Authentication apparatus and control method thereof

The authentication device adjusts threshold values based on shooting conditions to maintain accurate authentication in eye image-based systems, addressing issues of reduced usability and false acceptances.

JP2026028631APending Publication Date: 2026-02-20CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024131206
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-07
Publication Date
2026-02-20

AI Technical Summary

Technical Problem

Existing eye image-based authentication systems fail to perform correct authentication due to factors like unfavorable photographing conditions, leading to reduced usability and potential acceptance of false persons.

Method used

An authentication device that uses biometric authentication with adjustable threshold values based on predetermined conditions, switching between a first and second threshold value depending on the shooting conditions to enhance authentication success.

Benefits of technology

Prevents a decrease in usability by ensuring accurate authentication even under challenging conditions, reducing false rejections and acceptances.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026028631000001_ABST
    Figure 2026028631000001_ABST
Patent Text Reader

Abstract

To suppress deterioration of usability in authentication of a person.SOLUTION: An authentication device that authenticates a user of a predetermined device using biometric authentication includes holding means for holding a first feature amount of a predetermined person used for biometric authentication, acquisition means for acquiring biometric information of the user, and authentication means for authenticating that the user is the predetermined person when a similarity between a second feature amount derived from the biometric information and the first feature amount exceeds a threshold value. The authentication means performs authentication using a first threshold when the predetermined condition is not satisfied, and performs authentication using a second threshold lower than the first threshold when the predetermined condition is satisfied. The predetermined condition is associated with a second threshold.SELECTED DRAWING: Figure 10
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technique for authenticating a user of a device. [Background technology]

[0002] As a technology for authenticating (identifying) a person, a technology has been proposed in which a person is identified by matching based on an image of the person's eyes (eye image). Patent Document 1 discloses a technology for personal authentication using an image of the photographer's eyes looking through a viewfinder. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2024-2562 Summary of the Invention [Problem to be solved by the invention]

[0004] However, if an eye image suitable for matching cannot be acquired due to factors such as the circumstances at the time of photographing, correct authentication may not be performed. If correct authentication is not performed and the person is rejected or a false person is accepted, there is a problem of reduced usability.

[0005] The present invention has been made in view of the above problems, and aims to provide a technique for preventing a decline in usability in person authentication. [Means for solving the problem]

[0006] In order to solve the above-mentioned problems, an identification device according to the present invention has the following configuration: That is, an authentication device that authenticates a user of a predetermined device using biometric authentication, a storage means for storing a first feature amount of a predetermined person used in the biometric authentication; an acquisition means for acquiring biometric information of the user; an authentication means for authenticating the user as the predetermined person when a similarity between a second feature amount derived from the biometric information and the first feature amount exceeds a threshold value; Equipped with the authentication means performs authentication using a first threshold value as the threshold value when a predetermined condition is not satisfied, and performs authentication using a second threshold value lower than the first threshold value as the threshold value when the predetermined condition is satisfied; The predetermined condition is associated with the second threshold value. [Effects of the Invention]

[0007] According to the present invention, it is possible to provide a technique for preventing a decrease in usability in person authentication. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. [Figure 2] FIG. [Figure 3] FIG. 2 is a diagram illustrating a hardware configuration of a camera. [Figure 4] FIG. 2 is a diagram showing a field of view within a finder. [Figure 5] FIG. 2 is a diagram illustrating a functional configuration related to personal authentication. [Figure 6] 10 is a flowchart of a registration process. [Figure 7] 10 is a flowchart of an eye image acquisition process. [Figure 8] FIG. 10 is a diagram showing an example of a condition setting screen relating to similarity. [Figure 9] 10 is a flowchart of an authentication process. [Figure 10] 4 is a flowchart of a matching process (first embodiment). [Figure 11] 10A and 10B are diagrams illustrating a flowchart of an authentication status saving process and a structure of an image file. [Figure 12] 10 is a flowchart of a matching process (second embodiment). [Figure 13]FIG. 10 is a diagram showing an example of a table of shooting modes and corresponding settings. [Figure 14] 10 is a flowchart of a matching process (third embodiment). DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention claimed. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.

[0010] (First embodiment) A first embodiment of an authentication device according to the present invention will be described below by taking as an example a camera (image capture device) having a function for authenticating a user using biometric authentication.

[0011] <Device configuration> FIG. 1 shows the appearance of a camera 100 (digital still camera; interchangeable lens camera) according to the first embodiment. FIG. 1(a) is a front perspective view, and FIG. 1(b) is a rear perspective view. As shown in FIG. 1(a), the camera 100 has a photographing lens unit 100A and a camera housing 100B. The camera housing 100B is provided with a release button 101, which is an operation member that accepts image capture operations from the user (photographer). As shown in FIG. 1(b), the rear of the camera housing 100B is provided with an eyepiece 102 (finder) through which the user looks to view a display device 214 (display panel) (described below) included within the camera housing 100B. The rear of the camera housing 100B is also provided with operation members 103 to 105 that accept various operations from the user. For example, the operation member 103 is a touch panel that accepts touch operations, the operation member 104 is an operation lever that can be pushed in any direction, and the operation member 105 is a four-way key that can be pressed in each of four directions. The operation member 103 (touch panel) includes a display panel (for example, a liquid crystal panel) and has a function of displaying images on the display panel.

[0012] FIG. 2 is a cross-sectional view of the camera 100 taken along the YZ plane defined by the Y axis and Z axis shown in FIG. 1(a), and shows the general internal configuration of the camera 100. As shown in FIG.

[0013] Photographing lens unit 100A includes two lenses 201 and 202, an aperture 203, an aperture driver 204, a lens drive motor 205, a lens drive member 206, a photocoupler 207, a pulse plate 208, a mount contact 209, and a focus adjustment circuit 210. Lens drive member 206 includes a drive gear, and photocoupler 207 detects the rotation of pulse plate 208, which is linked to lens drive member 206, and transmits this information to focus adjustment circuit 210. Focus adjustment circuit 210 drives lens drive motor 205 based on information from photocoupler 207 and information from camera housing 100B (lens drive amount information), moving lens 201 and changing the focus position. Mount contact 209 is an interface between photographing lens unit 100A and camera housing 100B. While two lenses 201 and 202 are shown for simplicity, photographing lens unit 100A actually includes more than two lenses.

[0014] Camera housing 100B includes an image sensor 211, a CPU 212, a memory unit 213, a display device 214, and a display device drive circuit 215. Image sensor 211 is disposed at a planned imaging plane of photographing lens unit 100A. CPU 212 is a central processing unit of a microcomputer, and controls camera 100 as a whole. Memory unit 213 stores various information. For example, memory unit 213 stores images captured by image sensor 211. Display device 214 displays various information on the screen (display surface) of display device 214. For example, display device 214 is a liquid crystal panel, and displays the captured image (subject image) on the screen. Display device drive circuit 215 drives display device 214. A user can view the screen of display device 214 through eyepiece 102.

[0015] Camera housing 100B also includes light sources 216a and 216b, a beam splitter 217, a light receiving lens 218, and an eye imaging element 219. Light sources 216a and 216b are light sources conventionally used in single-lens reflex cameras to detect the line of sight from the relationship between the pupil and a reflection image of light reflected from the cornea (corneal reflection image), and are used to illuminate eyeball 220 of a user looking through the viewfinder (eyepiece 102). For example, light sources 216a and 216b are infrared light-emitting diodes that emit infrared light that is insensitive to the user, and are arranged around eyepiece 102. An optical image of the illuminated eyeball 220 (eye optical image; an optical image formed by light emitted from light sources 216a and 216b and reflected by eyeball 220) passes through eyepiece 102 and is reflected by beam splitter 217. The eye optical image is then formed by a light receiving lens 218 on an eye imaging element 219, which has a plurality of photoelectric conversion elements (for example, CCD or CMOS) arranged two-dimensionally. The light receiving lens 218 positions the pupil of the eyeball 220 and the eye imaging element 219 in a conjugate imaging relationship. By a gaze detection process described later, the gaze of the eyeball 220 is detected from the position of the corneal reflection image in the eye optical image formed on the eye imaging element 219. For example, at least one of information indicating the gaze direction (direction of the gaze) and information indicating the viewpoint (position where the gaze is fixed) on the screen of the display device 214 can be obtained as information related to the gaze. The viewpoint can be regarded as the position at which the user is looking, or as the gaze position.

[0016] <Hardware configuration> 3 is a block diagram showing the hardware configuration of camera 100. A gaze detection circuit 301, a photometry circuit 302, an autofocus detection circuit 303, a signal input circuit 304, a display device drive circuit 215, and a light source drive circuit 305 are communicatively connected to CPU 212. An inertial sensor 307 and a global positioning system (GPS) receiver 308 are also communicatively connected to CPU 212. CPU 212 transmits signals to a focus adjustment circuit 210 disposed in photographing lens unit 100A and to an aperture control circuit 306 included in aperture drive unit 204 within photographing lens unit 100A via mount contacts 209. A memory unit 213 attached to CPU 212 has a function of storing image signals from image sensor 211 and eye image sensor 219.

[0017] The gaze detection circuit 301 A / D converts the output of the eye imaging element 219 (an eye image obtained by capturing an image of the eye (eyeball 220)) when an eye optical image is formed on the eye imaging element 219, and transmits the result to the CPU 212. The CPU 212 extracts feature points required for gaze detection from the eye image according to gaze detection processing described later, and detects the user's gaze from the positions of the feature points.

[0018] The photometry circuit 302 receives a signal (for example, a luminance signal corresponding to the brightness of the subject field) obtained from the image sensor 211, which also serves as a photometry sensor (illuminance sensor). The photometry circuit 302 then performs predetermined processing (for example, amplification, logarithmic compression, and A / D conversion) on the signal, and sends the result to the CPU 212 as subject field luminance information.

[0019] The autofocus detection circuit 303 A / D converts signals from a plurality of detection elements (a plurality of pixels) included in the image sensor 211 that are used for phase difference detection, and sends the converted signals to the CPU 212. The CPU 212 calculates the distance to the subject corresponding to each focus detection point from the signals from the plurality of detection elements. This is a well-known technique known as image plane phase difference AF. In the first embodiment, as an example, it is assumed that there are focus detection points at 180 locations on the image plane that correspond to the 180 locations shown in the viewfinder field of view (the screen of the display device 214) in FIG. 4(a).

[0020] Switches SW1 and SW2 are connected to signal input circuit 304. Switch SW1 is turned on by the first stroke of release button 101, and is a switch for starting a shooting preparation operation (e.g., photometry and distance measurement) of camera 100. Switch SW2 is turned on by the second stroke of release button 101, and is a switch for starting a shooting operation. ON signals from switches SW1 and SW2 are input to signal input circuit 304 and transmitted to CPU 212. When switch SW1 is turned on, line of sight detection may be started.

[0021] A light source drive circuit 305 drives the light sources 216a and 216b. An inertial sensor 307 is, for example, an acceleration sensor or an angular velocity sensor, and detects the movement of the camera 100. A GPS receiver 308 continuously measures the current geographical position of the camera 100 to detect the movement of the camera 100.

[0022] Furthermore, operation members 103 to 105 are also connected to CPU 212. When a user operates operation members 103 to 105, operation members 103 to 105 output operation signals corresponding to the user's operation to CPU 212, and CPU 212 performs processing (control) corresponding to the operation signals. For example, CPU 212 moves a selection frame of a displayed menu in response to the operation signals.

[0023] FIG. 4(a) is a diagram showing the field of view within the viewfinder, and shows the state in which the display device 214 is operating (the state in which an image is displayed). As shown in FIG. 4(a), the field of view within the viewfinder includes a focus detection area 400, 180 ranging point indices 401, and a field of view mask 402. Each of the 180 ranging point indices 401 is displayed superimposed on a through image (live view image) displayed on the display device 214 so as to be displayed at a position corresponding to a focus detection point on the imaging surface. Of the 180 ranging point indices 401, the ranging point indices 401 that corresponds to the current viewpoint A (estimated position) is displayed highlighted, for example, with a frame.

[0024] <Functional configuration related to personal authentication> Fig. 5(a) is a block diagram showing the functional configuration related to personal authentication of a user of the camera 100. In this embodiment, "personal authentication" refers to a process of authenticating whether or not a user is a person registered in advance, based on an eye image of the user's eyeball 220 looking through the viewfinder (eyepiece 102), and recording the authentication result together with the captured image. Note that each functional unit shown in Fig. 5(a) is realized mainly by the CPU 212 executing a program.

[0025] The eye image acquisition unit 501 acquires an image of the user's eyeball 220 looking through the finder (eyepiece 102). Specifically, the eye image (eye image signal; electric signal of the eye image) is acquired from the eye imaging element 219 via the gaze detection circuit 301. A specific example of the eye image acquisition process will be described later with reference to FIG. 7.

[0026] The feature vector calculation unit 502 derives a feature vector, which is a feature quantity used for authentication, from the eye image. A neural network is used as a feature extractor to derive the feature vector. For example, a convolutional neural network (CNN), a type of neural network, is used. CNN extracts abstract information from an input image by repeatedly performing a process consisting of convolution, activation, and pooling on the input image. In this process, a processing unit consisting of convolution, activation, and pooling is often called a layer. There are several well-known activation methods used in this process, such as a method called rectified linear unit (ReLU). There are also several well-known pooling methods, such as a method called maximum pooling. For example, ResNet, introduced in Reference A, may be used as the CNN structure. Alternatively, a neural network known as Vision Transformer (ViT), described in Reference B, may be used. However, the configuration of the neural network is not limited to these. The feature vector calculation unit 502 stores information such as the structure and weights of the neural network in the memory unit 213 or the like. Document A: K. He, X. Zhang, S. Ren, and J. Sun, "Identity Mappings in Deep Residual Networks", In ECCV, 2016 Document B: Alexey Dosovitskiy, et al., "An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale", In ICLR, 2021

[0027] The weights of the neural network in the feature vector calculation unit 502 are acquired in advance through learning. For example, eye images of various people are acquired in advance for learning, and learning is performed using a method such as ArcFace shown in Reference C. Note that although a method using a neural network is exemplified as a personal authentication method using eye images, well-known methods such as iris authentication (e.g., Reference D) may also be used. The personal authentication method is not limited to these. Document C: J. Deng, J. Guo, N. Xue, and S. Zafeiriou, "ArcFace: Additive Angular Margin Loss for Deep Face Recognition", In CVPR, 2019 Document D: Patent No. 3307936

[0028] The data storage unit 503 manages the registration information of users who use the camera. Specifically, the feature vector of the eye image of the registered user is linked to the name of the registered user and stored in the memory unit 213. The registered personal information table shown in FIG. 5(b) and the registered feature vector table shown in FIG. 5(c) show an example in which one user is registered. The registered feature vector table records "feature vectors" used by the similarity calculation unit 507. The registered personal information table and the registered feature vector table link the information of the registered user by "person ID." The registered personal information table records "name" information.

[0029] The data registration unit 504 creates data to be registered in the data holding unit 503. A specific user registration process will be described later with reference to FIG.

[0030] The condition setting unit 505 sets the similarity condition. Here, the similarity condition is set as a similarity threshold, which is a threshold for determining whether matching is successful. By setting the similarity threshold lower than the normal threshold, which is the default setting, it is possible to increase the false acceptance rate (the rate at which false matches are successfully matched) and decrease the false rejection rate (the rate at which the true match is unsuccessful). Depending on the shooting conditions, an eye image suitable for matching may not be acquired. In such cases, setting a lower threshold than normal increases the likelihood of successful authentication. For example, when photographing a subject that moves vigorously, such as a person playing sports, an animal, or a vehicle, the camera may be rotated while shooting, making it difficult to acquire an eye image suitable for the shot. Similarly, when photographing from a moving object such as a car, vibration-induced blurring may make it difficult to acquire an eye image suitable for the shot. If the shooting environment is too bright or too dark, the eye image may be overexposed or the dark areas may be crushed. Even if an eye image with appropriate brightness is acquired, the pupil size may change from the time of registration due to the influence of external light, resulting in a low similarity. In such cases, a low similarity threshold is used for matching to reduce the possibility of rejection of the person. Specific conditions for similarity will be described later with reference to FIG.

[0031] The reason setting unit 506 sets the reason for setting the conditions set by the condition setting unit 505. If matching is always performed using a low similarity threshold, matching may succeed even for unrelated persons. In this setting, the reason for setting a low similarity threshold can also be set. Here, the circumstances at the time of shooting described above are set as the reason. Specific reasons for setting similarity conditions will be described later with reference to FIG. 8.

[0032] The sensor information acquisition unit 515 acquires information from the inertial sensor 307, GPS receiver 308, and photometry circuit 302 of the camera at the time of shooting.

[0033] The reason evaluation unit 514 evaluates whether the reason for the similarity condition set by the reason setting unit 506 matches the information acquired by the sensor information acquisition unit 515. For example, when photographing a subject that moves rapidly, the camera's inertial sensor 307 can be used to detect the movement and rotation of the camera. When photographing from a moving object, the camera's inertial sensor 307 or information continuously acquired by the GPS receiving unit 308 can be used to detect the movement of the camera. The brightness of the shooting environment can be detected by the camera's photometry circuit 302. Based on this, it is evaluated whether the reason for the similarity condition matches the sensor information.

[0034] The similarity calculation unit 507 compares the user's feature vector with the feature vectors of people registered in the data storage unit 503, and calculates the similarity between the two feature vectors. Specifically, for example, the cosine similarity between the two feature vectors is calculated. The cosine similarity is closer to 0 if the distance between the feature vectors is large, and closer to 1 if the distance is small. Furthermore, when calculating the similarity, other well-known similarities other than the cosine similarity may be used.

[0035] The user identification unit 508 uses the similarity to perform a process of authenticating whether the user at the time of image capture is a person registered in the data storage unit 503. In this process, the matching is determined to be successful only when the reason for the similarity condition matches the sensor information, and the similarity exceeds a low similarity threshold. On the other hand, when the reason for the similarity condition does not match the sensor information, the matching is determined to be successful when the similarity exceeds a normal similarity threshold. This reduces the chance of successful matching even for a different person. Specific authentication processing will be described later with reference to FIG. 9.

[0036] The execution unit 509 executes processing according to the authentication state determined by the user identification unit 508. The execution unit 509 includes an authentication state management unit 510, an authentication state storage unit 511, and an authentication state display unit 512.

[0037] The authentication status management unit 510 manages the authentication status by the user identification unit 508. The authentication status table shown in FIG. 5(d) is an example of a table that stores the authentication status. The "authentication status" in the authentication status table indicates whether authentication by the user identification unit 508 is being performed, and takes one of the values ​​"authenticated" and "unauthenticated." The "person ID" is the person ID identified by the user identification unit 508. When the authentication status is "unauthenticated," the person ID takes a value indicating an empty value, such as NULL. Specific details of the authentication status table update process will be described later together with the explanation of the authentication process by the user identification unit 508 (FIG. 9). The authentication status table is held in the memory unit 213. The method for holding the authentication status table is not limited to a table structure. For example, a key-value structure may be used. The format of information held in the memory unit 213 is not limited to these.

[0038] When the imaging unit 513 receives a signal indicating that the release button 101 has been pressed by the user, it records the image captured by the imaging element 211 in the memory unit 213 .

[0039] An authentication status storage unit 511 records the authentication status of the authentication status management unit 510 as metadata in association with the image acquired by the imaging unit 513. A method known as C2PA, described in document E, is one method for recording image metadata. Document E:Coalition for Content Provenance and Authenticity (C2PA), "C2PA Specifications", Technical Specifications Version 1.2, 2022

[0040] C2PA is a method of adding metadata indicating the edits made to an image to authenticate the origin, history, and provenance of the image. Therefore, the authentication status may be recorded in accordance with C2PA. However, other methods of recording may also be used. Alternatively, the image file and the metadata file may be recorded separately. Alternatively, the metadata may be managed in a database. The metadata recording method is not limited to these. Specific authentication status storage processing in this embodiment will be described later with reference to FIG. 11(a).

[0041] Authentication status display unit 512 displays the authentication status on the camera based on the authentication status of authentication status management unit 510. For example, when the authentication status is "authenticating", "authenticating" is displayed on display device 214 or the touch panel (operation member 103). Alternatively, the camera may be configured to include an LED lamp (not shown) or the like that is lit when the authentication status is "authenticating".

[0042] <Device Operation> The following describes in order the registration process that is performed prior to the photographing operation in which authentication is performed, the authentication process that is performed during the photographing operation, and the storage process when the photographed image is stored.

[0043] <Registration process> 6 is a flowchart of the registration process of this embodiment. It is assumed that the registration process is performed by the user operating the camera at a time other than when taking a picture. Therefore, this process is executed when the user operates the camera 100 and calls this process from a menu or the like. For example, this process is executed when a menu screen (not shown) is displayed on the touch panel (operation member 103) of the camera 100, and the user operates this screen with the operation members 103 to 105 to select a menu that calls this process.

[0044] In S601, the data registration unit 504 accepts input of personal information of the person to be registered. In this embodiment, input of "name" is accepted. Specifically, a screen for inputting a name (not shown) is displayed on the touch panel (operation member 103), and the user operates the operation members 103 to 105 to input the name. When the user has finished inputting, the user notifies the user that the name input is complete by pressing a completion button or the like displayed on the screen.

[0045] In S602, the data registration unit 504 instructs the user on how to register the eye image. Specifically, instructions are displayed on the touch panel to instruct the user to look into the viewfinder. Also, instructions are displayed to instruct the user to look at the indicator in the viewfinder. In addition, instructions may be displayed to enable the user to capture a desirable eye image, such as not blinking and keeping the eyes wide open.

[0046] Next, in steps S603 to S609, the index 401c shown in Fig. 4(c) is displayed on the display device 214, and a feature vector obtained from an image of the user's eye when looking at the index is stored in the data storage unit 503. The processing will be described in order.

[0047] In S603, the data registration unit 504 displays the indices on the display device 214. Specifically, only the index 401c shown in FIG. 4(c) is displayed, and the other indices are not displayed. Alternatively, all the indices may be displayed, and only the index 401c may be displayed in an emphasized color. Any other display method may be used as long as it conveys to the user that they should look at the index 401c. The display method of the indices is not limited to these.

[0048] In S604, the data registration unit 504 acquires an image of the user's eye when looking through the finder (eyepiece 102) via the eye image acquisition unit 501. The detailed processing will be described with reference to FIG.

[0049] FIG. 7 is a flowchart of the eye image acquisition process (S604).

[0050] In S701, the data registration unit 504 executes gaze detection processing. The gaze detection processing method may be a method described in Literature F or the like. For example, in the gaze detection processing, an eye image (eye image signal; electrical signal of the eye image) is acquired from the eye imaging element 219 via the gaze detection circuit 301. Then, the coordinates of the corneal reflection images of the light sources 216a and 216b and the pupil center observed on the eye image are calculated. Then, from these coordinates, the gaze coordinates on the display device 214 of the user are calculated. Document F: Japanese Patent Application Laid-Open No. 2024-2562

[0051] In S702, the data registration unit 504 determines whether an image suitable for authentication has been acquired. Specifically, this determination is made based on whether the gaze detection process has been successful. If the coordinates of the pupil center or the like cannot be detected in the gaze detection process, the gaze detection process fails. Therefore, if the coordinates of the pupil center or the like cannot be obtained in the process of obtaining those coordinates, it may be determined that an image suitable for authentication has not been acquired.

[0052] In S703, the data registration unit 504 branches the process based on the determination result of S702. If it is determined in S702 that an image suitable for authentication has been acquired, the process proceeds to S704. Otherwise, the process proceeds to S706.

[0053] In S704, the data registration unit 504 cuts out the eye image. Specifically, the eye image is acquired and, using the coordinates of the pupil-centered image, cropped to a certain size so that the pupil-centered image is at the center of the image. Furthermore, an image resized to the input size of the neural network of the feature vector calculation unit 502 is generated. In S705, the data registration unit 504 records, using a flag or the like, that the eye image has been successfully acquired.

[0054] In S706, the data registration unit 504 performs a process of waiting for a predetermined time, such as several hundred milliseconds. It is expected that the obtained eye image will change and gaze detection will be successful. In S707, the data registration unit 504 determines whether or not failures have occurred consecutively. A failure indicates that it has been determined in S703 that a suitable image could not be obtained. If failures have occurred consecutively a predetermined number of times, the process proceeds to S708. Otherwise, the process returns to S701. In S708, the data registration unit 504 records, by using a flag or the like, that the acquisition of the eye image failed.

[0055] In S605, the data registration unit 504 determines whether or not the acquisition of the eye image was successful in S604. Specifically, the success or failure of the acquisition of the eye image is determined based on the flags recorded in S705 and S708. If the acquisition was successful, the process proceeds to S606. Otherwise, the process proceeds to S608.

[0056] In S606, the data registration unit 504 extracts a feature vector from the eye image. Specifically, the feature vector calculation unit 502 extracts a feature vector from the eye image acquired in S704.

[0057] In S607, the data registration unit 504 displays on the display device 214 that the eye image was successfully captured using the displayed index. For example, a message such as "Eye image captured successfully" may be displayed. Alternatively, an icon or the like indicating success may be displayed.

[0058] In S608, the data registration unit 504 displays on the display device 214 that capturing an eye image using the currently displayed index has failed. For example, a message such as "Failed to capture an eye image" may be displayed. Alternatively, an icon or the like indicating the failure may be displayed.

[0059] In S609, the data registration unit 504 saves the obtained information in the registered personal information table and registered feature vector table of the data holding unit 503. Specifically, since the person IDs in the two tables are IDs for associating data between the tables, the same ID value is used in the two tables. Then, the name of the personal information obtained in S601 is added to the registered personal information table shown in FIG. 5(b). The feature vector obtained in S606 is recorded in the registered feature vector table shown in FIG. 5(c).

[0060] In S610, the data registration unit 504 displays a message on the touch panel (operation member 103) or the display device 214 to notify the user that registration has been completed.

[0061] In the above-described registration process, the process does not end unless the acquisition of the eye image is successful in S604. Therefore, it is preferable to configure the process to be interrupted if a predetermined number of failures are observed. However, it is also preferable to add processes for abnormal cases as appropriate.

[0062] <Authentication process> The user sets the similarity threshold to be used in the matching process in advance or when capturing an image. Specifically, if a situation is anticipated in which it will be difficult to obtain an eye image suitable for matching, the user sets the similarity threshold to a "low threshold" lower than the "normal threshold" and sets this situation as the "reason for setting." As described above, setting the "low threshold" increases the false acceptance rate and decreases the true rejection rate, thereby increasing the success rate of matching.

[0063] Fig. 8 is a diagram showing an example of a condition setting screen related to similarity. Fig. 8 is an example of a graphical user interface (GUI) displayed on the display panel of the operation member 103 (touch panel). The user can make a selection by tapping on the displayed menu. This screen corresponds to the condition setting section 505 and the reason setting section 506.

[0064] In the pull-down menu 801, when the "Similarity Threshold" menu is tapped, "Normal Threshold" and "Low Threshold" can be selected. The selected threshold is converted into a predetermined numerical value and stored in the memory unit 213. When "Low Threshold" is selected from the pull-down menu, a "Reason for Setting" menu can be selected to set the reason for setting the similarity threshold low. The items displayed in the "Similarity Threshold" pull-down menu are not limited to those mentioned above, and more similarity thresholds may be available as options.

[0065] In the pull-down menu 802, when the "Reason for Setting" menu is tapped, "Auto," "Photograph a Moving Object," "Photograph While Moving," "Outdoors on a Sunny Day (Bright)," and "Night Scene (Dark)" can be selected. The selected reason for setting is stored in the memory unit 213. The items displayed in the "Reason for Setting" pull-down menu are not limited to those mentioned above, and other reasons for wanting to lower the similarity threshold may be added.

[0066] Furthermore, when making this setting, the user may be authenticated first using a normal similarity threshold, which can prevent people other than the user from setting the similarity threshold too low.

[0067] FIG. 9 is a flowchart of the authentication process of this embodiment. It is assumed that the authentication process is performed when the user looks through the viewfinder during photography. Therefore, this process is initiated by an eyepiece sensor (not shown) mounted on the camera 100 detecting that the user has brought their eye close to the viewfinder (eyepiece 102). The eyepiece sensor is a sensor that detects contact of the skin around the user's eye with the periphery of the eyepiece 102. Alternatively, a sensor that detects the distance between the eyepiece 102 and the user's eye may be used. It can be determined that the user is looking through the viewfinder when the distance is equal to or less than a predetermined value. Alternatively, this process may be initiated when it is detected that the release button 101 has been pressed down to the first stroke. Alternatively, the gaze detection process may be initiated in advance, and the process may be initiated when the gaze detection process is successful.

[0068] In S901, the similarity calculation unit 507 determines whether the user is continuing to take pictures. Whether the user is continuing to take pictures is determined by an eyepiece sensor based on whether the user is keeping their eye close to the viewfinder. Note that whether or not taking pictures is in progress may also be determined by other methods, such as pressing the release button 101 or by line-of-sight detection processing. If taking pictures, the process proceeds to S902. Otherwise, the process proceeds to S915.

[0069] In S902, the similarity calculation unit 507 acquires an eye image when the user looks through the viewfinder (eyepiece 102) via the eye image acquisition unit 501. Specifically, this is the same as the eye image acquisition process (S604) described with reference to Fig. 7, and therefore a description thereof will be omitted. Note that if the gaze detection process has already been started, gaze detection may be skipped in S701, and the result of the gaze detection that has already been started may be used.

[0070] In S903, the similarity calculation unit 507 determines whether or not the acquisition of the eye image was successful in S902. Specifically, the success or failure of the acquisition of the eye image is determined based on the flags recorded in S705 and S708. If the acquisition was successful, the process proceeds to S905. Otherwise, the process proceeds to S904.

[0071] In S904, the similarity calculation unit 507 displays a message that the eye image has not been captured on the display device 214. For example, an icon indicating the failure may be displayed.

[0072] In S905, the similarity calculation unit 507 extracts a feature vector from the eye image via the feature vector calculation unit 502. Specifically, the feature vector calculation unit 502 is used to extract a feature vector from the eye image acquired in S902.

[0073] In S906, the similarity calculation unit 507 obtains the registered feature vector to be used for authentication from the data storage unit 503. Specifically, the similarity calculation unit 507 obtains the feature vector from the registered feature vector table shown in FIG.

[0074] In S907, the user identification unit 508 compares the feature vector to be compared obtained in S905 with the registered feature vector obtained in S906. The detailed processing will be described with reference to FIG.

[0075] FIG. 10 is a flowchart of the matching process (S907) in the first embodiment.

[0076] In S1001, the user identification unit 508 acquires the similarity threshold set in 801 of Fig. 8 from the memory unit 213. In S1002, the user identification unit 508 determines whether or not the "normal threshold" has been designated as the similarity threshold to be used. If the similarity threshold is the "normal threshold", the process proceeds to S1010, and otherwise (if it is the "low threshold") the process proceeds to S1003.

[0077] In S1003, the user identification unit 508 acquires the reason for setting the similarity threshold set in 802 of Fig. 8 from the memory unit 213. In S1004, the user identification unit 508 determines whether the reason for setting the similarity threshold is "automatic." If the reason for setting the similarity threshold is "automatic," the process proceeds to S1005; otherwise, the process proceeds to S1007.

[0078] In S1005, the user identification unit 508 determines whether the shooting mode of the camera 100 is subject to change in the similarity threshold. The shooting mode is an operating mode that specifies shooting operations corresponding to shooting conditions. For example, there are "a mode for when the subject moves a lot," "a mode for when the photographer is moving while shooting," "a mode in a bright shooting environment" (such as outdoors on a sunny day), and "a mode in a dark shooting environment" (such as a night view). The camera may also have "a mode suitable for shooting still people," "a mode suitable for shooting distant views," and so on. The camera automatically sets the appropriate settings for shooting these scenes. The shooting mode can be selected from a menu displayed on the touch panel (operation member 103), and the settings from the previous use are retained when the power is turned on.

[0079] As mentioned above, eye images suitable for matching may not be acquired under conditions such as "large subject movement," "the photographer is moving while taking a photo," "the shooting environment is bright," or "the shooting environment is dark." When a shooting mode corresponding to these conditions is set, the similarity threshold is subject to change and the process proceeds to S1006. Under other conditions, such as "a mode suitable for taking photos of a still person" or "a mode suitable for taking photos of a distant view," eye images suitable for matching can be acquired, and when a shooting mode corresponding to these conditions is set, the similarity threshold is not subject to change and the process proceeds to S1010.

[0080] In S1006, the reason setting unit 506 sets the reason for setting the similarity threshold according to the shooting mode. That is, in the "mode when the subject moves a lot," the setting reason is "shooting a moving object," and in the "mode when the photographer shoots while moving," the setting reason is "shooting while moving." Also, in the "mode when the shooting environment is bright," the setting reason is "outdoors, sunny (bright)," and in the "mode when the shooting environment is dark," the setting reason is "night view (dark)."

[0081] In S1007, the user identification unit 508 acquires sensor information (measured values) for evaluating the reason for setting the similarity threshold via the sensor information acquisition unit 515. That is, if the reason for setting is "photographing a moving object," information from the camera's inertial sensor 307 is acquired. If the reason for setting is "photographing while moving," information continuously acquired by the camera's inertial sensor 307 or the GPS receiving unit 308 is acquired. If the reason is "outdoors on a sunny day (bright)" or "night view (dark)," information from the camera's photometry circuit 302 is acquired.

[0082] In S1008, the user identification unit 508 evaluates, via the reason evaluation unit 514, whether or not the reason for setting the similarity threshold matches the status of the sensor information (measured value) acquired in S1007. That is, if the setting reason is "photographing a moving object," the evaluation is made based on whether or not camera movement or rotation was detected. If the setting reason is "photographing while moving," the evaluation is made based on whether or not camera movement was detected. If the setting reason is "outdoors on a sunny day (bright)" or "night view (dark)," the evaluation is made based on whether or not a photometry result that is brighter or darker than a predetermined value was obtained. If it is evaluated that the reason for setting the similarity threshold matches the sensor information, the process proceeds to S1009, and if it is evaluated that it does not match, the process proceeds to S1010.

[0083] In S1009, the user identification unit 508 uses the "low threshold" acquired in S1001 to compare the feature vector to be compared acquired in S905 with the registered feature vector acquired in S906.

[0084] In S1010, the user identification unit 508 uses the "normal threshold" to compare the feature vector to be compared obtained in S905 with the registered feature vector obtained in S906.

[0085] In S908, the user identification unit 508 determines whether or not authentication has been successful. Specifically, if there is a registered feature vector that exceeds the threshold in S907, it determines that authentication has been successful. If authentication has been successful, the process proceeds to S909. Otherwise, the process proceeds to S913.

[0086] In S909, the user identification unit 508 uses the authentication status management unit 510 to update the authentication status in the authentication status table shown in FIG. 5(d) to "authenticated."

[0087] In S910, the authentication status display unit 512 performs display control to notify the user of successful authentication on the display device 214. For example, an icon indicating successful authentication may be displayed.

[0088] In S911, the similarity calculation unit 507 determines whether the user is continuing to take pictures. The method for determining whether the user is continuing to take pictures is the same as in S901, so the description is omitted. If taking pictures, the process returns to S911; otherwise, the process proceeds to S912.

[0089] In S912 and S913, the authentication status management unit 510 updates the authentication status in the authentication status table shown in FIG. 5(d) to "unauthenticated" and also deletes the person ID.

[0090] In S914, the authentication status display unit 512 displays a message informing the user of the authentication failure on the display device 214. For example, an icon indicating the authentication failure may be displayed.

[0091] In S915, the authentication status display unit 512 updates the display on the display device 214. If image capture is no longer in progress, the display of the authentication status ends.

[0092] <Preservation processing> FIG. 11(a) is a flowchart of the authentication status saving process. This process saves the authentication status along with the image captured by the user. FIG. 11(b) is a diagram explaining the structure of the image file to be saved. This process is executed when the release button 101 is pressed down to the second stroke.

[0093] In S1101, the imaging unit 513 performs imaging. Specifically, imaging processing is performed to convert light received by the imaging element 211 into an electrical signal.

[0094] In S1102, the imaging unit 513 generates image data. Specifically, the image processing such as development processing and encoding processing is performed on the electrical signal obtained by the imaging processing in S1101, and image data 1153 is generated.

[0095] In S1103, the authentication status saving unit 511 generates photographer information 1160 of the photographer who captured the image data 1153. Specifically, the authentication status table managed by the authentication status management unit 510 is acquired. Personal information corresponding to the person ID is acquired from the data holding unit 503. In this embodiment, "name" is acquired. Then, metadata of the name and authentication status included in the photographer information 1160 is generated from the information included in the authentication status table.

[0096] In S1104, the authentication status storage unit 511 executes a hash function on the binary data of the image data 1153 and the photographer information 1160 to generate a hash value 1170.

[0097] In S1105, the authentication status storage unit 511 generates a digital signature 1180. The digital signature 1180 includes information indicating the signature value, the signer, and the date and time of signing. The signature value is generated by encrypting the hash value 1170 generated in S1104 using a private key prepared in advance. The public key that pairs with the private key used here is also stored in the digital signature 1180. In this embodiment, information indicating the manufacturer of the camera 100 is stored as the signer. Note that the model of the camera 100 may be used as the signer instead of the manufacturer. Furthermore, the date and time when the generation of the digital signature is completed is stored as the date and time of signing.

[0098] In S1106, the authentication status saving unit 511 assigns the photographer information 1160, hash value 1170, and digital signature 1180 to the image data 1153 as metadata 1151, and generates an image file 1150. Here, if the image data 1153 is a still image, the image file is generated in JPEG format, and if it is a moving image, the image file is generated in MPEG format.

[0099] In S1107, the authentication status saving unit 511 stores the image file 1150 in the memory unit 213. Note that the memory unit may also include a storage medium that is detachable from the camera 100, and the image file may be stored in the storage medium.

[0100] You can confirm that a file has not been tampered with by using the following verification method. First, the hash value is restored from the signature value using the public key. Next, the hash values ​​of the image data and photographer information are calculated again. If the restored hash value matches the newly calculated hash value, it can be determined that the file has not been tampered with. If they do not match, it can be determined that the file has been tampered with.

[0101] This is because, even if someone were to tamper with the image data, the person who tampered with the data would not be able to change the signature value because it is encrypted with a private key. Therefore, if the image data has been tampered with, the hash value calculated from the image data will not match the restored hash value. This makes it possible to detect data tampering.

[0102] In the above description, the hash value is also included and stored in the image file. However, the hash value is not necessary for the above verification itself. Therefore, the hash value may not be included in the image file.

[0103] In the case of a video, video shooting begins when the release button 101 is pressed down to the second stroke, and video shooting is completed when it is pressed down to the second stroke again. Then, video data is generated by steps S1101 to S1102. Then, a hash value of the video data is calculated, converted into a hash value of image data and saved, and the video data and metadata are combined and saved as a video file.

[0104] As described above, according to the first embodiment, when a situation in which it is difficult to acquire an eye image suitable for matching is predicted, the similarity threshold is set to a "low threshold" and the situation is set as the "reason for setting." During matching, if the "low threshold" is set, it is confirmed whether the situation matches the situation set in the "reason for setting." If they match, matching is performed using the "low threshold." If they do not match, matching is performed using the "normal threshold." This makes it possible to perform matching using the "low threshold" when the acquired eye image was acquired in the situation set in the "reason for setting," thereby increasing the success rate of matching. On the other hand, if the acquired eye image was not acquired in the situation set in the "reason for setting" (when the situation is such that an eye image suitable for matching can be acquired), matching is performed using the "normal threshold." This makes it possible to prevent excessive false acceptance during authentication.

[0105] (Variation) In the above embodiment, "name" is used as the personal information managed by the data storage unit 503. However, information other than name may be used. For example, in the case of a camera used within a company, an "employee number" assigned to an employee may be stored. Alternatively, account information such as an account name for another web service may be entered. In this case, when the web service is accessed and login is successful, this information may be used as personal information. Furthermore, a token may be issued from the web service upon successful access, and this token may also be stored as personal information. Furthermore, this personal information may be stored as image metadata in the authentication status storage unit 511. The personal information used by the data storage unit 503 and the authentication status storage unit 511 is not limited to these.

[0106] In the above embodiment, the number of registered users is one. However, multiple users may be registered. In this case, each time the registration process is initiated, registration information (personal information and feature vector) for a different person ID is registered in the data storage unit 503. Of course, a process for preventing registration by the same person may be added. For example, if the same name is found, a message indicating that the person has already been registered may be displayed and the process may end. Then, during the authentication process, a determination is made as to which person ID the user will use. At this time, if there are multiple person IDs that exceed a predetermined threshold, the most similar person ID may be authenticated. Alternatively, the authentication may be terminated as a failure. Furthermore, instead of using only whether the threshold is exceeded, whether the difference between the first and second similarities exceeds a predetermined threshold may also be used as a basis for determining authentication. In this case, the threshold for the difference between the first and second similarities may be changed as well as the similarity threshold as a similarity condition.

[0107] In the above-described embodiment, during the authentication process (FIG. 9), the authentication status display unit 512 displays the authentication result on the display device 214 (S910, S914, S915). However, when capturing an image, the image captured by the image sensor 211 is already displayed on the display device 214. Therefore, it is considered that the user wants to concentrate on capturing an image. Therefore, it is preferable to display the result so as not to interfere with the capturing of an image. Therefore, the authentication status display unit 512 may be modified as follows. For example, a display indicating success or failure may be displayed on the edge of the screen of the display device 214. Alternatively, since the user's gaze position on the display device 214 is obtained by the gaze detection process, the display may be determined based on the gaze position. For example, the display may be located far from the gaze position. However, since it is difficult to understand if the display position changes frequently, the display position may be determined in advance, such as near the four corners, and the display position may be determined based on the gaze position. In other words, an icon or the like may be displayed in a predetermined position that is farthest from the gaze position. Note that the method of displaying success or failure is not limited to these. The display in S904 may be omitted, in which case S904 may be omitted.

[0108] In the above-described embodiment, personal authentication is performed using an eye image. However, other authentication methods may be used. For example, other biometric authentication methods such as face authentication, fingerprint authentication, and voice authentication may be used. In the case of face authentication, a face-capturing camera is installed on the back of the camera 100 to capture an image of the photographer's face. For example, a face authentication camera may be installed above the touch panel (operation member 103) to perform authentication when the photographer looks into the touch panel. The camera then captures the photographer's face for authentication. Alternatively, in the case of fingerprint authentication, a fingerprint sensor may be installed on the release button 101, and fingerprint authentication may be performed when a finger is placed on the release button. Alternatively, voice authentication may be performed, and a microphone may be installed on the camera to perform voice authentication using voiceprints, etc.

[0109] In the above-described embodiment, authentication processing is performed when capturing an image. However, performing authentication when capturing an image may be difficult due to resource constraints such as speed. In such cases, information required for authentication may be saved when capturing an image, and authentication processing may be performed after capturing an image. For example, eye images may be saved when capturing an image, and authentication may be performed after capturing an image. Similarly, other biometric authentication (face authentication, fingerprint authentication) may also be performed by saving biometric information (face, fingerprint), etc. In this way, authentication does not necessarily have to be performed when capturing an image. Information required for authentication may be acquired when capturing an image, and authentication may be performed after capturing an image.

[0110] If authentication is performed later, it is possible that the authentication result will not be available in time for saving the image file. In this case, an authentication status other than "in progress" or "not authenticated" such as "processing" may be prepared and saved as metadata. Then, when the authentication result is obtained, the metadata may be corrected and saved again.

[0111] (Second embodiment) In the second embodiment, a form in which similarity conditions are automatically set according to the shooting mode will be described. Specifically, a form in which manual setting by the user is not required, as in the condition setting screen (FIG. 8) in the first embodiment, will be described. Note that the device configuration and processing other than the matching processing are the same as in the first embodiment, and therefore will not be described here.

[0112] <Authentication process> The authentication process in the second embodiment is similar to that in the first embodiment (FIG. 9), but the details of the matching process (S907) differ from those in the first embodiment.

[0113] 12 is a flowchart of the matching process (S907) in the second embodiment. In the first embodiment, the similarity threshold and the setting reason are manually set in advance, but in the second embodiment, they are not set in advance and are therefore set in this flow.

[0114] In S1005, the user identification unit 508 determines whether the shooting mode of the camera 100 is subject to change of the similarity threshold, as in the first embodiment. If the shooting mode is subject to change of the similarity threshold, the process proceeds to S1201, and if not, the process proceeds to S1010.

[0115] In S1201, the reason setting unit 506 automatically sets the similarity threshold and the setting reason according to the shooting mode in accordance with a table prepared in advance. In S1007 to S1010, the same processes as in the first embodiment are performed.

[0116] 13 is a diagram showing an example of a table of shooting modes and corresponding settings (similarity threshold, setting reason). This table is stored in the memory unit 213 at the time of factory shipment. A configuration may also be adopted in which a user stores a created / modified table in the memory unit 213.

[0117] As described above, according to the second embodiment, the similarity condition is automatically set according to the shooting mode. This makes it possible to perform matching using a "low threshold" when an eye image suitable for matching is acquired in a situation where it is not possible to acquire an eye image, thereby increasing the success rate of matching. It also makes it possible to prevent excessive acceptance of false images during authentication.

[0118] (Third embodiment) In the third embodiment, a form in which similarity conditions are automatically set according to sensor information will be described. As in the second embodiment, another form that does not require manual setting by the user, such as a condition setting screen (FIG. 8), will be described. Note that the device configuration and processing other than the matching processing are the same as in the first embodiment, so description thereof will be omitted.

[0119] <Authentication process> The authentication process in the third embodiment is similar to that in the first embodiment (FIG. 9), but the details of the matching process (S907) differ from those in the first embodiment.

[0120] 14 is a flowchart of the matching process (S907) in the third embodiment. In the first embodiment, the similarity threshold and the setting reason were manually set in advance, but in the third embodiment, they are not set in advance and are therefore set in this flow. Note that the setting reason for the similarity condition is not necessary in the third embodiment.

[0121] In S1007, the user identification unit 508 acquires sensor information via the sensor information acquisition unit 515. That is, information on at least one of the inertial sensor 307, the GPS receiving unit 308, and the photometry circuit 302 of the camera is acquired.

[0122] In S1401, the reason evaluation unit 514 evaluates whether the sensor information is a change target for the similarity threshold. For example, if information is acquired from the camera's inertial sensor 307 and camera movement or rotation is detected, it is estimated that "photographing a moving object" has been taken and is evaluated as a change target. Furthermore, if information is continuously acquired from the camera's inertial sensor 307 or the GPS receiver 308 and camera movement is detected, it is estimated that "photographing while moving" has been taken and is evaluated as a change target. Furthermore, information is acquired from the camera's photometry circuit 302, and if a photometry result that is brighter or darker than a predetermined value is obtained, it is estimated that the photometry was taken under "outdoor sunny weather (bright)" or "night scene (dark)" and is evaluated as a change target. Otherwise, it is evaluated as not a change target. If it is evaluated as not a change target, proceed to S1402; if it is evaluated as not a change target, proceed to S1010.

[0123] In S1402, the user identification unit 508 sets a threshold value according to the sensor information as a similarity threshold value, and compares the feature vector to be compared obtained in S905 with the registered feature vector obtained in S906.

[0124] As described above, according to the third embodiment, the similarity condition is automatically set according to the sensor information. This makes it possible to perform matching with a "low threshold" when an eye image suitable for matching is acquired in a situation where it is not possible to acquire an eye image, thereby increasing the success rate of matching. Furthermore, it is possible to prevent excessive acceptance of false persons during authentication.

[0125] The disclosure of this specification includes the following authentication device, control method, and program. (Item 1) An authentication device that authenticates a user of a predetermined device using biometric authentication, a storage means for storing a first feature amount of a predetermined person used in the biometric authentication; an acquisition means for acquiring biometric information of the user; an authentication means for authenticating the user as the predetermined person when a similarity between a second feature amount derived from the biometric information and the first feature amount exceeds a threshold value; Equipped with the authentication means performs authentication using a first threshold value as the threshold value when a predetermined condition is not satisfied, and performs authentication using a second threshold value lower than the first threshold value as the threshold value when the predetermined condition is satisfied; The predetermined condition is associated with the second threshold value. An authentication device characterized by: (Item 2) The device further includes a receiving unit for receiving settings of the second threshold value and the predetermined condition associated with the second threshold value. 2. The authentication device according to item 1, (Item 3) The authentication means determines whether the predetermined condition is satisfied when it is specified to use the second threshold as the threshold. 3. The authentication device according to item 2. (Item 4) the biometric authentication is authentication based on an eye image, the predetermined device is an imaging device having a finder, The acquisition means acquires, as the biometric information, an image of the user's eye acquired by an imaging unit provided in the finder. 4. The authentication device according to any one of items 1 to 3, (Item 5) the imaging device has a plurality of imaging modes, each of which performs an imaging operation corresponding to an imaging condition; The authentication device further includes a setting unit that sets the second threshold value and the predetermined condition according to a photographing mode used by the imaging device. 5. The authentication device according to item 4, (Item 6) the imaging device includes a sensor for measuring at least one of illuminance, acceleration, angular velocity, and geographic position; The authentication means determines whether the predetermined condition is met based on the measurement value obtained by the sensor. 6. An authentication device according to item 5, characterized in that: (Item 7) the imaging device includes a sensor for measuring at least one of illuminance, acceleration, angular velocity, and geographic position; The authentication means further includes setting means for setting the second threshold value based on the measurement value obtained by the sensor. 5. The authentication device according to item 4, (Item 8) a generating unit that generates, when the authentication unit has authenticated the user as the predetermined person, an image file that associates the image captured by the imaging device with information that identifies the predetermined person; 8. The authentication device according to any one of items 4 to 7, wherein: (Item 9) The apparatus further includes a display control means for displaying the authentication result by the authentication means in the finder. 9. The authentication device according to any one of items 4 to 8, wherein: (Item 10) A control method for an authentication device that authenticates a user of a predetermined device using biometric authentication, comprising: a first acquisition step of acquiring a first feature amount of a predetermined person to be used in the biometric authentication; a second acquisition step of acquiring biometric information of the user; an authentication step of authenticating the user as the predetermined person when a similarity between a second feature amount derived from the biometric information and the first feature amount exceeds a threshold; Including, In the authentication step, when a predetermined condition is not satisfied, authentication is performed using a first threshold value as the threshold value, and when the predetermined condition is satisfied, authentication is performed using a second threshold value lower than the first threshold value as the threshold value; The predetermined condition is associated with the second threshold value. A control method comprising: (Item 11) Item 11. A program for causing a computer to execute the control method according to Item 10.

[0126] (Other Examples) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.

[0127] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]

[0128] 501 Eye image acquisition unit; 502 Feature vector calculation unit; 503 Data storage unit; 504 Data registration unit; 505 Condition setting unit; 506 Reason setting unit; 507 Similarity calculation unit; 508 User identification unit; 509 Execution unit; 510 Authentication status management unit; 511 Authentication status storage unit; 512 Authentication status display unit; 513 Imaging unit; 514 Reason evaluation unit; 515 Sensor information acquisition unit

Claims

1. An authentication device that authenticates a user of a predetermined device using biometric authentication, a storage means for storing a first feature amount of a predetermined person used in the biometric authentication; an acquisition means for acquiring biometric information of the user; an authentication means for authenticating the user as the predetermined person when a similarity between a second feature amount derived from the biometric information and the first feature amount exceeds a threshold value; Equipped with the authentication means performs authentication using a first threshold value as the threshold value when a predetermined condition is not satisfied, and performs authentication using a second threshold value lower than the first threshold value as the threshold value when the predetermined condition is satisfied, The predetermined condition is associated with the second threshold value. An authentication device characterized by:

2. The apparatus further includes a receiving unit for receiving settings of the second threshold value and the predetermined condition associated with the second threshold value.

2. The authentication device according to claim 1.

3. The authentication means determines whether the predetermined condition is satisfied when it is specified to use the second threshold as the threshold.

3. The authentication device according to claim 2.

4. the biometric authentication is authentication based on an eye image, the predetermined device is an imaging device having a finder, The acquisition means acquires, as the biometric information, an image of the user's eye acquired by an imaging unit provided in the finder.

2. The authentication device according to claim 1.

5. the imaging device has a plurality of imaging modes, each of which performs an imaging operation corresponding to an imaging condition; The authentication device further includes a setting unit that sets the second threshold value and the predetermined condition according to a photographing mode used by the imaging device.

5. The authentication device according to claim 4.

6. the imaging device includes a sensor for measuring at least one of illuminance, acceleration, angular velocity, and geographic position; The authentication means determines whether the predetermined condition is met based on the measurement value obtained by the sensor.

6. The authentication device according to claim 5.

7. the imaging device includes a sensor for measuring at least one of illuminance, acceleration, angular velocity, and geographic position; The authentication means further includes setting means for setting the second threshold value based on the measurement value obtained by the sensor.

5. The authentication device according to claim 4.

8. a generating unit that generates, when the authentication unit has authenticated the user as the predetermined person, an image file that associates the image captured by the imaging device with information that identifies the predetermined person; 5. The authentication device according to claim 4.

9. The apparatus further includes a display control means for displaying the authentication result by the authentication means in the finder.

5. The authentication device according to claim 4.

10. A control method for an authentication device that authenticates a user of a predetermined device using biometric authentication, comprising: a first acquisition step of acquiring a first feature amount of a predetermined person to be used in the biometric authentication; a second acquisition step of acquiring biometric information of the user; an authentication step of authenticating the user as the predetermined person when a similarity between a second feature amount derived from the biometric information and the first feature amount exceeds a threshold; Including, In the authentication step, when a predetermined condition is not satisfied, authentication is performed using a first threshold value as the threshold value, and when the predetermined condition is satisfied, authentication is performed using a second threshold value lower than the first threshold value as the threshold value; The predetermined condition is associated with the second threshold value. A control method comprising:

11. A program for causing a computer to execute the control method according to claim 10.

Citation Information

Patent Citations

  • Identification device

    JP2024002562A