Server device

The described system addresses the challenge of balancing safety and convenience in biometric authentication systems by performing a first authentication at a primary terminal and a second authentication at secondary terminals using acquired rules, ensuring secure and convenient access across multiple locations.

JP7687380B2Active Publication Date: 2025-06-03NEC CORP
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2023500168
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-02-17
Publication Date
2025-06-03
Estimated Expiration
2041-02-17

AI Technical Summary

Technical Problem

Existing biometric authentication systems struggle to balance safety and convenience, particularly in scenarios where multiple authentication terminals are used across different locations, leading to issues such as unauthorized access and inconvenience to users.

Method used

A server device and system that perform a first biometric authentication at a primary terminal and a second biometric authentication at secondary terminals using acquired authentication rules, ensuring that the second authentication can only succeed if the first authentication has been completed, thereby maintaining security and convenience.

Benefits of technology

This approach enhances the convenience of users by allowing seamless transitions between authentication points while maintaining security by ensuring that access is only granted when all authentication conditions are met.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007687380000001
    Figure 0007687380000001
  • Figure 0007687380000002
    Figure 0007687380000002
  • Figure 0007687380000003
    Figure 0007687380000003
Patent Text Reader

Abstract

Provided is a server device that improves convenience in an authentication system including a plurality of authentication terminals. The server device comprises an acquisition unit and an authentication unit. The acquisition unit acquires an authentication rule including a condition for determining authentication success. The authentication unit performs a first biometric authentication in response to a first authentication request transmitted from a first terminal, and performs a second biometric authentication, using the authentication rule, in response to a second authentication request transmitted from a second terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a server device, a system, a biometric authentication method, and a storage medium.

Background Art

[0002] Patent Document 1 discloses an individual processing method for gate passers. In addition to access control of users using gates, biometric authentication is used for various services.

[0003] Patent Document 2 describes obtaining an individual authentication system that can easily set up a cooperation service between an individual authentication unit and a management server and can improve the responsiveness of the cooperation service. The system of Patent Document 2 includes a management server and a cooperation service adjustment unit. The management server can manage devices in association with the authentication results at the authentication device. The cooperation service adjustment unit, in response to a cooperation service request from the management server, establishes an access right between the management server and the authentication device and sets an association between the authentication result at the authentication device and the device management by the management server.

[0004] Patent Document 3 describes providing an individual authentication system and an individual authentication method that can surely perform individual authentication by complementing the uncertainty of the authentication system using biometric information and also consider improving the convenience of users. Patent Document 3 describes that individual authentication can be performed by combining optimal authentication methods according to users, transaction types, etc. The system of Patent Document 3 includes an authentication rule database, an authentication information database, an authentication information reception unit, and an authentication information determination unit. In the authentication rule database, combinations of authentication methods and authentication ranks are registered for each account, each transaction, etc. In the authentication information database, authentication data corresponding to each authentication method is registered. When the authentication information reception unit receives the authentication data input to the customer terminal, the authentication information determination unit performs individual authentication by collating the authentication information database, etc. according to the rules registered in the authentication rule database.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Patent Document 2

Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0006] A system using biometric authentication may include service terminals (authentication terminals) at multiple locations. Such service terminals operate independently for each service use, even if the usage locations and times are close. As a result, there may be a problem in the balance between safety and convenience in using the system. For example, in a hotel equipped with a check-in terminal corresponding to biometric authentication and functions for entry / exit gates and entry / exit rooms, in order to ensure the safety of the hotel, it is not desirable for a user who has not completed check-in to move to the accommodation building through the entry / exit gate. Similarly, it is not desirable for a user to be able to enter / exit the room without passing through the entry / exit gate. However, in conventional biometric authentication that operates independently for each service use, it has been difficult to prevent an undesirable operation where a user who has not completed check-in moves to the accommodation building through the entry / exit gate. Similarly, it has also been difficult to prevent an undesirable operation where a user can enter / exit the room without passing through the entry / exit gate after completing check-in. For the user as well, if they can enter the accommodation building before check-in but do not have the right to use the room they are staying in, they need to return to the check-in counter, which impairs the convenience that should be obtained through biometric authentication.

[0007] Note that this problem cannot be solved even by applying the technologies of Patent Document 2 and Patent Document 3. This is because Patent Document 2 does not assume multiple authentications by a plurality of authentication devices. Similarly, for Patent Document 3, the document does not assume multiple authentications by a plurality of authentication devices. Furthermore, in Patent Document 3, this is because it assumes application in a bank aiming for a one-stop window where a bank customer can satisfy all requirements by authenticating only once at one window.

[0008] A main object of the present invention is to provide a server device, a system, a biometric authentication method, and a storage medium that contribute to improving convenience in an authentication system including a plurality of authentication terminals.

Means for Solving the Problem

[0009] According to a first aspect of the present invention, there is provided a server device including: an acquisition unit that acquires an authentication rule including conditions for determining authentication success; and an authentication unit that performs a first biometric authentication in response to a first authentication request transmitted from a first terminal, and performs a second biometric authentication using the authentication rule in response to a second authentication request transmitted from a second terminal.

[0010] According to a second aspect of the present invention, there is provided a system including: a first terminal; a second terminal; and a server device connected to the first and second terminals, wherein the server device includes: an acquisition unit that acquires an authentication rule including conditions for determining authentication success; and an authentication unit that performs a first biometric authentication in response to a first authentication request transmitted from the first terminal, and performs a second biometric authentication using the authentication rule in response to a second authentication request transmitted from the second terminal.

[0011] According to a third aspect of the present invention, there is provided a biometric authentication method in a server device, including: acquiring an authentication rule including conditions for determining authentication success; performing a first biometric authentication in response to a first authentication request transmitted from a first terminal; and performing a second biometric authentication using the authentication rule in response to a second authentication request transmitted from a second terminal.

[0012] According to a fourth aspect of the present invention, a computer mounted on a server device is caused to execute a process of acquiring an authentication rule including conditions for determining successful authentication, perform a first biometric authentication in response to a first authentication request transmitted from a first terminal, and perform a second biometric authentication using the authentication rule in response to a second authentication request transmitted from a second terminal. A computer-readable storage medium storing a program for causing the computer to execute the above is provided.

Advantages of the Invention

[0013] According to each aspect of the present invention, a server device, a system, a biometric authentication method, and a storage medium that contribute to improving the convenience in an authentication system including a plurality of authentication terminals are provided. Note that the effects of the present invention are not limited to the above. Instead of or together with the above effects, other effects may be achieved by the present invention.

Brief Description of the Drawings

[0014]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Figure 24

Figure 25

Figure 26

Best Mode for Carrying Out the Invention

[0015] First, an overview of an embodiment will be described. Note that the reference numerals in the drawings appended to this overview are for convenience of each element as an example to assist understanding, and the description of this overview is not intended to be limiting in any way. Also, unless otherwise specified, the blocks described in each drawing represent a configuration of functional units, not a configuration of hardware units. The connection lines between the blocks in each figure include both bidirectional and unidirectional ones. For the one-way arrow, it schematically shows the flow of the main signal (data) and does not exclude bidirectionality. In this specification and the drawings, for elements that can be similarly described, duplicate description may be omitted by assigning the same reference numerals.

[0016] The server device 100 according to one embodiment includes an acquisition unit 101 and an authentication unit 102 (see FIG. 1). The acquisition unit 101 acquires an authentication rule including conditions for determining authentication success. The authentication unit 102 performs a first biometric authentication in response to a first authentication request transmitted from a first terminal, and performs a second biometric authentication using the authentication rule in response to a second authentication request transmitted from a second terminal.

[0017] The authentication system including the server device 100 includes authentication terminals (the first terminal, the second terminal) installed at a plurality of locations, and can provide different services to users at these different locations. For example, in physical stores such as retail stores and hotels, access control such as check-in procedures, entry and exit management of gates, and payment services are provided to users. That is, the authentication system including the server device 100 is premised on performing different multiple authentications with different biometric authentication devices (authentication terminals) at a plurality of locations. The server device 100 acquires from the outside (such as a system administrator) an authentication rule for being determined as successful in the authentication after the second time among the multiple authentications. More specifically, the administrator can set an authentication rule for determining as successful the authentication in the authentication terminal associated with authentication such as a payment terminal and a gate installed after the entrance and exit of a hotel or a retail store. In an authentication system including a plurality of authentication terminals, the administrator can flexibly set the authentication rule so as to improve the convenience of users (for example, product purchasers, hotel guests). As a result, the convenience of users is improved. In addition, for the authentication of the subsequent terminal of the plurality of authentication terminals, the successful authentication of the previous terminal is required, so the risks in the system are appropriately managed. In other words, the administrator can set the authentication rule in consideration of a risk (acceptable) suitable for the user's planned actions. Thus, the server device 100 according to one embodiment can achieve both risk reduction and convenience during multiple short-term purchases of goods and services in a physical store, and both risk reduction and convenience during multiple short-term entries and exits to physical areas such as buildings and rooms.

[0018] Hereinafter, specific embodiments will be described in more detail with reference to the drawings.

[0019] [First Embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0020] FIG. 2 is a diagram showing an example of the schematic configuration of the authentication system according to the first embodiment. Referring to FIG. 2, the authentication system includes a server device 10, a main terminal 20, and slave terminals 30-1 and 30-2.

[0021] In the following description, when there is no particular reason to distinguish between slave terminals 30-1 and 30-2, they will simply be referred to as "slave terminal 30".

[0022] For example, the authentication system disclosed in the present application is used for providing services in a hotel as shown in FIG. 2. Specifically, a user (hotel guest) performs a check-in procedure using biometric authentication at the main terminal 20 installed at the entrance counter. Alternatively, when the user moves from the entrance to the accommodation area, the gate or door is opened by biometric authentication at the slave terminal 30-1. Alternatively, the user performs payment settlement by biometric authentication at the slave terminal 30-2 installed at the store.

[0023] The server device 10 is a device that provides services related to biometric authentication. The server device 10 stores the biometric information of the user. The server device 10 receives an authentication request from the authentication terminals (main terminal 20, slave terminal 30). The server device 10 performs biometric authentication using the stored biometric information to identify the person to be authenticated. The server device 10 transmits the authentication result (authentication success, authentication failure) to the authentication terminal. The server device 10 may be installed inside the hotel or on the cloud.

[0024] Here, the biometric authentication executed by the server device 10 includes two types.

[0025] The first biometric authentication is normal biometric authentication using the biometric information stored in the server device 10. The server device 10 performs the first biometric authentication when processing the authentication request received from the main terminal 20.

[0026] The second biometric authentication is biometric authentication using at least the biometric information stored in the server device 10 and the authentication rules input by the system administrator or the like into the server device 10. The server device 10 performs the second biometric authentication when processing the authentication request received from the slave terminal 30.

[0027] In addition, the server device 10 uses the information obtained as a result of providing the first service to the user who has successfully completed the first biometric authentication for the second biometric authentication. That is, the second biometric authentication cannot succeed unless the first biometric authentication has been completed. From this perspective, the main terminal 20 serves as the main authentication terminal in relation to the slave terminal 30. The slave terminal 30 provides the second service when the second biometric authentication is successful. The main terminal 20 corresponds to the first terminal, and the slave terminal 30 corresponds to the second terminal.

[0028] Note that which authentication terminal included in the authentication system is set as the "main terminal" or "slave terminal" may be set according to the business type and policy of the operator. That is, in the present disclosure, the "main terminal" and "slave terminal" can be set flexibly.

[0029] The devices shown in FIG. 2 are connected to each other. For example, the server device 10 and the authentication terminals (main terminal 20, slave terminal 30) are connected by wired or wireless communication means and are configured to be able to communicate with each other.

[0030] FIG. 2 is an illustration and is not intended to limit the configuration of the authentication system of the present disclosure. For example, the authentication system may include two or more server devices 10. Also, the authentication system may include at least one or more main terminals 20 and at least one or more slave terminals 30.

[0031] Note that in the first embodiment, the case where the authentication system of the present disclosure is applied to the services provided in a hotel will be described, but it is not intended to limit the application destination of the authentication system to a hotel. Other application destinations will be described in the second embodiment.

[0032] [Overview of System Operation] Subsequently, the general operation of the authentication system according to the first embodiment will be described.

[0033] [User Registration] As shown in FIG. 3, a user who uses the authentication system performs user registration in advance. The user registers his or her biometric information in the server device 10. For example, the user operates the possessed terminal to register the biometric information in the server device 10.

[0034] Examples of the user's biometric information include data (feature amounts) calculated from personal unique physical characteristics such as face, fingerprint, voiceprint, vein, retina, and iris pattern of the pupil. Alternatively, the user's biometric information may be image data such as a face image or a fingerprint image. The user's biometric information only needs to include the user's physical characteristics as information. In the first embodiment, the biometric information is a face image or a feature amount generated from the face image.

[0035] When the server device 10 acquires biometric information (for example, a face image), it generates a user ID (Identifier) for identifying the user. The server device 10 associates the user's biometric information with the user ID and stores it in an authentication information database (DB; Database). The server device 10 uses the authentication information database to associate and store the biometric information and user ID of each of a plurality of users.

[0036] The server device 10 issues the generated user ID to the user. More specifically, when the user registration is successful, the server device 10 transmits the generated user ID to the terminal. The terminal stores the issued user ID.

[0037] [Information Input Required for Service Provision] A user who wishes to receive a service through biometric authentication inputs the information required at that time into the system. For example, a user who wishes to perform a check-in procedure through biometric authentication inputs reservation information and the like into the hotel where he or she is staying. At that time, the user also inputs the user ID issued from the server device 10 into the hotel.

[0038] For example, as shown in FIG. 4, the user operates the terminal to access the WEB (web) page operated by the hotel. The user inputs the user ID and reservation information (e.g., name, date of birth, gender, address, accommodation period, contact information, etc.) on the WEB page (hotel reservation page). The information input on the WEB page is registered in the main terminal 20.

[0039] The main terminal 20 associates the user ID of the reserving person with the reservation information and stores it in the reservation information database.

[0040] In addition, users who perform payment settlement by biometric authentication input settlement information (e.g., bank account or credit card number for debit) on the WEB page. The settlement information is registered in the slave terminal 30-2 that requires the information. The slave terminal 30-2 stores the user ID and the settlement information in association with each other.

[0041] [Registration of Authentication Rules] As described above, the administrator registers the "authentication rules" for the server device 10 to perform the second biometric authentication in the server device 10. The administrator designates the slave terminal 30 and registers the authentication rules in the server device 10 (see FIG. 5).

[0042] For example, the administrator registers a rule (condition) such as "Authenticate the authenticated person who has completed check-in" as an authentication rule for the slave terminal 30-1 in the server device 10. Alternatively, the administrator registers a rule such as "Authenticate the authenticated person who is 20 years old or older" as an authentication rule for the slave terminal 30-2 in the server device 10.

[0043] The server device 10 associates the terminal ID of the slave terminal 30 with the authentication rules and stores them in the authentication rule management database. Note that the terminal ID is identification information for identifying the authentication terminals (main terminal 20, slave terminal 30). For the terminal ID, the MAC (Media Access Control) address, IP (Internet Protocol) address, etc. of each authentication terminal can be used. The terminal ID is shared between the server device 10 and the authentication terminal by any means.

[0044] [First Biometric Authentication] Referring to FIG. 6, the first biometric authentication will be described.

[0045] For example, a user (hotel guest) who arrives at a hotel moves in front of the main terminal 20 installed at the counter. The main terminal 20 acquires the biometric information (e.g., face image) of the user. The main terminal 20 transmits an "authentication request" including the acquired biometric information and the terminal ID to the server device 10.

[0046] The server device 10 identifies the user by biometric authentication (matching process) using the acquired biometric information and the pre-registered biometric information. The server device 10 notifies the main terminal 20 of the user ID of the identified user. When the authentication is successful, the server device 10 transmits an affirmative response including the user ID to the main terminal 20.

[0047] The main terminal 20 provides services to the user using the user ID acquired from the server device 10. Specifically, the main terminal 20 searches the reservation information database using the user ID as a key and identifies the corresponding reservation information. The main terminal 20 performs the check-in procedure using the identified reservation information.

[0048] When the main terminal 20 finishes the first service (check-in procedure), it transmits a log registration request including the user ID of the user and the log information regarding the service provision (hereinafter referred to as service provision log) to the server device 10. For example, the main terminal 20 transmits the user's name, age, gender, status (checked in) to the server device 10 as the service provision log.

[0049] The server device 10 associates the user ID with the service provision log and stores it in the "log management database".

[0050] [Second Biometric Authentication] Referring to FIG. 7, the second biometric authentication will be described.

[0051] For example, consider the case where a user moves from the entrance to the accommodation area. In this case, the user undergoes biometric authentication on the slave terminal 30-1. The slave terminal 30-1 acquires the user's biometric information (e.g., face image). The slave terminal 30-1 transmits an "authentication request" including the acquired biometric information and the terminal ID to the server device 10.

[0052] The server device 10 identifies the user through biometric authentication (matching process) using the acquired biometric information and the pre-registered biometric information. Further, the server device 10 acquires the pre-registered authentication rules based on the acquired terminal ID.

[0053] The server device 10 determines authentication success or failure based on the service provision log of the user identified through the matching process and the authentication rules. For example, since the authentication rule regarding the slave terminal 30-1 above is "Authenticate an authenticated person who has completed check-in as successful", if the authenticated person has completed the check-in procedure, it is determined as authentication success.

[0054] On the other hand, when a user who has not yet completed the check-in procedure attempts to move to the accommodation area, even if the biometric information of the user is registered in the server device 10, it is determined as authentication failure based on the authentication rules and the service provision log.

[0055] The server device 10 notifies the slave terminal 30-1 of the authentication result (authentication success, authentication failure). Upon receiving authentication success, the slave terminal 30-1 opens the gate and permits the authenticated person to move to the accommodation area. The slave terminal 30-1 provides the user with a second service of opening the gate. Upon receiving authentication failure, the slave terminal 30-1 closes the gate and rejects the authenticated person's movement to the accommodation area.

[0056] Subsequently, details of each device included in the authentication system according to the first embodiment will be described.

[0057] [Server Device] FIG. 8 is a diagram showing an example of the processing configuration (processing modules) of the server device 10 according to the first embodiment. Referring to FIG. 8, the server device 10 includes a communication control unit 201, a user registration unit 202, an authentication rule acquisition unit 203, an authentication unit 204, and a storage unit 205.

[0058] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the main terminal 20. Also, the communication control unit 201 transmits data to the main terminal 20. The communication control unit 201 delivers the data received from other devices to other processing modules. The communication control unit 201 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 201.

[0059] The user registration unit 202 is a means for realizing the above-described user registration. The user registration unit 202 acquires the biometric information of the user using any means. For example, the user registration unit 202 displays a GUI (Graphical User Interface) or an input form for acquiring biometric information on the terminal, and acquires biometric information (for example, a face image). Alternatively, a user who wishes to register may send an external storage medium storing biometric information to the administrator of the server device 10, and a staff member or the like of the administrator may input the biometric information into the server device 10 using the external storage medium.

[0060] The user registration unit 202 generates a feature amount (a feature vector composed of a plurality of feature amounts) from the acquired face image. Note that since existing technologies can be used for the generation process of the feature amount, a detailed description thereof is omitted. For example, the user registration unit 202 extracts eyes, nose, mouth, etc. as feature points from the face image. Thereafter, the user registration unit 202 calculates the position of each feature point and the distance between each feature point as feature amounts, and generates a feature vector (vector information characterizing the face image) composed of a plurality of feature amounts.

[0061] When the user registration unit 202 succeeds in generating the feature amount, it generates a user ID for uniquely identifying the user (the person who wishes to register). For example, the user registration unit 202 assigns a serial number to the user ID each time a user registration is performed.

[0062] Also, when the user registration unit 202 succeeds in generating the feature amount, it transmits the generated user ID to the terminal.

[0063] The user registration unit 202 stores the generated user ID and biometric information (for example, the feature amount) in the authentication information database (see FIG. 9). In this way, the user registration unit 202 acquires the biometric information of each of the plurality of users and stores the acquired biometric information in the authentication information database.

[0064] Note that the authentication information database shown in FIG. 9 is an example and is not intended to limit the items to be stored. For example, biometric information related to a face image may be stored in the authentication information database instead of or in addition to the feature amount.

[0065] The authentication rule acquisition unit 203 is a means for acquiring an authentication rule. The authentication rule includes conditions for determining authentication success when processing a second authentication request.

[0066] For example, the authentication rule acquisition unit 203 displays a GUI as shown in FIG. 10 in response to a request from an administrator or the like. The administrator designates the slave terminal 30 for setting the authentication rule using the terminal ID and inputs a rule (condition) for determining that an authentication request from the slave terminal 30 is successful.

[0067] The authentication rule acquisition unit 203 associates the acquired terminal ID with the authentication rule and stores it in the authentication rule management database (see FIG. 11). In the drawings including FIG. 11, for ease of understanding, the symbols assigned to each authentication terminal are described as the terminal ID.

[0068] Note that the authentication rule management database shown in FIG. 11 is an example and is not intended to limit the items to be stored. For example, the registration date and time of the authentication rule may be stored in the authentication rule management database.

[0069] The authentication unit 204 is means for processing an authentication request received from an authentication terminal and also for processing a log registration request received from the main terminal 20.

[0070] First, the processing of the service provision log will be described. In response to transmitting the result of the first biometric authentication to the main terminal 20, the authentication unit 204 acquires a service provision log obtained from the result of the main terminal 20 providing a service to the user. More specifically, in response to notifying the main terminal 20 of successful authentication, the authentication unit 204 receives a log registration request. The authentication unit 204 registers the user ID and the service provision log included in the log registration request in the log management database (see FIG. 12).

[0071] Note that the log management database shown in FIG. 12 is an example and is not intended to limit the items to be stored. For example, the date and time when the service provision log was received may be stored in the log management database.

[0072] Subsequently, with reference to FIGS. 13 and 14, the operation of the authentication unit 204 when receiving an authentication request from an authentication terminal will be described. The authentication unit 204 performs a first biometric authentication in response to the first authentication request transmitted from the main terminal 20, and performs a second biometric authentication using an authentication rule in response to the second authentication request transmitted from the slave terminal 30. When executing the second biometric authentication, the authentication unit 204 determines whether the conditions described in the authentication rule are satisfied using the service provision log.

[0073] The authentication unit 204 extracts biometric information (for example, a face image) from the received authentication request. The authentication unit 204 generates a feature amount from the extracted face image (step S101).

[0074] In step S102, the authentication unit 204 sets the generated feature amount as the feature amount on the collation side and the feature amount stored in the authentication information database as the feature amount on the registration side, and performs a one-to-N collation (N is a positive integer, the same hereinafter). Specifically, the authentication unit 204 calculates the similarity between the feature amount on the collation side and the feature amounts on each of the plurality of registration sides. For the similarity, the distance in the vector space, the distance in the probability distribution space, etc. can be used. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0075] The authentication unit 204 determines whether there is a feature amount whose similarity with the feature amount to be collated among the plurality of feature amounts registered in the authentication information database is equal to or greater than a predetermined value (step S103).

[0076] If there is no such feature amount (step S103, No branch), the authentication unit 204 determines that the authentication has failed (step S104). That is, the authentication unit 204 sets the authentication to fail if the biometric information of the person to be authenticated is not registered in the authentication information database regardless of the type of biometric authentication.

[0077] If there is such a feature amount (step S103, Yes branch), the authentication unit 204 identifies the entry having the feature amount with the highest similarity to the feature amount on the collation side from among the entries in the authentication information database, and reads out the corresponding user ID (step S105).

[0078] Next, the authentication unit 204 determines whether the source of the authentication request is the main terminal 20 based on the terminal ID included in the authentication request (step S106).

[0079] If the source of the authentication request is the main terminal 20 (step S106, Yes branch), the authentication unit 204 determines that it is the first biometric authentication, and executes the processing after step S107.

[0080] If the source of the authentication request is the slave terminal 30 (branch at step S106, No), the authentication unit 204 determines that it is the second biometric authentication and executes the processes after step S201. The processes after step S201 are described in FIG. 14.

[0081] In this way, regardless of the first biometric authentication or the second biometric authentication, the authentication unit 204 sets the biometric information obtained from the authentication request as the collation side and the plurality of biometric information stored in the authentication information database as the registration side, and executes a one-to-N collation (N is a positive integer). After that, the authentication unit 204 determines which of the first biometric authentication and the second biometric authentication to execute based on the terminal ID included in the authentication request.

[0082] In the case of the first biometric authentication, the authentication unit 204 determines that the authentication is successful (step S107). That is, when processing the first biometric authentication, if there is biometric information in the plurality of biometric information registered in the authentication information database whose similarity to the biometric information on the collation side is equal to or greater than a predetermined value, the authentication unit 204 determines that the authentication is successful.

[0083] The authentication unit 204 transmits the authentication result to the authentication terminal (master terminal 20) (step S108). In the case of authentication failure, the authentication unit 204 transmits a negative response indicating that to the master terminal 20. In the case of successful authentication, the authentication unit 204 transmits an affirmative response including the user ID read in step S105 to the master terminal 20.

[0084] In the case of the second biometric authentication, the authentication unit 204 searches the log management database using the user ID read in step S105 and determines whether there is an entry corresponding to the user ID (step S201 in FIG. 14).

[0085] If the corresponding entry does not exist (branch at step S201, No), the authentication unit 204 determines that the authentication has failed (step S202). The fact that the corresponding entry does not exist indicates that the service provision log required for the second biometric authentication has not been transmitted to the server device 10, that is, service provision has not been performed on the master terminal 20.

[0086] For example, when a hotel reservationist arrives at the hotel and arrives at the slave terminal 30 before completing check-in, the above authentication failure may occur. More specifically, a user who has not completed check-in cannot enter the accommodation area, and products such as cigarettes cannot be sold to a user whose age has not been confirmed.

[0087] When a corresponding entry exists (step S201, Yes branch), the authentication unit 204 acquires the service provision log of the corresponding entry (step S203).

[0088] The authentication unit 204 searches the authentication rule management database using the terminal ID included in the authentication request as a key, and acquires the corresponding authentication rule (step S204).

[0089] The authentication unit 204 determines whether the authenticated person (the attributes and status of the authenticated person) satisfies the authentication rule based on the service provision log acquired in step S203 and the authentication rule acquired in step S204 (step S205).

[0090] If the authentication rule is satisfied (step S205, Yes branch), the authentication unit 204 determines that the authentication is successful (step S206).

[0091] If the authentication rule is not satisfied (step S205, No branch), the authentication unit 204 determines that the authentication has failed (step S202).

[0092] For example, since the authentication rule of the slave terminal 30-1 is "the authenticated person has completed check-in" (see the first line of FIG. 11), the authentication of the authenticated persons corresponding to the three user IDs shown in FIG. 12 is successful.

[0093] Since the authentication rule of the slave terminal 30-2 is that the person to be authenticated must be 20 years or older (see the second line of FIG. 11), the authentication of the persons to be authenticated corresponding to "uID01" and "uID12" among the three user IDs shown in FIG. 12 is successful. On the other hand, the authentication of the person to be authenticated corresponding to "uID11" fails.

[0094] In this way, when processing the second biometric authentication, the authentication unit 204 determines that the authentication is successful when there is biometric information among the plurality of biometric information registered in the authentication information database whose similarity to the biometric information on the verification side is equal to or greater than a predetermined value and the authentication rule is satisfied.

[0095] The authentication unit 204 transmits the authentication result to the authentication terminal (slave terminal 30) (step S207). In the case of authentication failure, the authentication unit 204 transmits a negative response indicating that to the slave terminal 30. In the case of authentication success, the authentication unit 204 transmits an affirmative response indicating that to the slave terminal 30. Note that the authentication unit 204 transmits an affirmative response including the user ID to the slave terminal 30 as necessary. In the example of FIG. 2, when the authentication unit 204 notifies the slave terminal 30-2 of authentication success, it transmits an affirmative response including the user ID to the slave terminal 30-2.

[0096] The storage unit 205 is a means for storing information necessary for the operation of the server device 10. For example, the storage unit 205 stores table information defining the correspondence between the terminal ID and the authentication terminals (master terminal 20, slave terminal 30).

[0097] [Master terminal] FIG. 15 is a diagram showing an example of the processing configuration (processing module) of the master terminal 20 according to the first embodiment. Referring to FIG. 15, the master terminal 20 includes a communication control unit 301, an authentication request unit 302, a service providing unit 303, and a storage unit 304.

[0098] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the server device 10. Also, the communication control unit 301 transmits data to the server device 10. The communication control unit 301 delivers the data received from other devices to other processing modules. The communication control unit 301 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 301.

[0099] The authentication request unit 302 is a means for requesting biometric authentication of the person to be authenticated from the server device 10. The authentication request unit 302 controls the camera and acquires biometric information (face image) of the user. More specifically, the authentication request unit 302 determines whether a human face image is included in the acquired image, and if a face image is included, extracts the face image from the acquired image data.

[0100] Note that since existing technologies can be used for the face image extraction process by the authentication request unit 302, a detailed description is omitted. For example, the authentication request unit 302 may extract a face image (face region) from the image data using a learning model learned by a CNN (Convolutional Neural Network). Alternatively, the authentication request unit 302 may extract a face image using a method such as template matching.

[0101] The authentication request unit 302 transmits an authentication request including the extracted face image (biometric information) and the terminal ID of its own device to the server device 10.

[0102] The authentication request unit 302 acquires an authentication result (authentication success, authentication failure) from the server device 10.

[0103] If authentication fails, the authentication request unit 302 notifies the authentication failure to the person who failed authentication (the person to be authenticated determined to have failed authentication).

[0104] When authentication is successful, the authentication request unit 302 delivers the user ID included in the positive response to the service provision unit 303.

[0105] The service provision unit 303 is a means for providing services to the authentication successful users. As shown in FIG. 2, when the main terminal 20 is a terminal for performing a check-in procedure, the service provision unit 303 performs the check-in procedure for the authentication successful users.

[0106] Specifically, the service provision unit 303 searches the reservation information database (see FIG. 16) using the user ID obtained from the server device 10 as a key, and identifies the corresponding entry (reservation user). The service provision unit 303 performs the check-in procedure based on the reservation information of the identified reservation user. For example, the service provision unit 303 checks whether the arrival date of the reservation user is included in the accommodation period of the reservation information, and performs the check-in procedure.

[0107] When the service provision unit 303 provides a service to a user, it notifies the server device 10 of the resulting information as a service provision log. More specifically, the service provision unit 303 transmits a log registration request including the user ID of the user to whom the service was provided and the service provision log to the server device 10.

[0108] In the example of the above check-in procedure, the service provision unit 303 transmits, as a service provision log to the server device 10, information indicating that the check-in is completed (the state of the user), in addition to the name, age, gender, etc. of the user.

[0109] The storage unit 304 is a means for storing information necessary for the operation of the main terminal 20. The reservation information database is constructed in the storage unit 304. Acquisition of items to be stored in the reservation information database, etc., is different from the gist of the present disclosure and is obvious to those skilled in the art, and thus detailed description thereof is omitted.

[0110] [Slave terminal] FIG. 17 is a diagram showing an example of the processing configuration (processing modules) of the slave terminal 30 according to the first embodiment. Referring to FIG. 17, the slave terminal 30 includes a communication control unit 401, an authentication request unit 402, a service providing unit 403, and a storage unit 404.

[0111] Since the basic operations of each processing module included in the slave terminal 30 can be the same as those of each processing module included in the master terminal 20, detailed descriptions thereof are omitted. However, the service providing unit 403 does not need to transmit the "service providing log" to the server device 10.

[0112] [Operation of the System] Subsequently, the operation of the authentication system according to the first embodiment will be described. Note that descriptions of operations related to user registration and authentication rule registration are omitted.

[0113] FIG. 18 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment.

[0114] The master terminal 20 acquires biometric information of the person to be authenticated and transmits an authentication request including the biometric information to the server device 10 (step S01).

[0115] The server device 10 performs biometric authentication using the biometric information included in the acquired authentication request and the pre-registered biometric information (step S02).

[0116] The server device 10 transmits the result of the biometric authentication to the master terminal 20 (step S03).

[0117] When the biometric authentication is successful, the master terminal 20 provides the first service to the user (step S04).

[0118] The master terminal 20 transmits the service providing log obtained from the result of the service provision to the server device 10 (step S05).

[0119] The server device 10 stores the received service providing log (step S06).

[0120] The slave terminal 30 acquires the biometric information of the person to be authenticated and transmits an authentication request including the biometric information to the server device 10 (step S11).

[0121] The server device 10 performs biometric authentication using the biometric information included in the acquired authentication request and the pre-registered biometric information (step S12). At this time, the server device 10 determines the result of the authentication process (authentication success, authentication failure) using the service provision log acquired from the master terminal 20 and the authentication rules regarding the slave terminal 30.

[0122] The server device 10 transmits the result of the biometric authentication to the slave terminal 30 (step S13).

[0123] When the biometric authentication is successful, the slave terminal 30 provides a second service to the user (step S14).

[0124] As described above, in the authentication system according to the first embodiment, the administrator registers an authentication rule for determining that the authentication of the slave terminal 30 is successful in the server device 10. Further, the server device 10 grasps the actions, attributes, states, etc. of the person to be authenticated based on the service provision log received from the master terminal 20. For example, the server device 10 grasps whether the person to be authenticated has completed the check-in procedure or not via the service provision log. If the actions of the user, etc. match the actions assumed to be "authentication successful" by the administrator, the server device 10 determines that the authentication from the slave terminal 30 is successful and enables the service provision from the slave terminal 30. The administrator can determine the authentication rules while considering the convenience of the user and the security of the system.

[0125] [Second Embodiment] Subsequently, the second embodiment will be described.

[0126] In the first embodiment, the authentication system disclosed in the present application was described by taking a hotel as an example. In the first embodiment, it was described that the main terminal 20 provides the user with a first service (for example, check-in procedures), and the slave terminal 30 provides a second service (for example, entry to the accommodation area, payment settlement).

[0127] In the second embodiment, other specific examples of the relationship between the main terminal 20 and the slave terminal 30 and the provision of the second service after the first service is provided will be described. That is, in the second embodiment, specific examples of the main terminal 20, the slave terminal 30, the first service, and the second service as shown in FIG. 19 will be described.

[0128] <Specific Example 1> The authentication system disclosed in the present application can be used for access control in buildings such as buildings. Specifically, the main terminal 20 described above is set as a terminal for controlling the opening and closing of a gate set at the entrance and exit of a building. The slave terminal 30 is set as a terminal for controlling the opening and closing of a gate set at the entrance and exit of a workplace. The administrator sets "having successfully authenticated the main terminal 20" as the authentication rule for the slave terminal 30 in the server device 10. When the main terminal 20 successfully authenticates a user (employee), it transmits a service provision log including the authentication date and time, employee number, etc. to the server device 10. When processing an authentication request from the slave terminal 30, the server device 10 determines that the authentication is successful if the person to be authenticated has passed through the entrance and exit of the building (successfully authenticated at the main terminal 20).

[0129] <Specific Example 2> The authentication system disclosed in the present application can be used for boarding control of aircraft, ships, etc. Specifically, the main terminal 20 described above is used as a terminal for controlling the opening and closing of the entrance gate at an airport or the like. The slave terminal 30 is used as a terminal for controlling the opening and closing of the boarding gate when boarding an aircraft. The administrator sets "having successfully authenticated the main terminal 20" as the authentication rule for the slave terminal 30 in the server device 10. When the main terminal 20 successfully authenticates a user (passenger), it transmits a service provision log including the authentication date and time, passport number, etc. to the server device 10. When processing an authentication request from the slave terminal 30, the server device 10 determines that the authentication is successful if the person to be authenticated has passed through the entrance gate of the airport (successfully authenticated by the main terminal 20).

[0130] <Specific Example 3> The authentication system disclosed in the present application can be used for entrance control to an event venue or the like. Specifically, the main terminal 20 described above is used as a terminal for controlling the opening and closing of the entrance gate to an event venue or the like. The slave terminal 30 is used as a terminal for providing services related to the event. For example, the slave terminal 30 is used as a terminal for controlling the opening and closing of the gate installed at the entrance and exit of the waiting space (waiting room) in the event venue. The administrator sets "the user is a VIP (Very Important Person) member" as the authentication rule for the slave terminal 30 in the server device 10. When the main terminal 20 successfully authenticates a user (event participant), it transmits a service provision log including the authentication date and time, ticket number, membership number, etc. to the server device 10. When processing an authentication request from the slave terminal 30, the server device 10 determines that the authentication is successful if it determines that the user is a VIP based on the membership number.

[0131] <Specific Example 4> The authentication system disclosed in the present application can be used to restrict the use of information processing devices such as personal computers. Specifically, the main terminal 20 described above is used as the terminal for controlling the opening and closing of the entrance gate of the office. The slave terminal 30 is a personal computer. The administrator sets, in the server device 10, "being used by employees other than management staff during working hours" as the authentication rule for the slave terminal 30. When the main terminal 20 successfully authenticates the user (employee), it transmits a service provision log including the authentication date and time, employee number, etc. to the server device 10. When processing the authentication request from the slave terminal 30, the server device 10 determines whether the above authentication rule is satisfied based on the authentication date and time and the employee number.

[0132] <Specific Example 5> The authentication system disclosed in the present application can be used to restrict the use of vehicles such as rental cars. Specifically, the main terminal 20 described above is used as the terminal installed at the rental car business office. The main terminal 20 is a terminal for handling the rental car contract procedures. The slave terminal 30 is a rental car. The administrator sets, in the server device 10, "having completed the rental car contract" as the authentication rule for the slave terminal 30. When the main terminal 20 successfully authenticates the user, it transmits a service provision log including the contract status, etc. to the server device 10. When processing the authentication request from the slave terminal 30, the server device 10 determines whether the user has completed the rental car contract.

[0133] As described above, as described in the second embodiment, the authentication system disclosed in the present application can be applied not only to biometric authentication in hotels but also to any place such as airports and event venues.

[0134] Subsequently, the hardware of each device constituting the authentication system will be described. FIG. 20 is a diagram showing an example of the hardware configuration of the server device 10.

[0135] The server device 10 can be configured by an information processing device (so-called computer) and has the configuration illustrated in FIG. 20. For example, the server device 10 includes a processor 311, a memory 312, an input / output interface 313, a communication interface 314, and the like. The components such as the processor 311 are connected by an internal bus or the like and are configured to be able to communicate with each other.

[0136] However, the configuration shown in FIG. 20 is not intended to limit the hardware configuration of the server device 10. The server device 10 may include hardware not shown, or may not include the input / output interface 313 if necessary. Also, the number of components such as the processor 311 included in the server device 10 is not intended to be limited to the example shown in FIG. 20. For example, a plurality of processors 311 may be included in the server device 10.

[0137] The processor 311 is, for example, a programmable device such as a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or a DSP (Digital Signal Processor). Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit). The processor 311 executes various programs including an operating system (OS; Operating System).

[0138] The memory 312 is a RAM (Random Access Memory), a ROM (Read Only Memory), an HDD (Hard Disk Drive), an SSD (Solid State Drive), or the like. The memory 312 stores an OS program, an application program, and various data.

[0139] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display or the like. The input device is a device that accepts user operations such as a keyboard and a mouse.

[0140] The communication interface 314 is a circuit, a module, etc. that communicate with other devices. For example, the communication interface 314 includes a NIC (Network Interface Card) or the like.

[0141] The functions of the server device 10 are realized by various processing modules. The processing module is realized, for example, by the processor 311 executing a program stored in the memory 312. Further, the program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory one such as a semiconductor memory, a hard disk, a magnetic recording medium, and an optical recording medium. That is, the present invention can also be embodied as a computer program product. Further, the above program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the above processing module may be realized by a semiconductor chip.

[0142] Note that the main terminal 20 and the slave terminal 30 can also be configured by an information processing device in the same manner as the server device 10, and the basic hardware configuration is the same as that of the server device 10, so the description thereof is omitted. For example, the authentication terminal (main terminal 20, slave terminal 30) may be provided with a camera for imaging the user.

[0143] The server device 10, which is an information processing device, is equipped with a computer, and the functions of the server device 10 can be realized by causing the computer to execute a program. Further, the server device 10 executes a biometric authentication method according to the program.

[0144] [Modification Example] Note that the configuration, operation, etc. of the authentication system described in the above embodiments are examples, and are not intended to limit the configuration of the system or the like.

[0145] In the above embodiment, the configuration in which the server device 10 includes an authentication information database and an authentication rule management database has been described. However, these databases may be constructed in a database server different from the server device 10 or the like. Further, the authentication system only needs to include various means (such as the authentication unit 204) described in the above embodiments.

[0146] The main terminal 20 may guide the user to services and the like that become available in response to successful authentication on the terminal. For example, the main terminal 20 may guide a user who has completed the check-in procedure that biometric authentication can be used for entry into the accommodation building and each room, and for settlement at the store and the restaurant. Alternatively, the main terminal 20 may display a map of the location where the slave terminal 30 for receiving the above biometric authentication is installed.

[0147] Alternatively, the slave terminal 30 may present to the user the cause of the failure of authentication on the terminal, and guide the user to undergo biometric authentication on the main terminal 20. For example, when a user who has not completed the check-in procedure fails in biometric authentication in each room, the slave terminal 30 guides the user to complete the check-in procedure on the main terminal 20. In that case, the slave terminal 30 may display a map of the location of the main terminal 20.

[0148] Here, the relationship between the first service and the second service is not limited to one-to-one. As described in the first embodiment, a plurality of second services may be provided corresponding to one first service (see FIG. 21). Alternatively, as shown in FIG. 22, one second service may be provided corresponding to a plurality of first services. Alternatively, as shown in FIG. 23, a plurality of second services may be provided corresponding to a plurality of first services. That is, the relationship between the first service and the second service may be such that the second service is provided after the first service is provided.

[0149] In the above embodiment, the configuration of the so-called client-server system related to biometric authentication has been described. However, it is also possible to adopt a configuration in which the authentication terminals (main terminal 20 and slave terminal 30) alone complete biometric authentication.

[0150] In this case, for example, the configuration shown in FIG. 24 is adopted. The main terminal 20 includes a first authentication unit 501, a first control unit 502, and a first log management unit 503. The slave terminal 30 includes a second authentication unit 511, a second control unit 512, and a second log management unit 513. The user inputs information (biometric information, reservation information, etc.) necessary for receiving service provision to the authentication terminal via the user portal (web page). Also, the second control unit 512 acquires the authentication rule. The first authentication unit 501 and the second authentication unit 511 perform biometric authentication. The first control unit 502 and the second control unit 512 provide services to the user. For example, the first control unit 502 performs the check-in procedure, and the second control unit 512 performs the opening and closing control of the gate. The first log management unit 503 transmits the service provision log obtained from the result of service provision to the second control unit 512. The second control unit 512 determines whether service provision is possible according to the service provision log and the authentication rule. The second log management unit 513 collects the log information obtained from the result of service provision.

[0151] Alternatively, the main terminal 20 and the slave terminal 30 may have a configuration as shown in FIG. 25. That is, the function of the log management unit of each authentication terminal may be realized by an external device. In this case, the log management unit 523 collects, manages, and controls the log information obtained from the main terminal 20 and the slave terminal 30.

[0152] The server device 10 may verify the identity of the user at the time of user registration. Specifically, the server device 10 obtains, from the terminal, in addition to the biometric information of the user, an identity verification document (a document on which the biometric information is described; for example, a passport). The server device 10 determines that the identity verification of the user is successful when the one-to-one verification using the biometric information obtained from the acquired biometric information and the identity verification document is successful. The server device 10 may register the biometric information of the user when the identity verification is successful.

[0153] In the above embodiment, the case where biometric information related to a "face image" is transmitted from the authentication terminal to the server device 10 has been described. However, biometric information related to a "feature amount generated from a face image" may be transmitted from the authentication terminal to the server device 10. In this case, the server device 10 can omit the feature amount generation process.

[0154] In the above embodiment, the case where it is determined whether or not the authentication rule is satisfied based on one item included in the service provision log has been described. However, it may be determined whether or not the authentication rule is satisfied based on a plurality of items included in the service provision log. For example, the authentication rule may be something like "the check-in of the person to be authenticated is completed and the age is 20 years or older". Alternatively, one authentication terminal may be associated with and store a plurality of authentication rules, and the server device 10 may perform biometric authentication by the logical product (AND) or logical sum (OR) of the plurality of authentication rules.

[0155] One authentication terminal may serve as both the main terminal 20 and the slave terminal 30. For example, as shown in FIG. 26, consider the case where the unlocking and locking of a room in the accommodation area is performed by the slave terminal 30-3. In this case, the administrator sets the authentication rule corresponding to the slave terminal 30-3 to "having successfully authenticated the slave terminal 30-1". The slave terminal 30-1 transmits the user ID of the authenticated person and the authentication date and time to the server device 10 as a service provision log. When processing the authentication request from the slave terminal 30-3, the server device 10 refers to the service provision log received from the slave terminal 30-1 and the authentication rule obtained from the administrator. In the case of such a configuration, the slave terminal 30-1 operates as the "main terminal" for the slave terminal 30-3.

[0156] In the above embodiment, the case where the administrator or the like of the system inputs the authentication rule to the server device 10 has been described. However, the authentication rule may be input to the server device 10 by the user (the authenticated person, the general consumer). By such a measure, the convenience of the user can be further enhanced. For example, there are also travelers who are worried about the unauthorized use risk of biometric information and want to use biometric authentication only at the travel destination. Such travelers may want to enjoy appropriate convenience according to the period, the target area, the target product, and the service after recognizing a certain risk. In such a case, if the traveler can set the rules that become the available conditions in advance and update the rules on demand, the convenience and satisfaction of the user will be improved. Alternatively, when the user inputs the authentication rule himself / herself, the similarity threshold for determining the success or failure of authentication when the rule that becomes the available condition is activated may be changed, or a change may be made to add verification of liveness in addition to biometric authentication.

[0157] From the above description, it is clear that the authentication rules include rules for determining whether biometric authentication is successful (rules for whether authentication is possible), but the authentication rules may also include rules regarding operations after successful authentication (rules that operate according to the state after authentication). For example, consider a case where an entrance / exit gate (slave terminal 30-1) has a signage function (guidance display by signage). The authentication rules regarding the entrance / exit gate may include settings such as "prompt for check-in when the person to be authenticated has not completed the check-in procedure".

[0158] The form of data transmission and reception between each device (server device 10, master terminal 20, slave terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Between these devices, biometric information is transmitted and received, and in order to appropriately protect the biometric information, it is desirable that encrypted data is transmitted and received.

[0159] In the flowcharts (flowcharts, sequence diagrams) used in the above description, a plurality of steps (processes) are described in order, but the execution order of the steps executed in the embodiment is not limited to the described order. In the embodiment, for example, the order of the illustrated steps can be changed within a range that does not substantially affect the content, such as executing each process in parallel.

[0160] The above embodiments have been described in detail for ease of understanding of the disclosure of the present application, and it is not intended that all the configurations described above are necessary. Also, when a plurality of embodiments are described, each embodiment may be used alone or in combination. For example, it is also possible to replace a part of the configuration of an embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of an embodiment. Furthermore, it is possible to add, delete, or replace other configurations for a part of the configuration of an embodiment.

[0161] From the above description, the industrial applicability of the present invention is clear, but the present invention is suitably applicable to an authentication system such as a hotel where a plurality of authentication terminals are installed.

[0162] Some or all of the above embodiments may be described as follows in the appended claims, but are not limited thereto. [Appendix 1] An acquisition unit that acquires an authentication rule including conditions for determining successful authentication; An authentication unit that performs a first biometric authentication in response to a first authentication request transmitted from a first terminal, and performs a second biometric authentication using the authentication rule in response to a second authentication request transmitted from a second terminal; A server device comprising the above. [Appendix 2] The server device according to Appendix 1, wherein the authentication unit acquires a service provision log obtained from a result of service provision by the first terminal in response to transmitting the result of the first biometric authentication to the first terminal. [Appendix 3] The server device according to Appendix 2, wherein the authentication unit determines whether the authentication rule is satisfied using the service provision log when executing the second biometric authentication. [Appendix 4] The server device according to any one of Appendices 1 to 3, further comprising a user registration unit that acquires biometric information of each of a plurality of users and stores the acquired biometric information in an authentication information database. [Appendix 5] The server device according to Appendix 4, wherein the authentication unit sets the biometric information obtained from the first or second authentication request as the collation side, and sets the plurality of biometric information stored in the authentication information database as the registration side, and performs a one-to-N collation (N is a positive integer). [Appendix 6] The server device according to Appendix 5, wherein when processing the first biometric authentication, the authentication unit determines successful authentication if there is biometric information having a similarity with the biometric information on the collation side among the plurality of biometric information registered in the authentication information database that is equal to or greater than a predetermined value. [Appendix 7] When processing the second biometric authentication, the authentication unit determines that the authentication is successful when there is biometric information among the plurality of biometric information registered in the authentication information database that has a similarity with the biometric information on the verification side equal to or greater than a predetermined value and the authentication rule is satisfied. The server device according to Supplementary Note 5 or 6. [Supplementary Note 8] Based on the terminal ID included in the first authentication request and the second authentication request, the authentication unit determines which of the first biometric authentication and the second biometric authentication to execute. The server device according to any one of Supplementary Notes 1 to 7. [Supplementary Note 9] The biometric information is a face image or a feature amount generated from the face image. The server device according to any one of Supplementary Notes 4 to 7. [Supplementary Note 10] A first terminal, A second terminal, A server device connected to the first and second terminals, including, The server device, An acquisition unit that acquires an authentication rule including conditions for determining successful authentication, Performs first biometric authentication in response to a first authentication request transmitted from the first terminal, and performs second biometric authentication using the authentication rule in response to a second authentication request transmitted from the second terminal. An authentication unit, Comprising a system. [Supplementary Note 11] In a server device, Acquires an authentication rule including conditions for determining successful authentication, Performs first biometric authentication in response to a first authentication request transmitted from a first terminal, and performs second biometric authentication using the authentication rule in response to a second authentication request transmitted from a second terminal. A biometric authentication method. [Supplementary Note 12] On a computer mounted on a server device, A process of acquiring an authentication rule including conditions for determining successful authentication, Performing a first biometric authentication in response to a first authentication request transmitted from a first terminal, and performing a second biometric authentication using the authentication rule in response to a second authentication request transmitted from a second terminal; A computer-readable storage medium storing a program for causing the above to be executed.

[0163] Note that each disclosure of the above-cited prior art documents is incorporated herein by reference. As described above, embodiments of the present invention have been described, but the present invention is not limited to these embodiments. It will be understood by those skilled in the art that these embodiments are merely illustrative and that various modifications can be made without departing from the scope and spirit of the present invention. That is, the present invention naturally includes various modifications and corrections that can be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical idea.

Explanation of Reference Numerals

[0164] 10, 100 Server device 20 Main terminal 30, 30-1 to 30-3 Slave terminals 101 Acquisition unit 102, 204 Authentication units 201, 301, 401 Communication control units 202 User registration unit 203 Authentication rule acquisition unit 205, 304, 404 Storage units 302, 402 Authentication request units 303, 403 Service provision units 311 Processor 312 Memory 313 Input / output interface 314 Communication interface 501 First authentication unit 502 First control unit 503 First log management unit 511 Second authentication unit 512 Second control unit 513 Second log management unit 523 Log management unit

Claims

1. An acquisition unit that acquires an authentication rule including conditions for determining successful authentication; An authentication unit that performs a first biometric authentication in response to a first authentication request transmitted from a first terminal, and performs a second biometric authentication using the authentication rule in response to a second authentication request transmitted from a second terminal; Comprising: When the user succeeds in the first biometric authentication, a first service provided to the user from the first terminal is different from a second service provided to the user from the second terminal when the user succeeds in the second biometric authentication; The authentication rule includes that the first biometric authentication has been successful; The authentication unit acquires a service provision log obtained from the result of the service provided by the first terminal in response to transmitting the result of the first biometric authentication to the first terminal; When executing the second biometric authentication, the authentication unit determines whether the authentication rule including that the first biometric authentication has been successful is satisfied by using the service provision log; Server device.

2. The server device according to claim 1, further comprising a user registration unit that acquires biometric information of each of a plurality of users and stores the acquired biometric information in an authentication information database.

3. The authentication unit sets the biometric information obtained from the first or second authentication request as the collation side, and sets the plurality of biometric information stored in the authentication information database as the registration side, and performs a one-to-N collation (N is a positive integer). The server device according to claim 2.

4. When processing the first biometric authentication, if there is biometric information having a similarity with the biometric information on the collation side among the plurality of biometric information registered in the authentication information database that is equal to or greater than a predetermined value, the authentication unit determines that the authentication is successful. The server device according to claim 3.

5. When processing the second biometric authentication, if there is biometric information having a similarity with the biometric information on the collation side among the plurality of biometric information registered in the authentication information database that is equal to or greater than a predetermined value, and the authentication rule is satisfied, the authentication unit determines that the authentication is successful. The server device according to claim 3 or 4.

Citation Information

Patent Citations

  • Synchronizing sound recording device

    JP1987046403A

  • Personal identification system and method

    JP2004240645A

  • Personal authentication system

    JP2007109170A

  • Authentication system, biometrics authentication device, and biometrics authentication method

    JP2010092122A

  • Information processing apparatus, function restriction management method, and function restriction management program

    JP2018180952A