Access control system, access control method, access control program, and access control terminal

JP2026139116APending Publication Date: 2026-09-01PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025025542
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2026-09-01

AI Technical Summary

Benefits of technology

【0012】 本開示によれば、管理エリアに対するユーザの入退管理のために実行される顔認証に関し、認証対象のユーザを予め設定された認証可能領域内に円滑に移動させることが可能となる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026139116000001_ABST
    Figure 2026139116000001_ABST
Patent Text Reader

Abstract

The system smoothly guides the user targeted for facial recognition into a pre-defined authentication area. [Solution] The access control system 1 comprises a user terminal 4 and a facial recognition server 2 that performs facial recognition of the user based on the user's facial information acquired by the user terminal 4. The user terminal 4 acquires information about its current location and determines whether its current location is within a pre-configured authentication area corresponding to at least one of the entrance and exit of the management area 51. Based on the determination of the current location, if the current location is within the authentication area, it requests the facial recognition server 2 to perform facial recognition of the user. If the current location is not within the authentication area, it displays guidance screens 60A and 60B to guide the user to the authentication area.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an entrance / exit management system, an entrance / exit management method, an entrance / exit management program, and an entrance / exit management terminal for managing entry and exit of a user into and from a management area.

Background Art

[0002] In recent years, face authentication technology, which is one type of biometric authentication technology, has become widespread in entrance / exit management for facilities. According to face authentication technology, personal identification is performed using features of an individual's face, which eliminates the need for a dedicated physical authentication means such as an IC card, and can reduce risks such as loss, theft, and unauthorized use of such authentication means.

[0003] On the other hand, when introducing face authentication technology, it is necessary to prevent unnecessary execution of face authentication, erroneous recognition due to unauthorized face authentication (for example, impersonation), and the like. Therefore, for example, a technique for restricting the execution of authentication under specific conditions is known (see Patent Document 1). In this conventional technique, an authentication system that performs authentication to confirm the legitimacy of a user includes an authentication terminal that authenticates a user, an authenticable area that is an area within a predetermined distance from the authentication terminal is set around the authentication terminal, and the user can start authentication when the user approaches the authentication terminal and enters the authenticable area.

Prior Art Literature

Patent Literature

[0004]

Patent Document 1

Summary of the Invention

Problem to be Solved by the Invention

[0005] In the prior art described in Patent Document 1 above, when a user enters an authentication area, they can initiate authentication by touching a button displayed on the authentication terminal's display to have their face photographed. Furthermore, the authentication system enhances security by preventing impersonation by limiting the success of authentication when multiple users with similar faces are in the authentication area.

[0006] However, the conventional technologies described above do not take any particular care to smoothly guide the user to such an authentication-enabled area.

[0007] Therefore, the main purpose of this disclosure is to provide an access control system, an access control method, an access control program, and an access control terminal that enable smooth movement of a user to be authenticated into a pre-set authentication area, with respect to facial recognition performed for user access control to a management area. [Means for solving the problem]

[0008] The access control system of this disclosure is an access control system that manages the entry and exit of users to and from a management area, comprising a user terminal carried by the user and a face recognition server that performs face recognition of the user based on the user's face information acquired by the user terminal, wherein the user terminal acquires information on the current location, determines whether the current location is within a pre-configured authentication area corresponding to at least one of the entrance and exit of the management area, requests the face recognition server to perform face recognition of the user if the current location is within the authentication area as a result of the determination regarding the current location, and displays a guidance screen to guide the user to the authentication area if the current location is not within the authentication area.

[0009] The access control method of this disclosure is an access control method using an access control system that manages the entry and exit of users to and from a management area, wherein the method acquires information on the current location of a user terminal carried by the user, determines whether the current location is within an authenticationable area that is set in advance and corresponds to at least one of the entrance and exit of the management area, and if the result of the determination regarding the current location is that the current location is within the authenticationable area, performs facial recognition of the user, and if the current location is not within the authenticationable area, displays a guidance screen on the user terminal to guide the user to the authenticationable area.

[0010] The access control program of this disclosure is an access control program that manages the entry and exit of users to and from a management area, and is configured to cause the user terminal carried by the user to acquire information of the current location, to determine whether the current location is within an authenticationable area that is set in advance and corresponds to at least one of the entrance and exit of the management area, and if the result of the determination regarding the current location is that the current location is within the authenticationable area, to acquire the user's face information and to request a face authentication server that performs face authentication of the user to perform face authentication of the user based on the user's face information, and if the current location is not within the authenticationable area, to display a guidance screen to guide the user to the authenticationable area.

[0011] The access control terminal of this disclosure is an access control terminal for managing the entry and exit of users to and from a management area, and is configured to acquire information on the user's current location, determine whether the current location is within a pre-configured authentication area corresponding to at least one of the entrance and exit of the management area, and if, as a result of the determination regarding the current location, the current location is within the authentication area, acquire the user's facial information and perform facial authentication of the user based on the user's facial information, and if the current location is not within the authentication area, display a guidance screen to guide the user to the authentication area. [Effects of the Invention]

[0012] According to this disclosure, facial recognition performed for user access control to a management area makes it possible to smoothly move the user to be authenticated into a pre-configured authentication area. [Brief explanation of the drawing]

[0013] [Figure 1] Overall configuration diagram of the access control system according to the first embodiment [Figure 2] Figure 1 is a flowchart illustrating the user authentication process using user terminals in the access control system shown. [Figure 3] Figure 1 is an explanatory diagram showing an example of a management area set up in the access control system. [Figure 4] Figure 2 shows a flowchart illustrating the first modified version of the user authentication process. [Figure 5] Figure 4 is an explanatory diagram showing the first example of the user guidance screen for step ST210. [Figure 6] Figure 4 is an explanatory diagram showing a second example of the user guidance screen for step ST210. [Figure 7] Figure 2 shows a flowchart illustrating a second modified example of the user authentication process. [Figure 8] Sequence diagram showing the user registration process in the access control system according to the first embodiment. [Figure 9] Figure 8 is an explanatory diagram showing an example of access control information related to ST1003. [Figure 10] Figure 9 is an explanatory diagram showing another example of access control information. [Figure 11] Sequence diagram showing user entry and exit processing by the access control system according to the first embodiment. [Figure 12] A flowchart showing a first modified example of the user entry process shown in Figure 11. [Figure 13] A flowchart showing a second modified example of the user entry process shown in Figure 11. [Figure 14] Overall configuration diagram of the access control system according to the second embodiment [Figure 15] Sequence diagram showing the user registration process by the access control system according to the second embodiment. [Figure 16] Sequence diagram showing user entry / exit processing by the entry / exit management system according to the second embodiment MODE FOR CARRYING OUT THE INVENTION

[0014] A first invention made to solve the above problem is an entry / exit management system that manages entry and exit of a user to and from a management area, comprising: a user terminal carried by the user; and a face authentication server that performs face authentication of the user based on the user's face information acquired by the user terminal, wherein the user terminal acquires current position information, determines whether or not the current position is within a pre-set authenticable region corresponding to at least one of an entrance and an exit of the management area, requests the face authentication server to execute face authentication of the user when the current position is within the authenticable region as a result of the determination on the current position, and is configured to display a guidance screen for guiding the user to the authenticable region when the current position is not within the authenticable region.

[0015] According to this, regarding face authentication performed for managing entry and exit of a user to and from a management area, a user to be authenticated can be smoothly moved into a pre-set authenticable region.

[0016] Further, according to a second invention, the user terminal acquires current time information, determines whether or not the current time is included in a pre-set authenticable time zone, and is configured to request the face authentication server to execute face authentication of the user only when the current time is included in the authenticable time zone as a result of the determination on the current time.

[0017] According to this, since execution of face authentication is permitted only during the authenticable time zone, unnecessary execution of face authentication is prevented, and security is also improved.

[0018] Furthermore, the third invention further includes a management server for managing information regarding the entry and exit of the user, wherein the user terminal obtains the result of facial recognition of the user from the facial recognition server, transmits the result of facial recognition of the user to the management server, and the management server records the result of facial recognition of the user as part of the information regarding the entry and exit of the user.

[0019] According to this, information regarding user entry and exit can be managed based on the results of facial recognition performed for user access control to the management area.

[0020] Furthermore, the fourth invention is configured such that, if the management server determines that the user's identity has been successfully verified based on the results of the user's facial recognition, it executes an authorization granting process to grant the user pre-configured permissions.

[0021] According to this, based on the results of facial recognition performed to manage user access to the management area, users can be appropriately granted pre-configured permissions.

[0022] Furthermore, the fifth invention is an access control method using an access control system that manages the entry and exit of users to and from a management area, wherein the system acquires information on the current location of a user terminal carried by the user, determines whether the current location is within a preset authentication area corresponding to at least one of the entrance and exit of the management area, and if the result of the determination regarding the current location is that the current location is within the authentication area, it performs facial authentication of the user, and if the current location is not within the authentication area, it displays a guidance screen on the user terminal to guide the user to the authentication area.

[0023] According to this, facial recognition performed for user access control to a management area allows for smooth movement of the user being authenticated into a pre-configured authentication area.

[0024] Furthermore, the sixth invention is an access control program for managing the entry and exit of users to and from a management area, wherein the user terminal carried by the user is configured to acquire information of the current location, to determine whether the current location is within a pre-configured authentication area corresponding to at least one of the entrance and exit of the management area, and if the result of the determination regarding the current location is that the current location is within the authentication area, the user's facial information is acquired and the facial authentication server that performs facial authentication of the user is requested to perform facial authentication of the user based on the user's facial information, and if the current location is not within the authentication area, a guidance screen is displayed to guide the user to the authentication area.

[0025] According to this, facial recognition performed for user access control to a management area allows for smooth movement of the user being authenticated into a pre-configured authentication area.

[0026] Furthermore, the seventh invention is an access control terminal for managing the entry and exit of users to and from a management area, which acquires information on the user's current location, determines whether the current location is within a preset authentication area corresponding to at least one of the entrance and exit of the management area, and if, as a result of the determination regarding the current location, the current location is within the authentication area, acquires the user's facial information and performs facial authentication of the user based on the user's facial information, and if the current location is not within the authentication area, displays a guidance screen to guide the user to the authentication area.

[0027] According to this, facial recognition performed for user access control to a management area allows for smooth movement of the user being authenticated into a pre-configured authentication area.

[0028] The embodiments of this disclosure will be described below with reference to the drawings.

[0029] (First Embodiment) As shown in Figure 1, the access control system 1 according to the first embodiment includes a facial recognition server 2, a management server 3, and a user terminal 4, and manages user entry and exit to a management area using facial recognition technology. The facial recognition server 2, the management server 3, and the user terminal 4 can communicate with each other via a known communication network 5 such as the Internet or a dedicated line network. However, their communication with each other may be performed via other information processing devices (i.e., indirectly) that are not shown.

[0030] In Figure 1, for illustrative purposes, one management server 3 is shown, but the access control system 1 can typically include multiple management servers 3. In that case, the multiple management servers 3 are operated by, for example, multiple different operators. Such operators include individuals, corporations, local governments, and organizations that manage one or more of their own management areas. Similarly, the access control system 1 can typically include multiple user terminals 4 carried by multiple users who wish to enter or exit each management area. Note that the management servers 3 are not essential components of the access control system 1, as they are usually operated by operators different from the administrator of the access control system 1.

[0031] In the following explanation, the term "controlled area" refers to an area where entry and exit are permitted only to persons with specific authority. "Controlled areas" include, for example, construction sites, event venues, public facilities, commercial facilities, and office buildings, as well as specific areas within them (e.g., conference rooms in office buildings). Furthermore, the term "entry and exit" does not necessarily include both entry into and exit from the area in question (in this case, the controlled area); at least one of these is sufficient.

[0032] The facial recognition server 2 includes a communication unit 11, a feature generation unit 12, an authentication unit 13, and a storage unit 14, and performs facial recognition processing for the user to be authenticated in response to a request from the user terminal 4.

[0033] The communication unit 11 communicates with other devices via the communication network 5 in accordance with a known communication protocol. This allows the face recognition server 2 to obtain information and data necessary for face recognition processing from other devices (e.g., user terminal 4) while simultaneously transmitting processing results to other devices. The face recognition server 2 may obtain the necessary information and data from other devices only when it is necessary to perform face recognition processing.

[0034] The feature generation unit 12 detects a human face from the image (including the face image) of the user to be authenticated received from the user terminal 4, and obtains the user's face image by extracting the detected face region. Furthermore, the feature generation unit 12 can generate the user's face features from the obtained user's face image based on known methods.

[0035] Furthermore, if the facial recognition process for the user is performed without using facial features, the feature generation unit 12 may be omitted. Also, the user terminal 4 may have the same functionality as the feature generation unit 12, in which case the feature generation unit 12 may also be omitted.

[0036] The authentication unit 13 can compare the user's facial information with the facial information of multiple individuals (hereinafter referred to as "registered individuals") that have been registered in advance, based on known facial recognition technology. Here, the authentication unit 13 compares the user's facial features with the facial features of multiple registered individuals.

[0037] More specifically, for example, the authentication unit 13 can compare the two facial features and calculate a matching score. The matching score is a numerical value indicating the degree of agreement (matching degree) between the two facial features, with a higher value indicating a better match. When the matching score is above a predetermined threshold, the authentication unit 13 can determine that the person being authenticated is the same person as a registered user (i.e., a legitimate user). This allows the facial authentication server 2 to verify the user's identity. On the other hand, when the matching score is below a predetermined threshold, the authentication unit 13 can determine that the user being authenticated is not included in the registered users (i.e., is not a legitimate user).

[0038] In this embodiment, facial features are used as the facial information of the user and registered person to be authenticated. However, this facial information only needs to include at least one of the facial image generated by facial photography and the facial features extracted from that facial image. The authentication unit 13 can also perform facial matching using the facial image as the facial information of the user and registered person to be authenticated.

[0039] The storage unit 14 stores information and data necessary for information processing in the face recognition server 2. For example, the storage unit 14 includes a face information DB (database) 15 in which the face information of registered users is registered. The storage unit 14 may also store application software (an example of a program) for performing face recognition processing for users in response to requests from the user terminal 4.

[0040] The facial recognition server 2 is, for example, a computer equipped with hardware configurations to implement the above-described parts 11-14. The facial recognition server 2 may include a network interface consisting of an antenna and communication circuits as hardware for implementing the communication unit 11. The facial recognition server 2 may also include one or more processors (e.g., CPU, GPU, and DPU) capable of executing various application software and memory as hardware for implementing the communication unit 11, the feature generation unit 12, and the authentication unit 13. The facial recognition server 2 may also include memory and storage as hardware for implementing the storage unit 14.

[0041] Furthermore, the facial recognition server 2 is not limited to a single physical device. For example, the facial recognition server 2 may be implemented in a cloud environment where multiple processing units work together (i.e., as a cloud service), or it may be implemented by a distributed processing system or a virtual server. In that case, the facial recognition server 2 may consist of a distributed system including servers, data centers, storage, and network equipment, each connected to the communication network 5.

[0042] The management server 3 includes a communication unit 21, an access control unit 22, and a storage unit 23, and performs processing to manage one or more pre-configured management areas.

[0043] The communication unit 21, like the communication unit 11 described above, can communicate with other devices in the access control system 1. This allows the management server 3 to send and receive necessary information and data with the facial recognition server 2 and the user terminal 4.

[0044] The access control unit 22 records (or updates) access control information (an example of access information) for multiple individuals for each management area as a process for managing the management area.

[0045] The storage unit 23 stores information and data necessary for information processing in the management server 3. For example, the storage unit 23 includes an access control DB 24 in which access control information of individuals (usually registered users) is registered. The storage unit 23 may also store application software (an example of a program) for performing processes such as user registration and granting permissions to users in response to requests from user terminals 4. User registration includes registering the user's facial information to enable access to the management area. Registered users are treated as registered users (i.e., legitimate users) in the access control system 1. Granting permissions to users includes permission to enter and exit the management area.

[0046] The management server 3 is, for example, a computer equipped with the hardware configuration necessary to implement each of the above-described parts 21-23. The hardware configuration of the management server 3 can be the same as that of the facial recognition server 2 described above.

[0047] The user terminal 4 includes a communication unit 31, a camera unit 32, a display unit 33, a storage unit 34, and a facial recognition application 35, and is carried by the user and used for entering and exiting the user's managed area.

[0048] The communication unit 31, like the communication unit 11 described above, can communicate with other devices in the access control system 1. This allows the user terminal 4 to send and receive necessary information and data with the facial recognition server 2 and the management server 3.

[0049] The camera unit 32 acquires an image including the user's face (i.e., generates a user's face image) by photographing the user using the user terminal 4.

[0050] The display unit 33 displays a guidance screen for providing instructions and information to the user.

[0051] The storage unit 34 stores information and data necessary for information processing on the user terminal 4. For example, the storage unit 34 includes authorization information 36 granted to the user. The authorization information 36 includes calendar information, location information, and time information related to the user's access to and exit from designated management areas.

[0052] Calendar information may include information on the date (year, month, day) or period (hereinafter referred to as "authentication-enabled date") on which a user is permitted to enter and exit the management area (i.e., pass through the entrance / exit gates of the management area). Alternatively, calendar information may include information on the day of the week instead of dates or periods.

[0053] Location information includes information about the area where facial recognition can be performed when a user enters or exits the management area (hereinafter referred to as the "authentication area") (for example, coordinates indicating the area). The authentication area is pre-configured to correspond to at least one of the entrance and exit of the management area. For example, the authentication area is a plane (i.e., two-dimensional) area that ignores height. In that case, the authentication area is configured as an area of ​​a predetermined shape (for example, a rectangle or a circle) centered on the entrance to or exit from the management area 51 in a planar view.

[0054] The authentication area may be set to overlap with the entrance or exit of the management area 51, or it may be set near the entrance or exit of the management area 51. Also, the entrance and exit of the management area 51 may be the same, or they may be located in different positions.

[0055] Furthermore, the authentication area may include height information. In that case, the user terminal 4 can obtain height information at its current location based, for example, GPS (Global Positioning System) altitude data, barometric pressure sensor measurements, or beacon signals from a beacon transmitter described later.

[0056] The time information includes information about the time period during which users are permitted to enter and exit the management area (hereinafter referred to as the "authentication period"). However, such authentication period information may be included in the calendar information along with the date and period.

[0057] Furthermore, the storage unit 34 may store application software (an example of an access control program) for executing processes when a user terminal 4 enters or leaves the management area. Such application software may include a facial recognition application 35.

[0058] The user terminal 4 has the following functions implemented by the facial recognition application 35: a location acquisition unit 41, a date and time acquisition unit 42, an authentication feasibility determination unit 43, a facial image acquisition unit 44, a user guidance unit 45, and a user authority management unit 46.

[0059] The position acquisition unit 41 can utilize a known satellite positioning system such as GNSS (Global Navigation Satellite System). The position acquisition unit 41 can acquire information about the current location of the user terminal 4 based on positioning signals from satellites. Alternatively, the position acquisition unit 41 may acquire information about the current location of the user terminal 4 based on beacon signals from beacon transmitters installed within or around the management area.

[0060] The date and time acquisition unit 42 can acquire date (including period information as needed) and current time information from an NTP (Network Time Protocol) server connected to the communication network 5. Alternatively, the date and time acquisition unit 42 may acquire date and current time information from a real-time clock built into the user terminal 4.

[0061] The authentication feasibility determination unit 43 can determine whether or not to perform facial recognition on the user based on the current location information of the user terminal 4 obtained by the location acquisition unit 41 and the information of the authentication-enabled area. The authentication feasibility determination unit 43 can also determine whether or not to perform facial recognition on the user based on the date information obtained by the date and time acquisition unit 42 and the calendar information. Furthermore, the authentication feasibility determination unit 43 can also determine whether or not to perform facial recognition on the user based on the current time information obtained by the date and time acquisition unit 42 and the authentication-enabled time period.

[0062] The face image acquisition unit 44 acquires the user's face image captured by the shooting unit 32 as an image for user face recognition. The face image acquisition unit 44 can also prompt the user to take a picture of their face (for example, by displaying a shooting instruction on the display).

[0063] The user guidance unit 45 executes a process to guide the user (i.e., the user terminal 4) to the authentication area if the user's current location is not within the authentication area. For example, the user guidance unit 45 can display a guidance screen on the display to guide the user to the authentication area.

[0064] The user privilege management unit 46 obtains information regarding privileges granted to users from the management server 3 and stores it as privilege information 36. The user privilege management unit 46 can also update the privilege information 36 based on information obtained from the management server 3 as appropriate.

[0065] User terminal 4 is, for example, a computer equipped with the hardware configuration necessary to implement each of the above-described parts 31-34. User terminal 4 may be a smartphone or tablet used personally by the user. User terminal 4 may include a network interface consisting of an antenna and communication circuits as hardware for implementing the communication unit 31. User terminal 4 may also include a camera and a touch panel display as hardware for implementing the shooting unit 32 and the display unit 33, respectively. Furthermore, user terminal 4 may include one or more processors (e.g., CPU and GPU) and memory capable of running the face recognition application 35 as hardware for implementing the above-described functions by the face recognition application 35. Furthermore, user terminal 4 may include memory and storage as hardware for implementing the storage unit 34.

[0066] Next, with reference to Figures 2 and 3, the user authentication process by the user terminal 4 in the access control system 1 according to the first embodiment will be described. Here, as shown in Figure 3, the example will be that the user 50 to be authenticated is a worker at a construction site and enters and exits the management area 51 (in this case, the work area) for performing work.

[0067] As shown in Figure 2, when a user enters the management area 51, they activate the facial recognition application 35 by operating the user terminal 4 near the gate 52 located at the entrance / exit (ST101).

[0068] Subsequently, the user terminal 4 performs a calendar check using the facial recognition app 35. If it determines that the current date corresponds to an available authentication date (Yes in ST102), it then performs a location check.

[0069] If, in its location determination, user terminal 4 determines that its current location is within the authentication area (Yes in ST103), it then performs a time determination.

[0070] In determining its location, the user terminal 4 can acquire information about its current location based on positioning signals from satellite 55 when it is relatively far from gate 52 as shown in Figure 3. The same applies to determining the location when it is difficult to receive beacon signals from beacon transmitter 56A installed near gate 52.

[0071] Furthermore, when the user terminal 4 is relatively close to the gate 52 shown in Figure 3, it can acquire information about its current location based on the beacon signal from the beacon transmitter 56A. The same applies to location determination in locations where it is difficult to receive positioning signals from satellite 55. The beacon transmitter 56A is a wireless transmitter that emits radio waves based on, for example, Bluetooth®.

[0072] If the user terminal 4 determines in its time determination that the current time falls within the authentication-enabled time period (Yes in ST104), it determines that all the conditions for performing facial recognition have been met. As a result, the user terminal 4 displays information (e.g., text or graphics) on its display to inform the user that facial recognition is possible (ST105). Furthermore, the user terminal 4 sends a request to perform facial recognition to the facial recognition server 2 (ST106). Note that the user terminal 4 can also determine whether the conditions for performing facial recognition have been met based on at least one of the multiple determinations made in steps ST102-ST104. In other words, some of steps ST102-ST104 may be omitted.

[0073] When the facial recognition server 2 receives a request to perform facial recognition from the user terminal 4, it performs the facial recognition process for the user and sends the authentication result information to the user terminal 4. Based on the authentication result information received from the facial recognition server 2, if the user terminal 4 determines that facial recognition was successful (i.e., identity verification is complete) (Yes in ST107), it notifies (sends) the authentication result information to the management server 3 (ST108). Furthermore, the user terminal 4 displays information (e.g., text or a graphic) on its display to inform the user that facial recognition was successful (ST109).

[0074] Once the user's identity has been verified in this manner, gate 52 will open, and the user will be able to enter the management area 51.

[0075] Although Figure 2 illustrates the case where a user enters the management area 51, similar processing may be performed when a user exits the management area 51. If the user terminal 4 can receive positioning signals from satellite 55 in the management area 51, it can obtain information about its current location based on the positioning signals from satellite 55, as in the case described above. The user terminal 4 can also obtain information about its current location based on beacon signals from beacon transmitters 56B-56D installed within the management area 51. However, in the access control system 1, the user's facial recognition process may be omitted when a user exits the management area 51.

[0076] Furthermore, the user authentication process shown in Figure 2 is applicable to any management area, not just when the management area 51 is set as a construction site. For example, the user authentication process shown in Figure 2 can also be applied when the management area 51 is set as an event venue. In that case, the user is an event participant (for example, a concert attendee) and can enter and exit the management area (for example, a designated area in a concert venue) in order to participate in the event.

[0077] Next, with reference to Figures 4, 5, and 6, a first modified example of the user authentication process shown in Figure 2 will be described. Regarding the user authentication process shown in Figure 4, steps similar to those shown in Figure 2 are denoted by the same reference numerals, and detailed explanations are omitted. Furthermore, regarding the user authentication process related to the first modified example, matters not specifically mentioned below will be treated the same as in the above-mentioned case.

[0078] In the access control system 1, if the user to be authenticated is familiar with the management area and its entrances and exits, the user (user terminal 4) can easily reach the authentication area. On the other hand, for example, if the management area is set in a place the user is visiting for the first time, the user may not be fully familiar with the location of the management area and its entrances and exits.

[0079] Therefore, as shown in Figure 4, in the user authentication process according to the first modified example, if the current location of the user terminal 4 is not within the authentication area (No in ST103), the user terminal 4 executes a process to guide the user to a location where facial authentication is possible (ST210).

[0080] In step ST210, the user terminal 4's display shows, for example, the guidance screen 60A shown in Figure 5. The guidance screen 60A displays a map image of the area around the user's current location. The guidance screen 60A also displays information (in this case, a graphic and text) indicating the location the user should reach to perform authentication (in this case, the location of gate C, which is the entrance to the management area) and the user's current location, superimposed on the map image. Furthermore, the guidance screen 60A displays a message 61A to guide the user to the location they should reach (in this case, the text "You are approaching an authentication point. Proceed 20m further northeast.").

[0081] Alternatively, in step ST210, the user terminal 4's display may show, for example, the guidance screen 60B shown in Figure 6. On the guidance screen 60B, information indicating the authentication area (in this case, a circular area 62) is superimposed on the map image, surrounding the location the user should reach (in this case, the location of gate C, which is the entrance to the management area). Furthermore, the guidance screen 60B displays a message 61B to guide the user to the authentication area (in this case, the text: "You are approaching the authentication area. Please proceed to the red circular area (corresponding to the circular area indicating the management area 51).").

[0082] Furthermore, the user terminal 4 may display information about the facility or other area where the management area is set on the display screens 60A and 60B. For example, if the management area is set to an event venue, the user terminal 4 can display information about the event (for example, the start time of the event or information about the event's time schedule) on the display.

[0083] When the user moves according to the instructions on the guidance screen 60A (or guidance screen 60B) and the current location of the user terminal 4 finally enters the authentication area (Yes in ST103), the guidance to the user in step ST210 is completed.

[0084] Thus, in this first modified version of the user authentication process, if the user (user terminal 4) is not currently located within the authentication area, a guidance screen is displayed on the user terminal 4 to direct the user to the authentication area. This allows the user to be smoothly moved into the pre-configured authentication area.

[0085] Next, with reference to Figure 7, a second modified example of the user authentication process shown in Figure 2 will be described. Regarding the user authentication process shown in Figure 7, steps similar to those shown in Figure 2 are denoted by the same reference numerals, and detailed explanations are omitted. Furthermore, regarding the user authentication process related to the second modified example, matters not specifically mentioned below will be treated the same as in the above-mentioned case.

[0086] As shown in Figure 7, in the second modified example, if the current location of the user terminal 4 is not within the authentication area (No in ST103), the user terminal 4 determines whether the current time is within a predetermined time period from the authentication time period (the earliest time within that time period) (ST310). If the current time is within the predetermined time period (Yes in ST310), the user terminal 4 guides the user to a location where facial recognition is possible, similar to step ST201 shown in Figure 4 (ST311).

[0087] Thus, in this second modified version of the user authentication process, a guidance screen can be displayed at an appropriate time to direct the user to the authentication area.

[0088] Next, with reference to Figures 8, 9, and 10, the user registration process in the access control system 1 according to the first embodiment will be described.

[0089] Users who use the access control system 1 must register in advance in order to successfully execute the user authentication process described above.

[0090] As shown in Figure 8, a user can request user registration from the management server 3 by operating the user terminal 4. At this time, the user can access the management server 3 from the user terminal 4 by using, for example, a facial recognition application 35 or a general-purpose browser. In addition, user information to identify the user (for example, the user's name, date of birth, gender, and address) is sent to the management server 3 along with the user registration request.

[0091] When the management server 3 receives a user registration request from the user terminal 4, it registers the acquired user information and the corresponding authorization information for that user in the access control DB 24 as access control information (ST1001). Subsequently, the management server 3 requests a facial image for user registration from the user terminal 4.

[0092] When user terminal 4 receives a request for a face image from management server 3, it executes a process to acquire the user's face image (ST1002). At this time, user terminal 4 can, for example, display a message on its display prompting the user to take a picture of their face (i.e., a shooting instruction). The user can then take a picture of their own face using the camera of user terminal 4 in accordance with that message.

[0093] Next, user terminal 4 acquires the user's face image and sends it to management server 3. When management server 3 receives the user's face image from user terminal 4, it registers it as access control information in access control DB 24 along with the authorization information corresponding to that user (ST1003).

[0094] For example, if the user is a worker at a construction site, the access control information may include, as shown in Figure 9, the user ID, the user's name, the site name (name of the work location), the authentication area (coordinate data), the scheduled work date, the scheduled and actual start time, the scheduled and actual end time, the time the user leaves the premises, the time the user returns from leaving, the beacon ID (for example, the IDs of beacon transmitters 56A-56D shown in Figure 3), and the registered facial image (image data).

[0095] For example, if the user is an event participant (e.g., a concert attendee), the entry / exit management information may include, as shown in Figure 10, the user ID, the user's name, the venue name (the name of the event location), the authenticated area, the scheduled work date, the scheduled and actual work start time, the scheduled and actual work end time, the time the user leaves the premises, the time the user returns from leaving, the beacon ID, and the registered facial image.

[0096] Once the user registration process is successfully completed, the user will be treated as a legitimate user with the necessary permissions to enter and exit specific management areas.

[0097] Next, with reference to Figure 11, the user entry and exit process in the access control system 1 according to the first embodiment will be described.

[0098] During user entry and exit processing, user terminal 4 performs the same processes (ST2001-ST2004) as steps ST101-ST104 shown in Figure 4. In step ST2003, for example, user terminal 4 can perform location determination based on positioning signals from satellite 55 (see Figure 3). Then, when all the conditions for facial recognition are met, user terminal 4 displays information on its display to inform the user that facial recognition is possible, similar to step ST105 in Figure 4 (ST2005).

[0099] Furthermore, in step ST2003, the user terminal 4 may perform location determination based on beacon signals from beacon transmitters 56A-56D (see Figure 3) installed near the entrance and exit of the management area, for example, as shown in Figure 12 (first modified example of user entry processing). The beacon signals include, for example, beacon ID information to identify the originating beacon transmitters 56A-56D. Depending on its current location, the user terminal 4 can utilize beacon signals from beacon transmitter 56A installed outside the management area 51 or from beacon transmitters 56B-56D installed inside the management area 51.

[0100] Next, user terminal 4 executes the process of acquiring the user's face image (ST2006). This step ST2006 is executed in the same way as step ST1002 in Figure 8, but differs from step ST1002 in that a user face image for authentication (i.e., for entry / exit processing) is acquired. After that, user terminal 4 sends the acquired user face image to face authentication server 2 along with a request to execute face authentication.

[0101] When the facial recognition server 2 receives a request to perform facial recognition from the user terminal 4, it performs the facial recognition process described above (ST2007). Subsequently, the facial recognition server 2 sends the result of the facial recognition process (hereinafter referred to as the "facial recognition result") to the user terminal 4.

[0102] When the user terminal 4 recognizes that the facial recognition process was successful based on the received facial recognition result, it transmits the facial recognition result to the management server 3. The transmitted facial recognition result may also include at least some of the information used in the determination in steps ST2002-ST2004 (e.g., date, current location, and current time).

[0103] When the management server 3 receives a facial recognition result from the user terminal 4, it stores the information contained in the facial recognition result in the access control DB 24 as part of the access control information for the corresponding user (ST2008). At this time, for example, the management server 3 can record the current time information received along with the facial recognition result in the access control information (see Figure 9) as the actual arrival time (or departure time).

[0104] Therefore, the management server 3 can perform an authorization granting process to grant pre-configured privileges to the user (ST2009). For example, in the authorization granting process, the management server 3 can send an open-door operation command (control command) to an external device such as the gate 52 shown in Figure 3. As a result, when the gate 52 is opened, the user can enter the management area 51.

[0105] On the other hand, user terminal 4 can display on its screen that the facial recognition process has been successfully completed (ST2010).

[0106] Next, with reference to Figure 13, a second modified example of the user entry process shown in Figure 11 will be described. Regarding the user entry process shown in Figure 13, the user authentication process related to the second modified example will be the same as described above, unless otherwise specifically mentioned.

[0107] In this scenario, the management server 3 is equipped with application software that includes the functions of a location acquisition unit 41, a date and time acquisition unit 42, and an authentication success / failure determination unit 43, all controlled by the facial recognition application 35 of the user terminal 4 mentioned above.

[0108] As shown in Figure 13, when the facial recognition application 35 is launched (ST3001), the user terminal 4 sends date information (including period information if necessary) to the management server 3.

[0109] When the management server 3 receives date information from the user terminal 4, it performs the same process as the calendar determination performed by the user terminal 4 (see ST2002 in Figure 11) (ST3002). The management server 3 then sends the result of the calendar determination to the user terminal 4.

[0110] When user terminal 4 recognizes that the calendar determination was successful based on the received calendar determination result, it obtains its current location information (ST3003) and sends that information to management server 3.

[0111] When the management server 3 receives location information from the user terminal 4, it performs the same process as the location determination performed by the user terminal 4 (see ST2003 in Figure 11) (ST3004). Subsequently, the management server 3 sends the result of the location determination to the user terminal 4. After that, the management server 3 performs the same process as the time determination performed by the user terminal 4 (see ST2004 in Figure 11) (ST3005). Subsequently, the management server 3 sends the result of the time determination to the user terminal 4. Note that in the time determination in step ST3005, the management server 3 can obtain the current time information based on an NTP server or its built-in clock. However, the management server 3 may also obtain the current time information from the user terminal 4.

[0112] Subsequently, when the user terminal 4 recognizes that all conditions for performing facial recognition have been met based on the location and time determination results received from the management server 3, it displays information on the display to inform the user that facial recognition is possible, similar to step ST2005 in Figure 11 (ST3006).

[0113] The subsequent steps ST3007-ST3011 are the same as steps ST2006-ST2010 shown in Figure 11.

[0114] (Second Embodiment) Next, with reference to Figure 14, the access control system 1 according to the second embodiment will be described. Regarding the access control system 1 according to the second embodiment, components similar to those in the first embodiment are denoted by the same reference numerals, and detailed descriptions are omitted. Furthermore, regarding the access control system 1 according to the second embodiment, matters not specifically mentioned below are the same as in the first embodiment.

[0115] In the access control system 1 according to the second embodiment, the facial recognition server 2 (see Figure 1) is omitted, and the facial recognition process for the user to be authenticated is performed by the user terminal 4 (an example of an access control terminal).

[0116] As shown in Figure 14, the memory unit 34 of the user terminal 4 stores facial information 71. The facial information 71 includes the facial information of registered users that has been registered in advance. Unauthorized access to the facial information 71 can be prevented by security measures such as biometric authentication (e.g., fingerprint authentication) or passwords.

[0117] Furthermore, the user terminal 4 also includes a feature generation unit 72 and an authentication unit 73, which are functions implemented by the facial recognition application 35. The feature generation unit 72 and the authentication unit 73 function similarly to the feature generation unit 12 and the authentication unit 13 (see Figure 1) in the facial recognition server 2 described above.

[0118] Next, with reference to Figure 15, the user registration process in the access control system 1 according to the second embodiment will be described. Regarding the user registration process shown in Figure 15, components similar to those in the user registration process shown in Figure 8 described above are denoted by the same reference numerals and detailed explanations are omitted.

[0119] As shown in Figure 15, during the user registration process, when the user terminal 4 acquires the user's face image (ST1002), it sends the user's face image to the management server 3 and registers it as face information 71 on its own device (ST4005). At this time, the user terminal 4 may also register the face features generated from the face image as face information 71 along with (or instead of) the user's face image.

[0120] This user registration process ensures that only legitimate users can successfully perform facial recognition on user terminal 4.

[0121] Next, with reference to Figure 16, the user entry and exit process in the access control system 1 according to the second embodiment will be described. Regarding the user registration process shown in Figure 16, components similar to those in the user registration process shown in Figure 11 described above are denoted by the same reference numerals, and detailed explanations are omitted.

[0122] As shown in Figure 16, during the user registration process, when the user terminal 4 launches the facial recognition application 35 (ST2001), it performs the clock-in or clock-out reception process (ST5011). At this time, the user terminal 4 can display a reception screen on its display where the user can select clock-in or clock-out. When the user selects clock-in or clock-out on the reception screen, calendar determination (ST2002), etc., is performed.

[0123] When user terminal 4 acquires the user's facial image (ST2006), it then performs facial recognition processing (ST5012). After that, user terminal 4 sends the facial recognition result to management server 3. Sending the facial recognition result to management server 3 only needs to be done if the facial recognition process is successful (i.e., the user is determined to be a legitimate user). At this time, along with the facial recognition result, user information to identify the user (for example, the user's name, date of birth, gender, and address) is sent to management server 3.

[0124] When the management server 3 receives the facial recognition result from the user terminal 4, it performs an authorization verification process for that user (ST5013). In the authorization verification process, the management server 3 can extract authorization information corresponding to the user from the access control information in the access control DB 24 based on the user information. Subsequently, the management server 3 sends the result of the authorization verification process (i.e., the authorization information granted to the user) to the user terminal 4.

[0125] When user terminal 4 receives the result of the authorization verification process from management server 3, it displays on its screen that the facial recognition process has been successfully completed (ST2010). At this time, user terminal 4 can also display on its screen the authorization information granted to the user (for example, information on the time periods during which entry and exit are permitted).

[0126] Thus, in the user entry and exit processing by the access control system 1 according to the second embodiment, facial recognition processing can be performed on the user terminal 4 without requiring a facial recognition server 2.

[0127] As described above, embodiments have been explained as examples of the technology disclosed in this application. However, the technology in this disclosure is not limited to these embodiments and can be applied to embodiments that have been modified, replaced, added, or omitted. Furthermore, it is possible to create new embodiments by combining the components described in the above embodiments. [Industrial applicability]

[0128] The access control system, access control method, access control program, and access control terminal related to this disclosure are useful as access control systems, access control methods, access control programs, and access control terminals for managing user access to a management area, enabling users to smoothly move into a pre-configured authentication area in relation to facial recognition performed for user access control to a management area. [Explanation of Symbols]

[0129] 1: Access control system 2: Face recognition server 3: Management Server 4: User terminal 5: Communication Network 11: Communications Department 12,72: Feature generation unit 13,73: Authentication Department 14: Storage part 15: Facial Information Database 21: Communications Department 22:Entry / exit management department 23: Storage section 24:Entry / exit management DB 31: Communications Department 32: Photography Department 33: Display section 34: Storage part 35: Face recognition app 36: Permission Information 41: Position acquisition part 42: Date and time acquisition part 43: Authentication approval / rejection unit 44: Face Image Acquisition Unit 45: User Information Department 46: User Permission Management Department 50: User 51: Management Area 52: Gate 55: Satellite 56A-56D: Beacon Transmitter 60A, 60B: Information screen 71: Facial Information

Claims

1. An access control system that manages the entry and exit of users to and from a managed area, The user terminal carried by the aforementioned user, A facial recognition server performs facial recognition of the user based on the user's facial information acquired by the user terminal. Equipped with, The aforementioned user terminal is Get information about your current location, Determine whether the current location is within a pre-configured authentication area corresponding to at least one of the entrance and exit of the management area. An access control system that, as a result of the determination regarding the current location, requests the facial recognition server to perform facial recognition of the user if the current location is within the authentication area, and displays a guidance screen to guide the user to the authentication area if the current location is not within the authentication area.

2. The aforementioned user terminal is Get the current time information Determine whether the current time falls within a pre-set authentication time period. The access control system according to claim 1, wherein, as a result of the determination regarding the current time, the current time is requested to perform facial recognition of the user only if the current time falls within the authentication-enabled time period.

3. The system further includes a management server that manages information regarding the entry and exit of the aforementioned users. The aforementioned user terminal is The results of the user's facial recognition are obtained from the facial recognition server. The result of the user's facial recognition is transmitted to the management server. The access control system according to claim 1, wherein the management server records the results of the user's facial recognition as part of the information regarding the user's entry and exit.

4. The access control system according to claim 3, wherein the management server, based on the results of facial recognition of the user, determines that the user's identity has been successfully verified, and then executes an authorization granting process to grant the user pre-configured permissions.

5. An access control method using an access control system that manages the entry and exit of users to and from a managed area, The user acquires information about the current location of the user terminal carried by the user. Determine whether the current location is within a pre-configured authentication area corresponding to at least one of the entrance and exit of the management area. Access control method comprising: if, as a result of the determination regarding the current location, the current location is within the authenticationable area, performing facial recognition of the user; and if the current location is not within the authenticationable area, displaying a guidance screen on the user terminal to guide the user to the authenticationable area.

6. An access control program that manages the entry and exit of users to and from a managed area, On the user terminal carried by the aforementioned user, To obtain information about the current location, The system determines whether the current location is within a pre-configured authentication area corresponding to at least one of the entrance and exit of the management area. An access control program that, as a result of the determination regarding the current location, if the current location is within the authenticationable area, causes the program to acquire the user's facial information and request a facial authentication server that performs facial authentication of the user to perform facial authentication of the user based on the user's facial information; and if the current location is not within the authenticationable area, displays a guidance screen to guide the user to the authenticationable area.

7. An access control terminal for managing user entry and exit to a management area, The information of the user's current location is obtained, Determine whether the current location is within a pre-configured authentication area corresponding to at least one of the entrance and exit of the management area. An access control terminal that, as a result of the determination regarding the current location, if the current location is within the authenticationable area, obtains the user's facial information and performs facial authentication of the user based on the user's facial information, and if the current location is not within the authenticationable area, displays a guidance screen to guide the user to the authenticationable area.

Citation Information

Patent Citations

  • Wireless communication system, user terminal, wireless communication method, and program

    JP6761145B1