Biometric authentication terminal, biometric authentication system, and biometric authentication method
The biometric authentication system improves speed by parallel processing of template narrowing across multiple terminals, addressing load concentration and network failures in conventional systems.
Patent Information
- Application Number
- JP2024072883
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-26
- Publication Date
- 2025-11-07
AI Technical Summary
Biometric authentication systems face decreased speed due to a concentrated load on the management server handling template narrowing and distribution requests from multiple terminals, leading to potential network failures and unavailability during authentication.
Implementing a biometric authentication terminal that performs parallel template narrowing processes with other terminals, distributing the load and utilizing template history data to improve authentication speed.
The system enhances authentication speed by reducing the burden on the management server and minimizing network failure impacts, ensuring consistent and efficient user verification.
Smart Images

Figure 2025167887000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a biometric authentication terminal, a biometric authentication system, and a biometric authentication method. [Background technology]
[0002] There is a conventional technology (Patent Document 1) that efficiently performs biometric authentication using the 1:N authentication method. Patent Document 1 discloses a cache control device that reduces the number of registered users included in a cache set and improves cache efficiency by including only registered users who have a high probability of successful authentication in the cache set. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] International Publication No. 2023 / 242951 Summary of the Invention [Problem to be solved by the invention]
[0004] Biometric authentication systems (biometric authentication infrastructure) such as BSS (Biometric Signature Server) have been introduced that achieve biometric authentication without storing the biometric information itself or the private key anywhere. In such biometric authentication systems, the biometric information itself is not stored on the authentication server, but the user is required to register a biometric template, which is an encrypted version of authentication information (information required for authentication) that can be restored using biometric information, on a management server.
[0005] In a biometric authentication system, when authenticating a user to be authenticated using a biometric authentication terminal, a management server narrows down the biometric templates, distributes the narrowed down multiple biometric templates to the biometric authentication terminal, and the biometric authentication terminal performs authentication using the narrowed down multiple biometric templates. In such a biometric authentication system, the management server single-handedly handles requests to narrow down the biometric templates and requests to download the narrowed down multiple biometric templates from a large number of terminals, which may result in a decrease in response due to a concentrated load, periods when authentication is unavailable due to network failures, etc., and thus the speed of biometric authentication may decrease.
[0006] Note that Patent Document 1 does not describe selecting a terminal that is effective for narrowing down the biometric templates from a plurality of terminals and narrowing down the biometric templates in parallel in order to reduce the load on the management server.
[0007] The present invention has been made to solve the above-mentioned problems. That is, one of the objects of the present invention is to provide a biometric authentication terminal, a biometric authentication system, and a biometric authentication method that can improve the speed of biometric authentication. [Means for solving the problem]
[0008] In order to solve the above problems, a biometric authentication terminal of the present invention is a biometric authentication terminal including a calculation unit and a storage device, wherein the storage device stores template history data including a plurality of template history information related to a plurality of biometric templates that have been successfully authenticated, the calculation unit acquires biometric authentication information of a user to be authenticated, requests another biometric authentication terminal to narrow down biometric template candidates corresponding to the user to be authenticated from the template history data, executes a first template narrowing-down process to narrow down the biometric template candidates corresponding to the user to be authenticated from the template history data, causes the other biometric authentication terminal that has been requested to execute a second template narrowing-down process in parallel with the first template narrowing-down process to narrow down the biometric template candidates corresponding to the user to be authenticated from template history data including a plurality of template history information related to biometric templates that have been successfully authenticated by the other biometric authentication terminal, and authenticates the user by comparing the biometric template candidates narrowed down by the first template narrowing-down process and the second template narrowing-down process with the biometric authentication information of the user.
[0009] A biometric authentication system of the present invention includes a plurality of biometric authentication terminals and an authentication information management server, each of which holds template history data including a plurality of template history information related to a plurality of successfully authenticated biometric templates. A local biometric authentication terminal that authenticates a user to be authenticated acquires the biometric authentication information of the user to be authenticated and requests another biometric authentication terminal, a biometric authentication terminal other than the local biometric authentication terminal, to narrow down biometric template candidates corresponding to the user to be authenticated. The local biometric authentication terminal executes a first template narrowing-down process to narrow down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the local biometric authentication terminal. Upon receiving the request, the other biometric authentication terminal executes a second template narrowing-down process to narrow down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the other biometric authentication terminal in parallel with the first template narrowing-down process. The local biometric authentication terminal authenticates the user by comparing the biometric template candidates narrowed down by the first template narrowing-down process and the second template narrowing-down process with the user's biometric authentication information.
[0010] a first template narrowing-down process for narrowing down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the first biometric authentication terminal; a second template narrowing-down process for narrowing down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the second biometric authentication terminal, in parallel with the first template narrowing-down process; and a comparison between the biometric template candidates narrowed down by the first template narrowing-down process and the second template narrowing-down process and the user's biometric authentication information. [Effects of the Invention]
[0011] According to the present invention, it is possible to improve the speed of biometric authentication. Note that the effects described herein are not necessarily limited to those described herein, and may be any of the effects described in this disclosure. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of a biometric authentication system according to a first embodiment of the present invention. [Figure 2] FIG. 2 is a diagram showing an example of the hardware configuration of a terminal applied to a service terminal. [Figure 3] FIG. 3 is a diagram showing an example of the hardware configuration of a computer applied to an information processing device included in a terminal. [Figure 4]FIG. 4 is a diagram for explaining the template history. [Figure 5] FIG. 5 is a diagram for explaining in-area terminal information. [Figure 6] FIG. 6 is a diagram for explaining the active template table. [Figure 7] FIG. 7 is a diagram for explaining the terminal setting table. [Figure 8] FIG. 8 is a diagram for explaining the biometric template table. [Figure 9] FIG. 9 is a diagram for explaining the template usage history. [Figure 10] FIG. 10 is a diagram for explaining inter-terminal co-occurrence information. [Figure 11] FIG. 11 is a diagram for explaining the inter-service co-occurrence information. [Figure 12] FIG. 12 is a flowchart showing a processing flow executed by the authentication information management server. [Figure 13] FIG. 13 is a flowchart showing the processing flow executed by the service terminal. [Figure 14] FIG. 14 is a flowchart showing the processing flow executed by the requested service terminal. [Figure 15] FIG. 15 is a flowchart showing the processing flow executed by the service terminal. [Figure 16] FIG. 16 is a flowchart showing the processing flow executed by the service terminal. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, each embodiment of the present invention will be described with reference to the drawings. In all the drawings of the embodiments, the same or corresponding parts may be denoted by the same reference numerals.
[0014] In the following description, various types of information may be described using expressions such as "table," but the various types of information may also be expressed using other data structures. When describing identification information, expressions such as "identification number," "name," and "ID" are used, but these are interchangeable and other expressions may also be used. Processing may be described using a functional block as the subject, but the subject of the processing may be a CPU or device instead of a functional block.
[0015] The processing performed by executing the program may be performed by a computing unit (computing device), which may include a dedicated circuit for performing specific processing. Here, the dedicated circuit may be, for example, a Field Programmable Gate Array (FPGA), an Application Specific Integrated Circuit (ASIC), or a Complex Programmable Logic Device (CPLD).
[0016] A program may be installed on a computer from a program source. The program source may be, for example, a program distribution server or a computer-readable storage medium. When the program source is a program distribution server, the program distribution server may include a processor and storage resources for storing the program to be distributed, and the processor of the program distribution server may distribute the program to be distributed to other computers. In addition, in each embodiment, two or more programs may be realized as one program, or one program may be realized as two or more programs.
[0017] <<First Embodiment>> A biometric authentication system according to a first embodiment of the present invention will now be described. Fig. 1 is a diagram showing an example of the configuration of the biometric authentication system according to the first embodiment of the present invention. As shown in Fig. 1, the biometric authentication system according to the first embodiment includes a plurality of service terminals 100 and an authentication information management server 200.
[0018] The plurality of service terminals 100, the authentication information management server 200, and the authentication server 300 are configured to be able to send and receive information (be able to communicate) with each other via the network NW1.
[0019] The service terminal 100 includes a biometric authentication function unit 110, a parallel processing function unit 120, a template narrowing down function unit 130, a template history discarding function unit 140, and a parallel processing undertaking function unit 150. Details of the biometric authentication function unit 110, the parallel processing function unit 120, the template narrowing down function unit 130, the template history discarding function unit 140, and the parallel processing undertaking function unit 150 will be described later. The service terminal 100 may be referred to as a "biometric authentication terminal."
[0020] The service terminal 100 includes, as databases, template history 160, in-area terminal information 170, active template table 180, and per-terminal setting information 190. Details of template history 160, in-area terminal information 170, active template table 180, and per-terminal setting information 190 will be described later.
[0021] Authentication information management server 200 includes a template narrowing down function unit 210, an inter-terminal co-occurrence information creation function unit 220, and an inter-service co-occurrence information creation function unit 230. Details of template narrowing down function unit 210, inter-terminal co-occurrence information creation function unit 220, and inter-service co-occurrence information creation function unit 230 will be described later.
[0022] The authentication information management server 200 includes, as databases, a biometric template table 240, a template usage history 250, inter-terminal co-occurrence information 260, and inter-service co-occurrence information 270. Details of the biometric template table 240, the template usage history 250, the inter-terminal co-occurrence information 260, and the inter-service co-occurrence information 270 will be described later.
[0023] The authentication information management server 200 stores and manages biometric templates corresponding to multiple users used for user authentication in a biometric template table 240. The biometric template is information generated by one-way converting biometric authentication information into which authentication information (private key) is embedded so that the biometric authentication information can be used like a private key, and the authentication information (private key) can be restored using the biometric authentication information, but the biometric authentication information cannot be restored to its original state. Such a biometric template is sometimes referred to as a PBI (Public Biometrics Infrastructure) template.
[0024] When authenticating a user to be authenticated, the service terminal 100 acquires biometric information of the user to be authenticated. Note that the biometric information may be information based on biometric information such as features extracted from the biometric information. In this specification, biometric information or information based on biometric information may be referred to as "biometric authentication information."
[0025] The service terminal 100 checks whether the multiple biometric templates match the biometric information of the user to be authenticated (whether they are a correct combination). If there is a biometric template among the multiple biometric templates that matches the biometric information of the user to be authenticated (a correct combination), the service terminal 100 determines that the authentication of the user is successful. If there is no biometric template among the multiple biometric templates that matches the biometric information of the user to be authenticated (a correct combination), the service terminal 100 determines that the authentication of the user is unsuccessful.
[0026] The service terminal 100 checks whether the biometric template matches the biometric information (is a correct combination) as follows: The service terminal 100 restores the user's authentication information from the biometric template using the user's biometric information. At this time, the user's authentication information can be restored only if the user's biometric information and the biometric template are a correct combination.
[0027] In response to an authentication request from the authentication server 300, the service terminal 100 creates a digital signature using the restored authentication information (e.g., a private key) and transmits the signature to the authentication server 300. The authentication server 300 verifies the signature using authentication information (e.g., a public key) that it has previously acquired and stored. If the verification by the authentication server 300 is successful, the service terminal 100 determines that the biometric template and the biometric information of the user to be authenticated match (the combination is correct). If the verification by the authentication server 300 is unsuccessful, the service terminal 100 determines that the biometric template and the biometric information of the user to be authenticated do not match (the combination is not correct).
[0028] In the following explanation, for convenience of explanation, the service terminal 100 that authenticates the user to be authenticated may be referred to as the "own service terminal 100," and service terminals 100 other than the own service terminal 100 may be referred to as "other service terminals 100" or "other service terminals 100."
[0029] Fig. 2 is a diagram showing an example of the hardware configuration of a terminal 2000 applied to the service terminal 100. As shown in Fig. 2, the terminal 2000 includes a biometric information acquisition device 2010, a display 2020, and an information processing device 2030. These are configured to be able to communicate information with each other via a bus (not shown).
[0030] The biometric information acquisition device 2010 is a device for acquiring biometric information of a specific part (e.g., face, palm print, iris, fingerprint, etc.) used for biometric authentication of a person. The biometric information acquisition device 2010 is, for example, a camera, a sensor, etc. There may be one or more biometric information acquisition devices 2010.
[0031] The display 2020 is a display device capable of displaying images. In this example, the display 2020 is a touch panel display that functions as both a display device and an input device (operation device). Note that the terminal 2000 may also include an input device (operation device) separate from the display device.
[0032] 3 is a diagram showing an example of the hardware configuration of a calculator 3000 applied to an information processing device 2030 included in a terminal 2000. The calculator 3000 may be referred to as a "computer." The calculator 3000 includes a CPU 3001, a ROM 3002, a RAM 3003, a non-volatile storage device 3004 that can read and write data, a network interface 3005, and an input / output interface 3006. These are connected to each other via a bus 3007 so as to be able to communicate with each other.
[0033] The CPU 3001 is a computing device that loads various programs (not shown) stored in the ROM 3002 and / or storage device 3004 into the RAM 3003 and executes the programs loaded into the RAM 3003, thereby realizing various functions.
[0034] As described above, the various programs executed by the CPU 3001 are loaded into the RAM 3003, and data used when the CPU 3001 executes the various programs is temporarily stored in the RAM 3003. The ROM 3002 and / or the storage device 3004 are non-volatile storage media, and the ROM 3002 and / or the storage device 3004 store various programs.
[0035] The network interface 3005 is an interface for connecting the computer 3000 to the network NW1. The input / output interface 3006 is an interface for connecting the computer 3000 to an operation device and a display (display device) capable of displaying images.
[0036] Note that a hardware device configured with a field programmable gate array (FPGA) or the like may be used in part or in whole of the computer 3000 instead of the computer 3000. Such a hardware device may also be referred to as a "computing device."
[0037] The memory device 3004 of the information processing device 2030 of the terminal 2000 applied to the service terminal 100 stores (memorizes, holds) the following programs: a biometric authentication function unit 110, a parallel processing function unit 120, a template narrowing down function unit 130, a template history discarding function unit 140, and a parallel processing undertaking function unit 150.
[0038] The biometric authentication function unit 110 uses biometric authentication technology to acquire biometric information of a user to be authenticated by the biometric information acquisition device 2010, and performs biometric authentication using the biometric information. As described above, the biometric information may be information based on biometric information such as feature amounts extracted from the biometric information.
[0039] When authenticating a user to be authenticated, the parallel processing function unit 120 selects another service terminal 100 to narrow down the biometric templates and requests the selected other service terminal 100 to perform parallel processing of narrowing down the biometric templates. The template narrowing function unit 130 uses template narrowing information (e.g., partial information of the biometric templates) that is information for narrowing down biometric templates from the biometric information of the user to be authenticated to narrow down biometric templates (biometric template candidates) corresponding to the user to be authenticated from the biometric templates stored in the template history 160. Note that the template narrowing function unit 130 may use the template narrowing information to narrow down biometric templates (biometric template candidates) corresponding to the user to be authenticated from the active templates stored in the active template table 180.
[0040] The template history discarding function unit 140 discards template history information from the template history 160, and discards active template information from the active template table 180, as necessary. Note that the template history information is information (records) for each row in the template history 160, and the active template information is information (records) for each row in the active template table 180.
[0041] The parallel processing contracting function unit 150 contracts with another service terminal 100 to narrow down the biometric templates, and narrows down the biometric templates. The storage device 3004 of the information processing device 2030 of the terminal 2000 applied to the service terminal 100 stores (memorizes, holds) a template history 160, in-area terminal information 170, an active template table 180, and per-terminal setting information 190 as databases.
[0042] FIG. 4 is a diagram illustrating the template history 160. The template history 160 may be referred to as "template history data." As shown in FIG. 4, the template history 160 includes columns for storing information (values), such as a usage date and time 401, a sender 402, a sender service classification 403, a template ID 404, and an encrypted template 405. In the template history 160, information corresponding to each column relating to the history of biometric templates of the own service terminal 100 (the history of biometric templates for which authentication has been successful) is associated with each other and stored as row-by-row information (records). This row-by-row information (records) is referred to as "template history information."
[0043] Specifically, the date and time of use 401 stores the date and time when the biometric template was used. The sender 402 stores the name of the service terminal 100 or the authorization server (authentication information management server 200) that sent the biometric template. The sender service classification 403 stores the name of the service that the sender service terminal 100 is using. The template ID 404 stores the identification number of the biometric template (the user corresponding to the biometric template). The value (information) stored in the template ID 404 may be referred to as a "template ID" or a "user ID". The encrypted template 405 stores the biometric template.
[0044] In the template history 160, for example, the template history information (record) in the first row indicates that a biometric template with template ID 0101 received from the authentication information management server 200 was successfully authenticated on the service terminal 100 at the usage date and time of "24 / 3 / 3 08:06:04". The template history information (record) in the second row indicates that a biometric template with template ID 2002 received from a service terminal 100 with terminal name T28F used in a restaurant was successfully authenticated on the service terminal 100 at the usage date and time of "24 / 3 / 3 11:26:50". Note that this template history information (record) in the second row is template history information (record) when authentication was successful using the active template in the second row of the active template table 180 held by the service terminal 100. The information (record) on the third line indicates that the biometric template with template ID 0033 held by the service terminal 100 (own terminal) with terminal name: T01A used by the apparel company was successfully authenticated by the own service terminal 100 at the usage date and time "24 / 3 / 3 11:58:12".
[0045] Fig. 5 is a diagram for explaining in-area terminal information 170. As shown in Fig. 5, in-area terminal information 170 includes, as columns for storing information (values), terminal name 501, service classification 502, request response 503, template authentication speed 504, template narrowing-down capability 505, and communication speed 506. In in-area terminal information 170, information corresponding to each column relating to service terminals 100 present in a predetermined area including its own service terminal 100 is associated with each other and stored as row-by-row information (records).
[0046] Specifically, the terminal name 501 stores the name of the service terminal 100. The service classification 502 stores the name of the service for which the service terminal 100 is used. The request response 503 stores the response (response time) required for the service terminal 100 to authenticate the user to be authenticated. The template authentication speed 504 stores the template authentication speed of the service terminal 100 (the number of biometric templates that can be processed per second).
[0047] The template narrowing down ability 505 stores information (numerical values) indicating the guideline of narrowing down ability. When the narrowing down ability is expressed as a "fraction with a numerator of 1" as an ability per time as in the example of Fig. 5, the larger the value of the denominator, the higher the narrowing down ability. The communication speed 506 stores the communication speed of the service terminal 100.
[0048] FIG. 6 is a diagram illustrating the active template table 180. The active template table 180 may be referred to as "active template data." As shown in FIG. 6, the active template table 180 includes columns for storing information (values), such as a reception date and time 601, a sender 602, a sender service classification 603, a template ID 604, and an encrypted template 605. In the active template table 180, information corresponding to each column regarding the active templates held by the service terminal 100 is associated with each other and stored as row-by-row information (records). As described above, the row-by-row information in the active template table 180 may be referred to as "active template information."
[0049] An active template is a biometric template that has been successfully authenticated by at least one of "another service terminal 100 that is used in a service that has a high co-occurrence (continuous use) with the own service terminal 100" and "another service terminal 100 that has a high co-occurrence (continuous use) with the own service terminal 100." A biometric template that has been successfully authenticated by another service terminal 100 that has a high co-occurrence (continuous use) with the own service terminal 100 is likely to be successfully authenticated by the own service terminal 100, and another service terminal 100 that has a high co-occurrence (continuous use) with the terminal is likely to be successfully authenticated by the own service terminal 100. An active template can be said to be a biometric template that has a high probability of being successfully authenticated by the own service terminal 100. In this example, the "active template" is a biometric template that has been successfully authenticated by another service terminal 100 that is used in a service that has a high co-occurrence (continuous use) with the own service terminal 100.
[0050] The reception date and time 601 stores the date and time when the biometric template was received from another service terminal 100. The sender 602 stores the name of the service terminal 100 that sent the active template. The sender service classification 603 stores the name of the service used by the service terminal 100 that sent the active template. The template ID 604 stores the identification number of the active template (the user corresponding to the active template). The value (information) stored in the template ID 604 may be referred to as a "template ID" or a "user ID". The encrypted template 605 stores the active template (biometric template).
[0051] Fig. 7 is a diagram for explaining per-terminal setting information 190. As shown in Fig. 7, per-terminal setting information 190 includes, as columns for storing information (values), terminal 701, service classification 702, activity / history ratio 703, service usage periodicity 704, and special clause 705. In per-terminal setting information 190, information corresponding to each column related to the own service terminal 100 is associated with each other and stored as row-based information (records).
[0052] Specifically, the terminal 701 stores the name of the own service terminal 100. The service classification 702 stores the name of the service for which the own service terminal 100 is being used. The activity / history ratio 703 stores the ratio between the template history information (number of biometric templates) in the template history 160 held by the own service terminal 100 and the active template information (number of biometric templates) in the active template table 180. The service use periodicity 704 stores the period (service use period) at which the user uses the service for which the own service terminal 100 is being used. The special clause 705 stores information indicating special cases for determining the templates (template history information) to be held in the template history 160.
[0053] The computer 3000 shown in Fig. 2 is applied to the authentication information management server 200 in Fig. 1. A CPU 3001 of the computer 3000 executes programs stored in a ROM 3002 and / or a storage device 3004 to realize various functions. The authentication information management server 200 may be configured with multiple computers 3000, and may be not only physical computers 3000 but also virtual computers 3000. The computers 3000 may be computing resources and storage resources provided by a cloud, and the functions provided by the authentication information management server 200 may be provided by the cloud.
[0054] The storage device 3004 of the computer 3000 applied to the authentication information management server 200 stores (memorizes, holds) the following programs: a template narrowing down function unit 210, an inter-terminal co-occurrence information creation function unit 220, and an inter-service co-occurrence information creation function unit 230.
[0055] The template narrowing function unit 210 uses template narrowing information to narrow down biometric templates (biometric template candidates) from among the multiple biometric templates stored in the biometric template table 240. The inter-terminal co-occurrence information creation function unit 220 creates inter-terminal co-occurrence information 260. The inter-service co-occurrence information creation function unit 230 creates inter-service co-occurrence information 270.
[0056] The storage device 3004 of the computer 3000 applied to the authentication information management server 200 stores (memorizes, holds) as databases the biometric template table 240, template usage history 250, inter-terminal co-occurrence information 260, and inter-service co-occurrence information 270. The biometric template table 240, template usage history 250, inter-terminal co-occurrence information 260, and inter-service co-occurrence information 270 will be described in detail later.
[0057] Fig. 8 is a diagram illustrating the biometric template table 240. As shown in Fig. 8, the biometric template table 240 includes an ID 801 and an encrypted template 802 as columns for storing information (values). In the biometric template table 240, information corresponding to each column for managing biometric templates corresponding to each user registered in the authentication information management server 200 used for authentication is associated with each other and stored as row-based information (records).
[0058] Specifically, the identification number of the biometric template is stored in the ID 801. The encrypted template 802 stores the biometric template.
[0059] Fig. 9 is a diagram illustrating the template usage history 250. As shown in Fig. 9, the template usage history 250 includes, as columns for storing information (values), a usage date and time 901, a terminal used 902, a sender service classification 903, a template ID 904, and an encrypted template 905. In the template usage history 250, information corresponding to each column relating to the history of biometric templates (history of biometric templates for which authentication was successful) is associated with each other and stored as row-by-row information (records).
[0060] Specifically, the date and time of use 901 stores the date and time when the biometric template was used. The use terminal 902 stores the name of the service terminal 100 where the biometric template was used. The sender service classification 903 stores the name of the service used by the sender service terminal 100. The template ID 904 stores the identification number of the biometric template (the user corresponding to the biometric template). The value (information) stored in the template ID 904 may be referred to as a "template ID" or a "user ID". The encrypted template 905 stores the biometric template.
[0061] Fig. 10 is a diagram illustrating inter-terminal co-occurrence information 260. As shown in Fig. 10, inter-terminal co-occurrence information 260 includes, as columns for storing information (values), terminal name 1001, T01A 1002, T01B 1003, T02A 1004, and T03A 1005. In inter-terminal co-occurrence information 260, information corresponding to each column relating to the strength of the relationship (co-occurrence / affinity) between service terminals 100 is associated with one another and stored as row-based information (records).
[0062] Specifically, the terminal name 1001 stores the name of the service terminal 100. T01A 1002 stores a parameter (numeric value) indicating the strength of the co-occurrence (continuous use relationship) of the service terminal 100 with the terminal name: T01A relative to the corresponding service terminal 100. This parameter defines the strength of the relationship between two service terminals 100 existing in a specific area from the perspective of how frequently the two service terminals 100 are used together (continuously) by the same user, and may be referred to as a "first relationship value." T01B 1003 stores a parameter (first relationship value) indicating the strength of the co-occurrence (continuous use relationship) of the service terminal with the terminal name: T01B relative to the corresponding service terminal 100. T02A 1004 stores a parameter (first relationship value) indicating the strength of the co-occurrence (continuous use relationship) of the service terminal 100 with the terminal name: T02A relative to the corresponding service terminal 100. T03A1005 stores a parameter (first relation value) indicating the strength of the co-occurrence (continuous use relation) of the service terminal 100 with the terminal name: T03A for the corresponding service terminal 100.
[0063] Fig. 11 is a diagram illustrating inter-service co-occurrence information 270. As shown in Fig. 11, inter-service co-occurrence information 270 includes, as columns for storing information (values), service 1101, restaurant 1102, miscellaneous goods 1103, apparel 1104, and movie theater 1105. In inter-service co-occurrence information 270, as columns for storing information (values), information corresponding to each column regarding co-occurrence between services is associated with each other and stored as row-based information (records).
[0064] Specifically, the service 1101 stores the name of the service. The restaurant 1102 stores a parameter (numerical value) indicating the strength of the co-occurrence (continuous use relationship) of service: restaurant with respect to the corresponding service. This parameter defines the strength of the relationship between two services used by two service terminals 100 in a specific area from the perspective of how frequently the two services are used together (continuously) by the same user, and may be referred to as a "second relationship value." The miscellaneous goods 1103 stores a parameter (second relationship value) indicating the strength of the co-occurrence (continuous use relationship) of service: miscellaneous goods with respect to the corresponding service. The apparel 1104 stores a parameter (second relationship value) indicating the strength of the co-occurrence (continuous use relationship) of service: apparel with respect to the corresponding service. The movie theater 1105 stores a parameter (second relationship value) indicating the degree of co-occurrence (continuous use) of service: movie theater with respect to the corresponding service.
[0065] The computer 3000 shown in Fig. 2 is applied to the authentication server 300 in Fig. 1. The CPU 3001 of the computer 3000 executes programs stored in the ROM 3002 and / or the storage device 3004 to realize various functions. The authentication information management server 200 may be configured with multiple computers 3000, and is not limited to physical computers 3000, but may also be virtual computers 3000. The computers 3000 may be computing resources and storage resources provided by a cloud. The functions provided by the authentication server 300 may also be provided by a cloud.
[0066] <Summary> In a conventional biometric authentication system, a user inputs biometric information into a service terminal 100. The service terminal 100 creates template narrowing-down information using the biometric information, transmits the template narrowing-down information to the authentication information management server 200, and requests the authentication information management server 200 to narrow down the registered biometric templates to biometric templates (biometric template candidates) corresponding to the user.
[0067] A conventional authentication information management server 200 compares biometric template narrowing information (a part of the biometric templates) with registered biometric templates (a part of the registered biometric templates) to narrow down the registered biometric templates to a plurality of biometric templates to be used for biometric authentication. The authentication information management server 200 provides the narrowed down plurality of biometric templates to the service terminal 100. The service terminal 100 compares the narrowed down plurality of biometric templates with the user's biometric information to determine whether they match (are a correct combination). If the narrowed down plurality of biometric templates includes a biometric template that matches (is a correct combination with) the user's biometric information, user authentication is successful. If the narrowed down plurality of biometric templates does not include a biometric template that matches (is a correct combination with) the user's biometric information, user authentication fails.
[0068] The conventional authentication information management server 200 handles all requests from a large number of service terminals 100 to narrow down biometric templates and download biometric templates corresponding to user candidates, which increases the possibility of a period in which authentication is not possible due to a decrease in response time caused by a concentrated load, a network failure, etc. For this reason, the speed of biometric authentication may decrease in the conventional biometric authentication system.
[0069] Therefore, in the biometric authentication system according to one embodiment of the present invention, the service terminal 100 narrows down the biometric templates (template history 160) stored in the own service terminal 100, and also selects a service terminal 100 from among the other service terminals 100 and causes the selected other service terminal 100 to narrow down the biometric templates in parallel. Note that the narrowing down of the biometric templates performed by the own service terminal 100 may be referred to as a "first template narrowing down process," and the narrowing down of the biometric templates performed by the other service terminal 100 may be referred to as a "second template narrowing down process."
[0070] When the service terminal 100 acquires the plurality of narrowed-down biometric templates as the narrowed-down results of its own service terminal 100 and the other service terminals 100, the service terminal 100 checks whether the plurality of narrowed-down biometric templates match the biometric information of the user (are a correct combination). As described above, the checking is performed, for example, by restoring authentication information from the biometric templates using the biometric information and then checking a signature based on the restored authentication information in the authentication server 300. If there is a biometric template that matches the biometric information of the user (is a correct combination) among the plurality of narrowed-down biometric templates, the service terminal 100 determines that the authentication of the user is successful.
[0071] In the biometric authentication system according to the first embodiment, the service terminal 100 itself causes other service terminals 100 to narrow down the biometric templates in parallel, thereby preventing a decrease in response due to a concentrated load on the authentication information management server 200 and a period when authentication is not possible due to a network failure or the like, thereby improving the speed of biometric authentication.
[0072] <Specific operation> 12 is a flowchart showing the processing flow executed by the authentication information management server 200 using the inter-terminal co-occurrence information creation function unit 220 and the inter-service co-occurrence information creation function unit 230. The authentication information management server 200 starts processing from step 1200 and proceeds to step 1205, where it sorts the template history information stored in the template usage history 250 by user ID (template ID) and date.
[0073] Thereafter, the authentication information management server 200 proceeds to step 1210, which is the start point of the loop processing, and starts executing the loop processing from step 1210 to step 1225. This loop processing is repeatedly executed until the end condition of the loop processing (calculation has been performed for all history information pairs) is met at step 1225, which is the end point of the loop processing. Note that a history information pair refers to two consecutive pieces of template history information for the same date and the same user.
[0074] Step 1215: The authentication information management server 200 acquires two pieces of template history information (a pair of history information) of the same user that are consecutive in time on the same date.
[0075] Step 1220: The authentication information management server 200 obtains the following information from the two pieces of template history information acquired in step 1215: The transition status of the terminal used by the user (service terminal 100) (for example, the terminal used has transitioned from terminal T01A to terminal T01B) - The transition status of the service used by the user (for example, using apparel and then using a restaurant) - Difference in distance between the devices used by users - The time difference between the date and time of use between the devices used by the user
[0076] The authentication information management server 200 updates the inter-terminal co-occurrence information 260 and the inter-service co-occurrence information 270 based on the above information.
[0077] For example, the authentication information management server 200 updates the inter-terminal co-occurrence information 260 and the inter-service co-occurrence information 270 using an example of a calculation method described below.
[0078] The first relationship value is calculated so that it increases as the frequency of switching between two user terminals of the same user increases. For example, if the total number of history information pairs is N, the first relationship value of a certain terminal Y for a certain terminal X is calculated by dividing the number (total number) of times the user terminal has switched from terminal X to terminal Y by N. The calculated first relationship value may be corrected based on the difference in distance between the user terminals used by the user and the time difference between the dates and times of use. Examples of correction methods include the following. For example, the first relationship value may be corrected so that a smaller difference in distance between the user terminals is larger than a larger difference in distance. The first relationship value may be corrected so that a smaller difference in time between the dates and times of use is larger than a larger difference in time. If the difference in distance between the user terminals is larger than a predetermined value and the time difference between the dates and times of use is smaller than a predetermined time, the first relationship value may be corrected so that it increases.
[0079] The second relationship value is calculated so that it increases as the frequency of transitions between two services used by the same user increases. For example, the second relationship value for a certain service Y with respect to a certain service X is calculated by dividing the number (total number) of times the used service has transitioned from service X to service Y by N times. The calculated second relationship value may be corrected based on the difference in distance between the user terminals used by the user and the time difference between the dates and times of use. For example, the second relationship value may be corrected so that it is larger when the difference in distance between the user terminals is smaller than when the difference in time between the dates and times of use is larger. The second relationship value may be corrected so that it is larger when the difference in distance between the user terminals is larger than a predetermined value and the time difference between the dates and times of use is smaller than a predetermined time.
[0080] Regarding the time difference between the dates and times of use, if the role of the terminal used is known, such as for entry or payment, the time difference between the dates and times of use may be corrected taking into consideration the length of time the user stayed in the store, etc. For example, if the transition of terminal used is from an entry terminal to an entry terminal, the time difference between the dates and times of use may be corrected based on the average stay time for each category + distance (travel time).
[0081] If the change in terminal is from a terminal for transaction to a terminal for entry, the distance (travel time) may be used for correction. If the change in terminal is from a terminal for transaction to a terminal for transaction, the time difference between the date and time of use may be corrected by the average stay time for each category + the distance (travel time).
[0082] If a specific event occurs, a bonus correction may be made. For example, if a user moves directly between the transition usage terminals without passing through other locations, the first relationship value (second relationship value) may be corrected to be larger. In this case, if the distance between the transition usage terminals is long (longer than a predetermined distance), the first relationship value (second relationship value) may be corrected to be larger.
[0083] When the authentication information management server 200 proceeds to step 1225, which is the end point of the loop processing, it determines whether the termination condition of the loop processing (calculation has been performed for all history information pairs) is met. If the termination condition of the loop processing (calculation has been performed for all history information pairs) is not met, the authentication information management server 200 returns to step 1210, which is the start point of the loop processing. If the termination condition of the loop processing (calculation has been performed for all history information pairs) is met, the authentication information management server 200 ends the loop processing and proceeds to step 1295, where it temporarily ends this processing flow.
[0084] 13 is a flowchart showing the processing flow executed by the biometric authentication function unit 110, parallel processing function unit 120, and template narrowing-down function unit 130 when the service terminal 100 authenticates a user to be authenticated. The service terminal 100 starts processing from step 1300 and sequentially executes the processing from step 1305 to step 1320 described below.
[0085] Step 1305: The own service terminal 100 acquires the biometric information of the user to be authenticated.
[0086] Step 1310: The own service terminal 100 uses the user's biometric information to create template narrowing information for narrowing down the templates. The template narrowing information is, for example, information on a portion of the biometric templates.
[0087] Step 1315: The own service terminal 100 calculates the processable number of requests of the own service terminal 100 that is the request source. Based on the information corresponding to the own service terminal 100 in the in-area terminal information 170, the processable number of requests of the request source is calculated by multiplying the request response (seconds) by the template authentication speed (items / second).
[0088] Step 1320: The own service terminal 100 determines the amount of parallel processing to be shared. The own service terminal 100 determines the amount of parallel processing to be shared (the number of biometric templates to be shared) of the own service terminal 100 and the other service terminals 100 based on the narrowing down capability of the own service terminal 100 and the narrowing down capability of the other service terminals 100. For example, the service terminal 100 determines the amount of parallel processing to be shared based on the narrowing down processing capability (the reciprocal of the template narrowing down capability) of the own service terminal 100 (request source terminal) and the narrowing down processing capability (the reciprocal of the template narrowing down capability) of the other service terminals 100 (request destination terminal). For example, the service terminal 100 may use the ratio between the average value of the narrowing down processing capabilities of other service terminals 100 whose first relationship values to the service terminal 100 are ranked from a predetermined rank to 1 in the inter-terminal co-occurrence information 260 and the narrowing down processing capability of the service terminal 100 itself to calculate the share amount according to the ratio (the share is allocated so that the one with the larger narrowing down processing capability is given more).
[0089] Next, the own service terminal 100 executes the process of step 1325 and the processes of steps 1330 to 1350 in parallel, which will be described below.
[0090] Step 1325: The service terminal 100 (requesting terminal) executes template narrowing down processing. Specifically, the service terminal 100 uses the template narrowing down information to narrow down the biometric templates (biometric template candidates) corresponding to the user to be authenticated from the template history 160. For example, the service terminal 100 calculates the degree of matching between the template narrowing down information and part of the information of the biometric template, compares the degree of matching with a threshold value that is a reference value for the degree of matching, and narrows down the biometric templates that are equal to or greater than the threshold value as biometric template candidates. After that, the service terminal 100 proceeds to step 1355.
[0091] Step 1330: The service terminal 100 starts executing the loop process when it proceeds to step 1330, which is the starting point of the loop process from step 1330 to step 1350. This loop process is repeatedly executed until the end condition of the loop process (up to the parallel processing share of the requester's processable number (other service terminals 100)) is met at step 1350, which is the end point of the loop process.
[0092] Step 1335: The service terminal 100 acquires the inter-terminal co-occurrence information 260 and the inter-service co-occurrence information 270 from the authentication information management server 200, and calculates the affinity between the service terminal 100 and the other service terminal 100 based on the inter-terminal co-occurrence information 260 and the inter-service co-occurrence information 270.
[0093] For example, the own service terminal 100 calculates the affinity (=first relationship value×second relationship value) between the own service terminal 100 and the other service terminal 100 of the request destination by multiplying the first relationship value in the inter-terminal co-occurrence information 260 corresponding to the other service terminal 100 by the second relationship value in the inter-service co-occurrence information 270. Note that if the affinity value exceeds 1, the affinity value is calculated as 1.
[0094] The own service terminal 100 may calculate the first relationship value of the inter-terminal co-occurrence information 260 as affinity (=first relationship value), and may calculate the second relationship value of the inter-service co-occurrence information 270 as affinity (=second relationship value).
[0095] Step 1340: The own service terminal 100 calculates the request amount from the affinity and the processing capacity of the request destination. The own service terminal 100 calculates the request amount as follows: Request amount = Affinity × Narrowing processing capacity of the request destination (other service terminal 100) × Request response of the request source (own service terminal 100). The narrowing processing capacity is calculated using the reciprocal of the template narrowing down capacity. As mentioned above, the affinity value is calculated so that it is 1 or less. From the viewpoint of improving the efficiency of narrowing down, it is preferable to increase the request amount for other service terminals 100 with high affinity. However, this calculation is performed taking into consideration that constantly requesting a request amount equivalent to 100% of the processing capacity of the own service terminal 100, which is the request destination, from the other service terminal 100, which is the request destination, would place too much load on the other service terminal 100, which is the request destination, and that the response must not be slow.
[0096] Step 1345: The own service terminal 100 transmits the service usage periodicity information and the request volume to the other service terminals 100 in order starting from the other service terminals 100 with the highest affinity. By sending the service usage periodicity information together with the request volume to the other service terminal 100 as the request destination, the other service terminal 100 as the request destination can be made to narrow down the search taking into account the periodicity of the user's service usage.
[0097] Step 1350: When the own service terminal 100 proceeds to step 1350, which is the end point of the loop processing, it determines whether the end condition of the loop processing (up to the parallel processing share of the processable number of cases of the requester (other service terminals 100)) is met. If the end condition of the loop processing (up to the parallel processing share of the processable number of cases of the requester (until all parallel processing shares are assigned)) is not met, the own service terminal 100 returns to step 1330, which is the start point of the loop processing. If the end condition of the loop processing (up to the parallel processing share of the processable number of cases of the requester (other service terminals 100)) is met, the own service terminal 100 proceeds to step 1355.
[0098] When the service terminal 100 proceeds to step 1355, it performs an authentication attempt using the active template stored in the active template table 180 of the service terminal 100, the biometric template(s) resulting from the narrowing down of the service terminal 100, and the biometric template(s) returned from the other service terminal 100 that is the requestee. That is, as described above, the service terminal 100 verifies whether the narrowed down biometric templates match (are a correct combination with) the user's biometric information. If the narrowed down biometric templates include a biometric template that matches (are a correct combination with) the user's biometric information, the service terminal 100 determines that the user authentication is successful. If the narrowed down biometric templates include no biometric template that matches (are a correct combination with) the user's biometric information, the service terminal 100 determines that the user authentication is unsuccessful.
[0099] If the authentication is successful, the service terminal 100 determines "YES" in step 1360 and proceeds to step 1370. If the authentication is unsuccessful, the service terminal 100 determines "NO" in step 1360 and proceeds to step 1375. The service terminal 100 performs normal authentication processing using the authentication information management server 200, and then proceeds to step 1370. The normal authentication processing is performed as follows. The service terminal 100 causes the authentication information management server 200 to narrow down the biometric templates corresponding to the user to be authenticated, and returns the narrowed down biometric template candidates to the service terminal 100. The service terminal 100 verifies whether the returned biometric template candidates match the user's biometric information (are a correct combination). If there is a biometric template that matches the user's biometric information (are a correct combination) among the narrowed down multiple biometric templates, the service terminal 100 determines that the user's authentication is successful. If there is no biometric template that matches (is a correct combination with) the biometric information of the user among the narrowed-down plurality of biometric templates, the service terminal 100 determines that the authentication of the user has failed.
[0100] When the own service terminal 100 proceeds to step 1370, it selects a destination other service terminal 100 based on the second relationship value of the inter-service co-occurrence information 270, and transmits the successfully authenticated biometric template as an active template to the selected other service terminal 100. For example, the own service terminal 100 transmits history information about the successfully authenticated biometric template to the other service terminal 100 used for a service for which the second relationship value for the service of the own service terminal 100 is equal to or greater than a predetermined value. As a result, the biometric template (active template) is sent to the other service terminal 100 used for a service that is likely to be used continuously for the service for which the own service terminal 100 is used, and is stored in the other service terminal 100 as an active template. As a result, the possibility of successful user authentication in the other service terminal 100 is increased, thereby further improving the speed of biometric authentication.
[0101] In step 1370, the own service terminal 100 may select the other service terminal 100 as the destination based on the first relationship value of the inter-terminal co-occurrence information 260 and the second relationship value of the inter-service co-occurrence information 270. In this case, for example, the own service terminal 100 transmits history information related to the successfully authenticated biometric template to the other service terminal 100 whose value (for example, affinity) based on the first relationship value and the second relationship value for the own service terminal 100 is equal to or greater than a predetermined value.
[0102] Furthermore, in step 1370, the own service terminal 100 may select the other service terminal 100 as the destination based on the first relationship value of the inter-terminal co-occurrence information 260. In this case, for example, the own service terminal 100 transmits history information related to the biometric template that has been successfully authenticated to the other service terminal 100 whose first relationship value with the own service terminal 100 is equal to or greater than a predetermined value.
[0103] The other service terminal 100 stores the received biometric template as an active template in the active template table 180. Thereafter, the own service terminal 100 proceeds to step 1395 and temporarily ends this processing flow.
[0104] FIG. 14 is a flowchart showing the processing flow executed by the parallel processing contracting function unit 150 of each of one or more other service terminals 100 that are the request destinations.
[0105] The other service terminal 100 starts processing at step 1400 and proceeds to step 1400, where it receives template narrowing down information, service usage periodicity information, and the number of result requests (request amount at step 1345) from its own service terminal 100 that is the request source. Thereafter, the other service terminal 100 proceeds to step 1410, which is the start point of the loop processing, and begins executing the loop processing from step 1410 to step 1420. This loop processing is repeatedly executed until the loop processing termination condition (until the template narrowing down result (number of narrowed down templates) satisfies the requested number) is met at step 1420, which is the end point of the loop processing.
[0106] Step 1415: The other service terminal 100 executes a process of narrowing down the templates from the template history 160 by referring to the service usage periodicity information. For example, if the service usage periodicity information is one week, the other service terminal 100 executes a process of narrowing down the templates by matching biometric templates sequentially from the template history information one week before the current time toward the current time. This executes a process of narrowing down the biometric templates taking into account the service usage periodicity, and enables efficient narrowing down of the biometric templates.
[0107] When the other service terminal 100 proceeds to step 1420, which is the end point of the loop processing, it determines whether the loop processing termination condition (until the result of template narrowing down (the number of narrowed down templates) satisfies the requested number) is met. If the loop processing termination condition (until the result satisfies the requested number) is not met, the other service terminal 100 returns to step 1410, which is the start point of the loop processing. If the loop processing termination condition (until the result of template narrowing down (the number of narrowed down templates) satisfies the requested number) is met, the other service terminal 100 ends the loop processing and proceeds to step 1425.
[0108] When the other service terminal 100 proceeds to step 1425, it transmits the template narrowing-down result (narrowed-down biometric template) to the requesting service terminal 100. Thereafter, the other service terminal 100 proceeds to step 1495 and temporarily ends this processing flow.
[0109] 15 is a flowchart showing the processing flow executed by the service terminal 100 using the template history discarding function unit 140. The service terminal 100 starts processing from step 1500, and after sequentially executing the processing of steps 1505 and 1510 described below, proceeds to step 1515.
[0110] Step 1505: The service terminal 100 calculates the upper limit number of templates that can be processed within the requested response time based on the in-area terminal information 170. The upper limit number of templates that can be processed is calculated by multiplying the request response by the sum of the reciprocal of the template authentication speed and the template narrowing-down capability. That is, the service terminal 100 calculates the upper limit number of templates that can be processed as follows: request response × (template authentication speed + reciprocal of template narrowing-down capability). For example, if the service terminal 100 is TO1A, the upper limit number of templates that can be processed is 50, calculated by request response (1 second) × (template authentication speed (10 templates / second) + reciprocal of template narrowing-down capability (40 / second)).
[0111] Step 1510: The service terminal 100 deletes the active template information of the stored active templates from the active template table 180, which is older than one day before the current date. As a result, only biometric templates related to users who have been successfully authenticated using the service terminal 100 in a specific area on the same day as the current date remain in the active template table 180.
[0112] In step 1515, the service terminal 100 determines whether the total number of template history records in the template history 160 and the number of active template records in the active template table 180 is equal to or greater than the processable upper limit number.
[0113] If the total number is not greater than the upper limit of the number of templates that can be processed, there is no need to discard the history information (template history information and active template information), so the service terminal 100 determines "NO" in step 1515, proceeds to step 1595, and temporarily ends this processing flow.
[0114] If the calculated total number is equal to or greater than the upper limit of the number of templates that can be processed, the service terminal 100 determines "YES" in step 1520 in order to discard part of the history information (template history information and active template information), and after sequentially executing the processes of steps 1520 to 1530 described below, proceeds to step 1595 and temporarily ends this processing flow.
[0115] Step 1520: The service terminal 100 determines a storage ratio based on the storage ratio between the terminal history (template history information) in the per-terminal setting information 190 and the active template (active template information).
[0116] Step 1525: The service terminal 100 determines to retain template history information that meets the special conditions of the per-terminal setting information 190. The special conditions ensure that biometric templates with a high probability of success remain in the template history information.
[0117] Step 1530: Service terminal 100 acquires inter-service co-occurrence information 270 from authentication information management server 200, and determines template history information and / or active template information to delete based on the second relationship value of inter-service co-occurrence information 270 and the storage ratio. For example, service terminal 100 determines template history information and / or active template information to delete from at least one of template history 160 and active template table 180 so that the number of template history information (biometric templates) and the number of active template information (active templates) satisfy the storage ratio. At this time, service terminal 100 preferentially deletes template history information with a small second relationship value of inter-service co-occurrence information 270 for the service used by the service terminal 100 to be deleted, for example.
[0118] Service terminal 100 may acquire inter-terminal co-occurrence information 260 and inter-service co-occurrence information 270 from authentication information management server 200, and determine the template history information and / or active template information to delete based on the first relationship value of inter-terminal co-occurrence information 260, the second relationship value of inter-service co-occurrence information 270, and the storage ratio. Service terminal 100 may acquire inter-terminal co-occurrence information 260 from authentication information management server 200, and determine the template history information and / or active template information to delete based on the first relationship value of inter-terminal co-occurrence information 260 and the storage ratio.
[0119] <Effects> As described above, the biometric authentication system according to the first embodiment of the present invention can improve the speed of biometric authentication by reducing the load on the authentication information management server 200 by performing the first template narrowing-down process and the second template narrowing-down process in parallel.
[0120] <<Second embodiment>> A biometric authentication system according to a second embodiment of the present invention will now be described. The biometric authentication system according to the second embodiment differs from the biometric authentication system according to the first embodiment only in that the processing flow shown in the flowchart of Fig. 16 is executed instead of that shown in Fig. 13. The following description will focus on this difference.
[0121] 16 is a flowchart showing the processing flow executed by the biometric authentication function unit 110, parallel processing function unit 120, and template narrowing down function unit 130 when the service terminal 100 authenticates a user to be authenticated. The service terminal 100 itself starts processing from step 1600, and after sequentially executing the processing of steps 1305 and 1310 described above, proceeds to step 1605, where an authentication attempt is made using an active template stored in the active template table 180 of the service terminal 100 itself.
[0122] If the authentication is successful, the service terminal 100 determines "YES" in step 1610 and proceeds to step 1370, where it executes the processing of step 1370 described above, and then proceeds to step 1695, where it temporarily ends this processing flow.
[0123] If the authentication fails, the own service terminal 100 determines "NO" in step 1610 and executes the processing of steps 1315 to 1350 described above, whereby the own service terminal 100 executes the first template narrowing down processing and causes the other service terminal 100 to execute the second template narrowing down processing, and then proceeds to step 1615.
[0124] When the service terminal 100 proceeds to step 1615, it performs an authentication attempt using the biometric templates (multiple) of the narrowing down results of its own service terminal 100 (narrowing down results of the first template narrowing down process) and the biometric templates (multiple) of the narrowing down results of the second template narrowing down process returned from the other service terminal 100 that was the requestee.
[0125] Thereafter, the self service terminal 100 executes an appropriate process from among the processes of steps 1360 to 1375 described above, and then proceeds to step 1695 to temporarily end this processing flow.
[0126] <Effects> As described above, the biometric authentication system according to the second embodiment of the present invention can improve the speed of biometric authentication, similar to the first embodiment. Furthermore, the biometric authentication system according to the second embodiment first performs matching against active templates that are likely to result in successful authentication, and if authentication fails, performs first template narrowing down processing and second template narrowing down processing in parallel to narrow down candidates for biometric templates, thereby further improving the speed of biometric authentication.
[0127] <<Modifications>> The present invention is not limited to the above-described embodiments, and various modifications can be adopted within the scope of the present invention. The above-described embodiments can be combined with each other without departing from the scope of the present invention.
[0128] In each of the above embodiments, the service terminal 100 may hold the inter-terminal co-occurrence information 260 and the inter-service co-occurrence information 270. In this case, the service terminal 100 itself may use the inter-terminal co-occurrence information 260 and the inter-service co-occurrence information 270 held by the service terminal 100 itself in step 1335 of Fig. 13 and Fig. 16. The service terminal 100 itself may use the inter-service co-occurrence information 270 held by the service terminal 100 itself in step 1530 of Fig. 15.
[0129] In each of the above embodiments, the template history information to be stored as an exception may be determined based on an operation by a user on the service terminal 100. In this case, the template history information is determined as the history to be stored in step 1525 of Fig. 15. This modification is used, for example, when a store clerk wants to leave biometric templates corresponding to regular users on the service terminal 100.
[0130] In each of the above embodiments, the authentication server 300 of the biometric authentication system may be omitted, and the function of the authentication server 300 may be provided in the service terminal 100. Also, in each of the above embodiments, the authentication server 300 of the biometric authentication system may be omitted, and the function of the authentication server 300 may be provided in the authentication information management server 200.
[0131] In each of the above embodiments, the biometric template may not be a PBI template, but may be information based on biometric information such as biometric information or feature amounts extracted from biometric information.
[0132] In this case, the authentication server 300 of the biometric authentication system may be omitted. In this case, the service terminal 100 checks whether the narrowed-down plurality of biometric templates match (are a correct combination) with the user's biometric information as follows. Specifically, the service terminal 100 calculates the degree of matching between the input biometric authentication information and the biometric template for each of the narrowed-down biometric templates, compares the degree of matching with a threshold, which is a reference value for the degree of matching, and determines whether the user is authenticated based on the comparison result. The service terminal 100 determines that the user authentication is successful when there is only one candidate biometric template in the authentication result whose degree of matching is equal to or greater than the threshold. The service terminal 100 determines that the user authentication is unsuccessful when there is no biometric template whose degree of matching is equal to or greater than the threshold in the end, or when there are multiple biometric templates whose degree of matching is not equal to or greater than the threshold in the end (when there are multiple biometric templates).
[0133] The present invention can also have the following configuration. [1] Multiple biometric authentication terminals, an authentication information management server; A biometric authentication method using Each of the multiple biometric authentication terminals retaining template history data including multiple template history information related to multiple biometric templates that have been successfully authenticated; By the biometric authentication terminal itself, which is the biometric authentication terminal that authenticates the user to be authenticated, acquiring biometric authentication information of the user to be authenticated; requesting another biometric authentication terminal, which is a biometric authentication terminal other than the own biometric authentication terminal, to narrow down biometric template candidates corresponding to the user to be authenticated; executes a first template narrowing-down process for narrowing down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the biometric authentication terminal; The other biometric authentication terminal that received the request executes a second template narrowing-down process in parallel with the first template narrowing-down process, the second template narrowing-down process narrowing down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the other biometric authentication terminal that has received the request; By the biometric authentication terminal, authenticating the user by matching the biometric template candidates narrowed down by the first template narrowing down process and the second template narrowing down process with biometric authentication information of the user; Biometric authentication methods. [Explanation of symbols]
[0134] 100...service terminal, 110...biometric authentication function unit, 120...parallel processing function unit, 130...template narrowing down function unit, 140...template history discarding function unit, 150...parallel processing contracting function unit, 160...template history, 170...in-area terminal information, 180...active template table, 190...setting information for each terminal, 200...authentication information management server, 210...template narrowing down function unit, 220...inter-terminal co-occurrence information creation function unit, 230...inter-service co-occurrence information creation function unit, 240...biometric template table, 250...template usage history, 260...inter-terminal co-occurrence information, 270...inter-service co-occurrence information
Claims
1. A computing device; A storage device; A biometric authentication terminal including: the storage device stores template history data including multiple pieces of template history information relating to multiple biometric templates that have been successfully authenticated; The computing device Obtain biometric information of the user to be authenticated; requesting another biometric authentication terminal to narrow down biometric template candidates corresponding to the user to be authenticated; executes a first template narrowing-down process for narrowing down the biometric template candidates corresponding to the user to be authenticated from the template history data; causing the requested other biometric authentication terminal to execute, in parallel with the first template narrowing down process, a second template narrowing down process for narrowing down the biometric template candidates corresponding to the user to be authenticated from template history data including a plurality of template history information items related to biometric templates that have been successfully authenticated by the other biometric authentication terminal provided in the other biometric authentication terminal; authenticating the user by matching the biometric template candidates narrowed down by the first template narrowing down process and the second template narrowing down process with biometric authentication information of the user; It was configured as follows: Biometric authentication terminal.
2. The biometric authentication terminal according to claim 1, the storage device stores active template data including a plurality of active template information items including active templates that have been successfully authenticated at other biometric authentication terminals and are biometric templates that have a high probability of successful authentication; authenticating the user by matching the biometric template candidates and the active template narrowed down by the first template narrowing down process and the second template narrowing down process with biometric authentication information of the user; It was configured as follows: Biometric authentication terminal.
3. The biometric authentication terminal according to claim 1, The computing device before requesting the other biometric authentication terminal to narrow down the biometric template candidates corresponding to the user to be authenticated, authenticating the user by matching an active template with the user's biometric authentication information; If authentication of the user fails, a request is made to the other biometric authentication terminal to narrow down the biometric template candidates corresponding to the user to be authenticated. Biometric authentication terminal.
4. The biometric authentication terminal according to claim 1, The computing device acquire at least one value of a first relational value indicating continuous usability between the biometric authentication terminal itself and another biometric authentication terminal, and a second relational value indicating continuous usability between a service in which the biometric authentication terminal itself is used and a service in which the other biometric authentication terminal is used; selecting, from the other biometric authentication terminals, a plurality of other biometric authentication terminals to execute the second template narrowing-down process based on the at least one value, and requesting the selected other biometric authentication terminals to narrow down the biometric template candidates; It was configured as follows: Biometric authentication terminal.
5. The biometric authentication terminal according to claim 1, The computing device Set the number of biometric template candidates to be narrowed down, determining the number of the biometric template candidates narrowed down by the first template narrowing down process and the number of the biometric template candidates narrowed down by the second template narrowing down process so that the sum of the number of the biometric template candidates narrowed down by the first template narrowing down process and the number of the biometric template candidates narrowed down by the second template narrowing down process becomes the set number of the biometric template candidates to be narrowed down; It was configured as follows: Biometric authentication terminal.
6. The biometric authentication terminal according to claim 4, The computing device Based on the biometric template narrowing down capability of the own biometric authentication terminal and the biometric template narrowing down capability of the selected plurality of other biometric authentication terminals, determining the number of the biometric template candidates to be narrowed down by the first template narrowing-down process and the number of the biometric template candidates to be narrowed down by the second template narrowing-down process; It was configured as follows: Biometric authentication terminal.
7. The biometric authentication terminal according to claim 5, The computing device Based on the at least one value and the biometric template narrowing down processing capabilities of the selected plurality of other biometric authentication terminals, determining the number of the biometric template candidates narrowed down by the second template narrowing down process to be assigned to each of the plurality of other biometric authentication terminals; It was configured as follows: Biometric authentication terminal.
8. The biometric authentication terminal according to claim 1, The computing device transmitting periodicity information of service use to the other biometric authentication terminal when requesting narrowing down of the biometric template candidates; causing the other biometric authentication terminal to execute the second template narrowing-down process based on the periodicity information of the service usage; It was configured as follows: Biometric authentication terminal.
9. The biometric authentication terminal according to claim 2, The computing device receiving, from the other biometric authentication terminal, a biometric template that has been successfully authenticated by the other biometric authentication terminal, and storing the active template information including the received biometric template as the active template in the active template data; It was configured as follows: Biometric authentication terminal.
10. The biometric authentication terminal according to claim 2, The computing device acquire at least one value of a first relational value indicating continuous usability between the biometric authentication terminal itself and another biometric authentication terminal, and a second relational value indicating continuous usability between a service in which the biometric authentication terminal itself is used and a service in which the other biometric authentication terminal is used; When the total number of biometric templates stored in the template history data and the total number of biometric templates stored in the template history data is equal to or greater than a predetermined number, determining the biometric template to be deleted from the template history data and the active template data based on a storage ratio between the number of biometric templates stored in the template history data and the number of biometric templates stored in the active template data, and at least one of the first relation value and the second relation value, and deleting the determined biometric template. It was configured as follows: Biometric authentication terminal.
11. Multiple biometric authentication terminals, an authentication information management server; A biometric authentication system comprising: Each of the multiple biometric authentication terminals is retaining template history data including multiple template history information related to multiple biometric templates that have been successfully authenticated; The biometric authentication terminal that authenticates the user to be authenticated is a self-biometric authentication terminal, acquiring biometric authentication information of the user to be authenticated; requesting another biometric authentication terminal, which is a biometric authentication terminal other than the own biometric authentication terminal, to narrow down biometric template candidates corresponding to the user to be authenticated; executes a first template narrowing-down process for narrowing down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the biometric authentication terminal; the other biometric authentication terminal that has received the request executes, in parallel with the first template narrowing-down process, a second template narrowing-down process for narrowing down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the other biometric authentication terminal that has received the request; The biometric authentication terminal includes: authenticating the user by matching the biometric template candidates narrowed down by the first template narrowing down process and the second template narrowing down process with biometric authentication information of the user; Biometric authentication system.
12. The biometric authentication system according to claim 11, Each of the plurality of biometric authentication terminals retaining active template data including a plurality of active template information including active templates that have been successfully authenticated at the other biometric authentication terminal and are biometric templates that are highly likely to be successfully authenticated; The biometric authentication terminal includes: authenticating the user by matching the biometric template candidates and the active template narrowed down by the first template narrowing down process and the second template narrowing down process with biometric authentication information of the user; Biometric authentication system.
13. The biometric authentication system according to claim 11, The authentication information management server holding inter-terminal co-occurrence information including a first relationship value indicating continuous usability between two of a plurality of biometric authentication terminals, and inter-service co-occurrence information including a second relationship value indicating continuous usability between two of a plurality of identical or different services for which the biometric authentication terminal is used; calculating a first value as the first relation value, the first value being larger as the frequency of switching between two terminals of the same user increases; and calculating a second value as the second relation value, the second value being larger as the frequency of switching between services used by the same user increases; The biometric authentication terminal includes: selecting the other biometric authentication terminal to be requested to narrow down the biometric template candidates based on at least one of the inter-terminal co-occurrence information and the inter-service co-occurrence information; Biometric authentication system.
14. The biometric authentication system according to claim 13, The authentication information management server Calculating the first relationship value by correcting the first value based on a specific criterion; calculating the second relationship value by correcting the second value based on a specific criterion; Biometric authentication system.
15. Multiple biometric authentication terminals, an authentication information management server; A biometric authentication method using Each of the multiple biometric authentication terminals retaining template history data including multiple template history information related to multiple biometric templates that have been successfully authenticated; By the biometric authentication terminal itself, which is the biometric authentication terminal that authenticates the user to be authenticated, acquiring biometric authentication information of the user to be authenticated; requesting another biometric authentication terminal, which is a biometric authentication terminal other than the own biometric authentication terminal, to narrow down biometric template candidates corresponding to the user to be authenticated; executes a first template narrowing-down process for narrowing down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the biometric authentication terminal; The other biometric authentication terminal that received the request executes a second template narrowing-down process in parallel with the first template narrowing-down process, the second template narrowing-down process narrowing down the biometric template candidates corresponding to the user to be authenticated from the template history data held by the other biometric authentication terminal that has received the request; By the biometric authentication terminal, authenticating the user by matching the biometric template candidates narrowed down by the first template narrowing down process and the second template narrowing down process with biometric authentication information of the user; Biometric authentication methods.
Citation Information
Patent Citations
Cache control device, cache control method, and cache control program
WO2023242951A1