Authentication system, authentication method, and program

The authentication system uses three-dimensional sensors to capture and register skeletal and movement features for seamless and privacy-protected authentication, addressing the inconvenience of traditional face authentication methods.

JP2025185340APending Publication Date: 2025-12-22TOPPAN HOLDINGS INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024093503
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-10
Publication Date
2025-12-22

AI Technical Summary

Technical Problem

Face authentication systems require individuals to stay still for an extended period, making the authentication process inconvenient and potentially invasive.

Method used

An authentication system utilizing a three-dimensional sensor to generate three-dimensional feature data, including skeletal and movement features, which are registered as reference information for comparison during authentication, allowing for seamless and privacy-protecting identification without requiring individuals to remain stationary.

Benefits of technology

Enables smooth and privacy-respecting authentication by capturing three-dimensional features of individuals in motion, improving convenience and privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025185340000001_ABST
    Figure 2025185340000001_ABST
Patent Text Reader

Abstract

To provide an authentication system, an authentication method, and a program for allowing personal authentication to be implemented smoothly.SOLUTION: An authentication system includes: a solid feature data generation unit which generates solid feature data indicating a stereoscopic feature of an object person on the basis of three-dimensional data indicating a three-dimensional shape of the object person detected by a three-dimensional sensor; a registration unit which registers, as reference information used in an authentication process for authenticating a person, the solid feature data generated by the solid feature data generation unit in correspondence to authentication registration; and an authentication unit which executes, on the basis of the three-dimensional data obtained by the three-dimensional sensor detecting the three-dimensional shape of the object person during authentication, the authentication process by collating the authentication information as the solid feature data generated by the solid feature data generation unit, and the reference information registered by the registration unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an authentication system, an authentication method, and a program. [Background technology]

[0002] BACKGROUND ART There is known a technique for performing face authentication processing based on an image including a face captured by an imaging unit (see, for example, Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2024-61800 Summary of the Invention [Problem to be solved by the invention]

[0004] For example, in face authentication, a person to be authenticated needs to stay in front of an image capturing device for a certain period of time in order to have their face captured. In view of the above, an object of the present invention is to enable smooth authentication of individuals. [Means for solving the problem]

[0005] One aspect of the present invention that solves the above-mentioned problems is an authentication system that includes a three-dimensional feature data generation unit that generates three-dimensional feature data that indicates the three-dimensional features of a subject based on three-dimensional data that indicates the three-dimensional shape of the subject detected by a three-dimensional sensor; a registration unit that registers the three-dimensional feature data generated by the three-dimensional feature data generation unit in response to authentication registration as reference information to be used in an authentication process to authenticate a person; and an authentication unit that performs authentication processing by comparing the authentication information as three-dimensional feature data generated by the three-dimensional feature data generation unit based on the three-dimensional data obtained when the three-dimensional sensor detects the three-dimensional shape of the subject during authentication with the reference information registered by the registration unit.

[0006] One aspect of the present invention is an authentication method in an authentication system, including: a three-dimensional feature data generation step in which a three-dimensional feature data generation unit generates three-dimensional feature data indicating the three-dimensional features of a subject based on three-dimensional data indicating the three-dimensional shape of the subject detected by a three-dimensional sensor; a registration step in which a registration unit registers the three-dimensional feature data generated by the three-dimensional feature data generation step in response to authentication registration as reference information to be used in an authentication process to authenticate a person; and an authentication step in which the authentication unit performs the authentication process by comparing the authentication information as three-dimensional feature data generated by the three-dimensional feature data generation step based on three-dimensional data obtained by the three-dimensional sensor detecting the three-dimensional shape of the subject during authentication with the reference information registered by the registration step.

[0007] One aspect of the present invention is a program for causing a computer in an authentication system to function as a three-dimensional feature data generation unit that generates three-dimensional feature data indicating the three-dimensional features of a subject based on three-dimensional data indicating the three-dimensional shape of the subject detected by a three-dimensional sensor, a registration unit that registers the three-dimensional feature data generated by the three-dimensional feature data generation unit in response to authentication registration as reference information to be used in the authentication process to authenticate a person, and an authentication unit that performs the authentication process by comparing the authentication information as three-dimensional feature data generated by the three-dimensional feature data generation unit based on the three-dimensional data obtained when the three-dimensional sensor detects the three-dimensional shape of the subject during authentication with the reference information registered by the registration unit. [Effects of the Invention]

[0008] According to the present invention, an effect is obtained in that personal authentication can be performed smoothly. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is a diagram illustrating an example of the overall configuration of a service control system according to a first embodiment. [Figure 2]FIG. 4 is a diagram illustrating an example of a processing procedure executed by the three-dimensional sensor and the authentication system in response to authentication registration in the first embodiment. [Figure 3] 4 is a diagram showing an example of a processing procedure executed by the three-dimensional sensor, the authentication system, and the service system in the first embodiment in relation to the provision of a service in response to authentication. FIG. [Figure 4] FIG. 10 is a diagram illustrating an example of the overall configuration of a service control system according to a second embodiment. [Figure 5] FIG. 10 is a diagram illustrating an example of the functional configuration of an authentication-enabled information processing device, a store management server, and a customer terminal according to a second embodiment. [Figure 6] FIG. 10 is a diagram illustrating an example of a processing procedure executed by the service control system in the second embodiment in relation to authentication registration. [Figure 7] FIG. 10 is a diagram illustrating an example of a processing procedure executed by the service control system in the second embodiment in response to empty-handed payment. DETAILED DESCRIPTION OF THE INVENTION

[0010] First Embodiment 1 shows an example of the overall configuration of a service control system including an authentication system according to this embodiment. The service control system in the figure includes a three-dimensional sensor 100, an authentication system 200, and a service system 300.

[0011] 3D sensor 100 is installed at a predetermined position in a space corresponding to, for example, the service control system of this embodiment, and detects the 3D shape of a subject such as a person. 3D sensor 100 outputs 3D data indicating the detected 3D shape.

[0012] Three-dimensional sensor 100 may be, for example, a ToF (Time Of Flight) camera. A ToF camera detects the three-dimensional shape of a subject by emitting infrared light and measuring the distance to the subject based on the time it takes for the reflected light to return. The three-dimensional sensor may also be configured to detect the three-dimensional shape of a subject by irradiating the subject with laser light and measuring the distance to the subject based on the time it takes for the irradiated reflected light to return. Furthermore, three-dimensional sensor 100 may be a stereo camera capable of detecting the three-dimensional shape of a subject by calculating the distance based on the parallax between images captured by two cameras.

[0013] The 3D sensors 100 may be installed at different positions for registration and authentication of the person to be authenticated. In this case, multiple 3D sensors 100 for registration may be installed at different predetermined positions. Multiple 3D sensors 100 for authentication may also be installed at different predetermined positions.

[0014] Authentication system 200 performs authentication processing using the three-dimensional data captured by three-dimensional sensor 100. Authentication system 200 registers the person to be authenticated (registers authentication reference information used for authentication) and performs authentication processing for the person to be authenticated.

[0015] The figure shows an example of the functional configuration of authentication system 200. Authentication system 200 may be configured to include, as hardware, a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), and storage devices such as HDD (Hard Disk Drive) and SSD (Solid State Drive). The functions of authentication system 200 shown in the figure may be realized by a CPU included in authentication system 200 executing a program.

[0016] The authentication system 200 in the figure includes, as functional units, a communication unit 201, a preprocessing unit 202, a three-dimensional feature data generation unit 203, a registration unit 204, an authentication unit 205, an authentication reference information storage unit 206, and an authentication history information storage unit 207.

[0017] The communication unit 201 is connected to the three-dimensional sensor 100 and the service system 300 so as to be able to communicate with each other.

[0018] The preprocessing unit 202 captures three-dimensional data corresponding to the three-dimensional shape detected over a period of, for example, several seconds by the three-dimensional sensor 100. The preprocessing unit 202 extracts three-dimensional data portions representing the person of the target person (the person to be registered or the person to be authenticated) from the three-dimensional data captured by the three-dimensional sensor 100.

[0019] The three-dimensional feature data generating unit 203 generates three-dimensional feature data indicating the three-dimensional features of the subject from the three-dimensional data portion extracted by the pre-processing unit 202. The three-dimensional feature data of the subject may include skeleton feature data indicating the skeleton of the subject and movement feature data indicating the characteristics of the subject's body movement. The three-dimensional feature data generation unit 203 may generate skeletal data by, for example, calculating three-dimensional coordinates on the x-axis, y-axis, and z-axis for each specified skeletal key point of the three-dimensional data portion, and may generate skeletal feature data by extracting the features of the generated skeletal data. In addition, the three-dimensional feature data generation unit 203 may obtain parameters such as the angle at which each joint identified for the subject is bent and the speed at which it is bent, and convert the obtained parameters into features to generate movement feature data. Furthermore, the three-dimensional feature data generation unit 203 may use a trained model when generating the three-dimensional feature data. The trained model may be constructed by executing a learning process to output estimated results of skeleton and movement features in response to input of three-dimensional data of about a few seconds in which a moving person is detected.

[0020] In this embodiment, the three-dimensional feature data may include either skeletal feature data or movement feature data, but not the other. In the following description, an example will be given in which the three-dimensional feature data includes skeletal feature data and movement feature data.

[0021] The registration unit 204 registers the three-dimensional feature data generated by the three-dimensional feature data generation unit 203 during authentication registration as reference information to be used for authentication (authentication reference information). Specifically, the registration of the authentication reference information is performed by the registration unit 204 storing the authentication reference information in the authentication reference information storage unit 206.

[0022] The authentication unit 205 executes authentication processing. During authentication, the authentication unit 205 compares three-dimensional feature data serving as authentication information generated based on three-dimensional data obtained by the three-dimensional sensor 100 detecting the person to be authenticated with the authentication reference information stored in the authentication reference information storage unit 206. When the authentication unit 205 obtains authentication reference information whose feature amounts match the three-dimensional feature data serving as authentication information, the authentication unit 205 may output an authentication result indicating successful authentication. On the other hand, when the authentication unit 205 does not obtain authentication reference information whose feature amounts match the three-dimensional feature data serving as authentication information, the authentication unit 205 may output an authentication result indicating unsuccessful authentication.

[0023] The authentication reference information storage unit 206 stores the authentication reference information.

[0024] The authentication history information storage unit 207 stores authentication history information indicating the history of authentication processing by the authentication unit 205 .

[0025] Furthermore, the authentication system 200 is communicably connected to a service system 300. The service system 300 is a system that provides a predetermined service. The service system 300 includes a service control unit 301. The service control unit 301 controls the provision of services by the service system 300. The services provided by the service system 300 are not particularly limited, but in the following description, the service system 300 is a gate through which people enter, and the service control unit 301 controls the opening and closing of the gate depending on whether or not the person (person to be authenticated) attempting to pass through the gate in the authentication system 200 is authenticated, thereby allowing those who are authenticated to pass through but not those who are not authenticated to pass through.

[0026] An example of a processing procedure executed by the three-dimensional sensor 100 and the authentication system 200 in response to authentication registration will be described with reference to the flowchart of FIG. Step S100: For advance authentication and registration, the person to be registered acts in such a way that he or she can be detected by, for example, a 3D sensor 100 installed for authentication and registration. The 3D sensor 100 for authentication and registration detects the three-dimensional shape of the person to be registered and generates three-dimensional data indicating the detected three-dimensional shape.

[0027] Step S102: Three-dimensional sensor 100 transmits the three-dimensional data generated in step S100 to authentication system 200.

[0028] Step S200: In authentication system 200, communication unit 201 receives the three-dimensional data transmitted from three-dimensional sensor 100 in step S102.

[0029] Step S202: The preprocessing unit 202 performs preprocessing on the three-dimensional data received in step S200 to extract a three-dimensional data portion corresponding to the person to be registered.

[0030] Step S204: The three-dimensional feature data generating unit 203 generates skeletal feature amount data of the person to be enrolled from the three-dimensional data portion extracted by the preprocessing in step S202.

[0031] Step S206: Furthermore, the three-dimensional feature data generating unit 203 generates movement feature amount data from the three-dimensional data portion extracted by the preprocessing in step S202.

[0032] Step S208: The registration unit 204 registers authentication reference information corresponding to the person to be registered. That is, the registration unit 204 stores, in the authentication reference information storage unit 206, authentication reference information including the skeleton feature data generated in step S204 and the movement feature data generated in step S206.

[0033] Next, with reference to the sequence diagram of FIG. 3, an example of a processing procedure executed by the three-dimensional sensor 100, the authentication system 200, and the service system 300 in relation to the provision of a service in response to authentication will be described.

[0034] Step S300: The three-dimensional sensor 100 installed to authenticate (entry authentication) people attempting to enter through the gate (service system 300) detects the three-dimensional shape of the person attempting to enter through the gate and generates three-dimensional data indicating the detected three-dimensional shape.

[0035] Step S302: Three-dimensional sensor 100 transmits the three-dimensional data generated in step S300 to authentication system 200.

[0036] Step S304: In the authentication system 200, the communication unit 201 receives the three-dimensional data transmitted in step S302.

[0037] Step S306: The preprocessing unit 202 and the three-dimensional feature data generating unit 203 of the authentication system 200 perform the same processes as steps S202 to S206 in Fig. 2 on the three-dimensional data received in step S304. By performing the processes in this manner, skeleton feature data and movement feature data of the person to be authenticated are generated. The three-dimensional feature data generating unit 203 generates authentication information including the generated skeleton feature data and movement feature data.

[0038] Step S308: The authentication unit 205 of the authentication system 200 executes authentication processing. That is, the authentication unit 205 sequentially compares the authentication reference information stored in the authentication reference information storage unit 206 with the authentication information generated in step S306. If, as a result of the comparison, authentication reference information that matches each feature of the skeleton feature data and the movement feature data in the authentication information is obtained, the authentication unit 205 outputs an authentication result indicating successful authentication, and if matching authentication reference information is not obtained, the authentication unit 205 outputs an authentication result indicating unsuccessful authentication. Furthermore, the authentication unit 205 may store the result of the current authentication process in step S308 in the authentication history information storage unit 207.

[0039] Step S310: If the authentication result indicating successful authentication is output in step S308, the authentication unit 205 transmits a successful authentication notification to the service system 300.

[0040] Step S312: In response to receiving the authentication success notification, the service control unit 301 in the service system 300 performs control to open the gate.

[0041] Step S314: If the authentication result indicating that the authentication was not successful is output in step S308, the authentication unit 205 transmits a notification of the authentication not being successful to the service system 300.

[0042] Step S316: In response to receiving the authentication failure notification, the service control unit 301 does not control the gate to open, but instead notifies the user of an error that the entrance authentication has failed.

[0043] According to the configuration of the present embodiment described so far, the person to be registered can register authentication reference information as skeletal feature data and movement feature data as long as they behave appropriately without intentionally having their biometric information detected by the sensor, such as by moving as needed while remaining in the environment where the three-dimensional sensor 100 is installed. Furthermore, during authentication, the person to be authenticated can be authenticated as long as they behave in accordance with their own will, without intentionally having their biometric information detected by the sensor. In this way, in this embodiment, authentication registration and authentication processing are smoothly performed even if the person to be registered or authenticated does not intentionally stand in front of the sensor and perform actions that would cause their biometric information to be detected.

[0044] Furthermore, in this embodiment, the authentication reference information and authentication information used in the authentication process are information that indicates the characteristics of a person's bone structure and movements, and are not information that identifies an individual, which makes it possible to protect the privacy of individuals to be registered and authenticated.

[0045] The authentication system 200 shown in FIG. 1 may be configured, for example, as a distributed system across multiple devices and systems. As an example, the authentication system 200 may be distributed into a system that generates three-dimensional feature data from the three-dimensional data output by the three-dimensional sensor 100 (e.g., including a preprocessing unit 202 and a three-dimensional feature data generation unit 203), and a system that executes authentication processing (e.g., including a registration unit 204, an authentication unit 205, an authentication reference information storage unit 206, and an authentication history information storage unit 207). Distributing the authentication system 200 in this manner can also distribute the processing load of the system. In this case, for example, if the system that generates three-dimensional feature data is constructed using edge computing and the authentication system is constructed in the cloud, it can improve the convenience of system use and maintenance, for example.

[0046] Second Embodiment Next, a second embodiment will be described. In this embodiment, if a customer (member) has registered authentication reference information and is authenticated at a store, so-called empty-handed payment is possible. Hands-free payment is a payment method that allows a customer to pay for the purchase of a product without having to meet a store clerk or operate a self-service terminal at the store.

[0047] 4 shows an example of the overall configuration of a service control system according to this embodiment. As shown in the figure, the service control system of this embodiment includes a three-dimensional sensor 100, an authentication-enabled information processing device 400, a store management server 500, a customer terminal 600, and a data reader 700. In the service control system of this embodiment, functions equivalent to those of the authentication system 200 of the first embodiment are realized by the authentication-enabled information processing device 400 and the store management server 500.

[0048] Although one 3D sensor 100 is shown in the figure, 3D sensors 100 may be installed at multiple predetermined positions in the store ST. In this embodiment, the 3D sensor 100 generates 3D data that indicates the 3D shape of a customer CS who is present in the store ST and is to be registered or authenticated.

[0049] The authentication-enabled information processing device 400 generates three-dimensional feature data from the three-dimensional data generated by the three-dimensional sensor 100. The authentication-enabled information processing device 400 transmits the generated three-dimensional feature data to the store management server 500 via communication.

[0050] The store management server 500 is a server that performs various management operations for the store ST. In this embodiment, the store management server 500 performs customer authentication in response to empty-handed payment, and if authentication is successful, executes empty-handed payment, but if authentication is not successful, controls so that empty-handed payment is not executed.

[0051] The customer CS has a customer terminal 600. An application that supports empty-handed payment (empty-handed payment application) is installed on the customer terminal 600. The customer CS operates the empty-handed payment application at the store ST to make an empty-handed payment.

[0052] A data reader 700 is installed near gate GT, which is the entrance and exit of store ST. The data reader communicates with an RFID tag 800 attached to a product MC, for example, to read product information stored in the RFID tag 800. The product information may include information such as a product code, product name, and unit price. Furthermore, the data reader 700 communicates with the empty-handed payment application of the customer terminal 600 to read the customer ID from the empty-handed payment application. Furthermore, if the customer terminal 600 is capable of displaying the customer ID using a code symbol such as a two-dimensional code, the data reader 700 may be capable of acquiring the customer ID by reading the code symbol. The data reader 700 is communicably connected to the store management server 500. The data reader 700 is capable of transmitting the read product information and customer ID to the store management server 500.

[0053] 5 is a diagram showing an example of the functional configuration of the authentication-enabled information processing device 400, store management server 500, and customer terminal 600. Each of the authentication-enabled information processing device 400, store management server 500, and customer terminal 600 may be configured with hardware such as a CPU, ROM, RAM, and storage devices such as HDDs and SSDs. The functions of the authentication-enabled information processing device 400, store management server 500, and customer terminal 600 shown in the figure may be realized by executing a program on a CPU provided in the authentication-enabled information processing device 400, store management server 500, and customer terminal 600, respectively.

[0054] First, a description will be given of an example of the functional configuration of the authentication-enabled information processing device 400. The authentication-enabled information processing device 400 in the figure includes a communication unit 401, a preprocessing unit 402, and a three-dimensional feature data generation unit 403. The communication unit 401 is connected to the three-dimensional sensor 100 and the store management server 500 so as to be able to communicate with each other.

[0055] Preprocessing unit 402 performs preprocessing of the three-dimensional data captured by three-dimensional sensor 100, and extracts the three-dimensional data portion of the target customer (the customer to be registered or the customer to be authenticated).

[0056] The three-dimensional feature data generating unit 403 generates three-dimensional feature data (skeleton feature data, movement feature data) from the three-dimensional data portion of the target customer extracted from the three-dimensional data by the preprocessing unit 402. The three-dimensional feature data generation unit 403 transmits the generated three-dimensional feature data to the store management server 500 .

[0057] Next, we will explain an example of the functional configuration of the store management server 500. The store management server 500 in the figure includes a communication unit 501, a registration unit 502, an authentication unit 503, a payment processing unit 504, and a customer information storage unit 505.

[0058] The communication unit 501 is communicably connected to the authentication-enabled information processing device 400, the customer terminal 600, the data reader 700, and the like.

[0059] The registration unit 502 registers the three-dimensional feature data of the customer to be registered, received from the authentication-enabled information processing device 400, as authentication reference information of the customer to be registered. Specifically, the registration unit 502 stores the authentication reference information in the customer information stored in the customer information storage unit 505 in association with the customer ID of the customer to be registered.

[0060] Authentication unit 503 executes authentication processing. During authentication, authentication unit 503 compares authentication information generated based on the three-dimensional data obtained by detecting the customer to be authenticated using three-dimensional sensor 100 with authentication reference information stored in the customer information stored in customer information storage unit 505.

[0061] The payment processing unit 504 executes payment processing corresponding to empty-handed payment.

[0062] The customer information storage unit 505 stores customer information. Among the customer information, authentication reference information is stored in the customer information of a customer who has registered for empty-handed payment.

[0063] Next, a description will be given of an example of the functional configuration of the customer terminal 600. The customer terminal 600 includes a communication unit 601, an application processing unit 602, and a user interface unit 603. The communication unit 601 is connected to the store management server 500 so as to be able to communicate with it. The application processing unit 602 executes processing corresponding to the functions of the empty-handed payment application. The user interface unit 603 includes an operation unit, a display unit, an audio output unit, and the like, and provides a user interface.

[0064] An example of a processing procedure executed by the service control system of this embodiment in relation to authentication registration will be described with reference to the sequence diagram of FIG. Step S500: To authenticate and register the customer CS, the customer CS performs an authentication and registration instruction operation on the empty-handed payment application running on the customer terminal 600 in the store ST.

[0065] Step S502: In response to the authentication registration instruction operation, the application processing unit 602 of the customer terminal 600 sends an authentication registration request to the store management server 500. The authentication registration request includes the customer ID of the customer CS (customer to be registered) who is to be registered as the person to be authenticated this time.

[0066] Step S504: In response to receiving the authentication registration request sent in step S502, the registration unit 502 of the store management server 500 sets the authentication registration mode. The registration unit 502 stores the authentication reference information received as described below while the authentication registration mode is set in the customer information of the customer whose customer ID is included in the authentication registration request.

[0067] Step S506: After performing the authentication registration instruction operation, the customer to be registered may move around the store ST as desired.

[0068] Step S508: Of the three-dimensional sensors 100 installed in the store ST, the three-dimensional sensor 100 within whose detection range the customer to be registered moving within the store ST is present generates three-dimensional data including the three-dimensional shape of the customer to be registered.

[0069] Step S510: Three-dimensional sensor 100, which generated the three-dimensional data in step S508, transmits the generated three-dimensional data to authentication-enabled information processing device 400.

[0070] Step S512: In the authentication-enabled information processing device 400, the preprocessing unit 402 extracts the three-dimensional data portion of the customer to be registered from the three-dimensional data transmitted in step S510. The three-dimensional feature data generating unit 403 generates three-dimensional feature data (skeleton feature data, movement feature data) indicating the customer to be registered from the extracted three-dimensional data portion.

[0071] Step S514: The three-dimensional feature data generation unit 403 causes the communication unit 401 to transmit the three-dimensional feature data generated in step S512 to the store management server 500.

[0072] Step S516: In response to receiving the three-dimensional feature data transmitted in step S514, the registration unit 502 in the store management server 500 performs authentication registration. That is, the registration unit 502 stores the currently received three-dimensional feature data as authentication reference information in the customer information stored in the customer information storage unit 505, which is associated with the same customer ID as included in the authentication registration request transmitted in step S502.

[0073] Step S518: When the registration unit 502 completes the authentication registration in step S516, it transmits a registration completion notice to the customer terminal 600.

[0074] Step S520: Furthermore, upon completion of the authentication registration, the registration unit 502 may cancel the authentication registration mode set in step S504.

[0075] Step S522: In response to receiving the registration completion notification transmitted in step S518, the application processing unit 602 of the customer terminal 600 controls the user interface unit 603 to notify the customer to be registered that the authentication registration has been completed. The notification of the authentication registration completion may be made, for example, by display or sound.

[0076] An example of a processing procedure executed by the service control system of this embodiment in response to empty-handed payment will be described with reference to the sequence diagram of FIG. Step S600: When a customer CS wishes to make empty-handed payment for an item to be purchased at a store ST, the customer CS performs an operation (empty-handed payment declaration operation) on a customer terminal 600 running an empty-handed payment application at the store ST to declare that the customer will make empty-handed payment for this purchase.

[0077] Step S602: In response to the empty-handed payment declaration operation, the application processing unit 602 of the customer terminal 600 sends an empty-handed payment declaration notice to the store management server 500. The empty-handed payment declaration notice includes the customer ID of the corresponding customer.

[0078] Step S604: In response to receiving the empty-handed payment declaration notice, the authentication unit 503 in the store management server 500 sets an empty-handed payment flag corresponding to the customer CS indicated by the customer ID included in the received empty-handed payment declaration notice. A customer for whom the empty-handed payment flag is set becomes a customer (authentication target customer) who is subject to authentication processing to determine whether empty-handed payment is possible.

[0079] Step S606: The customer to be authenticated who has made the empty-handed payment declaration operation in step S600 moves around the store ST and places the products to be purchased into the shopping cart.

[0080] Step S608: As the customer moves within the store ST, the 3D sensor 100 installed in the store ST within whose detection range the customer to be authenticated moving within the store ST is present generates 3D data including the 3D shape of the customer to be authenticated.

[0081] Step S610: Three-dimensional sensor 100, which generated the three-dimensional data in step S608, transmits the generated three-dimensional data to authentication-enabled information processing device 400.

[0082] Step S612: In the authentication-enabled information processing device 400, the preprocessing unit 402 extracts the three-dimensional data portion of the customer to be authenticated from the three-dimensional data transmitted in step S610. The three-dimensional feature data generating unit 403 generates authentication information (skeleton feature data, movement feature data) corresponding to the customer to be authenticated from the extracted three-dimensional data portion.

[0083] Step S614: The three-dimensional feature data generation unit 403 causes the communication unit 401 to transmit the authentication information generated in step S612 to the store management server 500.

[0084] Step S618: The authentication unit 503 in the store management server 500 acquires the authentication information sent in step S614.

[0085] Step S620: To complete empty-handed payment, the customer to be authenticated goes near the gate GT and has the data reader 700 installed near the gate GT read the product information and customer ID stored in the RFID tag 800 of each product placed in the shopping cart. At this time, since the customer to be authenticated is located near the data reader 700, the RFID tag 800 of the product in the shopping cart and the customer to be authenticated are within the communication range of the data reader 700. In response to this state, the RFID tag 800 and the customer terminal 600 become capable of communicating with the data reader 700, and the data reader 700 can read the product information from the RFID tag 800 and the customer ID from the customer terminal 600. In addition, regarding the customer ID, the customer to be authenticated may display a code symbol (barcode or two-dimensional code) of the customer ID on the customer terminal 600 running the empty-hands payment application, and the displayed code symbol may be read by the code reader of the data reader 700.

[0086] Step S622: The data reader 700 reads the product information and the customer ID in response to the above-mentioned action of the customer to be authenticated corresponding to step S600.

[0087] Step S624: In response to reading the product information and customer ID, an authentication trigger including the read product information and customer ID is sent to the store management server 500.

[0088] Step S626: In response to receiving the authentication trigger, the authentication unit 503 of the store management server 500 executes authentication processing. The authentication unit 503 obtains, from the customer information storage unit 505, authentication reference information stored in the customer information associated with the same customer ID included in the authentication trigger sent in step S624. The authentication unit 503 compares the skeleton feature data and movement feature data included in the acquired authentication reference information with the skeleton feature data and movement feature data included in the authentication information acquired in step S616. If the comparison shows that both the skeleton feature data and the movement feature data match, the authentication unit 503 outputs an authentication result indicating successful authentication. On the other hand, if the comparison shows that at least one of the skeleton feature data and the movement feature data does not match, the authentication unit 503 may output an authentication result indicating unsuccessful authentication. Furthermore, the authentication unit 503 may also output an authentication result indicating unsuccessful authentication if the authentication reference information is not stored in the customer information associated with the same customer ID as that included in the authentication trigger transmitted in step S624.

[0089] Step S628: If the authentication result of step S626 indicates successful authentication, the payment processing unit 504 of the store management server 500 executes payment processing corresponding to the empty-handed payment for the customer to be authenticated. At this time, the payment processing unit 504 may execute payment processing corresponding to the empty-handed payment using credit card information or other predetermined non-cash payment information registered in the customer information of the customer to be authenticated for empty-handed payment. The payment processing unit 504 may store payment processing history information indicating the payment processing result in a predetermined memory unit, thereby storing the history of the payment processing.

[0090] Step S630: When the empty-handed payment processing in step S628 is completed, the payment processing unit 504 sends a payment completion notice to the customer terminal 600 that sent the empty-handed payment declaration notice.

[0091] Step S632: In response to receiving the payment completion notification, the application processing unit 602 of the customer terminal 600 notifies the user that the empty-handed payment has been completed by displaying or outputting audio on the user interface unit 603.

[0092] Step S634: On the other hand, if the authentication result in step S626 indicates that authentication was not successful, the payment processing unit 504 does not execute the payment process according to the empty-handed payment in step S628, and sends a payment failure notice to the customer terminal 600 that sent the empty-handed payment declaration notice. The payment failure notice notifies that empty-handed payment is not possible because authentication of the customer to be authenticated was not successful.

[0093] Step S636: In response to receiving the payment failure notification, the application processing unit 602 of the customer terminal 600 notifies the customer that empty-handed payment is not possible by displaying or outputting audio on the user interface unit 603. When notifying the customer that empty-handed payment is not possible, the notification may include information indicating that the reason for the non-availability of empty-handed payment is that authentication was not successful, or information informing the customer of payment methods other than empty-handed payment (such as cash payment or non-cash payment involving the use of a checkout device at the store ST).

[0094] If the authentication process result in step S626 indicates that authentication has not been established, the store management server 500 may, for example, control the gate GT to remain closed rather than open, so as to prevent the customer to be authenticated from exiting through the gate GT. At this time, the store management server 500 may issue an alert to the store clerk by lighting up a lamp or making a sound on the gate GT, or may display a message on a store terminal instructing the store clerk to settle the transaction face-to-face with the customer.

[0095] <Modification> A modification of this embodiment will now be described. In each of the above embodiments, if authentication is not successful after one authentication process, the service (passing through a gate, empty-handed payment) cannot be executed. However, depending on the position, movement, surrounding circumstances, etc. of the person to be authenticated (customer to be authenticated), there are cases where 3D sensor 100 is unable to obtain 3D data of sufficient quality. In such cases, errors may occur in the feature amounts used as authentication information, and authentication may not be successful even though it should have been successful. Therefore, in this modified example, if the result of the authentication process is unsuccessful, the authentication process may be retried up to a predetermined upper limit number of times. In this case, taking the system configuration of the first embodiment as an example, authentication system 200 may, in response to the failure of authentication, reacquire three-dimensional data from three-dimensional sensor 100 that is generating three-dimensional data of the person to be authenticated and that is present in the detection range, and re-execute the authentication process. In this case, in correspondence with the processing procedure of Fig. 3, in response to the failure of authentication, the processes of steps S300 to S308 are re-executed. Alternatively, if authentication is unsuccessful, the authentication system 200 may regenerate authentication information based on the three-dimensional data received in step S304, and re-execute the authentication process using the regenerated authentication information.

[0096] In each of the above embodiments, the preprocessing unit (202, 402) and the three-dimensional feature data generating unit (203, 403) may be provided separately for generating the authentication reference information and the authentication information. With this configuration, it is possible to improve the authentication accuracy by performing appropriate preprocessing and generating appropriate three-dimensional feature data for the authentication reference information and the authentication information, respectively.

[0097] <Additional Notes> (1) One aspect of this embodiment is an authentication system comprising: a three-dimensional feature data generation unit that generates three-dimensional feature data indicating the three-dimensional features of a subject based on three-dimensional data indicating the three-dimensional shape of the subject detected by a three-dimensional sensor; a registration unit that registers the three-dimensional feature data generated by the three-dimensional feature data generation unit in response to authentication registration as reference information to be used in an authentication process to authenticate a person; and an authentication unit that performs authentication processing by comparing the authentication information as three-dimensional feature data generated by the three-dimensional feature data generation unit based on three-dimensional data obtained by detecting the three-dimensional shape of the subject using the three-dimensional sensor during authentication with the reference information registered by the registration unit.

[0098] (2) One aspect of the present embodiment is the authentication system according to (1), wherein the three-dimensional feature data may be skeletal data indicating the skeleton of the person to be authenticated.

[0099] (3) One aspect of this embodiment is the authentication system according to (1) or (2), wherein the three-dimensional feature data may be movement feature data indicating the characteristics of the movement of the person to be authenticated.

[0100] (4) One aspect of this embodiment is an authentication system according to any one of (1) to (3), which may further include a service control unit that controls the provision of a specified service based on the result of authentication success or failure by the authentication unit.

[0101] (5) One aspect of this embodiment is an authentication system according to any one of (1) to (4), wherein the authentication unit may re-execute the authentication process using the authentication information regenerated by the three-dimensional feature data generation unit up to a maximum number of times when an authentication result indicating unsuccessful authentication is obtained.

[0102] (6) One aspect of this embodiment is the authentication system described in (5), wherein the three-dimensional feature data generation unit may regenerate the authentication information based on the three-dimensional data obtained by the three-dimensional sensor after the authentication unit obtains an authentication result indicating that authentication was not successful.

[0103] (7) One aspect of this embodiment is the authentication system described in (5), wherein the three-dimensional feature data generation unit may regenerate the authentication information based on the three-dimensional data used to generate the authentication information used when the authentication unit obtained an initial authentication result of unsuccessful authentication.

[0104] (8) One aspect of this embodiment is an authentication system described in any one of (1) to (7), wherein the registration unit registers the reference information in association with non-cash payment information used by the corresponding subject for non-cash payment, and may further include a payment processing unit that performs payment processing so that a non-cash payment corresponding to the subject is made upon successful authentication by the authentication unit.

[0105] (9) One aspect of this embodiment is an authentication method in an authentication system, including: a three-dimensional feature data generation step in which a three-dimensional feature data generation unit generates three-dimensional feature data indicating three-dimensional features of a subject based on three-dimensional data indicating the three-dimensional shape of the subject detected by a three-dimensional sensor; a registration step in which a registration unit registers the three-dimensional feature data generated by the three-dimensional feature data generation step in response to authentication registration as reference information to be used in an authentication process to authenticate a person; and an authentication step in which the authentication unit executes the authentication process by comparing the authentication information as three-dimensional feature data generated by the three-dimensional feature data generation step based on three-dimensional data obtained by the three-dimensional sensor detecting the three-dimensional shape of the subject during authentication with the reference information registered by the registration step.

[0106] (10) One aspect of this embodiment is a program for causing a computer in an authentication system to function as a three-dimensional feature data generation unit that generates three-dimensional feature data indicating the three-dimensional features of a subject based on three-dimensional data indicating the three-dimensional shape of the subject detected by a three-dimensional sensor, a registration unit that registers the three-dimensional feature data generated by the three-dimensional feature data generation unit in response to authentication registration as reference information to be used in the authentication process to authenticate a person, and an authentication unit that performs the authentication process by comparing the authentication information as three-dimensional feature data generated by the three-dimensional feature data generation unit based on three-dimensional data obtained when the three-dimensional sensor detects the three-dimensional shape of the subject during authentication with the reference information registered by the registration unit.

[0107] Note that programs for implementing the functions of the authentication system 200 and service system 300 in the first embodiment, the authentication-enabled information processing device 400, the store management server 500, and the customer terminal 600 in the second embodiment, etc., may be recorded on a computer-readable recording medium, and the programs may be loaded into a computer system and executed to perform the processing of the above-mentioned systems and devices. Here, "loading a program recorded on a recording medium into a computer system and executing it" includes installing the program on a computer system. The term "computer system" here includes hardware such as an OS and peripheral devices. The term "computer system" may also include multiple computer devices connected via a network, including the Internet, a WAN, a LAN, a dedicated line, or other communication lines. The term "computer-readable recording medium" refers to portable media such as a floppy disk, a magneto-optical disk, a ROM, or a CD-ROM, as well as storage devices such as a hard disk drive (HDD) or solid-state drive (SSD) built into a computer system. The recording medium storing the program may also be a non-transitory recording medium such as a CD-ROM. The term "recording medium" also includes internal or external recording media accessible from a distribution server for distributing the program. The program code stored on the recording medium of the distribution server may be different from the program code in a format executable by the terminal device. In other words, the format in which the program is stored on the distribution server is not important as long as it can be downloaded from the distribution server and installed in a format executable by the terminal device. The program may be divided into multiple parts, each downloaded at a different time and then combined on the terminal device, or each part may be distributed by a different distribution server. Furthermore, the term "computer-readable recording medium" also includes a storage medium that stores a program for a certain period of time, such as volatile memory (RAM) within a computer system that serves as a server or client when a program is transmitted over a network. The program may also be for implementing part of the functions described above.Furthermore, the above-mentioned functions may be realized in combination with a program already recorded in the computer system, that is, a so-called differential file (differential program). [Explanation of symbols]

[0108] 100 3D sensor, 200 authentication system, 201 communication unit, 202 pre-processing unit, 203 3D feature data generation unit, 204 registration unit, 205 authentication unit, 206 authentication reference information storage unit, 207 authentication history information storage unit, 300 service system, 301 service control unit, 400 authentication-compatible information processing device, 401 communication unit, 402 pre-processing unit, 403 3D feature data generation unit, 500 store management server, 501 communication unit, 502 registration unit, 503 authentication unit, 504 payment processing unit, 505 customer information storage unit, 600 customer terminal, 601 communication unit, 602 application processing unit, 603 user interface unit, 700 data reader, 800 RFID tag

Claims

1. a three-dimensional feature data generation unit that generates three-dimensional feature data that indicates three-dimensional features of the subject based on three-dimensional data that indicates the three-dimensional shape of the subject detected by the three-dimensional sensor; a registration unit that registers the three-dimensional feature data generated by the three-dimensional feature data generation unit in response to authentication registration as reference information to be used in authentication processing for authenticating a person; an authentication unit that executes authentication processing by collating authentication information as three-dimensional feature data generated by the three-dimensional feature data generation unit based on three-dimensional data obtained by detecting the three-dimensional shape of the subject using a three-dimensional sensor during authentication with reference information registered by the registration unit; An authentication system comprising:

2. The three-dimensional feature data is skeleton data indicating the skeleton of the person to be authenticated. The authentication system of claim 1 .

3. The three-dimensional feature data is movement feature data that indicates the movement features of the person to be authenticated.

3. The authentication system according to claim 1 or 2.

4. The apparatus further includes a service control unit that controls the provision of a predetermined service based on the result of authentication by the authentication unit.

3. The authentication system according to claim 1 or 2.

5. When the authentication result indicates that the authentication was not successful, the authentication unit re-executes the authentication process using the authentication information regenerated by the three-dimensional feature data generation unit up to an upper limit number of times.

3. The authentication system according to claim 1 or 2.

6. The three-dimensional feature data generation unit regenerates the authentication information based on the three-dimensional data obtained by the three-dimensional sensor after the authentication unit obtains an authentication result indicating that authentication was not successful. The authentication system according to claim 5 .

7. The three-dimensional feature data generation unit regenerates the authentication information based on the three-dimensional data used to generate the authentication information used when the authentication unit obtained an initial authentication result of failure. The authentication system according to claim 5 .

8. The registration unit registers the reference information in association with non-cash payment information used by the corresponding target person for non-cash payment, The authentication unit further includes a payment processing unit that performs payment processing so that a non-cash payment corresponding to the target person is made in response to authentication being established by the authentication unit.

3. The authentication system according to claim 1 or 2.

9. An authentication method in an authentication system, comprising: a three-dimensional feature data generating step in which a three-dimensional feature data generating unit generates three-dimensional feature data indicating three-dimensional features of the subject based on three-dimensional data indicating a three-dimensional shape of the subject detected by a three-dimensional sensor; a registration step in which a registration unit registers the three-dimensional feature data generated by the three-dimensional feature data generation step in response to the authentication registration as reference information to be used in an authentication process for authenticating a person; an authentication step in which an authentication unit executes authentication processing by collating authentication information as three-dimensional feature data generated in the three-dimensional feature data generating step based on three-dimensional data obtained by detecting the three-dimensional shape of the subject with the three-dimensional sensor during authentication, with reference information registered in the registration step; Authentication methods, including:

10. The computer in the authentication system a three-dimensional feature data generation unit that generates three-dimensional feature data that indicates three-dimensional features of the subject based on three-dimensional data that indicates the three-dimensional shape of the subject detected by the three-dimensional sensor; a registration unit that registers the three-dimensional feature data generated by the three-dimensional feature data generation unit in response to the authentication registration as reference information to be used in an authentication process for authenticating a person; an authentication unit that executes authentication processing by comparing authentication information as three-dimensional feature data generated by the three-dimensional feature data generation unit based on three-dimensional data obtained by detecting the three-dimensional shape of the subject with reference information registered by the registration unit during authentication; A program to function as a

Citation Information

Patent Citations

  • Face authentication system, access management system, management system, program

    JP2024061800A