Program, service server, control method for a terminal, and control method for a service server

The terminal and system allow users to manage and monitor their biometric authentication history across multiple service providers, enhancing personal and privacy protection by enabling authentication history management and detection of unauthorized uses.

JP7711820B2Active Publication Date: 2025-07-23NEC CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024137503
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-08-19
Publication Date
2025-07-23
Estimated Expiration
2042-12-07

AI Technical Summary

Technical Problem

Existing biometric authentication systems do not allow users to manage their authentication information and history across multiple service providers, compromising personal and privacy protection.

Method used

A terminal and system that enable users to select a service provider for biometric authentication, receive authentication success notifications, and manage the authentication history with the terminal, including a receiving unit and authentication history control unit to handle these functions.

Benefits of technology

Users can effectively manage and monitor their authentication history, detecting unauthorized uses and ensuring control over their biometric data across selected service providers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007711820000001
    Figure 0007711820000001
  • Figure 0007711820000002
    Figure 0007711820000002
  • Figure 0007711820000003
    Figure 0007711820000003
Patent Text Reader

Abstract

To provide a terminal that accomplishes management, etc., of an authentication record at a service provider selected by a user.SOLUTION: A terminal includes receiving means and authentication record controlling means. The receiving means receives an authentication success notification from the service server of a service provider which is selected by a user from among multiple service providers, and which succeeds the biometric authentication of the user. The authentication record controlling means executes a control relating to the record of the successful biometric authentication at the service provider in response to the receiving action of the authentication success notification.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a terminal, a system, a method for controlling a terminal, and a storage medium.

Background Art

[0002] There are technologies related to biometric authentication.

[0003] For example, Patent Document 1 describes providing a server device that improves convenience in an authentication system including a plurality of authentication terminals. The server device of Patent Document 1 includes an acquisition unit and an authentication unit. The acquisition unit acquires an authentication rule including conditions for determining authentication success. The authentication unit performs a first biometric authentication in response to a first authentication request transmitted from a first terminal, and performs a second biometric authentication using the authentication rule in response to a second authentication request transmitted from a second terminal.

[0004] Patent Document 2 describes enabling a plurality of service providers to use a biometric authentication terminal while minimizing the occupancy time of the authentication terminal per user. The authentication device of Patent Document 2 includes an authentication table, a reception means, an authentication means, and a notification means. The authentication table manages by associating identification information of each user and personal information including the contact information of the user terminal owned by the user. The reception means receives user identification information and authentication information from the user. The authentication means compares the authentication information input by the user with reference authentication information serving as a reference for authentication, and performs personal authentication based on the comparison result. The notification means refers to the authentication table and notifies the user terminal corresponding to the user of the result of the personal authentication.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0006] In recent years, various services using biometric authentication have started to be provided. Here, from the viewpoints of personal information protection and privacy protection, there is a desire for users to manage authentication information, authentication results, etc. used for biometric authentication by themselves. Specifically, there is a desire for users to select a service provider that performs biometric authentication from among a plurality of service providers, and to manage and check the authentication history, etc. in the selected service provider.

[0007] Note that this desire cannot be realized even by applying the technologies disclosed in Patent Document 1 and Patent Document 2. Patent Document 1 and Patent Document 2 do not disclose an authentication system in which a user selects a service provider from among a plurality of service providers.

[0008] A main object of the present invention is to provide a terminal, a system, a control method of the terminal, and a storage medium that contribute to realizing management of an authentication history in a service provider selected by a user.

Means for Solving the Problems

[0009] According to a first aspect of the present invention, there is provided a terminal including: a receiving means for receiving an authentication success notification from a service server of a service provider that the user has selected from among a plurality of service providers and in which biometric authentication of the user has been successful; and an authentication history control means for performing control regarding a history of successful biometric authentication in the service provider in response to the reception of the authentication success notification.

[0010] According to a second aspect of the present invention, there is provided a system including a service server of a service provider selected by a user from a plurality of service providers and having succeeded in biometric authentication of the user, and a terminal possessed by the user. The terminal includes a receiving unit configured to receive an authentication success notification from the service server, and an authentication history control unit configured to perform control regarding a history of biometric authentication that has succeeded in the service provider in response to the reception of the authentication success notification.

[0011] According to a third aspect of the present invention, there is provided a control method for a terminal, in which the terminal receives an authentication success notification from a service server of a service provider selected by a user from a plurality of service providers and having succeeded in biometric authentication of the user, and performs control regarding a history of biometric authentication that has succeeded in the service provider in response to the reception of the authentication success notification.

[0012] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium storing a program for causing a computer mounted on a terminal to execute a process of receiving an authentication success notification from a service server of a service provider selected by a user from a plurality of service providers and having succeeded in biometric authentication of the user, and a process of performing control regarding a history of biometric authentication that has succeeded in the service provider in response to the reception of the authentication success notification.

Advantages of the Invention

[0013] According to each aspect of the present invention, there are provided a terminal, a system, a control method for a terminal, and a storage medium that contribute to realizing management of an authentication history in a service provider selected by a user. Note that the effects of the present invention are not limited to the above. Instead of or together with the above effects, other effects may be achieved by the present invention.

Brief Description of the Drawings

[0014]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Figure 24

DETAILED DESCRIPTION OF THE INVENTION

[0015] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings appended to this overview are for convenience and are appended to each element as an example to assist understanding, and the description of this overview is not intended to be limiting in any way. Also, unless otherwise specified, the blocks shown in each drawing represent a configuration in terms of functional units rather than hardware units. The connection lines between the blocks in each figure include both bidirectional and unidirectional ones. For a one-way arrow, it schematically shows the flow of the main signal (data) and does not exclude bidirectionality. In this specification and the drawings, for elements that can be similarly described, duplicate description may be omitted by assigning the same reference numerals.

[0016] A terminal 100 according to an embodiment includes a receiving unit 101 and an authentication history control unit 102 (see FIG. 1). The receiving unit 101 receives an authentication success notification from a service server of a service provider selected by a user from among a plurality of service providers and for which the user's biometric authentication has succeeded (step S1 in FIG. 2). The authentication history control unit 102 performs control regarding the history of biometric authentication that has succeeded at the service provider in response to receiving the authentication success notification (step S2).

[0017] The user selects a service provider from among a plurality of service providers for which the user wishes to receive services. In response to the selection, the original authentication information used for biometric authentication is provided to the selected service provider. When the service server of the service provider successfully authenticates the user using the authentication information, the service server transmits an authentication success notification notifying the fact and details of the authentication success to the terminal 100. The terminal 100 performs control regarding the history of biometric authentication in response to receiving the authentication success notification. For example, the terminal 100 enables the user to view the authentication history. In this way, the terminal 100 realizes management of the authentication history and the like at the service provider selected by the user from among a plurality of service providers. By checking the authentication history and the like, the user can discover the implementation of unauthorized biometric authentication that the user does not remember.

[0018] Specific embodiments will be described in more detail below with reference to the drawings.

[0019] [First Embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0020] [Configuration of System] FIG. 3 is a diagram showing an example of a schematic configuration of an authentication system (information processing system) according to the first embodiment. As shown in FIG. 3, the authentication system includes a plurality of service providers A to C and an authentication center.

[0021] A service provider is an operator that provides services to users using biometric authentication. The authentication system according to the present disclosure assumes that service providers belonging to various industries and sectors provide services using biometric authentication. Note that the services provided by the service provider may be either paid or free of charge.

[0022] For example, operators providing rental housing services such as condominiums, operators where employees work (the workplace of users), operators providing events such as concerts, operators operating means of transportation such as airplanes, etc. are exemplified as service providers. Alternatively, operators providing accommodation services, operators such as retail stores, operators providing financial services, educational operators, etc. are also included in the service providers of the present disclosure. In addition, the service provider is not limited to private operators. Public institutions such as local governments may be service providers.

[0023] The authentication center controls, manages, etc. the biometric authentication of each of a plurality of service providers. An operator (service provider) that provides services using biometric authentication to users (general consumers) needs to conclude a contract with the authentication center.

[0024] The authentication center includes a control server 10. The control server 10 realizes the main functions of the authentication center. The control server 10 may be installed inside the building of the authentication center, or may be a server installed on a network (cloud).

[0025] As described above, the service provider provides services to users using biometric authentication. For example, biometric authentication is performed when a user goes to work at the office or returns home to the condominium, and a user (employee, resident) with legitimate qualifications can enter the office or the like. Alternatively, biometric authentication is performed in ticket confirmation at an event venue, check-in procedures at a hotel, immigration procedures at an airport, etc. Services are also provided to users with legitimate qualifications in such services (procedures). Alternatively, payment procedures at a retail store or the like are performed using biometric authentication.

[0026] As shown in FIG. 3, each service provider includes a service server 20 and at least one authentication terminal 30. The devices (service server 20, authentication terminal 30) provided by the service provider are connected to be communicable with each other. Specifically, the service server 20 and the authentication terminal 30 are connected by wired or wireless communication means.

[0027] The service server 20 is connected to the control server 10 via a network. The service server 20 may be installed in the building of the service provider or may be installed on the cloud.

[0028] The service server 20 stores information necessary for providing services to users. Specifically, the service server 20 stores business information necessary for each service provider to provide services using biometric authentication and information necessary for biometric authentication. The service server 20 stores business information and information necessary for biometric authentication using a user management database. Details of the user management database will be described later.

[0029] For example, the service server 20 of the company where the user works stores information such as the user's (employee's) name, date of birth, employee number, department, and place of work as business information. Also, the service server 20 of the event company that hosts the event stores information about the tickets purchased by the event participants as business information. Furthermore, the service server 20 of a retail store or the like stores credit card information (settlement information) necessary for payment as business information.

[0030] Details of the information necessary for biometric authentication stored by the service server 20 will be described later.

[0031] The authentication terminal 30 is a device that serves as an interface for users who receive services. The authentication terminal 30 is installed at each service provider's service providing location. More specifically, the authentication terminal 30 is installed in a store or the like that the user actually visits.

[0032] The authentication terminal 30 has functions and forms corresponding to the industry type of the service provider, etc. For example, the authentication terminal 30 installed in a workplace or an event venue can be a gate device equipped with a gate for restricting the passage of users (the persons to be authenticated). Also, for the authentication terminal 30 installed in a retail store, a tablet-type terminal can be used.

[0033] Note that FIG. 3 is an illustration and is not intended to limit the configuration of the authentication system disclosed in the present application. For example, the authentication center may include two or more control servers 10. Also, in the authentication system, at least one or more service providers may participate. Furthermore, each service provider may be equipped with at least one or more service servers 20 and at least one or more authentication terminals 30.

[0034] [Schematic Operation] Subsequently, the schematic operation of the authentication system according to the first embodiment will be described.

[0035] [Account Generation] A user who wishes to receive a service from a service provider needs to generate an account in the system. Specifically, the user operates the terminal 40 in his or her possession to access the control server 10 (see FIG. 4).

[0036] The user inputs login information (e.g., login ID, password), name, date of birth, contact information, etc. on a WEB (web) page or the like provided by the control server 10. When the control server 10 acquires the login information and the like, it generates an ID for identifying the user. In the following description, the ID generated by the control server 10 is referred to as the "system ID". The control server 10 stores the generated system ID, login information, etc. in association with each other in an account management database. The details of the account management database will be described later.

[0037] [Biometric Information Registration] A user who wishes to receive a service using biometric authentication needs to register their biometric information in the terminal 40.

[0038] Here, for the provision of a service using biometric authentication, authentication information generated from biometric information needs to be registered in advance with the service provider. For example, when a service is provided using face authentication, the feature amount (feature vector) generated from the face image needs to be registered in advance as authentication information. Alternatively, when a service is provided using fingerprint authentication, the feature amount generated from the fingerprint image needs to be registered in advance as authentication information.

[0039] In the following description, information that serves as the original (basis) when generating authentication information, such as a face image or a fingerprint image, is referred to as "original biometric information". Also, the feature amount generated from the original biometric information and registered in advance is referred to as "registered authentication information".

[0040] The user who has completed the system account generation needs to register in the terminal 40 that holds the original biometric information (for example, a face image). The terminal 40 acquires the original biometric information using a GUI (Graphical User Interface) or the like. The terminal 40 stores the acquired original biometric information (for example, a face image) internally. In this way, the terminal 40 stores the original biometric information that serves as the original of the authentication information used for biometric authentication.

[0041] <Service Selection> The user who has performed system registration (system account creation) and registration of the original biometric information selects the service provider from whom they wish to receive the biometric authentication service. The user selects the service provider from whom they wish to receive the service from among a plurality of service providers (service providers contracted with the authentication center) participating in the authentication system.

[0042] The control server 10 stores information on service providers participating in the authentication system. For example, the control server 10 stores the name, industry type, location, etc. of the service providers. The control server 10 holds information on each of a plurality of service providers and enables a user to select a service provider.

[0043] When the user operates the terminal 40 to perform a predetermined operation on the portal site, the control server 10 displays on the terminal 40 a GUI or the like that enables the selection of the service (service provider) desired by the user. The control server 10 acquires the service (biometric authentication service) desired by the user using the GUI.

[0044] <User registration> When the control server 10 acquires the service provider selected by the user, it executes control regarding "user registration" that enables the selected service provider to provide the user with a service using biometric authentication.

[0045] Specifically, the control server 10 performs control for the selected service provider to acquire the original biometric information stored in the user's terminal 40. The service provider generates registration authentication information from the acquired original biometric information, and by associating the generated registration authentication information with business information, preparations are made to provide the user with a service.

[0046] The user operates the terminal 40 to access the control server 10 and logs in to the user's portal site. When the user performs a predetermined operation (for example, pressing a service provider selection button) on the portal site, the control server 10 displays on the terminal 40 a GUI including a list of service providers.

[0047] When a service provider is selected, the control server 10 requests the user to provide original biometric information. Specifically, the control server 10 transmits an "original provision request" to the user's terminal 40 (see step S01 in FIG. 5).

[0048] When receiving the original document provision request, the terminal 40 transmits the user's original biometric information (e.g., face image) to the control server 10 (step S02).

[0049] The control server 10 notifies the service provider selected by the user of the user's system ID, the acquired original biometric information, personal identification information, etc. Note that the personal identification information is information for identifying the user. As the personal identification information, the user's name or a combination of the name and date of birth is exemplified.

[0050] The control server 10 transmits a "user registration request" including the system ID, original biometric information, and personal identification information, etc. to the service server 20 of the service provider selected by the user (step S03).

[0051] The service server 20 that has received the user registration request searches the user management database using the acquired personal identification information and identifies the user who wishes to register (provide services using biometric authentication). The service server 20 stores the registration authentication information (e.g., feature amount) obtained from the system ID and original biometric information in the entry of the identified user.

[0052] The service server 20 transmits a response including the result of user registration (success or failure of user registration) to the control server 10 (step S04).

[0053] Note that the control server 10 deletes the original biometric information (e.g., face image) obtained from the user at the timing when the user registration request is transmitted to the service server 20 or at the timing when the response to the request is received. Also, when the service server 20 generates the registration authentication information (e.g., feature amount), it deletes the original biometric information obtained from the control server 10.

[0054] <Service Provision> The user who has completed the selection of the service visits the service provider to receive the service. For example, the user visits the facility, store, etc. of the service provider that provides the service selected by the user himself / herself, such as an office, an amusement park, an event venue, a retail store, etc.

[0055] The authentication terminal 30 acquires the biometric information of the user (the person to be authenticated) who receives the service. For example, the authentication terminal 30 photographs the person to be authenticated and acquires biometric information (e.g., a face image) corresponding to the original biometric information. The authentication terminal 30 transmits an authentication request including the acquired face image to the service server 20 (see FIG. 6). Note that the authentication terminal 30 transmits other information (e.g., the name of the purchased product, the price of the purchased product, etc.) to the service server 20 together with the biometric information as necessary. Alternatively, the authentication terminal 30 may transmit information used for authentication processing (e.g., credit card information) together with the biometric information (information for identifying an individual, ID) to the service server 20.

[0056] The service server 20 generates authentication information for verification from the acquired face image. For example, the service server 20 generates feature amounts from the face image for verification. The service server 20 executes a verification process (1-to-N verification; N is a positive integer, the same hereinafter) using the generated authentication information for verification (hereinafter referred to as verification authentication information) and the registered authentication information registered in the user management database.

[0057] The service server 20 identifies the user (the person to be authenticated) registered in the user management database by the verification process.

[0058] The service server 20 authenticates the identified user using the business information of the user. For example, the service server 20 of the company where the employee works determines that "authentication is successful" if the person to be authenticated is an employee of the company and has the qualification to enter the office. Alternatively, the service server 20 installed at the event venue determines that "authentication is successful" if the ticket purchased by the person to be authenticated is valid. Alternatively, the service server 20 installed at the retail store determines that "authentication is successful" when the payment for the product or the like purchased by the person to be authenticated is successful.

[0059] Note that there are two types of service providers.

[0060] The first type of service provider is, in principle, a service provider that continues to hold registration authentication information (feature amounts), etc. even after successfully authenticating the person to be authenticated. For example, an employer company of a user, a condominium management company, etc. are exemplified as the first type of service provider. These service providers do not delete the registration authentication information, etc. stored in the user management database even after successfully authenticating the user (entering or leaving an office, condominium, etc.). Alternatively, a retail store that provides a service related to face payment for the price of goods using pre-registered credit card information, etc. is also exemplified as the first type of service provider. The retail store continues to store the credit card information and the registration authentication information in association with each other.

[0061] The second type of service provider is, in principle, a service provider that deletes the registration authentication information (feature amounts), etc. when the authentication of the person to be authenticated is successful. For example, an event company that holds an event is exemplified as the second type of service provider. When the event company successfully authenticates a user (when the user enters the event venue using a purchased ticket), it deletes the registration authentication information stored in the user management database.

[0062] Note that even for the same service provider, depending on the content of the service provided to the user, it may continue to store the registration authentication information or delete the registration authentication information. For example, an operator of an amusement park, etc. sells tickets limited to one-day use. In this case, the operator becomes the second type of service provider. When the above operator also sells tickets that allow entry to an amusement park, etc. for a predetermined period (for example, annual tickets), it becomes the first type of service provider. In this case, the operator continues to hold the registration authentication information until the expiration date of the annual ticket.

[0063] The service server 20 transmits the authentication result (authentication success, authentication failure) to the authentication terminal 30.

[0064] The authentication terminal 30 executes processing according to the authentication result. For example, when receiving successful authentication, the authentication terminal 30 installed in the office opens the gate and permits the authenticated person to pass. Alternatively, the authentication terminal 30 installed in the event venue permits the authenticated person to pass through the gate when receiving successful authentication. Alternatively, the authentication terminal 30 installed in the retail store notifies the authenticated person that the settlement of the goods has been completed when receiving successful authentication.

[0065] <Notification of successful authentication> In addition, when the service server 20 successfully authenticates the authenticated person, it notifies the user to that effect. The service server 20 notifies the user of the details of the authentication result via the control server 10 to the terminal 40 held by the user. Specifically, when successfully authenticating the authenticated person, the service server 20 transmits an authentication success notification including the system ID of the authentication successful person (the authenticated person determined to be successful in authentication), the detailed information of the authentication process, and the status of the authentication information to the control server 10 (see FIG. 7).

[0066] The detailed information of the authentication process includes, for example, the authentication date and time, the authentication location, and the details of the provided service (for example, the name of the purchased product, the payment amount, etc.).

[0067] For example, the service server 20 of the workplace of the authenticated person generates the attendance date and time of the authentication successful person and the name of the office as the details of the provided service. Alternatively, for example, the service server 20 of the retail store generates the visit date and time of the authentication successful person, the store, the purchased product, the payment amount, etc. as the details of the provided service.

[0068] The status of the authentication information sets the status (retention, deletion) of the registered authentication information (feature amount) of the authentication successful person after the authentication process.

[0069] For example, the service server 20 of the first service provider such as the workplace of the authenticated person sets "authentication information retention" in the status of the authentication information. Alternatively, the service server 20 of the second service provider such as the event company sets "authentication information deletion" in the status of the authentication information.

[0070] The control server 10 receives an authentication success notification. The control server 10 searches the account management database using the system ID included in the authentication success notification as a key, and identifies the corresponding entry (user). The control server 10 transmits (forwards) the authentication success notification received from the service server 20 to the terminal 40 of the identified user.

[0071] The terminal 40 generates an authentication history based on the received authentication success notification. Also, each time the terminal 40 receives an authentication success notification, it notifies the user of the fact that the notification has been received. For example, the terminal 40 displays the content included in the authentication success notification (details of the authentication process, status of the authentication information) by means such as a pop-up.

[0072] Alternatively, when a predetermined button (history confirmation button) is pressed on the terminal 40, the authentication history is displayed. The user can check for unauthorized use by checking the authentication history.

[0073] In this way, when the service provider preselected by the user successfully authenticates the user, the fact of the successful authentication is notified to the user. Note that, as described above, the service server 20 may transmit the authentication success notification to the terminal 40 via the control server 10, or may transmit the authentication success notification directly to the terminal 40 without going through the control server 10. In this case, when acquiring business information, the service server 20 may acquire the contact information of the user (such as an email address to which the terminal 40 can receive).

[0074] Subsequently, details of each device included in the authentication system according to the first embodiment will be described.

[0075] [Control Server] FIG. 8 is a diagram showing an example of the processing configuration (processing modules) of the control server 10 according to the first embodiment. Referring to FIG. 8, the control server 10 includes a communication control unit 201, an account management unit 202, a carrier management unit 203, a service selection control unit 204, a user registration control unit 205, and a storage unit 206.

[0076] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the service server 20. Also, the communication control unit 201 transmits data to the service server 20. The communication control unit 201 delivers the data received from other devices to other processing modules. The communication control unit 201 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0077] The account management unit 202 is a means for managing the user's account. When the user operates the terminal 40 to access a predetermined homepage or the like, the account management unit 202 acquires the information necessary for generating the user's account.

[0078] Specifically, the account management unit 202 acquires personal information such as login information, name, date of birth, contact information (for example, an email address that the terminal 40 can receive). When acquiring the login information and the like, the account management unit 202 generates a system ID for identifying the user. The system ID may be any information as long as it can uniquely identify the user. For example, the account management unit 202 may assign a unique value each time an account is generated and use it as the system ID.

[0079] The account management unit 202 associates the generated system ID, login information, name, etc. and stores them in the account management database (see FIG. 9). Note that the account management database shown in FIG. 9 is an example and is not intended to limit the items to be stored. For example, the account generation date and time, etc. may be stored in the account management database.

[0080] In addition, the account management unit 202 acquires login information for the user to log in to the portal site from the user's terminal 40. The account management unit 202 performs authentication using the login information.

[0081] The service provider management unit 203 is a means for managing service providers (service operators) participating in the authentication system. The service provider management unit 203 acquires business operator information (name of the service provider, type of business, location, address of the service server 20, etc.) to be system-registered from the employees of each service provider.

[0082] For example, the service provider management unit 203 may provide each service provider with an interface for inputting business operator information and the like. Alternatively, each service provider may send a USB (Universal Serial Bus) memory or the like storing business operator information and the like to the authentication center. The service provider management unit 203 may acquire business operator information and the like from the employees of the authentication center.

[0083] The service provider management unit 203 generates an ID (business operator ID) for the service provider that has acquired business operator information and the like. The service provider management unit 203 stores the generated business operator ID, the acquired business operator information, etc. in association with each other.

[0084] The service selection control unit 204 is a means for controlling the selection of biometric authentication services (service providers) by the user. The service selection control unit 204 enables the user to select a service provider from among a plurality of service providers that provide services using biometric authentication and from which the user wishes to receive services.

[0085] When the user operates the terminal 40 to log in to the portal site and performs a predetermined operation on the portal site, the service selection control unit 204 displays, for example, a GUI as shown in FIG. 10 on the terminal 40.

[0086] When displaying the above-mentioned GUI, the service selection control unit 204 performs a display that can distinguish between service providers selected by the user and unselected service providers. In the example of FIG. 10, a service provider with a check mark in the upper right corner of the icon indicating the service provider indicates a service provider that has already been selected, and a service provider without a check mark indicates an unselected service provider.

[0087] Note that the service selection control unit 204 uses the information registered in the business operator information and account management database to display the GUI as shown in FIG. 10. Specifically, the service selection control unit 204 refers to the business operator information and generates a list of service providers that have concluded contracts with the authentication center. In addition, the service selection control unit 204 refers to the selected service field of the account management database and acquires the service provider (business operator ID of the service provider) selected by the user.

[0088] In addition, when displaying the list of service providers, the service selection control unit 204 may also provide the user with more detailed information about each service provider (for example, industry type, services provided, location of the store, etc.).

[0089] The service selection control unit 204 delivers the information of the service provider selected by the user (for example, the business operator ID of the service provider for which user registration is desired) to the user registration control unit 205.

[0090] The user registration control unit 205 is a means for controlling "user registration" by the control server 10. The user registration control unit 205 controls "user registration" that enables the service provider selected by the user to provide the user with a service using biometric authentication.

[0091] When the user selects a service provider, the user registration control unit 205 sends a "document provision request" to the terminal 40 possessed by the user. The user registration control unit 205 receives the original biometric information (for example, face image) of the user from the terminal 40.

[0092] The user registration control unit 205 transmits a user registration request including the user's system ID, original biometric information, personal identification information, etc. to the service server 20 of the service provider corresponding to the service selected by the user.

[0093] Note that the user registration control unit 205 acquires the system ID and personal identification information (for example, name or combination of name and date of birth) from the account management database.

[0094] The user registration control unit 205 receives a response (positive response, negative response) to the user registration request.

[0095] When receiving a positive response (successful user registration), the user registration control unit 205 registers the business ID of the service provider selected by the user in the account management database. Also, when receiving a positive response, the user registration control unit 205 notifies the user that the user registration for the selected service provider has been successful.

[0096] When receiving a negative response (failed user registration), the user registration control unit 205 notifies the user to that effect.

[0097] The storage unit 206 is a means for storing information necessary for the operation of the control server 10.

[0098] [Service Server] FIG. 11 is a diagram showing an example of the processing configuration (processing modules) of the service server 20 according to the first embodiment. Referring to FIG. 11, the service server 20 includes a communication control unit 301, a business information management unit 302, a user registration control unit 303, an authentication unit 304, and a storage unit 305.

[0099] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the control server 10. Also, the communication control unit 301 transmits data to the control server 10. The communication control unit 301 delivers the data received from other devices to other processing modules. The communication control unit 301 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit for receiving data from other devices and a function as a transmitting unit for transmitting data to other devices.

[0100] The business information management unit 302 is a means for managing and controlling business information necessary for a service provider to provide services.

[0101] The business information management unit 302 acquires business information necessary for the service provision of its own company or organization using any means. For example, the business information management unit 302 of the user's employer company acquires information such as the name, date of birth, employee number, department, and place of work of employees as business information.

[0102] The business information management unit 302 may acquire the above business information from the service provider's staff or directly from the user using means such as a homepage.

[0103] The business information management unit 302 manages business information using a user management database.

[0104] Note that a more detailed description of the business information management unit 302 is omitted because the details of the business information in individual services and the method of acquiring it are different from the gist of the present application disclosure.

[0105] The user registration control unit 303 is a means for controlling user registration by a service provider. The user registration control unit 303 processes the user registration request received from the control server 10.

[0106] Upon receiving a user registration request, the user registration control unit 303 searches the user management database using the personal identification information (e.g., name) included in the user registration request as a key, and identifies the corresponding user (entry).

[0107] If the corresponding user is registered in the user management database, the user registration control unit 303 generates registration authentication information from the acquired original biometric information (e.g., face image). For example, when a face image is acquired, the user registration control unit 303 generates a feature amount (feature vector) corresponding to the face recognition algorithm adopted by the company as the registration authentication information.

[0108] Regarding the generation process of the feature amount, existing technologies can be used, so a detailed description thereof is omitted. For example, the user registration control unit 303 extracts eyes, nose, mouth, etc. from the face image as feature points. Then, the user registration control unit 303 calculates the position of each feature point and the distance between each feature point as the feature amount, and generates a feature vector (vector information characterizing the face image) composed of a plurality of feature amounts.

[0109] When the registration authentication information (e.g., feature amount) is generated, the user registration control unit 303 associates the system ID, the generated registration authentication information (feature amount), and the business information, and stores them in the user management database (see FIG. 12).

[0110] Note that the user management database shown in FIG. 12 is an example, and is not intended to limit the items to be stored. For example, the date and time of user registration etc. may be registered in the user management database.

[0111] When the user registration is successfully completed, the user registration control unit 303 sends an affirmative response indicating that the user registration has been successful to the control server 10. Note that when the user registration control unit 303 generates the registration authentication information (e.g., feature amount) and registers the generated registration authentication information in the user management database, it deletes the original biometric information acquired from the control server 10.

[0112] If the user registration does not end normally, the user registration control unit 303 sends a negative response indicating that the user registration has failed to the control server 10. For example, when the personal identification information (e.g., name) received from the control server 10 is not registered in the user management database, or when valid registration authentication information cannot be generated from the original biometric information, etc., a negative response is sent to the control server 10.

[0113] The authentication unit 304 is a means for performing biometric authentication of the person to be authenticated.

[0114] FIG. 13 is a flowchart showing an example of the operation of the authentication unit 304 according to the first embodiment. With reference to FIG. 13, the operation of the authentication unit 304 will be described.

[0115] When receiving an authentication request from the authentication terminal 30, the authentication unit 304 executes a collation process using biometric information (step S101).

[0116] Specifically, the authentication unit 304 generates collation authentication information from the biometric information included in the authentication request. For example, when acquiring a face image, the authentication unit 304 generates feature amounts corresponding to the face authentication algorithm adopted by the company. The authentication unit 304 executes a collation process using the generated collation authentication information (feature amounts) and the registration authentication information (feature amounts) registered in the user management database.

[0117] Specifically, the authentication unit 304 calculates the similarity between the feature amount (feature vector) to be collated and each of the plurality of feature amounts on the registration side. For the similarity, the chi-square distance, the Euclidean distance, etc. can be used. Note that the farther the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0118] If there is no feature quantity with a similarity equal to or higher than a predetermined value, the authentication unit 304 determines that the verification process has failed. If there is a feature quantity with a similarity equal to or higher than a predetermined value, the authentication unit 304 determines that the verification process has succeeded. When the verification process succeeds, among the plurality of entries registered in the user management database, the user of the entry having the feature quantity (registered authentication information) with the highest similarity is specified as the person to be authenticated.

[0119] When the verification process fails (branch to No in step S102), the authentication unit 304 ends the process. In this case, the authentication unit 304 may notify the authentication terminal 30 that the authentication has failed. Alternatively, the authentication unit 304 may store, as a log, the fact that the verification process has failed and the details of the verification process in order to confirm the soundness of face authentication.

[0120] When the verification process succeeds (branch to Yes in step S102), the authentication unit 304 determines whether or not it is possible to provide a service to the person to be authenticated using the business information of the person to be authenticated specified by the verification process. The authentication unit 304 determines whether or not service can be provided based on the business information (step S103).

[0121] For example, the authentication unit 304 of the service server 20 of the company where an employee works determines that service can be provided if the person to be authenticated is an employee of the company and has the qualification to enter the office. Alternatively, the service server 20 of an event company determines that service can be provided if the ticket purchased by the person to be authenticated is valid. Alternatively, the authentication unit 304 of the service server 20 of a retail store or the like determines that service can be provided when the payment for goods using credit card information or the like is successful.

[0122] Note that a more detailed description of the authentication process using the business information in each service provider is omitted. This is because the processes specific to each service provider are different from the gist of the present disclosure.

[0123] When service cannot be provided (branch to No in step S104), the authentication unit 304 sets "authentication failed" in the authentication result (step S105).

[0124] When the service can be provided (branch of step S104, Yes), the authentication unit 304 sets "authentication successful" in the authentication result (step S106).

[0125] The authentication unit 304 transmits the authentication result (authentication successful, authentication failed) to the authentication terminal 30 (step S107).

[0126] In the case of authentication failure, the authentication unit 304 transmits a negative response indicating that to the authentication terminal 30.

[0127] In the case of authentication success, the authentication unit 304 transmits an affirmative response indicating that to the authentication terminal 30. At that time, the authentication unit 304 transmits an affirmative response including information necessary to provide the service to the user to the authentication terminal 30 as necessary. In the above example of issuing a family register, the information necessary to issue (print) the family register is transmitted to the authentication terminal 30.

[0128] Also, in the case of authentication success, the authentication unit 304 updates the user management database as necessary (database update; step S108). More specifically, the authentication unit 304 deletes at least the registered authentication information of the authentication successful person according to the content of the authentication process.

[0129] For example, in the case of an authentication process related to the entry and exit of the person to be authenticated (going to work in the office, returning home to the condominium, etc.), the authentication unit 304 does not perform any special processing (does not delete the registered authentication information). Or, when the person to be authenticated settles the purchase of goods using credit card information, the authentication unit 304 also does not perform any special processing.

[0130] In this way, when not deleting the registered authentication information of the authentication successful person, the authentication unit 304 sets "authentication information retention" in the state of the authentication information.

[0131] When the authenticated person enters the event venue or the like using the purchased ticket, the authentication unit 304 deletes the registration authentication information of the authenticated person (deletes the entry in the corresponding user management database). In this case, the authentication unit 304 sets "authentication information deletion" in the status of the authentication information.

[0132] Whether to delete the registration authentication information is determined in advance according to the services provided to the user. Alternatively, the deletion of the registration authentication information (entry including the registration authentication information) may be determined based on the information included in the business information. For example, when the ticket purchased by the user is a reusable ticket such as an "annual passport", the authentication unit 304 does not delete the registration authentication information.

[0133] In the case of successful authentication, the authentication unit 304 sends a successful authentication notification to the control server 10 (step S109).

[0134] Specifically, the authentication unit 304 sends a successful authentication notification including the system ID of the authenticated person (user identified by the collation process), detailed information on the authentication process, and the status of the authentication information to the control server 10.

[0135] The authentication unit 304 acquires the system ID from the entry (entry in the user management database) identified by the collation process.

[0136] The authentication unit 304 generates an authentication date and time from the date and time when the authentication request received from the authentication terminal 30 was processed, and generates an authentication location from the installation location of the authentication terminal 30. In addition, the authentication unit 304 generates details of the provided service from the content of the authentication process using the business information.

[0137] For example, when the person to be authenticated arrives at the workplace, the authentication unit 304 generates detailed information on the authentication process including contents such as "authentication date and time = November 7, 2022, 08:30", "authentication location = head office building", and "details of provided services = arrival at work". Alternatively, when the person to be authenticated purchases goods at a retail store, the authentication unit 304 generates detailed information on the authentication process with contents such as "authentication date and time = November 7, 2022, 13:00", "authentication location = station front store", and "details of provided services = purchase of nutritional drink, 300 yen".

[0138] Note that when events such as the user's resignation, the user's departure from the apartment, or the expiration of the annual passport validity occur, the entry of the corresponding user is deleted from the user management database. In this case, since authentication of the user will not succeed, the user management database will not be updated and no authentication success notification will be sent.

[0139] The storage unit 305 is a means for storing information necessary for the operation of the service server 20.

[0140] [Authentication Terminal] FIG. 14 is a diagram showing an example of the processing configuration (processing modules) of the authentication terminal 30 according to the first embodiment. Referring to FIG. 14, the authentication terminal 30 includes a communication control unit 401, a provided service control unit 402, an authentication request unit 403, and a storage unit 404.

[0141] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the service server 20. Also, the communication control unit 401 transmits data to the service server 20. The communication control unit 401 delivers the data received from other devices to other processing modules. The communication control unit 401 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit for receiving data from other devices and a function as a transmitting unit for transmitting data to other devices.

[0142] The service providing control unit 402 is a means for executing control related to the services provided to the user. The service providing control unit 402 realizes the functions assigned to the authentication terminal 30.

[0143] When the user wishes to enjoy the service, the service providing control unit 402 acquires the biometric information (e.g., face image) of the user (the authenticated person). For example, the service providing control unit 402 images the front of its own device at regular intervals or at a predetermined timing. The service providing control unit 402 determines whether the acquired image contains a human face image, and if a face image is included, extracts the face image from the acquired image data.

[0144] Note that since existing technologies can be used for the face image detection process and the face image extraction process by the service providing control unit 402, detailed descriptions are omitted. For example, the service providing control unit 402 may extract a face image (face region) from the image data using a learning model learned by a CNN (Convolutional Neural Network). Alternatively, the service providing control unit 402 may extract a face image using a method such as template matching.

[0145] The service providing control unit 402 delivers the acquired biometric information (e.g., face image) to the authentication request unit 403.

[0146] The authentication request unit 403 is a means for requesting authentication of the authenticated person from the service server 20. When authentication of the authenticated person is required, the authentication request unit 403 transmits an authentication request including the biometric information of the authenticated person (the user in front of the authentication terminal 30) to the service server 20.

[0147] The authentication request unit 403 receives an authentication result (authentication success, authentication failure) from the service server 20. The authentication request unit 403 delivers the received authentication result to the service providing control unit 402.

[0148] For example, when the service control unit 402 of the authentication terminal 30 installed at the user's workplace receives a successful authentication, it opens the gate and permits the authenticated person to enter.

[0149] When receiving an authentication failure, the service control unit 402 may output a predetermined message or the like.

[0150] Note that a more detailed description of the service control unit 402 included in the authentication terminal 30 of each service provider is omitted. This is because the functional realization of the authentication terminal 30 by the service control unit 402 is different from the gist of the present disclosure.

[0151] The storage unit 404 is a means for storing information necessary for the operation of the authentication terminal 30.

[0152] [Terminal] FIG. 15 is a diagram showing an example of the processing configuration (processing modules) of the terminal 40 according to the first embodiment. Referring to FIG. 15, the terminal 40 includes a communication control unit 501, an account generation control unit 502, an original information acquisition unit 503, a service selection unit 504, an authentication history control unit 505, and a storage unit 506.

[0153] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the control server 10. Also, the communication control unit 501 transmits data toward the control server 10. The communication control unit 501 delivers the data received from other devices to other processing modules. The communication control unit 501 transmits the data acquired from other processing modules toward other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 501. The communication control unit 501 has a function as a receiving unit for receiving data from other devices and a function as a transmitting unit for transmitting data toward other devices.

[0154] In response to a request from the control server 10, which manages the biometric authentication for each of a plurality of service providers, the communication control unit 501 transmits the original biometric information stored in the storage unit 506 to the service server 20 of the service provider selected by the user via the control server 10. Further, the communication control unit 501 directly or indirectly receives a successful authentication notification from the service server 20 of the service provider selected by the user from among the plurality of service providers and for which the biometric authentication of the user has been successful.

[0155] The account generation control unit 502 is a means for controlling the account generation by the user. The account generation control unit 502 accesses a predetermined web page or the like provided by the control server 10 in response to the operation of the user.

[0156] The account generation control unit 502 inputs login information, name, date of birth, contact information, etc. into the web page in response to the operation of the user.

[0157] The original information acquisition unit 503 is a means for acquiring the biometric information (original biometric information) of the user. The original information acquisition unit 503 displays a GUI or the like for acquiring the original biometric information (for example, a face image) in response to the operation of the user. For example, the original information acquisition unit 503 acquires the original biometric information using a GUI as shown in FIG. 16.

[0158] The original information acquisition unit 503 stores the acquired original biometric information (for example, a face image) in the storage unit 506. At this time, the original information acquisition unit 503 may perform encryption, coding, etc. on the acquired original biometric information and store the encrypted original biometric information in the storage unit 506. That is, the terminal 40 possessed by the user may hold the encrypted original biometric information. The encrypted original biometric information may be decrypted when the original biometric information is transmitted to the control server 10. Alternatively, information for decrypting the encrypted original biometric information (for example, a common key) may be shared between the terminal 40 and the control server 10, and the control server 10 may decrypt the encrypted original biometric information.

[0159] In principle, the terminal 40 does not delete the original biometric information (e.g., face image) of the user. That is, the terminal 40 does not delete the original biometric information stored in the storage unit 506 without a clear instruction from the user.

[0160] The service selection unit 504 is a means that enables the user to select a biometric authentication service. The service selection unit 504 logs in to the portal site provided by the control server 10 according to the operation of the user. The service selection unit 504 transmits the information of the service provider selected by the user to the control server 10 using the GUI provided by the control server 10.

[0161] The service selection unit 504 receives a request for providing the original from the control server 10. When receiving the request, the service selection unit 504 transmits the original biometric information stored in the storage unit 506 to the control server 10. The original biometric information is transmitted to the service server 20 of the service provider selected by the user via the control server 10.

[0162] The authentication history control unit 505 is a means for executing control related to the authentication history of the user. The authentication history control unit 505 processes the authentication success notification received from the control server 10. The authentication history control unit 505 performs control related to the history of successful biometric authentication at the service provider in response to the reception of the authentication success notification.

[0163] The authentication success notification includes the detailed information of the authentication process successfully performed by the service provider and the status of the authentication information used by the service provider for biometric authentication.

[0164] The authentication history control unit 505 stores the detailed information of the authentication process and the status of the authentication information included in the authentication success notification in the authentication history management database (see FIG. 17). By storing the detailed information of the authentication process and the status of the authentication information in the authentication history management database, the authentication history control unit 505 generates a history related to the biometric authentication of the user. Note that the authentication history management database shown in FIG. 17 is an example and is not intended to limit the items to be stored.

[0165] Also, when receiving the authentication success notification, the authentication history control unit 505 notifies the user (the owner of the terminal 40) of the fact that the user's authentication has been performed. For example, every time the authentication history control unit 505 receives the authentication success notification, it displays information regarding the user's authentication using a pop-up notification as shown in FIG. 18. That is, every time the authentication history control unit 505 receives the authentication success notification, it displays a message including the detailed information of the authentication process and the status of the authentication information.

[0166] Alternatively, when the user performs a predetermined operation (for example, when pressing the authentication history button), the authentication history control unit 505 displays a list of the authentication history stored in the authentication history management database (see FIG. 19). That is, the authentication history control unit 505 displays the history regarding the biometric authentication stored in the authentication history management database according to a predetermined operation of the user.

[0167] Note that when performing the list display of the authentication history, the authentication history control unit 505 may display the detailed information of the authentication process as shown in FIG. 19, or may display the status of the authentication information in addition to the detailed information of the authentication process as shown in FIG. 20.

[0168] The storage unit 506 is a means for storing information necessary for the operation of the terminal 40. The storage unit 506 stores the original biometric information that is the original of the authentication information used for biometric authentication. Note that, for example, the original biometric information is a face image, and the authentication information is a feature amount generated from the face image.

[0169] [Operation of the System] Subsequently, the operation of the authentication system according to the first embodiment will be described. Note that the description of operations related to account generation and the like is omitted. FIG. 21 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment.

[0170] When receiving an authentication request from the authentication terminal 30, the service server 20 executes an authentication process (step S21).

[0171] When the authentication of the authenticated person is successful, the service server 20 sends an authentication success notification to the control server 10 (step S22).

[0172] The control server 10 forwards the authentication success notification to the terminal 40 of the authentication successful person (step S23).

[0173] The terminal 40 notifies the user of the fact that the authentication process has been performed (the fact of successful authentication and its details) (notifying the fact of authentication; step S24).

[0174] Subsequently, a modification according to the first embodiment will be described.

[0175] <Modification 1 according to the first embodiment> The user may select a service provider using a predetermined code. For example, an administrative code that enables the user to easily specify a service selector from among a large number of service providers may be used. For example, when the user selects a predetermined icon in the list of icons shown in FIG. 10, the control server 10 displays a GUI that requests input of an administrative code. The control server 10 treats the service provider corresponding to the administrative code input by the user as the service provider selected by the user.

[0176] Alternatively, the control server 10 may treat the administrative code input by the user as if it were a password. Specifically, when the user selects a service provider, the control server 10 requests the user to input the administrative code of the selected service provider. If the administrative code input by the user matches the predetermined administrative code of the selected service provider, the control server 10 may accept the selection of the service provider by the user. In other words, if the above two administrative codes do not match, the control server 10 rejects the selection of the service provider by the user.

[0177] <Modification 2 according to the first embodiment> In the above-described embodiment, when a user registers, the service provider (service server 20) has described the case where the user is identified using personal identifying information. However, the selection of the user may be made using an ID (hereinafter referred to as an individual ID) by which the service provider manages the user (customer).

[0178] Specifically, when a user selects a service provider, the control server 10 transmits a redirect URL (Uniform Resource Locator) embedded with the system ID of the user to the terminal 40. The redirect URL is a URL for logging in to the portal site (account) of the service provider selected by the user.

[0179] When the user logs in to the login page of the service provider according to the received redirect URL, the service server 20 acquires the individual ID (login ID) of the user and the system ID embedded in the redirect URL.

[0180] The service server 20 searches the user management database using the acquired individual ID and identifies the corresponding entry (user). The service server 20 stores the system ID in the identified entry.

[0181] In this way, user registration may be realized by using a redirect URL embedded with a system ID.

[0182] As described above, in the authentication system according to the first embodiment, the original biometric information stored in the user's terminal 40 is provided to the service server 20 of the service provider selected by the user. The service server 20 generates registration authentication information from the original biometric information of the user, and stores the generated registration authentication information in association with the business information, thereby enabling the service provider to provide services using biometric authentication to the user. When the user receives a biometric authentication service from the service provider, the service server 20 transmits an authentication success notification to the user's terminal 40 via the control server 10. In response to the reception of the authentication success notification, the terminal 40 pops up a notification indicating that biometric authentication has been performed by the service provider, or displays a list of past authentication results. The user can verify whether unauthorized biometric authentication has been performed based on the pop-up notification or the list display of the authentication history. In other words, the user can discover unauthorized biometric authentication based on the pop-up notification or the list display of the authentication history.

[0183] Subsequently, the hardware of each device constituting the authentication system will be described. FIG. 22 is a diagram showing an example of the hardware configuration of the control server 10.

[0184] The control server 10 can be configured by an information processing device (so-called computer) and has the configuration exemplified in FIG. 22. For example, the control server 10 includes a processor 311, a memory 312, an input / output interface 313, a communication interface 314, and the like. The components such as the processor 311 are connected by an internal bus or the like and are configured to be communicable with each other.

[0185] However, the configuration shown in FIG. 22 is not intended to limit the hardware configuration of the control server 10. The control server 10 may include hardware not shown, or may not include the input / output interface 313 if necessary. Also, the number of components such as the processor 311 included in the control server 10 is not intended to be limited to the example shown in FIG. 22. For example, a plurality of processors 311 may be included in the control server 10.

[0186] The processor 311 is a programmable device such as, for example, a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a DSP (Digital Signal Processor), etc. Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array), an ASIC (Application Specific Integrated Circuit), etc. The processor 311 executes various programs including an operating system (OS; Operating System).

[0187] The memory 312 is, for example, a RAM (Random Access Memory), a ROM (Read Only Memory), an HDD (Hard Disk Drive), an SSD (Solid State Drive), etc. The memory 312 stores an OS program, an application program, and various data.

[0188] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display or the like. The input device is a device that accepts user operations such as, for example, a keyboard and a mouse.

[0189] The communication interface 314 is a circuit, a module, etc. that communicates with other devices. For example, the communication interface 314 includes a NIC (Network Interface Card) or the like.

[0190] The functions of the control server 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. Further, the program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory one such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. Further, the above program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the above processing module may be realized by a semiconductor chip.

[0191] Note that the service server 20, the authentication terminal 30, the terminal 40, etc. can also be configured by an information processing apparatus in the same manner as the control server 10, and the basic hardware configuration is the same as that of the control server 10, so the description thereof is omitted. For example, the authentication terminal 30 may be provided with a camera device for photographing an authentication target person.

[0192] The control server 10, which is an information processing apparatus, is equipped with a computer, and the functions of the control server 10 can be realized by causing the computer to execute a program. Further, the control server 10 executes the control method of the control server 10 according to the program. Similarly, the terminal 40, which is an information processing apparatus, is equipped with a computer, and the functions of the terminal 40 can be realized by causing the computer to execute a program. Further, the terminal 40 executes the control method of the terminal 40 according to the program.

[0193] [Modification Example] Note that the configuration, operation, etc. of the authentication system described in the above embodiment are examples and are not intended to limit the configuration of the system.

[0194] In the above embodiment, the selection of service providers by users and the provision of original biometric information (opt-in) associated with such selection were described. As shown in FIG. 10, the control server 10 and the terminal 40 enable users to identify the information of the service providers for which opt-in has been performed by checking the icons of the service providers. The control server 10 and the terminal 40 may also enable opt-out, which deletes the registration authentication information from the opt-in service providers. In this case, in FIG. 10, when the control server 10 selects a service provider that has been selected by the user (the opt-in service provider), the control server 10 transmits a user registration cancellation request including the user's system ID to the service server 20 of the selected service provider. The service server 20 deletes the registration authentication information and the like of the user corresponding to the system ID.

[0195] If the service server 20 (authentication unit 304) fails to determine whether service provision is possible using the business information, the fact of the failure may be notified to the person to be authenticated (the person to be authenticated identified by the collation process). In that case, the authentication unit 304 may also notify the person to be authenticated of the cause of the authentication failure. For example, the authentication unit 304 may notify the person to be authenticated of reasons such as "no permission to enter the office", "failed payment by credit card", and "ticket is invalid". In this case, the authentication unit 304 transmits an authentication failure notice including the system ID of the person to be authenticated and the reason for the authentication failure to the control server 10. The control server 10 identifies the terminal 40 of the person to be authenticated using the system ID and transmits the authentication failure notice to the identified terminal 40. Upon receiving the authentication failure notice, the terminal 40 notifies the user of the reason for the authentication failure. For example, the terminal 40 notifies the user of the reason for the authentication failure by a pop-up notice as shown in FIG. 23. Alternatively, the terminal 40 may generate an authentication history using the authentication failure notice. In this case, the terminal 40 may display the cause at the time of authentication failure as shown in FIG. 24 according to the user's operation.

[0196] In the above-described embodiment, the operation of the authentication system was described by taking a person's "face" as an example of biometric information. However, the authentication system disclosed in the present application can also use other types of biometric information. For example, data having unique physical characteristics of an individual such as fingerprint, voiceprint, vein, retina, and iris pattern of the pupil may be used. That is, the biometric information of the user may be any information that includes the physical characteristics of the user as information.

[0197] Each time the user terminal 40 receives a request for providing the original from the control server 10, the user may be asked to give consent to transmit the original biometric information (for example, a face image) to the service provider. Specifically, when receiving the request for providing the original, the service selection unit 504 of the terminal 40 uses a GUI or the like to obtain whether the original biometric information (for example, a face image) can be provided. When the consent of the user regarding the provision of the original biometric information is obtained, the service selection unit 504 transmits the original biometric information stored internally to the control server 10.

[0198] In the above-described embodiment, the case where the account management database is configured inside the control server 10 has been described. However, the database may be constructed in an external database server or the like. That is, some functions of the control server 10 may be implemented in another server. More specifically, any device included in the system such as the "service selection control unit (service selection control means)" described above may be implemented.

[0199] The form of data transmission and reception between the devices (control server 10, service server 20, authentication terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Between these devices, biometric information and the like are transmitted and received. In order to appropriately protect these pieces of information, it is desirable that encrypted data is transmitted and received.

[0200] In the flowcharts (flowcharts, sequence diagrams) used in the above description, a plurality of steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order of the description. In the embodiments, for example, the order of the illustrated steps can be changed within a range that does not substantially affect the content, such as executing each process in parallel.

[0201] The above embodiments have been described in detail for the purpose of facilitating understanding of the present disclosure, and it is not intended that all the configurations described above are necessary. Also, when a plurality of embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace a part of the configuration of an embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of an embodiment. Furthermore, it is possible to add, delete, or replace other configurations for a part of the configuration of an embodiment.

[0202] From the above description, the industrial applicability of the present invention is clear, but the present invention is preferably applicable to an information processing system that provides a biometric authentication service and the like.

[0203] Some or all of the above embodiments may be described as follows in the appended claims, but are not limited thereto. [Appendix 1] A receiving means for receiving an authentication success notification from a service server of a service provider selected by a user from among a plurality of service providers and having succeeded in biometric authentication of the user; An authentication history control means for controlling the history of successful biometric authentication in the service provider in response to the reception of the authentication success notification; A terminal comprising the above. [Appendix 2] The authentication success notification includes detailed information on the authentication process successfully performed by the service provider and the status of the authentication information used by the service provider for biometric authentication. The authentication history control means generates a history regarding the biometric authentication of the user by storing the detailed information on the authentication process and the status of the authentication information. The terminal according to Appendix 1. [Appendix 3] The authentication history control means is the terminal according to Appendix 2 that displays a message including the detailed information of the authentication process and the status of the authentication information every time the authentication success notification is received. [Appendix 4] The authentication history control means is the terminal according to Appendix 3 that displays the stored history of biometric authentication in response to a predetermined operation of the user. [Appendix 5] A storage means for storing original biometric information that is the original of the authentication information used for the biometric authentication; A transmission means for transmitting the stored original biometric information to the service server of the service provider selected by the user via the control server in response to a request from the control server that manages the biometric authentication for each of the plurality of service providers; The terminal according to any one of Appendices 2 to 4, further comprising: [Appendix 6] The terminal according to Appendix 5, wherein the original biometric information is a face image, and the authentication information is a feature amount generated from the face image. [Appendix 7] A service server of a service provider selected by a user from among a plurality of service providers and that has succeeded in the user's biometric authentication; A terminal possessed by the user; comprising: The terminal: A receiving means for receiving an authentication success notification from the service server; An authentication history control means for performing control regarding the history of biometric authentication that has succeeded in the service provider in response to the reception of the authentication success notification; A system comprising: [Appendix 8] Further comprising a control server that manages the biometric authentication for each of the plurality of service providers, The receiving means receives the authentication success notification via the control server. The system according to Appendix 7. [Appendix 9] At the terminal, A service provider selected by a user from among a plurality of service providers, which has successfully authenticated the user, receives an authentication success notification from the service server of the service provider, A method for controlling a terminal that, in response to receiving the authentication success notification, controls the history of successful biometric authentication in the service provider. [Appendix 10] On a computer mounted on a terminal, A process of receiving an authentication success notification from a service server of a service provider selected by a user from among a plurality of service providers, which has successfully authenticated the user, and A process of controlling the history of successful biometric authentication in the service provider in response to receiving the authentication success notification, and A computer-readable storage medium that stores a program for causing the above to be executed.

[0204] It should be noted that each disclosure of the above-cited prior art documents is incorporated herein by reference. As described above, embodiments of the present invention have been described, but the present invention is not limited to these embodiments. It will be understood by those skilled in the art that these embodiments are merely illustrative and that various modifications can be made without departing from the scope and spirit of the present invention. That is, the present invention naturally includes various modifications and corrections that can be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical idea.

Explanation of Reference Numerals

[0205] 10 Control server 20 Service server 30 Authentication terminal 40 Terminal 100 Terminal 101 Receiving means 102 Authentication history control means 201 Communication control unit 202 Account management unit 203 Operator management unit 204 Service selection control unit 205 User registration control unit 206 Memory Unit 301 Communication Control Unit 302 Business Information Management Unit 303 User Registration Control Unit 304 Authentication Unit 305 Memory Unit 311 Processor 312 Memory 313 Input / Output Interface 314 Communication Interface 401 Communication Control Unit 402 Provided Service Control Unit 403 Authentication Request Unit 404 Memory Unit 501 Communication Control Unit 502 Account Generation Control Unit 503 Original Information Acquisition Unit 504 Service Selection Unit 505 Authentication History Control Unit 506 Memory Unit

Claims

1. A computer installed in a terminal, receiving, from a service server of a service provider selected by a user from among a plurality of service providers and having succeeded in biometric authentication of the user, information regarding the state of authentication information used by the service provider for biometric authentication, a receiving process; controlling, according to the received information, the state of the authentication information in the service provider to be viewable by the user, a control process; storing original biometric information that is the original of the authentication information used for the biometric authentication, a storage process; transmitting, in response to a request from a control server that manages biometric authentication for each of the plurality of service providers, the stored original biometric information to the service server of the service provider selected by the user via the control server, a transmission process; A program for causing the above to be executed.

2. The control process displays, each time information regarding the state of the authentication information is received, a message including detailed information on the authentication process in which the service provider has succeeded and the state of the authentication information. The program according to claim 1.

3. An authentication means for performing biometric authentication of a user; A transmission means for transmitting, when the biometric authentication of the user is successful, information regarding the state of authentication information used for the biometric authentication to a terminal possessed by the user; Comprising: The transmission means: A service server that transmits detailed information on the authentication process and the state of the authentication information to the terminal each time the biometric authentication is successful.

4. In response to a request from a control server that manages biometric authentication for each of a plurality of service providers, a terminal possessed by the user transmits original biometric information that is the original of the authentication information used for the biometric authentication and stored in the terminal to the control server, The service server according to claim 3, further comprising a receiving means for receiving the original biometric information from the control server.

5. The authentication information is set to be retained or deleted according to the service provided to the user. The service server according to claim 4.

6. In a terminal, receiving, from a service server of a service provider selected by a user from among a plurality of service providers and having succeeded in biometric authentication of the user, information regarding the state of authentication information used by the service provider for biometric authentication, Control the state of the authentication information in the service provider so that the user can view it according to the received information. Store the original biometric information that is the original of the authentication information used for biometric authentication. A control method for a terminal that, in response to a request from a control server that manages biometric authentication for each of the plurality of service providers, transmits the stored original biometric information to the service server of the service provider selected by the user via the control server.

7. In a service server, Execute biometric authentication of a user. A control method for a service server that, when the biometric authentication of the user is successful, transmits information regarding the state of the authentication information used for the biometric authentication to a terminal possessed by the user. A control method for a service server that transmits detailed information on the authentication process and the state of the authentication information to the terminal every time the biometric authentication is successful.

8. A program for causing a computer mounted on a service server to Execute a process for performing biometric authentication of a user, and When the biometric authentication of the user is successful, execute a process for transmitting information regarding the state of the authentication information used for the biometric authentication to a terminal possessed by the user. A program for causing the computer to Every time the biometric authentication is successful, execute a process for transmitting detailed information on the authentication process and the state of the authentication information to the terminal. ​

Citation Information

Patent Citations

  • Authentication device

    JP2006146456A

  • Personal authentication device and method

    JP2009217598A

  • Biometric authentication system, authentication client terminal, and biometric authentication method

    JP2009289253A

  • Network service providing system, network service providing method, and program

    JP2015111329A

  • Information processing device

    WO2022092266A1