User management system
The user management system addresses privacy concerns by employing a detection process without initial identification and using voluntary actions to trigger identification, enabling detailed user management with privacy protection.
Patent Information
- Application Number
- JP2024117149
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-22
- Publication Date
- 2026-02-03
AI Technical Summary
Existing user management systems face challenges in achieving detailed user management while respecting user privacy, as constant monitoring with devices like cameras is intrusive.
A user management system that employs a user detection process to identify user presence without identification, followed by an identification process triggered by voluntary user actions, using devices like infrared sensors and wireless sensing, and selectively applies identification only when specific actions are performed.
The system achieves detailed user management while protecting privacy by detecting users without constant identification, using voluntary actions to trigger identification, thus ensuring privacy considerations are met even with devices installed in each room.
Smart Images

Figure 2026016099000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a user management system that manages users who use one or more rooms. [Background technology]
[0002] Patent Document 1 discloses a behavior recognition system that can detect, identify, and specify behavior information of residents in a living space. The behavior recognition system includes a human presence sensor that detects the presence of a person and a human recognition sensor that acquires information to identify the detected person. The behavior recognition system estimates the person's behavior based on the human presence sensor and the information acquired by the human recognition sensor. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2024-011411 Summary of the Invention [Problem to be solved by the invention]
[0004] Consider managing users who use a room. To understand user behavior in detail and achieve more detailed user management, it is necessary to identify users. However, constantly monitoring users with cameras or other devices is not desirable from the perspective of protecting user privacy.
[0005] One object of the present disclosure is to provide a technology that can realize detailed user management while taking into consideration the aspect of privacy protection. [Means for solving the problem]
[0006] The first aspect relates to a user management system that manages one or more users who use first to Nth rooms (N is an integer of 1 or more). The user management system comprises one or more processors. One or more processors may: Execute a user detection process to detect a user present in the i-th room (i = 1 to N) without identifying the user; assigning an anonymous flag to the first user detected by the user detection process; Determine whether or not a first user assigned with an anonymous flag has performed a first specific action associated with the first user in a j-th room (j=1 to N); When a first user to which an anonymous flag is assigned performs a first specific action, a first specific flag for identifying the first user is assigned to the first user. It is configured as follows. [Effects of the Invention]
[0007] The user management system selectively uses a "user detection process" that detects users without identifying them, and a "user identification process" that identifies users based on specific actions performed by the user. Furthermore, because the specific actions that trigger the user identification process are voluntary actions of the user, management that takes privacy into consideration can be achieved even if devices that identify individuals are installed in each room. In other words, the user management system can achieve detailed user management that takes privacy protection into consideration. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a schematic diagram showing an overview of a user management system. [Figure 2] 10 is a flowchart showing the flow of processing in a user management system. [Figure 3] FIG. 10 is a schematic diagram showing some examples of re-anonymization processing. [Figure 4] FIG. 10 is a schematic diagram illustrating an overview of a movement determination process. [Figure 5] FIG. 10 is a schematic diagram illustrating an example of an indirect user identification process. [Figure 6] FIG. 1 is a block diagram illustrating an example of the configuration of a user management system. DETAILED DESCRIPTION OF THE INVENTION
[0009] Embodiments of the present disclosure will be described with reference to the accompanying drawings.
[0010] 1.User Management System 1-1.Main configuration FIG. 1 is a schematic diagram showing an overview of a user management system 1. The user management system 1 manages one or more users (hereinafter referred to as "users U") who use rooms 1 to N (N is an integer equal to or greater than 1). Rooms 1 to N are configured so that they can be accessed via corridors or other rooms. The user management system 1 is typically applied to spaces (such as apartment buildings, offices, etc.) made up of multiple private rooms and used by multiple specific people.
[0011] Each of the first to Nth rooms is equipped with a user detection unit 130 and a user identification unit 140.
[0012] The user management system 1 executes a "user detection process" to detect a user U present in a room in which the user detection unit 130 is installed. The user detection process is a process for detecting the presence of a person (user U) only, and does not identify the detected person. The user management system 1 assigns an "anonymity flag" to a user detected by the user detection process. The user detection unit 130 includes, for example, a human presence sensor such as an infrared sensor and a wireless sensing device. Wireless sensing is a mechanism for detecting an object by detecting fluctuations in radio waves caused by an object blocking radio waves of wireless communication. In this embodiment, for convenience of explanation, a user detected by the user detection process in the i-th room (i = 1 to N) is defined as a "first user U-1." In other words, the user detection process is a process for detecting the first user U-1 present in the i-th room and assigning an anonymous flag.
[0013] The user management system 1 determines whether the first user U-1, to whom an anonymous flag has been assigned, has performed a "specific action." A specific action is an action for identifying each user U, and is an action that the user U performs voluntarily and independently. Examples of specific actions include physical actions (such as sitting in a specific location or raising both hands) and device operations such as turning on a specific electronic device (e.g., a PC) or logging into a specific system using the electronic device. When a specific action by the first user U-1 is detected, the user management system 1 assigns a "first specific flag" to the first user U-1 to whom an anonymous flag has been assigned, thereby identifying the user. Hereinafter, the process of assigning a specific flag and identifying the user U will be referred to as a "user identification process." It is assumed that the first user U-1 performs the first specific action in the jth room (j = 1 to N) and is identified by the user identification process.
[0014] When detecting physical movements in the user identification process, the user identification unit 140 includes a photographing device such as a camera. Because the photographing device captures images of each room, it is not desirable from the perspective of privacy protection to use it constantly to identify the first user U-1. However, the user identification process by the user management system 1 is triggered by an action taken voluntarily by the first user U-1 himself / herself, that is, an action taken with the knowledge that he / she will be identified. It can be said that the user identification process in the user management system 1 can achieve both identification of individuals present in each room and privacy protection.
[0015] The user detection process and the user identification process may be performed in the same room or in different rooms. That is, the user U detected by the user detection process may move to another room and be identified by performing a specific action in the new room.
[0016] The user management system 1 acquires information about the anonymous flag and the specific flag as flag information F. The user management system 1 collectively manages the received flag information F. Specifically, based on the flag information F, the user management system 1 manages the number of users U present in each room and the status of users U entering and leaving each room.
[0017] This embodiment deals with a case in which the user management system 1 is applied to a facility 10 as shown in the lower part of Fig. 1. The facility 10 is formed by a collection of hexagonal rooms, and the central room is accessible to all the other rooms. In other words, the rooms of the facility 10 are configured so that they can be accessed via the central room. Note that the facility 10 is merely an example in which the user management system 1 is applied, and the number, shape, arrangement, etc. of the rooms are not limited to the example shown in this embodiment.
[0018] 1-2.Processing flow 2 is a flowchart showing the flow of processing in the user management system 1. The right part of the figure shows a schematic diagram of the state of the facility 10 in a series of steps.
[0019] In step S10, the user management system 1 executes a user detection process in the i-th room. If a user is detected (S10; Yes), the process proceeds to step S11. If a user is not detected (S10; No), the process repeats step S10.
[0020] In step S11, the user management system 1 assigns an anonymous flag to the first user U-1 detected in the i-th room. At this point, the user detection unit 130 recognizes that the first user U-1 is present in the i-th room, but has not yet identified the specific identity of the first user U-1. Next, the process proceeds to step S12.
[0021] In step S12, the user management system 1 determines whether or not a first specific action has been performed in the jth room. If the first specific action has been performed (S12; Yes), the process proceeds to step S13. If the first specific action has not been performed (S12; No), the process repeats step S12.
[0022] In step S13, the user management system 1 assigns a first identification flag to the first user U-1. At this point, the user identification unit 140 can identify the first user U-1 detected in the i-th room. Then, the process ends.
[0023] <Effects> The user management system 1 selectively uses a "user detection process" that detects the user U without identifying him / her, and a "user identification process" that identifies the user U based on a specific action performed by the user U. Furthermore, because the specific action that triggers the user identification process is a voluntary action of the user U, management that takes privacy into consideration can be achieved even if a device that identifies individuals is installed in each room. In other words, the user management system 1 can achieve detailed user management that takes privacy protection into consideration.
[0024] 2. Other processing 2-1. Re-anonymization process Consider a case where there are multiple users U. In this case, if there are multiple users U-1 to M (M is an integer equal to or greater than 2) in the kth room (k=1 to N), including the first user U-1 to whom a first identification flag has been assigned, it is desirable to update the first identification flag assigned to the first user U-1 to an anonymous flag. Hereinafter, the process of updating the identification flag to an anonymous flag will be referred to as the "re-anonymization process."
[0025] FIG. 3 is a schematic diagram showing several examples of the re-anonymization process. (A) in FIG. 3 illustrates a situation in which a second user U-2, assigned an anonymous flag, enters the kth room where a first user U-1 is present. Because the user management system 1 manages users U based on the number of flags in each room, if two users are present in the kth room, it is impossible to identify which of the two users is the identified first user U-1. Therefore, in such a case, it is desirable to update the first identification flag of the first user U-1 to an anonymous flag, so that two anonymous users exist in the kth room. The re-anonymization process helps prevent mismatches between the two types of flags (anonymous flag and identified flag). As shown in (B) in FIG. 3, when a second user U-2, assigned a second identification flag, enters the kth room, the re-anonymization process is performed not only on the first user U-1 but also on the second user U-2.
[0026] 2-2.Movement detection process Consider a case where the first to Nth rooms include two adjacent rooms. The user management system 1 may execute a "movement determination process" to determine whether a user present in one of the two adjacent rooms has moved to the other of the two adjacent rooms. FIG. 4 is a schematic diagram showing an overview of the movement determination process. If the two adjacent rooms are room s and room t (s, t = 1 to N), the movement determination process can be said to be a process to determine whether user U has moved between room s and room t. The movement determination process is executed based on the sth user number ns and the tth user number nt. The sth user number ns indicates the number of users present in room s. In other words, the sth user number ns can be said to be the number of flags (the sum of anonymous flags and specific flags) in room s. Similarly, the tth user number nt indicates the number of users present in room t. In the example of FIG. 4, user U has moved from room s to room t. When user U is present in room s, the sth user number ns is 1 and the tth user number nt is 0. When user U moves to room t, the s-th user number ns is 0 and the t-th user number nt is 1. Because room s and room t are adjacent to each other, changes in the s-th user number ns and the t-th user number nt accompanying user U's movement should occur within a short period of time. Generally speaking, if both the s-th user number ns and the t-th user number nt change within a predetermined time, the user management system 1 determines that user U has moved between room s and room t.
[0027] The s-th user number ns and the t-th user number nt can be considered to be adjacent user number information. In other words, the movement determination process can be considered to be a process of determining whether a user U present in one of two adjacent rooms has moved to the other of the two adjacent rooms, based on the adjacent user number information. In other words, by repeating the movement determination process, the user management system 1 can track users U within the facility 10.
[0028] 2-3. Indirect user identification processing In addition to the method based on the identification operation described in Section 1-1, the user identification process may also involve a method of indirectly identifying the first user U-1. Such a user identification process is specifically referred to as an "indirect user identification process."
[0029] 5 is a schematic diagram showing an example of an indirect user identification process. S1 and S2 are the same as (A) in FIG. 3. In S1, the first user U-1 is associated with "A," which is the user ID corresponding to the first identification flag.
[0030] In S2, a re-anonymization process is performed, and the first user U-1 and the second user U-2 are recognized as two anonymous users by the user management system 1. At this time, the user management system 1 records that "A" is included in the two anonymous users.
[0031] After that, the two anonymous users, including "A," each move and reach the state S3. At this time, if the movement determination process has been executed, the user management system 1 can track the two anonymous users, including "A." However, it cannot determine which of the two anonymous users is "A."
[0032] In S4, assume that one of the two anonymous users is identified as "B" (i.e., not "A") through the user identification process. At this time, the other of the two anonymous users (the one other than "B") is uniquely determined to be "A," so the user management system 1 can indirectly identify "A." At this time, the user management system 1 can identify "A" without determining the first identifying operation. Because "A" has already been identified by performing an identifying operation, it can be said that there is no problem from the perspective of privacy protection even if he is identified again.
[0033] The indirect user identification process can be applied not only to the case where there are two anonymous users, but also to the general case where there are multiple anonymous users. Generally speaking, the indirect user identification process is applied when, after the first user U-1 is assigned an anonymous flag by the re-anonymization process in the kth room, the second to Mth identification flags are assigned to all of the second to Mth users.
[0034] 3.Configuration example FIG. 6 is a block diagram showing an example of the configuration of the user management system 1. As shown in FIG.
[0035] 3-1. Example of the i-th room configuration An example of the configuration of the ith room is shown on the right side of Fig. 6. Note that the first to Nth rooms have the same configuration, so the ith room is shown here as a representative.
[0036] The control device 110 is a computer that controls each device installed in the i-th room. The control device 110 includes one or more processors 111 (hereinafter simply referred to as processors 111) and one or more storage devices 112 (hereinafter simply referred to as storage devices 112). The processor 111 executes various processes. For example, the processor 111 includes a CPU (central processing unit). The processor 111 can also be referred to as processing circuitry. The storage device 112 stores various information. Examples of the storage device 112 include a volatile memory, a non-volatile memory, an HDD (hard disk drive), an SSD (solid state drive), etc.
[0037] The flag program PROG1 is a computer program executed by the processor 111. The functions of the control device 110 are realized by cooperation between the processor 111, which executes the flag program PROG1, and the storage device 112. For example, the above-described user detection process and user identification process are performed by the control device 110 executing the flag program PROG1. The flag program PROG1 is stored in the storage device 112. Alternatively, the flag program PROG1 may be recorded on a computer-readable recording medium.
[0038] The control device 110 executes a user detection process and a user identification process. The control device 110 acquires information necessary for the user detection process via the user detection unit 130, and acquires information necessary for the user identification process via the user identification unit 140. The control device 110 also communicates with the management device 200 via the communication device 120. The control device 110 transmits the results of the user detection process and the user identification process, i.e., flag information F, to the management device 200.
[0039] The user registration information UR is information necessary for user identification processing. The user registration information UR is in a format in which the user ID of each user U is associated with data on a specific action corresponding to the user ID.
[0040] 3-2. Management device configuration example The control device 210 is a computer that controls the management device 200. The control device 210 includes one or more processors 211 (hereinafter simply referred to as processors 211) and one or more storage devices 212 (hereinafter simply referred to as storage devices 212). The processor 211 executes various processes. For example, the processor 211 includes a CPU (central processing unit). The processor 211 can also be referred to as processing circuitry. The storage device 212 stores various information. Examples of the storage device 212 include volatile memory, non-volatile memory, HDD (hard disk drive), SSD (solid state drive), etc.
[0041] The user management program PROG2 is a computer program executed by the processor 211. The functions of the control device 210 are realized by cooperation between the processor 211, which executes the user management program PROG2, and the storage device 212. The user management program PROG2 is stored in the storage device 212. Alternatively, the user management program PROG2 may be recorded on a computer-readable recording medium.
[0042] The flag information F is information about the anonymous flag and specific flag for each room. The flag information F includes information about when and in which room a flag was assigned. Based on the flag information F, the management device 200 can determine the number of users U present in each room, the time periods when users U tend to gather, and the like. The flag information F is used as neighboring user number information in the movement determination process.
[0043] The user behavior information UB is information indicating the behavior history of the user U. The user behavior information UB is obtained by aggregating the flag information F and the results of the movement determination process. The user behavior information UB is used to analyze the movement line of the user U within the facility 10.
[0044] The control device 210 communicates with the communication device 120 in the i-th room via the communication device 220.
[0045] 3-3.Other Note that at least a part of the user detection process and the user identification process may be executed by the management device 200. For example, when information acquired by the user detection unit 130 and the user identification unit 140 is sent from the control device 110 to the management device 200, the management device 200 can execute at least a part of the user detection process and the user identification process.
[0046] In general terms, one or more processors perform user detection processing, user identification processing, movement determination processing, re-anonymization processing, and indirect user identification processing. [Explanation of symbols]
[0047] 1: User management system, 10: Facility, 130: User detection unit, 140: User identification unit, F: Flag information, U: User
Claims
1. A user management system that manages one or more users who use first to Nth rooms (N is an integer of 1 or more), one or more processors; the one or more processors: Execute a user detection process to detect a user present in the i-th room (i=1 to N) without identifying the user; assigning an anonymous flag to the first user detected by the user detection process; determining whether or not the first user to whom the anonymous flag is assigned has performed a first specific action associated with the first user in a j-th room (j=1 to N); When the first user to which the anonymous flag is assigned performs the first specific action, a first specific flag for identifying the first user is assigned to the first user. It is configured as follows: User management system.
2. The user management system according to claim 1, the one or more users include a plurality of users; When it is detected by the user detection process that the first user to whom the first specific flag is assigned is present in the kth room (k = any one of 1 to N) and that second to Mth users (M is an integer of 2 or more) are present in the kth room, The one or more processors update the first specific flag assigned to the first user to the anonymous flag. It is configured as follows: User management system.
3. 3. The user management system according to claim 2, If second to Mth identification flags for identifying the second to Mth users are assigned to the second to Mth users, the one or more processors: The second to Mth specific flags assigned to the second to Mth users are updated to the anonymous flags. User management system.
4. 3. The user management system according to claim 2, After the anonymous flag is assigned to the first user in the kth room, second to Mth specific flags are assigned to all of the second to Mth users. the one or more processors: assigning the first specific flag to the first user without determining the first specific action; It is configured as follows: User management system.
5. The user management system according to any one of claims 1 to 4, N is 2 or more, The first to Nth rooms include two adjacent rooms, the adjacent user number information is information including the number of users detected by the user detection process in each of the two adjacent rooms; The one or more processors further Based on the information on the number of adjacent users, execute a movement determination process to determine whether or not a user present in one of the two adjacent rooms has moved to the other of the two adjacent rooms; It is configured as follows: User management system.
Citation Information
Patent Citations
Action recognition device, action recognition system, and action recognition method
JP2024011411A