Information processing system, information processing method, and information processing program

The system addresses vulnerabilities in smartphone-based authentication by using location information from both user and location devices for secure verification, ensuring reliable access to services even without a smartphone.

JP2026083656APending Publication Date: 2026-05-20THE JAPAN RES INST
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
THE JAPAN RES INST
Filing Date
2024-11-08
Publication Date
2026-05-20

AI Technical Summary

Technical Problem

Authentication using a smartphone's phone number is vulnerable to SIM swapping attacks and becomes unreliable if the user loses their smartphone, leading to potential fraud and authentication failures.

Method used

An information processing system that utilizes location information from both a user terminal and a location device associated with the user for authentication, comparing their location information to ensure a match within a predetermined range for secure verification.

Benefits of technology

Provides secure authentication that is resistant to SIM swapping and ensures authentication can be performed even if the user loses their smartphone, allowing seamless access to services using devices with built-in GPS capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026083656000001_ABST
    Figure 2026083656000001_ABST
Patent Text Reader

Abstract

We provide an information processing system that is even more secure and uses location information, which every user possesses, for authentication. [Solution] An information processing system 1 for performing authentication when a user makes a payment using a user terminal 20 in a store, comprising: a first location information acquisition unit 122 that acquires location information related to the user terminal 20 when it receives a payment request from the user via the user terminal 20; a second location information acquisition unit 123 that acquires location information related to a location device 40 associated with the user when it receives a payment request; and a determination unit 124 that compares the location information related to the user terminal 20 acquired by the first location information acquisition unit 122 with the location information related to the location device 40 acquired by the second location information acquisition unit 123, and outputs a determination result indicating that authentication was successful if the comparison result falls within a predetermined range.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing system, an information processing method, and an information processing program, and particularly relates to an information processing system, an information processing method, and an information processing program related to authentication using position information.

Background Art

[0002] In recent years, for example, when purchasing goods at a certain store, online electronic payment using a smartphone or the like with security ensured by an ID and a password has been widely performed. In addition, regarding passwords, in addition to being stolen by on-site peeping, they may be stolen by hacking online. Therefore, after entering the ID and password, a mechanism for re-authentication (referred to as "two-factor authentication") has come to be performed. As the re-authentication, for example, authentication using "stored information" such as answering a previously set secret question, authentication using "biometric information" such as face authentication or fingerprint authentication, and authentication using "possession information" such as entering a one-time password (throwaway password) sent by SMS to the smartphone.

[0003] Among these, authentication using "possession information" of entering a one-time password sent by SMS to the smartphone has been widely spread because the phone number of the smartphone serves as a unique key and is easy for users to use. Specifically, by registering the phone number of the smartphone that the user owns and possesses with the SNS authentication service provider, when the user enters the phone number at the time of settlement, a one-time password is sent to the smartphone by SNS from the SNS authentication service provider, and when the user enters the one-time password, authentication is performed by the SNS authentication service provider, and the identity confirmation is completed (for example, see Patent Document 1).

Prior Art Documents

Patent Documents

[0004] [Patent Document 1] Japanese Patent Publication No. 2018-036946 [Overview of the project] [Problems that the invention aims to solve]

[0005] However, authentication using a smartphone's phone number presented a challenge: malicious third parties could illegally obtain users' personal information through a technique called SIM swapping, obtain a replacement SIM card from the carrier, and then use that card for authentication to send money, potentially leading to fraud. Another challenge was that authentication would become impossible if the user lost their smartphone.

[0006] Therefore, the present invention aims to provide an information processing system, information processing method, and information processing program that are even more secure and use location information, which every user possesses, for authentication. [Means for solving the problem]

[0007] From one perspective, the present invention is an information processing system that performs authentication when a user makes a payment using a user terminal in a store, A first location information acquisition unit acquires location information related to the user terminal when it receives a payment request from the user via the user terminal, When the aforementioned payment request is received, a second location information acquisition unit acquires location information related to the location device associated with the user, The disclosed information processing system includes a determination unit that compares location information relating to the user terminal acquired by the first location information acquisition unit with location information relating to the location device acquired by the second location information acquisition unit, and outputs a determination result indicating that the authentication was successful if the comparison result falls within a predetermined range. [Effects of the Invention]

[0008] According to the present invention, it is possible to provide an information processing system, information processing method, and information processing program that are even more secure and use location information, which every user possesses, for authentication. [Brief explanation of the drawing]

[0009] [Figure 1] This is a schematic diagram of the overall configuration of an information processing system according to one embodiment. [Figure 2] This is an illustrative diagram (part 1) of an information processing system. [Figure 3] This is a diagram (part 2) illustrating an information processing system. [Figure 4] This is an illustrative diagram (part 3) of an information processing system. [Figure 5] This is an illustrative diagram (part 4) of an information processing system. [Figure 6] This is an illustrative diagram (part 5) of an information processing system. [Figure 7] This is a timing chart illustrating an example of how an information processing system operates. [Modes for carrying out the invention]

[0010] The embodiments will be described in detail below with reference to the attached drawings.

[0011] (Overall configuration of Information Processing System 1) Figure 1 is a schematic diagram of the overall configuration of the information processing system 1 according to this embodiment.

[0012] Information processing system 1 is a system that performs identity verification through location-based authentication, as described below. In location-based authentication, the server device 10 receives location information from the user terminal 20 and location device 40 held by the user using information processing system 1 via the network 30, and securely performs identity verification by matching the location information from both parties. Once authenticated, desired services such as payment are securely provided to the user.

[0013] Service providers to which this embodiment can be applied may include, for example, financial institutions such as various banks and insurance companies, as well as post offices and public or administrative service providers. An example of authentication using location information will be described later by taking a bank as an example with reference to FIGS. 2 to 6, but it can be deformed within a reasonable range according to the characteristics of each service provider.

[0014] As shown in FIG. 1, the information processing system 1 includes a server device 10, a user terminal 20, and a location device 40. In FIG. 1, one server device 10, one user terminal 20, and one location device 40 are illustrated, but in its specific application, the information processing system 1 may be configured by a plurality of server devices as necessary, and also by two or more user terminals 20 and location devices 40.

[0015] The server device 10, the user terminal 20, and the location device 40 are communicably connected to each other via a network 30. Although not illustrated in FIG. 1, a business operator such as a store where the user uses the information processing system 1 is positioned via the network 30.

[0016] The network 30 may include, for example, a wireless communication network of a mobile phone, the Internet, a VPN (Virtual Private Network), a WAN (Wide Area Network), a wired network, or any combination thereof.

[0017] The user terminal 20 is, for example, a portable smartphone (mobile phone) or a tablet, but it does not necessarily need to be a portable terminal, and it may be a fixed terminal such as a desktop-type or notebook-type personal computer (PC).

[0018] The user terminal 20 includes a communication unit 21, a processing unit 22, an input unit 23, and a display unit 24. The communication unit 21 performs various communications via the network 30. The processing unit 22 realizes various functions that can be realized by the user terminal 20. The input unit 23 receives user input necessary for performing authentication based on position information. The display unit 24 outputs various processed information. The input unit 23 and the display unit 24 may be a liquid crystal display, an organic EL (Electro-Luminescence) display, etc., and may be configured as a shared one.

[0019] In this embodiment, the user terminal 20 only needs to have a built-in GPS function and a function capable of transmitting its own position information externally. In other words, it is not necessary for the user terminal 20 to install a specific application for receiving authentication based on position information. As will be described in detail later, when making a payment request (such as smartphone payment), the user terminal 20 may transmit its ID and password as login information, and at the same time, transmit its own position information to the server device 10. As will be described next, the identification information of the user terminal 20 and the position device 40 is pre-registered in the server device 10.

[0020] The position device 40 only needs to have a built-in GPS function and a transmitting unit 41 capable of transmitting its own position information externally. Also, instead of the GPS function, the position device 40 may be able to track position information using short-range wireless communications such as Bluetooth (registered trademark, the same applies hereinafter), Wi-Fi (registered trademark, the same applies hereinafter). For example, the position device 40 may be a smartwatch (registered trademark, the same applies hereinafter), a smart tag, an AirTag (registered trademark, the same applies hereinafter), etc., and its form is not limited, such as wearable, strap type, bag type, etc.

[0021] In this embodiment, as described above, the location device 40, along with the user terminal 20, has its identification information pre-registered with the server device 10. When payment (such as smartphone payment) is made by the user terminal 20, the server device 10 performs authentication for identity verification by matching the location information received for the logged-in user terminal 20 with the current location information of the location device 40, which is acquired separately from the user terminal 20, as described below. The user only needs to send its own location information to the server device 10.

[0022] The server device 10 is installed at a service provider that provides a service that enables location-based authentication according to this embodiment. The server device 10 may be configured to cover the entire organization of the service provider, or it may be configured to cover specific areas, head office / branch offices, or buildings, depending on the organization's structure. The server device 10 is formed by, for example, a server computer. The server device 10 may be realized by multiple server computers. For example, the server device 10 may be realized by multiple server computers located in different locations working together.

[0023] The types of services that require location-based authentication are arbitrary, but here we will explain them using credit card payments provided by the service provider (such as smartphone payments) as an example. Therefore, the services referred to here are services that can only be used by users who meet certain prerequisites. These prerequisites are arbitrary, but may include, for example, being qualified to use the service provider in question, being qualified to use individual services provided by the service provider, paying usage fees, or not meeting certain prohibited conditions.

[0024] In this embodiment, as mentioned above, the service provider may include financial institutions such as various banks and insurance companies, as well as post offices and public or administrative service providers. However, in the following explanation, we will use a bank (for example, a commercial bank, which is a type of ordinary bank) as an example.

[0025] Server device 10 is a server that performs various individual services related to authentication using location information, but server device 10 may also be used as a server for services (purposes) other than authentication using location information.

[0026] (Functions of Information Processing System 1) Before describing the various parts of the server device 10, we will now explain how location-based authentication according to this embodiment is achieved, and describe the functions of the information processing system 1 in this embodiment with reference to Figures 2 to 6. For the sake of clarity, in the following explanation and in the figures, a smartphone is used as the user terminal 20. However, as mentioned above, the user terminal 20 is not limited to a smartphone. The smartphone is denoted as "smartphone 20." Furthermore, in the following explanation and in the figures, there are instances where "device," "smart tag," or "tag" are used, all referring to the location device 40.

[0027] First, to explain the functions of Information Processing System 1 from the user's perspective, user authentication for identity verification is processed through the following steps. The user registers identification information related to the location device 40, which has location information, as authentication information in the information processing system 1. When a user requests authentication for identity verification, such as during payment, they transmit the location information of their smartphone 20 to the information processing system 1. The information processing system 1 matches the location information of the smartphone 20 at the time of payment with the location information of the registered location device 40 at the time of payment. If they match within a predetermined range, it authenticates the user's identity and authorizes the payment.

[0028] Based on Figures 2 and 3, the authentication process for verifying identity provided by Information Processing System 1 will be further explained, divided into the preparatory stage and the service usage stage.

[0029] Figure 2 shows the preliminary setup stages for Information Processing System 1. Users of Information Processing System 1 (referred to as "users" in Figure 2 and elsewhere, but will be referred to as "users" hereafter) register a location device 40 (referred to as "device" in Figure 2 and elsewhere, but will be referred to as "location device 40" hereafter) that has location information when registering as a user for service use in Information Processing System 1. Examples of location devices 40 include smart tags, smartwatches, and air tags. The location information held by the location device 40 can be obtained using latitude and longitude via GPS or location confirmation via Bluetooth, depending on the type of location device 40.

[0030] The information processing system 1 receives user registration, links the user information with the identification information of the location device 40, and stores it in the storage unit 13 of the server device 10. The service provider operating the information processing system 1 may be, for example, a financial institution such as a bank.

[0031] Figure 3 shows the stages of a user using a service provided by the information processing system 1, when the user possesses a pre-registered location device 40. For example, when purchasing goods at a store, the user uses authentication by the information processing system 1 for payment, and simultaneously transmits the ID and password of the smartphone 20 used for payment, along with the location information related to the built-in GPS, to the server device 10.

[0032] Although not shown in Figure 3, when a store where a user is attempting to make a payment sends an authorization request, including store identification, from its store terminal to the service provider, the information processing system 1 obtains the store registration location information from the store identification information included in the authorization request.

[0033] The server device 10, having received the login information and location information of the smartphone 20, obtains the location information of the location device 40, which was registered in the preparation stage, based on a request from the server device 10.

[0034] The information processing system 1 then determines that the location information of the smartphone 20 and the location information of the location device 40 match within a predetermined range, authenticates the user's identity, and permits (authorizes) the use of services such as payment.

[0035] Authentication for identity verification using such an information processing system 1 has the following advantages from the user's perspective. • Since the location information of the smartphone 20 is transmitted automatically, users can use the service smoothly. Since authentication is not based on a phone number, it is not susceptible to SIM swapping or other fraudulent activities, and authentication can be performed securely as long as the location device 40 is not lost. Instead of using a smartphone (including mobile phones), users can access the service if they carry a device with built-in GPS (such as a personal computer or tablet), even if it is a different type of device.

[0036] Furthermore, since the authentication of identity by such information processing system 1 involves the collection of the user's location information, from the perspective of the service provider, it offers the following advantages, as shown in Figure 4 and others. By accumulating location information, it becomes possible to collect pedestrian flow data as big data, and based on this pedestrian flow data, for example, financial institutions can select locations for installing ATMs. • Users are required to provide location information during authentication, and the location of the person requesting authentication at a specific time and date can be identified, which helps deter crime. Because it employs a method of matching location information, it eliminates the need to develop a two-factor authentication application or build an email server to send one-time passwords, as is the case with conventional authentication technologies. Since payments can be made using a PC or tablet as a terminal with built-in GPS, users who do not have a smartphone 20 or users who are hesitant to use smartphone payments can also be incorporated into the information processing system 1. Currently, it is possible to add two-factor authentication to payment methods that are already using one-factor authentication on smartphones, and to implement secure and smooth two-factor authentication for all types of web-based services other than payments.

[0037] Figure 5 summarizes the functions of Information Processing System 1, taking into account the points explained above, including users and service providers, as well as businesses that sell goods and various services to users, fraudsters, and malicious third parties who hack third-party information on the web (referred to as "bad guys" in the figure). Although there is some overlap with the explanation above, the main points are as follows.

[0038] Users can avoid the inconvenience of two or more steps (or even three or more steps in the case of multi-factor authentication involving multiple factors) that are unavoidable with currently widespread two-factor authentication. By sending location information simultaneously with login authentication, secure authentication can be performed smoothly in a single step. Furthermore, secure authentication can be performed by using location information, which is not susceptible to leakage, instead of phone numbers, which may be leaked through methods such as SIM swapping.

[0039] For service providers, the advantages include providing users with smooth authentication through location-based authentication, utilizing human flow data accumulated during the authentication process, preventing crimes such as the leakage of personal information associated with authentication, i.e., preventing malicious third parties from infiltrating the authentication service, minimizing additional development required when building the authentication system, and providing authentication services in a way that also includes users who make payments using methods other than smartphones.

[0040] Furthermore, payment data and pedestrian flow data associated with location information, accumulated through the operation of Information Processing System 1, may be provided to businesses that sell goods and various services to users as market data. This data is, of course, not the personal information of users, but rather big data in the form of what kind of demand is expected in a particular market. For example, if big data shows that a region has many users who purchase golf equipment, it can be a useful source of information for related businesses, indicating that there is a need to build a golf driving range in that region. Moreover, it can also be used to assist in regional development projects considered by the public sector.

[0041] The above describes authentication using location information, but in addition to or instead of this, the following configuration may also be provided.

[0042] The above explanation focuses on payments (smartphone payments) made when users purchase goods or various services, but the location-based information processing system 1 may be applied not only to payment services but also to authentication for the use of various social networking services and search services provided on the web.

[0043] The above explains that the authentication process involves obtaining the current location information. However, the determination may also be made based on whether the location information matches not only the current location but also past location information (for example, a few minutes ago). In this case, the smartphone 20 and the location device 40 need to transmit location information at predetermined time intervals, i.e., periodically, that is, they need to continuously send current location information to the server device 10. Therefore, a smartwatch is more appropriate as the location device 40 than a smart tag or air tag.

[0044] The above explains how location information is obtained using GPS functionality. However, in case the user enters a place where GPS location information is difficult to obtain, such as an underground shopping mall, the smartphone 20 and the location device 40 may each record the location information immediately prior to that entry (such as the entrance), and authentication may be performed using the recorded location information at the time of authentication. Alternatively, when entering a place where GPS location information is difficult to obtain, such as an underground shopping mall, the user may send a self-declaration to the server device 10 in advance.

[0045] In the above explanation, when the service provider's server device 10 receives an authentication request from the smartphone 20, it is explained that it obtains the location information of the location device 40 based on the request from the server device 10. However, the acquisition of this location information of the location device 40 may be performed automatically at the same time as the authentication request is received, without being based on a request from the server device 10.

[0046] In addition to the above, as shown in Figure 6, the location information of the location device 40 may be verified using a communication line other than the user's own user terminal 20. This is done to prevent tampering with the location of the location device 40 by using a third-party communication line. To reliably transmit the location information of the location device 40 via a third-party line, it is advisable to turn off the internet connection of the user's own user terminal 20. Even if the location device 40 is not connected to the paired user terminal 20, it can transmit location information by borrowing radio waves from nearby devices. In this way, when the location information of the location device 40 is verified using a communication line other than the user's own user terminal 20, the communication line used to obtain the location information of the location device 40 from the service provider is different from the communication line of the user terminal 20 that made the payment request. Therefore, even if the payment request is made by a malicious party, it is possible to verify the location information without allowing involvement by the user terminal 20.

[0047] In this case, the location device 40 may be owned by the user, but the service provider may also provide it and lend it to the user. For example, when an item to which the location device 40 is attached is lost, a network is provided to search for the lost item based on the location information of the location device 40, and the information processing system 1 may utilize such a search network.

[0048] Furthermore, regarding the location information of the location device 40, due to its nature, if it is transmitted continuously, the user's privacy will be revealed to the outside. Therefore, the information processing system 1 may allow the user to turn off the authentication determination at their own discretion in order to ensure their own security. In addition, the information processing system 1 may, instead of or in addition to the user's own setting to turn off the authentication determination, allow the service provider to turn off the authentication determination when it is necessary to maintain the integrity of the information processing system 1, such as when there is a user error, when it is discovered that the user does not meet the conditions for using the information processing system 1, or when there is concern or it is discovered that a malicious third party has infiltrated the information processing system 1.

[0049] The location information of the location device 40 may also be given an expiration date (valid time: in minutes, hours, etc.). For example, as mentioned above, if the user enters a location where it is difficult to obtain location information as an authentication site, the device may be usable only for the valid time from the most recent location information. Even if the location is not a place where it is difficult to obtain location information as an authentication site, the device may be usable only for a certain period of time from the time of entry. The time related to the location information of these location devices 40 is collectively referred to as elapsed time.

[0050] If, instead of using the user's own smartphone network, a third party's smartphone network is lent to the user as the communication line for acquiring the location information of the location device 40, the third party who lent the smartphone network may be given points as a reward, regardless of whether the lending was done consciously or unconsciously (see Figure 6).

[0051] The location device 40 may be lent to a caregiver (family member, guardian, or other person accompanying the user) if the user is a minor or elderly person. If lent, it is recommended to turn on a flag indicating that the location device 40 is on loan. This allows, for example, a minor, especially a child, to experience a sense of accomplishment when shopping for the first time, by having their mother, who is carrying the location device 40, nearby. Also, for example, when an elderly person with dementia or a person under guardianship goes shopping, having a caregiver carrying the location device 40 nearby can prevent unnecessary purchases or the purchase of the wrong items.

[0052] In addition to the above, the information processing system 1 may also have various additional functions if the user terminal 20 and location device 40 are in a state where communication is possible. For example, the following functions may be added. • Service providers may utilize pedestrian flow data to understand, create, and provide purchasing maps (customer maps, customer journey maps, etc.) (see Figure 6). • In the event of an emergency involving the user (for example, becoming unconscious or missing), the service provider may offer search and rescue assistance services (see Figure 6). • By notifying the service provider in advance of the purpose of the withdrawal, elderly people with dementia or those under guardianship may be allowed to have their caregivers withdraw funds from an account set up at the service provider. However, withdrawals for purposes other than those notified in advance are not permitted.

[0053] Next, referring again to Figure 1, we will further explain the server device 10 of the information processing system 1, supplementing the information explained in Figures 2 through 6.

[0054] In this embodiment, as shown in Figure 1, the server device 10 may include, as a processing unit 12, a registration unit 120, a login processing unit 121, a first location information acquisition unit 122, a second location information acquisition unit 123, a determination unit 124, a service authorization unit 125, and, depending on the function of the information processing system 1, a receiving unit 126, a third location information acquisition unit 127, a measurement unit 128, and an on / off setting unit 129. The storage unit 13 may include a user information storage unit 130, a login information storage unit 131, and a location device identification information storage unit 132. Each part of the processing unit 12 can be implemented by the CPU of the server computer executing a program. The storage unit 13 can be implemented by the storage device of the server computer.

[0055] The registration unit 120 registers users who will use the information processing system 1 and obtains the necessary information from the user terminal 20. The necessary information includes general personal information such as the user's name and address, as well as the account number if the user has an account with the service provider, identification information of the user terminal 20 (smartphone, etc.) used for payment, and identification information of the location device 40 which is necessary for using the information processing system 1. The registered information is stored in the user information storage unit 130.

[0056] The identification information of the location device 40 may be stored as an item in the user information storage unit 130, but as mentioned above, Figure 1 shows a configuration in which a separate storage unit is provided as the location device identification information storage unit 132, taking into consideration its use as pedestrian flow data. Whether the identification information of the location device 40 is stored in the user information storage unit 130 or separately in the location device identification information storage unit 132, it is stored linked to the user information.

[0057] The login processing unit 121 logs the user into individual services, such as payment services, provided by the service provider, as requested by the user. It obtains the ID and password from the user terminal 20. Once the login information relating to the user is obtained, the login processing unit 121 determines whether the person to be logged in is the user based on the relationship between the login information and the data in the login information storage unit 131, and then performs the login process.

[0058] The method of login processing by the login processing unit 121 is arbitrary, but it may be performed as follows, for example. When a registered user logs in manually, the login processing unit 121 logs the user into the individual service provided by the service provider. Specifically, first, the login processing unit 121 identifies the corresponding ID from the login information related to the target person, based on the target person's account registration. In this case, data in the user information storage unit 130 (user information for identity verification) may be used. If the corresponding ID cannot be identified, the result of the login processing will be "inconsistent (authentication failed)".

[0059] The first location information acquisition unit 122 acquires location information transmitted from the user terminal 20 along with the login information. In this embodiment, the location information of the user terminal 20 is not transmitted as a process performed by the user, but is set to be transmitted automatically at the same time as the transmission of the login information. In conventional two-factor authentication, the user needs to perform two separate steps for two-step authentication, but in this embodiment, the location information of the user terminal 20 is transmitted to the server device 10 in one step along with the login information, so the user can obtain the same effect as two-factor authentication in one step.

[0060] When login information and location information are transmitted from the user terminal 20, the second location information acquisition unit 123 acquires the current (or past) location information of the location device 40, which stores identification information corresponding to the user terminal 20. As mentioned above, the location device 40 may have a built-in GPS function or use short-range wireless communication such as Bluetooth for location confirmation, and the second location information acquisition unit 123 acquires the location information according to the type of location device 40. The second location information acquisition unit 123 may also request the location information of the location device 40 or the entity operating the location device 40 to provide the location information and acquire the location information of the location device 40.

[0061] The determination unit 124 compares the location information of the user terminal 20 with the location information of the location device 40 and determines whether the two location information matches. If the determination unit 124 determines that the location information of the user terminal 20 and the location information of the location device 40 are within a predetermined range, it authenticates the user attempting to make a payment using the user terminal 20 based on the determination result and notifies the user terminal 20 of this. Furthermore, as described later, if elapsed time is measured, the determination unit 124 may only be able to determine authentication for a certain period within the elapsed time. The predetermined range refers to the range in which the location information of the user terminal 20 and the location device 40 can be determined to be located in the same or nearby location, based on the accuracy of the location information indicated by the user terminal 20 and the location device 40.

[0062] The service authorization unit 125, separately from or simultaneously with authentication, notifies the user terminal 20 of authorization for services such as payment that have become available through said authentication.

[0063] The receiving unit 126 receives an authorization request, including store identification, when the store where the user is attempting to make a payment sends the authorization request, including store identification, from the store's terminal to the service provider.

[0064] The third location information acquisition unit 127 acquires the store registration location information from the store identification information included in the authorization request when a store where a user is attempting to make a payment sends an authorization request including store identification from the store's terminal to the service provider.

[0065] The measurement unit 128 measures the elapsed time of the location information of the location device 40, including the validity period of the previous location information when entering a place where it is difficult to acquire location information, and the time available for use from the time of entering the store. In addition, if the measurement unit 128 is to determine whether the current location information matches past location information, it may periodically measure the elapsed time.

[0066] The on / off setting unit 129 allows the user to set the authentication determination on or off in the information processing system 1, either at their own discretion, or in addition to or in lieu of the user's discretion, by the service provider. The on / off setting unit 129 may also allow the user to set the on / off status of services other than authentication when the information processing system 1 provides such services.

[0067] With the configuration described above, the information processing system 1 according to this embodiment can perform the procedure for receiving documents that can only be handled at the service provider's counter within a virtual space, even if the user does not actually visit the service provider.

[0068] Next, with reference to Figure 7, an example of the operation of the information processing system 1 will be described.

[0069] Figure 7 is a timing chart showing an example of the operation of the information processing system 1. This example of operation is implemented as an information processing method processed by the information processing system 1 according to each step described below, and as an information processing program that causes the information processing system 1 to be executed by a computer according to the processing related to each step.

[0070] Figure 7 schematically shows the main information exchange between one user terminal 20, one location device 40, and one server device 10. Here, as a representative example, the case where the service provided by the information processing system 1 is location-based authentication for payment is shown, as will be explained below. If the service provided by the information processing system 1 is a different service (see the various configurations described above), the user terminal 20, location device 40, and server device 10 are not limited to one each, and may be configured in multiple units depending on the service provided.

[0071] First, in step S100, a user (hereinafter simply referred to as "user") uses the user terminal 20 to send user information necessary for initial registration to the server device 10, including the user's personal information, the identification information of the user terminal 20, and the identification information of the location device 40, in order to receive the service provided by the service provider.

[0072] Furthermore, as mentioned above, the location device 40 may be carried by a caregiver accompanying the user, depending on the user's condition. Therefore, for users where family members, guardians, or other legal representatives are required, the user information may include information about the caregiver. In addition, if the location device 40 is used for a service in which a caregiver withdraws money from the user's account at the financial institution providing the service, a list of the purpose of the withdrawal may be included in the user information.

[0073] In step S102, when the server device 10 receives the user's personal information, the identification information of the user terminal 20, and the identification information of the location device 40 from the user terminal 20, it registers the user as a user of the information processing system 1. That is, the server device 10 issues a user ID (user account) and stores the personal information in the user information storage unit 130 in association with the user ID. At this time, the identification information of the user terminal 20 and the identification information of the location device 40 are stored linked to the user. Steps S100 and S102 correspond to the preliminary preparation stage described above (see Figure 2) (registration step / registration process).

[0074] From this point onward, the process corresponds to the stages of service use described above (see Figure 3). In step S104, when the user makes a payment for the desired service, the user terminal 20 transmits its login information and its location information to the server device 10. The location information is latitude and longitude obtained using GPS.

[0075] In step S106, when the server device 10 receives login information and location information from the user terminal 20, it performs the login process and simultaneously acquires the location information of the user terminal 20. Having acquired the location information of the user terminal 20, the server device 10 notifies the user terminal 20 that the login process has been completed and requests the location device 40 to transmit the location information (first location information acquisition step / first location information acquisition process).

[0076] In step S108, the location device 40 transmits its location information to the server device 10 in response to a request from the server device 10.

[0077] In step S110, the server device 10 acquires location information transmitted from the location device 40 (second location information acquisition step / second location information acquisition process).

[0078] In Figure 7, the process (steps S106, S108, S110) based on a request from the server device 10 is shown when the server device 10 acquires location information from the location device 40. However, the server device 10 may be configured to actively acquire location information from the location device 40 at the same time as the login process.

[0079] In step S112, the server device 10 compares the location information of the user terminal 20 with the location information of the location device 40 and determines whether the two locations match. If the server device 10 determines that the location information of the user terminal 20 and the location information of the location device 40 are within a predetermined range, it authenticates that the user attempting to make a payment using the user terminal 20 is the legitimate user based on the determination result and notifies the user terminal 20 of this fact (determination step / determination process).

[0080] Whether the location information of the user terminal 20 and the location information of the location device 40 match is determined by whether the location information of both falls within a predetermined range. However, as mentioned above, it is possible that the location device 40 may be held by a caregiver accompanying the user, rather than the user themselves. In that case, the predetermined range may be set to be relatively wider than when the user themselves is holding the location device 40, based on user information regarding the presence or absence of a caregiver, and within a reasonable range.

[0081] In step S114, the server device 10, either simultaneously with or separately from the authentication, issues a notification authorizing the payment and other services that have become available through the authentication.

[0082] Although each embodiment has been described in detail above, the invention is not limited to any particular embodiment, and various modifications and changes are possible within the scope described in the claims. Furthermore, it is possible to combine all or more of the components of the embodiments described above.

[0083] For example, in the embodiment described above, the service provider is mainly exemplified as a server device 10 installed at the organization, but in order to provide a variety of services, it can be installed integrally with servers for other purposes. For example, the server device 10 may be installed at the organization's membership-based service provision location and implement the service provider's reception function. In this case, the service provider may be operated in response to execution commands from the server device 10 installed at the membership-based service provision location.

[0084] Furthermore, although the above explanation assumes that the service provider is a financial institution, the service provider may also be a public or administrative service provider, depending on the content of the service provided by the information processing system 1. For example, the server device 10 may be installed in a municipal office that provides public or administrative services, or in a place that accepts applications on behalf of public or administrative services, thereby realizing the reception function of the service provider.

[0085] Furthermore, in the embodiment described above, the processing unit 12 and the storage unit 13 are provided in a single server device 10. However, to suit the actual structure of the service provider, the processing unit 12 and the storage unit 13 may be distributed, and the individual parts of the processing unit 12 and the individual parts of the storage unit 13 may also be distributed. [Explanation of Symbols]

[0086] 1. Information Processing System 10 Server devices 12 Processing Units 120 Registration Department 121 Login Processing Unit 122 1st location information acquisition unit 123 Second location information acquisition unit 124 Judgment section 125 Service Licensing Department 126 Receiving Unit 127 Third location information acquisition unit 128 Measurement Unit 129 On / Off setting section 13 Storage section 130 User information storage unit 131 Login Information Storage Unit 132 Location device identification information storage 20 User Terminals 21 Communications Department 22 Processing Units 23 Input section 24 Display 30 Networks 40 Location Devices 41 Transmission Unit

Claims

1. An information processing system that performs authentication when a user makes a payment using a user terminal in a store, A first location information acquisition unit acquires location information related to the user terminal when it receives a payment request from the user via the user terminal, A second location information acquisition unit acquires location information related to a location device associated with the user when it receives the aforementioned payment request. An information processing system comprising: a determination unit that compares location information relating to the user terminal acquired by the first location information acquisition unit with location information relating to the location device acquired by the second location information acquisition unit, and outputs a determination result indicating that the authentication was successful if the comparison result falls within a predetermined range.

2. A receiving unit that receives an authorization request including store identification from the store terminal of the aforementioned store, The information processing system according to claim 1, further comprising a third location information acquisition unit that acquires store registration location information from the store identification information included in the authorization request.

3. The information processing system according to claim 2, wherein the determination unit compares the location information relating to the user terminal and the location information relating to the location device with the store registration location information, and outputs a determination result indicating that the authentication was successful when the comparison result of the three falls within a predetermined range.

4. The information processing system according to claim 1, further comprising an on / off setting unit that allows setting the on / off status of the authentication determination in the determination unit.

5. The system further includes a measuring unit that measures the elapsed time since the user entered the store, and / or the elapsed time since the user entered an area where communication is unavailable. The information processing system according to claim 1, wherein the determination unit can determine the authentication only for a certain period of time within the measured elapsed time.

6. The information processing system according to claim 1, wherein the first location information acquisition unit and the second location information acquisition unit acquire location information relating to the user terminal and location information relating to the location device, respectively, via a communication line of a third party different from the user.

7. An information processing method that causes a server to perform authentication when a user makes a payment using a user terminal in a store, A first location information acquisition step is performed when a payment request is received from the user via the user terminal, and the location information of the user terminal is acquired. Upon receiving the aforementioned payment request, a second location information acquisition step is performed to acquire location information relating to the location device associated with the user, Information processing method comprising: a determination step that compares location information relating to the user terminal obtained in the first location information acquisition step with location information relating to the location device obtained in the second location information acquisition step, and outputs a determination result indicating that the authentication was successful if the comparison result falls within a predetermined range.

8. An information processing program that causes a server to perform authentication when a user makes a payment using a user terminal in a store, When a payment request is received from the user via the user terminal, a first location information acquisition process is performed to acquire location information related to the user terminal, Upon receiving the aforementioned payment request, a second location information acquisition process is performed to acquire location information related to the location device associated with the user, An information processing program comprising: a determination process that compares location information relating to the user terminal obtained by the first location information acquisition process with location information relating to the location device obtained by the second location information acquisition process, and outputs a determination result indicating that the authentication was successful if the comparison result falls within a predetermined range.