Authentication terminal, method for controlling the authentication terminal, program and system

The authentication terminal system addresses the inefficiency of biometric authentication servers by requesting and using a list of authorized passers to reduce server load and improve accuracy in access control for restricted areas.

JP2026105095APending Publication Date: 2026-06-25NEC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
NEC CORP
Filing Date
2026-04-22
Publication Date
2026-06-25

Smart Images

  • Figure 2026105095000001_ABST
    Figure 2026105095000001_ABST
Patent Text Reader

Abstract

This product provides an authentication terminal that reduces the load on the server handling biometric authentication. [Solution] The authentication terminal comprises a list acquisition control means and an authentication request means. The system includes an authentication terminal, a management server, and an authentication server. The management server stores the user IDs of users who are allowed to pass through authentication points corresponding to restricted areas within the facility where entry is restricted, and the permitted time periods during which users are allowed to pass through the authentication points. The list acquisition control means requests the management server to provide a list of authorized passersby consisting of the user IDs of authorized passersby who are allowed to pass through the authentication points corresponding to its own device. The list acquisition control means receives the list of authorized passersby generated by the management server based on the permitted time periods from the management server. The authentication request means transmits at least the biometric information of the person to be authenticated and the list of authorized passersby to the authentication server, which stores the user IDs and biometric information of the person to be authenticated in a database.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication terminal, a control method for an authentication terminal, a storage medium, and a system.

Background Art

[0002] There are technologies related to entry and exit from a predetermined facility.

[0003] For example, Patent Document 1 describes providing a server device that can easily determine whether to have a meeting with a person while grasping the position of the person the visitor wishes to meet. Further, Patent Document 2 describes determining whether a user has permission to stay in a facility where the user is staying based on a beacon ID transmitted from a beacon transmitter.

[0004] Furthermore, there are technologies related to user authentication.

[0005] For example, Patent Document 3 describes accurately authenticating and determining whether the user of an authenticated device belongs to a specific group. Also, Patent Document 4 describes providing a mechanism for reducing the operation of inputting authentication information when a user (for example, a user who has forgotten a card) uses an image forming device (for example, a multifunction printer).

Prior Art Documents

Patent Documents

[0006]

Patent Document 1

Patent Document 2

Patent Document 3

Patent Document 4

Summary of the Invention

Problems to be Solved by the Invention

[0007] In facilities such as apartment buildings, there are areas that are only accessible to authorized personnel (restricted access areas). To implement access control to these restricted access areas, the authentication information (e.g., biometric information) of individuals permitted to enter these areas must be registered on the server, along with the date, time, and time slot in which the individual was authorized.

[0008] For example, consider a case where entry to a restricted area is controlled by biometric authentication. In this case, the biometric authentication server needs to have registered the biometric information, user ID, and permitted entry time slots of individuals who are allowed to enter the restricted area. Even if the biometric information is registered, the biometric authentication server will not determine that authentication was successful for individuals outside of the permitted entry time slots.

[0009] However, if the biometric authentication server performs such processing (authentication processing that takes into account the permitted entry time slot), the load on the biometric authentication server increases and the authentication speed decreases. As a result, a problem may arise in which the smooth entry and exit determination of authenticated individuals cannot be achieved.

[0010] The primary objective of this invention is to provide an authentication terminal, a method for controlling the authentication terminal, a storage medium, and a system that contribute to reducing the load on servers responsible for biometric authentication. [Means for solving the problem]

[0011] According to a first aspect of the present invention, an authentication terminal is provided, comprising: a list acquisition control means that stores the user IDs of users who can pass through an authentication point corresponding to a restricted area within a facility where entry is restricted, and the permitted time period during which the user can pass through the authentication point, and requests a management server to provide a list of authorized passers consisting of the user IDs of at least one authorized passer who can pass through the authentication point corresponding to the device, and receives the list of authorized passers generated by the management server based on the permitted time period from the management server; and an authentication request means that transmits at least the biometric information of the person to be authenticated and the list of authorized passers to an authentication server that stores the user ID and biometric information of the person to be authenticated in a database.

[0012] A second aspect of the present invention provides a method for controlling an authentication terminal, wherein the authentication terminal stores the user IDs of users who can pass through an authentication point corresponding to a restricted area within a facility where entry is restricted, and the permitted time period during which the user can pass through the authentication point, requests a management server to provide a list of authorized passers consisting of the user IDs of at least one authorized passer who can pass through the authentication point corresponding to the device, receives the list of authorized passers generated by the management server based on the permitted time period, and transmits at least the biometric information of the person to be authenticated and the list of authorized passers to an authentication server that stores the user ID and biometric information of the person to be authenticated in a database.

[0013] A third aspect of the present invention is provided, a computer-readable storage medium is provided, which stores a program for a computer mounted on an authentication terminal that causes the computer to perform the following steps: a process of requesting a management server to provide a list of authorized passersby consisting of the user IDs of at least one authorized passerby who is able to pass through the authentication point corresponding to the authentication point corresponding to the device; a process of receiving the list of authorized passersby generated by the management server based on the authorized passerby time period from the management server; and a process of transmitting at least the biometric information of the person to be authenticated and the list of authorized passersby to an authentication server that stores the user ID and biometric information of the person to be authenticated in a database.

[0014] According to a fourth aspect of the present invention, a system is provided comprising: an authentication terminal installed at an authentication point corresponding to a restricted area within a facility where entry is restricted; a management server that stores the user IDs of users who are allowed to pass through the authentication point and the permitted time period during which the users are allowed to pass through the authentication point; and an authentication server that stores the user IDs and biometric information of a person to be authenticated in a database, wherein the authentication terminal requests the management server to provide a list of authorized passers consisting of the user IDs of at least one authorized passer who is allowed to pass through the authentication point corresponding to the device; the management server generates the list of authorized passers based on the permitted time period and transmits the generated list of authorized passers to the authentication terminal; the authentication terminal transmits at least the biometric information of the person to be authenticated and the list of authorized passers to the authentication server; the authentication server extracts at least one piece of biometric information corresponding to at least one user ID included in the list of authorized passers from the database and performs a matching process using the extracted at least one piece of biometric information and the biometric information of the person to be authenticated.

[0015] According to a fifth aspect of the present invention, a system is provided comprising: an authentication terminal installed at an authentication point corresponding to a restricted area within a facility where entry is restricted; a management server that stores the user IDs of users who are allowed to pass through the authentication point and the permitted time period during which the users are allowed to pass through the authentication point; and an authentication server that stores the user IDs and biometric information of a person to be authenticated in a database, wherein the management server generates a list of authorized passersby consisting of the user IDs of at least one authorized passerby who is allowed to pass through the authentication point based on the permitted time period; the authentication server obtains the list of authorized passersby from the management server; the authentication terminal transmits a list ID for identifying the list of authorized passersby and the biometric information of the person to be authenticated to the authentication server; the authentication server extracts at least one piece of biometric information from the database corresponding to at least one user ID included in the list of authorized passersby; and performs a matching process using the extracted at least one piece of biometric information and the biometric information of the person to be authenticated.

[0016] According to a sixth aspect of the present invention, the present invention includes an authentication terminal installed at an authentication point corresponding to a restricted area within a facility where entry is restricted, a management server that stores the user IDs of users who are allowed to pass through the authentication point and the permitted time period during which the users are allowed to pass through the authentication point, and an authentication server that stores the user IDs and biometric information of the person to be authenticated in a database, wherein the authentication terminal requests the management server to provide a list of authorized passers consisting of the user IDs of at least one authorized passer who is allowed to pass through the authentication point corresponding to the device, and the management server, based on the permitted time period, A system is provided which generates a list of authorized passers, transmits the generated list of authorized passers to the authentication terminal, the authentication terminal transmits at least the list of authorized passers to the authentication server when authentication of the person to be authenticated is required, the authentication server extracts at least one biometric piece of information corresponding to at least one user ID included in the list of authorized passers from the database, transmits the extracted at least one biometric piece of information to the authentication terminal, and the authentication terminal performs a matching process using the at least one biometric piece of information obtained from the authentication server and the biometric information of the person to be authenticated. [Effects of the Invention]

[0017] From each perspective of the present invention, an authentication terminal, a method for controlling the authentication terminal, a storage medium, and a system are provided that contribute to reducing the load on a server responsible for biometric authentication. However, the effects of the present invention are not limited to those described above. The present invention may also produce other effects in lieu of or in conjunction with the effects described above. [Brief explanation of the drawing]

[0018] [Figure 1] Figure 1 is a diagram illustrating the outline of one embodiment. [Figure 2] Figure 2 is a flowchart illustrating the operation overview of one embodiment. [Figure 3] Figure 3 shows an example of a schematic configuration of the information processing system according to the first embodiment. [Figure 4] FIG. 4 is a diagram for explaining the arrangement of the authentication terminal according to the first embodiment. [Figure 5] FIG. 5 is a diagram for explaining the operation of the information processing system according to the first embodiment. [Figure 6] FIG. 6 is a diagram for explaining the operation of the information processing system according to the first embodiment. [Figure 7] FIG. 7 is a diagram for explaining the operation of the information processing system according to the first embodiment. [Figure 8] FIG. 8 is a diagram showing an example of the processing configuration of the management server according to the first embodiment. [Figure 9] FIG. 9 is a diagram showing an example of the display of the terminal according to the first embodiment. [Figure 10] FIG. 10 is a diagram showing an example of the display of the terminal according to the first embodiment. [Figure 11] FIG. 11 is a diagram showing an example of the display of the terminal according to the first embodiment. [Figure 12] FIG. 12 is a diagram showing an example of the display of the terminal according to the first embodiment. [Figure 13] FIG. 13 is a diagram showing an example of the user management database according to the first embodiment. [Figure 14] FIG. 14 is a diagram showing an example of the display of the terminal according to the first embodiment. [Figure 15] FIG. 15 is a diagram showing an example of the authentication terminal management database according to the first embodiment. [Figure 16] FIG. 16 is a diagram showing an example of the list of authorized passers according to the first embodiment. [Figure 17] FIG. 17 is a diagram showing an example of the processing configuration of the authentication server according to the first embodiment. [Figure 18] FIG. 18 is a diagram showing an example of the authentication target person management database according to the first embodiment. [Figure 19] FIG. 19 is a flowchart showing an example of the operation of the authentication control unit according to the first embodiment. [Figure 20]Figure 20 shows an example of the processing configuration of an authentication terminal according to the first embodiment. [Figure 21] Figure 21 is a sequence diagram showing an example of the operation of the information processing system according to the first embodiment. [Figure 22] Figure 22 is a diagram illustrating the operation of an information processing system according to a modified example of the first embodiment. [Figure 23] Figure 23 is a diagram illustrating the operation of an information processing system according to a modified example of the first embodiment. [Figure 24] Figure 24 shows an example of the hardware configuration of the management server disclosed in this application. [Modes for carrying out the invention]

[0019] First, an overview of one embodiment will be described. The reference numerals in the drawings attached to this overview are provided for convenience as examples to aid understanding, and this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. The connecting lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows schematically indicate the flow of the main signal (data) and do not exclude bidirectional flow. In this specification and in the drawings, elements that can be similarly described are given the same reference numerals to avoid redundant explanation.

[0020] An authentication terminal 100 according to one embodiment includes a list acquisition control means 101 and an authentication request means 102 (see Figure 1). The system includes the authentication terminal 100, a management server, and an authentication server. The management server stores the user IDs of users who are allowed to pass through authentication points corresponding to restricted areas within the facility where entry is restricted, and the permitted time periods during which users are allowed to pass through the authentication points. The list acquisition control means 101 requests the management server to provide a list of authorized passersby consisting of the user IDs of at least one authorized passerby who is allowed to pass through the authentication point corresponding to its own device (step S1 in Figure 2). The list acquisition control means 101 receives the list of authorized passersby generated by the management server based on the permitted time periods from the management server (step S2). The authentication request means 102 transmits at least the biometric information of the person to be authenticated and the list of authorized passersby to an authentication server that stores the user IDs and biometric information of the person to be authenticated in a database (step S3).

[0021] In the above system, the authentication terminal 100 transmits the user ID of a user who is allowed to pass through the authentication point managed by the device (allowed to enter the restricted area) and the biometric information of the person to be authenticated to the authentication server. The authentication server extracts the person to be authenticated based on the user ID. The authentication server performs a matching process using the extracted biometric information of the person to be authenticated and the biometric information of the person to be authenticated. Here, the process of extracting biometric information using the user ID has a higher processing load than the matching process using biometric information. Therefore, by narrowing down the person to be authenticated (decreasing the total number of people to be authenticated), the processing load on the authentication server decreases. Also, since the person to be authenticated is narrowed down based on the list of authorized passersby and the total number of people to be authenticated decreases, the authentication accuracy of biometric authentication improves. In other words, in one-to-many authentication (where N is a positive integer), if the number of people to be authenticated N is large, the authentication accuracy deteriorates and false authentications occur. The system disclosed in this application can suppress the deterioration of authentication accuracy by reducing the number of people to be authenticated N using the list of authorized passersby.

[0022] Specific embodiments will be described in more detail below with reference to the drawings.

[0023] [First Embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0024] [System Configuration] Figure 3 shows an example of a schematic configuration of an information processing system (authentication system) according to the first embodiment. As shown in Figure 3, the information processing system includes an authentication center and at least one apartment building.

[0025] The authentication center is operated by a service provider that offers biometric authentication services to condominiums (condominium management companies) that have entered into a prescribed contract with the company. The authentication center includes an authentication server 10. The authentication server 10 implements the main functions of the authentication center. The authentication server 10 stores the user ID and biometric information of the person to be authenticated in a database. The authentication server 10 provides biometric authentication services to at least one or more condominiums (multiple condominiums).

[0026] The authentication server 10 may be located within the authentication center building or on a network (on the cloud).

[0027] Each apartment building is equipped with a management server 20 and at least one authentication terminal 30.

[0028] The management server 20 is a server that manages information related to the residents of the apartment building. For example, the management server 20 stores and manages each resident's name, date of birth, address (room number), personal information, contact information, etc. The management server 20 also manages and controls reservations for the apartment building's common facilities (e.g., recreation room, meeting room, etc.).

[0029] The management server 20 stores the user IDs of users who are allowed to pass through authentication points corresponding to restricted areas within the facility (apartment building) where entry is restricted, as well as the date, time, and time slots during which those users are allowed to pass through the authentication points. The management server 20 may be installed in the building of each apartment building or the apartment management company, or it may be installed on a network (on the cloud).

[0030] The authentication terminal 30 is installed according to the restricted areas inside and outside the apartment building. For example, as shown in Figure 4, the authentication terminal 30 is installed near restricted areas where it is necessary to restrict user access, such as the entrances and exits of the apartment building, elevator lobbies, and the manager's office.

[0031] For example, authentication terminal 30-1 is installed near an entrance / exit. Authentication terminal 30-2 is installed in the elevator hall. Authentication terminal 30-3 is installed near the entrance / exit of the recreation room. Authentication terminal 30-4 is installed near the entrance / exit of the manager's office. Authentication terminal 30-5 is installed near the entrance / exit of the meeting room. In this way, if there are multiple restricted areas within the facility (apartment building), multiple authentication terminals 30 corresponding to each of the restricted areas are installed.

[0032] In the following explanation, unless there is a particular reason to distinguish between authentication terminals 30-1 to 30-5, they will simply be referred to as "authentication terminal 30".

[0033] Each authentication terminal 30 is connected to a door or gate. The authentication terminals 30 control the doors or gates and restrict residents from entering the restricted area (entering the restricted area, passing through the authentication point). For example, authentication terminal 30-4 allows the building manager to enter the manager's office and denies unauthorized residents from entering the manager's office.

[0034] As shown in Figure 3, each user, such as apartment residents, apartment building managers, and employees of the apartment management company, possesses a terminal 40. Users access the management server 20 using terminal 40.

[0035] The authentication server 10, the management server 20, and the authentication terminal 30 are configured to communicate with each other. For example, the management server 20 and the authentication terminal 30 are connected by wired or wireless communication means.

[0036] Figure 3 is illustrative and not intended to limit the configuration of the information processing system disclosed in this application. For example, an authentication center may include two or more authentication servers 10. Also, an apartment building may include at least one authentication terminal 30. Furthermore, Figure 4 is illustrative and not intended to limit the placement of each authentication terminal 30.

[0037] [General operation] Next, we will describe the general operation of the information processing system according to the first embodiment.

[0038] <User Registration> Users attempting to pass through each authentication point within the apartment building are required to register in advance. Users register by operating terminal 40. The apartment building management application is installed on terminal 40. Users use terminal 40 (apartment building management application) to perform user registration and other related tasks.

[0039] For example, residents of an apartment building register their status as "apartment residents" with the management server 20 (resident registration). Alternatively, an employee of the apartment building management company registers the "manager" who uses the manager's office with the management server 20 (manager registration). Or, a user who invites friends or others to the apartment building registers the "visitor" with the management server 20 (visitor registration).

[0040] For example, regarding resident registration, the management server 20 obtains the resident's user information (e.g., name, date of birth, address, biometric information, contact information, etc.) (see Figure 5).

[0041] Examples of user biometric information include data (feature quantities) calculated from individual physical characteristics such as face, fingerprints, voiceprints, veins, retina, and iris patterns. Alternatively, user biometric information may be image data such as a face image or fingerprint image. User biometric information only needs to include information about the user's physical characteristics. In the first embodiment, the biometric information is a person's face image or feature quantities generated from a face image.

[0042] When the management server 20 obtains user information, it generates a user ID to identify the resident (user). The management server 20 associates the generated user ID with the obtained user information and registers it in the user management database. Details of the user management database will be described later.

[0043] Similarly, for administrator registration and visitor registration, the management server 20 obtains user information (administrator information, visitor information) from the condominium management company and condominium residents. The management server 20 generates user IDs for administrators, visitors, etc. The management server 20 registers the generated user IDs and user information (administrator and visitor user information) in the user management database.

[0044] The management server 20 acquires information on users other than apartment residents (such as building managers and visitors), including the authentication points they can access and the times they can access them. For apartment residents, they are permitted to access authentication points within the building (restricted areas between the entrance and their homes) at all times (24 hours a day, 365 days a year). Normally, apartment residents are restricted from entering the manager's office or other people's residential areas unrelated to their own. Building managers may be permitted to move around the building at all times (24 hours a day, 365 days a year), excluding their own private areas.

[0045] Upon completion of user registration, the management server 20 notifies the authentication center of the user's user ID, biometric information, and apartment ID. Specifically, the management server 20 sends an authentication information notification, including the user ID, biometric information, and apartment ID, to the authentication server 10.

[0046] A condominium ID is information used to identify each condominium included in the information processing system. A condominium ID can be any information that uniquely identifies a condominium.

[0047] Furthermore, the condominium ID is shared among the authentication server 10, the management server 20, and the authentication terminal 30 by any method. For example, the system administrator determines the condominium ID and sets the determined condominium ID on the authentication server 10. The system administrator also sets the determined condominium ID on the management server 20 and the authentication terminal 30.

[0048] Upon receiving the authentication information notification, the authentication server 10 registers the user ID and biometric information contained in the notification into the authenticated person management database. Details of the authenticated person management database will be described later. If the authentication server 10 provides biometric authentication services to multiple apartment buildings, it will have an authenticated person management database for each apartment building. In other words, since the system disclosed in this application is multi-tenant compatible, the authentication server 10 will have one or more authenticated person management databases (databases with the same structure).

[0049] In this manner, when the management server 20 obtains a user's biometric information, it sends the user's user ID and the obtained biometric information to the authentication server 10. The authentication server 10 stores the user ID and biometric information received from the management server 20 in the authenticated user management database.

[0050] Note that the transmission and reception of biometric information between the management server 20 and the authentication server 10 is not limited to the transmission and reception of authentication information notifications that include user ID and biometric information. For example, when the management server 20 acquires new biometric information, it sends the acquired biometric information to the authentication server 10. Upon receiving the new biometric information, the authentication server 10 generates a person ID and stores the acquired biometric information and person ID in association. Furthermore, the authentication server 10 sends the generated person ID to the management server 10 (issues a person ID). The management server 10 manages the received person ID in association with the user ID. The management server 10 may also set the person ID instead of the user ID in the access permit list described later.

[0051] <Management of permit holders> The management server 20 manages and stores information about users who are allowed to pass through each authentication point (restricted area). More specifically, for each authentication point, the management server 20 stores the user ID of the user and the date, time, and time period during which that user is allowed to pass through the authentication point.

[0052] The management server 20 manages each authentication terminal 30 by associating it with the user ID of a user who is allowed to pass through the corresponding authentication point and the date and time period (hereinafter referred to as the permitted time period) during which that user is allowed to pass through the authentication point. The management server 20 stores the user ID and permitted time period of each user in an authentication terminal management database prepared for each authentication terminal 30. Details of the authentication terminal management database will be described later.

[0053] For example, the management server 20 allows apartment residents to pass through authentication points (restricted areas) located along the route from the apartment building's entrance to their home.

[0054] For example, if user A lives on the second floor of an apartment building, the management server 20 ensures that user A can reach their home on the second floor using the elevator. Specifically, the management server 20 stores user A's user ID and permitted time slots in the authentication terminal management databases of at least authentication terminals 30-1 and 30-2. Since user A does not have the authority to enter the manager's office, user A's user ID is not stored in the authentication terminal management database of authentication terminal 30-4.

[0055] Alternatively, the management server 20 allows the apartment building manager to enter the restricted areas of the apartment building's entrance and manager's office. In this case, the manager's user ID and permitted time slots are recorded in at least the authentication terminal management database of authentication terminal 30-1 and the authentication terminal management database of authentication terminal 30-4.

[0056] <Obtaining a list of permitted users> Each authentication terminal 30 obtains a "permitted user list" from the management server 20. The permitted user list is a list of user IDs of users who are allowed to pass through the authentication point corresponding to each authentication terminal 30 at the current time (more precisely, from the time the permitted user list is obtained until the next permitted user list is obtained).

[0057] The authentication terminal 30 sends a "list provision request" containing its own terminal ID to the management server 20 (see Figure 6).

[0058] The terminal ID is an ID used to identify each authentication terminal 30. The terminal ID can be the MAC (Media Access Control) address or IP (Internet Protocol) address of the authentication terminal 30. The terminal ID is shared between the management server 20 and the authentication terminal 30 by any method. For example, the system administrator determines the terminal ID and sets the determined terminal ID on the management server 20. The system administrator also sets the determined terminal ID on the authentication terminal 30.

[0059] The management server 20 identifies the source of the list provision request using the terminal ID included in the request. The management server 20 accesses the authentication terminal management database corresponding to the authentication terminal 30 of the source and generates a list of authorized users.

[0060] The management server 20 sends the generated list of authorized passers to the authentication terminal 30.

[0061] The authentication terminal 30 obtains the list of permitted travelers by periodically or at predetermined intervals by sending a list provision request to the management server 20. For example, the authentication terminal 30 sends a list provision request to the management server 20 every minute and obtains the list of permitted travelers from the management server 20. That is, the authentication terminal 30 obtains the latest list of permitted travelers by performing a polling process on the list of permitted travelers. When the authentication terminal 30 receives the list of permitted travelers from the management server 20, it may update or overwrite the previously received list of permitted travelers using the received list. Alternatively, the authentication terminal 30 may distinguish between the latest list of permitted travelers and older lists of permitted travelers and store them for a certain period of time.

[0062] For example, consider a case where the authentication terminal management database of authentication terminal 30-4 records that user B can enter the administrator's room between 15:00 and 15:30 on January 16, 2022.

[0063] In this case, if the list provision request is sent from authentication terminal 30-4 before 15:00, the user ID of user B will not be included in the list of authorized users generated by management server 20. If the list provision request is sent between 15:00 and 15:29, the user ID of user B will be included in the list of authorized users. If the list provision request is sent after 15:30, the user ID of user B will not be included in the list of authorized users.

[0064] In this manner, the authentication terminal 30 requests the management server 20 to provide a list of authorized users consisting of the user IDs of at least one authorized user who is allowed to pass through the authentication point corresponding to its device. The management server 20 generates a list of authorized users based on the permitted time period and transmits the generated list of authorized users to the authentication terminal 30.

[0065] <Authentication of the person being authenticated> When a user (authenticated person) attempts to pass through an authentication point (enter a restricted area), the user moves in front of the authentication terminal 30.

[0066] The authentication terminal 30 acquires the biometric information of the user (authenticated person). The authentication terminal 30 sends an authentication request to the authentication server 10 that includes the apartment ID of the apartment building where the device is installed, the acquired biometric information, and the list of authorized passersby (the latest list of authorized passersby) (see Figure 7).

[0067] The authentication server 10 identifies the apartment building where the authentication terminal 30 that sent the authentication request is located, based on the apartment building ID. The authentication server 10 refers to the authentication target management database of the identified apartment building and extracts the biometric information of the person to be authenticated corresponding to the user ID included in the obtained list of authorized passersby. For example, if the list of authorized passersby contains user IDs for 5 people, biometric information for 5 people will be extracted.

[0068] As mentioned above, once the authentication server 10 issues a person ID to the management server 20, the authentication server 10 can use the person ID to identify the apartment building where the authentication terminal 30 is installed. In this case, the authentication terminal 30 does not need to send the apartment building ID to the authentication server 10 (it only needs to send the list of permitted occupants to the authentication server 10).

[0069] The authentication server 10 performs a matching process (authentication process) using the biometric information included in the authentication request and the extracted biometric information.

[0070] If the matching process is successful (i.e., if the extracted biometric information contains biometric information that is substantially identical to the biometric information included in the authentication request), the authentication server 10 sends an affirmative response indicating successful authentication to the authentication terminal 30.

[0071] If the matching process fails (i.e., the extracted biometric information does not contain biometric information that is substantially identical to the biometric information included in the authentication request), the authentication server 10 sends a negative response indicating authentication failure to the authentication terminal 30.

[0072] Upon receiving an acknowledgment (successful authentication), the authentication terminal 30 permits the person to be authenticated to pass through the authentication point. For example, the authentication terminal 30 opens a door, allowing the person to pass through the authentication point.

[0073] Upon receiving a negative response (authentication failure), the authentication terminal 30 refuses the person to be authenticated to pass through the authentication point. For example, the authentication terminal 30 closes the door and refuses the person to be authenticated to pass through the authentication point.

[0074] In this manner, the authentication terminal 30 transmits at least the biometric information of the person to be authenticated and the list of authorized passersby to the authentication server 10. The authentication server 10 extracts at least one biometric piece of information corresponding to at least one user ID included in the list of authorized passersby from the authentication target management database. The authentication server 10 performs a matching process using the extracted biometric piece of information and the biometric information of the person to be authenticated. If the matching process is successful, the authentication server 10 notifies the authentication terminal 30 of the authentication success. Upon receiving notification of the authentication success, the authentication terminal 30 permits the person to be authenticated to pass through the authentication point.

[0075] In other words, the authentication terminal 30 obtains in real time a list of authorized users consisting of user IDs of users who are permitted to pass through the corresponding authentication point. When authentication of a person to be authenticated is required, the authentication terminal 30 sends the list of authorized users along with the biometric information of the person to be authenticated to the authentication server 10. The authentication server 10 narrows down the people to be authenticated (the registered people) according to the list of authorized users. The people to be authenticated that have been narrowed down according to the list of authorized users are users who can pass through the authentication point. Therefore, if the person to be authenticated is included in the people to be authenticated that have been narrowed down by the list of authorized users (i.e., if the biometric information of the person to be authenticated and the biometric information of the person to be authenticated substantially match), it is determined that the person to be authenticated can pass through the authentication point.

[0076] Next, we will describe the details of each device included in the information processing system according to the first embodiment.

[0077] [Management Server] Figure 8 shows an example of the processing configuration (processing module) of the management server 20 according to the first embodiment. Referring to Figure 8, the management server 20 comprises a communication control unit 201, a user management unit 202, an authentication information control unit 203, a user access control unit 204, a list provision control unit 205, and a storage unit 206.

[0078] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the authentication terminal 30. The communication control unit 201 also transmits data to the authentication terminal 30. The communication control unit 201 passes the data received from other devices to other processing modules. The communication control unit 201 transmits the data obtained from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 201. The communication control unit 201 has the function of a receiving unit that receives data from other devices and the function of a transmitting unit that transmits data to other devices.

[0079] The user management unit 202 is a means of controlling and managing users such as apartment residents. When a user operates terminal 40 and accesses the management server 20, the user management unit 202 displays a GUI (Graphical User Interface) on terminal 40 for selecting user registration and application for use of shared facilities.

[0080] For example, the user management unit 202 displays a GUI on terminal 40 as shown in Figure 9.

[0081] When a user requests to register as a resident (by pressing the resident registration button), the user management unit 202 obtains the user's name, date of birth, address, biometric information (facial image), contact information, etc. For example, the user management unit 202 obtains user information such as name using a GUI as shown in Figure 10.

[0082] When an employee of a condominium management company wishes to register as a building manager (when the building manager registration button is pressed), the user management unit 202 displays a menu screen similar to that in Figure 9, and then displays a GUI as shown in Figure 11 on the terminal 40. The user management unit 202 obtains the user's (building manager's) name and biometric information, as well as the facilities within the condominium that the building manager can use (facilities used; for example, the building manager's office), and the dates and times (permitted hours) on which those facilities can be used. In this way, an employee of a condominium management company registers as a building manager using a system management terminal.

[0083] If a resident of the apartment building wishes to register as a visitor (by pressing the visitor registration button), the user management unit 202 displays a GUI (guest registration webpage) as shown in Figure 12 on the terminal 40. The user management unit 202 obtains the user's (visitor's) name, biometric information, etc., as well as the facilities used by the visitor and the permitted time slots.

[0084] When the user information of a user (e.g., apartment resident, building manager, visitor, etc.) is obtained, the user management unit 202 generates a user ID to identify that user. The user ID can be any information that uniquely identifies the user. For example, the user management unit 202 may assign a unique value each time a user is registered and use that as the user ID.

[0085] The user management unit 202 registers the generated user ID, user type, user information, facility used, permitted time slot, etc., in the user management database (see Figure 13).

[0086] Regarding apartment residents, User Management Unit 202 will set the facility to be used as the resident's "home (address)". Furthermore, User Management Unit 202 will set the permitted usage time for the resident to "always" (24 hours a day, 365 days a year).

[0087] Note that the user management database shown in Figure 13 is an example and is not intended to limit the items to be stored. For example, biometric information such as feature quantities generated from facial images may be registered in the user management database. Alternatively, biometric information (facial images, feature quantities) may not be registered in the user management database.

[0088] Furthermore, one user can access multiple locations within the apartment building. For example, a user who has applied to use a facility can access both their home and the facility they applied for. In other words, the relationship between managing people and managing access is one-to-many. Therefore, the user management database (a database like the one shown in Figure 13) may contain multiple facilities and permitted time slots for the same person.

[0089] When user registration is complete (i.e., the user ID etc. is registered in the user management database), the user management unit 202 notifies the authentication information control unit 203 and the user access control unit 204 of the user ID of the registered user.

[0090] Furthermore, the user management unit 202 accepts applications from condominium residents for the use of shared facilities. For example, when "Facility Use Application" is selected on the menu screen shown in Figure 9, the user management unit 202 displays a facility use application screen on terminal 40, as shown in Figure 14.

[0091] The user management unit 202 uses a GUI as shown in Figure 14 to acquire information that identifies facility users (for example, their name or a combination of name and date of birth), the facility used, and the date and time of use (permitted time slot).

[0092] The user management unit 202 searches the user management database using information that identifies facility users (for example, name or a combination of name and date of birth) as a key, and identifies the corresponding user (apartment resident). The user management unit 202 notifies the user access control unit 204 of the identified user's user ID, the facility used, and the permitted time period.

[0093] Detailed explanations regarding facility use applications (facility reservations) are omitted, as facility reservations and similar procedures are outside the scope of this disclosure.

[0094] Furthermore, the user management unit 202 accesses the user management database periodically or at predetermined intervals. The user management unit 202 deletes entries whose permitted time period has expired. In the example in Figure 13, the entry for the visitor with user ID "ID05" will be deleted after 4:00 PM on January 17, 2023.

[0095] The authentication information control unit 203 is a means for controlling the user's authentication information (user ID, biometric information).

[0096] When user registration is complete, the authentication information control unit 203 sends an authentication information notification to the authentication server 10, which includes the user's user ID, biometric information (e.g., facial image), and apartment ID.

[0097] The user access control unit 204 is a means of controlling the access of registered users (apartment residents, managers, visitors, etc.) and facility users to their destinations.

[0098] The user access control unit 204 calculates routes that users who have completed user registration can take (routes that include at least one authentication point (restricted area)). The user access control unit 204 sets the entrance / exit of the apartment building as the starting point and the facility to be used (resident's home, manager's office, visitor's destination, etc.) as the destination, and identifies the authentication points (authentication terminals 30) that exist between the starting point and the destination.

[0099] For example, the user access control unit 204 refers to table information that stores authentication points for each combination of starting point and destination point, and identifies the authentication points that exist between the user and their destination (home, caretaker's office, destination).

[0100] Next, the user access control unit 204 uses the user's user ID to refer to the user management database and obtains the permitted time period (date, time zone) during which the user is allowed to pass through each authentication point.

[0101] The user access control unit 204 stores the user ID and permitted time period of the user in the authentication terminal management database corresponding to the authentication terminal 30 on the user's route (see Figure 15). In other words, for each of the multiple authentication terminals 30, the user access control unit 204 stores the user ID and permitted time period of the user who is allowed to pass through the corresponding authentication point.

[0102] The authentication terminal management database shown in Figure 15 is an example and is not intended to limit the items to be stored. Note that the authentication terminal management database shown in Figure 15 is an example of a database corresponding to authentication terminal 30-5 installed in the meeting room.

[0103] Similarly, for users whose facility use applications have been approved, the user ID and permitted time period are set in the authentication terminal management database of the authentication terminal 30 that is present between the time the user arrives at the facility.

[0104] Here, the user access control unit 204 accesses each authentication terminal management database periodically or at predetermined intervals. The user access control unit 204 deletes entries for which the permitted time period has expired. In the example in Figure 15, two entries are deleted after 3:00 PM on January 17, 2023.

[0105] The list provision control unit 205 is a means for managing and controlling the list of authorized passers. Specifically, the list provision control unit 205 processes list provision requests received from the authentication terminal 30.

[0106] The list provision control unit 205 identifies the source of the list provision request (authentication terminal 30) using the terminal ID included in the list provision request. The list provision control unit 205 then refers to the authentication terminal management database corresponding to the identified authentication terminal 30.

[0107] The list provision control unit 205 refers to the permitted time period field in the authentication terminal management database and extracts entries (users) whose time of receiving the list provision request falls within the permitted time period.

[0108] The list provision control unit 205 generates a list of user IDs listed in the extracted entries as a list of authorized users. For example, when a list provision request is received and five users are allowed to pass through the authentication point corresponding to the authentication terminal 30, a list of authorized users as shown in Figure 16 is generated.

[0109] The list provision control unit 205 sends the generated list of authorized passers to the source of the list provision request (authentication terminal 30). In this way, the list provision control unit 205 generates a list of authorized passers for the authentication terminal 30 corresponding to the terminal ID and sends the generated list of authorized passers to the authentication terminal 30.

[0110] The memory unit 206 is a means for storing information necessary for the operation of the management server 20.

[0111] [Authentication Server] Figure 17 shows an example of the processing configuration (processing module) of the authentication server 10 according to the first embodiment. Referring to Figure 17, the authentication server 10 comprises a communication control unit 301, an authentication information notification processing unit 302, an authentication control unit 303, and a storage unit 304.

[0112] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the authentication terminal 30. The communication control unit 301 also transmits data to the authentication terminal 30. The communication control unit 301 passes the data received from other devices to other processing modules. The communication control unit 301 transmits the data obtained from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 301. The communication control unit 301 has the function of a receiving unit that receives data from other devices and the function of a transmitting unit that transmits data to other devices.

[0113] The authentication information notification processing unit 302 is a means for processing authentication information notifications received from the management server 20.

[0114] If the authentication information notification includes a user's face image, the authentication information notification processing unit 302 generates feature quantities from the face image. Since existing technologies can be used for the feature quantity generation process by the authentication information notification processing unit 302, a detailed explanation is omitted. For example, the authentication information notification processing unit 302 extracts features such as the eyes, nose, and mouth from the face image. Then, the authentication information notification processing unit 302 calculates the position of each feature point and the distance between each feature point as feature quantities (generating a feature vector consisting of multiple feature quantities).

[0115] The authentication information notification processing unit 302 identifies the apartment building (management server 20) that sent the authentication information notification based on the apartment building ID included in the authentication information notification.

[0116] The authentication information notification processing unit 302 stores the user ID and biometric information (for example, the generated features) included in the authentication information notification in the authentication target management database corresponding to the identified condominium (see Figure 18). Note that the authentication target management database shown in Figure 18 is an example and is not intended to limit the items to be stored. For example, a "face image" may be registered as biometric information in the authentication target management database.

[0117] The authentication control unit 303 is a means for controlling the biometric authentication of the person to be authenticated. The authentication control unit 303 processes the authentication request received from the authentication terminal 30.

[0118] Figure 19 is a flowchart illustrating an example of the operation of the authentication control unit 303 according to the first embodiment. The operation of the authentication control unit 303 will be explained with reference to Figure 19.

[0119] The authentication control unit 303 identifies the apartment building where the authentication terminal 30 is installed based on the apartment building ID included in the authentication request (step S101).

[0120] The authentication control unit 303 accesses the authentication target management database corresponding to the identified apartment building. The authentication control unit 303 extracts the biometric information of the person to be authenticated from the authentication target management database, corresponding to the user ID included in the list of authorized passersby obtained from the authentication request (step S102).

[0121] The authentication control unit 303 performs a matching process (authentication process) using the biometric information included in the authentication request and the extracted biometric information (step S103). For example, if the list of authorized passers contains user IDs for five people, five biometric pieces of information are extracted and these five biometric pieces of information are used in the matching process.

[0122] More specifically, the authentication control unit 303 generates feature quantities from the facial image included in the authentication request. The authentication control unit 303 sets the generated feature quantities as the matching target and performs a matching process (one-to-many matching; N is a positive integer, the same applies hereafter) with the feature quantities extracted from the authentication target management database.

[0123] The authentication control unit 303 calculates the similarity between the feature quantity to be matched and each of the multiple feature quantities on the registration side (at least one extracted feature quantity). The chi-squared distance, Euclidean distance, etc., can be used to calculate this similarity. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0124] The authentication control unit 303 determines that the matching process has failed if, among the multiple features extracted from the authenticated person management database, there is no feature whose similarity to the feature to be matched is equal to or greater than a predetermined value.

[0125] The authentication control unit 303 determines that the matching process was successful if, among the multiple features extracted from the authentication target management database, there is a feature whose similarity to the feature to be matched is equal to or greater than a predetermined value.

[0126] If the matching process is successful (step S104, Yes branch), the authentication control unit 303 sends an affirmative response indicating successful authentication to the authentication terminal 30 (step S105). If the matching process fails (step S104, No branch), the authentication control unit 303 sends a negative response indicating authentication failure to the authentication terminal 30 (step S106).

[0127] The memory unit 304 is a means for storing information necessary for the operation of the authentication server 10.

[0128] [Authentication device] Figure 20 shows an example of the processing configuration (processing module) of the authentication terminal 30 according to the first embodiment. Referring to Figure 20, the authentication terminal 30 comprises a communication control unit 401, a list acquisition control unit 402, a biometric information acquisition unit 403, an authentication request unit 404, and a storage unit 405.

[0129] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the management server 20. The communication control unit 401 also transmits data to the management server 20. The communication control unit 401 passes the data received from other devices to other processing modules. The communication control unit 401 transmits the data acquired from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 401. The communication control unit 401 has the function of a receiving unit that receives data from other devices and the function of a transmitting unit that sends data to other devices.

[0130] The list acquisition control unit 402 is a means for controlling the acquisition of the list of permitted travelers. The list acquisition control unit 402 periodically or at predetermined intervals sends a "list provision request" including the terminal ID of its own device to the management server 20. In this way, the list acquisition control unit 402 is a means for requesting the management server 20 to provide the list of permitted travelers.

[0131] The list acquisition control unit 402 acquires the list of authorized users from the management server 20. The list acquisition control unit 402 acquires the list of authorized users for its own device by periodically or at predetermined intervals by transmitting its own device's terminal ID to the management server 20. The list acquisition control unit 402 stores the acquired list of authorized users internally.

[0132] Thus, the list acquisition control unit 402 requests the management server 20 to provide a list of authorized users consisting of the user IDs of at least one authorized user who is able to pass through the authentication point corresponding to its device. The list acquisition control unit 402 receives the list of authorized users generated by the management server 20 based on the permitted time period from the management server 20.

[0133] The biometric information acquisition unit 403 is a means for controlling the camera and acquiring the user's biometric information (e.g., facial image). The biometric information acquisition unit 403 images the area in front of the device periodically or at predetermined intervals. The biometric information acquisition unit 403 determines whether or not a human facial image is included in the acquired image, and if a facial image is included, it extracts the facial image from the acquired image data.

[0134] Note that existing technologies can be used for the face image detection and face image extraction processes by the biometric information acquisition unit 403, so a detailed explanation will be omitted. For example, the biometric information acquisition unit 403 may extract face images (face regions) from image data using a learning model trained by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 403 may extract face images using methods such as template matching.

[0135] The biometric information acquisition unit 403 hands over the extracted facial image to the authentication request unit 404.

[0136] The authentication request unit 404 is a means of requesting authentication of the person to be authenticated from the authentication server 10. When authentication of the person to be authenticated is required, the authentication request unit 404 sends an authentication request to the authentication server 10 that includes the biometric information of the person to be authenticated (the user in front of the authentication terminal 30), the latest list of authorized passersby, and the apartment ID.

[0137] The authentication request unit 404 receives the authentication result (authentication successful, authentication failed) from the authentication server 10.

[0138] If the response from the authentication server 10 is a "negative response" (in the case of authentication failure), the authentication request unit 404 closes the door or gate and refuses the person to be authenticated to pass through the authentication point (refuses the person to be authenticated to enter the restricted area). The authentication request unit 404 may also notify the person to be authenticated that they cannot pass through the authentication point.

[0139] If the response from the authentication server 10 is an "affirmative response" (indicating successful authentication), the authentication request unit 404 opens the door or gate and allows the person to pass through the authentication point (allows the person to enter the restricted area).

[0140] Thus, the authentication request unit 404 sends at least the biometric information of the person to be authenticated and the list of authorized passersby to the authentication server 10, which stores the user ID and biometric information of the person to be authenticated in a database. When the authentication request unit 404 receives notification of successful authentication from the authentication server 10, it permits the person to be authenticated to pass through the authentication point.

[0141] The memory unit 405 stores the information necessary for the operation of the authentication terminal 30.

[0142] [Terminal] Examples of terminal 40 include mobile devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, laptops). Terminal 40 can be any device or equipment as long as it can receive user input and communicate with the management server 20, etc. Furthermore, the configuration of terminal 40 is obvious to those skilled in the art, so a detailed explanation is omitted.

[0143] [System operation] Next, the operation of the information processing system according to the first embodiment will be described.

[0144] Figure 21 is a sequence diagram showing an example of the operation of the information processing system according to the first embodiment. The operation of the information processing system according to the first embodiment will be explained with reference to Figure 21.

[0145] The authentication terminal 30 periodically or at predetermined intervals sends a list provision request to the management server 20 (step S01).

[0146] The management server 20 sends a list of user IDs of users who are allowed to pass through the authentication point corresponding to the authentication terminal 30 as a list of authorized users to pass through (step S02). The authentication terminal 30 stores the received list of authorized users to pass through.

[0147] When the authentication terminal 30 detects a person to be authenticated in front of it, it acquires the biometric information of that person. The authentication terminal 30 sends an authentication request to the authentication server 10, which includes the acquired biometric information and the latest list of authorized passersby (step S03).

[0148] The authentication server 10 extracts individuals to be authenticated using the list of authorized passers, and performs a matching process using the biometric information of the extracted individuals to be authenticated and the biometric information included in the authentication request (step S04).

[0149] The authentication server 10 sends the authentication result (authentication successful, authentication failed) to the authentication terminal 30 (step S05).

[0150] The authentication terminal 30 controls the gate, etc., according to the authentication result (step S06).

[0151] <Modification example 1 of the first embodiment> In the above embodiment, it was explained that the authentication terminal 30 holds the latest list of authorized passers, and when authentication of the person to be authenticated is required, it sends the latest list of authorized passers to the authentication server 10.

[0152] However, the latest list of authorized users may be held by the authentication server 10. For example, the management server 20 and the authentication server 10 share the list ID of the authorized user list corresponding to each authentication terminal 30.

[0153] The management server 20 generates a list of authorized users in real time, consisting of user IDs of authorized users who are allowed to pass through each authentication point, based on the permitted time slots for each user.

[0154] The authentication server 10 obtains the list of authorized users for each authentication terminal 30 by periodically or at predetermined intervals by sending a list provision request to the management server 20. Alternatively, the management server 20 may periodically or at predetermined intervals send the list of authorized users for each authentication terminal 30 to the authentication server 10 (see Figure 22).

[0155] When authentication of the person to be authenticated is required, the authentication terminal 30 sends an authentication request to the authentication server 10, which includes the list ID corresponding to its device and the biometric information of the person to be authenticated.

[0156] The authentication server 10 identifies the list of authorized users based on the list ID included in the authentication request. Based on the identified list of authorized users, the authentication server 10 extracts the individuals to be authenticated and performs a matching process.

[0157] In this way, the management server 20 generates a list of authorized users consisting of user IDs of at least one authorized user who is allowed to pass through the authentication point, based on the permitted time slot for each user. The authentication server 10 obtains the list of authorized users from the management server 20. When authentication of a person to be authenticated is required, the authentication terminal 30 sends a list ID to identify the list of authorized users and the biometric information of the person to be authenticated to the authentication server 10. The authentication server 10 extracts at least one biometric piece of information corresponding to at least one user ID included in the list of authorized users from the authentication target management database. The authentication server 10 performs a matching process using the extracted biometric information and the biometric information of the person to be authenticated. In other words, the amount of communication between the authentication server 10 and the authentication terminal 30 is reduced by sending and receiving the list ID between the authentication server 10 and the authentication terminal 30.

[0158] <Modification example 2 of the first embodiment> In the above embodiment, it was explained that the authentication server 10 performs a matching process (authentication process) using biometric information narrowed down based on the list of authorized passersby. This matching process may also be performed on the apartment building side (edge ​​side; authentication terminal 30).

[0159] In this case, when authentication of the person to be authenticated is required, the authentication terminal 30 sends a biometric information request (a request that does not include the biometric information of the person to be authenticated) to the authentication server 10, which includes the latest list of authorized passers (see Figure 23).

[0160] The authentication server 10 extracts biometric information from the authentication target management database for entries corresponding to user IDs listed in the access permit list. For example, if the access permit list contains five user IDs, five biometric pieces of information corresponding to the user IDs will be extracted.

[0161] The authentication server 10 transmits the extracted biometric information to the authentication terminal 30.

[0162] The authentication terminal 30 performs a verification process using the biometric information of the person being authenticated and the biometric information obtained from the authentication server 10.

[0163] If the verification process is successful, the authentication terminal 30 permits the person to be authenticated to pass through the authentication point. If the verification process fails, the authentication terminal 30 refuses the person to be authenticated to pass through the authentication point.

[0164] In this manner, when authentication of a person to be authenticated is required, the authentication terminal 30 sends at least a list of authorized users to the authentication server 10. The authentication server 10 extracts at least one piece of biometric information corresponding to at least one user ID included in the list of authorized users from the authentication target management database. The authentication server 10 sends the extracted at least one piece of biometric information to the authentication terminal 30. The authentication terminal 30 performs a matching process using the at least one piece of biometric information obtained from the authentication server 10 and the biometric information of the person to be authenticated. Since the authentication server 10 does not perform a matching process, the processing load on the authentication server 10 is reduced.

[0165] As described above, in the information processing system according to the first embodiment, the authentication terminal 30 transmits to the authentication server 10 a list of user IDs of users who are allowed to pass through the authentication point managed by the device (allowed to enter the restricted area) and the biometric information of the person to be authenticated. The authentication server 10 narrows down the people to be authenticated based on the list of user IDs (list of authorized passersby). The authentication server 10 performs a matching process (authentication process) using the biometric information of the narrowed-down people to be authenticated. Here, the matching process using biometric information and the extraction process of biometric information using user IDs have a higher processing load than the former. Therefore, by narrowing down the people to be authenticated (by reducing N in one-to-many matching), the processing load on the authentication server 10 decreases. In addition, by reducing the number of people to be authenticated, the accuracy and processing speed of biometric authentication improve.

[0166] Furthermore, the authentication server 10 does not manage information such as the permitted time slots for each user. That is, even if an application for use of shared facilities is made and the time slots during which a user can use the facilities change, it does not affect the authentication server 10's database of authorized users. Changes in the permitted time slots for each user within the apartment building are reflected in the authentication terminal management database managed by the management server 20. Furthermore, these changes in permitted time slots are reflected in the list of authorized users acquired by the authentication terminal 30. In this way, changes in the user's situation as seen from the authentication center (authentication server 10) are absorbed by the user, allowing the authentication server 10 to concentrate on verifying the authenticated users. Moreover, by adopting this configuration, the authentication server 10 can provide authentication services to a large number of apartment buildings, and changes (customization) to suit the specific circumstances of each apartment building are not required.

[0167] Next, we will describe the hardware of each device that makes up the information processing system. Figure 24 shows an example of the hardware configuration of the management server 20.

[0168] The management server 20 can be configured using an information processing device (a so-called computer), and has the configuration illustrated in Figure 24. For example, the management server 20 includes a processor 311, memory 312, input / output interface 313, and communication interface 314, etc. The components of the processor 311, etc., are connected by an internal bus or the like and are configured to communicate with each other.

[0169] However, the configuration shown in Figure 24 is not intended to limit the hardware configuration of the management server 20. The management server 20 may include hardware not shown, and it may not have to have an input / output interface 313 if necessary. Also, the number of processors 311 etc. included in the management server 20 is not intended to be limited to the example in Figure 24; for example, multiple processors 311 may be included in the management server 20.

[0170] The processor 311 is a programmable device such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), or DSP (Digital Signal Processor). Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit). The processor 311 executes various programs, including an operating system (OS).

[0171] Memory 312 includes RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), etc. Memory 312 stores the OS program, application programs, and various data.

[0172] The input / output interface 313 is an interface for a display device or input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user input such as a keyboard, mouse, or touch panel.

[0173] The communication interface 314 is a circuit, module, etc., that communicates with other devices. For example, the communication interface 314 includes a NIC (Network Interface Card), etc.

[0174] The functions of the management server 20 are realized by various processing modules. These processing modules are realized, for example, by the processor 311 executing a program stored in memory 312. The program can also be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as semiconductor memory, hard disk, magnetic recording medium, or optical recording medium. In other words, the present invention can also be embodied as a computer program product. Furthermore, the program can be downloaded via a network or updated using the storage medium on which the program is stored. Moreover, the processing module may be realized by a semiconductor chip.

[0175] Furthermore, the authentication server 10, authentication terminal 30, etc., can also be configured using information processing devices, similar to the management server 20. Since their basic hardware configuration is the same as that of the management server 20, a detailed explanation will be omitted.

[0176] The management server 20 is equipped with a computer, and its functions are realized by having the computer execute a program. Furthermore, the management server 20 executes control methods using this program.

[0177] [Differentiation] The configuration and operation of the information processing system described in the above embodiment are illustrative examples and are not intended to limit the system configuration.

[0178] In the above embodiment, an apartment building was used as an example of a facility with a restricted area. However, the information processing system disclosed in this application is not limited to apartment buildings. The information processing system disclosed in this application is applicable to any facility with a restricted area, such as an office.

[0179] In the above embodiment, the authentication server 10 has an authentication target management database for each apartment building and stores the authentication information (user ID, biometric information) of the authenticated person for each apartment building. However, the authentication server 10 may also store the authentication information of the authenticated persons for each apartment building that has a contract with the authentication center in a single authentication terminal management database. In this case, it is sufficient that the user IDs of the users do not overlap between apartment buildings.

[0180] The above embodiment describes a case where the authentication terminal 30 requests the management server 20 to provide a list of authorized users. The management server 20 may send the list of authorized users to each authentication terminal 30 periodically or at predetermined intervals. For example, the list of authorized users may be sent to the authentication terminal 30 when the user ID included in the list changes in accordance with a change in the user's permitted time period. That is, the management server 20 may send the list of authorized users to the authentication terminal 30 unilaterally or periodically, even if there is no request from the authentication terminal 30.

[0181] In the above embodiment, the authentication terminal 30 was described as sending an authentication request to the authentication server 10. The authentication terminal 30 may also send an authentication request to the management server 20. Specifically, when the authentication terminal 30 detects a person to be authenticated, it sends an authentication request to the management server 20 that includes the biometric information of the person to be authenticated and the terminal ID. The management server 20 identifies the authentication terminal 30 based on the terminal ID and generates a corresponding list of authorized users. The management server 20 sends the generated list of authorized users and the biometric information of the person to be authenticated to the authentication server 10. The authentication server 10 sends the authentication result to the authentication terminal 30 directly or indirectly via the management server 20.

[0182] If the user ID is not included in the list of authorized passers, the authentication terminal 30 may not send an authentication request to the authentication server 10 and may instead mark the authentication result of the person being authenticated as an authentication failure. This is because the fact that the user ID is not listed in the list of authorized passers indicates that there are no persons being authenticated who can pass through the authentication point.

[0183] In the above embodiment, it was explained that the management server 20 sends a list of authorized users, including the user IDs of users who are allowed to pass through the authentication point, to the authentication terminal 30 upon receiving a list provision request. However, the management server 20 may also send a list of authorized users, including the user IDs of users who are allowed to pass through the authentication point, to the authentication terminal 30 within a predetermined period from the time of receiving the list provision request. For example, consider the case where the management server 20 receives a list provision request at 15:00 and the predetermined period is "10 minutes". In this case, the management server 20 may send a list of authorized users, including the user IDs of users who are allowed to pass through the authentication point, to the authentication terminal 30 between 15:00 and 15:10.

[0184] In the above embodiment, the case in which the user management database and the authentication terminal management database are configured inside the management server 20 was described, but these databases may be built on an external database server or the like. In other words, some functions of the management server 20 may be implemented in another device. More specifically, it is sufficient that the "list provision control unit (list provision control means)" etc. described above is implemented in any device included in the system.

[0185] The form of data transmission and reception between each device (authentication server 10, management server 20, authentication terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Since biometric information and the like are transmitted and received between these devices, it is desirable that encrypted data be transmitted and received in order to properly protect this information.

[0186] In the flowcharts (sequence diagrams) used in the above description, multiple processes (processes) are shown in order, but the execution order of the processes performed in the embodiment is not limited to the order in which they are shown. In the embodiment, the order of the illustrated processes can be changed to the extent that it does not impair the content, for example, by executing each process in parallel.

[0187] The embodiments described above are explained in detail to facilitate understanding of the disclosure, and it is not intended that all the configurations described above are necessary. Furthermore, when multiple embodiments are described, each embodiment may be used individually or in combination. For example, it is possible to replace parts of the configuration of one embodiment with those of another embodiment, or to add configurations from other embodiments to the configuration of one embodiment. In addition, it is possible to add, delete, or replace parts of the configuration of one embodiment with those of another.

[0188] As described above, the industrial applicability of the present invention is clear, and it is particularly suitable for information processing systems that implement biometric authentication in apartments and other buildings with restricted areas.

[0189] Some or all of the above embodiments may also be described as follows, but are not limited to the following: [Note 1] A list acquisition control means that stores the user IDs of users who can pass through authentication points corresponding to restricted areas within a facility and the permitted time periods during which such users can pass through the authentication points, requests a management server to provide a list of authorized users consisting of the user IDs of at least one authorized user who can pass through the authentication points corresponding to the device, and receives the list of authorized users generated by the management server based on the permitted time periods from the management server. An authentication request means that transmits at least the biometric information of the person to be authenticated and the aforementioned list of authorized passers to an authentication server that stores the user ID and biometric information of the person to be authenticated in a database, An authentication terminal equipped with the necessary components. [Note 2] The authentication server extracts at least one biometric piece of information from the database corresponding to at least one user ID included in the list of authorized passers, and performs a matching process using the extracted biometric piece of information and the biometric information of the person being authenticated. The authentication request means is an authentication terminal as described in Appendix 1, which, upon receiving notification of successful authentication from the authentication server, permits the authenticated person to pass through the authentication point. [Note 3] The aforementioned facility is an apartment building, and the authentication terminal is as described in Appendix 2. [Note 4] The aforementioned biometric information is a facial image or a feature quantity generated from the facial image, as described in any one of the appendices 1 to 3 of the authentication terminal. [Note 5] On the authentication terminal, The system requests a management server, which stores the user IDs of users who are allowed to pass through authentication points corresponding to restricted areas within the facility and the permitted time periods during which such users are allowed to pass through the authentication points, to provide a list of authorized users consisting of the user IDs of at least one authorized user who is allowed to pass through the authentication points corresponding to the system. The management server receives the list of authorized passers generated by the management server based on the permitted time period. A method for controlling an authentication terminal, which transmits at least the biometric information of the person to be authenticated and the list of authorized passersby to an authentication server that stores the user ID and biometric information of the person to be authenticated in a database. [Note 6] On the computer installed in the authentication terminal, A process to request a management server, which stores the user IDs of users who are allowed to pass through authentication points corresponding to restricted areas within the facility and the permitted time periods during which such users are allowed to pass through the authentication points, to provide a list of authorized users consisting of the user IDs of at least one authorized user who is allowed to pass through the authentication points corresponding to the device, The process of receiving the list of authorized passers generated by the management server based on the permitted time period from the management server, The process includes sending at least the biometric information of the person to be authenticated and the aforementioned list of authorized passers to an authentication server that stores the user ID and biometric information of the person to be authenticated in a database, A computer-readable storage medium that stores a program to execute. [Note 7] Authentication terminals are installed at authentication points corresponding to restricted areas within the facility where entry is restricted, A management server that stores the user ID of a user who is allowed to pass through the authentication point and the permitted time period during which the user is allowed to pass through the authentication point, An authentication server stores the user ID and biometric information of the person to be authenticated in a database, Includes, The authentication terminal requests the management server to provide a list of authorized users consisting of the user IDs of at least one authorized user who is able to pass through the authentication point corresponding to its device. The management server generates the list of authorized passers based on the permitted time period and transmits the generated list of authorized passers to the authentication terminal. The authentication terminal transmits at least the biometric information of the person to be authenticated and the list of authorized passers to the authentication server. The authentication server is a system that extracts at least one biometric piece of information from the database corresponding to at least one user ID included in the list of authorized passers, and performs a matching process using the extracted biometric piece of information and the biometric information of the person being authenticated. [Note 8] Within the facility, there are multiple restricted areas, and each of the multiple restricted areas includes multiple authentication terminals corresponding to it. The management server stores, for each of the multiple authentication terminals, the user ID and the permitted time period of the user who is allowed to pass through the corresponding authentication point. The authentication terminal periodically or at predetermined intervals transmits its terminal ID to the management server. The system as described in Appendix 7, wherein the management server generates a list of authorized users for the authentication terminal corresponding to the terminal ID, and transmits the generated list of authorized users to the authentication terminal. [Note 9] When the management server obtains the user's biometric information, it transmits the user's user ID and the obtained biometric information to the authentication server. The authentication server is the system described in Appendix 8, which stores the user ID and biometric information received from the management server in the database. [Note 10] If the authentication server succeeds in the matching process, it notifies the authentication terminal of the authentication success. The authentication terminal that has been notified of the successful authentication is the system described in Appendix 9, which permits the authenticated person to pass through the authentication point. [Note 11] The aforementioned facility is an apartment building, and is a system as described in any one of the appendices 7 to 10. [Note 12] The system described in Appendix 11, wherein the biometric information is a facial image or a feature quantity generated from the facial image. [Note 13] Authentication terminals are installed at authentication points corresponding to restricted areas within the facility where entry is restricted, A management server that stores the user ID of a user who is allowed to pass through the authentication point and the permitted time period during which the user is allowed to pass through the authentication point, An authentication server stores the user ID and biometric information of the person to be authenticated in a database, Includes, The management server generates a list of authorized users consisting of the user IDs of at least one authorized user who is allowed to pass through the authentication point, based on the permitted time period. The authentication server obtains the list of authorized passers from the management server, The authentication terminal transmits a list ID for identifying the list of authorized passers and the biometric information of the person to be authenticated to the authentication server. The authentication server is a system that extracts at least one biometric piece of information from the database corresponding to at least one user ID included in the list of authorized passers, and performs a matching process using the extracted biometric piece of information and the biometric information of the person being authenticated. [Note 14] Authentication terminals are installed at authentication points corresponding to restricted areas within the facility where entry is restricted, A management server that stores the user ID of a user who is allowed to pass through the authentication point and the permitted time period during which the user is allowed to pass through the authentication point, An authentication server stores the user ID and biometric information of the person to be authenticated in a database, Includes, The authentication terminal requests the management server to provide a list of authorized users consisting of the user IDs of at least one authorized user who is able to pass through the authentication point corresponding to its device. The management server generates the list of authorized passers based on the permitted time period and transmits the generated list of authorized passers to the authentication terminal. When the authentication terminal requires authentication of the person to be authenticated, it transmits at least the list of authorized persons to the authentication server. The authentication server extracts at least one biometric piece of information from the database corresponding to at least one user ID included in the list of authorized passers, and transmits the extracted biometric piece of information to the authentication terminal. The authentication terminal is a system that performs a matching process using at least one biometric piece of information obtained from the authentication server and the biometric information of the person being authenticated.

[0190] Furthermore, each disclosure of the above-mentioned prior art documents cited herein is incorporated herein by reference. Although embodiments of the present invention have been described above, the present invention is not limited to these embodiments. It will be understood by those skilled in the art that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. That is, the present invention naturally includes the entire disclosure, including the claims, and various modifications and alterations that can be made by those skilled in the art in accordance with the technical idea. [Explanation of Symbols]

[0191] 10 Authentication Server 20 Management Server 30 Authentication terminals 30-1 Authentication terminal 30-2 Authentication terminal 30-3 Authentication terminal 30-4 Authentication terminal 30-5 Authentication terminal 40 devices 100 Authentication Terminals 101 List acquisition control means 102 Authentication Request Means 201 Communication Control Unit 202 User Management Department 203 Authentication Information Control Unit 204 User Passage Control Unit 205 List Provision Control Unit 206 Memory section 301 Communication Control Unit 302 Authentication Information Notification Processing Unit 303 Authentication Control Unit 304 Storage section 311 Processors 312 memory 313 Input / Output Interfaces 314 Communication Interface 401 Communication Control Unit 402 List Acquisition Control Unit 403 Biological Information Acquisition Unit 404 Authentication Request Section 405 Storage section

Claims

1. A receiving means receives information about at least one authorized person who is allowed to pass through an authentication point corresponding to a restricted area within the facility, from a management server that stores information about authorized persons who are allowed to pass through the said authentication point. A biometric information acquisition means that acquires the biometric information of a person to be authenticated by photographing the person attempting to pass through the authentication point, A permit means that transmits at least the biometric information of the person to be authenticated and information about the person authorized to pass through to an authentication server that stores the biometric information of the person to be authenticated in a database, receives the result of an authentication process performed using the information stored in the database and the biometric information of the person to be authenticated from the authentication server, and permits the person to pass through the authentication point if the result of the authentication process is related to the success of authentication, An authentication terminal equipped with the following features.

2. The authentication server stores information about the authorized passer and the biometric information in a database, extracts at least one biometric piece of information corresponding to the authorized passer from the database, and performs an authentication process using the extracted at least one biometric piece of information and the biometric information of the person to be authenticated. The authentication terminal according to claim 1, wherein the authorization means, upon receiving a notification of successful authentication from the authentication server, permits the authenticated person to pass through the authentication point.

3. The authentication terminal according to claim 2, wherein the facility is an apartment building.

4. The authentication terminal according to any one of claims 1 to 3, wherein the biometric information is a facial image or a feature quantity generated from the facial image.

5. On the authentication terminal, From a management server that stores information on authorized persons who can pass through authentication points corresponding to restricted areas within the facility where entry is restricted, information on at least one authorized person who can pass through the said authentication point is received. By photographing the person to be authenticated as they attempt to pass through the authentication point, the biometric information of the person to be authenticated is obtained. At least the biometric information of the person being authenticated and the information of the person authorized to pass through are transmitted to an authentication server that stores the biometric information of the person being authenticated in a database. The authentication server receives the results of the authentication process performed using the information stored in the database and the biometric information of the person to be authenticated. A method for controlling an authentication terminal, which allows the authenticated person to pass through the authentication point if the result of the authentication process relates to the success of the authentication.

6. On the computer installed in the authentication terminal, A process of receiving information about at least one authorized person who is allowed to pass through an authentication point corresponding to a restricted area within the facility, from a management server that stores information about authorized persons who are allowed to pass through the said authentication point, A process to acquire the biometric information of a person to be authenticated by photographing the person attempting to pass through the authentication point, The process includes transmitting at least the biometric information of the person being authenticated and the information of the person authorized to pass through to an authentication server that stores the biometric information of the person being authenticated in a database, A process of receiving the results of an authentication process performed using the information stored in the database and the biometric information of the person to be authenticated from the authentication server, If the result of the authentication process relates to the success of authentication, the process includes allowing the authenticated person to pass through the authentication point, A program to execute.

7. Authentication terminals are installed at authentication points corresponding to restricted areas within the facility where entry is restricted, A management server stores information about authorized persons who are permitted to pass through the aforementioned authentication point, An authentication server stores the biometric information of the person being authenticated in a database, Includes, The authentication terminal requests the management server to provide a list of authorized passers, which consists of information about at least one authorized passer who is permitted to pass through the authentication point. The management server generates a list of authorized users based on the permitted time period during which the authorized user can pass through the authentication point, and transmits the generated list of authorized users to the authentication terminal. The authentication terminal acquires the biometric information of the person to be authenticated by photographing the person attempting to pass through the authentication point, and transmits at least the biometric information of the person to be authenticated and the list of authorized passersby to the authentication server. The authentication server extracts at least one biometric piece of information from the database corresponding to at least one of the persons with access permits included in the access permit list, and performs an authentication process using the extracted biometric piece of information and the biometric information of the person to be authenticated. The authentication terminal, upon receiving a notification of successful authentication from the authentication server, permits the authenticated person to pass through the authentication point.

8. Within the facility, there are multiple restricted areas, and each of the multiple restricted areas includes multiple authentication terminals corresponding to it. The management server stores information about the authorized person who is allowed to pass through the corresponding authentication point for each of the multiple authentication terminals. The authentication terminal periodically or at predetermined intervals transmits its own terminal ID to the management server. The system according to claim 7, wherein the management server generates a list of authorized users for the authentication terminal corresponding to the terminal ID, and transmits the generated list of authorized users to the authentication terminal.

9. Authentication terminals are installed at authentication points corresponding to restricted areas within the facility where entry is restricted, A management server that stores the permitted time period during which authorized persons who are permitted to pass through the aforementioned authentication point are allowed to pass through the aforementioned authentication point, An authentication server stores the biometric information of the person being authenticated in a database, Includes, The management server generates a list of authorized users, consisting of information about at least one authorized user who is permitted to pass through the authentication point, based on the permitted time period. The authentication server obtains the list of authorized passers from the management server, The authentication terminal obtains the biometric information of the person to be authenticated by photographing the person attempting to pass through the authentication point, and transmits the list ID for identifying the list of authorized passersby and the biometric information of the person to the authentication server. The authentication server extracts at least one biometric piece of information from the database corresponding to at least one of the persons with access permits included in the access permit list, and performs an authentication process using the extracted biometric piece of information and the biometric information of the person to be authenticated. The authentication terminal, upon receiving a notification of successful authentication from the authentication server, permits the authenticated person to pass through the authentication point.

10. Authentication terminals are installed at authentication points corresponding to restricted areas within the facility where entry is restricted, A management server that stores the permitted time period during which authorized persons who are permitted to pass through the aforementioned authentication point are allowed to pass through the aforementioned authentication point, An authentication server stores the biometric information of the person being authenticated in a database, Includes, The authentication terminal requests the management server to provide a list of authorized persons, which consists of information about at least one authorized person who is permitted to pass through the authentication point. The management server generates the list of authorized passers based on the permitted time period and transmits the generated list of authorized passers to the authentication terminal. When the authentication terminal requires authentication of a person to be authenticated who intends to pass through the authentication point, it obtains the biometric information of the person to be authenticated by taking a photograph of the person to be authenticated, and transmits at least the list of authorized persons to the authentication server. The authentication server extracts at least one biometric piece of information from the database corresponding to at least one of the persons with access permits included in the access permit list, and transmits the extracted biometric piece of information to the authentication terminal. The authentication terminal performs an authentication process using at least one biometric piece of information obtained from the authentication server and the biometric information of the person to be authenticated obtained, and if the authentication process is successful, permits the person to be authenticated to pass through the authentication point.

Citation Information

Patent Citations

  • Image forming apparatus, authentication system, and authentication method and program for the same

    JP2011128907A

  • Anonymous authentication system, anonymous authentication method, and anonymous authentication program

    JP2012032952A

  • Position information acquisition device and position information acquisition program

    JP2022031037A

  • Server device, entrance / exit management system, server device control method, and storage medium

    WO2022009380A1