Identity authentication method
The authentication method enhances personal authentication accuracy in services by using driving tendency information to detect impersonation, addressing spoofing issues in car sharing and other services.
Patent Information
- Application Number
- JP2024086631
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-28
- Publication Date
- 2025-12-10
AI Technical Summary
Car sharing services face spoofing issues due to impersonation, where malicious users impersonate celebrities to rent vehicles at higher rates, and similar problems exist in other personal authentication services, necessitating improved accuracy in user verification.
An authentication method that utilizes driving tendency information, acquired and compared against registered data to determine a match, enhancing personal authentication accuracy by leveraging unique driving habits.
The method effectively detects impersonation by comparing driving tendencies, improving personal authentication accuracy and making it difficult to tamper with driving data, thus ensuring secure service access.
Smart Images

Figure 2025179709000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a personal authentication method. [Background technology]
[0002] Conventionally, there are known technologies related to car sharing services that support car sharing between individuals. For example, Patent Document 1 discloses a vehicle rental determination device used in a car sharing support service that supports car sharing using private vehicles. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent Publication No. 2021-047605 Summary of the Invention [Problem to be solved by the invention]
[0004] As the car-sharing service market expands, rental vehicles may have added value depending on the vehicle owner, rather than simply being a means of transportation. For example, rental fees for celebrities' vehicles may be higher than for ordinary people's vehicles.
[0005] However, such car sharing services may be subject to spoofing using techniques such as deepfakes. For example, a malicious vehicle owner may impersonate a celebrity, register with a car sharing service, and rent out the vehicle for a high price. Similar spoofing may also occur in any other service that requires personal authentication, other than car sharing services.
[0006] The purpose of the present disclosure, made in consideration of the above circumstances, is to improve the accuracy of personal authentication when subscribing to or using a service. [Means for solving the problem]
[0007] According to an embodiment of the present disclosure, an authentication method executed by an information processing device includes: Acquiring first personal information indicating personal information of a first user who has applied to subscribe to or use the service through a terminal, and first tendency information indicating a driving tendency of the first user; Obtaining second personal information indicating personal information of a registered second user and matching the first personal information; Acquiring second tendency information that indicates the driving tendency of the second user and is registered in association with the second personal information; Calculating a degree of agreement between the first trend information and the second trend information; determining whether the first user matches the second user based on the degree of match; sending a message to the terminal indicating the result of the determination; Includes. [Effects of the Invention]
[0008] According to one embodiment of the present disclosure, the accuracy of personal authentication when subscribing to or using a service is improved. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a block diagram showing a schematic configuration of a system according to a first embodiment of the present disclosure. [Figure 2] FIG. 2 is a sequence diagram showing the operation of the system according to the first embodiment of the present disclosure. [Figure 3] FIG. 10 is a sequence diagram showing the operation of a system according to a second embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0010] (First embodiment) The first embodiment of the present disclosure will be described below.
[0011] (Outline of the first embodiment) A schematic configuration of a system 1 according to a first embodiment of the present disclosure will be described with reference to Fig. 1. The system 1 includes a first user terminal 10, an application server 20, and a registration server 30. The first user terminal 10, the application server 20, and the registration server 30 are communicably connected to a network 40 including, for example, the Internet or a mobile communication network. The system 1 may include multiple application servers 20.
[0012] The first user's terminal 10 (hereinafter referred to as "terminal 10") is any terminal device used by the first user. The terminal 10 includes devices such as a mobile phone, smartphone, tablet, or laptop computer. The first user is a user who applies to a service provider to subscribe to or use a service through the terminal 10. The service includes any service that requires identity authentication. In particular, the service includes vehicle services that use vehicles, such as vehicle sales, resales, rentals, leases, subscriptions, or sharing. The service may also include services other than vehicle services, such as opening a bank account or registering a credit card.
[0013] Vehicles include any vehicle such as automobiles and motorcycles, etc. Vehicles include, but are not limited to, gasoline-powered automobiles, battery electric vehicles (BEVs), hybrid electric vehicles (HEVs), plug-in hybrid electric vehicles (PHEVs), and fuel cell electric vehicles (FCEVs).
[0014] The application server 20 is an information processing device that accepts applications for subscription to or use of a service. The application server 20 may be any computer. The application server 20 is operated, for example, by a service provider. When the system 1 includes multiple application servers 20, each application server 20 may be operated by a different service provider. In the first embodiment, the application server 20 is an information processing device that executes a method according to an embodiment of the present disclosure. In order to apply for a service, the application server 20 requests, from the first user, first personal information indicating the first user's personal information and driving data indicating the first user's driving data.
[0015] The registration server 30 is an information processing device in which second personal information indicating the personal information of a second user and second tendency information indicating the second user's driving tendency, for example, driving habits or routines, are registered. The second user is a user who registered personal information and second tendency information in the registration server 30, for example, when purchasing or renting a vehicle. The second tendency information is registered in association with the second personal information. The registration server 30 may be any computer. The registration server 30 is operated, for example, by a vehicle seller. The registration server 30 may be operated by an administrative agency that accepts vehicle registration procedures, such as vehicle transfer registration procedures, or by an agency that accepts registration procedures on behalf of an administrative agency.
[0016] First, an overview of an embodiment of the present disclosure will be described, and details will be provided later. An identity authentication method according to this embodiment is executed by an information processing device. The information processing device acquires first personal information indicating the personal information of a first user who has applied to subscribe to or use a service through a terminal 10, and first tendency information indicating the user's driving tendency. The information processing device acquires second personal information indicating the personal information of a vehicle registrant and matching the first personal information. The information processing device acquires second tendency information indicating the driving tendency of the registrant and registered in association with the second personal information. The information processing device calculates the degree of match between the first tendency information and the second tendency information. The information processing device determines whether the first user matches the second user based on the degree of match. The information processing device transmits a message indicating the determination result to the terminal 10.
[0017] According to this embodiment, even if a first user impersonates a second user using the personal information of the second user, it is possible to detect the impersonation by the first user by comparing the driving tendency information of the first user and the second user.
[0018] Each characteristic of driving tendency varies from person to person, making it difficult to imitate. Therefore, the more types of driving tendency characteristics are compared, the greater the difficulty of imitating the driving tendency. Furthermore, determining driving tendency requires complex information processing based on driving data containing many variables. Therefore, it is difficult to directly tamper with driving tendency information and to tamper with driving data to obtain desired driving tendency information. Therefore, by using driving tendency information for user authentication, the accuracy of identity authentication is improved.
[0019] Once the driving tendency information is registered in the registration server, the second user can use the registered driving tendency information for identity authentication even if the second user changes the vehicle they use. Also, if the system 1 has multiple application servers 20 each associated with a different service, the second user can use the personal information and driving tendency information registered in a single registration server for identity authentication for each service.
[0020] As described above, the method according to this embodiment can improve the accuracy of personal authentication when subscribing to or using a service.
[0021] Next, each component of the system 1 will be described in detail with reference to FIG.
[0022] (Configuration of Terminal 10) The terminal 10 includes a communication unit 100, a control unit 101, and a storage unit .
[0023] The communication unit 100 includes at least one communication interface that connects to the network 40. The communication unit 100 has a communication module that supports wired or wireless LAN standards, a module that supports mobile communication standards such as LTE (Long Term Evolution), 4G (4th Generation), or 5G (5th Generation), and the like.
[0024] The control unit 101 includes one or more processors, one or more programmable circuits, one or more dedicated circuits, or a combination thereof. The control unit 101 controls the operation of the terminal 10.
[0025] The storage unit 102 includes one or more memories. Each memory included in the storage unit 102 may function as, for example, a main storage device, an auxiliary storage device, or a cache memory. The storage unit 102 stores any information used in the operation of the terminal 10. For example, the storage unit 102 may store system programs, application programs, embedded software, and the like.
[0026] (Configuration of application server 20) The application server 20 includes a communication unit 200 , a control unit 201 , and a storage unit 202 .
[0027] The communication unit 200 includes at least one communication interface that connects to the network 40. The communication unit 200 includes a communication module that supports a wired or wireless LAN standard, a module that supports a mobile communication standard such as LTE, 4G, or 5G, and the like.
[0028] The control unit 201 includes one or more processors, one or more programmable circuits, one or more dedicated circuits, or a combination thereof. The control unit 201 controls the operation of the application server 20.
[0029] The storage unit 202 includes one or more memories. Each memory included in the storage unit 202 may function as, for example, a main storage device, an auxiliary storage device, or a cache memory. The storage unit 202 stores any information used in the operation of the application server 20. For example, the storage unit 202 may store system programs, application programs, embedded software, etc.
[0030] (Configuration of registration server 30) The registration server 30 includes a communication unit 300 , a control unit 301 , and a storage unit 302 .
[0031] The communication unit 300 includes at least one communication interface that connects to the network 40. The communication unit 300 includes a communication module that supports wired or wireless LAN standards, a module that supports mobile communication standards such as LTE, 4G, or 5G, and the like.
[0032] The control unit 301 includes one or more processors, one or more programmable circuits, one or more dedicated circuits, or a combination thereof. The control unit 301 controls the operation of the registration server 30.
[0033] The storage unit 302 includes one or more memories. Each memory included in the storage unit 302 may function as, for example, a main storage device, an auxiliary storage device, or a cache memory. The storage unit 302 stores any information used in the operation of the registration server 30, second personal information indicating the personal information of the second user, and second tendency information indicating the driving tendency of the second user. The second tendency information is stored in association with the second personal information. The storage unit 302 may store system programs, application programs, embedded software, etc. The information stored in the storage unit 302 may be updated. For example, the second personal information and the second tendency information may be updated periodically to address changes in driving tendency due to aging, etc.
[0034] The driving tendency includes one or more tendencies of time series data of the vehicle speed, acceleration, following distance, steering wheel angular velocity, and brake / accelerator pedal depression amount while driving, or reaction speed to traffic light changes. The driving tendency may include these tendencies in a predetermined time period such as daytime or nighttime, and in a predetermined environment such as an ordinary road or a highway. The driving tendency may include one or more tendencies of the start and end times of driving in a day, or driving time, driving distance, and driving area in a predetermined period (including, but not limited to, a period of one day, one week, one month, etc.). The second tendency information may indicate these driving tendencies of the second user by any index such as a numerical value or a classification. The numerical value may include time series data or an average value of these tendencies. The classification may include, for example, a classification based on vehicle speed (e.g., "impatient" or "slow").
[0035] (Operation flow of system 1 according to the first embodiment) The operation of the system 1 according to the first embodiment will be described with reference to FIG. 2. In FIG. 2, the application server 20 is an information processing device that executes the method according to the embodiment of the present disclosure. Therefore, the method according to the embodiment of the present disclosure corresponds to the operation of the application server 20 among the operations shown in FIG. 2. In the following, communication between the terminal 10, the application server 20, and the registration server 30 is performed via the communication unit 100 of the terminal 10, the communication unit 200 of the application server 20, the communication unit 300 of the registration server 30, and the network 40.
[0036] S100: The control unit 101 of the terminal 10 transmits the first personal information and the driving data of the first user to the application server 20.
[0037] The first personal information and the driving data of the first user are information necessary for subscribing to or using the service. In this specification, personal information includes name, age, address, residence, telephone number, email address, facial photograph, occupation, place of work, or personal identification number such as My Number. The driving data may be data measured by, for example, a sensor or a drive recorder built into a vehicle, or a roadside device installed on a road or the like. The measurement may be performed over a predetermined period, for example, but is not limited to, one hour or less, one day or less, one week or less, one month or less, or one year or less. The first user may use driving data measured in the past or measured periodically.
[0038] The control unit 201 of the application server 20 receives the first personal information from the terminal 10, thereby acquiring the first personal information.
[0039] S101: The control unit 201 of the application server 20 transmits the first personal information to the registration server 30.
[0040] S102: The control unit 301 of the registration server 30 searches the storage unit 302 for second personal information that completely or partially matches the first personal information. If second personal information that matches the first personal information is found, the process proceeds to S103 (S102-YES). If second personal information that matches the first personal information is not found, the following steps S103 to S108 are not executed, and the process ends (S102-NO).
[0041] The second personal information is registered by the second user in the registration server 30 at the time of purchasing a vehicle, etc. The second personal information includes personal information of the same or similar type that can be compared with the first personal information.
[0042] If no second personal information matching the first personal information is found, the control unit 301 may send a message to the terminal 10 via the application server 20 indicating that no second personal information matching the first personal information is found.
[0043] S103: The control unit 301 of the registration server 30 acquires, from the storage unit 302 of the registration server 30, the second tendency information that is registered in association with the second personal information.
[0044] The second tendency information is registered by the second user in the registration server 30 at the same time as the second personal information or at a different time. For example, the second user may initially register only the second personal information when purchasing a vehicle, and then register the measured driving data at an appropriate time thereafter, for example, after the measurement of the driving data is completed. The registration server 30 may calculate the second tendency information from the driving data using an arbitrary algorithm and register the second tendency information. If the second user has the second tendency information, the second user may register the second tendency information in the registration server 30 at the same time as the second personal information.
[0045] S104: The control unit 301 of the registration server 30 transmits the second trend information to the application server 20.
[0046] The control unit 201 of the application server 20 receives the second trend information from the registration server 30, thereby acquiring the second trend information.
[0047] S105: The control unit 201 of the application server 20 calculates first tendency information from the driving data of the first user.
[0048] The first tendency information includes information that indicates the same or similar type of driving tendency as the second tendency information and that can be compared with the second tendency information. The control unit 201 may calculate the first tendency information using an arbitrary algorithm.
[0049] The control unit 201 of the application server 20 acquires the first tendency information by calculating the first tendency information from the driving data of the first user.
[0050] S106: The control unit 201 of the application server 20 calculates the degree of coincidence between the first trend information and the second trend information.
[0051] This degree of match may be the sum of the degrees of match for each item of the driving tendency indicated by the first trend information and the second trend information. The control unit 201 may use any algorithm or calculation method to calculate the degree of match. For example, when calculating the degree of match, the control unit 201 may set a weighting coefficient for each item of the driving tendency indicated by the first trend information and the second trend information. The control unit 201 may assign a larger weighting coefficient to an item that is more difficult to imitate or has greater individual differences, or may use a method such as machine learning to set such a weighting coefficient. For example, because actions that require quick decisions are considered difficult to imitate, a larger weighting coefficient may be assigned to the reaction speed to a change in a traffic light than to other items. Alternatively, because the vehicle speed can be easily determined from the speedometer, a smaller weighting coefficient may be assigned to the vehicle speed than to other items.
[0052] S107: The control unit 201 of the application server 20 determines whether the first user matches the second user based on the degree of match.
[0053] For example, the control unit 201 may determine that the first user and the second user match if the degree of match is equal to or greater than a threshold, and may determine that the first user and the second user do not match if the degree of match is less than the threshold. Alternatively, multiple thresholds may be set. For example, the control unit 201 may determine that the first user and the second user match if the degree of match is equal to or greater than a first threshold, that the first user and the second user may not match if the degree of match is less than the first threshold and equal to or greater than a second threshold, and that the first user and the second user do not match if the degree of match is less than the second threshold. If the system 1 includes multiple application servers 20, the thresholds of the application servers 20 may be the same or different from each other. The control unit 201 may approve or reject the application of the first user depending on the determination result.
[0054] S108: The control unit 201 of the application server 20 transmits a message indicating the result of the determination to the terminal 10.
[0055] The control unit 201 may transmit to the terminal 10 a message indicating approval or rejection of the application based on the result of the determination.
[0056] The control unit 201 may transmit the first trend information to the terminal 10. This allows the first user to reuse the first trend information when applying for subscription to or use of another service via another application server 20. In this case, the other application server 20 does not need to calculate the first trend information.
[0057] From the above, according to this embodiment, even if a first user impersonates a second user using the personal information of the second user, it is possible to detect the impersonation by the first user by comparing the driving tendency information of the first user and the second user.
[0058] Each characteristic of driving tendency varies from person to person, making it difficult to imitate. Therefore, the more types of driving tendency characteristics are compared, the greater the difficulty of imitating the driving tendency. Furthermore, determining driving tendency requires complex information processing based on driving data containing many variables. Therefore, it is difficult to directly tamper with the tendency information or to tamper with the driving data to obtain desired tendency information. Therefore, by using driving tendency information for user authentication, the accuracy of identity authentication is improved.
[0059] Once the trend information is registered in the registration server, the second user can use the trend information for identity authentication even if the second user changes the vehicle they use. Also, if the system has multiple application servers each associated with a different service, the second user can use the personal information and trend information registered in a single registration server for identity authentication for each service.
[0060] As described above, the method according to this embodiment can improve the accuracy of personal authentication when subscribing to or using a service.
[0061] (Second embodiment) Next, a second embodiment of the present disclosure will be described. The configuration of the system 1 according to the second embodiment is the same as that of the first embodiment, and therefore a description thereof will be omitted. The configurations of the terminal 10, application server 20, and registration server 30 according to the second embodiment are the same as those of the first embodiment, and therefore a description thereof will be omitted.
[0062] (Operation flow of system 1 according to the second embodiment) The operation of the system 1 according to the second embodiment will be described with reference to FIG. 3. In the second embodiment, the registration server 30 is an information processing device that executes the method according to the embodiment of the present disclosure. Therefore, the method according to the second embodiment corresponds to the operation of the registration server 30 among the operations shown in FIG. 3. In the following, communication between the terminal 10, the application server 20, and the registration server 30 is performed via the communication unit 100 of the terminal 10, the communication unit 200 of the application server 20, the communication unit 300 of the registration server 30, and the network 40.
[0063] The difference in operation of the system 1 between the first and second embodiments will be described below with reference to FIG.
[0064] S200, S202, and S203 in FIG. 3 are the same processes as S100, S102, and S103 in FIG. 2, respectively, and therefore will not be described.
[0065] S201: The control unit 201 of the application server 20 transmits the first personal information and the driving data of the first user to the registration server 30.
[0066] The control unit 301 of the registration server 30 receives the first personal information and the driving data of the first user from the application server 20, and thereby acquires this information.
[0067] 2. That is, in the second embodiment, the control unit 301 of the registration server 30 calculates first trend information (S204), calculates the degree of match between the first trend information and the second trend information (S205), determines whether the first user and the second user match (S206), and transmits a message indicating the determination result to the terminal 10 (S207). The items and calculation method of the first trend information, the calculation method of the degree of match, and the determination method of whether the first user and the second user match are the same as those in the first embodiment, and therefore description thereof will be omitted. In FIG. 3, the control unit 301 transmits a message indicating the determination result to the terminal 10 via the application server 20. The control unit 301 may also transmit the message directly to the terminal 10.
[0068] Also possible is an embodiment in which, for example, a general-purpose computer functions as the information processing device according to the above-described embodiment. Specifically, a program describing the processing content for realizing each function of the application server 20 or the registration server 30 is stored in the memory of the general-purpose computer, and the program is read and executed by a processor. Therefore, the present disclosure can also be realized as a program executable by a processor or a non-transitory computer-readable medium storing the program.
[0069] Although the present disclosure has been described based on the drawings and examples, it should be noted that those skilled in the art may make various modifications and alterations based on the present disclosure. Therefore, it should be noted that these modifications and alterations are included in the scope of the present disclosure. For example, the functions included in each unit or step can be rearranged so as not to be logically inconsistent, and multiple components or steps can be combined or divided into one.
[0070] In the second embodiment, the terminal 10 may communicate with the registration server 30 without going through the application server 20, and the application server 20 may not exist.
[0071] In the above-described S100 and S200, the control unit 101 of the terminal 10 transmits the first personal information and the driving data of the first user to the application server 20. The control unit 101 may transmit the first personal information and the first tendency information to the application server 20. In this case, the first tendency information may be information acquired by the first user using an arbitrary app or the like, or may be information received from the application server 20 when the first user previously used the system 1 according to this embodiment. [Explanation of symbols]
[0072] 1 System 10 devices 100 Communications Department 101 Control section 102 Storage section 20 Application Server 200 Communications Department 201 Control Unit 202 Storage section 30 Registration Server 300 Communications Department 301 Control Unit 302 Storage section 40 Network
Claims
1. An identity authentication method executed by an information processing device, Acquiring first personal information indicating personal information of a first user who has applied to subscribe to or use the service through a terminal, and first tendency information indicating a driving tendency of the first user; Obtaining second personal information indicating personal information of a registered second user and matching the first personal information; Acquiring second tendency information that indicates a driving tendency of the second user and is registered in association with the second personal information; Calculating a degree of agreement between the first trend information and the second trend information; determining whether the first user matches the second user based on the degree of match; sending a message to the terminal indicating the result of the determination; A method comprising:
2. 2. The method of claim 1, wherein obtaining the first trend information includes calculating the first trend information based on driving data indicative of driving data of the first user.
3. 2. The method of claim 1, wherein the driving tendency includes one or more tendencies of a vehicle speed, acceleration, following distance, steering wheel angular velocity, time series data of brake / accelerator depression amount, and reaction speed to traffic light changes while driving.
4. The method of claim 1 , wherein the service comprises selling, reselling, renting, leasing, subscribing, or sharing a vehicle.
5. 5. The method of claim 1, wherein the determining step includes determining that the first user matches the second user if the degree of match is greater than or equal to a threshold, and determining that the first user does not match the second user if the degree of match is less than the threshold.
Citation Information
Patent Citations
Vehicle rent determining device and car sharing assisting system
JP2021047605A