Information processing systems and information processing programs

By implementing re-verification of user authentication under specific conditions, the system prevents unauthorized use of personal information functions in public information processing systems, ensuring secure access control.

JP2026135975APending Publication Date: 2026-08-25FUJIFILM BUSINESS INNOVATION CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025021831
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

In information processing systems, particularly in public settings, there is a risk of third parties continuing to use personal information-related functions after the authorized user has left the operation screen, leading to potential misuse of personal data.

Method used

The system requests re-verification of user authentication information when predetermined conditions are met, such as a change in the user, detection of a specific operation, or elapsed time, using contactless or contact-based communication methods to ensure the user is still authorized.

Benefits of technology

This approach effectively deters third parties from using personal information functions by requiring re-authentication, thereby preventing unauthorized access and misuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026135975000001_ABST
    Figure 2026135975000001_ABST
Patent Text Reader

Abstract

When authentication grants a user permission to use functions related to personal information, this system prevents third parties from continuing to use those functions. [Solution] The information processing system includes a processor, which acquires user identification information and user authentication information used for authentication in combination with the user identification information. If the authentication using the user identification information and the user authentication information is successful, the system permits the use of functions related to personal information. After the use of functions related to personal information is permitted, if predetermined conditions are met, the system requests the provision of information that matches the information used for authentication. If, after requesting the provision of information that matches the information used for authentication, the system fails to acquire information that matches the information used for authentication, the system prohibits the continued use of functions related to personal information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology of the present disclosure relates to an information processing system and an information processing program.

Background Art

[0002] Patent Document 1 discloses an automatic logout device characterized by including: when a job is executed, after the execution of the job, an inactivity determination means for determining whether or not the operation of the user who instructed the job has stopped without performing logout of the user; a terminal device determination means for determining whether or not the terminal device of the user has been operated when, as a result of the determination, the operation of the user has stopped; and a user authentication means for logging out the login of the user when, as a result of the determination, the terminal device of the user has been operated.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In an information processing system, functions related to the personal information of users may be provided. For example, in a multifunction device installed in a public place, a function for printing a user's certificate may be provided. In an information processing system that provides such a function, first, authentication is performed, and when the authentication is successful, the user is permitted to use the function related to personal information. After the user is permitted to use the function related to personal information, when the user leaves the operation screen, there is a problem that the use of the function related to personal information is continued by a third party.

[0005] This disclosure aims to provide an information processing system and program that deter third parties from continuing to use personal information-related functions after the user has been authorized to use such functions through authentication, compared to a system where the user is not required to provide information that matches the information used for authentication. [Means for solving the problem]

[0006] The information processing system according to the first embodiment includes a processor, the processor acquires user identification information and user authentication information used for authentication in combination with the user identification information, and if the authentication using the user identification information and the user authentication information is successful, it permits the use of functions related to personal information, and if predetermined conditions are met after the use of functions related to personal information has been permitted, it requests the provision of information that matches the information used for authentication, and if, after requesting notification of information that matches the information used for authentication, it fails to acquire information that matches the information used for authentication, it prohibits the continuation of the use of functions related to personal information.

[0007] In the information processing system according to the second embodiment, the predetermined condition in the information processing system according to the first embodiment is at least one of the following: a predetermined operation is detected among the operations for performing the functions related to personal information; a change is detected in the person performing the operations for performing the functions related to personal information; or a predetermined time interval has elapsed.

[0008] In the information processing system according to the third embodiment, if the information processing system according to the second embodiment includes the detection of a predetermined operation in the predetermined conditions, the processor does not execute the function corresponding to the predetermined operation if it does not obtain information that matches the information used for authentication after requesting notification of information that matches the information used for authentication.

[0009] In the information processing system according to the fourth embodiment, in the information processing system according to the third embodiment, the predetermined operation is an operation to output the personal information in a visible manner, and if the processor does not obtain information that matches the information used for authentication after requesting notification of information that matches the information used for authentication, the personal information is not output in a visible manner.

[0010] In the information processing system relating to the fifth aspect, if the information processing system relating to any of the second to fourth aspects includes the elapsed time intervals predetermined by the predetermined conditions, the processor requests notification of information matching the information used for authentication each time the predetermined time intervals have elapsed since permission was granted to use the personal information function.

[0011] In the information processing system according to the sixth aspect, in the information processing system according to any of the first to fourth aspects, if the processor requests notification of information that matches the information used for authentication and obtains information that matches the information used for authentication, it permits the continuation of use of the personal information function.

[0012] In the information processing system according to the seventh embodiment, in the information processing system according to the first embodiment, the information that matches the information used for authentication is the information that matches the user identification information, and when the user identification information is obtained from a contactless communication-enabled information recording medium, and the predetermined conditions are met after permission to use the personal information function is granted, the processor requests the information recording medium to notify the information that matches the user identification information via contactless communication, and after requesting notification of the information that matches the user identification information, if the information that matches the user identification information is obtained from the information recording medium via contactless communication, the processor permits the continuation of use of the personal information function.

[0013] In the information processing system according to the eighth aspect, in the information processing system according to the seventh aspect, the information recording medium is a terminal with a lock function, and if the processor requests the terminal to notify it of information matching the user identification information via contactless communication, and then fails to obtain information matching the user identification information from the terminal via contactless communication, the processor prohibits the continued use of the personal information function and outputs a message indicating that the terminal is not unlocked.

[0014] In the information processing system according to the ninth aspect, in the information processing system according to the seventh or eighth aspect, the information recording medium is a terminal, and when the user identification information is obtained through an application operated on the terminal, and after requesting notification of information matching the user identification information, the processor prohibits the continuation of use of the personal information function and outputs a message indicating that the application is not displayed in an operable manner on the terminal.

[0015] In the information processing system according to the 10th embodiment, in the information processing system according to any of the first to fourth embodiments, the seventh embodiment, and the eighth embodiment, the information that matches the information used for authentication is the information that matches the user identification information, and when the user identification information is obtained from an information recording medium that can be communicated by contact, and after requesting notification of information that matches the user identification information, the processor outputs a message to prevent forgetting to take the information recording medium home.

[0016] The information processing program according to the 11th embodiment causes the computer to execute a process that includes obtaining user identification information and user authentication information used for authentication in combination with the user identification information, permitting the use of personal information functions if the authentication using the user identification information and the user authentication information is successful, requesting notification of information matching the information used for authentication if predetermined conditions are met after the use of personal information functions has been permitted, and prohibiting the continuation of the use of personal information functions if information matching the information used for authentication is not obtained after the notification of information matching the information used for authentication has been requested. [Effects of the Invention]

[0017] According to the first and eleventh embodiments, compared to cases where the user is not required to provide information that matches the information used for authentication after being authorized to use the personal information-related functions through authentication, it is possible to deter third parties from continuing to use the personal information-related functions.

[0018] According to the second aspect, it is possible to confirm whether a person attempting to use a personal information function is a third party if at least one of the following conditions is met: a predetermined operation is detected among the operations for performing a personal information function; a change is detected in the person performing the operation for performing a personal information function; or a predetermined time interval has elapsed.

[0019] According to the third aspect, it is possible to prevent a function corresponding to a predetermined operation from being executed on behalf of a third party.

[0020] According to the fourth aspect, it is possible to suppress the output of personal information to a third party in a visible manner.

[0021] According to the fifth aspect, it is possible to verify whether the person attempting to use the personal information function is a third party each time a predetermined time interval has elapsed.

[0022] According to the sixth aspect, it is possible to permit the continuation of the use of the function related to personal information after confirming that the person attempting to use the function related to personal information is not a third party.

[0023] According to the seventh aspect, it is possible to confirm whether a person attempting to use the function related to personal information is not a third party through non-contact communication using an information recording medium.

[0024] According to the eighth aspect, it is possible to prompt a person attempting to use the function related to personal information to unlock the terminal.

[0025] According to the ninth aspect, it is possible to prompt a person attempting to use the function related to personal information to display an application operably on the terminal.

[0026] According to the tenth aspect, it is possible to suppress the forgetting to take away the information recording medium used to confirm whether a person attempting to use the function related to personal information is not a third party.

Brief Description of the Drawings

[0027] [Figure 1] It is a diagram showing an example of the configuration of a function providing system including an information processing system according to an embodiment of the technology of the present disclosure. [Figure 2] It is a diagram showing an example of the hardware configuration of an information processing system according to an embodiment of the technology of the present disclosure. [Figure 3] It is a diagram showing an example of the functional configuration of an information processing system according to an embodiment of the technology of the present disclosure. [Figure 4] It is a diagram showing an example of a flowchart showing the main routine of the processing executed by an information processing system according to an embodiment of the technology of the present disclosure. [Figure 5] It is a diagram showing an example of a flowchart of a subroutine of the matching information request processing in step S112 in the flowchart of FIG. 4. [Figure 6]This figure shows an example of a flowchart for the subroutine that prohibits the continued use of the function in step S114 of the flowchart in Figure 4. [Modes for carrying out the invention]

[0028] Hereinafter, an example of an embodiment of the technology of this disclosure will be described with reference to the drawings. In each drawing, the same or equivalent components and parts are given the same reference numerals. Also, the dimensional ratios in the drawings are exaggerated for illustrative purposes and may differ from the actual ratios.

[0029] First, the configuration of the function-providing system 10 according to an embodiment of the technology of this disclosure will be described. Here, we will refer to Figure 1.

[0030] Figure 1 shows an example of the configuration of a function provisioning system 10 according to an embodiment of the technology of this disclosure. The function provisioning system 10 includes an information processing system 11, an information recording medium 12, and a server 13.

[0031] Here, one of the personal information-related functions provided by the function provision system 10 is the function of printing and issuing user certificates to users. These certificates may be, for example, copies of resident registration certificates, seal registration certificates, or family register certificates. This diagram shows an example of how the function provision system 10 provides such personal information-related functions.

[0032] Specifically, the information processing system 11 verifies whether a user operating the information processing system 11's operation screen has the authority to use the functions related to personal information before granting permission for that user to use those functions. The information processing system 11 communicates with the user's information recording medium 12 and requests the provision of user identification information. User identification information is information used to identify the user. For example, user identification information is a user identification number. However, user identification information is not limited to information such as a user identification number, and may be any information used to verify whether the user is registered. The information recording medium 12 holds the user identification information and provides it to the information processing system 11. The information processing system 11 requests the user to input user authentication information and also obtains user authentication information. For example, user authentication information is a password. However, user authentication information is not limited to information based on the user's knowledge, and may be any information used for authentication in combination with user identification information.

[0033] The information processing system 11 encrypts the user identification information and user authentication information and transmits them to the external server 13. At this time, the information processing system 11 retains the information used for authentication so that it can be referenced in a later process. In this example, the information processing system 11 retains the user identification information. The server 13 transmits the authentication result determined based on the received information to the information processing system 11. If the authentication result confirms that the user operating the operation screen has the authority to use the function, the information processing system 11 permits the use of the function related to personal information.

[0034] After permission to use such a function has been granted, at some point during the period when the function is permitted, the person using the information processing system 11 may change from the user themselves to a third party. For example, while the information processing system 11 is displaying a screen that allows printing of a copy of the resident registration certificate, the user goes to get their wallet from their car. In that moment, a third party who is near the information processing system 11 may try to use it.

[0035] Therefore, in order to confirm that the person attempting to use the personal information-related functions is not a third party, the information processing system 11 requests notification of information that matches the information used for authentication when predetermined conditions are met. For example, the information processing system 11 requests the communication medium 12 to again notify the user identification information. The information used for authentication is the information used when the authentication result by the server 13 was successful. Based on this information, the information processing system 11 confirms whether the person using the information processing system 11 has been replaced by a third party from the actual user. Once the information processing system 11 obtains the information, it compares it with the user identification information it has stored. If the information processing system 11 determines that it has obtained information that matches the user identification information it has stored, it permits the continuation of use of the personal information-related functions. If the information processing system 11 cannot determine that it has obtained information that matches the user identification information it has stored, it prohibits the continuation of use of the personal information-related functions.

[0036] In this way, in the function provision system 10, the information processing system 11, the information recording medium 12, and the server 13 exchange data to provide functions related to personal information.

[0037] The information processing system 11 is, for example, a multifunction device. A multifunction device is a device that combines the functions of a copier, printer, image scanner, and facsimile into one unit. However, the information processing system 11 is not limited to a device that prints images, but may be any device that provides functions related to personal information. For example, the information processing system 11 may be a device installed in a public place such as a convenience store, library, ward office, or co-working space.

[0038] The information recording medium 12 is, for example, a terminal. A terminal is, for example, a mobile phone, digital camera, tablet terminal, desktop computer, notebook computer, all-in-one computer, or tablet computer. However, the information recording medium 12 is not limited to electronic devices such as terminals, and may be any medium on which user identification information is recorded. For example, the information recording medium 12 may be an IC card such as a My Number Card on which an electronic certificate is recorded. The information recording medium 12 may be an information recording medium that can communicate by contact, or an information recording medium that can communicate without contact.

[0039] Hereinafter, information recording media that can communicate through contact may be referred to as contact-type information recording media. For example, a contact-type information recording media is a contact-type IC card. A contact-type IC card exchanges data by physically contacting a reader. Contact-type information recording media often need to be installed by methods such as inserting them into a reader.

[0040] Hereinafter, information recording media capable of communication without contact may be referred to as contactless information recording media. For example, a contactless information recording media is a terminal. The terminal can exchange data with the information processing system 11 via wireless communication by utilizing the functions of an application. The terminal can also exchange data without direct contact by holding it over a reader, by utilizing the functions of an application. Another example of a contactless information recording media is a contactless IC card. A contact-type IC card can exchange data without direct contact by holding it over a reader. In most cases, contactless information recording media are held in the hand while exchanging data. Therefore, it is considered that contactless information recording media are less likely to be forgotten than contact-type information recording media. Furthermore, it is considered that the likelihood of forgetting to take a contactless information recording media home is lower when it exchanges data with a device via wireless communication than when it exchanges data by holding it over a reader. This is because when a user holds a medium over a reader, they may place the medium on the reader.

[0041] If the information recording medium 12 containing user identification information is forgotten, there is a possibility that personal information could be misused by a third party. If the information recording medium 12 is a contact-type information recording medium, it is desirable to use the information recording medium 12 infrequently to verify that the person attempting to use the personal information-related functions is not a third party. However, in order to provide personal information-related functions securely, it is desirable to verify that the person attempting to use the personal information-related functions is not a third party more frequently. Therefore, in one embodiment, the information processing system 11 may verify that the person attempting to use the personal information-related functions is not a third party by communicating with a non-contact type information recording medium. According to the information processing system 11 of this embodiment, even if the number of verifications using the information recording medium 12 increases, the risk of forgetting to take the information recording medium 12 home is reduced.

[0042] In this example, Server 13 is a device that stores pre-registered user identification information and the corresponding user authentication information, receives encrypted user identification information and user authentication information from other devices such as the information processing system 11, and outputs the authentication result.

[0043] Next, the hardware configuration of the information processing system 11 according to an embodiment of the technology of this disclosure will be described. Here, we will refer to Figure 2.

[0044] Figure 2 shows an example of the hardware configuration of an information processing system 11 according to an embodiment of the technology of this disclosure. The information processing system 11 has the following components: a CPU (Central Processing Unit) 21, a ROM (Read Only Memory) 22, a RAM (Random Access Memory) 23, storage 24, an input unit 25, a display unit 26, a communication interface (communication I / F) 27, an imaging unit 28, and a reading unit 29. Each component is connected to the others so as to be able to communicate with each other via a bus 30.

[0045] The CPU 21 is a central processing unit that executes various programs and controls various components. Specifically, the CPU 21 reads a program from the ROM 22 or storage 24 and executes the program using the RAM 23 as a working area. The CPU 21 controls each of the above components and performs various calculations according to the program recorded in the ROM 22 or storage 24. In this embodiment, the ROM 22 or storage 24 stores an information processing program.

[0046] ROM22 stores various programs and data. RAM23 temporarily stores programs or data as a working area. Storage24 consists of an HDD (Hard Disk Drive) or SSD (Solid State Drive) and stores various programs, including the operating system, and various data.

[0047] The input unit 25 includes a pointing device such as a mouse and a keyboard, and is used for various types of input. The display unit 26 is, for example, a liquid crystal display and displays various types of information. The display unit 26 may also function as the input unit 25 by employing a touch panel system.

[0048] The communication interface 27 is an interface for communicating with other devices such as the information recording medium 12 and the server 13. For example, the communication interface 27 may use standards such as Wi-Fi®, Bluetooth®, Zigbee®, NFC (Near Field Communication), Ethernet®, or FDDI.

[0049] The imaging unit 28 is, for example, a camera. The image information obtained by imaging is used to determine when a person leaves, approaches, or is replaced in the imaging area, such as in front of the information processing system 11. Changes in a person in such an imaging area may be determined using face recognition technology or behavior recognition technology, etc.

[0050] The reading unit 29 is a reader that reads information from the information recording medium 12. The reading unit 29 is, for example, a contact-type card reader / writer or a contactless-type card reader / writer.

[0051] Next, the functional configuration of the information processing system 11 according to an embodiment of the technology of this disclosure will be described. Here, we will refer to Figure 3.

[0052] Figure 3 shows an example of the functional configuration of an information processing system 11 according to an embodiment of the technology of this disclosure. The information processing system 11 has an acquisition unit 31, an authorization unit 32, a request unit 33, a prohibition unit 34, and an output unit 35 as its functional configuration. Each functional configuration is realized by the CPU 21 reading an information processing program stored in the ROM 22 or storage 24, expanding it into the RAM 23, and executing it.

[0053] The acquisition unit 31 acquires user identification information and user authentication information used for authentication in combination with the user identification information. The acquisition unit 31 also stores the information used for authentication. For example, the acquisition unit 31 stores user identification information.

[0054] The authorization unit 32 permits the use of functions related to personal information. For example, if the authentication using user identification information and user authentication information is successful, the authorization unit 32 permits the use of functions related to personal information. The authorization unit 32 also permits the continued use of functions related to personal information. For example, if the authorization unit 32 requests the provision of information that matches the information used for authentication and then obtains information that matches the information used for authentication, it permits the continued use of functions related to personal information.

[0055] The request unit 33 requests the provision of information that matches the information used for authentication. For example, it requests the provision of information that matches the information used for authentication when predetermined conditions are met. Also, for example, if the use of the personal information function has not been completed and predetermined conditions are met, it requests the provision of information that matches the information used for authentication. Furthermore, the request unit 33 requests the provision of information that matches user identification information as information that matches the information used for authentication. For example, if user identification information is obtained from a contactless information recording medium that can communicate without contact, and predetermined conditions are met after permission to use the personal information function has been granted, the request unit 33 requests the contactless information recording medium to provide information that matches user identification information obtained through contact communication. Also, for example, if user identification information is obtained from a contact-type information recording medium that can communicate by contact, and predetermined conditions are met after permission to use the personal information function has been granted, the request unit 33 requests the contact-type information recording medium to provide information that matches user identification information obtained through contact communication.

[0056] The prohibition unit 34 prohibits the continued use of functions related to personal information. For example, if the prohibition unit 34 requests the provision of information that matches the information used for authentication, and fails to obtain such information, it prohibits the continued use of functions related to personal information. Also, for example, if the prohibition unit 34 requests the provision of information that matches the information used for authentication again, such as by outputting a message, and fails to obtain such information, it maintains the prohibition on the use of functions related to personal information. Also, for example, the prohibition unit 34 prohibits the use of functions related to personal information when the use of such functions has ended. As an example, the prohibition unit 34 does not execute functions corresponding to predetermined operations. For example, if a predetermined operation is detected, and the prohibition unit 34 requests the provision of information that matches the information used for authentication, but fails to obtain such information, it does not execute functions corresponding to the predetermined operation. Furthermore, the prohibition unit 34 does not allow personal information to be output in a visible manner. For example, if an operation that would cause personal information to be displayed in a visible manner is detected, and after requesting the provision of information that matches the information used for authentication, the prohibition unit 34 will not allow the personal information to be displayed in a visible manner.

[0057] The output unit 35 outputs a message indicating that the terminal is not unlocked. For example, if the output unit 35 requests the terminal to provide information matching user identification information via contactless communication, but fails to obtain such information from the terminal via contactless communication, it outputs a message indicating that the terminal is not unlocked. The output unit 35 also outputs a message indicating that the application is not displayed in an operable state on the terminal. For example, if user identification information is obtained via an application operated on the terminal, and the output unit 35 requests the provision of information matching user identification information, but fails to obtain such information, it outputs a message indicating that the application is not displayed in an operable state on the terminal. The output unit 35 also outputs a message to prevent users from forgetting to take home contact-type information recording media. For example, if user identification information is obtained from a contact-type information recording media that can communicate by contact, and the output unit 35 requests the provision of information matching user identification information, but obtains such information from the contact-type information recording media, it outputs a message to prevent users from forgetting to take home contact-type information recording media.

[0058] Next, the processing performed by the information processing system 11 according to an embodiment of the technology of this disclosure will be described. Here, we will refer to Figure 4.

[0059] Figure 4 is a diagram showing an example of a flowchart illustrating the main routine of processing performed by an information processing system 11 according to an embodiment of the technology of this disclosure. Information processing is performed by the CPU 21 reading an information processing program from the ROM 22 or storage 24, loading it into the RAM 23, and executing it. This flowchart starts with the display unit 26 indicating that the use of functions related to personal information is not permitted, that is, the user is not logged in.

[0060] In step S101, the CPU 21, as the acquisition unit 31, acquires user identification information and user authentication information used for authentication in combination with the user identification information. The CPU 21 acquires this information in order to query the server 13 whether the person attempting to operate the information processing system 11 is the registered user. The CPU 21 may acquire user identification information by communicating with the user's information recording medium 12 and requesting the provision of user identification information. The CPU 21 may acquire user authentication information by requesting the user to provide it by inputting it into the input unit 25.

[0061] The user identification information may be obtained by one or more methods. For example, the user identification information may be provided via short-range wireless communication by holding a contactless IC card over the reader 29. The user identification information may be obtained through an application operated on the terminal, which serves as the information recording medium 12. For example, the user identification information may be provided via a communication connection such as NFC or Bluetooth® through the functions of an application operated on the terminal, which serves as the information recording medium 12. In such a case, the information processing system 11 may establish a communication connection, or so-called pairing, with the terminal, which serves as the information recording medium 12. The user identification information may also be obtained from a contact-type information recording medium that can communicate by contact. For example, the user identification information may be provided from a contact-type IC card inserted into the reader 29. Separately from step S109 described later, a message to prevent forgetting to take the contact-type information recording medium home may be output at this stage. Information regarding which method the user authentication information was obtained may be stored for use in later processing.

[0062] Next, CPU21 proceeds to step S102.

[0063] In step S102, the CPU 21, acting as the authorization unit 32, determines whether the authentication using the user identification information and user authentication information was successful. Specifically, the CPU 21 encrypts the user identification information and user authentication information obtained in step S101, sends them to the external server 13, and then determines whether the authentication was successful from the information output from the server 13.

[0064] If the authentication is determined to be successful, the CPU 21 proceeds to step S103. If the authentication is determined to be unsuccessful, the CPU 21 terminates the main routine with the display unit 26 showing that the use of personal information-related functions is not permitted.

[0065] In step S103, the CPU 21, as the acquisition unit 31, holds the information used for authentication. The information used for authentication may be at least one of the user identification information and user authentication information acquired in step S101.

[0066] The retained information is referenced in step S113, described later, and used for information verification. By retaining the information in this way, it becomes unnecessary to query the server 13 in the processing of step S113. In other words, when a user is first authenticated, the information processing system 11 sends encrypted user identification information and user authentication information to the external server 13. The information processing system 11 then receives the authentication result determined by the server 13. In step S113, described later, the CPU 21 determines whether it has obtained information that matches the information used for authentication without making such a query to the server 13. Generally, querying an external server for information takes a certain amount of time. In this disclosure, it may be necessary to perform the determination of whether it has obtained information that matches the information used for authentication multiple times. Therefore, it is desirable for the convenience of the user to shorten the time required for each determination. For this reason, in step S103, the CPU 21 retains the information used for authentication as an acquisition unit 31. The CPU 21 may discard the data related to the information retained in this step after a certain processing step has been completed.

[0067] Next, CPU21 proceeds to step S104.

[0068] In step S104, the CPU 21, acting as the authorization unit 32, authorizes the use of functions related to personal information.

[0069] Specifically, the CPU 21 sets the display on the display unit 26 to a logged-in state. Once logged in, the CPU 21 displays a screen on the display unit 26 that allows the user to select the type of certificate required, the information to be included in the certificate, and the number of copies to print.

[0070] Next, CPU21 proceeds to step S105.

[0071] In step S105, the CPU 21, as the request unit 33, determines whether the use of the personal information-related function has ended.

[0072] Specifically, the CPU 21 may determine that the use of a function has ended when it can be inferred that the user's use of a function related to personal information has been interrupted or completed. For example, the CPU 21 may determine that the use of a function has ended when an operation to voluntarily end the use of the function is performed. An operation to voluntarily end the use of a function is, for example, when the "Cancel" button or "End" button displayed on the display unit 26 is selected. Also, for example, the CPU 21 may determine that the use of a function has ended when no input is made to the input unit 25 for a certain period of time or longer, i.e., when a timeout occurs. Also, for example, the CPU 21 may determine that the use of a function has ended when the execution of a predetermined function is completed. For example, the CPU 21 may determine that the use of a function has ended when it has executed the printing of a certificate and completed the issuance of a receipt.

[0073] Traditionally, after these conditions were met, a process to prohibit the use of personal information-related functions, such as a logout process, was executed, as described in step S110 below. However, a problem was that a third party could continue to use personal information-related functions before these conditions were met. For example, it was possible that the user would leave the information processing system 11 before the timeout occurred, allowing a third party to continue using it. The technology of this disclosure requests information that matches the information used for authentication before these conditions are met, and verifies whether the person attempting to use personal information-related functions is a third party. In this way, the technology of this disclosure prevents a third party from continuing to use personal information-related functions.

[0074] If the CPU 21 determines that the use of the personal information function has ended, it proceeds to step S106. Steps S106 to S108 below are steps to determine whether to execute the process in step S109. If the CPU 21 determines that the use of the personal information function has not ended, it proceeds to step S110.

[0075] In step S106, the CPU 21, acting as the output unit 35, determines whether user identification information has been obtained from the contact-type information recording medium that can communicate by contact. If user identification information has been obtained from the contact-type information recording medium, it is possible that the user has placed the contact-type information recording medium on the reading unit 29 and forgotten to take it home.

[0076] Specifically, the CPU 21 may determine whether the user identification information acquired in step S101 was read by the reading unit 29. Even with contactless information recording media, users may actually place them on the reading unit 29, potentially leading to users forgetting to take them home. Therefore, user identification information read using the reading unit 29 may be treated similarly to user identification information acquired from a contact-type information recording media, regardless of whether the medium is strictly classified as a contact-type information recording media.

[0077] If the CPU 21 determines that user identification information has been obtained from the contact-type information recording medium, it proceeds to step S107. If the CPU 21 determines that user identification information has not been obtained from the contact-type information recording medium, it proceeds to step S110.

[0078] In step S107, the CPU 21 determines whether the output unit 35 has requested the provision of information matching the user identification information. If the provision of information matching the user identification information is requested, it is because the user may have placed the information recording medium 12 on the reading unit 29 and forgotten to take it home. Specifically, in step S112, which will be described later, the CPU 21 determines whether the provision of information matching the user identification information has been requested.

[0079] If the CPU 21 determines that the user has requested the communication of information that matches the user identification information, the CPU 21 proceeds to step S108. If the CPU 21 determines that the user has not requested the communication of information that matches the user identification information, the CPU 21 proceeds to step S110.

[0080] In step S108, the CPU 21, as the output unit 35, determines whether information matching the user identification information has been obtained from the contact-type information recording medium. This is because if information matching the user identification information is read and obtained by the reading unit 29, the user may place the information recording medium 12 on the reading unit 29, potentially causing the user to forget to take it home.

[0081] Specifically, the CPU 21 may determine whether information matching the user identification information has been read and acquired by the reading unit 29. Even with contactless information recording media, users may actually place them on the reading unit 29, potentially leading to instances where users forget to take them home. Therefore, any information matching the user identification information read using the reading unit 29 can be considered similarly to information matching user identification information acquired from a contact-type information recording media, regardless of whether the medium is strictly classified as a contact-type information recording media.

[0082] If the CPU 21 determines that information matching the user identification information has been obtained from the contact-type information recording medium, it proceeds to step S109. Note that proceeding from step S108 to step S109 means that it has been determined that the contact-type information recording medium may be in a state where it could be forgotten, such as when it has been inserted into the reading unit 29. If the CPU 21 determines that information matching the user identification information has not been obtained from the contact-type information recording medium, it proceeds to step S110.

[0083] In step S109, the CPU 21 outputs a message via the output unit 35 to prevent users from forgetting to take home the contact-type information recording medium.

[0084] Specifically, the CPU 21 displays a message such as "Please remove the card" on the display unit 26. Even with contactless information recording media, users may actually place them on the reading unit 29, potentially leading to them forgetting to take them home. Therefore, if the information matches the user identification information read by the reading unit 29, the same message may be output regardless of whether the medium is strictly classified as a contact-type information recording medium. For the convenience of the user, in this example, a message to prevent forgetting to take the recording media is output after it is determined that the use of the function has ended, but before logging out. For example, when printing is completed, the CPU 21 outputs a message to prevent forgetting to take the recording media at a time when the user's attention is likely to shift to the printed material and they are more likely to forget the information recording media. In another example, a message to prevent forgetting to take the recording media may be output each time information matching the user identification information is requested.

[0085] In this case, if the user is asked to provide information matching their authentication information while the information recording medium is in their hand, the probability of forgetting to take it home is relatively low. Therefore, even if the number of such requests increases, the risk remains relatively small. However, if the user is asked to provide information matching their authentication information by reading it with the reader unit 29 after it has left their hand, the probability of forgetting to take it home is relatively high. Therefore, a message is output to prevent users from forgetting to take the contact-type information recording medium home, thereby suppressing the forgetting of the contact-type information recording medium.

[0086] Next, CPU21 proceeds to step S110.

[0087] In step S110, the CPU 21, as a prohibition unit 34, prohibits the use of functions related to personal information.

[0088] Specifically, the CPU 21 switches the display on the display unit 26 from the logged-in state to the logged-out state.

[0089] At this point, CPU21 terminates this main routine.

[0090] In step S111, the CPU 21, as the request unit 33, determines whether predetermined conditions are met. This step is for determining whether to request the provision of information that matches the information used for authentication in step S112, which will be described later.

[0091] For example, CPU21 determines whether a predetermined operation is detected among the operations for performing functions related to personal information. Operations for performing functions related to personal information include operations that do not cause problems when performed by a third party and operations that do cause problems when performed by a third party. An example of an operation that does not cause problems when performed by a third party is the operation to return to the previous page. An example of an operation that causes problems when performed by a third party is the operation to make personal information visible. For example, an operation that makes personal information visible is the operation to print a document containing personal information. Another example of an operation that makes personal information visible is the operation to preview a document containing personal information before printing it.

[0092] By pre-configuring an operation that makes such personal information visible, it is possible to verify whether the person attempting to use a function related to personal information is a third party before the personal information is made visible. However, unnecessarily frequently requesting information that matches the information used for authentication may excessively impair user convenience. The technology disclosed herein may request information that matches the information used for authentication at the time a pre-configured operation is detected. In this way, it is possible to verify whether the person attempting to use a function related to personal information is a third party without excessively impairing user convenience.

[0093] As another example, the CPU 21 determines whether a change has been detected in the person performing the operation to execute the personal information function. Specifically, the CPU 21 uses information obtained from the imaging unit 28. For example, the CPU 21 determines whether a person has left, approached, or been replaced in front of the information processing system 11 based on image information obtained when the imaging unit 28 images the front of the information processing system 11. A change in the person performing the operation to execute the personal information function may be detected as the person who was performing the operation to execute the personal information function having left. A change in the person performing the operation to execute the personal information function may be detected as the person different from the person who was performing the operation to execute the personal information function having approached the information processing system 11. A change in the person performing the operation to execute the personal information function may be detected as the person performing the operation to execute the personal information function having been replaced by a new person. Note that the method for detecting a change in the person performing the operation to execute the personal information function is not limited to the method using the imaging unit 28. A different type of sensor may be installed in the information processing system 11 to detect changes in a person. Furthermore, if a device for detecting human movement is provided in the facility where the information processing system 11 is installed, information may be obtained from such a device. The technology of this disclosure may request the provision of information matching the information used for authentication at the time a change is detected in a person performing an operation to execute a function related to personal information. This makes it possible to verify whether the person attempting to use a function related to personal information is a third party without excessively impairing user convenience.

[0094] As another example, the CPU 21 determines whether a predetermined time interval has elapsed. For example, in step S104, the CPU 21 determines whether one minute has elapsed since the display on the display unit 26 was set to the logged-in state. When such a condition is set, the CPU 21 may request the provision of information that matches the information used for authentication each time the predetermined time interval has elapsed. For example, the CPU 21 may request the provision of information that matches the information used for authentication each time one minute has elapsed since the display on the display unit 26 was set to the logged-in state. The shorter the predetermined interval is set, the fewer opportunities there are for a third party to use the function, and the more securely third parties can be prevented from using the function regarding personal information.

[0095] As yet another example, CPU21 determines whether at least one of the following conditions is met: a change is detected in the person performing the operation to execute the personal information function, or a predetermined time interval has elapsed. Thus, the predetermined condition may be at least one of the following: a predetermined operation among the operations to execute the personal information function is detected, a change is detected in the person performing the operation to execute the personal information function, or a predetermined time interval has elapsed.

[0096] As yet another example, CPU 21 determines whether a change has been detected in the person performing an operation to execute a function related to personal information, and whether a predetermined operation among the operations for executing a function related to personal information has been detected. For example, CPU 21 determines whether an operation to output personal information in a visible manner has been detected after a person different from the person performing the operation related to personal information has approached. In this way, the predetermined conditions may be a combination of multiple conditions.

[0097] Another example of a predetermined condition is that the terminal, which is an information recording medium 12 paired with the information processing system 11 via NFC or Bluetooth (registered trademark) in step S101, moves a certain distance or more away from the information processing system 11. When the terminal moves away from the information processing system, it can be presumed that the user possessing the terminal has moved away from the information processing system 11. At such a time, by requesting the provision of information that matches the information used for authentication, it is possible to confirm whether the person attempting to use the personal information function is a third party without excessively impairing the user's convenience.

[0098] If the CPU 21 determines that the predetermined conditions are met, it proceeds to step S112. If the CPU 21 determines that the predetermined conditions are not met, it returns to step S105.

[0099] In step S112, the CPU 21, as the request unit 33, requests the provision of information that matches the information used for authentication. In this specification, the request for "provision of information that matches the information used for authentication" may be expressed as a request for "re-provision of the information used for authentication." As an example, the CPU 21, as the request unit 33, executes a subroutine for matching information request processing. Refer to Figure 5 here.

[0100] Figure 5 shows an example of a flowchart for the subroutine for processing matching information in step S112 of the flowchart in Figure 4. In this example, the subroutine is described for the case where the information to be provided matches the user identification information, which is obtained in step S101 from the user identification information and user authentication information. Here, it is assumed that the user identification information is obtained from some kind of information recording medium and the user authentication information is entered by the user. In that case, the inconvenience for the user can be reduced by requesting the provision of user identification information that can be provided by communication via a medium rather than user authentication information that needs to be entered manually. However, in another example, the information to be provided matches the user authentication information, which is obtained in step S101 from the user identification information and user authentication information. In this case, the CPU 21 may, as processing in step S112, display a message on the display unit 26 of the information processing system 11 prompting the user to manually enter the user authentication information, for example, a password, again. In either example, the CPU 21 may, as part of the processing in step S112, request that the information used for authentication be re-provided using the same means of provision as when it was obtained in step S101.

[0101] In step S201, the CPU 21, as the request unit 33, determines whether user identification information has been obtained from a contactless information recording medium that can communicate without physical contact.

[0102] Here, there may be multiple options for how user identification information is provided by a contactless information recording medium. For example, user identification information may be provided via a contactless IC card as the information recording medium 12. Alternatively, user identification information may be provided via a terminal as the information recording medium 12. The CPU 21 determines which of these multiple possible methods was used to provide and obtain the user authentication information. The CPU 21 may also refer to the information stored in step S101 regarding how the user authentication information was obtained.

[0103] If the CPU 21 determines that user identification information has been obtained from the contactless information recording medium, it proceeds to step S202. If the CPU 21 determines that user identification information has not been obtained from the contactless information recording medium, it proceeds to step S203. In this example, the case where user identification information has not been obtained from the contactless information recording medium is assumed to be the case where user identification information has been obtained from the contact-type information recording medium.

[0104] In step S202, the CPU 21, as the request unit 33, requests the contactless information recording medium to provide information that matches the user identification information via contactless communication.

[0105] As an example, the CPU 21 requests the terminal application, which acts as the information recording medium 12, to provide information that matches the user identification information while in communication. In this case, the CPU 21 sends a signal to the terminal application requesting it to re-provide the user identification information. If the terminal application can comply with this request, it provides the user identification information. If the terminal application cannot comply with this request, it provides the information processing system 11 with the reason why it cannot comply. For how the system handles cases where the terminal application cannot comply with the request, please refer to steps S301 to S305 in the flowchart of Figure 6, which will be described later. When communicating with the terminal to request such provision, the CPU 21 may or may not inform the user that it is requesting the provision and ask for an operation of the application. By requesting the provision without asking the user to take action, inconvenience for the user can be reduced. Furthermore, when the information processing system 11 requests the re-provision of user identification information from a terminal that has established a communication connection, so-called pairing, the identity of the terminal will also be confirmed in addition to the matching of the user identification information. Therefore, in this case, it is possible to more reliably confirm that the person using the information processing system 11 has not been replaced by a third party from the actual user.

[0106] As another example, the CPU 21 requests information matching user identification information via contactless communication from the contactless IC card, which serves as the information recording medium 12, when it is held over the reader 29. In this case, the CPU 21 may display a message on the display unit 26 of the information processing system 11 prompting the user to hold the IC card over the card reader. When the user holds the contactless IC card over the reader 29, the reader 29 can receive information from the contactless IC card.

[0107] In step S203, the CPU 21, as the request unit 33, requests the contact-type information recording medium to provide information that matches the user identification information obtained through contact communication.

[0108] As an example, the CPU 21 requests the contact-type IC card, which serves as the information recording medium 12, to provide information that matches the user identification information obtained through contact communication, upon insertion into the reader unit 29. For example, the CPU 21 may display a message on the display unit 26 of the information processing system 11 prompting the user to insert the contact-type IC card into the card reader. As a result of such a request, the contact-type information recording medium may be inserted into the reader unit 29, potentially leading to it being forgotten. For measures to prevent the contact-type information recording medium from being forgotten in such a case, please refer to steps S106 to S109 in the flowchart of Figure 4 mentioned above.

[0109] At this point, CPU21 terminates this subroutine. Next, CPU21 proceeds to step S113 in the flowchart of Figure 4. Now, refer back to Figure 4.

[0110] In step S113, the CPU 21 determines, as the prohibition unit 34, whether it has obtained information that matches the information used for authentication.

[0111] Specifically, the CPU 21 first determines whether any information was obtained within a certain time period as a result of the request in step S112. If no information is obtained, the CPU 21 determines that it has not obtained information that matches the information used for authentication. If any information is obtained, the CPU 21 compares the obtained information with the information used for authentication that it has held in step S103. If the obtained information does not match the held information as a result of the comparison, the CPU 21 determines that it has not obtained information that matches the information used for authentication. If the obtained information matches the held information as a result of the comparison, the CPU 21 determines that it has obtained information that matches the information used for authentication. By performing a comparison with the information held in the information processing system 11, the CPU 21 can omit processing that would be necessary when querying information from an external server, etc. When requesting information that matches the information used for authentication multiple times, even a small reduction in processing time can improve user convenience.

[0112] If the CPU 21 determines that it has not obtained information that matches the information used for authentication, it proceeds to step S114. If the CPU 21 determines that it has obtained information that matches the information used for authentication, it proceeds to step S116.

[0113] In step S114, the CPU 21, acting as the prohibition unit 34, prohibits the continued use of functions related to personal information. As an example, the CPU 21, acting as the prohibition unit 34, executes a subroutine for processing the prohibition of continued use of the function. Refer to Figure 6 here.

[0114] Figure 6 shows an example of a flowchart for the subroutine for the process of prohibiting continued use of a function in step S114 of the flowchart in Figure 4. In this example, the subroutine for the case where the application of a terminal with a lock function was unable to respond to the request to re-provide user identification information and therefore could not obtain information that matches the information used for authentication is described. Here, a lock function is a function that makes a predetermined function on the terminal unusable unless the lock is released by performing a specific operation. For example, a lock function is a function that does not accept operations on the application on the terminal until the lock is released. However, in another example, the communication connection between the terminal as an information recording medium 12 and the information processing system 11 may be interrupted, and therefore it may not be possible to obtain information that matches the information used for authentication. In such a situation, instead of outputting the message described later, the CPU 21 may display a message indicating that communication has been interrupted on the display unit 26 of the information processing system 11.

[0115] In step S301, the CPU 21, as a prohibition unit 34, prohibits the continued use of functions related to personal information.

[0116] For example, the CPU 21 changes the display on the display unit 26 from the logged-in state to the logged-out state. Another example is when, after a predetermined operation is detected, the CPU 21 requests information matching the information used for authentication, but fails to obtain information matching the information used for authentication. In such a case, the CPU 21, acting as a prohibition unit 34, does not execute the function corresponding to the predetermined operation. As another example, when, after an operation that makes personal information visible is detected, the CPU 21 requests information matching the information used for authentication, but fails to obtain information matching the information used for authentication. In such a case, the CPU 21, acting as a prohibition unit 34, prevents the personal information from being made visible. Thus, if information matching the information used for authentication is not obtained in step S113, the CPU 21 prohibits the continued use of functions related to personal information because there is a possibility that the person using the information processing system 11 has changed from the user themselves to a third party. In particular, the CPU 21 prevents the execution of operations that would be problematic if performed by a third party, such as operations that make personal information visible.

[0117] As another example, the CPU 21 may switch the display screen on the display unit 26 to display a message indicating that no information matching the information used for authentication was obtained. As yet another example, the CPU 21 may disable some of the operations performed via the input unit 25.

[0118] Next, CPU21 proceeds to step S302.

[0119] In step S302, the CPU 21 determines, as the output unit 35, whether the terminal has been unlocked.

[0120] Specifically, the CPU 21 determines whether the terminal has been unlocked based on information from the terminal that was established in step S112. The information from the terminal indicates that the terminal's application cannot respond to the request for re-provision of user identification information because the terminal has not been unlocked.

[0121] Thus, the terminal application may be configured to respond to requests from the information processing system 11 only when the terminal is unlocked. It is common for terminals to be locked after a certain period of time has passed since the terminal was not used. Furthermore, it is considered that a third party cannot easily unlock the terminal. Even if the user leaves the area while the terminal is near the information processing system 11, if the terminal is locked, it will not respond to requests from the information processing system 11. Also, even if the user is in possession of the terminal, it may be locked if the user does not intend to continue using functions related to personal information. If it is locked, the terminal will not respond to requests from the information processing system 11.

[0122] If the CPU 21 determines that the device is not unlocked, it proceeds to step S303. If the CPU 21 determines that the device is unlocked, it proceeds to step S304.

[0123] In step S303, the CPU 21 outputs a message to the output unit 35 indicating that the terminal has not been unlocked.

[0124] For example, the CPU 21 displays a message on the display unit 26 such as, "The terminal is locked. Please unlock it." The message may also be delivered by voice from the information processing system 11. By outputting such a message in a way that is recognizable to a person near the information processing system 11, it is possible to prompt a person attempting to use a function related to personal information to unlock the terminal. Furthermore, by outputting such a message, it is possible to check whether information matching the user identification information has been obtained afterward, and to confirm whether the person attempting to use a function related to personal information is a third party who is unable to unlock the terminal.

[0125] Next, CPU21 proceeds to step S304.

[0126] In step S304, the CPU 21 determines, as the output unit 35, whether the application is displayed in an operable state on the terminal.

[0127] Specifically, the CPU 21 determines, based on information from the terminal established in step S112, whether the application is displayed in an operable state on the terminal. The information from the terminal refers to information indicating that the application on the terminal cannot respond to the request for re-provision of user identification information because the application is not displayed in an operable state on the terminal. Here, the state in which the application is displayed in an operable state on the terminal can be understood as the state in which the application is so-called foreground.

[0128] Thus, the terminal application may be configured to respond to requests from the information processing system 11 only when it is in the foreground. Even if the terminal is in the possession of a user and is in a location where it can communicate with the information processing system 11, the user may not intend to continue using functions related to personal information, for example, by using another application. If the terminal application is not in the foreground, the terminal will not respond to requests from the information processing system 11.

[0129] If the CPU 21 determines that the application is not displayed in an operable state on the terminal, it proceeds to step S305. If the CPU 21 determines that the application is displayed in an operable state on the terminal, it terminates this subroutine.

[0130] In step S305, the CPU 21 outputs a message via the output unit 35 indicating that the application is not displayed in an operable state on the terminal.

[0131] For example, the CPU 21 displays a message on the display unit 26 such as, "The application is not displayed. Please display the application." The message may also be announced audibly by the information processing system 11. By outputting such a message in a way that is recognizable to a person near the information processing system 11, it is possible to prompt a person attempting to use a function related to personal information to display the application in an operable state on their terminal. Furthermore, by outputting such a message, it is possible to check whether information matching the user identification information has been obtained afterward, and to confirm whether the person attempting to use a function related to personal information is a third party who cannot display the application in an operable state on their terminal.

[0132] At this point, CPU21 terminates this subroutine. Next, CPU21 proceeds to step S115 in the flowchart of Figure 4. Now, refer to Figure 4 again.

[0133] In step S115, the CPU 21, as the prohibition unit 34, determines whether it has obtained information that matches the information used for authentication. This is because, in connection with the processing in step S114, the CPU 21 may have requested again the provision of information that matches the information used for authentication, and as a result, it may have obtained information that matches the user identification information.

[0134] If the CPU 21 determines that it has obtained information that matches the user identification information, it proceeds to step S116. If the CPU 21 determines that it has not obtained information that matches the user identification information, it terminates this main routine.

[0135] In step S116, the CPU 21, acting as the authorization unit 32, permits the continued use of the personal information-related functions. In other words, the CPU 21 either continues the state in which it permitted the use of personal information-related functions in step S104, or it re-permits the use of a function that was previously prohibited in step S114. For example, the CPU 21 may execute a function corresponding to a predetermined operation. For example, the CPU 21 may output personal information in a visible format. In this way, after confirming that the person attempting to use the personal information-related functions is not a third party, the continued use of personal information-related functions can be permitted.

[0136] Next, CPU21 returns to step S105.

[0137] Thus, the technology disclosed herein, when authentication has authorized a user to use functions related to personal information and certain conditions are met, requests the provision of information that matches the information used for authentication, and verifies whether the person attempting to use the functions related to personal information is a third party. In this way, the technology disclosed herein can prevent a third party from continuing to use the functions related to personal information.

[0138] In this embodiment, each process is executed on any computer. Furthermore, any computer may execute these processes using a processor as hardware, a program as software, or a combination thereof. In that case, the processor is configured to work in cooperation with the program to execute the various processes in this embodiment, and can function as a unit or means in this embodiment. Also, the execution order of the processes by the processor is not limited to the order described and may be changed as appropriate. Any computer may be a general-purpose computer, a computer designed for a specific purpose, a workstation, or any other system capable of executing each process.

[0139] A processor may consist of one or more hardware components, and the type of hardware is not limited. For example, a processor may consist of a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a programmable logic device such as an FPGA (Field Programmable Gate Array), a dedicated circuit for executing a specific process such as an ASIC (Application Specific Integrated Circuit), a GPU (Graphic Processing Unit), or an NPU (Neural Processing Unit). Furthermore, the type of hardware may be a combination of different types of hardware. When multiple hardware components are configured to execute one or more processes of a processor, these components may reside in physically separate devices or in the same device. Also, in any embodiment, the order of each process performed by the processor is not limited to the order described above and may be changed as appropriate. Hardware is composed of electrical circuits (circuitry) that combine circuit elements such as semiconductor elements.

[0140] Furthermore, the program may be firmware or software such as microcode. Alternatively, the program may be, for example, a group of program modules, each function of which may be implemented by a processor configured to perform its respective function. The program may be program code or multiple code segments stored on one or more non-temporary computer-readable media (e.g., storage media or other storage). The program may be divided and stored on multiple non-temporary computer-readable media located on physically separate devices. The program code or code segments may represent any combination of procedures, functions, subprograms, routines, subroutines, modules, software packages, classes, or instructions, data structures, or program statements. The program code or code segments may be connected to other code segments or hardware circuits by sending and receiving information, data, arguments, parameters, or memory contents. The program of this application may also be provided as a program product.

[0141] (Note) (((1))) Equipped with a processor, The aforementioned processor, The user identification information and user authentication information used for authentication by combining the user identification information are obtained. If the authentication using the aforementioned user identification information and user authentication information is successful, permission will be granted to use the functions related to personal information. After permission is granted to use the aforementioned personal information function, if predetermined conditions are met, the system will request the provision of information that matches the information used for authentication. If, after requesting the provision of information matching the information used for the aforementioned authentication, the user fails to obtain such information, the user will be prohibited from continuing to use the personal information-related functions. Information processing system. (((2))) The predetermined conditions are at least one of the following: a predetermined operation is detected among the operations for performing the functions related to the personal information; a change is detected in the person performing the operations for performing the functions related to the personal information; or a predetermined time interval has elapsed. The information processing system described in (((1))). (((3))) If the predetermined conditions include the detection of the predetermined operation, the processor shall If, after requesting the provision of information matching the information used for authentication, information matching the information used for authentication is not obtained, the function corresponding to the predetermined operation will not be executed. The information processing system described in (((2))). (((4))) The aforementioned predetermined operation is an operation to make the personal information visible, and if the processor requests the provision of information that matches the information used for authentication, but fails to obtain information that matches the information used for authentication, it will not make the personal information visible. The information processing system described in (((3))). (((5))) If the predetermined conditions include the elapsed time interval, the processor shall After permission is granted to use the aforementioned personal information function, the system will request the provision of information that matches the information used for authentication at each predetermined time interval. An information processing system as described in any one of items (((2))) through (((4))). (((6))) The aforementioned processor, After requesting the provision of information that matches the information used for the authentication, if information that matches the information used for the authentication is obtained, the user is permitted to continue using the personal information function. An information processing system as described in any one of the items (((1))) through (((5))). (((7))) The information that matches the information used for the authentication is the information that matches the user identification information, and the processor, If user identification information is obtained from a contactless communication-enabled information recording medium, and the predetermined conditions are met after permission to use the personal information-related functions has been granted, the system requests the information recording medium to provide information matching the user identification information via contactless communication, and if, after requesting the provision of information matching the user identification information, information matching the user identification information is obtained from the information recording medium via contactless communication, the system permits the continued use of the personal information-related functions. An information processing system as described in any one of the items (((1))) through (((6))). (((8))) The aforementioned information recording medium is a terminal having a locking function, and the processor is If, after requesting the terminal to provide information matching the user identification information via contactless communication, the terminal fails to obtain information matching the user identification information via contactless communication, the continued use of the personal information function is prohibited, and a message indicating that the terminal is not unlocked is output. The information processing system described in (((7))). (((9))) The aforementioned information recording medium is a terminal, and the aforementioned processor is If user identification information is obtained through an application operated on the terminal, and after requesting the provision of information matching the user identification information, no matching information is obtained, the continued use of the personal information function is prohibited, and a message indicating that the application is not displayed in an operable state on the terminal is output. The information processing system described in (((7))) or (((8))). (((10))) The information that matches the information used for the authentication is the information that matches the user identification information, and the processor, When user identification information is obtained from an information recording medium that can communicate via contact, and after requesting the provision of information matching the user identification information, information matching the user identification information is obtained from the information recording medium, a message is output to prevent the user from forgetting to take the information recording medium home. An information processing system as described in any one of the items (((1))) through (((9))). (((11))) On the computer, The user identification information and user authentication information used for authentication by combining the user identification information are obtained. If the authentication using the aforementioned user identification information and user authentication information is successful, permission will be granted to use the functions related to personal information. After permission is granted to use the aforementioned personal information function, if predetermined conditions are met, the system will request the provision of information that matches the information used for authentication. If, after requesting the provision of information that matches the information used for the aforementioned authentication, the user fails to obtain such information, the user will be prohibited from continuing to use the personal information-related functions. An information processing program that performs a process that includes the following.

[0142] According to (((1))) and (((11))), compared to not requiring the provision of information matching the information used for authentication after the user has been authorized to use the personal information-related functions through authentication, it is possible to deter third parties from continuing to use the personal information-related functions.

[0143] According to (((2))), it is possible to confirm whether a person attempting to use a personal information function is a third party if at least one of the following conditions is met: a predetermined operation is detected among the operations for performing a personal information function; a change is detected in the person performing the operation for performing a personal information function; or a predetermined time interval has elapsed.

[0144] According to (((3))), it is possible to prevent functions corresponding to predetermined operations from being executed on behalf of a third party.

[0145] According to (((4))), it is possible to suppress the output of personal information to third parties in a visible manner.

[0146] According to (((5))), it is possible to verify whether the person attempting to use the personal information function is a third party each time a predetermined time interval has elapsed.

[0147] According to ((6)), it is possible to permit the continued use of personal information functions after confirming that the person attempting to use the personal information functions is not a third party.

[0148] According to (((7))), it is possible to verify whether the person attempting to use a function related to personal information is a third party through contactless communication using an information recording medium.

[0149] According to ((8)), it is possible to prompt a person who wishes to use a function related to personal information to unlock their device.

[0150] According to ((9)), it is possible to prompt those who wish to use functions related to personal information to display the application in an operable manner on their device.

[0151] It is possible to verify whether the person attempting to use the functions related to personal information is a third party who cannot display the application in an operable manner on the device.

[0152] According to (((10))), it is possible to prevent people from forgetting to take with them the information recording media used to verify whether the person attempting to use the function related to personal information is a third party. [Explanation of symbols]

[0153] 10. Function Delivery System 11. Information Processing Systems 12. Information recording media 31 Acquisition Department 32 Permit Department 33 Request part 34 Prohibited part 35 Output section

Claims

1. Equipped with a processor, The aforementioned processor, The user identification information and user authentication information used for authentication in combination with the user identification information are obtained. If the authentication using the aforementioned user identification information and user authentication information is successful, permission will be granted to use the functions related to personal information. After permission is granted to use the aforementioned personal information function, if predetermined conditions are met, the system will request the provision of information that matches the information used for authentication. If, after requesting the provision of information matching the information used for the aforementioned authentication, the user fails to obtain such information, the user will be prohibited from continuing to use the personal information-related functions. Information processing system.

2. The predetermined conditions are at least one of the following: a predetermined operation is detected among the operations for performing the functions related to the personal information; a change is detected in the person performing the operations for performing the functions related to the personal information; or a predetermined time interval has elapsed. The information processing system according to claim 1.

3. If the predetermined conditions include the detection of the predetermined operation, the processor shall If, after requesting the provision of information matching the information used for authentication, information matching the information used for authentication is not obtained, the function corresponding to the predetermined operation will not be executed. The information processing system according to claim 2.

4. The aforementioned predetermined operation is an operation to make the personal information visible, and if the processor requests the provision of information that matches the information used for authentication, but fails to obtain information that matches the information used for authentication, it will not make the personal information visible. The information processing system according to claim 3.

5. If the predetermined conditions include the elapsed time interval, the processor shall After permission is granted to use the aforementioned personal information function, the system will request the provision of information that matches the information used for authentication at each predetermined time interval. The information processing system according to any one of claims 2 to 4.

6. The aforementioned processor, After requesting the provision of information that matches the information used for the authentication, if information that matches the information used for the authentication is obtained, the user is permitted to continue using the personal information function. The information processing system according to any one of claims 1 to 4.

7. The information that matches the information used for the authentication is the information that matches the user identification information, and the processor, If user identification information is obtained from a contactless communication-enabled information recording medium, and the predetermined conditions are met after permission to use the personal information-related functions has been granted, the system requests the information recording medium to provide information matching the user identification information via contactless communication, and if, after requesting the provision of information matching the user identification information, information matching the user identification information is obtained from the information recording medium via contactless communication, the system permits the continued use of the personal information-related functions. The information processing system according to claim 1.

8. The aforementioned information recording medium is a terminal having a locking function, and the processor is If, after requesting the terminal to provide information matching the user identification information via contactless communication, the terminal fails to obtain information matching the user identification information via contactless communication, the continued use of the personal information function is prohibited, and a message indicating that the terminal is not unlocked is output. The information processing system according to claim 7.

9. The aforementioned information recording medium is a terminal, and the aforementioned processor is If user identification information is obtained through an application operated on the terminal, and after requesting the provision of information matching the user identification information, no matching information is obtained, the continued use of the personal information function is prohibited, and a message indicating that the application is not displayed in an operable state on the terminal is output. The information processing system according to claim 7 or 8.

10. The information that matches the information used for the authentication is the information that matches the user identification information, and the processor, When user identification information is obtained from an information recording medium that can communicate via contact, and after requesting the provision of information matching the user identification information, information matching the user identification information is obtained from the information recording medium, a message is output to prevent the user from forgetting to take the information recording medium home. An information processing system according to any one of claims 1 to 4, 7, and 8.

11. On the computer, The user identification information and user authentication information used for authentication in combination with the user identification information are obtained. If the authentication using the aforementioned user identification information and user authentication information is successful, permission will be granted to use the functions related to personal information. After permission is granted to use the aforementioned personal information function, if predetermined conditions are met, the system will request the provision of information that matches the information used for authentication. If, after requesting the provision of information that matches the information used for the aforementioned authentication, the user fails to obtain such information, the user will be prohibited from continuing to use the personal information-related functions. An information processing program that performs a process that includes the following.

Citation Information

Patent Citations

  • Automatic logout device and automatic logout method

    JP2015161971A