Biometric authentication device, biometric authentication system, biometric authentication method, and program

The biometric authentication system addresses the risk of user information leakage by delaying identification information transmission until biometric matching is complete, ensuring secure and timely service delivery.

JP2025150595APending Publication Date: 2025-10-09NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024051574
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-27
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

The risk of user information leakage increases when there is a significant time gap between service reservation and service provision, causing anxiety for both users and service providers.

Method used

A biometric authentication system and method that delays the transmission of user identification information until biometric information is matched, ensuring secure and timely service provision.

Benefits of technology

Reduces the risk of user information leakage by shortening the time during which user information is entrusted to a service provider, enhancing security and ease of service delivery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025150595000001_ABST
    Figure 2025150595000001_ABST
Patent Text Reader

Abstract

To provide a biometric authentication device, biometric authentication system, biometric authentication method and program, which make it easier for users to receive services provided for specific users.SOLUTION: A biometric authentication device provided herein is communicably connected to a service provision device and comprises a user information reading unit, information delayed transmission unit, biometric information acquisition unit, and biometric information verification unit.SELECTED DRAWING: Figure 9
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a biometric authentication device, a biometric authentication system, a biometric authentication method, and a program. [Background technology]

[0002] In a service provided to a specific user, biometric authentication is known, which performs personal authentication of the user using biometric information unique to the user (for example, a face image or a fingerprint image of the user). For example, Patent Document 1 describes that biometric authentication is performed by a system including an authentication terminal that collates the biometric information of the user. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] International Publication No. 2023 / 053268

[0004] Services provided to specific users include, for example, public services provided by government agencies and medical services provided by medical institutions. In such services, the user is identified and the service is provided by comparing information identifying the user (typically, identity information such as name and address) recorded in an official certificate. Examples of official certificates include My Number cards, driver's licenses, and passports. Official certificates have an IC chip on which information identifying the user is recorded. Recording the user's biometric information on this IC chip enables biometric authentication in public services, medical services, and other services provided to specific users (hereinafter, identity information and biometric information are collectively referred to as "user identification information" or simply "user information"). The IC chip in an official certificate is a user-specific recording medium on which information identifying the user is recorded. Summary of the Invention [Problem to be solved by the invention]

[0005] In many services, the timing when a service reservation is completed differs from the timing when the service is provided. The longer the span between these two timings, the higher the risk of user information being leaked. This causes anxiety for both users whose information may be leaked and service providers who may be held responsible for the leak of user information.

[0006] An object of the present disclosure is to provide a biometric authentication device, a biometric authentication system, a biometric authentication method, and a program that solve the above-mentioned problems. [Means for solving the problem]

[0007] A biometric authentication device according to one aspect of the present disclosure is communicatively connected to a service providing device that provides a service to a user, and includes a user information reading unit that reads the user's identification information and biometric information recorded on a recording medium, an information delay transmission unit that stores the user's identification information read by the user information reading unit, a biometric information acquisition unit that acquires the user's biometric information from the user, and a biometric information matching unit that compares the user's biometric information acquired by the biometric information acquisition unit with the user's biometric information read by the user information reading unit, wherein the information delay transmission unit transmits the user's identification information to the service providing device after the biometric information matching unit has compared the user's biometric information, and the service providing device provides the service to the user after confirming the user's identification information.

[0008] A biometric authentication system according to one aspect of the present disclosure comprises a service providing device that provides a service to a user, and a biometric authentication device that is communicatively connected to the service providing device, wherein the biometric authentication device comprises a user information reading unit that reads the user's identification information and biometric information recorded on a recording medium, an information delay transmission unit that stores the user's identification information read by the user information reading unit, a biometric information acquisition unit that acquires the user's biometric information from the user, and a biometric information matching unit that compares the user's biometric information acquired by the biometric information acquisition unit with the user's biometric information read by the user information reading unit, wherein the information delay transmission unit transmits the user's identification information to the service providing device after the biometric information matching unit has compared the user's biometric information, and the service providing device provides the service to the user after confirming the user's identification information.

[0009] A biometric authentication method according to one embodiment of the present disclosure includes a first step of reading a user's identification information recorded on a recording medium, a second step of reading the user's biometric information recorded on the recording medium, a third step of storing the read user's identification information, a fourth step of acquiring the user's biometric information from the user, a fifth step of comparing the user's biometric information acquired in the fourth step with the user's biometric information read in the second step, a sixth step of transmitting the user's identification information after comparing the user's biometric information in the fifth step, and a seventh step of providing a service to the user after confirming the user's identification information.

[0010] A program according to one embodiment of the present disclosure is a program for causing a computer to execute the following steps: a first step of reading a user's identification information recorded on a recording medium; a second step of reading the user's biometric information recorded on the recording medium; a third step of storing the read user's identification information; a fourth step of acquiring the user's biometric information from the user; a fifth step of comparing the user's biometric information acquired in the fourth step with the user's biometric information read in the second step; a sixth step of transmitting the user's identification information after comparing the user's biometric information in the fifth step; and a seventh step of providing a service to the user after confirming the user's identification information. [Brief explanation of the drawings]

[0011] [Figure 1] 1 is a block diagram illustrating an example configuration of a biometric authentication system and a biometric authentication device according to the present disclosure. [Figure 2] FIG. 1 is a hardware configuration diagram of a biometric authentication device 10. [Figure 3] FIG. 1 is a flow diagram illustrating an example of a biometric authentication method according to the present disclosure. [Figure 4] FIG. 10 is a sequence diagram showing an example of key issuing processing S1. [Figure 5] FIG. 10 is a sequence diagram showing an example of encryption processing S2. [Figure 6] FIG. 10 is a sequence diagram showing an example of reservation processing S3. [Figure 7] FIG. 10 is a sequence diagram showing an example of the matching process S4. [Figure 8] FIG. 10 is a sequence diagram showing an example of the matching process S4. [Figure 9] 1 is a block diagram illustrating an example configuration of a biometric authentication system and a biometric authentication device according to the present disclosure. [Figure 10] FIG. 1 is a flow diagram illustrating an example of a biometric authentication method according to the present disclosure. [Figure 11] FIG. 1 is a sequence diagram illustrating an example of a method for providing a service to a specific user online. DETAILED DESCRIPTION OF THE INVENTION

[0012] Each embodiment will be described below with reference to the drawings. In all drawings, the same or corresponding components are designated by the same reference numerals, and common descriptions will be omitted.

[0013] First Embodiment Hereinafter, one embodiment of the present disclosure will be described with reference to FIGS.

[0014] 1 is a block diagram showing an example of the configuration of a biometric authentication system and a biometric authentication device according to the present disclosure. The biometric authentication system 1 includes a biometric authentication device 10 and a service providing device 11.

[0015] The biometric authentication device 10 is a device that performs biometric authentication of a user. The biometric authentication device 10 is a terminal capable of communication. The biometric authentication device 10 is communicably connected to a service providing device 11 via a network NW such as the Internet. Alternatively, the biometric authentication device 10 and the service providing device 11 may be communicably connected by a wired connection or a wireless connection, which is a conventional technology, without via the network NW. The biometric authentication device 10 may be a terminal owned by a user, such as a smartphone, a tablet, or a PC. Alternatively, the biometric authentication device 10 may be a terminal installed at a location where a service provider provides a service. For example, the biometric authentication device 10 may be a card reader terminal or a kiosk terminal installed in a hospital.

[0016] FIG. 2 is a diagram showing the hardware configuration of the biometric authentication device 10. As shown in FIG. 2, the biometric authentication device 10 is a computer equipped with various hardware components such as a CPU (Central Processing Unit) 151, a ROM (Read Only Memory) 152, a RAM (Random Access Memory) 103, a database 104, and a communication module 105. The biometric authentication device 10 may be configured as a single computer, or may be configured as a single biometric authentication device 10 by connecting multiple computers for communication.

[0017] The biometric authentication device 10 includes an information delay transmission unit 101, a user information reading unit 102, a first control unit 103, an information temporary storage unit 104, a biometric information acquisition unit 105, a biometric information matching unit 106, a photographing unit 107, and a display unit 108.

[0018] The information delay transmission unit 101 stores user information during a reservation process in which a user reserves a service. The user information stored by the information delay transmission unit 101 is transmitted to the service providing device 11 during a matching process in which biometric information of the user is matched.

[0019] The user information reading unit 102 reads user information recorded in a public certificate. The read user information does not necessarily include all of the user information (identity information, biometric information). The read user information may include only a portion of the user information depending on the occasion when the reading is performed. The read user information may include only identity information. The read user information may include only biometric information. The read identity information may include only a portion of identity information, such as an address. The read biometric information may include only a portion of biometric information, such as a facial image. Hereinafter, biometric information read from a public certificate will be referred to as "read biometric information." The biometric information may include, for example, information including individual physical characteristics such as a face, iris, fingerprint, veins, or ear acoustics.

[0020] The first control unit 103 executes the biometric authentication method according to the present disclosure in the biometric authentication device 10. The first control unit 103 transmits information to the service providing device 11 for issuing a key for the service providing device 11 to encrypt user information. The first control unit 103 stores the key received from the service providing device 11. The first control unit 103 encrypts the user information using the stored key. The first control unit 103 transmits information for the user to reserve a service to the service providing device 11. In a reservation process in which the user reserves a service, the first control unit 103 causes the information delay transmission unit 101 to store the user information. In a matching process in which the user's biometric information is matched, the first control unit 103 transmits the user information to the service providing device 11.

[0021] The temporary information storage unit 104 temporarily stores information acquired or generated in the biometric authentication device 10 during the biometric authentication method according to the present disclosure. The temporary information storage unit 104 temporarily stores user information read from the user's official certificate. The temporary information storage unit 104 temporarily stores user information encrypted in the biometric authentication device 10. The temporary information storage unit 104 temporarily stores biometric information acquired from the user in the biometric authentication device 10.

[0022] The biometric information acquisition unit 105 acquires biometric information of a user from the user. The biometric information acquisition unit 105 acquires an image of the user's face captured by the biometric authentication device 10 during the biometric authentication method according to the present disclosure. The biometric information acquisition unit 105 acquires an image of the user's fingerprint captured by the biometric authentication device 10 during the biometric authentication method according to the present disclosure. Hereinafter, the user's biometric information acquired from the user by the biometric information acquisition unit 105 will be abbreviated as "acquired biometric information."

[0023] The biometric information matching unit 106 matches the acquired biometric information with the read biometric information.

[0024] The photographing unit 107 takes a photograph using a camera (not shown) of the biometric authentication device 10. The display unit 108 displays messages, images, input fields, etc. for the user on a touch panel (not shown) of the biometric authentication device 10.

[0025] The service providing device 11 is a storage medium external to the biometric authentication device 10. The service providing device 11 stores information such as reservation information and user information (identity information) transmitted from the user's biometric authentication device 10. The service providing device 11 is, for example, a server device or a cloud server.

[0026] The service providing device 11 includes an information receiving unit 111, a second control unit 112, and an information storage unit 113.

[0027] The information receiving unit 111 receives the information transmitted from the biometric authentication device 10.

[0028] The second control unit 112 issues a key for encryption. The second control unit 112 decrypts the encrypted user information (identity information). The second control unit 112 checks the identity information of the user who wishes to receive the service. The second control unit 112 checks whether the date and time when the service will be provided has arrived.

[0029] Fig. 3 is a flow diagram showing an example of a biometric authentication method according to the present disclosure. Figs. 4 to 7 are sequence diagrams showing an example of a biometric authentication method according to the present disclosure. Fig. 4 is a sequence diagram showing an example of a key issuing process S1. Fig. 5 is a sequence diagram showing an example of an encryption process S2. Fig. 6 is a sequence diagram showing an example of a reservation process S3. Fig. 7 is a sequence diagram showing an example of a verification process S4.

[0030] As shown in FIG. 3, the biometric authentication method according to the present disclosure includes a key issuing process step S1, an encryption process step S2, a reservation process step S3, and a matching process step S4. Each step will be explained below with reference to FIGS.

[0031] 4, in key issuance processing step S1, the service providing device 11 issues a key for encrypting user information and transmits it to the biometric authentication device 10. Key issuance processing step S1 includes a request information input step S101, a request information transmission step S102, a key issuance step S103, a decryption key storage step S104, an encryption key transmission step S105, and an encryption key storage step S106.

[0032] First, the user inputs information for requesting encryption to the biometric authentication device 10 (S101). In step S101, for example, a message prompting the user to input information and a button for permitting the information input are displayed on the display unit 108 of the biometric authentication device 10 (see FIG. 1). When the user presses the button, the information for requesting encryption is input. The information for requesting encryption is stored in the temporary information storage unit 104 of the biometric authentication device 10.

[0033] Next, the information temporary storage unit 104 (see FIG. 1) of the biometric authentication device 10 transmits information for requesting encryption to the first control unit 103. The first control unit 103 transmits the information for requesting encryption to the information receiving unit 111 of the service providing device 11 (S102).

[0034] Next, the second control unit 112 of the service providing device 11 (see FIG. 1) issues a key for encryption (S103). Here, the encryption method may be such that the keys used for encryption and decryption are the same or different. The encryption method may be, for example, a public key cryptosystem. When the keys used for encryption and decryption are different, the second control unit 112 issues an encryption key and a decryption key (a public key and a private key in the case of a public key cryptosystem).

[0035] Next, the information storage unit 113 (see FIG. 1) of the service providing device 11 stores the key issued by the second control unit 112 (S104). If the keys used for encryption and decryption are different, the information storage unit 113 stores the decryption key (a private key in the case of a public key cryptosystem).

[0036] Next, the control unit 112 (see FIG. 1) of the service providing device 11 transmits the key issued by the second control unit 112 to the biometric authentication device 10 (S105). If the keys used for encryption and decryption are different, the second control unit 112 transmits the encryption key (the public key in the case of a public key cryptosystem).

[0037] Next, the temporary information storage unit 104 of the biometric authentication device 10 stores the key (for encryption) transmitted from the service providing device 11. The temporary information storage unit 104 transmits the key (for encryption) to the first control unit 103. The first control unit 103 stores the key (for encryption) (S106). This completes the key issuing process S1.

[0038] If the service provided by the service providing device 11 is provided by a dedicated app on the biometric authentication device 10, the app needs to be installed in the biometric authentication device 10. In this case, for example, step S101 may be omitted, and step S102 may be performed simultaneously with the downloading of the app to the biometric authentication device 10.

[0039] 5, in encryption processing step S2, the biometric authentication device 10 reads user information from the official certificate and encrypts the identity information. Encryption processing step S2 includes an official certificate presentation step S201, a user information reading step S202, an identity information encryption step S203, and an encrypted identity information temporary storage step S204.

[0040] First, the user presents his / her official certificate to the biometric authentication device 10 (S201). Next, the user information reading unit 102 (see FIG. 1) of the biometric authentication device 10 reads user information from the IC chip of the presented official certificate. The temporary information storage unit 104 stores the read user information (S202). The user information read here includes at least information of identity that needs to be confirmed (S405 in FIG. 7) when providing a service (e.g., name, date of birth; hereinafter simply referred to as "identity information"). The user information read here may also include information of biometric information that is used for biometric authentication (S402 in FIG. 7) (e.g., face image; hereinafter simply referred to as "biometric information").

[0041] Next, the first control unit 103 (see FIG. 1) of the biometric authentication device 10 encrypts the read identification information using the stored key (for encryption) (S203). Next, the temporary information storage unit 104 stores the encrypted identification information (S204). At the end of step S204, the temporary information storage unit 104 stores at least the encrypted identification information. If biometric information is read in step S202, at the end of step S204, the temporary information storage unit 104 stores the read biometric information. This completes encryption processing step S2.

[0042] 6, in reservation processing step S3, reservation information is transmitted to the service providing device, and the encrypted identity information is made transmittable in matching processing step S4. Reservation processing step S3 includes reservation information input step S301, reservation information transmission step S302, reservation information storage step S303, and encrypted identity information transmission waiting step S304.

[0043] First, the user inputs reservation information into the biometric authentication device 10 (S301). In step S301, for example, a message prompting the user to input reservation information is displayed on the display unit 108 of the biometric authentication device 10 (see FIG. 1 ), and an input field for the reservation information is displayed. The reservation information is input by the user entering the reservation information (for example, reservation date and time) in the input field. The reservation information is stored in the temporary information storage unit 104 of the biometric authentication device 10.

[0044] Next, the information temporary storage unit 104 (see FIG. 1) of the biometric authentication device 10 transmits the reservation information to the first control unit 103. The first control unit 103 transmits the reservation information to the information receiving unit 111 of the service providing device 11 (S302). When transmitting the reservation information, the reservation information may be linked to information that can identify the biometric authentication device and transmitted. The reservation date and time stored in the biometric authentication device may be stored in association with the key described above.

[0045] Next, the information receiving unit 111 (see FIG. 1) of the service providing device 11 transmits the reservation information to the information storage unit 113. The information storage unit 113 stores the reservation information (S303).

[0046] Next, the information temporary storage unit 104 (see FIG. 1) of the personal authentication device 10 transmits the stored encrypted identity information to the information delay transmission unit 101. The information delay transmission unit 101 stores the encrypted identity information (S304) until it transmits the information to the service providing device 11 in the matching process S4 (S403). This completes the reservation processing step S3.

[0047] Step S303 and step S304 may be executed in any order, or may be executed simultaneously.

[0048] 7, in a matching step S4, the biometric authentication device 10 matches the biometric information of the user. Thereafter, the service providing device 11 confirms the identity information provided by the biometric authentication device 10 and provides a service to the user. The matching step S4 includes a biometric information presenting step S401, a biometric information matching step S402, an encrypted identity information transmitting step S403, an encrypted identity information decrypting step S404, an identity information confirming step S405, a date and time arrival confirming step S406, a service information transmitting step S407, and a service providing step S408.

[0049] First, the user presents his / her own biometric information to the biometric authentication device 10 (S401). The user may perform step S401 at any timing after the completion of the reservation processing step S3 and before the service is provided. Typically, the timing is close to the time when the service is provided (for example, one hour before the start of the online medical consultation).

[0050] In step S401, the photographing unit 107 (see FIG. 1) of the biometric authentication device 10 photographs the user's face, and the biometric information acquiring unit 105 acquires information on the photographed face image (acquired biometric information). The biometric information acquiring unit 105 transmits the acquired biometric information to the biometric information matching unit 106.

[0051] If the biometric information has been read in step S202, the information temporary storage unit 104 transmits the stored biometric information (read biometric information) to the biometric information matching unit . If the biometric information has not been read in step S202, in step S401, the user presents his / her own official certificate to the biometric authentication device 10. The user information reading unit 102 of the biometric authentication device 10 reads the biometric information from the IC chip of the presented official certificate. The user information reading unit 102 transmits the read biometric information (read biometric information) to the biometric information matching unit 106.

[0052] This completes step S401.

[0053] Next, the biometric information matching unit 106 matches the acquired biometric information with the read biometric information (S402). The biometric authentication device 10 may check whether the date and time for providing the service reserved by the user has arrived between step S402 and step S403. In this case, the second control unit 112 does not need to check the date and time in step S406, which will be described later.

[0054] If the biometric information matching is successful, the information delay transmission unit 101 transmits the encrypted identification information that has been stored to the information receiving unit 111 (see FIG. 1) of the service providing device 11 (S403). If the biometric information matching is unsuccessful, the process returns to step S401 and biometric information matching is performed again (not shown). Therefore, unless the biometric authentication is successful, the identification information of the user who made the reservation is not transmitted to the service providing device 11, and the service is not provided.

[0055] Next, the information receiving unit 111 (see FIG. 1) of the service providing device 11 transmits the received encrypted identification information to the second control unit 112. The second control unit 112 decrypts the encrypted identification information using the stored decryption key (in the case of public key cryptography, the private key) (S404). When multiple reservations are made with one biometric authentication device, the reservation date and time are linked to the key and stored in the biometric authentication device as described in step S302. This allows decryption to be performed using the key corresponding to the reservation date and time.

[0056] Next, the second control unit 112 of the service providing device 11 (see FIG. 1) verifies the decrypted identification information (S405). The verification is performed, for example, by checking against a list of user identification information stored in advance in the service providing device 11. For users who have been verified, the process proceeds to step S406 and subsequent steps, and the service is provided. For users who have not been verified, the process does not proceed to step S406 and subsequent steps, and the service is not provided (not shown).

[0057] Next, the second control unit 112 (see FIG. 1) of the service providing device 11 checks whether the date and time for providing the service reserved by the user has arrived by referring to the stored reservation information (S406). As described above, whether the reserved date and time has arrived may be determined by the biometric authentication device 10 between steps S402 and S403. In this case, the second control unit 112 does not need to check the date and time in step S406.

[0058] When the date and time for providing the service arrives, the second control unit 112 (see FIG. 1) of the service providing device 11 transmits information related to the service (for example, information on real-time video of the attending doctor) to the biometric authentication device 10 (S407). As a result, the biometric authentication device 10 provides the service to the user (S408).

[0059] The biometric authentication system 1 described above has an internal computer system. The steps of the biometric authentication method described above are stored in the form of a program on a computer-readable recording medium, and the computer reads and executes this program to perform the above processing. Here, the computer-readable recording medium refers to a magnetic disk, a magneto-optical disk, a CD-ROM, a DVD-ROM, a semiconductor memory, etc. Alternatively, the computer program may be distributed to a computer via a communication line, and the computer that receives the program may execute the program.

[0060] Alternatively, a biometric authentication method may be performed by recording a program for implementing the functions of the biometric authentication system 1 in FIG. 1 on a computer-readable recording medium, and then loading and executing the program on the recording medium into a computer system. Note that the term "computer system" as used herein includes hardware such as an OS and peripheral devices. It also includes a WWW system equipped with a website provision environment (or display environment). The term "computer-readable recording medium" refers to portable media such as flexible disks, optical magnetic disks, ROMs, and CD-ROMs, as well as storage devices such as hard disks built into computer systems. Furthermore, the term "computer-readable recording medium" also includes devices that retain a program for a certain period of time, such as volatile memory (RAM) within a computer system that acts as a server or client when the program is transmitted via a network such as the Internet or a communication line such as a telephone line.

[0061] The program may also be transmitted from a computer system storing the program in a storage device or the like to another computer system via a transmission medium or by transmission waves in the transmission medium. Here, the "transmission medium" that transmits the program refers to a medium that has the function of transmitting information, such as a network (communication network) such as the Internet or a communication line (communication line) such as a telephone line. The program may also be a program that realizes part of the above-mentioned functions. Furthermore, the program may be a so-called differential file (differential program) that can realize the above-mentioned functions in combination with a program already recorded in the computer system.

[0062] In the case of a service provided to a specific user, the service provider first checks the user's user information before providing the service to the user. An example of such a service is medical treatment at a hospital. Among the services provided to specific users, there are some that allow users to make reservations for services online using their own terminals and receive the services online on their own terminals at the reserved time. An example of such a service is online medical consultation.

[0063] FIG. 11 is a sequence diagram showing an example of a method for providing a service to a specific user online. First, the user inputs reservation information for the service they wish to receive into their own terminal (user terminal) (S901). The reservation information includes, for example, the date and time when the service will be provided and the person providing the service. In the case of a hospital visit, the reservation information includes, for example, the consultation date and time and the doctor in charge. Next, the user presents a public certificate to the user terminal (S902). Next, the user terminal reads the user information recorded on the IC chip of the public certificate (S903). Next, the user terminal transmits information to a device (service providing device) that provides the service of the service provider via a network such as the Internet (S904). The transmitted information includes the reservation information and user information. Next, the service providing device stores the received information (S905). Next, the service providing device checks whether the date and time when the service will be provided has arrived (S906). If the arrival is confirmed, the service providing device transmits information related to the service (for example, information on real-time video of the attending doctor) to the user terminal (S907), which then causes the user terminal to provide the service to the user (S908).

[0064] In many services, the time interval between the completion of a service reservation and the provision of the service (the time interval between step S905 and step S907 in FIG. 11) is long (for example, one month). Therefore, in the service provision method illustrated in FIG. 11, the user entrusts their user information (identification information) to the service provider for a long period of time. The longer this period, the higher the risk of user information being leaked due to attacks by malicious hackers or inappropriate information handling by the service provider. This causes anxiety for both users whose user information may be leaked and service providers who are held responsible for the leak of user information.

[0065] According to the biometric authentication system, biometric authentication device, biometric authentication method, and program of the present embodiment, it is possible to shorten the period during which a user entrusts his / her user information (identity information) to a service provider. This reduces the risk of user information being leaked. Therefore, it is easy for a user to receive services provided to a specific user.

[0066] Second Embodiment An embodiment according to the present disclosure will be described below with reference to Fig. 8. The description of Figs. 1 to 6 is the same as that already given, and will therefore be omitted.

[0067] In the biometric authentication method disclosed herein, in the matching process (S4) (see FIG. 3), as shown in FIG. 8 instead of FIG. 7, after the date and time arrival confirmation step S4001, reminder information sending step S4002, and reminder step S4003 are completed, the biometric information presentation step S401, biometric information matching step S402, encrypted identity information sending step S403, encrypted identity information decryption step S404, identity information confirmation step S405, service information sending step S407, and service provision step S408 are performed in this order.

[0068] In the matching process (S4) of the biometric authentication method according to the present disclosure, first, the second control unit 112 (see FIG. 1) of the service providing device 11 checks whether the date and time for providing the service reserved by the user falls within a predetermined time period (e.g., within one hour) by referring to the stored reservation information (S4001).

[0069] If the date and time when the service will be provided arrives within a predetermined time, the second control unit 112 (see FIG. 1) of the service providing device 11 transmits reminder information to the biometric authentication device 10 to remind the user that the date and time when the service will be provided arrives (S4002). If there are multiple biometric authentication devices, when the reservation information is sent in step S302, the reservation information is linked to information that can identify the biometric authentication device and sent, which makes it possible to identify which biometric authentication device the reminder information should be sent to.

[0070] Next, the biometric authentication device 10 reminds the user that the date and time when the service will be provided has arrived (S4003). The biometric authentication device 10, for example, displays on the display unit 108 of the biometric authentication device 10 (see FIG. 1) a message informing the user that the date and time when the service reserved by the user will be provided will arrive within a predetermined time. The biometric authentication device 10, for example, displays a message prompting the user to present his or her own biometric information. Having received the reminder from the biometric authentication device 10, the user presents his or her own biometric information to the biometric authentication device 10 (S401).

[0071] According to the biometric authentication system, biometric authentication device, biometric authentication method, and program of the present embodiment, it is possible to shorten the period during which a user entrusts his / her user information (identity information) to a service provider. This reduces the risk of user information being leaked. Therefore, it is easy for a user to receive services provided to a specific user.

[0072] <Third embodiment> An embodiment of the present disclosure will be described below with reference to FIGS.

[0073] As shown in FIG. 9, a biometric authentication device 50 according to the present disclosure is communicatively connected to a service providing device 51 that provides a service to a user, and includes a user information reading unit 501 that reads the user's identification information and biometric information recorded on a recording medium, an information delay transmission unit 502 that stores the user's identification information read by the user information reading unit 501, a biometric information acquisition unit 503 that acquires the user's biometric information from the user, and a biometric information matching unit 504 that compares the user's biometric information acquired by the biometric information acquisition unit 503 with the user's biometric information read by the user information reading unit 501. After the biometric information matching unit 504 has compared the user's biometric information, the information delay transmission unit 502 transmits the user's identification information to the service providing device 51, and the service providing device 51 provides the user with the service after confirming the user's identification information.

[0074] A biometric authentication system 5 according to the present disclosure comprises a service providing device 51 that provides a service to a user, and a biometric authentication device 50 communicatively connected to the service providing device 51. The biometric authentication device 50 is communicatively connected to the service providing device 51 that provides a service to the user, and comprises a user information reading unit 501 that reads the user's identification information and biometric information recorded on a recording medium, an information delay transmission unit 502 that stores the user's identification information read by the user information reading unit 501, a biometric information acquisition unit 503 that acquires the user's biometric information from the user, and a biometric information matching unit 504 that compares the user's biometric information acquired by the biometric information acquisition unit 503 with the user's biometric information read by the user information reading unit 501. After the biometric information matching unit 504 has compared the user's biometric information, the information delay transmission unit 502 transmits the user's identification information to the service providing device 51. The service providing device 51 provides the user with the service after confirming the user's identification information.

[0075] As shown in FIG. 10 , the biometric authentication method according to the present disclosure includes a first step of reading the user's identification information recorded on a recording medium, a second step of reading the user's biometric information recorded on a recording medium, a third step of storing the user's identification information read by the user information reading unit, a fourth step of acquiring the user's biometric information from the user, a fifth step of comparing the user's biometric information acquired in the fourth step with the user's biometric information read in the second step, a sixth step of transmitting the user's identification information to the service providing device after comparing the user's biometric information in the fifth step, and a seventh step of providing the service to the user after confirming the user's identification information.

[0076] The program of the present disclosure is a program for causing a computer to execute the following steps: a first step of reading the user's identification information recorded on a recording medium; a second step of reading the user's biometric information recorded on a recording medium; a third step of storing the user's identification information read by the user information reading unit; a fourth step of acquiring the user's biometric information from the user; a fifth step of comparing the user's biometric information acquired in the fourth step with the user's biometric information read in the second step; a sixth step of transmitting the user's identification information to the service providing device after comparing the user's biometric information in the fifth step; and a seventh step of providing the service to the user after confirming the user's identification information.

[0077] According to the biometric authentication system, biometric authentication device, biometric authentication method, and program of the present embodiment, it is possible to shorten the period during which a user entrusts his / her user information (identity information) to a service provider. This reduces the risk of user information being leaked. Therefore, it is easy for a user to receive services provided to a specific user.

[0078] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.

[0079] Some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.

[0080] (Appendix 1) a communication-capable connection to a service providing device that provides a service to a user; a user information reading unit that reads the user's identification information and biometric information recorded on a recording medium; an information delay transmission unit that stores the user's identification information read by the user information reading unit; a biometric information acquisition unit that acquires biometric information of the user from the user; a biometric information matching unit that matches the biometric information of the user acquired by the biometric information acquisition unit with the biometric information of the user read by the user information reading unit; Equipped with the information delay transmission unit transmits the user's identification information to the service providing device after the biometric information matching unit matches the user's biometric information; the service providing device provides the service to the user after verifying the user's identity information; Biometric authentication device.

[0081] (Appendix 2) A first control unit is provided, the first control unit encrypts the user's identification information read by the user information reading unit; The information delay transmission unit stores and transmits the user's identification information encrypted by the first control unit. 10. The biometric authentication device of claim 1.

[0082] (Appendix 3) the service providing device issues a first key for encrypting the user's identification information and a second key for decrypting the encrypted user's identification information; the first control unit receives the first key from the service providing device; The first control unit encrypts the user identification information read by the user information reading unit using the first key. 3. The biometric authentication device according to claim 1 or 2.

[0083] (Appendix 4) The first key and the second key are a public key and a private key of a public key cryptosystem, respectively. 4. The biometric authentication device according to any one of claims 1 to 3.

[0084] (Appendix 5) the biometric authentication device refers to the reservation information input by the user and transmits the reservation information to the service providing device, which confirms the date and time when the service will be provided to the user; 5. A biometric authentication device according to any one of claims 1 to 4.

[0085] (Appendix 6) and after confirming the date and time at which the service will be provided to the user, acquiring information as to whether the date and time will arrive within a predetermined time from the service providing device that has confirmed whether the date and time will arrive within a predetermined time. 6. A biometric authentication device according to any one of appendices 1 to 5.

[0086] (Appendix 7) If the date and time arrives within a predetermined time, the biometric information matching unit starts matching the biometric information of the user. 7. A biometric authentication device according to any one of appendices 1 to 6.

[0087] (Appendix 8) A display unit is provided, When the reminder information is received, the display unit displays a message to the user prompting the user to present his or her own biometric information. 8. The biometric authentication device according to any one of claims 1 to 7.

[0088] (Appendix 9) Equipped with a photography department, The photographing unit photographs a face of the user, the biometric information acquisition unit acquires facial image information of the user captured by the imaging unit; 9. A biometric authentication device according to any one of appendices 1 to 8.

[0089] (Appendix 10) a service providing device that provides a service to a user; a biometric authentication device communicably connected to the service providing device; Equipped with The biometric authentication device a user information reading unit that reads the user's identification information and biometric information recorded on a recording medium; an information delay transmission unit that stores the user's identification information read by the user information reading unit; a biometric information acquisition unit that acquires biometric information of the user from the user; a biometric information matching unit that matches the biometric information of the user acquired by the biometric information acquisition unit with the biometric information of the user read by the user information reading unit; Equipped with the information delay transmission unit transmits the user's identification information to the service providing device after the biometric information matching unit matches the user's biometric information; the service providing device provides the service to the user after verifying the user's identity information; Biometric authentication system.

[0090] (Appendix 11) the biometric authentication device includes a first control unit, the first control unit encrypts the user's identification information read by the user information reading unit; The information delay transmission unit stores and transmits the user's identification information encrypted by the first control unit. 11. The biometric authentication system of claim 10.

[0091] (Appendix 12) the service providing device includes a second control unit, the second control unit issues a first key for encrypting the user's identification information and a second key for decrypting the encrypted user's identification information; the second control unit transmits the first key to the biometric authentication device; the second control unit stores the second key; the second control unit decrypts the encrypted user identification information transmitted from the information delay transmission unit using the second key; 12. The biometric authentication system of claim 10 or 11.

[0092] (Appendix 13) The first key and the second key are a public key and a private key of a public key cryptosystem, respectively. 13. The biometric authentication system of any one of appendices 10 to 12.

[0093] (Appendix 14) the biometric authentication device transmits the reservation information input by the user to the service providing device; the service providing device refers to the reservation information and confirms the date and time when the service will be provided to the user; 14. The biometric authentication system of any one of appendices 10 to 13.

[0094] (Appendix 15) and after confirming the date and time at which the service will be provided to the user, the biometric authentication device acquires information as to whether the date and time will arrive within a predetermined time from the service providing device which has confirmed whether the date and time will arrive within a predetermined time. 15. The biometric authentication system of any one of appendices 10 to 14.

[0095] (Appendix 16) If the date and time arrives within a predetermined time, the biometric information matching unit starts matching the biometric information of the user. 16. The biometric authentication system of any one of appendices 10 to 15.

[0096] (Appendix 17) the biometric authentication device includes a display unit; When the reminder information is received, the display unit displays a message to the user prompting the user to present his or her own biometric information. 17. The biometric authentication system of any one of appendices 10 to 16.

[0097] (Appendix 18) the biometric authentication device includes a photographing unit, The photographing unit photographs a face of the user, the biometric information acquisition unit acquires facial image information of the user captured by the imaging unit; 18. The biometric authentication system of any one of appendices 10 to 17.

[0098] (Appendix 19) a first step of reading user identification information recorded on a recording medium; a second step of reading the biometric information of the user recorded on the recording medium; a third step of storing the retrieved user identity information; a fourth step of acquiring biometric information of the user from the user; a fifth step of comparing the biometric information of the user acquired in the fourth step with the biometric information of the user read in the second step; a sixth step of transmitting the user's identity information after matching the user's biometric information in the fifth step; a seventh step of providing a service to the user after verifying the user's identity; Equipped with Biometric authentication methods.

[0099] (Appendix 20) a step of encrypting the user's identification information read by the user information reading unit; 19. The biometric authentication method of claim 18.

[0100] (Appendix 21) generating a first key for encrypting the user's identity and a second key for decrypting the encrypted user's identity; transmitting the first key to the biometric authentication device; storing the second key; and a step of decrypting the encrypted user identification information transmitted from the information delay transmission unit using the second key. 21. The biometric authentication method according to claim 19 or 20.

[0101] (Appendix 22) issuing a public key and a private key of a public key cryptosystem as the first key and the second key, respectively; 22. The biometric authentication method according to any one of appendices 19 to 21.

[0102] (Appendix 23) transmitting reservation information input by the user to the service providing device; and referring to the reservation information to confirm the date and time when the service will be provided to the user. 23. The biometric authentication method according to any one of appendices 19 to 22.

[0103] (Appendix 24) a step of confirming the date and time when the service will be provided to the user, and then confirming whether the date and time will arrive within a predetermined time; and if the date and time arrives within a predetermined time, the biometric information matching unit starts matching the biometric information of the user. 24. The biometric authentication method of any one of appendices 19 to 23.

[0104] (Appendix 25) a step of confirming the date and time when the service will be provided to the user, and then confirming whether the date and time will arrive within a predetermined time; and if the date and time arrives within a predetermined time, the service providing device transmits reminder information to the biometric authentication device. 25. The biometric authentication method of any one of appendices 19 to 24.

[0105] (Appendix 26) a step of displaying a message to the user when the reminder information is received, prompting the user to submit his / her own biometric information; 26. The biometric authentication method of any one of appendices 19 to 25.

[0106] (Appendix 27) taking a picture of the user's face; acquiring face image information of the user captured by the image capturing unit, 27. The biometric authentication method of any one of appendices 19 to 26.

[0107] (Appendix 28) a first step of reading user identification information recorded on a recording medium; a second step of reading the biometric information of the user recorded on the recording medium; a third step of storing the retrieved user identity information; a fourth step of acquiring biometric information of the user from the user; a fifth step of comparing the biometric information of the user acquired in the fourth step with the biometric information of the user read in the second step; a sixth step of transmitting the user's identity information after matching the user's biometric information in the fifth step; a seventh step of providing a service to the user after verifying the user's identity; A program that causes a computer to execute the above.

[0108] (Appendix 29) a step of encrypting the user's identification information read by the user information reading unit; 28. The program described in Appendix 28.

[0109] (Appendix 30) generating a first key for encrypting the user's identity and a second key for decrypting the encrypted user's identity; transmitting the first key to the biometric authentication device; storing the second key; and a step of decrypting the encrypted user identification information transmitted from the information delay transmission unit using the second key. 29. The program according to claim 28 or 29.

[0110] (Appendix 31) a step of issuing a public key and a private key of a public key cryptosystem as the first key and the second key, respectively, by a computer; 31. The program of any one of appendices 28 to 30.

[0111] (Appendix 32) transmitting reservation information input by the user to the service providing device; and a step of confirming the date and time when the service is to be provided to the user by referring to the reservation information. 32. The program of any one of appendices 28 to 31.

[0112] (Appendix 33) a step of confirming the date and time when the service will be provided to the user, and then confirming whether the date and time will arrive within a predetermined time; and if the date and time arrives within a predetermined time, the biometric information matching unit starts matching the biometric information of the user. 33. The program of any one of appendices 28 to 32.

[0113] (Appendix 34) a step of confirming the date and time when the service will be provided to the user, and then confirming whether the date and time will arrive within a predetermined time; and if the date and time arrives within a predetermined time, the service providing device transmits reminder information to the biometric authentication device. 34. The program of any one of appendices 28 to 33.

[0114] (Appendix 35) and causing the computer to execute a step of displaying a message to the user prompting the user to submit his / her own biometric information when the reminder information is received. 35. The program of any one of appendices 28 to 34.

[0115] (Appendix 36) taking a picture of the user's face; and acquiring face image information of the user photographed by the photographing unit. 36. The program of any one of appendices 28 to 35. [Explanation of symbols]

[0116] 1.5 Biometric authentication system 10, 50 Biometric authentication device 11, 51 Service providing device 101, 502 Information delay transmission unit 102, 501 User information reading unit 103 First Control Section 104 Information Temporary Storage Department 105, 503 Biometric information acquisition unit 106, 504 Biometric information matching unit 107 Photography Department 108 Display section

Claims

1. a communication-capable connection to a service providing device that provides a service to a user; a user information reading unit that reads the user's identification information and biometric information recorded on a recording medium; an information delay transmission unit that stores the user's identification information read by the user information reading unit; a biometric information acquisition unit that acquires biometric information of the user from the user; a biometric information matching unit that matches the biometric information of the user acquired by the biometric information acquisition unit with the biometric information of the user read by the user information reading unit; Equipped with the information delay transmission unit transmits the user's identification information to the service providing device after the biometric information matching unit matches the user's biometric information; the service providing device provides the service to the user after verifying the user's identity information; Biometric authentication device.

2. A first control unit is provided, the first control unit encrypts the user's identification information read by the user information reading unit; The information delay transmission unit stores and transmits the user's identification information encrypted by the first control unit. The biometric authentication device according to claim 1 .

3. the service providing device issues a first key for encrypting the user's identification information and a second key for decrypting the encrypted user's identification information; the first control unit receives the first key from the service providing device; the first control unit encrypts the user identification information read by the user information reading unit using the first key; The biometric authentication device according to claim 2 .

4. the first key and the second key are a public key and a private key of a public key cryptosystem, respectively; The biometric authentication device according to claim 3 .

5. the biometric authentication device refers to the reservation information input by the user and transmits the reservation information to the service providing device, which confirms the date and time when the service will be provided to the user; The biometric authentication device according to claim 1 .

6. and after confirming the date and time at which the service will be provided to the user, acquiring information as to whether the date and time will arrive within a predetermined time from the service providing device that has confirmed whether the date and time will arrive within a predetermined time. The biometric authentication device according to claim 5 .

7. If the date and time arrives within a predetermined time, the biometric information matching unit starts matching the biometric information of the user. The biometric authentication device according to claim 6.

8. a service providing device that provides a service to a user; a biometric authentication device communicably connected to the service providing device; Equipped with The biometric authentication device a user information reading unit that reads the user's identification information and biometric information recorded on a recording medium; an information delay transmission unit that stores the user's identification information read by the user information reading unit; a biometric information acquisition unit that acquires biometric information of the user from the user; a biometric information matching unit that matches the biometric information of the user acquired by the biometric information acquisition unit with the biometric information of the user read by the user information reading unit; Equipped with the information delay transmission unit transmits the user's identification information to the service providing device after the biometric information matching unit matches the user's biometric information; the service providing device provides the service to the user after verifying the user's identity information; Biometric authentication system.

9. a first step of reading user identification information recorded on a recording medium; a second step of reading the biometric information of the user recorded on the recording medium; a third step of storing the retrieved user identity information; a fourth step of acquiring biometric information of the user from the user; a fifth step of comparing the biometric information of the user acquired in the fourth step with the biometric information of the user read in the second step; a sixth step of transmitting the user's identity information after matching the user's biometric information in the fifth step; a seventh step of providing a service to the user after verifying the user's identity; Equipped with Biometric authentication methods.

10. a first step of reading user identification information recorded on a recording medium; a second step of reading the biometric information of the user recorded on the recording medium; a third step of storing the retrieved user identity information; a fourth step of acquiring biometric information of the user from the user; a fifth step of comparing the biometric information of the user acquired in the fourth step with the biometric information of the user read in the second step; a sixth step of transmitting the user's identity information after matching the user's biometric information in the fifth step; a seventh step of providing a service to the user after verifying the user's identity; A program that causes a computer to execute the above.

Citation Information

Patent Citations

  • System, authentication terminal, authentication terminal control method, and storage medium

    WO2023053268A1