Information management system, management device, and information management method
The information management system addresses the challenge of secure biometric registration on IC cards by integrating a biosensor and management device for authorized authentication, ensuring secure biometric data management.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- KK TOSHIBA
- Filing Date
- 2024-11-20
- Publication Date
- 2026-06-01
AI Technical Summary
Conventional IC cards with biometric authentication functions face challenges in securely managing biometric information registration, especially when users register or re-register information without administrator oversight, leading to decreased security.
An information management system comprising a portable electronic device with a biosensor, communication interface, and memory units, and a management device with a communication and control unit, which ensures secure biometric information registration through authentication and authorization processes.
The system enables safe and controlled biometric information management, enhancing security by requiring authorized authentication before registering biometric data on IC cards.
Smart Images

Figure 2026089472000001_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to an information management system, a management device, and an information management method.
Background Art
[0002] In recent years, some IC cards as portable electronic devices have sensors for acquiring biometric information such as fingerprints and have a function of performing biometric authentication based on the biometric information acquired by the sensors. In order to prevent unauthorized registration of biometric information, conventional IC cards with biometric authentication functions are often operated such that biometric information is registered by the operation of an administrator in the presence of the administrator.
[0003] However, when IC cards with biometric authentication functions become widely popular, it becomes difficult to register or re-register biometric information for each individual IC card by the operation of an administrator. In addition, if users can register or re-register biometric information for IC cards only by themselves without management by an administrator or the like, there is a problem that the security level decreases.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] In order to solve the above problems, the present invention provides an information management system, a management device, and an information management method capable of safely managing the registration of biometric information.
Means for Solving the Problems
[0006] According to one embodiment, the information management system comprises a portable electronic device and a management device. The portable electronic device includes a biosensor, a communication interface, a first memory, a second memory, and a processor. The biosensor acquires a person's biometric information. The communication interface communicates with a reader / writer. The first memory stores authentication information for biometric information registration. The second memory is a rewritable memory that stores the biometric information of the user of the portable electronic device. If authentication is successful using the information received from the management device via the reader / writer communicating through the communication interface and the authentication information for biometric information registration stored in the first memory, the processor registers the biometric information acquired by the biosensor in the second memory in response to an instruction from the management device to perform biometric information registration. The management device includes a communication unit, a storage unit, and a control unit. The communication unit communicates with a terminal device to which the reader / writer is connected. The storage unit stores user authentication information of the user who is the user of the portable electronic device. When user authentication is successful based on the information input to the terminal device communicating via the communication unit and the user authentication information stored in the storage unit, the control unit transmits the authentication information for biometric information registration set on the portable electronic device possessed by the user of the user authentication information to the portable electronic device communicating via the terminal device and the reader / writer, and when authentication using the authentication information for biometric information registration on the portable electronic device is successful, the control unit causes the portable electronic device to perform biometric information registration. [Brief explanation of the drawing]
[0007] [Figure 1] Figure 1 shows an example of the configuration of an information management system according to the embodiment. [Figure 2] Figure 2 is a block diagram showing an example configuration of an IC card as a portable electronic device in an information management system according to this embodiment. [Figure 3] Figure 3 is a block diagram showing an example of the configuration of a user terminal in an information management system according to the embodiment. [Figure 4]Figure 4 is a block diagram showing an example configuration of a management device as a higher-level system in an information management system according to the embodiment. [Figure 5] Figure 5 shows an example of the configuration of a database managed by a management device in an information management system according to this embodiment. [Figure 6] Figure 6 shows an example of the fingerprint registration management screen displayed in administrator mode by the management device in the information management system according to the embodiment. [Figure 7] Figure 7 is a sequence diagram illustrating the flow of the process (fingerprint registration process) for registering a fingerprint on an IC card held by a user in the information management system according to the embodiment. [Figure 8] Figure 8 shows an example of a user operation screen displayed when a user capable of fingerprint registration logs into the management device in the information management system according to the embodiment. [Figure 9] Figure 9 shows an example of a user operation screen displayed when a user who cannot register their fingerprint logs into the management device in the information management system according to the embodiment. [Figure 10] Figure 10 is a sequence diagram illustrating the process of deleting fingerprints registered on an IC card held by a user in an information management system according to an embodiment of this system (fingerprint deletion process). [Modes for carrying out the invention]
[0008] The embodiments will be described below with reference to the drawings. First, the configuration of the information management system 1 according to the embodiment will be described. Figure 1 is a block diagram showing an example configuration of the information management system 1 according to an embodiment. Management system 1 is a system for managing information related to IC card 6, which is a portable electronic device provided to users. In addition, information management system 1 controls the registration of biometric information (e.g., fingerprint information for biometric authentication) on IC card 6 provided (distributed) to users, according to settings by the administrator.
[0009] In the configuration example shown in Figure 1, the information management system 1 includes a management device 2, a network 3, a user terminal (terminal device) 4, a reader / writer (R / W) 5, and an IC card (portable electronic device) 6, etc.
[0010] The management device 2 manages information related to the IC card 6 provided to the user. The management device 2 updates the managed information in response to operations by the administrator and communicates with the user terminal 4 via the network 3. The management device 2 also communicates with the IC card 6 via the user terminal 4 and the reader / writer 5. Furthermore, the management device 2 has a function to operate in a management mode, which is operated by the administrator to configure information and perform other operations. In management mode, the management device 2 updates the managed information in response to operations by the administrator.
[0011] User terminal 4 is an information processing device (terminal device) operated by a user who is the holder of an IC card 6 whose information is managed by the management device 2. Alternatively, the administrator who manages the IC card 6 may have the user operate an information processing device (terminal device) that they own. User terminal 4 may be a desktop or notebook personal computer (PC), or a mobile device such as a smartphone or tablet PC. User terminal 4 has the function of communicating with the management device 2 via a network and the function of communicating with the IC card 6 via a reader / writer 5.
[0012] The reader / writer 5 communicates with the IC card 6 while connected to the user terminal 4. The reader / writer 5 includes an interface for connecting to the user terminal 4 and a communication module that corresponds to the communication method of the IC card 6.
[0013] In the configuration example shown in FIG. 1, the reader / writer 5 is configured to be externally connected to the user terminal 4 via an interface. However, the user terminal 4 may be configured to incorporate the function as a reader / writer 5 (communication module with the IC card 6). For example, the user terminal 4 may be a mobile terminal such as a smartphone that includes a communication module with the IC card 6 corresponding to the reader / writer 5.
[0014] The IC card 6 is an example of a portable electronic device that is activated (put into an operable state) by power supplied from an external device. For example, the IC card 6 is also referred to as a smart card. The IC card 6 has a function of operating in accordance with an existing communication protocol used for IC cards standardized by international standards and the like. The IC card 6 communicates with the reader / writer 5 by a non-contact or contact communication method.
[0015] The IC card 6 as a portable electronic device according to this embodiment has a fingerprint authentication function and is provided (distributed) to the user from the operator who operates the information management system 1. The IC card 6 has a fingerprint (biometric) sensor 11 that acquires the fingerprint (fingerprint information) of the user as biometric information for biometric authentication. As illustrated in FIG. 1, the fingerprint sensor 11 is provided on the main body of the IC card 6 so as to contact the finger of the person holding the IC card 6. Also, in the configuration example shown in FIG. 1, a communication interface 12 for communicating with the reader / writer 5 is provided on the main body of the IC card 6.
[0016] Next, the configuration of the IC card 6 as a portable electronic device in the information management system 1 according to the embodiment will be described in detail. FIG. 2 is a block diagram showing a configuration example of the IC card 6 as a portable electronic device in the information management system 1 according to the embodiment. The IC card 6 is an example of a portable electronic device that is activated (started up) by the power supplied from the reader / writer 5 connected to the user terminal 4 and executes processing in response to commands supplied via the reader / writer 5. In the present embodiment, the IC card 6 as a portable electronic device has a fingerprint sensor 11 as a biometric sensor, and has a function of performing biometric authentication using fingerprint (biometric) information acquired by the fingerprint sensor 11. Note that the IC card 6 according to the embodiment may be implemented by replacing it with one function provided in a mobile terminal such as a smartphone, which is another example of a portable electronic device.
[0017] In the present embodiment, the IC card 6 as a portable electronic device will be described as having a biometric (fingerprint) authentication function for authenticating a person by fingerprint matching using a fingerprint as an example of biometric information acquired from a person. However, the biometric authentication function provided in the IC card 6 as a portable electronic device according to the embodiment is not limited to biometric matching by fingerprint, and any biometric authentication may be performed using biometric information acquired by a biometric sensor provided in the IC card 6.
[0018] In the configuration example shown in FIGS. 1 and 2, the IC card 6 has a main body C. The main body C is formed in a card shape, for example, by plastic or the like. The IC card 6 includes a module (control module) M as a control unit and a biometric matching unit 30 in the main body C. For example, the module M is integrally formed with a communication interface connected to one or more IC chips. The module M is provided in the main body C in a state of being connected to a biometric matching unit 30 having an MPU 31 and a fingerprint sensor 11. Also, the biometric matching unit 30 and the module M may be formed as one module.
[0019] In the configuration example shown in FIG. 1, the module M as a control unit has a processor 21, a ROM 22, a RAM 23, a data memory 24, and a communication interface 12. The processor 21 includes circuits that perform various processes. The processor 21 is, for example, a CPU (Central Processing Unit). The processor 21 controls the entire IC card 6. The processor 21 realizes various processing functions by executing programs stored in the ROM 22 or data memory 24. However, some or all of the various functions performed by the processor 21, as described later, may be realized by hardware circuits.
[0020] ROM22 is a non-volatile memory that functions as program memory. ROM22 stores control programs and control data in advance. ROM22 is incorporated into the IC card 6 during the manufacturing stage with the control programs and control data already stored in it. The control programs and control data stored in ROM22 are pre-installed according to the specifications of the IC card 6. For example, ROM22 may store, as a first memory, authentication information for registering fingerprints (generated information) for the IC card 6, such as a fingerprint registration PIN (personal identification number), the IC card's manufacturing number, and the IC card's management number (card ID).
[0021] RAM23 is a volatile memory that functions as working memory. RAM23 also functions as a buffer for temporarily storing data being processed by the processor 21. For example, RAM23 functions as a communication buffer for temporarily storing data transmitted to and from external devices via the communication interface 12.
[0022] The data memory 24 is a non-volatile memory that allows data to be written to and rewritten. The data memory 24 is composed of, for example, EEPROM (Electrically Erasable Programmable Read Only Memory). Programs and various data according to the operational use of the IC card 6 are written to the data memory 24. Program files and data files are defined in the data memory 24, and control programs and various data are written to these files. In addition, part or all of the area of the data memory 24 is tamper-resistant, allowing data to be stored securely.
[0023] The data memory 24 has a first memory and a second memory. The first memory in the data memory 24 has a first memory area (first memory) that stores the fingerprint registration PIN (personal identification number), which is authentication information for fingerprint registration that is registered in advance. The first memory is located in a memory area of the data memory 24 where data (fingerprint registration PIN) can be securely held. However, the fingerprint registration PIN may also be stored in the ROM 22, in which case the ROM 22 functions as the first memory.
[0024] Furthermore, the fingerprint registration PIN may be generated using a fingerprint registration PIN generation function (authentication information generation function) such as a hash function, based on unique identification information that identifies the IC card, such as the IC card's serial number or management number (card ID). When the fingerprint registration PIN is dynamically generated using a fingerprint registration PIN generation function based on unique identification information for each IC card, such as the IC card's serial number or management number (card ID), the fingerprint registration PIN generation function for generating the fingerprint registration PIN should be stored in the ROM 22 or data memory 24 as the first memory, as program data that is kept secret.
[0025] Furthermore, the second memory in the data memory 24 is a second memory area that stores fingerprint information (biometric information) for fingerprint authentication of the legitimate user (registered person) of the IC card 6. The second memory in the data memory 24 stores the registered person's authentication fingerprint information as data for performing fingerprint authentication. For example, the second memory in the data memory 24 registers fingerprint information for a predetermined number of fingers for one registered person. The registered person's fingerprint information registered (stored) in the second memory is a fingerprint image or fingerprint characteristic data for comparison with the fingerprint information acquired by the fingerprint sensor 11. The fingerprint image or fingerprint characteristic data may be registered in an encrypted state. In addition, the second memory in the data memory 24 is provided in a memory area that allows for rewriting (appending) and deletion of fingerprint information.
[0026] The communication interface 12 comprises a communication control unit and an interface unit, and constitutes the communication unit. The communication interface 12 is an interface for communicating with the reader / writer 5, which supplies power and commands to the IC card 6. The communication interface 12 realizes the communication function provided by the communication method of the reader / writer 5.
[0027] For example, the communication interface 12 shall be configured to support contact communication and contactless communication. In this case, the communication interface 12 shall include a communication unit for the IC card 6 to communicate with the reader / writer 5 in contact as a contact-type IC card, and a communication unit for contactless (wireless) communication with the reader / writer.
[0028] As a communication unit for the IC card 6 to communicate as a contact-type IC card, the communication interface 12 includes a contact portion that physically and electrically contacts a contact portion provided on the reader / writer 5. The communication interface 12 realizes contact communication with the reader / writer 5 through a communication control circuit that controls the transmission and reception of signals via the contact portion.
[0029] Furthermore, as a communication unit for the IC card 6 to communicate as a contactless IC card, the communication interface 12 is equipped with an antenna that transmits and receives radio waves for contactless (wireless) communication with the reader / writer 5. The communication interface 12 achieves contactless communication with the reader / writer 5 through a modulation circuit for generating radio waves to be transmitted from the antenna and a demodulation circuit for generating a signal from the radio waves received by the antenna.
[0030] The biometric authentication unit 30 includes an MPU 31 and a fingerprint sensor 11, and is connected to module M, which acts as a control unit. The biometric authentication unit 30 also has a memory that stores authentication programs and other information for the MPU 31 to perform biometric authentication using biometric (fingerprint) authentication.
[0031] The fingerprint sensor 11 is a biosensor that acquires fingerprint information as biological information (an example of a generated information acquisition unit). For example, the fingerprint sensor 11 consists of a sensor that reads the fingerprint information (fingerprint image) of a person's finger. The fingerprint sensor 11 is provided so that the sensor that reads the fingerprint is exposed on the surface of the main body C of the IC card 6, and is configured to read the fingerprint of a person's finger held over the exposed sensor portion.
[0032] The MPU31 performs fingerprint (biometric) authentication using fingerprint information acquired by the fingerprint sensor 11 by executing a biometric authentication program. For example, the MPU31 extracts a fingerprint image from the image read by the fingerprint sensor 11, and performs fingerprint authentication by comparing the fingerprint image extracted from the image read by the fingerprint sensor with the registered person's fingerprint image (or fingerprint feature data) registered in the data memory 24.
[0033] In the configuration example shown in Figure 1, the MPU 31, which is provided separately from the processor 21, performs biometric authentication by matching biometric (fingerprint) data. However, the processor 21 may also perform biometric authentication. If the processor 21 performs biometric authentication, the biometric information read by the fingerprint sensor 11 should be supplied to the processor 21. For example, the processor 21 may extract fingerprint information from the image supplied by the fingerprint sensor 11 and compare the extracted fingerprint information with the registered user's fingerprint information registered in the data memory 24.
[0034] Next, the configuration of the user terminal 4 in the information management system 1 according to this embodiment will be described. Figure 3 is a block diagram showing an example configuration of a user terminal 4 in the information management system 1 according to this embodiment. User terminal 4 is an example of a terminal device operated by a user, and is implemented as a PC or a mobile terminal such as a smartphone. User terminal 4 is a device to which a reader / writer 5 is connected and which communicates with an IC card 6 provided (distributed) to the user.
[0035] In the configuration example shown in Figure 3, the user terminal 4 includes a processor 41, ROM 42, RAM 43, storage unit 44, communication unit 45, interface 46, display unit 47, and operation unit 48.
[0036] The processor 41, ROM 42, and RAM 43 constitute the control unit. The processor 41 performs various processes such as controlling each part and processing data by executing a program. The processor 41 is, for example, a CPU (Central Processing Unit). The processor 41 realizes various processing functions by executing a program stored in the ROM 42 or the memory unit 44. However, some or all of the various functions performed by the processor 41, as described later, may be realized by hardware circuits.
[0037] ROM42 is a non-volatile memory that functions as program memory. ROM42 stores pre-programmed control programs and control data. The control programs and data stored in ROM42 are pre-configured according to the specifications of the user terminal 4.
[0038] RAM43 is a volatile memory that functions as working memory. RAM43 also functions as a buffer for temporarily storing data being processed by the processor 41. For example, RAM43 functions as a communication buffer for temporarily storing data transmitted and received via the communication unit 45.
[0039] The storage unit 44 is a non-volatile memory that allows data to be written to and rewritten. The storage unit 44 is composed of a storage device such as a hard disk drive (HDD) or a solid-state drive (SSD). The storage unit 44 stores operating system programs, various application programs, and various types of data.
[0040] The communication unit 45 has a communication interface for communicating with an external device. The communication unit 45 includes a communication interface for communicating with the management device 2 via the network 3. The communication unit 45 may include a communication interface for connecting to the network 3 via a wired line, or it may include a communication interface for connecting to the network 3 via wireless communication.
[0041] Interface 46 connects to the reader / writer 5. Interface 46 only needs to have communication functions that correspond to the communication method provided by the reader / writer 5. The reader / writer 5 connected to interface 46 supplies power and commands to the IC card 6. The reader / writer 5 connected to interface 46 has communication functions that correspond to the communication method provided by the IC card 6.
[0042] Specifically, the reader / writer 5 connected to interface 46 has either a communication unit for communicating with a contactless IC card or a communication unit for communicating with a contact-type IC card, or both. For example, the reader / writer 5 for communicating with a contactless IC card includes an antenna for contactless (wireless) communication and a communication control circuit for processing radio waves transmitted and received via the antenna, and supplies power to the IC card presented at a predetermined location where the antenna is located to perform contactless communication. The reader / writer 5 for communicating with a contact-type IC card includes a contact unit that contacts the contacts of the IC card and a communication control circuit for controlling the transmission and reception of signals via the contacts.
[0043] The display unit 47 is a display that displays images. The display unit 47 is connected to the main body (control unit) of the user terminal 4 via a display interface. The operation unit 48 is one or more operation devices for inputting information. The operation unit 48 consists of operation devices such as touch keys, keyboards, numeric keypads, and pointing devices such as mice. The operation devices as the operation unit 48 are connected to the main body (control unit) of the user terminal 4 via interfaces for each device. For example, the display unit 47 and the operation unit 48 may be configured as a display device with a touch panel.
[0044] Next, the configuration of the management device 2 in the information management system 1 according to this embodiment will be described. Figure 4 is a block diagram showing an example configuration of the management device 2 in the information management system 1 according to this embodiment. Management device 2 is a device that manages information related to IC card 6. Management device 2 consists of a server device located on the network. Management device 2 also includes a device operated by the administrator of the information management system 1 or the administrator who manages the operation of IC card 6 provided to users.
[0045] In the configuration example shown in Figure 4, the management device 2 includes a processor 51, ROM 52, RAM 53, storage unit 54, communication unit 55, display unit 56, and operation unit 57. The processor 51, ROM 52, and RAM 53 constitute the control unit. The processor 51 performs various processes such as controlling each part and processing data by executing a program. The processor 51 is, for example, a CPU. The processor 51 realizes various processing functions by executing a program stored in the ROM 52 or the memory unit 54. However, some or all of the various functions performed by the processor 51, as described later, may be realized by hardware circuits.
[0046] ROM52 is a non-volatile memory that functions as program memory. ROM52 stores control programs and control data, among other things. RAM 53 is a volatile memory that functions as working memory. RAM 53 also functions as a buffer for temporarily storing data being processed by the processor 51. For example, RAM 53 functions as a communication buffer for temporarily storing data transmitted and received via the communication unit 55.
[0047] The storage unit 54 is a non-volatile memory that allows data to be written to and rewritten. The storage unit 54 is composed of a storage device such as a hard disk drive (HDD) or a solid-state drive (SSD). The storage unit 54 may store operating system programs, various application programs, and various data. The storage unit 54 may also store authentication information for authenticating administrators.
[0048] In this embodiment, the storage unit 54 has a storage area (storage unit) that stores a management information database 54a that stores information about the IC card 6 provided to the user. The management information database 54a will be described in detail later.
[0049] The communication unit 55 has a communication interface for communicating with an external device. The communication unit 55 includes a communication interface for communicating with the user terminal 4 via a network. The communication unit 55 may include a communication interface that connects to the network 3 by a wired line, or it may include a communication interface that connects to the network 3 by wireless communication.
[0050] The display unit 56 is a display that displays images. The display unit 56 is connected to the main body (control unit) of the management device 2 via a display interface. The operation unit 57 is one or more operation devices for inputting information. The operation unit 57 consists of operation devices such as touch keys, keyboards, numeric keypads, and pointing devices such as mice. The operation devices as the operation unit 57 are connected to the main body (control unit) of the management device 2 via interfaces for each device. For example, the display unit 56 and the operation unit 57 may be configured as a display device with a touch panel.
[0051] Next, an example of the configuration of the management information database 54a for which the management device 2 according to this embodiment manages information related to the IC card 6 will be described. In this embodiment, the management device 2 stores a management information database 54a in the storage unit 54. However, the management information database 54a only needs to be stored in memory accessible to the management device 2, and may be stored in a storage unit provided in another device accessible to the management device 2.
[0052] Figure 5 shows an example of the configuration of the management information database 54a. The management information database 54a stores information about the IC card 6 provided to the user for each IC card (card ID). In the configuration example shown in Figure 5, the management information database 54a stores information for each IC card 6 such as card ID, password (PW), fingerprint registration eligibility information (biometric information registration eligibility information), fingerprint registration status, name, user ID, fingerprint registration PIN (authentication information for biometric information registration), and registration count. The management information database 54a can also store unique identification information for the IC card 6, such as the serial number.
[0053] Furthermore, when dynamically generating the fingerprint registration PIN for IC card 6 using unique information (identification information such as the serial number) obtained from IC card 6 and a fingerprint registration PIN generation function, the management information database 54a does not need to store the fingerprint registration PIN. In this case, the fingerprint registration PIN generation function for generating the fingerprint registration PIN to be supplied to IC card 6 can be stored in the storage unit 54.
[0054] The card ID is identification information assigned to the IC card 6 provided to the user. The card ID is IC card identification information stored in the ROM 22 or data memory 24 of the IC card 6. For example, the management device 2 can read the card ID from the IC card 6 after it has become communicable via the user terminal 4 and the reader / writer 5. The serial number of the IC card 6 is also stored in the ROM 22 or data memory 24 of the IC card 6, similar to the card ID. The management device 2 can also read the serial number from the IC card 6 after it has become communicable via the user terminal 4 and the reader / writer 5.
[0055] A password is an example of user authentication information provided to a user. The password is used as authentication information for a user possessing IC card 6 to log in. The password is made known to the user who provided IC card 6 by some means. For example, the password is presented to the user along with IC card 6.
[0056] Furthermore, the password may be set and changed at the discretion of the administrator or operator, or it may be changed to information specified by the user. For example, the password may be temporarily registered with the initial authentication information issued for each IC card 6 presented to the user, notified to the user, and then updated to the authentication information specified by the user (user-specified password) after logging in with the initial authentication information.
[0057] The fingerprint registration eligibility information indicates whether fingerprint registration is permitted for the corresponding IC card 6. An administrator logged into the management device 2 in administrator mode specifies whether fingerprint registration is permitted for each IC card 6. The fingerprint registration eligibility information is set (updated) according to the specifications made by the administrator operating the management device 2 in administrator mode. For example, if the administrator instructs that fingerprint registration be permitted for a specific user's IC card 6, the fingerprint registration eligibility information for that IC card 6 will be set to "fingerprint registration permitted". Conversely, if the administrator instructs that fingerprint registration is not permitted for a specific user's IC card 6, the fingerprint registration eligibility information for that IC card 6 will be set to "fingerprint registration not permitted".
[0058] Alternatively, the administrator may specify the number of times fingerprint registration is permitted for IC card 6. If the number of permitted fingerprint registrations is specified, the fingerprint registration eligibility information for IC card 6 will store information indicating the number of permitted registrations. The fingerprint registration eligibility information for IC card 6 is controlled so that fingerprint registration is permitted until the number of fingerprint registrations for IC card 6 reaches the specified (set) number. For example, if the administrator specifies that fingerprint registration is permitted only once, the fingerprint registration eligibility information for IC card 6 will be set to "fingerprint registration permitted only once." In this case, once a fingerprint registration is performed for IC card 6, the fingerprint registration eligibility information for IC card 6 will be updated to "fingerprint registration prohibited."
[0059] The fingerprint registration information indicates whether or not fingerprints are registered on IC card 6. In other words, for IC card 6 with registered fingerprints, the fingerprint registration information will be "Yes" (fingerprint registered), and for IC card 6 without registered fingerprints or IC card 6 whose fingerprint registration has been deleted, the fingerprint registration information will be "No" (fingerprint not registered).
[0060] The name is the name of the user who provided the IC card 6 as part of their personal information. The user ID is identification information that identifies the user who provided the IC card 6. The user ID may also be identification information issued by the system, in which case the system should notify the user who provides (distributes) the IC card 6 of the identification information issued by the system. In addition, if the system provides each employee of a company or similar organization with an IC card 6, the user ID may be information that the user is aware of in advance, such as the employee number assigned to the user who provided the IC card 6.
[0061] The fingerprint registration PIN is the authentication information required to register fingerprint information to the IC card 6. The fingerprint registration PIN is set on the IC card 6 before it is provided to the user. The IC card 6 becomes ready for fingerprint registration only after successful authentication (matching) using the fingerprint registration PIN.
[0062] Furthermore, the fingerprint registration PIN can also be dynamically generated using a fingerprint registration PIN generation function such as a hash function, based on identification information of the IC card 6, such as the serial number of the IC card 6. In this case, the management device 2 does not need to manage (store) the fingerprint registration PIN for each IC card in the management information database 54a, but only needs to manage (store) the fingerprint registration PIN generation function for generating the fingerprint registration PIN. Also, it is not necessary to prepare a separate fingerprint registration PIN generation function for each individual IC card; it may be common to multiple IC cards.
[0063] In this embodiment, the fingerprint registration PIN set for each IC card 6 is managed by the management device 2 in the management information database 54a or the like without being disclosed to the user. When the management device 2 authorizes fingerprint registration for a particular IC card 6, it supplies the fingerprint registration PIN corresponding to that IC card 6 to the IC card 6 without informing the user. As a result, the IC card 6 can perform PIN authentication using the fingerprint registration PIN set for itself and the fingerprint registration PIN supplied by the management device.
[0064] Furthermore, even when the fingerprint registration PIN is generated by a fingerprint registration PIN generation function, it is not necessary to inform the user of the fingerprint registration PIN generation function. In this case, the fingerprint registration PIN generation function can be stored as a secret function in the memory of the management device 2, such as in the storage unit 54. Alternatively, the fingerprint registration PIN generation function may also be incorporated as a program stored in the memory of the IC card 6, such as in the ROM 22.
[0065] The registration count indicates the number of times a fingerprint has been registered for IC card 6. For example, the registration count may represent the cumulative number of times fingerprint registration has been performed on IC card 6. In this case, the registration count is incremented each time fingerprint registration is performed on IC card 6. However, the registration count may also represent information indicating the number of fingerprint registrations performed over a predetermined period. Using such a registration count, it becomes possible to extract IC cards or users whose fingerprint registration count exceeds a predetermined threshold.
[0066] Next, we will describe the process by which the administrator sets whether or not to register fingerprints to the IC card 6 in the management device 2 according to this embodiment. The management device 2 according to this embodiment has an administrator authentication function that authenticates whether the user is a legitimate administrator. When authentication (administrator authentication) using administrator authentication information is successful, the management device 2 operates in administrator mode with the user logged in as an administrator. Two-factor authentication can also be introduced for administrator authentication. As one function in administrator mode, the management device 2 has a function to set whether or not fingerprint registration to the IC card 6 is permitted.
[0067] For example, when the administrator instructs the management device 2 to enable or disable fingerprint registration in administrator mode, the management device 2 displays a management screen on the display unit 56 to instruct whether or not fingerprint registration is enabled for each IC card (each IC card to be managed) 6 provided to the user. With the management screen displayed on the display unit 56, the administrator uses the operation unit 57 to instruct whether or not fingerprint registration is enabled (or the number of times fingerprint registration is enabled) for the IC cards 6 that are permitted to register fingerprints. The management device 2 sets whether or not fingerprint registration is enabled for each IC card 6 in the management information database 54a according to the instructions entered into the operation unit 57.
[0068] Figure 6 shows an example of a display on the display unit 56 of the management device 2 according to the embodiment, showing a management screen (fingerprint registration management screen) for setting whether or not to register fingerprints to the IC card 6. In the example of the fingerprint registration management screen shown in Figure 6, for each IC card 6, information managed in the management information database 54a is displayed, including the card ID, password (PW), whether fingerprint registration is possible (information on whether biometric information can be registered), whether fingerprint registration has been completed, name, user ID, and the number of registrations. The card ID, password (PW), whether fingerprint registration has been completed, name, user ID, and number of registrations each represent information stored in the management information database 54a.
[0069] In the example display shown in Figure 6, the fingerprint registration availability section displays checkboxes 61 that specify whether fingerprint registration is permitted for each IC card 6. A check mark is displayed on the checkbox 61 corresponding to the IC card 6 for which fingerprint registration is permitted, according to instructions from the administrator. Whether or not a check mark is displayed on the checkbox 61 indicates whether fingerprint registration is permitted.
[0070] The check marks on the checkboxes 61 corresponding to each IC card 6 can be shown or cleared by the administrator operating the control unit 57. For example, the administrator can show a check mark on the checkbox 61 corresponding to the IC card 6 for which fingerprint registration is permitted. The management device 2 sets the fingerprint registration status information for the IC card 6 corresponding to the checkbox 61 with the displayed check mark to "fingerprint registration permitted". Also, when the check mark on a checkbox 61 is cleared in response to the administrator's operation, the management device 2 sets the fingerprint registration status information for the IC card 6 corresponding to the checkbox 61 with the cleared check mark to "fingerprint registration not permitted".
[0071] In the example display shown in Figure 6, the administrator specifies whether or not to allow fingerprint registration based on the presence or absence of a checkmark in checkbox 61. However, the fingerprint registration management screen may also allow the administrator to specify the number of times fingerprint registration is permitted for each IC card 6. For example, in the example display shown in Figure 6, the number of times fingerprint registration is permitted for each IC card 6 may be entered in each checkbox 61. In this case, the management device 2 should set the number entered in checkbox 61 as the number of times fingerprint registration is permitted.
[0072] Next, an example of the operation of the process (fingerprint registration process) for registering fingerprint information on the IC card 6 provided to the user in the information management system 1 according to the embodiment will be described. Figure 7 is a sequence diagram illustrating an example of the operation of a fingerprint registration process in which fingerprint information is registered on an IC card 6 provided to a user in the information management system 1 according to the embodiment. Here, it is assumed that the user is provided (distributed) with an IC card 6 in which information is registered in a management information database 54a as shown in Figure 5. In addition, it is assumed that the user is notified of the password (or password and user ID) that is registered in association with the IC card 6.
[0073] In the information management system 1, the processor 51 of the management device 2 provides a web application (web app) to a user terminal 4 that communicates via the network 3. The processor 51 of the management device 2 receives instructions from the user terminal 4 via the web application, such as fingerprint registration for the IC card 6. For example, the processor 51 of the management device 2 accepts user login using the password (password and user ID) notified along with the IC card 6, and accepts processing such as fingerprint registration for the IC card 6 according to the instructions of the logged-in user.
[0074] In other words, a user who wants to register their fingerprint on the IC card 6 uses a user terminal 4 connected to a reader / writer 5 capable of communicating with the IC card 6 they possess to access the management device 2. The processor 41 of the user terminal 4 accesses the management device 2 via the network 3 using the communication unit 45 (step ST11).
[0075] When the processor 41 of the user terminal 4 accesses the management device 2, it executes a predetermined web application provided by the management device 2. When the web application is running, the processor 41 of the user terminal 4 inputs the user's user ID and a password for processing the IC card 6 using the operation unit 48 (step ST12). Note that the information entered by the user when logging in can also be a combination of card ID and password, rather than a combination of user ID and password. In this embodiment, the method of logging in using a combination of user ID and password will be described.
[0076] For example, a user who is newly provided with an IC card 6 enters the password notified when the IC card 6 is provided, along with their user ID (e.g., employee number), into the user terminal 4 using the operation unit 48. When the user ID and password are entered by the operation unit 48, the processor 41 of the user terminal 4 sends the entered user ID and password to the management device 2 along with a user authentication request (step ST13).
[0077] The management device 2 receives a user authentication request from the user terminal 4, including a password and user ID, via the communication unit 55. When the processor 51 of the management device 2 receives the user ID and password entered on the user terminal 4, it performs user authentication using the received user ID and password (step ST14).
[0078] For example, the processor 51 of the management device 2 searches the management information database 54a using the user ID received along with the user authentication request as the search key. The processor 51 of the management device 2 identifies the password corresponding to the user ID found in the management information database 54a and determines whether it matches the password received along with the user authentication request.
[0079] The processor 51 of the management device 2 determines that user authentication has been successful if the password in the management information database 54a matches the received password, recognizing the user as the user indicated by the user ID. Conversely, the processor 51 of the management device 2 determines that user authentication has failed if the user ID does not exist in the management information database 54a, or if the password corresponding to the user ID in the management information database 54a does not match the received password.
[0080] When user authentication is successful, the processor 51 of the management device 2 determines whether fingerprint authentication is possible for the IC card 6 held by the user who successfully authenticated (the logged-in user) (step ST15). For example, the processor 51 determines in the management information database 54a whether the fingerprint registration permission information corresponding to the authenticated user ID is set to allow fingerprint registration or not.
[0081] The processor 51 of the management device 2 generates a user operation screen to be provided to the user according to the result of the fingerprint registration approval / rejection determination (step ST16). The processor 51 of the management device 2 transmits the user operation screen corresponding to the fingerprint registration approval / rejection determination result to the user terminal 4 so that it is displayed on the display unit 47 of the user terminal 4 (step ST17).
[0082] For example, if fingerprint registration is permitted for the IC card 6 (the IC card with a card ID corresponding to the user ID) held by the user, the processor 51 of the management device 2 generates a user operation screen that includes a button to perform fingerprint registration (a registration button). If fingerprint registration is not permitted for the IC card 6 held by the user, the processor 51 of the management device 2 generates a user operation screen that does not have a fingerprint registration button (a registration button).
[0083] Figure 8 shows an example of the user operation screen (user operation screen with fingerprint registration enabled) displayed on the display unit 47 of the user terminal 4 when fingerprint registration for the IC card 6 held by the user is permitted. Figure 9 shows an example of the user operation screen displayed on the display unit 47 of the user terminal 4 when fingerprint registration for the IC card 6 held by the user is permitted.
[0084] According to the display example shown in Figure 8, the user operation screen where fingerprint registration is possible displays the fingerprint matching button 71, the registration confirmation button 72, the fingerprint registration button (registration button) 73, and the fingerprint deletion button 74. In contrast, the user operation screen where fingerprint registration is not possible does not display the fingerprint registration button 73 and the fingerprint deletion button 74, but displays the fingerprint matching button 71 and the registration confirmation button 72. If no fingerprints are registered, only the registration confirmation button 72 may be displayed.
[0085] The fingerprint matching button 71 is a button that is instructed when attempting fingerprint matching, and the registration confirmation button 72 is a button that is instructed when confirming information about the logged-in user (information corresponding to the user ID). The fingerprint registration button 73 is a button that is instructed when executing the fingerprint registration process to register a fingerprint (fingerprint information for fingerprint authentication) on the IC card 6, and the fingerprint deletion button 74 is a button that is instructed when deleting a fingerprint (fingerprint information for fingerprint authentication) registered on the IC card 6.
[0086] In other words, the processor 51 of the management device 2 displays a user operation screen on the display unit 47 of the user terminal 4 that instructs the user to register and delete fingerprints if the logged-in user's IC card 6 is capable of fingerprint registration, and displays a user operation screen on the display unit 47 of the user terminal 4 that does not allow the user to select fingerprint registration or deletion if the logged-in user's IC card 6 is not capable of fingerprint registration. As a result, when user authentication is successful, the management device 2 can provide a user interface in which the user can select fingerprint registration or deletion if the user's IC card 6 is capable of fingerprint registration, and a user interface in which the user cannot select fingerprint registration or deletion if the user's IC card 6 is not capable of fingerprint registration.
[0087] The user terminal 4 receives the user operation screen from the management device 2 via the communication unit 45. The processor 41 of the user terminal 4 displays the user operation screen received from the management device 2 on the display unit 47 (step ST18). Once the processor 41 of the user terminal 4 displays the user operation screen on the display unit 47, it receives operation instructions for the user operation screen from the operation unit 48.
[0088] When a user operation screen indicating that fingerprint registration is possible is displayed on the display unit 47, the user can instruct the user to register their fingerprint to the IC card 6 on that user operation screen. Here, it is assumed that a user operation screen indicating that fingerprint registration is possible, as shown in Figure 8, is displayed on the display unit 47, and that the fingerprint registration button 73 is selected (instructed) on the user operation screen (step ST19).
[0089] When the user terminal 4's processor 41 is instructed to perform fingerprint registration, it sends a request to the management device 2 to perform fingerprint registration on the IC card 6 (indicating that the fingerprint registration button 73 has been pressed) (step ST20). The user terminal 4's processor 41 may also confirm to the reader / writer 5 that the IC card 6 to be registered is being presented when the fingerprint registration button 73 is pressed.
[0090] For example, when the fingerprint registration button 73 is pressed, the processor 41 of the user terminal 4 confirms that there is an IC card 6 that is in a state where it can communicate with the reader / writer 5. In this case, when the fingerprint registration button 73 is pressed, the processor 41 of the user terminal 4 confirms that the IC card 6 to be registered is presented to the reader / writer 5, and the communication unit 45 may send a request to the management device 2 to execute fingerprint registration for the IC card 6. When a communicable IC card 6 is presented to the reader / writer 5, the management device 2 and the IC card 6 become capable of sending and receiving data via the user terminal 4 and the reader / writer 5.
[0091] When the fingerprint registration button 73 is pressed on the user terminal 4 communicating via the communication unit 55, the processor 51 of the management device 2 requests the card ID from the IC card 6 presented to the reader / writer 5 connected to the user terminal 4 (step ST21). For example, the processor 51 of the management device 2 sends a command to the IC card 6 presented to the reader / writer 5 connected to the user terminal 4 to request the reading of the card ID.
[0092] The IC card 6 receives a command requesting a card ID from the management device 2 via the communication interface 12 through the user terminal 4 and the reader / writer 5. The processor 21 of the IC card 6 reads the card ID stored in the ROM 22 or data memory 24 of the IC card 6 according to the received command (step ST22), and sends a response containing the read card ID to the management device 2, which is the source of the command (step ST23).
[0093] The management device 2 receives responses from the user terminal 4 and the IC card 6 via the reader / writer 5 using the communication unit 55. When the processor 51 of the management device 2 receives a response containing the card ID read by the IC card 6, it checks whether the received card ID matches the card ID of the IC card provided to the logged-in user (step ST24).
[0094] For example, the processor 51 of the management device 2 checks whether the card ID received from the IC card 6 matches the card ID corresponding to the logged-in user ID. If the card ID of the IC card 6 communicating with the reader / writer 5 matches the card ID corresponding to the logged-in user ID, the processor 51 of the management device 2 assumes that the logged-in user's legitimate IC card 6 has been presented to the reader / writer 5.
[0095] When the processor 51 of the management device 2 confirms that the user's IC card 6 is presented to the reader / writer 5 based on the card ID, it identifies the fingerprint registration PIN set on the IC card 6 (step ST25). For example, the processor 51 of the management device 2 identifies the fingerprint registration PIN set on the IC card corresponding to the card ID by searching the management information database 54a with the card ID.
[0096] Alternatively, the processor 51 of the management device 2 may obtain the serial number (identification information) of the IC card corresponding to the card ID and identify the card by generating a fingerprint registration PIN from that serial number using a fingerprint registration PIN generation function. In this case, the processor 51 of the management device 2 may obtain the serial number of the IC card corresponding to the card ID by searching the management information database 54a with the card ID, or it may request the serial number from the IC card 6 and obtain the serial number read by the IC card 6. Furthermore, the management device 2 may store a function such as a hash function in its storage unit as a fingerprint registration PIN generation function for generating a fingerprint registration PIN from the IC card's serial number.
[0097] As a specific example, let's assume the serial number of IC card 6 is "id1", the fingerprint registration PIN generation function is the hash function f(x), and the fingerprint registration PIN for IC card 6 generated from "id1" and the hash function f(x) is f(id1). In this case, the management device 2 holds the hash function f(x) as a secret function. The processor 51 of the management device 2 obtains id1, which is the serial number of IC card 6 (the serial number id1 corresponding to the card ID), and generates f(id1), which is the fingerprint registration PIN for IC card 6, from the obtained id1.
[0098] When the processor 51 of the management device 2 identifies the fingerprint registration PIN, it supplies an authentication request using that fingerprint registration PIN to the IC card 6 (step ST26). Here, since the authentication request including the fingerprint registration PIN is supplied from the management device 2 to the IC card 6, the fingerprint registration PIN can be kept secret from the user operating the user terminal 4. Alternatively, the processor 51 of the management device 2 may transmit the fingerprint registration PIN to the IC card 6 in a concealed state so that it can be decrypted within the IC card 6. This makes it possible to prevent the fingerprint registration PIN from being identified not only on the network 3, but also on the user terminal 4 and the reader / writer 5.
[0099] Furthermore, when the management device 2 generates f(id1) from the serial number (identification information) "id1" of the IC card 6 and the hash function (fingerprint registration PIN generation function) f(x), the processor 51 should supply the authentication request to the IC card 6 using the f(id1) generated using the hash function f(x) as the fingerprint registration PIN. By keeping the hash function f(x) used as the fingerprint registration PIN generation function secret through this process, the fingerprint registration PIN will not be known to third parties, and the vendor manufacturing the IC card can reduce the effort required to issue a separate fingerprint registration PIN for each IC card.
[0100] The IC card 6 receives an authentication request (command) from the management device 2 via the communication interface 12, using a fingerprint registration PIN, through the user terminal 4 and the reader / writer 5. The processor 21 of the IC card 6 performs authentication (PIN authentication) by determining whether the received fingerprint registration PIN matches a fingerprint registration PIN that has been pre-set (stored) in the ROM 22 or data memory 24 of the IC card 6 (step ST27). If the processor 21 of the IC card 6 matches a pre-set fingerprint registration PIN, it sends a response containing information indicating that the authentication of the fingerprint registration PIN was successful to the management device 2, which sent the command (step ST28).
[0101] Furthermore, the processor 21 of the IC card 6 may generate a fingerprint registration PIN using a fingerprint registration PIN generation function stored in the ROM 22 or data memory 24 of the IC card 6 and its own serial number (identification information), even if the fingerprint registration PIN is not stored in advance. In this case, the processor 21 of the IC card 6 may perform PIN authentication by comparing the fingerprint registration PIN generated using the fingerprint registration PIN generation function and its own serial number (identification information) with the fingerprint registration PIN received from the management device 2. In addition, the processor 21 of the IC card 6 may also perform fingerprint registration PIN authentication by generating information that will become the serial number (identification information) from the fingerprint registration PIN received from the management device 2 using the inverse function of the fingerprint registration PIN generation function, and checking whether the generated information matches its own serial number.
[0102] When the processor 51 of the management device 2 receives a response from the IC card 6 indicating that the authentication of the fingerprint registration PIN was successful, it supplies instructions to the user terminal 4 and the IC card 6 to perform fingerprint registration on the IC card 6 (steps ST29, ST30).
[0103] The processor 41 of the user terminal 4 displays instructions for fingerprint registration for the IC card 6 on the display unit 56, which are presented on the reader / writer 5, in response to an instruction from the management device 2 to perform fingerprint registration for the IC card 6 (step ST31). For example, as instructions for fingerprint registration, the processor 41 of the user terminal 4 displays instructions on the display unit 56 indicating that the finger to be registered is on the fingerprint sensor of the IC card 6.
[0104] Furthermore, when the processor 21 of the IC card 6 receives an instruction from the management device 2 to perform fingerprint registration, it reads the fingerprint using the fingerprint (biometric) sensor 11 (step ST32). For example, the processor 21 of the IC card 6 performs a predetermined number of fingerprint scans as a reading process to acquire a fingerprint (fingerprint information) for registration. Specifically, the processor 21 of the IC card 6 acquires fingerprint information from the fingerprint sensor 11 multiple times while confirming that the user is shifting the position and orientation of one finger relative to the fingerprint sensor 11. In this case, the processor 21 of the IC card 6 generates a fingerprint (fingerprint information) for registration by integrating the fingerprint information read by multiple scans. However, the present invention does not depend on an algorithm for generating a fingerprint (fingerprint information) for registration and is applicable to any algorithm.
[0105] The processor 21 of the IC card 6 generates fingerprint information for registration for one finger and securely registers (saves) the generated fingerprint information as registration fingerprint information in the data memory 24 (step ST33). Alternatively, the processor 21 of the IC card 6 may determine whether or not to register the generated registration fingerprint information by comparing it with the fingerprint information read again by the fingerprint sensor 11. In this case, the processor 21 registers the generated fingerprint information if the fingerprint matching is successful, and performs another fingerprint scan if the fingerprint matching fails.
[0106] When the IC card 6's processor 21 has completed registering the fingerprint information of one finger, it sends a response to the management device 2, which is the source of the command, containing information indicating that the fingerprint of one finger has been registered (step ST34).
[0107] When the processor 51 of the management device 2 receives notification that fingerprint registration is complete, it determines whether or not to terminate fingerprint registration for the IC card 6. For example, the processor 51 of the management device 2 determines whether fingerprint registration for a predetermined number of fingers has been completed for one IC card 6. In this case, if the number of registered fingers is less than the predetermined number, the processor 51 of the management device 2 repeats the process in steps ST29-34 described above. Also, if the number of registered fingers reaches the predetermined number, the processor 51 of the management device 2 completes fingerprint registration for the IC card 6. Furthermore, if the IC card 6 can register fingerprints for 2 or more fingers up to M fingers, the management device 2 may be configured to allow setting the number of registered fingerprints (1 or more, up to M).
[0108] When the processor 51 of the management device 2 completes fingerprint registration for the IC card 6, it updates the information in the management information database 54a corresponding to the IC card 6 of the logged-in user (user ID) (step ST35). The processor 51 of the management device 2 updates the information in the management information database 54a for the IC card 6 of the logged-in user (user ID), including information on whether fingerprint registration is possible, the number of registrations, and whether fingerprint registration has been completed.
[0109] For example, if the number of times a user's IC card 6 is permitted for fingerprint registration is set to only once, the processor 51 of the management device 2 updates the fingerprint registration availability information to "fingerprint registration not permitted," updates the fingerprint registration status information to "fingerprint registration present," and increments the registration count upon completion of fingerprint registration. Also, if the number of times a user's IC card 6 is permitted for fingerprint registration is set to N times, the processor 51 of the management device 2 updates the number of permitted fingerprint registrations in the fingerprint registration availability information to -1, updates the fingerprint registration status information to "fingerprint registration present," and increments the registration count upon completion of fingerprint registration.
[0110] According to the fingerprint registration process described above, the information management system according to the embodiment sets whether or not fingerprint registration is permitted for the IC card provided to the user in the management device, and when fingerprint registration is permitted for the IC card of a user who has logged into the management device, the management device supplies the fingerprint registration PIN set on the IC card of the logged-in user to the IC card that communicates with the reader / writer connected to the user terminal in response to a fingerprint registration request from the user terminal, and performs fingerprint registration for the IC card when PIN authentication using the fingerprint registration PIN from the management device on the IC card communicating with the reader / writer is successful.
[0111] As a result, according to the information management system of this embodiment, fingerprint registration on an IC card can be performed by PIN authentication based on the fingerprint registration PIN on the IC card of a user logged into the management device, without informing the user of the fingerprint registration PIN. As a result, it becomes unnecessary to notify each user who is provided (distributed) with an IC card of the fingerprint registration PIN. Furthermore, it eliminates the need for each user to manually enter the notified fingerprint registration PIN in order to register their fingerprint on the IC card, and prevents users from using the fingerprint registration PIN without restriction.
[0112] Furthermore, according to the information management system of this embodiment, the management device can set whether or not fingerprint registration is permitted for the IC card provided to the user. Therefore, the management device can allow fingerprint registration for IC cards of users for whom fingerprint registration is enabled. As a result, the management device can control (manage) the execution of fingerprint registration for IC cards provided to each user.
[0113] Next, an example of the operation of the process (fingerprint deletion process) for deleting fingerprint information registered on the IC card 6 held by the user in the information management system 1 according to the embodiment will be described. Figure 10 is a sequence diagram illustrating an example of the operation of a fingerprint deletion process in the information management system 1 according to the embodiment, which deletes fingerprint information registered on an IC card 6 held by a user. First, when the information management system 1 deletes a fingerprint registered on the IC card 6, it displays a user operation screen generated by the management device 2 on the display unit 47 of the user terminal 4 by a process similar to steps ST11-18 in Figure 7 described above (steps ST51-58).
[0114] In other words, if fingerprint registration on the IC card of a user logged into the management device 2 is permitted (fingerprint deletion is permitted), the display unit 47 of the user terminal 4 will display a user operation screen including a fingerprint registration button 73 and a fingerprint deletion button 74, as shown in Figure 9. At this point, the processor 41 of the user terminal 4 will be assumed to have detected that the fingerprint deletion button 74 has been selected (instructed) by the user (step ST59).
[0115] When the user terminal 4's processor 41 instructs the user to press the fingerprint deletion button 74, it sends a request to the management device 2 to execute fingerprint deletion on the IC card 6 (indicating that the fingerprint deletion button 74 was pressed) (step ST60).
[0116] Furthermore, the processor 41 of the user terminal 4 may be configured to confirm that the IC card 6 to be subject to fingerprint deletion is presented to the reader / writer 5 when the fingerprint deletion button 74 is pressed. For example, the processor 41 of the user terminal 4 may, after confirming that the IC card 6 to be subject to fingerprint deletion is presented to the reader / writer 5 when the fingerprint deletion button 74 is pressed, send a request to the management device 2 to execute fingerprint deletion on the IC card 6.
[0117] When the processor 51 of the management device 2 is notified that the fingerprint deletion button 74 is pressed on the user terminal 4, it requests the card ID from the IC card 6 presented to the reader / writer 5 connected to the user terminal 4, similar to step ST21 (step ST61). For example, the processor 51 of the management device 2 sends a command to the IC card 6 presented to the reader / writer 5 connected to the user terminal 4 to request the reading of the card ID.
[0118] The IC card 6 receives a command requesting a card ID from the management device 2 via the communication interface 12 through the user terminal 4 and the reader / writer 5. The processor 21 of the IC card 6 reads the card ID stored in the ROM 22 or data memory 24 of the IC card 6 according to the received command (step ST62), and sends a response containing the read card ID to the management device 2, which is the source of the command (step ST63).
[0119] When the processor 51 of the management device 2 receives a response from the IC card 6 that includes a card ID, it checks whether the received card ID matches the card ID of the IC card provided to the logged-in user (step ST64). For example, the processor 51 of the management device 2 checks whether the card ID received from the IC card 6 matches the card ID corresponding to the logged-in user ID.
[0120] The processor 51 of the management device 2, if the card ID from the IC card 6 matches the card ID corresponding to the logged-in user ID, assumes that a valid IC card 6 belonging to the logged-in user is being presented to the reader / writer 5, and identifies the fingerprint registration PIN set on the IC card 6 from the management information database 54a (step ST65). For example, the processor 51 of the management device 2 identifies the fingerprint registration PIN set on the IC card corresponding to the card ID by searching the management information database 54a with the card ID.
[0121] When the processor 51 of the management device 2 identifies the fingerprint registration PIN, it supplies an authentication request using that fingerprint registration PIN to the IC card 6 (step ST66). Here, since the authentication request including the fingerprint registration PIN is supplied from the management device 2 to the IC card 6, the user operating the user terminal 4 is prevented from knowing the fingerprint registration PIN.
[0122] When IC card 6 receives an authentication request (command) from management device 2 using a fingerprint registration PIN, it performs authentication (PIN authentication) by checking whether the received fingerprint registration PIN matches a fingerprint registration PIN that has been previously set (stored) in the ROM 22 or data memory 24 of IC card 6 (step ST67).
[0123] If the IC card 6's processor 21 matches a pre-set fingerprint registration PIN, it sends a response to the management device 2, the source of the command, containing information indicating that the authentication of the fingerprint registration PIN was successful (step ST68). Note that, similar to the fingerprint registration process, the fingerprint registration PIN may also be generated from the fingerprint registration PIN generation function and the serial number during the fingerprint deletion process.
[0124] When the processor 51 of the management device 2 receives a response from the IC card 6 indicating that the authentication of the fingerprint registration PIN was successful, it supplies a command to the user terminal 4 and the IC card 6 to delete the fingerprint (steps ST69, ST70).
[0125] The processor 41 of the user terminal 4 displays a message on the display unit 47 indicating that it will perform fingerprint deletion on the IC card 6 presented to the reader / writer 5, in response to an instruction from the management device 2 to delete the fingerprint (step ST71).
[0126] Furthermore, when the processor 21 of the IC card 6 receives an instruction from the management device 2 to execute fingerprint registration, it deletes the fingerprint (fingerprint information) for fingerprint authentication stored in the data memory 24 (step ST72). After deleting the fingerprint information for fingerprint authentication, the processor 21 of the IC card 6 sends a response to the management device 2, the source of the command, which contains information indicating that the fingerprint information for fingerprint authentication that was registered on the IC card has been deleted (step ST73).
[0127] When the processor 51 of the management device 2 receives notification that the fingerprint deletion is complete, it updates the management information in the management information database 54a corresponding to the IC card 6 of the logged-in user (user ID) in accordance with the deletion of the fingerprint information for fingerprint authentication on the IC card 6 (step ST74). For example, the processor 51 of the management device 2 updates the information regarding whether or not fingerprints are registered in the management information for the IC card 6 of the logged-in user (user ID) in the management information database 54a. Specifically, the processor 51 of the management device 2 updates the information regarding whether or not fingerprints are registered to "no fingerprint registration" in accordance with the completion of fingerprint deletion.
[0128] As described above, the information management system according to the embodiment can perform a fingerprint deletion process to delete fingerprint information already registered on an IC card, similar to the fingerprint registration process described above. If the IC card of a logged-in user is set to allow fingerprint registration (equivalent to allowing fingerprint deletion), the management device supplies the fingerprint registration PIN set on the logged-in user's IC card to the IC card communicating with the reader / writer connected from the management device to the user terminal in response to a fingerprint deletion request from the user terminal. The IC card deletes the fingerprint registered on the IC card if PIN authentication using the fingerprint registration PIN supplied by the management device is successful.
[0129] As a result, according to the information management system of this embodiment, fingerprint deletion from an IC card can be performed by PIN authentication based on the fingerprint registration PIN on the IC card of a user who is logged into the management device, without informing the user of the fingerprint registration PIN. As a result, it is no longer necessary to notify each user who is provided (distributed) with an IC card of the fingerprint registration PIN, and the user does not need to enter the fingerprint registration PIN themselves in order to delete fingerprints from the IC card.
[0130] The functions described in each of the embodiments above can be implemented not only using hardware, but also by loading a program containing each function into a computer using software. Furthermore, each function may be configured using either software or hardware, as appropriate.
[0131] While several embodiments of the present invention have been described, these embodiments are presented as examples only and are not intended to limit the scope of the invention. These novel embodiments can be carried out in a variety of other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims of the invention and its equivalents. [Explanation of symbols]
[0132] 1...Information management system, 2...Management device, 3...Network, 4...User terminal (terminal device), 5...Reader / writer, 6...IC card (portable electronic device), C...Main unit, M...Module, 11...Fingerprint sensor, 12...Communication interface, 21...Processor, 22...ROM (first memory), 23...RAM, 24...Data memory (first memory, second memory), 30...Biometric authentication unit, 31...MPU, 41...Processor, 42...ROM, 43...RAM, 44...Storage unit, 45...Communication unit, 46...Interface, 47...Display unit, 48...Operation unit, 51...Processor (control unit), 52...ROM, 53...RAM, 54...Storage unit, 54a...Management information database, 55...Communication unit, 56...Display unit, 57...Operation unit.
Claims
1. In an information management system having a portable electronic device and a management device, The aforementioned portable electronic device is A biosensor that acquires a person's biometric information, A communication interface for communicating with the reader / writer, A first memory for storing authentication information for biometric information registration, A rewritable second memory for storing the user's biometric information of the portable electronic device, The system includes a processor that, upon successful authentication using information received from the management device via the reader / writer communicating through the aforementioned communication interface and authentication information for biometric information registration stored in the first memory, registers the biometric information acquired by the biosensor in the second memory in response to an execution instruction for biometric information registration from the management device. The aforementioned control device is A communication unit that communicates with the terminal device to which the reader / writer is connected, A storage unit that stores user authentication information of a user who is a user of the portable electronic device, The system includes a control unit which, upon successful user authentication based on information input to the terminal device communicating via the communication unit and user authentication information stored in the storage unit, transmits authentication information for biometric information registration set on the portable electronic device possessed by the user of the user authentication information to the portable electronic device communicating via the terminal device and the reader / writer, and, upon successful authentication using the authentication information for biometric information registration on the portable electronic device, causes the portable electronic device to perform biometric information registration. Information management system.
2. The storage unit of the management device stores the user authentication information and the authentication information for biometric information registration set in the portable electronic device in association with each other. The control unit of the management device identifies the authentication information for biometric information registration corresponding to the user authentication information for which the user authentication was successful as the authentication information for biometric information registration set in the portable electronic device. The information management system according to claim 1.
3. The storage unit of the management device stores an authentication information generation function for generating authentication information for biometric information registration from the identification information of the portable electronic device, The control unit of the management device acquires identification information of the portable electronic device and generates authentication information for biometric information registration using the identification information of the portable electronic device and the authentication information generation function. The information management system according to claim 1.
4. The storage unit of the management device stores biometric information registration feasibility information, which indicates whether or not biometric information can be registered to the portable electronic device possessed by the user, in association with the user authentication information. If user authentication is successful, the control unit of the management device transmits the authentication information for biometric information registration to the portable electronic device that communicates with the reader / writer connected to the terminal device, if the portable electronic device is set to allow biometric information registration. The information management system according to claim 1.
5. The control unit of the management device receives an instruction from the administrator to set whether or not to register biometric information to the portable electronic device stored in the storage unit when the administrator logs in, and sets information on whether or not to register biometric information to the portable electronic device in accordance with the instruction from the administrator. The information management system according to claim 4.
6. The control unit of the management device receives an instruction from the administrator regarding the number of times biometric information registration is permitted for the portable electronic device stored in the storage unit when the administrator logs in, and sets information on whether biometric information registration is permitted for the portable electronic device to permit the registration of biometric information for the number of times instructed by the administrator. The information management system according to claim 5.
7. The control unit of the management device updates the registration status information for the portable electronic device to "registration not permitted" when it has performed the registration of biometric information for the portable electronic device the number of times permitted for registration of biometric information. The information management system according to claim 6.
8. The control unit of the management device, if the registration of biometric information for the portable electronic device corresponding to the user authentication information for which the user authentication was successful indicates that registration is possible, supplies the terminal device with a user operation screen including a registration button that instructs the registration of biometric information, and transmits authentication information for biometric information registration corresponding to the user authentication information to the portable electronic device in response to the instruction to press the registration button on the user operation screen. The information management system according to claim 4.
9. The portable electronic device is an IC card having a module having the communication interface, a first memory, a second memory, and the processor, and a main body that maintains the state in which the biosensor and the module are connected. An information management system according to any one of claims 1 to 8.
10. The aforementioned biometric information is fingerprint information, The aforementioned biosensor is a fingerprint sensor that acquires fingerprint information as biometric information. The information management system according to claim 9.
11. In a management device for managing portable electronic devices provided to users, A communication unit that communicates with a terminal device to which a reader / writer that communicates with the aforementioned portable electronic device is connected, A storage unit that stores user authentication information of a user who is a user of the portable electronic device, A control unit that, upon successful user authentication based on information input to the terminal device communicating via the communication unit and user authentication information stored in the storage unit, transmits authentication information for biometric information registration set on the portable electronic device possessed by the user of the user authentication information to the portable electronic device communicating via the terminal device and the reader / writer, and, upon successful authentication using the authentication information for biometric information registration on the portable electronic device, causes the portable electronic device to perform biometric information registration. A control device having the following features.
12. A method for managing information using a management device that manages portable electronic devices provided to users, The reader / writer that communicates with the aforementioned portable electronic device communicates with a terminal device to which it is connected. The user authentication information of the user who is a user of the portable electronic device is stored in the storage unit. User authentication is performed based on the information input to the terminal device and the user authentication information stored in the storage unit. If the user authentication is successful, the authentication information for biometric information registration, which is set on the portable electronic device held by the user of the user authentication information, is transmitted to the portable electronic device that communicates via the terminal device and the reader / writer. If authentication using the authentication information for biometric information registration is successful in the portable electronic device, the portable electronic device will be instructed to register the biometric information in response to a request from the terminal device. Information management method.