System, information processor, program and information processing method

A decentralized user authentication system improves response times and user experience by distributing biometric information processing across user, provider, and server devices, addressing server overload and connectivity issues.

JP2025165252APending Publication Date: 2025-11-04JCB CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024069253
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-22
Publication Date
2025-11-04

AI Technical Summary

Technical Problem

Existing user authentication systems face issues with server overload and user experience due to centralized biometric information processing, leading to congestion and slow response times.

Method used

A distributed user authentication system where biometric information is acquired and processed across multiple devices, including a user device, provider device, and server, allowing for decentralized authentication and reduced reliance on a single server.

Benefits of technology

Improves user experience and response time by distributing the authentication process, reducing server load and congestion, and ensuring seamless user authentication even in environments with limited network connectivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025165252000001_ABST
    Figure 2025165252000001_ABST
Patent Text Reader

Abstract

To provide a system, an information processor, a program, and an information processing method that enhance the response and user experience during user authentication when providing a service and the like.SOLUTION: A service provision system includes a provider device that provides services and / or products to a user, and a user device of the user. The user device includes a first biometric-information acquisition part that acquires first biometric information concerning the user from an external device, and a user provision part that provides the first biometric information to the provider device. The provider device includes a provider acquisition part that acquires the provided first biometric information from the user device, a detection part that detects second biometric information from the user when providing the services and / or the products, a provider authentication part that authenticates the user based on the first biometric information and the second biometric information, and a provider output part that outputs authentication-result information indicating a result of the authentication.SELECTED DRAWING: Figure 10
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a system, an information processing device, a program, and an information processing method. [Background technology]

[0002] There is known a technology for authenticating a user when providing the user with a service and / or product (also referred to as "service, etc."). The payment system described in Patent Document 1 is configured to perform payment when purchasing a service, etc., and includes a communication terminal with a camera and a server that receives a customer's facial image captured by the communication terminal, performs facial authentication, and grants a merit based on the authentication result to the customer when processing the payment for the customer whose facial authentication is successful. Furthermore, the terminal device described in Patent Document 2 detects the user's biometric information while the user is performing operations other than authentication, and performs biometric authentication based on the detected biometric information. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2023-170890 [Patent Document 2] Japanese Patent Publication No. 2023-159512 Summary of the Invention [Problem to be solved by the invention]

[0004] Here, in the configuration disclosed in Patent Document 1, biometric information is transmitted from the communication terminal to the server, and authentication is performed centrally in one server, which may place a heavy load on the server or cause congestion, leaving room for improvement in response. On the other hand, in the configuration disclosed in Patent Document 2, there are no such concerns about response, but biometric information must be detected on the terminal device used by the user, leaving room for improvement in the user experience (so-called UX) when services are provided.

[0005] Therefore, an object of the present invention is to improve response and user experience in user authentication when providing services, etc. [Means for solving the problem]

[0006] A system according to one embodiment of the present invention includes a provider device of a provider that provides services and / or products to a user, and a user device of the user, wherein the user device comprises a first biometric acquisition unit that acquires first biometric information related to the user's biometrics from an external device, and a user provision unit that provides the first biometric information to the provider device, and the provider device comprises a provider acquisition unit that acquires the first biometric information provided from the user device, a detection unit that detects second biometric information from the user when providing the service and / or product, a provider authentication unit that authenticates the user based on the first biometric information and the second biometric information, and a provider output unit that outputs authentication result information indicating the result of the authentication.

[0007] A program according to one embodiment of the present invention causes a user device of a user receiving a service and / or product to realize a first biometric acquisition function that acquires first biometric information about the user's biometrics from an external device and a user provision function that provides the first biometric information to a provider device; and causes a provider device of a provider that provides a service and / or product to a user to realize a provider acquisition function that acquires the first biometric information provided from the user device, a detection function that detects second biometric information from the user when providing the service and / or product, a provider authentication function that authenticates the user based on the first biometric information and the second biometric information, and a provider output function that outputs authentication result information indicating the result of the authentication.

[0008] In one embodiment of the information processing method of the present invention, a user device of a user receiving a service and / or product acquires first biometric information related to the user's biometrics from an external device and provides the first biometric information to a provider device, and a provider device of a provider providing the service and / or product to the user acquires the provided first biometric information from the user device, detects second biometric information from the user when providing the service and / or product, authenticates the user based on the first biometric information and the second biometric information, and outputs authentication result information indicating the authentication result.

[0009] An information processing device according to one embodiment of the present invention includes a registration unit that registers first biometric information relating to a user's biometrics in a user memory unit, a second biometric acquisition unit that acquires second biometric information detected from the user's body at the time of provision from a provider device of a provider that provides a service or product to the user, a user authentication unit that refers to the user memory unit and authenticates the user based on the first biometric information and the second biometric information, and a user provision unit that provides authentication result information indicating the result of the authentication to the provider device.

[0010] A program according to one embodiment of the present invention causes a computer to implement a registration function that registers first biometric information relating to a user's biometrics in a user memory unit; a second biometric acquisition function that acquires second biometric information detected from the user's body at the time of provision from a provider device of a provider that provides a service or product to the user; a user authentication function that refers to the user memory unit and authenticates the user based on the first biometric information and the second biometric information; and a user provision function that provides authentication result information indicating the result of the authentication to the provider device.

[0011] In an information processing method according to one aspect of the present invention, a computer registers first biometric information relating to a user's biometrics in a user memory unit, acquires second biometric information detected from the user's body at the time of provision from a provider device of a provider that provides a service or product to the user, refers to the user memory unit, authenticates the user based on the first biometric information and the second biometric information, and provides authentication result information indicating the authentication result to the provider device. [Effects of the Invention]

[0012] According to the present invention, it is possible to improve response and user experience in user authentication when providing services, etc. [Brief explanation of the drawings]

[0013] [Figure 1] 1 is a diagram illustrating an example of a system configuration of a service providing system according to an embodiment of the present invention. [Figure 2] 1 is a diagram for explaining an overview of a service providing system according to an embodiment of the present invention; [Figure 3] 1 is a diagram for explaining an overview of a service providing system according to an embodiment of the present invention; [Figure 4] 1 is a diagram for explaining an overview of a service providing system according to an embodiment of the present invention; [Figure 5] 1 is a diagram for explaining an overview of a service providing system according to an embodiment of the present invention; [Figure 6] FIG. 2 is a diagram illustrating an example of a functional configuration of a server device according to the present embodiment. [Figure 7] FIG. 2 is a diagram illustrating an example of the functional configuration of a user device according to the present embodiment. [Figure 8] FIG. 2 is a diagram illustrating an example of a functional configuration of a provider device according to the present embodiment. [Figure 9] FIG. 2 is a diagram illustrating an example of the operation of the service providing system according to the present embodiment. [Figure 10] FIG. 2 is a diagram illustrating an example of the operation of the service providing system according to the present embodiment. [Figure 11] FIG. 2 is a diagram illustrating an example of the operation of the service providing system according to the present embodiment. [Figure 12] FIG. 2 is a diagram illustrating an example of the operation of the service providing system according to the present embodiment. [Figure 13] FIG. 2 is a diagram illustrating an example of the hardware configuration of a server device, a user device, and a provider device according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0014] A preferred embodiment of the present invention (hereinafter referred to as "the present embodiment") will be described with reference to the accompanying drawings. In the drawings, components with the same reference numerals have the same or similar configurations.

[0015] In this invention, the terms "unit," "means," "device," or "system" do not simply mean physical means, but also include cases where the functions of the "unit," "means," "device," or "system" are realized by software. Furthermore, the functions of one "unit," "means," "device," or "system" may be realized by a combination of two or more physical means, devices, or software modules, and the functions of two or more "units," "means," "device," or "system" may be realized by a single physical means, device, or software module.

[0016] <1. System configuration> An example of the system configuration of a service providing system 1 according to this embodiment will be described with reference to FIG. 1. The service providing system 1 is a system for providing services and / or products (also referred to as "services, etc.") to users. When providing services, etc., the service providing system 1 authenticates the user (also referred to as "user authentication") using biometric information of the user, etc. The service providing system 1 may be developed using, for example, an SDK (Software Development Kit).

[0017] User authentication may be, for example, authentication to confirm the legitimacy of a user. User authentication may be performed once or multiple times. Performing user authentication multiple times may mean, for example, performing multi-factor authentication such as two-factor authentication using multiple authentication factors, or performing multi-stage authentication such as two-step authentication that performs authentication in stages. As another example, performing user authentication multiple times may mean performing two or more authentications with different authentication levels. User authentication is typically performed using biometric authentication, but biometric authentication may be combined with knowledge authentication and / or possession authentication. As another example, user authentication may normally involve knowledge authentication or possession authentication, and biometric authentication may be performed when performing account recovery, etc.

[0018] The authentication level may represent, for example, the strength of the authentication means. The authentication level may also represent, for example, whether or not multi-factor authentication is used. The authentication level may also represent, for example, whether or not multi-stage authentication is used. The authentication level may also represent, for example, whether or not multi-path authentication is used.

[0019] The user authentication may be, for example, authentication defined by NIST SP 800-63-3, and the authentication level applied to the user authentication may be, for example, AAL (Authenticator Assurance Level) defined by NIST SP 800-63B.

[0020] The information used for user authentication (also called "authentication information") is typically the user's biometric information, but may also include information about the user's belongings and / or stored information in addition to the biometric information.

[0021] The possession information may be, for example, device identification information or information stored on an IC card that identifies a device that is possessed by the user (e.g., a user device 200 such as a smartphone), and / or location information that indicates the location of the possession.

[0022] The biometric information may be, for example, information about a living body such as a user's physical characteristics, such as appearance (e.g., face), fingerprints, palm prints, veins, irises, and / or DNA, or may be, for example, information about a behavioral characteristic, such as a voiceprint, dynamic signature, gait, and / or device operations such as keystrokes.

[0023] The biometric information (so-called template data) that is acquired in advance for biometric authentication and serves as a reference for matching is referred to as “first biometric information,” and the biometric information that is detected from the user’s body during biometric authentication is referred to as “second biometric information.” The first biometric information may include, for example, certification information that certifies the user corresponding to the first biometric information or the first biometric information, as will be described later.

[0024] The stored information may be, for example, a user ID that identifies the user in the service providing system 1, a card number used to settle a transaction, an account number, a telephone number, an account name such as an email address, a password, a signature or figure entered or selected by the user, a free-entry or multiple-choice answer to a specified question, or any other information that is stored by the user and can be obtained by the server device 100.

[0025] When user authentication uses at least one of a plurality of authentication means (for example, when multi-factor authentication or multi-stage authentication is used), the authentication information may include, for example, authentication information for each of the plurality of authentication means. The authentication means may be, for example, possession information about belongings carried by the user, biometric information about the user's biometrics, or a means for user authentication based on stored information stored by the user.

[0026] As shown in FIG. 1, the service providing system 1 includes a server device 100, a user device 200 of a user, and a provider device 300 of a provider that provides services. The server device 100, the user device 200, and the provider device 300 are connected to each other via a first network N1. The user device 200 and the provider device 300 may also be communicably connected via a P2P (peer-to-peer) second network N2. At least a portion of the collaboration between the server device 100, the user device 200, and the provider device 300 may be realized by an API and / or SDK library.

[0027] [Server device] The server device 100 is an information processing device capable of communicating with the user device 200 and the provider device 300. The server device 100 executes a predetermined program (also referred to as a "server program") to generate information (also referred to as "certification information") that certifies the user or the user's authentication information (biometric information) for user authentication, and provides the certification information to the user device 200 in association with the authentication information. The server device 100 may also provide the user with a UI (also referred to as an "authentication service UI"), such as a dashboard function, for using a service related to user authentication (also referred to as an "authentication service") of the service providing system 1, via, for example, a web browser or a dedicated app described below. In the service providing system 1, the user may perform various operation inputs, such as input of authentication settings, via the authentication service UI.

[0028] [User device] User device 200 is an information processing device used (operation input) by a user, and is, for example, a mobile device such as a smartphone, laptop, or tablet. User device 200 may be any device used by a user, and other examples include a drone, a vehicle, an in-vehicle device, or a wearable device.

[0029] The user device 200 executes a predetermined program (also referred to as a "user program") to receive various requests from users, cooperate with the server device 100 and / or the provider device 300 to receive authentication requests for user authentication when a user logs in to the service providing system 1, and authenticate the user by comparing second biometric information (including certification information) acquired from an external device such as the server device 100 with first biometric information acquired from the provider device 300. The user program may be a general-purpose web browser, an add-in to other software, or an application program dedicated to the authentication service UI (also referred to as a "dedicated app"). This add-in or dedicated app may be developed, for example, using an SDK.

[0030] [Provider device] The provider device 300 is an information processing device used by a provider and is capable of communicating with the server device 100 and the user device 200. The provider device 300 may be, for example, a store terminal (for example, a tablet terminal or a POS register terminal equipped with a POS register app) of a store that provides services, etc., that executes processing for payment for services, etc. (also referred to as "payment processing").

[0031] The provider device 300 may execute a predetermined program (also referred to as a "provider program") to, for example, accept various requests from a provider, detect first biometric information from the user's body or behavior during biometric authentication, and authenticate the user by comparing the detected biometric information with second biometric information acquired from the user device 200 or the like. The provider program may also be a general-purpose web browser, an add-in to other software, or a dedicated app for the authentication service UI. This add-in or dedicated app may be developed using an SDK, for example.

[0032] The provider device 300 may have a built-in sensor (also called a "biometric sensor") that detects (reads) biometric information from the user's body, or may operate as an external sensor. For example, the biometric sensor may be a fingerprint sensor that reads a fingerprint if the biometric information is information related to a fingerprint, or an imaging device (camera) that captures an image of the user's appearance if the biometric information is information related to appearance.

[0033] [network] The first network N1 is configured by a wireless network or a wired network. Examples of the network N include a mobile phone network, a PHS (Personal Handy-phone System) network, a wireless LAN (a local area network, including communication conforming to IEEE802.11 (so-called WI / Fi (registered trademark))), 3G (3rd Generation), LTE (Long Term Evolution), 4G (4th Generation), 5G (5th Generation), WiMax (registered trademark), infrared communication, visible light communication, Bluetooth (registered trademark), a wired LAN, a telephone line, a power line communication, a power line network, a network conforming to IEEE1394, etc.

[0034] The second network N2 is a communication network for interconnecting multiple devices. The second network N2 includes, for example, a network that realizes short-distance wireless communication at a distance of about 10 cm using electromagnetic induction such as near field communication (NFC), and short-distance wireless communication at a distance of about 10 m such as Bluetooth (registered trademark), Bluetooth Low Energy (BLE), Ultra Wide Band (UWB), and infrared communication. The second network N2 may also include, for example, a wireless LAN conforming to the Wi-Fi (registered trademark) standard, and interconnection between multiple devices is realized by relaying the communication using a router (not shown).

[0035] <2. Overview> 2 to 5, an overview of an example of the service providing system 1 will be described. In the service providing system 1, for user authentication, functions are distributed as follows, for example, and all devices are assumed to have the authentication function for user authentication (specifically, a function for matching biometric information), and the device that executes this authentication function can be changed according to user settings. Server device 100: Registration and management of first biometric information of a user, generation of certification information to certify the user or biometric information User device 200: Acquires first biometric information from the server device 100 and provides it to the provider device 300 Provider device 300: Detects second biometric information of the user

[0036] Users of the service providing system 1 may be providers who provide services to users and users who receive services, etc., as well as, for example, operations managers who operate and manage the service providing system 1.

[0037] <2-1. Pre-settings> In the example of FIG. 2, an example of a scene prior to user authentication will be described. (1) As shown in FIG. 2, in response to a user's input, the user device 200 sends an information registration request including the user's user information or biometric information to the server device 100 in order to register a new account in the service providing system 1 or to start using the authentication service for an existing account.

[0038] The server device 100 receives the transmitted information registration request. Note that the biometric information to be registered or the information registration request may be received from the provider device 300 or another device in addition to the user device 200.

[0039] User information is information about a user. User information may include, for example, user identification information that identifies the user, user attribute information, and / or user authentication information. Attribute information may include, for example, name, gender, age, address, and / or information indicating contact information (e.g., email address, telephone number, etc.). User information may include, for example, payment method information.

[0040] Payment method information is information about payment methods available to users. Payment method information may include, for example, type information indicating the type of payment method (e.g., credit card payment, debit card payment, electronic money payment, etc.), payment method identification information for identifying the payment method (e.g., ID, card number, account number, etc.), payment service provider information about the payment service provider that provides the payment method, and user account information for the payment method (e.g., ID, etc.).

[0041] (2) The server device 100 may generate first biometric information for user authentication based on the biometric information transmitted in (1) above. The acquired biometric information and the first biometric information may be the same or different. In the latter case, for example, the server device 100 may perform preprocessing (e.g., normalization) on the acquired biometric information, extract features of the preprocessed biometric information, and use information indicating the extracted features as the first biometric information.

[0042] The server device 100 receives an information registration request (including biometric information) from the user device 200 and generates an electronic certificate as certification information that proves the legitimacy (e.g., authenticity, integrity, etc.) of the biometric information or the user corresponding to the biometric information.

[0043] The certification information may be, for example, an electronic certificate (e.g., an x.509 certificate or credential information such as VC (Verifiable Credentials)), an electronic signature (message digest), the user's e-seal, a timestamp, and / or information indicating the results of the user's identity verification (also referred to as "identity verification result information").

[0044] (3) The server device 100 associates the biometric information acquired in (1) above with part or all of the first biometric information and the certification information generated in (2) above and registers them in the server storage unit 130.

[0045] (4) The server device 100 provides the first biometric information and the digital certificate generated in (2) above to the user device 200. Note that the processes in (2) to (4) above may be executed again when a request to update the certification information is received from the user device 200.

[0046] (5) The user device 200 registers the first biometric information and the digital certificate provided in (4) above in the user storage unit 230.

[0047] (6) In response to the user's setting input, the user device 200 transmits to the server device 100 a registration request for settings related to user authentication, such as an authentication method (also called "authentication settings").

[0048] The authentication settings may include, for example, setting a device (also called an "authentication device") that authenticates a user (matches biometric information), the type of biometric authentication to be used (e.g., face authentication, fingerprint authentication, vein authentication, etc.), the expiration date of the authentication information, and / or the method of authentication information (e.g., electronic certificate, digital signature, etc.) for each service that uses biometric authentication and / or for each location where the service is used (e.g., a specific store, a specific facility, or a location related to a specific industry). The authentication device may be, for example, the user device 200, the provider device 300, or the server device 100 (cloud), etc.

[0049] The type of biometric authentication used may be, for example, one type, or two or more types may be combined. When two or more types are combined, a device that executes the authentication function may be assigned to each type. For example, when face authentication and fingerprint authentication are used for user authentication, matching in face authentication may be performed by the provider device 300, while matching in fingerprint authentication may be performed by the server device 100.

[0050] The authentication settings may be set for each situation where biometric authentication is further used (for example, when confirming a service reservation, when confirming membership information including whether the user is a member or non-member, when making payment for a service, etc.).

[0051] (7) In response to the request in (5) above, the server device 100 registers the authentication settings in association with the user information of the user. Specifically, the server device 100 associates setting information indicating the authentication settings with the user information and registers the information in the server storage unit 130.

[0052] The above processes (1) to (3) and the above processes (6) to (7) may be executed together or individually. Furthermore, the above processes (1) to (3) and the above processes (6) to (7) may be executed in a different order.

[0053] <2-2. Verification by the provider device 300> The examples of Figures 3 to 5 will be described as an example in which a user purchases a product at a provider's store. In the example of Figure 3, an example in which the authentication function is executed by the provider device 300 will be described. In this example, the provider device 300 is a POS register installed in a store, and an imaging device serving as a biometric sensor is linked to (externally attached to) this POS register. In this example, it is also assumed that communication via the second network N2 has been established in advance between the user device 200 and the provider device 300. In this example, the certification information is an electronic certificate.

[0054] (1) As shown in Fig. 3, when a user receives a service or the like (specifically, when paying for a service or the like), the user device 200 provides the first biometric information and electronic certificate registered in (5) of 2-1 above to the provider device 300 in response to operational input from the user. This provision may be triggered not only by operational input from the user but also by receipt of an authentication request for user authentication transmitted from the provider device 300. Note that part of this first biometric information and electronic certificate may be provided from the server device 100.

[0055] (2) The provider device 300 captures an image of the user's face using an imaging device that is a biometric sensor. The provider device 300 generates image information of the captured image of the user's appearance as second biometric information. The provider device 300 may also extract feature information from this image information as the second biometric information for matching with the first biometric information.

[0056] (3) The provider device 300 verifies the electronic certificate included in the first biometric information acquired in (1) above. If the provider device 300 determines that the electronic certificate is valid as a result of the verification, it performs user authentication (face authentication) based on the first biometric information and the second biometric information. Specifically, the provider device 300 compares the first biometric information with the second biometric information and determines whether the authentication is successful or unsuccessful based on the result of this comparison.

[0057] (4) The provider device 300 outputs authentication result information indicating the result of the user authentication described above in (3) to the user and the provider (store clerk) on a screen and / or by voice. The provider device 300 may also provide the authentication result information to the user device 200 and / or the server device 100.

[0058] With the above configuration, the service providing system 1 can perform user authentication without communicating with the server device 100 connected via the first network N1. This prevents situations where user authentication does not proceed due to a lack of communication or slow communication speed, even in an environment where communication with a wide area communication network such as the Internet is difficult. This improves the user experience when receiving services, etc. Furthermore, because user authentication is mainly processed on the edge side, user authentication is not concentrated in one place on the server device 100, reducing the load and congestion on the server device 100 and improving the response time of user authentication.

[0059] <2-3. Verification by the user device 200> 4, an example will be described in which the authentication function is executed by the user device 200. In this example, the biometric sensor is also an imaging device, and the second biometric information is image information of the user's face captured by this imaging device (or feature information extracted from the image information).

[0060] (1) As shown in FIG. 4, when a user receives a service or the like, the provider device 300 detects second biometric information from the face of the user using a biometric sensor.

[0061] (2) The provider device 300 provides the second biometric information detected in (1) above to the user device 200. The user device 200 acquires the provided second biometric information.

[0062] (3) The user device 200 performs user authentication based on the registered first biometric information and the second biometric information acquired in (2) above. Specifically, the user device 200 compares the first biometric information with the second biometric information. If the result of this comparison shows that the degree of match between the first biometric information and the second biometric information is equal to or greater than a predetermined threshold, the user device 200 determines that the authentication is successful.

[0063] (4) The user device 200 outputs authentication result information indicating the result of the user authentication described above in (3) to the user and the provider (store clerk) on a screen and / or by voice. The user device 200 may also output an electronic certificate certifying the first biometric information used for authentication together with the authentication result information. The user device 200 may also provide the authentication result information to the provider device 300 and / or the server device 100.

[0064] With the above configuration, in the service providing system 1, second biometric information can be obtained from the provider device 300 without the user having to take out the user device 200 and input an operation to a biometric sensor to detect the second biometric information, or without the user device 200 being equipped with a biometric sensor in the first place. Then, biometric authentication can be performed by comparing the second biometric information with the first biometric information (template data) registered in the user storage unit 230 of the user device 200. Furthermore, since there is no need to provide the first biometric information to the provider device 300, information security for biometric information can be improved.

[0065] With the above configuration, the service providing system 1 can perform user authentication without communicating with the server device 100 connected via the first network N1. This prevents situations where user authentication does not proceed due to communication failure or slow communication speeds, even in an environment where communication with a wide area communication network such as the Internet is difficult. This improves the user experience when receiving services, etc. Furthermore, because user authentication is processed on the edge side, user authentication is not concentrated in one place on the server device 100, reducing the load and congestion on the server device 100 and improving the response time of user authentication.

[0066] <2-4. Verification in the server device 100> 5, an example will be described in which the authentication function is executed by the server device 100. The processes (1) and (2) in this example are the same as the processes (1) and (2) in 2-2 above, and therefore will not be described here.

[0067] (3) As shown in Fig. 5, the provider device 300 provides the first biometric information and the digital certificate acquired from the user device 200 to the server device 100. The server device 100 acquires the provided first biometric information.

[0068] (4) The provider device 300 provides the second biometric information detected from the user's body to the server device 100. The server device 100 acquires the provided second biometric information. The provider device 300 may provide the second biometric information together with the first biometric information provided in (3) above, or may provide the second biometric information separately.

[0069] (5) The server device 100 verifies the digital certificate acquired in (3) above. If the server device 100 determines that the digital certificate is valid as a result of the verification, it performs user authentication based on the first biometric information and the second biometric information. Specifically, the server device 100 compares the first biometric information with the second biometric information, and if the degree of match between the first biometric information and the second biometric information is equal to or greater than a predetermined threshold, it determines that the authentication is successful.

[0070] (6) The server device 100 provides authentication result information indicating the result of the user authentication in (5) above to the provider device 300. The provider device 300 acquires the provided authentication result information.

[0071] (7) The provider device 300 outputs the authentication result information described in (6) above to the user and the provider (store clerk) by displaying it on a screen and / or by voice. The provider device 300 may provide the authentication result information to the user device 200.

[0072] With the above configuration, the service providing system 1 can change the authentication device according to the user's settings. This allows the user authentication process to be distributed to the server device 100, the user device 200, or the provider device 300. This avoids the user authentication process being concentrated in one location, the server device 100, thereby reducing the load and congestion on the server device 100 and improving the response time of the user authentication. Furthermore, since the user device 200 does not need to detect the user's biometric information when performing user authentication, the user device 200 does not need to take out the user device 200 and input the biometric information. Furthermore, since the user device 200 does not need to be equipped with a biometric sensor for detection, the user's experience (UX) when receiving the provision of services, etc., can be improved. This improves the response time and the user's experience when receiving user authentication when providing services, etc.

[0073] <3. Functional configuration> The functional configuration of each device according to this embodiment will be described with reference to FIGS.

[0074] <3-1. Server equipment> 6, the functional configuration of the server device 100 will be described. The server device 100 includes a server control unit 110, a server communication unit 120, and a server storage unit .

[0075] The server control unit 110 may include a server acquisition unit 111 , a generation unit 112 , a server authentication unit 113 , a server verification unit 114 , and / or a server provision unit 115 .

[0076] The server acquisition unit 111 acquires various types of information from the user device 200, the provider device 300, and / or other external devices. The server acquisition unit 111 may acquire various types of information in any manner, and may, for example, receive a data file or a message indicating biometric information from the user device 200 in an event-driven or periodic manner.

[0077] The server acquisition unit 111 may acquire, for example, from the user device 200, an information registration request including the user's biometric information or user information, and / or an information provision request (including an update request) from the user device 200. The server acquisition unit 111 may also acquire, for example, from the user device 200, a registration request for authentication settings. The server acquisition unit 111 may also acquire, for example, first biometric information and certification information, as well as second biometric information, from the provider device 300 for user authentication, etc. The server acquisition unit 111 may also acquire, for example, authentication result information from the user device 200 and / or the provider device 300.

[0078] The generation unit 112 may generate first biometric information for user authentication based on biometric information transmitted from the user device 200, for example. The generation unit 112 may perform preprocessing on the transmitted biometric information, such as removing information related to unnecessary environmental factors and normalizing spatial position, size, temporal changes, etc. Feature information may be extracted from the preprocessed biometric information, and the extracted feature information may be used as the first biometric information.

[0079] The generation unit 112 may generate the certification information based on, for example, the first biometric information. When the certification information is, for example, a digital certificate, the generation unit 112 may generate the certification information by issuing the digital certificate itself or by requesting a system such as a certification authority to issue the digital certificate. In the latter case, the generation unit 112 may obtain a digital certificate from the system such as a certification authority in response to the issuance request, and use the obtained digital certificate as the certification information.

[0080] The server authentication unit 113 performs user authentication based on the first biometric information and the second biometric information. Specifically, the server authentication unit 113 may perform user authentication when the setting of the authentication device in the setting information indicates the server device 100.

[0081] The server authentication unit 113 compares the first biometric information with the second biometric information. If the degree of match between the first biometric information and the second biometric information is equal to or greater than a predetermined threshold, the server authentication unit 113 may determine that the user receiving the service or the like is the pre-registered user and that the authentication has been successful. On the other hand, if the degree of match between the first biometric information and the second biometric information is less than the predetermined threshold, the server authentication unit 113 may determine that the authentication has been unsuccessful.

[0082] The server authentication unit 113 may perform user authentication, for example, depending on the result of verification by the server verification unit 114. If the verification by the server authentication unit 113 determines that the certification information is invalid, user authentication may not be performed. In this way, if user authentication is not performed, the server authentication unit 113 may notify the user device 200 and / or the provider device 300 of a user authentication error due to the result of this verification (for example, that user authentication cannot be performed because the certification information is invalid). On the other hand, the server authentication unit 113 may perform user authentication if it determines that the certification information is valid.

[0083] The server verification unit 114 verifies the certification information that certifies the user or the first biometric information. The server verification unit 114 may, for example, refer to the expiration date of the certification information and determine whether the expiration date has passed.

[0084] For example, if the certification information is a digital certificate, the server verification unit 114 may send a request to a certification authority (CA) or VA (Validation Authority) system to obtain a digital certificate revocation list (CRL: Certificate Revocation List) or a request to check the validity using OCSP (Online Certificate Status Protocol).The server verification unit 114 may determine whether the digital certificate has been revoked based on the response to these requests.

[0085] For example, if the certification information includes public keys of the user and / or the issuer of the certification information, the server verification unit 114 may verify the certification information using these public keys. For example, if the certification information includes a digital signature of the user or issuer encrypted with a private key paired with the public key of the user or issuer, the server verification unit 114 may decrypt the digital signature with this public key and verify the validity of the digital signature. Furthermore, if the decrypted information is a message digest, the server verification unit 114 may generate a message digest from the first biometric information using the same method, such as the same hash function, as the digital signature, and verify whether the decrypted message digest matches the generated message digest.

[0086] The server providing unit 115 provides various types of information to the user device 200, the provider device 300, and / or other devices. The server providing unit 115 may provide various types of information in any manner, for example, by sending a data file or message indicating the first biometric information and / or the certification information to these devices in an event-driven manner. As another example, the server providing unit 115 may cause the user device 200, the provider device 300, etc. to refer to such data via an API or SDK library implemented by the server providing unit 115 itself.

[0087] For example, server providing unit 115 may provide user device 200 with the user's first biometric information and certification information that certifies the user and / or the first biometric information, in response to an information registration request or based on an information provision request (including an update request) from user device 200. When providing this information, if the certification information is an electronic certificate or the like that includes the user's public key, server providing unit 115 may transmit the first biometric information (or a message digest of the first biometric information) encrypted with a private key that pairs with the public key.

[0088] For example, when user authentication is performed by the provider device 300, the server providing unit 115 may provide part or all of the first biometric information and / or the certification information to the provider device 300 instead of the user device 200.

[0089] The server providing unit 115 may provide the payment method information included in the user information to the provider device 300, for example, for payment processing in the provider device 300.

[0090] The server communication unit 120 transmits and receives various information and / or various requests to and from the user device 200 and / or the provider device 300, etc. via the first network N1.

[0091] For example, the server storage unit 130 may store the first biometric information, the certification information, and the setting information in association with each other for each user. The server storage unit 130 may store the user information in association with the above information for each user. Furthermore, the server storage unit 130 may store the authentication result information acquired from each device in chronological order as authentication history information for each user in association with the above information.

[0092] <3-2.User device> 7, a functional configuration of the user device 200 will be described. As shown in FIG. 7, the user device 200 includes a user control unit 210, a user communication unit 220, and a user storage unit 230.

[0093] The user control unit 210 may include a user acquisition unit 211 , a user authentication unit 212 , a user verification unit 213 , a user provision unit 214 , and / or a user output unit 215 .

[0094] The user acquisition unit 211 acquires various information and / or various requests from a user, the server device 100, the provider device 300, and / or other external devices. Similar to the server acquisition unit 111, the user acquisition unit 211 may acquire various information in any manner, such as by receiving a data file indicating the various information.

[0095] The user acquisition unit 211 may include a first biometric acquisition unit 211a. The first biometric acquisition unit 211a acquires first biometric information of the user from an external device such as the server device 100.

[0096] The user acquisition unit 211 may include, for example, a second biometric acquisition unit 211b. When providing a service or the like, if the setting of the device that authenticates the user in the setting information indicates the user device 200, the second biometric acquisition unit 211b acquires second biometric information from the provider device 300.

[0097] The user acquisition unit 211 may include, for example, a setting acquisition unit 211c. The setting acquisition unit 211c acquires setting information indicating the setting of an authentication device that performs user authentication by a user or a provider from an external device such as the server device 100 or the user storage unit 230.

[0098] The user acquisition unit 211 may include, for example, a registration unit 211d. The registration unit 211d registers the first biometric information and / or the certification information of the user in the user storage unit 230. The first biometric information to be registered may be information detected from the user by the device itself, or may be information acquired from an external device such as the server device 100.

[0099] The user authentication unit 212 refers to the user storage unit 230 and performs user authentication based on the first biometric information and the second biometric information. The user authentication unit 212 may perform user authentication, for example, when the authentication device setting in the setting information indicates the user device 200. The user authentication unit 212 may, for example, compare the first biometric information with the second biometric information in the same way as the server authentication unit 113, and determine whether the authentication is successful or unsuccessful based on the result of the comparison.

[0100] According to the above configuration, the user device 200 can perform user authentication using the first biometric information acquired from the external device and the second biometric information acquired from the provider device 300. Therefore, there is no need to perform user authentication on the server side (cloud side), and user authentication can be performed on the edge side when receiving a service or the like.

[0101] The user authentication unit 212 may perform user authentication, for example, depending on the result of verification by the user verification unit 213. Specifically, if the user verification unit 213 determines that the certification information is invalid as a result of the verification, the user authentication unit 212 may not perform user authentication, as with the server authentication unit 113, and may notify the user device 200 of an error regarding user authentication and / or cause the provider output unit 316 to output an error on a screen or the like. On the other hand, the user authentication unit 212 may perform user authentication if it determines that the certification information is valid.

[0102] According to the above configuration, the authenticity of the user or the first biometric information is ensured by the certification information that certifies the user or the first biometric information, and then the user authentication can be performed. This improves information security in the user authentication, and also prevents the execution of a potentially useless user authentication process when the certification information is invalid.

[0103] The user verification unit 213 verifies the certification information that certifies the user or the first biometric information. For example, similar to the server verification unit 114, the user verification unit 213 may determine whether the certification information is valid, including whether the certification information is within its expiration date.

[0104] For example, if the user verification unit 213 determines that the certification information is invalid, it may send an acquisition request (certification information update request) to the source of the certification information (e.g., server device 100, etc.) to acquire the latest certification information.

[0105] The user providing unit 214 provides various types of information to the server device 100, the provider device 300, and / or other external devices. Similar to the server providing unit 115, the user providing unit 214 may provide the various types of information in any manner, such as by transmitting a data file indicating the various types of information. For example, the user providing unit 214 may provide authentication result information indicating the result of user authentication by the user authentication unit 212 to the server device 100 and / or the provider device 300.

[0106] The user providing unit 214 provides the first biometric information and / or the certification information to the provider device 300. For example, when the setting of the authentication device in the setting information indicates the provider device 300, the user providing unit 214 may provide the first biometric information, etc. to the provider device 300. Furthermore, the user providing unit 214 may provide, for example, authentication result information indicating the result of user authentication by the user authentication unit 212 to the provider device 300. With this configuration, the result of user authentication performed by the user device 200 can be shared with the provider device 300. The provider device 300 can execute processing for providing subsequent services, etc., based on this shared authentication result.

[0107] The user output unit 215 serves as an authentication service UI and outputs various information on a screen and / or by voice. The user output unit 215 may output, for example, the result of user authentication and / or notified errors on a dashboard or the like.

[0108] The user communication unit 220 transmits and receives various information and / or various requests to and from the server device 100 and / or the provider device 300, etc. via the first network N1 and / or the second network N2.

[0109] For example, the user storage unit 230 may store the first biometric information, the certification information, and the setting information in association with each other. Furthermore, the area in the user storage unit 230 that stores this information may be set to a higher security level than a normal storage area.

[0110] <3-3. Provider device> 8, the functional configuration of the provider device 300 will be described. As shown in Fig. 8, the provider device 300 includes a provider control unit 310, a provider communication unit 320, a provider storage unit 330, and a first detection unit 340. The detection unit included in the provider device 300 may be the first detection unit 340 alone, or may be configured with the first detection unit 340 and a second detection unit 311, which will be described later.

[0111] The provider control unit 310 may include, for example, a second detection unit 311, a provider acquisition unit 312, a provider authentication unit 313, a provider verification unit 314, a provider providing unit 315, and / or a provider output unit 316.

[0112] The second detection unit 311 generates second biometric information from the biometric information detected by the first detection unit 340, for example. The second detection unit 311 performs preprocessing on the detected biometric information, for example, by removing information related to unnecessary environmental factors and normalizing spatial position, size, temporal changes, etc. Feature information may be extracted from the preprocessed biometric information, and the extracted feature information may be used as the second biometric information.

[0113] The provider acquisition unit 312 acquires various information and / or various requests from the provider, the server device 100, the user device 200, and / or other external devices. Similar to the server acquisition unit 111, the provider acquisition unit 312 may acquire various information in any manner, such as by receiving a data file indicating the various information. The provider acquisition unit 312 may acquire the first biometric information and certification information from the user device 200 (or the server device 100), for example.

[0114] The provider authentication unit 313 performs user authentication based on the first biometric information and the second biometric information. For example, the provider authentication unit 313 may perform user authentication when the setting of the authentication device in the setting information indicates the provider device 300. Similar to the server authentication unit 113, the provider authentication unit 313 may compare the first biometric information with the second biometric information and determine whether the authentication is successful or unsuccessful based on the result of the comparison.

[0115] The provider authentication unit 313 may perform user authentication, for example, depending on the result of verification by the provider verification unit 314. Specifically, if the provider verification unit 314 determines that the certification information is invalid as a result of verification, the provider authentication unit 313 may not perform user authentication, as with the server device 100, and may notify the user device 200 of an error regarding user authentication and / or cause the provider output unit 316 to output an error on a screen or the like.

[0116] According to the above configuration, the authenticity of the user or the first biometric information is ensured by the certification information that certifies the user or the first biometric information, and then the user authentication can be performed. This improves information security in the user authentication, and also prevents the execution of a potentially useless user authentication process when the certification information is invalid.

[0117] The provider verification unit 314 verifies this certification information. For example, similar to the server verification unit 114, the provider verification unit 314 may determine whether the certification information is valid, including whether the certification information is within its expiration date.

[0118] For example, if the provider verification unit 314 determines that the certification information is invalid, it may send an acquisition request (a request to update the certification information) to the provider of the certification information (for example, the user device 200 or the server device 100, etc.) to obtain the latest certification information.

[0119] The provider providing unit 315 provides various types of information to the server device 100, the user device 200, and / or other external devices. Similar to the server providing unit 115, the provider providing unit 315 may provide the various types of information in any manner, such as by transmitting a data file indicating the various types of information. For example, the provider providing unit 315 may provide authentication result information indicating the result of user authentication by the provider authentication unit 313 to the server device 100 and / or the user device 200.

[0120] The provider output unit 316 serves as an authentication service UI and outputs various types of information to the provider on a screen and / or by voice. The provider output unit 316 outputs, for example, authentication result information indicating the result of user authentication by the provider authentication unit 313. The provider output unit 316 may also output, for example, notified errors on a dashboard or the like.

[0121] The provider control unit 310 may have a function for providing services other than those described above. The provider control unit 310 may execute a process for settling the payment for a service (also referred to as "payment process") based on a payment request from a provider. Based on payment method information acquired from the server device 100, the provider control unit 310 may perform the payment process using a payment method such as card payment, such as credit card payment or debit card payment, code payment using a QR code (registered trademark), electronic money payment, mobile payment using NFC, or bank transfer payment.

[0122] According to the above configuration, the provider device 300 can perform user authentication based on the first biometric information acquired from the user device 200 and the second biometric information detected from the user. Therefore, there is no need to perform user authentication on the server side (cloud side), and user authentication can be performed on the edge side when receiving the provision of a service, etc. Furthermore, the result of this user authentication can be output to allow the user or provider to understand the result. For example, the user or provider can determine whether or not to provide the service, etc. or confirm the user's membership status depending on the result of this authentication. Therefore, it is possible to improve the response and user experience in user authentication when providing a service, etc.

[0123] The provider communication unit 320 transmits and receives various information and / or various requests to and from the server device 100 and / or the user device 200, etc., via the first network N1 and / or the second network N2.

[0124] The provider storage unit 330 stores, for example, the second biometric information detected from the user. The provider storage unit 330 may also delete the stored second biometric information when a predetermined period has elapsed since the time of detection or registration. The provider storage unit 330 may also delete, for example, the first biometric information and / or the certification information acquired from the user device 200 when a predetermined period has elapsed since the time of acquisition, or at a preset timing (for example, the expiration date of the certification information, etc.).

[0125] The first detection unit 340 serves as a biometric sensor and detects biometric information from the body or behavior of the user. This detected biometric information may be used as the second biometric information, or biometric information that has been subjected to preprocessing or feature extraction by the second detection unit 311 may be used as the second biometric information.

[0126] <5. Example of operation> An example of the operation of the service providing system 1 will be described with reference to Figures 9 to 12. Figures 9 to 12 are sequence diagrams showing an example of the processing flow and interactions between devices when paying and settling fees for services, etc. in the service providing system 1. Note that the order of processing and processing units shown in Figures 9 to 12 are merely examples and may be changed as appropriate.

[0127] 9, the provider device 300 receives a payment request (including an authentication request for user authentication and setting information) for payment of a fee for a service or the like from the provider (S10). The provider device 300 detects second biometric information from the user (S11). The provider device 300 refers to the setting information and determines which device the authentication device setting indicates (S12).

[0128] When the authentication device settings indicate the provider device 300, each device in the service providing system 1 executes processing within the upper area of ​​the area indicated by the combined fragment alt1 (alternative1). As shown by combined fragment ref1 (Reference1), this processing will be explained using Figure 10. Also, when the authentication device settings indicate the user device 200, each device in the service providing system 1 executes processing within the middle area of ​​the area indicated by the combined fragment alt1. As shown by combined fragment ref2, this processing will be explained using Figure 11. Also, when the authentication device settings indicate the user device 200, each device in the service providing system 1 executes processing within the lower area of ​​the area indicated by the combined fragment alt1. As shown by combined fragment ref3, this processing will be explained using Figure 12.

[0129] <5-1. Authentication by the provider device 300> 10, the provider device 300 transmits a request for providing the first biometric information and the certification information to the user device 200 (S20). In response to this request, the user device 200 transmits (provides) the first biometric information and the certification information to the provider device 300 (S21).

[0130] The provider device 300 acquires the transmitted first biometric information and certification information (S22), and verifies the acquired certification information (S23).

[0131] If the verification results in the authentication information being valid, each device in the service providing system 1 executes the process in the upper area of ​​the area indicated by the combined fragment alt2 (alternative2). Specifically, the provider device 300 performs biometric authentication of the user based on the first biometric information and the second biometric information (S24).

[0132] If the biometric authentication is successful, each device in the service providing system 1 executes processing within the upper area of ​​the area indicated by the combined fragment alt3 (alternative3). Specifically, the provider device 300 outputs a message to the provider indicating that authentication was successful (S25). The provider device 300 executes payment processing for the payment of the fee for the service, etc., based on the payment request (S26).

[0133] If the biometric authentication fails, each device in the service providing system 1 executes the process in the lower area of ​​the area indicated by the combined fragment alt3. Specifically, the provider device 300 outputs a message to the provider that authentication has failed (S27).

[0134] If the verification results in the certification information being invalid, each device in the service providing system 1 executes the process in the lower area of ​​the area indicated by the combined fragment alt2. Specifically, the provider device 300 outputs a message indicating that the certification information has expired (S28).

[0135] <5-2. Authentication on the user device 200> 11, the provider device 300 transmits the detected second biometric information to the user device 200 (S30). The user device 200 acquires the second biometric information from the provider device 300 (S31). The user device 200 performs biometric authentication of the user based on the first biometric information registered in the user storage unit 230 and the acquired second biometric information (S32).

[0136] If the biometric authentication is successful, each device in the service providing system 1 executes processing within the upper area of ​​the area indicated by the combined fragment alt4 (alternative4). Specifically, the user device 200 outputs a message to the user indicating that authentication was successful (S33). The user device 200 transmits authentication result information indicating that authentication was successful to the provider device 300 (S34). The provider device 300 acquires the transmitted authentication result information from the user device 200 (S35). Based on the authentication result information, the provider device 300 outputs a message to the provider indicating that authentication was successful (S36). Based on the payment request, the provider device 300 executes payment processing for the fee for the service, etc. (S26).

[0137] If the biometric authentication results in a failure, each device in the service providing system 1 executes processing within the lower area of ​​the area indicated by the combined fragment alt4. Specifically, the user device 200 outputs a message to the user indicating that the authentication has failed (S38). The user device 200 transmits authentication result information indicating that the authentication has failed to the provider device 300 (S39). The provider device 300 acquires the transmitted authentication result information from the user device 200 (S40). Based on the authentication result information, the provider device 300 outputs a message to the provider indicating that the authentication has failed (S41).

[0138] <5-3. Authentication in the server device 100> 12, the provider device 300 transmits a request for providing the first biometric information and the certification information to the user device 200 (S50). In response to this request, the user device 200 transmits the first biometric information and the certification information to the provider device 300 (S51).

[0139] The provider device 300 acquires the transmitted first biometric information and certification information (S52). The provider device 300 transmits the acquired first biometric information and certification information, as well as the detected second biometric information, to the server device 100 (S53).

[0140] The server device 100 acquires the transmitted first biometric information, second biometric information, and certification information (S54), and verifies the acquired certification information (S55).

[0141] If the verification results in the certification information being valid, each device in the service providing system 1 executes processing within the upper area of ​​the area indicated by the combined fragment alt5 (alternative5). Specifically, the server device 100 performs biometric authentication of the user based on the first biometric information and the second biometric information (S56). The server device 100 transmits authentication result information indicating the result of the biometric authentication to the provider device 300 (S57). The provider device 300 acquires the transmitted authentication result information (S58).

[0142] If the biometric authentication is successful, each device in the service providing system 1 executes processing within the upper area of ​​the area indicated by the combined fragment alt6 (alternative6). Specifically, the provider device 300 outputs a message indicating successful authentication to the provider (S59). Based on the payment request, the provider device 300 executes payment processing for the fee for the service (S60).

[0143] If the biometric authentication fails, each device in the service providing system 1 executes the process in the lower area of ​​the area indicated by the combined fragment alt6. Specifically, the provider device 300 outputs a message to the provider that authentication has failed (S61).

[0144] If the verification results in the certification information being invalid, each device in the service providing system 1 executes processing within the lower area of ​​the area indicated by the combined fragment alt5. Specifically, the provider device 300 transmits (notifies) error information indicating that the certification information has expired to the provider device 300 (S62). The provider device 300 outputs to the provider that the certification information has expired (S63).

[0145] <5. Hardware Configuration> 13, an example of a hardware configuration in which the above-described server device 100, user device 200, and provider device 300 are realized by a computer 800 will be described. Note that the functions of each device can also be realized by dividing them into multiple devices.

[0146] 13, the computer 800 includes a processor 801, a memory 803, a storage device 805, an input I / F unit 807, a data I / F unit 809, a communication I / F unit 811, and a display device 813. For example, in the case of the provider device 300, the computer 800 may include a sensor device (not shown) that detects biometric information from the user.

[0147] The processor 801 controls various processes in the computer 800 by executing programs stored in the memory 803. For example, the respective functional units and the like provided in the control units of the server device 100, the user device 200, and the provider device 300 can be realized by the processor 801 executing the programs temporarily stored in the memory 803.

[0148] The memory 803 is a storage medium such as a RAM (Random Access Memory), etc. The memory 803 temporarily stores the program code of the program executed by the processor 801 and data required when the program is executed.

[0149] The storage device 805 is a non-volatile storage medium such as a hard disk drive (HDD) or flash memory. The storage device 805 stores an operating system and various programs for implementing the above-mentioned configurations. In addition, the storage device 805 can also store tables for registering various types of information such as biometric information, authentication information, and / or setting information, and a DB for managing the tables. Such programs and data are loaded into the memory 803 as needed and can be referenced by the processor 801.

[0150] The input I / F unit 807 is a device for receiving input from a user. Specific examples of the input I / F unit 807 include a keyboard, a mouse, a touch panel, various sensors, and a wearable device. The input I / F unit 807 may be connected to the computer 800 via an interface such as a USB (Universal Serial Bus).

[0151] The data I / F unit 809 is a device for inputting data from outside the computer 800. A specific example of the data I / F unit 809 is a drive device for reading data stored in various storage media. The data I / F unit 809 may be provided outside the computer 800. In this case, the data I / F unit 809 is connected to the computer 800 via an interface such as a USB.

[0152] The communication I / F unit 811 is a device for performing data communication via the Internet N, either wired or wirelessly, with devices external to the computer 800. The communication I / F unit 811 may be provided outside the computer 800. In this case, the communication I / F unit 811 is connected to the computer 800 via an interface such as a USB.

[0153] The display device 813 is a device for displaying various types of information. Specific examples of the display device 813 include a liquid crystal display, an organic EL (Electro-Luminescence) display, and a display of a wearable device. The display device 813 may be provided outside the computer 800. In this case, the display device 813 is connected to the computer 800 via, for example, a display cable. Furthermore, when a touch panel is adopted as the input I / F unit 807, the display device 813 can be configured as an integral part of the input I / F unit 807.

[0154] It should be noted that the present embodiment is an example for explaining the present invention, and is not intended to limit the present invention to only this embodiment. Furthermore, the present invention can be modified in various ways without departing from the gist of the present invention. Furthermore, those skilled in the art can adopt embodiments in which the elements described below are replaced with equivalents, and such embodiments are also within the scope of the present invention.

[0155] The components of the server device described in the above embodiment are assumed to be implemented in cooperation with other hardware by the processor 801 executing a program stored in the storage device 805. In other words, these components can be considered as software or firmware, or as corresponding hardware, and in both of these concepts, they can also be described as "functions," "means," "parts," "processing circuits," "units," or "modules," and can be interpreted as such.

[0156] [Variations] Although the present invention has been described based on the above embodiment, the following cases are also included in the present invention.

[0157] [Variation 1] At least a part of the components of the server device 100 according to the above embodiment may be provided in the user device 200, the provider device 300, and / or other devices. Also, at least a part of the components of the user device 200 may be provided in the server device 100, the provider device 300, and / or other devices.

[0158] [Variation 2] In the above embodiment, the storage units for storing biometric information, certification information, etc. are the storage units of the server device 100, the user device 200, and / or the provider device 300, but the present invention is not limited to this. For example, at least some of these storage units may be provided in other devices of the service providing system 1 and / or devices of an external system such as cloud storage. [Explanation of symbols]

[0159] 1...service providing system, 100...server device, 110...control unit, 111...server acquisition unit, 112...generation unit, 113...server authentication unit, 114...server verification unit, 115...server providing unit, 120...server communication unit, 130...server memory unit, 200...user device, 210...user control unit, 220...user communication unit, 230...user memory unit, 300...provider device, 310...provider control unit, 311...second detection unit, 312...provider acquisition unit, 313...provider authentication unit, 314...provider verification unit, 315...provider providing unit, 316...provider output unit, 800...computer, 801...processor, 803...memory, 805...storage device, 807...input I / F unit, 809...data I / F unit, 811...communication I / F unit, 813...display device.

Claims

1. a provider device of a provider that provides services and / or products to users; a user device of the user; The user device a first biometric acquisition unit that acquires first biometric information relating to a biometric of the user from an external device; a user providing unit that provides the first biometric information to the provider device, the provider device, a provider acquisition unit that acquires the provided first biometric information from the user device; a detection unit that detects second biometric information from the user when the service and / or product is provided; a provider authentication unit that authenticates the user based on the first biometric information and the second biometric information; a provider output unit that outputs authentication result information indicating the result of the authentication. system.

2. the user providing unit further provides certification information that certifies the user and / or the first biometric information to the provider device; the provider device further includes a provider verification unit that verifies the certification information; the provider authentication unit performs the authentication depending on the result of the verification. The system of claim 1 .

3. The user device a setting acquisition unit that acquires setting information indicating a setting of a device that performs authentication of the user by the user or the provider; a second biometric acquisition unit that acquires the second biometric information from the provider device when the setting in the setting information indicates the user device; a user authentication unit that authenticates the user based on the first biometric information and the second biometric information; 3. The system according to claim 1 or 2.

4. a registration unit that registers first biometric information relating to the biometrics of a user who receives a service or product in a user storage unit; a second biometric acquisition unit that acquires, from a provider device of a provider that provides the service or the product to the user, second biometric information detected from the body of the user at the time of the provision; a user authentication unit that refers to the user storage unit and authenticates the user based on the first biometric information and the second biometric information; a user providing unit that provides authentication result information indicating a result of the authentication to the provider device, Information processing device.

5. the first biometric information includes certification information that certifies the user or the first biometric information, further comprising a verification unit that verifies the certification information; the user authentication unit authenticates the user according to the result of the verification. The information processing device according to claim 4 .

6. a setting acquisition unit that acquires setting information indicating a setting of a device that performs authentication of the user by the user or the provider; a providing unit that provides the first biological information to the provider device when the setting in the setting information indicates the provider device, 6. The information processing device according to claim 4.

7. To the user device of the user who receives the service and / or product, a first biometric acquisition function for acquiring first biometric information relating to the biometrics of the user from an external device; a user providing function of providing the first biometric information to the provider device, A provider device of a provider that provides the service and / or the product to the user. a provider acquisition function for acquiring the provided first biometric information from the user device; a detection function for detecting second biometric information from the user when the service and / or product is provided; a provider authentication function that authenticates the user based on the first biometric information and the second biometric information; a provider output function for outputting authentication result information indicating the result of the authentication; program.

8. A user device of a user who receives services and / or products, acquiring first biometric information relating to a biometric information of the user from an external device; providing the first biometric information to the donor device; a provider device of a provider that provides the service and / or the product to the user, acquiring the provided first biometric information from the user device; detecting second biometric information from the user when providing the service and / or product; authenticating the user based on the first biometric information and the second biometric information; outputting authentication result information indicating the result of the authentication; Information processing methods.

9. On the computer, a registration function of registering first biometric information relating to a biometric of the user in a user storage unit; a second biometric acquisition function that acquires, from a provider device of a provider that provides a service or product to a user, second biometric information detected from the body of the user when the service or product is provided; a user authentication function that refers to the user storage unit and authenticates the user based on the first biometric information and the second biometric information; a user providing function of providing authentication result information indicating the result of the authentication to the provider device; program.

10. The computer registering first biometric information relating to the biometric information of the user in a user storage unit; acquiring, from a provider device of a provider that provides a service or product to a user, second biometric information detected from the body of the user at the time of the provision; referring to the user storage unit, and authenticating the user based on the first biometric information and the second biometric information; providing authentication result information indicating a result of the authentication to the provider device; Information processing methods.

Citation Information

Patent Citations

  • Information processing device, information processing method, and information processing program

    JP2023159512A

  • Payment system

    JP2023170890A