Biometric authentication device, method for controlling the biometric authentication device, and program
The biometric authentication device adjusts authentication thresholds based on contextual factors to enhance security and reduce false acceptance, addressing vulnerabilities in biometric systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- CANON KK
- Filing Date
- 2024-10-16
- Publication Date
- 2026-04-28
AI Technical Summary
Biometric authentication systems are vulnerable to external changes such as injuries, disguises, and changes in lighting conditions, leading to increased costs and risks of false acceptance or unauthorized access.
A biometric authentication device that includes an information acquisition unit, biometric authentication unit, context acquisition unit, impersonation determination unit, and threshold adjustment unit to dynamically adjust authentication thresholds based on contextual factors.
Maintains convenience while suppressing increases in costs and acceptance by falsehoods, ensuring secure and reliable authentication.
Smart Images

Figure 2026070771000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a biometric authentication device, a control method for the biometric authentication device, and a program.
Background Art
[0002] In recent years, the use of biometric authentication that performs personal authentication using biometric information such as the face and fingerprint has been spreading. Biometric information is information that represents the unique physical characteristics of an individual, and biometric authentication using this information has the characteristic of high convenience because it does not require the memorization or input of passwords or the carrying of IC cards, etc. In addition, biometric information has a low risk of forgetting, leakage, or loss, and is also highly secure compared to authentication methods using passwords or IC cards.
[0003] On the other hand, biometric authentication is vulnerable to external changes such as injuries, disguises, and changes in lighting conditions. For example, if the eyes are injured and it becomes impossible to remove the eye bandage, it becomes difficult to break through authentication using the face or iris. In addition, spoof detection (technology for determining whether the user is a living body), which is often incorporated as a countermeasure against spoofing behavior that has been a concern in recent years, may not function correctly if the exposed parts of the living body are reduced by an eye bandage or mask. Spoofing behavior refers to, for example, an unauthorized user attempting to break through authentication by pretending to be an authorized user.
[0004] Regarding this problem, in Patent Document 1, a method is proposed that, in addition to biometric authentication, has an authentication method using an identification code and permits authentication with restrictions by the identification code when it is difficult to use biometric information. In addition, in Patent Document 2, a method is proposed that correctly performs authentication even if there are changes in the appearance of the user by changing the threshold value for authentication.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Patent Document 2
[0006] However, Patent Document 1 requires the preparation of authentication methods other than biometric authentication and the necessary equipment, resulting in high implementation costs. Furthermore, if biometric authentication is not used, authentication must be performed by another means, and even if authentication is successful, it is restricted, making it inconvenient. Patent Document 2 changes the threshold of the authentication itself, which carries the risk of unintentionally authenticating a user as another legitimate user (false acceptance).
[0007] This invention was made to solve these problems and aims to provide a biometric authentication device that maintains convenience while suppressing increases in costs and acceptance by falsehoods. [Means for solving the problem]
[0008] To achieve the above objective, a biometric authentication device as one aspect of the present invention is characterized by comprising: an information acquisition unit that acquires biometric information of a person to be authenticated; a biometric authentication unit that performs biometric authentication using the biometric information; a context acquisition unit that acquires context other than the biometric information; an impersonation determination unit that determines whether the person is engaging in impersonation based on a threshold; and an adjustment unit that adjusts the threshold based on the context from which the threshold was acquired. [Effects of the Invention]
[0009] According to the present invention, it is possible to provide a biometric authentication device that maintains convenience while suppressing increases in costs and acceptance by unintended parties. [Brief explanation of the drawing]
[0010] [Figure 1] This figure shows an example of the hardware configuration of the present invention. [Figure 2] This figure shows the assumed usage scenario for Embodiment 1. [Figure 3] This is a functional configuration diagram of the biometric authentication device according to Embodiment 1. [Figure 4] This is a flowchart showing the processing procedure for Embodiment 1. [Figure 5] This is a functional configuration diagram of the biometric authentication device according to Embodiment 2. [Figure 6] This is a flowchart showing the processing procedure for Embodiment 2. [Figure 7] This figure shows an example of the functional configuration of the biometric authentication device according to Embodiment 3. [Modes for carrying out the invention]
[0011] Embodiments for carrying out the present invention will be described in detail with reference to the accompanying drawings. Note that the configurations shown in the following embodiments are merely examples, and the present invention is not limited to the illustrated configurations. In each figure, the same or corresponding parts are denoted by the same reference numerals. Repetitive explanations of such parts will be simplified or omitted as appropriate.
[0012] Figure 1 shows an example of the hardware configuration of the biometric authentication device 100 common to each embodiment. As shown in Figure 1, the biometric authentication device 100 of this embodiment includes an information processing device 101, an input device 102, an output device 103, a network 104, a sensor 105, and an access control device 106.
[0013] The information processing device 101 includes a CPU 101a, RAM 101b, ROM 101c, external storage device 101d, input interface 101e, output interface 101f, and communication interface 101g. Each of these components is connected to each other via a system bus 101h so as to be able to communicate with one another.
[0014] The CPU (Central Processing Unit) 101a is a processor (central processing unit) that comprehensively controls the entire information processing device 101. The CPU 101a controls the information processing device 101 by executing control programs stored in the ROM (Random Access Memory) 11 and RAM (Read Only Memory) 12.
[0015] The RAM (Random Access Memory) 101b temporarily stores data supplied from external devices such as the external storage device 101d, the input I / F 101e, and the communication I / F 101g, and functions as the main memory, work area, etc. of the CPU 101a. The ROM (Read Only Memory) 101c stores control programs and the like executed by the CPU 101a. The external storage device 101d is a storage device such as a hard disk or a memory card fixedly installed in the information processing device 101. Note that the external storage device 101d may include a removable flexible disk (FD), an optical disk such as a compact disk (CD), a magnetic or optical card, an IC card, a memory card, etc. from the information processing device 101.
[0016] The input I / F 101e is an interface between the information processing device 101 and the input device 102. The output I / F 101f is an interface between the information processing device 101 and the output device 103. The communication I / F 101g is an interface between the information processing device 101 and an external device connected to the network 104.
[0017] The input device 102 is a device such as a pointing device or a keyboard that receives the user's operation and inputs data. The output device 103 is a device such as a display for displaying the data held by the information processing device 101 and the processing results of programs.
[0018] The sensor 105 is a sensor device capable of acquiring biometric information such as a network camera, an IR camera, a fingerprint reader, a microphone, an illuminometer, a wind speed meter, a temperature and humidity meter, etc. that captures RGB images, and context around the biometric authentication device 100. Here, the context refers to environmental information, spatio-temporal information around the biometric authentication device 100 other than biometric information, appearance information and monitoring information of the user that serve as clues for personal identification. Note that the sensor 105 is not limited to one, and a plurality of sensors may be combined and used according to the application.
[0019] The entrance / exit management device 106 is a series of devices composed of a control device or the like that controls gates through which an authenticated user passes at the time of entry / exit and their opening and closing. The entrance / exit management device 106 may, for example, have a configuration in which a plurality of gates are associated with one control device and these gates are interlocked when opening and closing.
[0020] The sensor 105 and the entrance / exit management device 106 have a communication function and mutually transmit and receive data with the information processing device 101 via the network 104. Incidentally, the CPU 101a stores the data obtained here in the RAM 101b or the like. The CPU 101a uses these data and the control program stored in the RAM 101b or the like to realize the functions and processes of the biometric authentication device 100 in each of the embodiments described later.
[0021] <Embodiment 1> FIG. 2 is a diagram showing an example of a usage scene in Embodiment 1. In FIG. 2, a device 201 in which a network camera corresponding to the sensor 105 and a display corresponding to the output device 103 are integrated is installed in an open space such as the entrance of a training gym or the lobby of a hotel. Also, a device 202 that controls entry by opening and closing a flap corresponding to the entrance / exit management device 106 is installed. And there are other facility users 204, 205, 206 and a facility manager 207 around the facility user 203 who uses the device 201 and the device 202. In Embodiment 1, such a situation is assumed as an example.
[0022] In such a situation, it is often the case that among other facility users 204, 205, 206 and the facility manager 207, there are people the facility user 203 remembers. Also, because it is an open space, if the facility user 203 behaves suspiciously, it will stand out from the surroundings. In this embodiment, paying attention to the fact that it is extremely difficult to perform an impersonation act in such a situation, a method of suppressing an increase in cost and acceptance of others while maintaining the convenience of biometric authentication will be described below.
[0023] Figure 3 is a functional configuration diagram (functional block diagram) of the biometric authentication device 100 in Embodiment 1. In this embodiment, the biometric authentication device 100 has as its functional units a biometric information acquisition unit 301, a storage unit 302, a matching unit 303, a context acquisition unit 304, a threshold adjustment unit 305, a spoofing detection unit 306, and an access control unit 307.
[0024] The biometric information acquisition unit 301 acquires biometric information of the person (user) to be authenticated. In this embodiment, the biometric information is acquired as the person's face information, which includes the user's face image obtained via the network camera sensor 105 and the corresponding feature quantities. The biometric information acquisition unit 301 outputs the biometric information to the matching unit 303.
[0025] The memory unit 302 stores the facial images of multiple regular users and their corresponding feature quantities as registered information. The registered information stored in the memory unit 302 is assumed to have been acquired in advance using the same procedure as the biometric information acquired by the biometric information acquisition unit 301.
[0026] The matching unit 303 performs biometric authentication of the person to be authenticated based on the biometric information acquired by the biometric information acquisition unit 301. Specifically, the matching unit 303 compares the biometric information acquired by the biometric information acquisition unit 301 with the registered information stored in the storage unit 302 to determine whether the user is a legitimate user or not, thereby performing biometric authentication of the person to be authenticated. In other words, the matching unit 303 also functions as a biometric authentication unit that determines whether authentication is possible or not by comparing the biometric information of the person to be authenticated with the registered information previously stored in the storage unit 302 and verifying whether the person to be authenticated is a legitimate user or not. The matching unit 303 outputs the matching result to the entry / exit processing unit 307.
[0027] The context acquisition unit 304 acquires the surrounding context other than the biological information acquired by the biological information acquisition unit 301 via the sensor 105. The context acquisition unit 304 outputs the acquired context to the threshold adjustment unit 305.
[0028] The threshold adjustment unit 305 adjusts the threshold used for impersonation detection according to the context acquired by the context acquisition unit 304. The threshold adjustment unit 305 outputs the adjusted threshold to the impersonation detection unit 306.
[0029] The impersonation detection unit 306 uses the biometric information acquired by the biometric information acquisition unit 301 and the threshold adjusted by the threshold adjustment unit 305 to detect impersonation. In other words, the impersonation detection unit 306 determines whether the person to be authenticated is engaging in impersonation based on the biometric information acquired by the biometric information acquisition unit 301 and the threshold adjusted by the threshold adjustment unit 305.
[0030] In biometric authentication using facial recognition, impersonation often involves holding a printed face or a display showing a face up to the user's face, making it crucial to distinguish between biological and non-biological information. Therefore, in this embodiment, the likelihood of biological information being biological, i.e., the biolikelihood, is calculated. Specifically, the impersonation detection unit 306 acquires the biological information acquired by the biological information acquisition unit 301 and calculates the likelihood of biological information being biological. If the calculated biolikelihood exceeds a threshold, it is determined that the biological information is highly likely to be of biological origin and is not an impersonation attempt; otherwise, it is determined that the biological information is highly likely to be of non-biological origin and is an impersonation attempt. After calculating the biolikelihood, the impersonation detection unit 306 outputs the biolikelihood information to the entry / exit processing unit 307. Note that the calculation of the biolikelihood may be performed by a functional unit other than the impersonation detection unit 306. Alternatively, for example, a biolikelihood calculation unit may be provided to perform the calculation of the biolikelihood.
[0031] The access control unit (access control unit) 307 processes the user's access using the verification result from the verification unit 303 if the impersonation detection unit 306 does not detect any impersonation (i.e., it determines that no impersonation has occurred). In other words, the access control unit 307 controls the user's access based on the determination result from the impersonation detection unit 306 and the verification result (authentication result) from the verification unit 303. If the verification result determines that the user is a legitimate user (authentication successful), the access control unit 307 opens the gate of the access control device 106. On the other hand, if the verification result determines that the user is not a legitimate user (authentication failed), the access control device 106 closes the gate (does not open the gate).
[0032] Figure 4 is a flowchart showing an example of the processing procedure of the information processing device 101 of the biometric authentication device 100 in Embodiment 1. The processing performed by the information processing device 101 in Embodiment 1 will be described below with reference to Figure 4. Each operation (process) shown in the flowchart of Figure 4 is controlled by the CPU 101a of the information processing device 101 executing a program. Furthermore, the notation of each process (step) is omitted by prefixing it with "S". Here, the processing in Figure 4 begins when the sensor 105 is able to acquire a sufficient image of the user's face.
[0033] In S401, the biometric information acquisition unit 301 acquires the facial image of the user, who is the person to be authenticated, obtained via the network camera sensor 105, and features extracted from the acquired facial image as biometric information. In other words, the biometric information acquisition unit 301 acquires the biometric information of the person to be authenticated in the biometric authentication described later.
[0034] Regarding the method for acquiring face images, in this embodiment, face images are acquired by performing facial feature point detection on images obtained via a network camera and then performing a normalization process to extract only the face region based on that information. Any known method may be used for the normalization process; for example, a method may be used in which face frame detection is performed on the image and the face region is extracted based on that information to acquire face images. Regarding the method for extracting features from face images, in this embodiment, features are extracted using a neural network that has been pre-trained so that features that are close to the same person are extracted, and features that are far apart from the same person are extracted, using the face image as input. The use of a neural network here is merely an example, and features may be extracted using other machine learning methods. For example, linear dimensionality reduction methods such as principal component analysis (PCA) and linear discriminant analysis (LDA), nonlinear dimensionality reduction methods such as kernel PCA, and clustering methods such as k-means may be used, and the method is not limited to a specific form. The registration information stored in the memory unit 302 used in the later stage is also assumed to be a set of face images and their corresponding features acquired by the same procedure as described above.
[0035] In S402, the context acquisition unit 304 acquires the surrounding context other than the biometric information acquired by the biometric information acquisition unit 301 in S401. In S402, the context acquisition unit 304 acquires monitoring information around the biometric authentication device 100 (around the biometric authentication device) as context. Here, the monitoring information in this embodiment is a combination of, for example, the number of people who used the biometric authentication device 100 within a certain period, the number of people around the biometric authentication device 100, and the number of people other than facility user 203 looking at the biometric authentication device 100 or facility user 203. When the combined number is large, it is considered that there is a high possibility of being monitored, and when the combined number is small, it is considered that there is a low possibility of being monitored. Note that the information to be included in the above monitoring information is just an example, and other information may be included. For example, information on the amount of time spent looking at the biometric authentication device 100 or facility user 203 may be included. In this case, the longer the time spent looking at facility user 203, the more the number may be converted to a number corresponding to that time and combined with the above. Furthermore, when the context acquisition unit 304 aggregates these numbers, it may weight the number of people or figures to be considered, depending on the situation.
[0036] Furthermore, when acquiring the above monitoring information as context, the sensor 105, which is a network camera used for acquiring biometric information in S401, is used. This makes it easy to acquire monitoring information, so it is not necessary to use an additional sensor to acquire the context.
[0037] In S403, the verification unit 303 compares the biometric information acquired by the biometric information acquisition unit 301 in S401 with the registration information stored in the storage unit 302 to determine whether the user is a legitimate user or not.
[0038] In this embodiment, the similarity (cosine similarity) between the user and each registered regular user is calculated by normalizing the features of the biometric information and registration information and taking their dot product. Among the pairs whose similarity exceeds a predetermined threshold, the one with the highest value is designated as the regular user corresponding to the user. If no pair has a similarity exceeding the threshold, it is assumed that there is no regular user corresponding to the user. Here, cosine similarity obtained by comparing features is used as the similarity, but other comparison methods may be used. For example, methods that do not use features, such as pattern matching or frequency analysis, or distance-based methods such as Euclidean distance or Manhattan distance may be used, and the method is not limited to a specific form.
[0039] In S404, the threshold adjustment unit 305 adjusts the impersonation detection threshold according to the context acquired by the context acquisition unit 304 in S402. In this embodiment, the threshold adjustment unit 305 adjusts the threshold to be lower than a predetermined standard value (standard threshold) when there is a high probability that the user is being monitored by another user, based on the monitoring information around the biometric authentication device 100. Conversely, when there is a low probability of being monitored and impersonation is easy, the threshold is adjusted to be higher than the standard value. This threshold adjustment is performed steplessly using a neural network that has been trained to output an appropriate threshold in accordance with the above, taking the monitoring information as input. However, this is just one example, and other machine learning methods may be used, similar to feature extraction in S401.
[0040] In S405, the impersonation detection unit 306 calculates the biolikelihood, which is the likelihood of the biolikeness of the biometric information acquired by the biometric information acquisition unit 301 in S401. In this embodiment, a neural network pre-trained to take an image as input and output a larger value the higher the biolikelihood, and a smaller value the lower the biolikelihood, is used to calculate this biolikelihood. However, this is merely an example, and other machine learning methods may be used, similar to feature extraction in S401.
[0041] In S406, the impersonation detection unit 306 determines whether the biolikelihood calculated in S405 exceeds the threshold adjusted by the threshold adjustment unit 305 in S404 (adjusted threshold). If the biolikelihood exceeds the adjusted threshold, the threshold adjustment unit 305 determines that the biometric information acquired by the biometric information acquisition unit 301 in S401 is not due to impersonation and proceeds to S407. On the other hand, if the biolikelihood does not exceed the adjusted threshold, it determines that the biometric information is due to impersonation and terminates the process. In other words, in this case, it is determined that the user is engaging in impersonation, and the entry / exit process for the person to be authenticated is not performed (the gate is closed or the gate is sealed).
[0042] In S407, the access control unit 307 performs access control for the user based on the verification result obtained by the verification unit 303 in S403. After that, the process ends. Here, access control refers to the process of opening and closing the flap of the device 202. Specifically, based on the verification result of the verification unit 303, the access control unit 307 opens the flap of the device 202 (or maintains the open state if it is already open) if the user is one of the regular users. On the other hand, if there is no regular user corresponding to the user, the flap of the device 202 is closed (or maintains the closed state if it is already closed).
[0043] The above describes the processing procedure of the information processing device 101 of the biometric authentication device 100 in this embodiment. By performing the above processing, if a user is unable to use their original biometric information due to injury or other reasons, they can bypass authentication using only the biometric authentication device by "impersonating themselves" by holding up a photo of themselves stored on a mobile device such as a smartphone. Therefore, it is possible to suppress cost increases while maintaining convenience. In addition, since the biometric authentication device 100 in this embodiment does not adjust the threshold for matching, it is also possible to suppress an increase in false acceptance.
[0044] The above describes an example in which monitoring information around the biometric authentication device 100 is acquired as context, and the threshold for detecting impersonation is adjusted accordingly. However, this is just one example, and the threshold adjustment unit 305 may perform threshold adjustments by acquiring other information as context. For example, the context acquisition unit 304 acquires the installation location of the biometric authentication device 100 as context. The threshold adjustment unit 305 may then adjust the threshold to be lower if the location is one that is easily visible to people, and to be higher if the location is not easily visible to people (a location that is not easily visible to people). In this case, whether or not a location is easily visible to people should be set manually in advance. In other words, the setting of a location that is easily visible to people should be set in advance by the user using the input device 102, etc.
[0045] Furthermore, the context acquisition unit 304 may acquire information as monitoring information, such as whether a specific person, such as an administrator or person in charge, is present around the biometric authentication device 100. In this case, the threshold adjustment unit 305 adjusts the threshold to be lower if the specific person is present around the biometric authentication device 100, based on the acquired monitoring information. On the other hand, if the specific person is not present around the biometric authentication device 100, the threshold is adjusted to be higher. Note that the user may pre-configure the aforementioned specific person using the input device 102 or the like.
[0046] Furthermore, in usage scenarios other than those envisioned in Embodiment 1, the same threshold adjustments as described above can be made by changing the context acquired. For example, in payment scenarios using biometric authentication in closed environments such as school or company stores, the risk of impersonation is very high. Focusing on this, the same effect as described above can be achieved by adjusting the threshold so that the smaller the payment amount, the lower the threshold, and the higher the payment amount, using the situation and payment amount as context. In other words, this is equivalent to acquiring information about the likelihood of impersonation occurring as context, and it is unlikely that anyone would take on a high risk by impersonating someone when the return (payment amount) is small. Therefore, in such cases, convenience can be improved by adjusting the threshold to a lower value.
[0047] Furthermore, as another example, in biometric authentication in environments with large fluctuations in illuminance and wind speed, such as outdoors, certain impersonation acts may be difficult. Therefore, the context acquisition unit 304 acquires information as context that allows for the measurement of the difficulty level of each impersonation method, such as illuminance and wind speed. Based on the acquired information that allows for the measurement of the difficulty level of each impersonation method, it is possible to adjust the threshold for impersonation acts that are difficult to perform to a lower level than the threshold for other impersonation acts. For example, when the wind is strong, impersonation by printing a face image on paper is difficult, so the threshold for that would be adjusted lower than that for other impersonation acts. The impersonation method referred to here includes the method of impersonating a person performing an impersonation act. In addition, the same context acquisition method as in Embodiment 1 can be used to adjust thresholds in other cases, such as logging into a PC using biometric authentication.
[0048] Up to this point, the explanation has assumed that only a single piece of information is obtained as context, and the threshold is adjusted accordingly. However, this is not always necessary. For example, multiple contexts such as location and time of day could be obtained according to the situation, and these multiple contexts could be combined to adjust the threshold based on the combined context. This would allow for more detailed threshold adjustments depending on the situation, thereby improving usability.
[0049] Furthermore, while the explanation so far has described controlling whether or not to permit impersonation by adjusting the threshold, it is also conceivable to control this by changing the method of detecting (determining) impersonation itself. That is, if it is determined from the context that impersonation is easy, an advanced detection method capable of detecting various impersonation methods such as printed materials, display images, and 3D masks is used. On the other hand, if it is determined from the context that impersonation is not easy, a simpler detection method capable of detecting only printed materials is used. In this way, the method of detecting impersonation may be controlled depending on whether or not it is easy from the context. In other words, the impersonation detection unit 306 in this embodiment can change the determination method in determining impersonation according to the acquired context.
[0050] Furthermore, instead of being limited to these methods, various publicly known methods exist for detecting impersonation, so it is appropriate to flexibly select the most suitable method depending on the context. Also, even if the detection method is not changed, it can be controlled, for example, by replacing the neural network used to calculate the biolikelihood above with a high-performance / low-performance version.
[0051] Furthermore, in the explanation so far, the biometric information has been described as a user's facial image obtained via a network camera and the features extracted from this facial image. However, this embodiment can also be applied when other biometric information is used. For example, the biometric information could be the user's iris image obtained via an IR camera and the features extracted from this iris image, or the user's fingerprint information obtained via a fingerprint sensor and the features extracted from this fingerprint information. However, when using sensors specialized for acquiring specific information, such as fingerprint sensors, it may be necessary to install other sensors, such as network cameras, in order to acquire context.
[0052] As described above, according to the biometric authentication device 100 of Embodiment 1, in situations where a user cannot use their original biometric information, the user can bypass authentication using only the biometric authentication device by impersonating themselves. This makes it possible to provide a biometric authentication device that can maintain convenience while suppressing costs and the increase in acceptance of false identities.
[0053] <Embodiment 2> Embodiment 2 focuses on the usage trends of each legitimate user and describes a method to maintain the convenience of biometric authentication regardless of the usage scenario while preventing an increase in costs and false acceptance. Since the biometric authentication device 100 in Embodiment 2 has the same configuration as the biometric authentication device 100 in Embodiment 1, as described above, redundant explanations will be omitted, and the differences from Embodiment 1 will be explained. For example, in Embodiment 2, some of the configuration of the functional unit shown in Figure 5, which will be described later, differs from that of Embodiment 1.
[0054] Figure 5 is a functional configuration diagram (functional block diagram) of the biometric authentication device 100 in Embodiment 2. In this embodiment, the biometric authentication device 100 has the following functional units: a biometric information acquisition unit 301, a storage unit 302, a matching unit 303, a context acquisition unit 304, a likely legitimate user identification unit 501, a threshold adjustment unit 305, a spoofing detection unit 306, and an entry / exit processing unit 307. The basic configuration is similar to that of Figure 3, but in Embodiment 2, the functions of the storage unit 302 and the threshold adjustment unit 305 are different from those in Figure 3, and a likely legitimate user identification unit 501 is added.
[0055] The memory unit 302 stores facial images and corresponding feature quantities, which are biometric information of multiple regular users. Furthermore, it stores information about the regular users' usage trends, such as usage time, simultaneous users, clothing, and actions, as well as appearance information provided in advance by the regular users themselves. The memory unit 302 stores all of this information together as registered information. Here, appearance information provided in advance by the regular users themselves refers to information that is highly likely to be unique to the user and can be obtained from their appearance, such as information about the location of injuries or information about belongings at a specific date and time. The information about the regular users' usage trends and the appearance information provided in advance by the regular users themselves are assumed to have been acquired in advance via the context acquisition unit 304.
[0056] The likely legitimate user identification unit (legitimate user determination unit) 501 compares the context acquired by the context acquisition unit 304 with the registration information stored in the storage unit 302 to determine which of the legitimate users the user is most likely to be. The functions of the likely legitimate user identification unit 501 will be explained in detail in the processing procedure described later.
[0057] The threshold adjustment unit 305 separately adjusts the impersonation detection thresholds for specific legitimate users determined by the general legitimate user identification unit 501 and for other legitimate users.
[0058] Figure 6 is a flowchart showing an example of the processing procedure of the information processing device 101 of the biometric authentication device 100 in Embodiment 2. The processing performed by the information processing device 101 in Embodiment 2 will be described below with reference to Figure 6. Note that each operation (process) shown in the flowchart of Figure 6 is controlled by the CPU 101a of the information processing device 101 executing a program. Furthermore, the notation of each process (step) is omitted by prefixing it with "S".
[0059] Here, the process in Figure 6 is started when the sensor 105 is able to acquire a sufficient image of the user's face, similar to Embodiment 1. Note that the process similar to Embodiment 1 will not be explained. In Embodiment 2, the process in S402 differs from that in Embodiment 1, with the addition of processes S601 and S602 instead of S404 in Embodiment 1.
[0060] In S402, the context acquisition unit 304 acquires the surrounding context other than the biometric information acquired by the biometric information acquisition unit 301 in S401. In Embodiment 2, the context includes the usage time period, simultaneous users, clothing, actions, appearance information provided in advance by the user whose biometric information is registered, and other appearance information. This context can be acquired using the sensor 105, which is a network camera used for biometric information acquisition in S401. Therefore, as in Embodiment 1, it is not necessary to use an additional sensor to acquire the context.
[0061] In S601, the likely legitimate user identification unit 501 compares the context acquired by the context acquisition unit 304 in S402 with the registration information stored in the storage unit 302 to determine which of the legitimate users the user is most likely to be. Note that the determination in S601 differs from the identification of a person by biometric authentication and roughly identifies a likely legitimate user, and multiple legitimate users may be identified as candidates by this determination. In Embodiment 2, the context, which includes usage time, simultaneous users, clothing, actions, and other appearance information, is compared with the corresponding registration information of each legitimate user, and if the degree of matching meets a certain standard, that legitimate user is determined to be highly likely to be the user. In other words, the likely legitimate user identification unit 501 identifies one or more people (legitimate users) who meet predetermined standards based on the context acquired by the context acquisition unit 304 in S402 and the registration information stored in the storage unit 302.
[0062] Furthermore, to calculate the degree of similarity, a pre-trained neural network is used that takes as input the usage time periods, simultaneous users, clothing, actions, and other appearance information for two people and outputs the degree of similarity as a probability. However, this is merely an example, and any other machine learning method may be used. For example, methods such as logistic regression, decision trees, and support vector machines may be similarly trained and used. This embodiment is not limited to these methods.
[0063] In S602, the threshold adjustment unit 305 adjusts the impersonation detection threshold for the group of legitimate users that the likely legitimate user identification unit 501 determined to be highly likely to be legitimate users in S601, so that it is lower than a predetermined standard value. In other words, the threshold adjustment unit 305 adjusts only the threshold for the person who best meets the standard value among the individuals (legitimate users) identified by the likely legitimate user identification unit 501. At this time, the impersonation detection threshold for legitimate user groups other than these legitimate user groups is not changed from the standard value, or is adjusted to be higher than the standard value.
[0064] The above describes the processing procedure in Embodiment 2. This makes it possible to bypass authentication using only biometric authentication by "impersonating oneself" when the user is unable to use their original biometric information, regardless of the usage scenario.
[0065] As explained above, the threshold adjustment unit 305 adjusts the impersonation detection thresholds separately for the group of legitimate users determined to be highly likely to be users by the general legitimate user identification unit 501 and for other groups of legitimate users. Here, by acquiring additional context with the context acquisition unit 304 and using it with the threshold adjustment unit 305, it is possible to combine this with the threshold adjustment for all legitimate users as shown in Embodiment 1. Specifically, when acquiring information such as usage time, simultaneous users, clothing, actions, and other appearance information, as well as pedestrian flow information around the biometric authentication device 100, the threshold is adjusted based on whether the location is generally exposed to public view. Furthermore, the threshold is further adjusted for specific groups of legitimate users.
[0066] As described above, with the biometric authentication device 100 of Embodiment 2, even when a user cannot use their original biometric information in any given usage scenario, the user can bypass authentication using only the biometric authentication device by impersonating themselves. This makes it possible to maintain convenience, similar to Embodiment 1, while suppressing costs and the increase in acceptance of false identities.
[0067] <Embodiment 3> While Embodiments 1 and 2 can prevent unintended unauthorized access, unauthorized access may still occur if a malicious user cleverly impersonates a legitimate user after analyzing their usage patterns and avoiding detection. Embodiment 3 describes the process for minimizing such damage in the biometric authentication device 100. As described above, the biometric authentication device 100 of Embodiment 3 has the same configuration as the biometric authentication device 100 of Embodiment 1, so redundant explanations will be omitted, and the differences from Embodiment 1 will be explained. For example, in Embodiment 3, some of the configurations of the functional unit shown in Figure 7, which will be described later, differ from those of Embodiment 1.
[0068] Figure 7 is a functional configuration diagram (functional block diagram) of the biometric authentication device in Embodiment 3. In Embodiment 3, the biometric authentication device 100 has the following functional units: a biometric information acquisition unit 301, a storage unit 302, a matching unit 303, a context acquisition unit 304, a threshold adjustment unit 305, a spoofing detection unit 306, an entry / exit processing unit 307, a notification unit 701, and an entry information storage unit. The basic configuration is similar to that of Figure 3, but in Embodiment 3, the notification unit 701 and the authentication information storage unit 702 are added as differences from Figure 3.
[0069] The notification unit 701 notifies authorized users via email, short message, phone, or smartphone application notifications. The authentication information storage unit 702 stores information obtained via the sensor 105 in the RAM 101b or external storage device 101d. The notification unit 701 and the authentication information storage unit 702 may be controlled by the access control unit 307.
[0070] In this configuration, the access control unit 307 of Embodiment 3 notifies the legitimate user corresponding to the user who has successfully authenticated when the impersonation detection threshold falls below a certain standard, via the notification unit 701. In other words, the access control unit 307 controls the notification unit 701 to send a predetermined notification to the user whose biometric information has been registered and who has successfully authenticated when the threshold used for impersonation determination falls below a predetermined value. As a result, if the legitimate user was impersonating someone else, it will be clear that they have successfully bypassed authentication, and if not, the impersonated legitimate user can promptly contact the administrator, thereby minimizing damage caused by malicious users.
[0071] Furthermore, in the configuration of Embodiment 3, when the access control unit 307 processes an authentication when the threshold for detecting impersonation falls below a certain standard, it stores the information obtained via the sensor 105 before and after the series of processes via the authentication information storage unit 702. In other words, the access control unit 307 controls the authentication information storage unit 702 to store authentication information, including time information before and after authentication, in a storage medium such as RAM 101b or external storage device 101d, when the threshold used for determining impersonation falls below a predetermined value. This makes it possible to determine which legitimate user the malicious user attempted to impersonate by referring to the stored information if a malicious user appears, thereby minimizing damage regardless of whether the malicious user succeeds in bypassing authentication.
[0072] Furthermore, the access control unit 307 may control the system to restrict the entry of users who have successfully authenticated when the threshold for impersonation detection falls below a certain threshold (when the threshold falls below a certain level) and the biometric likelihood falls below a certain value. Note that the restriction referred to here means allowing entry to at least some areas but not to other areas. For example, in the case of a training gym, this refers to access restrictions such as allowing entry to the free weight area but not to the locker area.
[0073] As described above, the biometric authentication device 100 of Embodiment 3 can be used in a system that maintains convenience while suppressing costs and the increase in false acceptance.
[0074] Furthermore, in the embodiments described above, the biometric authentication device 100 was shown as being composed of a single device, as shown in Figure 1, but it may also be composed of multiple devices in which each component is separate.
[0075] The present invention can take the form of, for example, a system, apparatus, method, program, or storage medium. Specifically, it may be applied to a system consisting of multiple devices (e.g., a host computer, interface devices, imaging devices, a web application, etc.) or to an apparatus consisting of a single device.
[0076] Furthermore, the present invention can also be realized by performing the following process: supplying software (programs) that realize the functions of the embodiments described above to a system or device via a network or various storage media, and having the computer (or CPU or MPU, etc.) of that system or device read and execute the program. In this case, the program code read from the storage media itself realizes the functions of the embodiments described above, and the storage media on which the program code is recorded constitutes the present invention.
[0077] Although preferred embodiments of the present invention have been described above, the present invention is not limited to these embodiments, and various modifications and changes are possible within the scope of its essence. Furthermore, the above embodiments may be implemented in combination.
[0078] This embodiment includes the following configurations, methods, and programs.
[0079] (Composition 1) An information acquisition unit that acquires biometric information of the person to be authenticated, A biometric authentication unit that performs biometric authentication using the aforementioned biometric information, A context acquisition unit that acquires context other than the aforementioned biological information, An impersonation detection unit that determines whether the aforementioned person is engaging in impersonation based on a threshold, The system includes an adjustment unit that adjusts the threshold based on the context from which the threshold was obtained, A biometric authentication device characterized by the following features.
[0080] (Configuration 2) The biometric authentication device according to Configuration 1, characterized in that the context acquisition unit acquires monitoring information around the biometric authentication device as the context.
[0081] (Composition 3) The biometric authentication device according to configuration 2, characterized in that the adjustment unit adjusts the threshold to a lower value when there is a high probability from the monitoring information that the person to be authenticated is being monitored by another person, and adjusts the threshold to a higher value when there is a low probability that the person to be authenticated is being monitored by another person.
[0082] (Composition 4) The biometric authentication device according to configuration 2 or 3, characterized in that the monitoring information is a compilation of information including the number of people who have used the biometric authentication device within a certain period of time, the number of people around the biometric authentication device, the number of people looking at the biometric authentication device, and the number of people looking at the person to be authenticated.
[0083] (Composition 5) The biometric authentication device according to any one of configurations 2 to 4, characterized in that the monitoring information is information on whether or not a specific person pre-set is present in the vicinity of the biometric authentication device.
[0084] (Composition 6) The biometric authentication device according to any one of configurations 1 to 5, characterized in that the context acquisition unit acquires information regarding the likelihood of impersonation as the context.
[0085] (Composition 7) The biometric authentication device according to any one of configurations 1 to 6, characterized in that the context acquisition unit acquires information as the context for measuring the difficulty level of each impersonation method in the vicinity of the biometric authentication device.
[0086] (Composition 8) The biometric authentication device according to any one of configurations 1 to 7, characterized in that the context acquisition unit acquires information on the installation location of the biometric authentication device as the context.
[0087] (Composition 9) The biometric authentication device according to any one of configurations 1 to 8, characterized in that the context acquisition unit acquires appearance information provided in advance by a user whose usage time, simultaneous users, clothing, actions, and biometric information have been registered, as the context.
[0088] (Composition 10) The biometric authentication device according to any one of configurations 1 to 9, characterized in that the impersonation detection unit changes the detection method in the impersonation detection depending on the context.
[0089] (Composition 11) The biometric authentication device according to any one of configurations 1 to 10, characterized in that the adjustment unit adjusts the threshold by combining multiple contexts.
[0090] (Composition 12) An identification unit identifies at least one person who meets predetermined criteria based on the aforementioned context and registration information stored in the memory unit, The biometric authentication device according to any one of configurations 1 to 11, characterized in that the adjustment unit adjusts only the threshold value for the person with the highest standard value among the persons identified by the identification unit.
[0091] (Composition 13) The biometric authentication device according to any one of configurations 1 to 12, further comprising an access control unit that controls the entry and exit of the person to be authenticated based on the determination result of the impersonation determination unit and the authentication result of the biometric authentication unit.
[0092] (Composition 14) The impersonation detection unit calculates the biolikelihood, which is the likelihood of the organism's authenticity, based on the biological information. The biometric authentication device according to configuration 13, characterized in that the access control unit implements an access restriction on a person who has successfully authenticated when the threshold and the biolikelihood fall below a certain value.
[0093] (Composition 15) The biometric authentication device according to configuration 14, further comprising a notification unit that notifies a user whose biometric information is registered and who has successfully authenticated a person when the threshold falls below a predetermined value.
[0094] (Composition 16) The biometric authentication device according to configuration 14 or 15, further comprising a storage unit that stores information at the time of authentication when the threshold falls below a predetermined value, including time information before and after authentication, in a storage medium.
[0095] (Composition 17) The biometric authentication device according to any one of configurations 1 to 16, characterized in that the information acquisition unit acquires facial information of a person as the biometric information.
[0096] (Composition 18) A method for controlling a biometric authentication device, The process involves obtaining biometric information of the person to be authenticated, A biometric authentication step that performs biometric authentication using the aforementioned biometric information, A context acquisition step to acquire context other than the aforementioned biological information, A spoofing detection step that determines whether the aforementioned person is engaging in impersonation based on a threshold, The system includes an adjustment step of adjusting the threshold based on the context from which the threshold was obtained, A method for controlling a biometric authentication device, characterized by the following features.
[0097] (Composition 19) A program for causing a computer to execute a method for controlling a biometric authentication device, wherein the program causes the computer to: The process involves obtaining biometric information of the person to be authenticated, A biometric authentication step that performs biometric authentication using the aforementioned biometric information, A context acquisition step to acquire context other than the aforementioned biological information, A spoofing detection step that determines whether the aforementioned person is engaging in impersonation based on a threshold, An adjustment step is performed to adjust based on the context from which the threshold was obtained. A program characterized by the following features. [Explanation of Symbols]
[0098] 100 Biometric devices 101 Information Processing Device 101a CPU 101b RAM 101c ROM 101d External storage device 101e Input I / F 101f Output Interface 101g Communication I / F 101h System Bus 102 Input device 103 Output device 104 Network 105 Sensor 106 Access control device
Claims
1. An information acquisition unit that acquires biometric information of the person to be authenticated, A biometric authentication unit that performs biometric authentication using the aforementioned biometric information, A context acquisition unit that acquires context other than the aforementioned biological information, An impersonation detection unit that determines whether the aforementioned person is engaging in impersonation based on a threshold, The system includes an adjustment unit that adjusts the threshold based on the context from which the threshold was obtained, A biometric authentication device characterized by the following features.
2. The biometric authentication device according to claim 1, characterized in that the context acquisition unit acquires monitoring information of the surrounding area of the biometric authentication device as the context.
3. The biometric authentication device according to claim 2, characterized in that the adjustment unit adjusts the threshold to be lower when there is a high probability from the monitoring information that the person to be authenticated is being monitored by another person, and adjusts the threshold to be higher when there is a low probability that the person to be authenticated is being monitored by another person.
4. The biometric authentication device according to claim 2, characterized in that the monitoring information is a compilation of information including the number of people who have used the biometric authentication device within a certain period of time, the number of people around the biometric authentication device, the number of people looking at the biometric authentication device, and the number of people looking at the person to be authenticated.
5. The biometric authentication device according to claim 2, characterized in that the monitoring information is information on whether or not a specific person, pre-set in advance, is present in the vicinity of the biometric authentication device.
6. The biometric authentication device according to claim 1, characterized in that the context acquisition unit acquires information regarding the likelihood of impersonation as the context.
7. The biometric authentication device according to claim 1, characterized in that the context acquisition unit acquires information as the context for measuring the difficulty level of each impersonation method in the vicinity of the biometric authentication device.
8. The biometric authentication device according to claim 1, characterized in that the context acquisition unit acquires information on the installation location of the biometric authentication device as the context.
9. The biometric authentication device according to claim 1, characterized in that the context acquisition unit acquires appearance information provided in advance by a user whose usage time, simultaneous users, clothing, actions, and biometric information have been registered as the context.
10. The biometric authentication device according to claim 1, characterized in that the impersonation detection unit changes the detection method in the impersonation detection depending on the context.
11. The biometric authentication device according to claim 1, characterized in that the adjustment unit adjusts the threshold by combining multiple contexts.
12. An identification unit identifies at least one person who meets predetermined criteria based on the aforementioned context and registration information stored in the storage unit, The biometric authentication device according to claim 1, characterized in that the adjustment unit adjusts only the threshold value for the person with the highest standard value among the people identified by the identification unit.
13. The biometric authentication device according to claim 1, further comprising an access control unit that controls the entry and exit of the person to be authenticated based on the determination result of the impersonation determination unit and the authentication result of the biometric authentication unit.
14. The impersonation detection unit calculates the biolikelihood, which is the likelihood of the organism's authenticity, based on the biological information. The biometric authentication device according to claim 13, characterized in that the access control unit implements an access restriction on a person who has successfully authenticated when the threshold and the biolikelihood fall below a certain value.
15. The biometric authentication device according to claim 14, further comprising a notification unit that notifies a user whose biometric information is registered and who has successfully authenticated a person when the threshold falls below a predetermined value.
16. The biometric authentication device according to claim 14, further comprising a storage unit that stores information at the time of authentication when the threshold falls below a predetermined value, including time information before and after authentication, in a storage medium.
17. The biometric authentication device according to claim 1, characterized in that the information acquisition unit acquires facial information of a person as the biometric information.
18. A method for controlling a biometric authentication device, The process involves obtaining biometric information of the person to be authenticated, A biometric authentication step that performs biometric authentication using the aforementioned biometric information, A context acquisition step to acquire context other than the aforementioned biological information, A spoofing detection step that determines whether the aforementioned person is engaging in impersonation based on a threshold, The system includes an adjustment step of adjusting the threshold based on the context from which the threshold was obtained, A method for controlling a biometric authentication device, characterized by the following features.
19. A program for causing a computer to execute a method for controlling a biometric authentication device, wherein the program causes the computer to: The process involves obtaining biometric information of the person to be authenticated, A biometric authentication step that performs biometric authentication using the aforementioned biometric information, A context acquisition step to acquire context other than the aforementioned biological information, A spoofing detection step that determines whether the aforementioned person is engaging in impersonation based on a threshold, An adjustment step is performed to adjust based on the context from which the threshold was obtained. A program characterized by the following features.
Citation Information
Patent Citations
Control system for electric discharge machine
JP1982048424A
Face authentication device
JP2019125002A