Authentication device, authentication method, and program

The authentication device addresses the inconvenience of frequent biometric data transmission by using stored biometric information for authentication, minimizing data transmission and improving user convenience and security.

JP7708204B2Active Publication Date: 2025-07-15NEC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023559360
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-11-12
Publication Date
2025-07-15
Estimated Expiration
2041-11-12

AI Technical Summary

Technical Problem

Existing biometric authentication systems require frequent transmission of master biometric information from mobile terminals, reducing user convenience.

Method used

An authentication device that acquires authentication biometric information from a biometric information generation device at the entrance and stores master biometric information from a mobile terminal for a predetermined time, reducing the need for repeated transmission by validating against stored information.

Benefits of technology

Reduces the number of times master biometric information is transmitted from mobile terminals, enhancing user convenience and security by leveraging stored biometric data for authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007708204000001
    Figure 0007708204000001
  • Figure 0007708204000002
    Figure 0007708204000002
  • Figure 0007708204000003
    Figure 0007708204000003
Patent Text Reader

Abstract

An acquisition unit (110) acquires master biometric information relating to a subject person from a mobile terminal (20), and acquires authentication biometric information generated by a biometric information generation device (50) installed at the entrance of a subject area. An authentication unit (120) uses the authentication biometric information and the master biometric information to perform processing of authenticating the subject person. A storage unit (150) stores the master biometric information. Then, the acquisition unit (110) acquires the authentication biometric information before acquisition of the master biometric information. The authentication unit (120) performs processing of authenticating the authentication biometric information in relation to the master biometric information stored in the storage unit (150). Then, when the master biometric information matching the authentication biometric information is not stored in the storage unit (150), the acquisition unit (110) acquires the master biometric information from the mobile terminal (20).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication device, an authentication method, and a program.

Background Art

[0002] In recent years, biometric authentication has been used in various scenarios. For example, Patent Document 1 describes the following technology. First, a portable user device stores pass permission data required for the user to pass through a gate and feature data indicating the features of the user. An example of the feature data is face data related to facial features. The passability determination unit acquires the pass permission data and the feature data from the user device via the wireless communication unit. The passability determination unit also acquires an image of the user attempting to pass through the gate. Then, the passability determination unit opens the gate when the pass permission data is valid and the image of the user matches the feature data acquired from the user device.

[0003] Note that Patent Document 2 describes measuring the position of a wireless communication terminal and determining whether the wireless communication terminal can pass through a gate based on this position.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0005] In the technology described in Patent Document 1, the mobile terminal needs to transmit master biometric information to the authentication device every time the user attempts to pass through a gate or the like. In this case, there is a risk of reducing the convenience of the user.

[0006] An example of the object of the present invention is to reduce the number of times of transmitting master biometric information from a mobile terminal when authenticating a user using the master biometric information stored in the mobile terminal.

Means for Solving the Problem

[0007] According to one aspect of the present invention, an acquisition unit that acquires master biometric information of a target person from a mobile terminal and acquires authentication biometric information that is the biometric information of the target person generated by a biometric information generation device installed at an entrance of a target area; an authentication unit that performs an authentication process of the target person using the authentication biometric information and the master biometric information; an admission process unit that performs at least a part of a process for enabling the target person to enter the target area when the authentication process is successful; a storage process unit that stores the master biometric information in a storage unit when the authentication process is successful, and invalidates or deletes the master biometric information whose storage time in the storage unit has reached a predetermined time or more; is provided with before the acquisition unit acquires the master biometric information from the mobile terminal, the acquisition unit acquires the authentication biometric information, the authentication unit performs an authentication process of the authentication biometric information with respect to the valid master biometric information stored in the storage unit, the acquisition unit acquires the master biometric information from the mobile terminal when the master biometric information that matches the authentication biometric information and is valid is not stored in the storage unit, and an authentication device is provided.

[0008] According to one aspect of the present invention, a computer an acquisition process of acquiring master biometric information of a target person from a mobile terminal and acquiring authentication biometric information that is the biometric information of the target person generated by a biometric information generation device installed at an entrance of a target area; an authentication process of authenticating the target person using the authentication biometric information and the master biometric information; When the authentication process is successful, an admission process that performs at least part of the process for enabling the subject to enter the target area, When the authentication process is successful, the master biometric information is stored in the storage means, and the master biometric information whose storage time in the storage means has reached a predetermined time or more is invalidated or deleted from the storage means. A storage process, are performed, In the acquisition process, before acquiring the master biometric information from the mobile terminal, the biometric information for authentication is acquired, In the authentication process, the biometric information for authentication is authenticated against the valid master biometric information stored in the storage means, In the acquisition process, when the master biometric information that matches the biometric information for authentication and is valid is not stored in the storage means, the master biometric information is acquired from the mobile terminal. An authentication method is provided.

[0009] According to one aspect of the present invention, In a computer An acquisition function for acquiring master biometric information of a subject from a mobile terminal and acquiring biometric information for authentication, which is the biometric information of the subject generated by a biometric information generation device installed at the entrance of the target area, An authentication function for performing an authentication process of the subject using the biometric information for authentication and the master biometric information, An admission process function for performing at least part of the process for enabling the subject to enter the target area when the authentication process is successful, A storage process function for storing the master biometric information in the storage means when the authentication process is successful, and invalidating or deleting the master biometric information whose storage time in the storage means has reached a predetermined time or more from the storage means, are provided, The acquisition function acquires the biometric information for authentication before acquiring the master biometric information from the mobile terminal, The authentication function performs authentication processing of the biometric information for authentication with respect to the valid master biometric information stored in the storage means. The acquisition function is provided with a program that acquires the master biometric information from the mobile terminal when the master biometric information that matches the biometric information for authentication and is valid is not stored in the storage means.

Effect of the Invention

[0010] According to one aspect of the present invention, when authenticating a user using the master biometric information stored in a mobile terminal, the number of times of transmitting the master biometric information from the mobile terminal is reduced.

Brief Description of the Drawings

[0011] The above-described object, as well as other objects, features, and advantages, will become more apparent from the preferred embodiments described below and the accompanying drawings.

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Mode for Carrying Out the Invention

[0013] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In all the drawings, the same components are denoted by the same reference numerals, and the description will be omitted as appropriate.

[0014] (First Embodiment) FIG. 1 is a diagram for explaining the usage environment of the authentication device 10 according to the present embodiment. The authentication device 10 authenticates a subject using biometric information. An example of the biometric information is face information, but it may be other biometric information, such as fingerprint information, vein information, or iris information. Further, the biometric information may be a combination of a plurality of the above-mentioned pieces of information.

[0015] The authentication device 10 is used together with a mobile terminal 20, a biometric information acquisition device 50, and a communication device 60. The mobile terminal 20 is held by a user. The authentication device 10 has a function as an electronic identity certificate, for example, an electronic employee ID, and stores master biometric information of the subject in advance. The biometric information acquisition device 50 and the communication device 60 are installed at a place where the user is to be authenticated, for example, in front of a gate or a door.

[0016] The biometric information acquisition device 50 is installed at a place where the subject is to be authenticated, generates biometric information of the subject, and transmits it to the authentication device 10. Hereinafter, this biometric information will be referred to as authentication biometric information. Further, the mobile terminal 20 transmits the master biometric information to the authentication device 10 via the communication device 60. For example, the communication device 60 attempts to communicate with the mobile terminal 20 at regular intervals, for example, every 1 second. The communication possible distance between the mobile terminal 20 and the communication device 60 is, for example, 5 m or less, preferably 3 m or less, more preferably 1.5 m or less, but is not limited thereto. Then, the authentication device 10 performs authentication processing of the subject using the authentication biometric information generated by the biometric information acquisition device 50 and the master biometric information acquired from the mobile terminal 20.

[0017] Also, when the authentication device 10 successfully authenticates the biometric information for authentication, it stores the master biometric information used at that time for a certain period and re-uses it.

[0018] The mobile terminal 20 may store at least one of the subject identification information assigned to the subject who possesses the mobile terminal 20 and the terminal identification information assigned to the mobile terminal 20. In this case, the mobile terminal 20 transmits at least one of the subject identification information and the terminal identification information together with the subject identification information and the master biometric information as necessary. An example of the subject identification information is a subject ID such as an employee ID.

[0019] In the example shown in this figure, the authentication device 10 is further used together with the control device 30. The control device 30 performs at least part of the process for enabling the subject to enter the target area. For example, the control device 30 opens the gate 40 installed at the entrance of the target area. As another example, the control device 30 unlocks the lock of the door installed at the entrance of the target area. The target area may be a place where a plurality of facilities are gathered, such as a theme park, the building itself, a predetermined floor in the building, or a part of a predetermined floor in the building, such as a predetermined room. Further, when the control device 30 opens the gate 40 or unlocks the door, the control device 30 may perform a process of notifying the subject of this by lighting a light-emitting device installed on the gate 40 or the door.

[0020] The successful authentication process by the authentication device 10 may be a part of the conditions for opening the gate or unlocking the door lock. As an example, there may be a case where the people who can enter the target area in advance are predetermined. After the authentication process by the authentication device 10 is successful, the control device 30 may further open the gate or unlock the door lock when it can be confirmed that the subject is a person who can enter the target area. This confirmation is performed using at least one of the subject identification information and the terminal identification information, for example.

[0021] Note that a plurality of gates 40 may be arranged in parallel at the entrance of the target area. In this case, the authentication device 10 and the communication device 60 may be provided for each of the plurality of gates 40. Here, it is preferable to provide a shielding member, for example, a shielding plate, between adjacent gates 40 to suppress the passage of radio waves. By doing so, the possibility that the mobile terminal 20 possessed by a person trying to pass through a certain gate 40 accidentally communicates with the communication device 60 provided at the adjacent gate 40 is reduced.

[0022] FIG. 2 is a diagram showing an example of the functional configuration of the authentication device 10. The authentication device 10 includes an acquisition unit 110, an authentication unit 120, a storage processing unit 130, and an admission processing unit 140.

[0023] The acquisition unit 110 acquires master biometric information from the mobile terminal 20 via the communication device 60 and acquires authentication biometric information from the biometric information acquisition device 50. The acquisition unit 110 also acquires other information from the mobile terminal 20 as necessary. An example of the other information is at least one of the subject identification information and the terminal identification information. Hereinafter, this information is referred to as authentication identification information.

[0024] A plurality of mobile terminals 20 may exist simultaneously within the communication range of the communication device 60, and these plurality of mobile terminals 20 may become communicable with the communication device 60. In this case, the acquisition unit 110 acquires the reception intensity when the communication device 60 receives the radio wave output by the mobile terminal 20, and uses this reception intensity to determine the mobile terminal 20 to be processed. For example, the acquisition unit 110 determines the mobile terminal 20 to be processed in descending order of reception intensity.

[0025] The authentication unit 120 performs authentication processing of the subject using the authentication biometric information and the master biometric information acquired by the acquisition unit 110. For example, the authentication unit 120 calculates the degree of coincidence of the authentication biometric information with respect to the master biometric information, and determines that the authentication of the subject has succeeded when this degree of coincidence is equal to or higher than a reference value. When the authentication is successful, the authentication unit 120 generates authenticated information indicating that fact.

[0026] When the authentication by the authentication unit 120 is successful, the memory processing unit 130 stores the master biometric information used at that time in the storage unit 150. Further, the memory processing unit 130 invalidates or deletes from the storage unit 150 the master biometric information whose storage time in the storage unit 150 has reached or exceeded a predetermined time. The storage unit 150 may be part of the authentication device 10 or may be located outside the authentication device 10. Note that the memory processing unit 130 may store the master biometric information in the storage unit 150 in association with the authentication identification information acquired together with the master biometric information.

[0027] The valid time of the master biometric information stored in the storage unit 150, that is, the above-mentioned predetermined time, is, for example, 24 hours, but may be other lengths, for example, 12 hours or 8 hours. Also, this predetermined time may be determined for each subject, or may be determined for each subject and for each target area. As an example, the memory processing unit 130 determines this predetermined time using the schedule information of the subject. For example, the schedule information has information indicating the target area the subject should go to and the date and time of staying in the target area. As an example, the schedule information stores the location where the meeting is held and the date and time when the meeting is held. Then, the admission processing unit 140 sets a predetermined time for each target area so as to include the date and time of the planned stay, and stores this predetermined time in the storage unit 150 in association with each subject and the area identification information.

[0028] The master biometric information stored in the storage unit 150 and being valid is used for the authentication process of the biometric information for authentication. Specifically, the acquisition unit 110 acquires the biometric information for authentication before acquiring the master biometric information from the mobile terminal 20. Then, the authentication unit 120 performs the authentication process of the biometric information for authentication on the master biometric information stored in the storage unit 150 and being valid. And when there is no master biometric information that matches the biometric information for authentication and is valid stored in the storage unit 150, the acquisition unit 110 acquires the master biometric information from the mobile terminal 20.

[0029] When the authentication unit 120 generates authenticated information, the entry processing unit 140 performs at least a part of the processing for enabling the target person to enter the target area. This part of the processing is appropriately set according to the functional sharing between the entry processing unit 140 and the control device 30. An example of this part of the processing is to transmit the authenticated information to the control device 30.

[0030] In addition, the storage unit 150 further stores, for each target area, at least one of the target person identification information and the terminal identification information of the person who can enter the target area. The storage unit 150 also stores other information as necessary.

[0031] FIG. 3 is a diagram showing a first example of the information stored in the storage unit 150. As described above, the storage unit 150 stores the master biometric information that has been successfully authenticated by the authentication unit 120 among the master biometric information acquired by the acquisition unit 110. In the example shown in this figure, the storage unit 150 stores this master biometric information in association with the authentication identification information acquired together with the master biometric information.

[0032] The master biometric information stored in the storage unit 150 has not elapsed a predetermined time since it was acquired by the acquisition unit 110. That is, the master biometric information for which the predetermined time has elapsed has been deleted from the storage unit 150. However, instead of deleting the master biometric information for which the predetermined time has elapsed from the storage unit 150, the storage processing unit 130 may store information indicating that the predetermined time has elapsed, for example, a flag, in the storage unit 150 in association with the master biometric information.

[0033] FIG. 4 is a diagram showing a second example of the information stored in the storage unit 150. In addition to the information shown in FIG. 3, the storage unit 150 stores, as shown in this figure, the area identification information for identifying the target area and the authority identification information in association with each other. The authority identification information is at least one of the target person identification information of the target person who can enter the target area and the terminal identification information of the mobile terminal 20 used by the target person. In FIG. 4, the area identification information is in units of buildings, but the storage unit 150 may further store the authority identification information in units of rooms or floors.

[0034] FIG. 5 is a diagram showing an example of the functional configuration of the mobile terminal 20. The mobile terminal 20 includes a storage unit 210 and a transmission unit 220.

[0035] The storage unit 210 stores master biometric information of the person who uses the mobile terminal 20. The storage unit 210 further stores at least one of the person identification information of the person who uses the mobile terminal 20 and the terminal identification information of the mobile terminal 20 used by the person, that is, authentication identification information.

[0036] The transmission unit 220 transmits the master biometric information stored in the storage unit 210 to the authentication device 10. At this time, the transmission unit 220 also transmits authentication identification information as necessary.

[0037] FIG. 6 is a diagram showing an example of the hardware configuration of the authentication device 10. The authentication device 10 includes a bus 1010, a processor 1020, a memory 1030, a storage device 1040, an input / output interface 1050, and a network interface 1060.

[0038] The bus 1010 is a data transmission path for the processor 1020, the memory 1030, the storage device 1040, the input / output interface 1050, and the network interface 1060 to transmit and receive data to and from each other. However, the method of connecting the processor 1020 and the like to each other is not limited to bus connection.

[0039] The processor 1020 is a processor realized by a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), or the like.

[0040] The memory 1030 is a main storage device realized by a RAM (Random Access Memory) or the like.

[0041] The storage device 1040 is an auxiliary storage device realized by a hard disk drive (HDD), a solid state drive (SSD), a removable medium such as a memory card, or a read only memory (ROM). The storage device 1040 stores program modules that implement each function of the authentication device 10 (for example, the acquisition unit 110, the authentication unit 120, the storage processing unit 130, and the admission processing unit 140). When the processor 1020 reads and executes these program modules onto the memory 1030, each function corresponding to the program module is realized. Further, the storage device 1040 also functions as a storage unit 150.

[0042] The input / output interface 1050 is an interface for connecting the authentication device 10 and various input / output devices. For example, the input / output interface 1050 has a short-range wireless communication module. In this case, the authentication device 10 communicates with the communication device 60 via the input / output interface 1050.

[0043] The network interface 1060 is an interface for connecting the authentication device 10 to a network. This network is, for example, a local area network (LAN) or a wide area network (WAN). The method by which the network interface 1060 connects to the network may be a wireless connection or a wired connection. The authentication device 10 may communicate with the mobile terminal 20 via the network interface 1060.

[0044] Note that the hardware configuration of the mobile terminal 20 is also the same as the hardware configuration of the authentication device 10 shown in FIG. 5. Here, at least the device that stores the master biometric information in the storage device 1040 that serves as the storage unit 210 is preferably made impossible to falsify the stored information.

[0045] FIG. 7 is a flowchart showing an example of the process performed by the authentication device 10 together with the process performed by the mobile terminal 20. The process shown in this figure is performed when the subject passes through the gate 40 installed at the entrance of the building.

[0046] In the example shown in this figure, the control device 30 controls each of the gate 40 installed at the entrance of the building and the lock of the door provided in the room in the building. And when the subject passes through the gate 40, at least authentication by biometric information is required. Here, authentication by authentication identification information, that is, at least one of the subject identification information and the terminal identification information may be further required.

[0047] First, when the subject approaches the gate 40, the authentication device 10 transmits a request for communication start to the mobile terminal 20 via the communication device 60 (step S10). Then the communication device 60 acquires at least one of the authentication identification information, that is, the subject identification information and the terminal identification information, from the mobile terminal 20 and transmits it to the authentication device 10. The acquisition unit 110 of the authentication device 10 acquires this authentication identification information (step S20).

[0048] Then, the acquisition unit 110 of the authentication device 10 checks whether the master biometric information corresponding to the authentication identification information acquired in step S20 is stored in the storage unit 150 (step S30). When the storage unit 150 stores this master biometric information (step S30: Yes), the authentication unit 120 reads this master biometric information from the storage unit 150. On the other hand, when the storage unit 150 does not store this master biometric information (step S30: No), the authentication unit 120 requests the mobile terminal 20 for the master biometric information (step S40). Then the mobile terminal 20 transmits the master biometric information and the authentication identification information to the authentication device 10. The acquisition unit 110 acquires this master biometric information (step S50).

[0049] Then, the biological information acquisition device 50 acquires the biological information for authentication of the target person and transmits it to the authentication device 10. For example, the biological information acquisition device 50 generates at least one of the facial information, fingerprint information, vein information, and iris information of the target person as the biological information for authentication, and transmits the generated biological information for authentication to the authentication device 10. The acquisition unit 110 of the authentication device 10 acquires this biological information for authentication (step S60).

[0050] In addition, a human presence sensor, for example, an infrared sensor, may be provided at or near the gate 40. In this case, when the human presence sensor detects a person, the authentication device 10 may perform the process shown in step S60.

[0051] Then, the authentication unit 120 of the authentication device 10 performs an authentication process on the biological information for authentication acquired in step S60 by using the master biological information read from the storage unit 150 or the master biological information acquired in step S50 (step S70). When the authentication unit 120 succeeds in this authentication (step S70: Yes), it generates the above-mentioned authenticated information. In addition, when the acquisition unit 110 has acquired the master biological information from the mobile terminal 20, the authentication unit 120 stores this master biological information in the storage unit 150 in association with the authentication identification information acquired in step S20 (step S80).

[0052] When the authenticated information is generated (step S70: Yes), the entry processing unit 140 sets the expiration date of this authenticated information, associates this expiration date with the authentication identification information, and stores it in the storage unit 150 (step S90). The expiration date of the authenticated information is, for example, a predetermined time after the authenticated information is generated. This predetermined time can be set by, for example, the administrator of the building. As an example, the predetermined time is 24 hours, but other values, such as 12 hours or 8 hours, may also be used.

[0053] Next, the entry processing unit 140 outputs the authenticated information to the control device 30. Then, the control device 30 opens the gate 40 (step S100). Thereby, the target person can pass through the gate 40 and enter the building.

[0054] Here, the acquisition unit 110 may acquire area identification information assigned to the building that the subject is about to enter this time. In this case, the entrance processing unit 140 reads out the authorized identification information corresponding to the area identification information acquired by the acquisition unit 110 from the storage unit 150, and includes that this authorized identification information contains the authentication identification information acquired by the acquisition unit 110 as a condition for performing step S100.

[0055] Note that there are various methods for the acquisition unit 110 to acquire area identification information. As a first example, the communication device 60 stores area identification information, and transmits this area identification information together with the information acquired from the mobile terminal 20 to the authentication device 10. As a second example, the subject operates the mobile terminal 20 to transmit the area identification information to the authentication device 10.

[0056] FIG. 8 shows the processing performed when the subject enters a predetermined floor or room of the building after the processing shown in FIG. 7. In this processing, the authentication device 10 does not perform authentication based on biometric information. Instead, it performs authentication based on authentication identification information.

[0057] A door or a gate is installed at the entrance of a predetermined floor of the building. Also, a door is installed at the entrance of the room in the building. And the control device 30 controls the opening and closing of these gates or the locking of the doors. Also, a communication device 60 is provided near these gates or doors.

[0058] When the subject approaches the gate or the door, the mobile terminal 20 transmits the authentication identification information to the authentication device 10 via the communication device 60. The acquisition unit 110 of the authentication device 10 acquires this authentication identification information. At this time, the acquisition unit 110 also acquires area identification information. The method for acquiring this area identification information is as described with reference to FIG. 7 (step S110).

[0059] The authentication unit 120 of the authentication device 10 checks whether the expiration date corresponding to the authentication identification information acquired in step S110 is stored in the storage unit 150. If the expiration date is stored and has not expired (step S120: Yes), the authentication unit 120 reads out the authorized identification information associated with the area identification information acquired in step S110 from the storage unit 150. Then, the authentication unit 120 checks whether the read authorized identification information includes the authentication identification information acquired in step S110 (step S130). If the authorized identification information includes the authentication identification information (step S130: Yes), the entry processing unit 140 causes the control device 30 to open the gate or unlock the door (step S140).

[0060] In step S80 of FIG. 7, the entry processing unit 140 may set the expiration date of the authenticated information using the schedule information of the subject. For example, the schedule information includes information indicating the target area that the subject should go to and the date and time of the planned stay in the target area. As an example, the schedule information stores the location where the meeting is held and the date and time when the meeting is held. Then, the entry processing unit 140 sets the expiration date to include the date and time of the planned stay for each target area, and associates this expiration date with the area identification information and stores it in the storage unit 150. In this case, in step S120 of FIG. 8, the authentication unit 120 acquires and uses the expiration date corresponding to the area identification information acquired in step S110.

[0061] Also, when the subject enters a predetermined floor or room of the building, the process shown in FIG. 7 may be performed instead of the process shown in FIG. 8. However, in this case, a biometric information acquisition device 50 is also provided near these gates or doors. Also, when entering the building and when entering a predetermined floor or room of the building, the process shown in step S80 may not be performed.

[0062] As described above, according to this embodiment, the mobile terminal 20 stores the master biometric information of the target person. Then, the authentication device 10 acquires this master biometric information from the mobile terminal 20 and uses it for the authentication process of the target person. Also, the authentication device 10 stores the master biometric information acquired from the mobile terminal 20 for a predetermined time and uses it for the authentication process of the target person. Therefore, the number of times of transmitting the master biometric information from the mobile terminal 20 can be reduced. As a result, when the target person is to be authenticated by the authentication device 10, it is not necessary to always carry the mobile terminal 20.

[0063] (Second Embodiment) This embodiment is the same as the above-described first embodiment except for the following points. First, the storage unit 210 of the mobile terminal 20 stores certificate information. This certificate information proves that the mobile terminal 20 is a terminal used together with the authentication device 10. Then, the authentication device 10 makes it a condition for performing the authentication process or a condition for succeeding in the authentication process that this certificate information is acquired from the authentication device 10.

[0064] FIG. 9 is a diagram showing an example of the process performed by the authentication device 10 according to this embodiment, and corresponds to FIG. 7 of the first embodiment. The process shown in this figure is also performed when the target person passes through the gate 40 installed at the entrance of the building.

[0065] When the target person approaches the gate 40, the authentication device 10 transmits a request for starting communication to the mobile terminal 20 via the communication device 60 (step S10). Then, the communication device 60 acquires the authentication identification information and the certificate information from the mobile terminal 20 and transmits them to the authentication device 10 (step S22).

[0066] Also, when the mobile terminal 20 is requested for the master biometric information from the authentication device 10 (step S40), it transmits the master biometric information, the authentication identification information, and the certificate information to the authentication device 10 (step S52).

[0067] The other processes (steps S30, steps S60 to S100) are as described with reference to FIG. 7. However, the authentication unit 120 performs an authentication process in step S70 when the acquisition unit 110 is acquiring the certificate information from the mobile terminal 20. In other words, when the certificate information has not been acquired, the authentication unit 120 determines that the authentication of the subject has failed.

[0068] Also according to this embodiment, the authentication device 10 can reduce the number of times of transmitting the master biometric information from the mobile terminal. In addition, the authentication unit 120 does not perform the authentication process when the certificate information has not been acquired from the mobile terminal 20. Therefore, the possibility that a person without a legitimate mobile terminal 20 accidentally enters the target area is reduced.

[0069] As described above, the embodiments of the present invention have been described with reference to the drawings, but these are examples of the present invention, and various configurations other than the above can also be adopted.

[0070] Also, in the plurality of flowcharts used in the above description, a plurality of steps (processes) are described in order, but the execution order of the steps executed in each embodiment is not limited to the described order. In each embodiment, the order of the illustrated steps can be changed within a range that does not substantially affect the content. Also, the above-described embodiments can be combined within a range where the contents do not conflict.

[0071] Some or all of the above embodiments can be described as follows in the appended claims, but are not limited thereto. 1. Acquisition means for acquiring the master biometric information of a subject from a mobile terminal and acquiring authentication biometric information that is the biometric information of the subject generated by a biometric information generation device installed at the entrance of the target area; Authentication means for performing an authentication process of the subject using the authentication biometric information and the master biometric information; Admission processing means for performing at least a part of the processing for enabling the subject to enter the target area when the authentication process is successful; When the authentication process is successful, a storage processing means for storing the master biometric information in a storage means and invalidating or deleting from the storage means the master biometric information whose storage time in the storage means has reached a predetermined time or more; comprising; Before the acquisition means acquires the master biometric information from the mobile terminal, the acquisition means acquires the biometric information for authentication. The authentication means performs an authentication process on the biometric information for authentication with respect to the valid master biometric information stored in the storage means. The acquisition means acquires the master biometric information from the mobile terminal when the master biometric information that matches the biometric information for authentication and is valid is not stored in the storage means, an authentication device. 2. In the authentication device according to 1 above, The acquisition means acquires schedule information indicating the schedule of the subject. The storage processing means sets the predetermined time for each target area using the schedule information, an authentication device. 3. In the authentication device according to 1 or 2 above, In the target area, there is pre-associated at least one of an authorized person who is the subject having the right to enter the target area and an authorized terminal which is the mobile terminal held by the authorized person, authorization identification information for identifying at least one of them. The acquisition means acquires, from the mobile terminal, authentication identification information for identifying at least one of the subject and the mobile terminal. The entry processing means performs at least a part of the processing when the authentication identification information is included in the authorization identification information, an authentication device. 4. In the authentication device according to any one of 1 to 3 above, The acquisition means acquires, from the mobile terminal, authentication identification information for identifying at least one of the subject and the mobile terminal. The storage processing means associates the master biometric information and the authentication identification information acquired by the acquisition means with each other and stores them in the storage means. Before the acquisition means acquires the master biometric information from the mobile terminal, the authentication biometric information and the authentication identification information are acquired. The authentication means identifies the master biometric information associated with the authentication identification information acquired by the acquisition means in the storage means, and performs the authentication process using the master biometric information. The acquisition means is an authentication device that, when there is no master biometric information associated with the authentication identification information in the storage means, acquires the master biometric information from the mobile terminal and performs the authentication process. 5. In the authentication device according to any one of the above items 1 to 4, The entry processing means outputs authentication-completed information indicating that the authentication process has succeeded to a control means that controls the opening and closing of a gate installed at the entrance of the target area or the locking of a door installed at the entrance. 6. In the authentication device according to any one of the above items 1 to 5, The acquisition means acquires the master biometric information from the mobile terminal via a wireless communication device installed at the entrance. The communication range of the wireless communication device is 5 m or less. 7. In the authentication device according to item 6 above, The acquisition means acquires the reception intensity when the wireless output by the mobile terminal is received by the wireless communication device, and when the wireless communication device can communicate with a plurality of the mobile terminals, determines the mobile terminal to be processed using the reception intensity. 8. A computer performs an acquisition process of acquiring the master biometric information of a target person from a mobile terminal and acquiring authentication biometric information that is the biometric information of the target person generated by a biometric information generation device installed at the entrance of a target area, performs an authentication process of authenticating the target person using the authentication biometric information and the master biometric information, and when the authentication process is successful, performs at least a part of a process for enabling the target person to enter the target area. When the authentication process is successful, the master biometric information is stored in the storage means, and a storage process is performed to invalidate or delete from the storage means the master biometric information for which the time stored in the storage means has reached a predetermined time or more. Perform In the acquisition process, before acquiring the master biometric information from the mobile terminal, acquire the authentication biometric information. In the authentication process, authenticate the authentication biometric information against the valid master biometric information stored in the storage means. In the acquisition process, when there is no valid master biometric information that matches the authentication biometric information stored in the storage means, acquire the master biometric information from the mobile terminal. An authentication method. 9. In the authentication method according to item 8 above, The computer In the acquisition process, acquire schedule information indicating the schedule of the subject. In the storage process, set the predetermined time for each target area using the schedule information. An authentication method. 10. In the authentication method according to item 8 or 9 above, At least one of the target areas is pre-associated with authority identification information for identifying at least one of the authorized person who is the subject having the right to enter the target area and the authorized terminal which is the mobile terminal held by the authorized person. The computer In the acquisition process, acquire authentication identification information for identifying at least one of the subject and the mobile terminal from the mobile terminal. In the entry process, when the authentication identification information is included in the authority identification information, perform at least a part of the process for enabling entry. An authentication method. 11. In the authentication method according to any one of items 8 to 10 above, The computer In the acquisition process, acquire authentication identification information for identifying at least one of the subject and the mobile terminal from the mobile terminal. In the memory process, the master biometric information and the authentication identification information acquired in the acquisition process are associated with each other and stored in the storage means. In the acquisition process, before acquiring the master biometric information from the mobile terminal, the authentication biometric information and the authentication identification information are acquired. In the authentication process, the master biometric information associated with the authentication identification information acquired in the acquisition process in the storage means is specified, and the authentication process is performed using the master biometric information. In the acquisition process, when there is no master biometric information associated with the authentication identification information in the storage means, the master biometric information is acquired from the mobile terminal and the authentication process is performed. An authentication method. 12. In the authentication method according to any one of the above items 8 to 11, In the entry process, the computer outputs authentication completed information indicating that the authentication process has been successful to a control means that controls the opening and closing of a gate installed at the entrance of the target area or the locking of a door installed at the entrance. An authentication method. 13. In the authentication method according to any one of the above items 8 to 12, In the acquisition process, the computer acquires the master biometric information from the mobile terminal via a wireless communication device installed at the entrance. The communication range of the wireless communication device is 5 m or less. An authentication method. 14. In the authentication method according to item 13 above, In the acquisition process, the computer acquires the reception strength when the wireless output by the mobile terminal is received by the wireless communication device, When the wireless communication device can communicate with a plurality of the mobile terminals, the mobile terminal to be processed is determined using the reception strength. An authentication method. 15. In a computer an acquisition function of acquiring master biometric information of a target person from a mobile terminal and acquiring authentication biometric information that is the biometric information of the target person generated by a biometric information generation device installed at the entrance of a target area, An authentication function that performs authentication processing of the subject using the authentication biometric information and the master biometric information, An admission processing function that performs at least part of the processing for enabling the subject to enter the target area when the authentication processing is successful, A storage processing function that stores the master biometric information in the storage means when the authentication processing is successful, and invalidates or deletes the master biometric information whose storage time in the storage means has reached a predetermined time or more, and has Before the acquisition function acquires the master biometric information from the mobile terminal, it acquires the authentication biometric information, The authentication function performs authentication processing of the authentication biometric information with respect to the valid master biometric information stored in the storage means, The acquisition function acquires the master biometric information from the mobile terminal when there is no valid master biometric information that matches the authentication biometric information and is stored in the storage means. Program. 16. In the program according to 15 above, The acquisition function acquires schedule information indicating the schedule of the subject, The storage processing function sets the predetermined time for each target area using the schedule information. Program. 17. In the program according to 15 or 16 above, The target area is associated in advance with at least one of the authorized person who is the subject having the right to enter the target area and the authorized terminal which is the mobile terminal possessed by the authorized person. Authorization identification information, The acquisition function acquires authentication identification information for identifying at least one of the subject and the mobile terminal from the mobile terminal, The admission processing function performs at least part of the processing when the authentication identification information is included in the authorization identification information. Program. 18. In the program according to any one of 15 to 17 above, The acquisition function acquires authentication identification information for identifying at least one of the subject person and the mobile terminal from the mobile terminal, The storage processing function associates the master biometric information and the authentication identification information acquired by the acquisition function with each other and stores them in the storage means, Before acquiring the master biometric information from the mobile terminal, the acquisition function acquires the authentication biometric information and the authentication identification information, The authentication function identifies the master biometric information associated with the authentication identification information acquired by the acquisition function in the storage means, and performs the authentication process using the master biometric information, When there is no master biometric information associated with the authentication identification information in the storage means, the acquisition function acquires the master biometric information from the mobile terminal and performs the authentication process, a program. 19. In the program according to any one of the above items 15 to 18, The entry processing function outputs authenticated information indicating that the authentication process has been successful to control means for controlling the opening and closing of a gate installed at the entrance of the target area or the locking of a door installed at the entrance, a program. 20. In the program according to any one of the above items 15 to 19, The acquisition function acquires the master biometric information from the mobile terminal via a wireless communication device installed at the entrance, The communication range of the wireless communication device is 5 m or less, a program. 21. In the program according to item 20 above, The acquisition function acquires the reception intensity when the wireless communication device receives the wireless output by the mobile terminal, When the wireless communication device can communicate with a plurality of the mobile terminals, the mobile terminal to be processed is determined using the reception intensity, a program.

Explanation of Signs

[0072] 10 Authentication device 20 Mobile terminal 30 Control device 40 Gate 50 Biological information acquisition device 60 Communication device 110 Acquisition unit 120 Authentication unit 130 Memory processing unit 140 Entrance processing unit 150 Memory unit 210 Memory unit 220 Transmission unit

Claims

1. An acquisition means for acquiring master biometric information of a target person from a mobile terminal and acquiring authentication biometric information, which is the biometric information of the target person generated by a biometric information generation device installed at an entrance of a target area; An authentication means for performing an authentication process of the target person using the authentication biometric information and the master biometric information; An admission process means for performing at least a part of a process for enabling the target person to enter the target area when the authentication process is successful; A storage process means for storing the master biometric information in a storage means when the authentication process is successful, and invalidating or deleting the master biometric information whose storage time in the storage means has reached a predetermined time or more; Comprising: Before acquiring the master biometric information from the mobile terminal, the acquisition means acquires the authentication biometric information; The authentication means performs an authentication process of the authentication biometric information with respect to the valid master biometric information stored in the storage means; The acquisition means acquires the master biometric information from the mobile terminal when there is no valid master biometric information that matches the authentication biometric information and is stored in the storage means. An authentication device.

2. In the authentication device according to Claim 1, The acquisition means acquires schedule information indicating the schedule of the target person; The storage process means sets the predetermined time for each target area using the schedule information. An authentication device.

3. In the authentication device according to Claim 1 or 2, At least one of an authorized person who is the target person having the right to enter the target area and an authorized terminal which is the mobile terminal possessed by the authorized person is associated in advance with the target area with authorized identification information for identifying them; The acquisition means acquires authentication identification information for identifying at least one of the target person and the mobile terminal from the mobile terminal; The admission process means performs at least a part of the process when the authentication identification information is included in the authorized identification information. An authentication device.

4. In the authentication device according to any one of Claims 1 to 3, The acquisition means acquires authentication identification information for identifying at least one of the target person and the mobile terminal from the mobile terminal; The storage process means stores the master biometric information and the authentication identification information acquired by the acquisition means in association with each other in the storage means. Before the acquisition means acquires the master biometric information from the mobile terminal, the authentication biometric information and the authentication identification information are acquired. The authentication means specifies the master biometric information associated with the authentication identification information acquired by the acquisition means in the storage means, and performs the authentication process using the master biometric information. The acquisition means is an authentication device that, when there is no master biometric information associated with the authentication identification information in the storage means, acquires the master biometric information from the mobile terminal and performs the authentication process.

5. In the authentication device according to any one of claims 1 to 4, The entrance processing means outputs authentication completed information indicating that the authentication process has succeeded to a control means that controls the opening and closing of a gate installed at the entrance of the target area or the locking of a door installed at the entrance.

6. In the authentication device according to any one of claims 1 to 5, The acquisition means acquires the master biometric information from the mobile terminal via a wireless communication device installed at the entrance. The communication range of the wireless communication device is 5 m or less.

7. In the authentication device according to claim 6, The acquisition means acquires the reception intensity when the wireless communication device receives the wireless output by the mobile terminal, and when the wireless communication device can communicate with a plurality of the mobile terminals, determines the mobile terminal to be processed using the reception intensity.

8. A computer performs an acquisition process of acquiring the master biometric information of a target person from a mobile terminal and acquiring the authentication biometric information, which is the biometric information of the target person generated by a biometric information generation device installed at the entrance of the target area, an authentication process of authenticating the target person using the authentication biometric information and the master biometric information, an entrance process of performing at least a part of a process for enabling the target person to enter the target area when the authentication process is successful, and a storage process of storing the master biometric information in a storage means when the authentication process is successful, and invalidating or deleting from the storage means the master biometric information whose storage time in the storage means has reached a predetermined time or more, and in the acquisition process, before acquiring the master biometric information from the mobile terminal, the authentication biometric information is acquired. In the authentication process, authenticate the biometric information for authentication against the valid master biometric information stored in the storage means. In the acquisition process, when the master biometric information that matches the biometric information for authentication and is valid is not stored in the storage means, acquire the master biometric information from the mobile terminal. Authentication method.

9. In a computer An acquisition function that acquires the master biometric information of the target person from a mobile terminal and acquires the biometric information for authentication, which is the biometric information of the target person generated by a biometric information generation device installed at the entrance of the target area. An authentication function that performs an authentication process of the target person using the biometric information for authentication and the master biometric information. An entrance processing function that performs at least a part of the process for enabling the target person to enter the target area when the authentication process is successful. When the authentication process is successful, a storage processing function that stores the master biometric information in the storage means and invalidates or deletes the master biometric information whose storage time in the storage means has reached a predetermined time or more from the storage means. having Before acquiring the master biometric information from the mobile terminal, the acquisition function acquires the biometric information for authentication. The authentication function performs an authentication process of the biometric information for authentication against the valid master biometric information stored in the storage means. When the master biometric information that matches the biometric information for authentication and is valid is not stored in the storage means, the acquisition function acquires the master biometric information from the mobile terminal. Program.

Citation Information

Patent Citations

  • Face identification contactless access controller and intelligent gate

    CN108109250A

  • Automatic gate system

    JP2003331323A

  • Gate device and method for gate device

    WO2019049623A1

  • Customer authentication device, customer authentication method, and program

    WO2021193138A1