system
A dynamic authentication system using AI-generated questions addresses the challenges of password management, improving security and user experience by providing unique questions each time, reducing the risk of unauthorized access.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-10-18
- Publication Date
- 2026-05-01
AI Technical Summary
The challenges of remembering complex passwords, the security risks due to reusing passwords, and the inefficiency of resetting passwords pose a significant burden on users, making static password systems vulnerable to unauthorized access and cyberattacks.
A system that dynamically generates authentication questions based on user information, using an artificial intelligence model to create unique questions each time, which are answered and verified by the server to grant or deny access.
This system enhances security by reducing the risk of unauthorized access and provides a more efficient, user-friendly authentication process without relying on memory.
Smart Images

Figure 2026073456000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance that responds to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the modern digital environment, it is difficult to remember complex passwords, the security risks due to reusing passwords are increasing, and the time and effort associated with resetting passwords pose a significant burden on users. In particular, static password systems have a higher risk of unauthorized access and are more vulnerable to cyberattacks. There is a need to solve such security issues and provide a safe and comfortable authentication environment for users.
Means for Solving the Problems
[0005] This invention provides a system that dynamically generates authentication questions, including means for generating and storing user information, thereby presenting the user with different security questions each time. The user answers the presented questions and transmits the answers to the server via the receiving means. The answers are compared with the user information, and access is granted or denied based on the comparison result. This process allows the user to be authenticated without relying on memory, thereby reducing the risk of unauthorized access. This system utilizes an artificial intelligence model to provide a dynamic and flexible authentication experience, thereby enhancing security.
[0006] "Generating means" refers to a function or process for creating the information and questions necessary for user authentication.
[0007] "Means for storing user information" refers to a function or device that securely and efficiently records personal data and historical information about a user.
[0008] A "means for generating dynamic authentication questions" refers to a technology or algorithm for creating new authentication questions to present to the user each time.
[0009] "Means for receiving user responses" refers to a function or device that retrieves the user's answers to authentication questions and passes them on to the next process.
[0010] "Means for matching received responses with user information" refers to a system or method for comparing and verifying user input with information stored in advance.
[0011] "Means for determining whether to grant or deny access based on matching results" refers to a function or program that determines whether to provide a user with access to the system based on the results of an authentication process.
[0012] An "artificial intelligence model" is a computer program or system that uses technologies such as machine learning and deep learning to learn patterns from data and perform inference. [Brief explanation of the drawing]
[0013] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Figure 11] This is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] This is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] This is a sequence diagram showing the processing flow of the data processing system in Example 2, which incorporates an emotion engine. [Figure 14]It is a sequence diagram showing the processing flow of a data processing system in Application Example 2 when a sentiment engine is combined.
Embodiment for Carrying Out the Invention
[0014] Hereinafter, an example of an embodiment of a system according to the technology of the present disclosure will be described with reference to the accompanying drawings.
[0015] First, the terms used in the following description will be explained.
[0016] In the following embodiments, the numbered processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), APU (Accelerated Processing Unit), etc.
[0017] In the following embodiments, the numbered RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.
[0018] In the following embodiments, the numbered storage is one or more non-volatile storage devices that store various programs and various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disk (e.g., hard disk), or magnetic tape, etc.
[0019] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0020] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."
[0021] [First Embodiment]
[0022] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.
[0023] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0024] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0025] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.
[0026] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0027] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0028] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0029] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0030] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0031] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0032] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0033] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0034] The present invention is a system for making the user authentication process dynamic and secure. The system comprises means for generating, storing user information, generating dynamic authentication questions, receiving user responses, matching received responses with user information, and determining whether to grant or deny access based on the matching result.
[0035] The system's program first stores personal information and historical data provided by the user on the server. This ensures that the information necessary to identify each user is compiled. Next, when a user attempts to access the system, an authentication request is sent to the server via the terminal.
[0036] The server uses an artificial intelligence model to generate dynamic security questions based on stored user information. These questions are randomly generated from past user data and are different each time, providing a higher level of security compared to fixed passwords.
[0037] For example, a question like "What was the name of the first country you visited?" might be generated based on places the user has visited or products they have purchased in the past. The user enters the correct answer to the question displayed on their device. The device sends this answer to the server, which then compares the received answer with stored data.
[0038] If the verification is successful, the server sends a notification of successful authentication to the terminal, and the user is granted access to the system. Conversely, if the verification fails, the server sends a notification of authentication failure to the terminal, and the user is required to try authenticating again.
[0039] In this way, users can enjoy a secure and efficient authentication experience without relying on their memory. This invention is particularly applicable to many online services where security is critical.
[0040] The following describes the processing flow.
[0041] Step 1:
[0042] When a user accesses the system for the first time, they use a terminal to enter and register personal information and history data. This information is sent to the server and stored in the database.
[0043] Step 2:
[0044] When a user initiates authentication to the system, an authentication request is sent from the terminal to the server. The server then prepares to accept the request.
[0045] Step 3:
[0046] The server uses an artificial intelligence model to generate dynamic authentication questions based on stored user information. The generated questions change each time and are associated with specific user information.
[0047] Step 4:
[0048] The generated authentication question is sent from the server to the terminal and presented to the user. The user reviews the question and answers appropriately.
[0049] Step 5:
[0050] The user's input is sent to the server via the terminal. The server compares the received input with stored user information to evaluate its accuracy.
[0051] Step 6:
[0052] The server makes a decision to grant or deny access based on the matching result. If the matching is successful, it sends the result to the terminal and grants the user access to the system. If it fails, it sends a message prompting the user to try again.
[0053] Throughout this entire process, users can receive dynamic and secure authentication.
[0054] (Example 1)
[0055] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0056] In today's digital environment, authentication using fixed passwords is a factor that increases security risks. Password leaks and unauthorized access using specific passwords are serious problems. Therefore, there is a need for new authentication methods that improve user management and access security.
[0057] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0058] In this invention, the server includes a data storage means for storing user information, a communication device for receiving authentication requests, and a data generation means for generating dynamic authentication questions based on the stored information. This enables the generation of dynamic and unique questions each time based on the user's past history, resulting in a highly secure authentication level.
[0059] "User information" refers to individual user data within the system, including personally identifiable information and historical data necessary for authentication.
[0060] "Data storage means" refers to technical means for efficiently and securely storing user information and historical data, and generally includes relational databases and cloud storage.
[0061] A "communication device" is a technical means for sending and receiving data such as authentication requests between a user and a server, and includes network interfaces and protocols.
[0062] "Data generation means" refers to technical means for constructing dynamic authentication questions based on the user's stored information.
[0063] An "interface" is the environment or means by which a user interacts with a system, and is usually implemented through a display or input device.
[0064] "Data matching means" refers to technical methods for comparing input obtained from the user with stored information, thereby enabling accurate authentication.
[0065] A "determination means" is a technical means that provides a decision-making function for granting or denying access rights based on the results of data matching.
[0066] A "machine learning model" refers to a computer algorithm used to automatically learn from past data and generate authentication questions.
[0067] This invention relates to a security-focused dynamic authentication system. The system securely manages user information and generates dynamic, unique authentication questions to prevent unauthorized access.
[0068] The server first uses a relational database management system to store personal information and behavioral history obtained from users. This database can be managed using software such as MySQL® or PostgreSQL. User information forms the basis for maintaining consistent authentication standards for each user.
[0069] The terminal is responsible for sending authentication requests when a user attempts to access the system. The HTTPS protocol is used for this communication to ensure the secure transmission of data. The terminal reliably transmits the information entered by the user to the server.
[0070] The server generates dynamic authentication questions using a generative AI model based on stored user information. This process utilizes language models such as OpenAI® GPT. This enables a variety of questions tailored to each user's history, thereby improving the security level.
[0071] As a concrete example, a question such as "What was the last city you visited?" is generated based on information about places the user has visited in the past. The user answers this question on their device, and the server receives the answer. This answer is then verified by a data matching system built using Python and TENSORFLOW®.
[0072] The server determines whether the response matches the user's stored information and, based on the result, approves or denies the user's access.
[0073] Examples of prompt statements to be input to a generative AI model include the following:
[0074] "Generate new authentication questions based on past travel history." "Create dynamic authentication questions from information on recently purchased items."
[0075] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0076] Step 1:
[0077] The server stores personal information and historical data submitted by users during registration in a database. As input, users provide their personal information (e.g., name, email address) and optional historical data. The server receives this data and stores it in a relational database using data storage methods; this data serves as the basis for future authentication processes.
[0078] Step 2:
[0079] The user initiates an authentication attempt on their device to access the system. The user accesses the login screen on their device and submits an authentication request. Upon receiving this input, the device sends the authentication request to the server using the HTTPS protocol. The output here indicates that the authentication request has been securely delivered to the server.
[0080] Step 3:
[0081] After receiving an authentication request from a user, the server references stored information and uses a generative AI model to create dynamic authentication questions. The user's stored history data is referenced as input. The server analyzes this data and uses the generative AI model to generate questions such as, for example, "What was the first item you purchased?". The output is the dynamically generated authentication question.
[0082] Step 4:
[0083] The terminal displays authentication questions sent from the server to the user. The user answers the questions based on past experience and memory. The input is a manual response based on the user's memory. This response is stored on the terminal, and the user's response is sent to the server as output.
[0084] Step 5:
[0085] The server receives responses from users and compares them with information stored in a database. The inputs used are the user's responses and the stored information in the database. Machine learning models such as TensorFlow are used as data matching tools to determine if there is a match. The output is the matching result, which determines the next step.
[0086] Step 6:
[0087] Based on the matching results, the server makes a decision to approve or deny the user's access. If approved, the server sends an access permission notification to the terminal, and the user can successfully log in to the system. If denied, the server notifies the terminal that authentication failed and instructs the user to try again. The output is a notification of success or failure as a result of the authentication process.
[0088] (Application Example 1)
[0089] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0090] In recent years, the proliferation of electronic payment services has increased security risks, and there is a need for effective authentication methods to ensure user safety. Traditional fixed passwords and question-based authentication methods carry a high risk of unauthorized access, and a dynamic and secure authentication method is needed to overcome this. In particular, there is a need for a method that prevents unauthorized access while not compromising user convenience, such as by using different questions for each transaction.
[0091] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0092] In this invention, the server includes a generation mechanism, a mechanism for storing user information, and a mechanism for verifying the user's identity in the payment process based on dynamic authentication questions. This enables secure and efficient electronic payments by generating different authentication questions each time from information such as transaction history and visit history.
[0093] A "generating mechanism" is a technical means for creating dynamic authentication questions.
[0094] A "mechanism for storing user information" refers to a technical means for recording and retaining a user's personal information and transaction history.
[0095] A "mechanism for verifying user identity in payment processing based on dynamic authentication questions" is a technical means of using generated authentication questions to verify the user's identity and securely process payments.
[0096] An "artificial intelligence model" is a computer program designed to perform data analysis and reasoning, and is used to dynamically generate authentication questions.
[0097] "Transaction history" refers to a record of all purchases and payments a user has made in the past.
[0098] "Visit history" refers to a record of stores and places that a user has visited in the past.
[0099] A "dynamic authentication question" is a question that is generated based on the user's sensitive information and is in a different format each time, and is used to prevent unauthorized access.
[0100] The system implementing this invention first has a mechanism in which a server stores the user's personal information, past transaction history, and visit history. The server can also use a generation AI model to create dynamic authentication questions based on this historical data. When a user attempts electronic payment, the terminal sends an authentication request to the server, and the server generates dynamic authentication questions from the stored information and sends them to the terminal.
[0101] The user reviews the authentication question displayed on their device and provides an accurate answer. The device sends this answer to the server, which verifies it against stored information. If the verification is successful, the server can authorize the user's payment, ensuring a secure transaction. This process typically uses programming languages such as Python, and a database management system (e.g., MySQL or PostgreSQL) is commonly used to manage user information.
[0102] As a concrete example, when a user purchases an item on an online shopping site, a question is generated based on their transaction history: "What category did you last purchase in?" If the user answers "electronics" and this matches their past history, the payment process proceeds smoothly.
[0103] Examples of prompts for a generative AI model include the following:
[0104] "Generate dynamic authentication questions based on the user's past history. History data: Product category: Electronics, Place visited: Cafe X. Example: 'What category was the last product you purchased?'"
[0105] In this way, users can make payments safely and quickly by going through a different authentication process each time.
[0106] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0107] Step 1:
[0108] The server stores personal information obtained during user registration, as well as past transaction and visit history, in a database. It processes data by receiving personal information from users as input and storing it in the database as output. This ensures that the data necessary for user identification is prepared.
[0109] Step 2:
[0110] When a user attempts to make an electronic payment using a terminal, the terminal sends the request to the server. It receives the payment request as input and transmits that request to the server as output. This initiates the payment process.
[0111] Step 3:
[0112] The server generates dynamic authentication questions using a generative AI model based on stored user history data. It takes history data and prompts as input and outputs a generated question. An AI algorithm is used for this data processing, resulting in the dynamic generation of questions that differ each time.
[0113] Step 4:
[0114] The generated authentication question is sent to the device and displayed to the user. The system receives the question from the server as input and displays it on the screen as output. This allows the user to verify the question required for authentication.
[0115] Step 5:
[0116] The user enters their answer to a question on their device. The system receives the user's answer as input and sends it to the server as output. This completes the user's response process.
[0117] Step 6:
[0118] The server compares the user's response against stored historical data. It takes the user's response as input and generates an authentication result (success or failure) as output. This comparison authenticates the user.
[0119] Step 7:
[0120] If the verification is successful, the server approves the payment and notifies the terminal. Conversely, if the verification fails, a notification is sent to the terminal prompting a retry. The authentication result is received as input and notified to the user as output. This establishes a secure payment process.
[0121] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0122] The present invention provides a system for enhancing the user authentication process and strengthening security, comprising means for generating, storing, generating dynamic authentication questions, receiving user responses, matching received responses with user information, determining whether to grant or deny access based on the matching results, and an emotion engine that recognizes the user's emotions.
[0123] This system's program is designed to implement multi-layered authentication. First, when accessing the system, the user enters personal information using a terminal and sends it to the server. The server stores this information in a database and uses it in the authentication process.
[0124] When an authentication request is sent from the terminal to the server, the server uses an artificial intelligence model to generate dynamic authentication questions. The content of the generated questions is based on the user's stored information and is specific to this authentication process.
[0125] In addition, the emotion engine analyzes the user's facial expressions and voice during responses to recognize their emotional state. The emotional data collected when the user answers questions is sent to the server and used as context for the user's response. For example, if a user is nervous, the emotion engine can detect this state and perform appropriate processing based on the matching process.
[0126] As a concrete example, consider a scenario where a user answers the question, "What was the name of the first country you visited?" In this case, the emotion engine analyzes whether the user is confident or anxious about the answer based on the user's facial expressions and tone of voice on the device. The server then considers this emotion data and compares the user's answer with stored information to make a decision.
[0127] In this way, users can enjoy secure and flexible authentication without relying excessively on memory. This invention is applicable to various digital authentication systems as a means of enriching the user experience and improving security.
[0128] The following describes the processing flow.
[0129] Step 1:
[0130] When a user accesses the system for the first time, they use a terminal to enter and register necessary personal information and history data. This information is sent to the server and securely stored in a database.
[0131] Step 2:
[0132] When a user attempts to log in to the system, an authentication request is sent from the terminal to the server. Upon receiving this request, the server initiates the authentication process for the user.
[0133] Step 3:
[0134] The server uses an artificial intelligence model to generate dynamic authentication questions based on stored user information. The generated questions are selected based on the user's past behavior. These questions are then sent from the server to the terminal and presented to the user.
[0135] Step 4:
[0136] The user reads the authentication questions presented to them and enters their answers into the device. During this process, the emotion engine analyzes the user's facial expressions and voice in real time to recognize the user's emotional state.
[0137] Step 5:
[0138] The device sends the user's response data and the emotion data recognized by the emotion engine to the server. The server receives this data and compares the responses with the stored user information.
[0139] Step 6:
[0140] The server evaluates the accuracy of the response and the user's emotional state based on sentiment data, and decides to grant or deny access based on the matching results. This result is sent to the terminal and notified to the user. If authentication is successful, the user is granted access to the system. If unsuccessful, the user may be asked to retry.
[0141] This allows users to have a more secure and intuitive authentication experience.
[0142] (Example 2)
[0143] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0144] In recent years, with the advancement of digitalization, there has been a growing demand for enhanced security in authentication processes that utilize personal information. However, traditional methods rely on static information and carry a high risk of misuse. Furthermore, improving security without compromising the user experience remains a challenge.
[0145] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0146] In this invention, the server includes means for generating, means for storing personal data, means for generating dynamic authentication questions, and means for performing sentiment analysis. This enhances security by presenting different authentication questions each time, and in addition, enables more flexible and reliable authentication by taking into account the user's emotional state.
[0147] "Generating means" refers to components that have the function of creating user information and authentication questions.
[0148] "Means of storing personal data" refers to technologies for securely recording and storing personal information provided by users.
[0149] A "means for generating dynamic authentication questions" refers to a technology for generating and presenting context-dependent authentication questions, rather than static ones.
[0150] "Means for receiving user responses" refers to an implementation that receives the content of the user's response to an authentication question.
[0151] "Means for matching received responses with personal data" refers to a system for comparing collected data with user responses to determine whether they match or not.
[0152] "Methods for performing emotion analysis" refer to technologies that identify a user's emotional state from their facial expressions and voice, and utilize this information as data.
[0153] "Means for determining whether to grant or deny access based on matching results" refers to a function that determines whether or not a user can access the system based on the results of data comparison.
[0154] This invention is a system for enhancing user authentication, and its implementation is as follows: The user inputs personal data using a terminal and sends it to a server. The terminal is equipped with a camera and microphone, which can capture the user's facial expressions and voice. The server stores this information in a database and uses it for the authentication process. The server uses a generative AI model to generate dynamic authentication questions. This model generates contextual questions from the user's stored data and is implemented using, for example, Python. Specifically, the user will be asked personally relevant questions such as, "What was the first product you purchased?" The user answers these questions through the terminal.
[0155] To perform sentiment analysis, the device utilizes open-source computer vision libraries and machine learning frameworks. Specifically, it uses OpenCV and TensorFlow to analyze the user's facial features and voice tone in real time to evaluate the user's emotional state. For example, it can determine whether the user is confident or nervous when answering questions. This sentiment information is sent to a server and compared with the user's responses to make a final decision on access permission.
[0156] In this way, the authentication process is secured at multiple layers, improving the user experience. This invention enhances the reliability of authentication, allowing users to use the system smoothly while maintaining security. An example of a specific prompt is, "Generate questions about the user's past travel destinations." Using this prompt, the generation AI model can construct appropriate authentication questions.
[0157] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0158] Step 1:
[0159] Users enter personal information using their devices and transmit the data. This personal information may include name, email address, and address. The device sends this information to the server. The entered data is then converted for storage in the database.
[0160] Step 2:
[0161] The server receives personal information sent from the terminal and stores it in the database. The received data is stored in the database as user authentication information. Secure storage methods are applied here, and measures are taken to prevent unauthorized access.
[0162] Step 3:
[0163] The server receives an authentication request from the terminal and generates dynamic authentication questions. In this process, it uses a generation AI model to generate questions related to pre-stored personal information. For example, a question such as "What country did you last visit?" might be created.
[0164] Step 4:
[0165] The terminal displays an authentication question generated by the server to the user. The user enters an answer to this question. The input is sent to the server in real time.
[0166] Step 5:
[0167] The device's camera and microphone capture the user's facial expressions and voice as they answer questions, and perform emotion analysis. Libraries such as OpenCV and TensorFlow are used to analyze the user's emotional state. The analysis results are sent to a server and output as user emotion data.
[0168] Step 6:
[0169] The server receives user responses and sentiment data and compares them with information stored in the database. By comparing the input data with the stored information, it determines whether the responses are accurate and whether the user's sentiment is stable. Based on the results, it grants or denies access.
[0170] Step 7:
[0171] Finally, the server notifies the terminal of the access decision based on the matching results. Based on the notification, the user checks whether access to the system is permitted. This completes the authentication process.
[0172] (Application Example 2)
[0173] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as a "server" and the smart device 14 as a "terminal".
[0174] In recent years, with the spread of electronic transactions, unauthorized access to personal information and data theft have increased. Therefore, improving the security of user authentication processes has become an urgent necessity. However, existing authentication technologies rely on fixed questions and passwords, making them easily bypassed by attackers. Furthermore, they do not consider the user's psychological state, potentially compromising the user experience. Overcoming these problems and providing a more secure and user-friendly authentication system is essential.
[0175] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0176] In this invention, the server includes means for generating, means for storing user attribute information, means for dynamically generating authentication tasks, and means for acquiring sentiment analysis data. This makes it possible to provide a flexible authentication process tailored to each individual based on dynamically generated authentication tasks and the user's sentiment state, thereby reducing the risk of unauthorized access.
[0177] "Means of generation" refers to a function that automatically creates specific information or data as part of a system.
[0178] "Means for storing user attribute information" refers to a function that stores personal data about each user and keeps it available for reference as needed.
[0179] A "means for dynamically generating authentication challenges" refers to a function that generates different authentication problems depending on the user's specific information and circumstances.
[0180] "Means for receiving user responses" refers to a function that takes in user-inputted and selected responses and makes them available within the system for processing.
[0181] "Means for matching received responses with user attributes" refers to a function that compares acquired responses with pre-stored user information and verifies the degree of match.
[0182] "Means for acquiring emotion analysis data" refers to a function that analyzes the user's emotional state from their voice, facial expressions, etc., and acquires the results as data.
[0183] "Means for determining whether to approve or deny access based on matching results and sentiment analysis data" refers to a function that determines whether a user can access the system based on the degree of match and sentiment evaluation obtained through verification.
[0184] The system necessary to implement this invention consists of a cloud-based server and a user's mobile terminal. The server includes means for generating data, means for storing user attribute information, means for dynamically generating authentication tasks, and means for acquiring sentiment analysis data. The program is implemented in a programming language such as Python, and TensorFlow or PyTorch are used as AI models. In addition, OpenCV and Google's (registered trademark) natural language processing API are utilized for sentiment recognition.
[0185] When a user accesses or conducts a transaction via a terminal, the server first stores the user's attribute information in a database. During a transaction, the server utilizes a generative AI model to generate a dynamic authentication task based on the user's past attribute information. While the user answers this task, the terminal uses its camera and microphone to record the user's facial expressions and voice. This information is sent to the server as sentiment analysis data and used to recognize and judge the user's emotional response.
[0186] As a concrete example, when a user uses an online travel service, the server generates questions related to places the user has previously visited. During this process, sentiment analysis is used to assess the user's excitement and sense of security, and then determine whether the answer is correct. This process ensures authentication that prevents unauthorized access while minimizing user stress.
[0187] Examples of prompts to be input into the generation AI model include: "Generate questions that prompt the user to confirm memories based on their past visit information. Also, read expressions of anxiety from the user's responses, evaluate their trustworthiness, and then decide whether to allow payment." This will create a system that balances authentication accuracy and usability.
[0188] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0189] Step 1:
[0190] The user starts up the device and attempts to access online services. The device first inputs user attribute information (e.g., past visited locations and transaction history) and sends it to the server. This updates the user-specific data on the server side.
[0191] Step 2:
[0192] The server stores the received attribute information in a database. Based on this stored information, a generative AI model is used to generate dynamic authentication tasks tailored to the user. Specifically, prompts are used to instruct the model to create a task such as "generate questions that prompt the user to confirm memories based on information about places they have visited in the past."
[0193] Step 3:
[0194] The generated authentication task is sent to the device and presented to the user. The user answers the task, and the answer is sent back to the server via the device. During this response process, the device simultaneously uses its camera and microphone to sense the user's facial expressions and voice, and collects emotion analysis data.
[0195] Step 4:
[0196] The server processes user responses and sentiment analysis data received from the terminal. The server matches the user's responses with attribute information in the database and calculates the degree of match. Furthermore, the sentiment analysis data is evaluated using OpenCV and natural language processing APIs to assess the user's emotional response (e.g., whether they feel safe or anxious).
[0197] Step 5:
[0198] The server decides whether to grant or deny access based on the matching results and sentiment analysis results. For example, if the degree of match is high and the user is deemed to be at ease, access is granted; if there is strong anxiety, further confirmation is requested. The user is notified of the result through their device.
[0199] Step 6:
[0200] The server records these results and uses them for later analysis and system improvement. This information is then stored again in the database and used as data to contribute to future authentication task generation and analysis processes.
[0201] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0202] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0203] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.
[0204] [Second Embodiment]
[0205] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0206] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0207] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0208] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0209] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0210] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0211] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0212] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0213] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0214] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0215] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0216] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0217] The present invention is a system for making the user authentication process dynamic and secure. The system comprises means for generating, storing user information, generating dynamic authentication questions, receiving user responses, matching received responses with user information, and determining whether to grant or deny access based on the matching result.
[0218] The system's program first stores personal information and historical data provided by the user on the server. This ensures that the information necessary to identify each user is compiled. Next, when a user attempts to access the system, an authentication request is sent to the server via the terminal.
[0219] The server uses an artificial intelligence model to generate dynamic security questions based on stored user information. These questions are randomly generated from past user data and are different each time, providing a higher level of security compared to fixed passwords.
[0220] For example, a question like "What was the name of the first country you visited?" might be generated based on places the user has visited or products they have purchased in the past. The user enters the correct answer to the question displayed on their device. The device sends this answer to the server, which then compares the received answer with stored data.
[0221] If the verification is successful, the server sends a notification of successful authentication to the terminal, and the user is granted access to the system. Conversely, if the verification fails, the server sends a notification of authentication failure to the terminal, and the user is required to try authenticating again.
[0222] In this way, users can enjoy a secure and efficient authentication experience without relying on their memory. This invention is particularly applicable to many online services where security is critical.
[0223] The following describes the processing flow.
[0224] Step 1:
[0225] When a user accesses the system for the first time, they use a terminal to enter and register personal information and history data. This information is sent to the server and stored in the database.
[0226] Step 2:
[0227] When a user initiates authentication to the system, an authentication request is sent from the terminal to the server. The server then prepares to accept the request.
[0228] Step 3:
[0229] The server uses an artificial intelligence model to generate dynamic authentication questions based on stored user information. The generated questions change each time and are associated with specific user information.
[0230] Step 4:
[0231] The generated authentication question is sent from the server to the terminal and presented to the user. The user reviews the question and answers appropriately.
[0232] Step 5:
[0233] The user's input is sent to the server via the terminal. The server compares the received input with stored user information to evaluate its accuracy.
[0234] Step 6:
[0235] The server makes a decision to grant or deny access based on the matching result. If the matching is successful, it sends the result to the terminal and grants the user access to the system. If it fails, it sends a message prompting the user to try again.
[0236] Throughout this entire process, users can receive dynamic and secure authentication.
[0237] (Example 1)
[0238] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0239] In today's digital environment, authentication using fixed passwords is increasing security risks. Password leaks and unauthorized access using specific passwords are serious problems. Therefore, there is a need for new authentication methods that improve user management and access security.
[0240] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0241] In this invention, the server includes a data storage means for storing user information, a communication device for receiving authentication requests, and a data generation means for generating dynamic authentication questions based on the stored information. This enables the generation of dynamic and unique questions each time based on the user's past history, resulting in a highly secure authentication level.
[0242] "User information" refers to individual user data within the system, including personally identifiable information and historical data necessary for authentication.
[0243] "Data storage means" refers to technical means for efficiently and securely storing user information and historical data, and generally includes relational databases and cloud storage.
[0244] A "communication device" is a technical means for sending and receiving data such as authentication requests between a user and a server, and includes network interfaces and protocols.
[0245] "Data generation means" refers to technical means for constructing dynamic authentication questions based on the user's stored information.
[0246] An "interface" is the environment or means by which a user interacts with a system, and is usually implemented through a display or input device.
[0247] "Data matching means" refers to technical methods for comparing input obtained from the user with stored information, thereby enabling accurate authentication.
[0248] A "determination means" is a technical means that provides a decision-making function for granting or denying access rights based on the results of data matching.
[0249] A "machine learning model" refers to a computer algorithm used to automatically learn from past data and generate authentication questions.
[0250] This invention relates to a security-focused dynamic authentication system. The system securely manages user information and generates dynamic, unique authentication questions to prevent unauthorized access.
[0251] The server first uses a relational database management system to store personal information and behavioral history obtained from users. This database can utilize software such as MySQL or PostgreSQL. User information forms the basis for maintaining consistent authentication standards for each user.
[0252] The terminal is responsible for sending authentication requests when a user attempts to access the system. The HTTPS protocol is used for this communication to ensure the secure transmission of data. The terminal reliably transmits the information entered by the user to the server.
[0253] The server generates dynamic authentication questions using a generative AI model based on stored user information. This process utilizes language models such as OpenAI GPT. This enables a variety of questions tailored to each user's history, thereby improving security levels.
[0254] As a concrete example, a question such as "What was the last city you visited?" is generated based on information about places the user has visited in the past. The user answers this question on their device, and the server receives the answer. This answer is then verified by a data matching system built using Python and TensorFlow.
[0255] The server determines whether the response matches the user's stored information and, based on the result, approves or denies the user's access.
[0256] Examples of prompt statements to be input to a generative AI model include the following:
[0257] "Generate new authentication questions based on past travel history." "Create dynamic authentication questions from information on recently purchased items."
[0258] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0259] Step 1:
[0260] The server stores personal information and historical data submitted by users during registration in a database. As input, users provide their personal information (e.g., name, email address) and optional historical data. The server receives this data and stores it in a relational database using data storage methods; this data serves as the basis for future authentication processes.
[0261] Step 2:
[0262] The user initiates an authentication attempt on their device to access the system. The user accesses the login screen on their device and submits an authentication request. Upon receiving this input, the device sends the authentication request to the server using the HTTPS protocol. The output here indicates that the authentication request has been securely delivered to the server.
[0263] Step 3:
[0264] After receiving an authentication request from a user, the server references stored information and uses a generative AI model to create dynamic authentication questions. The user's stored history data is referenced as input. The server analyzes this data and uses the generative AI model to generate questions such as, for example, "What was the first item you purchased?". The output is the dynamically generated authentication question.
[0265] Step 4:
[0266] The terminal displays authentication questions sent from the server to the user. The user answers the questions based on past experience and memory. The input is a manual response based on the user's memory. This response is stored on the terminal, and the user's response is sent to the server as output.
[0267] Step 5:
[0268] The server receives responses from users and compares them with information stored in a database. The inputs used are the user's responses and the stored information in the database. Machine learning models such as TensorFlow are used as data matching tools to determine if there is a match. The output is the matching result, which determines the next step.
[0269] Step 6:
[0270] Based on the matching results, the server makes a decision to approve or deny the user's access. If approved, the server sends an access permission notification to the terminal, and the user can successfully log in to the system. If denied, the server notifies the terminal that authentication failed and instructs the user to try again. The output is a notification of success or failure as a result of the authentication process.
[0271] (Application Example 1)
[0272] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0273] In recent years, the proliferation of electronic payment services has increased security risks, and there is a need for effective authentication methods to ensure user safety. Traditional fixed passwords and question-based authentication methods carry a high risk of unauthorized access, and a dynamic and secure authentication method is needed to overcome this. In particular, there is a need for a method that prevents unauthorized access while not compromising user convenience, such as by using different questions for each transaction.
[0274] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0275] In this invention, the server includes a generation mechanism, a mechanism for storing user information, and a mechanism for verifying the user's identity in the payment process based on dynamic authentication questions. This enables secure and efficient electronic payments by generating different authentication questions each time from information such as transaction history and visit history.
[0276] A "generating mechanism" is a technical means for creating dynamic authentication questions.
[0277] A "mechanism for storing user information" refers to a technical means for recording and retaining a user's personal information and transaction history.
[0278] A "mechanism for verifying user identity in payment processing based on dynamic authentication questions" is a technical means of using generated authentication questions to verify the user's identity and securely process payments.
[0279] An "artificial intelligence model" is a computer program designed to perform data analysis and reasoning, and is used to dynamically generate authentication questions.
[0280] "Transaction history" refers to a record of all purchases and payments a user has made in the past.
[0281] "Visit history" refers to a record of stores and places that a user has visited in the past.
[0282] A "dynamic authentication question" is a question of a different format each time, generated based on the user's sensitive information and used to prevent unauthorized access.
[0283] The system for implementing this invention first has a mechanism where the server stores the user's personal information, past transaction history, and store visit history. Also, the server can create dynamic authentication questions based on this historical data using a generation AI model. When the user attempts an electronic payment, the terminal sends an authentication request to the server, and the server generates a dynamic authentication question from the stored information and sends it to the terminal.
[0284] The user checks the authentication question displayed on the terminal and provides an accurate answer. The terminal sends this answer to the server, and the server compares it with the stored information. If the comparison is successful, the server can permit the user's payment and ensure a secure transaction. In this process, programming languages such as Python are used, and it is common to use a database management system (for example, MySQL or PostgreSQL) to manage user information.
[0285] As a specific example, when a user purchases a product on an online shopping site, a question such as "What was the category you last purchased?" is generated based on that transaction history. If the user answers "electronics" and it matches the past history, the payment will proceed smoothly.
[0286] Examples of prompt texts for the generation AI model could be sentences like the following:
[0287] "Generate a dynamic authentication question based on the user's past history. Historical data: Product category: electronics, Visit destination: Café X. Example: 'What was the category of the last product purchased?'"
[0288] In this way, users can make payments safely and quickly by going through a different authentication process each time.
[0289] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0290] Step 1:
[0291] The server stores personal information obtained during user registration, as well as past transaction and visit history, in a database. It processes data by receiving personal information from users as input and storing it in the database as output. This ensures that the data necessary for user identification is prepared.
[0292] Step 2:
[0293] When a user attempts to make an electronic payment using a terminal, the terminal sends the request to the server. It receives the payment request as input and transmits that request to the server as output. This initiates the payment process.
[0294] Step 3:
[0295] The server generates dynamic authentication questions using a generative AI model based on stored user history data. It takes history data and prompts as input and outputs a generated question. An AI algorithm is used for this data processing, resulting in the dynamic generation of questions that differ each time.
[0296] Step 4:
[0297] The generated authentication question is sent to the device and displayed to the user. The system receives the question from the server as input and displays it on the screen as output. This allows the user to verify the question required for authentication.
[0298] Step 5:
[0299] The user enters their answer to a question on their device. The system receives the user's answer as input and sends it to the server as output. This completes the user's response process.
[0300] Step 6:
[0301] The server compares the user's response against stored historical data. It takes the user's response as input and generates an authentication result (success or failure) as output. This comparison authenticates the user.
[0302] Step 7:
[0303] If the verification is successful, the server approves the payment and notifies the terminal. Conversely, if the verification fails, a notification is sent to the terminal prompting a retry. The authentication result is received as input and notified to the user as output. This establishes a secure payment process.
[0304] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0305] The present invention provides a system for enhancing the user authentication process and strengthening security, comprising means for generating, storing, generating dynamic authentication questions, receiving user responses, matching received responses with user information, determining whether to grant or deny access based on the matching results, and an emotion engine that recognizes the user's emotions.
[0306] This system's program is designed to implement multi-layered authentication. First, when accessing the system, the user enters personal information using a terminal and sends it to the server. The server stores this information in a database and uses it in the authentication process.
[0307] When the authentication request is sent from the terminal to the server, the server uses an artificial intelligence model to generate dynamic authentication questions. The content of the generated questions is based on the user's saved information and is specific to this authentication.
[0308] In addition, the emotion engine analyzes the user's expression and voice when answering, and recognizes the emotional state. The emotional data when the user answers the question is sent to the server and used as the context of the user's answer. For example, when the user is nervous, the emotion engine can sense this state and perform processing according to the verification process.
[0309] As a specific example, consider the scenario where the user answers the question "What is the name of the country you first visited?". At this time, based on the user's expression and voice tone on the terminal, the emotion engine analyzes whether the user is confident or feels uneasy about the answer. The server makes a judgment while considering this emotional data and comparing the user's answer with the saved information.
[0310] In this way, the user can enjoy safe and flexible authentication without relying too much on memory. The present invention is applicable to various digital authentication systems as a means to enrich the user experience and improve security.
[0311] The following describes the processing flow.
[0312] Step 1:
[0313] When the user first accesses the system, the terminal is used to input and register the necessary personal information and historical data. These information are sent to the server and safely stored in the database.
[0314] Step 2:
[0315] When the user attempts to log in to the system, an authentication request is sent from the terminal to the server. Upon receiving this request, the server starts the authentication process for the user.
[0316] Step 3:
[0317] The server uses an artificial intelligence model to generate dynamic authentication questions based on stored user information. The generated questions are selected based on the user's past behavior. These questions are then sent from the server to the terminal and presented to the user.
[0318] Step 4:
[0319] The user reads the authentication questions presented to them and enters their answers into the device. During this process, the emotion engine analyzes the user's facial expressions and voice in real time to recognize the user's emotional state.
[0320] Step 5:
[0321] The device sends the user's response data and the emotion data recognized by the emotion engine to the server. The server receives this data and compares the responses with the stored user information.
[0322] Step 6:
[0323] The server evaluates the accuracy of the response and the user's emotional state based on sentiment data, and decides to grant or deny access based on the matching results. This result is sent to the terminal and notified to the user. If authentication is successful, the user is granted access to the system. If unsuccessful, the user may be asked to retry.
[0324] This allows users to have a more secure and intuitive authentication experience.
[0325] (Example 2)
[0326] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0327] In recent years, with the advancement of digitalization, there has been a growing demand for enhanced security in authentication processes that utilize personal information. However, traditional methods rely on static information and carry a high risk of misuse. Furthermore, improving security without compromising the user experience remains a challenge.
[0328] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0329] In this invention, the server includes means for generating, means for storing personal data, means for generating dynamic authentication questions, and means for performing sentiment analysis. This enhances security by presenting different authentication questions each time, and in addition, enables more flexible and reliable authentication by taking into account the user's emotional state.
[0330] "Generating means" refers to components that have the function of creating user information and authentication questions.
[0331] "Means of storing personal data" refers to technologies for securely recording and storing personal information provided by users.
[0332] A "means for generating dynamic authentication questions" refers to a technology for generating and presenting context-dependent authentication questions, rather than static ones.
[0333] "Means for receiving user responses" refers to an implementation that receives the content of the user's response to an authentication question.
[0334] "Means for matching received responses with personal data" refers to a system for comparing collected data with user responses to determine whether they match or not.
[0335] "Methods for performing emotion analysis" refer to technologies that identify a user's emotional state from their facial expressions and voice, and utilize this information as data.
[0336] "Means for determining whether to grant or deny access based on matching results" refers to a function that determines whether or not a user can access the system based on the results of data comparison.
[0337] This invention is a system for enhancing user authentication, and its implementation is as follows: The user inputs personal data using a terminal and sends it to a server. The terminal is equipped with a camera and microphone, which can capture the user's facial expressions and voice. The server stores this information in a database and uses it for the authentication process. The server uses a generative AI model to generate dynamic authentication questions. This model generates contextual questions from the user's stored data and is implemented using, for example, Python. Specifically, the user will be asked personally relevant questions such as, "What was the first product you purchased?" The user answers these questions through the terminal.
[0338] To perform sentiment analysis, the device utilizes open-source computer vision libraries and machine learning frameworks. Specifically, it uses OpenCV and TensorFlow to analyze the user's facial features and voice tone in real time to evaluate the user's emotional state. For example, it can determine whether the user is confident or nervous when answering questions. This sentiment information is sent to a server and compared with the user's responses to make a final decision on access permission.
[0339] In this way, the authentication process is secured at multiple layers, improving the user experience. This invention enhances the reliability of authentication, allowing users to use the system smoothly while maintaining security. An example of a specific prompt is, "Generate questions about the user's past travel destinations." Using this prompt, the generation AI model can construct appropriate authentication questions.
[0340] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0341] Step 1:
[0342] Users enter personal information using their devices and transmit the data. This personal information may include name, email address, and address. The device sends this information to the server. The entered data is then converted for storage in the database.
[0343] Step 2:
[0344] The server receives personal information sent from the terminal and stores it in the database. The received data is stored in the database as user authentication information. Secure storage methods are applied here, and measures are taken to prevent unauthorized access.
[0345] Step 3:
[0346] The server receives an authentication request from the terminal and generates dynamic authentication questions. In this process, it uses a generation AI model to generate questions related to pre-stored personal information. For example, a question such as "What country did you last visit?" might be created.
[0347] Step 4:
[0348] The terminal displays an authentication question generated by the server to the user. The user enters an answer to this question. The input is sent to the server in real time.
[0349] Step 5:
[0350] The device's camera and microphone capture the user's facial expressions and voice as they answer questions, and perform emotion analysis. Libraries such as OpenCV and TensorFlow are used to analyze the user's emotional state. The analysis results are sent to a server and output as user emotion data.
[0351] Step 6:
[0352] The server receives user responses and sentiment data and compares them with information stored in the database. By comparing the input data with the stored information, it determines whether the responses are accurate and whether the user's sentiment is stable. Based on the results, it grants or denies access.
[0353] Step 7:
[0354] Finally, the server notifies the terminal of the access decision based on the matching results. Based on the notification, the user checks whether access to the system is permitted. This completes the authentication process.
[0355] (Application Example 2)
[0356] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0357] In recent years, with the spread of electronic transactions, unauthorized access to personal information and data theft have increased. Therefore, improving the security of user authentication processes has become an urgent necessity. However, existing authentication technologies rely on fixed questions and passwords, making them easily bypassed by attackers. Furthermore, they do not consider the user's psychological state, potentially compromising the user experience. Overcoming these problems and providing a more secure and user-friendly authentication system is essential.
[0358] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0359] In this invention, the server includes means for generating, means for storing user attribute information, means for dynamically generating authentication tasks, and means for acquiring sentiment analysis data. This makes it possible to provide a flexible authentication process tailored to each individual based on dynamically generated authentication tasks and the user's sentiment state, thereby reducing the risk of unauthorized access.
[0360] "Means of generation" refers to a function that automatically creates specific information or data as part of a system.
[0361] "Means for storing user attribute information" refers to a function that stores personal data about each user and keeps it available for reference as needed.
[0362] A "means for dynamically generating authentication challenges" refers to a function that generates different authentication problems depending on the user's specific information and circumstances.
[0363] "Means for receiving user responses" refers to a function that takes in user-inputted and selected responses and makes them available within the system for processing.
[0364] "Means for matching received responses with user attributes" refers to a function that compares acquired responses with pre-stored user information and verifies the degree of match.
[0365] "Means for acquiring emotion analysis data" refers to a function that analyzes the user's emotional state from their voice, facial expressions, etc., and acquires the results as data.
[0366] "Means for determining whether to approve or deny access based on matching results and sentiment analysis data" refers to a function that determines whether a user can access the system based on the degree of match and sentiment evaluation obtained through verification.
[0367] The system necessary to implement this invention consists of a cloud-based server and a user's mobile terminal. The server includes means for generating data, means for storing user attribute information, means for dynamically generating authentication tasks, and means for acquiring sentiment analysis data. The program is implemented in a programming language such as Python, and TensorFlow or PyTorch are used as AI models. In addition, OpenCV and Google's natural language processing API are utilized for sentiment recognition.
[0368] When a user accesses or conducts a transaction via a terminal, the server first stores the user's attribute information in a database. During a transaction, the server utilizes a generative AI model to generate a dynamic authentication task based on the user's past attribute information. While the user answers this task, the terminal uses its camera and microphone to record the user's facial expressions and voice. This information is sent to the server as sentiment analysis data and used to recognize and judge the user's emotional response.
[0369] As a concrete example, when a user uses an online travel service, the server generates questions related to places the user has previously visited. During this process, sentiment analysis is used to assess the user's excitement and sense of security, and then determine whether the answer is correct. This process ensures authentication that prevents unauthorized access while minimizing user stress.
[0370] Examples of prompts to be input into the generation AI model include: "Generate questions that prompt the user to confirm memories based on their past visit information. Also, read expressions of anxiety from the user's responses, evaluate their trustworthiness, and then decide whether to allow payment." This will create a system that balances authentication accuracy and usability.
[0371] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0372] Step 1:
[0373] The user starts up the device and attempts to access online services. The device first inputs user attribute information (e.g., past visited locations and transaction history) and sends it to the server. This updates the user-specific data on the server side.
[0374] Step 2:
[0375] The server stores the received attribute information in a database. Based on this stored information, a generative AI model is used to generate dynamic authentication tasks tailored to the user. Specifically, prompts are used to instruct the model to create a task such as "generate questions that prompt the user to confirm memories based on information about places they have visited in the past."
[0376] Step 3:
[0377] The generated authentication task is sent to the device and presented to the user. The user answers the task, and the answer is sent back to the server via the device. During this response process, the device simultaneously uses its camera and microphone to sense the user's facial expressions and voice, and collects emotion analysis data.
[0378] Step 4:
[0379] The server processes user responses and sentiment analysis data received from the terminal. The server matches the user's responses with attribute information in the database and calculates the degree of match. Furthermore, the sentiment analysis data is evaluated using OpenCV and natural language processing APIs to assess the user's emotional response (e.g., whether they feel safe or anxious).
[0380] Step 5:
[0381] The server decides whether to grant or deny access based on the matching results and sentiment analysis results. For example, if the degree of match is high and the user is deemed to be at ease, access is granted; if there is strong anxiety, further confirmation is requested. The user is notified of the result through their device.
[0382] Step 6:
[0383] The server records these results and uses them for later analysis and system improvement. This information is then stored again in the database and used as data to contribute to future authentication task generation and analysis processes.
[0384] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0385] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0386] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.
[0387] [Third Embodiment]
[0388] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0389] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0390] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0391] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0392] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0393] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0394] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0395] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0396] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0397] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0398] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0399] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".
[0400] The present invention is a system for making the user authentication process dynamic and secure. The system comprises means for generating, storing user information, generating dynamic authentication questions, receiving user responses, matching received responses with user information, and determining whether to grant or deny access based on the matching result.
[0401] The system's program first stores personal information and historical data provided by the user on the server. This ensures that the information necessary to identify each user is compiled. Next, when a user attempts to access the system, an authentication request is sent to the server via the terminal.
[0402] The server uses an artificial intelligence model to generate dynamic security questions based on stored user information. These questions are randomly generated from past user data and are different each time, providing a higher level of security compared to fixed passwords.
[0403] For example, a question like "What was the name of the first country you visited?" might be generated based on places the user has visited or products they have purchased in the past. The user enters the correct answer to the question displayed on their device. The device sends this answer to the server, which then compares the received answer with stored data.
[0404] If the verification is successful, the server sends a notification of successful authentication to the terminal, and the user is granted access to the system. Conversely, if the verification fails, the server sends a notification of authentication failure to the terminal, and the user is required to try authenticating again.
[0405] In this way, users can enjoy a secure and efficient authentication experience without relying on their memory. This invention is particularly applicable to many online services where security is critical.
[0406] The following describes the processing flow.
[0407] Step 1:
[0408] When a user accesses the system for the first time, they use a terminal to enter and register personal information and history data. This information is sent to the server and stored in the database.
[0409] Step 2:
[0410] When a user initiates authentication to the system, an authentication request is sent from the terminal to the server. The server then prepares to accept the request.
[0411] Step 3:
[0412] The server uses an artificial intelligence model to generate dynamic authentication questions based on stored user information. The generated questions change each time and are associated with specific user information.
[0413] Step 4:
[0414] The generated authentication question is sent from the server to the terminal and presented to the user. The user reviews the question and answers appropriately.
[0415] Step 5:
[0416] The user's input is sent to the server via the terminal. The server compares the received input with stored user information to evaluate its accuracy.
[0417] Step 6:
[0418] The server makes a decision to grant or deny access based on the matching result. If the matching is successful, it sends the result to the terminal and grants the user access to the system. If it fails, it sends a message prompting the user to try again.
[0419] Throughout this entire process, users can receive dynamic and secure authentication.
[0420] (Example 1)
[0421] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0422] In today's digital environment, authentication using fixed passwords is increasing security risks. Password leaks and unauthorized access using specific passwords are serious problems. Therefore, there is a need for new authentication methods that improve user management and access security.
[0423] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0424] In this invention, the server includes a data storage means for storing user information, a communication device for receiving authentication requests, and a data generation means for generating dynamic authentication questions based on the stored information. This enables the generation of dynamic and unique questions each time based on the user's past history, resulting in a highly secure authentication level.
[0425] "User information" refers to individual user data within the system, including personally identifiable information and historical data necessary for authentication.
[0426] "Data storage means" refers to technical means for efficiently and securely storing user information and historical data, and generally includes relational databases and cloud storage.
[0427] A "communication device" is a technical means for sending and receiving data such as authentication requests between a user and a server, and includes network interfaces and protocols.
[0428] "Data generation means" refers to technical means for constructing dynamic authentication questions based on the user's stored information.
[0429] An "interface" is the environment or means by which a user interacts with a system, and is usually implemented through a display or input device.
[0430] "Data matching means" refers to technical methods for comparing input obtained from the user with stored information, thereby enabling accurate authentication.
[0431] A "determination means" is a technical means that provides a decision-making function for granting or denying access rights based on the results of data matching.
[0432] A "machine learning model" refers to a computer algorithm used to automatically learn from past data and generate authentication questions.
[0433] This invention relates to a security-focused dynamic authentication system. The system securely manages user information and generates dynamic, unique authentication questions to prevent unauthorized access.
[0434] The server first uses a relational database management system to store personal information and behavioral history obtained from users. This database can utilize software such as MySQL or PostgreSQL. User information forms the basis for maintaining consistent authentication standards for each user.
[0435] The terminal is responsible for sending authentication requests when a user attempts to access the system. The HTTPS protocol is used for this communication to ensure the secure transmission of data. The terminal reliably transmits the information entered by the user to the server.
[0436] The server generates dynamic authentication questions using a generative AI model based on stored user information. This process utilizes language models such as OpenAI GPT. This enables a variety of questions tailored to each user's history, thereby improving security levels.
[0437] As a concrete example, a question such as "What was the last city you visited?" is generated based on information about places the user has visited in the past. The user answers this question on their device, and the server receives the answer. This answer is then verified by a data matching system built using Python and TensorFlow.
[0438] The server determines whether the response matches the user's stored information and, based on the result, approves or denies the user's access.
[0439] Examples of prompt statements to be input to a generative AI model include the following:
[0440] "Generate new authentication questions based on past travel history." "Create dynamic authentication questions from information on recently purchased items."
[0441] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0442] Step 1:
[0443] The server stores personal information and historical data submitted by users during registration in a database. As input, users provide their personal information (e.g., name, email address) and optional historical data. The server receives this data and stores it in a relational database using data storage methods; this data serves as the basis for future authentication processes.
[0444] Step 2:
[0445] The user initiates an authentication attempt on their device to access the system. The user accesses the login screen on their device and submits an authentication request. Upon receiving this input, the device sends the authentication request to the server using the HTTPS protocol. The output here indicates that the authentication request has been securely delivered to the server.
[0446] Step 3:
[0447] After receiving an authentication request from a user, the server references stored information and uses a generative AI model to create dynamic authentication questions. The user's stored history data is referenced as input. The server analyzes this data and uses the generative AI model to generate questions such as, for example, "What was the first item you purchased?". The output is the dynamically generated authentication question.
[0448] Step 4:
[0449] The terminal displays authentication questions sent from the server to the user. The user answers the questions based on past experience and memory. The input is a manual response based on the user's memory. This response is stored on the terminal, and the user's response is sent to the server as output.
[0450] Step 5:
[0451] The server receives responses from users and compares them with information stored in a database. The inputs used are the user's responses and the stored information in the database. Machine learning models such as TensorFlow are used as data matching tools to determine if there is a match. The output is the matching result, which determines the next step.
[0452] Step 6:
[0453] Based on the matching results, the server makes a decision to approve or deny the user's access. If approved, the server sends an access permission notification to the terminal, and the user can successfully log in to the system. If denied, the server notifies the terminal that authentication failed and instructs the user to try again. The output is a notification of success or failure as a result of the authentication process.
[0454] (Application Example 1)
[0455] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0456] In recent years, the proliferation of electronic payment services has increased security risks, and there is a need for effective authentication methods to ensure user safety. Traditional fixed passwords and question-based authentication methods carry a high risk of unauthorized access, and a dynamic and secure authentication method is needed to overcome this. In particular, there is a need for a method that prevents unauthorized access while not compromising user convenience, such as by using different questions for each transaction.
[0457] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0458] In this invention, the server includes a generation mechanism, a mechanism for storing user information, and a mechanism for verifying the user's identity in the payment process based on dynamic authentication questions. This enables secure and efficient electronic payments by generating different authentication questions each time from information such as transaction history and visit history.
[0459] A "generating mechanism" is a technical means for creating dynamic authentication questions.
[0460] A "mechanism for storing user information" refers to a technical means for recording and retaining a user's personal information and transaction history.
[0461] A "mechanism for verifying user identity in payment processing based on dynamic authentication questions" is a technical means of using generated authentication questions to verify the user's identity and securely process payments.
[0462] An "artificial intelligence model" is a computer program designed to perform data analysis and reasoning, and is used to dynamically generate authentication questions.
[0463] "Transaction history" refers to a record of all purchases and payments a user has made in the past.
[0464] "Visit history" refers to a record of stores and places that a user has visited in the past.
[0465] A "dynamic authentication question" is a question that is generated based on the user's sensitive information and is in a different format each time, and is used to prevent unauthorized access.
[0466] The system implementing this invention first has a mechanism in which a server stores the user's personal information, past transaction history, and visit history. The server can also use a generation AI model to create dynamic authentication questions based on this historical data. When a user attempts electronic payment, the terminal sends an authentication request to the server, and the server generates dynamic authentication questions from the stored information and sends them to the terminal.
[0467] The user reviews the authentication question displayed on their device and provides an accurate answer. The device sends this answer to the server, which verifies it against stored information. If the verification is successful, the server can authorize the user's payment, ensuring a secure transaction. This process typically uses programming languages such as Python, and a database management system (e.g., MySQL or PostgreSQL) is commonly used to manage user information.
[0468] As a concrete example, when a user purchases an item on an online shopping site, a question is generated based on their transaction history: "What category did you last purchase in?" If the user answers "electronics" and this matches their past history, the payment process proceeds smoothly.
[0469] Examples of prompts for a generative AI model include the following:
[0470] "Generate dynamic authentication questions based on the user's past history. History data: Product category: Electronics, Place visited: Cafe X. Example: 'What category was the last product you purchased?'"
[0471] In this way, users can make payments safely and quickly by going through a different authentication process each time.
[0472] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0473] Step 1:
[0474] The server stores personal information obtained during user registration, as well as past transaction and visit history, in a database. It processes data by receiving personal information from users as input and storing it in the database as output. This ensures that the data necessary for user identification is prepared.
[0475] Step 2:
[0476] When a user attempts to make an electronic payment using a terminal, the terminal sends the request to the server. It receives the payment request as input and transmits that request to the server as output. This initiates the payment process.
[0477] Step 3:
[0478] The server generates dynamic authentication questions using a generative AI model based on stored user history data. It takes history data and prompts as input and outputs a generated question. An AI algorithm is used for this data processing, resulting in the dynamic generation of questions that differ each time.
[0479] Step 4:
[0480] The generated authentication question is sent to the device and displayed to the user. The system receives the question from the server as input and displays it on the screen as output. This allows the user to verify the question required for authentication.
[0481] Step 5:
[0482] The user enters their answer to a question on their device. The system receives the user's answer as input and sends it to the server as output. This completes the user's response process.
[0483] Step 6:
[0484] The server compares the user's response against stored historical data. It takes the user's response as input and generates an authentication result (success or failure) as output. This comparison authenticates the user.
[0485] Step 7:
[0486] If the verification is successful, the server approves the payment and notifies the terminal. Conversely, if the verification fails, a notification is sent to the terminal prompting a retry. The authentication result is received as input and notified to the user as output. This establishes a secure payment process.
[0487] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0488] The present invention provides a system for enhancing the user authentication process and strengthening security, comprising means for generating, storing, generating dynamic authentication questions, receiving user responses, matching received responses with user information, determining whether to grant or deny access based on the matching results, and an emotion engine that recognizes the user's emotions.
[0489] This system's program is designed to implement multi-layered authentication. First, when accessing the system, the user enters personal information using a terminal and sends it to the server. The server stores this information in a database and uses it in the authentication process.
[0490] When an authentication request is sent from the terminal to the server, the server uses an artificial intelligence model to generate dynamic authentication questions. The content of the generated questions is based on the user's stored information and is specific to this authentication process.
[0491] In addition, the emotion engine analyzes the user's facial expressions and voice during responses to recognize their emotional state. The emotional data collected when the user answers questions is sent to the server and used as context for the user's response. For example, if a user is nervous, the emotion engine can detect this state and perform appropriate processing based on the matching process.
[0492] As a concrete example, consider a scenario where a user answers the question, "What was the name of the first country you visited?" In this case, the emotion engine analyzes whether the user is confident or anxious about the answer based on the user's facial expressions and tone of voice on the device. The server then considers this emotion data and compares the user's answer with stored information to make a decision.
[0493] In this way, users can enjoy secure and flexible authentication without relying excessively on memory. This invention is applicable to various digital authentication systems as a means of enriching the user experience and improving security.
[0494] The following describes the processing flow.
[0495] Step 1:
[0496] When a user accesses the system for the first time, they use a terminal to enter and register necessary personal information and history data. This information is sent to the server and securely stored in a database.
[0497] Step 2:
[0498] When a user attempts to log in to the system, an authentication request is sent from the terminal to the server. Upon receiving this request, the server initiates the authentication process for the user.
[0499] Step 3:
[0500] The server uses an artificial intelligence model to generate dynamic authentication questions based on stored user information. The generated questions are selected based on the user's past behavior. These questions are then sent from the server to the terminal and presented to the user.
[0501] Step 4:
[0502] The user reads the authentication questions presented to them and enters their answers into the device. During this process, the emotion engine analyzes the user's facial expressions and voice in real time to recognize the user's emotional state.
[0503] Step 5:
[0504] The device sends the user's response data and the emotion data recognized by the emotion engine to the server. The server receives this data and compares the responses with the stored user information.
[0505] Step 6:
[0506] The server evaluates the accuracy of the response and the user's emotional state based on sentiment data, and decides to grant or deny access based on the matching results. This result is sent to the terminal and notified to the user. If authentication is successful, the user is granted access to the system. If unsuccessful, the user may be asked to retry.
[0507] This allows users to have a more secure and intuitive authentication experience.
[0508] (Example 2)
[0509] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0510] In recent years, with the advancement of digitalization, there has been a growing demand for enhanced security in authentication processes that utilize personal information. However, traditional methods rely on static information and carry a high risk of misuse. Furthermore, improving security without compromising the user experience remains a challenge.
[0511] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0512] In this invention, the server includes means for generating, means for storing personal data, means for generating dynamic authentication questions, and means for performing sentiment analysis. This enhances security by presenting different authentication questions each time, and in addition, by taking into account the user's emotional state, more flexible and reliable authentication becomes possible.
[0513] "Generating means" refers to components that have the function of creating user information and authentication questions.
[0514] "Means of storing personal data" refers to technologies for securely recording and storing personal information provided by users.
[0515] A "means for generating dynamic authentication questions" refers to a technology for generating and presenting context-dependent authentication questions, rather than static ones.
[0516] "Means for receiving user responses" refers to an implementation that receives the content of the user's response to an authentication question.
[0517] "Means for matching received responses with personal data" refers to a system for comparing collected data with user responses to determine whether they match or not.
[0518] "Methods for performing emotion analysis" refer to technologies that identify a user's emotional state from their facial expressions and voice, and utilize this information as data.
[0519] "Means for determining whether to grant or deny access based on matching results" refers to a function that determines whether a user can access the system based on the results of data comparison.
[0520] This invention is a system for enhancing user authentication, and its implementation is as follows: The user inputs personal data using a terminal and sends it to a server. The terminal is equipped with a camera and microphone, which can capture the user's facial expressions and voice. The server stores this information in a database and uses it for the authentication process. The server uses a generative AI model to generate dynamic authentication questions. This model generates contextual questions from the user's stored data and is implemented using, for example, Python. Specifically, the user will be asked personally relevant questions such as, "What was the first product you purchased?" The user answers these questions through the terminal.
[0521] To perform sentiment analysis, the device utilizes open-source computer vision libraries and machine learning frameworks. Specifically, it uses OpenCV and TensorFlow to analyze the user's facial features and voice tone in real time to evaluate the user's emotional state. For example, it can determine whether the user is confident or nervous when answering questions. This sentiment information is sent to a server and compared with the user's responses to make a final decision on access permission.
[0522] In this way, the authentication process is secured at multiple layers, improving the user experience. This invention enhances the reliability of authentication, allowing users to use the system smoothly while maintaining security. An example of a specific prompt is, "Generate questions about the user's past travel destinations." Using this prompt, the generation AI model can construct appropriate authentication questions.
[0523] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0524] Step 1:
[0525] Users enter personal information using their devices and transmit the data. This personal information may include name, email address, and address. The device sends this information to the server. The entered data is then converted for storage in the database.
[0526] Step 2:
[0527] The server receives personal information sent from the terminal and stores it in the database. The received data is stored in the database as user authentication information. Secure storage methods are applied here, and measures are taken to prevent unauthorized access.
[0528] Step 3:
[0529] The server receives an authentication request from the terminal and generates dynamic authentication questions. In this process, it uses a generation AI model to generate questions related to pre-stored personal information. For example, a question such as "What country did you last visit?" might be created.
[0530] Step 4:
[0531] The terminal displays an authentication question generated by the server to the user. The user enters an answer to this question. The input is sent to the server in real time.
[0532] Step 5:
[0533] The device's camera and microphone capture the user's facial expressions and voice as they answer questions, and perform emotion analysis. Libraries such as OpenCV and TensorFlow are used to analyze the user's emotional state. The analysis results are sent to a server and output as user emotion data.
[0534] Step 6:
[0535] The server receives user responses and sentiment data and compares them with information stored in the database. By comparing the input data with the stored information, it determines whether the responses are accurate and whether the user's sentiment is stable. Based on the results, it grants or denies access.
[0536] Step 7:
[0537] Finally, the server notifies the terminal of the access decision based on the matching results. Based on the notification, the user checks whether access to the system is permitted. This completes the authentication process.
[0538] (Application Example 2)
[0539] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0540] In recent years, with the spread of electronic transactions, unauthorized access to personal information and data theft have increased. Therefore, improving the security of user authentication processes has become an urgent necessity. However, existing authentication technologies rely on fixed questions and passwords, making them easily bypassed by attackers. Furthermore, they do not consider the user's psychological state, potentially compromising the user experience. Overcoming these problems and providing a more secure and user-friendly authentication system is essential.
[0541] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0542] In this invention, the server includes means for generating, means for storing user attribute information, means for dynamically generating authentication tasks, and means for acquiring sentiment analysis data. This makes it possible to provide a flexible authentication process tailored to each individual based on dynamically generated authentication tasks and the user's sentiment state, thereby reducing the risk of unauthorized access.
[0543] "Means of generation" refers to a function that automatically creates specific information or data as part of a system.
[0544] "Means for storing user attribute information" refers to a function that stores personal data about each user and keeps it available for reference as needed.
[0545] A "means for dynamically generating authentication challenges" refers to a function that generates different authentication problems depending on the user's specific information and circumstances.
[0546] "Means of receiving user responses" refers to a function that takes in user-inputted and selected responses and makes them available within the system for processing.
[0547] "Means for matching received responses with user attributes" refers to a function that compares acquired responses with pre-stored user information and verifies the degree of match.
[0548] "Means for acquiring emotion analysis data" refers to a function that analyzes the user's emotional state from their voice, facial expressions, etc., and acquires the results as data.
[0549] "Means for determining whether to approve or deny access based on matching results and sentiment analysis data" refers to a function that determines whether a user can access the system based on the degree of match and sentiment evaluation obtained through verification.
[0550] The system necessary to implement this invention consists of a cloud-based server and a user's mobile terminal. The server includes means for generating data, means for storing user attribute information, means for dynamically generating authentication tasks, and means for acquiring sentiment analysis data. The program is implemented in a programming language such as Python, and TensorFlow or PyTorch are used as AI models. In addition, OpenCV and Google's natural language processing API are utilized for sentiment recognition.
[0551] When a user accesses or conducts a transaction via a terminal, the server first stores the user's attribute information in a database. During a transaction, the server utilizes a generative AI model to generate a dynamic authentication task based on the user's past attribute information. While the user answers this task, the terminal uses its camera and microphone to record the user's facial expressions and voice. This information is sent to the server as sentiment analysis data and used to recognize and judge the user's emotional response.
[0552] As a concrete example, when a user uses an online travel service, the server generates questions related to places the user has previously visited. During this process, sentiment analysis is used to assess the user's excitement and sense of security, and then determine whether the answer is correct. This process ensures authentication that prevents unauthorized access while minimizing user stress.
[0553] Examples of prompts to be input into the generation AI model include: "Generate questions that prompt the user to confirm memories based on their past visit information. Also, read expressions of anxiety from the user's responses, evaluate their trustworthiness, and then decide whether to allow payment." This will create a system that balances authentication accuracy and usability.
[0554] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0555] Step 1:
[0556] The user starts up the device and attempts to access online services. The device first inputs user attribute information (e.g., past visited locations and transaction history) and sends it to the server. This updates the user-specific data on the server side.
[0557] Step 2:
[0558] The server stores the received attribute information in a database. Based on this stored information, a generative AI model is used to generate dynamic authentication tasks tailored to the user. Specifically, prompts are used to instruct the model to create a task such as "generate questions that prompt the user to confirm memories based on information about places they have visited in the past."
[0559] Step 3:
[0560] The generated authentication task is sent to the device and presented to the user. The user answers the task, and the answer is sent back to the server via the device. During this response process, the device simultaneously uses its camera and microphone to sense the user's facial expressions and voice, and collects emotion analysis data.
[0561] Step 4:
[0562] The server processes user responses and sentiment analysis data received from the terminal. The server matches the user's responses with attribute information in the database and calculates the degree of match. Furthermore, the sentiment analysis data is evaluated using OpenCV and natural language processing APIs to assess the user's emotional response (e.g., whether they feel safe or anxious).
[0563] Step 5:
[0564] The server decides whether to grant or deny access based on the matching results and sentiment analysis results. For example, if the degree of match is high and the user is deemed to be at ease, access is granted; if there is strong anxiety, further confirmation is requested. The user is notified of the result through their device.
[0565] Step 6:
[0566] The server records these results and uses them for later analysis and system improvement. This information is then stored again in the database and used as data to contribute to future authentication task generation and analysis processes.
[0567] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0568] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0569] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.
[0570] [Fourth Embodiment]
[0571] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0572] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0573] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0574] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0575] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0576] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0577] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0578] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0579] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0580] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0581] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0582] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0583] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0584] The present invention is a system for making the user authentication process dynamic and secure. The system comprises means for generating, storing user information, generating dynamic authentication questions, receiving user responses, matching received responses with user information, and determining whether to grant or deny access based on the matching result.
[0585] The system's program first stores personal information and historical data provided by the user on the server. This ensures that the information necessary to identify each user is compiled. Next, when a user attempts to access the system, an authentication request is sent to the server via the terminal.
[0586] The server uses an artificial intelligence model to generate dynamic security questions based on stored user information. These questions are randomly generated from past user data and are different each time, providing a higher level of security compared to fixed passwords.
[0587] For example, a question like "What was the name of the first country you visited?" might be generated based on places the user has visited or products they have purchased in the past. The user enters the correct answer to the question displayed on their device. The device sends this answer to the server, which then compares the received answer with stored data.
[0588] If the verification is successful, the server sends a notification of successful authentication to the terminal, and the user is granted access to the system. Conversely, if the verification fails, the server sends a notification of authentication failure to the terminal, and the user is required to try authenticating again.
[0589] In this way, users can enjoy a secure and efficient authentication experience without relying on their memory. This invention is particularly applicable to many online services where security is critical.
[0590] The following describes the processing flow.
[0591] Step 1:
[0592] When a user accesses the system for the first time, they use a terminal to enter and register personal information and history data. This information is sent to the server and stored in the database.
[0593] Step 2:
[0594] When a user initiates authentication to the system, an authentication request is sent from the terminal to the server. The server then prepares to accept the request.
[0595] Step 3:
[0596] The server uses an artificial intelligence model to generate dynamic authentication questions based on stored user information. The generated questions change each time and are associated with specific user information.
[0597] Step 4:
[0598] The generated authentication question is sent from the server to the terminal and presented to the user. The user reviews the question and answers appropriately.
[0599] Step 5:
[0600] The user's input is sent to the server via the terminal. The server compares the received input with stored user information to evaluate its accuracy.
[0601] Step 6:
[0602] The server makes a decision to grant or deny access based on the matching result. If the matching is successful, it sends the result to the terminal and grants the user access to the system. If it fails, it sends a message prompting the user to try again.
[0603] Throughout this entire process, users can receive dynamic and secure authentication.
[0604] (Example 1)
[0605] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0606] In today's digital environment, authentication using fixed passwords is increasing security risks. Password leaks and unauthorized access using specific passwords are serious problems. Therefore, there is a need for new authentication methods that improve user management and access security.
[0607] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0608] In this invention, the server includes a data storage means for storing user information, a communication device for receiving authentication requests, and a data generation means for generating dynamic authentication questions based on the stored information. This enables the generation of dynamic and unique questions each time based on the user's past history, resulting in a highly secure authentication level.
[0609] "User information" refers to individual user data within the system, including personally identifiable information and historical data necessary for authentication.
[0610] "Data storage means" refers to technical means for efficiently and securely storing user information and historical data, and generally includes relational databases and cloud storage.
[0611] A "communication device" is a technical means for sending and receiving data such as authentication requests between a user and a server, and includes network interfaces and protocols.
[0612] "Data generation means" refers to technical means for constructing dynamic authentication questions based on the user's stored information.
[0613] An "interface" is the environment or means by which a user interacts with a system, and is usually implemented through a display or input device.
[0614] "Data matching means" refers to technical methods for comparing input obtained from the user with stored information, thereby enabling accurate authentication.
[0615] A "determination means" is a technical means that provides a decision-making function for granting or denying access rights based on the results of data matching.
[0616] A "machine learning model" refers to a computer algorithm used to automatically learn from past data and generate authentication questions.
[0617] This invention relates to a security-focused dynamic authentication system. The system securely manages user information and generates dynamic, unique authentication questions to prevent unauthorized access.
[0618] The server first uses a relational database management system to store personal information and behavioral history obtained from users. This database can utilize software such as MySQL or PostgreSQL. User information forms the basis for maintaining consistent authentication standards for each user.
[0619] The terminal is responsible for sending authentication requests when a user attempts to access the system. The HTTPS protocol is used for this communication to ensure the secure transmission of data. The terminal reliably transmits the information entered by the user to the server.
[0620] The server generates dynamic authentication questions using a generative AI model based on stored user information. This process utilizes language models such as OpenAI GPT. This enables a variety of questions tailored to each user's history, thereby improving security levels.
[0621] As a concrete example, a question such as "What was the last city you visited?" is generated based on information about places the user has visited in the past. The user answers this question on their device, and the server receives the answer. This answer is then verified by a data matching system built using Python and TensorFlow.
[0622] The server determines whether the response matches the user's stored information and, based on the result, approves or denies the user's access.
[0623] Examples of prompt statements to be input to a generative AI model include the following:
[0624] "Generate new authentication questions based on past travel history." "Create dynamic authentication questions from information on recently purchased items."
[0625] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0626] Step 1:
[0627] The server stores personal information and historical data submitted by users during registration in a database. As input, users provide their personal information (e.g., name, email address) and optional historical data. The server receives this data and stores it in a relational database using data storage methods; this data serves as the basis for future authentication processes.
[0628] Step 2:
[0629] The user initiates an authentication attempt on their device to access the system. The user accesses the login screen on their device and submits an authentication request. Upon receiving this input, the device sends the authentication request to the server using the HTTPS protocol. The output here indicates that the authentication request has been securely delivered to the server.
[0630] Step 3:
[0631] After receiving an authentication request from a user, the server references stored information and uses a generative AI model to create dynamic authentication questions. The user's stored history data is referenced as input. The server analyzes this data and uses the generative AI model to generate questions such as, for example, "What was the first item you purchased?". The output is the dynamically generated authentication question.
[0632] Step 4:
[0633] The terminal displays authentication questions sent from the server to the user. The user answers the questions based on past experience and memory. The input is a manual response based on the user's memory. This response is stored on the terminal, and the user's response is sent to the server as output.
[0634] Step 5:
[0635] The server receives responses from users and compares them with information stored in a database. The inputs used are the user's responses and the stored information in the database. Machine learning models such as TensorFlow are used as data matching tools to determine if there is a match. The output is the matching result, which determines the next step.
[0636] Step 6:
[0637] Based on the matching results, the server makes a decision to approve or deny the user's access. If approved, the server sends an access permission notification to the terminal, and the user can successfully log in to the system. If denied, the server notifies the terminal that authentication failed and instructs the user to try again. The output is a notification of success or failure as a result of the authentication process.
[0638] (Application Example 1)
[0639] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0640] In recent years, the proliferation of electronic payment services has increased security risks, and there is a need for effective authentication methods to ensure user safety. Traditional fixed passwords and question-based authentication methods carry a high risk of unauthorized access, and a dynamic and secure authentication method is needed to overcome this. In particular, there is a need for a method that prevents unauthorized access while not compromising user convenience, such as by using different questions for each transaction.
[0641] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0642] In this invention, the server includes a generation mechanism, a mechanism for storing user information, and a mechanism for verifying the user's identity in the payment process based on dynamic authentication questions. This enables secure and efficient electronic payments by generating different authentication questions each time from information such as transaction history and visit history.
[0643] A "generating mechanism" is a technical means for creating dynamic authentication questions.
[0644] A "mechanism for storing user information" refers to a technical means for recording and retaining a user's personal information and transaction history.
[0645] A "mechanism for verifying user identity in payment processing based on dynamic authentication questions" is a technical means of using generated authentication questions to verify the user's identity and securely process payments.
[0646] An "artificial intelligence model" is a computer program designed to perform data analysis and reasoning, and is used to dynamically generate authentication questions.
[0647] "Transaction history" refers to a record of all purchases and payments a user has made in the past.
[0648] "Visit history" refers to a record of stores and places that a user has visited in the past.
[0649] A "dynamic authentication question" is a question that is generated based on the user's sensitive information and is in a different format each time, and is used to prevent unauthorized access.
[0650] The system implementing this invention first has a mechanism in which a server stores the user's personal information, past transaction history, and visit history. The server can also use a generation AI model to create dynamic authentication questions based on this historical data. When a user attempts electronic payment, the terminal sends an authentication request to the server, and the server generates dynamic authentication questions from the stored information and sends them to the terminal.
[0651] The user reviews the authentication question displayed on their device and provides an accurate answer. The device sends this answer to the server, which verifies it against stored information. If the verification is successful, the server can authorize the user's payment, ensuring a secure transaction. This process typically uses programming languages such as Python, and a database management system (e.g., MySQL or PostgreSQL) is commonly used to manage user information.
[0652] As a concrete example, when a user purchases an item on an online shopping site, a question is generated based on their transaction history: "What category did you last purchase in?" If the user answers "electronics" and this matches their past history, the payment process proceeds smoothly.
[0653] Examples of prompts for a generative AI model include the following:
[0654] "Generate dynamic authentication questions based on the user's past history. History data: Product category: Electronics, Place visited: Cafe X. Example: 'What category was the last product you purchased?'"
[0655] In this way, users can make payments safely and quickly by going through a different authentication process each time.
[0656] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0657] Step 1:
[0658] The server stores personal information obtained during user registration, as well as past transaction and visit history, in a database. It processes data by receiving personal information from users as input and storing it in the database as output. This ensures that the data necessary for user identification is prepared.
[0659] Step 2:
[0660] When a user attempts to make an electronic payment using a terminal, the terminal sends the request to the server. It receives the payment request as input and transmits that request to the server as output. This initiates the payment process.
[0661] Step 3:
[0662] The server generates dynamic authentication questions using a generative AI model based on stored user history data. It takes history data and prompts as input and outputs a generated question. An AI algorithm is used for this data processing, resulting in the dynamic generation of questions that differ each time.
[0663] Step 4:
[0664] The generated authentication question is sent to the device and displayed to the user. The system receives the question from the server as input and displays it on the screen as output. This allows the user to verify the question required for authentication.
[0665] Step 5:
[0666] The user enters their answer to a question on their device. The system receives the user's answer as input and sends it to the server as output. This completes the user's response process.
[0667] Step 6:
[0668] The server compares the user's response against stored historical data. It takes the user's response as input and generates an authentication result (success or failure) as output. This comparison authenticates the user.
[0669] Step 7:
[0670] If the verification is successful, the server approves the payment and notifies the terminal. Conversely, if the verification fails, a notification is sent to the terminal prompting a retry. The authentication result is received as input and notified to the user as output. This establishes a secure payment process.
[0671] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0672] The present invention provides a system for enhancing the user authentication process and strengthening security, comprising means for generating, storing, generating dynamic authentication questions, receiving user responses, matching received responses with user information, determining whether to grant or deny access based on the matching results, and an emotion engine that recognizes the user's emotions.
[0673] This system's program is designed to implement multi-layered authentication. First, when accessing the system, the user enters personal information using a terminal and sends it to the server. The server stores this information in a database and uses it in the authentication process.
[0674] When an authentication request is sent from the terminal to the server, the server uses an artificial intelligence model to generate dynamic authentication questions. The content of the generated questions is based on the user's stored information and is specific to this authentication process.
[0675] In addition, the emotion engine analyzes the user's facial expressions and voice during responses to recognize their emotional state. The emotional data collected when the user answers questions is sent to the server and used as context for the user's response. For example, if a user is nervous, the emotion engine can detect this state and perform appropriate processing based on the matching process.
[0676] As a concrete example, consider a scenario where a user answers the question, "What was the name of the first country you visited?" In this case, the emotion engine analyzes whether the user is confident or anxious about the answer based on the user's facial expressions and tone of voice on the device. The server then considers this emotion data and compares the user's answer with stored information to make a decision.
[0677] In this way, users can enjoy secure and flexible authentication without relying excessively on memory. This invention is applicable to various digital authentication systems as a means of enriching the user experience and improving security.
[0678] The following describes the processing flow.
[0679] Step 1:
[0680] When a user accesses the system for the first time, they use a terminal to enter and register necessary personal information and history data. This information is sent to the server and securely stored in a database.
[0681] Step 2:
[0682] When a user attempts to log in to the system, an authentication request is sent from the terminal to the server. Upon receiving this request, the server initiates the authentication process for the user.
[0683] Step 3:
[0684] The server uses an artificial intelligence model to generate dynamic authentication questions based on stored user information. The generated questions are selected based on the user's past behavior. These questions are then sent from the server to the terminal and presented to the user.
[0685] Step 4:
[0686] The user reads the authentication questions presented to them and enters their answers into the device. During this process, the emotion engine analyzes the user's facial expressions and voice in real time to recognize the user's emotional state.
[0687] Step 5:
[0688] The device sends the user's response data and the emotion data recognized by the emotion engine to the server. The server receives this data and compares the responses with the stored user information.
[0689] Step 6:
[0690] The server evaluates the accuracy of the response and the user's emotional state based on sentiment data, and decides to grant or deny access based on the matching results. This result is sent to the terminal and notified to the user. If authentication is successful, the user is granted access to the system. If unsuccessful, the user may be asked to retry.
[0691] This allows users to have a more secure and intuitive authentication experience.
[0692] (Example 2)
[0693] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0694] In recent years, with the advancement of digitalization, there has been a growing demand for enhanced security in authentication processes that utilize personal information. However, traditional methods rely on static information and carry a high risk of misuse. Furthermore, improving security without compromising the user experience remains a challenge.
[0695] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0696] In this invention, the server includes means for generating, means for storing personal data, means for generating dynamic authentication questions, and means for performing sentiment analysis. This enhances security by presenting different authentication questions each time, and in addition, by taking into account the user's emotional state, more flexible and reliable authentication becomes possible.
[0697] "Generating means" refers to components that have the function of creating user information and authentication questions.
[0698] "Means of storing personal data" refers to technologies for securely recording and storing personal information provided by users.
[0699] A "means for generating dynamic authentication questions" refers to a technology for generating and presenting context-dependent authentication questions, rather than static ones.
[0700] "Means for receiving user responses" refers to an implementation that receives the content of the user's response to an authentication question.
[0701] "Means for matching received responses with personal data" refers to a system for comparing collected data with user responses to determine whether they match or not.
[0702] "Methods for performing emotion analysis" refer to technologies that identify a user's emotional state from their facial expressions and voice, and utilize this information as data.
[0703] "Means for determining whether to grant or deny access based on matching results" refers to a function that determines whether a user can access the system based on the results of data comparison.
[0704] This invention is a system for enhancing user authentication, and its implementation is as follows: The user inputs personal data using a terminal and sends it to a server. The terminal is equipped with a camera and microphone, which can capture the user's facial expressions and voice. The server stores this information in a database and uses it for the authentication process. The server uses a generative AI model to generate dynamic authentication questions. This model generates contextual questions from the user's stored data and is implemented using, for example, Python. Specifically, the user will be asked personally relevant questions such as, "What was the first product you purchased?" The user answers these questions through the terminal.
[0705] To perform sentiment analysis, the device utilizes open-source computer vision libraries and machine learning frameworks. Specifically, it uses OpenCV and TensorFlow to analyze the user's facial features and voice tone in real time to evaluate the user's emotional state. For example, it can determine whether the user is confident or nervous when answering questions. This sentiment information is sent to a server and compared with the user's responses to make a final decision on access permission.
[0706] In this way, the authentication process is secured at multiple layers, improving the user experience. This invention enhances the reliability of authentication, allowing users to use the system smoothly while maintaining security. An example of a specific prompt is, "Generate questions about the user's past travel destinations." Using this prompt, the generation AI model can construct appropriate authentication questions.
[0707] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0708] Step 1:
[0709] Users enter personal information using their devices and transmit the data. This personal information may include name, email address, and address. The device sends this information to the server. The entered data is then converted for storage in the database.
[0710] Step 2:
[0711] The server receives personal information sent from the terminal and stores it in the database. The received data is stored in the database as user authentication information. Secure storage methods are applied here, and measures are taken to prevent unauthorized access.
[0712] Step 3:
[0713] The server receives an authentication request from the terminal and generates dynamic authentication questions. In this process, it uses a generation AI model to generate questions related to pre-stored personal information. For example, a question such as "What country did you last visit?" might be created.
[0714] Step 4:
[0715] The terminal displays an authentication question generated by the server to the user. The user enters an answer to this question. The input is sent to the server in real time.
[0716] Step 5:
[0717] The device's camera and microphone capture the user's facial expressions and voice as they answer questions, and perform emotion analysis. Libraries such as OpenCV and TensorFlow are used to analyze the user's emotional state. The analysis results are sent to a server and output as user emotion data.
[0718] Step 6:
[0719] The server receives user responses and sentiment data and compares them with information stored in the database. By comparing the input data with the stored information, it determines whether the responses are accurate and whether the user's sentiment is stable. Based on the results, it grants or denies access.
[0720] Step 7:
[0721] Finally, the server notifies the terminal of the access decision based on the matching results. Based on the notification, the user checks whether access to the system is permitted. This completes the authentication process.
[0722] (Application Example 2)
[0723] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0724] In recent years, with the spread of electronic transactions, unauthorized access to personal information and data theft have increased. Therefore, improving the security of user authentication processes has become an urgent necessity. However, existing authentication technologies rely on fixed questions and passwords, making them easily bypassed by attackers. Furthermore, they do not consider the user's psychological state, potentially compromising the user experience. Overcoming these problems and providing a more secure and user-friendly authentication system is essential.
[0725] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0726] In this invention, the server includes means for generating, means for storing user attribute information, means for dynamically generating authentication tasks, and means for acquiring sentiment analysis data. This makes it possible to provide a flexible authentication process tailored to each individual based on dynamically generated authentication tasks and the user's sentiment state, thereby reducing the risk of unauthorized access.
[0727] "Means of generation" refers to a function that automatically creates specific information or data as part of a system.
[0728] "Means for storing user attribute information" refers to a function that stores personal data about each user and keeps it available for reference as needed.
[0729] A "means for dynamically generating authentication challenges" refers to a function that generates different authentication problems depending on the user's specific information and circumstances.
[0730] "Means of receiving user responses" refers to a function that takes in user-inputted and selected responses and makes them available within the system for processing.
[0731] "Means for matching received responses with user attributes" refers to a function that compares acquired responses with pre-stored user information and verifies the degree of match.
[0732] "Means for acquiring emotion analysis data" refers to a function that analyzes the user's emotional state from their voice, facial expressions, etc., and acquires the results as data.
[0733] "Means for determining whether to approve or deny access based on matching results and sentiment analysis data" refers to a function that determines whether a user can access the system based on the degree of match and sentiment evaluation obtained through verification.
[0734] The system necessary to implement this invention consists of a cloud-based server and a user's mobile terminal. The server includes means for generating data, means for storing user attribute information, means for dynamically generating authentication tasks, and means for acquiring sentiment analysis data. The program is implemented in a programming language such as Python, and TensorFlow or PyTorch are used as AI models. In addition, OpenCV and Google's natural language processing API are utilized for sentiment recognition.
[0735] When a user accesses or conducts a transaction via a terminal, the server first stores the user's attribute information in a database. During a transaction, the server utilizes a generative AI model to generate a dynamic authentication task based on the user's past attribute information. While the user answers this task, the terminal uses its camera and microphone to record the user's facial expressions and voice. This information is sent to the server as sentiment analysis data and used to recognize and judge the user's emotional response.
[0736] As a concrete example, when a user uses an online travel service, the server generates questions related to places the user has previously visited. During this process, sentiment analysis is used to assess the user's excitement and sense of security, and then determine whether the answer is correct. This process ensures authentication that prevents unauthorized access while minimizing user stress.
[0737] Examples of prompts to be input into the generation AI model include: "Generate questions that prompt the user to confirm memories based on their past visit information. Also, read expressions of anxiety from the user's responses, evaluate their trustworthiness, and then decide whether to allow payment." This will create a system that balances authentication accuracy and usability.
[0738] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0739] Step 1:
[0740] The user starts up the device and attempts to access online services. The device first inputs user attribute information (e.g., past visited locations and transaction history) and sends it to the server. This updates the user-specific data on the server side.
[0741] Step 2:
[0742] The server stores the received attribute information in a database. Based on this stored information, a generative AI model is used to generate dynamic authentication tasks tailored to the user. Specifically, prompts are used to instruct the model to create a task such as "generate questions that prompt the user to confirm memories based on information about places they have visited in the past."
[0743] Step 3:
[0744] The generated authentication task is sent to the device and presented to the user. The user answers the task, and the answer is sent back to the server via the device. During this response process, the device simultaneously uses its camera and microphone to sense the user's facial expressions and voice, and collects emotion analysis data.
[0745] Step 4:
[0746] The server processes user responses and sentiment analysis data received from the terminal. The server matches the user's responses with attribute information in the database and calculates the degree of match. Furthermore, the sentiment analysis data is evaluated using OpenCV and natural language processing APIs to assess the user's emotional response (e.g., whether they feel safe or anxious).
[0747] Step 5:
[0748] The server decides whether to grant or deny access based on the matching results and sentiment analysis results. For example, if the degree of match is high and the user is deemed to be at ease, access is granted; if there is strong anxiety, further confirmation is requested. The user is notified of the result through their device.
[0749] Step 6:
[0750] The server records these results and uses them for later analysis and system improvement. This information is then stored again in the database and used as data to contribute to future authentication task generation and analysis processes.
[0751] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0752] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0753] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.
[0754] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0755] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0756] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0757] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0758] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0759] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0760] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0761] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.
[0762] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.
[0763] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0764] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0765] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0766] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0767] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0768] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0769] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0770] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0771] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[0772] The following is further disclosed regarding the embodiments described above.
[0773] (Claim 1)
[0774] Means of generating,
[0775] Means for storing user information,
[0776] A means for generating dynamic authentication questions,
[0777] Means for receiving user responses,
[0778] A means of matching the received response with user information,
[0779] A means of determining whether to grant or deny access based on the matching results,
[0780] A system that includes this.
[0781] (Claim 2)
[0782] The system according to claim 1, which uses an artificial intelligence model to generate authentication questions.
[0783] (Claim 3)
[0784] The system according to claim 1, which presents a different authentication question each time based on dynamically generated questions.
[0785] "Example 1"
[0786] (Claim 1)
[0787] A data storage means for storing user information,
[0788] A communication device that receives authentication requests,
[0789] A data generation means for generating dynamic authentication questions based on stored information,
[0790] An interface that accepts user input,
[0791] A data matching means for comparing user input with stored information,
[0792] A determination means that controls access based on the matching result,
[0793] A system that includes this.
[0794] (Claim 2)
[0795] The system according to claim 1, which applies a machine learning model when generating dynamic authentication questions.
[0796] (Claim 3)
[0797] The system according to claim 1, which presents a different authentication question each time based on past usage history.
[0798] "Application Example 1"
[0799] (Claim 1)
[0800] The generation mechanism,
[0801] A mechanism for storing user information,
[0802] A mechanism for generating dynamic authentication questions,
[0803] A mechanism for receiving user responses,
[0804] A mechanism for matching received responses with user information,
[0805] A mechanism that determines whether to grant or deny access based on the matching results,
[0806] A mechanism to verify the user's identity in payment processing based on dynamic authentication questions,
[0807] A system that includes this.
[0808] (Claim 2)
[0809] The system according to claim 1, which uses an artificial intelligence model to generate authentication questions and generates dynamic authentication questions from information such as past transaction history and visit history.
[0810] (Claim 3)
[0811] The system according to claim 1, which presents the user with a different authentication question each time during the payment process based on dynamically generated questions, thereby improving security.
[0812] "Example 2 of combining an emotion engine"
[0813] (Claim 1)
[0814] Means of generating,
[0815] Means of storing personal data,
[0816] A means for generating dynamic authentication questions,
[0817] Means for receiving user responses,
[0818] A means of matching the received response with personal data,
[0819] A means of determining whether to grant or deny access based on the matching results,
[0820] Means for performing emotion analysis,
[0821] A system that includes this.
[0822] (Claim 2)
[0823] The system according to claim 1, which uses an artificial intelligence model to generate authentication questions.
[0824] (Claim 3)
[0825] The system according to claim 1, which presents a different authentication question each time based on dynamically generated questions, and further evaluates the response based on user sentiment analysis.
[0826] "Application example 2 when combining with an emotional engine"
[0827] (Claim 1)
[0828] Means of generating,
[0829] A means of storing user attribute information,
[0830] A means of dynamically generating authentication tasks,
[0831] Means for receiving user responses,
[0832] A means of matching the received response with user attributes,
[0833] Means for obtaining emotion analysis data,
[0834] Means for determining whether to approve or deny access based on matching results and sentiment analysis data,
[0835] A system that includes this.
[0836] (Claim 2)
[0837] The system according to claim 1, which uses a computational model to generate authentication tasks.
[0838] (Claim 3)
[0839] The system according to claim 1, which presents a different authentication task each time based on dynamically generated tasks and utilizes sentiment analysis data. [Explanation of symbols]
[0840] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>
Claims
1. A means of generating the information and questions necessary for user authentication, Means for storing user information, A means for generating dynamic authentication questions, Means for receiving user responses, A means of matching the received response with user information, A means of determining whether to grant or deny access based on the matching results, A system that includes this.
2. The system according to claim 1, which uses an artificial intelligence model to generate authentication questions.
3. The system according to claim 1, which presents a different authentication question each time based on dynamically generated questions.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A