Right determination system, right determination method, information processing terminal, and control method thereof

The rights determination system addresses the lack of group rights management in facial recognition by enabling efficient user rights transfer and notification, enhancing convenience for group users.

JP2025178371APending Publication Date: 2025-12-05PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025160362
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2025-12-05

AI Technical Summary

Technical Problem

Existing facial recognition systems for group management lack a rights manager, making it cumbersome to manage and adjust user rights within a group effectively.

Method used

A rights determination system that includes a registration unit, identification unit, and notification unit to manage and determine user rights within a group based on facial recognition, allowing for the transfer and registration of rights information and facial data to identify group membership and notify users of determination results.

Benefits of technology

Enhances convenience for group users by improving the management and adjustment of rights through facial recognition, allowing seamless access to various services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025178371000001_ABST
    Figure 2025178371000001_ABST
Patent Text Reader

Abstract

To provide a right determination system that improves convenience of a user belonging to a group when using face authentication.SOLUTION: A right determination system, which determines whether a desired process can be provided to a second user on the basis of right information associated with a group consisting of at least one first user and at least one second user, includes: a registration unit that sets up a transfer of the right information for service to each second user belonging to a group within a range indicated in the right information for the service reserved or used by the first user, and accepts and registers face information of the second user; an identification unit that identifies, on the basis of authentication processing based on the face information of the second user, a group to which the second user belongs; a determination unit that determines, on the basis of the right information of the service associated with the group identified by the identification unit, whether or not a desired process requested by the second user can be provided; and a notification unit that notifies the first user of the determination result by the determination unit.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a rights determination system, a rights determination method, an information processing terminal, and a control method thereof. [Background technology]

[0002] Conventionally, a method using facial recognition has been known as a biometric authentication technology. By using facial recognition, users do not need to have a specific device or tool in their possession when authenticating, and can be easily authenticated by simply having their face recognized by the authentication device.

[0003] Patent Document 1 discloses a system in which multiple users are registered as a group at a hotel front desk or the like, rights are associated with biometric authentication information such as the face of each user for that group, authentication is performed using the biometric authentication information, and if authentication is successful, permission to use the hotel facilities is granted based on the rights set for the group. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2018-190274 Summary of the Invention [Problem to be solved by the invention]

[0005] Consider providing various services using facial recognition. For example, Patent Document 1 discloses assigning a range of rights to a group and setting rights available to each user belonging to the group within that range of rights. However, Patent Document 1 does not have a rights manager within the group, making management of rights within the group cumbersome. In particular, it does not sufficiently consider the ability of the manager within the group to properly understand how other users are using the rights or to change the settings according to the situation.

[0006] The present disclosure has been devised in consideration of the above-mentioned conventional circumstances, and aims to provide a rights determination system, rights determination method, information processing terminal, and control method thereof that can further improve the convenience when users belonging to a group use various services through facial recognition. [Means for solving the problem]

[0007] The present disclosure provides a rights determination system that determines whether a desired process can be provided to a second user based on rights information associated with a group consisting of at least one first user and at least one second user, the rights determination system including: a registration unit that accepts and registers a setting to transfer the rights information of the service to each second user belonging to the group within a range indicated in the rights information of the service reserved or used by the first user, and facial information of the second user; an identification unit that identifies the group to which the second user belongs based on an authentication process based on the facial information of the second user; a determination unit that determines whether the desired process requested by the second user can be provided based on the rights information of the service associated with the group identified by the identification unit; and a notification unit that notifies the first user of the determination result by the determination unit.

[0008] The present disclosure also provides a rights determination method for determining whether a desired process can be provided to a second user based on rights information associated with a group consisting of at least one first user and at least one second user, the rights determination method comprising the steps of: receiving and registering a setting to transfer the rights information of the service to each second user belonging to the group within a range indicated in the rights information of the service reserved or used by the first user, and face information of the second user; identifying the group to which the second user belongs based on an authentication process based on the face information of the second user; determining whether the desired process requested by the second user can be provided based on the rights information of the service associated with the group identified in the identification step; and notifying the first user of the determination result of the determination step.

[0009] The present disclosure also provides an information processing terminal having: a request unit that requests a rights determination system to receive rights information associated with a group consisting of at least one first user and at least one second user, the rights information being for a service reserved or used by the first user, a setting to transfer the rights information for the service to each of the second users, and to register facial information of the second users; and a receiving unit that receives a determination result, when a determination is made based on the rights information for the service as to whether or not a desired process can be provided by the second user, whose group to which the second user belongs is identified based on an authentication process based on the facial information of the second user, and the determination result satisfies a predetermined condition.

[0010] The present disclosure also provides a control method for an information processing terminal, the control method including the steps of: requesting a rights determination system to register rights information associated with a group consisting of at least one first user and at least one second user, the rights information for a service reserved or used by the first user, a setting to transfer the rights information for the service to each of the second users, and facial information of the second users; and receiving a determination result based on the rights information for the service as to whether or not the desired processing requested by the second user, whose group to which the second user belongs is identified based on an authentication process based on the facial information of the second user, can be provided if the determination result satisfies a predetermined condition.

[0011] Any combination of the above components, and conversion of the expression of the present disclosure into a method, device, system, storage medium, computer program, etc., are also valid aspects of the present disclosure. [Effects of the Invention]

[0012] According to the present disclosure, it is possible to further improve the convenience when users belonging to a group use various services through facial authentication. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a diagram showing an example of the overall configuration of a system according to a first embodiment. [Figure 2] FIG. 1 is a diagram showing an example of the functional configuration of each device according to the first embodiment; [Figure 3] FIG. 1 is a diagram illustrating an example of a hardware configuration of a mobile terminal according to a first embodiment. [Figure 4] FIG. 1 is a diagram illustrating an example of a hardware configuration of an information processing device according to a first embodiment. [Figure 5] FIG. 1 shows an example of a database configuration according to the first embodiment. [Figure 6] Processing sequence of an example of a registration processing procedure between devices according to the first embodiment [Figure 7]FIG. 10 is a diagram showing an example of a UI screen during registration processing according to the first embodiment; [Figure 8] FIG. 10 is a diagram showing an example of a UI screen during registration processing according to the first embodiment; [Figure 9] Processing sequence of an example of a matching processing procedure between devices according to the first embodiment [Figure 10] FIG. 10 is a diagram showing an example of a UI screen during a matching process according to the first embodiment; [Figure 11] Processing sequence of another example 1 of the verification processing procedure between each device [Figure 12] FIG. 10 is a diagram showing an example of a UI screen for another example 1 of the matching process. [Figure 13] Processing sequence of another example 2 of the verification processing procedure between each device [Figure 14] A diagram showing an example of a UI screen for another example 2 of the matching process [Figure 15] Processing sequence of Alternative Example 3 of the matching processing procedure between each device [Figure 16] FIG. 10 is a diagram showing an example of a UI screen for another example 3 of the matching process. [Figure 17] Processing sequence of Alternative Example 4 of the matching processing procedure between each device [Figure 18] A diagram showing an example of a UI screen for Alternative Example 4 of the matching process [Figure 19] Processing sequence of Alternative Example 5 of the collation processing procedure between each device [Figure 20] FIG. 10 is a diagram showing an example of a UI screen for another example 5 of the matching process. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, with appropriate reference to the accompanying drawings, embodiments specifically disclosing a face recognition system, a face recognition method, an information processing terminal, and a control method thereof according to the present disclosure will be described in detail. However, more detailed explanation than necessary may be omitted. For example, detailed explanations of already well-known matters or redundant explanations of substantially identical configurations may be omitted. This is to avoid unnecessary redundancy in the following explanation and to facilitate understanding by those skilled in the art. Note that the accompanying drawings and the following explanation are provided to enable those skilled in the art to fully understand the present disclosure, and are not intended to limit the subject matter recited in the claims.

[0015] <First Embodiment> [System Configuration] FIG. 1 illustrates an example of the overall configuration of a system according to the first embodiment. In this embodiment, the system includes a parent mobile terminal 10, a child mobile terminal 20, a face authentication system 30, a face matching terminal 40, and a service providing system 50, and the various devices are communicatively connected via a network 60. While each of the various devices is illustrated as one device in FIG. 1 , multiple devices may be included. While each of the various devices is illustrated as a single device, the multiple devices in FIG. 1 may be implemented by a single device, such as by incorporating the functions of the face authentication system 30 and the face matching terminal 40 into the same device. In this specification, the terms "parent" and "child" refer to the relative relationship between users when setting rights, as described below. Therefore, one user can be both a parent user and a child user, or one user can be a child user of multiple parent users. In the following description, when it is necessary to clearly indicate the role of each user in a parent-child relationship, the terms "user (parent)" and "user (child)" will be used. Details will be described later.

[0016] The parent mobile terminal 10 and the child mobile terminal 20 are mobile terminals owned by each user, and for convenience, the mobile terminal owned by a user with the role of "parent" will be referred to as the parent mobile terminal 10, and the mobile terminal owned by a user with the role of "child" will be referred to as the child mobile terminal 20.

[0017] The face authentication system 30 performs face authentication processing according to this embodiment, and stores and manages various types of face information. The service providing system 50 is a system for providing various services in cooperation with the face authentication system 30. Examples of services that can be provided by the service providing system 50 will be described later. The face authentication system 30 and the service providing system 50 may be configured as on-premise systems installed within the facilities of administrators of the respective services, or may be configured as off-premise systems using cloud computing or the like.

[0018] The face matching terminal 40 is installed in a facility that provides various services and is used to acquire a face image of a user and verify the user's rights. The network 60 is configured to connect various devices so that they can communicate with each other, and there is no particular limitation on whether the network is wired or wireless or on the communication standard.

[0019] [Function Configuration] FIG. 2 is a diagram illustrating an example of the functional configuration of various devices according to the present embodiment. Each component of the various devices may be implemented by a control unit (e.g., a processor) of the device reading a program stored in a storage unit, or by providing dedicated hardware. Here, the processor may be configured using, for example, a CPU (Central Processing Unit), a DSP (Digital Signal Processor), or an FPGA (Field Programmable Gate Array). Note that only components corresponding to the functions according to the present embodiment are illustrated here, and the various devices may further include components for implementing other functions. The configuration illustrated in FIG. 2 is merely an example, and the components illustrated in FIG. 2 may be configured collectively or further divided into smaller components. The links and arrows of the components illustrated in FIG. 2 indicate an example of data transmission and reception, but the present invention is not limited to this connection configuration, and other linkages and connections may also be implemented.

[0020] The parent mobile terminal 10 includes a usage status display unit 11, a parent right information registration unit 12, a child right information registration unit 13, a parent face information acquisition unit 14, a child face information acquisition unit 15, an imaging unit 16, and a child registration link transmission unit 17. The usage status display unit 11 displays the usage status of the rights held by the user (parent) of the parent mobile terminal 10 based on the contents of a notification from the face authentication system 30. The parent right information registration unit 12 performs a process of registering the rights held by the user (parent) (hereinafter referred to as "parent right information") in the face authentication system 30. The child right information registration unit 13 performs a process of registering in the face authentication system 30 the rights (hereinafter referred to as "child right information") granted to another user (child) within the scope of the parent right information held by the user (parent) of the parent mobile terminal 10 (in other words, on the premise that the parent right information is satisfied). In other words, the child right information is conceptually or substantively included in the parent right information.

[0021] The parent face information acquisition unit 14 acquires face information (face image) of the user (parent) via the imaging unit 16 and performs a process of registering the face information in the face authentication system 30. The child face information acquisition unit 15 acquires face information (face image) of the user (child) via the imaging unit 16 and performs a process of registering the face information in the face authentication system 30. The imaging unit 16 is configured to include a camera for acquiring a face image, and passes the face image obtained by photographing the face based on the user's operation to the parent face information acquisition unit 14 and the child face information acquisition unit 15. When the child mobile terminal 20 performs a process of photographing the face image when registering the face information (face image) of the user (child), the child registration link transmission unit 17 performs a process of transmitting a request for this to the child mobile terminal 20. This request includes access information (hereinafter referred to as a "child registration link") to the face authentication system 30 used when registering the face image.

[0022] The child mobile terminal 20 includes a child registration link receiving unit 21, an imaging unit 22, and a child face information acquiring unit 23. The child registration link receiving unit 21 receives a request transmitted from the parent mobile terminal 10 and notifies the user of the contents of the request. The imaging unit 22 includes a camera for acquiring a facial image, and passes the facial image obtained by photographing the face based on the user's operation to the child face information acquiring unit 23. The child face information acquiring unit 23 acquires facial information (facial image) of the user (child) via the imaging unit 22. The child face information acquiring unit 23 then performs processing to register the facial information of the user (child) in the face authentication system 30 based on the child registration link included in the request transmitted from the parent mobile terminal 10.

[0023] The facial authentication system 30 includes a parent-child relationship determination unit 31, a parent face information management unit 32, a child face information management unit 33, a usage right determination unit 34, a parent right management unit 35, and a child right management unit 36. The facial authentication system 30 further includes an external system linkage unit 37, a usage history management unit 38, a usage result notification unit 39, and a result notification unit 45. The parent-child relationship determination unit 31 performs facial authentication based on registered facial images to identify the user of the facial image included in the matching request from the face matching terminal 40. The parent-child relationship determination unit 31 then determines the parent-child relationship established for the identified user. Any known method can be used for facial authentication, and is not particularly limited. For example, template matching, feature point extraction, 3D face recognition, and other methods may be used. The parent face information management unit 32 registers and manages the facial image transmitted from the parent mobile terminal 10 as the user's (parent's) facial image. The child face information management unit 33 registers and manages the face images transmitted from the parent mobile terminal 10 and the child mobile terminal 20 as face images of the user (child). The parent face information management unit 32 and the child face information management unit 33 set a parent-child relationship based on instructions from the user (parent).

[0024] The usage right determination unit 34 determines whether the usage right specified in the matching request from the face matching terminal 40 is permitted to the user identified based on the face information. When making its determination, the usage right determination unit 34 refers to information managed by the parent right management unit 35 and the child right management unit 36. The parent right management unit 35 holds and manages the parent right information specified by the parent mobile terminal 10. The parent right information indicates the content of the rights to use the user authentication service as well as various services provided by the service providing system 50. Certain rights are granted by applying for or purchasing the use of various services. The child right management unit 36 ​​holds and manages the child right information specified by the parent mobile terminal 10.

[0025] The external system cooperation unit 37 cooperates with an external system (for example, one of the various systems included in the service providing system 50) to perform processing according to the rights of each user, based on a matching request from the face matching terminal 40, etc. The content of the cooperation may vary depending on the requested content, and may be, for example, processing such as referring to or updating a database (hereinafter referred to as DB) held by the external system. Alternatively, the external system may be configured to cause the external system to execute part of the processing according to the requested content. Furthermore, when processing that does not require cooperation with an external system is requested, the external system cooperation unit 37 may perform the processing using various information held inside the face authentication system 30.

[0026] The usage history management unit 38 holds and manages the processes executed in response to requests from the face matching terminal 40, i.e., the usage history of the rights. The usage history may be managed to include information on processes executed in the service providing system 50 as well as processes within the face authentication system 30. The usage result notification unit 39 notifies the parent mobile terminal 10 of the usage history managed by the usage history management unit 38 at a predetermined timing. The parent mobile terminal 10 that is the notification destination here is a mobile terminal owned by the user (parent) if the user corresponding to the facial image indicated in the request from the face matching terminal 40 is the parent. On the other hand, if the user corresponding to the facial image is a child, the notification destination is a mobile terminal owned by a user (parent) who has a parent-child relationship with the user (child). The result notification unit 45 notifies the face matching terminal 40, which is the request source, of the facial authentication result and the processing content executed as a result of the processing requested by the face matching terminal 40.

[0027] The face matching terminal 40 includes an imaging unit 41, a face information acquisition unit 42, a usage right setting unit 43, and a matching result display unit 44. The imaging unit 41 includes a camera for acquiring a face image, and passes the face image obtained by photographing the face based on the user's operation to the face information acquisition unit 42. The face information acquisition unit 42 acquires face information (face image) of the user who is the target of face authentication via the imaging unit 41, and passes it to the usage right setting unit 43. The usage right setting unit 43 sets the right that the user who is the target of face authentication wishes to use, and transmits it together with the face image to the face authentication system 30 as a matching request. The right that the user wishes to use here varies depending on the content of the service to be provided.

[0028] The service providing system 50 may be configured with various systems depending on the content of the services to be provided. As an example, it may include a payment system 51 that provides payment services, an accommodation management system 52 that manages accommodation at accommodation facilities, a facility management system 53 that manages the use of facilities such as amusement facilities, or a lost child determination system 54 that manages lost children. Each of the various systems listed here may be configured with a separate server or device. In this embodiment, several examples of situations to which the present disclosure can be applied will be specifically described.

[0029] [Device configuration] (Mobile device) 3 is a diagram showing an example of the hardware configuration of an information processing terminal applicable as the parent mobile terminal 10 and the child mobile terminal 20 according to the present embodiment. Note that in the present embodiment, the parent mobile terminal 10 and the child mobile terminal 20 are described as having the same hardware configuration, but they may have different configurations. The mobile terminal 300, which is the information processing terminal, may be, for example, a smartphone, a tablet terminal, a mobile PC (Personal Computer), a wearable terminal, or the like. Here, a smartphone will be described as an example.

[0030] The mobile terminal 300 includes a CPU 301, a communication unit 302, a touch panel display 303, a microphone 304, a speaker 305, a memory 306, a storage 307, and a camera 309. The CPU 301 provides various functions by reading and executing various programs (for example, an application 308) stored in the storage 307.

[0031] The communication unit 302 communicates with the outside world via a mobile phone communication network, the Internet, short-range wireless communication, etc., and transmits and receives various data and signals. The communication method used by the communication unit 302 may be, for example, a 4G / 5G communication method using a wide-area communication line such as a telephone line, or a short-range wireless communication method such as the Wi-Fi (registered trademark) standard or Bluetooth (registered trademark) standard of a wireless LAN (Local Area Network).

[0032] The touch panel display 303 functions as a display unit that displays various information to the user, and also accepts touch operations from the user. The microphone 304 accepts the user's voice and surrounding audio information as input. The speaker 305 outputs audio information. The memory 306 is a volatile storage area, and is used, for example, as a work area when the CPU 301 performs various processes. The storage 307 is a non-volatile storage area, and, for example, stores applications 308 for various processes according to this embodiment. The applications 308 provide various functions by being read and executed by the CPU 301. The camera 309 photographs an object based on a user operation and acquires the image. In this embodiment, the user's face is photographed and acquired as a facial image.

[0033] (Information processing device) 4 is a diagram showing an example of the hardware configuration of an information processing device applicable as face authentication system 30 and face matching terminal 40 according to the present embodiment. Here, a PC will be described as an example of the information processing device, but face matching terminal 40 may be configured as a dedicated terminal for face matching, for example.

[0034] The information processing device 400 includes a CPU 401, a communication unit 402, a display unit 403, an external I / F (interface) 404, a memory 405, and a storage device 406. Note that the face matching terminal 40 is further equipped with a camera (not shown). The CPU 401 realizes various functions by reading out various programs and data stored in the memory 405 and the storage device 406 and executing processing. The communication unit 402 communicates with the outside via the Internet, short-range wireless communication, etc., and transmits and receives various data and signals. The communication method used by the communication unit 402 may be, for example, the Wi-Fi (registered trademark) standard of wireless LAN, which is short-range wireless communication, or the Bluetooth (registered trademark) standard.

[0035] The display unit 403 displays various information based on instructions from the CPU 401. The external I / F 404 is an interface for transmitting and receiving data to and from an external device, and accepts data input via an operation device (not shown) such as a mouse or keyboard. The memory 405 is a storage area for storing and holding various information, and is configured, for example, by a ROM (Read Only Memory), which is a non-volatile storage area, or a RAM (Random Access Memory), which is a volatile storage area. The storage device 406 is a storage area for storing and holding various information, and is configured by an HDD (Hard Disk Drive), etc. Various DBs according to this embodiment may be stored in the storage device 406.

[0036] [Database Configuration] Fig. 5 is a diagram showing an example of a DB configuration according to this embodiment. The DB configuration shown here is an example, and is not limited to this configuration. Therefore, any of the DBs shown in Fig. 5 may be configured as one DB, or one DB may be divided into multiple DBs. Furthermore, other items may be further added.

[0037] FIG. 5(a) shows an example of the configuration of a face information DB according to this embodiment. The face information DB is managed, for example, by the parent face information management unit 32 or the child face information management unit 33 of the face authentication system 30. The face information DB includes columns for Person ID, face image, name, phone number, and SNS. The Person ID column indicates Person ID, which is identification information for uniquely identifying a user. The Person ID is assigned, for example, by the face authentication system 30 when the user is registered. Note that the specifications of the IDs included in each DB shown below (such as the number of digits and characters used) are merely examples and are not limited to those shown in FIG. 5. The face image column indicates a face image corresponding to the face of a registered user. The face image may be stored as registered image data, or may be converted into a specific data format according to the face authentication algorithm or the like before being stored. The face image column may also indicate a storage location for the face image.

[0038] The name column indicates the name information of the user. The phone number column indicates the phone number of the user. The SNS column indicates the information used on the user's SNS (Social Network Service). For example, email addresses and account information are set in the SNS column. Note that there are no particular limitations on the services that can be used as SNS, and examples include communication tools such as email. Note that this name information is used as the display name of each user (child) on the parent mobile terminal 10.

[0039] FIG. 5(b) shows an example of the configuration of the rights information DB according to this embodiment. The rights information DB is managed, for example, by the parent rights management unit 35 of the face authentication system 30. The rights information DB includes columns for rights ID, person ID, and rights information details. The rights ID column indicates a rights ID, which is identification information for uniquely identifying a right. The rights ID is assigned, for example, when a user (parent) acquires a right. The person ID column indicates the person ID of the user who has the right (i.e., the user (parent)), and corresponds to the person ID shown in FIG. 5(a). The rights information details column indicates detailed information about the rights. The content of the detailed information here changes depending on the content of various services provided by the service providing system 50. For example, if the service is an accommodation management service, information such as the accommodation facility, accommodation date and time, number of guests, and accommodation plan is managed as detailed rights information.

[0040] FIG. 5(c) shows an example of the configuration of a group DB according to this embodiment. The group DB is managed, for example, by the parent face information management unit 32 of the face authentication system 30. The group DB includes columns for a group ID, a rights ID, a parent member ID, and a child member ID. The group ID column indicates a group ID, which is information for uniquely identifying a group. The group ID is assigned, for example, when a user (parent) sets up a group. The rights ID column indicates the rights ID of the rights used in the group, and corresponds to the rights ID shown in FIG. 5(b). The parent member ID column indicates the person ID of the user (parent) who is the administrator of the group, and corresponds to the person ID shown in FIG. 5(b). The child member ID column indicates the person ID of a user (child) who belongs to the group, and corresponds to the person ID in FIG. 5(a).

[0041] Fig. 5(d) shows another example of the configuration of the rights information DB according to this embodiment. Details of Fig. 5(d) will be described later together with application examples of the present disclosure.

[0042] [Operation sequence] Next, the processing sequence between devices in the system according to this embodiment will be explained. The processing according to this embodiment is divided into two steps: a rights registration process and a rights usage (checking) process. In the registration process, a user (parent) registers the rights he or she owns and one or more users (children) who can use those rights. In the usage process, whether or not the registered rights can be used is determined based on the user's facial image, and the rights are used according to the result. The flow of each process will be explained below using the drawings.

[0043] (Registration process) 6 is a diagram showing a processing sequence of the registration process according to the present embodiment. Each device, which is a processing subject in the processing sequence, realizes each function by, for example, a control unit such as a CPU reading and executing a program corresponding to each function shown in FIG.

[0044] The parent mobile terminal 10 receives a registration instruction from the user (step S601). The registration instruction here may be given via a screen (not shown) that is displayed when the user accesses a system that corresponds to the service to be used. The registration instruction may also be configured to allow the user to select whether or not to register a right when the right is acquired in subsequent step S602.

[0045] The parent mobile terminal 10 acquires the desired rights via a screen displayed by accessing a system corresponding to the service to be used (step S602). For example, assume a case where a reservation for use of a facility is made using the facility management system 53. In this case, a reservation for use of the facility is made via a reservation screen 700 as shown in FIG. 7(a). The reservation screen 700 includes setting items for reservation details 701 and reservation user information 704 (customer information). The reservation details 701 include a facility name 702 indicating the facility to be used and a date and time 703 indicating the date and time of use. The reservation user information 704 includes a name 705 indicating the name of the person making the reservation and a contact information 706 indicating the contact information of the person making the reservation. The user makes a reservation by entering each piece of displayed information and then pressing a reservation button 707. That is, in the example of FIG. 7(a), the user acquires the right to use the facility by making a reservation. Note that the reservation screen 700 shown in FIG. 7(a) is merely an example, and the displayed and input items may vary depending on the content of the service to be used. After the parent mobile terminal 10 has acquired the right, it notifies the face authentication system 30 of information relating to the right.

[0046] The face authentication system 30 stores the rights acquired by the user as parent right information based on the data received from the parent mobile terminal 10 (step S603). Specifically, the parent right information is registered in the right information DB shown in FIG. 5(b).

[0047] The parent mobile terminal 10 photographs the face of the user who will become the parent and acquires it as a facial image (step S604). For example, the parent mobile terminal 10 displays a photographing screen 710 for registering the facial image of the user (parent) as shown in FIG. 7(b) to prompt the user to take a photograph. The photographing screen 710 may display an icon 711 or a message to acquire an appropriate facial image. After acquiring the facial image, the parent mobile terminal 10 registers it as the facial image of the user (parent) in the facial authentication system 30. Note that the parent mobile terminal 10 may be configured to allow the user to select a facial image from images that have already been photographed.

[0048] The face authentication system 30 registers the face image of the user (parent) acquired from the parent mobile terminal 10 (step S605). Specifically, the face image of the user (parent) is registered in the face information DB shown in Fig. 5(a). At this time, the face authentication system 30 may perform a process of converting the face image into arbitrary data according to a face authentication algorithm or the like.

[0049] The parent mobile terminal 10 sets up a group including one or more users (children) who can use the acquired rights (step S606). For example, the parent mobile terminal 10 displays a registration screen such as those shown in FIGS. 7(c) and 7(d) to allow the user (parent) to set up a group. FIG. 7(c) shows an example of the configuration of a group registration screen 720. The registration screen 720 displays a list 721 of users (children) included in the group. In the example of FIG. 7(c), as shown by icons 722, two users are designated as children, "child 1" and "child 2." A user (child) can be added by pressing an add button 723. Pressing the add button 723 displays a registration screen 730 shown in FIG. 7(d). The registration screen 730 is a screen for setting information about the user (child), and displays setting items 731 indicating basic information about the user (child). In the example of FIG. 7(d), the basic information includes the user's (child's) name 732, face information 733, phone number 735, and SNS 736. The registration screen 730 further has a registration button 734 and a send button 737. When the registration button 734 is pressed, the parent mobile terminal 10 takes a face image of the user who will become the child. On the other hand, when the send button 737 is pressed, the child mobile terminal 20 carried by the user who will become the child takes a face image of the user. The parent mobile terminal 10 transmits various setting information of the group to the face authentication system 30, and registers the group.

[0050] The face authentication system 30 registers the group using the various setting information of the group received from the parent mobile terminal 10 (step S607). Specifically, the group information is registered in the group DB shown in FIG. 5(c).

[0051] The parent mobile terminal 10 determines whether the facial image of the user who will become a child is to be acquired from the parent mobile terminal 10 or the child mobile terminal 20 (step S608). As described above, when the registration button 734 is pressed on the registration screen 730 of FIG. 7(d), it is assumed that the facial image of the user who will become a child is to be captured by the parent mobile terminal 10 (step S608, YES), and the processing of the parent mobile terminal 10 proceeds to step S609. On the other hand, when the send button 737 is pressed on the registration screen 730 of FIG. 7(d), it is assumed that the facial image of the user who will become a child is to be captured by the child mobile terminal 20 (step S608, NO), and the processing of the parent mobile terminal 10 proceeds to step S610.

[0052] The parent mobile terminal 10 photographs the face of the user who will become the child and acquires it as a facial image (step S609). For example, the parent mobile terminal 10 displays a photographing screen 800 for registering a facial image of the user (child) as shown in FIG. 8(a) to prompt the user to take a photograph. The photographing screen 800 may display an icon 801 or a message to acquire an appropriate facial image. After acquiring the facial image, the parent mobile terminal 10 registers it as the facial image of the user (child) in the facial authentication system 30. Note that the parent mobile terminal 10 may be configured to allow the user to select a facial image from images that have already been taken.

[0053] The parent mobile terminal 10 transmits a request to the child mobile terminal 20 to capture facial information (face image) of the user who will become a child (step S610). The request here includes access information (child registration link) to the face authentication system 30 used when registering the facial image. The request may be transmitted by email, for example, and the destination may be the information set in the SNS 736 on the registration screen 730 of FIG. 7(d). When the request is transmitted by email, for example, email 810 with content as shown in FIG. 8(b) may be transmitted. A subject 811 indicating an outline of the request is set in the email 810. The body 812 also includes details of the request and a registration button 813 for executing face registration. When the registration button 813 is pressed, the facial image registration process is performed.

[0054] The child mobile terminal 20 photographs the face of the user who will become the child based on the registration request (e.g., email 810) received from the parent mobile terminal 10, and acquires the photograph as a facial image (step S611). For example, when a registration button 813 indicated in the email 810 is pressed, the child mobile terminal 20 displays a photographing screen 820 for registering the facial image of the user (child) as shown in FIG. 8(c) to prompt the user to take a photograph. The photographing screen 820 may display an icon 821, a message, or the like to acquire an appropriate facial image. After acquiring the facial image, the child mobile terminal 20 registers the acquired facial image as the facial image of the user (child) in the face authentication system 30. This processing may be performed using a predetermined SNS app in response to the registration request received from the parent mobile terminal 10, or may be performed via a web browser (not shown), etc.

[0055] The face authentication system 30 registers the face image of the user (child) received from the parent mobile terminal 10 or the child mobile terminal 20 (step S612). Specifically, the face image of the user (child) is registered in the face information DB shown in Fig. 5(a). At this time, the face authentication system 30 may perform a process of converting the face image into arbitrary data according to a face authentication algorithm or the like.

[0056] The face authentication system 30 sets up a parent-child relationship based on the information of the registered user (parent) and user (child) (step S613). Specifically, the contents of the group DB shown in Fig. 5(c) are updated based on the specified information, thereby associating each user. In this embodiment, a registrant of a group is set as a user (parent), and other users belonging to the group are set as users (child).

[0057] The parent mobile terminal 10 accepts the right setting for the user (child) (step S614). For example, the right setting for the user (child) is performed by displaying a setting screen 830 as shown in FIG. 8(d). The setting screen 830 displays basic information 831 of the user (child) that has already been set and right information 832 that the user (child) is permitted to use. Here, the items of the right information 832 are assumed to be payment services, and include payment availability 833, a payment upper limit amount 834, and coupon availability 835. When the setting button 836 is pressed, the content of the entered right information 832 is passed to the face authentication system 30, which instructs registration. The setting screen 830 shown in FIG. 8(d) is an example, and the displayed and input items may vary depending on the content of the service to be used.

[0058] The face authentication system 30 determines whether the rights information of the user (child) received from the parent mobile terminal 10 is within the scope of the rights of the user (parent) (step S615). At this time, if the rights of the user (parent) are exceeded, the face authentication system 30 may notify the parent mobile terminal 10 of this fact and prompt the user to re-enter the information. Alternatively, the setting screen 830 shown in FIG. 8(d) may be configured to be controlled so that settings that exceed the rights of the user (parent) cannot be specified.

[0059] Based on the confirmation result in step S615, the face authentication system 30 stores the rights information for the user (child) (step S616), and then ends this processing sequence in FIG.

[0060] In the above example, the child rights information is set (step S614) after each face image is registered, but the procedure is not limited to this. For example, the setting of the user (child) rights information may be performed together with the group setting process (step S606). If the face image of the child user is not registered, even if rights information is set for the child, the rights cannot be used.

[0061] Furthermore, adding or deleting a user (child) to a group may be done at any time, and is not limited to the timing of setting up the group. Furthermore, the parent-child relationship is not limited to that set up when the group is registered. For example, a configuration may be possible in which a user (parent) can be changed at any time.

[0062] Furthermore, rights of the user (parent) may be added or deleted at any time. A configuration may be adopted in which the user (parent) can update an already created group by adding or deleting new rights. In this case, instead of the processing of steps S604 to S607, a configuration may be adopted in which a group to which newly acquired rights are to be associated can be selected from groups already created in association with the user (parent).

[0063] Furthermore, when setting up a group, a configuration may be adopted in which a group already created by the user (parent) can be copied and created, thereby reducing the time and effort required for group setting up.

[0064] (Matching process: basic pattern) Next, the matching process according to this embodiment will be described. FIG. 9 is a diagram showing a processing sequence of the matching process according to this embodiment. Each device, which is the processing subject in the processing sequence, realizes each function by, for example, a control unit such as a CPU reading and executing a program corresponding to each function shown in FIG. 2. It is assumed that various information has been registered by the registration process described with reference to FIG. 6 before the matching process described below. Furthermore, the basic processing flow remains the same regardless of whether the user performing face matching is a parent or a child. However, in order to more clearly explain the features of the present disclosure, the following description will be given assuming that the user who is the target of face authentication (hereinafter referred to as the "target user") is a user (child).

[0065] First, the face matching terminal 40, face authentication system 30, and service providing system 50 cooperate to perform a common face matching process (step S900). The common face matching process is made up of steps S901 to S907. This process is also performed in common in other cases described below. Note that although the screens displayed and the contents of data exchanged between various devices may change depending on the case in which it is applied, the general flow is the same.

[0066] The face matching terminal 40 receives a face matching instruction (step S901). The instruction here may be given, for example, by an operator of a facility where the face matching terminal 40 is installed performing an instruction operation when performing face matching.

[0067] The face matching terminal 40 photographs the face of the target user using a camera (not shown) and acquires it as a face image (step S902). For example, the face matching terminal 40 displays a photographing screen 1000 for face matching as shown in Fig. 9(a) to prompt the target user to photograph. The photographing screen 1000 may display an icon 1001, a message, or the like to acquire an appropriate face image.

[0068] Face matching terminal 40 sets the right of use for the target user (step S903). The setting here may be predefined on the face matching terminal 40 side depending on the content of the service to be used, or may be performed by an operator of the facility where face matching terminal 40 is installed selecting from several options. For example, if the service to be used is admission to a facility, "admission" is set as the right of use.

[0069] The face matching terminal 40 transmits an authentication request (matching request) including the face image acquired in step S902 and the right set in step S903 to the face authentication system 30 (step S904).

[0070] The face authentication system 30 checks the registration status of the face information based on the authentication request received from the face matching terminal 40 (step S905). Here, the face authentication system 30 performs face authentication processing by referring to the face information DB shown in FIG. 5(a). As described above, any known face authentication method can be used, and there is no particular limitation. For example, methods such as template matching, feature point extraction, and 3D face authentication may be used. This makes it possible to identify the target user indicated by the face image.

[0071] The face authentication system 30 identifies the parent-child relationship of the target user (here, user (child)), and identifies the user (parent) and its rights information (step S906). For example, the face authentication system 30 performs processing by referring to the rights information DB and group DB shown in FIGS. 5(b) and 5(c). Furthermore, as necessary, the face authentication system 30 requests confirmation of the rights held by the user from any system included in the service providing system 50, which is an external system. Whether or not this confirmation request is sent or received depends on the configuration of the various DBs, the content of the service being used, etc.

[0072] When the service providing system 50 receives a right confirmation request from the face authentication system 30, it performs a process of confirming the right of each user in response to the request and returns the result to the face authentication system 30 (step S907). As described above, the confirmation process on the service providing system 50 side may be omitted depending on the DB configuration, system configuration, etc. The process up to this point is the common face matching process included in step S900.

[0073] The face authentication system 30 notifies the face matching terminal 40 of the result of the face matching common processing (step S908). Here, as an example, a description will be given assuming that face authentication of the user is set in step S903. In this case, the face authentication system 30 notifies the face matching terminal 40 of the authentication result based on the face image of the user.

[0074] The face matching terminal 40 displays the processing result received from the face authentication system 30 (step S909). For example, the face matching terminal 40 displays an authentication result screen 1010 as shown in Fig. 10(b). The authentication result screen 1010 includes an icon 1011 indicating the authentication result, a face image 1012 used for face authentication, user information 1013 of the target user, and a message 1014 regarding the authentication result.

[0075] The face authentication system 30 stores the processing result of the common face matching process in step S900 as history information (step S910). For example, when face authentication is performed, information indicating that face authentication has been performed and the authentication result are stored. In other words, the contents of the rights that the user has used or attempted to use are stored.

[0076] The face authentication system 30 identifies the parent mobile terminal 10 owned by the user (parent) based on the parent-child relationship identified in step S906, and notifies the parent mobile terminal 10 of the history information saved in step S910 (step S911). Here, the notification may be sent by email, for example.

[0077] The parent mobile terminal 10 displays the notification received from the face authentication system 30. When the notification is made by email, for example, an email 1020 with the content shown in FIG. 10(c) may be sent. In the email 1020, a subject 1021 indicating an overview of the history information is set. Furthermore, a body 1022 includes details of the history information (such as the content of the rights used). Then, this processing sequence in FIG. 9 ends.

[0078] In the above processing sequence, an example is shown in which the details of use are notified for each use of a right. However, this is not limited to this, and for example, a configuration may be adopted in which the usage history for a predetermined period is notified in chronological order or as a cumulative result. Furthermore, the timing of notification to the user (parent) is not limited to the timing of right use, but may be configured so that the user (parent) can set the timing of notification as desired. Such notification setting may be configured, for example, in the group setting process (step S606) in FIG. 6, so that notification is performed according to the setting contents.

[0079] (Matching process: Facility use case) The basic processing sequence of the matching process according to this embodiment has been described with reference to Figures 9 and 10. Next, a case where this basic processing sequence is applied to a facility usage case will be described.

[0080] In this case, it is assumed that a user (parent) has purchased and registered in advance the right to use a facility multiple times (or for multiple people) (e.g., admission rights) based on the registration process shown in FIG. 6 . In this case, a configuration may be adopted in which users belonging to a group can use the rights associated with the group without identifying the rights associated with the group, or a configuration may be adopted in which the rights assigned to each user (child) are identified and used. In the former case, implementation is possible using, for example, the rights information DB configuration shown in FIG. 5( b). In the latter case, implementation is possible using, for example, the rights information DB configuration shown in FIG. 5( d). In the rights information DB configuration shown in FIG. 5( d), when a user (parent) registers multiple usage rights (here, tickets for facility use) in association with a group, each of the multiple usage rights is assigned to a user (child) who can use the rights. In this configuration, the user (child) uses the assigned usage right from among the multiple usage rights associated with the group.

[0081] 11 is a diagram showing a processing sequence when the verification process according to this embodiment is applied to facility use. Each device, which is the processing subject in the processing sequence, realizes each function by, for example, a control unit such as a CPU reading and executing a program corresponding to each function shown in FIG.

[0082] The face matching terminal 40, face authentication system 30, and service providing system 50 cooperate to perform a common face matching process (step S900). This process is the common face matching process described with reference to FIG. 9. During this process, for example, the face matching terminal 40 displays a photographing screen 1200 for face matching as shown in FIG. 12(a) to prompt the target user to take a photograph. The photographing screen 1200 may display an icon 1201, a message, or the like to acquire an appropriate face image.

[0083] The face authentication system 30 checks the rights information available to the target user (here, user (child)) and updates the rights information to be used according to the matching results of the common face matching process (step S1101). For example, the face authentication system 30 performs the checking process by referring to the rights information DB and group DB shown in FIGS. 5(b) and 5(c). Furthermore, as necessary, the face authentication system 30 sends an update request to any system included in the service providing system 50, which is an external system, in connection with the use of the rights held by the user (parent). Whether or not this update request is sent or received depends on the configuration of the various DBs and the content of the service being used. For example, in the case of the right to enter a facility, the DB is updated to indicate that the right has been used (lost) upon entry.

[0084] When the service providing system 50 receives an update request for use of a right from the face authentication system 30, it performs an update process for the right of each user in response to the request and returns the result to the face authentication system 30 (step S1102). As described above, the update process on the service providing system 50 side may be omitted depending on the DB configuration, system configuration, etc.

[0085] Based on the processing contents up to this point, the face authentication system 30 notifies the face matching terminal 40 of the availability information indicating whether the target user can use the right (step S1103). Specifically, the face authentication of the user (child) is successful, and the system notifies whether the user (child) can use the facility.

[0086] The face matching terminal 40 displays the availability information received from the face authentication system 30 (step S1104). For example, the face matching terminal 40 displays an authentication result screen 1210 as shown in Fig. 12(b). The authentication result screen 1210 includes an icon 1211 indicating availability, a face image 1212 used for face authentication, user information 1213 of the target user, and a message 1214 regarding the authentication result.

[0087] The face authentication system 30 stores the usage result received from the service providing system 50 as history information (step S1105). Specifically, when using a facility, information such as the success or failure of face authentication, whether the facility can be used, and the date and time of use is stored. In other words, the contents of the rights that the target user has used or attempted to use are stored.

[0088] The face authentication system 30 identifies the parent mobile terminal 10 owned by the user (parent) based on the parent-child relationship identified in the common face matching process in step S900, and notifies the parent mobile terminal 10 of the history information saved in step S1105 (step S1106). Here, the notification may be sent by email, for example.

[0089] The parent mobile terminal 10 displays the notification received from the face authentication system 30. When the notification is made by email, for example, an email 1220 with the content as shown in FIG. 12(c) may be sent. In the email 1220, a subject 1221 indicating an overview of the history information is set. Furthermore, the body 1222 includes details of the usage information (date and time of usage, user, facility name, etc.). Then, this processing sequence in FIG. 11 ends.

[0090] (Matching process: Payment use case) Next, a case where the basic processing sequence explained in FIGS. 9 and 10 is applied to the use of a payment service will be explained.

[0091] In this case, it is assumed that the user (parent) has registered account information available for payment in advance as a right to use the payment service in cooperation with payment system 51, which is one of service providing systems 50, based on the registration process shown in Fig. 6. More specifically, whether payment can be used 833 and the upper limit of payment amount 834 are set on setting screen 830 shown in Fig. 8(d).

[0092] 13 is a diagram showing a processing sequence when the matching process according to this embodiment is applied to the use of a payment service. Each device, which is the processing subject in the processing sequence, realizes each function by, for example, a control unit such as a CPU reading and executing a program corresponding to each function shown in FIG.

[0093] The face matching terminal 40, the face authentication system 30, and the service providing system 50 cooperate to perform a common face matching process (step S900). This process is the common face matching process described with reference to FIG. 9. During this process, for example, the face matching terminal 40 displays a payment screen 1400 as shown in FIG. 14(b) to accept the setting of the right to use (step S903). The payment screen 1400 includes payment information 1401 indicating the payment amount, a cancel button 1402 for canceling the execution of the payment, and a confirm button 1403 for instructing the execution of the payment. Furthermore, during the common face matching process, the face matching terminal 40 displays a photographing screen 1410 for face matching as shown in FIG. 14(b) to prompt the target user to take a photograph. The photographing screen 1410 may display an icon 1411, a message, or the like to acquire an appropriate face image.

[0094] The face authentication system 30 checks the rights information available to the target user (here, user (child)), and confirms the rights information to be used according to the matching result of the common face matching process (step S1301). For example, the face authentication system 30 performs the confirmation process by referring to the rights information DB and group DB shown in FIGS. 5(b) and 5(c). Furthermore, the face authentication system 30 identifies the service providing system 50 (here, the payment system 51) that provides the service to be used based on the rights.

[0095] The face authentication system 30 requests the service providing system 50 (here, the payment system 51) that provides the service used by the user to use the service based on the identified right (step S1302). This request includes the usage amount, user information, etc.

[0096] The service providing system 50 provides the service based on the request from the face authentication system 30 (step S1303). Specifically, the payment system 51 performs payment processing based on the specified amount. Then, the service providing system 50 returns the result of service use based on the right to the face authentication system 30.

[0097] The face authentication system 30 notifies the face matching terminal 40 of the usage result received from the service providing system 50 (step S1304).

[0098] The face matching terminal 40 displays the usage result received from the face authentication system 30 (step S1305). For example, the face matching terminal 40 displays a usage result screen 1420 as shown in Fig. 14(c). The usage result screen 1420 includes an icon 1421 indicating the result of the payment, a payment amount 1422, and an end button 1423 for closing the usage result screen 1420.

[0099] The face authentication system 30 stores the usage result received from the service providing system 50 as history information (step S1306). Specifically, when a payment service is used, information such as the success or failure of face authentication, the payment amount, and the date and time of use is stored. In other words, the content of the rights that the user has used or attempted to use is stored.

[0100] The face authentication system 30 identifies the parent mobile terminal 10 owned by the user (parent) based on the parent-child relationship identified in the common face matching process in step S900, and notifies the parent mobile terminal 10 of the history information saved in step S1306 (step S1307). Here, the notification may be sent by email, for example.

[0101] The parent mobile terminal 10 displays the notification received from the face authentication system 30. When the notification is made by email, for example, email 1430 with the content shown in FIG. 14(d) may be sent. In the email 1430, a subject 1431 indicating an overview of the history information is set. Furthermore, the body 1432 includes details of the usage information (such as the date and time of usage, the user, and the payment amount). Then, this processing sequence in FIG. 13 ends.

[0102] (Matching process: Variation 1 for payment use) 13 and 14 have described a case where the application is to a payment service. Here, a modified example of the case where the application is to a payment service will be further described. More specifically, a case where the rights setting of a user (child) is updated based on the processing sequence of FIG. 13 will be described. Note that processes that overlap with those shown in FIG. 13 are given the same reference numbers, and descriptions thereof will be omitted.

[0103] The parent mobile terminal 10 accepts right settings for the user (child) (step S1501). For example, right settings for the user (child) are performed by displaying a setting screen 1600 as shown in FIG. 16(a). The setting screen 1600 displays basic information 1601 of the user (child) that has already been set, and right information 1602 granted to the user (child). Items in the right information 1602 include payment availability 1603, a payment upper limit 1604, whether notification to the user (parent) is required 1605, and conditions for notification 1606. The payment upper limit 1604 is set as a cumulative amount that can be used. The condition 1606 may specify, for example, that the remaining available amount, as a result of use of the amount set in the payment upper limit 1604, becomes a predetermined amount (e.g., less than 1,000 yen). When the setting button 1607 is pressed, the parent mobile terminal 10 passes the content of the input rights information 1602 to the face authentication system 30 and instructs it to be registered.

[0104] The face authentication system 30 determines whether the rights information of the user (child) received from the parent mobile terminal 10 is within the range of the rights of the user (parent) (step S1502). At this time, if the rights of the user (parent) are exceeded, the face authentication system 30 may notify the parent mobile terminal 10 of this fact and prompt the user to re-enter the information. Alternatively, the setting screen 1600 shown in Fig. 16(a) may be configured so that settings that exceed the rights of the user (parent) cannot be specified.

[0105] Based on the confirmation result of step S1502, the face authentication system 30 stores the rights information for the user (child) (step S1503).

[0106] Next, the face matching terminal 40, the face authentication system 30, and the service providing system 50 cooperate to perform a common face matching process (step S900). This process is the common face matching process described with reference to FIG. 9. During this process, for example, the face matching terminal 40 displays a payment screen 1610 as shown in FIG. 16(b) to accept the setting of the right to use (step S903). The payment screen 1610 includes payment information 1611 indicating the payment amount, a cancel button 1612 for canceling the execution of the payment, and a confirm button 1613 for instructing the execution of the payment. Furthermore, during the common face matching process, the face matching terminal 40 displays a photographing screen 1620 for face matching as shown in FIG. 16(c) to prompt the user to take a photograph of the target user. The photographing screen 1620 may display an icon 1621, a message, or the like to acquire an appropriate face image.

[0107] The face authentication system 30 performs the processes of steps S1301 to S1306, similar to the processing sequence shown in Fig. 13. In this series of flows, the face matching terminal 40 displays a usage result screen 1630 as shown in Fig. 16(d) as the usage result of the payment service. The usage result screen 1630 includes an icon 1631 indicating the result of the payment, a payment amount 1632, and an end button 1633 for closing the usage result screen 1630.

[0108] After the processing of step S1306, the face authentication system 30 determines whether the notification conditions set on the setting screen 1600 are met as a result of using the service (step S1504). In this example, it is assumed that the payment upper limit 1604 is set to "10,000 yen," the notification requirement 1605 is set to "ON," and the notification condition 1606 is set to "less than 1,000 yen" on the setting screen 1600. In this case, as shown in FIG. 16(d), if the payment amount is "9,980 yen," the condition 1606 is met. If the notification condition for resetting is met (step S1504, YES), the processing of the face authentication system 30 proceeds to step S1505. On the other hand, if the notification condition for resetting is not met (step S1504, NO), the processing of the face authentication system 30 proceeds to step S1307.

[0109] The face authentication system 30 identifies the parent mobile terminal 10 owned by the user (parent) based on the parent-child relationship identified in the common face matching process in step S900, and notifies the parent mobile terminal 10 of the history information saved in step S1306 (step S1505). The notification here may be sent by email, for example. The notification here includes a message urging the user (child) to reset their rights.

[0110] The parent mobile terminal 10 displays the notification received from the face authentication system 30 (step S1308). If the notification is sent by email and the notification includes a message prompting the user to reset the rights in step S1505, an email 1640 with content such as that shown in FIG. 16(e) may be sent. The email 1640 includes a subject 1641 indicating an overview of the history information. The body 1642 includes details of the usage information (such as the date and time of use, the user, and the payment amount) and a message prompting the user (child) to reset the rights. The email 1640 also includes a change button 1643 for changing the settings of the user (child) rights. If the processing of step S1307 is performed, the parent mobile terminal 10 displays an email such as that shown in FIG. 14(d).

[0111] The parent mobile terminal 10 determines whether or not an instruction to reset the rights of the user (child) has been issued (step S1506). For example, if the change button 1643 in the email 1640 shown in FIG. 16(e) is pressed, it is assumed that an instruction to reset has been issued (step S1506, YES), and the processing of the parent mobile terminal 10 returns to step S1506, where the parent mobile terminal 10 resets the rights of the user (child). At this time, the parent mobile terminal 10 causes the right setting for the user (child) to be executed by displaying, for example, a setting screen 1650 as shown in FIG. 16(f). The configuration of the setting screen 1650 is basically the same as the setting screen 1600 shown in FIG. 16(a). Here, as shown in the payment upper limit 1651, it may be configured to display the values ​​before and after the change. If an instruction to reset has not been issued (step S1506, NO), the processing returns to step S900, and the processing is repeated as appropriate.

[0112] (Matching process: Variation 2 for payment use) 13 and 14 have described a case where the application is to a payment service. Here, a second modified example of a case where the application is to a payment service will be described. More specifically, a case where the rights settings of a user (child) are updated based on the processing sequence of FIG. 13 will be described. Note that processes that overlap with those shown in FIG. 13 will be given the same reference numbers and will not be described again. Here, an example will be described assuming an insufficient balance, i.e., an attempt to make a payment that exceeds the upper limit of the available amount.

[0113] The face matching terminal 40, the face authentication system 30, and the service providing system 50 cooperate to perform a common face matching process (step S900). This process is the common face matching process described with reference to FIG. 9. During this process, for example, the face matching terminal 40 displays a payment screen 1800 as shown in FIG. 18(a) to accept the setting of the right to use (step S903). The payment screen 1800 includes payment information 1801 indicating the payment amount, a cancel button 1802 for canceling the execution of the payment, and a confirm button 1803 for instructing the execution of the payment. Furthermore, during the common face matching process, the face matching terminal 40 displays a photographing screen 1810 for face matching as shown in FIG. 18(b) to prompt the target user to take a photograph. The photographing screen 1810 may display an icon 1811, a message, or the like to acquire an appropriate face image.

[0114] The face authentication system 30 performs the processes of steps S1301 to S1306, similar to the processing sequence shown in Fig. 13. In this series of flows, the face matching terminal 40 displays a usage result screen 1820 as shown in Fig. 18(c) as the result of using the payment service. The usage result screen 1820 includes an icon 1821 indicating the result of the payment, a payment amount 1822, and an end button 1823 for closing the usage result screen 1820. Here, a case is shown in which the payment failed due to insufficient balance.

[0115] After the process of step S1306, the face authentication system 30 determines whether or not the payment has failed due to insufficient balance as a result of using the service (step S1701). If the payment has failed due to insufficient balance (step S1701, YES), the process of the face authentication system 30 proceeds to step S1702. On the other hand, in other cases (step S1701, NO), the process of the face authentication system 30 proceeds to step S1307.

[0116] The face authentication system 30 identifies the parent mobile terminal 10 owned by the parent user based on the parent-child relationship identified in the common face matching process in step S900, and notifies the parent mobile terminal 10 of the history information saved in step S1306 (step S1702). Here, the notification may be sent by email, for example. Here, the notification includes content that includes wording urging the user (child) to reset their rights.

[0117] The parent mobile terminal 10 displays the notification received from the face authentication system 30 (step S1308). If the notification is sent by email and the notification includes a message prompting the user to reset the rights in step S1505, for example, email 1830 with content as shown in FIG. 18(d) may be sent. The email 1830 includes a subject 1831 indicating an overview of the history information. The body 1832 includes details of the usage information (such as the date and time of use, the user, and the payment amount) and a message prompting the user (child) to reset the rights. The email 1830 also includes a change button 1833 for changing the settings of the user (child) rights. If the processing of step S1307 is performed, the parent mobile terminal 10 displays email 1430 as shown in FIG. 14(d).

[0118] The parent mobile terminal 10 determines whether or not an instruction to reset the user's (child's) rights has been issued (step S1703). For example, if the change button 1833 of the email 183 shown in Fig. 18(d) is pressed, it is determined that an instruction to reset has been issued (step S1703, YES), and the processing of the parent mobile terminal 10 proceeds to step S1704. If an instruction to reset has not been issued (step S1703, NO), the processing returns to step S900, and the processing is repeated as appropriate.

[0119] The parent mobile terminal 10 accepts right settings for the user (child) (step S1704). For example, right settings for the user (child) are performed by displaying a setting screen 1840 as shown in FIG. 18(e). The setting screen 1840 displays basic information 1841 of the user (child) that has already been set, and right information 1842 that is permitted for the user (child). Items of the right information 1842 here include payment availability 1843 and a payment upper limit 1844. The payment upper limit 1844 sets the cumulative amount that can be used. As shown in the payment upper limit 1844, the parent mobile terminal 10 may be configured to display the values ​​before and after the change. When the setting button 1845 is pressed, the parent mobile terminal 10 passes the content of the input right information 1842 to the face authentication system 30 and instructs it to register.

[0120] The face authentication system 30 determines whether the rights information of the user (child) received from the parent mobile terminal 10 is within the range of the rights of the user (parent) (step S1705). At this time, if the rights of the user (parent) are exceeded, the face authentication system 30 may notify the parent mobile terminal 10 of this fact and prompt the user to re-enter the information. Alternatively, the setting screen 1840 shown in FIG. 18(e) may be configured so that settings that exceed the rights of the user (parent) cannot be specified.

[0121] Based on the confirmation result in step S1705, the face authentication system 30 stores the rights information for the user (child) (step S1706), and then ends this processing sequence in FIG.

[0122] In the above example, the available amount and remaining amount are described as being common to the entire group, but an upper limit or remaining amount may be set for each user (child). In this case, a setting screen may be provided that displays the setting information for each user (child) in an identifiable manner. For example, even if the remaining amount is 10,000 yen, a certain user (child) may be restricted to using only up to 500 yen unless the parent mobile terminal 10 resets the rights. In this way, it is possible to prevent a user (child) from excessively using the rights of the entire group.

[0123] (Matching process: Case of using accommodation management service) 9 and 10 will be described when applied to the use of an accommodation management service. The accommodation management service here is a service provided in cooperation with the accommodation management system 52 of the service providing system 50, and will be described as a service that presents user information related to accommodation through facial recognition.

[0124] 19 is a diagram showing a processing sequence when the verification process according to this embodiment is applied to facility use. Each device, which is the processing subject in the processing sequence, realizes each function by, for example, a control unit such as a CPU reading and executing a program corresponding to each function shown in FIG.

[0125] The face matching terminal 40, face authentication system 30, and service providing system 50 cooperate to perform a common face matching process (step S900). This process is the common face matching process described with reference to FIG. 9. During this process, for example, the face matching terminal 40 displays a photographing screen 2000 for face matching as shown in FIG. 20(a) to prompt the target user to take a photograph. The photographing screen 2000 may display an icon 2001, a message, or the like to acquire an appropriate face image.

[0126] The face authentication system 30 requests information registered for the identified user from the service providing system 50 (here, the accommodation management system 52) that provides the service used by the user (step S1901). This request includes user information (such as parent-child relationship) managed by the face authentication system 30.

[0127] The service providing system 50 provides the service based on the request from the face authentication system 30 (step S1902). Specifically, the accommodation management system 52 identifies the registration information based on the specified user information. Then, the service providing system 50 returns the identified registration information to the face authentication system 30.

[0128] The face authentication system 30 notifies the face matching terminal 40 of the registration information received from the service providing system 50 (step S1903).

[0129] The face matching terminal 40 displays the registration information received from the face authentication system 30 (step S904). For example, the face matching terminal 40 displays an information provision screen 2010 as shown in FIG. 20(b). The information provision screen 2010 includes an icon 2011 indicating the face authentication result, a face image 2012 used for the face authentication, and information 2013 registered in association with the user (child). In this example, the information 2013 indicates a room number of an accommodation facility.

[0130] The face authentication system 30 stores the service usage results, including the registration information received from the service providing system 50, as history information (step S1905). Specifically, when the accommodation management service is used, information such as the success or failure of face authentication, the provided registration information, and the date and time of service usage is stored.

[0131] The face authentication system 30 identifies the parent mobile terminal 10 owned by the user (parent) based on the parent-child relationship identified in the common face matching process in step S900, and notifies the parent mobile terminal 10 of the history information saved in step S1905 (step S1906). The notification here may be sent by email, for example.

[0132] The parent mobile terminal 10 displays the notification received from the face authentication system 30. When the notification is made by email, for example, an email 2020 with the content as shown in FIG. 20(c) may be sent. In the email 2020, a subject 2021 indicating an overview of the history information is set. Furthermore, the body 2022 includes details of the history information (such as the date and time of use, the user, and the referenced registration information). Then, this processing sequence in FIG. 19 ends.

[0133] (Specific application examples) The cooperation with the payment service described with reference to Figures 11 to 14 can be applied to situations where people move around empty-handed in accommodation facilities (such as hotels and inns) or amusement facilities. For example, when a child (i.e., a user (child)) belonging to a group moves around the facility empty-handed, facial recognition alone can be used to purchase items, use paid facilities (such as lounges, hot spring facilities, swimming pools, gyms, etc.), manage admission, and board transportation (such as shuttle buses and vehicles reserved for guests). In addition, the user (parent) can manage the user (child)'s behavior by restricting usage and can also check information on usage.

[0134] It can also be applied to services such as rental cars, car sharing, and bus tours. For example, in rental car services, facial recognition can be used to allow the service to be used in cases where the person who makes the reservation and the person who receives the vehicle are different. In addition, in services such as bus tours, facial recognition can be used to allow the service to be used in cases where the boarding location of the bus is different for each participant.

[0135] Furthermore, even if the user (child) is not with the user (parent), the user (child) can freely act within the scope of pre-defined rights without needing any specific tools. For example, the user (child) can check in to the accommodation booked by the user (parent) using only facial recognition, and can also lock the door. Users can enter the reserved room without a room key. Also, users who are not registered in the group are restricted from checking in, which is expected to have a security effect.

[0136] Furthermore, the lost child determination service provided by the lost child determination system 54 can be implemented by applying it in the same way as the accommodation management service shown in FIG. 19. For example, by photographing and authenticating a child's face image, it is possible to obtain information on which group (for example, family) the child belongs to. This makes it possible to determine whether the child is lost or not, and notify the relevant parties (i.e., the user (parent)). In addition, if a user (child) belonging to a group experiences some kind of trouble (such as injury or illness), it is possible to notify the user (parent) by authenticating the user (child)'s face.

[0137] The lost child detection service may take a picture of the child's face using a terminal used to utilize the rights. In this embodiment, since terminals used to utilize the rights are placed in various locations within the facility, lost child notification can be performed accurately without the need for a special terminal.

[0138] Furthermore, the lost child determination service may notify information about the terminal on which facial authentication was last performed in response to an instruction from a user (parent) or a user (child) other than the lost child. In this embodiment, facial authentication is performed when a child (an example of a user (child)) uses a right, and therefore information about the terminal on which the child (an example of a user (child)) last used or attempted to use a right is recorded in the system. Therefore, by adopting such a configuration, even if the child (an example of a user (child)) does not understand how to operate the terminal, the approximate current location of the child (an example of a user (child)) can be known through operations by a parent (an example of a user (parent)) or family member.

[0139] Furthermore, by authenticating their own faces, users can easily check the registered information, which can prevent them from taking actions based on incorrect information (such as the room number of their accommodation). For example, by installing face recognition terminals in elevators, etc., it is possible to control the elevators to automatically stop at the floor where the accommodation room is located, and to display information (such as maps and arrows) guiding the user to the accommodation using terminals installed in the elevator halls on each floor.

[0140] In addition, by registering coupons, preferential treatments, points, etc. issued by facilities as rights to be registered in a group, not only the user (parent) but also users (children) belonging to the group can use them, thereby improving the convenience of using the service.

[0141] Furthermore, it is possible for other users in a group to take over and use the services used by one user. Specifically, it is conceivable that when one user uses a luggage storage service, the other user in the same group can pick up luggage that had been left there. It is also possible to share the rights granted to a user (parent). For example, it is conceivable that points granted to a user (parent) can be shared and used by other users (children) in the group.

[0142] As described above, the face authentication system 30 according to embodiment 1 includes a parent face information management unit 32 and a parent right management unit 35 that register the rights information of a parent user in association with a group, a child face information management unit 33 that registers face images of one or more child users in association with the group, a parent-child relationship determination unit 31 that, upon receiving a face image, performs face authentication based on the information registered in the child face information management unit 33 to identify the group to which the user corresponding to the face image belongs, a usage right determination unit 34 that determines whether the desired processing requested by the child user corresponding to the face image is permitted based on the rights information associated with the group identified by the parent-child relationship determination unit 31, an external system collaboration unit 37 that executes the desired processing based on the determination result by the usage right determination unit 34, and a usage result notification unit 39 that notifies the parent user of at least one of the determination result by the usage right determination unit 34 and the processing result by the external system collaboration unit 37.

[0143] This allows the face authentication system 30 to further improve the convenience when users belonging to a group use various services through face authentication.

[0144] Furthermore, the child right management unit 36 ​​receives and registers the settings of rights granted to each child user belonging to the group within the scope indicated by the right information of the parent user.

[0145] This allows the face authentication system 30 to grant any right within the scope of the parent user's rights to each child user belonging to the group.

[0146] Furthermore, in response to a request from a parent user, the parent right management unit 35 updates the right information of the parent user associated with the group.

[0147] This allows the parent user to appropriately set the sharing rights within the group.

[0148] Furthermore, face authentication system 30 is communicatively connected to face matching terminal 40, which has a face information acquisition unit 42 that acquires a face image of a user, and a usage right setting unit 43 that sets information on desired processing by the user and transmits a request including the user's face image acquired by face information acquisition unit 42 and the set information on desired processing to face authentication system 30. Furthermore, face authentication system 30 further has a result notification unit 45 that transmits the determination result by usage right determination unit 34 and the processing result by external system cooperation unit 37 to face matching terminal 40 as a response to the request from the face matching terminal.

[0149] This allows the face authentication system 30 to easily execute any process by acquiring a face image using the face matching terminal 40.

[0150] In addition, the facial authentication system 30 is communicatively connected to the parent mobile terminal 10, and the parent mobile terminal 10 has a parent facial information acquisition unit 14 that acquires a facial image and requests the facial authentication system 30 to register the rights information of the parent user who is the user of the parent mobile terminal 10 in association with the group, and a child registration link sending unit 17 that determines whether or not to acquire a facial image of a child user belonging to the group at the parent mobile terminal 10, and if it is determined that the facial image of the child user should not be acquired at the parent mobile terminal 10, sends a request including information for registering the facial image of the child user in the facial authentication system 30 to the child mobile terminal 20 that acquires the facial image of the child user.

[0151] This allows the face authentication system 30 to easily register the face image of the child user on a terminal other than the parent mobile terminal 10.

[0152] In addition, if it is determined that the facial image of the child user is to be acquired by the parent mobile terminal 10, the child facial information acquisition unit 15 acquires the facial image of the child user and then requests the facial authentication system 30 to register the facial image of the child user in association with the group.

[0153] This allows the face authentication system 30 to easily register the face image of the child user even in the parent mobile terminal 10.

[0154] In addition, the facial authentication system 30 is communicatively connected to a service providing system 50 that executes at least a portion of the desired processing, and the external system collaboration unit 37 collaborates with the service providing system 50 to execute the desired processing based on the determination result by the usage right determination unit 34.

[0155] This allows the face authentication system 30 to perform processing in cooperation with systems that are provided outside the face authentication system 30 and provide various services.

[0156] The desired process is one of a payment service, an accommodation management service, an admission management service to a facility, and a registration information provision service.

[0157] This allows the face authentication system 30 to apply face authentication processing to payment services, accommodation management services, facility admission management services, or registration information provision services.

[0158] <Other embodiments> In the above-described embodiments, the notification of the use of the right is sent to the parent mobile terminal 10. However, the notification may also be sent to the child mobile terminal 20. For example, the notification can be sent by the user (parent) specifying the child mobile terminal 20 owned by the user (child) to whom the notification is sent. This allows the user (child) to check the results of the use of the right via the child mobile terminal 20. The notification of the use of the right may also be sent to the child mobile terminal 20 owned by the user (child) who used the right. This allows the user (child) to later check information about the right and service used via the child mobile terminal 20. In particular, if the user (child) uses the right while separated from the user (parent), the user (child) may feel uneasy because it is difficult to know whether the use of the right was successful. Therefore, if the notification is sent to the child mobile terminal 20 owned by the user (child) who used the right, the user (child) can confirm the success or failure of the use of the right himself / herself, thereby reducing such anxiety. Furthermore, as long as the user (child) successfully uses the right, the notification of the use of the right may not be sent to the parent mobile terminal 10. This eliminates the need to check notifications on the parent mobile terminal 10 when no particular problem has occurred, thereby preventing excessive notifications to the user (parent). Also, the parent mobile terminal 10 or the child mobile terminal 20 may make a request to the face authentication system 30 or the like to check the history of use of rights.

[0159] Furthermore, in the above-described embodiments, the face matching terminal 40 has been described as being installed in a facility that provides various services, but it may also be installed inside a mobile vehicle. One example is a shuttle bus that runs between a station and a hotel. In this case, the desired processing is a transportation service that uses the mobile vehicle, or a service provided inside the mobile vehicle (such as in-vehicle sales or tourist guides). Furthermore, the face matching terminal 40 does not need to be associated with a specific facility. For example, the face matching terminal 40 may be in a form in which software for providing various services is installed in a mobile terminal (specifically, a parent mobile terminal 10 or a child mobile terminal 20) owned by a user or the like. In this case, the software provides the service on the condition that face authentication is successful and the right is used.

[0160] Furthermore, in each of the above-described embodiments, the facial information of the user (parent) is registered in the facial authentication system, but registration of the user (parent)'s face may be omitted. This is because the user (parent) is likely to carry the parent mobile terminal 10 in order to understand the usage status of the user (child)'s rights, and in this case, the parent mobile terminal 10 can be used for the user (parent)'s own use of the rights. Similarly, if the user (parent) does not plan to use the rights himself / herself and only manages the rights for the user (child), registration of the user (parent)'s facial information may be omitted. In these cases, instead of the facial information of the user (parent), other biometric information of the user (parent) (such as a fingerprint) or an ID uniquely assigned to the user (parent) may be used as information for identifying the group representative.

[0161] In addition, in each of the above-described embodiments, each piece of user information is registered by the parent mobile terminal 10 or the child mobile terminal 20, but this is not limiting. For example, registration may be performed by a device installed in a facility, such as a terminal installed at the front desk of a hotel.

[0162] Furthermore, in the above-described embodiments, it has been described that there is only one user (parent) in a group, but it is also possible to set up multiple users (parents). In this case, notifications to the parent mobile terminal 10 may be sent to terminals owned by each of the multiple users (parents). Furthermore, the notifications received and the rights that can be changed may be different between users (parents). For example, it is conceivable that only one user (parent) can change rights related to money, but other users (parents) can also change rights that are not related to money (such as the right to use a facility free of charge).

[0163] Furthermore, in each of the above-described embodiments, the information notified to the parent mobile terminal 10 may be only the result of face authentication of the user (child) or only the result of using the service. In particular, if face authentication of the user (child) fails, the result of the determination as to whether or not the service can be used is "no," so it is not necessary to notify the result of the use.

[0164] In addition, the programs and applications for realizing the functions of one or more of the above-described embodiments can be supplied to a system or device using a network or storage medium, etc., and one or more processors in the computer of the system or device can read and execute the programs.

[0165] Alternatively, it may be realized by a circuit that realizes one or more functions (for example, an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array)).

[0166] Although various embodiments have been described above with reference to the drawings, it goes without saying that the present disclosure is not limited to these examples. It is clear to those skilled in the art that various modifications, alterations, substitutions, additions, deletions, and equivalents may be made within the scope of the claims, and it is understood that these also fall within the technical scope of the present disclosure. Furthermore, the components of the various embodiments described above may be combined in any manner without departing from the spirit of the invention. [Industrial Applicability]

[0167] The present disclosure is useful as a face authentication system, a face authentication method, an information processing terminal, and a control method thereof that can improve the convenience of actions according to rights for multiple users. [Explanation of symbols]

[0168] 10 Parent mobile device 20 Child mobile device 30 Facial Recognition System 40 Face matching terminal 50 Service Delivery System 60 Network 300 mobile devices 400 Information processing equipment

Claims

1. A rights determination system that determines whether a desired process can be provided to a second user based on rights information associated with a group consisting of at least one first user and at least one second user, a registration unit that receives and registers a setting for transferring the right information of the service to each of the second users belonging to the group within a range indicated by the right information of the service reserved or used by the first user, and face information of the second users; an identification unit that identifies a group to which the second user belongs based on authentication processing based on face information of the second user; a determination unit that determines whether or not a desired process requested by the second user can be provided based on the rights information of the service associated with the group identified by the identification unit; a notification unit that notifies the first user of a determination result by the determination unit; A rights determination system comprising:

2. the registration unit updates the right information of the second user associated with the group in response to a request from the first user. The right determination system according to claim 1 .

3. the right determination system is communicatively connected to a right determination terminal; The right determination terminal a first acquisition unit that acquires authentication information of a user; a first setting unit that sets information about a desired process; a first request unit that transmits a request to the right determination system, the request including the user authentication information acquired by the first acquisition unit and information on the desired process set by the first setting unit; The right determination system further comprises: a first transmitting unit configured to transmit a determination result by the determining unit to the right determination terminal as a response to the request; The right determination system according to claim 1 .

4. the right determination system is communicably connected to a service providing system that executes at least a part of the desired process; a processing unit that executes the desired process in cooperation with the service providing system based on the determination result by the determination unit; The right determination system according to claim 1 .

5. The desired process is one of picking up luggage in a luggage storage service or picking up a rental vehicle in a vehicle rental service. The right determination system according to claim 1 .

6. A rights determination method for determining whether a desired process can be provided to a second user based on rights information associated with a group consisting of at least one first user and at least one second user, the method comprising: a step of receiving and registering a setting for transferring the right information of the service to each of the second users belonging to the group within a range indicated by the right information of the service reserved or used by the first user, and face information of the second users; Identifying a group to which the second user belongs based on authentication processing based on face information of the second user; determining whether or not a desired process requested by the second user can be provided based on the rights information of the service associated with the group identified in the identifying step; notifying the first user of a determination result obtained by the determining step; A rights determination method comprising:

7. An information processing terminal, a request unit that requests a rights determination system to register rights information associated with a group consisting of at least one first user and at least one second user, the rights information being related to a service reserved or used by the first user, a setting for taking over the rights information of the service to each of the second users, and face information of the second users; a receiving unit that receives a determination result when a determination is made based on the rights information of the service as to whether or not a desired process requested by the second user, whose group is identified based on the authentication process based on the face information of the second user, can be provided and the determination result satisfies a predetermined condition; Information processing terminal.

8. A control method for an information processing terminal, comprising: a step of requesting a rights determination system to register rights information associated with a group consisting of at least one first user and at least one second user, the rights information being related to a service reserved or used by the first user, a setting for taking over the rights information of the service to each of the second users, and face information of the second users; and receiving a determination result when a determination is made based on the rights information of the service as to whether or not a desired process requested by the second user, whose group is identified based on the authentication process based on the face information of the second user, can be provided and the determination result satisfies a predetermined condition. A method for controlling an information processing terminal.

Citation Information

Patent Citations

  • Authentication device, authentication method, authentication program, and authentication system

    JP2018190274A