Information processing method and information processing system
The server system authenticates users by combining pattern codes with time displays and stringent time/tolerance checks, accurately verifying the location of image capture to prevent fraudulent access.
Patent Information
- Application Number
- JP2024065048
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-13
- Publication Date
- 2025-10-24
AI Technical Summary
Existing two-dimensional code authentication methods struggle to accurately distinguish between users accessing a server system from a specific location and those using a copied image from a nearby location, especially in areas where GPS signals are unavailable, leading to potential fraudulent access.
A server system that authenticates users by simultaneously photographing a pattern code embedded with an authentication code and a time display, ensuring the time difference between capture and transmission is within a predetermined tolerance, and optionally using additional positional relationships or image comparisons to verify the location of image capture.
This method significantly enhances authentication accuracy by differentiating between legitimate users at the specific location and those accessing from other locations using copied images, thereby reducing fraudulent access.
Smart Images

Figure 2025161669000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to information processing using a pattern code in which information is embedded so as to be optically readable. [Background technology]
[0002] QR Code (registered trademark), a well-known two-dimensional code, has recently become readable by most camera-equipped communication terminals and is widely used as a tool for accessing web information. Furthermore, this two-dimensional code is used for a wide range of purposes, including providing various services, managing personnel activities, managing goods in circulation, and verifying their authenticity. The following five patent documents are listed as documents disclosing information processing for these purposes, and the contents of each are briefly explained.
[0003] Patent Document 1 discloses an information processing system that places a two-dimensional code embedded with information about the event at an event venue, and enables a communication terminal device that reads the information in the two-dimensional code to send a request including the read information to a server, thereby enabling the downloading of an AR (augmented reality) sticker that can be combined with an image taken within the venue from the server. Patent Document 1 further describes that a plurality of AR stickers linked to location information and a distribution period are registered on the server, and from these, stickers that match the location information and current date and time of the communication terminal device that sent the request are extracted and sent to the communication terminal device.
[0004] Patent Document 2 describes a method in which a two-dimensional code embedded with an authentication code for a predetermined activity area is placed within the activity area, and the authentication code read from the two-dimensional code and the time of reading, etc. are transmitted from a communication terminal device that captures an image of the area including the two-dimensional code and its surroundings to a server, and when these match the authentication code and time data registered in the server, the information received from the communication terminal device is stored in the server as an activity record. Patent Document 2 also describes that an image generated by capturing an image of the two-dimensional code with the communication terminal device is compared with an image registered in the server, and the comparison result is stored in the server.
[0005] Patent Document 3 describes a method in which a two-dimensional code containing embedded information such as a URL, store name, and product name, and a specific mark are affixed to a product for which points are to be awarded, and a communication terminal device with an embedded application simultaneously photographs the two-dimensional code and mark, and, on the condition that the mark matches a pre-registered image, reads the two-dimensional code information from the photographed image and transmits the read data to a server, which then processes the information to award points. Patent Document 3 further describes that by including date and time information obtained from an internal clock and location information obtained from a GPS in the transmission from the communication terminal device, it is possible to vary the amount of points awarded depending on the date and time on the server and to confirm the location where the photo was taken.
[0006] Patent Document 4 describes how, in order to prevent fraudulent applications to a system that accepts applications for campaigns using receipts from product purchases, a two-dimensional code embedded with the time of sale is displayed on a display device within the store, and the time read from the two-dimensional code is transmitted to a server from a customer's smartphone that reads the two-dimensional code.The customer then photographs a receipt issued by the store with their smartphone, and when the captured image is transmitted to the server, the time extracted from the image is compared with the time read from the two-dimensional code and transmitted to the server, and it is determined whether the difference between the two is within a specified time.
[0007] Patent document 5 describes a method of printing a color two-dimensional code containing two types of colors (metameric colors) that appear the same color under natural light sources such as sunlight or fluorescent lights but appear different colors when observed under a special light source or through a filter on an object to be authenticated, and then processing an image of the color two-dimensional code photographed under lighting that allows the metamerism to be observed to determine authenticity. [Prior art documents] [Patent documents]
[0008] [Patent Document 1] Patent No. 7364757 [Patent Document 2] Patent No. 7107560 [Patent Document 3] Patent No. 6101843 [Patent Document 4] Japanese Patent Application Laid-Open No. 2018-101189 [Patent Document 5] Japanese Patent Application Laid-Open No. 2012-141729 Summary of the Invention [Problem to be solved by the invention]
[0009] Two-dimensional codes can be used to provide special information, service points, and other benefits only to people in specific locations, such as event venues and entertainment facilities. In a server system used for this purpose, on the premise that two-dimensional codes with embedded access information are deployed only in specific locations, the system performs the same process as described in Patent Document 1, that is, acquires location information from a communication terminal device that reads the two-dimensional code and accesses the server, and determines that the communication terminal device has legitimate access authority if the location information matches the registered information.
[0010] However, with the GPS location information used in general information processing, it is difficult to accurately distinguish between a specific location and nearby locations. Even if a location-specific authentication code is embedded in a 2D code placed at a specific location, it is easy to photograph and transmit the 2D code. Therefore, if an image of the 2D code photographed by a person at a specific location is transmitted to people waiting nearby without entering the location, those people may access the system from the display screen or printout of the image and fraudulently receive benefits. Furthermore, if the specific location is located in a place where GPS signals cannot reach, such as underground, authentication using GPS location information becomes impossible.
[0011] The invention described in Patent Document 2 not only compares images of a range including a two-dimensional code placed in a specific location and its surroundings, but also determines whether the time the two-dimensional code is read falls within the range of registered time data. However, even with this method, there is a risk that the captured image may be sent outside the specific location, allowing unauthorized access from that outside location.
[0012] The invention described in Patent Document 3 also assumes that the server will be accessed from within a store, and describes including GPS location information in the transmission from the communication terminal device. However, even with this method, after the two-dimensional code and mark are photographed, the captured image may be sent to someone in a location near the store, which could lead to access from near the store.
[0013] The invention described in Patent Document 4 ensures that only those who shop at a store are granted the privilege of qualifying for a campaign. The store displays a two-dimensional code representing the time of sale, prompting the purchaser to scan the code. The purchaser is also provided with a receipt printed with the time of sale close to the time of the code scan, allowing the two times to be verified by a server. However, even with this method, it is possible for a purchaser to save an image of the two-dimensional code or receipt and use it to repeatedly enter a campaign. This could potentially lead to fraudulent entries by individuals other than the purchaser. To prevent this problem, the store requires the purchaser to access the server system within the store immediately after purchase, preventing access from outside the store. However, paragraph 0039 of Patent Document 4 states, "The receipt does not need to be photographed immediately after the transaction," and does not indicate the technical idea of requiring access from within the store.
[0014] In view of the above problems, the present invention aims to improve the accuracy of authentication for access using a pattern code, so that it is possible to distinguish between a user who photographs a pattern code such as a two-dimensional code at a specific location and accesses a server system from that specific location, and a user who accesses the server system from another location using a copy of the photographed image of the pattern code. [Means for solving the problem]
[0015] The information processing according to the present invention is carried out by a server system in which an authentication code associated with a specific location or information linked to the authentication code is registered, and a communication terminal device with a photographing function, and is based on the premise that a pattern code in which the above authentication code is embedded so as to be optically readable, and a time display showing the current time, are positioned in a specific location in such a positional relationship that they can be photographed simultaneously.
[0016] The pattern code can be a two-dimensional code such as a QR code (registered trademark) or a one-dimensional barcode. The authentication code embedded in this pattern code is code information that can uniquely derive the corresponding location, such as an identification code assigned to a specific location, an encrypted code obtained by encrypting the identification code according to a predetermined rule, or a random code generated using random numbers and linked to the identification code. The authentication code can also be registered in the server system, but if the authentication code is obtained by encrypting the registered information, key information for decrypting the original information from the authentication code may be registered instead of the authentication code itself.
[0017] It is desirable to use a portable device such as a smartphone or tablet terminal as the communication terminal device, but depending on the purpose of use of the present invention, a relatively large device such as a personal computer connected to a camera can also be used.The server system is an information processing system consisting of one or more computers, and is configured to be able to communicate with an unspecified number of communication terminal devices via the Internet or a dedicated communication line.
[0018] In a first information processing method of the present invention, when a communication terminal device receives an operation to access a server system while taking a photograph using its photography function, or extracts an image of a form that matches a pattern code from the image generated by the photography, the communication terminal device transmits the image generated after the operation or extraction to the server system together with time data representing the time recognized by the clock function of the device after the time of its generation, and the server system that receives this transmission performs information processing to authenticate that the received image was sent from a communication terminal device with legitimate access authority. The communication terminal recognizes the time at any time between the time the image is generated and the time the image is transmitted to the server system.
[0019] If a pattern code and a time display having the relationship described above are installed in a specific location and a communication terminal device is in a communication environment where it can transmit data to a server system, a communication terminal device that simultaneously photographs the pattern code and the time display at the specific location can transmit the image generated by the photograph to the server system immediately after the photograph is taken. It is believed that the difference between the time the photograph and transmission are taken by the communication terminal device and the time read from the time display in the image generated by the photograph will be extremely small.
[0020] On the other hand, if an image taken at a specific location is sent to a device other than the server system, and the communication terminal device that photographed the screen on which the image was displayed or the printout of the image accesses the server system, the difference between the time the image was taken or sent and the time indicated by the time display in the image is likely to be significantly larger than the difference that would occur if the image were taken at a specific location.
[0021] Based on the above considerations, in the first information processing method of the present invention, the prerequisite conditions for the above-mentioned authentication are that the first condition, that the image transmitted from the communication terminal device contains a pattern code embedded with an authentication code that matches the information registered in the server system, and the second condition, that the image transmitted from the communication terminal device contains an image representing the time, and the difference between the time represented by the image and the time represented by the time data transmitted with the image is within a predetermined tolerance, are both met.The server system performs information processing to determine whether these prerequisite conditions are met, and determines whether to perform the above-mentioned authentication based on the result of the determination.
[0022] In the process of determining whether or not to authenticate, authentication may be determined to be possible only if the above-mentioned essential conditions are met, but it is also possible to add conditions such as those shown in the first or second embodiment below to determine whether or not to perform authentication.
[0023] In the first embodiment, a two-dimensional pattern that is not an element of a pattern code deployed in a specific location is placed inside or outside the pattern code, and a numerical value representing the relative positional relationship of the two-dimensional pattern with respect to the pattern code is registered in a server system.
[0024] Furthermore, the server system of the first embodiment is provided with a function for extracting the two-dimensional pattern from the image transmitted from the communication terminal device, obtaining a numerical value representing the relative positional relationship of the two-dimensional pattern to the pattern code in the received image, and comparing the numerical value with the registered numerical value, and an additional condition for authentication is that the result of the comparison using this function is that the difference between the numerical value obtained for the two-dimensional pattern in the image and the registered numerical value is within a predetermined tolerance range.
[0025] For example, as a preliminary step, a two-dimensional pattern with a distinctive appearance is placed in a position where it can be photographed simultaneously with a pattern code or a time display at a specific location, and these are photographed using a standard communication terminal device.The distance and angle of one or more feature points of the two-dimensional pattern in the generated image relative to a specific position of the pattern code are calculated and registered in the server system.For an image received from a user's communication terminal device, the distance and angle of the feature points of the two-dimensional pattern relative to the pattern code can be calculated using the same method as above, and by comparing these with the registered values, it can be determined with a high degree of accuracy whether the received image was obtained by photographing a pattern code at a specific location.
[0026] By adding the above conditions, even if a photograph of the same pattern code and fake time display combination as those deployed in a specific location is taken at a location other than the specific location, and the resulting image is sent to a server system along with the time data at the time of or immediately after the photograph, the communication terminal device that sent the image will not be recognized as having legitimate access rights unless an image containing a two-dimensional pattern with the same relative positional relationship as the numerical values registered in the server system is sent.
[0027] In the server system of the second embodiment, an image of at least a part of an area of a predetermined size surrounding a pattern code placed at a specific location is registered. The server system is further provided with a function for comparing the registered image with an image transmitted from a communication terminal device, and a condition for authentication is added that the result of the comparison by this function is that an image matching the registered image is included in the received image.
[0028] In the second embodiment, by distributing a pattern code in an area containing a two-dimensional pattern that can be identified by some characteristic and registering an image containing the two-dimensional pattern in the server system, it is possible to determine with high accuracy whether an image transmitted from a communication terminal device was taken at a specific location. Therefore, even if a combination of the same pattern code and a fake time display as those deployed at a specific location is photographed at a location other than the specific location and the resulting image is transmitted to the server system together with the time data at the time of or immediately after the photograph, the communication terminal device that transmitted the image will not be recognized as having legitimate access rights unless it transmits an image containing characteristics that match the image for verification registered in the server system.
[0029] As described above, in the first and second embodiments, conditions are added to increase the accuracy of determining whether the image received from the communication terminal device was generated at a location where the pattern code is deployed, thereby further increasing the accuracy of authentication.
[0030] In the first information processing method, when the authentication code and the time display are displayed as an image and a dedicated terminal device for displaying the image is installed in a specific location, the reliability of authentication in the server system can be further improved by using the dedicated terminal device to control the operation of the communication terminal device of the user in the specific location. .
[0031] In one embodiment using a dedicated terminal device, the dedicated terminal device displays predetermined text information in response to access from the communication terminal device. After displaying the text information, the dedicated terminal device receives information from the communication terminal device that matches the text information. In response to this, the dedicated terminal device displays a pattern code in which information including an authentication code is optically embedded so as to be optically readable, a time display area showing the current time, and transmits a notification to the communication terminal device permitting photography. Upon receiving this notification, the communication terminal device photographs the screen of the dedicated terminal device and transmits the image including the pattern code and the time display area, as well as the time data, to the server system, thereby receiving the authentication described above.
[0032] In another embodiment using a dedicated terminal device, the dedicated terminal device displays the above-mentioned pattern code and time display area without requiring the display of text information, and has a communication terminal device photograph the display screen to read the pattern code information and transmit at least a portion of the read information to the dedicated terminal device. In this case, in response to receiving code information that matches the pattern code being displayed from the communication terminal device under the above-mentioned display state, the dedicated terminal device transmits a notification permitting the transmission of an image generated by the communication terminal device to the server system. By receiving permission from the dedicated terminal device, the communication terminal device becomes able to generate and transmit an image to be transmitted to the server system.
[0033] In either of the above two embodiments, the current time displayed in the time display area can be obtained from the clock function of the dedicated terminal device.
[0034] According to the above-mentioned dedicated terminal device, only communication terminal devices that are able to transmit information that matches the information displayed on the screen of the dedicated terminal device can be authorized to generate images to be transmitted to the authentication server and transmit those images to the server, thereby preventing with a high degree of certainty fraudulent acts of accessing the authentication server from a location other than where the dedicated terminal device is deployed and obtaining authorization.
[0035] In a second information processing method of the present invention, the communication terminal device not only takes a photograph but also reads the pattern code and the image representing the time in the image generated by the photograph, and transmits the read information obtained by each reading process to the server system together with time data representing the time recognized by the clock function of the communication terminal device after the image to be read was generated.
[0036] Even with the above method, if a pattern code and a time display are photographed at a specific location, and the code and time are read immediately after the photograph and each read information is sent to a server system, there will not be a significant difference between the time of reading or transmission and the time represented by the time data.In contrast, if read information obtained by a reading process using a display screen or printout of an image sent from a specific location is sent to a server system, it is thought that there will be a considerable difference between the time of reading or transmission and the time represented by the time data.
[0037] Therefore, the server system of the second information processing method requires that the first condition that the read information of the pattern code transmitted from the communication terminal device contains an authentication code that matches the information registered in the server system, and the second condition that the difference between the time indicated by the read information of the time transmitted from the communication terminal device and the time indicated by the time data transmitted together with the read information is within a predetermined tolerance, be satisfied as essential conditions for authenticating that each read information has been transmitted from a communication terminal device with legitimate access authority. The server system executes information processing to determine whether the above essential conditions are met, and determines whether to perform the authentication based on the determination result.
[0038] In the second information processing method, if the communication terminal device is made to send the image used to read the pattern code and time to the server system, the server system can add conditions similar to those in the first or second embodiment of the first information processing method to the authentication conditions, thereby increasing the accuracy of authentication.
[0039] The third information processing method of the present invention is executed by a server system in which an authentication code associated with a specific location or information linked to the authentication code is registered, a dedicated terminal device that is deployed at the specific location to display a pattern code in which the authentication code is embedded so that it can be optically read, and a communication terminal device that has a photographing function.
[0040] The server system of the third information processing method transmits a plurality of authentication codes with different contents to the dedicated terminal device sequentially or all at once.
[0041] The dedicated terminal device converts code information, including an authentication code received from the server system and time data based on the time recognized by the device's clock function, into a pattern code, and displays the pattern code obtained by the conversion on a display unit every time a predetermined time has elapsed or whenever the time for display arrives.
[0042] The communication terminal device, while taking a photograph using the photographing function, extracts a pattern code of the same type as the pattern code from the image generated by the photographing and reads the content of the pattern code, and then transmits the read information to the server system. This transmission can include time data indicating the time recognized by the communication terminal device using its own clock function after the time of reading.
[0043] The server system that receives the transmission executes information processing to determine whether or not the first condition that the transmitted read information contains an authentication code that matches the information registered in the server system and the second condition that the difference between the time indicated by the information indicating the time included in the read information and the time indicated by the time data transmitted together with the read information is within a predetermined tolerance are both satisfied, as these are essential conditions for authenticating that the read information has been transmitted from a communication terminal device with legitimate access authority, and then determines whether or not to perform the authentication based on the result of the determination.
[0044] If the transmitted information from the communication terminal device does not contain time data, the second condition is that the read information contains information representing a time whose difference from the time the read information was received from the communication terminal device is within a predetermined tolerance range.
[0045] In the third information processing method, only a pattern code is displayed on the dedicated terminal device for authentication purposes, but this pattern code includes time data based on the time recognized by the dedicated terminal device's own clock function. Therefore, if a pattern code converted from code information including time data representing the time recognized by the clock function is displayed immediately after the conversion, the time immediately before the display can be read from the pattern code. Furthermore, if a pattern code converted from code information including time data representing a time a predetermined time later than the time recognized by the clock function is displayed at the time represented by the time data, the start time of the display can be read from the pattern code.
[0046] With the pattern code configured as described above, if a communication terminal device that reads a pattern code displayed on a dedicated terminal device immediately transmits the read information to a server system after reading it, it is considered that the difference between the time indicated by the time data included in the read information and the time indicated by the time data transmitted together with the read information (or the time when the server system received the read information) will be very small. In contrast, if the pattern code displayed on a dedicated terminal device is transmitted to a location distant from a specific location, and the read information of the pattern code is transmitted from that location to the server system, it is considered that a considerable difference will occur between the two types of time. Therefore, the server system can detect the latter case by determining that the second condition is not met, and can reject authentication.
[0047] Furthermore, the pattern code displayed on the dedicated terminal device is not constant, but the content of the pattern code is updated over time, or each time a display that is limited to a specified time period is made. Therefore, even if an attempt is made to access the server system using a pattern code that has had its time data portion tampered with at a certain point in time, the server system can determine that the first condition above is not met and refuse authentication.
[0048] The server system can also transmit to the dedicated terminal device code information including the authentication code and time data indicating the scheduled display time, or an image of a pattern code in which the code information is embedded so that it can be optically read. In this case, multiple pieces of code information or multiple images can be transmitted sequentially or all at once.
[0049] The dedicated terminal device described above displays the pattern code based on the information received from the server system on the display unit at the time indicated by the time data embedded in the pattern code, thereby updating the content of the displayed two-dimensional code each time the scheduled display time set by the server system arrives.
[0050] A server system (hereinafter referred to as the "first server system") implementing the first information processing device of the present invention is provided with: a storage means for registering an authentication code associated with a specific location or information linked to the authentication code; a reception means for receiving, from any communication terminal device having a photographing function, information transmission including an image generated by the device by photographing and time data representing the time recognized by the device using its own clock function after the time of generation; a code reading means for extracting a pattern code in which predetermined code information is embedded so that it can be optically read from the image in the information received by the reception means and performing a reading process on the code; a time reading means for extracting an image representing the time from the image and reading the time; a first comparison means for comparing the code information read by the code reading means with information registered in the storage means; and a second comparison means for comparing the time read by the time reading means with the time represented by the time data in the information received by the reception means.
[0051] Furthermore, the first server system is provided with an authentication means which determines whether or not a first condition, that is, that the above-mentioned code information is determined to contain an authentication code that matches the information registered in the storage means through comparison by the first comparison means, and a second condition, that is, that the difference between the two types of time is determined to be within a predetermined tolerance through comparison by the second comparison means, is met as a necessary condition for authenticating that the information received by the receiving means has been sent from a communication terminal device with legitimate access authority, and which determines whether or not to perform the above-mentioned authentication based on the determination result.
[0052] Furthermore, the present invention can provide an information processing system having an authentication server according to the above server system and a dedicated terminal device according to the following first or second aspect.
[0053] The first form of dedicated terminal device has a code receiving means that receives from an authentication server an image of the authentication code or a pattern code in which the authentication code is embedded so that it can be optically readable, and in response to receiving access from any communication terminal device that has a photographing function, displays specified character information on the display unit, and in response to receiving information that matches the character information from the communication terminal device, displays on the display unit a combination of the pattern code based on the information received by the code receiving means and a time display area that shows the current time, and sends a notification to the communication terminal device that permission to photograph is granted.
[0054] The dedicated terminal device of the second form has a code receiving means similar to that of the first form, and displays on a display unit a combination of a pattern code based on information received by the code receiving means and a time display area showing the current time, and in response to receiving information that matches the pattern code being displayed from any communication terminal device having a photographing function under that display state, sends a notification to that communication terminal device permitting it to send an image generated by photographing with that device to an authentication server.
[0055] Furthermore, the first server system can be provided with a configuration for implementing the first and second embodiments of the first information processing method.
[0056] A server system (hereinafter referred to as the "second server system") for implementing the second information processing method of the present invention is provided with: a storage means for registering an authentication code associated with a specific location or information linked to the authentication code; a reception means for receiving, from any communication terminal device having a photographing function, information including read information of a pattern code and time read by the device from an image generated by the device through photographing, and time data representing the time recognized by the communication terminal device using its own clock function after the image was generated; a first comparison means for comparing the read information of the pattern code in the information received by the reception means with information registered in the storage means; and a second comparison means for comparing the time based on the read information of the time in the information received by the reception means with the time represented by the time data in the received information.
[0057] Furthermore, the second server system is provided with an authentication means which determines whether or not the first condition, that is, that the first comparison means has determined that the read information of the pattern code contains an authentication code that matches the information registered in the storage means, and the second condition, that the second comparison means has determined that the difference between the two types of time is within a predetermined tolerance, are both met as necessary conditions for authenticating that the information accepted by the accepting means has been sent from a communication terminal device with legitimate access authority, and which determines whether or not to perform the authentication based on the determination result.
[0058] The first server system can also accept transmission of an image generated by photography from a communication terminal device along with read information of the pattern code read from the image. In this case, the first comparison means can confirm that the read information transmitted from the communication terminal device matches the information read by the code reading means, and then compare the read information with the information registered in the storage means.
[0059] The second server system may also be provided with a means for accepting transmission of images used in the reading process from a communication terminal device, and may be added with a configuration for implementing a method conforming to the first and second embodiments of the first information processing method.
[0060] The present invention further provides the following two types of information processing systems to which the third information processing method is applied, as information processing systems including a dedicated terminal device equipped with a display unit and deployed at a predetermined specific location, and an authentication server having a storage means for registering an authentication code associated with the specific location or information linked to the authentication code.
[0061] The authentication server of the information processing system of the first embodiment includes a code generating means that repeatedly generates a different authentication code for each location whose information is registered in the storage means, and links the generated authentication code to the information registered in the storage means in association with the location, and a code transmitting means that sequentially or collectively transmits, for each location, the multiple authentication codes generated by the code generating means to a dedicated terminal device installed at the location. The dedicated terminal device includes a display control means that converts code information, including the authentication code received from the authentication server and time data based on the time recognized by its own clock function, into a pattern code and displays the pattern code obtained by the conversion on a display unit, every time a predetermined time has elapsed or whenever the timing for display arrives.
[0062] The authentication server of the information processing system of the second aspect comprises a code generating means similar to that of the first aspect, and a code transmitting means for transmitting, for each location where information is registered in the storage means, a plurality of code information pieces each having different contents of an authentication code and time data indicating a scheduled display time, or a plurality of images each representing a pattern code in which such code information pieces are embedded so as to be optically readable, to a dedicated terminal device provided at that location, sequentially or all at once. The dedicated terminal device comprises a code receiving means for receiving the above transmissions from the authentication server, and a display control means for displaying, on a display unit, the pattern code based on the information received by the code receiving means at the time indicated by the time data embedded in the pattern code.
[0063] Furthermore, as a configuration common to the first and second forms, the authentication server is equipped with: a receiving means for receiving, from any communication terminal device having a photographing function, transmission of read information of the pattern code read from an image generated by the device by photographing the pattern code (which may also include time data indicating the time recognized by the communication terminal device using its own clock function after the time of reading); a first comparison means for comparing the part of the read information received by the receiving means that corresponds to the authentication code with the authentication code registered in the storage means; a second comparison means for comparing the time indicated by the part of the read information that corresponds to the time data with the time indicated by the time data transmitted together with the read information or the time at which the read information was received; and an authentication means for determining, based on the determination results of the first and second comparison means, whether to authenticate the read information received by the receiving means as having been transmitted from a communication terminal device with legitimate access authority.
[0064] The above authentication means determines whether or not the necessary conditions for the above authentication are met, namely, the first condition that the first comparison means has determined that the read information contains an authentication code that matches the information registered in the storage means, and the second condition that the second comparison means has determined that the difference between the two types of time is within a predetermined tolerance range.
[0065] According to the first aspect, the dedicated terminal device can update the content of the displayed pattern code by converting code information, including the authentication code received from the authentication server and the latest time data obtained by the clock function of the dedicated terminal device, into a pattern code every time a predetermined time has elapsed or at any timing. The authentication code may be transmitted from the authentication server in accordance with the timing of display, or may be transmitted at an earlier time and stored in the dedicated terminal device.
[0066] According to the second aspect, the dedicated terminal displays a pattern code based on information received in advance from the authentication server at the time indicated by the time data embedded in the pattern code, thereby updating the content of the pattern code at each scheduled display time determined by the authentication server. [Effects of the Invention]
[0067] According to the present invention, it is possible to distinguish with high accuracy between a user who photographs a pattern code placed at a specific location and accesses a server system immediately after photographing, and a user who accesses the server system from another location using a copy of an image photographed at the specific location.
[0068] Furthermore, an end user who transmits an image or read information for authentication to the server system can transmit the information necessary for authentication processing to the server system simply by aligning the camera of their communication terminal device so that the combination of the pattern code and the time display, or the pattern code with the authentication code and time data embedded therein, is within the field of view of the camera, thereby enabling transmission to the server system. Thus, the information necessary for authentication can be transmitted to the server system without placing a particularly large burden on the end user. [Brief explanation of the drawings]
[0069] [Figure 1] 1 is a diagram showing an overview of an information processing system to which the present invention is applied; [Figure 2] 4A to 4C are diagrams showing an example of transition of a screen of a communication terminal device in the first embodiment. [Figure 3] FIG. 10 is a diagram showing an example of a combination of a two-dimensional code and a time display. [Figure 4] FIG. 10 is a diagram showing another example of a combination of a two-dimensional code and a time display. [Figure 5] FIG. 10 is a diagram showing another example of a combination of a two-dimensional code and a time display. [Figure 6] FIG. 10 is a diagram showing another example of a combination of a two-dimensional code and a time display. [Figure 7] FIG. 10 is a functional block diagram of a communication terminal device in which a request application and a game application are installed. [Figure 8] FIG. 2 is a functional block diagram of an authentication server. [Figure 9] 10A and 10B are diagrams illustrating examples of information registered in an area information storage unit and a history information storage unit of the authentication server. [Figure 10] 1A and 1B are a functional block diagram of a game server and a diagram showing an example of information registered in a character image storage unit. [Figure 11] 10 is a flowchart showing a processing procedure of a request application. [Figure 12] 10 is a flowchart showing a processing procedure of an authentication server. [Figure 13] 10 is a flowchart showing the corresponding processing procedures of a game application and a game server. [Figure 14] FIG. 10 is a functional block diagram of an authentication server used in the second embodiment. [Figure 15] 10A and 10B are diagrams showing examples of combinations of two-dimensional codes and time indicators used in the second embodiment, and examples of calculation of feature amounts that represent the relative positional relationship of the outline pattern of the time indicator with respect to the two-dimensional code. [Figure 16] 4 is a diagram showing an example of an external arrangement of a two-dimensional pattern and an example of calculating a feature amount that indicates the relative positional relationship of the two-dimensional pattern with respect to the two-dimensional code, for a two-dimensional code having the same form as that of FIG. 3. FIG. [Figure 17] FIG. 4 is a diagram showing another example of external arrangement of a two-dimensional pattern and calculation of feature amounts for a two-dimensional code having the same form as that of FIG. 3. [Figure 18] FIG. 4 is a diagram showing another example of external arrangement of a two-dimensional pattern and calculation of feature amounts for a two-dimensional code having the same form as that of FIG. 3. [Figure 19] FIG. 10 is a diagram illustrating an example of information registered in a feature storage unit of an authentication server according to a second embodiment. [Figure 20] 10 is a flowchart showing a procedure of a third verification process in the authentication server according to the second embodiment. [Figure 21] 13A to 13C are diagrams showing an example of transition of a screen of a communication terminal device in the third embodiment. [Figure 22] FIG. 22 is a sequence diagram showing the main flow of processing involving screen transitions in FIG. 21. [Figure 23] 13A to 13C are diagrams showing an example of transition of a screen of a communication terminal device in the fourth embodiment. [Figure 24] FIG. 24 is a sequence diagram showing the main flow of processing involving screen transitions in FIG. 23. [Figure 25] FIG. 25 is a sequence diagram illustrating an example in which a process for enhancing security is added to the process procedure of FIG. 24. [Figure 26] FIG. 26 is a sequence diagram showing an example in which the process of FIG. 25 is applied to a case in which only a two-dimensional code in a general format is displayed without combining a time display device. [Figure 27] FIG. 10 is a diagram illustrating the principle of generating a two-dimensional code used in the fifth embodiment. [Figure 28] FIG. 13 is a sequence diagram showing the flow of main processes in the fifth embodiment. [Figure 29] 29 is a flowchart showing a specific processing procedure of the matching process in FIG. 28. [Figure 30] FIG. 1 is a diagram showing an example of the structure of a two-dimensional code containing text used for distribution management. [Figure 31] 10A and 10B are diagrams illustrating an example of calculating a feature amount that indicates the relative positional relationship of a character portion in a two-dimensional code containing characters with respect to an encoded portion. [Figure 32] FIG. 10 is a functional block diagram showing an example of the configuration of a distribution management server using a two-dimensional code containing text. DETAILED DESCRIPTION OF THE INVENTION
[0070] <Basic embodiment> FIG. 1 shows the configuration of one embodiment of an information processing system to which the present invention is applied. This information processing system provides a service of providing images of rare characters to users of online game application software, and its main components are a game server system 3 (hereinafter abbreviated as "game server 3") that provides the online game environment, and an authentication server system 1 (hereinafter abbreviated as "authentication server 1") that receives image requests from users' communication terminal devices 2 (hereinafter abbreviated as "user terminals 2"). Although not shown in the figure, this information processing system also includes communication terminal devices (personal computers, smartphones, tablet terminals, etc.; hereinafter, these will be collectively referred to as "administrator terminals") used by administrators of each server system 1 and 3.
[0071] The two server systems 1 and 3 are each comprised of one or more computers and software installed on them. Each server system 1 and 3 is operated by a different business operator, and the authentication server 1 can be linked to a server system other than the game server 3.
[0072] A user can communicate with each of the server systems 1 and 3 using a user terminal 2 (in this embodiment, a smartphone) with a photographing function. Application software for online games (hereinafter referred to as a "game app") and application software for sending requests to the authentication server 1 (hereinafter referred to as a "request app") are installed in advance on the user terminal 2.
[0073] In this embodiment, the condition for providing the image is that the user enters a location (a real space, not a virtual space) determined by the service provider and sends a request from that location to the authentication server 1. Multiple locations are set for providing the image (hereinafter, each location will be referred to as an "area" in accordance with the notation in the figure), and a different character image is provided for each area. The image of each character is registered in the game server 3.
[0074] The authentication server 1 performs a matching process on the request sent from the user terminal 2 according to the procedure described below, and determines whether or not to permit the request based on the result of the matching. If the determination result is that the request is permitted, the authentication server 1 sends a permission notice to the user terminal 2. The user terminal 2 that has received this permission notice is then able to access the character image download page, and can download the image file by accessing it.
[0075] In each area, a two-dimensional code in which information specific to the area is embedded is placed as a medium for transmitting the above request to the authentication server 1.
[0076] The following describes in detail five embodiments applied to the information processing system described above. Unless otherwise specified, the configuration and information processing content common to each embodiment will be described in the first embodiment. In the second and subsequent embodiments, the configuration common to the first embodiment will be referred to by the same reference numerals, and the description of that configuration will be omitted or will be limited to a brief description.
[0077] <First Example> Figure 2 shows an example of the screen transitions that occur when a user uses a user terminal 2 that has a game app and a request app installed to receive the above services. Screens (A) through (D) in the figure are screens for the request app, and (E) and (F) are screens for the game app.
[0078] The request app screen first displays a screen (Fig. 2(A)) that requests the user to photograph a two-dimensional code. When the user holds the user terminal 2 over the two-dimensional code at the site so that the two-dimensional code fits within the frame w on the screen, the screen changes to a state in which a request transmission button 20 is displayed, as shown in Fig. 2(B). When the user operates this button 20, a still image is captured, and a request including the captured image is sent to the authentication server 1.
[0079] During the period from the above transmission until a reply is received from the authentication server 1, a standby screen such as that shown in FIG. 2(C) is displayed on the user terminal 2. After that, when a permission notification is received from the authentication server 1, the screen changes to that shown in FIG. 2(D). When the user operates the download button 21 on this screen, the screen automatically switches to the game app screen and the image download begins (FIG. 2(E)). When the download is complete, the screen changes to display the downloaded image (FIG. 2(F)).
[0080] The two-dimensional code used in the above information processing is combined with information indicating the current time. This combination is placed at one or more locations within the service area.
[0081] Figure 3 shows a combination of a two-dimensional code and time information. In the following figures showing two-dimensional codes, the finder patterns (characteristic patterns for identifying the position and orientation of the two-dimensional code) provided at the three corners of the two-dimensional code are indicated by the symbols fp1, fp2, and fp3.
[0082] The two-dimensional code 5 in the example of Figure 3 is based on Frame QR (registered trademark) from Denso Wave Inc., and is printed on the surface of a frame-shaped panel 50 with a rectangular hole cut out in the center. Inside the rectangular hole 51 in this panel 50 is placed a time display 6 that shows the current time.
[0083] The time display 6 is a digital clock that can accurately display the current time down to the second, such as a Wi-Fi clock with a time setting function using NTP (Network Time Protocol). As in this embodiment, it is desirable for the time display 6 to also display the year, month, and date.
[0084] In the first embodiment, the combination of the two-dimensional code 5 and time display 6 shown in Figure 3 is used, but the set of two-dimensional code 5 and time display 6 is not limited to the above configuration, and for example, the above two-dimensional code 5 may be printed on a rectangular panel without holes (a sticker of the two-dimensional code 5 may also be attached), and the above time display 6 may be attached to the blank space in the center. Furthermore, the set of the two-dimensional code 5 and the time display 6 can be replaced with the configurations shown in FIGS.
[0085] In the example of Figure 4, a two-dimensional code 5 in the same format as Figure 3 is displayed on the screen 52 of a display device, and a display area 60 for the time and date is provided in the blank space in the center, and the time and date within this area change in real time. This corresponds to an image in which the two-dimensional code 5 and time display 6 of Figure 3 are integrated.
[0086] The area 60 that displays the time in the example of FIG. 4 will also be referred to as the "time display 6" below. A tablet device can also be used to display Figure 4. Images created on a personal computer or other device can also be projected onto a wall using a projector.
[0087] In the example of Figure 5, a panel 53 (which may be a sheet of paper or the like) on which a two-dimensional code 5N of a general configuration is printed is arranged vertically next to a digital clock time display 6. The vertical relationship between the two may be reversed, or the two may be arranged horizontally. The two-dimensional code 5N and the time display 6 in FIG. 5 can also be integrated as an image and displayed on a display device.
[0088] 6(A) and 6(B) is a digital clock with a wide margin below the display where the time is displayed, and a sticker 55 with a typical two-dimensional code 5N printed on it is affixed to that margin. The two-dimensional code 5N can also be printed directly on the surface of the margin of the time display 6.
[0089] The two-dimensional code 5N in the example of Figure 6(A) is set in a normal position with the length and width directions aligned with the vertical and horizontal directions, while the two-dimensional code 5N in the example of Figure 6(B) is set in a position with the length and width directions tilted relative to the horizontal and vertical directions.
[0090] The relationship between the two-dimensional code 5 or 5N and the time display 6 is not limited to the examples in Figures 3 to 6, and can be changed as long as it is possible to photograph both simultaneously and to read the two-dimensional code and time from the photographed image. Also, if the time display 6 is not to be built in, a one-dimensional barcode can be used instead of the two-dimensional code.
[0091] In either case, it is essential that the time and date be accurately displayed on the time display 6. Assuming that this requirement is met, in this embodiment, the data representing the time is a combination of the values representing the date and the values representing the time displayed on the time display 6, arranged in the order of year, month, day, hour, minute, and second.
[0092] 7 is a functional block diagram showing the configuration of the request application and game application (hereinafter referred to as 200 and 210, respectively) of the user terminal 2, along with their relationship with the main hardware (camera 25, touch panel 26, communication circuit 27) of the user terminal 2. Although not shown in the figure, information exchange between each of the applications 200, 210 and the hardware, and information exchange between the applications 200, 210, is performed via the operation system of the user terminal 2.
[0093] The request application 200 includes a main control unit 201, a communication control unit 202, a code extraction unit 203, a time data acquisition unit 204, and a request generation unit 205. The game application 210 includes a game control unit 211, a communication control unit 212, a download processing unit 213, and an image storage unit 214.
[0094] 2A to 2D on the touch panel 26, the main control unit 201 of the request application 200 recognizes operations performed on those screens and executes the processing instructed by the operations. The processing includes controlling the camera 25 and contacting the game application 210.
[0095] In response to the main control unit 201 starting up the camera 25, the code extraction unit 203 executes a process of extracting finder patterns fp1, fp2, fp3 (see FIGS. 3 to 6) of the two-dimensional code 5 from the hourly frame image generated by the camera 25. The time data acquisition unit 204 acquires data indicating the current time including the year, month, and date (hereinafter referred to as "current time data") from the clock function of the user terminal 2.
[0096] The request generation unit 205 generates a request to the authentication server 1 in response to the still image being captured by the camera 25. This request includes the still image generated by capturing the still image, the current time data acquired by the time data acquisition unit 204, and the user's identification code (hereinafter referred to as "user code") read from the internal memory. The user code is a random code sent from the authentication server 1 during initial setup immediately after the request application 200 is installed in the user terminal 2. Therefore, the user code does not include any personal information of the user.
[0097] The communication control unit 202 transmits the request to the authentication server 1 via the communication circuit 27, and then receives a notification in response to the request sent back from the authentication server 1. The content of the notification is analyzed by the main control unit 201, and if it is a permission notification, the screen shown in Fig. 2(D) is displayed, and if it is a denial notification, a message stating that the image download is not permitted is displayed.
[0098] The game control unit 211 of the game application 210 controls the progress of the online game, which is the main purpose of the application. While the game control unit 211 is operating, the communication control unit 212 communicates with the game server 3 via the communication circuit 27 in conjunction with the operation of the game control unit 211, receives image data, audio data, etc. necessary for executing the game, and transmits data output from the game control unit 211 (representing operation content, etc.) to the game server 3.
[0099] The download processing unit 213 operates in response to a notification from the main control unit 201 of the request application 200 in an inactive state, and cooperates with the communication control unit 212 to download images from the game server 3. After the download is complete, the download processing unit 213 also performs processing to display the screen shown in FIG. 2(F).
[0100] The image storage unit 214 stores images downloaded by the download processing unit 213 and images downloaded while the game is being played.
[0101] FIG. 8 is a block diagram showing the functions of the authentication server 1. As shown in FIG. The authentication server 1 of this embodiment is provided with a request processing unit 10, a two-dimensional code reading processing unit 11, a time reading processing unit 12, a current time data acquisition unit 13, a first matching processing unit 14, a second matching processing unit 15, an authentication processing unit 16, a history information management unit 17, an area information registration processing unit 18, a two-dimensional code generation unit 19, an area information storage unit 100, a history information storage unit 101, and the like.
[0102] Information related to each area where a service is provided is registered in the area information storage unit 100. FIG. 9(A) shows an example of information stored in the area information storage unit 100. In this example, an area code, which is an identification code for the area, the name of the area, an address, an authentication code, and a download URL are stored for each area. Of these, the area code, name, and address are transmitted from a communication terminal device (personal computer, tablet terminal, etc.) of the administrator of the authentication server 1 or the game server 3, and are registered by the area information registration processing unit 18.
[0103] The authentication code is a random code generated in response to the registration of the above three types of information by the area information registration processing unit 18. This authentication code is also linked to the above three types of information and registered in the area information storage unit 100 by the area information registration processing unit 18.
[0104] The download URL is the address of the download page for the requested image. The download URL is set by the game server 3, combined with the area code, and sent to the authentication server 1, where it is linked to a record already registered in the area information storage unit 100 using the area code as a key. The download URL is also saved in the area information storage unit 100 by the area information registration processing unit 100.
[0105] Referring back to Figure 8. In response to receiving a request to generate a two-dimensional code specifying an area registered in the area information storage unit 100 from the administrator terminal of the authentication server 1, the two-dimensional code generation unit 19 reads the authentication code for that area from the area information storage unit 100 and encodes it into a two-dimensional code. The two-dimensional code is sent to the administrator terminal as an image file, and a printout of the image of this file or a display device displaying the image is installed in the actual area.
[0106] The request processing unit 10 accepts a request from the user terminal 2 of an end user, and returns to the user terminal 2 a notification of permission or denial of permission for the request.
[0107] The two-dimensional code reading processing unit 11 extracts the two-dimensional code 5 from the image included in the request and reads its contents. The first verification processing unit 14 verifies the information read by the two-dimensional code reading processing unit 11 with the authentication code registered in the area information storage unit 100.
[0108] The time reading processing unit 12 extracts an image of the time display 6 from the image included in the request, reads the date and time shown in the image using OCR processing, and generates time data in which each piece of information read is arranged in the order of year, month, day, hour, minute, and second.
[0109] The current time data acquisition unit 13 acquires the current time data in the request and converts it into the same format as the time data generated by the time reading processing unit 12 .
[0110] The second matching processing unit 15 calculates the difference between the time data generated by the time reading processing unit 12 and the time data processed by the current time data acquisition unit 13, and compares the value of this difference with a predetermined allowable value.
[0111] The matching results of the first matching processing unit 14 and the second matching processing unit 15 are represented by flag data (hereinafter referred to as "matching result flags") indicating "OK" or "NG", respectively. Based on the value of each matching result flag, the authentication processing unit 16 decides whether to authenticate the request from the user terminal 2, and if the request is permitted, creates a permission notice including a download URL for the requested image, or if it is not permitted, creates a denial notice including a code indicating "NG". The created notice is passed to the request processing unit 10, and is sent from the request processing unit 10 to the user terminal 2 that issued the request.
[0112] In response to the determination result by the authentication processing unit 16, the history information management unit 17 stores the determination result and information about the request to be determined in the history information storage unit 101. Fig. 9(B) shows an example of this stored information.
[0113] In the example of Figure 9(B), for each request, the request time (current time data included in the request), the request acceptance time (the time when the authentication server 1 received the request), the user code included in the request, the authentication result by the authentication processing unit 16, the area code identified in the processing before authentication, and the download URL included in the permission notification are saved.
[0114] In addition to the above, the history information storage unit 101 can also store the matching results of the first matching processing unit 14 and the second matching processing unit 15, and information about the image corresponding to the download URL included in the permission notification (such as the identification code of the character image and the address where the image is saved).
[0115] 10(A) shows the functions related to the provision of character images, namely, login authentication unit 31, download management unit 32, image registration processing unit 33, and user information registration processing unit 34, among the functions included in game server 3, along with their relationship with character image storage unit 300 and user information storage unit 301, which store information related to these functions. FIG. 10(B) shows an example of the configuration of a reference table stored in character image storage unit 300.
[0116] Character image files corresponding to each area are registered in the character image storage unit 300, and a reference table TB shown in Fig. 10(B) is also stored. For each area, this table TB stores the area code, the file name of the image provided to users in that area, the address (URL) of the location where the file is saved, and the download URL of the file.
[0117] The image registration processing unit 33 accepts the designation of an area and upload of a character image file from the administrator terminal of the game server 3, saves the file in the character image storage unit 300, and also saves the file name and the URL of the save destination in combination with the area code of the area designated by the administrator in the above-mentioned reference table TB. Furthermore, the image registration processing unit 33 creates a download page for the above-mentioned file, and saves the URL of that page as a download URL in the reference table TB, linking it to the three types of information saved earlier.
[0118] The combination of area code and download URL registered in the area information storage unit 100 of the authentication server 1 is also read from this reference table TB and sent to the authentication server 1. This transmission may require the intervention of an administrator, but it can also be sent automatically from the game server 3 to the authentication server 1 upon completion of registration in the reference table TB.
[0119] The user information storage unit 301 stores information (such as a user ID and password) required for a user using the game app 210 to log in to the game server 3. This information is transmitted from the user's user terminal 2 when the user who downloaded the game app 210 accesses the game server 3 for the first time, and is stored in the user information storage unit 301 by the user information registration processing unit 34. The user information storage unit 301 may also store specific personal information of the user, such as name and age.
[0120] The login authentication unit 31 requests the user terminal 2 that has accessed the download URL to transmit login information, and collates the transmitted information with the registered information in the user information storage unit 301 to determine whether to permit access by the user terminal 2. When the login authentication unit 31 permits access to the download URL, the image file of the destination URL linked to the download URL is read by the download management unit 32 and transmitted to the user terminal 2.
[0121] Fig. 11 is a flowchart showing the processing steps executed by the request application 200 of the user terminal 2. Fig. 12 is a flowchart showing the processing steps executed by the authentication server 2 that receives the request. Fig. 13 shows a corresponding flowchart showing the processing steps by the game application 210 and a corresponding flowchart showing the processing steps by the game server 3 that receives access from the game application 210. Below, with reference to these flowcharts, a series of processing steps that are executed from when a request is sent by the user terminal 2 until the download of an image is completed will be described.
[0122] When a user touches the icon of the request application 200 on their own user terminal 2, the process shown in Fig. 11 starts. In the first step S1, the main control unit 201 of the request application 200 starts up the camera 25 to start capturing video, and the screen shown in Fig. 2(A) is displayed. In response to this, the process of the code extraction unit 203 also starts.
[0123] The code extraction unit 203 searches for finder patterns fp1, fp2, and fp3 (see FIG. 3, etc.) of the two-dimensional code 5 in the hourly frame images generated by the camera 25. When the two-dimensional code 5 enters the center of the camera's field of view (the range corresponding to the frame w shown in FIGS. 2(A) and 2(B)) and the finder patterns fp1, fp2, and fp3 at the three corners are extracted by the code extraction unit 203 ("YES" in step S2), the main control unit 201 displays the request send button 20 shown in FIG. 2(B) on the screen (step S3).
[0124] When the user operates the request transmission button 20 (step S4 is "YES"), the main control unit 201 causes the camera 25 to take a still image (step S5), and immediately thereafter causes the time data acquisition unit 204 to access the clock function within the device to acquire current time data (step S6).
[0125] Next, the request generation unit 205 generates a request including the still image generated by the shooting in step S5, the current time data acquired in step S6, and the user code registered in the internal memory (step S7). Next, the communication control unit 202 adds formal data to this request and sends it to the authentication server 1 (step S8). After this, the process waits, repeating the determination in step S9, until the authentication server 1 completes its processing, which will be described below, and returns a notification. During this time, the main control unit 201 displays the screen shown in FIG. 2(C).
[0126] Because the processes from step S5 to step S8 above proceed instantaneously, the execution timing of each step may be expressed in seconds at the same time. Therefore, the current time data acquired in step S6 may be considered to represent the time when the still image was captured or the time when the request was sent to the authentication server.
[0127] Reference is now made to FIG. In the authentication server 1 that has received the request, the request processing unit 10 first accepts the request from the user terminal 2 and extracts from the request a still image showing the two-dimensional code 5 and the time display 6, the current time data, and the user code (step V1). This information is stored in a linked state in the working memory of the authentication server 1, and using this information, a first matching process for the two-dimensional code 5 (steps V2 to V7) and a second matching process for the time data (steps V8 to V13) are executed in parallel. However, these processes are not limited to parallel processing, and may be executed in the order of first matching followed by second matching, or vice versa.
[0128] In the first verification process, the two-dimensional code reader 11 reads the contents of the two-dimensional code 5 in the image (step V2), and the first verification processor 14 performs a verification process between the read information of the two-dimensional code and the authentication code stored in the area information storage unit 100 (step V3). If an authentication code matching the read information is found through this verification (step V4 is "YES"), the first verification processor 14 acquires the area code corresponding to the authentication code (step V5) and sets the verification result flag to an ON state indicating "OK" (step V6). If an authentication code matching the read information is not found (step V4 is "NO"), the first verification processor 14 sets the verification result flag to an OFF state indicating "NG" (step V7).
[0129] In the second verification process, the time reading processing unit 12 reads the time display 6 in the image (step V8), and the current time data acquisition unit 13 acquires current time data (step V9), before proceeding to time verification by the second verification processing unit 15 (step V10). The second verification processing unit 15 calculates the difference between the times acquired by the previous processing units 12 and 13 and compares this difference with a predetermined tolerance. If this difference is equal to or less than the tolerance (step V11 is "YES"), the second verification processing unit 15 sets the verification result flag to ON, indicating "OK" (step V12). If the difference is greater than the tolerance, the second verification processing unit 15 sets the verification result flag to OFF, indicating "NG" (step V13).
[0130] When the processing by the first verification processing unit 14 and the second verification processing unit 15 is completed, the authentication processing unit 16 determines whether or not to permit the request based on the value of the verification result flag in each verification. Specifically, the authentication processing unit 16 issues a decision of permit only when both verification result flags are on (step V14 is "YES"), and issues a decision of denial in other cases.
[0131] If permission is granted, the authentication processing unit 16 reads out the download URL associated with the area code acquired by the first verification processing unit 14 in step V5 from the area information storage unit 100 and creates a permission notification including the URL (step V15). The permission notification is sent by the request processing unit 10 to the user terminal 2 (request application 200) that issued the request (step V16).
[0132] Now, reference is made again to FIG. In the request application 200, when a permission notification is returned from the authentication server 1, steps S9 and S10 become "YES", and the main control unit 201 displays a notification screen (see FIG. 2(D)) including a download button 21 (step ST11).
[0133] When the download button 21 is operated by the user ("YES" in step S12), the main control unit 201 sends the permission notification sent from the authentication server 1 to the game application 210 (step S13). Upon receiving this notification, the processing of the request application 200 ends, and the game application 210 enters an active state.
[0134] Now, reference is made to FIG. In game application 210, upon receiving the permission notification from request application 200, download processing unit 213 extracts a download URL from the notification (step T1). Furthermore, download processing unit 213 cooperates with communication control unit 212 to access the download URL (step T2).
[0135] Upon receiving this access, the game server 3 performs user authentication (step U1) and access permission (U2) by the login authentication unit 31, and then moves on to processing by the download management unit 32. If the game application 210 is set to automatically log in to the game server 3 or if a previously logged-in state is maintained, authentication is completed instantly without requiring any input operation by the user, and access to the download URL is promptly permitted.
[0136] When the download management unit 32 confirms the download URL accessed by the user terminal 2, it reads the image file linked to that URL from the character image storage unit 300 (step U3) and sends this image file to the user terminal 2 that has been granted access (step U4).
[0137] In game application 210 that has received the image file, the standby screen shown in Fig. 2(E) is displayed under the control of download processing unit 213 until reception of the image file is complete (step T3). Once reception is complete, download processing unit 213 opens the received file and displays the screen shown in Fig. 2(F) (step T4). The display of this image completes the series of processes for the request.
[0138] If the game application 210 fails to automatically log in to the game server 3, the login authentication unit 31 sends a login screen to the game application 210. In response to this, the user enters a username and password via the login screen displayed on the game application 210, and when these are sent to the game server 3, the login authentication unit 31 performs user authentication (step U1) and access permission (step U2), and then the process proceeds to the download management unit 32.
[0139] In the processing of the authentication server 1 in FIG. 12, if the condition that the matching result flags for both the first matching and the second matching are turned on is not met (step V14 is "NO"), the authentication processing unit 16 creates a denial notice including a code representing "NG", and this notice is sent from the request processing unit 10 to the user terminal 2 (step V17).
[0140] 11, the requesting application 200 proceeds to step S14, where it determines "NO" in step S10 and displays a notification screen containing a message indicating that the download is not permitted, and ends the process. Therefore, when a denial notice is received, no notification is sent to the game application 210, and the denial notice does not cause the game application 210 to enter an active state.
[0141] 11 to 13, when a user in one of the areas registered in the area information storage unit 100 of the authentication server 1 launches the request application 200 on their user terminal 2 in that area, takes a picture of the set of the two-dimensional code 5 and the time display 6 placed in that area, and operates the request send button 20 displayed on the screen, a still image showing the time immediately after the request operation is performed is generated, and a request is generated that includes the image and current time data indicating the time immediately after the image was generated. Therefore, the difference between the time shown in the image and the time indicated by the current time data is extremely small, and they may be the same time if expressed in seconds.
[0142] On the other hand, if a malicious user takes a picture of the set of the two-dimensional code 5 and the time display 6 using the standard camera application on the user terminal 2, sends the image to a friend outside the area, and the friend then sends a request from the request application 200 using the display screen or printout of the received image, no matter how quickly the user is in, it will take several seconds from receiving the image to sending the request.
[0143] 12 is set to a value slightly larger than the maximum possible difference between the two types of time included in a correct request from a registered area, the matching result flag of the second matching in the authentication server 1 that receives the correct request will almost certainly be turned on (OK), and a permission notice can be sent to the user terminal 2 that sent the request. The user who has received the permission notice can quickly download the requested character image by operating the download button 21 displayed on the user terminal 2 in response to receiving the notice.
[0144] On the other hand, in the second verification performed by the authentication server 1 that receives a request from a location outside the registered area, the difference between the two types of time definitely exceeds the allowable value, the verification result flag is turned off, and no permission notification is sent to the user terminal 2 that sent the request.
[0145] In this way, a bona fide user can easily obtain a character image within the registered area by pointing the camera 25 at the set of the two-dimensional code 5 and the time display 6 and operating the request send button 20 and the download button 21. In contrast, the possibility of a user making an unauthorized request from outside the area being able to obtain a character image is extremely low.
[0146] Although not shown in FIG. 12, in the authentication server 1, the history information management unit 17 stores the information shown in FIG. 9(B) in the history information storage unit 101 in response to the determination result issued by the authentication processing unit 16. As described above, in this embodiment, it is possible to prevent fraudulent requests from being authenticated with a high degree of certainty, thereby increasing the reliability of the information in the history information storage unit 101. Therefore, relevant parties such as the operator of the online game and the administrator of each area can obtain highly reliable analysis results by analyzing the information in the history information storage unit 101. Because the only information that the authentication server 1 obtains from the user who sent the request is the user code, the operator of the authentication server 1 does not need to consider managing the personal information of each user, and can respond to requests from an unspecified number of users and analyze processing results.
[0147] The game server 3 can also store history information that links the login identification code of the user who accessed each download page to the time of access. This history information allows the operator of the game server 3 to identify who sent the request, when, and from where.
[0148] <Second Example> 14 shows the functions of an authentication server 1 according to a second embodiment of the present invention. The authentication server 1 of the second embodiment is provided with the same functions as those of the first embodiment (indicated by the same reference numerals 10 to 19, 100, and 101 as in FIG. 8), and is also provided with a feature storage unit 110, a two-dimensional pattern extraction unit 111, a feature calculation unit 112, and a third matching processing unit 113 in order to increase the accuracy of the authentication result for a request from a user terminal 2.
[0149] The configurations and functions of the request application 200 and game application 210 of the user terminal 2 and the game server 3 are generally the same as those in the first embodiment, and therefore will not be illustrated. However, the medium for transmitting the request will be in a different form from that in the first embodiment, and specific examples thereof will be described with reference to Figures 15 to 18.
[0150] Figure 15(A) shows an example of a set of a two-dimensional code 5 and a time display 6 used in the second embodiment. In this example, as in the example of Figure 3, a two-dimensional code 5 based on Frame QR (registered trademark) is used. As in the first embodiment, the time display 6 is placed in the blank space in the center of the two-dimensional code 5, but in this example the time display 6 is positioned at an angle relative to the vertical and horizontal directions of the two-dimensional code 5.
[0151] When the set of two-dimensional code 5 and time display 6 shown in Figure 15(A) is used as a medium for sending a request, in addition to determining whether the information read from them is correct or incorrect, the correctness of the numerical value representing the relative positional relationship of the outline pattern P of the time display 6 to the two-dimensional code 5 is also determined.
[0152] Figure 15(B) shows the set of two-dimensional code 5 and time display 6 shown in Figure 15(A) in a diagram in which the encoded part of the two-dimensional code is shown as only the outline, and shows an example of calculating a numerical value (hereinafter referred to as "feature value") that represents the relative positional relationship of the outline pattern P of the time display 6 to the two-dimensional code 5.
[0153] In the example of Figure 15(B), of the four vertices of the rectangular outline pattern P of the time display 6, the upper left vertex q1 and the lower left vertex q2 are set as feature points, and feature quantities are calculated that represent the relative positional relationships of feature points q1 and q2 with respect to finder patterns fp1 and fp2 that are closest to these feature points q1 and q2, respectively.
[0154] Specifically, for feature point q1, calculations are made to calculate the distance L1 between the upper left vertex of the upper left finder pattern fp1 of the two-dimensional code 5 and feature point q1, and the angle θ1 between the line connecting that vertex to feature point q1 and the left side of the two-dimensional code 5. For feature point q2, calculations are made to calculate the distance L2 between the lower left vertex of the lower left finder pattern fp2 of the two-dimensional code 5 and the angle θ2 between the line connecting that vertex to feature point q2 and the bottom side of the two-dimensional code 5.
[0155] The side used as the reference for determining the angle is not limited to the above example. For example, for feature point q1, the top side of 2D code 5 may be used as the reference, and the angle formed between the top side and a line connecting feature point q1 and the upper left vertex of finder pattern fp1 may be determined. For feature point q2, the left side of 2D code 5 may be used as the reference, and the angle formed between the left side and a line connecting feature point q2 and the lower left vertex of finder pattern fp2 may be determined.
[0156] 15 are installed in different positions in each area, the above-mentioned feature values will also differ for each area. Therefore, if the set of the two-dimensional code 5 and the time display 6 in each area is photographed in advance and the feature values calculated from the photographed images are registered in the feature storage unit 110, it can be determined by comparing these feature values whether the image in the request sent from the user terminal 2 of the user was photographed in the corresponding area.
[0157] 16, the two-dimensional code 5 and the time display 6 are arranged in the same relationship as in Fig. 3, and two-dimensional patterns P11, P12, and P13 (represented by stars for convenience of illustration) that are smaller than the finder patterns fp1, fp2, and fp3 of the two-dimensional code 5 are arranged outside the finder patterns fp1, fp2, and fp3 of the two-dimensional code 5. In this example, the center points q11, q12, and q13 within the two-dimensional patterns P11, P12, and P13 are set as feature points, and for each of these feature points, the distances L11, L12, and L13 to one vertex of the nearest finder patterns fp1, fp2, and fp3, and the angles θ11, θ12, and θ13 formed between the lines representing these distances and one side of the two-dimensional code 5 are calculated as feature quantities.
[0158] In the example of Fig. 17, the two-dimensional code 5 and the time display 6 are arranged in the same relationship as in Fig. 3, and a two-dimensional pattern Px in the form of a trapezoid large enough to encompass the entire two-dimensional code 5 is arranged around the two-dimensional code 5. In other words, the two-dimensional code 5 and the time display 6 are contained within the two-dimensional pattern Px.
[0159] 17, of the four vertices of two-dimensional pattern Px, point q21 near finder pattern fp1 and point q22 near finder pattern fp2 are set as feature points. For feature point q21, distance L21 from the upper left vertex of finder pattern fp1 and angle θ21 formed between the line connecting feature point q21 to the upper right vertex of right-side finder pattern fp3 and the line representing distance L21 are calculated as feature amounts. For feature point q22, distance L22 from the lower left vertex of finder pattern fp2 and angle θ22 formed between the line connecting feature point q22 to the lower left vertex of finder pattern fp1 above and the line representing distance L22 are calculated as feature amounts.
[0160] In the example of Fig. 18, a two-dimensional code 5 and a time display 6 of the same form as those shown in Fig. 3 are used, and the outline shape of an item placed in the area where they are placed is used as the two-dimensional pattern Py. The specific item is a rectangular sticker attached above the two-dimensional code 5, and the bottom left and bottom right vertices q31 and q32 of the outline pattern Py of this sticker are set as feature points.
[0161] For feature point q31, the calculated feature amounts are the distance L31 between that point and the closest upper right vertex of finder pattern fp1, and the angle θ31 between the line representing that distance and the top side of the two-dimensional code 5. For feature point q32, the calculated feature amounts are the distance L32 between that point and the closest upper left vertex of finder pattern fp2, and the angle θ32 between the line representing that distance and the top side of the two-dimensional code 5.
[0162] Not limited to the examples of Figures 15 to 18 above, for example, even in a configuration in which a two-dimensional code 5 is placed at an angle on the surface of a clock that serves as a time display 6, as in Figure 6(B) above, the outline of the time display screen can be treated as a two-dimensional pattern, and multiple vertices within that pattern can be used as feature points to calculate the feature quantity using calculation rules similar to those of the examples of Figures 16 to 18.
[0163] Returning to reference to FIG. 15 to 18, model data representing the contour shapes and the positions of feature points on the contours of a plurality of types of two-dimensional patterns including patterns P, P11, P12, P13, Px, and Py are registered in the feature storage unit 110. Furthermore, for each area registered in the area information registration processing unit 100, the type of two-dimensional pattern to be applied to that area, a calculation rule for the feature amount, and specific feature amount values are registered in the feature storage unit 110 (these will be described in detail with reference to FIG. 19).
[0164] The two-dimensional pattern extraction unit 111 extracts two-dimensional patterns and feature points from the image included in the request from the user terminal 2, using model data corresponding to the area to which the request was sent. The feature calculation unit 112 calculates the feature amount for each feature point based on the calculation rule associated with the model data.
[0165] The third matching processing unit 113 matches the feature calculated by the feature calculation unit 112 with the feature registered in the feature storage unit 110. The authentication processing unit 16 refers to the matching results by the third matching unit 113 in addition to the matching results by the first matching unit 14 and the second matching unit 15, and determines whether to permit the request.
[0166] Although not shown in FIG. 14, the authentication server 1 further has a function of registering, in the feature storage unit 110, model data of the two-dimensional pattern to be applied to each area where a set of the two-dimensional code 5, the time indicator 6, and the two-dimensional pattern is deployed, while receiving setting operations from the administrator terminal, and a function of calculating, using images captured in advance in each area, feature amounts to be used for matching by the third matching processing unit 113, and registering these in the feature storage unit 110.
[0167] 19 shows an example of information registered in area units among the information registered in the feature storage unit 110. One unit of information includes the same area code (see FIG. 9(A)) as registered in the area information storage unit 100, an identification code (pattern ID) of the two-dimensional pattern applied to that area, and a reference size of the two-dimensional pattern.
[0168] The pattern ID is an identification code for identifying the model data (outline shape and position information of feature points) of the two-dimensional pattern registered in the feature storage unit 110.
[0169] The reference size is the size (number of pixels) of one side of the two-dimensional code 5 in the image used in the process of registering the feature in the feature storage unit 110. This value is used in the process of correcting the distance when determining the feature for the third matching, which will be described later.
[0170] The area-unit information further includes, for each feature point, information indicating the reference position for measurement (a combination of one of finder patterns fp1, fp2, or fp3 and one of its vertices), information indicating the reference direction used to calculate the angle (in this example, one of the four sides of the two-dimensional code 5), and feature amounts (distance and angle) calculated from the pre-captured image based on this information. The information indicating the reference position and the information indicating the reference direction correspond to feature amount calculation rules.
[0171] 11 of the first embodiment, the request application 200 of the user terminal 2 sends a request including an image generated by capturing a still image, current time data obtained from an internal clock function, and a user code to the authentication server 1. Upon receiving this, the authentication server 1 performs the same processes as steps V1 to V13 of FIG. 12, and then, on the condition that the matching result flags for both the first matching and the second matching are turned on, the 2D pattern extraction unit 111, the feature calculation unit 112, and the third matching processing unit 113 perform the processes shown in FIG.
[0172] In the processing of FIG. 20, first, the two-dimensional pattern extraction unit 111 operates and reads out information (the information shown in FIG. 19) corresponding to the area code acquired in the processing related to the first matching (see step V5 of FIG. 12) from the feature storage unit 110 (step V21).
[0173] Next, the two-dimensional pattern extraction unit 111 measures the size (number of pixels on one side) of the two-dimensional code 5 in the image (step V22), and calculates a magnification α for that size relative to the reference size in the information read out in step V21 (step V23).
[0174] Furthermore, the two-dimensional pattern extraction unit 111 reads out the model data linked to the pattern ID in the information read out in step V21, and based on this model data, extracts the two-dimensional pattern and one or more feature points inside or around the two-dimensional code 5 in the image (step V24).
[0175] If the extraction is successful (step V25 is "YES"), the process proceeds to the feature calculation unit 112, where the feature (distance and angle) of each feature point is calculated based on the feature calculation rule in the information read out in step V21 (step V26). Furthermore, the feature calculation unit 112 corrects the calculated distance value to the value when applied to a two-dimensional code 5 of the standard size by a correction calculation using the magnification α calculated in step V23 (step V27).
[0176] Once the angles and corrected distances have been calculated for all feature points, the process proceeds to step V28, where the third matching processor 113 matches the calculated distances and angles for each feature point with the corresponding distance or angle values (which were also read out in step V21). Specifically, the difference between each pair of corresponding numerical values is calculated, and it is determined whether the difference is equal to or smaller than a predetermined tolerance.
[0177] If the above collation results in the difference between all the corresponding numerical values being equal to or less than the allowable value (step V29 is "YES"), the third collation processing unit 113 sets the collation result flag of the third collation to ON, indicating "OK" (step V30). On the other hand, if there is a numerical value whose difference with respect to the registered numerical value exceeds the allowable value, the third collation unit 113 sets the collation result flag to OFF, indicating "NG" (step V31).
[0178] When the third verification process is completed in this manner, the process proceeds to the determination process of the authentication processing unit 16, and an approval notice is created on the condition that all of the verification result flags from the first, second, and third verifications are on. After this, in the same manner as in the first embodiment, an approval notice is sent to the user terminal 2 that issued the request, and the game app 210 of the user terminal 2 accesses the download URL, and the image of the requested character is sent to the user terminal 2.
[0179] If the collation result flag for one or both of the first and second collation is set to OFF, the process of FIG. 20 is not performed, and the collation result flag for the third collation is automatically set to OFF (NG).
[0180] 20, even if the extraction process in step V24 fails (step V25 is "NO"), the matching result flag for the third matching is set to OFF. Therefore, even if a fraudulent act is committed by reading a two-dimensional code 5 in an area where an image provision service is performed using general reading software, and then sending a request from outside the area using a set of a two-dimensional code 5 generated from the read information and a fake time display 6 that can display the time in real time, it is possible to prevent the authentication processing unit 16 from issuing a permission notice because the registered two-dimensional pattern could not be extracted.
[0181] Possible arrangements of the second embodiment will be explained below, with item numbers (1) to (4) assigned.
[0182] (1) The reference points for calculating the distance and angle that serve as the feature quantities for the feature points of the two-dimensional pattern are not limited to the vertices of the outer rectangles of the finder patterns fp1 to fp3, but can also be the vertices or center points of the inner rectangles of the finder patterns fp1 to fp3. Also, a specific point outside the finder patterns fp1 to fp3, such as the center point of the two-dimensional code 5, can be used as a common reference point for each feature point. For each feature point, the distance between the reference point and the angle between a line extending horizontally or vertically through the two-dimensional pattern and a line representing the distance can be calculated as the feature quantity. Furthermore, the two-dimensional pattern is not limited to those specified by the administrator; patterns of features that are originally present at the installation location (such as pillars, windows, parts of fixtures, wall decorations, etc.) can also be registered.
[0183] (2) In the second embodiment, information was registered in the feature storage unit 110 on an area-by-area basis, based on the premise that a combination of a two-dimensional code 5, a time display 6, and a two-dimensional pattern is provided in one location in each area. However, the above combinations can also be provided in multiple locations within the same area. In this case, the two-dimensional code 5 may be common within the area, but it is desirable to vary the type of two-dimensional pattern or the positional relationship of the two-dimensional pattern with respect to the two-dimensional code 5 for each location. The pattern ID, reference size, feature calculation rule, and feature reference value can also be registered individually in the feature storage unit 110 for each of multiple locations within the area.
[0184] (3) Regarding the third matching, instead of matching the features of the two-dimensional pattern, it is also possible to perform matching on an image within a range a predetermined distance from the two-dimensional code 5 or a portion of an image within that range (hereinafter collectively referred to as the “background image”).
[0185] The background image must contain a pattern with some kind of characteristic. For example, an image in the range including patterns P11, P12, P13, Px, and Py shown in Figures 16, 17, and 18 can be used as the background image. The characteristics included in the background image may be formed by items previously placed by the administrator (for example, the sticker in the example of Figure 18), or may be formed by features that are originally present at the installation location (pillars, windows, parts of furniture, wall decorations, etc.). It is also desirable to make the characteristics of the background image different for each installation location.
[0186] When matching a background image, the authentication server 1 is provided with a model image memory unit that stores an image generated by capturing an image of an area including the 2D code 5, the time indicator 6, and the characteristic pattern deployed at the site, instead of the feature memory unit 110. The 2D pattern extraction unit 111 and the feature amount calculation unit 112 are also eliminated, and the third matching processing unit 113 is provided with an image processing function for matching the image included in the request from the user terminal 2 with the image registered in the model image memory unit.
[0187] An edge image generated by edge extraction processing on a captured image may be registered in the model image storage unit, and the image included in a request from the user terminal 2 may also be converted into an edge image, and these edge images may be compared with each other. Furthermore, it is not necessarily necessary to include images of the two-dimensional code 5 and the time display 6 in the images registered in the model image storage unit; only images within a range that includes the feature pattern to be compared may be registered.
[0188] (4) In addition to the first check on the information read from the two-dimensional code 5, the second check on the time read from the image of the time display 6, and the third check on the two-dimensional pattern or background image, the authentication server 1 can be added with a function to request the user terminal 2 that sent the request to send some additional information, and the authentication processing unit 16 can be configured to determine whether the content of the information sent in response to the request is appropriate before making a final judgment.
[0189] For example, a function can be added to the authentication server 1 that sends a message requesting a photo shoot for some purpose to the user terminal 2 that has received the permission notification from the authentication server 1, provided that all of the first, second, and third verification result flags are "OK," and checks whether an image that meets the request is sent within a certain time period after the transmission. A function for receiving the above message is also added to the request application 200 of the user terminal 2.
[0190] As one example, a command can be sent to the user terminal 2 that sent the permission notice, requesting that an image be taken of an area (a location containing characteristics unique to that area) where the two-dimensional code 5 is installed. As another example, a display device with a number input function can be installed at the site where the two-dimensional code 5 is deployed, a numeric code generated by random numbers can be sent from the authentication server 1 to the user terminal 2, the numeric code can be displayed on the display device, and a command can be sent to the user terminal 2 requesting that an image be taken of the display screen.
[0191] In addition to requesting photography, it is possible to request the transmission of information that can only be transmitted in a location where two-dimensional code 5 is displayed, such as displaying a simple quiz question on the display device and having the answer transmitted from user terminal 2, or requesting the transmission of the title of the background music playing in the area where two-dimensional code 5 is located or part of the lyrics.
[0192] In the processing up to the level of the second embodiment, if an unauthorized request is made from a location outside the registered area by using the standard photography function of the user terminal 2 to photograph the two-dimensional code 5 and its surrounding area, and then combining the photographed image with a fake time display 6, there is a risk that the fraudulent activity will not be detected and a permission notice will be sent. However, as in (4) above, by having the user terminal 2 send information that cannot be sent from anywhere other than the location where the two-dimensional code 5 is displayed to the authentication server 1 and determining whether that information is valid, it is possible to almost certainly prevent unauthorized requests from outside from being permitted. Note that the processing in (4) can also be added to the first embodiment.
[0193] <Third Example> In the third embodiment, a dedicated terminal device (hereinafter referred to as the "dedicated terminal") equipped with a display unit is provided within an area registered in the authentication server 1, and this dedicated terminal communicates with the authentication server 1 and the user's user terminal 2. The combination of the two-dimensional code 5 and the time display 6 is displayed as an image on the dedicated terminal using the method shown in Fig. 4.
[0194] Although the specific form of the dedicated terminal is not shown in the drawings, a display device (including a tablet terminal) with a built-in computer can be used. This dedicated terminal has the following functions: a function for communicating with the authentication server 1 via the Internet; a function for creating an image of a two-dimensional code 5 serving as a medium for a request using an authentication code received from the authentication server 1 through this communication, a function for combining this image with an image of a time display 6 and displaying it on the display; and a function for temporarily connecting a nearby user terminal 2 via Bluetooth (registered trademark) and controlling the operation of the user terminal 2 so that the user terminal 2 can send a request to the authentication server 1.
[0195] A specific code commonly included in the identification codes (device names) of the dedicated terminals in each area is registered in the request application 200 of the user terminal 2, and the request application 200 is provided with a function to catch radio waves including this specific code to recognize the dedicated terminal, and a function to send a connection request and a connection passcode to the dedicated terminal. The functions of the game application 210 and the relationship between the request application 200 and the game application 210 are the same as those in the first embodiment.
[0196] FIG. 21 shows an example of screen transitions on a user terminal 2 equipped with the above-mentioned functions, where (A) to (F) in the figure are screens of the request application 200, and (G) and (H) are screens of the game application 210.
[0197] Fig. 22 is a sequence diagram showing the main flow of processing in the information processing accompanied by the screen transitions shown in Fig. 21 (processing up to the point where the authentication server 1 makes a decision on the request from the user terminal 2. The same applies to Figs. 24, 25, 26, and 28 described later). Below, the processing of each embodiment will be described in detail with reference to the step codes (ST1 to ST17) in Fig. 22 and Fig. 21.
[0198] When request application 200 of user terminal 2 is launched in an area where a dedicated terminal is deployed, the above-mentioned recognition function is activated, and when this function recognizes the dedicated terminal, a screen such as that shown in Fig. 21(A) is displayed. When the user operates connection button 22 on this screen (step ST1), user terminal 2 accesses the recognized dedicated terminal and sends a connection request (step ST2).
[0199] The dedicated terminal that has received the connection request encrypts the passcode for connection using random numbers, converts it into a four-digit number, and displays this number on the display unit (step ST3).
[0200] Meanwhile, in response to the connection request, a screen (FIG. 21(B)) requesting the user to enter a four-digit number is displayed on the user terminal 2 (step ST4). When the user enters the number exactly as displayed on the dedicated terminal (step ST5), the passcode is sent to the dedicated terminal (step ST6), and the passcode is verified in the dedicated terminal (step ST7).
[0201] When the dedicated terminal confirms that the received passcode matches the displayed code, it sends a notification to the user terminal 2 permitting connection (pairing) (step ST8) and switches the display screen to one showing the combination of the two-dimensional code 5 and the time display 6 (step ST9).
[0202] In response to receiving permission to connect to the dedicated terminal, the user terminal 2 starts capturing video images (step ST10). The screen also switches to displaying the captured image (FIG. 21(C)). When the entire two-dimensional code 5 displayed on the dedicated terminal is within the frame w of this screen, a request transmission button 20 is displayed on the screen (FIG. 21(D)). When the request transmission button 20 is operated, a still image is captured and a request is generated (steps ST13 and ST14), and the request is sent to the authentication server 1 (step ST15).
[0203] The request includes an image generated by capturing a still image, current time data acquired after the image was captured, and a user code, as in the first embodiment. The authentication server 1 also performs the first and second verifications similar to those in the first embodiment (step ST16), makes an authentication decision based on the results of these verifications, and transmits the decision result to the user terminal 2 (steps ST17 and ST18).
[0204] The screen of the user terminal 2 that has received the permission notification from the authentication server 1 changes from the state shown in Fig. 21(E) to the state shown in Fig. 21(F). The processing of the game app 210 and the game server 3 after the download button 21 on this screen is sent is the same as in the first embodiment, and due to this processing, the screen of the user terminal 2 changes from the state shown in Fig. 21(G) to the state shown in Fig. 21(H).
[0205] According to the third embodiment, in order for a user to display a set of two-dimensional code 5 and time display 6 on the dedicated terminal, the user must connect the user terminal 2 to the dedicated terminal by entering the passcode displayed on the dedicated terminal into the user's own user terminal 2. Furthermore, only after this connection is permitted can a request be generated by photographing the set of two-dimensional code 5 and time display 6 displayed on the dedicated terminal. Therefore, unless the user's user terminal 2 is located within an area where connection to the dedicated terminal is possible and in a position where the screen of the dedicated terminal can be seen, it is impossible to send a request to the authentication server 1.
[0206] The connection permission from the dedicated terminal serves as a trigger to put the user terminal 2 into a state where it can take the photographs required to generate a request, and once photographing has started on the user terminal 2, there is no need to maintain the connection to the dedicated terminal. With this in mind, in the example of Fig. 22, immediately after starting photographing, the user terminal 2 sends a response to the connection permission to the dedicated terminal (step ST11), and upon receiving this response, the dedicated terminal disconnects the connection with the user terminal 2 (step ST12). The display of the two-dimensional code 5 and the time display 6 also disappears within a certain time after the disconnection.
[0207] According to the above mechanism, it is considered impossible to send a request to the authentication server 1 from a location other than the area where the dedicated terminal is deployed and receive a permission notification unless the dedicated terminal is remotely controlled or the authentication server 1 is hacked.
[0208] In the above example, a passcode had to be sent to connect to the dedicated terminal, but a password for the Bluetooth (registered trademark) connection itself may not be required, and other authentication information may be displayed on the dedicated terminal, and connection of the communication terminal device may be permitted on the condition that the user terminal 2 can send information consistent with this display to the dedicated terminal.
[0209] Information for authentication by methods other than Bluetooth (registered trademark) may also be a numerical value with a certain number of digits as in the above embodiment, but it is not limited to this and can also be composed of characters (such as a combination of multiple types of characters including hiragana, katakana, alphabets, numbers, and symbols) that can be input by operating the user terminal 2.
[0210] The dedicated terminal may display only a general two-dimensional code 5N (see FIG. 5) without combining it with the image of the time display 6. In this case, the verification process performed by the authentication server 1 will be only a first verification targeting the read information of the two-dimensional code 5N. However, if the passcode or authentication character information displayed on the dedicated terminal is different each time, it will be impossible for a user terminal 2 other than the one authorized to connect by transmitting information matching this display to the dedicated terminal to display the two-dimensional code 5N on the dedicated terminal and photographing it. Because the two-dimensional code is displayed for a very short time, even when only the two-dimensional code 5N is displayed and authentication is determined solely by verifying the read information of the two-dimensional code 5N, it is possible to prevent unauthorized requests from being permitted from locations where communication with the dedicated terminal is impossible or where the display screen of the dedicated terminal cannot be viewed or photographed.
[0211] <Fourth Example> In the fourth embodiment, a combination of a two-dimensional code 5 and a time display is displayed on a dedicated terminal having the same functions as the third embodiment. The two-dimensional code 5 in this embodiment includes an authentication code as well as a passcode for connecting the user terminal 2 to the dedicated terminal. A function for reading the two-dimensional code 5 is added to the user terminal 2.
[0212] 23 shows an example of screen transitions on a user terminal 2 to which the fourth embodiment is applied, with (A) to (E) in the figure being screens of the request application 200, and (F) and (G) being screens of the game application 210. These screens change in almost the same way as the screens of the first embodiment shown in FIG. 2, but the time from when the two-dimensional code 5 enters the frame w on the screen displaying the image captured by the camera 25 until the request send button 20 is displayed is slightly longer, and as shown in FIG. 23(B), the words "Authentication in progress" are displayed on the screen before the request send button 20 is displayed.
[0213] Figure 24 is a sequence diagram showing the main flow of information processing that is carried out while the screen changes shown in Figure 23 are occurring. As can be seen by comparing Figure 23 with the previous Figure 22, the processing of the dedicated terminal in the fourth embodiment is simpler than that in the third embodiment.
[0214] The dedicated terminal displays an image of a time display 6 combined with a two-dimensional code 5, in which an authentication code previously received from the authentication server 1 and a connection passcode are embedded (step S21). The passcode is encrypted into a number with a certain number of digits, as in the third embodiment, and is placed at the beginning of the entire code embedded in the two-dimensional code 5.
[0215] When the user terminal 2 on which the request application 200 has been started recognizes the dedicated terminal using the same function as in the third embodiment, the user terminal 2 displays the screen shown in Fig. 23(A) and starts the process of capturing an image and reading the two-dimensional code 5 (step ST22). After reading the two-dimensional code 5 is completed, the user terminal 2 transmits a connection request including the passcode in the read information to the user terminal 2 (step ST23).
[0216] The dedicated terminal compares the received passcode with the passcode embedded in the two-dimensional code 5 being displayed (step ST24), and if it confirms that the two match, it permits connection of the user terminal 2 (step ST25).
[0217] 23(B) is displayed on the user terminal 2 until connection permission is granted, but once connection permission is granted, a request transmission button 20 is displayed (step ST26) as shown in Fig. 23(C). After this, in response to operation of the request transmission button 20, a still image is captured (step ST29), a request is generated (step ST30), and the request is transmitted to the authentication server 1 (step ST31) in this order.
[0218] The request in this embodiment also includes, as in the first embodiment, an image generated by the immediately preceding still image capture, current time data obtained from the internal clock function after the still image capture, and a user code. The processing in the authentication server 1 that receives the request is also the same as in the first embodiment (steps ST32, ST33, ST34).
[0219] The connection between the dedicated terminal and the user terminal 2 is disconnected when the dedicated terminal receives a response sent to the dedicated terminal immediately after the user terminal 2 displays the request transmission button 20 in response to receiving connection permission (steps ST27 and ST28). Therefore, in the fourth embodiment as well, the connection time between the dedicated terminal and the user terminal 2 can be limited to an extremely short time.
[0220] In the fourth embodiment, the set of the two-dimensional code 5 and the time display 6 is displayed before the user terminal 2 is connected to the dedicated terminal, but the request send button 20 required to take a still image of them and send a request to the authentication server 1 is not displayed until connection permission is received from the dedicated terminal. Moreover, since the passcode portion of the two-dimensional code 5 displayed on the dedicated terminal changes each time, it is impossible to send a request to the authentication server 1 unless the user terminal 2 is connected to the dedicated terminal in a location where it is possible to take an image of the display screen of the dedicated terminal.
[0221] Connection to the dedicated terminal is automatically established by taking a picture of the display screen of the dedicated terminal, so what the user has to do before sending the request is exactly the same as in Example 1. This improves the ability to block fraudulent requests without imposing a burden on well-intentioned users.
[0222] Furthermore, in the fourth embodiment, the authentication server 1 is notified of the time when the dedicated terminal and the user terminal 2 are connected, and the authentication server 1 compares the notified time with the time based on the time data included in the request from the user terminal 2, thereby further increasing the accuracy of the authentication decision. A sequence diagram with this process added is shown in Fig. 25.
[0223] In the example of Fig. 25, the same procedures (steps ST31 to ST35) as steps ST21 to ST25 in Fig. 24 are executed. Immediately after issuing connection permission to the user terminal 2 in step ST35, the dedicated terminal acquires current time data from its own clock function and transmits a connection notification including the time data and the area code of the area in which the dedicated terminal is installed to the authentication server 1 (step ST36). The authentication server 1 saves the received connection notification in its internal memory (step ST37).
[0224] The processing of the user terminal 2 that has received permission to connect proceeds in the same manner as steps ST26, ST29, and ST30 in Fig. 24 (steps ST38, ST41, and ST42), and a request including an image obtained by capturing a still image, current time data, and a user code is sent to the authentication server 1 (step ST43). The connection between the dedicated terminal and the user terminal 2 is also completed in the same procedures (steps S39 and ST40) as steps S27 and S28 in Fig. 24.
[0225] Upon receiving the request, the authentication server 1 executes the first and second verifications similar to those in the first embodiment (step ST44). Then, in response to these verification result flags both being turned on, the authentication server 1 reads out the latest connection notification associated with the area code identified by the first verification from among the saved connection notifications, and compares the time data included in that notification with the time read from the image in the request (step ST45).
[0226] In the above-mentioned verification, the difference between the two types of time to be verified is compared with an allowable value that is larger than the allowable value used in the second verification. The authentication server 1 performs an authentication decision that combines the results of the first verification and the second verification and the result of the verification in step ST45, and transmits the decision result to the user terminal 2 (steps ST46 and ST47). Only when the verification result flags for both the first verification and the second verification are turned on and it is determined in the verification in step ST45 that the time difference does not exceed the allowable value, will the notification from the authentication server 1 be a notification of permission.
[0227] According to the procedure shown in FIG. 25, when a user launches the request application 200 and starts capturing a set of the two-dimensional code 5 and the time display 6 on the dedicated application screen, the two-dimensional code 5 is quickly read, the connection between the user terminal 2 and the dedicated terminal is quickly completed, and the request transmission button 20 is displayed. If the user immediately performs a request transmission operation in response to this display, the time from connection to the dedicated terminal to transmission of the request can be kept to approximately 1 to 2 seconds. Therefore, if the tolerance value used for the verification in step ST45 is set to a value within the range of approximately 2 to 5 seconds, most legitimate requests transmitted from the site can be permitted. Even if the operation of the request transmission button 20 is delayed for some reason, the verification result flag in step ST45 is turned off (NG), and a denial notice is transmitted from the authentication server 1, the process can be repeated from step ST31, so the user at the site will not suffer any disadvantage (i.e., will not be able to obtain a character image).
[0228] 25 is performed, the request send button 20 will not be displayed on the screen of the request application 200 unless the user terminal 2 is connected to the dedicated terminal, and it is impossible to send a request to the authentication server 1 from outside the area where communication with the dedicated terminal is possible or from a location where the screen of the dedicated terminal cannot be photographed. Moreover, the processing of step ST45 in the authentication server 1 allows only requests where the difference between the time very close to the time the request send button 20 was displayed on the user terminal 2 (the time immediately after the connection permission was sent) and the time immediately after the still image was photographed is within the allowable range, so the possibility of an unauthorized request being permitted is extremely low.
[0229] 24 and 25 can also be executed by displaying only a general two-dimensional code 5N that is not combined with the time display 6 on the dedicated terminal. In this case, the verification process performed by the authentication server 1 will be only the first verification that targets the read information of the two-dimensional code 5N, but by making the two-dimensional code 5N displayed on the dedicated terminal different each time and introducing a mechanism that sends the correct read information of this two-dimensional code 5N to the dedicated terminal and that only user terminals 2 that are authorized to connect to the dedicated terminal can send requests, it is possible to prevent unauthorized requests from being accepted from locations where communication with the dedicated terminal is impossible or where the display screen of the dedicated terminal cannot be photographed.
[0230] Figure 26 shows the processing procedure when only a general two-dimensional code 5N is displayed on a dedicated terminal and information processing is performed in accordance with Figure 25. In Figure 26, the same processes as in the example in Figure 25 are given the same reference numerals as in Figure 25, and processes that have been changed from the example in Figure 25 are given reference numerals that have an A added to the original reference numeral.
[0231] The dedicated terminal in this example also displays a two-dimensional code in which a code that combines a passcode that is different each time with the authentication code transmitted from the authentication server 1 is embedded. However, the time display 6 is not displayed on this screen (step ST31A).
[0232] As in the example of Figure 25, in response to the user terminal 2 reading the above two-dimensional code, a connection request is sent to the dedicated terminal, and a connection notification is sent from the dedicated terminal that has accepted the connection request to the authentication server 1, and the notification is stored in the authentication server (steps ST32 to ST37).
[0233] On the other hand, the user terminal 2 that has been permitted to connect does not display the request transmission button 20 or take a still image (steps ST38 and ST41 in FIG. 25), but instead performs a request generation process immediately after the connection is permitted (step ST42A). This request includes the information read from the two-dimensional code in step ST32 and the current time data acquired after the information was read.
[0234] When the above request is generated, the user terminal 2 transmits a response to the connection permission to the dedicated terminal (step ST39A), and transmits a request to the authentication server 1 (step ST43). In response to the transmission of the response, the dedicated terminal disconnects the connection with the user terminal 2 (step ST40).
[0235] Upon receiving the request, the authentication server 1 compares the read information in the request with the registered authentication code (step ST44A), compares the time indicated by the current time data included in the latest connection notification from the dedicated terminal corresponding to the area code identified by this comparison with the time indicated by the current time data in the request (step ST45A), and performs an authentication decision based on the comparison results (step ST46).
[0236] In this way, even when only a general two-dimensional code 2N is displayed on a dedicated terminal, a highly accurate authentication result can be obtained by comparing the time represented by the time data included in the connection notification from the dedicated terminal displaying the two-dimensional code 2N with the time represented by the time data in the request sent from the user terminal 2 that read the two-dimensional code 2N.
[0237] At the beginning of the explanation of the fourth embodiment, it was explained that the connection passcode portion of the two-dimensional code 5 is changed by encryption on the dedicated terminal, but security can be made even stronger if the entire code including the authentication code is changed each time.
[0238] For example, an initial screen similar to that of the third embodiment (see FIG. 21(A)) is displayed on the user terminal 2, and in response to operation of the connect button 22 on this screen, the user terminal 2 sends a connection request to the dedicated terminal, which in turn sends a code issuance request to the authentication server 1. In response to this request, the authentication server 1 encrypts the authentication code linked to the area code corresponding to the dedicated terminal using random numbers and sends the encrypted code to the dedicated terminal. The dedicated terminal then encodes this code plus the encrypted passcode into a two-dimensional code 5 and displays it on the display unit.
[0239] Even in the above arrangement, the dedicated terminal can issue permission for connection by verifying the passcode portion extracted by the user terminal 2 from the read information of the two-dimensional code 5. The authentication server 1 can also smoothly perform the first verification by linking the encryption code sent to the dedicated terminal or the key information used for encryption to the original authentication code and storing it in its internal memory. Since the authentication code cannot be obtained by reading the displayed two-dimensional code 5 with general reading software, the security of the authentication server 1 is also improved.
[0240] If the authentication code is changed each time by encryption, the passcode may be removed from the requirements for connection with the dedicated terminal, and the two-dimensional code 5 encoded with only the authentication code may be displayed. In this case, too, the user terminal 2 transmits all of the information read from the two-dimensional code 5 to the dedicated terminal, and the dedicated terminal compares the received read information with the two-dimensional code 5 being displayed. If the two match, the dedicated terminal may issue permission for connection to the communication terminal device, and the process may proceed in the same manner as in Figures 24, 25, and 26.
[0241] In either case, by varying the content of the two-dimensional code 5 displayed on the dedicated terminal each time, it is possible to almost ensure that only one user terminal 2 that first reads the displayed two-dimensional code 5 and is connected to the dedicated terminal can send a request to the authentication server 1.
[0242] <Common arrangement between the third and fourth embodiments> The combination of the two-dimensional code 5 and the time display 6 displayed on the dedicated terminals of the third and fourth embodiments is not limited to the form shown in Fig. 4, and it is also possible to apply the form of Fig. 5 and display a general two-dimensional code 5N in parallel with the time display 6. It is also possible to display a barcode instead of the two-dimensional code 5N.
[0243] In each embodiment, the authentication server 1 transmits an authentication code to the dedicated terminal, and the dedicated terminal generates and displays a two-dimensional code with information including the authentication code embedded therein, but in the third embodiment, the authentication server 1 can encode the authentication code into a two-dimensional code, and send an image of the two-dimensional code to the dedicated terminal for display. In the fourth embodiment, if the two-dimensional code does not include a passcode, the authentication server 1 can similarly generate a two-dimensional code and send an image of the code to the dedicated terminal.
[0244] In each embodiment, the basic matching process has been described as being the same as in the first embodiment, but it is also possible to add some kind of two-dimensional pattern to the display screen of the two-dimensional code 5 and the time display 6 of the dedicated terminal, and to provide the authentication server 1 with a function to perform a third matching process similar to that of the second embodiment.
[0245] In each embodiment, Bluetooth (registered trademark) is used to connect the dedicated terminal and the user terminal 2, but since the connection is limited to a very short time, the means of connection can also be changed to Wi-Fi. In all embodiments, the connection between the dedicated terminal and the user terminal 2 is very short, and in the third embodiment, the passcode displayed for connection changes each time, and in the fourth embodiment, the two-dimensional code 5 displayed can also be different each time, so security can be sufficiently ensured even with a connection via Wi-Fi.
[0246] When Wi-Fi is used in the fourth embodiment, the two-dimensional code 5 including the IP address of the dedicated terminal without encryption is displayed on the display unit of the dedicated terminal, and all of the read information of the two-dimensional code 5 or information excluding the IP address is transmitted from the user terminal 2 to the dedicated terminal, thereby enabling the dedicated terminal to perform verification equivalent to steps ST24 and ST34. Furthermore, by providing the dedicated terminal with an access point function and allowing the user terminal 2 to be directly connected to the dedicated terminal, security can be further enhanced.
[0247] In the third and fourth embodiments, it is desirable to have one-to-one communication between the dedicated terminal and the user terminal 2, but if the dedicated terminal has the capability to handle this, processing for multiple user terminals 2 may be performed in parallel.
[0248] <Common arrangements for the first to fourth embodiments> (1) In each of the first to fourth embodiments, the request application 200 is provided with a dedicated photographing function. However, it is also possible to link photographing software that is pre-installed on the user terminal 2 with the request application 200, and have the pre-installed software photograph the set of the two-dimensional code 5 and the time display 6. In this case, a still image is captured in response to operation of a shutter button on the screen of the pre-installed software instead of the request transmission button 20, and a request including the captured still image is transmitted to the authentication server 1. Therefore, an operation on the shutter button, like an operation on the request transmission button 200, is also an operation for accessing the authentication server 1.
[0249] It is not always necessary to operate the request transmission button 20 or the shutter button to generate a still image to be included in the request to the authentication server 1. For example, in the first to third embodiments, a still image may be captured in response to the extraction of three finder patterns fp1, fp2, and fp3 by the code extraction unit 203. The request application of the fourth embodiment can also be modified to capture a still image in response to receiving connection permission from the dedicated terminal, and to transmit a request to the dedicated terminal immediately after the capture.
[0250] It is not necessary to take still images; a frame image at a certain point in time may be captured while continuing video recording that has been taking place since before the request could be sent, and a request including this captured image may be sent to the management server 1.
[0251] (2) In the first to third embodiments, the request application 200 only determines whether or not the captured image contains a two-dimensional code 5, without reading the two-dimensional code 5. However, the request application 200 may also read the two-dimensional code 5 and transmit a request including the read information, the captured image, and current time data to the authentication server 1. In the fourth and fifth embodiments, the information read from the two-dimensional code 5 may also be included in the request to the authentication server 1. In either case, the two-dimensional code 5 may be read from the captured image when the image to be included in the request is captured, or it may be read at a time before the image is captured, for example, when the finder patterns FP1 to FP3 are extracted by the code extraction unit 203.
[0252] When a request including read information of the two-dimensional code 5 is sent from the user terminal 2, the authentication server 1 that receives it reads only the time from the image in the request, and for the first matching, it can match the read information in the request with the authentication code registered in the area information storage unit 100. However, if the authentication server 1 also reads the image of the two-dimensional code 5, compares the read information with the read information included in the request, and, if the two match, proceeds to matching with the registered information in the area information storage unit 100, the reliability of the result of the first matching can be significantly improved.
[0253] (3) Furthermore, the request application 200 may be provided with a function for reading the time displayed on the time display 6 in the captured image. In this case, the request sent from the user terminal 2 to the authentication server 1 may not include an image, but may include the read information for the two-dimensional code 5 and the time, the current time data acquired after the image to be read was generated, and the user code. All of this information may be read not only from a still image but also during video capture. In this case, the current time data is acquired at the time of the time read process or immediately thereafter.
[0254] Upon receiving the request, the authentication server 1 extracts various information from the request, and then performs a first check to compare the read information of the two-dimensional code 5 with the authentication code stored in the area information storage unit 100, and a second check to compare the time indicated by the read time information with the time indicated by the current time data. If the first check determines that there is an authentication code that matches the read information, and if the second check determines that the difference between the two types of time is within an allowable value, the request can be approved. In this way, authentication decisions can be made at a level equivalent to that of the first embodiment.
[0255] Furthermore, by placing a two-dimensional pattern of any shape inside or around the two-dimensional code 5, and registering numerical values representing the relative positional relationship between multiple feature points in the two-dimensional pattern and the two-dimensional code 5 in the authentication server 1, and also including the captured image in the request of the above configuration from the user terminal 2, it is possible to add a matching process to the authentication server 1 that corresponds to the third matching in the second embodiment.
[0256] (4) In anticipation of a case where an image obtained by photographing the two-dimensional code 5 and the time display 6 placed in a registered area is used to tamper with the image so that a permission notice from the authentication server 1 can be received in a location other than the registered area, the authentication server 1 may be provided with a function to detect image tampering. Also, in order to easily detect unauthorized access from a location that is clearly different from the registered area, the location information of each area may be registered in the area information storage unit 100, and the request from the user terminal 2 may include the location information obtained from GPS, and verification based on the location information may be performed before the first verification and the second verification.
[0257] (5) In the first to fourth embodiments, the requirement for generating a request is that the two-dimensional code 5 or 5N and the time display 6 are photographed simultaneously. However, as shown in FIG. 5, if a typical two-dimensional code 5N and the time display 6 are placed at a predetermined distance from each other, the distance may be slightly increased, and the two-dimensional code 5N (or a barcode) and the time display 6 may be photographed in sequence within a certain period of time, and a request including each photographed image and current time data may be sent to the authentication server 1.
[0258] Instead of the above method, a two-dimensional code 5N (which may also be a barcode) and a time display 6 may be displayed on the display device in sequence at predetermined intervals, and when the user terminal 2 photographs them, a request including each photographed image and current time data may be sent to the authentication server 1.
[0259] When photographing the two-dimensional code 5N and the time display 6 in sequence, the two-dimensional code 5N is read from the photographed image, and a request including the read information, an image of the time display 6, and current time data obtained at the time the time display 6 was photographed or immediately thereafter is sent to the authentication server 1. The authentication server 1 then performs a first comparison to compare the read information of the two-dimensional code 5N with the authentication code registered in the area information storage unit 100, and a second comparison to compare the time read from the image of the time display 6 with the time indicated by the current time data, and an authentication decision can be made based on the results of these comparisons.
[0260] (6) In each embodiment, it is assumed that the time on the time display 6 is displayed numerically, with the year, month, day, hour, and minute values being displayed. However, if the possibility of a request being sent during the midnight period is extremely low and requests including the time of that period can be invalidated, it is acceptable to display only the hour and minute. In that case, the time display 6 is not limited to a digital display, and an analog clock with a second hand (one that accurately displays the time down to the second) may also be used.
[0261] <Fifth Example> A dedicated terminal is also used in the fifth embodiment, but in this embodiment the dedicated terminal does not communicate with the user terminal 2, and communication with the authentication server 1 is limited to receiving information about the two-dimensional code to be displayed. In this embodiment, the user terminal 2 is not equipped with dedicated software for sending requests, and requests to receive character images are made by accessing a reception page on the Internet managed by the authentication server 1.
[0262] The dedicated terminal of the fifth embodiment displays a two-dimensional code 5N in a general format, but does not display an image of the time display 6. However, as will be explained below, the code information embedded in the two-dimensional code 5N of this embodiment includes data representing the time.
[0263] 27 shows the data structure of a two-dimensional code 5N used in Example 5. In this example, three types of information, namely a reception URL, an authentication code, and time data, are used as source data, and code information is created in the form of a reception URL followed by the authentication code and time data as parameters, and this is then converted into a two-dimensional code 5N.
[0264] The reception URL is the address of the reception page described above. In this embodiment, the reception URL is assumed to be fixed information, but this is not limiting, and the reception URL may be changed as appropriate, or a separate reception URL may be set for each area.
[0265] As in the first to fourth embodiments, the authentication code is a code for identifying one of a plurality of areas registered in the area information storage unit 100. The authentication server 1 of the fifth embodiment periodically updates the authentication code of the two-dimensional code 5N displayed on the dedicated terminal by generating a code for each area registered in the area information storage unit 100 using a combination of random numbers and symbols every time a certain period of time passes and transmitting this code to the dedicated terminal.
[0266] The time data indicates the time just before the dedicated terminal displays the 2D code 5N or when it starts to display it, and is data in seconds, including the year, month, and day. The time data also changes over time.
[0267] Fig. 28 is a sequence diagram showing the flow of processing (from when an authentication code is generated by the authentication server 1 for a specific area at a certain point in time to when the result of authentication determination based on the authentication code is transmitted to the user terminal 2) performed using a two-dimensional code 5N in which the authentication code is embedded. Fig. 29 shows the detailed procedure of the matching processing performed in step ST59 of Fig. 28 (each step is indicated by the symbols ST101 to ST109). The information processing performed in the fifth embodiment will be described below with reference to these two figures.
[0268] First, refer to FIG. When it is time to update the authentication code, the authentication server 1 uses an internal random number generating function to obtain a predetermined number of random numbers, and generates a new authentication code using these and a predetermined number of symbols (step ST51). This authentication code is linked to the area code of the target area and registered in the area information storage unit 100. At this time, the authentication code registered one step before is deleted or invalidated.
[0269] The authentication server 1 transmits code information with the above authentication code added as a parameter to the reception URL (in the example of FIG. 27, this would be "https: / / www.ABCD.com / uketuke-main / ?code=5968hfo%399af") (step ST52). The dedicated terminal that receives this transmission adds a code representing a parameter based on the current time data acquired from its own clock function ("&time=2024-04-10-15:00:00" in the example of FIG. 27) to the received code information, and generates an image of the two-dimensional code 5N with the processed code information embedded (step ST53).
[0270] The two-dimensional code 5N is displayed immediately after being generated and remains displayed for a predetermined time (step ST54). At that time, when a user near the dedicated terminal activates the photographing function of his / her user terminal 2 and starts photographing the two-dimensional code 5N displayed on the screen of the dedicated terminal, the standard two-dimensional code reading function of the user terminal 2 is activated and the reading process of the two-dimensional code 5N is started (step ST55).
[0271] After reading the two-dimensional code 5N, the user terminal 2 accesses the reception URL by transmitting the read information to the Internet using the communication software (browser) installed on the user terminal 2 (step ST56). In response to this access, the authentication server 1 acquires the time when the access was received (step ST57), extracts the authentication code and time data from the parameter portion of the information received from the user terminal 2 (step ST58), and executes a matching process for these pieces of information (step ST59).
[0272] In this embodiment, two types of verification processing are executed in order. In the following, the verification processing executed first is referred to as "first verification," and the verification processing executed after that is referred to as "second verification." Here, the specific contents of each collation process will be described with reference to FIG.
[0273] In the first verification, the time indicated by the time data received from the user terminal 2 (extracted in step ST58 of FIG. 28) is verified against the time at which the access from the user terminal 2 was accepted (acquired in step ST57 of FIG. 28) (step ST101). If the difference between the two types of time is equal to or less than a predetermined allowable value ("YES" in step ST102), the authentication server 1 sets the verification result flag of the first verification to ON (OK) (step ST103) and proceeds to the second verification.
[0274] Note that the "time when access is accepted" refers to the time when authentication server 1 analyzes the received information and recognizes it as read information, but since the difference between that time and the time when the read information reaches authentication server 1 is small, "time when access is accepted" can also be rephrased as "time when read information is received."
[0275] In the second verification, the authentication code received from the user terminal 2 (extracted in step ST58 in FIG. 28) is verified against the authentication codes registered in the area information storage unit 100 (step ST104). The object of verification on the area information storage unit 100 side is the latest authentication code linked to each area code.
[0276] If the above comparison finds information that matches the authentication code received from the user terminal 2 (step ST105: "YES"), the authentication server 1 acquires the area code corresponding to the information (step ST106) and sets the comparison result flag for the second comparison to on (OK) (step ST107).
[0277] On the other hand, if no information matching the authentication code received from the user terminal 2 is found (step ST105 is "NO"), the matching result flag for the second matching is set to off (NG) (step ST109). Also, if the difference between the two types of time in the first matching exceeds the allowable value (step ST102 is "NO"), the authentication server 1 sets the matching result flags for both the first matching and the second matching to off without proceeding to the second matching (step ST108).
[0278] In the above, in order to quickly determine whether or not access is permitted when there is a clear discrepancy in time, the first check is made on the time and the second check is made on the authentication code, but the order of these checks may be reversed and each check may be performed in the same order as in the previous embodiments.
[0279] Returning to reference to FIG. When the above-mentioned matching process is completed, the authentication server 1 performs an authentication decision based on the matching result flags of each match (step ST60), and notifies the user terminal 2 of the decision result (step ST61). In this embodiment, too, a permission notice is issued only when the matching result flags of both the first and second matches are on, and a denial notice is issued in other cases.
[0280] The permission notification is sent by transmitting a download URL (under the control of the game server 3) for the character image linked to the area code acquired in step ST106 of Fig. 29. By accepting this transmission via a browser, the user terminal 2 can access the download URL and receive the character image after automatic authentication similar to that described in the first embodiment.
[0281] The denial notification is sent by sending the URL of a web page that displays a message indicating that the request is not permitted. In this case, the user terminal 2 is still connected to the web page of this URL, but since the web page is under the control of the authentication server 1, the user terminal 2 will not be connected to the game server 3 if the request is not permitted.
[0282] According to the above series of processes, the user terminal 2 can receive the character image by the general method of reading the two-dimensional code 5N displayed on the dedicated terminal and transmitting the read information to the Internet.
[0283] Although not shown in Figure 28, the authentication server 1 updates the authentication code every fixed time (for example, one minute) and transmits the new authentication code to the dedicated terminal. The dedicated terminal also updates the display of the two-dimensional code 5N by obtaining the latest time data from its own clock function and executing steps ST53 and ST54 every fixed time (for example, three seconds) that is shorter than the period until the authentication code is updated. Alternatively, the time interval between the authentication server 1's authentication code update and transmission to the dedicated terminal can be shortened, and the dedicated terminal can obtain the latest time data and execute steps S53 and S54 every time it receives a new authentication code, so that both the authentication code and the time data are changed every time the display of the two-dimensional code 5N is updated.
[0284] By updating both the authentication code and the time data in this way, the dedicated terminal can continue to display the two-dimensional code 5N while frequently changing the content of the displayed two-dimensional code 2N. Therefore, no matter when the two-dimensional code 5N is read, the difference between the time indicated by the time data embedded in the two-dimensional code 5N and the time when the user terminal 2 accesses the authentication server 1 can be made very small.
[0285] Therefore, if an image of the two-dimensional code 5N displayed on the dedicated terminal at a certain point in time or information read from the two-dimensional code 5N is transmitted to the outside, and the transmitted information is used to estimate the length of time it would take for fraudulent activity to access the authentication server 1 from a location other than the area where the dedicated terminal is deployed, the display of the two-dimensional code 5N on the dedicated terminal 2 is updated at time intervals shorter than that estimated time, and the allowable value for the first matching is set to a value slightly larger than that display time, then most fraudulent accesses based on the above assumption can be denied by the first matching alone.
[0286] If an unauthorized act is committed by rewriting the time data portion of the information read from the two-dimensional code 5N displayed on the dedicated terminal and then reading the rewritten two-dimensional code 5N to access the authentication server 1, the first verification may give a result of "OK." However, since rewriting the code should also take a considerable amount of time, if the time required to perform the rewriting and execute the unauthorized access is estimated, and the authentication code is updated at intervals much shorter than this estimated time, this type of unauthorized access can also be denied by the second verification.
[0287] In this way, even in the fifth embodiment, it is possible to prevent with a high degree of certainty unauthorized access from locations outside the registered area. On the other hand, a bona fide user can easily receive a character image by photographing the two-dimensional code with the camera 25 and accessing the download page, a method familiar to everyday life.
[0288] In the above example, the download URL is sent immediately as the permission notification, but instead, a method may be adopted in which a web page with a link to the download URL is set up under the management of the authentication server, and the URL of this web page is sent as the permission notification. In other words, a method may be adopted in which the user is prompted to access the download page, as in the previous embodiments.
[0289] In the process of generating the two-dimensional code 5N by the dedicated terminal (step ST53 in FIG. 28), time data indicating a time a predetermined time after the current time can be added to the code information provided by the authentication server 1 and encoded into the two-dimensional code 5N, and the two-dimensional code 5N can be displayed at the time indicated by the added time data. In this way, it is possible to display a two-dimensional code with embedded time data indicating the time when the display started.
[0290] Although it depends on the capabilities of the authentication server 1, a server system with standard functions can accept multiple accesses at the same time. Therefore, even if the screen of a dedicated terminal is photographed by multiple user terminals 2 and these user terminals 2 access the authentication server 1 at almost the same time, each access can be accepted individually and a permission notification can be sent.
[0291] Other methods for varying the two-dimensional code 5N displayed on the dedicated terminal are possible. For example, the authentication server 1 may generate multiple authentication codes with different contents in advance and determine the scheduled display times for those authentication codes. A data file containing combinations of these authentication codes and the scheduled display times may be sent to the dedicated terminal, and the dedicated terminal may update the display at the scheduled display times according to the information in the data file. Alternatively, the authentication server 1 may generate an image of the two-dimensional code 5N each time and send that image to the dedicated terminal in advance. Alternatively, the authentication server 1 may periodically generate multiple pieces of code information each containing an authentication code and time data indicating the scheduled display times, and send the code information or an image of the two-dimensional code 5N converted from the code information to the dedicated terminal. In these cases, too, the dedicated terminal can display the two-dimensional code 5N with embedded time data indicating the time when the display started by displaying the two-dimensional code 2N based on the information received from the authentication server 1 at the scheduled display time embedded therein. The authentication server 1 can also execute the matching process shown in Fig. 29 by registering a combination of each authentication code and scheduled display time and validating them in turn as time passes.
[0292] The display mode of the two-dimensional code 5N of the dedicated terminal may not be maintained for a long time, but may be terminated in a short time, and a two-dimensional code 5N having a different authentication code and time data immediately before or at the start of display embedded therein may be displayed each time.
[0293] For example, an operation button for instructing the display of a two-dimensional code 5N can be provided on a dedicated terminal, and when this button is operated, a request for issuing new code information is sent from the dedicated terminal to the authentication server 1. In response to this request, the authentication server 1 generates and sends the code information, adds current time data to it, and displays the encoded two-dimensional code 5N. By clearing the screen after a certain period of time or in response to an end operation, it is possible to display two-dimensional codes with different authentication code and time data contents each time a display instruction operation is performed.
[0294] It is also possible to send only one authentication code from the authentication server 1 to the dedicated terminal, or to extend the time interval for updating the authentication code, and to repeat the process of encrypting the authentication code with a different encryption key each time on the dedicated terminal and displaying the two-dimensional code 5N with code information including the authentication code embedded in it.In this case, too, by sending the encrypted authentication code or encryption key from the dedicated terminal to the authentication server 1, the authentication server 1 can perform the second verification without any problems.
[0295] In the fifth embodiment, including the arrangements described above, the user terminal 2 may be provided with dedicated software for sending a request to the authentication server 1, and the software may read the two-dimensional code 5N and transmit a request to the authentication server 1 including the read information and current time data acquired by the user terminal 2 using its own clock function after the time of reading. In the first verification by the authentication server 1, the time included in the read information in the request may be verified against the time indicated by the current time data in the request. In this way, the tolerance used in the first verification can be made smaller, thereby increasing the accuracy of the verification.
[0296] Since the process from reading the two-dimensional code 5N by the dedicated software to sending the request is instantaneous, the time indicated by the current time data included in the request can be considered to represent the time when the two-dimensional code 5N was read or the time when the read information was sent. Furthermore, when using dedicated software, the access address can be registered in the software in advance, making it possible to access the authentication server 1 from the user terminal 2 without including a reception URL in the two-dimensional code 5N. Furthermore, when using dedicated software, a barcode with an embedded authentication code and time data can be used instead of the two-dimensional code 5N.
[0297] <Application to information processing systems other than those shown in Figure 1> The information processing mechanisms shown in the first to fifth embodiments can be incorporated into information processing systems for various purposes, not limited to the information processing system shown in Fig. 1. Several specific examples will be described below. Note that the fourth embodiment also includes the arrangements shown in Figs. 25 and 26.
[0298] (1) The request application 200 and authentication server 1 of each embodiment can be used to provide various digital information, such as image data other than character images and music data. In either case, they can be used to provide rare information to only those who have paid to enter a paid facility such as a movie theater, theme park, concert hall, or baseball stadium, thereby improving customer service and increasing the operator's profits. Furthermore, since it is possible to prevent fraudulent requests from being approved with a high degree of accuracy, facility operators and information providers can grasp how many people they have provided information to at each facility and how much revenue they have earned from their services, thereby improving the accuracy of cost-effectiveness analysis of their services.
[0299] The items provided to customers are not limited to digital information; real prizes such as mascot dolls and posters can also be offered. For example, a private website can be set up to accept applications for desired prizes, and the authentication server 1 can send a permission notice including the URL of the website to a user terminal 2 that accesses the authentication server 1 by photographing a set of two-dimensional code 5 and time display 6 or a two-dimensional code 5N containing time data at the application venue. This makes it possible to restrict applications for the prize to those outside the application venue. Furthermore, a prize can be smoothly handed over by sending an image of the prize to the user terminal 2 after completing the application, and then showing the image to the operation staff to receive the prize.
[0300] In either case, the conditions for granting a privilege can be added to the condition of having entered an area registered in authentication server 1, as well as having engaged in an activity in that area that benefits the operator or its affiliates, such as shopping or dining. For example, if downloading information such as images is made possible upon receiving a permission notice from authentication server 1, the user can present a set of two-dimensional code 5 and time display 6 or a two-dimensional code 5N containing time data upon completing payment for a purchase, etc., and when the request sent by photographing them is approved by authentication server 1 and directed to a website for downloading, the payment amount can be sent to the website by manual entry or by sending a photograph of the receipt, etc., and the higher the transmitted amount, the more rare the information that becomes available for download becomes.
[0301] (2) The request application 200 and authentication server 1 of the first to fourth embodiments can also be used for a service that awards service points to customers who shop or dine at a store. In this case, the authentication server 1 works in conjunction with a point management server, and the area information storage unit 100 registers the identification code (hereinafter referred to as "store ID"), name, address, authentication code, etc. of each store. In addition, the request application 200 according to each embodiment and application software for communication with the point management server (hereinafter referred to as "point management application") are installed in the user's user terminal 2.
[0302] The store presents the combination of the two-dimensional code 5 and the time display 6 to the customer who has completed payment, for example by displaying it on a display device. In this case, the two-dimensional code 5 can include a numerical value indicating the amount paid in addition to the authentication code. A request is sent to the authentication server 1 from the user terminal 2 that photographed the two-dimensional code 5 and the time display 6, and if the request is permitted by the authentication server 1, the authentication server 1 sends an authorization notice to the user terminal 2 that sent the request, the authorization notice including a URL for accessing the points management server, the store ID linked to the authentication code that was confirmed to match the read information of the two-dimensional code 5, and the payment amount information read from the two-dimensional code 5.
[0303] The permission notification is passed from the request application 200 of the user terminal 2 to the point management application. The user terminal 2, in which the point management application is activated, accesses the URL included in the permission notification, and after being connected to the point management server through user authentication and access permission similar to those described in the first embodiment, transmits the store ID and payment amount information included in the permission notification to the point management server. In response, the point management server calculates service points according to the payment amount, adds them to the user's points, and transmits a notification including the added points to the user terminal 2. The point addition process is performed for each store or for each group, such as a region, based on the store ID transmitted from the user terminal 2.
[0304] When the fifth embodiment is applied to cooperation with the point management server, upon completion of payment, the dedicated terminal adds time data and payment amount information as parameters to the code information provided by the authentication server 1, and converts this processed code information into a two-dimensional code 5N and displays it. Then, the authentication server 1 that processes the read information of this two-dimensional code 5N can also issue a permission notification in the form of a URL in a format in which the store ID and payment amount information are added as parameters to the URL for accessing the point management server, and the user terminal 2 that receives this notification can access the URL to make the point management server recognize the store ID and payment amount information.
[0305] Each time a payment is completed, a request for issuing new code information is sent from the dedicated terminal to the authentication server 1, and if the authentication server 1 responds to this request with code information containing a different authentication code each time, the two-dimensional code 5N may be displayed without time data. Even in this case, the method shown in Fig. 26 can be applied to notify the authentication server 1 of the time when the dedicated terminal displayed the two-dimensional code 5N or the time immediately after it was displayed, and the authentication server compares the notified time with the time when it received the read information from the user terminal 2. Access to the point management server is only permitted if the difference between these times is within an allowable value and the authentication code comparison result is "OK", thereby extremely reducing the possibility of unauthorized access being permitted.
[0306] In either method, it is not necessarily necessary to include payment amount information in the information sent to the authentication server 1, and payment amount information can also be sent after the user terminal 2 is connected to the point management server. For example, the user can manually input and send the payment amount in front of the store clerk, or the store's cash register system can display a two-dimensional code or barcode with the payment amount embedded in it, which can then be read by the user terminal 2 and sent to the point management server.
[0307] The number of point management servers is not limited to one, and once the request is approved by the authentication server 1, it is possible to connect to an existing point management server of a major company and perform point update processing according to the method defined by that server system.
[0308] The above information processing allows users to accumulate service points at each store they visit, without the need to carry multiple point cards. Stores also no longer need to issue point cards, eliminating the need to worry about points earned from using their own stores being transferred to other stores, and encouraging repeat customer use. This system can be integrated with point services offered by small, non-digitalized stores, as well as digitalized point services offered by major companies, allowing for centralized management of various point services. User authentication when accessing the point management server can also be performed automatically, as described for the game server 3 in the first embodiment, eliminating any burden on users.
[0309] (3) The request application 200 and authentication server 1 of the first to fifth embodiments can also be used for attendance management. When the first to fourth embodiments are applied, for example, a set of a two-dimensional code 5 embedded with an authentication code unique to the business and a time display 6 is installed at the employee entrance of the business, or displayed on a display device. The authentication server 1 is linked to a management server, and application software for communication between the request application 200 and the management server (hereinafter referred to as a "communication application") is installed in each employee's user terminal 2. Personal information including each employee's identification code (hereinafter referred to as an "employee ID") is registered in the management server, and the employee ID and the URL of the data entry page of the management server are registered in the communication application. It is desirable to update the authentication code embedded in the two-dimensional code 5 as needed.
[0310] When each employee arrives at work or leaves work, they take a photo of the set of the two-dimensional code 5 and the time display 6 on the user terminal 2 on which the request application 200 is running, and perform a request transmission operation, which causes a request to be sent from the user terminal 2 to the authentication server 1. An authorization notification from the authentication server 1 that authorizes this request is passed from the request application 200 to the communication application, which then becomes active. The user terminal 2 on which the communication application has started logs in to the management server using the employee ID (automatic login can also be enabled in this case), and accesses the above URL of the management server.
[0311] Once the access is approved, a data entry screen is displayed on the user terminal 2, and the employee operates the selection buttons on the screen to send information such as arrival time, departure time, etc. to the attendance management server. This sent information also includes the current time data obtained from the clock function of the user terminal 2, and by saving the sent information in the attendance management server, it is possible to digitize the arrival time and departure time of each employee.
[0312] When the fifth embodiment is applied to attendance management, for example, a dedicated terminal connected to a motion sensor may be installed at an employee entrance / exit, and a two-dimensional code 5N containing a different authentication code and the current time data may be displayed for a certain period of time each time the motion sensor detects a person. In this case, too, a request for issuing new code information may be sent from the dedicated terminal to the authentication server 1 each time the code information is displayed, and the code information sent from the authentication server 1 plus the time data may be converted into the two-dimensional code 5N and displayed. Furthermore, by sending the URL of the data input page of the management server as a permission notification to the user terminal 2 that reads the two-dimensional code 5N and accesses the authentication server 1, information input from the user may be accepted.
[0313] When workers dispatched to designated sites for cleaning, construction, or other work are required to submit work reports, a set of a two-dimensional code 5 with an authentication code unique to that site embedded and a time display 6 can be installed or displayed on a display device for each site, or a two-dimensional code 5N with an authentication code and time data embedded can be displayed on a dedicated terminal, and after confirming that a request from the worker's user terminal 2 has been sent from the site in a manner similar to that used for attendance management, the user terminal 2 can be connected to the management server. Therefore, if the data input screen of this management server is configured so that text data representing the contents of the work report and image data taken at the site can be attached, the worker can create a detailed work report and send it to the management server.
[0314] For authentication decisions for attendance management and work management, the same method as described for the service point awarding service can be applied, and the method can be changed to use a 2D code 5N with code information that does not include time data.
[0315] According to the authentication method using the first to fifth embodiments, it is possible to extremely reduce the possibility that a request from a location other than the site where the set of the two-dimensional code 5 and the time display 6 or the dedicated terminal is installed will be approved, so that highly reliable information generated at the actual site can be transmitted to the management server. Workers can also accurately report the results of their work to the manager without having to submit work reports in the form of daily reports, etc., thereby reducing the burden on workers and improving the quality and efficiency of work.
[0316] As explained in the first embodiment, the user code included in the request to the authentication server 1 does not include personal information, and the user code is not used for authentication judgment, so it is possible to exclude the user code from the request. Therefore, the operator of the authentication server 1 can respond to requests from an unspecified number of users and analyze historical information without having to consider the management of each user's personal information.
[0317] Meanwhile, the management server allows employees and workers to log in using a unique identification code (automatic login is possible using a communication app), send the necessary information using user terminal 2, and saves this information linked to login history information, thereby making it possible to accurately record when, who, where, and what actions or tasks were performed.
[0318] (4) The authentication server 1 and the game server 3 of the information processing system (see FIG. 1) on which the first to fifth embodiments are based can be integrated into a single server system. Similarly, in the arrangements described above in (1) to (3), the authentication server 1 and the server that performs post-authentication processing can be integrated into a single server system.
[0319] In the integrated authentication system, the result of the authentication decision for a request from the user terminal 2 is not returned to the user terminal 2, and instead, upon making a decision to grant permission, processing corresponding to the request (sending a character image, etc., adding and notifying points, and allowing connection to a data input screen) can be performed.
[0320] <Example of 2D code 5 used for other purposes> FIG. 30 shows an example of a special two-dimensional code used for managing the distribution of goods. The two-dimensional code 5S in this example is based on a two-dimensional code 500 using Frame QR (registered trademark) similar to that illustrated in Figures 3 and 4, etc., and two rectangular patterns 501 and 502 containing character information are displayed in the central part of this two-dimensional code 500 where no coding pattern is provided.
[0321] As shown in Figure 30(A), rectangular patterns 501 and 502 may be arranged so that their vertical and horizontal directions match the two-dimensional pattern 500, but as shown in Figure 30(B), rectangular patterns 501 and 502 can also be arranged at an angle relative to the two-dimensional pattern 500.
[0322] In Figures 30(A) and 30(B), the two-dimensional code that combines two-dimensional code 500 and two rectangular patterns 501 and 502 is represented by the symbol 5S. Hereinafter, this two-dimensional code 5S will be referred to as "two-dimensional code 5S with text."
[0323] In this embodiment, the JAN code assigned to the item to be managed is embedded in the encoded portion (two-dimensional code 500) of the two-dimensional code with text 5S. Information representing the serial code of the item is written in rectangular pattern 501, and information representing the lot number of the item is written in rectangular pattern 502.
[0324] Therefore, by photographing this two-dimensional code 5S with text, the above three types of information can be obtained at once, and the three types of information can be extracted individually by reading the encoded portion of the image and the text within each of the rectangular patterns 501 and 502. However, it is not necessary to extract all three types of information at once; it is also possible to read only the encoded portion or only the text portion.
[0325] The coded portion (two-dimensional code 500) can be easily read using software with a Frame QR (registered trademark) reading function. Text information can also be read using general OCR software.
[0326] It is possible to embed the three types of information into conventional 2D codes, and by using dedicated software in which the format of that information has been registered, it is possible to separate and extract each piece of information from the information read from the 2D code. However, the most commonly used code in the distribution process is the JAN code linked to the POS system, and if the dedicated software is not installed at the transaction site and the JAN code cannot be read, there is a risk of disruption to the transaction.
[0327] However, with the text-included 2D code 5S of this embodiment, the encoded portion can be read using existing software for Frame QR (registered trademark), and the lot number and serial code can also be read individually using OCR software, greatly improving convenience. Each reading process can be performed using already established technology, so it is expected to be extremely versatile.
[0328] Furthermore, by fixing the relative positional relationship of each rectangular pattern to the encoded portion by printing, engraving, or other methods, this character-containing two-dimensional code 5S can also utilize the numerical value (feature value) representing that relative positional relationship as information specific to the item under management. There is no need to use a special method for printing or engraving, such as that described in Prior Art Document 5 (JP Patent Publication No. 2012-141729) listed in [Prior Art], and no special lighting is required for reading, so reading can be easily performed by applying existing technology.
[0329] Figures 31(A) and (B) illustrate the rules for calculating the above-mentioned feature quantities by showing only the contour lines of the encoded pattern of the two-dimensional code 500 of the two-dimensional code 5S containing text shown in Figures 30(A) and (B). In both examples, one vertex is determined as a feature point for each of the two rectangular patterns 501 and 502 in the two-dimensional code 5S containing text, and the distances La and Lb from the vertices of the corners of the finder patterns fp1 and fp2 that are closest to these feature points Qa and Qb are used as feature quantities that represent the relative positional relationship of each rectangular pattern with respect to the encoded portion.
[0330] Furthermore, in the example of Figure 31(B), for feature points Qa and Qb of a rectangular pattern that is arranged at an angle relative to the encoding portion, the angles θa and θb formed between the line representing the distance and one side of the two-dimensional code 500 are added to the feature.
[0331] 32 shows an example of the configuration of a server system (hereinafter abbreviated as "distribution management server") for distribution management using the above-mentioned two-dimensional text-containing code 5S. This distribution management server has the functions of accepting a request including a photographed image of the two-dimensional text-containing code 5S from a communication terminal device (not shown) with a photographing function such as a smartphone, analyzing the photographed image in the request, determining whether the two-dimensional text-containing code 5S is genuine, and returning traceability information of an item corresponding to the two-dimensional text-containing code 5S determined to be genuine to the communication terminal device that sent the request.
[0332] Specifically, the distribution management server of this embodiment includes a traceability information storage unit 400 that stores traceability information for an unspecified number of items, a code information storage unit 420 that stores information (JAN codes, serial codes, lot numbers) about the text-containing two-dimensional codes 5S assigned to these items, and a feature storage unit 421 that stores feature amounts of the rectangular patterns 501 and 502 of each text-containing two-dimensional code 5S and calculation rules for those features. These storage units 400, 420, and 421 are linked to each other via serial codes or the like. Furthermore, the feature storage unit 421 stores, as a reference size, the size (number of pixels) of one side of the text-containing two-dimensional code 5S in the image used to calculate the feature amounts for each registered text-containing two-dimensional code 5S.
[0333] Furthermore, the distribution management server of this embodiment is provided with the functions of a request processing unit 401, a two-dimensional code reading processing unit 402, an OCR processing unit 403, a rectangular pattern extraction unit 404, a feature calculation unit 405, a first matching processing unit 406, a second matching processing unit 407, a third matching processing unit 408, an authentication processing unit 409, and a browsing information creation processing unit 410.
[0334] In the above-mentioned distribution management server, when the request processing unit 401 receives a request including an image of a two-dimensional code 5S containing text from any communication terminal device, the encoded portion (two-dimensional code 500) of the two-dimensional code 5S containing text is read by the two-dimensional code reading processing unit 402, and the character information inside the rectangular patterns 501, 502 is read by the OCR processing unit 403.
[0335] The first verification processing unit 406 collates the information read by the two-dimensional code reading processing unit 402 with the JAN code registered in the code information storage unit 420. When a JAN code that matches the read information is found through this collation, the first verification result flag is turned on, and the serial code and lot number linked to the verified JAN code are passed to the second verification processing unit 407.
[0336] The second matching processing unit 407 matches the serial code and lot number with the character information read by the OCR processing unit 403. If this matching results in the read character information matching the serial code and lot number, the matching result flag for the second matching is also turned on, and processing by the rectangular pattern extraction unit 404 and the feature calculation unit 405 is executed.
[0337] A rectangular pattern extraction unit 404 extracts rectangular patterns 501 and 502 that surround the character information read by the OCR processing unit 403. A feature calculation unit 405 calculates the feature amounts of each of the rectangular patterns 501 and 502 in accordance with calculation rules registered in a feature storage unit 421. Of these feature amounts, the numerical values representing distances are corrected using a reference size, as in the second embodiment.
[0338] The third matching processing unit 408 matches the feature calculated by the feature calculation unit 405 with the feature associated with the serial code and registered in the feature storage unit 421. This matching method is also the same as the third matching in the second embodiment, and the matching result flag is set to ON only when the difference value is equal to or less than the allowable value for all combinations of feature amounts in a corresponding relationship.
[0339] When the respective matching result flags of the first matching processing unit 406, the second matching processing unit 407, and the third matching processing unit 408 are all turned on, the authentication processing unit 409 determines that the character-containing two-dimensional code 5S being processed is a legitimate code and passes the serial code in the code to the viewing information creation unit 410. The viewing information creation unit 410 reads information corresponding to this serial code from the traceability information storage unit 400 and creates a web page for viewing. A notification including the URL of this web page is sent from the request processing unit 401 to the communication terminal device that sent the request, allowing the user of the communication terminal device to view the traceability information.
[0340] According to the distribution management server having the above configuration, a user can view the traceability information of an item simply by taking a picture of the two-dimensional code 5S with text attached to the item in hand and sending a request including the photographed image to the management server. Therefore, business operators who conduct commercial transactions usually perform tasks such as inventory management, sales management, and delivery management by reading the two-dimensional code 500 of the two-dimensional code 5S with text using general-purpose software, and can access the distribution management server as needed to view the traceability information.
[0341] The third verification in the above embodiment is not a mandatory requirement, and the two-dimensional code 5S containing text may be authenticated based solely on the results of the first and second verifications. In this case, the rectangular patterns 501 and 502 may be eliminated, and only the text information may be placed in the center of the two-dimensional code 500.
[0342] The two-dimensional code 5S with text can be copied, and there is a possibility that the copy may be attached to a counterfeit item. However, by including information to distinguish between the authenticity of an item, such as a photographic image of the details of a genuine item and a description of features not publicly available, among the information registered in the traceability information storage unit 400, the user can determine with a high degree of certainty whether the item in his or her hands is genuine.
[0343] Furthermore, the distribution management server can be provided with a function to receive new information from the communication terminal device regarding the item corresponding to the character-containing two-dimensional code 5S being compared and register that information in the traceability information storage unit 400, upon determining that the code is genuine.
[0344] The above-mentioned distribution management server can be divided into a viewing server system including a traceability information storage unit 400 and a viewing information creation processing unit 410, and an authentication server system including other functions, and by applying the technique of the first embodiment described above, the authentication server system can be configured to send an authorization notification including a URL for accessing the viewing server system to the communication terminal device in response to authorizing a request from the communication terminal device.
[0345] The combination of information stored in the character-containing 2D code 5S is not limited to the above example, and the content of the combined information can be changed depending on the purpose. The character information to be incorporated is also not limited to two types, and three or more types of character information can be incorporated, provided that they fit into the blank space in the center of the encoded part and can be read individually, or conversely, only one type of character information can be incorporated. [Explanation of symbols]
[0346] 1 Authentication Server 2. Communication terminal equipment 6 Time display 5,5N 2D code 10 Request Processing Section 11 2D code reading processing unit 12 Time reading processing section 13 Current time data acquisition section 14 First matching processing unit 15 Second matching processing unit 16 Authentication processing section 100 Area information storage unit 110 Feature memory unit 111 2D pattern extraction unit 112 Feature calculation unit 113 Third matching processing unit 200 Request App 201 Main control unit 202 Communication control section 203 Code Extraction Unit 204 Time data acquisition unit 205 Request Generation Unit
Claims
1. A method executed by a server system in which the authentication code or information linked to the authentication code is registered and a communication terminal device having a photographing function, on the premise that a pattern code in which an authentication code associated with a specific location is embedded so as to be optically readable and a time display device showing the current time are arranged in the specific location in a positional relationship in which the authentication code and information linked to the authentication code can be photographed simultaneously, the method comprising: the communication terminal device, in response to receiving an operation for accessing the server system or extracting an image in a form that matches the pattern code from the image generated by the photographing while photographing using the photographing function, transmits the image generated after the operation or extraction to the server system together with time data indicating the time recognized by a clock function of the device after the generation of the image; An information processing method in which a server system that receives the above-mentioned transmission performs information processing to determine whether or not the following necessary conditions are met for authenticating that the image was sent from a communication terminal device with legitimate access authority: a first condition that the image sent from the communication terminal device contains a pattern code embedded with an authentication code that matches the information registered in the server system; and a second condition that the image sent from the communication terminal device contains an image representing the time, and the difference between the time represented by the image and the time represented by the time data sent with the image is within a predetermined tolerance value, and the server system determines whether or not to perform the authentication based on the result of the determination.
2. A method executed by a server system in which an authentication code or information linked to the authentication code is registered, a dedicated terminal device, and a communication terminal device having a photographing function, on the premise that a pattern code in which an authentication code associated with a specific location is embedded so as to be optically readable and a time display area showing the current time are displayed on the dedicated terminal device arranged in the specific location in a positional relationship that allows photographing of the pattern code and the time display area showing the current time simultaneously, the method comprising: the dedicated terminal device displays predetermined character information in response to being accessed by the communication terminal device, and after the display, in response to receiving information that matches the character information from the communication terminal device, displays a combination of a pattern code in which information including the authentication code is optically embedded and the time display area based on information previously received from the server system, and transmits a notification to the communication terminal device permitting photography; The communication terminal device that has received the notification starts taking an image using the photographing function, and in response to receiving an operation to access the server system or extracting an image having a form that matches the pattern code from the image generated by the photographing, transmits the image generated after the operation or extraction to the server system together with time data indicating the time recognized by the clock function of the device after the generation of the image, An information processing method in which a server system that receives the above-mentioned transmission performs information processing to determine whether or not the following necessary conditions are met for authenticating that the image was sent from a communication terminal device with legitimate access authority: a first condition that the image sent from the communication terminal device contains a pattern code embedded with an authentication code that matches the information registered in the server system; and a second condition that the image sent from the communication terminal device contains an image representing the time, and the difference between the time represented by the image and the time represented by the time data sent with the image is within a predetermined tolerance value, and the server system determines whether or not to perform the authentication based on the result of the determination.
3. A method executed by a server system in which an authentication code or information linked to the authentication code is registered, a dedicated terminal device, and a communication terminal device having a photographing function, on the premise that a pattern code in which an authentication code associated with a specific location is embedded so as to be optically readable and a time display area showing the current time are displayed on the dedicated terminal device arranged in the specific location in a positional relationship that allows photographing of the pattern code and the time display area showing the current time simultaneously, the method comprising: The dedicated terminal device displays a combination of a pattern code in which information including the authentication code is embedded so as to be optically readable and the time display area based on information previously received from the server system, and in response to receiving code information that matches the pattern code being displayed from the communication terminal device under this display state, transmits a notification to the communication terminal device permitting the communication terminal device to transmit an image generated by the device to the server system; the communication terminal device, in response to extracting the pattern code while photographing using the photographing function, reads the information and transmits at least a part of the read information to a dedicated terminal device, and, in response to receiving the permission from the dedicated terminal device in response to the transmission while photographing, in response to receiving an operation to access the server system or extracting an image in a form that matches the pattern code from an image generated by the photographing, transmits the image generated after the operation or extraction to the server system together with time data indicating the time recognized by a clock function of the device after the generation of the image; An information processing method in which a server system that receives the above-mentioned transmission performs information processing to determine whether or not the following necessary conditions are met for authenticating that the image was sent from a communication terminal device with legitimate access authority: a first condition that the image sent from the communication terminal device contains a pattern code embedded with an authentication code that matches the information registered in the server system; and a second condition that the image sent from the communication terminal device contains an image representing the time, and the difference between the time represented by the image and the time represented by the time data sent with the image is within a predetermined tolerance value, and the server system determines whether or not to perform the authentication based on the result of the determination.
4. a storage means for registering an authentication code associated with a specific location or information linked to the authentication code; a receiving means for receiving, from any communication terminal device having a photographing function, transmission of information including an image generated by the device through photographing and time data representing the time recognized by the device through its own clock function after the generation of the image; a code reading means for extracting a pattern code in which predetermined code information is embedded so as to be optically readable from the image in the information received by the receiving means, and for executing a reading process on the extracted code; a time reading means for extracting an image representing a time from the image and reading the time; a first verification means for verifying the code information read by the code reading means with the information registered in the storage means; a second verification means for verifying the time read by the time reading means with the time represented by the time data in the information received by the receiving means; an authentication means for determining whether or not a first condition, that is, that the code information is determined to include an authentication code matching the information registered in the storage means through the comparison by the first comparison means, and a second condition, that the difference between two types of time is determined to be within a range of a predetermined tolerance through the comparison by the second comparison means, are both satisfied as essential conditions for authenticating that the information received by the receiving means has been transmitted from a communication terminal device having legitimate access authority, and for determining whether or not the essential conditions are satisfied based on the determination result; A server system comprising the above means.
5. An information processing system including a dedicated terminal device provided with a display unit and deployed at a predetermined specific location, and an authentication server having storage means for registering an authentication code associated with the specific location or information linked to the authentication code, The dedicated terminal device a code receiving means for receiving from the authentication server an image of the authentication code or a pattern code in which the authentication code is embedded so as to be optically readable; a control means for displaying predetermined character information on the display unit in response to receiving access from an arbitrary communication terminal device having a photographing function, and for displaying a combination of a pattern code based on the information received by the code receiving means and a time display area showing the current time on the display unit in response to receiving information matching the character information from the communication terminal device, and for transmitting a notification to the communication terminal device permitting photographing; The authentication server a receiving means for receiving, from any communication terminal device having a photographing function, transmission of information including an image generated by the device through photographing and time data representing the time recognized by the device through its own clock function after the generation of the image; a code reading means for extracting a pattern code in which predetermined code information is embedded so as to be optically readable from the image in the information received by the receiving means, and for executing a reading process on the extracted code; a time reading means for extracting an image representing a time from the image and reading the time; a first verification means for verifying the code information read by the code reading means with the information registered in the storage means; a second verification means for verifying the time read by the time reading means with the time represented by the time data in the information received by the receiving means; and authentication means for determining whether or not the first condition, that is, that the code information is determined to include an authentication code that matches the information registered in the storage means through comparison by the first comparison means, and the second condition, that the difference between two types of time is determined to be within a predetermined tolerance through comparison by the second comparison means, are both satisfied as essential conditions for authenticating that the information accepted by the acceptance means has been transmitted from a communication terminal device having legitimate access authority, and for determining whether or not the authentication is to be performed based on the determination result. Information processing system.
6. An information processing system including a dedicated terminal device provided with a display unit and deployed at a predetermined specific location, and an authentication server having storage means for registering an authentication code associated with the specific location or information linked to the authentication code, The dedicated terminal device a code receiving means for receiving from the authentication server an image of the authentication code or a pattern code in which the authentication code is embedded so as to be optically readable; a control means for displaying on the display unit a combination of a pattern code based on the information received by the code receiving means and a time display area showing the current time, and for transmitting to the communication terminal device a notification permitting the communication terminal device to transmit an image generated by photographing with the communication terminal device to the authentication server in response to receiving, under this display state, code information matching the pattern code being displayed from the communication terminal device having a photographing function; The authentication server a receiving means for receiving, from any communication terminal device having a photographing function, transmission of information including an image generated by the device through photographing and time data representing the time recognized by the device through its own clock function after the generation of the image; a code reading means for extracting a pattern code in which predetermined code information is embedded so as to be optically readable from the image in the information received by the receiving means, and for executing a reading process on the extracted code; a time reading means for extracting an image representing a time from the image and reading the time; a first verification means for verifying the code information read by the code reading means with the information registered in the storage means; a second verification means for verifying the time read by the time reading means with the time represented by the time data in the information received by the receiving means; and authentication means for determining whether or not the first condition, that is, that the code information is determined to include an authentication code that matches the information registered in the storage means through comparison by the first comparison means, and the second condition, that the difference between two types of time is determined to be within a predetermined tolerance through comparison by the second comparison means, are both satisfied as essential conditions for authenticating that the information accepted by the acceptance means has been transmitted from a communication terminal device having legitimate access authority, and for determining whether or not the authentication is to be performed based on the determination result. Information processing system.
7. A method executed by a server system in which the authentication code or information linked to the authentication code is registered and a communication terminal device having a photographing function, on the premise that a pattern code in which an authentication code associated with a specific location is embedded so as to be optically readable and a time display device showing the current time are arranged in the specific location in a positional relationship in which the authentication code and information linked to the authentication code can be photographed simultaneously, the method comprising: the communication terminal device, in response to receiving an operation for accessing the server system or extracting the pattern code from the image generated by the photographing while photographing using the photographing function, executes a reading process on an image representing the pattern code and the time in the image generated after the operation or extraction, and transmits the read information obtained by each reading process to the server system together with time data representing the time recognized by a clock function of the device itself after the image to be read was generated; The server system that receives the transmission determines whether or not the first condition, that the read information of the pattern code transmitted from the communication terminal device contains an authentication code that matches the information registered in the server system, and the second condition, that the difference between the time indicated by the read information of the time transmitted from the communication terminal device and the time indicated by the time data transmitted together with the read information is within a predetermined tolerance, are met as essential conditions for authenticating that each read information has been transmitted from a communication terminal device with legitimate access authority, and performs information processing to determine whether or not these essential conditions are met, and determines whether or not to perform the authentication based on the determination result. Information processing methods.
8. a storage means for registering an authentication code associated with a specific location or information linked to the authentication code; a receiving means for receiving, from any communication terminal device having a photographing function, information including read information of a pattern code and time read by the device from an image generated by the device through photographing, and time data indicating the time recognized by the communication terminal device using its own clock function after the image was generated; a first verification means for verifying the read information of the pattern code in the information received by the receiving means with the information registered in the storage means; a second collating means for collating the time indicated by the time read information in the information received by the receiving means with the time indicated by the time data in the received information; an authentication means for determining whether or not a first condition, that is, that the read information of the pattern code is determined to include an authentication code that matches the information registered in the storage means through the comparison by the first comparison means, and a second condition, that is, that the difference between two types of time is determined to be within a predetermined tolerance through the comparison by the second comparison means, are both satisfied as essential conditions for authenticating that the information accepted by the acceptance means has been transmitted from a communication terminal device having legitimate access authority, and for determining whether or not the authentication is to be performed based on the result of the determination; A server system comprising the above means.
9. A method is executed by a server system in which an authentication code associated with a specific location or information associated with the authentication code is registered, the dedicated terminal device, and a communication terminal device having a photographing function, on the premise that a pattern code in which an authentication code associated with the specific location is embedded so as to be optically readable is displayed on the dedicated terminal device located at the specific location, the method comprising: the server system transmits a plurality of authentication codes with different contents to the dedicated terminal device sequentially or collectively; the dedicated terminal device executes a process of converting code information, including the authentication code received from the server system and time data based on a time recognized by a clock function of the dedicated terminal device, into the pattern code, and a process of displaying the pattern code obtained by the conversion on the display unit, every time a predetermined time elapses or every time a timing for displaying the pattern code arrives; the communication terminal device, while photographing using the photographing function, extracts a pattern code of the same type as the pattern code from the image generated by the photographing and reads its content, and then transmits the read information to the server system together with time data indicating the time recognized by a clock function of the communication terminal device after the time of the read information; The server system that receives the transmission determines whether or not the first condition, that the transmitted read information contains an authentication code that matches the information registered in the server system, and the second condition, that the difference between the time indicated by the information indicating the time included in the read information and the time indicated by the time data transmitted together with the read information, is within a predetermined tolerance range, are both met as essential conditions for authenticating that the read information has been transmitted from a communication terminal device with legitimate access authority, and performs information processing to determine whether or not these essential conditions are met, and determines whether or not to perform the authentication based on the result of the determination. Information processing methods.
10. A method is executed by a server system in which an authentication code associated with a specific location or information associated with the authentication code is registered, the dedicated terminal device, and a communication terminal device having a photographing function, on the premise that a pattern code in which an authentication code associated with the specific location is embedded so as to be optically readable is displayed on the dedicated terminal device located at the specific location, the method comprising: the server system transmits to the dedicated terminal device sequentially or collectively a plurality of images each representing a plurality of code information items each including the authentication code and time data indicating the scheduled display time and each having different contents for the authentication code and the time data, or a plurality of images each representing a pattern code in which the code information items are embedded so as to be optically readable; the dedicated terminal device updates the content of the displayed two-dimensional code each time a scheduled display time corresponding to the plurality of code information arrives by displaying a pattern code based on the information received from the server system on the display unit at the time indicated by the time data embedded in the pattern code; the communication terminal device, while photographing using the photographing function, extracts a pattern code of the same type as the pattern code from the image generated by the photographing and reads its content, and then transmits the read information to the server system together with time data indicating the time recognized by a clock function of the communication terminal device after the time of the read information; The server system that receives the transmission determines whether or not the first condition, that the transmitted read information contains an authentication code that matches the information registered in the server system, and the second condition, that the difference between the time indicated by the information indicating the time included in the read information and the time indicated by the time data transmitted together with the read information, is within a predetermined tolerance range, are both met as essential conditions for authenticating that the read information has been transmitted from a communication terminal device with legitimate access authority, and performs information processing to determine whether or not these essential conditions are met, and determines whether or not to perform the authentication based on the result of the determination. Information processing methods.
11. An information processing system including a dedicated terminal device provided with a display unit and deployed at a predetermined specific location, and an authentication server having storage means for registering an authentication code associated with the specific location or information linked to the authentication code, the dedicated terminal device comprises a display control means for executing a process of converting code information, including an authentication code received from the authentication server and time data based on a time recognized by a clock function of the dedicated terminal device, into the pattern code, and a process of displaying the pattern code obtained by the conversion on the display unit, every time a predetermined time elapses or every time a timing for displaying arrives; The authentication server a code generating means for repeatedly generating an authentication code with different contents each time for each location whose information is registered in the storage means, and for linking the generated authentication code to the information registered in the storage means in association with the location; a code transmitting means for transmitting, for each location whose information is registered in the storage means, a plurality of authentication codes generated by the code generating means to a dedicated terminal device installed in the location, either sequentially or all at once; a receiving means for receiving, from any communication terminal device having a photographing function, transmission of information including read information of the pattern code read from an image generated by the device by photographing the pattern code, and time data indicating the time recognized by the device using its own clock function after the reading; a first verification means for verifying a portion of the read information received by the reception means that corresponds to the authentication code with information registered in the storage means; a second verification means for verifying the time represented by the portion of the read information corresponding to the time data with the time represented by the time data transmitted together with the read information; and authentication means for determining whether or not a first condition, that is, that the first comparison means has determined that the read information contains an authentication code that matches the information registered in the storage means, and a second condition, that the second comparison means has determined that the difference between two types of time is within a predetermined tolerance, are both satisfied as essential conditions for authenticating that the read information accepted by the accepting means has been transmitted from a communication terminal device having legitimate access authority, and for determining whether or not the aforementioned authentication is to be performed based on the result of the determination. Information processing system.
12. An information processing system including a dedicated terminal device provided with a display unit and deployed at a predetermined specific location, and an authentication server having storage means for registering an authentication code associated with the specific location or information linked to the authentication code, The dedicated terminal device a code receiving means for receiving, from the authentication server, code information including an authentication code and time data indicating a scheduled display time, or an image of a pattern code in which the code information is embedded so as to be optically readable; a display control means for displaying a pattern code based on the information received by the code receiving means on the display unit at a time indicated by time data embedded in the pattern code, The authentication server a code generating means for repeatedly generating an authentication code with different contents each time for each location whose information is registered in the storage means, and for linking the generated authentication code to the information registered in the storage means in association with the location; a code transmitting means for transmitting, for each location whose information is registered in the storage means, a plurality of code information pieces each having different contents of the authentication code and the time data, or a plurality of images individually representing pattern codes in which the code information pieces are embedded so as to be optically readable, to a dedicated terminal device provided at the location, either sequentially or all at once; a receiving means for receiving, from any communication terminal device having a photographing function, transmission of information including read information of the pattern code read from an image generated by the device by photographing the pattern code, and time data indicating the time recognized by the device using its own clock function after the reading; a first verification means for verifying a portion of the read information received by the reception means that corresponds to the authentication code with information registered in the storage means; a second verification means for verifying the time represented by the portion of the read information corresponding to the time data with the time represented by the time data transmitted together with the read information; and authentication means for determining whether or not a first condition, that is, that the first comparison means has determined that the read information contains an authentication code that matches the information registered in the storage means, and a second condition, that the second comparison means has determined that the difference between two types of time is within a predetermined tolerance, are both satisfied as essential conditions for authenticating that the read information accepted by the accepting means has been transmitted from a communication terminal device having legitimate access authority, and for determining whether or not the aforementioned authentication is to be performed based on the result of the determination. Information processing system.
13. A method is executed by a server system in which an authentication code associated with a specific location or information associated with the authentication code is registered, the dedicated terminal device, and a communication terminal device having a photographing function, on the premise that a pattern code in which an authentication code associated with the specific location is embedded so as to be optically readable is displayed on the dedicated terminal device located at the specific location, the method comprising: the server system transmits a plurality of authentication codes with different contents to the dedicated terminal device sequentially or collectively; the dedicated terminal device executes a process of converting code information, including the authentication code received from the server system and time data based on a time recognized by a clock function of the dedicated terminal device, into the pattern code, and a process of displaying the pattern code obtained by the conversion on the display unit, every time a predetermined time elapses or every time a timing for displaying the pattern code arrives; the communication terminal device, while photographing using the photographing function, extracts a pattern code of the same type as the pattern code from an image generated by the photographing and reads the content of the pattern code, and transmits the read information to the server system; The server system that receives the transmission determines whether or not the first condition, that is, that the transmitted read information contains an authentication code that matches the information registered in the server system, and the second condition, that the read information contains information that indicates a time whose difference from the time the read information was received is within a predetermined tolerance, are both met as essential conditions for authenticating that the read information was transmitted from a communication terminal device that has legitimate access authority, and performs information processing to determine whether or not these essential conditions are met, and determines whether or not to perform the authentication based on the determination result. Information processing methods.
14. A method is executed by a server system in which an authentication code associated with a specific location or information associated with the authentication code is registered, the dedicated terminal device, and a communication terminal device having a photographing function, on the premise that a pattern code in which an authentication code associated with the specific location is embedded so as to be optically readable is displayed on the dedicated terminal device located at the specific location, the method comprising: the server system transmits to the dedicated terminal device sequentially or collectively a plurality of images each representing a plurality of code information items each including the authentication code and time data indicating the scheduled display time and each having different contents for the authentication code and the time data, or a plurality of images each representing a pattern code in which the code information items are embedded so as to be optically readable; the dedicated terminal device updates the content of the displayed two-dimensional code each time a scheduled display time corresponding to the plurality of code information arrives by displaying a pattern code based on the information received from the server system on the display unit at the time indicated by the time data embedded in the pattern code; the communication terminal device, while photographing using the photographing function, extracts a pattern code of the same type as the pattern code from an image generated by the photographing and reads the content of the pattern code, and transmits the read information to the server system; The server system that receives the transmission determines whether or not the first condition, that is, that the transmitted read information contains an authentication code that matches the information registered in the server system, and the second condition, that the read information contains information that indicates a time whose difference from the time the read information was received is within a predetermined tolerance, are both met as essential conditions for authenticating that the read information was transmitted from a communication terminal device that has legitimate access authority, and performs information processing to determine whether or not these essential conditions are met, and determines whether or not to perform the authentication based on the determination result. Information processing methods.
15. An information processing system including a dedicated terminal device provided with a display unit and deployed at a predetermined specific location, and an authentication server having storage means for registering an authentication code associated with the specific location or information linked to the authentication code, the dedicated terminal device comprises a display control means for executing a process of converting code information, including an authentication code received from the authentication server and time data based on a time recognized by a clock function of the dedicated terminal device, into the pattern code, and a process of displaying the pattern code obtained by the conversion on the display unit, every time a predetermined time elapses or every time a timing for displaying arrives; The authentication server a code generating means for repeatedly generating an authentication code whose contents are different each time for each location whose information is registered in the storage means, and for linking the generated authentication code to the information registered in the storage means in association with the location; a code transmitting means for transmitting, for each location whose information is registered in the storage means, a plurality of authentication codes generated by the code generating means to a dedicated terminal device installed in the location, either sequentially or all at once; a receiving means for receiving, from any communication terminal device having a photographing function, transmission of read information of the pattern code read from an image generated by photographing the pattern code with the device; a first verification means for verifying a portion of the read information received by the reception means that corresponds to the authentication code with information registered in the storage means; a second collating means for collating the time represented by the portion of the read information corresponding to the time data with the time at which the read information was received; and authentication means for determining whether or not a first condition, that is, that the first comparison means has determined that the read information contains an authentication code that matches the information registered in the storage means, and a second condition, that the second comparison means has determined that the difference between two types of time is within a predetermined tolerance, are both satisfied as essential conditions for authenticating that the read information accepted by the accepting means has been transmitted from a communication terminal device having legitimate access authority, and for determining whether or not the aforementioned authentication is to be performed based on the result of the determination. Information processing system.
16. An information processing system including a dedicated terminal device provided with a display unit and deployed at a predetermined specific location, and an authentication server having storage means for registering an authentication code associated with the specific location or information linked to the authentication code, The dedicated terminal device a code receiving means for receiving, from the authentication server, code information including an authentication code and time data indicating a scheduled display time, or an image of a pattern code in which the code information is embedded so as to be optically readable; a display control means for displaying a pattern code based on the information received by the code receiving means on the display unit at a time indicated by time data embedded in the pattern code, The authentication server a code generating means for repeatedly generating an authentication code with different contents each time for each location whose information is registered in the storage means, and for linking the generated authentication code to the information registered in the storage means in association with the location; a code transmitting means for transmitting, for each location whose information is registered in the storage means, a plurality of code information pieces each having different contents of the authentication code and the time data, or a plurality of images individually representing pattern codes in which the code information pieces are embedded so as to be optically readable, to a dedicated terminal device provided at the location, either sequentially or all at once; a receiving means for receiving, from any communication terminal device having a photographing function, transmission of read information of the pattern code read from an image generated by photographing the pattern code with the device; a first verification means for verifying a portion of the read information received by the reception means that corresponds to the authentication code with information registered in the storage means; a second collating means for collating the time represented by the portion of the read information corresponding to the time data with the time at which the read information was received; and authentication means for determining whether or not a first condition, that is, that the first comparison means has determined that the read information contains an authentication code that matches the information registered in the storage means, and a second condition, that the second comparison means has determined that the difference between two types of time is within a predetermined tolerance, are both satisfied as essential conditions for authenticating that the read information accepted by the accepting means has been transmitted from a communication terminal device having legitimate access authority, and for determining whether or not the aforementioned authentication is to be performed based on the result of the determination. Information processing system.
Citation Information
Patent Citations
Starting control device of internal-combustion engine for car
JP1986001843A
Authenticity determination method, authenticity determination device, authenticity determination system, and color two-dimentional code
JP2012141729A
Campaign application authentication device
JP2018101189A
Behavior management system and behavior management method
JP7107560B2
Information processing system, information processing method, program, storage medium, and information processing device
JP7364757B1