Management server, information providing method, and computer program
The authentication system allows users to control and manage personal information sharing by consenting to third-party access after successful biometric authentication, addressing privacy concerns and user control in biometric authentication services.
Patent Information
- Application Number
- JP2025131765
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-10-28
AI Technical Summary
The challenge lies in providing personal information used in biometric authentication services to third parties without user consent, while ensuring user privacy and control over their data.
An authentication system comprising an authentication server, management server, and user terminal that allows users to consent to the sharing of their personal information with third parties after successful biometric authentication, enabling user control over data management.
Enables users to manage and control the provision of personal information related to biometric authentication services, ensuring privacy and consent is obtained before sharing data with third parties.
Smart Images

Figure 2025163217000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a management server, an information providing method, and a computer program. [Background technology]
[0002] In recent years, various services using biometric information have become widespread. For example, facial recognition is used for various procedures at airports (check-in, baggage drop-off, etc.) and hotel check-ins.
[0003] For example, Patent Document 1 describes that an electronic payment system is provided that strengthens security and enables rapid payment processing. The electronic payment system disclosed in Patent Document 1 uses biometric information of users for payment.
[0004] Services that use facial recognition follow the following process: First, a terminal (installed at an airport or hotel) captures a facial image of the customer and generates a feature vector that characterizes the facial image. The generated feature vector is then sent to a server on the network.
[0005] The server has a database that stores the biometric information and personal information (such as name and address) of users who receive facial recognition services. When the server receives a matching request from a terminal, it searches (matches) the database and identifies the biometric information and personal information that correspond to the matching request from the terminal. The server then transmits the identified personal information to the terminal, and the terminal installed at the airport or other location performs its business based on the acquired personal information. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-190112 Summary of the Invention [Problem to be solved by the invention]
[0007] As mentioned above, when providing services using biometric authentication, personal information of users is required. Collecting and storing a large amount of personal information creates great value. Specifically, data on what age groups of users receive what services can be a valuable tool for corporate marketing decisions.
[0008] However, from the viewpoint of protecting the user's privacy, it is difficult to provide personal information used when providing services using biometric authentication to a third party without the user's consent.
[0009] The main object of the present invention is to provide an authentication system, a terminal, a method for controlling a terminal, and a storage medium that contribute to users' control and management of personal information related to the provision of services using biometric authentication. [Means for solving the problem]
[0010] According to a first aspect of the present invention, there is provided an authentication system including an authentication server that stores first biometric information of a user and performs biometric authentication of the user using the first biometric information, a management server that stores personal information of the user, and a terminal carried by the user, wherein, when the biometric authentication of the user is successful, the authentication server sends an authentication notification to the terminal indicating that the biometric authentication of the user has been successful, and in response to receiving the authentication notification, the terminal obtains the user's intention regarding whether or not to consent to the provision of the stored personal information to a third party, and if the user consents to the provision of the stored personal information to a third party, sends a consent notification to the management server.
[0011] According to a second aspect of the present invention, there is provided an authentication system including an authentication server that stores first biometric information of a user and performs biometric authentication of the user using the first biometric information, a management server that stores personal information of the user, and a terminal carried by the user, wherein, when the authentication server successfully performs biometric authentication of the user, the management server sends an authentication notification to the terminal indicating that the biometric authentication of the user has been successful, and in response to receiving the authentication notification, the terminal obtains the user's intention regarding whether or not to consent to the provision of the stored personal information to a third party, and if the user consents to the provision of the stored personal information to a third party, sends a consent notification to the management server.
[0012] According to a third aspect of the present invention, there is provided a terminal that stores first biometric information of a user, performs biometric authentication of the user using the first biometric information, receives an authentication notification from an authentication server indicating that the biometric authentication of the user has been successful, and in response to receiving the authentication notification, obtains the user's intention regarding whether or not to consent to a management server that stores personal information of the user providing the stored personal information to a third party, and if the user consents to the provision of the stored personal information to a third party, sends a consent notification to the management server.
[0013] According to a fourth aspect of the present invention, there is provided a method for controlling a terminal, the method including: storing first biometric information of a user in a terminal; performing biometric authentication of the user using the first biometric information; receiving an authentication notification from an authentication server indicating that biometric authentication of the user has been successful; and, in response to receiving the authentication notification, a management server that stores personal information of the user obtains the user's intention regarding whether or not to consent to providing the stored personal information to a third party; and, if the user consents to providing the stored personal information to the third party, transmitting a consent notification to the management server.
[0014] According to a fifth aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on a terminal to execute the following processes: storing first biometric information of a user, performing biometric authentication of the user using the first biometric information, and receiving an authentication notification from an authentication server indicating that biometric authentication of the user has been successful; and, in response to receiving the authentication notification, having a management server that stores personal information of the user acquire the user's intention regarding whether or not to consent to providing the stored personal information to a third party, and if the user consents to providing the stored personal information to a third party, sending a consent notification to the management server. [Effects of the Invention]
[0015] According to each aspect of the present invention, an authentication system, a terminal, a method for controlling a terminal, and a storage medium are provided that contribute to a user's control and management of personal information related to the provision of services using biometric authentication. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]
[0016] [Figure 1] FIG. 1 is a diagram for explaining an overview of an embodiment. [Figure 2] 1 is a diagram illustrating an example of a schematic configuration of an authentication system according to a first embodiment. [Figure 3] FIG. 2 is a diagram for explaining the operation in the user registration phase of the authentication system according to the first embodiment. [Figure 4] FIG. 2 is a diagram for explaining the operation of the authentication system according to the first embodiment in a service registration phase. [Figure 5] FIG. 2 is a diagram for explaining the operation of the authentication system according to the first embodiment in a service provision phase. [Figure 6] FIG. 2 is a diagram for explaining the operation of the authentication system according to the first embodiment in a personal information collection phase. [Figure 7]FIG. 2 is a diagram illustrating an example of a processing configuration of an authentication server according to the first embodiment. [Figure 8] FIG. 4 is a diagram for explaining the operation of a user registration unit of the authentication server according to the first embodiment. [Figure 9] FIG. 4 is a diagram for explaining the operation of a user registration unit of the authentication server according to the first embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of an authentication information database. [Figure 11] FIG. 10 is a diagram illustrating an example of an authentication information database. [Figure 12] FIG. 10 is a diagram illustrating an example of an authentication information database. [Figure 13] FIG. 2 is a diagram illustrating an example of a processing configuration of a management server according to the first embodiment. [Figure 14] 5 is a diagram for explaining the operation of a personal information acquisition unit of the management server according to the first embodiment. FIG. [Figure 15] FIG. 2 is a diagram illustrating an example of a user information database. [Figure 16] FIG. 2 is a diagram illustrating an example of a processing configuration of an authentication terminal according to the first embodiment. [Figure 17] FIG. 2 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment. [Figure 18] 4 is a diagram for explaining the operation of a personal information control unit of the terminal according to the first embodiment. FIG. [Figure 19] 4 is a diagram for explaining the operation of a personal information control unit of the terminal according to the first embodiment. FIG. [Figure 20] 4 is a diagram for explaining the operation of a personal information control unit of the terminal according to the first embodiment. FIG. [Figure 21] 4 is a diagram for explaining the operation of a personal information control unit of the terminal according to the first embodiment. FIG. [Figure 22] FIG. 4 is a sequence diagram showing an example of an operation related to a service registration phase of the authentication system according to the first embodiment. [Figure 23] FIG. 4 is a sequence diagram showing an example of an operation related to a service provision phase of the authentication system according to the first embodiment. [Figure 24] FIG. 4 is a sequence diagram showing an example of an operation related to a personal information collection phase of the authentication system according to the first embodiment. [Figure 25] FIG. 10 is a diagram for explaining the operation of the authentication system in the personal information collection phase according to the second embodiment. [Figure 26] FIG. 11 is a diagram for explaining the operation of the authentication system in the service provision phase according to the third embodiment. [Figure 27] FIG. 2 is a diagram illustrating an example of a hardware configuration of a terminal. DETAILED DESCRIPTION OF THE INVENTION
[0017] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.
[0018] An authentication system according to one embodiment includes an authentication server 101, a management server 102, and a terminal 103 carried by a user (see FIG. 1). The authentication server 101 stores first biometric information of the user and performs biometric authentication of the user using the first biometric information. The management server 102 stores personal information of the user. When the authentication server 101 successfully authenticates the user, it transmits an authentication notification to the terminal 103 indicating that the biometric authentication of the user has been successful. In response to receiving the authentication notification, the terminal 103 acquires the user's intention regarding whether or not to consent to the provision of the stored personal information to a third party. When the user consents to the provision of the stored personal information to a third party, the terminal 103 transmits a consent notification to the management server 102.
[0019] In the above authentication system, the fact that authentication processing has been performed using biometric information registered in authentication server 101 is notified to terminal 103. The user recognizes from the authentication notification notified to terminal 103 that biometric authentication using biometric information has been performed. Thereafter, terminal 103 acquires the user's intention as to whether or not to consent to the provision of personal information related to the biometric authentication to a third party (for example, information server 40 described below). If the user agrees to the provision of personal information, terminal 103 transmits a consent notification indicating this to management server 102. In this way, in an authentication system including terminal 103, the user can control and manage personal information related to the provision of services using biometric authentication.
[0020] Specific embodiments will be described in more detail below with reference to the drawings.
[0021] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.
[0022] [System Configuration] Fig. 2 is a diagram showing an example of a schematic configuration of an authentication system according to the first embodiment. As shown in Fig. 2, the authentication system includes an authentication center, an information center, and a plurality of service providers.
[0023] Each service provider participating in the authentication system provides a service using biometric authentication. Examples of services provided by a service provider include payment services at retail stores and accommodation services at hotels. Alternatively, a service provided by a service provider may be immigration inspections at airports or ports. The service provider disclosed herein may provide any service that can be provided using biometric authentication.
[0024] An authentication server 10 is installed in the authentication center. The authentication server 10 stores biometric information (first biometric information) of a user and performs biometric authentication of the user using the biometric information. The authentication server 10 operates as an authentication authority for authentication using the biometric information. The authentication server 10 may be a server installed on the premises of the authentication center, or may be a server installed on the cloud.
[0025] The user's biometric information may be, for example, data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, or iris pattern. Alternatively, the user's biometric information may be image data such as a face image or fingerprint image. The user's biometric information may be any information that includes the user's physical characteristics. In the present disclosure, a case where biometric information related to a person's "face" is used will be described.
[0026] The authentication server 10 is a server device for realizing services based on biometric authentication. The authentication server 10 processes an "authentication request" sent from each service provider and sends the result of the authentication process to the service provider.
[0027] Each service provider has a management server and an authentication terminal.
[0028] For example, a service provider S1 is provided with a management server 20 and a plurality of authentication terminals 30. A service provider S2 is provided with a management server 20 and a plurality of authentication terminals 31.
[0029] In the following explanation, when it is necessary to distinguish between the components, the symbol to the right of the hyphen will be used. The operation of each device included in service provider S1 and service provider S2 can be the same, so the following explanation will focus on service provider S1.
[0030] The devices shown in Fig. 2 are interconnected. For example, the authentication server 10 and the management server 20 are connected by wired or wireless communication means and are configured to be able to communicate with each other.
[0031] The management server 20 is a server that controls and manages the overall business of the service provider. For example, if the service provider is a retail store, the management server 20 manages inventory of products. Alternatively, if the service provider is a hotel operator, the management server 20 manages reservation information of guests.
[0032] In addition to the functions related to providing the above services, the management server 20 has control functions and management functions related to biometric authentication of users. The management server 20 stores personal information (such as names) of users who use the authentication system.
[0033] The authentication terminal 30 is a device connected to the management server 20 and serves as an interface for users (customers) who visit a service provider. The users receive various services via the authentication terminal 30. For example, if the service provider is a retail store, the users use the authentication terminal 30 to pay for the service. Alternatively, if the service provider is a hotel operator, the users use the authentication terminal 30 to complete check-in procedures.
[0034] An information server 40 is installed in the information center. The information center and information server 40 are equivalent to "third parties" from the user's perspective. The information server 40 collects personal information of users who receive services from service providers. For example, the information server 40 collects the type of service used by the user, as well as their name, age, gender, etc. The collected personal information is transferred to other businesses, etc. The other businesses use the acquired personal information for marketing purposes, etc.
[0035] FIG. 2 is an example and is not intended to limit the configuration of the authentication system disclosed herein. For example, an authentication center may include two or more authentication servers 10. Alternatively, a service provider may include at least one authentication terminal 30. Alternatively, the functions of the management server 20 and the authentication terminal 30 may be integrated, and a service using biometric authentication may be provided by this integrated single device. Alternatively, at each service provider, multiple authentication terminals 30 may be connected to one management server 20 as shown in FIG. 2, or one authentication terminal 30 may be connected to one management server 20. Alternatively, the functions of the authentication server 10 and the information server 40 may be integrated. In other words, the authentication server 10 may also be considered a "third party" from the user's perspective.
[0036] [System operation overview] Next, the general operation of the authentication system according to the first embodiment will be described.
[0037] The operation of the authentication system involves four phases.
[0038] The first phase is a phase in which users are registered in the system (user registration phase).
[0039] The second phase is a phase in which services are registered (service registration phase).
[0040] The third phase is the phase in which services using biometric authentication are provided to users (service provision phase).
[0041] The fourth phase is a phase in which personal information of users who have received the service is collected (personal information collection phase).
[0042] [User registration phase] FIG. 3 is a diagram for explaining the operation in the user registration phase of the authentication system according to the first embodiment.
[0043] Users who wish to use services that use biometric authentication must register in advance. The user determines information to identify themselves in the authentication system (user ID (identifier) and password (PW; Password)) and registers it in the system. In the drawings including Figure 3, the user ID is represented as "uID."
[0044] In addition, the user registers his / her own biometric information (for example, a facial image) and contact information (for example, an email address of an account that can receive emails on the terminal 50) in the system.
[0045] The user registers the above four pieces of information (user ID, password, biometric information, and contact information) in the system using any means. For example, the user may mail a document containing the above four pieces of information to the authentication center, and an employee of the authentication center may enter the above four pieces of information into the authentication server 10. Alternatively, the user may mail an external storage device, such as a USB (Universal Serial Bus), on which the above four pieces of information are stored to the authentication center.
[0046] Alternatively, the user may operate the terminal 50 owned by the user to input a captured image of the user's face, a user ID, a password, and contact information to the authentication server 10. Examples of the terminal 50 include mobile terminal devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, laptop computers), etc.
[0047] The authentication server 10 generates features (feature vectors consisting of multiple features) from the acquired face image, and stores the features in association with the user ID, password, and contact information. Specifically, the authentication server 10 adds a new entry to the authentication information database and stores the above four pieces of information in association with each other.
[0048] In this way, in the user registration phase, a first ID (e.g., a user ID) that uniquely identifies a user in the system and first biometric information used to authenticate the user are registered in the system. Note that, in the first embodiment, an example will be described in which a user ID and a password are used as an identifier (first ID) that uniquely identifies a system user, but as long as there is no overlap of user IDs between users, it is also possible to use the user ID as the identifier (first ID).
[0049] [Service registration phase] FIG. 4 is a diagram for explaining the operation in the service registration phase of the authentication system according to the first embodiment.
[0050] After completing user registration, the user selects the service provider from which they wish to receive services using biometric authentication and registers the selected service provider in the system. For example, in Figure 2, if the user wishes to receive services from service provider S1, the user registers service provider S1 in the system.
[0051] The user registers personal information (such as name) required to receive services from the selected service provider in the system. Examples of the personal information include name, age, and gender. In addition to the personal information, the user also registers the user ID and password determined in the user registration phase in the system.
[0052] In this disclosure, personal information is defined as information that does not include biometric information of the user (person to be authenticated). In other words, biometric information and features generated from the biometric information are excluded from the "personal information" disclosed in this disclosure.
[0053] The user inputs the above three pieces of information (personal information, user ID, and password) to the service provider using any means. For example, the user mails a medium (paper or electronic medium) containing the above three pieces of information to the selected service provider. An employee of the service provider inputs the above three pieces of information into the management server 20. The user may also input the above three pieces of information into the management server 20 by operating an authentication terminal 30 installed at the service provider.
[0054] 4, the user may operate a terminal 50 to input the above three pieces of information into the management server 20. In this case, the user inputs the above three pieces of information on a WEB page managed and operated by the service provider.
[0055] Upon acquiring the above three pieces of information (personal information, user ID, and password), the management server 20 transmits a "service registration request" to the authentication server 10. Specifically, the management server 20 transmits a service registration request including the service provider ID, user ID, and password to the authentication server 10.
[0056] The service provider ID is identification information for uniquely identifying a service provider (such as a retailer participating in an authentication infrastructure that uses biometric authentication) included in the authentication system. In the example of Figure 2, different service provider IDs are assigned to service providers S1 and S2.
[0057] Note that the service provider ID is an ID assigned to each service provider, not to each service. For example, in Figure 2, even if service providers S1 and S2 are businesses that provide the same type of service (e.g., accommodation services), if they are managed by different entities, different IDs will be assigned to these service providers.
[0058] The authentication server 10 and the management server 20 share the service provider ID by any method. For example, when a service provider joins the authentication infrastructure, the authentication server 10 generates a service provider ID and distributes (notifies) the generated service provider ID to the service provider. In the drawings including FIG. 4, the service provider ID is represented as "spID."
[0059] When receiving a service registration request, the authentication server 10 searches the authentication information database using the user ID and password included in the request as keys to identify the corresponding user. The authentication server 10 then generates a "service user ID."
[0060] The service user ID is identification information that uniquely defines the correspondence (combination) between a user and a service provider. For example, in the example of Fig. 2, the service user ID determined from the combination of user U1 and service provider S1 and the service user ID determined from the combination of user U1 and service provider S2 are set to different values.
[0061] The authentication server 10 stores the user ID, password, feature amount, contact information, service provider ID, and the generated service user ID in association with each other. In the drawings including Fig. 4, the service user ID is represented as "suID".
[0062] The authentication server 10 transmits the generated service user ID to the sender of the service registration request. The authentication server 10 transmits a response including the service user ID to the management server 20, and issues the service user ID.
[0063] The management server 20 stores the service user ID acquired from the authentication server 10 in association with the user's personal information. The management server 20 adds a new entry to the user information database and stores the above information (personal information, service user ID).
[0064] The user repeats the above-described registration operation for each service provider from which the user wishes to receive services using biometric authentication. In other words, the user does not need to register for service providers from which the user does not wish to receive services.
[0065] In this way, in the service registration phase, a service registration request including a first ID (e.g., a user ID) and a second ID (e.g., a service provider ID) is sent to the authentication server 10 from the service provider of the service that the user wishes to use. When processing the service registration request, the authentication server 10 generates a third ID (e.g., a service user ID) that is uniquely determined by the combination of the user and the service provider. The authentication server 10 sends the third ID to the service provider. The service provider (management server 20) stores the user's personal information and the third ID in association with each other.
[0066] [Service provision phase] FIG. 5 is a diagram for explaining the operation in the service provision phase of the authentication system according to the first embodiment.
[0067] After completing the service registration (service registration phase), the user visits the service provider. The user moves to the authentication terminal 30.
[0068] The authentication terminal 30 acquires biometric information from a user in front of the user. Specifically, the authentication terminal 30 captures an image of the user and acquires a facial image. The authentication terminal 30 transmits the acquired facial image to the management server 20.
[0069] The management server 20 generates features from the acquired face image, and transmits an authentication request including the generated features and the service provider ID to the authentication server 10.
[0070] The authentication server 10 extracts the feature amount from the authentication request, and executes a matching process (1:N matching; N is a positive integer, the same applies below) using the extracted feature amount and the feature amount registered in the authentication information database.
[0071] The authentication server 10 identifies the user through a matching process, and identifies a service user ID corresponding to the service provider ID included in the authentication request from among a plurality of service user IDs associated with the identified user.
[0072] The authentication server 10 transmits the identified service user ID to the sender of the authentication request, and transmits a response (response to the authentication request) including the identified service user ID to the management server 20.
[0073] The management server 20 searches the user information database using the acquired service user ID as a key, and identifies the personal information corresponding to the service user ID. The management server 20 transmits the identified personal information to the authentication terminal 30. The authentication terminal 30 provides services using the acquired personal information.
[0074] As described above, in the service provision phase, the authentication terminal 30 acquires the second biometric information of the user and transmits the acquired second biometric information to the management server. The authentication server 10 receives an authentication request from the service provider, which includes the user's biometric information and a second ID (service provider ID). The authentication server 10 identifies a third ID (service user ID) through a matching process using the first and second biometric information and the second ID. The authentication server 10 transmits the identified third ID to the service provider. When providing a service to the user, the management server 20 identifies the user's personal information using the third ID acquired by transmitting an authentication request to the authentication server 10. The service provider provides the service to the user using the identified personal information.
[0075] [Personal information collection phase] FIG. 6 is a diagram for explaining the operation of the authentication system according to the first embodiment in the personal information collection phase.
[0076] In the service provision phase, when the authentication server 10 authenticates the user, the authentication server 10 notifies the user of the authentication. Specifically, the authentication server 10 transmits an "authentication notification" to the terminal 50 carried by the user.
[0077] The authentication notification includes the service user ID of the service provider from which the user receives the service. The authentication notification also includes information regarding the destination of the acceptance notification (hereinafter referred to as acceptance notification destination information). The acceptance notification destination information is information regarding the management server 20 to which the "acceptance notification" described below is sent. For example, the IP (Internet Protocol) address of the management server 20 to which the acceptance notification is sent is exemplified as the acceptance notification destination information.
[0078] Upon receiving the authentication notification, the terminal 50 generates a GUI (Graphical User Interface) for inputting whether or not the personal information will be provided to the information server 40 (whether or not the user consents to the provision of the personal information). That is, the terminal 50 uses the GUI to acquire the user's intention (thoughts) regarding whether or not to consent to the provision of the personal information stored in the management server 20 to the information server 40.
[0079] If the user refuses to provide personal information to the information server 40, the terminal 50 will not take any particular action.
[0080] If the user consents to providing personal information to the information server 40, the terminal 50 notifies the management server 20 of that fact. At that time, the terminal 50 notifies the management server 20 corresponding to the consent notification destination information of the consent to the provision of personal information (user consent). In the following explanation, the "consent to the provision of personal information" notified from the terminal 50 to the management server 20 will be referred to as an "consent notification."
[0081] The acceptance notice sent by the terminal 50 includes the service user ID acquired from the authentication server 10.
[0082] Upon receiving the acceptance notice, the management server 20 searches the user information database using the acquired service user ID as a key to identify the corresponding personal information. The management server 20 then transmits the identified personal information to the information server 40.
[0083] The information server 40 stores the received personal information.
[0084] For example, in the example of FIG. 2, consider a case where a facial image is captured by the authentication terminal 30-1 of the service provider S1. In this case, if the authentication server 10 successfully authenticates the user, it notifies the user (the terminal 50 carried by the user) of this fact as an "authentication notification." The terminal 50 generates a GUI for inputting the user's intention regarding the provision of personal information. If the user agrees to the provision of personal information, the terminal 50 transmits an "acceptance notification" to the management server 20-1 installed in the service provider S1. Upon receiving the acceptance notification, the management server 20-1 transmits the corresponding personal information to the information server 40.
[0085] It is generally assumed that users will not agree to provide personal information unless there is a benefit to providing such information. Therefore, it is desirable to present or propose benefits to users in exchange for providing personal information. For example, coupons or points that can be used at service providers may be given to users as benefits. There are various possible forms of the benefits and the manner in which the benefits are given, and as these are not within the scope of the present disclosure, detailed explanations will be omitted.
[0086] Thus, in the personal information collection phase, if the authentication server 10 succeeds in biometric authentication of the user, it transmits an "authentication notification" to the terminal 50 indicating that the user's biometric authentication was successful. In response to receiving the authentication notification, the terminal 50 transmits to the management server 20 an "acceptance notification" indicating that the user has consented to the provision of the personal information stored in the management server 20 to the information server 40. In response to receiving the acceptance notification, the management server 20 transmits the user's personal information to a third party (information server 40). Note that if the user receives an authentication notification even though he or she has no recollection of having undergone biometric authentication, he or she may suspect that someone else is "spoofing" the user. In this case, the user may inquire with the administrator of the authentication center, etc.
[0087] Next, each device included in the authentication system according to the first embodiment will be described in detail.
[0088] [Authentication Server] 7 is a diagram showing an example of a processing configuration (processing module) of the authentication server 10 according to the first embodiment. Referring to FIG. 7, the authentication server 10 includes a communication control unit 201, a user registration unit 202, a database management unit 203, a service registration unit 204, an authentication unit 205, and a storage unit 206.
[0089] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the management server 20. The communication control unit 201 also transmits data to the management server 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201.
[0090] The user registration unit 202 is a means for realizing the above-mentioned user registration. The user registration unit 202 acquires the user ID, password, biometric information (facial image), and contact information (destination for sending authentication notifications) of the user (a user who wishes to receive services using biometric authentication; a system user).
[0091] The user registration unit 202 acquires the above four pieces of information (user ID, password, biometric information, and contact information) using any means. For example, the user registration unit 202 displays a GUI or an input form for determining a user ID and password on the terminal 50. For example, the user registration unit 202 displays a GUI such as that shown in FIG. 8 on the terminal 50.
[0092] The user registration unit 202 verifies that the user ID and password acquired via the GUI or the like do not overlap with any user IDs and passwords that have already been registered. If no overlap occurs, the user registration unit 202 displays a GUI on the terminal 50 for acquiring the user's biometric information and contact information.
[0093] For example, the user registration unit 202 displays a GUI such as that shown in Fig. 9 on the terminal 50. For example, the user presses the "Select File" button shown in Fig. 9 and specifies image data of a facial image to be registered in the system. The specified facial image is displayed in the preview area (displayed as a selected facial image in Fig. 9).
[0094] The user inputs the email address of an account that can receive emails from the terminal 50 into the contact field. When registering the previewed face image and contact information, the user presses the "OK" button.
[0095] The user registration unit 202 acquires a user ID, password, biometric information (face image), and contact information using a GUI such as those shown in Figures 8 and 9, and then generates a feature (a feature vector consisting of multiple feature values) from the face image.
[0096] Specifically, the user registration unit 202 extracts feature points from the acquired facial image. Since existing technology can be used for the feature point extraction process, a detailed description thereof will be omitted. For example, the user registration unit 202 extracts the eyes, nose, mouth, etc. from the facial image as feature points. The user registration unit 202 then calculates the position of each feature point and the distance between each feature point as feature amounts, and generates a feature vector (vector information that characterizes the facial image) consisting of multiple feature amounts.
[0097] The user registration unit 202 passes the user ID, password, contact information, and the generated feature amount to the database management unit 203 .
[0098] The database management unit 203 is a means for managing the authentication information database. The authentication information database stores information identifying a system user (user ID, password), the user's contact information, biometric information (feature amount), a service provider ID identifying a service provider, and a service user ID identifying a user for each service, in association with each other.
[0099] When the database management unit 203 acquires the above four pieces of information (user ID, password, feature amount, and contact information) from the user registration unit 202, it adds a new entry to the authentication information database. For example, when the above four pieces of information about user U1 are acquired, the database management unit 203 adds the entry shown in the bottom row of Fig. 10. Note that at the user registration stage, the service provider ID and service user ID have not been generated, so nothing is set in these fields.
[0100] The service registration unit 204 is a means for enabling individual service registration by system users. The service registration unit 204 processes service registration requests received from the management server 20 of the service provider.
[0101] The service registration unit 204 searches the authentication information database using the user ID and password included in the acquired service registration request as keys. The service registration unit 204 checks the service provider ID field of the identified user (the user identified from the pair of the user ID and password).
[0102] The service registration unit 204 determines whether the service provider ID included in the service registration request acquired from the management server 20 is set in the service provider ID field. If the service provider ID acquired from the management server 20 is already registered in the database, the service registration unit 204 notifies the management server 20 of this fact. In this case, the service (service provider) that the user is attempting to register is already registered in the authentication information database, so the service registration unit 204 sends a "negative response" in response to the service registration request.
[0103] On the other hand, if the service provider ID included in the service registration request is not set in the service provider ID field of the identified user, the service registration unit 204 generates a service user ID corresponding to the user and the service provider.
[0104] As described above, the service user ID is identification information that is uniquely determined from a combination of a user and a service provider. For example, the service registration unit 204 calculates a hash value using the user ID, password, and service provider ID, and sets the calculated hash value as the service user ID. Specifically, the service registration unit 204 calculates a concatenated value of the user ID, password, and service provider ID, and then calculates a hash value of the calculated concatenated value to generate the service user ID.
[0105] Note that the generation of the service user ID using the hash value described above is merely an example and is not intended to limit the method of generating the service user ID. The service user ID may be any information that can uniquely identify the combination of a system user and a service provider. For example, the service registration unit 204 may assign a unique value each time it processes a service registration request and use this value as the service user ID.
[0106] When the service user ID is generated, the service registration unit 204 passes the service provider ID and service user ID along with the user ID, password, etc. to the database management unit 203. The database management unit 203 registers the two IDs (service provider ID, service user ID) in the authentication information database. For example, when user U1 registers a service for service provider S1, the above two IDs are added to the entry shown at the bottom of Fig. 11.
[0107] Since service registration is performed for each service provider, multiple service providers and service user IDs may be set for one user. For example, if user U1 performs service registration for each of service providers S1 and S2, the entries in the second and third lines of Figure 12 are generated. Note that if user U2 performs service registration for service provider S1, the entry in the bottom row of Figure 12 is generated.
[0108] The authentication information database shown in Fig. 12 etc. is merely an example and is not intended to limit the information stored in the authentication information database. For example, a facial image may be registered in the authentication information database instead of features for authentication. That is, features may be generated from a facial image registered in the authentication information database each time authentication is performed.
[0109] When the service provider ID and service user ID are registered in the authentication information database, the service registration unit 204 notifies the management server 20 that the service registration request has been processed successfully. The service registration unit 204 transmits an "acknowledgement" as a response to the service registration request. At that time, the service registration unit 204 transmits a response including the service user ID to the management server 20.
[0110] The authentication unit 205 is a means for performing authentication processing for system users, and processes authentication requests received from the management server 20 of the service provider.
[0111] The authentication unit 205 extracts the feature amount and the service provider ID included in the authentication request, searches the authentication information database using the extracted feature amount and the service provider ID as keys, and identifies the corresponding service user ID.
[0112] The authentication unit 205 sets the feature extracted from the authentication request as the feature on the matching side and the feature stored in the database as the feature on the registration side, and performs one-to-many matching. Specifically, the authentication unit 205 calculates the similarity between the feature on the matching side and each of the multiple registration sides. The similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0113] The authentication unit 205 determines whether or not there is a feature quantity among the multiple feature quantities registered in the database that has a similarity with the feature quantity to be matched that is equal to or greater than a predetermined value and has the highest similarity. If such a feature quantity is present, the authentication unit 205 determines whether or not there is an entry that matches the service provider ID included in the authentication request among at least one or more service provider IDs associated with the user identified by the one-to-N matching.
[0114] If such an entry exists (if the above two determinations are successful), the authentication unit 205 determines that the authentication of the user has been successful. In this case, the authentication unit 205 sends an "acknowledgement" to the management server 20, which is the sender of the authentication request. At that time, the authentication unit 205 generates a response (response to the authentication request) including the service user ID of the identified entry and sends it to the management server 20.
[0115] If at least one of the above two determinations fails, the authentication unit 205 determines that the authentication of the user has failed. In this case, the authentication unit 205 sends a "negative response" to the management server 20, which is the sender of the authentication request.
[0116] 12, when the authentication request includes the feature "FV1" and the service provider ID "S1," the entries (users) in the second and third lines are identified by the feature FV1, and the entry in the second line is identified by the service provider ID "S1." As a result, the authentication request is processed normally, and an affirmative response including the service user ID "U1S1" is sent to the management server 20.
[0117] On the other hand, if the authentication request contains the feature value "FV2" and the service provider ID "S2," the feature value identifies the bottom entry, but the service provider ID of that entry is "S1" and not "S2," so the authentication request is not processed normally. As a result, a negative response is sent to the management server 20.
[0118] Furthermore, when the authentication unit 205 successfully authenticates the user, it sends an "authentication notification" to the corresponding contact address. Specifically, the authentication unit 205 sends the authentication notification to the address written in the contact address field of the entry identified by the matching process. At that time, the authentication unit 205 generates an authentication notification including the service user ID identified by the matching process and an acceptance notification destination, and sends the generated authentication notification to the terminal 50. Note that the authentication unit 205 may set the IP address of the management server 20 that sent the response to the authentication request as the acceptance notification destination.
[0119] The storage unit 206 stores information necessary for the operation of the authentication server 10. In the storage unit 206, an authentication information database is constructed.
[0120] [Administration Server] 13 is a diagram showing an example of a processing configuration (processing module) of the management server 20 according to the first embodiment. Referring to FIG. 13, the management server 20 includes a communication control unit 301, a personal information acquisition unit 302, a service registration request unit 303, a database management unit 304, an authentication request unit 305, a personal information provision unit 306, and a storage unit 307.
[0121] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the authentication server 10, the authentication terminal 30, etc. The communication control unit 301 also transmits data to the authentication server 10, the authentication terminal 30, etc. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301.
[0122] The personal information acquisition unit 302 is a means for acquiring personal information required when a service provider provides a service. For example, if the service provider is a "retail store," the personal information acquisition unit 302 acquires payment-related information (e.g., credit card information, bank account information) in addition to the user's name, etc. Alternatively, if the service provider is a "hotel operator," the personal information acquisition unit 302 acquires reservation information regarding accommodation (e.g., the date of stay, etc.) in addition to the user's name, etc.
[0123] The personal information acquisition unit 302 acquires the user ID and password determined when the user registered with the system, in addition to the personal information such as the name.
[0124] The personal information acquisition unit 302 acquires personal information, a user ID, and a password by any means. For example, the personal information acquisition unit 302 displays a GUI or a form for inputting the above information on the terminal 50 (see FIG. 14). Alternatively, the information shown in FIG. 14 may be displayed on a web page managed and operated by the service provider. Alternatively, the terminal 50 may download an application provided by the service provider, and the display shown in FIG. 14 may be produced by the application. In particular, the web page may be a web page that manages member information of the service provider. That is, members of each service provider may register for a service on a web page that manages their own member information.
[0125] The personal information acquisition unit 302 passes the personal information, user ID, and password acquired using a GUI or the like to the service registration request unit 303 .
[0126] The service registration request unit 303 is a means for requesting (requesting) the authentication server 10 to register the user's use of the service.
[0127] The service registration request unit 303 selects a user ID and a password from the three pieces of information (personal information, user ID, and password) acquired from the personal information acquisition unit 302. The service registration request unit 303 transmits a service registration request including the selected user ID, password, and service provider ID to the authentication server 10.
[0128] The service registration request unit 303 acquires a response to the service registration request from the authentication server 10. If the acquired response is a "negative response," the service registration request unit 303 notifies the user of this. For example, the service registration request unit 303 notifies the user that service registration has already been completed.
[0129] If the acquired response is an "affirmative response," the service registration request unit 303 notifies the user that the service registration was successful. The service registration request unit 303 also passes the service user ID included in the response and the personal information acquired from the personal information acquisition unit 302 to the database management unit 304.
[0130] The database management unit 304 is a means for managing a user information database. The user information database is a database that manages information on users (system users) to whom services are provided. The user information database stores personal information (e.g., name) of the user and a service user ID obtained from the authentication server 10 in association with each other.
[0131] The database management unit 304 adds a new entry to the user information database when it acquires the above information (personal information, service user ID) from the service registration request unit 303. For example, when the management server 20 of the service provider S1 acquires the above information regarding the user U1, the entry shown at the bottom of Fig. 15 is added.
[0132] The authentication request unit 305 is a means for requesting the authentication server 10 to authenticate the user.
[0133] When the authentication request unit 305 acquires biometric information (face image) from the authentication terminal 30, it generates features from the face image. The authentication request unit 305 transmits an authentication request including the generated features and the service provider ID to the authentication server 10.
[0134] If the response from the authentication server 10 is a "negative response" (if the authentication has failed), the authentication request unit 305 notifies the authentication terminal 30 of this fact.
[0135] If the response from the authentication server 10 is an "affirmative response" (if the authentication is successful), the authentication request unit 305 extracts the service user ID included in the response from the authentication server 10. The authentication request unit 305 searches the user information database using the service user ID as a key, and identifies the corresponding entry.
[0136] The authentication request unit 305 reads out the personal information set in the personal information field of the identified entry and transmits it to the authentication terminal 30. For example, in the example of FIG. 15, if the service user ID is "U1S1", the personal information in the bottom row is transmitted to the authentication terminal 30.
[0137] The personal information providing unit 306 is a means for providing the information server 40 with personal information of the user to whom the service is provided.
[0138] The personal information providing unit 306 receives an "acceptance notice" from the user's terminal 50. The personal information providing unit 306 extracts the service user ID included in the acceptance notice. The personal information providing unit 306 searches the user information database using the extracted service user ID as a key to identify the corresponding personal information.
[0139] The personal information providing unit 306 transmits the identified personal information to the information server 40.
[0140] The storage unit 307 stores information necessary for the operation of the management server 20. A user information database is constructed in the storage unit 307.
[0141] [Authentication terminal] The authentication terminal 30 transmits the biometric information acquired from the user to the management server 20, thereby acquiring the personal information of the user from the management server 20. The authentication terminal 30 provides services to the user using the acquired personal information.
[0142] 16 is a diagram showing an example of the processing configuration (processing modules) of the authentication terminal 30 according to the first embodiment. Referring to FIG. 16, the authentication terminal 30 includes a communication control unit 401, a biometric information acquisition unit 402, a service providing unit 403, a message output unit 404, and a storage unit 405.
[0143] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the management server 20. The communication control unit 401 also transmits data to the management server 20. The communication control unit 401 passes data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401.
[0144] The biometric information acquisition unit 402 is a means for controlling the camera and acquiring biometric information (face image) of the user. The biometric information acquisition unit 402 captures an image in front of the device periodically or at a predetermined timing. The biometric information acquisition unit 402 determines whether the acquired image contains a human face image, and if a face image is included, extracts the face image from the acquired image data.
[0145] Note that since existing technologies can be used for the facial image detection process and facial image extraction process by the biometric information acquisition unit 402, detailed description thereof will be omitted. For example, the biometric information acquisition unit 402 may extract a facial image (face region) from image data using a learning model trained by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 402 may extract a facial image using a method such as template matching.
[0146] The biometric information acquisition unit 402 passes the extracted facial image to the service provision unit 403 .
[0147] The service providing unit 403 is a means for providing a predetermined service to a user. The service providing unit 403 transmits the facial image acquired from the biometric information acquiring unit 402 to the management server 20. The management server 20 returns personal information (e.g., name, etc.) corresponding to the facial image. The service providing unit 403 uses the returned personal information to provide the service to the user.
[0148] The message output unit 404 is a means for outputting various messages to the user. For example, the message output unit 404 outputs a message regarding the authentication result of the user or a message regarding the provision of services. The message output unit 404 may display the message using a display device such as an LCD monitor, or may play an audio message using an audio device such as a speaker.
[0149] The storage unit 405 stores information necessary for the operation of the authentication terminal 30 .
[0150] [Device] 17 is a diagram showing an example of a processing configuration (processing module) of the terminal 50 according to the first embodiment. Referring to FIG. 17, the terminal 50 includes a communication control unit 501, a personal information control unit 502, and a storage unit 503.
[0151] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the authentication server 10 or the like. The communication control unit 501 also transmits data to the management server 20 or the like. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 501.
[0152] The personal information control unit 502 is a means for controlling whether or not personal information held by the service provider is to be provided to the information server 40 in accordance with the user's will.
[0153] When the personal information control unit 502 receives an authentication notification from the authentication server 10, it acquires the user's intention regarding whether or not to consent to the provision of personal information stored in the management server 20 to the information server 40. Specifically, the personal information control unit 502 generates a GUI for the user to input whether or not they wish to provide their personal information. For example, the personal information control unit 502 generates a GUI such as that shown in FIG. 18 to acquire the user's consent regarding the provision of personal information. If the user does not perform any operation for a predetermined period of time, the personal information control unit 502 may automatically select either the action of providing or refusing personal information and proceed with the process. For example, in FIG. 18, if the "YES" button is not pressed within the predetermined period of time, the personal information control unit 502 may determine that the "No" button has been pressed.
[0154] 18 is an example. For example, as shown in Fig. 19, personal information control unit 502 may display details of authentication by authentication server 10 (authentication result, authentication date and time, authentication location, and authenticated face image (photographed image)).
[0155] Alternatively, the personal information control unit 502 may generate a GUI for inputting the validity period of the personal information to be provided, as shown in Fig. 20. The personal information control unit 502 also notifies the information server 40 of the acquired period. The information server 40 stores the personal information for the specified period and discards the personal information after the period has elapsed.
[0156] Alternatively, the personal information control unit 502 may generate a GUI that allows the user to select the personal information to be provided, as shown in Fig. 21. When the user sees a display such as that shown in Fig. 21, he or she individually selects services (recipients of personal information) for which he or she can agree to provide personal information. Alternatively, the personal information control unit 502 may store (acquire) for each user whether or not to provide personal information for each recipient of personal information. Furthermore, the personal information control unit 502 may generate a GUI that allows the user to input the validity period of personal information to be provided for each recipient of personal information.
[0157] If the user refuses to provide personal information, personal information control unit 502 does not take any particular action.
[0158] When the user agrees to the provision of personal information, the personal information control unit 502 transmits an acceptance notification to the management server 20. At that time, the personal information control unit 502 transmits the acceptance notification including the service user ID notified by the authentication server 10 to the management server 20, which is the acceptance notification destination notified by the authentication server 10.
[0159] The storage unit 503 stores information necessary for the operation of the terminal 50.
[0160] [Information Server] The processing configuration (processing module) of the information server 40 will be clear to those skilled in the art, and therefore a description thereof will be omitted. The information server 40 only needs to have the function of communicating with other devices and the function of storing personal information.
[0161] [System Operation] Next, a description will be given of the operation of the authentication system according to the first embodiment. Note that the operation will be described for the service registration phase, the service provision phase, and the personal information collection phase, and a description of the user registration phase will be omitted.
[0162] FIG. 22 is a sequence diagram showing an example of operations related to the service registration phase of the authentication system according to the first embodiment.
[0163] The management server 20 acquires personal information (information necessary to provide the service), a user ID, and a password from the user (step S01).
[0164] The management server 20 transmits a service registration request including the acquired user ID, password, and service provider ID to the authentication server 10 (step S02).
[0165] The authentication server 10 generates a service user ID using the acquired user ID, password, and service provider ID (step S03).
[0166] The authentication server 10 stores the service provider ID and the service user ID in the authentication information database (step S04).
[0167] The authentication server 10 transmits a response (response to the service registration request) including the service user ID to the management server 20 (step S05).
[0168] The management server 20 associates the personal information acquired in step S01 with the service user ID acquired from the authentication server 10 and stores them in the user information database (step S06).
[0169] In this way, the management server 20 acquires the service user ID by sending an authentication request including the user ID, password, and service provider ID to the authentication server 10. The management server 20 stores the acquired service user ID in association with the user's personal information.
[0170] FIG. 23 is a sequence diagram showing an example of operations related to the service providing phase of the authentication system according to the first embodiment.
[0171] The authentication terminal 30 acquires a facial image (biometric information) of the user, and transmits the acquired facial image to the management server 20 (step S11).
[0172] The management server 20 generates a feature amount from the acquired face image (step S12).
[0173] The management server 20 transmits an authentication request including the generated feature amount and the service provider ID to the authentication server 10 (step S13).
[0174] The authentication server 10 executes authentication processing using the feature amount and the service provider ID included in the authentication request, and identifies the corresponding service user ID (step S14).
[0175] The authentication server 10 transmits a response (response to the authentication request) including the identified service user ID to the management server 20 (step S15).
[0176] The management server 20 searches the user information database using the acquired service user ID, and identifies the corresponding personal information (step S16).
[0177] The management server 20 transmits the identified personal information to the authentication terminal 30 (step S17).
[0178] The authentication terminal 30 provides the service using the acquired personal information (step S18).
[0179] FIG. 24 is a sequence diagram showing an example of operations related to the personal information collection phase of the authentication system according to the first embodiment.
[0180] If the authentication of the user is successful, the authentication server 10 transmits an authentication notification to the terminal 50 carried by the user (step S21).
[0181] Upon receiving the authentication notification, the terminal 50 generates a GUI for acquiring the user's intention regarding providing personal information to a third party (information center, information server 40) (step S22).
[0182] If the user agrees to provide personal information, the terminal 50 transmits an acceptance notice to the management server 20 (step S23).
[0183] Upon receiving the acceptance notice, the management server 20 transmits the personal information of the user to the information server 40 (step S24).
[0184] The information server 40 stores the received personal information (step S25).
[0185] In this way, the authentication server 10 transmits an authentication notification including the service user ID and the destination of the acceptance notification (acceptance notification destination information) to the terminal 50. If the user agrees to the provision of personal information, the terminal 50 transmits an acceptance notification including the service user ID to the management server 20.
[0186] As described above, in the authentication system according to the first embodiment, when the authentication server 10 has successfully authenticated a user, it notifies the user (terminal 50) of this fact. The terminal 50 then inquires of the user as to whether personal information related to the biometric authentication can be provided to a third party (for example, the information server 40). If the user agrees to the provision of personal information, the terminal 50 notifies the management server 20 of this. In this way, in the authentication system according to the first embodiment, the user can control and manage personal information related to the provision of services using biometric authentication.
[0187] Furthermore, in the authentication system according to the first embodiment, the authentication server 10 performs centralized control of biometric authentication of users. By transmitting an authentication notification to the terminal 50 from the authentication server 10 performing such centralized control, various benefits can be obtained. For example, it is conceivable to provide coupons or the like to users to motivate them to provide personal information. In this case, the authentication server 10 can provide coupons or the like related to multiple service providers to the users. For example, the authentication server 10 can provide coupons that can be used at service providers S1 and S2, or can provide a coupon from service provider S2 to a user who provides personal information held by service provider S1.
[0188] [Second embodiment] Next, the second embodiment will be described in detail with reference to the drawings.
[0189] In the first embodiment, a case has been described in which, in the personal information collection phase, the authentication server 10 transmits an authentication notification to the terminal 50. In the second embodiment, a case will be described in which the management server 20 transmits an authentication notification.
[0190] The configuration of the authentication system according to the second embodiment can be the same as that of the first embodiment, and therefore the explanation corresponding to Fig. 2 will be omitted. In addition, the processing configurations of the authentication server 10, management server 20, authentication terminal 30, and terminal 50 according to the second embodiment can also be the same as those of the first embodiment, and therefore the explanation thereof will be omitted.
[0191] The following description will focus on the differences between the first and second embodiments.
[0192] In the user registration phase according to the second embodiment, the authentication server 10 does not need to acquire the user's contact information (email address). In the user registration phase according to the second embodiment, the user only needs to input their user ID, password, and biometric information (face image) to the authentication server 10.
[0193] In the service registration phase according to the second embodiment, the management server 20 acquires the user's contact information. The management server 20 acquires the email address of an account that can be received at the terminal 50 as one of the pieces of personal information acquired from the user.
[0194] As for the service provision phase, the operations can be the same in the first and second embodiments.
[0195] FIG. 25 is a diagram for explaining the operation of the authentication system in the personal information collection phase according to the second embodiment.
[0196] 25, upon receiving a response to the authentication request from the authentication server 10, the management server 20 transmits an "authentication notification" to the user who has been successfully authenticated. The terminal 50 that has received the authentication notification obtains from the user whether or not to provide personal information, and if the user agrees to the provision of personal information, transmits a consent notification to the management server 20.
[0197] The management server 20 transmits the personal information of the user to the information server 40.
[0198] Among the processing modules of the management server 20 according to the second embodiment, modules whose operations differ from those of the processing modules of the management server 20 according to the first embodiment will be described.
[0199] The personal information acquisition unit 302 acquires personal information including contact information such as an email address from the user.
[0200] When the authentication request unit 305 receives a response to the authentication request from the authentication server 10 , it passes the response to the personal information provision unit 306 .
[0201] If the response is a positive response (authentication successful), the personal information providing unit 306 searches the user information database using the service user ID included in the response as a key to identify the corresponding personal information. The personal information providing unit 306 reads out the contact information included in the identified personal information and sends an authentication notification to the contact information.
[0202] When an acceptance notice is received from the terminal 50, the personal information providing unit 306 transmits to the information server 40 the personal information of the user who sent the authentication notice.
[0203] The basic operations of the authentication server 10 and the terminal 50 according to the second embodiment are the same as those described in the first embodiment and are obvious to those skilled in the art, so a description thereof will be omitted. Furthermore, the authentication terminal 30 can operate in the same manner in the first and second embodiments.
[0204] The authentication notification and consent notification sent and received in the second embodiment need only notify the fact of authentication or consent, and do not need to include information (such as the service user ID) as described in the first embodiment.
[0205] As described above, in the authentication system according to the second embodiment, when the authentication server 10 successfully performs biometric authentication of a user, the management server 20 transmits to the terminal 50 an authentication notification indicating that the biometric authentication of the user has been successful. In response to receiving the authentication notification, the terminal 50 transmits to the management server 20 a consent notification indicating that the user has consented to the provision of personal information stored in the management server 20 to the information server 40. The second embodiment also allows the user to appropriately control and manage personal information related to services using biometric authentication.
[0206] [Third embodiment] Next, the third embodiment will be described in detail with reference to the drawings.
[0207] In the third embodiment, a case will be described in which the authentication terminal 30 acquires whether or not personal information can be provided.
[0208] The configuration of the authentication system according to the third embodiment can be the same as that of the first and second embodiments, and therefore the description corresponding to Fig. 2 will be omitted. In addition, the processing configurations of the authentication server 10, management server 20, authentication terminal 30, and terminal 50 according to the third embodiment can also be the same as those of the first and second embodiments, and therefore the description thereof will be omitted.
[0209] In the third embodiment, the user's contact information, which was required in the first and second embodiments, is not required because the authentication terminal 30 acquires whether or not personal information can be provided.
[0210] FIG. 26 is a diagram for explaining the operation of the authentication system in the service provision phase according to the third embodiment.
[0211] 26, when the authentication terminal 30 acquires personal information from the management server 20, it uses the personal information to provide a service. After the provision of the service is completed, the authentication terminal 30 displays a GUI asking whether or not to provide personal information.
[0212] If the user agrees to provide the personal information, the authentication terminal 30 sends a consent notice indicating this to the management server 20. The management server 20 sends the personal information sent to the authentication terminal 30 to the information server 40.
[0213] As described above, in the authentication system according to the third embodiment, the authentication terminal 30 acquires the user's intention regarding the provision of personal information. According to the third embodiment, the user can also appropriately control and manage personal information related to services using biometric authentication.
[0214] Next, the hardware of each device constituting the authentication system will be described. Fig. 27 is a diagram showing an example of the hardware configuration of terminal 50.
[0215] The terminal 50 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 27. For example, the terminal 50 has a processor 311, a memory 312, an input / output interface 313, a communication interface 314, etc. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
[0216] However, the configuration shown in Fig. 27 is not intended to limit the hardware configuration of the terminal 50. The terminal 50 may include hardware not shown. Furthermore, the number of processors 311 and the like included in the terminal 50 is not intended to be limited to the example shown in Fig. 27, and for example, the terminal 50 may include multiple processors 311.
[0217] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).
[0218] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.
[0219] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.
[0220] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a wireless communication circuit, a NIC (Network Interface Card), etc.
[0221] The functions of the terminal 50 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by semiconductor chips.
[0222] The authentication server 10, management server 20, authentication terminal 30, information server 40, etc. can also be configured using information processing devices similar to the terminal 50, and their basic hardware configurations are no different from those of the terminal 50, so a description thereof will be omitted. For example, the authentication terminal 30 may be provided with a camera for capturing an image of the user.
[0223] The terminal 50 is equipped with a computer, and the computer executes a program to realize the functions of the terminal 50. The terminal 50 also executes a control method for the terminal 50 by the program.
[0224] [Variations] The configuration, operation, etc. of the authentication system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.
[0225] In the above embodiment, a user determines a user ID and a password, and the user (system user) registered in the system is identified using the user ID and password. However, the authentication system may determine an ID (identifier) that uniquely identifies a system user. For example, in the user registration phase, the authentication server 10 acquires the user's biometric information (facial image, feature amounts). The authentication server 10 may generate the ID based on the biometric information. For example, the authentication server 10 may calculate a hash value from the feature amounts of the facial image and use the calculated hash value instead of the user ID and password. The feature amounts of the facial image differ for each user, and the hash value generated from the feature amounts also differs for each user, so it can be used as the system user's ID.
[0226] In the above embodiment, it has been described that the user registration phase and the service registration phase are executed at different times, but these phases may be executed substantially at the same time. For example, the above two registration phases may be executed using an authentication terminal 30 installed at a service provider to which the user wishes to receive a service. Specifically, the user may perform user registration using the authentication terminal 30, and then perform service registration consecutively. In this case, the authentication terminal 30 may be provided with a user registration function (user registration unit 202) of the authentication server 10 and a personal information acquisition function (personal information acquisition unit 302) of the management server 20.
[0227] The multiple authentication terminals 30 owned by a service provider do not have to be installed on the same premises, building, etc. As long as the service provider is the same, the authentication terminals 30 may be installed in spatially separate locations.
[0228] In the above embodiment, one service provider ID is assigned to one service provider, but one service provider ID may be assigned to multiple service providers. Multiple service providers may be grouped together and a service provider ID may be issued for each group. For example, if service providers S1 and S2 cooperate with each other and provide the same service, a common service provider ID may be issued to these service providers S1 and S2.
[0229] In the above embodiment, a case has been described in which biometric information related to "features generated from a facial image" is transmitted from the management server 20 to the authentication server 10. However, biometric information related to a "facial image" may also be transmitted from the management server 20 to the authentication server 10. In this case, the authentication server 10 may generate features from the acquired facial image and execute the authentication process (matching process).
[0230] In the above embodiment, the authentication terminal 30 acquires a facial image and the management server 20 generates features from the facial image. However, the authentication terminal 30 may generate features from the facial image and transmit the generated features to the management server 20. In other words, the management server 20 does not have to generate features.
[0231] In the above embodiment, a case has been described in which a user enters a user ID and a password to a service provider when registering personal information in the service registration phase (see FIG. 14). However, instead of the user ID and password, the user's biometric information (facial image) may be entered to the service provider. In this case, the management server 20 transmits a service registration request to the authentication server 10, including features generated from the facial image and a service provider ID. The authentication server 10 performs a matching process using the features included in the request and features registered in the authentication information database to identify the corresponding user. If the authentication server 10 successfully identifies (authenticates) the user, it issues a service user ID. This approach allows the user to easily register for a service even if they have forgotten their user ID or password. Alternatively, the service provider may acquire the user's biometric information (facial image) in addition to the user ID and password. In this case, the authentication server 10 may issue a service user ID if the user ID, password, and biometric information match (two-factor authentication using biometric information and a password may be performed).
[0232] The service provider may cache (temporarily store) information acquired from the authentication server 10 or the authentication terminal 30. For example, the management server 20 caches the biometric information acquired from the authentication terminal 30 and the authentication result (service user ID) based on the biometric information for a predetermined period of time. When acquiring biometric information from the authentication terminal 30, the management server 20 first checks the cached data, and if there is cached data that matches the acquired biometric information, the management server 20 does not send an authentication request to the authentication server 10. The management server 20 identifies personal information using the service user ID included in the cached data. Alternatively, the management server 20 may cache a combination of biometric information and personal information. Alternatively, the conditions for deleting cached data may be changed depending on the type of service. For example, when a hotel operator provides accommodation services, the management server 20 may delete the cached data when the guest's stay period ends.
[0233] The form of data transmission and reception between the devices (authentication server 10, management server 20, authentication terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Biometric information is transmitted and received between these devices, and in order to appropriately protect the biometric information, it is desirable to transmit and receive encrypted data.
[0234] In the above embodiment, if the user does not agree to the provision of personal information, the terminal 50 does not perform any particular operation. However, in such a case, the terminal 50 may transmit a "rejection notice" to the management server 20 indicating that the user has refused to provide personal information.
[0235] In the above embodiment, one information center is exemplified as a recipient of personal information. However, personal information may be provided to multiple information centers (information banks). In this case, the user may use the terminal 50 to select an information center from among the multiple information centers to which personal information is to be provided. Alternatively, the user may determine whether or not personal information is to be provided for each of the multiple information centers. Alternatively, the terminal 50 may display the information centers together with the benefits that can be obtained by providing personal information to each information center.
[0236] In the above embodiment, the user decides whether or not to provide personal information for each service provider. However, the terminal 50 may be provided with a GUI that allows the user to input whether or not to provide personal information for the entire authentication system.
[0237] The authentication server does not need to send a new authentication notification for a combination of a user and a service provider to which it has already sent an authentication notification. For example, in the example of Figure 2, if the user permits the service provider S1 to provide personal information, the authentication server does not need to send an authentication notification when the user receives a service from the service provider S1 on another occasion. In other words, the authentication server 10 does not need to send an authentication notification more than once for the same service user ID. This is because it is assumed that the personal information notification from the same service provider will not change if the user is the same user.
[0238] In the above embodiment, whether or not to provide personal information is determined after the service is provided by the service provider. However, the determination may be made before the service is provided. In other words, the determination may be made either before or after the service is provided, as long as it is after authentication by the authentication server 10.
[0239] In the above embodiment, the case where the terminal 50 acquires the permission / inhibition regarding the provision of personal information has been described. The terminal 50 may be used for a purpose other than the above. For example, the user may use the terminal 50 to update other information registered in the authentication server 10. For example, the user may use the terminal 50 to access the authentication server 10 and select a service provider from which to receive services through biometric authentication. That is, the user may register for a service via the authentication server 10. In this case, if there are many service providers, service providers that are used less frequently or have not been used recently may be displayed preferentially. Alternatively, the user may use the terminal 50 to request withdrawal from the system or service.
[0240] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.
[0241] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.
[0242] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to authentication systems for authenticating customers of retail stores, hotels, etc.
[0243] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. [Appendix 1] an authentication server that stores first biometric information of a user and performs biometric authentication of the user using the first biometric information; a management server that stores personal information of the user; A terminal owned by the user; Including, When the biometric authentication of the user is successful, the authentication server transmits an authentication notification indicating that the biometric authentication of the user is successful to the terminal; In response to receiving the authentication notification, the terminal acquires the user's intention regarding whether or not to consent to providing the stored personal information to a third party; When the user agrees to provide the stored personal information to a third party, the authentication system sends a consent notice to the management server. [Appendix 2] 2. The authentication system of claim 1, wherein the management server transmits the user's personal information to the third party in response to receiving the acceptance notification. [Appendix 3] further including an authentication terminal connected to the management server, acquiring second biometric information of the user, and transmitting the acquired second biometric information to the management server; the management server transmits an authentication request including the second biometric information to the authentication server; 3. The authentication system according to claim 1, wherein the authentication server performs biometric authentication of the user using the first and second biometric information. [Appendix 4] 4. The authentication system of claim 3, wherein the authentication server sends the authentication notification to the terminal, the authentication notification including information regarding a destination of the acceptance notification. [Appendix 5] 5. The authentication system according to claim 4, wherein the authentication server stores a destination of the authentication notification. [Appendix 6] The authentication server storing, in association with each other, a first ID that uniquely identifies a user in the system, a second ID that identifies a service provider in which the management server is installed, a third ID that is uniquely determined by a combination of the user and the service provider, the first biometric information, and a destination of the authentication notification; The management server An authentication system as described in Appendix 5, which obtains the third ID by sending the authentication request including the first ID and the second ID to the authentication server, and stores the obtained third ID in association with the user's personal information. [Appendix 7] the authentication server transmits the authentication notification to the terminal, the authentication notification including the third ID and a destination of the authentication notification; 7. The authentication system of claim 6, wherein the terminal transmits the acceptance notification including the third ID to the management server. [Appendix 8] 8. The authentication system according to claim 3, wherein the first and second biometric information are biometric information relating to a face. [Appendix 9] An authentication system described in any one of Appendices 1 to 8, wherein the terminal uses a GUI (Graphical User Interface) to obtain the user's intention regarding whether or not to agree to providing the stored personal information to the third party. [Appendix 10] an authentication server that stores first biometric information of a user and performs biometric authentication of the user using the first biometric information; a management server that stores personal information of the user; A terminal owned by the user; Including, When the authentication server has successfully performed the biometric authentication of the user, the management server transmits an authentication notification indicating that the biometric authentication of the user has been successful to the terminal; In response to receiving the authentication notification, the terminal acquires the user's intention regarding whether or not to consent to providing the stored personal information to a third party; When the user agrees to provide the stored personal information to a third party, the authentication system sends a consent notice to the management server. [Appendix 11] storing first biometric information of a user, and performing biometric authentication of the user using the first biometric information; receiving an authentication notification from an authentication server indicating that biometric authentication of the user has been successful; In response to receiving the authentication notification, a management server that stores personal information of the user acquires the user's intention regarding whether or not the user consents to the provision of the stored personal information to a third party; If the user agrees to provide the stored personal information to a third party, the terminal transmits a consent notice to the management server. [Appendix 12] On the device, storing first biometric information of a user, and performing biometric authentication of the user using the first biometric information; receiving an authentication notification from an authentication server indicating that biometric authentication of the user has been successful; In response to receiving the authentication notification, a management server that stores personal information of the user acquires the user's intention regarding whether or not the user consents to the provision of the stored personal information to a third party; A terminal control method, wherein if the user agrees to provide the stored personal information to a third party, a consent notice is sent to the management server. [Appendix 13] The computer installed in the device a process of storing first biometric information of a user, performing biometric authentication of the user using the first biometric information, and receiving an authentication notification from an authentication server indicating that the biometric authentication of the user has been successful; In response to receiving the authentication notification, a management server that stores personal information of the user acquires the user's intention regarding whether or not the user consents to the provision of the stored personal information to a third party; a process of transmitting a consent notice to the management server when the user consents to the provision of the stored personal information to a third party; A computer-readable storage medium that stores a program for executing the above.
[0244] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]
[0245] 10, 101 Authentication Server 20, 20-1, 20-2, 102 Management Server 30, 30-1, 30-2, 31-1, 31-2 Authentication terminal 40 Information Server 50, 103 terminals 201, 301, 401, 501 Communication control unit 202 User Registration Department 203, 304 Database (DB) Management Department 204 Service Registration Department 205 Authentication Department 206, 307, 405, 503 Storage section 302 Personal Information Acquisition Department 303 Service Registration Request Section 305 Authentication Request Section 306 Personal information provision department 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface 402 Biometric information acquisition unit 403 Service Provision Department 404 message output section 502 Personal Information Control Section
Claims
1. a storage unit that stores personal information of the user regarding the use of the service provided to the user; an information providing unit that transmits the personal information of the user stored in the storage unit to a third party when the biometric authentication of the user in connection with the use of the service is successful by an authentication server that performs biometric authentication of the user using the biometric information of the user and when the intention of the user to consent to providing the personal information of the user stored in the storage unit to a third party is acquired from a terminal operated by the user; A management server comprising:
2. 2. The management server according to claim 1, wherein the user's willingness to consent to the provision of the user's personal information to the third party is acquired from the user using a GUI (Graphical User Interface) on the terminal.
3. 3. The management server according to claim 2, wherein the GUI displayed by the terminal displays information for acquiring the user's consent and information regarding biometric authentication of the user by the authentication server.
4. 4. The management server according to claim 1, wherein a validity period is set for the personal information of the user that is provided to the third party.
5. The management server according to claim 1 , further comprising: acquiring, from the terminal, information indicating the third party selected as a recipient of the user's personal information.
6. By computer, storing personal information of the user relating to the use of the service provided to the user in a storage unit; When the biometric authentication of the user associated with the use of the service is successful by an authentication server that performs biometric authentication of the user using the biometric information of the user, and when the user's intention to consent to providing the personal information of the user stored in the storage unit to a third party is acquired from a terminal operated by the user, the personal information of the user stored in the storage unit is transmitted to the third party. Information provision method.
7. A process of storing personal information of the user related to the use of the service provided to the user in a storage unit; a process of transmitting the personal information of the user stored in the storage unit to the third party when the biometric authentication of the user associated with the use of the service is successful by an authentication server that performs biometric authentication of the user using the biometric information of the user and when the user's intention to consent to providing the personal information of the user stored in the storage unit to a third party is acquired from a terminal operated by the user; A computer program that causes a computer to execute the following.
Citation Information
Patent Citations
Electronic settlement system, terminal for individual, terminal for member store, authentication / settlement apparatus, electronic settlement method and electronic settlement program
JP2006190112A