Authority determination system, authority determination method, authority determination program, and management server

The authority determination system uses a management server to remotely manage authorization information, enabling efficient and accurate user rights determination through short-range wireless communication and biometric verification, addressing the challenge of updating and managing rights information on authentication terminals.

JP2025177741APending Publication Date: 2025-12-05PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024084813
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-24
Publication Date
2025-12-05

AI Technical Summary

Technical Problem

Existing authentication terminals face difficulties in efficiently updating and managing authority determination information, making it challenging to determine user rights accurately.

Method used

An authority determination system that utilizes a management server to perform authorization decisions based on authority and reservation information stored remotely, eliminating the need for local storage on authentication terminals, and incorporates biometric verification through short-range wireless communication with user terminals.

Benefits of technology

Enables efficient and accurate user authorization without requiring authentication terminals to store rights determination information, reducing complexity and improving the speed of decision-making.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025177741000001_ABST
    Figure 2025177741000001_ABST
Patent Text Reader

Abstract

To provide an authority determination system, an authority determination method, an authority determination program, and a management server capable of performing authority determination without storing authority determination information in an authentication terminal.SOLUTION: An authority determination system comprises an authentication terminal 7 capable of short-range wireless communication with a user terminal 5 associated with each user; a service provider apparatus 6; and a management server 8. The service provider apparatus is configured to be able to provide the management server with authority determination information regarding services associated with each of the authentication terminals and authorization information regarding reservations for services associated with each of the users. When the authentication terminal and the user terminal are capable of short-range wireless communication, the management server is configured to perform a determination process to determine whether or not authority exists based on the authority determination information corresponding to the authentication terminal and authorization information of a user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.SELECTED DRAWING: Figure 17
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an authority determination system, an authority determination method, an authority determination program, and a management server for determining whether a user is authorized to use a service provided by a service provider. [Background technology]

[0002] Conventionally, there is known an authentication terminal that provides predetermined services to users who have been successfully authenticated (see Patent Document 1). When the authentication terminal and a user terminal carried by a user become capable of communicating via short-range wireless communication, the authentication terminal acquires first biometric information of the user from the terminal carried by the user via short-range wireless communication. Furthermore, the authentication terminal acquires second biometric information of the user by photographing the user who has arrived at the authentication terminal. Thereafter, the authentication terminal executes a matching process using the first biometric information and the second biometric information.

[0003] Next, the authentication terminal acquires authentication data by specifying authentication data necessary for determining whether to provide a service to the user and requesting the user terminal to transmit the specified authentication data. After that, the authentication terminal determines that the authentication process of the user has been successful if the result of the matching process using the first biometric information and the second biometric information is successful and the authentication data acquired from the user terminal is valid.

[0004] The authentication data is used to determine whether or not the person attempting authentication satisfies the requirements for using the service (i.e., whether or not the person has the authority to use the service). Patent Document 1 gives an example of authentication data such as a vaccination certificate that must be presented when checking in at an airport or the like. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Patent No. 7151944 Summary of the Invention [Problem to be solved by the invention]

[0006] In Patent Document 1, an authentication terminal determines whether or not a user has authority to use a service (hereinafter referred to as authority determination).

[0007] However, in order to perform rights determination in an authentication terminal, it may be necessary to set various information required for the rights determination (hereinafter referred to as rights determination information) in the authentication terminal. In particular, when the rights determination information is frequently updated, it is difficult to appropriately set the rights determination information in each authentication terminal.

[0008] Therefore, the main object of the present disclosure is to provide an authority determination system, an authority determination method, an authority determination program, and a management server that can perform authority determination without storing authority determination information in an authentication terminal. [Means for solving the problem]

[0009] The authority determination system disclosed herein is an authority determination system for determining whether a user is authorized to use a service provided by a service provider, and includes an authentication terminal capable of short-range wireless communication with a user terminal associated with each user, a service provider device managed by the service provider, and a management server connected to the authentication terminal and the service provider device, wherein the service provider device is configured to provide the management server with authority determination information regarding the service associated with each of the authentication terminals and authorization information regarding reservations for the service associated with each of the users, and when the authentication terminal and the user terminal become capable of short-range wireless communication, the management server is configured to perform a determination process to determine whether or not the user has authority based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

[0010] The authority determination method disclosed herein is an authority determination method for determining whether a user is granted authority to use a service provided by a service provider, and is implemented by an authority determination system comprising an authentication terminal capable of short-range wireless communication with a user terminal associated with each user, a service provider device managed by the service provider, and a management server connected to the authentication terminal and the service provider device, wherein the service provider device is configured to be able to provide the management server with authority determination information regarding the service associated with each of the authentication terminals and authorization information regarding reservations for the service associated with each of the users, and when the authentication terminal and the user terminal become capable of short-range wireless communication, the management server is configured to perform a determination process to determine whether or not authority exists based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

[0011] The authority determination program disclosed herein is an authority determination program for determining whether a user has the authority to use a service provided by a service provider, and is executed by an authority determination system including an authentication terminal capable of short-range wireless communication with a user terminal associated with each user, a service provider device managed by the service provider, and a management server connected to the authentication terminal and the service provider device, wherein the service provider device is configured to be able to provide the management server with authority determination information regarding the service associated with each of the authentication terminals and authorization information regarding reservations for the service associated with each of the users, and when the authentication terminal and the user terminal become capable of short-range wireless communication, the management server is configured to perform a determination process to determine whether or not the user has the authority based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

[0012] The management server of the present disclosure is a management server for determining whether a user has the authority to use a service provided by a service provider, and is configured to be able to communicate with an authentication terminal capable of short-range wireless communication with a user terminal associated with each user, and a service provider device managed by the service provider and configured to provide authority determination information regarding the service associated with each of the authentication terminals and authorization information regarding reservations for the service associated with each of the users, and is configured to perform a determination process to determine whether or not a user has the authority, when the authentication terminal and the user terminal are capable of short-range wireless communication, based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal. [Effects of the Invention]

[0013] According to the present disclosure, it is possible to provide a rights determination system, a rights determination method, a rights determination program, and a management server that can perform rights determination without storing rights determination information in an authentication terminal. [Brief explanation of the drawings]

[0014] [Figure 1] FIG. 1 is an overall configuration diagram of a user authentication system including an authority determination system according to an embodiment. [Figure 2] User terminal configuration diagram [Figure 3] Operator server configuration diagram [Figure 4] Functional block diagram of the provider's server [Figure 5] Authentication terminal configuration diagram [Figure 6] Functional block diagram of authentication terminal [Figure 7] Management server configuration diagram [Figure 8] Management server functional block diagram [Figure 9] Sequence diagram showing the process flow for registering businesses on the integrated platform [Figure 10]Sequence diagram showing the process flow for user registration on the integrated platform [Figure 11] Sequence diagram showing the process flow for requesting collaboration with a business operator's server [Figure 12] Sequence diagram showing the process flow for registering an authentication device to the integrated platform [Figure 13] Sequence diagram showing the process flow for registering service content to the provider's server [Figure 14] A sequence diagram showing the process flow of the user authentication system when a user makes a reservation. [Figure 15] A sequence diagram showing a modified example of the flow of processing performed by the user authentication system when a user makes a reservation. [Figure 16] A sequence diagram showing the process flow of the user authentication system when setting up an authentication terminal. [Figure 17] A sequence diagram showing the processing performed by the user authentication system during user authentication up to the transmission of an authentication permission signal. [Figure 18] A sequence diagram showing the processing performed by the user authentication system during user authentication after an authentication permission signal is transmitted. [Figure 19] Example data of (A) authentication terminal database and (B) user reservation database according to a first application example of a user authentication system [Figure 20] Example data of (A) authentication terminal database and (B) user reservation database relating to a second application example of the user authentication system [Figure 21] Example data of (A) authentication terminal database and (B) user reservation database relating to the third application example of the user authentication system [Figure 22] Example data of (A) authentication terminal database and (B) user reservation database relating to the fourth application example of the user authentication system [Figure 23] 10 is a sequence diagram showing a modified example of a process flow for registering service content to a business server. [Figure 24]A modified example of a sequence diagram showing the flow of processing performed by the user authentication system when setting up an authentication terminal. DETAILED DESCRIPTION OF THE INVENTION

[0015] The first invention made to solve the above problem is an authority determination system for determining whether a user is authorized to use a service provided by a service provider, comprising: an authentication terminal capable of short-range wireless communication with a user terminal associated with each user; a service provider device managed by the service provider; and a management server connected to the authentication terminal and the service provider device, wherein the service provider device is configured to be able to provide the management server with authority determination information regarding the service associated with each of the authentication terminals and authorization information regarding reservations for the service associated with each of the users, and wherein when the authentication terminal and the user terminal become capable of short-range wireless communication, the management server is configured to perform a determination process to determine whether or not the user has authority based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

[0016] According to this system, the management server determines whether or not a person is authorized to use the service, and therefore, an authorization determination system can be provided that can perform authorization determination without requiring the authentication terminal to store information for determining whether the person attempting authentication satisfies the requirements.

[0017] In addition, the second invention is configured such that, when the authentication terminal becomes capable of short-range wireless communication with the user terminal, it transmits authentication terminal identification information to the user terminal to identify the authentication terminal, and the user terminal transmits the user identification information of the user corresponding to itself and the authentication terminal identification information acquired from the authentication terminal to the management server, and when the management server acquires the authentication terminal identification information and the user identification information from the user terminal, it executes the judgment process based on the authority judgment information of the authentication terminal corresponding to the authentication terminal identification information acquired from the user terminal and the authorization information of the user corresponding to the user identification information acquired from the user terminal.

[0018] This allows the management server to determine whether or not the user corresponding to the user terminal is authorized to use the service.

[0019] In addition, a third invention is configured such that the authentication terminal is equipped with a sensor that acquires biometric information, the user terminal stores the associated biometric information of the user, and when it is determined in the judgment process that the user has authority, the authentication terminal performs authentication by a matching process that compares the biometric information acquired by the sensor of the authentication terminal with the biometric information stored in the user terminal.

[0020] This allows the authentication terminal to verify the user only when it is determined that the user corresponding to the user terminal has authority.

[0021] In addition, a fourth aspect of the present invention is configured such that the authentication terminal transmits a result of the matching process to the user terminal and the management server.

[0022] This allows the user to be notified of the matching result via the user terminal, allowing the user to check the matching result. Also, the matching result can be stored in the management server, allowing the administrator who manages the management server to check the matching result.

[0023] In addition, a fifth aspect of the present invention is configured such that, after completing the matching process, the authentication terminal erases the two pieces of biometric information used in the matching process from its own memory.

[0024] This allows the biometric information to be managed appropriately.

[0025] In addition, the sixth invention is configured such that the authority determination information corresponds to the content of the service provided, the authorization information corresponds to the reservation content of the service for the user corresponding to the user terminal, and the management server determines that authority exists when the reservation content matches or is included in the content of the service provided.

[0026] This makes it easy to determine whether or not an authority exists.

[0027] In addition, a seventh invention is configured such that the management server is configured to be able to store multiple pieces of authority determination information and multiple pieces of authorization information in advance before the user terminal and the authentication terminal become capable of short-range wireless communication.

[0028] This allows the management server to manage a plurality of pieces of rights decision information and a plurality of pieces of authorization information, and also reduces the time required for rights decision.

[0029] In addition, an eighth invention is an authority determination method for determining whether a user is authorized to use a service provided by a service provider, which is implemented by an authority determination system comprising: an authentication terminal capable of short-range wireless communication with a user terminal associated with each user; a service provider device managed by the service provider; and a management server connected to the authentication terminal and the service provider device, wherein the service provider device is configured to be able to provide the management server with authority determination information regarding the service associated with each of the authentication terminals and authorization information regarding reservations for the service associated with each of the users, and wherein, when the authentication terminal and the user terminal become capable of short-range wireless communication, the management server is configured to perform a determination process to determine whether or not the user has authority based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

[0030] According to this method, the management server determines whether or not the person is authorized to use the service, and therefore, it is possible to provide an authorization determination method that can perform authorization determination without storing information in the authentication terminal for determining whether the person attempting authentication satisfies the requirements.

[0031] A ninth invention is an authority determination program for determining whether a user has the authority to use a service provided by a service provider, the program being executed by an authority determination system comprising an authentication terminal capable of short-range wireless communication with a user terminal associated with each user, a service provider device managed by the service provider, and a management server connected to the authentication terminal and the service provider device, the service provider device being configured to be able to provide the management server with authority determination information regarding the service associated with each of the authentication terminals and authorization information regarding reservations for the service associated with each of the users, and the management server being configured to perform a determination process to determine whether or not the user has the authority, when the authentication terminal and the user terminal are capable of short-range wireless communication, based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

[0032] According to this, the management server determines whether or not the person is authorized to use the service. Therefore, it is possible to provide an authorization determination program that can perform authorization determination without storing information in the authentication terminal for determining whether the person attempting authentication satisfies the requirements.

[0033] A tenth aspect of the present invention is a management server for determining whether a user has authority to use a service provided by a service provider, the management server comprising: an authentication terminal capable of short-range wireless communication with a user terminal associated with each user; connected to a service provider device that is managed by the service provider and configured to be able to provide authority decision information related to the service associated with each of the authentication terminals and authorization information related to reservations for the service associated with each of the users; When the authentication terminal and the user terminal become capable of short-range wireless communication, a determination process is performed to determine whether or not authority exists based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

[0034] This makes it possible to provide a management server that can make authority decisions without requiring the authentication terminal to store information for determining whether a person attempting authentication satisfies the requirements.

[0035] In addition, the 11th invention is configured such that, in the 9th invention, the authority determination information corresponds to the content of the service to be provided, the authorization information corresponds to the reservation content of the service for the user corresponding to the user terminal, and when the user reserves a service, the reservation content is sent in bulk to the user terminal corresponding to the user.

[0036] This allows the reservation details to be sent to the user terminal all at once when reserving a service.

[0037] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.

[0038] As shown in FIG. 1, the right determination system 1 constitutes a part of a system (user authentication system 2) for performing user authentication in order to provide a service.

[0039] The user authentication system 2 provides a plurality of services to the user, which may be provided by a single service provider, or may be provided to the user by a plurality of different service providers.

[0040] Services provided to users include, for example, sales of tickets for concerts, live shows, and movie theaters, use of various facilities such as live venues, accommodations, conference rooms, and transportation, medical examinations and treatments at hospitals, guarantees or provision of credit for credit sales, sales of various products, permission to log in to specific websites, rental cars, and rental of various facilities and goods, etc. A service provider is a business that provides at least one of these services, and includes, for example, providers of live venues and concert organizers.

[0041] The user authentication system 2 provides a single environment (integrated platform) that serves as the foundation for providing various functions to multiple service providers. Specifically, the functions provided by the user authentication system 2 include user authentication when using a service.

[0042] The user authentication provided by the user authentication system 2 includes two types of authentication: first authentication and second authentication. The first authentication determines whether a user has the authority to use a service provided by a service provider (hereinafter referred to as authority determination). The authority determination is performed, for example, by determining whether authorization information related to a service reservation associated with each user is consistent (also referred to as a match) with authority information related to the service provided by the service provider. The second authentication confirms whether a person attempting to use a service is the user who has been determined to be authorized by the authority determination. The second authentication can be performed using various types of biometric information. The authority determination system 1 executes an authority determination program to implement an authority determination method, execute a process related to authority determination (also referred to as a determination process or authority determination process), and perform the first authentication. Note that the authority determination system 1 may also perform the second authentication in addition to the first authentication.

[0043] The user authentication system 2 includes a user terminal 5 (an example of a user terminal 5) carried by each user, a provider server 6 (an example of a service provider device) that performs processing to provide services to users, an authentication terminal 7 (an example of an authentication terminal 7, also referred to as an authentication device) that authenticates users, and a management server 8 (an example of a management server 8, also referred to as a management device) that manages processing for user authentication (user authentication processing). The user terminal 5, provider server 6, authentication terminal 7, and management server 8 are connected to each other so as to be able to communicate with each other via a communication network 9 that is configured from the Internet, a LAN (Local Area Network), etc.

[0044] For the sake of convenience, the following description will be given of an example in which the user authentication system 2 includes one provider server 6. The provider server 6 is managed by one service provider. However, the number of service providers using the user authentication system 2 and the number of provider servers 6 managed by those service providers may be changed as appropriate.

[0045] The management server 8 is managed by the operator of the integrated platform. However, the business operator server 6 may also be managed by the operator of the integrated platform.

[0046] 1 shows only one user terminal 5, the user authentication system 2 may include more user terminals 5. In other words, the user authentication system 2 may be used by multiple users.

[0047] Similarly, the user authentication system 2 may include one or more authentication terminals 7. Each of the authentication terminals 7 may be managed by a service provider, or may be managed by the person who operates the user authentication system 2.

[0048] The authentication terminal 7 may be configured to be capable of controlling various devices for making services available to users. For example, if the service is selling tickets for a concert or movie theater, the authentication terminal 7 may be configured to be capable of controlling the opening and closing of gate devices 10 installed at the concert venue or movie theater. Alternatively, if the service is the use of accommodation facilities, the authentication terminal 7 may be installed near the entrance door of each guest room and may be configured to be capable of controlling the opening and closing of the entrance door. If the service is the use of public transportation, the authentication terminal 7 may be configured to be capable of controlling the opening and closing of a ticket gate, which is one type of gate device 10.

[0049] The following describes a first application example in which the user authentication system 2 is used to provide a specific service, namely, permission to enter a live venue, to a user from among multiple services provided to the user. Permission to enter the live venue is granted to the user by the authentication terminal 7 controlling the opening and closing of a gate device 10 installed at the entrance to the venue.

[0050] <User device> Each user holds (carries) a user terminal 5, which is associated with the user. As shown in Fig. 1, the user terminal 5 may be configured as an information device having various communication functions including short-range communication, such as a smartphone, a tablet terminal, or a PC.

[0051] As shown in FIG. 2, the user terminal 5 may include known hardware such as a processor 5A (CPU, MPU, etc.), memory 5B (RAM, ROM, etc.), a touch panel display 5C, a network interface 5D, and storage 5E.

[0052] The user terminal 5 is equipped with a biometric information acquisition device 5F that acquires biometric information for biometric authentication of a user. The biometric information acquisition device 5F includes a sensor that acquires biometric information required for biometric authentication of a user. The biometric information acquired by the sensor is information required to identify a person and is used for facial authentication, iris authentication, vein authentication, fingerprint authentication, etc., and in this embodiment, is configured by a camera 5G that acquires images required for facial authentication.

[0053] Each user can carry out procedures such as applying to use the user authentication system 2 by communicating with the management server 8 via the user terminal 5 that the user carries. Each user can install an application program for using the user authentication system 2 on the user terminal 5. The application program may be provided by store distribution on the integrated platform, or may be provided to the integrated platform directly from the site of the management company.

[0054] When applying to use a service provided by a service provider, the user terminal 5 obtains from the provider server 6 a user identification number for the service provider (hereinafter referred to as a business user ID) that allows the service provider (i.e., the provider server 6) to identify the user who is using the user terminal 5.

[0055] When applying to use the user authentication system 2, the user terminal 5 obtains from the management server 8 a user identification number (hereinafter referred to as PF user ID) for authentication purposes to identify the user who is using the user terminal 5 on the integrated platform (integrated PF), and a user terminal identification number (hereinafter referred to as user terminal ID) to identify the user terminal 5.

[0056] The business user ID is assigned to each user by each business operator, and is different for each business operator even for the same user. On the other hand, the PF user ID is not dependent on the business operator, and one PF user ID is assigned to each user on the integrated platform.

[0057] Furthermore, each user terminal 5 is assigned a unique identification number (hereinafter referred to as a terminal ID) in advance for identifying the user terminal 5.

[0058] When applying to use the user authentication system 2, the user terminal 5 acquires biometric information of the user who holds (carries) the user terminal 5 using the camera 5G. The acquired biometric information is used for the second authentication of the user. In this embodiment, the biometric information is facial data such as the user's facial image and facial features, and the user terminal 5 (processor 5A) acquires an image including the user's facial portion (hereinafter referred to as a facial image) using the camera 5G and extracts the facial features as corresponding facial data. The user terminal 5 associates the facial data (extracted facial features) with the PF user ID and stores them in the storage 5E. Note that the user terminal 5 may store the facial image acquired by the camera 5G together with the user identification number in the storage 5E instead of the facial features.

[0059] In addition, by communicating with the provider server 6 via the user terminal 5, the user can carry out procedures to reserve (apply for) the provision of services from each service provider (for example, reserving or applying for use of a service).

[0060] <Provider server> As shown in FIG. 3, the business server 6 may be configured as a computer equipped with known hardware such as a processor 6A (CPU, MPU, etc.), memory 6B (RAM, ROM, etc.), a display 6C, an input device 6D, a network interface 6E, and storage 6F.

[0061] The provider server 6 (an example of a service provider device) is managed by the service provider. The provider server 6 executes various processes for providing the service provider's services to users. The processes executed by the provider server 6 include processes related to user registration and processes related to accepting reservations for services.

[0062] 4, the provider server 6 includes, as functional units, a storage unit 11, a user registration unit 12, a link reception unit 13, an identification information management unit 14, a service registration unit 15, a service information providing unit 16, a reservation reception unit 17, and a reservation information providing unit 18. The storage unit 11 is mainly composed of a memory 6B and a storage 6F, and the user registration unit 12, the link reception unit 13, the identification information management unit 14, the service registration unit 15, the service information providing unit 16, the reservation reception unit 17, and the reservation content providing unit can each be configured by the processor 6A executing a predetermined program.

[0063] The storage unit 11 stores various types of information required for executing the service provision process. The information stored in the storage unit 11 includes user information 11A, linkage information 11B, business operator identification information 11C, service information 11D, and user reservation information 11E.

[0064] User information 11A is information related to a user, and stores a business user ID and personal information of the user corresponding to the business user ID in association with each other. The personal information stored in user information 11A may include, for example, the user's name, address, email address, and information related to the user's attributes, such as age and gender.

[0065] The PF user ID and the business user ID are recorded in association with each other in the association information 11B. The association information 11B is used to associate the business user ID with the PF user ID.

[0066] The business operator identification information 11C is information for identifying a business operator (hereinafter referred to as a business operator ID), and is assigned to each service business operator on the integrated platform and used to identify the service business operator. When the service business operator registers for use of the integrated platform with the management server 8, the business operator ID is generated for each business operator by the management server 8 and transmitted to the business operator server 6.

[0067] Service information 11D is information relating to one or more services provided by a service provider, and stores an identification number of the service provided by the provider to the user (hereinafter referred to as service ID), information indicating the content of the service provided corresponding to each service ID (hereinafter referred to as service content information), and information indicating the content of the service content information that can be reserved by the user (hereinafter referred to as reservation availability information) in association with each other.

[0068] The service content information indicates the content of the service provided by the operator. For example, if the service provided by the operator is Live A to be held at Tokyo Dome on March 1, 2023 at 6:00 PM, the service content information may be set to "Tokyo Dome Live A on March 1, 2023 at 6:00 PM."

[0069] The reservation information indicates the content of the services that users can reserve. Users use all or part of the services provided by the business operator. Therefore, the content of the services included in the reservation information is included in the service content information.

[0070] The user reservation information 11E is information related to a user's service reservation, and includes the business user ID of the user who made the reservation and the reservation details of the service reserved by the user (hereinafter referred to as reservation details information). For example, if the service reserved by the user is Live A to be held at Tokyo Dome on March 1, 2023 at 6:00 PM, the reservation details information may be set to "Tokyo Dome Live A on March 1, 2023 at 6:00 PM." In addition, the user reservation information 11E may include an identification number (hereinafter referred to as reservation ID) for identifying each service reservation.

[0071] The user selects and reserves one or more of the services that the user can reserve, and therefore at least one of the reservation availability information included in the service information 11D is set in the reservation content information.

[0072] The reservation content information indicates the content of the service that the user is authorized to use, and is therefore also called authorization information. Note that the first authentication is performed by determining whether the user's reservation content matches or is included in the content of the service provided by the service provider. In other words, the service content information is information for determining whether the user has authorization to use the service, and is also called authorization determination information.

[0073] The user registration unit 12 accepts input of user information 11A from the user at the user terminal 5, acquires the user information 11A input from the user terminal 5, and stores it in the storage unit 11.

[0074] The collaboration reception unit 13 executes collaboration processing for collaborating the PF user ID and the business user ID. The collaboration reception unit 13 acquires the PF user ID and the business user ID from the user terminal 5, associates the PF user ID and the business user ID, and stores the association information 11B in the storage unit 11.

[0075] When the identification information management unit 14 acquires the business ID from the management server 8, it stores the business ID in the storage unit 11.

[0076] The service registration unit 15 receives input of service content information and reservation availability information from the service provider (more specifically, the administrator or operator of the service provider), and stores it in the storage unit 11 as service information 11D.

[0077] The service registration unit 15 receives input of information from the service provider for identifying the authentication terminal 7 that should control the opening and closing of the gate device 10 in accordance with the service content information. The service registration unit 15 associates the received information for identifying the authentication terminal 7 with the service content information included in the service information 11D and transmits the information to the management server 8.

[0078] The service information providing unit 16 transmits the service information 11D stored in the storage unit 11 to the management server 8, and provides the service information 11D to the management server 8. As a result, the business server 6 is configured to be able to provide the management server 8 with service content information (rights determination information) associated with each authentication terminal 7.

[0079] The reservation receiving unit 17 acquires information relating to a reservation for use of a service from a user, and executes a reservation receiving process to store the information in the storage unit 11 as user reservation information 11E.

[0080] In the reservation acceptance process, the reservation acceptance unit 17 transmits reservation availability information to the user terminal 5 and causes the user terminal 5 to accept the user's selection. At this time, the reservation acceptance unit 17 may use the reservation availability information to cause the user terminal 5 to display a list of contents that the user can reserve and accept the user's selection.

[0081] When the user selects one or more pieces of reservation available information on the user terminal 5, the user terminal 5 transmits the selected one or more pieces of reservation available information to the reservation reception unit 17 together with the business user ID as reservation content information.

[0082] When the reservation reception unit 17 acquires the business user ID and the reservation content information, it associates the business user ID with the reservation content information and stores them as user reservation information 11E in the storage unit 11. Furthermore, the reservation reception unit 17 acquires a PF user ID corresponding to the business user ID based on the link information 11B, transmits the reservation content information together with the PF user ID to the management server 8, and associates the PF user ID with the reservation content information and stores them as user reservation information 11E. Thereafter, the reservation reception unit 17 (or the management server 8) transmits a notification to the user terminal 5 that the reservation has been completed, and upon receiving the notification, the user terminal 5 displays on the touch panel that the reservation has been completed.

[0083] In this way, the reservation information providing unit 18 transmits the user reservation information 11E stored in the storage unit 11 to the management server 8, and provides the user reservation information 11E to the management server 8. As a result, the business server 6 is configured to be able to provide reservation content information (authorization information) associated with each user.

[0084] <Authentication terminal> As shown in FIG. 1, the authentication terminal 7 is provided near the gate device 10, and performs second authentication using biometric information to verify that the person using the service is a legitimate user.

[0085] As shown in Figures 1 and 5, the authentication terminal 7 comprises a box-shaped housing 21, a biometric information acquisition device 22 supported by the housing 21, a display device 23 supported by the housing 21, and an authentication control device 24 housed within the housing 21.

[0086] The biometric information acquisition device 22 may be configured with a sensor that acquires biometric information required for biometric authentication of a user. In this embodiment, the biometric information acquisition device 22 is configured with a camera 22A that acquires images required for face authentication, and is supported on the top of the housing 21.

[0087] The display device 23 displays various information to notify the user. In this embodiment, the display device 23 is configured as a touch panel display.

[0088] As shown in FIG. 5, the authentication control device 24 may be configured by a microcomputer equipped with known hardware such as a processor 24A (CPU, MPU, etc.), memory 24B (RAM, ROM, etc.), a communication interface 24C, and storage 24D.

[0089] 6, the authentication control device 24 has a network communication unit 31, a short-range communication unit 32, a storage unit 33, and a control unit 34. The network communication unit 31 and the short-range communication unit 32 are mainly constituted by a communication interface 24C, and the storage unit 33 may be mainly constituted by a memory 24B and / or a storage 24D. The control unit 34 may be mainly constituted by the processor 24A executing a predetermined program.

[0090] The network communication unit 31 communicates with other devices (such as the business server 6 and the user terminal 5) wirelessly or via wired lines in accordance with a known communication protocol.

[0091] The short-range communication unit 32 performs short-range wireless communication with other devices (e.g., the user terminal 5) located near the authentication terminal 7 in accordance with a known communication protocol. The short-range communication unit 32 is configured to be able to communicate only with other devices located within a short distance, within a range of several tens of meters, more preferably within a range of several meters. In this embodiment, the short-range communication unit 32 communicates with other devices using Bluetooth (registered trademark). However, the short-range communication unit 32 may also communicate based on other communication standards (e.g., Wi-Fi) as long as wireless communication is possible only when the communication partner is located in a short distance. For example, the short-range communication unit 32 may include an NFC (Near Field Communication) reader / writer capable of reading and writing information from an IC chip or the like incorporated in the user terminal 5.

[0092] The short-range communication unit 32 periodically (e.g., once every few seconds) wirelessly transmits a beacon signal within a predetermined range in order to establish communication with other nearby communication devices (e.g., the user terminal 5, etc.). The range over which the beacon signal is transmitted is preferably a few meters or less. When a communication device receives a beacon signal, it transmits a response signal containing a Bluetooth address (a number assigned to each Bluetooth (registered trademark) device) to the authentication terminal 7 (short-range communication unit 32), thereby establishing short-range communication between the communication device and the authentication terminal 7.

[0093] The storage unit 33 stores an authentication terminal identification number (hereinafter referred to as authentication terminal ID). The authentication terminal ID is an identification number assigned to each authentication terminal 7, and is used to identify each authentication terminal 7 in the integrated platform. In addition, the storage unit 33 temporarily stores various information for performing processes required during biometric authentication.

[0094] The control unit 34 includes an authentication terminal registration unit 41, a request unit 42, a biometric authentication unit 43, and a gate control unit 44. The authentication terminal registration unit 41, the request unit 42, the biometric authentication unit 43, and the gate control unit 44 can each be configured by the processor 24A executing a predetermined program.

[0095] The authentication terminal registration unit 41 executes an authentication terminal registration process for registering each authentication terminal 7 as an authentication terminal 7 of the user authentication system 2. The service provider can use the authentication terminal 7 to perform operations for registering the authentication terminal in the user authentication system 2. Alternatively, the service provider may be configured to be able to use the provider server 6 or a terminal that the service provider uses to perform operations for registering the authentication terminal in the user authentication system 2. After the authentication terminal registration process is completed, the authentication terminal 7 becomes available as an authentication terminal 7 of the user authentication system 2.

[0096] By executing the authentication terminal registration process, the authentication terminal registration unit 41 stores the authentication terminal ID in the storage unit 33 and also transmits it to the management server 8, where it is stored.

[0097] The authentication terminal ID may be generated by the authentication terminal registration unit 41 itself using the execution time of the authentication terminal registration process, etc. The authentication terminal 7 transmits the authentication terminal ID that it generated to the management server 8, and causes the management server 8 to store it.

[0098] Alternatively, the authentication terminal ID may be a unique number assigned to each authentication terminal 7 by the management server 8 or the like. In this case, the authentication terminal registration unit 41 acquires the authentication terminal ID from the management server 8 or the like in the authentication terminal registration process, and stores the authentication terminal ID in the storage unit 33 and also in the management server 8.

[0099] When executing the authentication terminal registration process, the authentication terminal registration unit 41 may accept input of a provider ID corresponding to a service provider that provides a service to be authenticated. At this time, the authentication terminal registration unit 41 may store the generated authentication terminal ID and provider ID in the storage unit 33, and may also transmit them to the management server 8 and store them in the management server 8.

[0100] When the short-range communication unit 32 is able to communicate with the user terminal 5 by short-range communication, the request unit 42 transmits the authentication terminal ID to the user terminal 5 and causes the user terminal 5 to transmit a determination request signal requesting the management server 8 to determine whether or not biometric authentication can be performed. When transmitting the determination request signal, the user terminal 5 transmits the received authentication terminal ID and the PF user ID of the user corresponding to itself to the management server 8, together with the determination request signal.

[0101] When the management server 8 receives the determination request signal, it executes a determination process to determine the authority. If the management server 8 determines in the determination process that the authority is present, it transmits an authentication permission signal to the user terminal 5 that transmitted the determination request signal, permitting the execution of the second authentication.

[0102] When the user terminal 5 receives the authentication permission signal, it transmits the biometric information (facial features) previously stored in the user terminal 5 at the time of user registration for the user authentication system 2 and a second authentication start command to the authentication terminal 7 via communication via the short-range communication unit 32.

[0103] When the biometric authentication unit 43 receives the second authentication start command, it starts the second authentication. Specifically, when the biometric authentication unit 43 receives the second authentication start command, it displays on the display unit that biometric authentication will be performed, and acquires an image (face image) including the user's face using the camera 22A. Then, the biometric authentication unit 43 acquires facial features from the image (face image) including the user's face using the camera 22A, and compares it with the biometric information (facial features) acquired from the user terminal 5. When the biometric authentication unit 43 determines that the user is the same person as the person in question (i.e., face authentication has been successful), it transmits a signal to the gate control unit 44 instructing the gate to open. The biometric authentication unit 43 further transmits the authentication result of the second authentication to the user terminal 5 and the management server 8, respectively.

[0104] When the biometric authentication unit 43 completes the process of matching the biometric information acquired from the user terminal 5 with the biometric information acquired by the camera 22A and completes the transmission of the authentication result to the user terminal 5 and the management server 8, it erases from its own memory the two pieces of biometric information (facial feature amounts) used for the matching. In this embodiment, after completing the process of matching (second authentication), the biometric authentication unit 43 deletes the facial feature amounts acquired from the user terminal 5, the facial image acquired by the camera 22A, and the facial feature amounts acquired from the facial image from the memory 24B and the storage 24D, regardless of the authentication result. The biometric authentication unit 43 further transmits a notification of the deletion to the user terminal 5.

[0105] The gate control unit 44 controls the opening and closing of the gate device 10. When the gate control unit 44 receives a signal instructing an opening operation, it controls the opening and closing of the gate device 10 so that only one person can pass through the gate device 10. When the gate control unit 44 receives a notification that face authentication has been successful, it may control the gate device 10 to open and close after a predetermined time has elapsed.

[0106] <Administration Server> As shown in FIG. 7, the management server 8 may be configured as a computer equipped with known hardware such as a processor 8A (CPU, MPU, etc.), memory 8B (RAM, ROM, etc.), display 8C, input device 8D, network interface 8E, and storage 8F.

[0107] The management server 8 mainly plays a role of managing the integrated platform. When providing services from the business server 6 or a terminal used by the business, the management server 8 executes various processes, including an authentication terminal setting process for setting the authentication terminal 7 and an authentication permission process for determining whether or not to execute the second authentication.

[0108] 8, the management server 8 has, as functional units, a storage unit 51, an authentication terminal setting unit 52, a reservation information management unit 53, and an authority determination unit 54 in order to execute the authentication terminal setting process and the determination process. The storage unit 51 is mainly constituted by the memory 8B and / or the storage 8F, and the authentication terminal setting unit 52, the reservation information management unit 53, and the authority determination unit 54 are mainly constituted by the processor 8A executing predetermined programs.

[0109] The storage unit 51 holds an authentication terminal database (hereinafter referred to as an authentication terminal DB) and a user reservation database (hereinafter referred to as a user reservation DB).

[0110] The authentication terminal DB stores, in association with each other, an authentication terminal ID and service content information (authority determination information) of a service for which the corresponding authentication terminal 7 should perform second authentication. In addition to the authentication terminal ID and the service content information, the authentication terminal DB may also store, in association with each other, an operator ID of a operator that provides a service corresponding to the service content information.

[0111] The user reservation DB stores a PF user ID and the reservation content information (also called authorization information) of the corresponding user in association with each other.

[0112] The authentication terminal setting unit 52 sets and manages the data recorded in the authentication terminal DB. When an authentication terminal ID is transmitted from the authentication terminal 7, the authentication terminal setting unit 52 records the authentication terminal ID in the authentication terminal DB. When the authentication terminal ID and the provider ID are transmitted from the authentication terminal 7, the authentication terminal setting unit 52 may record both of them together in the authentication terminal DB.

[0113] The authentication terminal setting unit 52 also executes an authentication terminal setting process, transmits the authentication terminal ID to the provider server 6 (service registration unit 15), and receives input from the service provider for associating service content information (rights determination information) with the authentication terminal ID. Thereafter, the authentication terminal setting unit 52 stores the received input in the provider server 6 (service registration unit 15) as service information 11D in the storage 6F (storage unit 51). Thereafter, the authentication terminal setting unit 52 transmits service information 11D including the authentication terminal ID and service content information to the provider server 6 (service information providing unit 16). As a result, the management server 8 (authentication terminal setting unit 52) ​​receives the rights determination information from the provider server 6.

[0114] When the authentication terminal setting unit 52 receives the service information 11D from the provider server 6, it associates the authentication terminal ID with the service content information and records them in the authentication terminal DB. As a result, the authentication terminal ID and the service content information (rights determination information) are stored in association with each other in the storage unit 51. Note that the service information 11D is transmitted from the provider server 6 (service information providing unit 16) before entry to the live venue begins (i.e., before short-range wireless communication becomes possible between the user terminal 5 and the authentication terminal 7).

[0115] In this embodiment, the authentication terminal DB stores an authentication terminal ID, service content information, and a provider ID in association with each other. When the authentication terminal setting unit 52 receives an input from the provider server 6, it stores the authentication terminal ID, service content information, and provider ID in association with each other in the authentication terminal DB.

[0116] The reservation information management unit 53 manages the data recorded in the user reservation DB. When user reservation information 11E including a PF user ID and reservation content information is transmitted from the business server 6 (reservation information providing unit 18), the reservation information management unit 53 records the PF user ID and the reservation content information in the user reservation DB in association with each other. As a result, the management server 8 (reservation information management unit 53) is provided with reservation content information (authorization information) from the business server 6. The storage unit 51 stores the PF user ID and the reservation content information in association with each other.

[0117] In addition, the user reservation information 11E (information linking the PF user ID with reservation content information) is sent from the business server 6 (reservation information provider 18) before entry to the live venue begins (i.e., before short-range wireless communication becomes possible between the user terminal 5 and the authentication terminal 7).

[0118] When the authority determining unit 54 receives the determination request signal, it executes a determination process to determine whether or not the authority is granted.

[0119] The authority determination unit 54 acquires the authentication terminal ID included in the determination request signal, and refers to the authentication terminal DB to extract service content information associated with the authentication terminal ID included in the determination request signal. Next, the authority determination unit 54 acquires the PF user ID included in the determination request signal, and refers to the user reservation DB to extract reservation content information associated with the PF user ID.

[0120] Thereafter, the authority determination unit 54 determines whether the extracted service content information (authority determination information) and the extracted reservation content information (authorization information) match. If the extracted service content information matches the extracted reservation content information or contains the extracted reservation content information, the authority determination unit 54 determines that the two match and that the first authentication is successful.

[0121] If the authority determining unit 54 determines that the first authentication is successful, it transmits an authentication permission signal permitting execution of the second authentication to the user terminal 5 that transmitted the received determination request signal.

[0122] In this embodiment, the management server 8 further includes an authentication result transfer unit. When the management server 8 receives the authentication result of the second authentication from the authentication terminal 7 (biometric authentication unit 43), it refers to the authentication terminal DB and acquires the business ID of the business that provides the service authenticated by the authentication terminal 7. Next, the authentication result transfer unit transmits the authentication result to the business server 6 corresponding to the business ID.

[0123] The management server 8 may include a bulk notification unit that notifies a user of the reservation details that the user has made in a lump sum. When the reservation information management unit 53 has completed recording the PF user ID and reservation detail information in the user reservation DB, the bulk notification unit extracts all reservation detail information corresponding to the PF user ID from the user reservation DB. The bulk notification unit then transmits all of the extracted reservation detail information to the user terminal 5 carried (held) by the user corresponding to the PF user ID, and the user terminal 5 displays all of the reservation detail information on the touch panel display 5C. Alternatively, the management server 8 may transmit the reservation details that the user has made to the user terminal 5 every time the user makes a reservation, and notify the user.

[0124] Next, referring to Fig. 9, the processing performed by the user authentication system 2 when the business server 6 is registered in the integrated platform will be described. Note that a description of the user's application for use to the business server 6 will be omitted, but it is assumed that the user terminal 5 acquires a business user ID and stores it in storage 5E when the user applies for use to the business server 6. It is also assumed that the business server 6 acquires the business user ID and the corresponding user terminal ID when the user applies for use to the business server 6 and stores them in storage 6F.

[0125] When a business operator who wishes to register with the business server 6 accesses the management server 8 using the business server 6, a business registration screen is displayed on the display 6C of the business server 6. The business registration screen includes input fields for contract information, business information, information indicating services that can be reserved by users (reservation available information), etc. When the business operator enters information into the input fields and presses the send button, the input information (hereinafter referred to as business registration information) is sent to the management server 8 (S101).

[0126] When the management server 8 receives the business registration information, it acquires the business ID (S102) and stores the business registration information in storage 8F in association with the business ID (S103). At this time, the management server 8 may specify the business server 6 in the business registration information and store the information required for sending and receiving information (such as the business server ID) in storage 8F. Thereafter, the management server 8 transmits the acquired business ID to the business server 6 (S104), and the business server 6 stores the acquired business ID in storage 6F (S105). Thereafter, the management server 8 displays a registration completion screen on the display 6C to notify the business that registration has been completed (S106).

[0127] Next, with reference to FIG. 10, a process performed by the user authentication system 2 when a user registers in the integrated platform will be described.

[0128] A user who wishes to register with the integrated platform downloads and installs a predetermined application as a preliminary step on the user terminal 5. After that, the user starts up the installed application on the user terminal 5 and executes it.

[0129] When the application is launched, the user terminal 5 (more specifically, the processor 5A of the user terminal 5) displays a usage registration application / consent acquisition screen on the touch panel (S201). The usage registration application / consent acquisition screen includes an input field for user information 11A and a send button. When the user enters information into the input field for user information 11A and touches the send button, the user terminal 5 transmits the user information 11A entered by the user to the management server 8 together with the user terminal ID of the user (S202).

[0130] The management server 8 (more specifically, the processor 8A of the management server 8) stores the received user information 11A in the storage 8F and performs user registration (registration for use in the integrated platform). Specifically, when recording the user registration in the storage 8F, the management server 8 generates a PF user ID corresponding to the user recorded in the user information 11A (S203), and stores it in the storage 8F together with the user information 11A and the terminal ID (S204).

[0131] When the management server 8 completes storing the PF user ID and the user information 11A in the storage 8F, it transmits the PF user ID to the user terminal 5 (S205). When the user terminal 5 receives the PF user ID, it stores the PF user ID in the storage 8F (S206).

[0132] Thereafter, the user terminal 5 displays a message indicating that facial information needs to be registered for the integrated platform, and acquires (takes) a facial image of the user holding the user terminal 5 using the camera 5G (an example of the biometric information acquisition device 5F) (S207). Thereafter, the user terminal 5 extracts facial features from the acquired facial image, associates it with the PF user ID and the terminal ID, and stores it in the storage 5E (S208). Once storage in the storage 5E is complete, the user terminal 5 displays a registration completion screen on the touch panel to notify the user that registration is complete (S209).

[0133] Next, the process performed by the user authentication system 2 when a user newly registers with a service provider will be described with reference to Fig. 11. It is assumed that the user has already obtained a provider ID and a PF user ID before executing this process.

[0134] A user who requests the association of a business ID and a PF user ID accesses the business server 6 using the user terminal 5 and causes the user terminal 5 to display a login screen (S301). The login screen includes an input field for the business user ID and a send button.

[0135] When the user enters the business user ID in the input field and touches the send button, the user terminal 5 transmits the business user ID entered by the user together with the user's own user terminal ID to the business server 6 (S302). The business server 6 transmits a notification (acquisition completion notification) to the user terminal 5 that acquisition of the business user ID and user terminal ID has been completed (S303).

[0136] Next, the user terminal 5 displays a PF user ID input screen (S304). The PF user ID input screen includes a PF user ID input field and a send button. The PF user ID input screen may also be provided with a button for extracting a PF user ID stored in the user terminal 5 and automatically inputting the PF user ID into the business user ID input field. The PF user ID input screen may also be provided with a check box indicating consent to the linkage (hereinafter referred to as consent check box). When the user touches the send button after filling in the consent check box, the user terminal 5 transmits the input PF user ID to the business server 6 (S305).

[0137] When the business server 6 receives the PF user ID, it associates the PF user ID with the business user ID and stores the association information 11B in the storage unit 11 (S306). When the business server 6 has completed storing the PF user ID in the storage unit 11, it transmits a notification (storage completion notification) to the user terminal 5 indicating that the storage has been completed (S307). When the user terminal 5 receives the storage completion notification, it displays a linkage application completion screen on the touch panel display 5C (S308).

[0138] 12, a description will be given of the processing performed by the user authentication system 2 when registering the authentication terminal 7 in the management server 8. Note that it is preferable to register the authentication terminal 7 promptly after the authentication terminal 7 is installed.

[0139] When an operator who registers the authentication terminal 7 starts up the authentication terminal 7, the authentication terminal 7 generates an authentication terminal ID, which is its own identification number, and stores it in the storage 24D (S401). Thereafter, the authentication terminal 7 transmits the generated authentication terminal ID to the management server 8 (S402). At this time, the authentication terminal 7 may also accept input of a business operator ID and transmit it to the management server 8 together with the generated authentication terminal ID.

[0140] If there are multiple businesses, the worker who registers the authentication terminal 7 may input and set the business ID of each business, linking it to the authentication terminal 7. When the worker sets it up remotely, the management server 8 may generate a terminal ID, link and save the terminal ID and business ID, and further transmit the terminal ID from the management server 8 to the authentication terminal 7.

[0141] When the management server 8 acquires the authentication terminal ID, it stores the authentication terminal ID in the storage 8F (S403). When the management server 8 acquires the generated authentication terminal ID and provider ID from the authentication terminal 7, it may store them in association with each other in the storage 8F.

[0142] Next, with reference to FIG. 13, a process performed by the user authentication system 2 when a business operator registers service content in the business operator server 6 will be described.

[0143] First, when a business operator accesses the business operator server 6 to register service content, an input screen for service information 11D including service content information (rights determination information) is displayed on the display 6C of the business operator server 6 (S501). The input screen for service information 11D includes an input field for service information 11D and a complete button.

[0144] When the business operator inputs the service information 11D and presses the Complete button, the input service information 11D is stored in the memory unit 11 (storage 6F) of the business operator server 6 (S502). After that, an input screen for reservation information showing options for contents that the user can reserve is displayed on the display 6C of the business operator server 6 (S503). The input screen for reservation information includes an input field for reservation information and a Complete button.

[0145] At this time, the input field for available reservation information provided on the input screen may be configured so that the service provided by the service provider is automatically entered. For example, if the service content provided by the service provider is "Tokyo Dome Live A, March 1, 2023, 6:00 PM," the input field for available reservation information may be configured so that information such as "Tokyo Dome Live A, March 1, 2023, 6:00 PM, 1st floor seats," "Tokyo Dome Live A, March 1, 2023, 6:00 PM, 2nd floor seats," etc. is automatically entered.

[0146] When the business operator inputs the reservation availability information and presses the completion button, the input reservation availability information is stored in the storage unit 11 (storage 6F) of the business operator server 6 (S504), and a completion screen notifying that the registration of the service contents has been completed is displayed (S505). Note that the processing shown in Fig. 13 may be performed after the registration completion screen shown in Fig. 9 has been displayed (S106).

[0147] Next, with reference to FIG. 14, a process performed by the user authentication system 2 when a user makes a reservation will be described.

[0148] First, when a user accesses the reservation site of the provider server 6 using the user terminal 5 (S601), the provider server 6 acquires reservation availability information and sends it to the user terminal 5 (S602). The user terminal 5 generates and displays a reservation acceptance screen based on the acquired reservation availability information (S603). The reservation acceptance screen displays a list of reservation availability information that the user can select and a send button, and the user inputs the reservation availability information by selecting from the list of reservation availability information. To make such selections easier, the reservation acceptance screen may include check boxes, pull-down menus, etc. for selecting from the list of reservation availability information.

[0149] When the user makes a selection from the list of available reservation information and presses the send button, the reservation details selected by the user (that is, reservation details information) are sent together with the business user ID (S604).

[0150] When the business server 6 acquires the reservation content information and the business user ID, it refers to the link information 11B based on the business user ID and acquires a PF user ID (S605). After acquiring the PF user ID, the business server 6 transmits the PF user ID and the reservation content information to the management server 8 (S606).

[0151] When the management server 8 acquires the PF user ID and the reservation content information, it records them in the user reservation DB, thereby storing the PF user ID and the reservation content information in the storage 8F (S607). When storage in the storage 8F is completed, the management server 8 transmits a storage completion notice indicating that storage is completed to the business server 6 (S608).

[0152] When the business provider server 6 receives the storage completion notification from the management server 8, it transmits a reservation completion notification to the user terminal 5 to notify that the reservation has been completed (S609). When the user terminal 5 receives the reservation completion notification from the business provider server 6, it displays a reservation completion screen on the touch panel display 5C (S610).

[0153] FIG. 15 shows a modified example of the process performed by the user authentication system 2 when a user makes a reservation.

[0154] 15, the management server 8 stores the PF user ID and reservation content information in the storage 8F by recording it in the user reservation DB, and then acquires all reservation content information corresponding to the PF user ID in a lump (S611). The management server 8 then transmits the collectively acquired reservation content information in a lump to the user terminal 5 in a lump (S612). Upon acquiring the collectively acquired reservation content information, the user terminal 5 displays a reservation completion screen including the collectively acquired reservation content information on the touch panel (S610).

[0155] Next, with reference to Fig. 16, a process performed by the user authentication system 2 when setting up the authentication terminal 7 will be described. Note that if the process of Fig. 13 is completed after S106, the setting of Fig. 16 may be performed after the process of Fig. 12.

[0156] First, when the business operator sets up the authentication terminal 7, the business operator server 6 accesses an authentication terminal setting page provided by the management server 8 (S701). When the management server 8 detects access to the authentication terminal setting page from the business operator server 6, it acquires a list of authentication terminal IDs it holds and sends it to the business operator server 6 (S702). When the business operator server 6 acquires the list of authentication terminal IDs, it displays an input screen for inputting service content information and association of the authentication terminal 7 (S703). The input screen for inputting service content information and association of the authentication terminal 7 includes an input field for inputting the association and a send button.

[0157] When the entry into the input field for entering the association between the service information 11D and the authentication terminal 7 is completed and the send button is pressed, the business server 6 transmits the entry content of the input field to the management server 8 (S704). When the management server 8 receives the entry content of the input field, it stores the association between the service content information and the authentication terminal 7 in the storage 8F (S705). When storage in the storage 8F is complete, the management server 8 transmits a completion notification (S706), and when the business server 6 receives the completion notification, it displays a completion screen notifying that the association setting has been completed (S707).

[0158] Next, with reference to FIGS. 17 and 18, the process performed by the user authentication system 2 during user authentication will be described.

[0159] As shown in Fig. 17, when entering a live venue, the user activates a predetermined application on the user terminal 5 (S801). A module (short-range communication module) for communicating with the short-range communication unit 32 is activated. Thereafter, when the user holds the user terminal 5 and approaches the gate device 10, the user terminal 5 receives a beacon signal transmitted from the authentication terminal 7 (S802). The beacon signal is for establishing short-range communication, and upon receiving the beacon signal, the user terminal 5 transmits a response signal to the authentication terminal 7 (S803). The response signal includes a BD address, which is a number assigned to each device capable of short-range communication.

[0160] When the authentication terminal 7 receives the response signal, it reads out its own authentication terminal ID, which was set when the authentication terminal 7 was registered, from the storage 24D (S804), and transmits it to the user terminal 5 (S805).

[0161] When the user terminal 5 receives the authentication terminal ID transmitted from the authentication terminal 7, it transmits a determination request signal to the management server 8 requesting execution of the first authentication (rights determination) (S806). The determination request signal transmitted from the user terminal 5 includes the authentication terminal ID transmitted from the authentication terminal 7 and the PF user ID of the user corresponding to that user terminal 5.

[0162] When the management server 8 (more specifically, the processor 8A of the management server 8) receives the judgment request signal, it executes the rights judgment program to implement the rights judgment method, thereby performing a judgment process and carrying out the first authentication (rights judgment).

[0163] When the management server 8 (rights determination unit 54) starts the determination process, it acquires the authentication terminal ID included in the determination request signal (S807). Next, the management server 8 refers to the authentication terminal DB and extracts the service content information (rights determination information) associated with the authentication terminal ID included in the determination request signal (S808).

[0164] The management server 8 further acquires the PF user ID included in the determination request signal (S809), and refers to the user reservation DB to extract reservation content information (authorization information) associated with the PF user ID (S810).

[0165] When the management server 8 completes the extraction of the service content information and reservation content information, it determines whether the reservation content corresponding to the extracted reservation content information matches or is included in the service provision content corresponding to the extracted service content information (also called the authorization condition) (S811, first authentication).

[0166] For example, when the service content information is "Tokyo Dome Live A, March 1, 2023, 6:00 PM" and the reservation content information is "Tokyo Dome Live A, March 1, 2023, 6:00 PM, 1st floor seats," the reservation content information is part of the service content information (more specifically, the reservation content corresponding to the reservation content information is part of the service content corresponding to the service content information), and therefore the reservation content information is determined to be included in the service content information (the reservation content corresponding to the reservation content information is included in the service content corresponding to the service content information). The management server 8 may determine that the reservation content is included in the provision content when a character string indicating the service content information is included in the character string indicating the reservation content information. Alternatively, the service content information and the reservation content information may each be expressed by a code (also referred to as a code). In this case, the management server 8 may determine whether the reservation content matches or is included in the provision content by comparing the code indicating the reservation content information with the code indicating the service content information.

[0167] If the extracted reservation content information matches or is included in the extracted service content information, the management server 8 determines that the first authentication is successful and sends an authentication permission signal permitting the execution of the second authentication to the user terminal 5 that sent the judgment request signal (S812).

[0168] In this way, it is possible to permit the execution of the authentication process related to the second authentication without storing information for determining whether the user attempting to perform authentication satisfies the authorization conditions in the authentication terminal 7. Furthermore, since the management server 8 stores the service content information and reservation content information in advance before the user terminal 5 and the authentication terminal 7 are able to communicate with each other in short distances, it is possible to quickly determine whether the authorization conditions are met.

[0169] If the extracted reservation content information does not match and is not included in the extracted service content information, the management server 8 may notify the user terminal 5 or a terminal held by a staff member involved in the service that the first authentication has failed. When the user terminal 5 is notified that the first authentication has failed, it may display a message notifying the staff member that the reservation cannot be confirmed. When the terminal held by the staff member is notified that the first authentication has failed, it may display a message instructing the staff member to confirm the user's reservation content.

[0170] When the user terminal 5 receives the authentication permission signal, as shown in Figure 18, it transmits the biometric information (facial features) that was previously stored in the user terminal 5 when registering for use of the user authentication system 2 and a second authentication start command to the authentication terminal 7 via communication using the short-range communication unit 32 (S813).

[0171] Upon receiving the second authentication start command, the authentication terminal 7 starts the second authentication. Specifically, upon receiving the second authentication start command, the authentication terminal 7 displays on the display unit a message indicating that biometric authentication will be performed, and captures an image of the user's face using the camera 22A to obtain an image including the user's face (face image) (S814).

[0172] Thereafter, the authentication terminal 7 extracts facial features from the facial image acquired by the camera 22A (S815). Next, the authentication terminal 7 compares (face comparison) the facial features extracted from the facial image with the facial features (biometric information) acquired from the user terminal 5 (S816).

[0173] The authentication terminal 7 transmits the result of matching the facial features extracted from the facial image with the facial features acquired from the user terminal 5 (i.e., the authentication result) to the user terminal 5 and the management server 8 together with its own authentication terminal ID (S817, S818).

[0174] Thereafter, the user terminal 5 and management server 8 store the authentication result, respectively (S819, S820), and the authentication terminal 7 and user terminal 5 display the authentication result of the second authentication, respectively (S821, S822).

[0175] If authentication is not successful in the second authentication, the authentication terminal 7 and / or the user terminal 5 may display a message that authentication was not successful and may also display a message requesting the user to perform the second authentication (face authentication) again.

[0176] Furthermore, when the management server 8 has completed storing the authentication result, it refers to the authentication terminal DB based on the authentication terminal ID transmitted together with the authentication result, and extracts the corresponding business ID. Thereafter, the management server 8 transmits the authentication result to the business server 6 corresponding to the extracted business ID using the business registration information (S823), and the business server 6 stores the received authentication result (S824).

[0177] Furthermore, if the facial feature amount extracted from the facial image is matched with the facial feature amount acquired from the user terminal 5 (determining that the user is the same person, and second authentication is successful), the authentication terminal 7 issues an operational instruction to the gate device 10 to open the gate 10A (see FIG. 1) (S825). When the gate device 10 is opened, the gate 10A is opened based on the operational instruction from the authentication terminal 7 to allow the user who has passed the second authentication to pass through (S826).

[0178] When the authentication terminal 7 completes the process of matching the facial feature values ​​acquired from the user terminal 5 with the facial feature values ​​acquired from the face image captured by the camera 22A and completes the transmission of the authentication result to the user terminal 5 and the management server 8, the authentication terminal 7 erases from its own memory the two facial feature values ​​used in the matching. In this embodiment, when the matching process (second authentication) and the operation of the gate device 10 are completed, the authentication terminal 7 erases (also referred to as deleting) the facial feature values ​​acquired from the user terminal 5, the face image captured by the camera 22A, and the facial feature values ​​acquired from the face image from the memory 24B and the storage 24D, regardless of the authentication result (S827). The authentication terminal 7 may notify the user terminal 5 of the deletion. By notifying the user, the user can confirm that the facial feature values ​​transmitted to the authentication terminal and the facial feature values ​​stored in the authentication terminal 7 are no longer stored.

[0179] Next, the operation of the user authentication system 2 will be explained using an example (first embodiment) in which the user authentication system 2 is used for user authentication at the time of entry to the live venue of Live A, which will be held at Tokyo Dome at 6:00 p.m. on March 1, 2023.

[0180] In the example shown in Figure 19(A), authentication terminals 7 with authentication terminal IDs Dev001 and Dev002 are installed at entrances A and B of the live venue for live performance a, respectively. As shown in Figure 19(B), the authentication terminal DB records the authentication terminal ID, Dev001 (Dev002), and the service content information "Tokyo Dome Live Performance a, March 1, 2023, 6:00 PM" in association with each other.

[0181] As shown in Figure 19 (C), the user reservation DB records the PF user ID (e.g., User001) of the user who made a reservation for Live A and the corresponding reservation content information, "Tokyo Dome Live A March 1, 2023 6:00 PM."

[0182] When a user with a PF user ID of User001 approaches entrance A carrying a user terminal 5, short-range communication becomes possible between the user terminal 5 carried by the user and the authentication terminal 7 with an authentication terminal ID of Dev001. As a result, the user terminal 5 acquires the authentication terminal ID from the authentication terminal 7 with the authentication terminal ID of Dev001, and transmits to the management server 8 a determination request signal including the PF user ID (User001) of the user corresponding to itself and the acquired authentication terminal ID (Dev001).

[0183] Upon receiving the determination request signal, the management server 8 executes a determination process to make an authority determination. In the determination process, the management server 8 first extracts the authentication terminal ID, Dev001, from the determination request signal, and then refers to the authentication terminal DB to obtain the corresponding service content information (authority determination information), "Tokyo Dome Live A, March 1, 2023, 6:00 PM."

[0184] Next, the management server 8 extracts the PF user ID, User001, from the determination request signal, and references the user reservation DB to obtain the corresponding reservation content information (authorization information), "Tokyo Dome Live A March 1, 2023, 6:00 PM."

[0185] The management server 8 compares the acquired service content information "Tokyo Dome Live A March 1, 2023 18:00" with the acquired reservation content information "Tokyo Dome Live A March 1, 2023 18:00", determines that the reservation content information matches the service content information, determines that the first authentication has been successful (approval conditions have been met), and sends an authentication permission signal to the user terminal 5 allowing the second authentication to be performed.

[0186] As a result, execution of the second authentication (facial authentication) for the user whose PF user ID is User001 is permitted, and when facial authentication is successful, the gate device 10 corresponding to the authentication terminal 7 whose authentication terminal ID is Dev001 is opened. As a result, the user whose PF user ID is User001 is able to enter the live concert venue for Live A to be held at Tokyo Dome at 6:00 pm on March 1, 2023. Similarly, execution of the second authentication (facial authentication) for the user whose PF user ID is User002 is permitted, and when facial authentication is successful, the gate device 10 corresponding to the authentication terminal 7 whose authentication terminal ID is Dev001 is opened.

[0187] Next, the operation of the user authentication system 2 will be described by taking as an example a case where the user authentication system 2 is used for user authentication at the time of entry into accommodation facility B (second embodiment).

[0188] In the example shown in Figure 20(A), authentication terminals 7 with authentication terminal IDs Dev001 and Dev002 are installed in rooms 101 and 102 of accommodation facility B, respectively. As shown in Figure 20(B), the authentication terminal DB records the authentication terminal ID, Dev001 (Dev002), and the service content information "Accommodation facility B, February 16, 2024, Room 101" (Accommodation facility B, February 16, 2024, Room 102) in association with each other.

[0189] As shown in Figure 20 (C), the user reservation DB records the PF user ID (e.g., User001) of the user who made a reservation for Room 101 at Accommodation Facility B in association with the corresponding reservation content information, "Accommodation Facility B, February 16, 2024, Room 101."

[0190] When a user with a PF user ID of User001 approaches the entrance to Room 101 carrying a user terminal 5, short-range communication becomes possible between the user terminal 5 carried by the user and the authentication terminal 7 with an authentication terminal ID of Dev001. As a result, the user terminal 5 acquires the authentication terminal ID from the authentication terminal 7 with the authentication terminal ID of Dev001, and transmits to the management server 8 a determination request signal including the PF user ID (User001) of the user corresponding to itself and the acquired authentication terminal ID (Dev001).

[0191] When the management server 8 receives the determination request signal, it executes a determination process. In the determination process, the management server 8 first extracts the authentication terminal ID, Dev001, from the determination request signal, and references the authentication terminal DB to obtain the corresponding service content information (rights determination information), "Accommodation facility B, February 16, 2024, Room 101."

[0192] Next, the management server 8 extracts the PF user ID, User001, from the determination request signal, and references the user reservation DB to acquire the corresponding reservation content information (authorization information), "Accommodation facility B, February 16, 2024, Room 101."

[0193] The management server 8 compares the acquired service content information "Accommodation B, February 16, 2024, Room 101" with the acquired reservation content information "Accommodation B, February 16, 2024, Room 101", determines that the reservation content information matches the service content information, determines that the first authentication has been successful (approval conditions have been met), and sends an authentication permission signal to the user terminal 5 allowing the second authentication to be performed.

[0194] As a result, execution of the second authentication (face authentication) for the user with the PF user ID User001 is permitted, and when face authentication is successful, the gate device 10 corresponding to the authentication terminal 7 with the authentication terminal ID Dev001 is opened. As a result, the user with the PF user ID User001 is allowed to enter Room 101 of Accommodation Facility B.

[0195] Furthermore, when a user with PF user ID User001 approaches the entrance to Room 102 while carrying user terminal 5, the acquired service content information "Accommodation B, February 16, 2024, Room 102" differs from the acquired reservation content information "Accommodation B, February 16, 2024, Room 101," so an authentication permission signal is not sent and gate device 10 does not open.

[0196] In addition, the service content information and reservation content information may include time information, and the management server 8 may be configured to compare the respective time information to determine authority, and to send an authentication permission signal to the user terminal 5 when it determines that authority exists.

[0197] Specifically, the authentication terminal DB may record Dev001 as the authentication terminal ID and "Accommodation B, Room 101, February 16, 2024 (check-in), Room 101, February 17, 11:00 (check-out)" as the corresponding service content information, and may record Dev002 as the authentication terminal ID and "Accommodation B, Room 102, February 16, 2024 (check-in), Room 101, February 18, 11:00 (check-out)" as the corresponding service content information.

[0198] In addition, the user reservation DB may record User001 as the PF user ID and the corresponding reservation content information "Accommodation B, February 16, 2024, Room 101, 1 night" in association with each other, and may record User002 as the PF user ID and the corresponding reservation content information "Accommodation B, February 16, 2024, Room 102, 2 nights" in association with each other.

[0199] This means that, for example, if User001 leaves the room before 11:00 on February 17th and returns at 12:00, attempting to enter Room 101, he or she will be deemed to have no permission because the check-out time has passed, and will not be able to enter Room 101.

[0200] Next, the operation of the user authentication system 2 will be described by taking as an example a case where the user authentication system 2 is used for user authentication when passing through a ticket gate at a station using a commuter pass (third embodiment).

[0201] In the example shown in Fig. 21(A), authentication terminals 7 with authentication terminal IDs Dev001 and Dev002 are installed at the ticket gates of stations X and Y, respectively. As shown in Fig. 21(B), the authentication terminal DB records the authentication terminal ID, Dev001 (Dev002), and the service content information "Passengers can board and disembark at railway operator CX station" (Passengers can board and disembark at railway operator CY station) in association with each other.

[0202] As shown in Figure 21 (C), when a user with a PF user ID of User001 purchases a commuter pass that allows boarding and alighting at railway operator CX station, the user's PF user ID (e.g., User001) and the corresponding reservation content information "allowing boarding and alighting at railway operator CX station" are recorded in association with each other in the user reservation DB.

[0203] When a user with a PF user ID of User001 approaches the entrance to Room 101 carrying a user terminal 5, short-range communication becomes possible between the user terminal 5 carried by the user and the authentication terminal 7 with an authentication terminal ID of Dev001. As a result, the user terminal 5 acquires the authentication terminal ID from the authentication terminal 7 with the authentication terminal ID of Dev001, and transmits to the management server 8 a determination request signal including the PF user ID (User001) of the user corresponding to itself and the acquired authentication terminal ID (Dev001).

[0204] When the management server 8 receives the determination request signal, it executes a determination process. In the determination process, the management server 8 first extracts the authentication terminal ID, Dev001, from the determination request signal, and then refers to the authentication terminal DB to obtain the corresponding service content information (authority determination information) "Railway operator CX station boarding and alighting permitted."

[0205] Next, the management server 8 extracts the PF user ID, User001, from the determination request signal, and refers to the user reservation DB to obtain the corresponding reservation content information (authorization information), which is "Railway operator CX station boarding and disembarking permitted (expiration date February 25, 2024)."

[0206] The management server 8 compares the acquired service content information "Boarding and disembarking possible at railway operator CX station" with the acquired reservation content information "Boarding and disembarking possible at railway operator CX station (expiration date February 25, 2024)", determines that the reservation content information is included in the service content information, determines that the first authentication has been successful (approval conditions have been met), and sends an authentication permission signal to the user terminal 5 that allows the second authentication to be performed.

[0207] As a result, execution of the second authentication (face authentication) for the user with the PF user ID User001 is permitted, and when face authentication is successful, the gate device 10 corresponding to the authentication terminal 7 with the authentication terminal ID Dev001 is opened. As a result, the user with the PF user ID User001 is allowed to get on and off at station X.

[0208] Furthermore, when a user with PF user ID User001 approaches the ticket gate at station Y while carrying user terminal 5, the acquired reservation content information "Boarding and alighting possible at railway operator CX station (expiration date February 25, 2024)" is not included in the acquired service content information "Boarding and alighting possible at railway operator CY station," so an authentication permission signal is not sent and the ticket gate at station Y is not opened.

[0209] Note that when determining the authority, the management server 8 compares the time information included in the service content information with the time information included in the reservation content information. Therefore, for example, if the expiration date has passed, the ticket gates at Station X will not open even if a user with a PF user ID of User001 approaches the ticket gates at Station X while carrying the user terminal 5.

[0210] Next, the operation of the user authentication system 2 will be described by taking as an example a case where the user authentication system 2 is used to perform admission authentication for a movie theater (fourth embodiment).

[0211] In the example shown in Fig. 22(A), an authentication terminal 7 with an authentication terminal ID of Dev001 is installed together with a gate device 10 in a passageway that allows entrance to screens A and B, and an authentication terminal 7 with an authentication terminal ID of Dev002 is installed together with a gate device 10 in a passageway that allows entrance to screen B. As shown in Fig. 22(B), the authentication terminal DB records the authentication terminal ID, Dev001, and the service content information, "Screens A and B, March 1st, 8:00 to 9:30," in association with each other. The authentication terminal DB also records the authentication terminal ID, Dev002, and the service content information, "Screen C, March 1st, 12:00 to 1:30 p.m."

[0212] As shown in Figure 22(C), when a user with a PF user ID of User001 purchases a ticket for a movie showing at 9:00 on March 1st at cinema screen A, the user's PF user ID (e.g., User001) and the corresponding reservation content information "Cinema screen A, March 1st, 9:00" are recorded in association with each other in the user reservation DB.

[0213] When a user with a PF user ID of User001 approaches the entrance to Room 101 carrying a user terminal 5, short-range communication becomes possible between the user terminal 5 carried by the user and the authentication terminal 7 with an authentication terminal ID of Dev001. As a result, the user terminal 5 acquires the authentication terminal ID from the authentication terminal 7 with the authentication terminal ID of Dev001, and transmits to the management server 8 a determination request signal including the PF user ID (User001) of the user corresponding to itself and the acquired authentication terminal ID (Dev001).

[0214] When the management server 8 receives the determination request signal, it executes a determination process. In the determination process, the management server 8 first extracts the authentication terminal ID, Dev001, from the determination request signal, and references the authentication terminal DB to obtain the corresponding service content information (rights determination information), "Screen A, B March 1st 8:00 to 9:30."

[0215] Next, management server 8 extracts the PF user ID, User001, from the determination request signal, and references the user reservation DB to obtain the corresponding reservation content information (authorization information) "Movie theater screen A, March 1st, 9:00 am."

[0216] The management server 8 compares the acquired service content information "Screens A, B, March 1st, 8:00-9:30" with the acquired reservation content information "Movie theater screen A, March 1st, 9:00" and determines whether the reservation content information is included in the service content information.

[0217] For example, the management server 8 extracts "A" or "B" indicating the screen number and the character string "March 1st, 8:00 AM" indicating the time period from the service content information. The management server 8 further extracts "A" indicating the screen number and the character string "March 1st, 9:00 AM" indicating the time from the reservation content information. Thereafter, the management server 8 may determine that the reservation content information is included in the service content information when the screen number extracted from the reservation content information is included in the screen number extracted from the service content information and the time extracted from the reservation content information is included in the time period extracted from the service content information. In this way, the management server 8 also checks the time information to confirm the time when making an authorization decision.

[0218] If the reservation content information is included in the service content information, the management server 8 determines that the first authentication has been successful (the authorization conditions have been met), and transmits an authentication permission signal to the user terminal 5 permitting execution of the second authentication.

[0219] This allows the execution of second authentication (face authentication) for the user with the PF user ID User001, and when face authentication is successful, the gate device 10 corresponding to the authentication terminal 7 with the authentication terminal ID Dev001 is opened. This allows the user with the PF user ID User001 to watch the movie being screened on movie theater screen A.

[0220] As described above, the embodiments have been described as examples of the technology disclosed in this application. However, the technology in this disclosure is not limited to these, and can be applied to embodiments in which modifications, substitutions, additions, omissions, etc. are made. Furthermore, it is also possible to combine the components described in the above embodiments to create new embodiments.

[0221] In the above embodiment, Figures 9 to 18 show sequence diagrams focusing on one authentication terminal, but the present invention is not limited to the number of authentication terminals as long as one or more authentication terminals are included.

[0222] In the above embodiment, the second authentication is performed by matching biometric information, but the second authentication is not limited to being based on biometric information. For example, after authentication is performed by the first authentication, the management server 8 transmits a password to each of the authentication terminal 7 and the user terminal 5. Thereafter, the user terminal 5 may transmit the received password, and when the password received by the authentication terminal 7 and the password transmitted from the user terminal 5 match (for example, when they match), it may be determined that authentication by the second authentication has been successful.

[0223] In the user authentication system 2 according to the above embodiment, execution of the second authentication is permitted upon successful authentication in the first authentication, but this is not limited to the above. The user authentication system 2 may be configured to execute processing for the second authentication regardless of the result of the first authentication, and to determine that user authentication has been performed when a user is authenticated in both the first authentication and the second authentication. In this case, the user terminal 5 and the authentication terminal 7 may display the results of the first authentication and the second authentication after the processing related to the first authentication and the second authentication is completed.

[0224] In the above embodiment, the provider server 6 (service provider device) is configured to acquire service content information (authority determination information) (S501, S501) in advance, and the management server 8 acquires the service content information from the provider server 6 (S704), but the present invention is not limited to this form.

[0225] Specifically, the management server 8 may be configured to acquire authority determination information (service content information) by communicating with the business server 6 or a terminal owned by the business (hereinafter referred to as the business terminal 60).

[0226] Fig. 23 shows a modified sequence diagram illustrating the flow of processing related to the registration of service content to the business operator's server 6. In this modified example, the input of service content information (S501 and S502 in Fig. 13) is not accepted, and only the input of reservation availability information (i.e., S503 to S505) is accepted.

[0227] 24 shows a sequence diagram for acquiring authority determination information and setting an authentication terminal using the provider terminal 60 when service content information is not input when registering the service content. Note that, like the user terminal 5, the provider terminal 60 is configured by a computer (smartphone, tablet, notebook PC, etc.) having a processor, memory, display, etc.

[0228] 24, similarly to the case shown in Fig. 16, when a business operator accesses the management server 8 using the business operator terminal 60 (S701), a list of authentication terminal IDs is transmitted from the management server 8 to the business operator terminal 60 (S702). Thereafter, the business operator terminal 60 receives input of authority determination information (service content information) from the business operator by, for example, displaying an input screen on the display (S901).

[0229] When the input of the rights determination information is completed, the business operator terminal 60 uses the transmitted authentication terminal ID to accept input relating to the association between the rights determination information and the authentication terminal (authentication terminal ID) (S703), as in the case shown in Fig. 16. When accepting input, the business operator terminal 60 may display an input screen relating to the association between the rights determination information and the authentication terminal on the display.

[0230] When the operator terminal 60 acquires the association between the rights determination information and the authentication terminal, it transmits the association to the operator server 6 (S704). When the operator server 6 receives the association between the rights determination information and the authentication terminal, it saves it in storage (S705) and transmits a completion notice to the operator terminal 60 (S706), as in the case shown in FIG. 16. When the operator terminal 60 receives the storage completion notice, it displays a completion screen on the display (S707). As shown in FIG. 24, the management server 8 can also acquire the rights determination information (and the association between the rights determination information and the authentication terminal) from the operator terminal 60. [Industrial Applicability]

[0231] The authority determination system, authority determination method, authority determination program, and management server disclosed herein have the effect of being able to allow the authentication terminal to perform matching if the requirements are met, without having to store information in the authentication terminal to determine whether the person attempting authentication meets the requirements, and are useful as authority determination systems, authority determination methods, authority determination programs, and management servers that allow a user who can use multiple services provided by a service provider to perform authentication processing to provide a specific service, which is one of the multiple services. [Explanation of symbols]

[0232] 1: Permission Judgment System 2: User authentication system 5: User terminal 5A: Processor 5B: Memory 5C: Touch panel display 5D: Network Interface 5E: Storage 5F: Biometric information acquisition device 5G: Camera 6: Provider server (an example of a service provider device) 6A: Processor 6B: Memory 6C: Display 6D: Input device 6E: Network Interface 6F: Storage 7: Authentication terminal 8: Management Server 8A: Processor 8B: Memory 8C: Display 8D: Input device 8E: Network Interface 8F: Storage 9: Communication Network 10: Gate device 10A: Gate 11: Storage section 11A: User Information 11B: Collaboration information 11C: Business identification information 11D: Service Information 11E: User reservation information 12: User registration section 13: Collaboration Reception Department 14:Identification information management department 15: Service registration section 16: Service Information Department 17: Reservations 18: Reservation Information Department 21: Housing 22: Biometric information acquisition device 22A: Camera 23:Display device 24: Authentication control device 24A: Processor 24B: Memory 24C: Communication interface 24D: Storage 31: Network communication section 32: Near field communication department 33: Storage section 34: Control section 41: Authentication terminal registration unit 42:Request part 43: Biometric authentication unit 44: Gate control section 51: Storage section 52: Authentication terminal setting section 53: Reservation Information Management Department 54: Authority determination section 60: Operator terminal

Claims

1. An authority determination system for determining whether a user is authorized to use a service provided by a service provider, comprising: an authentication terminal capable of short-range wireless communication with a user terminal associated with each user; a service provider device managed by the service provider; a management server connected to the authentication terminal and the service provider device, the service provider device is configured to be able to provide the management server with authority decision information regarding the service associated with each of the authentication terminals and authorization information regarding reservation of the service associated with each of the users; The management server is an authority determination system that performs a determination process to determine whether or not authority exists when the authentication terminal and the user terminal become capable of short-range wireless communication based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

2. the authentication terminal, when it becomes possible to communicate with the user terminal by short-range wireless communication, transmits authentication terminal identification information for identifying the authentication terminal to the user terminal; The user terminal transmits the user identification information of the user corresponding to the user terminal and the authentication terminal identification information acquired from the authentication terminal to the management server; The authority determination system described in claim 1, wherein when the management server acquires the authentication terminal identification information and the user identification information from the user terminal, it executes the determination process based on the authority determination information of the authentication terminal corresponding to the authentication terminal identification information acquired from the user terminal and the authorization information of the user corresponding to the user identification information acquired from the user terminal.

3. the authentication terminal is equipped with a sensor for acquiring biometric information; the user terminal stores the associated biometric information of the user; The authority determination system described in claim 1, wherein when the authentication terminal determines that the user has authority in the determination process, it performs authentication by a comparison process that compares biometric information acquired by the sensor of the authentication terminal with biometric information stored in the user terminal.

4. The right determination system according to claim 3 , wherein the authentication terminal transmits a result of the matching process to the user terminal and the management server.

5. 4. The right determination system according to claim 3, wherein the authentication terminal erases the two pieces of biometric information used in the matching process from its own memory after the matching process is completed.

6. The authority determination information corresponds to the content of the service provided, the authorization information corresponds to the reservation content of the service of the user corresponding to the user terminal; 6. The authority determination system according to claim 1, wherein the management server determines that the authority is granted when the reservation details match or are included in the provision details.

7. The rights determination system described in claim 1, wherein the management server is configured to be able to store multiple pieces of rights determination information and multiple pieces of authorization information in advance before the user terminal and the authentication terminal become capable of short-range wireless communication.

8. An authority determination method for determining whether a user is authorized to use a service provided by a service provider, comprising: an authentication terminal capable of short-range wireless communication with a user terminal associated with each user; a service provider device managed by the service provider; an administration server connected to the authentication terminal and the service provider device, the service provider device is configured to be able to provide the management server with authority decision information regarding the service associated with each of the authentication terminals and authorization information regarding reservation of the service associated with each of the users; An authority determination method in which, when the authentication terminal and the user terminal become capable of short-range wireless communication, the management server performs a determination process to determine whether or not authority exists based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

9. An authority determination program for determining whether a user has authority to use a service provided by a service provider, an authentication terminal capable of short-range wireless communication with a user terminal associated with each user; a service provider device managed by the service provider; an administration server connected to the authentication terminal and the service provider device, the service provider device is configured to be able to provide the management server with authority decision information related to the service associated with each of the authentication terminals and authorization information related to reservations for the service associated with each of the users; The management server is an authority determination program that performs a determination process to determine whether or not authority exists when the authentication terminal and the user terminal become capable of short-range wireless communication based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

10. A management server for determining whether a user has an authority to use a service provided by a service provider, an authentication terminal capable of short-range wireless communication with a user terminal associated with each user; connected to a service provider device that is managed by the service provider and configured to be able to provide authority decision information related to the service associated with each of the authentication terminals and authorization information related to reservations for the service associated with each of the users; When the authentication terminal and the user terminal become capable of short-range wireless communication, a management server performs a determination process to determine whether or not authority exists based on the authority determination information corresponding to the authentication terminal and the authorization information of the user associated with the user terminal that has become capable of short-range wireless communication with the authentication terminal.

11. The authority determination information corresponds to the content of the service provided, the authorization information corresponds to the reservation content of the service of the user corresponding to the user terminal, 11. The management server according to claim 10, wherein when the user makes a reservation for a service, the reservation details are transmitted in a lump to the user terminal corresponding to the user.

Citation Information

Patent Citations

  • Authentication terminal, system, authentication terminal control method and program

    JP7151944B1