User Management System

The user management system addresses privacy concerns by using detection processes and databases to identify user actions without cameras, enabling detailed user management and behavior analysis.

JP2026110385APending Publication Date: 2026-07-02TOYOTA JIDOSHA KK

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2024-12-20
Publication Date
2026-07-02

AI Technical Summary

Technical Problem

Existing user management systems that rely on cameras for identifying user actions infringe on privacy and are undesirable from a privacy protection standpoint.

Method used

A user management system that utilizes detection processes to identify user actions without specifying the user, using sensors to detect presence and specific actions, and records these actions in a database for later identification, allowing for privacy-respecting user management.

Benefits of technology

Enables detailed user management by detecting and identifying user actions without requiring direct identification methods, thus protecting user privacy while understanding user behavior patterns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026110385000001_ABST
    Figure 2026110385000001_ABST
Patent Text Reader

Abstract

The goal is to provide technology that enables user management while taking privacy protection into consideration. [Solution] The user management system performs a detection process to detect an action performed in room i without specifying which user performed it, and records event data in the database, which is data that associates the detected action with the time. The user management system further performs a first identification process. The first identification process includes determining whether the detected action corresponds to the p-th specific action associated with user p. The first identification process further includes, if the detected action corresponds to the p-th specific action, adding a p-th specific flag to the event data to indicate that user p performed the detected action.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a user management system for managing users who use one or more rooms.

Background Art

[0002] Patent Document 1 discloses an action detection device that detects a person's actions using a camera. The action detection device identifies a person passing through a gate by collating a face image with a camera image captured by the camera. The action detection device tracks the person using the camera image and detects the characteristics of the target person's actions.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Consider managing one or more users who use one or more rooms. In order to grasp the actions of each user in detail and realize appropriate user management, it is necessary to identify the users. However, always acquiring an image of a user with a camera for this purpose is not preferable from the viewpoint of protecting the user's privacy.

[0005] One object of the present disclosure is to provide a technology capable of realizing user management while taking into account the viewpoint of privacy protection.

Means for Solving the Problems

[0006] A first aspect relates to a user management system for managing first to P users who use first to N rooms (both N and P are integers of 1 or more). The user management system includes one or more processors and a database. One or more processors, A detection process is executed to detect an action performed in the i-th room (i=1 to N) without specifying which user performed it. Event data, which is data that associates the detected action with the time, is recorded in the database. It is configured to execute the first specific process. The first specific process is, To determine whether the detected action corresponds to the p-th specific action associated with the p-th user (any of p=1 to P), If the detected action corresponds to the p-th specific action, a p-th specific flag will be added to the event data to indicate that the p-th user performed the detected action. Includes. [Effects of the Invention]

[0007] The user management system described in this disclosure utilizes a detection process that detects users without identifying them, and a first identification process that identifies the user who performed a specific action based on that action. The user management system can also perform the first identification process on past actions based on the time series data in the database. This eliminates the need for devices that directly identify individuals, such as cameras. In other words, the user management system allows for understanding user behavior while taking privacy protection into consideration. [Brief explanation of the drawing]

[0008] [Figure 1] This is a schematic diagram illustrating the overview of the user management system. [Figure 2] This is a flowchart showing the processing flow of the user management system. [Figure 3] This is a schematic diagram illustrating several examples of the re-anonymization process. [Figure 4] This is a schematic diagram illustrating the overview of the movement detection process. [Figure 5] This is a schematic diagram illustrating an example of indirect user identification processing. [Figure 6]This is a schematic diagram showing a portion of the database that records the actions detected on a given day. [Figure 7] This is a schematic diagram showing a portion of the database regarding actions recorded on a different day. [Figure 8] Furthermore, this is a schematic diagram showing a portion of the database of actions recorded on a different day. [Figure 9] This is a schematic diagram illustrating an example of a learning-based specific processing method. [Figure 10] This is a block diagram showing an example configuration for a user management system. [Modes for carrying out the invention]

[0009] Embodiments of this disclosure will be described with reference to the attached drawings.

[0010] 1. User Management System 1-1.Main configuration Figure 1 is a schematic diagram illustrating the user management system 1. User management system 1 manages the first to P users (hereinafter referred to as "user U," where P is an integer of 1 or more) who use the first to Nth rooms (where N is an integer of 1 or more). The first to Nth rooms are configured to be accessible from each other via corridors and other rooms. User management system 1 is typically applied to spaces (such as apartment buildings, offices, etc.) that consist of multiple private rooms and are used by multiple specific individuals.

[0011] Each of the first to Nth rooms is equipped with a detection unit 130 and a user identification unit 140.

[0012] The user management system 1 executes a detection process for detecting a user U present in the room where the detection unit 130 is installed. The detection process is merely a process for detecting the presence of a person (user U), and does not identify who the detected person is. The user management system 1 assigns an "anonymous flag" to the user detected by the detection process. The detection unit 130 includes, for example, a human sensor such as an infrared sensor and a device for wireless sensing. Wireless sensing is a mechanism for detecting an object by detecting fluctuations in radio waves caused by the radio waves of wireless communication being blocked by the object. In the present embodiment, for convenience of explanation, the user detected by the detection process in the i-th room (where i is any one of 1 to N) is defined as the "first user U-1". That is, the detection process is a process for detecting the first user U-1 present in the i-th room and assigning an anonymous flag.

[0013] Various sensors are used in the detection process. The sensors are included in the detection unit 130. The sensors are attached in various places. For example, by attaching pressure sensors to a bed, desk, chair, etc., it is possible to detect actions such as waking up, going to bed, sitting down, and standing up performed by the user U. The detection process is a process for detecting the actions performed by the user U and detecting the presence of the user U. That is, the detection process can also be called an action detection process for detecting actions, or a user detection process for detecting the presence of the user U.

[0014] The user management system 1 determines whether the first user U-1 with an anonymous flag has performed a "specific operation". The specific operation is an operation for identifying each user U. Examples of specific operations include physical operations (sitting in a specific place, raising both hands, etc.), and device operations such as turning on the power of a predetermined electronic device (e.g., a PC) or logging in to a specific system using an electronic device. When a specific operation associated with the first user U-1 is detected, the user management system 1 identifies who the user is by assigning a "first specific flag" to the first user U-1 with an anonymous flag. Hereinafter, the process of assigning a specific flag to identify user U is referred to as "user identification process". It is assumed that the first user U-1 performs the first specific operation in the j-th room (j = any one of 1 to N) and is identified by the user identification process.

[0015] Note that the detection process and the user identification process may be executed in the same room or in different rooms. That is, the user U detected by the detection process may move to another room and be identified by performing a specific operation in the destination room.

[0016] The user management system 1 acquires information regarding the anonymous flag and the specific flag as flag information F. The user management system 1 manages the received flag information F in an aggregated manner. Specifically, the user management system 1 manages the number of users U existing in each room and the entry / exit status of users U for each room based on the flag information F.

[0017] This embodiment takes up the case where the user management system 1 is applied to the facility 10 as shown in the lower part of FIG. 1. The facility 10 is formed by gathering hexagonal-shaped rooms, and the central room is accessible from any other room. That is, each room in the facility 10 is configured to be accessible via the central room. Note that the facility 10 is merely an example to which the user management system 1 is applied, and the number, shape, arrangement, etc. of the rooms are not limited to the examples shown in this embodiment.

[0018] 1-2. Flow of the process Figure 2 is a flowchart showing the processing flow of the user management system 1. The right side of this figure schematically shows the status of facility 10 in a series of steps.

[0019] In step S10, the user management system 1 performs a detection process in room i. If a user is detected (S10; Yes), the process proceeds to step S11. If no user is detected (S10; No), the process repeats step S10.

[0020] In step S11, the user management system 1 assigns an anonymous flag to the first user U-1 detected in room i. At this point, the detection unit 130 is aware that the first user U-1 is in room i, but has not identified who the first user U-1 is specifically. Next, the process proceeds to step S12.

[0021] In step S12, the user management system 1 determines whether or not the first specific operation was performed in room j. If the first specific operation was performed (S12; Yes), the process proceeds to step S13. If the first specific operation was not performed (S12; No), the process repeats step S12.

[0022] In step S13, the user management system 1 assigns a first identification flag to the first user U-1. At this point, the user identification unit 140 can identify who the first user U-1 detected in room i is. The process then ends.

[0023] <Effects> The user management system 1 uses two distinct processes: a "detection process" that detects user U without identifying the user U, and a "user identification process" that identifies user U based on specific actions performed by user U. This series of processes does not require devices that directly identify individuals, such as cameras or microphones. The sensors used in User Management System 1 only need to detect that action has occurred. Furthermore, when detecting specific actions in the user identification process, information that can directly identify an individual (such as video captured by a camera or audio captured by a microphone) is not required. In other words, User Management System 1 makes it possible to acquire information about user U's movements and behavioral patterns while respecting user U's privacy.

[0024] 2. Related processes 2-1. Re-anonymization process Let's consider the case where there are multiple users U. In this case, if there are multiple users U-1 to M (where M is an integer greater than or equal to 2) in the k-th room (k=1 to N), including the first user U-1 who has been assigned the first specific flag, it is desirable that the first specific flag assigned to the first user U-1 be updated to an anonymous flag. Hereafter, the process of updating a specific flag to an anonymous flag will be called the "re-anonymization process".

[0025] Figure 3 is a schematic diagram illustrating several examples of the re-anonymization process. Figure 3(A) shows a situation where the second user U-2, who has been assigned an anonymous flag, enters the kth room where the first user U-1 resides. Since the user management system 1 manages users U by the number of flags in each room, it cannot distinguish which of the two users is the identified first user U-1 when two users exist in the kth room. Therefore, in such cases, it is desirable to update the first identification flag of the first user U-1 to an anonymous flag so that two anonymous users exist in the kth room. The re-anonymization process helps prevent errors in matching the two types of flags (anonymous flag and identification flag). As shown in Figure 3(B), when the second user U-2, who has been assigned a second identification flag, enters the kth room, the re-anonymization process is performed not only on the first user U-1 but also on the second user U-2.

[0026] 2-2. Movement detection process Consider the case where rooms 1 through N include two adjacent rooms. The user management system 1 may perform a "movement determination process" to determine whether a user present in one of the two adjacent rooms has moved to the other of those adjacent rooms. Figure 4 is a schematic diagram showing an overview of the movement determination process. When the two adjacent rooms are room s and room t (s, t = 1 to N), the movement determination process can be described as the process of determining whether user U has moved between room s and room t. The movement determination process is performed based on the number of users in room s ns and the number of users in room t nt. The number of users in room s ns indicates the number of users present in room s. In other words, the number of users in room s ns can be described as the number of flags in room s (the sum of anonymous flags and specific flags). Similarly, the number of users in room t nt indicates the number of users present in room t. In the example in Figure 4, user U has moved from room s to room t. When user U is present in room s, the number of users in room s ns is 1 and the number of users in room t nt is 0. When user U moves to room t, the number of users in room s, ns, is 0, and the number of users in room t, nt, is 1. Since rooms s and t are adjacent to each other, the changes in the number of users in s and t due to user U's movement should occur within a short time. Generally speaking, the user management system 1 determines that user U has moved between rooms s and t if both the number of users in s and t change within a predetermined time.

[0027] Information regarding the number of users ns (sth) and nt (tth) can be called adjacent user count information. In other words, the movement determination process is a process that determines, based on the adjacent user count information, whether or not a user U, who is in one of two adjacent rooms, has moved to the other of those two adjacent rooms. In other words, by repeating the movement determination process, the user management system 1 can track user U within the facility 10.

[0028] 2-3. Indirect User Identification Process In addition to the methods based on specific actions described in Section 1-1, user identification processes can also be considered indirectly, such as identifying the first user U-1. Such user identification processes are specifically referred to as "indirect user identification processes."

[0029] Figure 5 is a schematic diagram illustrating an example of indirect user identification processing. S1 and S2 represent the same situation as (A) in Figure 3. In S1, the first user U-1 is associated with the user ID "A," which corresponds to the first identification flag. Note that the user ID here only needs to be a simple identification symbol and does not need to be linked to personal information such as a facial photograph, address, telephone number, or email address.

[0030] In S2, the re-anonymization process is performed, and the first user U-1 and the second user U-2 are recognized by the user management system 1 as two anonymous users. At this time, the user management system 1 records that the two anonymous users include "A".

[0031] Suppose that the two anonymous users, including "A," then move to another location and reach the state of S3. At this point, if the move detection process has been executed, the user management system 1 can track the two anonymous users, including "A." However, it cannot determine which of the two anonymous users is "A."

[0032] In S4, suppose one of the two anonymous users is identified as "B" (i.e., not "A") through the user identification process. At this point, the other anonymous user (the one who is not "B") is uniquely determined to be "A", so the user management system 1 can indirectly identify "A". In this case, the user management system 1 can identify "A" without determining the first identification operation.

[0033] Indirect user identification is applicable not only when there are two anonymous users, but also when there are multiple anonymous users in general. Generally speaking, indirect user identification is applied when, after the first user U-1 is given an anonymous flag through the re-anonymization process in room k, all of the second to M users are given identification flags for the second to M users.

[0034] 3. User identification process using a database User management system 1 may also include a database DB. User management system 1 can efficiently perform user identification processing by referring to the database DB. The database DB records actions detected by the detection process, associated with the time the action was performed. Data associated with actions and times is called "event data". The longer the user management system 1 is in operation, the more event data accumulates in the database DB. The user identification processing that utilizes the database DB is described below. Here, facility 10 is assumed to be a house where a family lives. In the following description, rooms 1 to 3 are assumed to be adjacent to the kitchen, and the kitchen and living room are assumed to be adjacent to each other.

[0035] Figure 6 is a schematic diagram showing a portion of the database DB that records actions detected on a given day. For ease of explanation, each action is numbered. The outline of each action is as follows. The data containing actions A1 to A10 is labeled with event data E1 to E10. Actions moving between rooms are determined by the movement determination process described above. The behavioral patterns of each user shown in Figure 6 are defined as pattern X. It is assumed that the 1st to Pth users will use facility 10. <Action A1> Get up in Room 1 <Action A2> Get up in Room 2 <Action A3> Get up in the third room. <Action A4> Move from Room 1 to the kitchen <Action A5> Make breakfast in the kitchen <Action A6> Eat breakfast in the kitchen <Action A7> Move from the kitchen to the living room <Action A8> Move from Room 2 to the kitchen <Action A9> Eat breakfast in the kitchen <Action A10> Vacuum the living room.

[0036] 3-1. First Specific Processing The user management system 1 executes the first identification process. In the first identification process, the user management system 1 determines whether each action recorded in the database DB corresponds to a specific action associated with each user. If the recorded action corresponds to a specific action, an identification flag is added to the event data. This process is the same as the user identification process described in Section 1-1, except that it uses the database DB. The upper part of Figure 6 shows the contents of the database DB after the first identification process. Event data E1 containing action A1 is assigned the first identification flag F1, indicating that it was performed by the first user U-1. Event data containing action A2 is assigned the second identification flag F2, indicating that it was performed by the second user U-2. Event data containing action A3 is assigned the third identification flag F3, indicating that it was performed by the third user. Actions A1 to A3 are all actions of getting up in a room, so they are detected, for example, by a sensor attached to the bed. Furthermore, the user who performed the action is identified by the correspondence between the getting-up action and the room in which the action was detected. User Management System 1 cannot identify which user performed actions A4-A10; therefore, no identification flag is assigned to the corresponding event data E4-E10. Hereafter, the person performing each action will be referred to as the "actor."

[0037] More generally, the first identification process includes determining whether the action detected by the detection process corresponds to the p-th specific action associated with the p-th user (where p is one of 1 to P). The first identification process further includes, if the detected action corresponds to the p-th specific action, attaching a p-th specific flag to the event data to indicate that the p-th user performed that action. Event data to which the p-th specific flag has been attached by the first identification process is called the p-th specific event data. Event data to which the p-th specific flag has not been attached by the first identification process is called anonymous event data. In other words, in Figure 6, actions A1 to A3 are the 1st to 3rd specific event data, respectively. On the other hand, actions A4 to A10 are anonymous event data.

[0038] 3-2. Second Specific Processing Following the first identification process, the user management system 1 executes the second identification process. The second identification process is the process of assigning an identification flag to anonymous event data based on the time series shown in the database DB. The lower part of Figure 6 shows the contents of the database DB after the second identification process. For example, in action A4, it is determined that the only person who could move from room 1 to the kitchen is the first user U-1, who was originally in room 1. Therefore, the user management system 1 assigns the first identification flag F1 to action A4. Since it is determined that action A4 was performed by the first user U-1, it is also determined that the subsequent actions A5 to A7 were performed by the first user U-1. This is because, during the relevant time period, there are no other users in the kitchen besides the first user U-1. Action A8 is determined to be performed by the second user U-2 using the same logic as action A4. Furthermore, action A9, which follows action A8, is also determined to be performed by the second user U-2. The act of eating breakfast is common to both actions A5 and A8, but at the time of action A8, no one in the kitchen is present except for the second user U-2 (the first user U-1 has already moved to the living room). Therefore, it is determined that action A8 was performed by the second user U-2. Action A10 is determined to be performed by the first user U-1, who moved to the living room in action A7. The user management system 1 assigns a specific flag to anonymous event data where the actor has been determined. Also, since no movement originating from the third room has been detected (recorded), it is determined that the third user has not moved from the third room.

[0039] In the second identification process, the user management system 1 determines whether or not it is determined that the p-th user performed a certain action, based on the time series shown in the database containing the p-th identification event data. Furthermore, if it is determined that the p-th user performed a certain action, the user management system 1 assigns the p-th identification flag to the anonymous event data. That is, in the example in Figure 6, the user management system 1 assigns the first identification flag F1 to event data E4-E7 and E10, and the second identification flag F2 to event data E8-E9.

[0040] Figure 7 is a schematic diagram showing a portion of the database DB regarding actions recorded on a different day. The behavioral pattern of each user shown in Figure 7 is defined as Pattern Y. In Pattern Y, the timing of actions A4 and A8 is swapped with that of Pattern X. In this case, the actor of each action determined in the second identification process is different from that in Pattern X. Specifically, actions A5-A8 and A10 are determined to be actions performed by the second user U-2, and actions A4 and A9 are determined to be actions performed by the first user U-1. In this case, the user management system 1 assigns the second identification flag F2 to event data E5-E8 and E10, and the first identification flag F1 to event data E4 and E9.

[0041] In the second identification process, the actor is not always determined for every action. Figure 8 is a schematic diagram showing a portion of the database DB related to actions recorded on yet another day. The behavioral pattern of each user shown in Figure 8 is defined as Pattern Z. In Pattern Z, two actions (A4 and A8) of moving to the kitchen are recorded immediately after action A3. In this case, since there are two users in the kitchen at the same time, the user management system 1 cannot determine the correspondence between the two users and the first user U-1 and the second user U-2. That is, the user management system 1 performs a re-anonymization process. Therefore, the actors for actions A5, A6, and A9 performed in the kitchen cannot be determined. Consequently, the user management system 1 does not assign an identification flag to the event data after 7:30. However, even in this case, it is determined that the actions after 7:30 were performed by either the first user U-1 or the second user U-2 (the possibility that the third user, who has not moved from the third room, is the actor is ruled out). Therefore, even in cases like Pattern Z, where the actor is not uniquely determined, the user management system 1 is still somewhat useful in understanding the behavioral pattern.

[0042] 3-3. Extraction of behavioral features User management system 1 can execute the first specific process more efficiently by extracting the characteristics of each operation. The process is explained below.

[0043] For example, in pattern X (see Figure 6), actions A5 and A10 are known to have been performed by the first user U-1. The user management system 1 can extract the characteristics of actions A5 and A10 performed by the first user U-1. The characteristics of each action are extracted based on information obtained from sensors. Characteristics of action A5 include, for example, the time of day when breakfast is prepared, the time required to prepare breakfast, the speed and acceleration of the cooking utensils, and whether or not the stove is used. Alternatively, the installed sensors may measure the load on the kitchen floor, and the measured value may be considered as body weight for feature extraction. Characteristics of action A10 include, for example, the time of day when the vacuum cleaner is used, the length of time the vacuum cleaner is used, and the speed and acceleration of the vacuum cleaner. In other words, the user management system 1 extracts characteristics specific to actions A5 and A10 performed by the first user U-1 from the data of pattern X. To put it another way, the more pattern X is repeated, the more the user management system 1 learns the gestures and habits associated with action A5 performed by the first user U-1. Similarly, in the case of pattern Y (see Figure 7), the user management system 1 extracts (learns) features specific to actions A5 and A10 performed by the second user U-2.

[0044] User Management System 1 can utilize learned features in the first identification process. The first identification process without feature learning can be called "unlearned identification process," and the first identification process with feature learning can be called "learned identification process." The difference between these two types of processes is described here. Figure 9 is a schematic diagram illustrating an example of learned identification process. The contents of the database DB are pattern Z (same as Figure 8). Figure 8 is an example of unlearned identification process, while Figure 9 is an example of learned identification process; the two differ in this respect. In the case of unlearned identification process, the actors of actions A5 and A10 are not determined, so no identification flags are assigned to event data E5 and E10. On the other hand, in the case of learned identification process (Figure 9), actions A5 and A10 may be determined. This is because User Management System 1 learns the unique features of the actions performed by each user in patterns X and Y. In Figure 9, the user management system 1 determines that the actor performing action A5 is the first user U-1, and the actor performing action A10 is the second user U-2.

[0045] In other words, the user management system 1 extracts the characteristics of actions contained in anonymous event data to which the p-th identification flag has been assigned by the second identification process. The user management system 1 further uses the extracted characteristics as characteristics of the p-th identification action in the first identification process. The longer the user management system 1 is in operation, the more event data is accumulated, and the more the system learns the actions performed by each user. As a result, the efficiency of the user management system 1 in identifying each user in the first identification process gradually improves. Examples of extracted action characteristics include the time period in which the action occurred, the location in which the action occurred, the duration of the action, and mechanical parameters related to the action. Mechanical parameters are parameters such as speed, acceleration, and load acquired by sensors attached to equipment or facilities.

[0046] Furthermore, in the second identification process, based on the time-series relationship, it is determined that the room movement immediately preceding action A10 (action A7) was performed by the second user U-2. Although the actors for actions A6 and A9 have not yet been determined, it may become possible to determine them by continuing feature learning. However, even in the state shown in Figure 9, the movement paths of the two users can be understood. In other words, it is determined that the actor for action A6 is either the first user U-1 or the second user U-2, and the actor for action A9 is the other user. Therefore, in pattern Z, the user management system 1 can determine that the first user U-1 moved from the first room to the kitchen, and that the second user U-2 moved from the second room to the living room via the kitchen.

[0047] 3-4. Unknown Event Data In the user management system 1, there may be event data for which a specific flag is not assigned even after going through the first and second specific processing. For example, suppose a person enters facility 10 from outside, moves to the kitchen, and then leaves. The user management system 1 detects this series of actions and records it in the database DB. However, in this case, the user management system 1 cannot basically identify the person who performed this series of actions. The user management system 1 may assign an unknown flag to such event data to indicate that the person who performed the action is unknown. Event data with the unknown flag assigned will be referred to as "unknown event data" below. Since the person who performed the unknown event data may be an intruder, the user management system 1 may notify the administrator of the user management system 1 or user U when unknown event data is accumulated.

[0048] As another case, consider the situation where user U's friend regularly visits facility 10 and cooks in the kitchen. Initially, user management system 1 treats this cooking activity as unknown event data. As mentioned earlier, user management system 1 can extract the characteristics of this cooking activity, so if this friend repeatedly performs the cooking activity, it can recognize this cooking activity as a specific activity and execute the first specific processing. In other words, user management system 1 will start treating this friend as a new user.

[0049] As described above, the user management system 1 performs user identification processing for past actions based on the time series shown in the database DB. This allows the user management system 1 to identify the person who performed each action without using information that can directly identify an individual, such as video or audio. The configuration in which the user management system 1 uses the database DB is particularly effective when the user management system 1 does not include a camera. Note that there are no particular limitations on the timing at which the user identification processing using the database DB (i.e., the first identification process and the second identification process) is executed. Typically, these identification processes are executed periodically according to arbitrarily configurable intervals (monthly, quarterly, semi-annually, etc.).

[0050] 4. Example Configuration Figure 10 is a block diagram showing an example configuration of the user management system 1.

[0051] 4-1. Example of Room i Configuration The right side of Figure 10 shows an example of the configuration of Room i. Note that the configurations of Rooms 1 through N are the same, so Room i is shown here as a representative example.

[0052] The control device 110 is a computer that controls each device installed in the i-th room. The control device 110 includes one or more processors 111 (hereinafter simply referred to as processor 111) and one or more storage devices 112 (hereinafter simply referred to as storage devices 112). The processors 111 perform various processes. For example, the processor 111 includes a CPU (central processing unit). The processor 111 can also be called a processing circuitry. The storage devices 112 store various information. Examples of storage devices 112 include volatile memory, non-volatile memory, HDD (hard disk drive), SSD (solid state drive), etc.

[0053] The flag program PROG1 is a computer program executed by the processor 111. The functions of the control device 110 are realized through the cooperation of the processor 111, which executes the flag program PROG1, and the storage device 112. For example, the detection process and user identification process described above function when the control device 110 executes the flag program PROG1. The flag program PROG1 is stored in the storage device 112. Alternatively, the flag program PROG1 may be recorded on a computer-readable recording medium.

[0054] The control device 110 performs detection processing and user identification processing. The control device 110 acquires information necessary for detection processing via the detection unit 130 and information necessary for user identification processing via the user identification unit 140. The control device 110 also communicates with the management device 200 via the communication device 120. The control device 110 transmits the results of the detection processing and user identification processing, i.e., flag information F, to the management device 200.

[0055] User registration information (UR) is information necessary for user identification processing. User registration information (UR) is in a format that associates each user's user ID with data related to a specific action corresponding to that user ID.

[0056] 4-2. Example of a control device configuration The control device 210 is a computer that controls the management device 200. The control device 210 includes one or more processors 211 (hereinafter simply referred to as processor 211) and one or more storage devices 212 (hereinafter simply referred to as storage devices 212). The processors 211 perform various processes. For example, the processor 211 includes a CPU (central processing unit). The processor 211 can also be called a processing circuitry. The storage devices 212 store various information. Examples of storage devices 212 include volatile memory, non-volatile memory, HDD (hard disk drive), SSD (solid state drive), etc.

[0057] The user management program PROG2 is a computer program executed by the processor 211. The functions of the control unit 210 are realized through the cooperation of the processor 211 executing the user management program PROG2 and the storage device 212. The user management program PROG2 is stored in the storage device 212. Alternatively, the user management program PROG2 may be recorded on a computer-readable recording medium.

[0058] Flag information F contains information about anonymous flags and specific flags for each room. Flag information F includes information about when, in which room, and what type of flag was assigned. Based on flag information F, the management device 200 can determine the number of users U present in each room, the time periods when users U tend to gather, etc. Flag information F is used as adjacent user count information in the movement determination process.

[0059] The database (DB) records user U's actions over time. The database (DB) is used to analyze user U's movement patterns and behavioral patterns within facility 10.

[0060] The control device 210 communicates with the communication device 120 on the i-th room side via the communication device 220.

[0061] 4-3. Others Furthermore, the management device 200 may perform at least a portion of the detection process and user identification process. For example, if information acquired by the detection unit 130 and the user identification unit 140 is sent from the control device 110 to the management device 200, the management device 200 can perform at least a portion of the detection process and user identification process.

[0062] In general, one or more processors perform various processes such as detection, user identification, movement determination, and re-anonymization. [Explanation of Symbols]

[0063] 1: User management system, 10: Facility, 130: Detection unit, 140: User identification unit, F: Flag information, U: User, DB: Database

Claims

1. A user management system for managing the first to P users (P being an integer of 1 or more) who use the first to N rooms (where N is an integer of 1 or more), One or more processors, database and Equipped with, The one or more processors described above are: A detection process is executed to detect an action performed in the i-th room (i=1 to N) without specifying which user performed it. Event data, which is data relating the detected action and time in the detection process, is recorded in the database. Execute the first specific processing. It is configured in such a way, The first specific process is, The process involves determining whether the detected action corresponds to the p-th specific action associated with the p-th user (any of p = 1 to P), If the detected action corresponds to the p-specific action, the p-specific flag indicating that the p-user performed the detected action is added to the event data. including User management system.

2. A user management system according to claim 1, The p-th specific event data includes event data to which the p-th specific flag has been assigned by the first specific processing, Anonymous event data includes event data to which the p-specific flag was not assigned by the first specific processing, The one or more processors are further configured to perform a second specific process. The second specific process described above is: Based on the time series shown in the database including the p-specific event data, it is determined whether or not the p-user performed the detected action. If it is determined that user p performed the detected action, the p-specific flag is added to the anonymous event data. including User management system.

3. A user management system according to claim 1, The one or more processors further include: Extract the characteristics of the detected behavior, The extracted features are used as features of the p-specific operation in the first specific process. It is configured to User management system.

4. A user management system according to claim 3, The characteristics of the detected operation are, The detected action includes at least one of the following: the time period during which the detected action occurred, the location where the detected action occurred, the duration of the detected action, and mechanical parameters related to the detected action. User management system.

5. A user management system according to any one of claims 1 to 4, Camera not included User management system.