by the invention]
[0004] On the other hand, when communicating with a server via a network in response to the results of reading an authentication medium such as an IC card during user authentication, delays may occur due to the state of the network, etc. Such delays can be a factor in reducing user convenience, and the impact of such reduced convenience tends to be more pronounced in services that are frequently used by users, such as delivery locker services and entrance management services.
[0005] In view of the above problems, the present invention aims to realize a more suitable mode of user authentication using an authentication medium when providing a service that uses the user's personal information. [Means for solving the problem]
[0006] The information processing device according to the present invention includes a first acquisition means for acquiring, in accordance with a result of reading an authentication medium via near field communication, first identification information uniquely assigned to the authentication medium and stored in the authentication medium, and second identification information assigned to a communication unit of the authentication medium that is involved in realizing the near field communication; a request means for, when personal information about an individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read, requesting a server device that manages personal information in association with the first identification information to execute a first authentication process related to authentication of the individual, based on the first identification information acquired from the authentication medium; and a request means for requesting, in accordance with a result of the first authentication process, a server device that manages personal information about an individual associated with the authentication medium, to execute a first authentication process related to authentication of the individual, based on the first identification information acquired from the authentication medium. a second acquisition means for acquiring the personal information associated with the first identification information acquired from the server device; a storage means for storing the personal information acquired from the server device, third identification information generated based on a portion of the first identification information, and the second identification information acquired from the authentication medium in the storage area in association with each other; and an authentication means for, when the personal information is stored in the storage area when the authentication medium is read, executing a second authentication process for authenticating the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on the portion of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area. [Effects of the Invention]
[0007] According to the present invention, it is possible to realize authentication of a user using an authentication medium in a more suitable manner when providing a service that uses personal information of the user. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 illustrates an example of a system configuration of an information processing system. [Figure 2] FIG. 2 illustrates an example of a hardware configuration of a management server. [Figure 3] FIG. 1 illustrates an example of a hardware configuration of an information processing device. [Figure 4] FIG. 2 is a functional block diagram illustrating an example of a functional configuration of the information processing system. [Figure 5] FIG. 10 is a diagram illustrating an overview of a process related to user authentication. [Figure 6] FIG. 10 is a diagram illustrating an overview of a process related to user authentication. [Figure 7] 10 is a flowchart illustrating an example of processing by an information processing device. DETAILED DESCRIPTION OF THE INVENTION
[0009] Preferred embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. In this specification and drawings, components having substantially the same functional configurations are designated by the same reference numerals, and redundant description will be omitted.
[0010] <Summary> An overview of an information processing system according to an embodiment of the present disclosure will be described below. 1 shows an example of the system configuration of an information processing system according to this embodiment. In the information processing system 1 according to this embodiment, a management server 200 manages various pieces of information about individual users (hereinafter also referred to as personal information) in association with a medium such as an IC card (hereinafter also referred to as authentication medium 300). Then, an information processing device 100 connected to the management server 200 via a network authenticates the user by reading the authentication medium 300, and if the authentication is successful, various services are provided to the user based on the personal information associated with the authentication medium 300. For convenience, in this embodiment, various explanations will be given focusing on the case where the information processing device 100 is realized as a so-called delivery locker installed in an apartment building or the like. That is, the information processing device 100, which is a delivery locker, authenticates the user based on the results of reading the authentication medium 300, and if the authentication is successful, identifies a room number (or building and room number if there are multiple buildings) which is information indicating a residence in the apartment building managed in association with the authentication medium 300, and unlocks the door of the locker in which a delivery item addressed to the room number is stored. For simplicity, in this embodiment, the explanation will be given assuming that a room number is identified as information indicating a residence in the apartment building, but it goes without saying that if the apartment building is made up of multiple buildings, the building and room number can also be identified.
[0011] 1, the information processing system 1 includes an information processing device 100 and a management server 200. The management server 200 and the information processing device 100 are connected via a network N1 so as to be able to send and receive data to and from each other. The type of network N1 is not particularly limited as long as it can connect the information processing device 100 and the management server 200 so that they can transmit and receive data to and from each other. As a specific example, the network N1 may be the Internet, a wide area network (WAN), a local area network (LAN), or the like. Furthermore, the network N1 may be a network conforming to a wireless communication standard such as LTE or 5G. Furthermore, the network N1 may be realized by a plurality of networks. In this case, the plurality of networks may include two or more networks of different types, and the type of transmission path or the communication method applied in some networks may be different from those in other networks. Furthermore, communication between the information processing device 100 and the management server 200 may be mediated by another communication device.
[0012] As described above, the management server 200 manages personal information of the user who is the owner of the authentication medium 300 in association with identification information (hereinafter also referred to as identification information IDi) uniquely assigned to the authentication medium 300. The authentication medium 300 is realized, for example, as an IC card or a portable communication terminal such as a smartphone. In the information processing system 1 according to this embodiment, from the viewpoint of security, it is assumed that the locations where the identification information IDi is allowed to be persistently stored are limited to within the management server 200 and within the authentication medium 300. Upon receiving a request from the information processing device 100, the management server 200 authenticates the target user based on the identification information IDi that is also notified, and if the authentication is successful, transmits the personal information associated with and managed by the identification information IDi to the information processing device 100. As a specific example, the management server 200 may notify the information processing device 100, which is a delivery locker, of the room number in the apartment building of the user that is managed in association with the identification information IDi. This enables the information processing device 100 to identify the locker that contains the delivery addressed to the room number notified by the management server 200, and unlock the door of the locker.
[0013] The information processing device 100 is configured to be able to acquire information held in the authentication medium 300 by reading the authentication medium 300 via short-range wireless communication (contactless communication) typified by NFC (Near Field Communication). In the following description, for convenience, the short-range wireless communication network formed between the information processing device 100 and the authentication medium 300 is also referred to as network N2. The information processing device 100 according to the present embodiment acquires identification information stored in the authentication medium 300 based on the result of reading the authentication medium 300, and authenticates the user who owns the authentication medium 300 based on the identification information. At this time, the information processing device 100 acquires identification information IDi uniquely assigned to the authentication medium 300 itself and identification information (hereinafter also referred to as identification information IDm) assigned to the communication unit of the authentication medium 300 related to short-range wireless communication, and uses these identification information for user authentication. Note that the identification information IDm assigned to the communication unit related to short-range wireless communication is used to identify the individual communication unit, but its uniqueness is not necessarily guaranteed. Therefore, in the following, various descriptions will be provided assuming that the uniqueness of the identification information IDm is not guaranteed, in order to more clearly explain the features of the technology disclosed herein. In other words, although the identification information IDm can be used to identify the individual communication unit in practice, there is a possibility that it may be duplicated between different individuals, although the probability is extremely low.
[0014] Furthermore, the information processing device 100 requests the management server 200 to authenticate the user based on the identification information IDi acquired from the authentication medium 300, and acquires personal information of the user in response. This enables the information processing device 100 to provide services to the user based on the acquired personal information. Furthermore, the information processing device 100 may store in a local environment the personal information acquired from the management server 200 in association with the identification information acquired from the authentication medium 300. This allows the information processing device 100 to use the personal information previously acquired from the management server 200 to provide services based on local authentication, without having to access the management server 200 again for authentication. As described above, in this embodiment, the storage of the identification information IDi in the local environment of the information processing device 100 is restricted. Furthermore, the uniqueness of the identification information IDm is not guaranteed. Therefore, under these assumptions, hereinafter, a mechanism that can ensure security within a practical range in a situation where the information processing device 100 manages personal information of a user in a local environment and uses the personal information by authenticating the user will be described in more detail.
[0015] <Hardware configuration> An example of the hardware configuration of various information processing devices (for example, the management server 200 and the information processing device 100) that constitute the information processing system 1 according to this embodiment shown in FIG. 1 will be described below with reference to FIGS.
[0016] First, an example of the hardware configuration of an information processing device 900 applicable as the management server 200 will be described with reference to Fig. 2. The information processing device 900 includes a CPU (Central Processing Unit) 901, a communication interface device 902, a HD (Hard Disk) 903, a ROM (Read Only Memory) 908, and a RAM (Random Access Memory) 909. The information processing device 900 may also include at least one of an input device 904 and an output device 905. The information processing device 900 may also include a recording medium drive device 906.
[0017] The CPU 901 controls various operations of the information processing device 900. The ROM 908 stores control programs, boot programs, and the like that can be executed by the CPU 901. The RAM 909 is the main storage memory of the CPU 901 and is used as a work area or a temporary storage area for expanding various programs. The HD 903 stores various data and programs. The CPU 901 reads out a program stored in the HD 903, expands it in the RAM 909, and executes the program, thereby realizing the functions described below with reference to Fig. 5 and the processes described below with reference to Figs. 6 to 9. Instead of the HD 903 or together with the HD 903, a storage device other than the HD 903, such as a nonvolatile memory typified by an SSD (Solid State Drive), may be used.
[0018] The communication interface device 902 is an interface that connects the information processing device 900 to various networks such as the network N1. The device used as the communication interface device 902 may be changed as appropriate depending on the type of the network N1 and the communication method applied. As a specific example, if the network N1 is a wired network, the communication interface device 902 may include a connector for connecting a cable used as a transmission path, a device related to receiving data via the cable, and a device related to transmitting data via the cable. As another example, if the network N1 is a wireless network, the communication interface device 902 may include various devices for achieving wireless communication, such as an antenna device and an RF circuit.
[0019] The input device 904 is a device for receiving instructions from an administrator of the information processing device 900. The input device 904 may be realized by, for example, an operation device such as a mouse, a keyboard, a touch panel, a button, a switch, a lever, or a pedal. Furthermore, the device used as the input device 904 may be changed as appropriate depending on the method by which the user gives instructions to the information processing device 900 (in other words, the method of operating the information processing device 900). For example, when the information processing device 900 receives instructions from the user by voice input, the input device 904 may be realized by a sound collection device that receives voice input, such as a microphone.
[0020] The output device 905 is a device for presenting various types of information to the user of the information processing device 900. The output device 905 may be realized by a display device, such as a display, that presents information to the user by displaying various types of display information, screens, etc. Furthermore, the device used as the output device 905 may be changed as appropriate depending on the method of presenting information to the user. For example, when information is presented to the user by sound such as voice or electronic sound, the output device 905 may be realized by an audio output device that outputs sound, such as a speaker.
[0021] The program for the information processing device 900 is provided to the information processing device 900 by a recording medium 907 such as a CD-ROM, a DVD-ROM, or an IC card memory, or is downloaded via a network, etc. When the program for the information processing device 900 is provided by the recording medium 907, the recording medium 907 is set in the recording medium drive device 906, and the program recorded on the recording medium 907 is installed in the HD 903 via the recording medium drive device 906.
[0022] Next, an example of a hardware configuration of an information processing device 950 applicable as the information processing device 100 will be described with reference to Fig. 3. The information processing device 950 includes a CPU 951, a ROM 952, a RAM 953, a HD 954, a communication interface device 955, and a reading interface device 956. The information processing device 950 may also include at least one of an input device 957 and an output device 958. Note that the CPU 951, ROM 952, RAM 953, HD 954, input device 957, and output device 958 are substantially similar to the CPU 901, ROM 908, RAM 909, HD 903, input device 904, and output device 905 shown in Fig. 3, and therefore detailed description thereof will be omitted.
[0023] The communication interface device 955 is an interface that connects the information processing device 950 to various networks such as the network N2. The device used as the communication interface device 955 may be changed as appropriate depending on the type of the network N2 and the communication method applied. This is substantially the same as the device used as the communication interface device 902, which may be changed as appropriate depending on the type of the network N1 and the communication method applied, and therefore a detailed description thereof will be omitted.
[0024] The reading interface device 956 is an interface for the information processing device 950 to read the authentication medium 300 and thereby obtain information (such as information used for authentication) stored in the authentication medium 300. The device used as the reading interface device 956 may be changed as appropriate depending on the reading method of the authentication medium 300. As a specific example, when so-called non-contact communication is applied as the reading method of the authentication medium 300, the reading interface device 956 may include a device for realizing the non-contact communication, such as an antenna device or an RF circuit.
[0025] 2 and 3 are merely examples and do not necessarily limit the hardware configuration of the information processing device that constitutes the information processing system 1 according to this embodiment. As a specific example, the information processing device 900 may not include some components such as the input device 904 and the output device 905. As another example, components according to the functions realized by the information processing device 900 may be added as appropriate. The same applies to the information processing device 950.
[0026] An example of the hardware configuration of the various information processing devices that make up the information processing system 1 according to this embodiment shown in FIG. 1 has been described above with reference to FIGS.
[0027] <Functional configuration> 4, an example of the functional configuration of the information processing system 1 according to this embodiment will be described, focusing particularly on the parts related to user authentication according to the reading result of the authentication medium 300, the information processing device 100, and the management server 200. In the example shown in FIG. 4, it is assumed that contactless communication is applied as a method for the information processing device 100 to read the authentication medium 300.
[0028] First, a description will be given of an example of the configuration of the authentication medium 300. The authentication medium 300 includes a non-contact communication unit 310, a transmission processing unit 320, and a storage unit 330.
[0029] When the non-contact communication unit 310 detects an information processing device 100 located nearby (in other words, an information processing device 100 located within a communication range), it establishes a wireless communication path (network N2) with the information processing device 100. This allows the information processing device 100 to read the authentication medium 300, and the authentication medium 300 becomes able to send and receive information to and from the information processing device 100 via the wireless communication path. Note that the non-contact communication unit 310 is assigned identification information IDm for identifying each device, and the identification information IDm is stored in a predetermined storage area of the non-contact communication unit 310.
[0030] The storage unit 330 schematically shows a storage area for the authentication medium 300 to hold various pieces of information. As described above, the authentication medium 300 is assigned identification information IDi for uniquely identifying the authentication medium 300 itself. The storage unit 330 stores this identification information IDi. The storage unit 330 may also store other data. For example, if the authentication medium 300 is also used as a transaction medium for transactions using electronic value such as so-called electronic money or for settling fares for public transportation, data on the electronic value may be stored in the storage unit 330.
[0031] When communication with the information processing device 100 is established, the transmission processing unit 320 transmits various pieces of information stored in the authentication medium 300 to the information processing device 100 via the communication in response to a request from the information processing device 100. Specifically, the transmission processing unit 320 transmits the identification information IDi stored in the storage unit 330 and the identification information IDm stored in the storage area of the non-contact communication unit 310 to the information processing device 100. This enables the information processing device 100 to authenticate the user who is the holder of the authentication medium 300, based on the identification information IDi and identification information IDm transmitted from the authentication medium 300 (transmission processing unit 320). The identification information IDi corresponds to an example of first identification information uniquely assigned to the authentication medium, and the identification information IDm corresponds to an example of second identification information assigned to a communication unit for realizing close proximity wireless communication (contactless communication) possessed by the authentication medium.
[0032] Note that the configuration of the authentication medium 300 described above is merely an example and does not limit the functional configuration of the authentication medium 300 applied to the information processing system 1 according to this embodiment. As a specific example, as described above, an IC card or a communication terminal applied as the authentication medium 300 may also serve as a transaction medium applied to transactions using electronic value or the settlement of fares for public transportation. In such cases, the authentication medium 300 may be provided with components related to the realization of electronic transactions and components related to the settlement of fares. In this way, separate components may be added to the configuration of the authentication medium 300 depending on the functions realized by the authentication medium 300.
[0033] Next, a description will be given of an example of the configuration of the management server 200. The management server 200 includes a communication unit 210, an authentication processing unit 220, a conversion processing unit 230, and a storage unit 240.
[0034] The communication unit 210 is a communication interface that enables the management server 200 to communicate with external devices such as the information processing device 100 via a predetermined network N1. The communication unit 210 can be realized by, for example, a communication interface device 902. In the following description, when each component of the management server 200 transmits and receives information to and from an external device via the network N1, it is assumed that the transmission and reception of the information is performed via the communication unit 210, even if no special explanation is provided.
[0035] The storage unit 240 schematically shows a storage area for storing various types of information, and stores, for example, information that is to be managed by the management server 200. As a specific example, the storage unit 240 stores identification information IDi assigned to each authentication medium 300 in association with personal information of an individual with whom the authentication medium 300 is associated (for example, a user who is the owner of the authentication medium 300).
[0036] The authentication processing unit 220 receives an authentication request from an external device such as the information processing device 100, and authenticates the user by comparing the identification information IDi sent together with the identification information IDi stored in the storage unit 240. If the authentication is successful, the authentication processing unit 220 transmits to the requesting information processing device 100 personal information associated with the target identification information IDi and managed in the storage unit 240, and other identification information (hereinafter also referred to as mask IDi) generated by the conversion processing unit 230 (described later) based on part of the information in the identification information IDi. Details of the mask IDi will be described separately below, along with the processing of the conversion processing unit 230.
[0037] The conversion processing unit 230 generates other identification information different from the identification information IDi based on a portion of the information of the identification information IDi. This other identification information generated by the conversion processing unit 230 corresponds to the mask IDi. The mask IDi can be generated, for example, by masking information other than the target portion of information from a series of information constituting the identification information IDi. As another example, the mask IDi may be generated by extracting target portions of information from the series of information constituting the identification information IDi and then combining the target portions of information according to a predetermined rule. Of course, the above is merely an example, and the method of generating the mask IDi is not particularly limited as long as the target portion of information from the series of information constituting the identification information IDi is used based on predetermined conditions. The mask IDi corresponds to an example of third identification information generated based on part of the information of the first identification information (identification information IDi).
[0038] Next, a description will be given of an example of the configuration of the information processing device 100. The information processing device 100 includes a non-contact communication unit 110, a communication unit 120, an authentication processing unit 140, a conversion processing unit 130, a service providing unit 150, and a storage unit 160.
[0039] When the non-contact communication unit 110 detects an authentication medium 300 located nearby (in other words, an authentication medium 300 located within a communication range), it establishes a wireless communication path (network N2) with the authentication medium 300. This enables the information processing device 100 to read the authentication medium 300 and obtain information held in the authentication medium 300 (e.g., identification information IDi and identification information IDm). The non-contact communication unit 110 can be realized by, for example, a reading interface device 956. Note that the configuration of the non-contact communication unit 110 may be changed as appropriate depending on the method for reading the authentication medium 300.
[0040] The communication unit 120 is a communication interface that enables the information processing device 100 to communicate with external devices such as the management server 200 via a predetermined network N1. The communication unit 120 can be realized by, for example, a communication interface device 955. In the following description, when each component of the information processing device 100 transmits and receives information to and from an external device via the network N1, it is assumed that the transmission and reception of the information is performed via the communication unit 120, even if no special explanation is provided.
[0041] The storage unit 160 schematically shows a storage area for storing various data. The storage unit 160 stores, for example, information (e.g., identification information IDm) acquired from the authentication medium 300 in accordance with the result of reading the authentication medium 300, and information (e.g., personal information, mask IDi) acquired from the management server by the authentication processing unit 140 (described later) based on the authentication result. Note that, as will be described in detail later, if personal information of the user to be authenticated has already been stored in the storage unit 160, the identification information IDm and mask IDi stored in the storage unit 160 are used to authenticate the user.
[0042] The conversion processing unit 130 generates a mask IDi from the identification information IDi acquired from the authentication medium 300 in accordance with the reading result of the authentication medium 300. Note that the logic by which the conversion processing unit 130 generates the mask IDi from the identification information IDi is the same as the logic by which the conversion processing unit 230 of the management server 200 generates the mask IDi from the identification information IDi. In addition, the mask IDi generated by the conversion processing unit 130 is used for user authentication by the authentication processing unit 140, which will be described later.
[0043] The authentication processing unit 140 authenticates the user associated with the authentication medium 300 based on the identification information IDi and identification information IDm acquired from the authentication medium 300 in accordance with the reading result of the authentication medium 300. At this time, the authentication processing unit 140 selectively switches the process related to user authentication depending on whether or not information related to the read authentication medium 300, in particular personal information acquired from the management server 200 by a process described in detail below, is stored in the storage unit 160. Therefore, with reference to Figures 5 and 6, the process related to user authentication by the authentication processing unit 140 will be described in detail for two cases: when the personal information of the target user is not stored in the storage unit 160 and when the personal information is stored.
[0044] First, referring to Fig. 5, an example of processing related to authentication of a user by the authentication processing unit 140 when the personal information of the target user is not stored in the storage unit 160 will be described. The case shown in Fig. 5 may correspond to a situation in which the user causes the information processing device 100 to read the authentication medium 300 for the first time in order to receive a predetermined service. In this case, the authentication processing unit 140 accesses the management server 200 via the network N1 and authenticates the user with the management server 200 based on the identification information IDi acquired from the authentication medium 300. Then, if the authentication processing unit 140 is successful in authenticating the user, it acquires the personal information of the user (personal information managed in association with the identification information IDi used for authentication) from the management server 200.
[0045] First, Fig. 5(a) will be described. Fig. 5(a) shows an example of a processing flow when the authentication processing unit 140 of the information processing device 100 requests the management server 200 to authenticate a user in accordance with the reading result of the authentication medium 300. When the authentication medium 300 is read, the authentication processing unit 140 of the information processing device 100 acquires the identification information IDi and the identification information IDm from the authentication medium 300. Next, the authentication processing unit 140 checks whether information related to the read authentication medium 300 (for example, personal information of the user associated with the authentication medium 300) is stored in the storage unit 160. Note that when the authentication medium 300 is read for the first time, no information related to the authentication medium 300 is stored in the storage unit 160. In this case, the authentication processing unit 140 stores the identification information IDm acquired from the authentication medium 300 in the storage unit 160 as information related to the authentication medium 300. Furthermore, the authentication processing unit 140 accesses the management server 200 via the network N1, transmits the identification information IDi acquired from the authentication medium 300 to the management server 200, and then requests authentication of the user. Upon receiving this request, the authentication processing unit 220 of the management server 200 compares the identification information IDi transmitted from the information processing device 100 with the identification information IDi stored in the storage unit 240 of the management server 200, thereby authenticating the target user.
[0046] Next, Fig. 5(b) will be described. Fig. 5(b) shows an example of the flow of processing when user authentication in the management server 200 is successful. The authentication processing unit 220 of the management server 200 reads out personal information associated with the identification information IDi that is the target of the authentication process from the storage unit 240. For example, when the information processing device 100 provides a delivery locker service, a room number that indicates the residence of the target user in an apartment building is read out as the personal information. The authentication processing unit 220 also causes the conversion processing unit 230 to generate a mask IDi based on the identification information IDi that is the target of the authentication process. The authentication processing unit 220 then transmits the personal information read out from the storage unit 240 and the mask IDi generated by the conversion processing unit 230 to the information processing device 100 that is the source of the user authentication request. Note that the timing of generating the mask IDi by the authentication processing unit 220 is not particularly limited as long as the mask IDi can be transmitted in response to the user authentication request from the information processing device 100. For example, the authentication processing unit 220 may cause the conversion processing unit 230 to generate the mask IDi in advance and then store the mask IDi in the storage unit 240 in association with the identification information IDi that generated the mask IDi. In this case, the authentication processing unit 220 may transmit the mask IDi stored in the storage unit 240 to the information processing device 100 in response to a request for user authentication from the information processing device 100. When the authentication processing unit 140 of the information processing device 100 acquires personal information and a mask IDi from the management server 200 in response to a user authentication request, the authentication processing unit 140 associates the personal information and the mask IDi with the identification information IDm previously stored in the storage unit 160 and stores the personal information and the mask IDi in the storage unit 160. As a result, the identification information IDm acquired from the authentication medium 300 and the personal information and the mask IDi acquired from the management server 200 are stored in the storage unit 160 as information related to the authentication medium 300 read in FIG. 5(a).
[0047] Next, referring to Fig. 6, an example of processing related to authentication of a target user by the authentication processing unit 140 in the case where personal information of the target user is already stored in the storage unit 160 will be described. Note that the case shown in Fig. 6 may correspond to a situation where the user has received a predetermined service in the past and has caused the information processing device 100 to read the authentication medium 300 in order to receive the service again.
[0048] When the identification information IDi and the identification information IDm are read from the authentication medium 300, the authentication processing unit 140 of the information processing device 100 acquires the identification information IDi and the identification information IDm from the authentication medium 300. This process is the same as the example shown in FIG. 5. Next, the authentication processing unit 140 checks whether or not information related to the read authentication medium 300 is stored in the storage unit 160. For example, when the authentication processing unit 140 confirms that the identification information IDm acquired from the authentication medium 300 is stored in the storage unit 160 and that personal information is associated with the identification information IDm, it may determine that information related to the authentication medium 300 is stored in the storage unit 160. Next, the authentication processing unit 140 causes the conversion processing unit 130 to generate a mask IDi based on the identification information IDi acquired from the authentication medium 300. Then, the authentication processing unit 140 authenticates the user associated with the authentication medium 300 by comparing a set of the identification information IDm acquired from the authentication medium 300 and the mask IDi generated by the conversion processing unit 130 with a set of the identification information IDm and the mask IDi associated with each other and stored in the storage unit 160. That is, in this case, the authentication processing unit 140 authenticates the user based on information held in the local environment without accessing the management server 200, and therefore, it is possible to complete authentication without being affected by delays associated with congestion of the network N1, for example. The above processing by the authentication processing unit 140 is merely an example, and the processing steps up to that point are not particularly limited as long as it is possible to substantially confirm whether information related to the read authentication medium 300 is stored in the storage unit 160 and to perform authentication based on a comparison of a pair of the identification information IDm and the mask IDi. For example, the authentication processing unit 140 may generate a mask IDi from the identification information IDi, and then, based on a pair of the mask IDi and the identification information IDm acquired from the authentication medium 300, confirm whether information related to the read authentication medium 300 is stored in the storage unit 160. As another example, the authentication processing unit 140 may confirm whether information related to the read authentication medium 300 is stored in the storage unit 160 based on the mask IDi generated from the identification information IDi. As described above, although the identification information IDm is used to identify the communication unit related to short-range wireless communication (contactless communication), its uniqueness is not guaranteed. Furthermore, since the mask IDi is generated from a portion of the information in the identification information IDi, its uniqueness is not likely to be guaranteed. Although the uniqueness of each of the identification information IDm and the mask IDi is not guaranteed, combining these information for authentication can significantly reduce the possibility of duplication between different users, thereby enabling individual users to be identified within an acceptable margin of error.
[0049] 4 will now be referred to again. When the authentication processing unit 140 has successfully authenticated the user, the service providing unit 150 executes processing related to the provision of the service based on the personal information acquired from the management server 200 or the personal information of the user stored in the storage unit 160. For example, when the information processing device 100 provides a delivery locker service, the service providing unit 150 unlocks the door of the locker in which a delivery item addressed to a room number is stored, based on the room number, which is the personal information of the target user.
[0050] The above-described configuration is merely an example and does not necessarily limit the functional configuration of the information processing system according to this embodiment. For example, in the example described above, when the personal information of the target user is not stored in the storage unit 160 as shown in Fig. 5, the authentication processing unit 140 acquires the mask IDi from the management server 200. On the other hand, in this case, the authentication processing unit 140 may cause the conversion processing unit 130 in the information processing device 100 to generate the mask IDi and store the mask IDi in the storage unit 160, similar to the case when the personal information of the target user is stored in the storage unit 160 as shown in Fig. 6. In this case, the conversion processing unit 230 may not be provided on the management server 200 side. Furthermore, the components corresponding to the management server 200 may be realized by a plurality of devices working together. As a specific example, the functions of some of the components of the management server 200 may be realized by an external device communicably connected to the management server 200. As another example, the processing load of at least some of the components of the management server 200 may be distributed to a plurality of devices. Furthermore, the management server 200 may be realized as a so-called network service, such as a cloud service.
[0051] Above, with reference to Figures 4, 5, and 6, an example of the functional configuration of the information processing system 1 according to this embodiment has been described, focusing particularly on the parts related to authenticating a user according to the reading results of the authentication medium 300, the information processing device 100, and the management server 200.
[0052] <Processing> An example of the processing of the information processing system 1 according to this embodiment will be described with reference to FIG. 7, focusing particularly on the processing of the information processing device 100 relating to user authentication according to the reading result of the authentication medium 300.
[0053] In S101, when the non-contact communication unit 110 detects an authentication medium 300 located nearby, it establishes a wireless communication path (network N2) with the authentication medium 300. This allows the information processing device 100 to read the authentication medium 300. Depending on the reading result of the authentication medium 300, the authentication processing unit 140 acquires the identification information held in the authentication medium 300, i.e., the identification information IDi and the identification information IDm.
[0054] In S102, the authentication processing unit 140 determines whether information related to the authentication medium 300 read in S101, specifically, personal information of the user associated with the authentication medium 300, is stored in the memory unit 160. If the authentication processing unit 140 determines in S102 that the personal information of the user associated with the authentication medium 300 is not stored in the storage unit 160, the processing proceeds to S103. On the other hand, if the authentication processing unit 140 determines in S102 that the personal information of the user associated with the authentication medium 300 is stored in the storage unit 160, the processing proceeds to S105.
[0055] First, an example of the processing of S103 and S104 in the case where the personal information of the user associated with the authentication medium 300 is not stored in the storage unit 160 will be described. In S103, the authentication processing unit 140 stores the identification information IDm acquired from the authentication medium 300 in the storage unit 160 as information related to the authentication medium 300. The authentication processing unit 140 also accesses the management server 200 via the network N1, transmits the identification information IDi acquired from the authentication medium 300 to the management server 200, and requests authentication of the user. In response to this request, the authentication processing unit 220 of the management server 200 authenticates the target user by comparing the identification information IDi transmitted from the information processing device 100 with the identification information IDi stored in the storage unit 240 of the management server 200. It is assumed here that the authentication of the target user is successful. In S104, the authentication processing unit 140 acquires, as a response to the user authentication request from the management server 200, personal information of the user associated with the authentication medium 300 read in S101 and a mask IDi generated from the identification information IDi that was the target of the authentication process. The authentication processing unit 140 associates the personal information and mask IDi acquired from the management server 200 with the identification information IDm stored in the storage unit 160 in S103, and stores them in the storage unit 160. As a result, the identification information IDm acquired from the authentication medium 300 and the personal information and mask IDi acquired from the management server 200 are stored in the storage unit 160 as the authentication medium 300 read in S101. In this case, as described above, the authentication process based on the identification information IDi in the management server 200 authenticates the user associated with the authentication medium 300 read in S101. The authentication process based on the identification information IDi executed by the management server 200 in S103 corresponds to an example of a first authentication process.
[0056] Next, an example of the processing in S105 and S106 in the case where the personal information of the user associated with the authentication medium 300 has already been stored in the storage unit 160 will be described. In S105, the authentication processing unit 140 causes the conversion processing unit 130 to generate a mask IDi based on the identification information IDi acquired from the authentication medium 300. In S106, the authentication processing unit 140 authenticates the user associated with the authentication medium 300 by comparing a set of the identification information IDm acquired from the authentication medium 300 and the mask IDi generated by the conversion processing unit 130 with a set of the identification information IDm and the mask IDi associated with each other and stored in the storage unit 160. It is assumed here that the authentication of the target user has been successful. The authentication processing unit 140 reads out, from the storage unit 160, personal information associated with the identification information IDm and the mask IDi that are the targets of the authentication process. In this case, as described above, the management server 200 is not accessed, and the user is authenticated based on the information stored in the local environment. Therefore, it is possible to complete the authentication without being affected by delays due to congestion of the network N1, for example. The authentication process based on the identification information IDm and the mask IDi executed by the information processing device 100 (authentication processing unit 140) in S106 corresponds to an example of a second authentication process.
[0057] In S107, the service providing unit 150 executes processing related to the provision of a service in accordance with the personal information of the user associated with the authentication medium 300 read in S101. Note that, with regard to the personal information in question, if information has been acquired from the management server 200, that information may be used, or if information has already been stored in the storage unit 160, that information read from the storage unit 160 may be used.
[0058] An example of the processing of the information processing system 1 according to this embodiment has been described above with reference to FIG. 7, focusing particularly on the processing of the information processing device 100 related to user authentication according to the reading result of the authentication medium 300.
[0059] <Conclusion> As described above, the information processing system according to this embodiment is configured by connecting an information processing device configured to be able to read an authentication medium via close proximity wireless communication and a server device via a network. The server device manages first identification information uniquely assigned to the authentication medium and personal information about the individual associated with the authentication medium in association with each other. Furthermore, upon receiving a request from the information processing device based on the result of reading the authentication medium in the information processing device, the server device executes a first authentication process related to authentication of the individual to be managed based on the first identification information transmitted from the information processing device. Based on the result of the first authentication process, the server device transmits to the information processing device the personal information managed in association with the first identification information that was the subject of the first authentication process. The information processing device acquires, in accordance with the result of reading the authentication medium, first identification information stored in the authentication medium and second identification information assigned to a communication unit of the authentication medium that realizes close proximity wireless communication. Furthermore, if personal information about an individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read, the information processing device requests the server device to execute a first authentication process based on the first identification information acquired from the authentication medium. Then, based on the result of the first authentication process, the information processing device acquires, from the server device, personal information associated with the first identification information that was the target of the first authentication process. The information processing device then associates the personal information acquired from the server device, third identification information generated based on a portion of the first identification information, and the second identification information acquired from the authentication medium, and stores them in a storage area. In addition, when personal information is stored in the memory area when the authentication medium is read, the information processing device performs a second authentication process related to individual authentication based on a pair of second identification information obtained from the authentication medium and third identification information generated based on part of the information of the first identification information obtained from the authentication medium, and the pair of second identification information and third identification information stored in the memory area.
[0060] With the above-described configuration, the information processing system according to this embodiment allows for personal authentication without communication with the management server when the authentication medium is read again, if the authentication medium has previously been read and personal information has been acquired. This characteristic is expected to reduce the frequency of communication over the network, particularly when providing services that are used repeatedly. Furthermore, when user authentication is performed without communication over the network, such as when using a service for the second or subsequent time, the system is not affected by delays associated with network congestion, and is therefore expected to improve user convenience when using the service. As described above, when user authentication is performed without communication via a network, the uniqueness of the identification information IDm and mask IDi used for the authentication is not necessarily guaranteed. However, according to the information processing system of this embodiment, by combining these pieces of identification information and using them for user authentication, it is possible to extremely reduce the possibility of duplication, and it is possible to identify individual users within an allowable error range.
[0061] It should be noted that the above-described embodiment is merely an example and does not necessarily limit the configuration or processing of the present invention, and various modifications and changes may be made without departing from the technical concept of the present invention. The present invention also includes a program for realizing the functions of the above-described embodiments, and a computer-readable recording medium storing the program. Furthermore, the above-described embodiment is merely an example and does not limit the application of the technology according to the present disclosure. In other words, the technology according to the present disclosure can be applied to any system that authenticates a user based on the results of reading an authentication medium such as an IC card and provides a service to the user based on the authentication result. Furthermore, due to the technical features described above, the technology according to the present disclosure has a high affinity with systems that provide services that are used repeatedly by each user.
[0062] The following configurations also fall within the technical scope of the present disclosure. (1) A first acquisition means for acquiring, in accordance with a result of reading an authentication medium via near field communication, first identification information uniquely assigned to the authentication medium and stored in the authentication medium, and second identification information assigned to a communication unit of the authentication medium related to realizing the near field communication; a request means for, when personal information on an individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read, requesting a server device that manages personal information in association with the first identification information to execute a first authentication process related to authentication of the individual, based on the first identification information acquired from the authentication medium; and a request means for requesting, in accordance with a result of the first authentication process, the first identification information uniquely assigned to the authentication medium and stored in a predetermined storage area when the personal information on the individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read, to execute a first authentication process related to authentication of the individual, based on the first identification information acquired from the authentication medium. an information processing device comprising: a second acquisition means for acquiring the personal information associated with information; a storage means for storing in the storage area the personal information acquired from the server device, third identification information generated based on information of a portion of the first identification information, and the second identification information acquired from the authentication medium in association with each other; and an authentication means for, when the personal information is stored in the storage area when the authentication medium is read, executing a second authentication process for authenticating the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on information of the portion of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area. (2) The information processing device described in (1), wherein the second acquisition means acquires the third identification information from the server device based on the result of the first authentication process, and the storage means associates the personal information and the third identification information acquired from the server device with the second identification information acquired from the authentication medium and stores them in the storage area. (3) An information processing device described in (1) or (2), which has a generation means for generating the third identification information based on the part of the information of the first identification information acquired from the authentication medium, and when the personal information is stored in the memory area when the authentication medium is read, the authentication means executes the second authentication process based on a pair of the second identification information acquired by the first acquisition means and the third identification information generated by the generation means, and a pair of the second identification information and the third identification information stored in the memory area. (4) The information processing device according to any one of (1) to (3), wherein the third identification information is generated by masking information other than the part of the first identification information. (5) A server device connected via a network to an external device configured to be able to read an authentication medium via near field communication, the server device comprising: a management means for managing, in association with each other, first identification information uniquely assigned to the authentication medium and personal information about an individual associated with the authentication medium; an authentication means for receiving a request from the external device based on a result of reading the authentication medium in the external device and performing a first authentication process related to authentication of the individual based on the first identification information transmitted from the external device; and a transmission means for transmitting, to the external device, the personal information that the management means manages in association with the first identification information that was the target of the first authentication process based on a result of the first authentication process; and the external device, in accordance with the result of reading the authentication medium via near field communication, the first identification information held in the authentication medium and the second identification information assigned to a communication unit of the authentication medium related to realizing the near field communication, the second identification information being stored in the authentication medium and the second identification information being stored in the communication unit of the authentication medium and the second identification information being transmitted to the communication unit of the authentication medium related to realizing the near field communication. and if the personal information is not stored in a predetermined storage area when the authentication medium is read, requests the authentication means to execute the first authentication process to the server device based on the first identification information acquired from the authentication medium, and based on a result of the first authentication process, associates and stores the personal information acquired from the server device, third identification information generated based on partial information of the first identification information, and the second identification information acquired from the authentication medium, and if the personal information is stored in the storage area when the authentication medium is read, executes a second authentication process related to authentication of the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on the partial information of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area. (6) An information processing system in which an information processing device configured to be able to read an authentication medium via near field wireless communication and a server device are connected via a network, wherein the server device has a management means for managing first identification information uniquely assigned to the authentication medium and personal information about an individual associated with the authentication medium in association with each other, a first authentication means for receiving a request from the information processing device based on a reading result of the authentication medium in the information processing device and performing a first authentication process related to authentication of the individual managed by the management means based on the first identification information transmitted from the information processing device, and a transmission means for transmitting the personal information managed by the management means in association with the first identification information targeted for the first authentication process to the information processing device based on a result of the first authentication process, and the information processing device has a first acquisition means for acquiring the first identification information held in the authentication medium and second identification information assigned to a communication unit for realizing the near field wireless communication possessed by the authentication medium in accordance with the reading result of the authentication medium, and an information processing system comprising: a request means for requesting the server device to execute the first authentication process based on the first identification information acquired from the authentication medium when personal information about an individual associated with an authentication medium is not stored in a predetermined storage area; a second acquisition means for acquiring from the server device the personal information associated with the first identification information that was the subject of the first authentication process based on a result of the first authentication process; a storage means for storing in the storage area the personal information acquired from the server device, third identification information generated based on partial information of the first identification information, and the second identification information acquired from the authentication medium in association with each other; and a second authentication means for executing a second authentication process related to authentication of the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on the partial information of the first identification information acquired from the authentication medium when the personal information is stored in the storage area when the authentication medium is read. (7) An information processing method executed by an information processing device, comprising: a first acquisition step of acquiring, in accordance with a result of reading an authentication medium via near field communication, first identification information uniquely assigned to the authentication medium and stored in the authentication medium, and second identification information assigned to a communication unit of the authentication medium related to realizing the near field communication; a request step of, when personal information on an individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read, requesting a server device that manages the personal information in association with the first identification information to execute a first authentication process related to authentication of the individual, based on the first identification information acquired from the authentication medium; and a request step of requesting, from the server device, the execution of a first authentication process related to authentication of the individual, based on a result of the first authentication process. a second acquisition step of acquiring the personal information associated with the first identification information set forth above; a storage step of storing the personal information acquired from the server device, third identification information generated based on partial information of the first identification information, and the second identification information acquired from the authentication medium in the storage area in association with each other; and an authentication step of, if the personal information is stored in the storage area when the authentication medium is read, executing a second authentication process relating to authentication of the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on the partial information of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area. (8) An information processing method executed by a server device connected via a network to an external device configured to be able to read an authentication medium via near field communication, the method comprising: a management step of associating and managing first identification information uniquely assigned to the authentication medium with personal information about an individual associated with the authentication medium; an authentication step of receiving a request from the external device based on a reading result of the authentication medium in the external device, and performing a first authentication process related to authentication of the individual to be managed by the management step based on the first identification information transmitted from the external device; and a transmission step of transmitting the personal information managed in association with the first identification information targeted for the first authentication process in the management step to the external device based on a result of the first authentication process, wherein the external device, in response to a reading result of the authentication medium via near field communication, transmits the first identification information held in the authentication medium and the personal information of the authentication medium to the external device. and second identification information assigned to a communication unit related to realizing communication; and if the personal information is not stored in a predetermined storage area when the authentication medium is read, requesting the server device to execute the first authentication process based on the first identification information acquired from the authentication medium; based on a result of the first authentication process, storing the personal information acquired from the server device, third identification information generated based on a portion of the first identification information, and the second identification information acquired from the authentication medium in association with each other; and if the personal information is stored in the storage area when the authentication medium is read, executing a second authentication process related to authenticating the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on the portion of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area. (9) A computer includes a first acquisition step of acquiring, in accordance with a result of reading an authentication medium via near field communication, first identification information uniquely assigned to the authentication medium and stored in the authentication medium, and second identification information assigned to a communication unit related to realizing the near field communication that the authentication medium has; a request step of, when personal information about an individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read, requesting a server device that manages the personal information in association with the first identification information to execute a first authentication process related to authentication of the individual, based on the first identification information acquired from the authentication medium; and a request step of, when the result of the first authentication process is not stored in a predetermined storage area when the personal information about the individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read, requesting a server device that manages the personal information in association with the first identification information to execute a first authentication process related to authentication of the individual, based on the first identification information acquired from the authentication medium. a storage step of storing in the storage area the personal information acquired from the server device, third identification information generated based on a portion of the first identification information, and the second identification information acquired from the authentication medium in association with each other; and an authentication step of, when the personal information is stored in the storage area when the authentication medium is read, performing a second authentication process related to authentication of the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on the portion of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area. (10) A computer is caused to execute the following steps as a server device connected via a network to an external device configured to be able to read an authentication medium via near field communication: a management step of associating and managing first identification information uniquely assigned to the authentication medium with personal information about an individual associated with the authentication medium; an authentication step of receiving a request from the external device based on a reading result of the authentication medium in the external device, and performing a first authentication process related to authentication of the individual to be managed by the management step based on the first identification information transmitted from the external device; and a transmission step of transmitting the personal information managed in association with the first identification information that was the subject of the first authentication process in the management step to the external device based on the result of the first authentication process; and the external device acquires the first identification information held in the authentication medium and second identification information assigned to a communication unit related to realizing the near field communication possessed by the authentication medium according to the reading result of the authentication medium via near field communication, and if the personal information is not stored in a predetermined memory area when the authentication medium is read, a program that requests the server device to execute the first authentication process based on the first identification information acquired from the authentication medium, and based on a result of the first authentication process, associates and stores the personal information acquired from the server device, third identification information generated based on a portion of the first identification information, and the second identification information acquired from the authentication medium, and, if the personal information is stored in the memory area when the authentication medium is read, executes a second authentication process related to authentication of the individual based on the set of the second identification information acquired from the authentication medium and the third identification information generated based on the portion of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the memory area. [Explanation of symbols]
[0063] 1 Information processing system, 100 Information processing device, 110 Non-contact communication unit, 120 Communication unit, 130 Conversion processing unit, 140 Authentication processing unit, 150 Service providing unit, 160 Storage unit, 200 Management server, 210 Communication unit, 220 Authentication processing unit, 230 Conversion processing unit, 240 storage unit, 300 authentication medium, 310 non-contact communication unit, 320 transmission processing unit, 330 storage unit
Claims
1. a first acquisition means for acquiring, according to a result of reading an authentication medium via close proximity wireless communication, first identification information uniquely assigned to the authentication medium and held in the authentication medium, and second identification information assigned to a communication unit related to realizing the close proximity wireless communication that the authentication medium has; a requesting means for, when the personal information of an individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read, requesting a server device that manages the personal information in association with the first identification information to execute a first authentication process related to authentication of the individual based on the first identification information acquired from the authentication medium; a second acquiring means for acquiring, from the server device based on a result of the first authentication process, the personal information associated with the first identification information that was the target of the first authentication process; a storage means for storing the personal information acquired from the server device, third identification information generated based on a part of the first identification information, and the second identification information acquired from the authentication medium in the storage area in association with each other; an authentication means for executing a second authentication process for authenticating the individual based on a set of the second identification information acquired from the authentication medium and third identification information generated based on the part of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area, when the personal information is stored in the storage area when the authentication medium is read; An information processing device having the above.
2. the second acquisition means acquires the third identification information from the server device based on a result of the first authentication process; the storage means stores the personal information and the third identification information acquired from the server device and the second identification information acquired from the authentication medium in association with each other in the storage area; The information processing device according to claim 1 .
3. a generating means for generating the third identification information based on the part of the first identification information acquired from the authentication medium; When the personal information is stored in the storage area when the authentication medium is read, the authentication means executes the second authentication process based on a set of the second identification information acquired by the first acquisition means and the third identification information generated by the generation means, and a set of the second identification information and the third identification information stored in the storage area. The information processing device according to claim 1 .
4. the third identification information is generated by masking information other than the part of the first identification information. The information processing device according to claim 1 .
5. A server device connected via a network to an external device configured to be able to read an authentication medium via near field wireless communication, a management means for managing first identification information uniquely assigned to the authentication medium and personal information relating to an individual associated with the authentication medium in association with each other; an authentication means for receiving a request from the external device based on a result of reading the authentication medium in the external device, and performing a first authentication process related to authentication of the individual based on the first identification information transmitted from the external device; a transmitting means for transmitting, based on a result of the first authentication process, the personal information managed by the managing means in association with the first identification information that has been subjected to the first authentication process, to the external device; and The external device is acquiring, according to a result of reading the authentication medium via close proximity wireless communication, the first identification information held in the authentication medium and second identification information assigned to a communication unit of the authentication medium involved in realizing the close proximity wireless communication; If the personal information is not stored in a predetermined storage area when the authentication medium is read, requesting the authentication means to execute the first authentication process from the server device based on the first identification information acquired from the authentication medium; based on a result of the first authentication process, associate and store the personal information acquired from the server device, third identification information generated based on information of a portion of the first identification information, and the second identification information acquired from the authentication medium; If the personal information is stored in the storage area when the authentication medium is read, execute a second authentication process related to authentication of the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on the part of the first identification information acquired from the authentication medium, and based on the set of the second identification information and the third identification information stored in the storage area; Server device.
6. An information processing system in which an information processing device configured to be able to read an authentication medium via close proximity wireless communication and a server device are connected via a network, The server device a management means for managing first identification information uniquely assigned to the authentication medium and personal information relating to an individual associated with the authentication medium in association with each other; a first authentication means for receiving a request from the information processing device based on a result of reading the authentication medium in the information processing device, and for executing a first authentication process related to authentication of the individual to be managed by the management means based on the first identification information transmitted from the information processing device; a transmitting means for transmitting, based on a result of the first authentication process, the personal information managed by the managing means in association with the first identification information that was the target of the first authentication process, to the information processing device; and The information processing device includes: a first acquiring means for acquiring, according to a reading result of the authentication medium, the first identification information held in the authentication medium and second identification information assigned to a communication unit for realizing the close proximity wireless communication that the authentication medium has; a requesting means for requesting the server device to execute the first authentication process based on the first identification information acquired from the authentication medium when personal information relating to an individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read; a second acquiring means for acquiring, from the server device based on a result of the first authentication process, the personal information associated with the first identification information that was the target of the first authentication process; a storage means for storing the personal information acquired from the server device, third identification information generated based on a part of the first identification information, and the second identification information acquired from the authentication medium in the storage area in association with each other; a second authentication means for executing a second authentication process for authenticating the individual based on a set of the second identification information acquired from the authentication medium and third identification information generated based on the part of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area, when the personal information is stored in the storage area when the authentication medium is read; having Information processing system.
7. An information processing method executed by an information processing device, a first acquisition step of acquiring, according to a result of reading an authentication medium via close proximity wireless communication, first identification information uniquely assigned to the authentication medium and held in the authentication medium, and second identification information assigned to a communication unit related to realizing the close proximity wireless communication that the authentication medium has; a request step of requesting a server device that manages personal information associated with the authentication medium in association with the first identification information to execute a first authentication process related to authentication of the individual based on the first identification information acquired from the authentication medium, when personal information related to the individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read; a second acquisition step of acquiring, from the server device based on a result of the first authentication process, the personal information associated with the first identification information that was the target of the first authentication process; a storage step of storing the personal information acquired from the server device, third identification information generated based on part of the first identification information, and the second identification information acquired from the authentication medium in the storage area in association with each other; an authentication step of executing a second authentication process for authenticating the individual based on a set of the second identification information acquired from the authentication medium and third identification information generated based on the part of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area, when the personal information is stored in the storage area when the authentication medium is read; An information processing method, including:
8. An information processing method executed by a server device connected via a network to an external device configured to be able to read an authentication medium via close proximity wireless communication, comprising: a management step of associating and managing first identification information uniquely assigned to the authentication medium with personal information about an individual associated with the authentication medium; an authentication step of receiving a request from the external device based on a result of reading the authentication medium in the external device, and executing a first authentication process related to authentication of the individual to be managed by the management step based on the first identification information transmitted from the external device; a transmission step of transmitting, based on a result of the first authentication process, the personal information managed in association with the first identification information that was the target of the first authentication process in the management step, to the external device; Including, The external device is acquiring, according to a result of reading the authentication medium via close proximity wireless communication, the first identification information held in the authentication medium and second identification information assigned to a communication unit of the authentication medium involved in realizing the close proximity wireless communication; If the personal information is not stored in a predetermined storage area when the authentication medium is read, requesting the server device to execute the first authentication process based on the first identification information acquired from the authentication medium; based on a result of the first authentication process, associate and store the personal information acquired from the server device, third identification information generated based on information of a portion of the first identification information, and the second identification information acquired from the authentication medium; If the personal information is stored in the storage area when the authentication medium is read, execute a second authentication process related to authentication of the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on the part of the first identification information acquired from the authentication medium, and based on the set of the second identification information and the third identification information stored in the storage area; Information processing methods.
9. On the computer, a first acquisition step of acquiring, according to a result of reading an authentication medium via close proximity wireless communication, first identification information uniquely assigned to the authentication medium and held in the authentication medium, and second identification information assigned to a communication unit related to realizing the close proximity wireless communication that the authentication medium has; a request step of requesting a server device that manages personal information associated with the authentication medium in association with the first identification information to execute a first authentication process related to authentication of the individual based on the first identification information acquired from the authentication medium, when personal information related to the individual associated with the authentication medium is not stored in a predetermined storage area when the authentication medium is read; a second acquisition step of acquiring, from the server device based on a result of the first authentication process, the personal information associated with the first identification information that was the target of the first authentication process; a storage step of storing the personal information acquired from the server device, third identification information generated based on part of the first identification information, and the second identification information acquired from the authentication medium in the storage area in association with each other; an authentication step of executing a second authentication process for authenticating the individual based on a set of the second identification information acquired from the authentication medium and third identification information generated based on the part of the first identification information acquired from the authentication medium, and the set of the second identification information and the third identification information stored in the storage area, when the personal information is stored in the storage area when the authentication medium is read; A program that executes.
10. On the computer, A server device connected via a network to an external device configured to be able to read an authentication medium via close proximity wireless communication, a management step of associating and managing first identification information uniquely assigned to the authentication medium with personal information about an individual associated with the authentication medium; an authentication step of receiving a request from the external device based on a result of reading the authentication medium in the external device, and executing a first authentication process related to authentication of the individual to be managed by the management step based on the first identification information transmitted from the external device; a transmission step of transmitting, based on a result of the first authentication process, the personal information managed in association with the first identification information that was the target of the first authentication process in the management step, to the external device; Execute The external device is acquiring, according to a result of reading the authentication medium via close proximity wireless communication, the first identification information held in the authentication medium and second identification information assigned to a communication unit of the authentication medium involved in realizing the close proximity wireless communication; If the personal information is not stored in a predetermined storage area when the authentication medium is read, requesting the server device to execute the first authentication process based on the first identification information acquired from the authentication medium; based on a result of the first authentication process, associate and store the personal information acquired from the server device, third identification information generated based on information of a portion of the first identification information, and the second identification information acquired from the authentication medium; If the personal information is stored in the storage area when the authentication medium is read, execute a second authentication process related to authentication of the individual based on a set of the second identification information acquired from the authentication medium and the third identification information generated based on the part of the first identification information acquired from the authentication medium, and based on the set of the second identification information and the third identification information stored in the storage area; program.
Citation Information
Patent Citations
Lock device for door, home delivery box system and home delivery box
JP2022000568A