Owner serial authentication system, lost property recovery system, spare item creation system, and seal
The system enhances seal authentication by integrating biometric and location verification to ensure continuous authentication, addressing vulnerabilities in existing methods and improving security for seal usage.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- MAINA & CO CO LTD
- Filing Date
- 2026-05-07
- Publication Date
- 2026-07-29
AI Technical Summary
Existing seal authentication methods lack sufficient security measures beyond simple comparison of unique identification information, leaving them vulnerable to unauthorized use and impersonation.
A system that incorporates biometric authentication, location detection, and continuous verification to ensure that the user's biometric information matches the registered data, enhancing security by requiring multiple steps and continuous authentication.
Improves security by ensuring that only the authorized owner can use the seal, reducing the risk of unauthorized access and improving the reliability of seal-based transactions and services.
Smart Images

Figure 2026123254000001_ABST
Abstract
Description
Technical Field
[0004] , , , , , ,
[0003] , , , ,
[0001] The present disclosure relates to an owner continuous authentication system, a lost property relief system, a spare creation system for belongings, and a seal. More specifically, it relates to a method for authenticating the owner of a seal, a system for authenticating the owner of a seal, and a seal, which reads information stored in a memory unit provided in the seal and information on the seal face with a terminal, and processes the information output from the terminal by a server.
Background Art
[0002] An example of a seal authentication method (owner authentication method) that reads information stored in a memory unit provided in a seal and information on the seal face with a terminal, and processes the information output from the terminal by a server, is described in Patent Document 1. Patent Document 1 describes a seal authentication method that reads identification information unique to a seal stored in an IC tag (memory unit) with a terminal, and authenticates the impression of the seal by a server connected to the terminal through a network. The terminal transmits the identification information unique to the seal read when the seal is stamped to the server through the network. When the server receives the unique information sent from the terminal, it collates the received information with the information registered in the database to confirm the validity of the received unique information. Further, Patent Document 1 describes a method of reading the seal face and the IC chip with a terminal and authenticating only the seal face and the IC chip via a network.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
[0005] The objective of this embodiment is to provide a continuous owner authentication system, a lost property recovery system, a spare item creation system, and a seal that improve security associated with the use of personal belongings. [Means for solving the problem]
[0006] One embodiment of the owner continuous authentication system includes a registration device that registers the owner's biometric authentication information in association with the owner's possessions; a location detection device that detects the current location of the possessions after the owner's biometric authentication information has been registered by the registration device; and a determination device that, when the location detection device has detected the current location of the possessions, determines whether the user's biometric authentication information matches the biometric authentication information registered by the registration device when the user uses the possessions. [Effects of the Invention]
[0007] According to one embodiment of the owner continuous authentication system, when a user uses an item they own, the system determines whether the user's biometric authentication information matches the biometric authentication information registered in the registration device. Therefore, the security associated with the use of the item is improved. [Brief explanation of the drawing]
[0008] [Figure 1] This is a schematic diagram of an environment including a seal authentication system, which is an example of the owner continuous authentication system in this embodiment. [Figure 2](A) is a perspective view of the seals and documents used in the seal authentication system, and (B) is a schematic diagram of a vehicle that can access the seal authentication system. [Figure 3] (A) is a schematic diagram showing an example of a mobile terminal in Figure 1, and (B) is a schematic diagram showing an example of a fixed terminal in Figure 1. [Figure 4] (A) is a flowchart showing a first control example that can be performed with the seal authentication system, and (B) is a flowchart showing a second control example that can be performed with the seal authentication system. [Figure 5] (A) is a flowchart showing a third control example that can be performed in the seal authentication system, and (B) is a flowchart showing a fourth control example that can be performed in the seal user authentication system. [Figure 6] (A) is a perspective view showing an example of a card-type seal, and (B) is a perspective view showing an example of a coin-type seal. [Figure 7] This figure shows an example of a lost property retrieval system according to this embodiment. [Figure 8] This diagram shows the portable terminal for the lost and found recovery system in this embodiment. [Figure 9] This diagram shows the flow of the lost item retrieval system in this embodiment. [Figure 10] This diagram shows the flow of the lost item retrieval system in this embodiment. [Figure 11] This diagram shows a modified example of the lost item retrieval system in this embodiment. [Figure 12] This diagram shows a modified flow of the lost item retrieval system according to this embodiment. [Figure 13] This diagram shows a modified example of the lost item retrieval system in this embodiment. [Figure 14] This figure shows an example of a second lost item retrieval system in this embodiment. [Figure 15] This diagram shows the flow of the second lost item retrieval system in this embodiment. [Figure 16] This diagram shows the flow of the second lost item retrieval system in this embodiment. [Modes for carrying out the invention]
[0009] This embodiment will now be described based on the drawings. As shown in Figure 1, the seal authentication system 10, which is an example of an owner continuous authentication system, a lost property recovery system, and a spare property creation system, comprises a seal 11, a terminal 13 used by the owner 12 of the seal 11, and a seal authentication server 15 connected to the terminal 13 via the internet (network, communication line) 14. The owner 12 includes all users of the seal authentication system 10, such as the owner of the seal 11, the representative of a corporation, and a person entrusted with the right to use the seal 11 by the owner of the seal 11. This seal authentication system 10 is authenticated via the internet from the owner's terminal. In this case, the owner includes not only individual owners but also all users of this system, such as a person entrusted by the representative of a corporation.
[0010] As shown in Figure 2(A), the seal 11 can be a cylindrical or polygonal, ring-shaped, or watch-shaped object made of, for example, ivory, buffalo horn, wood, or titanium, and has a seal surface 16 at its tip. A seal memory unit (IC (Integrated Circuit) seal, IC chip, IC tag, etc.) 18 is provided on a part of the seal 11, for example, on its outer surface 17. The seal 11 has a power supply 100 and a communication unit 101, and the communication unit 101 operates using the power from the power supply 100 to output a signal. The power supply 100 is, for example, a rechargeable and dischargeable secondary battery. The seal memory unit 18 can be attached to or embedded in the outer surface 17.
[0011] If the seal memory unit 18 is located on the upper side of the seal surface unit 16 in the vertical direction, the seal memory unit 18 acts as a marker (indicator) indicating the vertical direction of the seal surface unit 16. However, if a dedicated marker is provided on the outer surface 17 of the seal 11, the seal memory unit 18 will be located in a different position from the marker. If the seal is watch-shaped, the seal surface is located on the front, back, or belt, and the seal memory unit is located inside. If the seal is ring-shaped, the seal surface is located at the top, and the seal memory unit is located inside.
[0012] The seal storage unit 18 of seal 11 stores unique information of seal 11, such as the name, address, date of birth, gender of the individual who is the owner, the identification number assigned to each owner, phone number, and photo. By logging in to the My Portal, it has the functions of a driver's license and an insurance certificate. This serves as a backup driver's license, insurance certificate, identity certificate in case of loss, etc., and as a key for cars, houses, etc. When only using this function, the shape and form, such as the presence or absence of the seal surface, are not questioned.
[0013] As the identification number, for example, it is assigned by a public institution or a private institution. As an identification number assigned by a public institution to an individual, for example, there is a My Number (registered trademark) common to the social security fields such as driver's licenses, insurance, welfare, and labor insurance, and the national and local tax fields, which can identify and prove an individual. Note that the identification number may include not only arithmetic numbers but also English letters, symbols, Greek letters, etc.
[0014] As shown in FIG. 1, the owner 12 owns an identification number card (for example, a My Number card) 19 corresponding to the identification number. The identification number card 19 has a card storage unit 20 and a face photo unit 21. The card storage unit 20 is, for example, an IC chip, and the card storage unit 20 stores unique information, such as the name, address, date of birth, etc. of an individual.
[0015] The terminal 13 includes at least one of a mobile terminal 22 or a fixed terminal 23. The mobile terminal 22 is, for example, a smartphone, a tablet terminal, a wristwatch-type terminal, etc. The mobile terminal 22 can be used both indoors, outdoors, and inside a vehicle, and the owner 12 who holds the mobile terminal 22 can move outdoors. When the mobile terminal 22 is connected to the Internet 14, the mobile terminal 22 can detect information on its current position on the earth by GPS (Global Positioning System). The fixed terminal 23 is a desktop computer, a notebook computer, etc., and the fixed terminal 23 is basically used within a limited range indoors.
[0016] As shown in Figure 3(A), the mobile terminal 22 includes an operation unit 24, a camera 25, a recognition sensor 26, a terminal memory unit 27, a control unit 28, a receiving unit, and a transmitting unit. The mobile terminal 22 has a writing function. The writing function is achieved, for example, by a structure such as the "IoT ID platform," a next-generation security service that can issue and centrally manage electronic certificates, or "G-Shield," which directly writes certificates to an IC chip. The camera 25 can photograph the stamp surface 16 of the seal 11, and the information of the stamp surface 16 photographed by the camera 25 is stored in the terminal memory unit 27. The information of the stamp surface 16 may be the impression 30 formed when the stamp surface 16 is pressed onto a document (document, paper) 29, as shown in Figure 2.
[0017] The recognition sensor 26 reads the information stored in the seal storage unit 18 and the card storage unit 20 and sends it to the control unit 28. When the owner 12 operates the operation unit 24, the control unit 28 performs processing corresponding to the operation. The control unit 28 sends the information captured by the camera 25 and the information read by the recognition sensor 26 to the seal authentication server 15 via the internet 14.
[0018] The fixed terminal 23, as shown in Figure 3(B), includes an operation unit 31, a camera 32, a reader 33 as a recognition sensor, a control unit 34, a terminal storage unit 35, a display unit 36, a receiving unit, and a transmitting unit. The camera 32 is capable of photographing the stamp surface 16 of the seal 11, and the information of the stamp surface 16 photographed by the camera 32 is stored in the terminal storage unit 35. The information of the stamp surface 16 may be the stamp impression 30 shown in Figure 2.
[0019] The reader 33 reads the information stored in the seal storage unit 18 and the card storage unit 20 and sends it to the control unit 34. The owner 12 operates the operation unit 31 while visually checking the display unit 36, and the control unit 34 processes according to the operation. The control unit 34 stores the information captured by the camera 32 and the information read by the reader 33 in the storage unit. Subsequently, the user logs in to the portal site of the seal authentication server 15, reads the information from the seal storage unit 18 of the seal 11, and sends it to the seal authentication server 15 along with the data from the seal surface unit 16.
[0020] The seal authentication server 15 is installed in a public or private institution acting as an authentication authority. Public institutions include, for example, city halls, ward offices, branch offices, etc. The seal authentication server 15 has a receiving unit, a transmitting unit, a server storage unit 37, and a control unit 38, etc. The server storage unit 37 stores the seal surface 16 and seal impression 30 of the seal 11, and the unique information of the seal 11, in association with each other. When the seal authentication server 15 is installed in a public institution, when the owner 12 of the seal 11 registers the seal at the public institution, the seal authentication server 15 of the public institution stores the seal surface 16 and seal impression 30, the identification number, and the unique information in association with each other. The owner authentication server and the seal authentication server 15 provide a portal site (identification number portal) on the Internet 14.
[0021] When owner 12 logs into the portal site for the first time from the internet 14 using terminal 13, there is no need to enter an identification number, password, or perform biometric authentication. Owner 12, while logged into the portal site, registers an identification number, registers a password, registers biometric authentication information, reads and registers an identification number card 19, and registers the seal surface 16 of the seal 11. Biometric authentication can be performed using a camera, recognition sensor, or reader, and includes at least one of the following: fingerprint authentication, vein authentication, facial recognition, iris authentication, etc. The password is determined separately from the identification number by owner 12 or the authentication authority, and consists of Arabic numerals, letters, symbols, etc.
[0022] Furthermore, the seal authentication system 10 may be configured to perform short-range wireless communication (NFC: Near Field Communication) between the terminal 13 and the vehicle 39. Examples of short-range wireless communication technologies that can be used include Bluetooth®, Bluetooth Low Energy (BLE®), Felica®, Wi-Fi®, UWB®, and TransferJet®. As shown in Figure 2(B), the vehicle 39 has a drive source 40, a control unit 41, a reading unit 42, a transmitting unit, and a receiving unit. In addition, a key 43 for switching the start and stop of the drive source 40 is provided separately from the vehicle 39.
[0023] The owner 12 holds and operates the key 43. The key 43 has a memory unit that stores personal information or identification information, and also has a function for sending and receiving signals. The drive source 40 generates rotational force, and the drive source 40 may be either an engine or an electric motor. The key 43 may be equipped with a primary battery and a secondary battery that can be charged and discharged. The battery may be capable of wireless (contactless) charging.
[0024] Owner 12 drives the vehicle 39 while carrying a driver's license (hereinafter abbreviated as "license") 44. The license 44 has a memory unit, which stores the personal information of the owner of the license 44. The reading unit 42 reads the information from the memory unit of the key 43 and the memory unit of the license 44 and sends a signal to the control unit 41. When owner 12 operates the key 43, the control unit 41 can switch between stopping and starting the drive source 40. When the drive source 40 is started, it is possible to transmit the rotational force of the drive source 40 to the drive wheels 45.
[0025] (First control example) An example of control that can be performed by the seal authentication system 10 is shown in Figure 4(A). First, in step S1, the owner 12 of the seal 11, while accessing and logging into the seal authentication server 15, registers the actual seal surface 16 and seal impression 30 of the seal 11, and registers biometric authentication information. Also in step S1, the owner sets a password and registers the identification number of the seal 11 at the seal authentication server 15.
[0026] After step S1, in step S2, the seal authentication server 15 detects the current location of the seal 11. The current location of the seal 11 may be detected continuously or at predetermined time intervals. With the location information of the seal 11 detected, the user uses the seal 11 at the user institution 46 in step S4. Also in step S4, information on the actual seal surface 16 and the impression 30 of the seal 11 to be used is read by the terminal 22 or the reader at the user institution 46 and sent to the seal authentication server 15. Also in step S4, biometric authentication of the user is performed by the terminal 22 or the reader at the user institution 46, and the biometric authentication information is sent to the seal authentication server 15.
[0027] In step S5, the seal authentication server 15 determines whether the actual seal surface 16 and seal impression 30 of the seal 11 included in the information input from the terminal 13 match the seal surface 16 and seal impression 30 registered in the server storage unit 37. In step S5, the seal authentication server 15 also determines whether the pre-registered biometric authentication information of the owner matches the biometric authentication information of the user.
[0028] If the seal authentication server 15 determines Yes in step S5 and confirms that the biometric authentication information of the user matches the biometric authentication information of the owner that has been registered in advance, and that the actual seal surface 16 and impression 30 of the seal 11 used match the seal surface 16 and impression 30 registered in the server storage unit 37, it enables the use of the seal 11 in step S6 and terminates the control example in Figure 4(A). If the seal authentication server 15 determines No in step S3 or step S5, step 6 is skipped and the control example in Figure 4(A) terminates. In other words, since the user of the seal 11 is not the registered owner 12, the seal 11 cannot be used.
[0029] As described above, according to the seal authentication system 10, when a user uses a seal 11, it is determined whether the user's biometric authentication information matches the biometric authentication information registered in the seal authentication server 15. If the user's biometric authentication information matches the biometric authentication information registered in the seal authentication server 15, the seal 11 can be used; otherwise, the seal 11 cannot be used. Therefore, the security associated with using the seal 11 is improved.
[0030] Furthermore, in the seal authentication method and seal authentication system 10, the seal authentication server 15 performs authentication of the seal 11 presented via the terminal 13 in three steps: the first step, the second step, and the third step. The first step is that the terminal 13 is logged in to the portal site provided by the seal authentication server 15 and is in an active state. The second step is that, if the terminal 13 is in the active state, the seal authentication server 15 determines whether the 3D seal impression 30 or the 3D seal impression of the seal surface 16 of the actual seal 11 matches the seal impression 30 or the 3D seal impression of the seal surface 16 registered with the seal authentication server 15. The third step is that, if the terminal 13 is in the active state, the information of the seal storage unit 18 is read. Therefore, the number of steps required for authentication of the seal 11 increases, and the security of owner authentication of the seal 11 is enhanced.
[0031] If the seal authentication server 15 is installed in a public administrative agency, the owner 12 can receive administrative services such as the issuance of family register transcripts, resident registration certificates, and various other certificates while logged into the portal site. If the seal authentication server 15 is installed in a private institution, the owner 12 can receive various private services such as product reservations, product sales and settlements, real estate lease agreements, real estate sales agreements, and ticket purchase payments by accessing the user institution 46 via the internet 14 using the terminal 13, or by the owner 12 going directly to the user institution 46. The user institution 46 may be any of the following: internet services (including e-commerce), home improvement stores, banks, securities companies, real estate companies, department stores, and other commercial facilities.
[0032] The various services described above can be received by the owner 12 generating a seal impression 30 on a document 29 created with various applications or software such as Word or PDF, attaching electronic authentication or electronic signature data, or both, and then transferring or sending the said document 29 to an administrative agency or user agency 46. The services described above can be received by generating a seal impression 30 on a document 29 created with an application such as Word or PDF, attaching electronic authentication or electronic signature data, or both, and then transferring or sending the said document 29 to an administrative agency or user agency 46.
[0033] Furthermore, the seal 11 is not limited to a personal seal, but may also be a corporate seal, etc. If the seal 11 is a corporate seal, it stores the name of the representative, the address of the corporation, identification number, telephone number, corporate number, etc. In other words, the disclosed seal authentication method and seal authentication system 10 contribute to public authentication services. If the seal 11 is a corporate seal, it stores the name of the representative, the address of the corporation, identification number, telephone number, corporate number, etc. In other words, the seal authentication system 10 contributes to public authentication services.
[0034] Furthermore, the method for registering the seal surface 16 and impression 30 of the seal 11 with the seal authentication server 15 can also be performed by the terminal 13 logging into the portal site of the seal authentication server 15 using biometric authentication or a password, reading the seal storage unit 18 with the recognition sensor 22 of the mobile terminal 22 or the reader 33 of the fixed terminal 23, and performing three-dimensional (3D) recognition of the seal surface 16 with the camera 25 or the reader 33. The method for registering the seal 11 can also be performed by logging into the My Number Portal and performing IC chip authentication and 3D recognition with a camera.
[0035] (Second control example) Other control examples that can be performed with the seal authentication system 10, specifically methods for recovering lost items, will be explained with reference to Figure 4(B). If the owner 12 loses any of the seal 11, the mobile terminal 22, or the identification number card 19, in step S10, the owner logs in to the portal site provided by the seal authentication server 15 using an auxiliary terminal other than the one lost, for example, the recognition sensor (reader) and operation unit of a terminal 48 at a convenience store 47 as shown in Figure 1, or the reader 33 and operation unit 31 of a fixed terminal 23, a terminal 13 that has not been lost, or a mobile terminal 22C owned by a collaborator (third party) 49A who is cooperating in recovering the owner's item. For example, the owner logs in to the portal site provided by the seal authentication server 15 by reading either the seal storage unit 18 of the seal 11 or the card storage unit 20 of the identification number card 19, and performing biometric authentication or entering a password.
[0036] Then, while logged into the portal site, owner 12 submits a lost item report in step S11. The seal authentication server 15 then displays in step S12 that it has locked the lost seal 11 so that finder 49 cannot use it. In the case of the mobile terminal 22, the lost mobile terminal 22A, the mobile terminal 22B owned by finder 49, and the terminal 48 at convenience store 47 display information such as that the terminal has been locked so that it cannot be used, that the finder 49's personal information has been obtained, that the current location information of the mobile terminal 22A found by finder 49 and the current location information of the mobile terminal 22B owned by finder 49 have been identified, that the power of the mobile terminal 22A cannot be turned off, and that the found item should be taken to a convenience store 47 or the like and scanned with terminal 48. Mobile device 22A is actually mobile device 22, but for convenience, it is referred to as mobile device 22A because it was found by finder 49. Finder 49's personal information includes fingerprints, facial recognition, and iris recognition.
[0037] If the owner loses their belongings such as a seal 11, a mobile terminal 22, or an identification number card 19, they can go to a convenience store 47 or terminal 13, hold a non-lost item 10 over the reader 33, log in using biometric authentication or a password, file a lost item report, lock the lost item to prevent its use, obtain personal information including the finder's fingerprint, facial recognition, and iris recognition to identify the finder, determine their current location, the mobile terminal 22A cannot be turned off, and request that they take it to a convenience store 47. This information will be displayed on the screen of the mobile terminal 22A, the screen of the mobile terminal 22B owned by the finder 49, or the terminal 48 at the convenience store 47.
[0038] This personal information is automatically acquired when the finder 49 turns on the mobile terminal 22A or performs any operation, by the recognition sensor 26 and camera 25 of the mobile terminal 22A. Information acquired by the mobile terminal 22B owned by the finder 49 is also used. Furthermore, in step S13, the seal authentication server 15 displays the method of returning the mobile terminal 22A, the reward amount if it is returned, etc., on the screen of the mobile terminal 22A, the screen of the mobile terminal 22B owned by the finder 49, or the screen of the terminal 48 at the convenience store 47, and terminates the control example in Figure 4(B). Note that the owner authentication and seal authentication server 15 can also terminate the control example in Figure 4(B) without performing the processing in steps S12 and S13 after step S11.
[0039] (Third control example) Other control examples that can be performed in the seal authentication system 10 and vehicle 39 will be described with reference to Figure 5(A). In step S20, the key 43 is read by the mobile terminal 22, and at least one of the storage units of the seal storage unit 18 of the seal 11 or the card storage unit 20 of the identification number card 19 is read, and the read information is sent from the mobile terminal 22 to the control unit 41 of the vehicle 39 without going through the internet. Then the control unit 41 starts the drive source 40 in step S21. The control unit 41 can also process the information sent from the mobile terminal 22 to determine that the driver of the vehicle 39 is the owner 12.
[0040] In step S22, the mobile terminal 22 detects that owner 12 has left vehicle 39 without the seal 11 or identification number card 19, or without the seal 11, and a signal is sent from the mobile terminal 22 to the control unit 41 of vehicle 39. The control unit 41 then performs a process in step S23 to sound the horn of vehicle 39, or notifies the owner by sounding an alarm on the app on the mobile terminal 22. As a result, owner 12 realizes that they did not have the seal 11 or identification number card 19 with them, that is, that they left it in vehicle 39.
[0041] Furthermore, if the control unit 41 identifies the driver in step S20, it can utilize data such as insurance information to assist with medical care if the driver is involved in an accident or becomes ill in the vehicle. Also, if the control unit 41 detects a traffic accident involving vehicle 39, it can send accident information to the police or registered family members if it has a communication function, or via the mobile terminal 22 if it does not have a communication function. In addition to identifying the accident scene and the driver of vehicle 39, it can also automatically identify perpetrators of hit-and-run incidents.
[0042] (Fourth control example) Other control examples that can be performed in vehicle 39 are shown in Figure 5(B). In step S30, the reader 42 of vehicle 39 reads the information of the key 43, the driver's license 44, and the identification number card 19, and when the seal 11 is read by the terminal 13, the control unit 41 performs authentication processing of the unique information of the seal 11. In step S31, if any one of the first, second, or third states is established, the control unit 41 starts the drive source 40 in step S32 and terminates the control example in Figure 5(B).
[0043] The first state is when it is detected that the key 43 has been brought into the interior of the vehicle 39, and the driver's license 44 has been read by the reader 42. The second state is when it is detected that the key 43 has been brought into the interior of the vehicle 39, the driver's license 44 has been read by the reader 42, and the owner 12's biometric authentication has been performed at the terminal 13. The third state is when it is detected that the key 43 has been brought into the interior of the vehicle 39, the driver's license 44 has been read by the reader 42, the owner 12's biometric authentication has been performed at the mobile terminal 22 or a device installed in the vehicle 39, and the owner 12 has turned on the start button located inside the vehicle 39.
[0044] Furthermore, if the owner 12 introduces (establishes) the seal authentication system 10 when purchasing a vehicle 39, or at the time of vehicle inspection, etc., then within three years after the introduction of the seal authentication system 10, unlicensed driving, driving during license suspension, driving of stolen vehicles, etc., will decrease in vehicles running in Japan.
[0045] (Additional information) The seal may be cylindrical, or it may be a card-shaped seal 50 as shown in Figure 6(A), or a coin-shaped seal 60 as shown in Figure 6(B), or a polygonal, ring-shaped, or watch-shaped seal. Seal 50 has, for example, a card 51 made of synthetic resin, and a seal surface portion 52 and a storage portion 53 provided on one side of the card 51. Seal 60 has, for example, a disc portion 61 made of synthetic resin, a seal surface portion 62 provided on the first side of the disc portion 61, and a storage portion 63 provided on the second side of the disc portion 61. If seal authentication is not performed and only the seal authentication server 15 is used, the seal surface portion 16 is not required, and there are no restrictions on the shape and form of the seal 11.
[0046] An example of the technical meaning disclosed in the embodiments is as follows: The seal authentication system 10 is an example of an owner continuous authentication system and a lost property recovery system. The seal 11 is an example of an item of ownership. The seal authentication server 15 is an example of a registration device, a location detection device, a judgment device and a control device. The seal authentication server 15 is an example of a server. The terminal 13 is an example of a terminal.
[0047] The seal authentication server 15 is an example of a server and owner authentication server. The seal storage unit 18 and storage units 53, 63 of the seal 11 are examples of storage units. The terminal 48 of the convenience store 47 is an example of an auxiliary terminal, and the finder 49 is an example of a third party. The collaborator 49A, who provides the terminal 13 exclusively for lost property reports, is an example of a third party.
[0048] The routine that determines "Yes" in step S1 shown in Figure 4(A) is an example of the first step, the determination made in step S2 is the second step, and the processing made in step S3 is an example of the third step. Step 12 in Figure 4(B) is an example of the first and second notification steps, and step 13 is an example of the third notification step. The control unit 41 and the reading unit 42 are examples of in-vehicle equipment.
[0049] (Continuous Ownership Authentication System) Owner authentication system. Is the person performing the operation truly the owner? The current state of owner authentication.
[0050] 1. Unauthorized logins via iris recognition or facial recognition. A relay attack on biometric authentication is easy. By extending the cable of a WindowsHallo! (registered trademark) compatible webcam or transmitting the signal via Wi-Fi (registered) or Bluetooth (registered trademark), remote login is possible. Adding a telephoto lens makes remote login even easier. Authentication can be easily performed through a mirror. It might even be possible through a one-way mirror.
[0051] 2. Unauthorized login using PIN code, pattern, or password. It's possible to log in simply by mimicking the owner's finger movements. Most close relatives should be able to bypass this. A hacker could log in using IDs and passwords collected from the internet.
[0052] 3. Unauthorized logins via fingerprint or vein authentication. The owner logs in by touching the device while sleeping. A third party can log in at any time by registering their fingerprint. A certain number of lovers register each other's fingerprints on their smartphones as a pledge of their loyalty. If fingerprints or facial recognition are registered when informing someone about changing phones, the smartphone and account can be completely hijacked. As with current smartphones, fingerprint authentication can be embedded in the screen or switches, so there is a concern that fingerprint information could be leaked without the user noticing.
[0053] 4. Unauthorized logins through multi-factor / multi-step authentication. One-time passwords and QR code (registered trademark) authentication are completely ineffective against anyone who logs in via smartphone. Since the token can be found by searching the room, it cannot be used by a partner, friend, or family member.
[0054] 5. Defects in PCs, smartphones, and the My Number Portal. Even if biometric authentication is not possible, the risk of security is doubled because it's possible to log in using a password by mimicking hand movements. Most My Number cards have their passwords stored at home. If someone logs into Mozilla Firefox (registered trademark), antivirus apps, Google (registered trademark), or iCloud (registered trademark) keychain using the methods described above, all passwords can be easily stolen.
[0055] 6. Face ID can authenticate even fraternal twins.
[0056] 7. Face ID can authenticate even if the person is a parent, child, sibling, or simply looks similar. Therefore, facial recognition and iris recognition alone cannot guarantee security. A continuous owner authentication system will provide the solution.
[0057] The login methods described above all share a common drawback. Even with multi-factor authentication and multi-step authentication, which are cleverly combined, the owner's identity is only verified at the moment of login. After logging in, operations are permitted based on the assumption that the owner is operating the device. This means that if a third party takes over during operation, or if a partner or family member logs into the device without permission, or if the account is hacked, they can operate the device just like the owner, which is dangerous.
[0058] In fact, besides hacking, unauthorized logins such as LINE messages being viewed by a partner or family member, or elementary school children making unauthorized purchases or in-game purchases using their parents' smartphones, have become a social problem. The current one- or two-step owner authentication system is insufficient to prevent impersonation, but this continuous owner authentication system can completely eliminate security vulnerabilities that arise from the moment of login.
[0059] Things that are expected to be effective. 1. Impersonation and unauthorized login to devices such as PCs and smartphones. 2. Account impersonation and unauthorized logins by hackers. 3. Impersonation during telephone identity verification. 4. It can be expected to be effective against nuisance calls such as those from phone scammers, stalkers, and complainers. 5. Stalking behavior using location information systems. Therefore, this type of crime can be eliminated.
[0060] The next generation of fraudulent logins involves biometric authentication relay attacks. Can you imagine what crime will be like in ten years? Just as vehicle thefts are rampant due to relay attacks, it's possible that people will be stealing biometric authentication and IC chip data in the streets using relay attacks. For example, even now, with facial recognition logins on computers, if you extend the cable of a USB-connected Windows Hello! compatible webcam and use facial recognition, someone more than 10 meters away from the computer can log in to the computer, smartphone, or account services using biometric authentication. If products that transmit USB signals via Bluetooth or Wi-Fi become available, a parent could use a Windows Hello!-compatible webcam to perform facial recognition on their child while they're in the bathroom, allowing the child to illegally log into the PC. This would enable them to do whatever they want, such as making in-app purchases, online shopping, and sending money. A hacker could potentially take over a housewife's laptop while she's watching daytime dramas at home, bypass biometric authentication using the housewife's own device, and then freely take over the account to make money, change passwords, or alter biometric authentication settings, all while profiting from the hacker's actions.
[0061] The Owner Sequential Authentication System will lead to a solution. Owner Sequential Authentication Login Method: Logging into the device: (1) Log in to the device (2) using biometric authentication or password, etc. Logging into the account: (1) Log in to the device (2) using the account ID and (3) using biometric authentication or password, etc. Logging into the account using My Number: (1) Log in to the device and (2) log in to the My Number Portal (3) using the service's account ID and (4) using biometric authentication, etc. After logging in as usual as described above, the device will automatically repeat the Owner Sequential Authentication process. When logging into an account, in addition to the above, the device will continuously send information such as device information and location information, as well as a private key that serves as proof of owner authentication, to the server, thereby guaranteeing owner authentication and completely detecting impersonation by third parties and hackers.
[0062] 1. Log in to the device. Register the owner's biometric authentication. There are also methods to authenticate or link using personal identification data from your My Number Card for eKYC authentication.
[0063] 2. Multi-factor, multi-step authentication, including various biometric authentication methods, password / PIN number / pattern input, is continuously and randomly implemented on the device in a complex manner, either sequentially, periodically, in conjunction with user operation, or on an ad-hoc basis, protecting the device and data from unauthorized operation, unauthorized logins, and eavesdropping.
[0064] 3. After logging into your account, the device will generate a private key and send it to the account server. The private key will be stored on both the device and the server and used for verification.
[0065] Each time steps 4 and 2 are repeated, the private key is continuously sent to the account server as proof of continuous owner authentication. This ensures that the account owner is logging in from their own device, thus protecting the account from unauthorized logins.
[0066] If the 5, 2, 4 owner authentication sequence is interrupted, the screen will dim to ensure security.
[0067] 6. We send third-party acquired data to the owner to protect the owner from the risk of crime.
[0068] For example, in the past, if a child registered their biometric authentication on their parent's computer or smartphone, it was possible to make fraudulent transfers via online banking. With the owner serial authentication system, security is ensured by layering multiple methods such as facial recognition, iris recognition, and fingerprint recognition, including passwords and QR code authentication, to the point where even looking at the device screen is not permitted, thus guaranteeing a level of security.
[0069] Comparison with antivirus software and encrypted communication.
[0070] When discussing security, the security of network connections is often a major concern. Encrypted communications such as TSL, used for the My Number Portal, and SSL, used for payment screens, are not designed to authenticate the owner, and therefore are ineffective in this regard. Antivirus software also lacks effective anti-spoofing features; in fact, it often displays all passwords with just a brief biometric authentication or password, raising concerns about leaks from password management apps. Even apps considered secure, such as Mozilla Firefox, iCloud Keychain, and Google Password Manager, can similarly display passwords, raising concerns about leaks using the methods described above. A continuous owner authentication system will provide a solution.
[0071] Solutions for when a third party registers their fingerprint on the device.
[0072] If a third party's fingerprint is registered on the owner's smartphone, the device will recognize the third party's fingerprint as the owner's. As a result, operations will be executed under the mistaken assumption that the owner is performing the action, putting all accounts and passwords, including those for online shopping, banking, cashless payments, and social media, at a significant risk. This risk is so great that the user would have to notice the fraud, change all biometric authentication and passwords, check the settings of each app, and review all their online shopping and banking history. In effect, the device and accounts would have been almost completely taken over. However, with smartphones that have implemented a continuous owner authentication system, there is no need to worry about this at all.
[0073] This is because no third party can track and follow a device, and then be continuously required to provide both high-resolution biometric authentication stored on the device and actual biometric authentication. To create this situation, the owner continuous authentication system continuously implements multi-factor, multi-step authentication on the device side, including various biometric authentications, passwords, PIN numbers, and pattern inputs, either continuously, periodically, in conjunction with user operation, or on an ad-hoc basis. Furthermore, any device that detects someone other than the owner will consider it an unauthorized login and forcibly dim the screen. Therefore, even if the password is correct, it is virtually impossible to bypass the multiple layers of linked biometric authentication, and we can confidently say that there is no possibility of a third party changing the password or overwriting the biometric authentication. Both the device and the account are completely guaranteed to be secure by the owner continuous authentication system.
[0074] If an unauthorized login is detected, the system communicates with the impersonator's device using biometric authentication such as fingerprints, video footage of the impersonator, and, if possible, short-range wireless communication to read the My Number and the device's unique number, and notifies the owner's device. If the owner deems the activity malicious, they can use this information to file a police report. The owner authentication system will then guide the resolution of the issue.
[0075] The solution to account hijacking is to ensure that each account, device, and owner authentication system work together to protect accounts from unauthorized logins. First, as a common operation, owner authentication is performed immediately after logging in from the device. If the account server supports the owner authentication system, when the account is created, the account server and the device automatically issue a private key as proof of owner authentication to be used exclusively for that account.
[0076] The private key is stored on the owner's device and the account server. The continuous owner authentication system tracks the owner using cameras and sensors, and continuously performs multi-factor authentication and multi-step authentication on the device side, either continuously, periodically, in conjunction with user actions, or on an ad-hoc basis, building trust one after another through various biometric authentications such as facial recognition, fingerprint recognition, and iris recognition, as well as password, PIN number, and pattern input.
[0077] Furthermore, it has a function to monitor and block unauthorized logins by other locations or third parties by comparing and verifying unique information such as device, app, and browser information, as well as the account holder's location information, private keys, and personal identification numbers with the server.
[0078] Therefore, each time the owner is authenticated, the private key is repeatedly sent to the account server for authentication, almost indefinitely. This ensures that the account owner is consistently logging in from their own device. By effectively utilizing the functions of this continuous owner authentication system, even if the owner's ID and password are leaked, accounts with this system in place become completely unhackable. Of course, the password cannot be changed, and biometric authentication cannot be registered. Complete security is guaranteed.
[0079] For example, even if someone attempts to log in by registering a fingerprint through imitation, the screen will go dark within seconds because iris recognition, facial recognition, and vein recognition are performed in succession. Furthermore, if the owner's biometric authentication and tracking of the owner become impossible, both the device and the account will be judged as having committed an unauthorized login, the screen will go dark, and operation will be impossible.
[0080] One example of owner authentication is linking a device or account to a personal identification number such as a My Number. The My Number card stores a photograph of the person. This photograph is used to authenticate the device using eKYC (a method of authentication that involves comparing a photograph of the identification document with a photograph of oneself taken with a camera).
[0081] After the owner's eKYC authentication is completed, the device requests high-resolution biometric authentication such as facial recognition, iris recognition, fingerprint recognition, and vein recognition, and stores this information securely in a safe location on the device. The device then issues a personal identification number or private key to the account server, which is stored on the device, the My Number Card, and the server.
[0082] After logging into the account, the device continuously builds trust by performing multi-factor authentication and multi-step authentication, including various biometric authentication methods as well as password, PIN, and pattern input, while tracking the owner using cameras and sensors. This authentication can be performed continuously, periodically, in conjunction with user actions, or as needed.
[0083] Furthermore, by continuously sending a unique identification number or private key, which serves as proof of continuous owner authentication, to the account server at appropriate intervals or continuously, it is shared that owner authentication is being maintained continuously. Since hackers and third parties cannot possess the personal identification number or private key that serves as proof of continuous owner authentication in this case, they will be unable to log into other people's accounts, thus protecting the owner and the account from crime.
[0084] When using a personal identification number, you will need to log in to a compatible device and portal. Alternatively, you can log in without using a personal identification number or use a private key for owner authentication. If someone attempts to log in illegally, video, biometric authentication, device information, and unique details will be captured, and the owner will be notified or alerted. If the owner considers the attempt malicious, they can use this information as evidence to file a police report. The owner authentication system will then help resolve the issue.
[0085] A fraudulent website that combines payment and biometric authentication.
[0086] I've heard there's an app or website circulating that automatically authenticates your iPhone with Face ID and completes payments if you leave it on a table while chatting or something. Apparently, it's notorious among young people because canceling the service is a real hassle.
[0087] I have no proof whether this is true or false. However, since absolute security is impossible, we cannot ignore it. With continuous owner authentication, during payment, facial recognition, iris recognition, fingerprint or vein recognition, PIN code or password, and one-time password can be performed simultaneously or sequentially, thus preventing damage even if such apps become widespread.
[0088] The owner's continuous authentication system will lead to a solution. It has a function to grant login permission. When a third party needs to use a device for operational instructions, maintenance, accounting, or for people with disabilities, the owner can grant permission to log in to the device, apps, and accounts based on their authority. In this case, detailed permissions can be set for each device, user, and account, specifying which apps are allowed, which websites are permitted to access (for example, which parts of financial services are allowed, which are locked, which do not require permission, and up to what amount permission is not required).
[0089] Furthermore, to prevent damage from occurring as a result of the operation, the system can request permission from the owner or grant permission in some way. The owner can also, at their discretion, turn off the continuous owner authentication system for a set period of time, or even turn it off completely.
[0090] How to spot phishing scams and fraudulent websites. Phishing scams have become a social problem, but thankfully, the online world is controlled by accounts. If a service is linked to an owner authentication system, it should automatically prepare to exchange your personal identification number or private key. If this does not happen, you can assume that the site is highly likely to be a fraudulent site.
[0091] As long as the owner authentication system's private key is synchronized with your account, a secure connection is maintained. As proof of this, a green mark indicating a secure connection will be displayed to the left of the URL in your browser. If the owner authentication system's private key is not synchronized with your account, a yellow or red mark will light up or blink to indicate that the connection does not synchronize the private key.
[0092] Successful login to Yahoo!'s homepage, Yahoo! Shopping, Yahoo! Mail, search results, SNS, Ameba Blog, YouTube (registered trademark), etc. = Green. If you go to a personal website from there, access it without logging into Yahoo!, or are not logged into YouTube = Yellow. If you are logged into your account but the private key cannot be verified = Flashing red & logout, screen goes black & image biometric authentication GPS device information is collected for arrest purposes and sent to the owner. The screen will display a message indicating a high possibility of it being a fraudulent site.
[0093] The ability to alert users with sounds or flashy visuals depends on the functionality of apps and browsers. Therefore, it is possible to develop a system that can detect fraudulent websites with a high degree of accuracy without relying on internet security apps. The continuous owner authentication system will lead to a solution. Protection against fraudulent use of credit cards, banks, cashless payments, other financial services, and cryptocurrencies online.
[0094] Credit card fraud has become a social problem. However, thankfully, credit cards, banks, cashless payment systems, and cryptocurrencies can all be prevented from fraudulently using the private keys of the owner authentication system. Payment processing services and online marketplaces that are integrated with the owner authentication system should be ready to automatically exchange personal identification numbers and private keys.
[0095] To use an online shopping example, one layer of authentication is performed by the device owner, plus a second private key is used when logging into the online shopping site, a second private key is used on the payment processing screen, and a third private key is used for VISA, Mastercard, JCB, banks, and cashless payments.
[0096] At least globally, if we consider this as a standard practice, using a private key to perform sequential authentication of the cardholder when making online payments with VISA, Mastercard, JCB, etc., fraudulent payments can be prevented. A sequential authentication system for the cardholder will lead to a solution.
[0097] Measures to prevent fraudulent use of card payments and cashless payments at stores. While there are no annual losses from fraudulent withdrawals of savings by third parties other than family members using bank seals, credit cards incur losses of 25 billion yen per year, and bank cards incur losses of over 30 billion yen. The reason is simple: continuous owner authentication is not performed.
[0098] If we move away from the traditional credit card model and completely integrate credit cards into apps like cashless payments, or if we register cards with cashless payment systems and use a continuous owner authentication system, the amount of damage to both credit cards and banks can be reduced to zero. The same applies to cryptocurrencies, because they use accounts. If we maintain a continuous authentication state using facial recognition or fingerprint authentication—essentially making it impossible to make payments without continuous owner authentication—it will become impossible to send or receive money through unauthorized logins. A continuous owner authentication system will lead to this solution.
[0099] A crucial point is how to resolve fraudulent payments. For example, by changing your address on the My Number Portal, at the post office, or on online shopping sites, criminals can receive and forward goods and mail. As mentioned earlier, current login methods can be bypassed even on the My Number Portal, even if it's registered with eKYC authentication.
[0100] This is because eKYC authentication (a method of verifying that the person is the same person by taking a photo of their My Number Card with a camera) is an authentication method used during the migration process when adding My Number Card functionality to a smartphone. Therefore, from next time onward, the user can log in to the My Number Portal using the same method as the owner, without any trouble, by using biometric authentication secretly registered when the user changes models or when they are taught how to use the device, or by remembering the owner's finger movements and logging in while the owner is taking a bath and registering a single fingerprint.
[0101] However, if My Number Portal or the post office has implemented a continuous owner authentication system, you won't get that far. In reality, the device's continuous owner authentication system will activate, causing the screen to go dark much faster, the moment you glance at it. The continuous owner authentication system will solve the problem.
[0102] Solutions to prevent fraudulent logins by impersonation. The screen will go dark if any biometric authentication is interrupted. The camera and sensors will continuously track the owner and monitor for substitution by a third party. In parallel with tracking, facial recognition and iris recognition will be used to monitor for substitution by an impersonator. Fingerprint recognition and vein recognition will also be used in conjunction with these to monitor for substitution by an impersonator. For PCs, it would be even better if fingerprint or vein recognition were available on the mouse and keyboard. For smartphones and tablets, it would be even better if fingerprint or vein recognition were available on the screen or back. For smartwatches, it would be even better if biometric authentication such as vein recognition could be obtained from the wrist. It would be even better if the device could sense electrical signals from the body and monitor for substitution by an impersonator. All of the above will be switched flexibly and continuously for authentication without interruption.
[0103] Multi-factor authentication and multi-step authentication, including various biometric authentication methods and password / PIN / pattern input, are continuously performed on the device side, either continuously, periodically, in conjunction with user operation, or as needed. Furthermore, knowledge-based authentication such as passwords, QR code authentication, tokens, and one-time passwords are used in conjunction as necessary to further enhance security.
[0104] The above operations, along with the automatic tracking function for the owner, will continue virtually without interruption, switching between functions as needed. If these cannot be confirmed, it will be considered an unauthorized login, and operation will be disabled. Iris recognition will dim the screen even if the owner is dozing off or has their eyes half-closed. If the owner goes out of the camera's reach or to a place they cannot reach, the screen will immediately dim to prevent peeping. When returning to operation, some form of biometric authentication will be performed. The continuous owner authentication system will resolve the issue.
[0105] Continuous owner authentication security feature. If the system detects a third party peeking at the screen within viewing range, it will either display a warning that someone is watching or dim the screen as a safety measure. If it detects impersonation, unauthorized login, peeking, or attempted hacking, it will acquire the third party's video, biometric authentication, and other unique information obtained via short-range communication, and notify the owner with a notification or alarm.
[0106] If a third party engages in any malicious activity that the owner deems insulting, such as unauthorized login, snooping, theft, or vandalism, the owner can use the third party's information obtained as evidence to file a police report. The continuous owner authentication system will help resolve the issue.
[0107] Turn continuous owner authentication on or off. These safety features can be turned on or off, or their level adjusted, for each function, depending on the scene, by setting the time, app, etc., solely at the owner's discretion and responsibility. This allows you to learn how to operate it, collaborate, enjoy movies and games on a large TV connected to the device, and continue to enjoy stationary shooting as before.
[0108] If the owner suddenly falls ill, collapses, or passes away, it would be problematic if they could not log in to the device. A very limited number of authorized individuals, such as government agencies or carriers, can log in and disable the owner authentication system. In such cases, the login information for the device and account should, if possible, be stored on the device, including the logger's personal identification information, biometric authentication, and operation history. (For legal proceedings such as inheritance) the owner authentication system will facilitate resolution.
[0109] Solving the problems of online classes, lectures, and exams. In the future, digital transformation will lead to online learning in school education, including license renewals, classroom instruction, and exams. However, there are concerns that online learning may lead to individuals engaging in activities contrary to its original purpose, such as having third parties take classes or exams.
[0110] Implementing a continuous owner authentication system for online classes and exams completely prevents impersonation, allowing third parties to take classes or exams. Only the registered user will be able to earn credits for the classes and courses. The system can also detect drowsiness or distractions such as looking at a smartphone or comic book, effectively ensuring proper attendance. To prevent dozing off, audio and other methods can be used to encourage the user to focus on the screen. Regarding cheating during exams, which is a common problem, measures can be taken using biometric authentication and sensors that can accurately monitor eye and hand movements. Cheating can also be detected by picking up even slight sound leaks from bone conduction earphones with a microphone.
[0111] When it is necessary to more effectively detect sound leakage via bone conduction, one method is to attach a bone conduction biomicrophone to pick up sounds emitted from the body, connect it to the test terminal via wired or short-range wireless communication, and continuously monitor whether any cheating sounds are being played. Therefore, if a continuous owner authentication system is introduced, online classes and exams can maintain the same level of quality as existing classroom-based instruction and examinations.
[0112] Previously, identity verification via telephone relied on simply checking the phone number and assuming the person was legitimate if they provided personal information, which was a flawed and unreliable method. The solution involves simply making a video call or hands-free call with the owner's device, which then triggers a continuous owner authentication system that guarantees reliable identity verification, improving both security and productivity. Furthermore, by rejecting incoming calls from phones that are not logged into the owner authentication system, it can automatically block calls from scammers and spam. By requiring the owner's personal information and biometric authentication to be registered before a call can be made, criminals can be prevented from making calls in the first place. This includes calling functions for mobile phones, landlines, and apps. This system can be used for anything requiring owner authentication, not just devices and accounts. For example, car drivers, government agencies, financial services, ATMs, and more. Companies invest enormous sums of money in security year after year, yet security remains insufficient, and logins only become more complex. It's an incredibly unproductive situation. The owner authentication system offers a solution.
[0113] The twin birth rate is 2% in Japan and 3.4% in the United States. During checkpoints and other situations where driver's licenses were checked, identity verification was often based on the assumption that the person was the same as the photo and could provide personal information. This led to concerns about impersonation by those with suspended licenses or driving without licenses. While biometric authentication and electronic driver's license verification are expected to become the norm, logging into the My Number Portal from a device with the continuous owner authentication system turned OFF would not work for twins, posing security and authentication problems. As a solution, logging into the My Number Portal from a device with the continuous owner authentication system ON and verifying the driver's license displayed on the device would ensure reliable identity and owner authentication, even for twins. This would contribute to the accuracy and productivity of police investigations. By implementing this owner authentication system, the login process will be simplified, making it impossible to commit fraudulent logins and identity theft, which have been a problem for many years, and ensuring true user authentication.
[0114] (Lost and Found Recovery System) In addition to My Number accounts, personal identification numbers, and electronic certificates, unique numbers issued by account services such as Google® accounts, Apple® IDs, docomo®, au®, Yahoo!®, SoftBank®, and Rakuten Mobile®, or the accounts themselves, are used as personal identification numbers. Devices or IC chips that store these personal identification numbers are referred to as lost property recovery items.
[0115] Typical examples of these devices include PC tablets, smartphones, and smartwatches, but also music players and game consoles. These devices can have screens, GPS, internet connectivity, biometric authentication, camera functions, and near-field communication. The above devices, as well as IC stickers, IC chips, and IC tags, can communicate using NFC, Bluetooth (registered trademark), Bluetooth Low Energy (BLE: registered trademark), Felica (registered trademark), and Wi-Fi (registered trademark). Furthermore, it will be possible to log in to the above accounts, such as My Number, from terminals at convenience stores, etc.
[0116] By logging into the My Number Portal, selecting "Create a spare electronic certificate for My Number Card," and holding the IC chip or mobile device 22 over the reader 33 on the fixed terminal 23, you can write your My Number personal identification number, electronic certificate, and unique information.
[0117] It can contain data such as driver's license and insurance card information. You can log in with your Google or Apple account and create an IC chip for lost item recovery. IC chips can be attached to wallets, umbrellas, or any other item you don't want to lose. They can also be given to elderly people who tend to wander, pets such as dogs, cats, and birds, or children who are prone to getting lost.
[0118] If the owner realizes they have lost their My Number Card or Minus Maho, they can log in to the My Number Portal, Google, Apple, or other websites and file a lost item report. If the owner has an item with a personal identification number, such as a My Number Card or Minus Maho, they can have it scanned at a reader on a terminal at a convenience store or mobile carrier, log in using biometric authentication or a password, and file a lost item report.
[0119] You can file a lost item report at a terminal in a convenience store or similar location by entering your Google or Apple account name, logging in with biometric authentication or a password, and submitting the report. Alternatively, you can have a third party, such as a friend or family member, launch the My Number Portal on their smartphone, and then access it using the My Number Card, device, or IC chip that the owner had with them and which can handle their personal identification number. By logging in with biometric authentication or a password, you can also file a lost item report from there.
[0120] Lost devices can also be reported from a home device that hasn't been lost, or from other mobile devices. Once a lost device report is filed, the server locks the lost item. When the founder picks up the lost device and operates it, the device is locked, personal information including the finder's fingerprint, facial recognition, and iris recognition is obtained to identify the finder, their current location is determined, and identification data of the finder's mobile device is obtained. Information is also collected through short-range communication between the lost device and the finder's device.
[0121] The lost mobile device's screen, the finder's mobile device's screen, or the screens of convenience stores or carriers' terminals should display information that the device cannot be turned off and that it should be taken to a convenience store or carrier.
[0122] The lost item, instructions on how to return the mobile device, and the amount of the reward for returning it will be displayed on the screen of the lost mobile device, the screen of the finder's mobile device, or on a terminal at a convenience store or carrier. The finder will scan the found item at the convenience store where they reported it, enter how they want to receive the reward, take the issued receipt to the cashier, and hand over the found item to complete the process.
[0123] If the found item belongs to an elderly person prone to wandering, a pet such as a dog, cat, or bird, or a child who is prone to getting lost, the convenience store will report the item as found, report the child as lost to the police, and arrange for someone to pick them up. Once the lost item is left at the convenience store, the owner will be contacted by email or phone. Sometimes the police will also contact the owner.
[0124] If it's nearby, you can pick it up directly; if it's far away, you can have it sent by mail with payment on delivery, and pay the reward via cash on delivery. If you pick it up or receive it directly, you can pay the reward at a convenience store. There should be various ways for the finder to receive the reward, including bank transfer, cashless payment, and mobile carrier points.
[0125] When receiving the reward money at a convenience store counter, you will need to scan your My Number Card or similar card at the convenience store or mobile carrier's reader if necessary, and authenticate using biometric authentication or verify your identity with identification such as a driver's license. The reward money can be paid via carrier billing or by credit card. Once the reward money has been successfully paid and the lost device has been returned to its owner, the entire lost and found recovery system will be completed when the owner logs in using their usual login method.
[0126] My Number Card / Minus Smartphone Spare Function in Case of Loss. Recovery from Loss of Electronic Certificates, Health Insurance Cards, Driver's Licenses, and Cashless Payments. To create a spare, log in to the Identification Number Portal, select "Create Spare," and hold the device or IC chip you want to use as a spare over the device's reader to write the information. If the My Number Card's personal identification number and electronic certificate are stored on the IC chip or device, the spare will also function as an electronic certificate, driver's license, and health insurance card, in addition to the functions of the My Number Card. It can also be used as a spare for cashless payments that support NFC payments or QR code payments on smartwatches.
[0127] As a temporary public telephone function, it allows you to make calls from compatible public telephones or terminals at convenience stores. It also has a simple phonebook function. In addition to your My Number Card, the lost and found item can store multiple account IDs, electronic certificates, and personal identification numbers from Google, Apple, car manufacturers, mobile carriers, etc. In an emergency, you can hold the lost and found item over a terminal at a convenience store, log in to your Google or Apple account, and send a help request email to a friend.
[0128] (Rescue through the spare key function in case of key loss) The spare key function provides relief in case of key loss. If personal identification numbers such as My Number or driver's license information, as well as accounts, unique identification information, and key information for Android Auto, Apple CarKey, and various automotive manufacturers are stored on the IC chip or device, it can also be used as a spare key for your car.
[0129] To create a spare key, log in to the portal, select "Create Spare," and hold the device or IC chip you want to use as a spare over the device's reader to write the information. When used as a spare key for a car, the mobile device or the vehicle's reader control unit verifies the owner, driver's license, and key information, and verifies the biometric authentication of the owner driving the car. If this type of car key is implemented (configured) when the owner purchases the vehicle or during vehicle inspection, etc., it will reduce unlicensed driving, driving during license suspension, and driving of stolen vehicles on the roads within three years of the system's implementation.
[0130] If the owner leaves the car with the spare key inside, the system will sound the horn or trigger an alarm on a mobile device app to alert the owner that the key has been left inside.
[0131] Furthermore, if the driver is involved in an accident or becomes ill while in the vehicle, data such as insurance information can be used to assist with medical care. Alternatively, if the vehicle control unit detects a traffic accident, if the control unit has a communication function, it can identify the accident scene and the driver, or, if not, through a mobile device. In addition, by linking with the onboard camera, it can automatically and quickly identify the perpetrator of hit-and-run accidents. Vehicles are equipped with many sensors and cameras. These can be used as security cameras. Accident information can be sent to the police or to registered family members.
[0132] If you lose your car keys or house keys, which were created using your Google, Apple, or automotive manufacturer account IDs and personal identification numbers, you can file a lost property report with the account server. You can file a lost property report from any device, including convenience stores. In this case, you can also log in using your account ID and password, in addition to your personal identification number (such as My Number), to file the report.
[0133] There is also a function to distribute spare keys to third parties. This can be done by selecting "distribute spare keys only" from the portal and writing the key to the IC chip or the device using the device's reader. You can also set a time limit and cancel the distribution. The same basic principle applies to spare keys for houses. When using a mobile device such as a smartphone or smartwatch as a spare key for a car, if the device and the vehicle's control system can communicate via short-range wireless communication, specific low-power wireless communication, or the internet, the device's app can be used to turn the engine on and off, unlock the doors, adjust the air conditioning temperature, and adjust the car audio volume. To prevent malfunctions, biometric authentication is required for operation.
[0134] Rescue in case of car theft: (1) The vehicle control unit will be equipped with GPS, internet, and short-range wireless communication capabilities. (1) alone will function, but considering the possibility of the power being cut off, there is a hidden function: (2) another device with similar functionality is installed. Alternatively, when (1) or the vehicle's power is cut off, even if all screens such as the navigation system turn off, it will actually switch to emergency mode and emergency power, so even though it will appear to the thieves that (1) or the vehicle's power is completely off, it is actually operating normally.
[0135] (1) and (2) utilize various sensors and cameras already installed on the vehicle as security cameras, in addition to dedicated sensors and cameras. This is true even when the vehicle is completely stopped and the owner is not present. The devices in (1) and (2) notify the owner and the police of any vehicle abnormalities via network communication. The vehicle is equipped with many sensors and cameras. These are used as security cameras, and if an abnormality is detected in the vehicle, the horn will also sound. However, it is anticipated that a criminal might unplug the horn's power or remove the fuse. Even if the power is unplugged, the system will operate in emergency mode using emergency power.
[0136] Then, recording begins from the camera that detects the anomaly. If the vehicle is equipped with a 360-degree camera, it will record all around. The interior of the vehicle is also recorded. Audio is also included, so the suspect's conversations can be heard clearly. Hidden cameras also exist. Not only is the footage recorded, but it is also live-streamed to the police and the owner. Devices (1) and (2) record the entire sequence of events of the suspect's crime and escape, and also acquire GPS information and biometric authentication. Furthermore, unique information is obtained from the suspect's mobile phone and transmitted to the police.
[0137] Even if the owner is asleep and unaware of the theft, the police receive the information and track the vehicle using live video and transmitted data. By the time the owner wakes up, the vehicle has been apprehended and returned. As an ultimate feature, the system allows for remote control of the stolen vehicle, including setting a maximum speed, preventing reverse movement, locking and controlling the steering wheel, applying the brakes, faking a fuel shortage or battery failure to safely stop the car, and preventing doors and windows from being opened. It is a vehicle hijacking function by the police. It makes it possible to return the vehicle undamaged, apprehend the perpetrator, and locate the yard where the vehicle was stolen from.
[0138] Let's say someone steals aluminum wheels, bags, and other items from cars and sells them on flea market apps or to second-hand shops. In most cases, this system, which uses vehicle sensors for security, would detect the intrusion and immediately sound the horn, causing the thief to stop and flee. However, if the items are stolen, the system would compare the video footage of the crime with biometric authentication, device-specific information obtained from the device, and data from the flea market app and second-hand shop to make an arrest.
[0139] This embodiment discloses a continuous owner authentication method, a continuous owner authentication system, a lost property recovery method, and a lost property recovery system. In the continuous owner authentication method, the continuous owner authentication system, the lost property recovery method, and the lost property recovery system, the owner's possessions (lost items, lost items) may be any of the following: seals and their spares, My Number cards, driver's licenses, health insurance cards, identification cards, car keys and their spares, house keys and their spares, IC chip-equipped products, smartwatches, game consoles, players, etc. A spare is a replica of the original and has the same structure and function as the original. These spares are shown as spare 11A in Figure 1.
[0140] The owner logs into the My Number Portal, selects "Create a spare My Number Card (including health insurance card and driver's license)" on the portal site, and touches a seal, smartwatch, or blank IC card containing the My Number to the NFC reader / writer on the back of the mobile terminal 22. This allows the My Number, name, address, gender, date of birth, image, and other unique information to be written to the IC chip or the terminal's secure storage area using near-field communication such as NFC, Bluetooth, or Wi-Fi. For example, this can be done through the "IoT ID Platform," a next-generation security service that enables the issuance and centralized management of electronic certificates, or "G-Shield," which allows certificates to be written directly to the IC chip. This completes the creation of the spare 11A. Furthermore, while possessions other than seals do not have a seal surface, they each have a storage unit, control unit, communication unit, etc., and are assigned a readable, recognizable, or detectable identification number.
[0141] Furthermore, the fact that a seal has been affixed (stamped) is detected when the seal surface 16 is scanned by the terminal's camera, or the impression 30 stamped on the document 29 is scanned, and the unique information of the seal storage unit 18 is read by the reader 33 as a recognition sensor of the fixed terminal 23 or the recognition sensor 26 of the mobile terminal 22, and the user responds to the question "Is this OK?" with "Confirm, stamp." In addition, the history of the seal affixing may be saved via email or other means to the My Number Portal, the seal registration server, the servers of companies related to the affixing, and to companies and parties involved in the affixing and contract, so that after the seal is affixed, the administrative parties as well as companies and parties involved in the contract and affixing can view it from their respective terminals via the internet. It is possible to save information such as the person who affixed the seal, the date and time of affixing, the counterparty to the contract on which the seal was affixed, the contents of the contract, and the location information of the seal owner as PDFs or images on the My Number Portal, the seal registration server, and the servers of companies involved in the affixing of seals, depending on the need (for example, for submission to administrative bodies such as courts, or for later verification). It is also possible to send copies of the contract via email to the companies and parties involved in the affixing of seals. Furthermore, it is possible to issue copies of the document to the companies and parties involved in the affixing of seals as email attachments or downloads, depending on the need (for example, for submission to administrative bodies such as courts, or for later verification).
[0142] Furthermore, this embodiment can also be used for public and private contract content certification servers, or for blockchain-based seals and contract content certification. The public and private contract content certification server has a configuration and functions for securely managing and utilizing contract content, and can be used by government agencies and private organizations as needed (for example, for submission to administrative bodies such as courts, or for later verification). Blockchain-based seals and contract content certification can be used by government agencies and private organizations as needed (for example, for submission to administrative bodies such as courts, or for later verification).
[0143] In addition to personal identification numbers such as My Number and driver's license numbers, if general accounts or smart keys from Android Auto®, Apple CarKey®, and various automotive manufacturers are stored on the IC chip or terminal, they can also be used as spare keys for vehicles under those systems. When used as a spare key for a vehicle, the mobile terminal or the vehicle's reader control unit will verify the driver's license information if possible, and the driver's identity will be verified through biometric authentication. If a vehicle key or house door key created from a Google®, Apple®, or automotive manufacturer's account ID or personal identification number is lost, a lost property report can be submitted to the account server. Lost property reports can be submitted from any terminal, including convenience stores. In that case, in addition to personal identification numbers such as My Number, it is also possible to log in with an account ID and password to submit a lost property report.
[0144] The same principles apply to spare keys for houses. When using a mobile device such as a smartphone or smartwatch as a spare key for a vehicle, if the device and the vehicle's control system can communicate via short-range wireless communication, low-power wireless communication, or internet communication, the device's app can be used to turn the engine on and off, unlock the doors, adjust the air conditioning temperature, and adjust the car audio volume. To prevent malfunctions, biometric authentication is required for operation.
[0145] This embodiment also discloses the following: Step 1: A server that has pre-registered the seal impression is in an active state capable of authenticating information entered from an external source. If the server is in the enabled state, the second step is to determine whether the actual seal impression included in the information matches the registered seal surface portion. When the server is in the enabled state and the server determines that the actual seal impression matches the registered seal surface, The third step involves the server reading unique information stored in the memory section of the seal, A method for continuous owner authentication that includes the following:
[0146] In the above owner authentication method, The server provides an identification number portal that allows the use of an identification number assigned to each owner of the seal. The active state of the server includes the state in which the owner is logged into the identification number portal using a terminal.
[0147] In the above method of continuous ownership certification, The terminal is capable of logging into the identification number portal using at least one of the following: the seal, the identification number card corresponding to the identification number, biometric authentication, or a password.
[0148] In the above owner successive authentication method, A method for continuous owner authentication in which, if the owner loses the seal, the identification number card, or the terminal, the owner can log in to the server using an auxiliary terminal separate from the terminal and submit a lost property report indicating that the seal, the identification number card, or the terminal has been lost.
[0149] In the above owner successive authentication method, A first notification step in which the owner notifies a third party that the item has become unusable if the owner has lost any of the items, such as the seal, the identification number card, or the terminal. A second notification step involves notifying the third party who found any of the aforementioned possessions that information about the third party has been obtained, A method for authenticating the owner, comprising:
[0150] In the above owner successive authentication method, A successive owner authentication method comprising a third notification step of notifying the third party of at least one of the following: a method for returning the property found by the third party to the owner, a reward amount for the return, and that the power of the terminal cannot be turned off.
[0151] In the above owner successive authentication method, The terminal is capable of sending and receiving information, and the vehicle is equipped with in-vehicle equipment. A continuous owner authentication method in which, when the server is in the enabled state, information can be sent and received between the terminal and the in-vehicle device.
[0152] Step 1: A server that has pre-registered the seal impression is in an active state capable of authenticating information entered from an external source. If the server is in the enabled state, the second step is for the server to determine whether the actual seal impression included in the information matches the registered seal surface portion. A third step in which, when the server is in the enabled state and the server determines that the actual seal impression matches the registered seal surface, the server reads the unique information stored in the memory unit provided in the seal. It has, The server provides an identification number portal that allows the use of an identification number assigned to each owner of the seal. The valid state of the server includes the state in which the owner is logged into the identification number portal using a terminal. A method for recovering lost property, wherein if the owner loses the seal, the identification number card, or the terminal, the owner can log in to the server using an auxiliary terminal separate from the terminal and file a lost property report indicating that the seal, the identification number card, or the terminal has been lost.
[0153] In this embodiment, possessions include a first article and a second article. The first article is an article that can be used (available) by the owner in at least one of the following cases at a public institution or service provider: when receiving services, proving identity, or disclosing personal information. Examples of the first article include a seal (official seal), My Number card, driver's license, passport, health insurance card, cash card, employee ID card, public transport card, mobile terminal, etc. Public transport cards include magnetic cards, stored-value cards, contactless IC cards, digital tickets, etc. The second type of item is for personal use only and is not to be used by public institutions or service providers when the owner receives services from them. The second type of item includes, for example, CD players, vehicle door lock keys, vehicle starter keys, house or apartment door lock keys, warehouse lock keys, etc. 2. If the owner misplaces their belongings, loses track of them, or drops them, the belongings are considered lost. In some cases, belongings may be stolen or found by someone other than the owner.
[0154] Based on the above content filed on February 1, 2021, the following describes the examples.
[0155] Referring to Figure 7, the lost item recovery system 10A of the present invention will be described. The lost item recovery system 10A of the present invention is particularly suitable for use when a mobile phone is lost. When a mobile phone is lost, it is common practice to lock the device using a password or fingerprint authentication to prevent it from being used by a third party. By using the lock function, it becomes more difficult for a third party to use the device, so the finder does not need to keep the unusable device, and it may be returned to the owner by reporting it to the police or other authorities. However, found mobile devices are sometimes disassembled and sold for parts, and may not be returned to their owners. Therefore, the present invention provides a lost property recovery system that makes it easier for a person who finds a lost mobile phone to hand it over to its owner. This invention is a lost property recovery system that makes it less likely for the founder to sell the item as parts and more likely to be returned by paying them a reward (gratitude payment). Furthermore, the present invention can improve the performance of the mobile device's locking function, making it more difficult for a third party to unlock it by constantly performing biometric authentication, thereby reducing the need for the finder to continue to possess the found mobile device.
[0156] The lost property recovery system 10A of the present invention comprises a mobile terminal 220A, a management server 15A, another terminal 23A different from the mobile terminal 220A, and an intermediary terminal 48A managed by an intermediary business 47A.
[0157] (Mobile terminal 220A) As shown in Figure 8, the mobile terminal 220A has the functions of the mobile terminal 22 of terminal 13 and can communicate with the management server 15A via an internet connection. In addition, the mobile terminal 220A is equipped with a biometric information acquisition unit 29A. Although not shown in the figure, it is also equipped with a display unit (screen) and a battery (power supply).
[0158] <Biometric Information Acquisition Unit 29A> The biometric information acquisition unit 29A includes a camera 25 and has a function to acquire fingerprint information when a person touches the touch panel of the operation unit 24. In other words, the biometric information acquisition unit 29A acquires information for biometric authentication, and biometric authentication includes at least one of the following: fingerprint authentication, vein authentication, facial authentication, iris authentication, etc. When the mobile device 220A is in the owner's possession (before it is lost), a lock function using a password and / or the user's biometric authentication is activated. If the lock function is not released, the operation of the mobile device 220A is restricted, and it cannot be used by a third party.
[0159] <Application Software 29B> Furthermore, the terminal storage unit 27 of the mobile terminal 220A is equipped with application software 29B. The application software 29B is a control program that disables the mobile terminal 220A when it receives loss information 38A1 from the management server 15A, and the control unit 28 performs the control to disable the mobile terminal. Furthermore, if the mobile terminal 220A becomes inoperable, the application software 29B executes a lost status notification means to inform the finder that the mobile terminal 220A is lost.
[0160] Furthermore, the mobile terminal 220A in this specification has two states: an inoperable state and a locked state. The "locked" state refers to the lock function that is active when the mobile device 220A is not lost, and examples include fingerprint authentication and passwords. An inoperable state is a fraud prevention function that is executed when the mobile terminal 220A is lost and there is a high risk of it being used by a third party, and it is a protective state that is the same as or stronger than the locked state. A protective state stronger than the locked state is, for example, a state in which the mobile phone 220A does not accept any operations other than the state in which the terminal identification information 220B described later can be read and the message information 38A2 described later is displayed on the screen or given voice guidance, and the mobile terminal 220A becomes operable when it receives a command from the management server 15A to release the inoperable state, or a state in which multiple types of lock functions equipped on the mobile terminal 220A are applied, and an example is a state in which it is protected by both fingerprint authentication and password lock functions.
[0161] Examples of means for notifying the device of a lost state include displaying message information 38A2 indicating that the device is lost on the screen or emitting the message information 38A2 by voice. The message information 38A2 may be stored in advance in the terminal memory unit 27 of the mobile terminal 220A, or it may be sent together with the lost information 38A1 sent from the server 15A and received by the mobile terminal 22. Message information 38A2 includes information on what the finder should do next, such as where to report the found item and the procedure for returning it. Message information 38A2 may also include information containing instructions for employee 47B. Furthermore, the application software 29B may include a registration form that guides the owner of the mobile terminal 220A to create a user account on the management server 15A.
[0162] <Terminal Identification Information Storage Unit 29C> The mobile terminal 220A is equipped with a terminal identification information storage unit 29C, which performs the same role as the seal storage unit 18. In this embodiment, a specific example is the inclusion of an IC tag 18A. The IC tag 18A may be attached to or embedded in the outer surface of the mobile terminal 220A. The IC tag 18A comprises an antenna unit 18A1, a power generation unit 18A2, a storage unit 18A3, and a control unit 18A4. The antenna unit 18A1 transmits and receives radio waves to and from the reading device 48A1 of the intermediary terminal 48A, which will be described later, and exchanges information. The power generation unit 18A2 generates power using the induced electromotive force generated when the antenna unit 18A1 receives radio waves from the reader device 48A1. The power generation unit 18A2 is not required if the storage unit 18A3 and control unit 18A4 are operated using the power of the battery in the mobile terminal 220A. However, it is preferable to include the power generation unit 18A2 so that information can be sent and received even when the battery of the mobile terminal 220A is depleted and the mobile phone 22A cannot be started.
[0163] The memory unit 18A3 stores terminal identification information 220B. Terminal identification information 220B includes not only the unique identification number of the mobile terminal 220A assigned to identify it, but also unique information about the mobile terminal 220A, such as the name, address, date of birth, and gender of the owner of the mobile terminal 220A. Furthermore, it can also store an identification number assigned to each owner, a telephone number, and a photograph. Furthermore, examples of identification numbers include numbers assigned by public or private institutions. Examples of identification numbers assigned by public institutions to individuals include the My Number (registered trademark), which is common in the fields of social security such as driver's licenses, insurance, welfare, and labor insurance, as well as in the national and local tax fields. These are examples of numbers that can identify and verify an individual. It should be noted that identification numbers may include not only Arabic numerals, but also English letters, symbols, Greek letters, etc. Furthermore, the memory unit 18A3 may be shared with the terminal memory unit 27 of the mobile terminal 220A, or it may be provided separately.
[0164] The control unit 18A4 reads the terminal identification information 220B stored in the memory unit 18A3 and transmits it from the antenna unit 18A1 to the reading device 48A1. The control unit 18A4 may be shared with the control unit 28 of the mobile terminal 220A, or it may be provided separately.
[0165] [Management Server 15A] As shown in Figure 7, the management server 15A has the same functions as the seal authentication server 15, and is equipped with a receiving unit 38A and a transmitting unit 38B, as well as a lost information management unit 38A, a biometric authentication management unit 38B, a notification confirmation unit 38C, a payment processing unit 38D, and a return determination unit 38E. The receiving unit 15A1 and the transmitting unit 15A2 receive and transmit information with and from payment institutions (not shown) processed by the mobile terminal 220A, the intermediary terminal 48A, and the payment processing unit 38D. The control unit 38 also controls the lost information management unit 38A, the biometric authentication management unit 38B, the report confirmation unit 38C, the payment processing unit 38D, and the return decision unit 38E. Furthermore, terminal identification information 220C is stored in the server storage unit 37 of the management server 15A. The management server 15A may be a server managed by a private organization or a server managed by a government or public institution. An example of a private organization would be a company that provides and manages application software 29B. An example of a server managed by a government or public institution would be the My Number Portal Site, which manages My Number information. Furthermore, the management server 15A also includes cases where multiple servers are operated in cooperation with each other, including cases where servers managed by private organizations and servers managed by government or public organizations cooperate to form a single management server 15A.
[0166] <Lost and Found Information Management Department 38A> When the owner of a mobile terminal 220A loses the mobile terminal 220A, the Lost Information Management Unit 38A receives instruction information from another terminal 23A, and the Lost Information 38A1 is transmitted from the transmission unit 15A1 of the management server 15A to the mobile terminal 220A. The lost item information management unit 38A may also include message information 38A2 in addition to lost item information 38A1. The message information 38A2 may be sent to the mobile terminal 220A together with the loss information 38A1, or it may be sent to the mobile terminal 220A before the loss information 38A1 is sent and stored in the mobile memory unit 27 of the mobile terminal 220A. Furthermore, message information 38A2 may include information about a lost property report filed with the police. In this case, when the loss information 38A1 is sent to the mobile terminal 220A, the information about the lost property report to the police is sent to a server managed by the police, and the lost property application is completed. Furthermore, information regarding lost property reports to police agencies may be managed separately from message information 38A2 and sent separately from the loss information 38A1. This has the effect of allowing reports to be made to police agencies earlier, before the loss information 38A1 is sent.
[0167] Message information 38A2 is information used by the application software 29B's lost status notification means. A specific example of message information 38A2 is to instruct the finder 49, who has found the lost mobile terminal 220A, to report it to the intermediary business 47A. It may also indicate that the mobile terminal 22 has been locked so that the finder 49 cannot use it. Furthermore, it may indicate that the mobile terminal 22 has been locked so that it cannot be used, that personal information including the finder 49's fingerprint, facial recognition, and iris recognition has been obtained, that the current location information of the mobile terminal 220A found by the finder 49 and the current location information of the mobile terminal 22B owned by the finder 49 have been identified, and that the power of the mobile terminal 220A cannot be turned off.
[0168] Furthermore, the personal information of the finder 49, including the finder's fingerprints, facial recognition, and iris recognition, the current location information of the mobile terminal 220A found by the finder 49, and the current location information of the mobile terminal 22B owned by the finder 49 may be stored in the terminal storage unit 27 of the mobile terminal 220A, or transmitted from the mobile terminal 220A to the management server 15A and stored in the server storage unit 37.
[0169] Furthermore, the payment processing unit 38D, as described later, may control the control unit 28 of the mobile terminal 220A and the control unit 38 of the management server 15A so that when payment is completed, the personal information of the finder 49, the current location information of the mobile terminal 220A found by the finder 49, and the current location information of the mobile terminal 22B owned by the finder 49 are deleted.
[0170] Furthermore, the message information 38A2 also includes information on procedures such as taking the found mobile terminal 220A to an intermediary business 47A, including a convenience store 47, and having the intermediary business terminal 48A read the terminal identification information 220B recorded in the terminal identification information storage unit 29C of the mobile terminal 220A. This information is then communicated to the finder by the lost status notification means of the mobile terminal 220A. Furthermore, this information may be displayed on the screen of the intermediary terminal 48A managed by the intermediary business operator 47A, including convenience stores 47, or announced via voice. Furthermore, the message information 38A2 may also include information about the reward for handing over the lost mobile device 22 to the intermediary 47, and confirmation, either on the screen or via voice, that a lost property report has been filed with the police.
[0171] <Biometric Authentication Management Department 38B> The biometric authentication management unit 38B compares the biometric information received by the management server 15A with the biometric information pre-recorded in the server storage unit 37 to perform biometric authentication. It determines whether the received biometric information matches the pre-recorded biometric information and controls the management server 15A or transmits the information to the mobile terminal 220A or the intermediary business operator 47A based on the result.
[0172] <Notification Confirmation Section 38C> After receiving the terminal identification information 220B read by the reader 48A1, the notification confirmation unit 38C transmits a deposit confirmation information 38C1 to the intermediary business terminal 48A, confirming that it has received the terminal identification information 220B and that an employee 47B of the intermediary business 47A has received the mobile terminal 220A from the finder 49. Employee 47B responds to the custody confirmation information 38C1, causing the intermediary terminal 48A to send receipt information indicating that the mobile terminal 220A has been received to the management server 15A.
[0173] Furthermore, when a response operation for the custody confirmation information 38C1 is performed, the notification confirmation unit 38C notifies the owner's contact information of the mobile terminal 220A that a lost item has been reported and the location (location where it was reported) of the intermediary business 47A to which it was reported, or notifies the owner by displaying it on the screen of the other terminal 23A when the other terminal 23A logs in to the management server 15A. In addition, examples of contact methods for the owner include contacting another device 23A, sending an email to a specific email address, or making a phone call to a specific phone number.
[0174] Furthermore, the deposit confirmation information 38C1 may also include information regarding reward payment, allowing the finder to select the type of reward and method of receipt, or to enter the finder's bank account information to which the reward will be paid. The information regarding reward payment may be transmitted to the management server 15A, and the reward settlement processing unit 38D, described later, may perform the settlement based on that information.
[0175] <Reward Settlement Processing Unit 38D> After the notification confirmation unit 38C receives the receipt information, the reward settlement processing unit 38D settles the reward (gratuity) set by the owner with the intermediary business operator 47A. After the payment is completed, the payment processing unit 38D sends a payment completion notification to the intermediary terminal 48A indicating that the payment has been completed. The payment completion notification includes information on the amount to be paid to the finder 49. The payment of rewards by the reward payment processing unit 38D can be done using any payment method, and is carried out with a payment institution not shown in the diagram. Examples of payment services include credit cards and electronic money. Furthermore, the payment processing unit 38D settles the payment with the intermediary business operator, and in addition to cases where the intermediary business operator 47A, having received the payment, directly hands the payment to the finder 49, the payment processing unit 38D also includes cases where it directly pays the finder 49. For example, this includes cases where the payment processing unit 38D directly transfers the payment to the finder 49's bank account. Specifically, the payment may also be made according to the payment information described above.
[0176] Furthermore, the payment processing unit 38D may immediately settle the payment of the payment after the notification confirmation unit 38C receives the receipt information, or it may be done after the mobile terminal 220A has been returned to the owner. When the mobile terminal 220A is returned to its owner, the reward settlement processing unit 38D may settle the reward according to the instructions of the owner who has logged into the management server 15A from another terminal 23A or the mobile terminal 220A, or it may be done at the same time as the inoperable state of the mobile terminal 220A is resolved.
[0177] <Return determination unit 38E> The return determination unit 38E performs a process to confirm whether the employee 47B of the intermediary business 47A, who is holding the mobile terminal 220A, is authorized to hand it over to the owner when the owner receives the mobile terminal 220A from the intermediary business 47A. In other words, it performs a process to confirm that the person who comes to pick up the mobile terminal 220A is the owner himself.
[0178] When the return determination unit 38E receives terminal identification information 220B read by the intermediary terminal 48A and personal information entered by the owner, it compares this information with terminal identification information 220C recorded in the management server 15A to determine whether the person is the owner. For example, if the terminal identification information 220B matches the personal information entered by the owner, the system checks whether the matching information exists in the terminal identification information 220C recorded on the management server 15A. If all the information matches, the system determines that the person is indeed the owner. If the terminal identification information 220B does not match the personal information entered by the owner, the system checks whether both pieces of information exist in the terminal identification information 220C recorded on the management server 15A. If both pieces of information exist, the system determines that the user is the owner. Based on the employee's decision, information regarding whether or not the mobile device 220A should be returned is sent to the intermediary terminal 48A. Furthermore, if the handover confirmation unit 38E transmits information indicating whether the mobile terminal 220A can be returned, it may also transmit an instruction to the mobile terminal 220A to release the inoperable state.
[0179] [Other terminal 23A] Other terminals 23A refer to terminals other than the mobile terminal 220A, and are terminals that can communicate with the management server 15A when the mobile terminal 220A is lost. They include a control unit, storage unit, CPU, ROM, input unit, display unit, transceiver unit, etc. (not shown). Examples of other terminals 23A may include a terminal equivalent to the fixed terminal 23, a mobile terminal 22C owned by a collaborator, or an intermediary terminal 48A managed by the intermediary business operator. Furthermore, it is desirable that other terminals 23A are terminals equipped with the function to acquire the owner's biometric information. When logging into the management server 15A, biometric authentication is performed using biometric information acquired by another terminal 23A and biometric information recorded in the management server 15A (biometric authentication management unit 38B). This prevents unauthorized logins and fraudulent operations by anyone other than the biometric information owner.
[0180] [Intermediary Terminal 48A] Intermediary operator terminal 48A is a terminal managed by intermediary operator 47A and is capable of communicating with management server 15A. Intermediary operator terminal 48A also includes a reading device 48A1 that reads terminal identification information 220B from the terminal identification information storage unit 29C of the mobile terminal 220A, and a personal information input device 48A2. Intermediary operator terminal 48A is a terminal operated by employee 47B of intermediary operator 47A, and is an information terminal installed within the store of intermediary operator 47A. Alternatively, it may be an information terminal operated by a customer of intermediary operator 47A. The intermediary operator terminal 48A is operated according to the message information 38A2, causing the intermediary operator terminal 48A to read the terminal identification information 220B of the mobile terminal 220A and to transmit that information to the management server 15A. Furthermore, the intermediary terminal 48A receives a payment completion notification from the management server 15A and displays the notification on its screen or informs the employee 47B and / or the finder via voice.
[0181] When the owner comes to pick up the mobile terminal 220A from the intermediary operator 47, the intermediary operator terminal 48A transmits to the management server 15A the terminal identification information 220B read from the terminal identification information storage unit 29C by the reader device 48A1 and the personal information entered by the personal information input device 48A2, in order to determine whether the person who came to pick up the mobile terminal 220A is the owner. The personal information input device 48A2 is for inputting information that proves the user is the owner. For example, this could be an identification document with an IC chip, specifically, an IC chip that can be read, such as a My Number Card or a driver's license. Alternatively, it could be a device capable of acquiring biometric information, or a keyboard-like device that allows input of information that proves identity, such as a My Number.
[0182] Examples of intermediary businesses (47A) include convenience stores, train stations, government offices, telephone-related companies including mobile phone companies, police stations, post offices, and courier services.
[0183] Referring to Figures 9 and 10, the flow of the lost item retrieval system 10A in this embodiment will be described. First, as S101, in order to create a user account on the management server 15A according to the application software 29B of the mobile terminal 220A, the server storage unit 37 registers the information necessary for account creation and terminal identification information 220C. After creating a user account, the owner's identity will need to be verified using a password and / or biometric authentication when logging into the user account on the management server 15A. Biometric authentication of the owner's identity is performed by the biometric authentication management unit 38B. Furthermore, if the terminal identification information 220C is stored as information from an IC chip such as a My Number Card or driver's license, the system may read the information from those IC chips when a user logs into their account, and use the read information and the IC chip information stored on the management server 15A to verify the user's identity. S101 corresponds to the step of registering terminal identification information with the management server.
[0184] As S102, terminal identification information 220B is stored in the terminal identification information storage unit 29C of the mobile terminal 220A. In this case, the terminal identification information 220B stored in the terminal identification information storage unit 29C may store all of the terminal identification information 220C registered in the server storage unit 37, but at least one type is registered in common. Note that S102 may be performed before S101. Step S102 corresponds to the step of storing terminal identification information in the terminal identification information storage unit of the mobile terminal.
[0185] Next, as S103, when the owner loses the mobile terminal 220A, another terminal 23A logs into the management server 15A and instructs the lost information management unit 38A to send the lost information 38A1. As a result, the lost information 38A1 is registered with the management server 15A. At this time, the message information 38A2 for the finder 49 of the mobile terminal 220A has been created, and the payment method and amount of the reward necessary for processing by the reward settlement processing unit 38D have also been determined. Step S103 corresponds to the step where the owner registers the loss information on the server after losing their mobile device.
[0186] Next, as S104, the transmission unit 38B of the management server 15A transmits the loss information 38A1 to the mobile terminal 220A. At this time, message information 38A2 and information regarding the reward may also be transmitted. In addition, when transmitting the loss information 38A1 to the mobile terminal 220A, a lost property report may be filed with the police. S104 corresponds to the step in which the management server transmits the loss information to the mobile terminal.
[0187] Next, in S105, the mobile terminal 220A receives the loss information 38A1, and the control unit 28 of the mobile terminal 220A disables the mobile terminal 220A. At this time, the loss status notification means displays or reads aloud (voice notification) information based on the message information 38A2 on the screen. S105 corresponds to the step in which the mobile terminal receives loss information from the management server, and the control unit of the mobile terminal puts the mobile terminal into an inoperable state.
[0188] Next, as S106, the mobile terminal 220A is found by finder 49. S106 corresponds to the step where the finder acquires the mobile device. The found mobile device 220A is brought to the intermediary business 47A by the finder 49, in accordance with the contents of message information 38A2.
[0189] Next, in S107, the terminal identification information 220B from the terminal identification information storage unit 29C is read by the reading device of the intermediary business terminal 48A.
[0190] Next, as shown in Figure 10, in S108, the terminal identification information 220B read in S107 is transmitted to the management server 15A. At this time, the location information of the intermediary business operator 47A is also transmitted. S108 corresponds to the step in which the terminal identification information read by the reading device is transmitted to the management server.
[0191] Next, as S109, the notification confirmation unit 38C of the management server 15A, which received the information from S108, sends a deposit confirmation information 38C1 to the intermediary business terminal 48A, confirming that it has received the terminal identification information 220B and that an employee 47B of the intermediary business 47A has received the mobile terminal 220A from the finder 49. Then, employee 47B of intermediary operator 47A receives the mobile terminal 220A from the finder 49 and responds to the receipt confirmation information 38C1. The intermediary operator terminal 48A sends the response result to the management server 15A. S109 corresponds to the step in which the notification confirmation unit confirms that it has received the mobile device from the finder.
[0192] Next, as S110, the reward settlement processing unit 38D, having received the deposit confirmation information 38C1 response, settles the reward set by the owner with the intermediary business operator 47A. After the settlement is completed, the reward settlement processing unit 38D sends a settlement completion notification to the intermediary business operator terminal 48A indicating that the settlement has been completed. S110 corresponds to the step in which the reward settlement processing unit settles the reward set by the owner.
[0193] Next, as S111, employee 47B, having confirmed the payment completion notice, hands over the reward to the finder 49 according to the information in the payment completion notice, thereby completing the exchange of the mobile terminal 220A and the reward.
[0194] Next, as S112, the owner receives the mobile terminal 220A after identity verification. The owner visits the intermediary 47A with their personal information. The owner then requests to receive the mobile terminal 220A from employee 47B of intermediary 47A. Employee 47B, upon receiving the request, has the intermediary terminal 48A read the terminal identification information 220B of the mobile terminal 220A, and the owner then enters their personal information into the intermediary terminal 48A. The intermediary terminal 48A transmits the terminal identification information 220B that it has read and the entered personal information to the management server 15A.
[0195] Next, in S113, the management server 15A, which has received the read terminal identification information 220B and the entered personal information, compares the received information with the terminal identification information 220C recorded on the management server 15A to determine whether the person is the correct individual. If the person's identity is confirmed after their assessment, the process moves to S114, where employee 47 hands over the mobile device 220A to the owner, completing the handover process. If, after the individual's assessment, their identity cannot be confirmed, the process proceeds to S115, and employee 47 does not hand over the mobile device 220A to the owner. Then, the process returns to S112, and the identity verification process resumes. If the owner is unable to verify their identity, they can log in to the management server 15A from another terminal 23, update their personal information, or register their personal information again, thereby allowing them to perform the identity verification process for S112 once more.
[0196] In this embodiment, the lost and found recovery system 10A is shown as an example in which, in S107, the terminal identification information 220B in the terminal identification information storage unit 29C is read by the reader of the intermediary business operator terminal 48A, and then in S108, the terminal identification information 220B read in S107 and the location information of the intermediary business operator 47A are transmitted to the management server 15A.
[0197] However, as a modification of S107 and S108 of the embodiment, S107 may further include a finder information input step in which the finder 49 inputs the finder 49's information into the intermediary operator terminal 48A. Then, in S108, the terminal identification information 220B, the finder 49's information, and the location information of the intermediary operator 47A may be transmitted.
[0198] The information of the finder 49 may include the finder 49's name, address, contact information, and My Number information, and the intermediary business operator's terminal 48A may read or input the finder 49's information using its reader. If the information of the finder 49 includes the finder 49's contact information, the finder 49 and the owner may be allowed to contact each other directly based on that information and negotiate compensation, etc. Additionally, information about the finder 49 may be recorded by the employee 49 through interviews or by verifying it using the finder's identification documents (such as a My Number card or driver's license) that the finder 49 possesses.
[0199] Furthermore, in S110 and S111 of the lost property retrieval system 10A of this embodiment, the reward settlement processing unit 38D, upon receiving the response of the deposit confirmation information 38C1, settles the reward with the intermediary business operator 47A, and the employee 47B hands over the reward to the finder 49 in accordance with the information in the settlement completion notification.
[0200] However, as a variation of S110 and S111 of the embodiment, the reward settlement processing unit 38D, upon receiving the response of the deposit confirmation information 38C1, may not immediately perform the settlement, but rather after the mobile terminal 220A has been returned to the owner. Settlement may be performed when the owner, who has logged into the management server 15A from another terminal 23A or the mobile terminal 220A, instructs the reward settlement processing unit 38D to make the settlement, or when the mobile terminal 220A is released from its inoperable state. In this case, the reward to the finder 49 is paid based on the information regarding the payment of the reward.
[0201] Furthermore, in steps S112 and S113 of the lost property retrieval system 10A of this embodiment, an example was given in which the owner visits the intermediary business 47A with their personal information, has the intermediary business terminal 48A read the terminal identification information 220B of the mobile terminal 220A, and then verifies the owner's identity by having the owner input their personal information into the intermediary business terminal 48A, after which the mobile terminal 220A is returned to the owner.
[0202] However, instead of S112 and S113, the deposit confirmation information 38C1 in S109 and the payment completion notification in S111 may include return request information, such as the shipping address information for the mobile terminal 220A, and instruct the employee 47B or finder 49 to send it to that address, thereby requesting its return to the owner. Alternatively, after S111, the owner who learns the location of the intermediary business 47A where the mobile phone 220A was deposited may instruct the employee 47B by telephone or other means to send it to the shipping address, so that the mobile terminal 220A is returned to the owner.
[0203] (Regarding the lost and found recovery system 10A1) In this embodiment, terminal identification information 220B and personal information of the mobile terminal 220A, which are input into the intermediary terminal 48A, are transmitted to the management server 15. The transmitted information is compared with the terminal identification information 220C recorded in the management server 15A, and the management server 15A performs identity verification (S112-S113). However, as shown in Figure 11, in the lost and found recovery system 10A1, which is a modified version of this embodiment, the return determination unit 38E' of the management server 15A may be replaced with a return determination unit 38E' that is provided in the application software 29B to perform identity verification. If the return determination unit 38E' is provided in the application software 29B, an example of the application software 29B can be provided with the application software 29B prompting the owner to input the biometric authentication and / or password provided in the mobile terminal 220A as a way for the user to determine whether or not to release the inoperable state. This embodiment has the advantage of allowing the inoperable state to be resolved with a simplified procedure without communicating with the management server 15A.
[0204] Next, referring to Figure 12, we will explain the flow of the lost and found recovery system 10A1. Since steps S101 to S111 of the lost and found recovery system 10A are the same, the explanation will be omitted.
[0205] In S121, an offer is made to employee 47B of intermediary 47A to receive the mobile device 220A. Upon receiving the offer, employee 47B is instructed to enter the biometric authentication and / or password for the mobile device 220A (at their own discretion).
[0206] As S122, if the inoperable state is resolved based on the user's own judgment, the user is determined to be the legitimate owner, and the process moves to S114, returning the mobile terminal 220A to that owner. On the other hand, if the inoperable state is not resolved, the system proceeds to S115, determines that the user is not the legitimate owner, and does not return the mobile terminal 220A to its owner.
[0207] By following the steps above, it is also possible to simplify the return process.
[0208] Refer to Figure 13 to explain the lost and found recovery system 10A2. This embodiment differs from the lost and found system 10 in that, as shown in Figure 13, the intermediary terminal 48A is the finder's terminal 47C that found the mobile terminal 220A.
[0209] (Found terminal 47C) The finder's terminal 47C is an information terminal owned by the finder, and a mobile terminal is a specific example. The finder's terminal 47C has the same functions as the mobile terminal 220A and is further equipped with a reader device 48A1 that can read terminal identification information 220B.
[0210] Furthermore, the terminal memory unit 27 stores finder identification information 220C, which includes personally identifiable information such as the finder's name, address, contact information, and location information when the terminal was read, and also includes information such as My Number and driver's license. In other words, finder identification information 220C is the same type of information as terminal identification information 220B, but it is information related to the finder. Note that the finder terminal 47C also includes cases where the finder terminal 47C has a memory unit with the same function as the terminal identification information memory unit 29C of the mobile terminal 220A, and finder identification information 220C is stored in that memory unit.
[0211] Next, we will explain the flow of the lost and found recovery system 10A2. Since steps S101 to S105 of the lost and found recovery system 10A are the same, the explanation will be omitted.
[0212] Next, as A131 (corresponding to S106), the mobile terminal 220A is found by the finder 49. The found mobile terminal 220A is handled by the finder 49 according to the contents of message information 38A2. Next, in S132 (equivalent to S107), the terminal identification information 220B in the terminal identification information storage unit 29C is read by the reader device of the finder's terminal 47C of the finder 49.
[0213] Next, in S133 (equivalent to S108), the terminal identification information 220B read in S132 is transmitted to the management server 15A. At this time, the finder identification information 220C of the finder 49 is also transmitted. The transmission of this information is performed by the control unit 28 of the finder terminal 47C, and application software (not shown) that controls this transmission is stored in the terminal storage unit 27 of the finder terminal 47C.
[0214] Next, as S134 (equivalent to S109), the notification confirmation unit 38C of the management server 15A, which received the information from S133, transmits to the finder's terminal 47C that it has received terminal identification information 220B and finder identification information 220C. The management server 15A also transmits the owner's contact information to the finder's terminal 47C of the finder 49 and instructs them to determine how to return the item, thereby enabling the finder and the owner to communicate. Since the finder's contact information is also stored in the management server 15A, the owner can also contact the finder.
[0215] Furthermore, the agreement can determine the amount of compensation, settle the compensation via the compensation settlement processing unit 38D, hand over the compensation directly, or determine the method of returning the mobile terminal 220A.
[0216] Referring to Figure 14, the second lost item retrieval system 10B will be described. Systems with the same function as the lost and found system 10A are given the same code and their descriptions are omitted. The lost and found recovery system 10B in this implementation configuration is equipped with a biometric authentication unit 29A1 on the mobile terminal 220A. In other words, this configuration includes a biometric authentication unit 29A1 permanently installed in the mobile terminal 220A of the lost and found recovery system 10A. Furthermore, the terminal storage unit 27A is always equipped with first biometric information 27B and second biometric information 27B for biometric authentication.
[0217] [Always-on biometric authentication unit 29A1] The always-on biometric authentication unit 29A1 performs always-on authentication using the first biometric information 27B pre-stored in the terminal storage unit 27 and the first biometric information acquired by the biometric information acquisition unit 29A, and also performs always-on authentication using the second biometric information 27C pre-stored in the terminal storage unit 27 and the second biometric information acquired by the biometric information acquisition unit 29A. The first biological information 27B and the second biological information 27C use different types of biological information. Examples of different types of biometric information include biometric authentication using facial information and biometric authentication using biometric information from a location other than the face. For example, the first biometric information 27B could be facial recognition or iris recognition using facial information, and the second biometric information 27C could be fingerprints or vein patterns using hand information. In this implementation, the biometric information acquisition unit 29A will be described using the example of a case where the camera and the operation unit (entire touch panel) have fingerprint authentication sensors.
[0218] Next, the operation of the always-on biometric authentication unit 29A1 will be explained with reference to Figures 15 and 16. First, as S201, the first biometric information and the second biometric information are recorded (initially registered) in the terminal memory unit 27 of the mobile terminal 220A.
[0219] Next, to operate the S202 mobile terminal 220A from its locked state, an unlock operation (unlocking) is performed. To unlock it, the always-on biometric authentication unit 29A1 is activated. The always-on biometric authentication unit 29A1 is activated, for example, by touching the power button or the fingerprint authentication sensor (which is the biometric information acquisition unit) from sleep mode. In this implementation, the explanation assumes that the fingerprint authentication sensor is located across the entire screen.
[0220] As S203, when the always-on biometric authentication unit 29A1 is activated, the biometric information acquisition unit 29A1 starts acquiring the first biometric information and the second biometric information. Specifically, it acquires information for facial recognition using the camera (first biometric information) and fingerprint information using the fingerprint sensor (second biometric information). As S204, first biometric authentication is performed using the first biometric information acquired by the always-on biometric authentication unit 29A1 and the first biometric information 27B recorded in the terminal storage unit 27. If the first biometric authentication matches, the response is YES, and the process proceeds to S205. On the other hand, if the first biometric authentication does not match, the process proceeds to S206, and the locked state is maintained.
[0221] As S205, second biometric authentication is performed using the second biometric information 27C acquired by the always-on biometric authentication unit 29A1 and the second biometric information recorded in the terminal storage unit 27. If the second biometric authentication matches, the answer is YES, and the process proceeds to S207. On the other hand, if the second biometric authentication does not match, the process proceeds to S206, the locked state is maintained, and the process ends.
[0222] As S207, the lock state is released, allowing operation of the mobile terminal 220A.
[0223] As S208, when the mobile terminal 220A is operational, the biometric authentication unit 29A1 continuously acquires first biometric information (information for facial recognition acquired by the camera) and second biometric information (fingerprint information acquired by the fingerprint sensor) from the biometric information acquisition unit 29A1.
[0224] As S209, first biometric authentication is performed using the first biometric information acquired by the always-on biometric authentication unit 29A1 and the first biometric information 27B recorded in the terminal storage unit 27. If the first biometric authentication matches, the result is YES, and the process proceeds to S210, maintaining the operational state of the mobile terminal 220A. On the other hand, if the first biometric authentication does not match, the process proceeds to S211.
[0225] As S211, second biometric authentication is performed using the second biometric information acquired by the always-on biometric authentication unit 29A1 and the second biometric information 27C recorded in the terminal storage unit 27. If the second biometric authentication matches, the response is YES, and the process proceeds to S210. The mobile terminal 220A remains operational. On the other hand, if the second biometric authentication does not match, the process proceeds to S212 and locks the device.
[0226] In this implementation, the unlocked (operable) state is maintained by matching the first biometric authentication or the second biometric information. Furthermore, even in the operable state, the biometric authentication unit 29A1 continuously performs repeated first and second biometric authentication. As a result, when both the first and second biometric authentications no longer match, the mobile terminal 220A can be immediately locked, preventing unauthorized use by a third party. In other words, even if you turn your face away from the camera (the first biometric authentication fails), as long as your finger remains touching the screen (the fingerprint authentication matches), the device can remain operational. This reduces the tedious process of repeatedly unlocking the device while also preventing unauthorized use by third parties.
[0227] In this embodiment, we have provided an example where facial recognition is used as the first biometric authentication and fingerprint authentication is used as the second biometric authentication when unlocking (S201-S207) and when maintaining the operable state (S208-S210) (when using the same first and second biometric authentication). However, different biometric authentications may be used when unlocking and when maintaining the operable state.
[0228] Also, when performing face authentication, the mobile terminal 220A may further include a tracking sensor or a following sensor. For example, these sensors may be used to make the camera constantly track the face for face authentication.
[0229] In addition, the mobile terminal 220A may be provided with a distance sensor, a touch sensor, and a temperature sensor, and may further include an operable state maintenance determination means for maintaining or locking the operable state based on the constantly measured information of these sensors. For example, when maintaining the operable state, even if the first biometric authentication and the second biometric authentication do not match, if the distance between the terminal 220A and the owner is not separated by a certain distance based on the information of the distance sensor, or if an input is continuously detected by the touch sensor on the mobile terminal 220A based on the information of the touch sensor, or if it can be determined that the owner is nearby based on the information of the temperature sensor, control may be performed to maintain the operable state. By doing so, for example, when the mobile terminal 220A is playing music, even if the owner puts the mobile terminal 220A in the pocket, it can be determined that the owner is nearby, and the operable state can be maintained even if the face authentication (first biometric authentication) or fingerprint authentication (second biometric authentication) does not match, enabling convenient control.
[0230] In this embodiment, the case where the mobile terminal 220A of the lost item recovery system 10A is constantly provided with the biometric authentication unit 29A1 has been described, but the mobile terminal 220A of the lost item recovery system 10A1 may also be constantly provided with the biometric authentication unit 29A1.
[0231] Note that the operation of the constant biometric authentication unit 29A1 is not limited to the application of the mobile terminal 220A. For example, the operations of S201 to 212 can also be applied to information terminals such as notebook computers and desktop computers to form a constant biometric authentication method, preventing unauthorized use by third parties. In addition, when applied to a notebook computer, a desktop computer, etc., it is desirable to be equipped with a camera for face authentication or iris authentication, and a device for acquiring fingerprints or vein patterns in an input device such as a keyboard or a mouse. When applied to a notebook computer, a desktop computer, etc., a distance sensor, a touch sensor, or a temperature sensor may be provided and used as an operationable state maintenance determination means.
Industrial Applicability
[0232] The lost item recovery system of the present invention can be suitably used for a mobile terminal. Further, the always-on biometric authentication method of the present invention can also be suitably applied to terminals such as a notebook computer and a desktop computer in addition to the mobile terminal.
Explanation of Signs
[0233] 10… Seal authentication system (owner continuous authentication system, lost item relief system) 11, 50, 60… Seal (possession) 11A… Spare [[ID=I21]] 15… Seal authentication server (owner authentication server) 16… Seal face part 18… Seal storage part 30… Seal image 53, 63… Storage part 10A, A1, A2, B… Lost item recovery system 220A… Mobile terminal 15A… Management server 18A… IC tag 23A… Other terminal 29A… Biometric information acquisition part 29B… Application software 29C… Terminal specific information storage part 38A… Lost information management part 38B… Biometric authentication management part 38C… Report confirmation part 38D… Reward settlement processing part 38E… Return judgment part 47A… Intermediary business operator 47B… Employee 47C… Finder terminal 48A... Intermediary terminal 29A1... Always-on biometric authentication department 220C…Founder identification information
Claims
1. The steps include registering terminal identification information with the management server, The steps include storing terminal identification information in the terminal identification information storage unit of a mobile terminal, The owner registers the loss information on the server after losing the mobile device, The management server transmits the lost information to the mobile terminal, The steps include: the mobile terminal receiving loss information from the management server, and the control unit of the mobile terminal disabling the mobile terminal; The steps include: the finder acquiring the mobile device, The steps include: transmitting the terminal identification information read by the reading device to the management server; The reward settlement processing unit performs the settlement of the reward set by the owner, A method for recovering lost property, characterized by comprising the following:
2. The method for recovering lost property according to claim 1, further comprising the step of confirming that the notification confirmation unit has received the mobile terminal from the finder.
3. The method for recovering lost property according to claim 1, characterized in that the reading device is the terminal of the finder who found the mobile terminal.
4. A lost and found recovery system comprising a mobile terminal, an intermediary terminal, and a management server, The aforementioned mobile terminal includes a terminal identification information storage unit in which terminal identification information is stored, The system includes a control unit that, upon receiving loss information from the management server, disables the mobile terminal, The intermediary operator terminal includes a reading device for reading the terminal identification information from the terminal identification information storage unit, A personal information input device for entering information to prove that the user is the owner, and The system includes a transmission unit that transmits the terminal identification information read by the system to the management server, The aforementioned management server A transmission unit that transmits loss information to the mobile terminal, A notification confirmation unit, upon receiving the terminal identification information transmitted from the intermediary's terminal, transmits a deposit confirmation information to confirm that the mobile terminal has been received from the finder. A compensation settlement processing unit that settles the compensation set by the owner, A lost item recovery system characterized by being equipped with [a specific feature].
5. The aforementioned mobile terminal has a constant biometric authentication unit and a biometric information acquisition unit. The aforementioned always-on biometric authentication unit has different types of first and second biometric authentication. The continuous biometric authentication unit continuously determines whether the first biometric information pre-stored in the mobile terminal matches the first biometric information acquired by the biometric information acquisition unit, and also continuously determines whether the second biometric information pre-recorded in the mobile terminal matches the second biometric information acquired by the biometric information acquisition unit. The constant biometric authentication unit maintains the operable state of the mobile terminal when the first biometric information pre-recorded on the mobile terminal matches the first biometric information acquired by the biometric information acquisition unit, and / or when the second biometric information pre-recorded on the mobile terminal matches the second biometric information acquired by the biometric information acquisition unit. The lost item retrieval system according to claim 4, characterized in that if the first biometric information pre-recorded on the mobile terminal does not match the first biometric information acquired by the biometric information acquisition unit, and the second biometric information pre-recorded on the mobile terminal does not match the second biometric information acquired by the biometric information acquisition unit, the mobile terminal is locked and cannot be operated.
6. The lost item retrieval system according to claim 5, characterized in that the first biometric information is a face and / or iris, and the second biometric information is a fingerprint and / or vein pattern.
7. The information terminal has a constant biometric authentication unit and a biometric information acquisition unit. The aforementioned always-on biometric authentication unit has different types of first and second biometric authentication. The continuous biometric authentication unit continuously determines whether the first biometric information pre-stored in the information terminal matches the first biometric information acquired by the biometric information acquisition unit, and also continuously determines whether the second biometric information pre-recorded in the information terminal matches the second biometric information acquired by the biometric information acquisition unit. The constant biometric authentication unit maintains the operational state of the information terminal when the first biometric information pre-recorded on the information terminal matches the first biometric information acquired by the biometric information acquisition unit, and / or when the second biometric information pre-recorded on the information terminal matches the second biometric information acquired by the biometric information acquisition unit. A continuous biometric authentication method characterized in that, if the first biometric information pre-recorded on the information terminal does not match the first biometric information acquired by the biometric information acquisition unit, and the second biometric information pre-recorded on the information terminal does not match the second biometric information acquired by the biometric information acquisition unit, the information terminal is locked and cannot be operated.
8. The method for continuous biometric authentication according to claim 7, wherein the information terminal has at least one of a tracking sensor, a follow sensor, a distance sensor, a touch sensor, and a temperature sensor, and further comprises a determination of whether to maintain an operable state or a locked state based on the continuously measured information of these sensors.