Facial recognition system
The facial recognition system addresses the inconvenience of limited use of registered face data by integrating face authentication with other systems for enhanced user authentication and payment processing, improving service convenience.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- ミガロホールディングス株式会社
- Filing Date
- 2026-05-12
- Publication Date
- 2026-07-29
AI Technical Summary
Existing facial recognition systems are inconvenient as registered face image data cannot be utilized by authentication engines for purposes beyond face authentication.
A facial recognition system that includes a face memory unit, an ID storage unit, an authentication means, and a user-owned information terminal, enabling linking of facial recognition with other information processing systems for user authentication and payment processing.
Expands the applications of facial recognition, enhancing the convenience of various services by allowing seamless integration with other systems for user authentication and payment processing.
Smart Images

Figure 2026123291000001_ABST
Abstract
Description
Technical Field
[0005] , , , , ,
[0001] The present invention relates to a face recognition system.
Background Art
[0002] Conventionally, as an authentication system that performs authentication based on face data, an authentication system that performs personal authentication by collating input face data with registered face data registered in advance is known (see, for example, Patent Documents 1 and 2).
[0003] In the authentication system described in Patent Document 1, the target person is authenticated using an image of a face portion in a captured image captured by a camera. Further, in the authentication system described in Patent Document 2, for example, when there are four registered face images, two are used as face patterns for accuracy assurance, one is used as a face pattern for absorbing disturbance components, and one is used as a face pattern for updating. Then, when registering a new face pattern, among the four face patterns registered in advance, the face pattern for updating, which has the second lowest similarity to the newly registered face pattern, is deleted. That is, by leaving the face pattern for absorbing disturbance components, which has the lowest similarity to the newly registered face pattern, face authentication is performed in accordance with variations in the environment.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0005] In the authentication systems disclosed in Patent Documents 1 and 2, there is a problem that it is inconvenient because the data of the registered face image cannot be used by an authentication engine that performs authentication other than face authentication.
[0006] This invention has been made with these points in mind, and aims to provide a facial recognition system that can expand the applications of facial recognition and improve the convenience of various services. [Means for solving the problem]
[0007] The facial recognition system of the present invention is A face memory unit where the user's face image or processed face data is registered, An ID storage unit where user identification information is registered, An authentication means that identifies a user by comparing a face captured by a camera with the aforementioned face data, A user-owned information terminal, a user terminal on which the user takes a photograph of a face image that will be the source data for the aforementioned face data, The system includes a linking means for linking the aforementioned identification information with information that can uniquely identify a user of another information processing system, The gist of this invention is to authenticate users of the aforementioned other information processing system using facial recognition with the aforementioned authentication means.
[0008] Furthermore, the facial recognition system of the present invention is A face memory unit where the user's face image or processed face data is registered, Authentication means for comparing a face captured by a photographic means with the aforementioned face data, A user-owned information terminal, a user terminal on which the user takes a photograph of a face image that will be the source data for the aforementioned face data, The gist of the system is that it includes a payment means that, upon successful authentication by the aforementioned authentication means, transmits payment information for the goods or services provided to the user to a payment-related institution. [Effects of the Invention]
[0009] The facial recognition system of the present invention can broaden the applications of facial recognition and improve the convenience of various services. [Brief explanation of the drawing]
[0010] [Figure 1] This figure schematically shows an example of an authentication system and imaging units to be deployed at each service organization according to an embodiment of the present invention. [Figure 2] Figure 1 is a flowchart showing the processes performed when registering a user's facial image using the authentication system. [Figure 3] Figure 1 is a flowchart illustrating an example of the processes performed when authenticating a user using the authentication system and imaging unit shown. [Figure 4] This figure schematically illustrates another example of an authentication system and imaging units to be deployed in each service organization according to an embodiment of the present invention. [Figure 5] Figure 4 is a flowchart showing the processes performed when registering a user's facial image using the authentication system. [Figure 6] Figure 4 is a flowchart illustrating an example of the processes performed when authenticating a user using the authentication system and imaging unit shown. [Figure 7] This figure schematically illustrates yet another example of an authentication system and imaging units to be deployed in each service organization according to an embodiment of the present invention. [Figure 8] Figure 7 is a flowchart showing the processes performed when registering a user's facial image using the authentication system. [Figure 9] Figure 7 is a flowchart illustrating an example of the processes performed when authenticating a user using the authentication system and imaging unit shown. [Figure 10] This diagram shows the initial screen displayed on the user's terminal. [Figure 11] This diagram shows the registration screen displayed on the user's terminal. [Figure 12] This diagram shows the registration screen displayed on the user's terminal. [Figure 13] This diagram shows the service addition screen displayed on the user's terminal. [Figure 14] This diagram shows the authentication history screen displayed on the user's terminal. [Figure 15] This is a diagram showing a detailed screen of the authentication history displayed on the user terminal. [Figure 16] This is a diagram schematically showing another example of the authentication system according to an embodiment of the present invention and imaging units arranged in each company. [Figure 17] This is a diagram schematically showing another example of the authentication system according to an embodiment of the present invention and imaging units arranged in each company.
Embodiments for Carrying Out the Invention
[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings. FIGS. 1 to 15 are diagrams showing the authentication system according to the present embodiment and imaging units arranged in each service institution.
[0012] As shown in FIG. 1, imaging units 30A, 30B, 30C for authenticating users are arranged in each service institution such as a restaurant, a hotel, a transportation facility, an office building, an apartment complex facility, and a convenience store. Although three imaging units 30A, 30B, 30C are shown in FIG. 1, two or four or more imaging units may be used. In addition, an authentication system 10 installed in a company different from each service institution is communicably connected to each of the imaging units 30A, 30B, 30C via a network such as an Internet line. Further, a user terminal 20 such as a smartphone possessed by the user is communicably connected to the authentication system 10 and each of the imaging units 30A, 30B, 30C via a network such as an Internet line. Hereinafter, details of the authentication system 10 and each of the imaging units 30A, 30B, 30C will be described.
[0013] The authentication system 10 is composed of, for example, a computer, and the authentication system 10 has a processor 12 such as a CPU, a memory 16, and a communication unit 18. The processor 12 has a feature extraction means 14 that extracts the feature quantities of the user's face image corresponding to each imaging unit 30A, 30B, and 30C as hash values based on face image data received from the user terminal 20, and a registration means 13 that registers the extracted feature quantities of the user's face image. The processor 12 executes a program stored in the memory 16, so that the feature extraction means 14 extracts the feature quantities of the user's face image corresponding to each imaging unit 30A, 30B, and 30C as hash values. Specifically, the feature extraction means 14 extracts the hash value obtained from the received user's face image data using a predetermined hash function as the feature quantity of the user's face image. Note that even if the user's face image data is the same, the feature quantities of the user's face image may differ depending on the type of imaging unit 30A, 30B, and 30C. This is because the specifications of the imaging units 30A, 30B, and 30C used by different service providers differ depending on the service provider. Therefore, the feature extraction means 14 extracts feature quantities of the user's face image for each imaging unit 30A, 30B, and 30C. In other words, from a single face image data, feature quantities of multiple user face images corresponding to each imaging unit 30A, 30B, and 30C are extracted. Furthermore, the processor 12 executes a program stored in memory 16 to store the feature quantities (specifically, hash values) of the user's face image for each imaging unit 30A, 30B, and 30C extracted by the feature extraction means 14 in memory 16, associated with the user's identification information and the identification information of the imaging units 30A, 30B, and 30C, via the registration means 13. Note that the program executed by the processor 12 is not limited to those stored in memory 16. The processor 12 may execute a program transmitted from an external device to the authentication system 10, or a program stored on a recording medium detachably attached to the authentication system 10, thereby performing processing in the feature extraction means 14 and the registration means 13, respectively.In this embodiment, the information acquisition means 17 is comprised of the feature extraction means 14 and the registration means 13. The information acquisition means 17 receives the user's face image data when a user is registered, extracts the feature quantities of the user's face image based on the received face image data, and stores the information relating to the extracted feature quantities of the user's face image in the memory 16 as the user's identification information.
[0014] As described above, the memory 16 stores the feature quantities (specifically, hash values) of the user's face image extracted by the feature quantity extraction means 14, associated with the user's identification information and the identification information of the imaging units 30A, 30B, and 30C. As described above, the feature quantities of the user's face image extracted by the feature quantity extraction means 14 may differ depending on the type of imaging unit 30A, 30B, and 30C. Therefore, the feature quantity extraction means 14 extracts the feature quantities of the user's face image for each imaging unit 30A, 30B, and 30C. Consequently, the feature quantities of the user's face image extracted by the feature quantity extraction means 14 also need to be stored in the memory 16 in association with each imaging unit 30A, 30B, and 30C. In addition, the memory 16 stores the user's identification information and the service organization selected by this user in association with each other. Furthermore, as described above, the memory 16 stores programs for causing the processor 12 to perform various processes. Furthermore, the processor 12 is configured to transmit and receive signals via a network such as an internet connection to imaging units 30A, 30B, 30C, or user terminals 20 located at each service organization, through a communication unit 18.
[0015] Each imaging unit 30A, 30B, and 30C, deployed at each service organization, is composed of, for example, a computer, and each imaging unit 30A, 30B, and 30C has a processor 32A, 32B, and 32C such as a CPU, a memory 36A, 36B, and 36C, an imaging unit 38A, 38B, and 38C, a processing unit 40A, 40B, and 40C, and a communication unit 42A, 42B, and 42C. The processors 32A, 32B, and 32C have feature extraction means 34A, 34B, and 34C that extract feature quantities of the user's face image as hash values based on the user's face image data captured by the imaging units 38A, 38B, and 38C, and authentication means 35A, 35B, and 35C. Processors 32A, 32B, and 32C execute programs stored in memories 36A, 36B, and 36C, causing feature extraction means 34A, 34B, and 34C to extract feature quantities of the user's face image as hash values. Specifically, feature extraction means 34A, 34B, and 34C extract hash values obtained from the received user face image data using a predetermined hash function as feature quantities of the user's face image. Furthermore, processors 32A, 32B, and 32C execute programs stored in memories 36A, 36B, and 36C, causing authentication means 35A, 35B, and 35C to authenticate the user. Details of these processes will be described later. Note that the programs executed by processors 32A, 32B, and 32C are not limited to those stored in memories 36A, 36B, and 36C. The processors 32A, 32B, and 32C execute programs transmitted from an external device to the imaging units 30A, 30B, and 30C, or programs stored on recording media detachably attached to the imaging units 30A, 30B, and 30C. This allows various processes to be performed in the feature extraction means 34A, 34B, and 34C and the authentication means 35A, 35B, and 35C, respectively. Furthermore, each imaging unit 30A, 30B, and 30C is not limited to corresponding to a single service organization. For example, imaging unit 30A may correspond to multiple service organizations.
[0016] Furthermore, memories 36A, 36B, and 36C store pre-registered user identification information and associated feature quantities of the user's facial image. Also, as mentioned above, memories 36A, 36B, and 36C store programs for causing processors 32A, 32B, and 32C to perform various processes. In addition, imaging units 38A, 38B, and 38C have, for example, cameras and acquire facial image data of the user by capturing images of the user.
[0017] Furthermore, processing units 40A, 40B, and 40C perform various processes for authenticated users. For example, if imaging units 30A, 30B, and 30C are installed in office buildings or apartment complexes, processing units 40A, 40B, and 40C will unlock doors at entrances to these buildings or apartment complexes once a user has been authenticated. Also, if imaging units 30A, 30B, and 30C are installed in restaurants, hotels, transportation facilities, convenience stores, etc., they enable cashless payment when users pay for services at these service providers. In this case, payment information is transmitted from imaging units 30A, 30B, and 30C to the servers of financial institutions or credit card companies, causing the payment amount to be automatically debited from the user's bank account or added to their credit card statement. In addition, processors 32A, 32B, and 32C transmit and receive signals with the authentication system 10 or user terminal 20 via a network such as the internet, using communication units 42A, 42B, and 42C.
[0018] Furthermore, in each imaging unit 30A, 30B, and 30C, the user's face image is captured by the imaging units 38A, 38B, and 38C, allowing the feature quantities of this user's face image to be registered in each imaging unit 30A, 30B, and 30C. Specifically, when registering the feature quantities of a user's face image in each imaging unit 30A, 30B, and 30C, once the user's face image is captured by the imaging units 38A, 38B, and 38C, the processors 32A, 32B, and 32C extract the feature quantities of the user's face image as hash values using the feature quantity extraction means 34A, 34B, and 34C based on the user's face image data captured by the imaging units 38A, 38B, and 38C. These extracted feature quantities of the user's face image (specifically, hash values) are then stored in the memories 36A, 36B, and 36C. In this way, the feature quantities of the user's face image are registered in each imaging unit 30A, 30B, and 30C.
[0019] The user terminal 20 can install a facial recognition application via an online store or similar means. Once such a facial recognition application is installed, the user can register facial image data, register service providers using the service, etc., via the user terminal 20. The processing details of such a facial recognition application will be described later. Note that such a facial recognition application may be provided by the authentication system 10, or it may be provided by a system separate from the authentication system 10.
[0020] In this embodiment, the authentication system 10 and the imaging units 30A, 30B, and 30C located at each service organization are connected via API (Application Programming Interface). This makes it easier to configure the systems of each imaging unit 30A, 30B, and 30C compared to configuring each system independently.
[0021] Next, the process for user authentication performed by the authentication system 10 and each imaging unit 30A, 30B, and 30C will be explained using Figures 2, 3, and 10 to 12.
[0022] First, we will explain the process by which a user registers facial image data with the authentication system 10 using the user terminal 20. Initially, the user installs a facial recognition application on the user terminal 20. The initial screen of such a facial recognition application displays the screen shown in Figure 10. The user then registers as a user using this facial recognition application on the user terminal 20. Specifically, pressing the account button on the screen shown in Figure 10 brings up the user registration screen shown in Figure 11. On this user registration screen, the user enters registration information such as name, date of birth, phone number, email address, and password, checks the box to agree to the terms of service, and then presses the register button, which brings up the facial image capture screen shown in Figure 12. When the user captures a facial image with the user terminal 20 on this capture screen, various information entered on the user registration screen and the user's facial image data are sent from the user terminal 20 to the authentication system 10. In this way, the processor 12 of the authentication system 10 receives the facial image data from the user terminal 20 (STEP 1). Furthermore, the processor 12 of the authentication system 10 receives identification information of the user terminal 20, as well as registration information such as the user's name, date of birth, telephone number, email address, and password entered into the user terminal 20. The processor 12 also issues a user ID as user identification information and stores this issued user ID in the memory 16.
[0023] Next, the processor 12 of the authentication system 10 extracts the feature quantities of the face images corresponding to each imaging unit 30A, 30B, and 30C as hash values using the feature extraction means 14, based on the face image data received from the user terminal 20 (STEP 2). At this time, the feature quantities of the user's face image extracted by the feature extraction means 14 may differ depending on the type of imaging unit 30A, 30B, and 30C. For this reason, the feature extraction means 14 extracts the feature quantities of the user's face image for each imaging unit 30A, 30B, and 30C. Furthermore, the feature extraction means 14 extracts only the feature quantities of the user's face image corresponding to the imaging unit 30A, 30B, and 30C of the service organization that has been pre-selected by the user. For example, if the user has permitted the use of face image data for the service organization where imaging unit 30A is installed, but has not permitted the use of face image data for the service organization where imaging unit 30B is installed, the feature extraction means 14 extracts only the feature quantities of the user's face image corresponding to imaging unit 30A. As described above, the memory 16 stores the user's identification information and the service provider selected by the user in association. The processor 12 then stores the feature quantities of the face images corresponding to each imaging unit 30A, 30B, and 30C, extracted by the feature quantity extraction means 14, in the memory 16 of the authentication system 10 in association with the user ID (user's identification information) and the identification information of the imaging units 30A, 30B, and 30C (STEP 3) using the registration means 13. In this way, the registration of the user's face image captured by the user terminal 20 is completed. The information regarding the feature quantities of the user's face image stored in the memory 16 is then transmitted from the authentication system 10 to the imaging units 30A, 30B, and 30C of the service provider selected by the user (STEP 4). At this time, the feature quantities of the user's face image corresponding to each imaging unit 30A, 30B, and 30C are transmitted to the imaging units 30A, 30B, and 30C. The imaging units 30A, 30B, and 30C store information related to the feature quantities of the user's facial image transmitted from the authentication system 10 in the memories 36A, 36B, and 36C, associating it with the user's identification information.
[0024] Next, the process for user authentication in each imaging unit 30A, 30B, and 30C will be described. When user authentication is required at a service organization where each imaging unit 30A, 30B, and 30C is installed, first, the user's face image data is acquired by imaging the user using the imaging units 38A, 38B, and 38C of the imaging units 30A, 30B, and 30C (STEP 11). In addition, in the imaging units 30A, 30B, and 30C, the processors 32A, 32B, and 32C extract the features of the user's face image as hash values using the feature extraction means 34A, 34B, and 34C based on the acquired face image data (STEP 12). Then, processors 32A, 32B, and 32C authenticate the user by comparing the feature quantities (specifically, hash values) of the user's face image extracted by feature extraction means 34A, 34B, and 34C with the feature quantities (specifically, hash values) of the user's face image stored in memory 36A, 36B, and 36C (STEP 13). More specifically, if the matching rate between the feature quantities of the user's face image extracted by feature extraction means 34A, 34B, and 34C and the feature quantities of the user's face image stored in memory 36A, 36B, and 36C exceeds a predetermined threshold (for example, 80%), authentication means 35A, 35B, and 35C authenticate the user. As mentioned above, memory 36A, 36B, and 36C stores pre-registered user identification information and the feature quantities of this user's face image in association with each other.
[0025] Then, once the user is authenticated by the authentication means 35A, 35B, and 35C ("YES" in STEP 14), the processors 32A, 32B, and 32C enable the processing units 40A, 40B, and 40C to perform the services corresponding to the imaging units 30A, 30B, and 30C (STEP 15). Specifically, as described above, if the imaging units 30A, 30B, and 30C are located in office buildings or apartment complexes, the processing units 40A, 40B, and 40C will unlock the doors located at the entrances and exits of these office buildings or apartment complexes once the user has been authenticated. Furthermore, if the imaging units 30A, 30B, and 30C are located in restaurants, hotels, transportation facilities, convenience stores, etc., they will enable cashless payment when users pay for services at these service providers. In addition, two-factor authentication may be implemented when cashless payment is performed. Subsequently, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit information regarding the service usage status to the authentication system 10 (STEP 17). As a result, the authentication system 10 stores information regarding the service usage status at each service provider in the memory 16 for each user.
[0026] On the other hand, if the feature quantities of the user's face image extracted by the feature quantity extraction means 34A, 34B, and 34C do not substantially match the feature quantities of the user's face image stored in the memory 36A, 36B, and 36C, and the authentication means 35A, 35B, and 35C are unable to authenticate the user ("NO" in STEP 14), the processors 32A, 32B, and 32C will disable the service corresponding to the imaging unit 30A, 30B, and 30C through their respective processing units 40A, 40B, and 40C (STEP 16). In this case as well, the processors 32A, 32B, and 32C of the imaging unit 30A, 30B, and 30C will transmit information regarding the service usage status (specifically, information that the user attempted to authenticate with the imaging unit 30A, 30B, and 30C but was not authenticated and therefore could not use the service) to the authentication system 10 (STEP 17).
[0027] With this authentication method, even if the features of a user's face image are registered in the imaging engine of one service provider (e.g., imaging unit 30A) but not in the imaging engine of another service provider (e.g., imaging unit 30B), the features of this user's face image are stored in the memory 16 of the authentication system 10 and in the memories 36A, 36B, and 36C of each imaging unit 30A, 30B, and 30C, associated with the identification information of the imaging units 30A, 30B, and 30C. This allows the service provider whose features are not registered to authenticate the user by capturing the user's face image with their imaging unit. In this case, the user does not need to register face image data in all of the multiple imaging units, thus saving the user time and effort.
[0028] The authentication system 10 and authentication method according to this embodiment are not limited to those shown in Figures 1 to 3. Other examples of the authentication system 10 and authentication method according to this embodiment will be explained using Figures 4 to 6. Note that for the authentication system 10 and each imaging unit 30A, 30B, and 30C shown in Figure 4, the same reference numerals are used for components that are the same as those shown in the authentication system 10 and each imaging unit 30A, 30B, and 30C shown in Figure 1, and their explanations are omitted.
[0029] As shown in Figure 4, the processor 12 of the authentication system 10 includes a feature extraction means 14 that extracts feature quantities of the user's face image corresponding to each imaging unit 30A, 30B, and 30C as hash values based on face image data received from the user terminal 20, a registration means 13 that registers the extracted feature quantities of the user's face image, and an authentication means 15 that authenticates the user based on the feature quantities (specifically, hash values) of the user's face image captured by the imaging units 38A to 38C of each imaging unit 30A, 30B, and 30C. The processor 12 executes a program stored in the memory 16 so that the registration means 13 stores the feature quantities (specifically, hash values) of the user's face image extracted by the feature extraction means 14 in the memory 16, associating them with the user's identification information and the identification information of the imaging units 30A, 30B, and 30C. Furthermore, the processor 12 executes a program stored in the memory 16, thereby enabling the authentication means 15 to authenticate the user by comparing the feature quantities (specifically, hash values) of the user's face images captured by the imaging units 38A to 38C of each imaging unit 30A, 30B, and 30C with the feature quantities (specifically, hash values) of the user's face images corresponding to each imaging unit 30A, 30B, and 30C stored in the memory 16. Note that the program executed by the processor 12 is not limited to those stored in the memory 16. The processor 12 may execute a program transmitted from an external device to the authentication system 10, or a program stored on a recording medium detachably attached to the authentication system 10, thereby performing processing in the feature quantity extraction means 14, the registration means 13, and the authentication means 15, respectively. In this embodiment as well, the feature quantity extraction means 14 and the registration means 13 constitute the information acquisition means 17. The information acquisition means 17 receives the user's face image data when the user is registered, extracts feature quantities from the user's face image data based on the received user's face image data, and stores the information related to the extracted feature quantities of the user's face image in the memory 16 as the user's identification information.
[0030] Each imaging unit 30A, 30B, and 30C, deployed at each service organization, is composed of, for example, a computer, and each imaging unit 30A, 30B, and 30C has a processor 32A, 32B, and 32C such as a CPU, memory 36A, 36B, and 36C, imaging unit 38A, 38B, and 38C, processing unit 40A, 40B, and 40C, and communication unit 42A, 42B, and 42C. The processors 32A, 32B, and 32C have feature extraction means 34A, 34B, and 34C that extract feature quantities of the user's face image as hash values based on the user's face image data captured by the imaging units 38A, 38B, and 38C. In the example shown in Figure 4, the processors 32A, 32B, and 32C do not have the authentication means 35A, 35B, and 35C as shown in Figure 1. Processors 32A, 32B, and 32C execute programs stored in memories 36A, 36B, and 36C, thereby enabling feature extraction means 34A, 34B, and 34C to extract features of the user's face image as hash values. Specifically, feature extraction means 34A, 34B, and 34C extract hash values obtained from the received user face image data using a predetermined hash function as features of the user's face image. Note that the programs executed by processors 32A, 32B, and 32C are not limited to those stored in memories 36A, 36B, and 36C. Various processes may be performed in feature extraction means 34A, 34B, and 34C by executing programs transmitted from external devices to imaging units 30A, 30B, and 30C, or programs stored on recording media detachably attached to imaging units 30A, 30B, and 30C. Furthermore, in the example shown in Figure 4, the user's facial image features are not stored in memories 36A, 36B, and 36C.
[0031] In the example shown in Figure 4, the authentication system 10 and the imaging units 30A, 30B, and 30C located at each service organization are connected via API (Application Programming Interface). This makes it easier to configure the systems of each imaging unit 30A, 30B, and 30C compared to configuring each system independently.
[0032] Next, the process of user authentication performed by the authentication system 10 and each imaging unit 30A, 30B, and 30C, as shown in Figure 4, will be explained using Figures 5 and 6.
[0033] First, we will explain the process by which a user registers facial image data with the authentication system 10 using the user terminal 20. Note that the specific method by which the user captures facial images with the user terminal 20 has already been explained and will be omitted here. When a user first registers using such a facial recognition application on the user terminal 20, various information entered on the user registration screen and the user's facial image data are sent from the user terminal 20 to the authentication system 10. In this way, the processor 12 of the authentication system 10 receives the facial image data from the user terminal 20 (STEP 21). The processor 12 of the authentication system 10 also receives the identification information of the user terminal 20, as well as registration information such as the user's name, date of birth, telephone number, email address, and password entered on the user terminal 20. The processor 12 also issues a user ID as the user's identification information and stores this issued user ID in memory 16.
[0034] Next, the processor 12 of the authentication system 10 extracts the feature quantities of the face images corresponding to each imaging unit 30A, 30B, and 30C as hash values using the feature extraction means 14, based on the face image data received from the user terminal 20 (STEP 22). At this time, the feature quantities of the user's face image extracted by the feature extraction means 14 may differ depending on the type of imaging unit 30A, 30B, and 30C, and the feature extraction means 14 extracts the feature quantities of the user's face image for each imaging unit 30A, 30B, and 30C. Furthermore, the feature extraction means 14 extracts only the feature quantities of the user's face image corresponding to the imaging unit 30A, 30B, and 30C of the service organization that has been selected in advance by the user. Then, the processor 12 stores the feature quantities of the face images corresponding to each imaging unit 30A, 30B, and 30C extracted by the feature quantity extraction means 14 in the memory 16 of the authentication system 10, associating them with the user ID (user identification information) and the identification information of the imaging units 30A, 30B, and 30C (STEP 23) using the registration means 13. In this way, the registration of the user's face image captured by the user terminal 20 is completed. Note that in the example shown in Figure 4, the information relating to the feature quantities of the user's face image stored in the memory 16 is not transmitted from the authentication system 10 to the imaging units 30A, 30B, and 30C of the service organization selected by the user.
[0035] Next, the process for user authentication in each imaging unit 30A, 30B, and 30C will be described. When user authentication is required at a service organization where each imaging unit 30A, 30B, and 30C is installed, first, the user's face image data is acquired by imaging the user using the imaging units 38A, 38B, and 38C of the imaging units 30A, 30B, and 30C (STEP 31). In addition, in the imaging units 30A, 30B, and 30C, the processors 32A, 32B, and 32C extract the features of the user's face image as hash values using the feature extraction means 34A, 34B, and 34C based on the acquired face image data (STEP 32). Then, the processors 32A, 32B, and 32C transmit the features of the user's face image (specifically, the hash values) extracted by the feature extraction means 34A, 34B, and 34C to the processor 12 of the authentication system 10 via the communication units 42A, 42B, and 42C (STEP 33). Furthermore, when the processor 12 of the authentication system 10 receives information relating to the feature quantities of the user's face image from the imaging units 30A, 30B, and 30C, it receives information relating to the feature quantities of the user's face image that has been transmitted only from the imaging units 30A, 30B, and 30C of the service organization selected by the user, which is stored in the memory 16. Then, in the authentication system 10, the processor 12 authenticates the user by comparing the feature quantities of the user's face image (specifically, hash values) received from the imaging units 30A, 30B, and 30C with the feature quantities of the user's face image (specifically, hash values) stored in the memory 16 using the authentication means 15 (STEP 34). More specifically, if the matching rate between the feature quantities of the user's face image received from the imaging units 30A, 30B, and 30C and the feature quantities of the user's face image stored in the memory 16 exceeds a predetermined threshold (for example, 80%), the authentication means 15 authenticates the user. As mentioned above, the memory 16 stores pre-registered user identification information and identification information for imaging units 30A, 30B, and 30C, along with the feature quantities of the user's face image, in association with each other.
[0036] Then, when the user is authenticated by the authentication means 15 ("YES" in STEP 35), information relating to the authentication result is transmitted from the processor 12 of the authentication system 10 to the imaging units 30A, 30B, and 30C via the communication unit 18 (STEP 36). Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C enable the respective processing units 40A, 40B, and 40C to perform the services corresponding to these imaging units 30A, 30B, and 30C (STEP 37). Subsequently, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit information relating to the service usage status to the authentication system 10. As a result, information relating to the service usage status at each service provider is stored in the memory 16 for each user in the authentication system 10.
[0037] On the other hand, if the feature quantities of the user's face image received from the imaging units 30A, 30B, and 30C do not substantially match the feature quantities of the user's face image stored in the memory 16, and the authentication means 15 is unable to authenticate the user ("NO" in STEP 35), information relating to the authentication result is transmitted from the processor 12 of the authentication system 10 to the imaging units 30A, 30B, and 30C via the communication unit 18 (STEP 38). Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C, respectively, disable the service corresponding to these imaging units 30A, 30B, and 30C via their respective processing units 40A, 40B, and 40C (STEP 39). In this case as well, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit information regarding the service usage status (specifically, information that the user attempted to authenticate with the imaging units 30A, 30B, and 30C but was not authenticated and therefore could not use the service) to the authentication system 10.
[0038] With this authentication method, even if the feature quantities of a user's face image are registered in the imaging engine of one service provider (e.g., imaging unit 30A) but not in the imaging engine of another service provider (e.g., imaging unit 30B), the authentication system 10's memory 16 stores these feature quantities in association with the identification information of imaging units 30A, 30B, and 30C. This allows the service provider whose facial image feature quantities are not registered to authenticate the user by capturing the user's face image with its imaging unit. In this case, the user does not need to register their face image data with all of the imaging units, thus saving the user time and effort.
[0039] Furthermore, other examples of the authentication system 10 and authentication method according to this embodiment will be explained with reference to Figures 7 to 9. Note that for the authentication system 10 and each imaging unit 30A, 30B, and 30C shown in Figure 7, the same reference numerals are used for components that are the same as those shown in the authentication system 10 and each imaging unit 30A, 30B, and 30C in Figures 1 and 4, and their explanations will be omitted.
[0040] As shown in Figure 7, the processor 12 of the authentication system 10 includes a feature extraction means 14 that extracts feature quantities of the user's face image corresponding to each imaging unit 30A, 30B, and 30C as hash values based on face image data received from the user terminal 20, a registration means 13 that registers the extracted feature quantities of the user's face image, and an authentication means 15 that authenticates the user based on the feature quantities (specifically, hash values) of the user's face image captured by the imaging units 38A to 38C of each imaging unit 30A, 30B, and 30C. The processor 12 executes a program stored in the memory 16 so that the registration means 13 stores the feature quantities (specifically, hash values) of the user's face image extracted by the feature extraction means 14 in the memory 16, associating them with the user's identification information and the identification information of the imaging units 30A, 30B, and 30C. Furthermore, the processor 12 executes a program stored in the memory 16, thereby enabling the authentication means 15 to authenticate the user by comparing the feature quantities (specifically, hash values) of the user's face images captured by the imaging units 38A to 38C of each imaging unit 30A, 30B, and 30C with the feature quantities (specifically, hash values) of the user's face images corresponding to each imaging unit 30A, 30B, and 30C stored in the memory 16. Note that the program executed by the processor 12 is not limited to those stored in the memory 16. The processor 12 may execute a program transmitted from an external device to the authentication system 10, or a program stored on a recording medium detachably attached to the authentication system 10, thereby performing processing in the feature quantity extraction means 14, the registration means 13, and the authentication means 15, respectively. In this embodiment as well, the feature quantity extraction means 14 and the registration means 13 constitute the information acquisition means 17. The information acquisition means 17 receives the user's face image data when the user is registered, extracts feature quantities from the user's face image data based on the received user's face image data, and stores the information related to the extracted feature quantities of the user's face image in the memory 16 as the user's identification information.
[0041] Each imaging unit 30A, 30B, and 30C, deployed at each service organization, is composed of, for example, a computer. Each imaging unit 30A, 30B, and 30C includes a processor such as a CPU 32A, 32B, and 32C, memory 36A, 36B, and 36C, imaging unit 38A, 38B, and 38C, processing unit 40A, 40B, and 40C, and communication unit 42A, 42B, and 42C. In the example shown in Figure 7, the processors 32A, 32B, and 32C do not have the feature extraction means 34A, 34B, and 34C and authentication means 35A, 35B, and 35C as shown in Figure 1. Also, in the example shown in Figure 7, the memory 36A, 36B, and 36C do not store the feature quantities of the user's face image.
[0042] In the example shown in Figure 7, the authentication system 10 and the imaging units 30A, 30B, and 30C deployed at each service organization are connected via API (Application Programming Interface). This makes it easier to configure the systems of each imaging unit 30A, 30B, and 30C compared to configuring each system independently.
[0043] Next, the process of authenticating a user using the authentication system 10 and each imaging unit 30A, 30B, and 30C as shown in Figure 7 will be explained with reference to Figures 8 and 9.
[0044] First, we will explain the process by which a user registers facial image data with the authentication system 10 using the user terminal 20. Note that the specific method by which the user captures facial images with the user terminal 20 has already been explained and will be omitted here. When a user first registers using such a facial recognition application on the user terminal 20, various information entered on the user registration screen and the user's facial image data are sent from the user terminal 20 to the authentication system 10. In this way, the processor 12 of the authentication system 10 receives the facial image data from the user terminal 20 (STEP 41). The processor 12 of the authentication system 10 also receives the identification information of the user terminal 20, as well as registration information such as the user's name, date of birth, telephone number, email address, and password entered on the user terminal 20. The processor 12 also issues a user ID as the user's identification information and stores this issued user ID in memory 16.
[0045] Next, the processor 12 of the authentication system 10 extracts the feature quantities of the face images corresponding to each imaging unit 30A, 30B, and 30C as hash values using the feature extraction means 14, based on the face image data received from the user terminal 20 (STEP 42). At this time, the feature quantities of the user's face image extracted by the feature extraction means 14 may differ depending on the type of imaging unit 30A, 30B, and 30C, and the feature extraction means 14 extracts the feature quantities of the user's face image for each imaging unit 30A, 30B, and 30C. Furthermore, the feature extraction means 14 extracts only the feature quantities of the user's face image corresponding to the imaging unit 30A, 30B, and 30C of the service organization that has been selected in advance by the user. Then, the processor 12 stores the feature quantities of the face images corresponding to each imaging unit 30A, 30B, and 30C extracted by the feature quantity extraction means 14 in the memory 16 of the authentication system 10, associating them with the user ID (user identification information) and the identification information of the imaging units 30A, 30B, and 30C (STEP 43) via the registration means 13. In this way, the registration of the user's face image captured by the user terminal 20 is completed. Note that in the example shown in Figure 7, the information relating to the feature quantities of the user's face image stored in the memory 16 is not transmitted from the authentication system 10 to the imaging units 30A, 30B, and 30C of the service organization selected by the user.
[0046] Next, the process for user authentication in each imaging unit 30A, 30B, and 30C will be described. When user authentication is required at a service organization where each imaging unit 30A, 30B, and 30C is installed, first, the user's face image data is acquired by imaging the user using the imaging units 38A, 38B, and 38C of the imaging units 30A, 30B, and 30C (STEP 51). The processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit the user's face image data captured by the imaging units 38A, 38B, and 38C to the processor 12 of the authentication system 10 via the communication units 42A, 42B, and 42C (STEP 52). Furthermore, when the processor 12 of the authentication system 10 receives user face image data from the imaging units 30A, 30B, and 30C, it receives user face image data transmitted only from the imaging units 30A, 30B, and 30C of the service organization selected by the user, which is stored in the memory 16. Then, in the authentication system 10, the processor 12 uses the feature extraction means 14 to extract the features of the user's face image as hash values based on the face image data received from the imaging units 30A, 30B, and 30C (STEP 53). The processor 12 then uses the authentication means 15 to compare the features of the user's face image extracted by the feature extraction means 14 (specifically, hash values) with the features of the user's face image stored in the memory 16 (specifically, hash values) to authenticate the user (STEP 54). More specifically, if the matching rate between the features of the user's face image extracted by the feature extraction means 14 and the features of the user's face image stored in the memory 16 exceeds a predetermined threshold (for example, 80%), the authentication means 15 authenticates the user. As mentioned above, the memory 16 stores pre-registered user identification information and identification information of imaging units 30A, 30B, and 30C, along with the features of the user's face image, in association with each other.
[0047] Then, when the user is authenticated by the authentication means 15 ("YES" in STEP 55), information relating to the authentication result is transmitted from the processor 12 of the authentication system 10 to the imaging units 30A, 30B, and 30C via the communication unit 18 (STEP 56). Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C enable the respective processing units 40A, 40B, and 40C to perform the services corresponding to these imaging units 30A, 30B, and 30C (STEP 57). Subsequently, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit information relating to the service usage status to the authentication system 10. As a result, information relating to the service usage status at each service provider is stored in the memory 16 for each user in the authentication system 10.
[0048] On the other hand, if the feature quantities of the user's face image received from the imaging units 30A, 30B, and 30C do not substantially match the feature quantities of the user's face image stored in the memory 16, and the authentication means 15 is unable to authenticate the user ("NO" in STEP 55), information relating to the authentication result is transmitted from the processor 12 of the authentication system 10 to the imaging units 30A, 30B, and 30C via the communication unit 18 (STEP 58). Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C, respectively, disable the service corresponding to these imaging units 30A, 30B, and 30C via their respective processing units 40A, 40B, and 40C (STEP 59). In this case as well, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit information regarding the service usage status (specifically, information that the user attempted to authenticate with the imaging units 30A, 30B, and 30C but was not authenticated and therefore could not use the service) to the authentication system 10.
[0049] With this authentication method, even if the feature quantities of a user's face image are registered in the imaging engine of one service provider (e.g., imaging unit 30A) but not in the imaging engine of another service provider (e.g., imaging unit 30B), the authentication system 10's memory 16 stores these feature quantities in association with the identification information of imaging units 30A, 30B, and 30C. This allows the service provider whose facial image feature quantities are not registered to authenticate the user by capturing the user's face image with its imaging unit. In this case, the user does not need to register their face image data with all of the imaging units, thus saving the user time and effort.
[0050] Next, we will explain the process when a user wants to add more service providers to which the facial recognition service described above applies in the authentication system 10 shown in Figures 1 to 9. After the user has completed the user registration described above, when the user presses the "Add Service" button on the initial screen of the user terminal 20 shown in Figure 10, a list of service providers shown in Figure 13 is displayed. This list of service providers is pre-registered in the authentication system 10. On the screen shown in Figure 13, the icons for unregistered services and registered services are displayed in different colors, or the icons for unregistered services are displayed faintly, thus distinguishing between the icons for unregistered services and registered services. When the user presses the icon for an unregistered service, the terms and conditions of the service to be added are displayed. When the user enters an instruction to agree to the terms and conditions of the service, the unregistered service becomes a registered service. At this time, in the authentication system 10, the service provider associated with this registered service is linked to the user ID (user identification information) and stored in memory 16. After that, the user terminal 20 displays a screen for capturing a facial image, as shown in Figure 12. When a user captures a facial image using the user terminal 20 on such an imaging screen, the user's facial image data is transmitted from the user terminal 20 to the authentication system 10. In this way, the processor 12 of the authentication system 10 receives the facial image data from the user terminal 20. The processor 12 then uses the feature extraction means 14 to extract the facial image features corresponding to the imaging unit of the new service provider as hash values based on the facial image data received from the user terminal 20. The processor 12 stores the facial image features corresponding to the new imaging unit extracted by the feature extraction means 14 in the memory 16 of the authentication system 10, associating them with the user ID (user identification information) and the identification information of the imaging unit of the new service provider, using the registration means 13. In this way, the registration of the new service provider is completed.Furthermore, as will be described later, if the user's face image data is stored in memory 16, when the user registers a new service provider using the user terminal 20, the user terminal 20 does not need to capture the user's face image. Instead, the feature quantity extraction means 14 may extract the feature quantities of the face image corresponding to the imaging unit of the new service provider as a hash value based on the user's face image data stored in memory 16. In addition, the screen shown in Figure 13 may allow the user to delete registered services. In this case, the registered service becomes an unregistered service. Also, the information related to the feature quantities of the user's face image corresponding to the imaging unit of the service provider related to the deleted registered service, which is stored in memory 16, is deleted.
[0051] Furthermore, after the user has completed the user registration described above, when the user presses the "Authentication History" button on the initial screen of the user terminal 20 as shown in Figure 10, a list of past authentication history information (in other words, a list of information related to the user's usage of the service provider) will be displayed on the user terminal 20 as shown in Figure 14. More specifically, the user's past authentication history information is stored in the memory 16 of the authentication system 10, associated with the user's identification information. When the user presses the "Authentication History" button on the initial screen of the user terminal 20 as shown in Figure 10, a signal is sent from the user terminal 20 to the processor 12 of the authentication system 10 requesting the user's past authentication history information. When the processor 12 of the authentication system 10 receives the signal from the user terminal 20 requesting the user's past authentication history information, it sends the past authentication history information corresponding to the user's identification information stored in the memory 16 to the user terminal 20 via the communication unit 18. As a result, the user terminal 20 will display a list of the user's past authentication history information. Furthermore, in the list of past authentication history information shown in Figure 14, when a user taps on a particular authentication history entry, the user terminal 20 will display the details of that authentication history, as shown in Figure 15.
[0052] Furthermore, in this embodiment, instead of the user registering the user's facial recognition features in the authentication system 10 using the user terminal 20, the user may register the user's facial recognition features in the authentication system 10 using certain imaging units 30A, 30B, and 30C. Specifically, when the user inputs registration information into certain imaging units 30A, 30B, and 30C and the imaging units 38A, 38B, and 38C capture an image of the user's face, the input registration information and the user's facial image data are transmitted from the imaging units 30A, 30B, and 30C to the authentication system 10. In this way, the processor 12 of the authentication system 10 receives the facial image data from the imaging units 30A, 30B, and 30C. The processor 12 also issues a user ID as user identification information based on the registration information received from the imaging units 30A, 30B, and 30C, and stores this issued user ID in the memory 16.
[0053] Next, the processor 12 of the authentication system 10 extracts the feature quantities of the face images corresponding to each imaging unit 30A, 30B, and 30C as hash values using the feature extraction means 14, based on the face image data received from the imaging units 30A, 30B, and 30C. In this process, the feature extraction means 14 extracts the feature quantities of the user's face image for each imaging unit 30A, 30B, and 30C. Furthermore, the feature extraction means 14 extracts only the feature quantities of the user's face image corresponding to the imaging unit 30A, 30B, and 30C of the service organization pre-selected by the user. For example, if the user has authorized the use of face image data for the service organization where imaging unit 30A is installed, but has not authorized the use of face image data for the service organization where imaging unit 30B is installed, the feature extraction means 14 extracts only the feature quantities of the user's face image corresponding to imaging unit 30A. As described above, the memory 16 stores the user's identification information and the service organization selected by this user in association with each other. The processor 12 then uses the registration means 13 to store the feature quantities of the face images corresponding to each imaging unit 30A, 30B, and 30C extracted by the feature quantity extraction means 14 in the memory 16 of the authentication system 10, associating them with the user ID (user identification information) and the identification information of the imaging units 30A, 30B, and 30C. In this way, the registration of the user's face images captured by the imaging units 38A, 38B, and 38C of the imaging units 30A, 30B, and 30C is completed. In this configuration, the user can register the feature quantities of their face authentication in the authentication system 10 without using the user terminal 20.
[0054] According to the authentication method performed by the authentication system 10 of this embodiment, which has the configuration described above, the system receives the user's face image data and user identification information, and extracts the feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, and 30C based on the received user's face image data. Then, the information relating to the extracted feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, and 30C is stored in the memory 16 in association with the received user identification information. With such an authentication method, face authentication can be easily performed using multiple imaging units 30A, 30B, and 30C.
[0055] Specifically, while it is common practice to use facial recognition-based authentication engines, conventional authentication systems could not perform facial recognition if the authentication engine did not have registered facial data. Therefore, in order to perform authentication with multiple authentication engines, users had to register their facial data with each of them, which was time-consuming and stressful. In contrast, in this embodiment, even if the feature quantities of a user's facial image are registered with one service provider's authentication engine (e.g., imaging unit 30A) but not with another service provider's authentication engine (e.g., imaging unit 30B), the authentication system 10's memory 16 stores these feature quantities for each imaging unit 30A, 30B, and 30C. This allows the imaging unit 38A, 38B, and 38C of a service provider where the user's facial image feature quantities are not registered to capture the user's facial image and perform user authentication. In this case, the user does not need to register facial image data with all of the imaging units 30A, 30B, and 30C, thus saving the user time and effort. This makes it easier to encourage users who previously used various services that utilized imaging units without registered facial image data, as registering facial image data was cumbersome, to use these services.
[0056] Furthermore, when extracting feature quantities of the user's face image, such as hash values, and storing them in memory 16, the amount of data stored in memory 16 can be significantly reduced compared to when the user's face image data itself is stored in memory 16. This is because the amount of data for the feature quantities of the user's face image is smaller compared to the amount of data for the user's face image data itself. Also, in this case, since the user's face image data itself is not stored in memory 16, the user's privacy can be protected even more reliably. In addition, when sending information related to the feature quantities of the user's face image between the authentication system 10 and each imaging unit 30A, 30B, and 30C, the amount of data communication can be significantly reduced compared to when the user's face image data is sent between the authentication system 10 and each imaging unit 30A, 30B, and 30C.
[0057] Furthermore, in the authentication method of this embodiment, as described above, when extracting the feature quantities of the user's face image based on the received user's face image data, the feature quantities of the user's face image are extracted for each of the multiple imaging units 30A, 30B, and 30C, and the extracted feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, and 30C are stored in memory in association with the user's identification information by the registration means 13. At this time, it is possible to handle cases where the feature quantities of the user's face image extracted by the feature quantity extraction means 14 differ depending on the type of imaging unit 30A, 30B, and 30C. Note that if the same program is used for the multiple imaging units 30A, 30B, and 30C, and the feature quantities of the user's face image extracted by the feature quantity extraction means 14 are common to all imaging units 30A, 30B, and 30C, it is not necessary to extract the feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, and 30C.
[0058] Furthermore, in the authentication method of this embodiment, as described above, the memory 16 stores information related to the service provider selected by the user, associated with the user's identification information. In the process of extracting the feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, and 30C based on the received user's face image data, the feature quantity extraction means 14 extracts the feature quantities of the user's face image corresponding only to the imaging unit of the service provider selected by the user, which is stored in the memory 16. In this case, the feature quantities of the user's face image corresponding to the imaging units 30A, 30B, and 30C of service providers not selected by the user are not stored in the memory 16, thus improving security and reassuring the user. In addition, companies participating in the group of authentication engines managed comprehensively by the authentication system 10 can appeal to customers with improved customer convenience, as they can be authenticated by multiple authentication engines simply by registering face image data on the user terminal 20, etc.
[0059] Furthermore, in the authentication method of this embodiment, as described above, the feature extraction means 14 extracts a hash value obtained from the received user's face image data using a predetermined hash function as a feature of the user's face image for each of the multiple imaging units 30A, 30B, and 30C. In this case, since the hash value is stored in the memory 16 as a feature of the user's face image, the amount of data stored in the memory 16 can be reduced compared to the case where the face image data itself is stored in the memory 16. In addition, it is difficult to reconstruct or infer the face image data from the hash value, and since the authentication system 10 stores only the hash value, the privacy and security of the user can be enhanced.
[0060] In this embodiment, the feature extraction means 14 is not limited to extracting the features of the user's face image as hash values for each of the multiple imaging units 30A, 30B, and 30C based on the received user's face image data. The feature extraction means 14 may also extract the features of the user's face image as values of a different type than hash values for each of the multiple imaging units 30A, 30B, and 30C based on the received user's face image data. For example, the features of the user's face image may include the relative position, size, and shape of each part of the face (eyes, nose, ears, etc.). Even in this case, if the amount of data of the value of a different type than hash values is less than the amount of data of the face image itself, the amount of data stored in the memory 16 can be reduced.
[0061] Furthermore, in the authentication method of this embodiment, as described above, in the step of extracting the feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, 30C based on the received user's face image data, the feature quantities of the user's face image are extracted for each of the multiple imaging units 30A, 30B, 30C based on the user's face image data transmitted from the user terminal 20 held by the user. Alternatively, in the step of extracting the feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, 30C based on the received user's face image data, the feature quantities of the user's face image may be extracted for each of the multiple imaging units 30A, 30B, 30C based on the user's face image data transmitted from one of the multiple imaging units 30A, 30B, 30C.
[0062] Furthermore, in this embodiment, a program for performing an authentication method by the authentication system 10, executed by the processor 12, and a recording medium on which this program is stored are used. Here, when the processor 12 executes the program, it receives the user's face image data and the user's identification information, and extracts the feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, and 30C based on the received user's face image data. Then, the information relating to the extracted feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, and 30C is stored in the memory 16 in association with the received user's identification information. With such a program and recording medium, face authentication can be easily performed with multiple imaging units 30A, 30B, and 30C.
[0063] Furthermore, in this embodiment, an authentication system 10 equipped with a processor 12 is used. In such an authentication system 10, the processor 12 receives the user's face image data and user identification information by executing a program, and extracts the feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, and 30C based on the received user's face image data. Then, the information relating to the extracted feature quantities of the user's face image for each of the multiple imaging units 30A, 30B, and 30C is stored in the memory 16 in association with the received user identification information. With such an authentication system 10, face authentication can be easily performed using multiple imaging units 30A, 30B, and 30C.
[0064] Furthermore, the authentication method and authentication system according to the present invention are not limited to the embodiments described above, and can be modified in various ways.
[0065] For example, an authentication system like the one shown in Figure 16 may be used. The authentication system 50 shown in Figure 16 includes a processor 52, a first server 56, a second server 58, and a third server 60. Here, each server 56, 58, and 60 corresponds to each imaging unit 30A, 30B, and 30C. Specifically, the first server 56 corresponds to imaging unit 30A, the second server 58 corresponds to imaging unit 30B, and the third server 60 corresponds to imaging unit 30C. Although three imaging units 30A, 30B, and 30C are shown in Figure 16, if two or more imaging units are used, a server corresponding to each imaging unit is provided in the authentication system 10. The processor 52 also includes a server management means 52a, a feature extraction means 54, a registration means 53, and an authentication means 55. The feature extraction means 54, registration means 53, and authentication means 55 of the processor 52 have substantially the same functions as the feature extraction means 14, registration means 13, and authentication means 15 of the processor 12 of the authentication system 10 shown in Figures 1, 4, and 7. The server management means 52a is configured to manage each of the servers 56, 58, and 60.
[0066] Each server 56, 58, and 60 stores feature quantities of user face image data corresponding to each imaging unit 30A, 30B, and 30C, associated with the user's identification information. Furthermore, each server 56, 58, and 60 is communicably connected to the corresponding imaging units 30A, 30B, and 30C via a network such as the Internet. Each server 56, 58, and 60 is configured to be centrally managed via an API (Application Programming Interface) by the server management means 52a. This makes it easier to configure the systems (programs) of each server 56, 58, and 60 compared to configuring each server's system (program) independently. Additionally, the server management means 52a and the service organizations where each imaging unit 30A, 30B, and 30C are installed are linked via API. For example, by opening the platform of the server management means 52a to each service organization and allowing each service organization to use the same platform as the server management means 52a, systems for providing services at each service organization can be easily constructed.
[0067] An authentication system 50 having such a processor 52 and servers 56, 58, and 60 can perform the same processing as an authentication system 10 having a processor 12. That is, according to the authentication method performed by the authentication system 50 shown in Figure 16, the processor 52 extracts the feature quantities of the user's face image from the received user's face image data using a feature quantity extraction means 54 for each imaging unit 30A, 30B, and 30C, and stores the extracted feature quantities of the user's face image in each server 56, 58, and 60 in association with the user's identification information and imaging units 30A, 30B, and 30C using a registration means 53.
[0068] Furthermore, information relating to the feature quantities of the user's face image stored in each server 56, 58, and 60 is transmitted from each server 56, 58, and 60 to the corresponding imaging units 30A, 30B, and 30C. As a result, when each imaging unit 30A, 30B, and 30C performs user authentication, the imaging units 38A, 38B, and 38C capture the user to obtain the user's face image data, and the feature quantity extraction means 34A, 34B, and 34C extract the feature quantities of the user's face image based on the acquired face image data, thereby enabling each imaging unit 30A, 30B, and 30C to perform user authentication. Subsequently, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit information relating to the service usage status to the authentication system 10. As a result, the authentication system 50 stores information relating to the service usage status at each service provider in each server 56, 58, and 60 for each user.
[0069] Another method for user authentication is performed by each imaging unit 30A, 30B, and 30C. When user authentication is performed, the imaging units 38A, 38B, and 38C capture images of the user to acquire the user's facial image data, and the feature extraction means 34A, 34B, and 34C extract the features of the user's facial image based on the acquired facial image data. Then, information related to the features of the user's facial image is transmitted from each imaging unit 30A, 30B, and 30C to the authentication system 50. This enables the authentication means 55 to authenticate the user. Subsequently, the user authentication result is transmitted from the authentication system 50 to the original imaging units 30A, 30B, and 30C.
[0070] As yet another method of user authentication, when each imaging unit 30A, 30B, and 30C performs user authentication, it acquires user face image data by imaging the user using the imaging units 38A, 38B, and 38C. Then, the user's face image data is transmitted from each imaging unit 30A, 30B, and 30C to the authentication system 50. The processor 52 then uses the feature extraction means 54 to extract the feature quantities of the user's face image based on the user's face image data transmitted to each server 56, 58, and 60, and the authentication means 55 compares the extracted feature quantities of the user's face image with the feature quantities of the user's face image stored in each server 56, 58, and 60. This enables the authentication means 55 to authenticate the user. After that, the user authentication result is transmitted from the authentication system 50 to the original imaging units 30A, 30B, and 30C.
[0071] These authentication methods make it easy to perform facial recognition using multiple imaging units 30A, 30B, and 30C.
[0072] Furthermore, in the authentication system 10 shown in Figures 1, 4, and 7, the processor 12 may store the user's face image data itself, transmitted from the user terminal 20 and each imaging unit 30A, 30B, and 30C, in the memory 16.
[0073] Furthermore, although the above example shows an arrangement in which authentication systems 10 and 50 are installed separately from the imaging units 30A, 30B, and 30C installed at each service organization, one of the imaging units 30A, 30B, and 30C installed at each service organization may also perform the functions of authentication systems 10 and 50. That is, the processor of one of the imaging units 30A, 30B, and 30C installed at each service organization may have feature extraction means, registration means, and authentication means that have functions equivalent to the feature extraction means 14, registration means 13, and authentication means 15 in the processor 12 of authentication system 10 shown in Figures 1, 4, and 7.
[0074] As yet another example, the authentication system 10 may perform two-step user authentication (two-factor authentication) by using the user's facial image data features extracted from the user's facial image data (specifically, for example, a hash value) and other elements besides the user's facial image features (specifically, for example, a password entered into the user terminal 20 during user registration or identification information of the user terminal 20). In this case, the elements required for authentication may be combined according to the security level required for the imaging units 30A, 30B, and 30C of the service organization.
[0075] Furthermore, in the above description, when a user registers facial image data with the authentication system 10 using the user terminal 20, the user enters registration information such as name, date of birth, telephone number, email address, and password on the user registration screen, checks the box to agree to the terms of service, and then presses the registration button. When the user captures a facial image with the user terminal 20 on the imaging screen, various information entered on the user registration screen and the user's facial image data are transmitted from the user terminal 20 to the authentication system 10. Subsequently, the processor 12 issues a user ID as user identification information and stores this issued user ID in the memory 16. However, this embodiment is not limited to this configuration. In another configuration, the feature quantities of the user's facial image data (specifically, hash values, for example) extracted from the user's facial image data by the feature quantity extraction means 14 for each imaging unit 30A, 30B, and 30C may be used as the user ID. In this case, each imaging unit 30A, 30B, and 30C has a different user ID (i.e., a hash value), but the processor 12 of the authentication system 10 is configured to link multiple different user IDs for the same user across imaging units 30A, 30B, and 30C.
[0076] Furthermore, the processor 12 of the authentication system 10 may link a user ID issued as user identification information after receiving various information entered on the user registration screen and the user's facial image data with a user ID (user identification information) used by the authentication engine 30D of various service organizations that perform authentication other than facial recognition. In other words, the authentication system 10 may further include a linking means 19 that links a user ID (user identification information) used by the authentication engine 30D of service organizations that perform authentication other than facial recognition with a user ID (user identification information) related to the feature quantities of the user's facial image stored in memory 16. Specifically, the user ID used by the authentication engine 30D of various service organizations that perform authentication other than facial recognition could be identification information of the user terminal 20 such as a smartphone owned by the user, user identification information obtained from biometric information such as the user's fingerprint information or vein information (for example, a hash value), or a multi-digit code (specifically, a combination of numbers and Roman letters) or password entered by the user into the user terminal 20 such as a smartphone. In this case, when a user authenticates using the authentication engine 30D of various service providers that perform authentication other than facial recognition, a user ID based on the user's facial image data obtained by capturing a facial image with the user terminal (specifically, a hash value extracted from the facial image data) can be used as a substitute, thereby improving convenience for the user. Furthermore, even after linking by the linking means 19, the user ID used by the service provider's authentication engine 30D may be retained. In this case, user authentication can be properly performed even when user authentication is performed standalone using the service provider's authentication engine 30D without using the cloud-based authentication system 10.
[0077] Furthermore, different levels of authentication may be set depending on the type of service provider. Specifically, for example, if the locking system of the office building or home where the user works is used as the authentication engine for the service provider, a so-called smart lock is used that unlocks the door based on the identification information of the user terminal 20, such as a smartphone. Specifically, by simply bringing the user terminal 20 close to the door of the locking system in the office building or home where the user works, or to a receiving device installed nearby, the user terminal 20's identification information is read via Bluetooth® functionality, or the user inputs a command to unlock the door using a smart lock app installed on the user terminal 20, and the user is authenticated based on the identification information of the user terminal 20. Once authentication confirms that the user is a pre-registered user, the door of the office building or home where the user works is unlocked. On the other hand, if a bank account transfer system or payment system is used as the authentication engine for the service provider, facial recognition is required when logging into the financial institution service or payment service on the user terminal 20, and in addition to facial recognition, authentication via SMS (Short Message Service) delivery or password entry is required when transferring money to an account or making a payment. In this way, by varying the authentication strength of user IDs according to their purpose, it is possible to improve user convenience by lowering the authentication strength for frequently used service providers' authentication engines, and to improve security by increasing the authentication strength for service providers that handle money, etc.
[0078] Furthermore, the user may be able to add or remove service providers that perform authentication other than facial recognition, in addition to the service providers related to facial recognition, using the user terminal 20 on a screen such as the one shown in Figure 13. That is, in addition to the list of service providers related to facial recognition, a list of service providers that perform authentication other than facial recognition is also registered in the authentication system 10 in advance. When the user registers an unregistered service on the screen of the user terminal 20 as shown in Figure 13, the user ID used in the authentication engine of the newly registered service provider is stored in memory 16. At this time, the user IDs of other service providers already stored in memory 16 and the user ID used in the authentication engine of the newly registered service provider (for example, the identification information of the user terminal 20, or a multi-digit code or password entered by the user when registering a new service provider) are linked by the linking means 19. In this case, when a service provider that performs authentication other than facial recognition is newly registered, the user ID based on the user's facial image data obtained by capturing a facial image with the user terminal (specifically, a hash value extracted from the facial image data) can be used as a substitute when the user performs authentication with the authentication engine of this service provider, thereby improving convenience for the user. In addition, as shown in the screen in Figure 13, if a service provider that performs authentication other than facial recognition is already registered, this registered service can be deleted. In this case, the registered service becomes an unregistered service. Also, the user ID corresponding to the authentication engine of the service provider related to the deleted registered service, which is stored in memory 16, is deleted.
[0079] According to the authentication system 10 in the manner described above, the authentication system 10 shown in Figures 4 to 6 and the authentication system 10 shown in Figures 7 to 9 includes: an information acquisition means 17 that, when registering a user, receives the user's face image data from the user terminal, extracts the feature quantities of the user's face image based on the received user's face image data, and stores the information related to the extracted feature quantities of the user's face image in the memory 16 as the user's identification information; an authentication means 15 that, when authenticating a user, authenticates the user by comparing the feature quantities of the user's face image extracted from the user's face image data received from the service organization's imaging units 30A, 30B, and 30C, or the feature quantities of the user's face image received from the imaging units 30A, 30B, and 30C, with the feature quantities of the user's face image stored in the memory 16; and a linking means 19 that links the user's identification information used by the service organization's authentication engine 30D, which performs authentication other than face authentication, with the user's identification information related to the feature quantities of the user's face image stored in the memory 16. According to this authentication system 10, convenience can be improved by using the registered facial image data (specifically, the feature quantities of the user's facial image) in the authentication engine 30D that performs authentication other than facial recognition.
[0080] Furthermore, in the authentication system 10 shown in Figures 1 to 3, the authentication system 10 includes an information acquisition means 17 that, upon user registration, receives the user's facial image data from the user terminal, extracts the feature quantities of the user's facial image based on the received facial image data, and stores the information related to the extracted feature quantities of the user's facial image in memory 16 as the user's identification information; a communication unit 18 as a transmission means that transmits the information related to the feature quantities of the user's facial image stored in memory 16 to the imaging units 30A, 30B, and 30C of each service organization in order to perform authentication based on the user's facial image; and a linking means 19 that links the user's identification information used by the authentication engine 30D of the service organization that performs authentication other than facial recognition with the user's identification information related to the feature quantities of the user's facial image stored in memory 16. Even in such an authentication system 10, convenience can be improved by using the registered facial image data (specifically, the feature quantities of the user's facial image) in the authentication engine 30D that performs authentication other than facial recognition.
[0081] Furthermore, in the authentication system 10 of this embodiment, the user identification information used by the authentication engine 30D of the service organization that performs authentication other than facial recognition includes at least one of the following: identification information of the user terminal possessed by the user, information obtained from biometric information other than the user's face, and a code or password entered by the user into the user terminal.
[0082] Furthermore, in the authentication system 10 of this embodiment, when the user terminal receives an instruction to add an authentication engine of a service organization, the linking means 19 links the user identification information used for authentication by the added service organization's authentication engine with the user identification information related to the feature quantities of the user's face image stored in the memory 16.
[0083] Furthermore, in the authentication system 10 of this embodiment, even after the user identification information is linked by the linking means 19, the user identification information used by the authentication engine of each service provider remains unchanged.
[0084] Furthermore, the authentication system 10 shown in Figures 4 to 6 and the information processing method by the authentication system 10 shown in Figures 7 to 9 include the following steps: when registering a user, the system receives the user's face image data from the user terminal 20, extracts the feature quantities of the user's face image based on the received user's face image data, and stores the information related to the extracted feature quantities of the user's face image as user identification information in the memory 16; when authenticating a user, the system authenticates the user by comparing the feature quantities of the user's face image extracted from the user's face image data received from the service organization's imaging units 30A, 30B, and 30C, or the feature quantities of the user's face image received from the service organization's imaging units 30A, 30B, and 30C, with the feature quantities of the user's face image stored in the memory 16; and the system links the user identification information used by the service organization's authentication engine 30D, which performs authentication other than face authentication, with the user identification information related to the feature quantities of the user's face image stored in the memory 16. This information processing method allows for improved convenience by using the registered facial image data (specifically, the feature quantities of the user's facial image) in the authentication engine 30D, which performs authentication other than facial recognition.
[0085] Furthermore, the information processing method of the authentication system 10 shown in Figures 1 to 3 includes the steps of: receiving the user's face image data from the user terminal 20 during user registration, extracting the feature quantities of the user's face image based on the received face image data, and storing the information related to the extracted feature quantities of the user's face image in memory 16 as the user's identification information; transmitting the information related to the feature quantities of the user's face image stored in memory 16 to the imaging units 30A, 30B, and 30C of each service organization in order to perform authentication based on the user's face image; and linking the user's identification information used by the authentication engine 30D of the service organization that performs authentication other than face recognition with the user's identification information related to the feature quantities of the user's face image stored in memory 16. Even with such an information processing method, convenience can be improved by using the registered face image data (specifically, the feature quantities of the user's face image) in the authentication engine 30D that performs authentication other than face recognition.
[0086] As yet another example, the authentication system 10 shown in Figure 17 may be used. For the authentication system 10 and each imaging unit 30A, 30B, and 30C shown in Figure 17, the same reference numerals are used for components that are the same as those shown in the authentication system 10 and each imaging unit 30A, 30B, and 30C shown in Figures 1, 4, and 7, and their explanations are omitted.
[0087] As shown in Figure 17, the processor 12 of the authentication system 10 includes a registration means 13 for registering face image data received from the user terminal 20, and an authentication means 15 for authenticating the user based on the user's face image data captured by the imaging units 38A to 38C of each imaging unit 30A, 30B, and 30C. The processor 12 executes a program stored in the memory 16 to store the user's face image data registered in the registration means 13 in the memory 16, associating it with the user's identification information and the identification information of the imaging units 30A, 30B, and 30C. Furthermore, the processor 12 executes a program stored in the memory 16 to enable the authentication means 15 to authenticate the user by comparing the user's face image data captured by the imaging units 38A to 38C of each imaging unit 30A, 30B, and 30C with the user's face image data stored in the memory 16. Note that the program executed by the processor 12 is not limited to those stored in the memory 16. The processor 12 may execute a program transmitted from an external device to the authentication system 10, or a program stored on a recording medium detachably attached to the authentication system 10, thereby performing processing in the registration means 13 and the authentication means 15, respectively. In this embodiment, the registration means 13 constitutes the information acquisition means 17. The information acquisition means 17 receives the user's face image data during user registration and stores the received user face image data in the memory 16 as the user's identification information.
[0088] Each imaging unit 30A, 30B, and 30C, which is deployed at each service organization, is composed of, for example, a computer, and each imaging unit 30A, 30B, and 30C has a processor such as a CPU 32A, 32B, and 32C, memory 36A, 36B, and 36C, an imaging unit 38A, 38B, and 38C, a processing unit 40A, 40B, and 40C, and a communication unit 42A, 42B, and 42C.
[0089] In the example shown in Figure 17, the authentication system 10 and the imaging units 30A, 30B, and 30C deployed at each service organization are connected via API (Application Programming Interface). This makes it easier to configure the systems of each imaging unit 30A, 30B, and 30C compared to configuring each system independently.
[0090] Next, we will briefly explain the process of user authentication performed by the authentication system 10 and each imaging unit 30A, 30B, and 30C as shown in Figure 17.
[0091] First, we will explain the process by which a user registers facial image data with the authentication system 10 using the user terminal 20. Note that the specific method by which the user captures facial images with the user terminal 20 has already been explained and will be omitted here. When a user first registers using such a facial recognition application on the user terminal 20, various information entered on the user registration screen and the user's facial image data are sent from the user terminal 20 to the authentication system 10. In this way, the processor 12 of the authentication system 10 receives the facial image data from the user terminal 20. The processor 12 of the authentication system 10 also receives the identification information of the user terminal 20, as well as registration information such as the user's name, date of birth, telephone number, email address, and password entered on the user terminal 20. The processor 12 also issues a user ID as the user's identification information and stores this issued user ID in memory 16.
[0092] Next, the processor 12 of the authentication system 10 stores the facial image data received from the user terminal 20 in the memory 16 of the authentication system 10, associating it with the user ID (user identification information) and the identification information of the imaging units 30A, 30B, and 30C, using the registration means 13. In this way, the registration of the user's facial image captured by the user terminal 20 is completed. Note that in the example shown in Figure 17, the user's facial image data stored in the memory 16 is not transmitted from the authentication system 10 to the imaging units 30A, 30B, and 30C of the service organization selected by the user.
[0093] Next, the process for user authentication in each imaging unit 30A, 30B, and 30C will be described. When user authentication is required at a service organization where each imaging unit 30A, 30B, and 30C is installed, first, the user's face image data is acquired by imaging the user using the imaging units 38A, 38B, and 38C of the imaging units 30A, 30B, and 30C. The processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit the user's face image data captured by the imaging units 38A, 38B, and 38C to the processor 12 of the authentication system 10 via the communication units 42A, 42B, and 42C. When the processor 12 of the authentication system 10 receives the user's face image data from the imaging units 30A, 30B, and 30C, it receives only the user's face image data transmitted from the imaging units 30A, 30B, and 30C of the service organization selected by the user, which is stored in the memory 16. In the authentication system 10, the processor 12 authenticates the user by comparing the facial image data received from the imaging units 30A, 30B, and 30C with the user's facial image data stored in the memory 16 using the authentication means 15. More specifically, if the matching rate between the user's facial image data received from the imaging units 30A, 30B, and 30C and the user's facial image data stored in the memory 16 exceeds a predetermined threshold (for example, 80%), the authentication means 15 authenticates the user. As mentioned above, the memory 16 stores pre-registered user identification information and identification information of the imaging units 30A, 30B, and 30C, along with the user's facial image data, in association with each other.
[0094] Then, when the user is authenticated by the authentication means 15, information relating to the authentication result is transmitted from the processor 12 of the authentication system 10 to the imaging units 30A, 30B, and 30C via the communication unit 18. Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C enable the services corresponding to these imaging units 30A, 30B, and 30C to be implemented by their respective processing units 40A, 40B, and 40C. Subsequently, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit information relating to the service usage status to the authentication system 10. As a result, information relating to the service usage status at each service provider is stored in the memory 16 of the authentication system 10 for each user.
[0095] On the other hand, if the user's face image data received from the imaging units 30A, 30B, and 30C does not substantially match the user's face image data stored in the memory 16, and the authentication means 15 is unable to authenticate the user, information relating to the authentication result is transmitted from the processor 12 of the authentication system 10 to the imaging units 30A, 30B, and 30C via the communication unit 18 (STEP 58). Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C, respectively, disable the service corresponding to these imaging units 30A, 30B, and 30C through their respective processing units 40A, 40B, and 40C. In this case as well, the processors 32A, 32B, and 32C of the imaging units 30A, 30B, and 30C transmit information relating to the service usage status (specifically, information that the user attempted to authenticate with the imaging units 30A, 30B, and 30C but was not authenticated and was unable to use the service) to the authentication system 10.
[0096] With this authentication method, even if a user's facial image data is registered in the authentication engine of one service provider (e.g., imaging unit 30A) but not in the authentication engine of another service provider (e.g., imaging unit 30B), the authentication system 10 stores the user's facial image data in its memory 16. This allows the service provider whose facial image data is not registered to authenticate the user by capturing the user's facial image data with its imaging unit. In this case, the user does not need to register their facial image data with all of the multiple authentication engines, thus saving the user time and effort.
[0097] Furthermore, the authentication system 10 shown in Figure 17 also includes a linking means 19. The linking means 19 links the user's identification information used by the authentication engine 30D of a service organization that performs authentication other than facial recognition with the user's identification information related to the user's facial image data stored in memory 16. With such an authentication system 10, convenience can be improved by using the registered facial image data (specifically, the user's facial image data) in the authentication engine 30D that performs authentication other than facial recognition.
[0098] Furthermore, in a further modification, in the authentication system 10 shown in Figures 1 to 3, the authentication means 35A, 35B, and 35C of each imaging unit 30A, 30B, and 30C may authenticate the user using the user's facial image data rather than the feature quantities of the user's facial image. In this case, the user's facial image data registered in the authentication system 10 is transmitted to each imaging unit 30A, 30B, and 30C. In this case, the linking means 19 of the authentication system 10 shown in Figures 1 to 3 links the user's identification information used in the authentication engine 30D of a service organization that performs authentication other than facial recognition with the user's identification information related to the user's facial image data stored in memory 16. Even in such an authentication system 10, convenience can be improved by using the registered facial image data (specifically, the feature quantities of the user's facial image) in the authentication engine 30D that performs authentication other than facial recognition. [Explanation of Symbols]
[0099] 10 Authentication System 12 processors 13. Registration Method 14. Feature extraction method 15 Authentication methods 16 memory 17 Information acquisition means 18 Communications Department 19. Linking method 20 User Terminals 30A, 30B, 30C Imaging Units 30D Authentication Engine 32A, 32B, 32C processors 34A, 34B, 34C Feature extraction means 35A, 35B, 35C Authentication methods 36A, 36B, 36C memory 38A, 38B, 38C Imaging Unit 40A, 40B, 40C Processing Unit 42A, 42B, 42C Communication Department 50 Authentication Systems 52 processors 52a Server Management Means 53. Registration methods 54 Feature Extraction Method 55 Authentication methods 56 Server 1 58 Second Server 60 Third Server
Claims
1. A face memory unit where the user's face image or processed face data is registered, An ID storage unit where user identification information is registered, An authentication means that identifies a user by comparing a face captured by a camera with the aforementioned face data, A user-owned information terminal, a user terminal on which the user takes a photograph of a face image that will be the source data for the aforementioned face data, The system includes a linking means for linking the aforementioned identification information with information that can uniquely identify a user of another information processing system, The authentication of users of the aforementioned other information processing system is performed by facial recognition using the aforementioned authentication means. Facial recognition system.
2. The owners of the aforementioned other information processing systems and the providers of this system are different businesses. The facial recognition system according to claim 1.
3. The aforementioned other information processing system has authentication means other than facial recognition for authenticating users registered in the information processing system. The facial recognition system according to claim 1.
4. A face memory unit where the user's face image or processed face data is registered, Authentication means for comparing a face captured by a photographic means with the aforementioned face data, A user-owned information terminal, a user terminal on which the user takes a photograph of a face image that will be the source data for the aforementioned face data, A payment means that, upon successful authentication by the aforementioned authentication means, transmits payment information for the goods or services provided to the user to a payment-related institution. Facial recognition system.
5. The provider of the aforementioned goods or services and the provider of this system are different businesses. The payment method obtains at least the amount of the goods or services provided to the user and transmits the payment information. The facial recognition system according to claim 4.
6. The user terminal is a smartphone owned by the user. The facial recognition system according to claim 1 or 4.
7. The aforementioned authentication means requires additional authentication by other authentication means in addition to facial recognition of the user. The facial recognition system according to claim 1 or 4.
8. The authentication means and the server device having the face memory unit and the shooting means are communicated with each other via the Internet. The facial recognition system according to claim 1 or 4.
9. The user terminal has a history display means that displays the user's past facial recognition authentication history information. The facial recognition system according to claim 1 or 4.