Authentication device, authentication method and program
The authentication device improves personal authentication accuracy by integrating device and biometric authentication, addressing false rejection and acceptance rates while enabling secure, real-time authentication with lower biometric accuracy and local storage.
Patent Information
- Application Number
- JP2024083620
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-22
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2044-05-22
AI Technical Summary
Biometric authentication systems face challenges in minimizing false rejection and acceptance rates, and managing sensitive biometric information poses risks of information leakage, making it difficult to store locally for real-time authentication.
An authentication device that performs both device authentication and biometric authentication, using a receiving unit, device authentication unit, biometric information acquisition unit, memory unit, and biometric authentication unit to improve accuracy by associating user identifiers with registered biometric information, allowing for lower accuracy biometric authentication and local storage.
Enhances overall authentication accuracy by combining device and biometric authentication, enabling secure, real-time personal authentication even with lower biometric accuracy, and allowing local storage of biometric information.
Smart Images

Figure 2025177095000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an authentication device or the like that performs biometric authentication. [Background technology]
[0002] Conventionally, biometric authentication such as facial recognition has been performed (see, for example, Patent Document 1). When authentication is performed using a personal identification number or password, there is a possibility that authentication cannot be performed if the personal identification number or password is forgotten or lost, but biometric authentication has the advantage of not having such a problem. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180831 Summary of the Invention [Problem to be solved by the invention]
[0004] However, when authenticating an individual using only biometric authentication, it is necessary to minimize false positives. For example, when authenticating an individual using only biometric authentication, it is necessary to reduce the False Rejection Rate (FRR), which is the rate at which a person is mistakenly determined to be a false identity, and the False Acceptance Rate (FAR), which is the rate at which a person is mistakenly determined to be a false identity, despite being the person in question.
[0005] To improve the accuracy of such biometric authentication, i.e., to reduce the false rejection rate and false acceptance rate, it is necessary to use more detailed biometric information about an individual. Because such detailed biometric information can easily identify an individual, handling of the information must be extremely sensitive from the perspective of the risk of information leakage. For this reason, it is difficult to store the biometric information of an individual used for biometric authentication in, for example, a local system that performs biometric authentication. On the other hand, while it is possible to manage a huge amount of biometric information on a secure server and access the server via a network, such biometric information management is not suitable for real-time biometric authentication.
[0006] The present invention has been made in response to the above circumstances, and aims to provide an authentication device etc. that can achieve more accurate personal authentication even when the accuracy of biometric authentication is not necessarily high. [Means for solving the problem]
[0007] In order to achieve the above object, an authentication device according to one aspect of the present invention includes: a receiving unit that receives an authentication request transmitted from a device to be authenticated, the authentication request including a user identifier that identifies a user carrying the device to be authenticated and authentication information used to authenticate the device to be authenticated; a device authentication unit that performs device authentication to determine whether the device to be authenticated that transmitted the authentication request is legitimate, using the authentication information included in the authentication request received by the receiving unit; a biometric information acquisition unit that acquires biometric information of the user carrying the device to be authenticated; a memory unit that stores a plurality of correspondence information that associates a user identifier that identifies the user with registered biometric information that is the user's biometric information; a biometric authentication unit that performs biometric authentication to determine whether the user whose biometric information is acquired is legitimate, using the registered biometric information that is associated by the correspondence information with the user identifier included in the authentication request received by the receiving unit and the biometric information acquired by the biometric information acquisition unit; and an output unit that outputs a result of the device authentication by the device authentication unit and a result of the biometric authentication by the biometric authentication unit.
[0008] With this configuration, by performing device authentication and biometric authentication, it is possible to improve the accuracy of personal authentication that authenticates the identity of a person. Therefore, even if the accuracy of biometric authentication is not necessarily high, personal authentication can be performed appropriately.
[0009] In addition, in an authentication device according to one aspect of the present invention, the receiving unit may include a first receiver set including one or more first receivers and a second receiver set including one or more second receivers located at a different location from the first receiver set, and may further include an identification unit that identifies the location of the device to be authenticated based on the strength difference between the authentication requests received by the first and second receiver sets, respectively, and the biometric information acquisition unit may acquire biometric information of a user carrying the device to be authenticated that is located at the location identified by the identification unit.
[0010] With this configuration, the biometric information acquisition unit can acquire the biometric information of the target user using the results of identifying the location of the device to be authenticated, thereby improving the accuracy of biometric authentication.
[0011] In addition, in the authentication device according to one aspect of the present invention, the biometric authentication may be face authentication.
[0012] With this configuration, for example, hands-free authentication can be realized.
[0013] In the authentication device according to one aspect of the present invention, the biometric authentication may be at least one of biometric authentication using height, biometric authentication using stride length, and iris authentication.
[0014] With this configuration, personal authentication can be performed appropriately even if the accuracy of the biometric authentication is not necessarily high, such as biometric authentication using height or stride length.
[0015] Furthermore, in the authentication device according to one aspect of the present invention, the accuracy of the biometric authentication performed by the biometric authentication unit may be lower than the accuracy when authenticating an individual using only biometric information.
[0016] With this configuration, for example, it becomes possible to store registered biometric information in a local storage unit.
[0017] In the authentication device according to an aspect of the present invention, the receiving unit may receive the authentication request as a radio wave.
[0018] With this configuration, it becomes possible to authenticate the device even when the device to be authenticated is placed in the user's bag, for example.
[0019] Furthermore, an authentication method according to one aspect of the present invention is an authentication method processed using a receiving unit, a device authentication unit, a biometric information acquisition unit, a memory unit in which multiple correspondence information correlating a user identifier that identifies a user with registered biometric information that is the user's biometric information, a biometric authentication unit, and an output unit, and includes the steps of: the receiving unit receiving an authentication request transmitted from the device to be authenticated, the authentication request including a user identifier that identifies a user carrying the device to be authenticated and authentication information used to authenticate the device to be authenticated; the device authentication unit performing device authentication to determine whether the device to be authenticated that transmitted the authentication request is legitimate, using the authentication information included in the received authentication request; the biometric information acquisition unit acquiring biometric information of the user carrying the device to be authenticated; the biometric authentication unit performing biometric authentication to determine whether the user whose biometric information was acquired is legitimate, using the registered biometric information that is associated by correspondence information with the user identifier included in the authentication request received in the authentication request receiving step and the biometric information acquired in the biometric information acquiring step; and the output unit outputting a result of the device authentication in the device authentication step and a result of the biometric authentication in the biometric authentication step. [Effects of the Invention]
[0020] According to an authentication device or the like according to one aspect of the present invention, the accuracy of authentication as a whole can be improved by performing device authentication for the device to be authenticated and biometric authentication of the user carrying the device to be authenticated. [Brief explanation of the drawings]
[0021] [Figure 1] FIG. 1 is a block diagram showing a configuration of an authentication device according to an embodiment of the present invention. [Figure 2] FIG. 10 is a diagram for explaining how to specify the position of the authenticated device in the embodiment. [Figure 3] FIG. 10 is a diagram for explaining the acquisition of biometric information in the embodiment. [Figure 4] FIG. 10 is a diagram showing an example of correspondence information according to the embodiment; [Figure 5] A flowchart showing the operation of the authentication device according to the embodiment. [Figure 6] FIG. 2 shows an example of the configuration of a computer system according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0022] An authentication device and authentication method according to the present invention will be described below using embodiments. In the following embodiments, components and steps denoted by the same reference numerals are the same or equivalent, and repeated description may be omitted. The authentication device according to this embodiment performs device authentication of a device to be authenticated and biometric authentication of a user carrying the device to be authenticated.
[0023] FIG. 1 is a block diagram showing the configuration of an authentication device 1 according to this embodiment. The authentication device 1 according to this embodiment includes a receiving unit 11, a device authentication unit 12, an identifying unit 13, a biometric information acquiring unit 14, a storage unit 15, a biometric authentication unit 16, and an output unit 17. The authentication device 1 according to this embodiment authenticates a device to be authenticated 2 carried by a user 5, and if the device to be authenticated 2 is determined to be valid in the authentication, the authentication device 1 performs biometric authentication of the user 5 carrying the valid device to be authenticated 2. Note that while FIG. 1 shows a situation in which the user 5 is holding the device to be authenticated 2 in his / her hand, the state in which the device to be authenticated 2 moves in accordance with the movement of the user 5 refers to a state in which the device to be authenticated 2 also moves in accordance with the movement of the user 5, and the user 5 does not necessarily have to be holding the device to be authenticated 2 in his / her hand. Also, while FIG. 1 shows a case in which the authentication device 1 receives an authentication request from a single device to be authenticated 2, the authentication device 1 may receive authentication requests from, for example, multiple devices to be authenticated 2, respectively.
[0024] The authentication device 1 may be, for example, a device that performs authentication in an automatic ticket gate, a gate for entering a venue such as an event, a vending machine, a control device that locks and unlocks the doors of a hotel or a rental conference room, a cash register, etc., or may be a mobile information terminal with a communication function such as a smartphone. The device to be authenticated 2 may be, for example, a mobile information terminal with a communication function such as a smartphone, a tablet terminal, a PDA (Personal Digital Assistant), a laptop computer, a transceiver, etc., or may be other devices.
[0025] The receiving unit 11 receives an authentication request transmitted from the device to be authenticated 2, the authentication request including a user identifier identifying the user carrying the device to be authenticated 2 and authentication information used to authenticate the device to be authenticated 2. The device to be authenticated 2 may transmit an authentication request in the form of, for example, radio waves, or may transmit an authentication request in the form of sound waves. That is, the receiving unit 11 may receive an authentication request in the form of, for example, radio waves, or may receive an authentication request in the form of sound waves. In this embodiment, a case where an authentication request in the form of radio waves is transmitted and received will be mainly described. Note that when an authentication request in the form of sound waves is transmitted and received, it is preferable that there are no obstacles in the space from the device to be authenticated 2 to the authenticating device 1. On the other hand, when an authentication request in the form of radio waves is transmitted and received, the distance from the device to be authenticated 2 to the authenticating device 1 may or may not be line of sight. In the latter case, the user 5 may carry the device to be authenticated 2, for example, in a pocket or a bag.
[0026] The authentication request, which is a radio wave, may be, for example, a pulse wave transmitted intermittently or a continuous wave transmitted continuously. Furthermore, any wireless communication standard may be used to transmit and receive the authentication request. For example, the authentication request may be communicated via Bluetooth Low Energy (BLE), Bluetooth Basic Rate (BR) / Enhanced Data Rate (EDR), wireless LAN (IEEE802.11), IEEE802.15.4 such as ZigBee (registered trademark), or any other wireless communication standard. It is preferable that the authentication request be transmitted and received via short-range wireless communication such as BLE, Bluetooth BR / EDR, or wireless LAN.
[0027] The frequency of the radio wave of the authentication request is not particularly limited, and may be, for example, a frequency in the range of 300 MHz to 300 GHz. Furthermore, the device to be authenticated 2 may transmit the authentication request by broadcast or by unicast, for example. Transmitting the authentication request by broadcast is preferable because it allows the authentication request to be transmitted without specifying the communication partner. In this embodiment, a case where the device to be authenticated 2 transmits the authentication request by broadcast will be mainly described. It is preferable that the device to be authenticated 2 transmits the authentication request without receiving a transmission instruction from the user 5. The device to be authenticated 2 may transmit the authentication request in response to receiving a predetermined beacon, for example. This beacon may be transmitted in an area where authentication using the authentication request is performed. As an example, the authentication device 1 may transmit a beacon. In this case, the authentication device 1 may further include a transmitter that transmits the beacon.
[0028] The user identifier may be, for example, a sequence of at least one of letters, numbers, and symbols unique to the user, or a device identifier that identifies the device to be authenticated 2 may be used as the user identifier. The device identifier may be, for example, an address such as the physical address of the device to be authenticated 2, a telephone number, or a sequence of at least one of letters, numbers, and symbols unique to the device. The user identifier may be, for example, encrypted and included in the authentication request, or may be included in the authentication request in plain text.
[0029] The authentication information may include any information that can be used to authenticate the device to be authenticated 2. For example, the authentication information may include cryptographic information obtained by encrypting unique information, which is unique information. The unique information may include, for example, a time, a random number, a count value, or a one-time password. The unique information may be information specific to an authentication request. That is, the unique information corresponding to the cryptographic information included in each authentication request may be different. The unique information may be, for example, information generated by the device to be authenticated 2 or information transmitted from the authentication device 1 to the device to be authenticated 2. In the latter case, challenge-response authentication may be performed by the authentication device 1. When the unique information is transmitted from the authentication device 1, the authentication device 1 may further include a transmitting unit that transmits the unique information. This embodiment mainly describes the case where the unique information is generated by the device to be authenticated 2. Like the cryptographic information described above, it is preferable that the authentication information includes different information for each authentication request. This is to prevent the authentication information from being reused by a malicious third party. Furthermore, for example, the cryptographic information may be information obtained by encrypting a user identifier and unique information. In this case, the encryption information may be considered to be information including, for example, a user identifier and authentication information.
[0030] The encryption of the unique information may be, for example, encryption using a common key encryption or encryption using a public key encryption. That is, the encryption key used to encrypt the unique information may be, for example, a common key or a public key corresponding to the authentication device 1. When the encryption key is a common key, it is preferable that the authentication device 1 and the device to be authenticated 2 have the same common key. It is also preferable that the common key is different for each device to be authenticated 2.
[0031] The receiving unit 11 may include a first receiver set 21 including one or more receivers 23 that receive an authentication request transmitted from the device to be authenticated 2, and a second receiver set 22 including one or more receivers 24 that receive the authentication request. This embodiment will mainly describe this case. When the receiving unit 11 includes the first receiver set 21 and the second receiver set 22, the authentication request may also be used to identify the location of the device to be authenticated 2. The first receiver set 21 may be located at a first location. Furthermore, the second receiver set 22 may be located at a second location different from the first location. From the viewpoint of realizing more accurate location identification of the device to be authenticated 2, it is preferable that the first receiver set 21 include a plurality of first receivers 23, and the second receiver set 22 include a plurality of second receivers 24. 1, for example, the first receiver set 21 may include four first receivers 23, and the second receiver set 22 may include four second receivers 24, but the number of receivers included in the first and second receiver sets 21, 22 may be any number from one to three, or may be five or more. Each of the receivers 23, 24 included in the first and second receiver sets 21, 22 is capable of acquiring the intensity of radio waves or sound waves of an authentication request.
[0032] When the first receiver set 21 includes a plurality of first receivers 23, the first position may be, for example, the position of the center of gravity of the plurality of first receivers 23. More specifically, the position of the center of gravity of each first receiver 23 may be identified, and the position of the center of gravity of the identified plurality of center of gravity may be set as the first position. The plurality of first receivers 23 may be located, for example, close to each other, or may be located at distant locations. Even in the latter case, it is preferable that the plurality of first receivers 23 are included within a range of the distance from the first position to the second position. The same applies to the second position of the second receiver set 22.
[0033] The receiving unit 11 may include a wireless receiving device such as an antenna for receiving radio waves, or may include a receiving device such as a microphone for receiving sound waves, or may not include a receiving device. The receiving unit 11 may be realized by hardware, or may be realized by software such as a driver that drives the receiving device.
[0034] The device authenticator 12 performs device authentication using authentication information included in the authentication request received by the receiver 11 to determine whether the device to be authenticated 2 that sent the authentication request is legitimate. For example, if the authentication information includes cryptographic information in which unique information is encrypted, the device to be authenticated 2 that sent the authentication information may be determined to be legitimate if the unique information corresponding to the cryptographic information matches the unique information stored in the authentication device 1 and corresponding to the device to be authenticated 2 that sent the authentication information. Otherwise, the device authenticator 12 may be determined to be invalid. Whether the unique information corresponding to the cryptographic information matches the unique information stored in the authentication device 1 may be determined, for example, by whether the unique information obtained by decrypting the cryptographic information matches the unique information stored in the authentication device 1, or by whether the cryptographic information matches the result of encrypting the unique information stored in the authentication device 1.
[0035] When the unique information is acquired in the device to be authenticated 2, the unique information stored in the authentication device 1 may be, for example, acquired by the same method as that of the device to be authenticated 2. Furthermore, when the device to be authenticated 2 receives the unique information from the authentication device 1, the unique information stored in the authentication device 1 may be, for example, the unique information transmitted from the authentication device 1 to the device to be authenticated 2.
[0036] When the cryptographic information included in the authentication information is encrypted with a common key, the device authentication unit 12 may, for example, read from the storage unit 15 the common key that is stored together with the authentication information in association with the user identifier included in the authentication information, and decrypt the cryptographic information using the read common key, or may use the read common key to encrypt the unique information stored in the authentication device 1. When the cryptographic information included in the authentication information is encrypted with a public key, the device authentication unit 12 may, for example, read from the storage unit 15 a private key and decrypt the cryptographic information using the read private key, or may read from the storage unit 15 a public key and encrypt the unique information stored in the authentication device 1 using the read public key.
[0037] The device authentication unit 12 may perform device authentication using one authentication request, or may perform device authentication using multiple authentication requests received within a predetermined period. For authentication using multiple authentication requests, see, for example, the following document: Literature: International Publication No. WO2020 / 080301
[0038] The identification unit 13 identifies the location of the authenticated device 2 based on the strength difference of the authentication requests received by the first and second receiver sets 21 and 22, respectively. The strength difference of the authentication requests may be, for example, the difference in received signal strength (RSSI: Received Signal Strength Indicator) of the authentication requests. Furthermore, if the first and second receiver sets 21 and 22 include two or more receivers, the strength difference may be, for example, the difference between representative values of multiple received signal strengths acquired by the two or more receivers in the first and second receiver sets 21 and 22, respectively. The representative value may be, for example, an average value, a median value, or the like. Furthermore, if the first and second receiver sets 21 and 22 include two or more receivers, it is preferable that the two or more receivers have equivalent performance. For example, it is preferable that the antenna gains of the two or more receivers included in the first receiver set 21 or the second receiver set 22 are the same. When determining the location of the wave source using the intensity difference of the received authentication request, for example, an Apollonius circle or line corresponding to the difference in reception intensity can be determined using the reception intensity of the authentication request received by the first and second receiver sets 21, 22 and the first and second positions of the first and second receiver sets 21, 22, and the position on the Apollonius circle, line, or within the circle can be determined as the location of the device to be authenticated 2, or the location of the device to be authenticated 2 can be determined by other methods.
[0039] Furthermore, the position identified by the identification unit 13 may be, for example, a point-like position, or a linear, planar, or three-dimensional position. In this embodiment, a case where a point-like position of the device to be authenticated 2 is identified by the identification unit 13 will be mainly described. The identified position may be, for example, a position on a two-dimensional plane or a position in three-dimensional space. In this embodiment, the former case will mainly be described. FIG. 2 is a plan view showing an area R1 where the device to be authenticated 2 may be present. As an example, the area R1 may be an area where a user 5 passing through a ticket gate may be present. The identification unit 13 may, for example, identify a position P1 of the device to be authenticated 2 in the area R1 based on the strength difference between the authentication requests received by the first and second receiver sets 21 and 22, respectively.
[0040] Since the method of determining the location of a wave source using the difference in the received intensity of radio waves or sound waves is already known, a detailed description thereof will be omitted. For such a method of determining the location of a wave source, please refer to the following document, for example: Literature: International Publication No. 2020 / 080314
[0041] The biometric information acquiring unit 14 acquires biometric information of a user carrying the device to be authenticated 2. The biometric information acquiring unit 14 may acquire biometric information of a user carrying the device to be authenticated 2 located at a position identified by the identifying unit 13, for example. Biometric authentication using the biometric information acquired by the biometric information acquiring unit 14 may be authentication using an individual's physical characteristics or authentication using an individual's behavioral characteristics. The biometric authentication is not particularly limited, and may be, for example, at least one of facial authentication, biometric authentication using height, biometric authentication using stride length, biometric authentication using weight, skeletal authentication using bone structure, iris authentication, fingerprint authentication, and voice authentication. The biometric authentication is preferably authentication that acquires biometric information without contact, such as facial authentication, but may also be authentication that acquires biometric information through contact, such as fingerprint authentication. In this embodiment, a case where the biometric authentication is facial authentication will be mainly described.
[0042] The biometric information acquired by the biometric information acquisition unit 14 is preferably information corresponding to the biometric authentication performed by the biometric authentication unit 16. For example, when face authentication is performed by the biometric authentication unit 16, it is preferable that the biometric information acquisition unit 14 acquires biometric information that is a face image or biometric information that is information on feature quantities corresponding to the face image.
[0043] When the biometric information acquisition unit 14 acquires biometric information using a captured image acquired by the photographing unit 7, the biometric information may be, for example, a partial image of the captured image (e.g., an image of the face or an image of the iris), or may be information on features acquired from a partial image of the captured image (e.g., information on the features of the face or the features of the iris).
[0044] The biometric information acquiring unit 14 may acquire biometric information using, for example, a captured image captured by the imaging unit 7. The captured image may be an image of an area where the authenticated device 2, which is the sender of the authentication request received by the receiving unit 11, may be located. FIG. 3 is a diagram showing an example of a captured image. The captured image in FIG. 3 may be an image captured in an area R1 near an automatic ticket gate. Assume that users 5a to 5c carry authenticated devices 2a to 2c, respectively, and that authentication requests are transmitted from these authenticated devices 2a to 2c. As shown in FIG. 2, if the position P1 of the authenticated device 2a on a two-dimensional plane is identified by the identifying unit 13 using the authentication request transmitted from the authenticated device 2a, the biometric information acquiring unit 14 identifies a circular area R2 of a predetermined radius centered on the identified position P1 in the captured image. The radius may be, for example, 30 centimeters, 50 centimeters, or 80 centimeters. The biometric information acquisition unit 14 may then identify an image PH1 of the face region of the user 5a where part of the body is within the identified region R2, and acquire biometric information, which is facial feature quantities of the user 5a, from the identified image PH1. Note that, although the present embodiment describes a case where the biometric information is facial feature quantities, the biometric information may also be an image of the face. Similarly, for users 5b and 5c, the identification unit 13 may identify the positions of the authenticated devices 2b and 2c, and acquire the biometric information of users 5b and 5c based on the identified positions.
[0045] The biometric information acquisition unit 14 may acquire the biometric information, which is the height of the user 5, for example, using a captured image, a distance measurement sensor, or other sensing results. When measuring the height using a distance measurement sensor, for example, the height of the user 5 may be acquired by measuring the distance from the ceiling to the top of the head of the user 5 using one or more distance measurement sensors arranged on the ceiling, and subtracting the distance from the ceiling to the top of the head from the distance from the floor to the ceiling.
[0046] Furthermore, the biometric information acquisition unit 14 may acquire biometric information, which is the stride length of the user 5, using, for example, a captured image, a pressure sensor disposed on the floor, or other sensing results. When acquiring the stride length using a captured image, the captured image may be a moving image. The biometric information acquisition unit 14 may then identify the position where the foot touches the ground in the captured image. When acquiring the stride length using a pressure sensor, the biometric information acquisition unit 14 may identify the position where the foot of the user 5 touches the ground according to the position of the pressure sensor where the pressure becomes high, and identify the stride length of the user 5 using the position of the pressure sensor.
[0047] Furthermore, the biometric information acquiring unit 14 may acquire the biometric information, which is the weight of the user 5, using, for example, a weight sensor placed on the floor surface, or may acquire the information using other sensing results.
[0048] Furthermore, the biometric information acquisition unit 14 may acquire biometric information indicating the skeleton of the user 5, for example, by using a captured image. Methods for acquiring a person's skeleton by using a captured image are already known, and detailed explanations thereof will be omitted. Note that when the biometric information is information indicating the skeleton of the user 5, the captured image may be a still image or a moving image. In the latter case, biometric information indicating changes in the skeleton over time may be acquired by using the captured image, which is a moving image.
[0049] Furthermore, the biometric information acquisition unit 14 may acquire biometric information, which is information about the iris of the user 5, by using, for example, a captured image. In this case, the image capture unit 7 is preferably positioned so that it can capture an image of the user 5 from the front, so as to be able to capture an image of the iris of the user 5. In other words, it is preferable that the captured image be acquired so that the optical axis of the image capture unit 7 is in the line of sight of the user 5. Note that, when iris authentication is performed, the user 5 may be instructed to look in the direction of the image capture unit 7.
[0050] Furthermore, the biometric information acquisition unit 14 may acquire biometric information, which is information about the fingerprint of the user 5, using, for example, a fingerprint sensor. In this case, an instruction may be given to the user 5 to read the fingerprint using the fingerprint sensor.
[0051] Furthermore, the biometric information acquisition unit 14 may acquire biometric information, which is information about the voice of the user 5, using, for example, a microphone. In this case, the user 5 may be instructed to speak. This voice may be, for example, a predetermined voice or any voice.
[0052] The storage unit 15 stores a plurality of pieces of correspondence information. The correspondence information is information that associates a user identifier that identifies the user 5 with registered biometric information, which is biometric information of the user 5. When the registered biometric information is information acquired using a captured image, similar to the biometric information acquired by the biometric information acquisition unit 14, the registered biometric information may be, for example, a partial image of the captured image (e.g., a face image or an iris image), or may be feature information acquired from a partial image of the captured image (e.g., information on face feature information or information on iris feature information). The registered biometric information stored in the storage unit 15 is preferably information corresponding to biometric authentication performed by the biometric authentication unit 16. For example, when face authentication is performed by the biometric authentication unit 16, the storage unit 15 preferably stores registered biometric information that is a face image or registered biometric information that is feature information acquired from a face image.
[0053] FIG. 4 is a diagram showing an example of multiple pieces of correspondence information stored in the storage unit 15. As shown in FIG. 4, the correspondence information may be information including a user identifier and registered biometric information. In this case, the user identifier and registered biometric information included in one piece of correspondence information may be associated with each other. For example, the registered biometric information of a user identified by a user identifier "U001" (hereinafter, also referred to as "user U001") is "B001." When the biometric authentication is face authentication, this registered biometric information "B001" may be, for example, a face image or information on features acquired from a face image.
[0054] The process by which the correspondence information is stored in the storage unit 15 is not important. For example, the correspondence information may be stored in the storage unit 15 via a recording medium, or the correspondence information transmitted via a communication line or the like may be stored in the storage unit 15. Information other than the correspondence information may also be stored in the storage unit 15. For example, an encryption key, a decryption key, unique information, etc. used in device authentication may be stored in the storage unit 15. The storage unit 15 is preferably realized by a non-volatile recording medium, but may also be realized by a volatile recording medium. The recording medium may be, for example, a semiconductor memory, a magnetic disk, etc.
[0055] The biometric authentication unit 16 performs biometric authentication to determine whether the user 5 from whom the biometric information was acquired is legitimate, using the registered biometric information associated by the correspondence information with the user identifier included in the authentication request received by the receiving unit 11 and the biometric information acquired by the biometric information acquisition unit 14. As described above, this biometric authentication may be, for example, at least one of face authentication, biometric authentication using height, biometric authentication using stride length, biometric authentication using weight, skeletal authentication using bone structure, iris authentication, fingerprint authentication, and voice authentication.
[0056] The order in which device authentication and biometric authentication are performed does not matter. For example, biometric authentication may be performed after device authentication, or biometric authentication may be performed after device authentication, or both may be performed in parallel. When biometric authentication is performed after device authentication, for example, biometric authentication may be performed only when the device authentication is determined to be valid. In other words, if the device authentication is determined to be invalid, biometric authentication may not be performed. This embodiment mainly describes this case. When biometric authentication is performed after the device authentication is determined to be valid, the biometric authentication unit 16 may perform biometric authentication using the biometric information acquired by the biometric information acquisition unit 14 of the user 5 carrying the device to be authenticated 2 located at a position identified using the authentication request when the device authentication is determined to be valid using the authentication information included in the authentication request received by the receiving unit 11. The biometric authentication may be performed using the registered biometric information associated by correspondence information with the user identifier included in the authentication request transmitted from the device to be authenticated 2 determined to be valid in the device authentication, and the biometric information acquired by the biometric information acquisition unit 14. For example, if the biometric authentication is face authentication, the biometric authentication unit 16 compares the facial feature information acquired by the biometric information acquisition unit 14 or the facial feature information acquired from the image acquired by the biometric information acquisition unit 14 with the facial feature information indicated by the registered biometric information or the facial feature information acquired from the image that is the registered biometric information. If the two match, the biometric authentication unit 16 determines that the user 5 whose biometric information is acquired is legitimate. If the two do not match, the biometric authentication unit 16 determines that the user 5 is not legitimate. Note that the facial feature information matching may be, for example, an exact match or a match with a predetermined tolerance. In the latter case, the two may be determined to match when the similarity exceeds a threshold. Note that biometric authentication methods are already known, and detailed description thereof will be omitted.
[0057] Here, because the biometric authentication unit 16 performs biometric authentication of the user 5 carrying the device to be authenticated 2, the accuracy of the biometric authentication performed by the biometric authentication unit 16 does not need to be very high. This is because biometric authentication can be performed with a narrower target. For example, the accuracy of the biometric authentication performed by the biometric authentication unit 16 may be lower than the accuracy required to authenticate an individual using only biometric information. Therefore, the registered biometric information stored in the storage unit 15 may be information sufficient to perform biometric authentication with such accuracy. As a result, information that does not easily identify an individual can be used as the registered biometric information. For example, registered biometric information indicating height can be used. This makes it possible to store the registered biometric information locally in the authentication device 1, thereby enabling optimal real-time biometric authentication. Furthermore, performing biometric authentication with lower accuracy can, for example, enable biometric authentication to be performed in a shorter time. This is because, for example, a smaller number of feature values need to be compared.
[0058] The output unit 17 outputs the result of device authentication by the device authentication unit 12 and the result of biometric authentication by the biometric authentication unit 16. It is preferable that this output allows the user to know whether both the device authentication and the biometric authentication have been determined to be valid, or whether at least one of them has been determined to be invalid. Therefore, for example, the output may indicate that the authenticated device 2 has been determined to be valid or invalid by device authentication, and that the user 5 has been determined to be valid or invalid by biometric authentication. For example, the output unit 17 may output an authentication result indicating whether both the device authentication and the biometric authentication have been determined to be valid, or whether at least one of them has been determined to be invalid. Furthermore, the output unit 17 may output the authentication result only when both the device authentication and the biometric authentication have been determined to be valid. In other words, if at least one of the device authentication and the biometric authentication has been determined to be invalid, the authentication result need not be output. Furthermore, if biometric authentication is performed after device authentication has been determined to be valid, the result of the biometric authentication is output, indicating that device authentication has been determined to be valid. Therefore, in this case, the output unit 17 may output only the result of the biometric authentication. The result of the authentication may be output together with, for example, a user identifier that identifies the user 5 who is the subject of authentication. This user identifier may be, for example, the user identifier included in the authentication request.
[0059] Here, this output may be, for example, a display on a display device (e.g., a liquid crystal display or an organic EL display), a transmission to a predetermined device via a communication line, a printing by a printer, an audio output by a speaker, storage on a recording medium, or a transfer to another component. Note that output unit 17 may or may not include a device that performs output (e.g., a display device or a communication device). Also, output unit 17 may be realized by hardware, or may be realized by software such as a driver that drives such a device.
[0060] Next, the operation of the authentication device 1 will be described with reference to the flowchart of FIG. (Step S101) The receiving unit 11 determines whether or not an authentication request has been received. If an authentication request has been received, the process proceeds to step S102; if not, the process of step S101 is repeated until an authentication request is received.
[0061] (Step S102) The device authentication unit 12 performs device authentication using the received authentication request. When performing device authentication using multiple authentication requests, for example, the authentication requests may be continuously received until a predetermined period has elapsed since the first authentication request was received, and device authentication may be performed using the multiple authentication requests received during that predetermined period.
[0062] (Step S103) If it is determined in the device authentication in step S102 that the authenticated device 2 that sent the authentication request is valid, the process proceeds to step S104, and if not, the process proceeds to step S107.
[0063] (Step S104) The identification unit 13 uses the received authentication request to identify the location of the authenticated device 2. When multiple authentication requests are received, the location of the authenticated device 2 may be identified using the authentication request received closest to the time when the biometric information is acquired, for example, the last authentication request received.
[0064] (Step S105) The biometric information acquiring unit 14 acquires biometric information of the user 5 who is carrying the device to be authenticated 2 that is located at the position identified in step S104.
[0065] (Step S106) The biometric authentication unit 16 performs biometric authentication using the registered biometric information associated with the user identifier included in the received authentication device and the biometric information acquired in step S105.
[0066] (Step S107) The output unit 17 outputs the result of the biometric authentication in step S106. In the flowchart of Fig. 5, biometric authentication is performed only when the device authentication is determined to be authentic, so that the output of the result of biometric authentication indirectly indicates that the device authentication is authentic. Note that if the biometric authentication in step S106 is not performed, that is, if the authenticated device 2 is determined to be invalid in the device authentication, the output unit 17 may output the result of the device authentication. Then, the process returns to step S101.
[0067] The processing order in the flowchart of Fig. 5 is an example, and the order of each step may be changed as long as the same results can be obtained. For example, the location of the authenticated device 2 may be identified before device authentication. Also, device authentication may be performed after biometric authentication. Also, in the flowchart of Fig. 5, the processing may end due to an interrupt such as power off or processing end.
[0068] Next, the operation of the authentication device 1 according to this embodiment will be described using a specific example. In this specific example, it is assumed that the biometric authentication is face authentication. It is also assumed that a plurality of pieces of correspondence information shown in FIG. 4 are stored in the memory unit 15. In this specific example, it is assumed that the registered biometric information is information on feature amounts acquired from a captured image of the face area of the user 5. It is also assumed in this specific example that authentication is performed at a ticket gate.
[0069] First, assume that user U001 enters an automatic ticket gate while carrying device to be authenticated 2, which is a smartphone. Device to be authenticated 2 then receives a beacon transmitted by the automatic ticket gate, generates authentication information in response to the beacon, and transmits an authentication request including the generated authentication information and the user identifier "U001."
[0070] The authentication request sent from the device to be authenticated 2 of user U001 is received by the first and second receiver sets 21, 22 of the authentication device 1, respectively, and the authentication request is passed to the device authentication unit 12, and the received signal strength of the authentication request by the multiple first receivers 23 possessed by the first receiver set 21 and the received signal strength of the authentication request by the multiple second receivers 24 possessed by the second receiver set 22 are passed to the identification unit 13 (step S101).
[0071] Upon receiving the authentication request, the device authentication unit 12 performs device authentication using the authentication information included in the authentication request (step S102). Assume that this device authentication determines that the authenticated device 2 is legitimate (step S103). Then, the device authentication unit 12 passes information that the authenticated device 2 is legitimate to the identification unit 13 and the biometric information acquisition unit 14, and passes information that the authenticated device 2 is legitimate and the user identifier "U001" included in the received authentication request to the biometric authentication unit 16.
[0072] Upon receiving the received signal strength and the result of device authentication, the identification unit 13 acquires a representative value of the received signal strength acquired by the plurality of first receivers 23 and a representative value of the received signal strength acquired by the plurality of second receivers 24, and identifies the location of the authenticated device 2 using the difference between the representative values of the received signal strength and the first and second positions that are the positions of the first and second receiver sets 21, 22 (step S104). The identified location is assumed to be position P1 shown in FIG. 2. The position P1 is passed to the biometric information acquisition unit 14.
[0073] Upon receiving the device authentication result and the identified position P1, the biometric information acquisition unit 14 uses the captured image acquired by the imaging unit 7 at that time to identify an area R2 of a predetermined radius centered on the position P1, as shown in Figures 2 and 3. The biometric information acquisition unit 14 also identifies the user 5a present in the area R2, identifies an image PH1 of the face area of the identified user 5a, and acquires biometric information, which is information on features used in face authentication, from the identified image PH1 and passes it to the biometric authentication unit 16 (step S105). Note that the user 5a is user U001.
[0074] Upon receiving the device authentication result, the user identifier, and the biometric information, the biometric authentication unit 16 searches for the multiple pieces of correspondence information shown in FIG. 4 using the received user identifier "U001" as a search key, and reads out the registered biometric information "B001" included in the first matched piece of correspondence information from the storage unit 15. The biometric authentication unit 16 then performs biometric authentication using the registered biometric information "B001" and the received biometric information (step S106). Assume that this biometric authentication finds that the similarity between the two exceeds a threshold, and that user U001 is determined to be authentic. The biometric authentication result and the user identifier "U001" are then passed to the output unit 17.
[0075] Upon receiving the biometric authentication result, the output unit 17 transmits the biometric authentication result and the user identifier to a management system that manages the entry and exit of the user 5 (step S107). As a result, for example, the system may manage that the user U001 has entered or exited the ticket gate at a predetermined station. In the latter case, for example, the management system may perform a process of charging the user U001 the fare from the station where the user U001 entered the ticket gate to the station where the user U001 exited the ticket gate.
[0076] In this specific example, if the device authentication determines that the device is not legitimate, for example, if the user 5 is using an unauthorized device to be authenticated 2, or if a user 5 who is not the original user of the device to be authenticated 2 is carrying the device to be authenticated 2, and as a result the device is determined to be invalid by biometric authentication, a message to that effect may be sent to the management system. Then, for example, the user 5 may be prevented from entering the ticket gate.
[0077] Finally, examples of devices and systems in which the authentication device 1 according to this embodiment is implemented will be briefly described.
[0078] The authentication device 1 may be incorporated into an automatic ticket gate. When the authentication device 1 determines that both the device authentication and the biometric authentication are valid based on an authentication request transmitted from a nearby device to be authenticated 2 and biometric information of a user 5 carrying the device to be authenticated 2, the gate of the automatic ticket gate may open, allowing the user to enter or exit the ticket gate. Furthermore, the user may be charged when entering or exiting the ticket gate. In this way, for example, the user may be able to ride a train or the like without operating a smartphone or the like, which is the device to be authenticated 2.
[0079] The authentication device 1 may be incorporated into a vending machine for drinks or the like. After a user operates the purchase button on the vending machine, the authentication device 1 determines that both the device authentication and the biometric authentication are valid based on an authentication request transmitted from a nearby device to be authenticated 2 and biometric information of the user 5 carrying the device to be authenticated 2. If this determines that both the device authentication and the biometric authentication are valid, the vending machine may provide the user with a product such as a drink corresponding to the purchase button operated by the user. In addition, the user may be charged appropriately depending on the processing. In this way, for example, the user can purchase a product from the vending machine without operating a smartphone or the like, which is the device to be authenticated 2.
[0080] The authentication device 1 may be installed near the entrance of an event venue such as a concert, sporting event, or seminar, or an art gallery, museum, theme park, sports club, or members-only lounge. When the authentication device 1 determines that both the device authentication and the biometric authentication are valid based on an authentication request transmitted from a nearby device to be authenticated 2 and biometric information of a user 5 carrying the device to be authenticated 2, the authentication device 1 may output, at a specified location on the device to be authenticated 2, a display of information about a ticket or the like (e.g., information about the type of ticket or information about the pre-registered ticket owner) corresponding to a user identified by a user identifier included in the authentication request. Event staff can identify people entering through the entrance who do not possess a ticket or membership card by viewing the display. Note that the staff may request that people without a ticket or the like present their ticket or the like. In this way, for example, a user can enter an event venue, museum, sports club, or the like without operating a smartphone or the like serving as the device to be authenticated 2.
[0081] The authentication device 1 may be incorporated into a cash register in a store. Then, for example, after a user or a store clerk operates the payment button on the cash register, the authentication device 1 determines that both the device authentication and the biometric authentication are valid based on an authentication request sent from a nearby device to be authenticated 2 and biometric information of the user 5 carrying the device to be authenticated 2, and then charges a pre-registered payment method (e.g., credit card, electronic money, etc.) according to the purchase amount. In this way, for example, the user can purchase goods and the like at a store without operating a smartphone or the like that is the device to be authenticated 2.
[0082] The authentication device 1 may be incorporated into a device that requires identity authentication, such as a PC (Personal Computer) or an ATM (Automated Teller Machine). For example, after a user operates a device such as a PC or an ATM, the authentication device 1 determines that both the device authentication and the biometric authentication are valid based on an authentication request transmitted from a nearby device to be authenticated 2 and biometric information of a user 5 carrying the device to be authenticated 2. For example, the user identified by the user identifier included in the authentication request may log in to a PC, a website operated on the PC, or withdraw cash from an ATM. In this way, for example, the user can be authenticated on a device such as a PC or an ATM and can operate the device without having to enter a personal identification number or the like.
[0083] The authentication device 1 according to this embodiment can also be used in situations other than those described above. For example, it may be used for authentication in car sharing, rental cars, airplane boarding procedures, etc. It may also be used for user authentication when operating equipment such as a personal computer.
[0084] As described above, the authentication device 1 according to the present embodiment performs device authentication, thereby preventing impersonation of another person. For example, if an authentication request contains only a user identifier, a malicious third party who obtains another person's user identifier can transmit an authentication request containing the obtained user identifier to the authentication device 1 and impersonate the user identified by the user identifier. However, since the authentication request also contains authentication information and device authentication is performed using the authentication information, such impersonation can be prevented. Furthermore, by performing biometric authentication together with device authentication, appropriate personal authentication can be performed without necessarily requiring highly accurate biometric authentication. This is because the use of an authentication request can limit the users who undergo biometric authentication. Therefore, the accuracy of the biometric authentication performed by the biometric authentication unit 16 can be lower than that of biometric authentication that authenticates an individual using only biometric information. Therefore, information with a degree of accuracy that cannot identify an individual by itself, such as height or stride length, can be used as registered biometric information. As a result, it is possible to store the registered biometric information locally in the authentication device 1, thereby enabling optimal real-time biometric authentication. Furthermore, when the biometric authentication unit 16 performs biometric authentication with the same degree of accuracy as biometric authentication that uses only biometric information to authenticate an individual, the overall accuracy of authentication will be higher.
[0085] Furthermore, by performing biometric authentication in addition to device authentication, if an unauthorized user carries the device to be authenticated 2, the device will be determined to be unauthorized by the biometric authentication, thereby preventing unauthorized users from using the device to be authenticated 2. For example, if user B carries user A's device to be authenticated 2, it is possible to prevent user B from impersonating user A and entering an event venue such as a concert.
[0086] Furthermore, by acquiring biometric information using the position of the authenticated device 2 identified by the identification unit 13, it is possible to appropriately acquire the biometric information of the target user, thereby improving the accuracy of biometric authentication. Furthermore, by performing biometric authentication using biometric information that can be acquired contactlessly, such as face authentication, it is possible to achieve, for example, hands-free personal authentication, i.e., personal authentication that does not involve any operation by the user 5.
[0087] In the present embodiment, the receiving unit 11 has been mainly described as having two receiver sets, i.e., the first and second receiver sets 21 and 22. However, the receiving unit 11 may have three or more receiver sets. That is, the receiving unit 11 may have first to Nth receiver sets arranged at first to Nth positions, respectively. N is an integer equal to or greater than two. The first to Nth receiver sets may also be similar to the first and second receiver sets 21 and 22. For example, the Kth receiver set may include one or more receivers. K is an integer equal to any integer from 1 to N. It is preferable that the first to Nth positions are different from each other. Furthermore, when N is three or greater and the positions are identified by, for example, triangulation, it is preferable that the first to Nth positions do not lie on a single straight line. However, if this is not the case, the first to Nth positions may lie on a single straight line. Furthermore, when N is 4, for example, when the location is identified by triangulation or the like, it is preferable that the first to fourth positions are not the vertices of a parallelogram. However, if this is not the case, the first to fourth positions may be the vertices of a parallelogram. In this way, when the receiving unit 11 has first to N receiver sets, the identifying unit 13 may identify the location of the device to be authenticated 2 based on the intensity difference of the authentication requests received by the first to N receiver sets. Note that this location identification may be performed, for example, by repeatedly identifying an Apollonius circle or line based on the intensity difference of the authentication requests received by each of the two receiver sets for different combinations of two receiver sets among the first to N receiver sets, thereby identifying multiple Apollonius circles or lines, and identifying a position on the identified Apollonius circle, line, or within the circle as the location of the device to be authenticated 2, or by other methods.
[0088] Furthermore, in this embodiment, the case where the location of the device to be authenticated 2 is identified by the identification unit 13 has been mainly described, but this is not necessarily the case. When the location of the device to be authenticated 2 is not identified, the authentication device 1 may not include, for example, the identification unit 13, and the receiving unit 11 may not include the first and second receiver sets 21 and 22. That is, the receiving unit 11 may receive the authentication request using, for example, a single receiver. In this case, the biometric information acquiring unit 14 may acquire, for example, biometric information of a user 5 present in an area assumed to be the sender of the authentication request received by the receiving unit 11. When the device to be authenticated 2 transmits an authentication request in response to receiving a predetermined beacon, the area may be, for example, the reachable range of the predetermined beacon. Furthermore, when the location of the device to be authenticated 2 is not identified, the biometric information acquiring unit 14 may acquire, for example, biometric information of one or more users 5. When multiple pieces of biometric information are acquired, the biometric authentication unit 16 may determine that the user 5 whose biometric information is acquired is legitimate when at least one of the pieces of biometric information matches the registered biometric information associated with the user identifier included in the received authentication request. In this case, it may be difficult to acquire only the biometric information of the user 5 who carries the device to be authenticated 2 that sent the authentication request.
[0089] Furthermore, in the above embodiments, each process or function may be realized by centralized processing by a single device or a single system, or may be realized by distributed processing by multiple devices or multiple systems.
[0090] Furthermore, in the above embodiments, the transfer of information between components may be performed, for example, by one component outputting information and the other component receiving information if the two components transferring the information are physically different, or by moving from a processing phase corresponding to one component to a processing phase corresponding to the other component if the two components transferring the information are physically the same.
[0091] Furthermore, in the above-described embodiments, information related to the processing performed by each component, such as information accepted, acquired, selected, generated, transmitted, or received by each component, and information such as thresholds, formulas, and addresses used in processing by each component, may be temporarily or long-term stored in a recording medium (not shown), even if not explicitly stated in the above description. Furthermore, the storage of information in the recording medium (not shown) may be performed by each component or a storage unit (not shown). Furthermore, the reading of information from the recording medium (not shown) may be performed by each component or a reading unit (not shown).
[0092] Furthermore, in the above-described embodiments, if the information used by each component, such as thresholds, addresses, and various setting values used by each component in processing, may be changed by the user, the user may or may not be able to change the information as appropriate, even if not explicitly stated in the above description. If the information is changeable by the user, the change may be realized, for example, by a receiving unit (not shown) that receives a change instruction from the user and a changing unit (not shown) that changes the information in accordance with the change instruction. The change instruction may be received by the receiving unit (not shown), for example, from an input device, by receiving information transmitted via a communication line, or by receiving information read from a predetermined recording medium.
[0093] Furthermore, in the above embodiment, when two or more components included in the authentication device 1 have a communication device, an input device, etc., the two or more components may have a single physical device or may have separate devices.
[0094] Furthermore, in the above-described embodiments, each component may be configured by dedicated hardware, or a component that can be realized by software may be realized by executing a program. For example, each component may be realized by a program execution unit such as a CPU reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. During execution, the program execution unit may execute the program while accessing a storage unit or recording medium. The software that realizes the authentication device 1 in the above-described embodiments is the following program. In other words, this program may be a program for causing a computer that can access a storage unit that stores multiple pieces of correspondence information that associate a user identifier that identifies a user with registered biometric information that is the user's biometric information, to execute the following steps: receiving an authentication request sent from the device to be authenticated, the authentication request including a user identifier that identifies a user carrying the device to be authenticated and authentication information used to authenticate the device to be authenticated; performing device authentication using the authentication information included in the received authentication request to determine whether the device to be authenticated that sent the authentication request is legitimate; acquiring biometric information of the user carrying the device to be authenticated; performing biometric authentication to determine whether the user whose biometric information is acquired is legitimate, using the registered biometric information that is associated by correspondence information with the user identifier included in the authentication request received in the step of receiving the authentication request and the biometric information acquired in the step of acquiring biometric information; and outputting the result of the device authentication in the step of performing device authentication and the result of the biometric authentication in the step of performing biometric authentication.
[0095] In addition, in the above program, the steps of receiving information, acquiring information, outputting information, etc. do not include processing that can only be performed by hardware, such as processing performed by a communication device in the receiving step, or processing performed by a communication device or display device in the output device.
[0096] This program may be executed by being downloaded from a server or the like, or by being read from a predetermined recording medium (for example, an optical disk such as a CD-ROM, a magnetic disk, or a semiconductor memory). This program may also be used as a program constituting a program product.
[0097] Furthermore, the computer that executes this program may be a single computer or multiple computers, and may perform centralized processing or distributed processing.
[0098] 6 is a diagram showing an example of a computer system 900 that executes the above program to realize the authentication device 1 according to the above embodiment. The above embodiment can be realized by computer hardware and a computer program executed thereon.
[0099] 6, the computer system 900 includes an MPU (Micro Processing Unit) 911, a ROM 912 such as a flash memory that stores programs such as a boot-up program, application programs, system programs, and data, a RAM 913 connected to the MPU 911 and that temporarily stores instructions for the application program and provides temporary storage space, a touch panel 914, a wireless communication module 915, and a bus 916 that interconnects the MPU 911, the ROM 912, and the like. The computer system 900 may include, for example, multiple wireless communication modules 915 corresponding to the first and second receiver sets 21 and 22, or may be connected to multiple wireless communication modules corresponding to the first and second receiver sets 21 and 22. The computer system 900 may also include a display and input devices such as a mouse and a keyboard instead of the touch panel 914. The computer system 900 may also include other storage media such as a hard disk.
[0100] A program that causes the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment may be stored in the ROM 912 via the wireless communication module 915. The program is loaded into the RAM 913 when executed. The program may also be loaded directly from the network.
[0101] The program does not necessarily include an operating system (OS) or a third-party program that causes the computer system 900 to execute the functions of the authentication device 1 according to the above embodiment. The program may include only instructions that call appropriate functions or modules in a controlled manner to achieve the desired results. How the computer system 900 operates is well known, and a detailed description thereof will be omitted.
[0102] Furthermore, the above-described embodiments are merely examples for specifically implementing the present invention, and are not intended to limit the technical scope of the present invention. The technical scope of the present invention is defined by the claims, not by the description of the embodiments, and is intended to include modifications within the literal scope of the claims and within the scope of equivalent meanings. [Explanation of symbols]
[0103] 1 Authentication device 2, 2a~2c Authenticated device 5, 5a~5c users 11 Receiving unit 12 Device authentication unit 13 Specific section 14 Biometric information acquisition unit 15 Storage section 16 Biometric authentication unit 17 Output section 21 First Receiver Set 22 Second receiver set 23 First Receiver 24 Second Receiver
Claims
1. a receiving unit that receives an authentication request transmitted from the device to be authenticated, the authentication request including a user identifier that identifies a user carrying the device to be authenticated and authentication information used to authenticate the device to be authenticated; a device authentication unit that performs device authentication by using authentication information included in the authentication request received by the receiving unit to determine whether the device to be authenticated that has transmitted the authentication request is legitimate; a biometric information acquisition unit that acquires biometric information of a user carrying the device to be authenticated; a storage unit that stores a plurality of pieces of correspondence information that associate a user identifier that identifies a user with registered biometric information that is biometric information of the user; a biometric authentication unit that performs biometric authentication by using registered biometric information associated with a user identifier included in the authentication request received by the receiving unit by the correspondence information and the biometric information acquired by the biometric information acquisition unit to determine whether the user whose biometric information has been acquired is legitimate; an output unit that outputs a result of device authentication by the device authentication unit and a result of biometric authentication by the biometric authentication unit.
2. The receiving unit a first receiver set including one or more first receivers; a second receiver set including one or more second receivers, the second receiver set being located at a different location from the first receiver set; and a determination unit that determines the location of the authenticatee based on a difference in strength of the authentication requests received by the first and second receiver sets, respectively. The authentication device according to claim 1 , wherein the biometric information acquisition unit acquires biometric information of a user carrying the device to be authenticated that is located at the position identified by the identification unit.
3. 3. The authentication device according to claim 1, wherein the biometric authentication is face authentication.
4. 3. The authentication device according to claim 1, wherein the biometric authentication is at least one of biometric authentication using height, biometric authentication using stride length, and iris authentication.
5. 3. The authentication device according to claim 1, wherein the accuracy of the biometric authentication performed by the biometric authentication unit is lower than the accuracy when authenticating an individual using only biometric information.
6. 3. The authentication device according to claim 1, wherein the receiving unit receives the authentication request as a radio wave.
7. An authentication method performed using a receiving unit, a device authentication unit, a biometric information acquisition unit, a storage unit that stores a plurality of pieces of correspondence information that associate a user identifier that identifies a user with registered biometric information that is biometric information of the user, a biometric authentication unit, and an output unit, a step in which the receiving unit receives an authentication request transmitted from the device to be authenticated, the authentication request including a user identifier that identifies a user carrying the device to be authenticated and authentication information used to authenticate the device to be authenticated; a step in which the device authentication unit performs device authentication by using authentication information included in the received authentication request to determine whether the device to be authenticated that has sent the authentication request is legitimate; a step in which the biometric information acquisition unit acquires biometric information of a user carrying the device to be authenticated; a step in which the biometric authentication unit performs biometric authentication to determine whether the user whose biometric information has been acquired is legitimate, using registered biometric information associated with the user identifier included in the authentication request received in the step of receiving the authentication request by the association information and the biometric information acquired in the step of acquiring the biometric information; an output unit outputting a result of the device authentication in the step of performing the device authentication and a result of the biometric authentication in the step of performing the biometric authentication.
8. A computer that can access a storage unit that stores a plurality of pieces of correspondence information that associate a user identifier that identifies a user with registered biometric information that is biometric information of the user, receiving an authentication request transmitted from the device to be authenticated, the authentication request including a user identifier identifying a user carrying the device to be authenticated and authentication information used to authenticate the device to be authenticated; performing device authentication using authentication information included in the received authentication request to determine whether the authenticated device that has sent the authentication request is legitimate; acquiring biometric information of a user carrying the device to be authenticated; performing biometric authentication to determine whether the user whose biometric information has been acquired is legitimate, using registered biometric information associated with the user identifier included in the authentication request received in the step of receiving the authentication request by the correspondence information and the biometric information acquired in the step of acquiring the biometric information; and a step of outputting a result of the device authentication in the step of performing the device authentication and a result of the biometric authentication in the step of performing the biometric authentication.
Citation Information
Patent Citations
Information processing system, information processing apparatus, authentication method, and program
JP2017151709A
Authentication system and authentication method
WO2020158860A1
Notification system, notification method, and computer program for notification
WO2020203302A1
Benefit information issuing device, system, and method, and computer-readable medium
WO2024024012A1
Authentication device, authentication method, authentication system, and program
JP2022180831A