History Management Device, History Management Method, and Program

The history management device and system address the issue of inappropriate disclosure scope in access control systems by managing and controlling the disclosure of visitor history data based on requester attributes, ensuring secure and privacy-compliant information sharing.

JP7704179B2Active Publication Date: 2025-07-08NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023113511
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-07-11
Publication Date
2025-07-08
Estimated Expiration
2040-09-18

AI Technical Summary

Technical Problem

Existing access control systems in apartment buildings fail to adjust the disclosure scope of authentication history information according to different requester types, such as residents and building managers, necessitating a solution to manage and control the appropriate disclosure of visitor history data.

Method used

A history management device and system that stores user application information, releases entry restrictions upon successful biometric authentication, registers authentication history, generates disclosure information based on requester attributes, and outputs it to terminals, allowing controlled disclosure of authentication history.

Benefits of technology

Enables appropriate disclosure of authentication history information to different requester types, ensuring privacy and security by tailoring the disclosed data based on requester attributes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007704179000001
    Figure 0007704179000001
  • Figure 0007704179000002
    Figure 0007704179000002
  • Figure 0007704179000003
    Figure 0007704179000003
Patent Text Reader

Abstract

To provide a history management device, a history management system, a history management method, and a non-transitory computer readable medium for controlling an appropriate disclosure range of authentication history of a facility where entry restriction is released by authentication in accordance with a disclosure requester.SOLUTION: A history management device (1) includes a storage unit (11) for storing usage application information (111) about a user in a region where entry is restricted by biometric authentication, a release control unit (12) for releasing the restriction in entry into the region when biometric authentication of a predetermined visitor is successful at an entrance of the region and the usage application information is satisfied, a history registration unit (13) for registering history information of the visitor whose biometric authentication has been successful in the storage unit (11), a generation unit (14) for, when a disclosure request of the history information is received from a terminal of a predetermined disclosure requester, generating disclosure information in which the history information is subjected to predetermined processing in accordance with an attribute of the disclosure requester, and an output unit (15) for outputting the disclosure information to the terminal.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a history management device, a history management system, a history management method, and a non-transitory computer-readable medium, and more particularly to a history management device, a history management system, a history management method, and a non-transitory computer-readable medium for managing the history of visitors entering a predetermined area.

Background Art

[0002] In apartment buildings such as condominiums, there are common facilities in addition to the residences. In order for residents to use the common facilities, they need to apply for and reserve users in advance and also pay the fees corresponding to the use. In addition, users can include visitors other than residents. In recent years, in apartment buildings, due to enhanced security, access restrictions to common facilities and residences by biometric authentication have been increasing.

[0003] Patent Document 1 discloses a technology related to an access control system that performs access control for entry into a facility by performing face authentication at an entrance of the facility or the like for a person whose face image has been registered in advance. The access control system stores the entry history of a person who has been permitted to enter.

[0004] Patent Document 2 discloses a technology related to an entry management device that manages entry (room entry) into each room by face authentication in an apartment building or the like where a plurality of rooms are grouped together. In addition, the entry management device holds an authentication history and presents the authentication history in response to a request.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0006] However, Patent Documents 1 and 2 were unable to adjust the disclosure scope for various disclosure requesters regarding the disclosure of authentication history information. For example, disclosure requesters can include not only residents of apartment buildings but also building managers, developers of apartment buildings, etc. In such cases, it is necessary to adjust the disclosure scope.

[0007] The present disclosure has been made to solve such problems, and provides a history management device, a history management system, a history management method, and a non-transitory computer-readable medium for controlling an appropriate disclosure scope according to a disclosure requester regarding the authentication history of a facility whose entry restriction is released by authentication.

Means for Solving the Problems

[0008] The history management device according to the first aspect of the present disclosure is storage means for storing usage application information of a user in an area where entry is restricted by biometric authentication; release control means for releasing the entry restriction to the area when a predetermined visitor succeeds in biometric authentication at the entrance of the area and satisfies the usage application information; history registration means for registering the history information of the visitor who has succeeded in the biometric authentication in the storage means; generation means for generating disclosure information obtained by performing predetermined processing on the history information according to the attribute of the disclosure requester when receiving a disclosure request for the history information from a terminal of a predetermined disclosure requester; output means for outputting the disclosure information to the terminal; and includes.

[0009] The history management system according to the second aspect of the present disclosure is an authentication terminal installed at the entrance of an area where entry is restricted by biometric authentication; a history management device for managing the history information of the release of the entry restriction; a terminal of a disclosure requester for the history information; and includes the history management device is Storage means for storing user application information in the area; Release control means for releasing the entry restriction to the area when a predetermined visitor succeeds in biometric authentication via the authentication terminal and satisfies the application information; History registration means for registering the history information of the visitor who has succeeded in the biometric authentication in the storage means; Generation means for generating disclosure information obtained by performing predetermined processing on the history information according to the attribute of the disclosure requester when a disclosure request for the history information is received from the terminal; Output means for outputting the disclosure information to the terminal; It is provided with.

[0010] The history management method according to the third aspect of the present disclosure is When a computer A predetermined visitor succeeds in biometric authentication at the entrance of an area where entry is restricted by biometric authentication and satisfies the user application information in the area, the entry restriction to the area is released, Register the history information of the visitor who has succeeded in the biometric authentication in the storage device, When a disclosure request for the history information is received from the terminal of a predetermined disclosure requester, generate disclosure information obtained by performing predetermined processing on the history information according to the attribute of the disclosure requester, Output the disclosure information to the terminal.

[0011] The non-temporary computer-readable medium storing the history management program according to the fourth aspect of the present disclosure is A process of releasing the entry restriction to the area when a predetermined visitor succeeds in biometric authentication at the entrance of an area where entry is restricted by biometric authentication and satisfies the user application information in the area, A process of registering the history information of the visitor who has succeeded in the biometric authentication in the storage device, A process of generating disclosure information obtained by performing predetermined processing on the history information according to the attribute of the disclosure requester when a disclosure request for the history information is received from the terminal of a predetermined disclosure requester, The process of outputting the disclosed information to the terminal, is executed by a computer.

Effect of the Invention

[0012] According to the present disclosure, there can be provided a history management device, a history management system, a history management method, and a non-transitory computer-readable medium for controlling an appropriate disclosure range according to a disclosure requester with respect to an authentication history for a facility whose entry restriction is released by authentication.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

[0014] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In each drawing, the same or corresponding elements are denoted by the same reference numerals, and duplicated descriptions will be omitted as necessary for clarity of explanation.

[0015] <Embodiment 1> FIG. 1 is a block diagram showing the configuration of a history management device 1 according to the first embodiment. The history management device 1 is an information processing device for accumulating a history of lifting of entry restrictions in accordance with biometric authentication of visitors who have applied for use in advance in an area where entry is restricted by biometric authentication, and disclosing the history to a predetermined disclosure requester. Here, the history management device 1 is connected to a network (not shown). The network may be wired or wireless. In addition, the network is connected to an authentication terminal (locking system, not shown) for restricting entry to the area, and a terminal of a person requesting disclosure of history information. The locking system is installed at the entrance to the area, and can unlock the entrance in response to an unlocking instruction from the history management device 1. In addition, the terminal is an information terminal operated by the person requesting disclosure.

[0016] The history management device 1 includes a storage unit 11, a release control unit 12, a history registration unit 13, a generation unit 14, and an output unit 15. The storage unit 11 is a storage device that stores usage application information 111 of users in an area where entry is restricted by biometric authentication. The release control unit 12 releases the entry restriction to the area when a specific visitor succeeds in biometric authentication at the entrance to the area and satisfies the usage application information 111. The history registration unit 13 registers the history information of the visitor who succeeded in biometric authentication in the storage unit 11. When the generation unit 14 receives a disclosure request for history information from a terminal of a specific disclosure requester, it generates disclosure information by performing a specific process on the history information according to the attributes of the disclosure requester. The output unit 15 outputs the disclosure information to the terminal.

[0017] Figure 2 is a flowchart showing the flow of the history management method according to Embodiment 1. As a premise, it is assumed that usage application information 111 is registered in advance in the storage unit 11. And it is assumed that a predetermined visitor has arrived at the entrance of the area. Then, the authentication terminal installed at the entrance of the area acquires biometric information from the visitor and transmits a biometric authentication request including the biometric information to the history management device 1.

[0018] Here, the release control unit 12 controls biometric authentication of the biometric information included in the received biometric authentication request with the biometric information of a plurality of pre-registered persons. Incidentally, when the biometric information of a plurality of persons is stored in the history management device 1 in advance, the release control unit 12 performs an authentication process. Or, when the face feature information of a plurality of persons is stored in an authentication device (not shown) outside the history management device 1 in advance, the release control unit 12 causes the authentication device to perform authentication and acquires the authentication result.

[0019] Then, the release control unit 12 determines whether or not biometric authentication has been successful. If biometric authentication is successful, the release control unit 12 determines whether or not the user (visitor) who has succeeded in biometric authentication satisfies the usage application information 111 (S11).

[0020] In step S11, when the visitor succeeds in biometric authentication and satisfies the usage application information 111, the release control unit 12 releases the entry restriction to the area (S12). For example, the release control unit 12 transmits a release instruction to the authentication terminal (locking system) installed at the entrance of the area. In response to this, the authentication terminal releases the entry restriction to the area. Then, the history registration unit 13 registers the history information of the visitor who has succeeded in biometric authentication in the storage unit 11 (S13).

[0021] Thereafter, the generation unit 14 determines whether or not a disclosure request for history information has been received from the terminal of a predetermined disclosure requester (S14). When a disclosure request is received, the generation unit 14 generates disclosure information obtained by performing predetermined processing on the history information according to the attributes of the disclosure requester (S15). Then, the output unit 15 outputs the disclosure information to the terminal (S16).

[0022] Thus, in this embodiment, when a pre-registered applicant successfully passes biometric authentication at the entrance of the area and meets the application information requirements, the access restriction to the area is lifted, and at that time, history information is saved. Here, the history information includes, in addition to information related to authentication, information about the visitor and the applicant of the application, and includes personal information of the visitor and the applicant. Therefore, the history management device 1 generates disclosure information obtained by performing predetermined processing on the history information according to the attributes of the disclosure requester, and presents it to the disclosure request. That is, the disclosure information for a certain disclosure requester may include personal information, and the disclosure information for other disclosure requesters may exclude personal information. Therefore, it is possible to control the appropriate disclosure range according to the disclosure requester for the authentication history of the facility where the access restriction is lifted by authentication.

[0023] Note that the history management device 1 includes a processor, a memory, and a storage device as a configuration not shown in the figure. Further, a computer program in which the processing of the history management method according to this embodiment is implemented is stored in the storage device. Then, the processor causes the memory to read the computer program from the storage device and executes the computer program. Thereby, the processor realizes the functions of the release control unit 12, the history registration unit 13, the generation unit 14, and the output unit 15.

[0024] Alternatively, the release control unit 12, the history registration unit 13, the generation unit 14, and the output unit 15 may each be realized by dedicated hardware. Further, some or all of the components of each device may be realized by general-purpose or dedicated circuitry, a processor, etc., or a combination thereof. These may be constituted by a single chip or by a plurality of chips connected via a bus. Some or all of the components of each device may be realized by a combination of the circuitry etc. described above and a program. Further, as the processor, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (field-programmable gate array), a quantum processor (quantum computer control chip), etc. can be used.

[0025] Further, when some or all of the components of the history management device 1 are realized by a plurality of information processing devices, circuitry, etc., the plurality of information processing devices, circuitry, etc. may be centrally arranged or may be distributed. For example, the information processing devices, circuitry, etc. may be realized in a form in which each is connected via a communication network, such as a client-server system, a cloud computing system, etc. Further, the function of the history management device 1 may be provided in the form of SaaS (Software as a Service).

[0026] <Embodiment 2> Embodiment 2 is a specific example of Embodiment 1 described above. FIG. 3 is a block diagram showing the overall configuration of the history management system 1000 according to this Embodiment 2. The history management system 1000 is an information system for controlling access to each area (entrance 300a, EV hall 300b, theater room 300c, dwelling 300d, and dwelling 300e) existing in the apartment house 700. Note that the examples and arrangements of the areas of the apartment house 700 are not limited to these. The history management system 1000 includes authentication terminals 100a to 100e, gate devices 200a to 200e, terminals 401 and 402, a history management device 500, and an authentication device 600. Also, each of the authentication terminals 100a to 100e, the terminals 401 and 402, the history management device 500, and the authentication device 600 is connected via the network N. Here, the network N is a wired or wireless communication line. Note that in the following description, biometric authentication is face authentication, and biometric information is face feature information, but other techniques using a photographed image can be applied to biometric authentication and biometric information. For example, the biometric information may use data (feature amounts) calculated from unique physical characteristics of an individual, such as fingerprints, voiceprints, veins, retinas, and patterns of the iris of the pupil.

[0027] First, residents U11, U12, etc. of the apartment house 700 are assumed to have already registered their face images, personal information (name, gender, credit information, etc.), and terminal information to be used with the history management device 500 and the authentication device 600. That is, residents U11, etc. are an example of legitimate users of the apartment house 700. Also, in addition to the dwellings, the apartment house 700 has shared facilities (study rooms, theater rooms, parking lots, etc.). And each of the dwellings and the shared facilities is referred to as an "area". In particular, it is assumed that residents U11, etc. need to make a reservation and it costs money to use the shared facilities.

[0028] The entrance 300a, the EV hall 300b, the theater room 300c, the dwelling 300d, and the dwelling 300e are an example of areas where entry is restricted by biometric authentication. Note that the entrance 300a, the EV hall 300b, and the theater room 300c are an example of the common facilities of the apartment building 700. At the entrance of the entrance 300a, the authentication terminal 100a and the gate device 200a are installed. Assume that the entrance 300a is adjacent to the EV hall 300b and the theater room 300c. Therefore, at the boundary between the entrance 300a and the EV hall 300b, the authentication terminal 100b and the gate device 200b installed at the entrance of the EV hall 300b are installed. Also, at the boundary between the entrance 300a and the theater room 300c, the authentication terminal 100c and the gate device 200c installed at the entrance of the theater room 300c are installed. Also, one or more elevators (EVs) are installed in the EV hall 300b, and it is possible to move to the floors of the dwellings 300d and 300e by a certain elevator. At the entrance of the dwelling 300d, the authentication terminal 100d and the gate device 200d are installed. Also, at the entrance of the dwelling 300e, the authentication terminal 100e and the gate device 200e are installed.

[0029] For example, assume that the resident U11 of the apartment building 700 has previously made a usage application for the visitor U21 to enter the entrance 300a using the terminal 401. In that case, the visitor U21 succeeds in face authentication via the authentication terminal 100a, the gate device 200a is unlocked, and the visitor can enter the entrance 300a. Also, for example, assume that the resident U12 of the apartment building 700 has previously made usage applications for himself / herself and his / her friend U22 to use the theater room 300c using his / her own terminal (not shown). In that case, the friend U22 succeeds in face authentication via the authentication terminal 100a, the gate device 200a is unlocked, the friend U22 can enter the entrance 300a, and then, the friend U22 succeeds in face authentication via the authentication terminal 100c, the gate device 200c is unlocked, and the friend U22 can enter the theater room 300c. However, since the friend U22 fails in face authentication by the authentication terminal 100b, the friend U22 cannot enter the EV hall 300b, the dwellings 300d, and 300e.

[0030] Also, for example, a resident (not shown) of the dwelling 300d in the apartment house 700 makes a usage application in advance using the resident's terminal (not shown) for the housework agent U23 to enter the dwelling 300d to clean while the resident (family) of the dwelling 300d is absent. In that case, the housework agent U23 succeeds in face authentication via the authentication terminals 100a, 100b, and 100d. Therefore, the housework agent U23 can enter the dwelling 300d via the entrance 300a and the EV hall 300b. However, the housework agent U23 cannot enter the theater room 300c or the dwelling 300e.

[0031] In the following description, the entrance 300a to the dwelling 300e may sometimes be simply referred to as the area 300. Similarly, the authentication terminals 100a to 100e may sometimes be simply referred to as the authentication terminal 100. Also, the gate devices 200a to 200e may sometimes be simply referred to as the gate device 200. Each of the authentication terminals 100a to 100e is an example of a locking system. Also, the gate device 200 is, for example, a flap gate, an automatic door, or a normal door, and is assumed to be able to unlock the key (release the access restriction) in response to a release instruction from the connected authentication terminal 100.

[0032] The authentication device 600 is an information processing device that stores face feature information of a plurality of persons. Also, the authentication device 600 collates the face image or face feature information included in the request with the face feature information of each user in response to a face authentication request received from the outside, and returns the collation result (authentication result) to the requester.

[0033] FIG. 4 is a block diagram showing the configuration of the authentication device 600 according to the second embodiment. The authentication device 600 includes a face information database (DB) 610, a face detection unit 620, a feature point extraction unit 630, a registration unit 640, and an authentication unit 650. The face information DB 610 stores the user ID 611 and the face feature information 612 of the user ID in association with each other. The face feature information 612 is a set of feature points extracted from a face image. Note that the authentication device 600 may delete the face feature information 612 in the face feature DB 610 according to the request of the registered user of the face feature information 612. Alternatively, the authentication device 600 may delete the face feature information 612 after a certain period has elapsed since the registration of the face feature information 612.

[0034] The face detection unit 620 detects a face area included in a registration image for registering face information and outputs it to the feature point extraction unit 630. The feature point extraction unit 630 extracts feature points from the face area detected by the face detection unit 620 and outputs face feature information to the registration unit 640. Further, the feature point extraction unit 630 extracts feature points included in a face image received from the history management device 500, the terminal 401, the authentication terminal 100, or the like, and outputs face feature information to the authentication unit 650.

[0035] When registering face feature information, the registration unit 640 newly issues a user ID 611. The registration unit 640 registers the issued user ID 611 and the face feature information 612 extracted from the registration image in the face information DB 610 in association with each other. Note that after registration, the registration unit 640 notifies the history management device 500 of the user ID 611 and the face image or the face feature information 612. The authentication unit 650 performs face authentication using the face feature information 612. Specifically, the authentication unit 650 collates the face feature information extracted from a face image with the face feature information 612 in the face information DB 610. When the collation is successful, the authentication unit 650 identifies the user ID 611 associated with the collated face feature information 612. The authentication unit 650 returns the presence or absence of the match of the face feature information to the history management device 500 as a face authentication result. The presence or absence of the match of the face feature information corresponds to the success or failure of the authentication. Note that the case where the face feature information matches (match exists) means that the degree of match is equal to or greater than a predetermined value. Further, the face authentication result includes the identified user ID when the face authentication is successful.

[0036] Also, the authentication unit 650 does not need to attempt to match with all the face feature information 612 in the face information DB 610. For example, the authentication unit 650 may preferentially attempt to match with the face feature information registered during the period from several days before the day when the face authentication request was received. This can improve the matching speed. Also, when the preferential matching fails, it is advisable to perform matching with all the remaining face feature information.

[0037] Subsequently, the authentication terminal 100 is an information processing device installed at the entrance of a predetermined area and connected to a gate device 200 similarly installed at the entrance. FIG. 5 is a block diagram showing the configuration of the authentication terminal (locking system) 100 according to the second embodiment. The authentication terminal 100 includes a camera 110, a storage unit 120, a communication unit 130, an input / output unit 140, and a control unit 150.

[0038] The camera 110 is a photographing device that performs photographing according to the control of the control unit 150. The storage unit 120 is a storage device in which programs for realizing the respective functions of the authentication terminal 100 are stored. The communication unit 130 is a communication interface with the network N. The input / output unit 140 includes a display device (display unit) such as a screen and an input device. The input / output unit 140 may be, for example, a touch panel. The control unit 150 controls the hardware of the authentication terminal 100. The control unit 150 includes a photographing control unit 151, a registration unit 152, an authentication control unit 153, a display control unit 154, and a locking control unit 155.

[0039] The photographing control unit 151 controls the camera 110 and photographs a registration image or an authentication image of a user at the entrance of a predetermined area. The registration image and the authentication image are images including at least the face area of the user (such as a resident or a visitor). The photographing control unit 151 outputs the registration image to the registration unit 152. Also, the photographing control unit 151 outputs the authentication image to the authentication control unit 153.

[0040] The registration unit 152 transmits a face information registration request including a registered image to the authentication device 600 via the network N. The authentication control unit 153 transmits a face authentication request including an authentication image to the history management device 500 via the network N. At this time, the authentication control unit 153 includes the area ID of the corresponding predetermined area and the shooting time of the authentication image (face image) in the face authentication request. Note that the identification information (terminal ID) of the authentication terminal 100 may be used instead of the area ID. The display control unit 154 receives various screen data from the history management device 500 via the network N and displays the received screen data on the input / output unit 140. When the locking control unit 155 receives an unlocking instruction from the history management device 500 via the network N, the locking control unit 155 outputs an unlocking instruction to the corresponding gate device 200.

[0041] Returning to FIG. 3, the description will continue. The terminal 401 is an information terminal owned by the resident U11. It is assumed that the resident U11 is a resident (regular user) of the dwelling 300e. The terminal 401 is, for example, a mobile phone terminal, a smartphone, a tablet terminal, a PC (Personal Computer) equipped with or connected to a camera, or the like. The terminal 401 is associated with the user ID or face feature information of the resident U11. That is, the terminal 401 is a terminal that can be specified by the user ID or face feature information in the history management device 500. For example, the terminal 401 is a terminal on which the resident U11 has logged in using his or her own user ID.

[0042] The terminal 401 transmits a usage application including the user name, specific area (area for which usage is applied), and usage application period input by the resident U11 to the history management device 500 via the network N. Also, the terminal 401 receives an application result (permission or rejection) from the history management device 500 via the network N and displays it on the screen or the like. Further, the terminal 401 may transmit a registration request including the face image of the visitor U21 or the like who is the user to the history management device 500 via the network N. Or, the terminal 401 transmits a registration destination request to the history management device 500 via the network N, and transmits the registration destination information returned from the history management device 500 to the terminal (not shown) of the visitor U21 or the like via the network N. Or, when the user name for which usage is applied is a visitor from outside, the terminal 401 receives the registration destination information from the history management device 500 via the network N and transmits it to the terminal of the visitor U21 or the like. Here, the registration destination information may be the URL (Uniform Resource Locator) of the authentication device 600 or the like. Then, the terminal 401 receives the user ID issued to the visitor U21 or the like from the history management device 500 via the network N and the face image of the visitor U21 or the like. The terminal 401 displays the received face image on the screen. The terminal 401 may accept the designation of the actionable range of the visitor U21 or the like based on the input of the resident U11. When the resident U11 confirms the display of the face image of the visitor U21 or the like and accepts the approval input, the terminal 401 transmits the fact of approval to the history management device 500 via the network N.

[0043] In addition, when the terminal (not shown) of the visitor U21 or the like receives the registration destination information from the terminal 401 via the network N, it transmits its own face image to the destination indicated by the registration destination information via the network N.

[0044] Further, in response to the input from the resident U11, the terminal 401 transmits a disclosure request for the history information of the entry (successful authentication) into the residence 300e to the history management device 500 via the network N. At this time, the disclosure request includes the user ID of the resident U11 and the area ID of the residence 300e. Further, the disclosure request may include a disclosure target period. The terminal 401 receives the disclosure information from the history management device 500 via the network N and displays the disclosure information on the screen.

[0045] The terminal 402 is an information terminal owned by the developer U3 of the apartment house 700. Note that the developer U3 is other than a regular user of the apartment house 700. Other than regular users of the apartment house 700 includes the manager (management association) of the apartment house 700. In response to the input from the developer U3, the terminal 402 transmits a disclosure request for the history information of the entry (successful authentication) into the theater room 300c to the history management device 500 via the network N. At this time, the disclosure request includes the user ID of the developer U3 and the area ID of the theater room 300c. Further, the disclosure request may include a disclosure period. The terminal 402 receives the disclosure information from the history management device 500 via the network N and displays the disclosure information on the screen.

[0046] The history management device 500 is an information processing device for controlling the entry of users (residents or visitors, etc.) into a predetermined area and managing the history of entry (authentication). The history management device 500 may be redundant on a plurality of servers, or each functional block may be realized by a plurality of computers.

[0047] Next, the history management device 500 will be described in detail. FIG. 6 is a block diagram showing the configuration of the history management device 500 according to the second embodiment. The history management device 500 includes a storage unit 510, a memory 520, an IF (InterFace) unit 530, and a control unit 540. The storage unit 510 is an example of a storage device such as a hard disk or a flash memory. The storage unit 510 stores a program 511, usage application information 512, resident information 513, history disclosure person information 514, and authentication history 515. The program 511 is a computer program in which the processing of the history management method according to the second embodiment is implemented.

[0048] The usage application information 512 is information for managing the usage applications for specific areas permitted by applicants such as the resident U11. The usage application information 512 has an applicant ID 5121, a user ID 5122, user information 5123, a usage application period 5124, a usage purpose 5125, and an actionable range 5126 associated therewith.

[0049] The applicant ID 5121 is the user ID of a user such as the resident U11 who has made a usage application. Therefore, the applicant ID 5121 may correspond to the user ID 611 of the face information DB 610 described above, the user ID 5131 of the resident information 513 described later, and the user ID 5141 described later.

[0050] The user ID 5122 is the user ID of the user (resident or visitor) for whom the usage application has been made. Therefore, the user ID 5122 corresponds to at least the user ID 611 of the face information DB 610 described above. That is, the face information DB 610 and the usage application information 512 are associated via the user ID.

[0051] The user information 5123 is detailed information about the user corresponding to the user ID 5122 and includes personal information and attribute information. The personal information of the user information 5123 includes, for example, the name, age, contact information (mobile phone number), etc. of the user. The attribute information of the user information 5123 includes, for example, information such as whether the user is a friend or a housework proxy, age group (e.g., in their 30s), gender, etc.

[0052] The usage application period 5124 is the period during which the user can use within the actionable range 5126. In other words, the usage application period 5124 is the period during which the user is permitted to pass through each area passed through until reaching the specific area and stay in the specific area.

[0053] The usage purpose 5125 is information indicating the purpose for which the user uses the specific area for which the usage application is made. The usage purpose 5125 is, for example, "cleaning", "playing", "viewing", etc. Note that the usage purpose 5125 may also be called the visit purpose.

[0054] The actionable range 5126 is a set of areas where the user is permitted to pass through or stay. The actionable range 5126 includes one or more area IDs. That is, the actionable range 5126 includes at least the area ID corresponding to the specific area for which the usage application is made. And when passing through a plurality of areas from the entrance of the facility until reaching the specific area for which the usage application is made, the actionable range 5126 includes the area IDs of each area passed through.

[0055] The resident information 513 is information for managing the residents of the apartment building 700. The resident information 513 is an example of the registration information described above. In the resident information 513, a user ID 5131, an attribute 5132, and resident personal information 5133 are associated with each other. The user ID 5131 is identification information of the resident. The attribute 5132 is attribute information of the resident corresponding to the user ID 5131. The attribute 5132 is information indicating, for example, whether the resident is the head of the household of the residence, the spouse of the head of the household, a child of the head of the household, an adult or a minor, gender, the grade of the residence owned or leased, etc. The attribute 5132 may include the user IDs of cohabitants corresponding to the associated user ID 5131. Further, the attribute 5132 may include information indicating family relationships (parent, child) among cohabitants. Further, the attribute 5132 may include information indicating the strength or weakness of authority among cohabitants. For example, the attribute 5132 may be information indicating that the authority of the head of the household or their spouse among cohabitants is relatively strong and the authority of the child of the head of the household is relatively weak. Also, the attribute 5132 may make the authority of an adult stronger than that of a minor. Further, the attribute 5132 may be information indicating authority according to the grade of the residence. The resident personal information 5133 includes, for example, the name, age, contact information (mobile phone number), credit information (debit account number), etc. of the resident corresponding to the user ID 5131.

[0056] The history disclosure user information 514 is information that defines a user who has been permitted to disclose history information and their attributes. In the history disclosure user information 514, a user ID 5141 and an attribute 5142 are associated with each other. The user ID 5141 includes the user ID of a resident (regular user) and the user ID of a developer U3, etc. (other than regular users). The attribute 5142 is information indicating whether the user is a resident (regular user) or other than a resident (other than regular users).

[0057] The authentication history 515 is history information of biometric authentication in a predetermined area (authentication location). Here, the authentication history 515 is information recorded when it is determined that biometric authentication is successful, the usage application information 512 is satisfied, and the entry restriction of the area is released. However, the authentication history 515 may include a history of failed authentication.

[0058] The authentication history 515 has the authentication date and time 5151, the authentication location 5152, the authenticator ID 5153, the face image 5154, and the usage application information 5155 associated therewith. The authentication date and time 5151 is information indicating the date and time when the biometric authentication was successful. The authentication date and time 5151 may be the shooting time included in the face authentication request received from the authentication terminal 100. The authentication location 5152 is information indicating the location where the biometric authentication was performed. For example, the authentication location 5152 may be the area ID included in the face authentication request received from the authentication terminal 100 or the area name corresponding to the area ID. The authenticator ID 5153 is the user ID included in the face authentication result when the biometric authentication is successful. The face image 5154 is the face image included in the face authentication request received from the authentication terminal 100. Here, the face image 5154 is the face image when the face authentication is successful. The usage application information 5155 is the usage application information when the biometric authentication is successful and it is determined that the usage application information 512 is satisfied. The usage application information 5155 may be the identification information of the usage application information 512.

[0059] The memory 520 is a volatile storage device such as a RAM (Random Access Memory), and is a storage area for temporarily holding information during the operation of the control unit 540. The IF unit 530 is a communication interface with the network N.

[0060] The control unit 540 is a processor that controls each component of the history management device 500, that is, a control device. The control unit 540 causes the memory 520 to read the program 511 from the storage unit 510 and executes the program 511. Thereby, the control unit 540 realizes the functions of the application registration unit 541, the authentication control unit 542, the cancellation control unit 543, the history registration unit 544, and the history disclosure control unit 545.

[0061] The application registration unit 541 registers the usage application received from the terminal 401 in the storage unit 510 as the usage application information 512 when the application is permitted. Further, when the application registration unit 541 receives a registration destination request from the terminal 401, it may return the destination information of the authentication device 600 to the terminal 401 as the registration destination information.

[0062] The authentication control unit 542 controls the face authentication for the face image included in the face authentication request received from the authentication terminal 100. That is, the authentication control unit 542 causes the authentication device 600 to perform face authentication on the face image. For example, the authentication control unit 542 transmits a face authentication request including the acquired face image to the authentication device 600 via the network N and receives a face authentication result from the authentication device 600. Note that the authentication control unit 542 may detect the face area of the user from the face image and include the image of the face area in the face authentication request. Alternatively, the authentication control unit 542 may extract face feature information from the face area and include the face feature information in the face authentication request. The authentication control unit 542 acquires the face authentication result from the authentication device 600 via the network N and outputs the face authentication result to the release control unit 543.

[0063] The release control unit 543 is an example of the release control unit 12 described above. When a predetermined visitor successfully passes face authentication at the entrance of a certain area and satisfies the usage application information 111, the release control unit 543 releases the access restriction to the area. In other words, when the conditions of the usage application information 512 are satisfied for a user who has successfully passed face authentication, the release control unit 543 outputs a release instruction to the authentication terminal 100 that made the face authentication request.

[0064] The history registration unit 544 is an example of the history registration unit 13 described above. When a release instruction is output by the release control unit 543, the history registration unit 544 registers the authentication history 515 of the visitor (authenticator) who has successfully passed face authentication in the storage unit 510.

[0065] The history disclosure control unit 545 is an example of the generation unit 14 and the output unit 15 described above. The history disclosure control unit 545 receives a request for disclosure of history information from the terminal 401 or the terminal 402. The history disclosure control unit 545 generates disclosure information obtained by performing predetermined processing on the history information according to the attribute of the disclosure requester of the received disclosure request. Then, the history disclosure control unit 545 outputs the disclosure information to the terminal that is the source of the request.

[0066] Specifically, first, the history disclosure control unit 545 identifies the attribute 5142 of the disclosure requester based on the history disclosure person information 514 from the user ID included in the disclosure request. Then, the history disclosure control unit 545 determines whether the identified attribute is a resident or non-resident (such as a developer, etc.). When the attribute of the disclosure requester is other than a regular user of the apartment house 700, the history disclosure control unit 545 may perform processing to exclude personal information from the history information. For example, the history disclosure control unit 545 generates disclosure information by excluding the personal information of the user and the personal information of the applicant.

[0067] Also, when the attribute of the disclosure requester is a regular user (resident) of the apartment house 700, the history disclosure control unit 545 may perform processing to exclude information when the visitor is a regular user from the history information. That is, the history disclosure control unit 545 generates disclosure information by excluding information in the authentication history 515 where the authenticator ID 5153 is the user ID 5131 of the resident information 513.

[0068] Also, the history disclosure control unit 545 may identify applicant information corresponding to the history information from the utilization application information 5155 within the authentication history 515, and generate disclosure information including the identified applicant information.

[0069] Also, the history disclosure control unit 545 may identify the purpose of use corresponding to the history information from the utilization application information 5155 within the authentication history 515, and generate disclosure information including the identified purpose of use.

[0070] Also, the history disclosure control unit 545 may generate disclosure information including information regarding the location where the visitor successfully passed biometric authentication (for example, the authentication location 5152).

[0071] FIG. 7 is a flowchart showing the flow of the utilization application process according to the second embodiment. Here, it is assumed that the resident U11 makes a utilization application for the visitor U21 to use (enter) the entrance 300a.

[0072] First, the terminal 401 transmits an application for use, which includes the user name (name of the visitor U21) input by the resident U11, the specific area (area ID of the entrance 300a), and the application period for use, to the history management device 500 via the network N. Note that the terminal 401 shall include the user ID of the resident U11 logged in to the terminal 401 (such as the use application application) as the applicant ID in the application for use. In addition, the terminal 401 may include the personal information and attribute information of the user in the application for use. Further, the terminal 401 may include the face image of the user in the application for use. Alternatively, when the user ID of the user is known (for example, in the case of a resident of the apartment house 700 or a visitor who has applied for use in the past), the terminal 401 may include the user ID in the application for use instead of the face image. Moreover, the terminal 401 may include the purpose of use of the user in the application for use.

[0073] In response to this, the application registration unit 541 of the history management device 500 receives the application for use via the network N and accepts the application for use (S201). Next, the application registration unit 541 determines whether to permit the application for use (S202). That is, the application registration unit 541 determines whether to permit the application for use based on the attributes of the applicant or the application history of use by the applicant (not shown). Specifically, the application registration unit 541 specifies the attribute 5132 associated with the applicant ID (user ID 5131) included in the application for use from among the resident information 513, and determines whether to permit the application for use of the area applied for according to the specified attribute. For example, when the specific area is the residence 300d and the specified attribute indicates a resident of the residence 300d, the application registration unit 541 determines to permit the application for use. Also, when the usage frequency of the applicant based on the application history of use is equal to or less than a predetermined number of times, the application registration unit 541 may determine to permit the application for use.

[0074] In step S202, when it is determined not to permit the application for use, the application registration unit 541 outputs a message indicating rejection of the application for use (S205). For example, the history management device 500 transmits a message indicating rejection of the application for use to the terminal 401 via the network N.

[0075] On the one hand, in step S202, when it is determined to permit the usage application, the application registration unit 541 generates usage application information 512 and registers it in the storage unit 510 (S203). For example, the application registration unit 541 generates the usage application information 512 by including the applicant ID 5121 and the usage application period 5124 included in the usage application.

[0076] Also, when the user who has applied for usage is a visitor U21 or the like, the following processing is performed. First, when the usage application does not include the personal information, attribute information, and usage purpose of the user, the application registration unit 541 requests these from the terminal 401, uses the personal information and attribute information of the user obtained from the terminal 401 as the user information 5123, and includes the obtained usage purpose as the usage purpose 5125 in the usage application information 512 to generate it. Also, if the usage application includes a user ID, the application registration unit 541 includes this as the user ID 5122 in the usage application information 512. On the other hand, if the usage application does not include a user ID but includes a face image, the application registration unit 541 transmits a face information registration request including the face image to the authentication device 600 via the network N. As a result, the authentication device 600 issues a user ID, associates the issued user ID 611 with the face feature information 612 extracted from the face image, and registers them in the face information DB 610. Then, the authentication device 600 returns the issued user ID to the history management device 500. In response to this, the application registration unit 541 receives the issued user ID from the authentication device 600 via the network N and includes the user ID as the user ID 5122 in the usage application information 512.

[0077] In addition, when the user ID for which the usage is applied indicates a resident, the application registration unit 541 acquires the attribute 5132 and the resident personal information 5133 corresponding to the user ID (user ID 5131) from the resident information 513 and includes them in the usage application information 512 as the user information 5123.

[0078] In addition, the application registration unit 541 specifies the actionable range 5126 based on the attributes of the applicant and the layout information (not shown) of each area of the apartment house 700, and includes it in the usage application information 512. The application registration unit 541 specifies the actionable range 5126 including each area passed through from the entrance of the apartment house 700 to the specific area. Here, the application registration unit 541 includes the area ID of the entrance 300a in the actionable range 5126. However, for example, when the specific area related to the usage application is the dwelling 300d, the application registration unit 541 includes the area IDs of the entrance 300a, the EV hall 300b, and the dwelling 300d in the actionable range 5126.

[0079] After that, the application registration unit 541 outputs that the usage application is permitted (S204). For example, the history management device 500 transmits a message indicating that the usage application is permitted to the terminal 401 via the network N.

[0080] FIG. 8 is a flowchart showing the flow of the entrance control process according to the second embodiment. Here, it is assumed that the usage application process in FIG. 7 has been completed. First, it is assumed that the visitor U21 arrives at the entrance of the entrance 300a of the apartment house 700. Here, the authentication terminal 100a captures the face image of the visitor U21. Then, the authentication terminal 100a transmits a face authentication request including the captured face image, the area ID of the entrance 300a, and the shooting time to the history management device 500 via the network N. In response to this, the authentication control unit 542 of the history management device 500 acquires the face image, the area ID, and the shooting time included in the face authentication request from the authentication terminal 100a via the network N (S211)

[0081] Then, the authentication control unit 542 transmits a face authentication request including the acquired face image to the authentication device 600 via the network N (S212). The authentication device 600 receives the face authentication request from the history management device 500 via the network N and performs face authentication processing based on the face image included in the face authentication request. Specifically, the face detection unit 620 detects a face region from the face image. Then, the feature point extraction unit 630 extracts face feature information from the face region. And the authentication unit 650 collates the extracted face feature information with the face feature information 612 in the face information DB 610. When the face feature information matches, that is, when the degree of match of the face feature information is equal to or greater than a predetermined value, the authentication unit 650 identifies the user ID 611 of the user whose face feature information matches, and generates a face authentication result including the fact that the face authentication was successful and the identified user ID. On the other hand, when there is no matching face feature information, the authentication unit 650 generates a face authentication result including the fact that the face authentication failed. Then, the authentication unit 650 transmits the generated face authentication result to the history management device 500 via the network N.

[0082] Accordingly, the authentication control unit 542 of the history management device 500 receives the face authentication result from the authentication device 600 via the network N and outputs the face authentication result to the release control unit 543. Then, the release control unit 543 determines whether the face authentication was successful based on the face authentication result (the first condition) (S213). When it is determined that the face authentication was successful, the release control unit 543 identifies the user ID included in the face authentication result (S214). And the release control unit 543 uses the identified user ID as the user ID 5122, and identifies the usage application information 512 including the user ID 5122 (S215).

[0083] Then, the release control unit 543 determines whether the usage application conditions are met (S216). Specifically, the release control unit 543 acquires the usage application period 5124 and the actionable range 5126 from the specified usage application information 512. Then, the release control unit 543 determines whether the area ID acquired in step S211 is within the specified actionable range (second condition). In addition, the release control unit 543 determines whether the shooting time acquired in step S231 is within the range of a predetermined period including the specified usage application period (third condition). Note that the predetermined period may include about 15 minutes before and after the usage application period.

[0084] If it is determined in step S216 that the usage application conditions (second condition and third condition) are met, the release control unit 543 transmits a release instruction to the authentication terminal 100a installed in the area corresponding to the area ID acquired in step S211 via the network N (S217). In other words, the release control unit 543 gives a release instruction to the authentication terminal 100a which is the requester of the face authentication request. In response to this, the locking control unit 155 of the authentication terminal 100a receives the release instruction from the history management device 500 via the network N and outputs the release instruction to the gate device 200a. Then, the gate device 200a releases the gate according to the received release instruction. As a result, the visitor U21 can enter the entrance 300a.

[0085] Thereafter, the history registration unit 544 registers the authentication history (history information) 515 in the storage unit 510 (S218). Specifically, the history registration unit 544 sets the shooting time acquired in step S211 or the time when it is determined that face authentication has succeeded in step S213 as the authentication date and time 5151. Also, the history registration unit 544 sets the area ID acquired in step S211 or the area name (entrance 300a) corresponding to the area ID as the authentication location 5152. Further, the history registration unit 544 sets the user ID specified in step S214 as the authenticator ID 5153. Also, the history registration unit 544 sets the face image acquired in step S211 as the face image 5154. Additionally, the history registration unit 544 sets the usage application information 512 specified in step S215 as the usage application information 5155. Then, the history registration unit 544 associates the above authentication date and time 5151, authentication location 5152, authenticator ID 5153, face image 5154, and usage application information 5155, and stores them in the storage unit 510 as the authentication history 515.

[0086] If it is determined that face authentication has failed in step S213, or if it is determined that the usage application conditions are not met in step S216, the release control unit 543 transmits (outputs) a message indicating that release is not possible to the authentication terminal 100a via the network N (S219).

[0087] FIG. 9 is a flowchart showing the flow of the history disclosure process according to the second embodiment. Here, a case where the resident U11 makes a request to disclose history information using the terminal 401 will be described. First, the history disclosure control unit 545 receives a request to disclose history information from the terminal 401 via the network N (S221). Here, it is assumed that the disclosure request includes the user ID of the resident U11 who is the disclosure requester, information indicating the location for which history is to be disclosed (area ID of the residence 300e), and the disclosure target period.

[0088] Next, the history disclosure control unit 545 acquires the history information corresponding to the received disclosure request (S222). That is, the history disclosure control unit 545 uses the area ID included in the disclosure request as the authentication location 5152, and searches for the history information of the authentication date and time 5151 included in the disclosure target period from the authentication history 515. Here, it is assumed that one or more pieces of history information are found in the search.

[0089] Then, the history disclosure control unit 545 determines whether the disclosure requester is a resident (S223). Specifically, the history disclosure control unit 545 identifies the attribute 5142 associated with the user ID 5141 included in the disclosure request from the history disclosure person information 514. Then, the history disclosure control unit 545 determines whether the identified attribute indicates a resident. Here, it is determined that the disclosure requester is a resident.

[0090] Then, the history disclosure control unit 545 generates disclosure information by excluding the history of residents from the history information (S224). Specifically, first, the history disclosure control unit 545 excludes the history in which the authenticator ID 5153 is the disclosure requester or a cohabitant thereof from the history information acquired in step S222. Alternatively, the history disclosure control unit 545 acquires a list of user IDs of the residents of the residence 300e, which is the history disclosure target location, from the resident information 513, and excludes the history information in which the authenticator ID 5153 is included in the list of the user IDs.

[0091] Then, the history disclosure control unit 545 generates disclosure information using the excluded history information. For example, the history disclosure control unit 545 includes the authentication date and time 5151, the authentication location 5152, and the face image 5154 among the excluded history information in the disclosure information. Also, the history disclosure control unit 545 identifies the name of the authenticator from the authenticator ID 5153 and the user information 5123 of the usage application information 5155 among the excluded history information, and includes it in the disclosure information. Further, the history disclosure control unit 545 identifies the applicant ID 5121 of the usage application information 5155 among the excluded history information, and identifies the resident personal information 5133 associated with the applicant ID (user ID 5131) identified from the resident information 513. Then, the history disclosure control unit 545 identifies the applicant name from the identified resident personal information 5133 and includes it in the disclosure information. Note that the history disclosure control unit 545 may generate the disclosure information as screen information in which the above-described each information is arranged in a predetermined layout.

[0092] After that, the history disclosure control unit 545 outputs the generated disclosure information (S226). That is, the history disclosure control unit 545 transmits the disclosure information to the terminal 401 via the network N. In response to this, the terminal 401 receives the disclosure information from the history management device 500 via the network N and displays the disclosure information on the screen.

[0093] FIG. 10 is a diagram showing an example of disclosure information according to the second embodiment. Here, an example in which disclosure information about two pieces of history information is displayed on the terminal 401 is shown. The first piece of disclosure information includes a face image 811, an authentication date and time 812, an authentication location 813, a usage purpose 814, an authenticator name 815, and an applicant name 816. The face image 811 shows the face image of the authenticator name 815 "Mr. Tanaka" who was face-authenticated (or photographed) at the authentication date and time 812 "2020 / 9 / 9 (Wed) 10:00" at the authentication terminal 100 installed at the entrance of the authentication location 813 "Room 501". The usage purpose 814 indicates that the usage purpose of the authenticator is "cleaning". Also, the applicant name 816 indicates that the usage application of the authenticator was made by "Ms. Kazuko Suzuki".

[0094] The second disclosure information includes a face image 821, an authentication date and time 822, an authentication location 823, a purpose of use 824, an authenticator's name 825, and an applicant's name 826. The face image 821 shows the face image of the authenticator named "Mr. Sato" who was face-authenticated (or photographed) at the authentication date and time 822 "September 8, 2020 (Tuesday) 15:00" at the authentication terminal 100 installed at the entrance of the authentication location 823, "Room 501". The purpose of use 824 indicates that the purpose of use of the authenticator is "play" (with the children of the resident). Also, the applicant's name 826 indicates that the use application of the authenticator was made by "Mr. Michio Suzuki".

[0095] Thus, in this embodiment, a resident of the apartment building 700 can refer to the visit history of visitors (other than residents) to his or her residence. At this time, as shown in FIG. 10, since the applicant's information (such as name) is also disclosed, even if the resident U11 himself / herself did not apply, it is possible to grasp who among the family members applied.

[0096] Also, when the resident U11 requests disclosure, in addition to their own residence, the historical disclosure target location may be specified as a shared facility (for example, the theater room 300c, study room, etc.). Also, even if the disclosure requester is a resident, the historical disclosure control unit 545 may leave the history of the disclosure requester and co-residents in the historical information. For example, the terminal 401 sends a disclosure request including the area IDs of the residence 300e and the theater room 300c to the history management device 500 as the historical disclosure target location. In this case, the historical disclosure control unit 545 acquires the first historical information in which the authentication location 5152 corresponds to the residence 300e from the authentication history 515. At this time, the historical disclosure control unit 545 may not exclude the history of the disclosure requester and co-residents from the acquired first historical information. Note that the first historical information can only be referenced on a per-resident (family) basis of the residence. This is because it is the authentication history in a place where privacy protection is required. Also, the historical disclosure control unit 545 acquires the second historical information in which the authentication location 5152 corresponds to the theater room 300c from the authentication history 515. At this time, the historical disclosure control unit 545 may include the residents of the residence 300e in addition to visitors (friends, etc.) from the acquired second historical information. For example, the historical disclosure control unit 545 extracts the historical information when the applicant is a resident of the residence 300e regarding the authentication history in the theater room 300c. Note that since the second historical information is the authentication history of the shared facility, any resident of the apartment building 700 can reference it including the history of residents of other residences. Then, the historical disclosure control unit 545 synthesizes the first historical information and the second historical information to generate disclosure information. Therefore, the terminal 401 displays the generated disclosure information. As a result, the resident U11 can confirm that their family members are using the shared facility in addition to their own residence 300e. At the same time, the resident U11 can also confirm the history of the visit of the housekeeper to their own residence 300e in the same manner as above.

[0097] Next, a case where the developer U3 of the apartment house 700 makes a disclosure request for history information using the terminal 402 will be described. First, the history disclosure control unit 545 receives a disclosure request for history information from the terminal 402 via the network N (S221). Here, it is assumed that the disclosure request includes the user ID of the developer U3 who is the disclosure requester, information indicating the location for which history is to be disclosed (the area ID of the theater room 300c), and the disclosure target period. Step S222 is the same as above. Then, in step S223, the history disclosure control unit 545 determines that the disclosure requester is not a resident.

[0098] Then, the history disclosure control unit 545 generates disclosure information by excluding personal information from the history information (S225). Specifically, first, the history disclosure control unit 545 excludes personal information from among the face image 5154 and the user information 5123 within the usage application information 5155 in the history information acquired in step S222. Further, the history disclosure control unit 545 excludes the resident personal information 5133 associated with the applicant ID 5121 (user ID 5131) within the usage application information 5155 from the excluded history information. In other words, the history disclosure control unit 545 leaves the attribute information regarding the users and applicants in the history information acquired in step S222.

[0099] Then, the history disclosure control unit 545 generates disclosure information using the excluded history information. For example, the history disclosure control unit 545 includes the authentication date and time 5151 and the authentication location 5152 in the excluded history information in the disclosure information. Also, the history disclosure control unit 545 specifies attribute information from the authenticator ID 5153 and the user information 5123 of the usage application information 5155 in the excluded history information and includes it in the disclosure information. Further, the history disclosure control unit 545 specifies the applicant ID 5121 of the usage application information 5155 in the excluded history information and specifies the attribute 5132 associated with the specified applicant ID (user ID 5131) from among the resident information 513. Then, the history disclosure control unit 545 includes the specified attribute 5132 in the disclosure information. Note that the history disclosure control unit 545 may generate the disclosure information as screen information in which the above-described respective information is arranged in a predetermined layout.

[0100] After that, the history disclosure control unit 545 outputs the generated disclosure information (S226). That is, the history disclosure control unit 545 transmits the disclosure information to the terminal 402 via the network N. In response to this, the terminal 402 receives the disclosure information from the history management device 500 via the network N and displays the disclosure information on the screen.

[0101] FIG. 11 is a diagram showing an example of the disclosure information according to the second embodiment. Here, an example in which the disclosure information about two pieces of history information is displayed on the terminal 402 is shown. The first piece of disclosure information includes an authentication date and time 832, an authentication location 833, a purpose of use 834, an authenticator attribute 835, and an applicant attribute 836. The authenticator attribute 835 indicates information in which the personal information of the authenticator is not specified. Here, the authenticator attribute 835 indicates that the person is not a resident, and the age and gender are used as attributes. Also, the applicant attribute 836 indicates information in which the personal information of the applicant is not specified. Here, the applicant attribute 836 indicates that the applicant is a resident of Room 501, is the spouse of the head of the household, and is a woman in her 30s.

[0102] The second piece of disclosure information includes an authentication date and time 842, an authentication location 843, a purpose of use 844, an authenticator attribute 845, and an applicant attribute 846. The authenticator attribute 835 indicates that the person is a resident and has the same attributes as the applicant attribute 836.

[0103] As described above, in this embodiment, a person other than the resident of the apartment house 700 can refer to the usage status of the common facilities. At this time, as shown in FIG. 11, personal information is protected. On the other hand, in the case of a condominium developer or the like, the attributes of the users of the common facilities can be grasped in detail. Therefore, it can be utilized for condominium development marketing and the like. Also, when a person other than the resident of the apartment house 700 is the manager, the necessity of repairing the common facilities can be considered by grasping the usage status of the common facilities. Also, although the management association includes residents, when referring to the usage status of the common facilities from the position of the management association (from a position other than that of a regular user of the residence), it is desirable that the personal information of residents and visitors be masked.

[0104] Also, residents may refer to the usage status of the shared facilities. That is, the disclosure requester may be any resident of the apartment building 700. In that case as well, similar to FIG. 11 above, any resident can check the usage status of the shared facilities in the apartment building 700 with personal information masked.

[0105] <Embodiment 3> This Embodiment 3 is a modification of the above-described Embodiment 2. In this Embodiment 3, a biometric authentication function is incorporated into the history management device. Since the history management system according to this Embodiment 3 is the same as the one in which the authentication device 600 in the above-described history management system 1000 is incorporated into the history management device 500a, the illustration and description thereof are omitted.

[0106] FIG. 12 is a block diagram showing the configuration of the history management device 500a according to this Embodiment 3. The storage unit 510 of the history management device 500a has the program 511 replaced by the program 511a and the face feature information 5127 added to the usage application information 512 as compared with the above-described history management device 500. Note that the face feature information 5127 is an example of biometric information. Also, the control unit 240 of the history management device 500a has the authentication control unit 542 replaced by the authentication control unit 542a as compared with the above-described history management device 500.

[0107] The program 511a is a computer program in which the processing of the history management method according to this Embodiment 3 is implemented.

[0108] The face feature information 5127 corresponds to the face feature information 612 of the above-described authentication device 600. The face feature information 5127 is associated with the user ID 5122. That is, the usage application information 512 includes the above-described face information DB 610.

[0109] The authentication control unit 542a controls face authentication by comparing the face feature information of multiple persons with the face feature information of the visitor. That is, the authentication control unit 542a obtains a face authentication result by performing face authentication by comparing the face feature information extracted from the face area of the user included in the acquired face image with the face feature information 5127 stored in the storage unit 510.

[0110] In addition, in the present embodiment, step 212 of FIG. 8 described above is replaced by face authentication processing in the history management device 500a by the authentication control unit 542a.

[0111] Thus, also in the third embodiment, the same effects as those of the second embodiment described above can be achieved.

[0112] <Other Embodiments> In addition, although the biometric authentication described above has been described as face authentication (single-modal) in principle, face authentication + iris authentication (multi-modal) may be used for the doors and payments of residences where higher security is required. In that case, the authentication terminal is assumed to be equipped with an infrared camera in addition to the camera 110.

[0113] The above-described history management devices 500 and 500a may further include a notification means for notifying the applicant's terminal that has applied for use of the area to that effect when the entry restriction to the area is released by the release control unit 543. Thereby, the applicant who has applied for use can grasp the actual visit in real time.

[0114] In addition, although described as a hardware configuration in the above embodiment, it is not limited thereto. The present disclosure can also be realized by causing a CPU to execute a computer program for any processing.

[0115] In the above example, the program can be stored using various types of non-transitory computer readable media and supplied to a computer. Non-transitory computer readable media include various types of tangible storage media. Examples of non-transitory computer readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical recording media (e.g., magneto-optical disks), CD-ROM (Read Only Memory), CD-R, CD-R / W, DVD (Digital Versatile Disc), and semiconductor memories (e.g., mask ROM, PROM (Programmable ROM), EPROM (Erasable PROM), flash ROM, RAM (Random Access Memory)). Also, the program may be supplied to the computer by various types of transitory computer readable media. Examples of transitory computer readable media include electrical signals, optical signals, and electromagnetic waves. Transitory computer readable media can supply the program to the computer via wired communication paths such as electric wires and optical fibers, or wireless communication paths.

[0116] Note that the present disclosure is not limited to the above embodiments and can be appropriately modified without departing from the spirit. Also, the present disclosure may be implemented by appropriately combining each embodiment.

[0117] Some or all of the above embodiments may be described as follows, but are not limited thereto. (Appendix A1) Storage means for storing user application information in an area where entry is restricted by biometric authentication; Release control means for releasing the entry restriction to the area when a predetermined visitor succeeds in biometric authentication at the entrance of the area and satisfies the utilization application information; A history registration means for registering the history information of the visitor who has successfully passed the biometric authentication in the storage means, When a disclosure request for the history information is received from the terminal of a predetermined disclosure requester, a generation means for generating disclosure information obtained by performing predetermined processing on the history information according to the attributes of the disclosure requester, An output means for outputting the disclosure information to the terminal, A history management device comprising: (Appendix A2) The generation means, When the attribute of the disclosure requester is other than a regular user of the facility including the area, performs processing to exclude personal information from the history information The history management device according to Appendix A1. (Appendix A3) The generation means, When the attribute of the disclosure requester is a regular user of the facility including the area, performs processing to exclude information when the visitor is the regular user from the history information The history management device according to Appendix A1 or A2. (Appendix A4) The usage application information includes applicant information for making a usage application for the area, The generation means, Identifies the applicant information corresponding to the history information from among the usage application information, Generates the disclosure information including the identified applicant information The history management device according to any one of Appendices A1 to A3. (Appendix A5) The usage application information further includes the usage purpose of the user for the area, The generation means, Identifies the usage purpose corresponding to the history information from among the usage application information, Generates the disclosure information including the identified usage purpose The history management device according to any one of Appendices A1 to A4. (Appendix A6) The generation means, Generates the disclosure information including information regarding the location where the visitor has successfully passed the biometric authentication The history management device according to any one of Supplementary Notes A1 to A5. (Supplementary Note A7) When the entry restriction to the area is released by the release control means, a notification means for notifying the applicant's terminal that has applied for use of the area to that effect is further provided. The history management device according to any one of Supplementary Notes A1 to A6. (Supplementary Note B1) An authentication terminal installed at the entrance of an area where entry is restricted by biometric authentication, A history management device that manages history information on the release of entry restrictions, The terminal of the disclosure requester for the history information, and comprising The history management device Storage means for storing the usage application information of users in the area, Release control means for releasing the entry restriction to the area when a predetermined visitor succeeds in biometric authentication via the authentication terminal and satisfies the usage application information, History registration means for registering the history information of the visitor who has succeeded in the biometric authentication in the storage means, Generation means for generating disclosure information obtained by performing predetermined processing on the history information according to the attribute of the disclosure requester when receiving a disclosure request for the history information from the terminal, Output means for outputting the disclosure information to the terminal, A history management system comprising (Supplementary Note B2) The generation means When the attribute of the disclosure requester is other than a regular user of the facility including the area, performs processing to exclude personal information from the history information. The history management system according to Supplementary Note B1. (Supplementary Note C1) A computer When a predetermined visitor succeeds in biometric authentication at the entrance of an area where entry is restricted by biometric authentication and satisfies the usage application information of users in the area, releases the entry restriction to the area, Registers the history information of the visitor who has succeeded in the biometric authentication in a storage device. When a disclosure request for the history information is received from a terminal of a specified disclosure requester, disclosure information obtained by performing specified processing on the history information according to the attributes of the disclosure requester is generated. The disclosure information is output to the terminal. History management method. (Appendix D1) When a specified visitor succeeds in biometric authentication at an entrance of a region where entry is restricted by biometric authentication and the usage application information of a user in the region is satisfied, a process of releasing the entry restriction to the region, A process of registering the history information of the visitor who has succeeded in the biometric authentication in a storage device, When a disclosure request for the history information is received from a terminal of a specified disclosure requester, a process of generating disclosure information obtained by performing specified processing on the history information according to the attributes of the disclosure requester, A process of outputting the disclosure information to the terminal, A non-transitory computer-readable medium storing a history management program that causes a computer to execute the above.

[0118] The present invention has been described above with reference to the embodiments (and examples), but the present invention is not limited to the above embodiments (and examples). Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.

Description of Signs

[0119] 1 History management device 11 Storage unit 111 Usage application information 12 Release control unit 13 History registration unit 14 Generation unit 15 Output unit 1000 History management system 100 Authentication terminal 110 Camera 120 Storage unit 130 Communication unit 140 Input / output unit 150 Control unit 151 Shooting control unit 152 Registration unit 153 Authentication control unit 154 Display control unit 155 Lock control unit 100a~100e Authentication terminals 200 Gate device 200a~200e Gate devices 300 Area 300a Entrance 300b EV hall 300c Theater room 300d Residence 300e Residence 401 Terminal 402 Terminal 500 History management device 500a History management device 510 Memory unit 511 Program 511a Program 512 Application information 5121 Applicant ID 5122 User ID 5123 User information 5124 Application period 5125 Purpose of use 5126 Actionable range 5127 Facial feature information 513 Resident information 5131 User ID 5132 Attribute 5133 Personal information of residents 514 History disclosure information 5141 User ID 5142 Attribute 515 Authentication history 5151 Authentication date and time 5152 Authentication location 5153 Authenticator ID 5154 Facial image 5155 Application information 520 Memory 530 IF unit 540 Control unit 541 Application Registration Department 542 Authentication Control Department 542a Authentication Control Department 543 Release Control Department 544 History Registration Department 545 History Disclosure Control Department 600 Authentication Device 610 Facial Information DB 611 User ID 612 Facial Feature Information 620 Face Detection Department 630 Feature Point Extraction Department 640 Registration Department 650 Authentication Department 700 Apartment Building 811 Facial Image 812 Authentication Date and Time 813 Authentication Location 814 Purpose of Use 815 Name of Authenticated Person 816 Name of Applicant 821 Facial Image 822 Authentication Date and Time 823 Authentication Location 824 Purpose of Use 825 Name of Authenticated Person 826 Name of Applicant 832 Authentication Date and Time 833 Authentication Location 834 Purpose of Use 835 Attributes of Authenticated Person 836 Attributes of Applicant N Network U11 Resident U12 Resident U21 Visitor U22 Friend U23 Housework Proxy U3 Developer

Claims

1. Storage means for storing user application information of users in an area where entry is restricted by biometric authentication; Release control means for releasing the entry restriction to the area when a predetermined visitor succeeds in biometric authentication at the entrance of the area and satisfies the user application information; History registration means for registering the history information of the visitor who has succeeded in the biometric authentication in the storage means; Generation means for generating disclosure information based on the history information from among the user application information when a disclosure request for the history information is received from a first person; Output means for outputting the disclosure information to the terminal of the first person, comprising: The disclosure request includes the user ID of the first person, the ID of the disclosure target location, and the disclosure target period; When the first person has a first attribute, the generation means includes the face image information of the visitor in the disclosure information, and when the attribute of the first person is a second attribute different from the first attribute, the generation means does not include the face image information in the disclosure information; History management device.

2. A computer: Stores user application information of users in an area where entry is restricted by biometric authentication; When a predetermined visitor succeeds in biometric authentication at the entrance of the area and satisfies the user application information, releases the entry restriction to the area; Registers the history information of the visitor who has succeeded in the biometric authentication in the storage means; When receiving a disclosure request for the history information from a first person, the disclosure request including the user ID of the first person, the ID of the disclosure target location, and the disclosure target period, generates disclosure information based on the history information from among the user application information, and when the first person has a first attribute, includes the face image information of the visitor in the disclosure information, and when the attribute of the first person is a second attribute different from the first attribute, does not include the face image information in the disclosure information; Outputs the disclosure information to the terminal of the first person; History management method.

3. A process of storing user application information of users in an area where entry is restricted by biometric authentication; A process of releasing the entry restriction to the area when a predetermined visitor succeeds in biometric authentication at the entrance of the area and satisfies the user application information; A process of registering the history information of the visitor who has succeeded in the biometric authentication in the storage means; When receiving, from a first person, a disclosure request for the history information, the disclosure request including the user ID of the first person, the ID of the disclosure target location, and the disclosure target period, generate disclosure information based on the history information from the utilization application information; when the first person has a first attribute, include the face image information of the visitor in the disclosure information, and when the attribute of the first person is a second attribute different from the first attribute, perform a process of not including the face image information in the disclosure information, a process of outputting the disclosure information to the terminal of the first person, A history management program that causes a computer to execute.

Citation Information

Patent Citations

  • Device and method for managing admission

    JP2002352291A

  • Visitor management device

    JP2003044892A

  • Entering and leaving management system

    JP2009116600A

  • Passage history retrieval system and retrieval method of entering / leaving management device

    JP2012155577A

  • Access control device, access control system and access control method

    WO2008066130A1