Face authentication management server and face authentication management method
The face authentication management server addresses the lack of comprehensive user information management in existing systems by integrating collation group and user information management, enabling secure and efficient face authentication across multiple devices in facilities.
Patent Information
- Application Number
- JP2024005480
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-01-17
- Publication Date
- 2025-07-28
- Estimated Expiration
- 2039-03-04
AI Technical Summary
Existing face authentication systems primarily focus on managing registered person's face images without considering the comprehensive management of various types of information related to facility users' events and behaviors.
A face authentication management server connected to a management terminal via a network, which accumulates and manages information related to face authentication, including collation group information, user management, and generates screens for confirming or changing settings related to face authentication devices, enabling appropriate management of user information.
The system effectively manages collation group information and user information for face authentication devices, ensuring appropriate management and identification of users across multiple devices, facilitating secure and efficient face authentication in various facility events.
Smart Images

Figure 0007713651000001 
Figure 0007713651000002 
Figure 0007713651000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a face authentication management server and a face authentication management method for accumulating and managing information related to face authentication such as image data obtained by photographing a target person.
Background Art
[0002] Conventionally, as a technique related to face authentication, at least a feature quantity extraction means, a registered person feature quantity storage means, and a collation means are configured in a first device, and a registered person face image storage means is stored in a place with a higher security level than the first device. It is configured by a second device, and when the first device needs to use the face image of the registered person, a data communication path is constructed between the first device and the second device, and the face image of the registered person is obtained from the second device through the data communication path. The data of the face image of the registered person is used on the work memory without being stored in a non-volatile recording medium, and even if the face verification system is stolen or attacked, it is possible to protect the face image of the registered person as much as possible (see Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, for example, when performing face authentication of a facility user, it is desirable to apply face authentication to various events (for example, entering and leaving the facility, entering and exiting a room, settlement for services received or purchased items in the facility, etc.) caused by the user's behavior in the facility and effectively utilize the information related to the event.
[0005] However, in the above prior art, only the proper management of the registered person's face image is intended, and no consideration is given to a mechanism for properly managing various types of information related to the face authentication of facility users.
[0006] Therefore, the main object of the present disclosure is to appropriately manage various types of information related to the face authentication of facility users by a face authentication management server connected to a management terminal via a network.
Means for Solving the Problem
[0007] The face authentication management server of the present disclosure is connected to a management terminal via a network, and prior to face authentication for an event based on a user's behavior, Associate a face authentication device that executes face authentication of the user with a face matching server, and is a face authentication management server that accumulates and manages management information related to the face authentication of the user, collation group information that is set according to the installation location of each of a plurality of face authentication devices and that identifies one or more of the face matching servers that request face authentication of the user comprising a collation group management unit that manages settings related to, a user management unit that integrates and manages first information including a face image for registration of the user acquired by the user's registration device and second information other than the face image and used for identifying the user, a first management screen for confirming or changing the collation group information for each face authentication device managed by the collation group management unit in response to a request from the management terminal, and a second management screen for confirming or changing the first information and the second information managed by the user management unit, and the screen generation unit is configured to generate the second management screen including an input unit for the collation group information corresponding to the face authentication device for which the user undergoes face authentication as the first information.
[0008] Also, the face authentication management method of the present disclosure is a face authentication management method for accumulating and managing management information related to the face authentication of a user prior to face authentication for an event based on the user's behavior by a face authentication management server connected to a management terminal via a network, Associate a face authentication device that executes face authentication of the user with a face matching server, and wherein collation group information that is set according to the installation location of each of a plurality of face authentication devices and that identifies one or more of the face matching servers that request face authentication of the user Manage the settings related thereto, integrate and manage the first information including the face image for user registration acquired by the user's registration device and the second information other than the face image and used for identifying the user, and generate a first management screen for checking or changing the collation group information for each face authentication device and a second management screen for checking or changing the first information and the second information in response to a request from the management terminal. The configuration is such that the confirmation or change of the collation group information corresponding to the face authentication device for which the user undergoes face authentication is performed from the second management screen.
Effect of the Invention
[0009] According to the present disclosure, a face authentication management server connected to a management terminal via a network manages the settings related to the collation group information for each of a plurality of face authentication devices, checks or changes the collation group information corresponding to the face authentication device for which the user undergoes face authentication, and can appropriately manage the collation group information necessary for the face authentication of the facility users. Identify one or more face matching servers that request face authentication of the user
Brief Description of the Drawings
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Figure 23
Figure 24
Figure 25
Figure 26
Mode for Carrying Out the Invention
[0011] The first invention made to solve the above problem is a system connected to a management terminal via a network, and prior to face authentication for an event based on a user's action, Associate a face authentication device that executes face authentication of the user with a face matching server, and A face authentication management server that accumulates and manages management information related to face authentication of the user, collation group information that is set according to the installation location of each of a plurality of face authentication devices and that identifies one or more of the face matching servers that request face authentication of the user a matching group management unit that manages settings related to the facial image of the user for registration acquired by the user's registration device and second information other than the facial image and used to identify the user; and a screen generation unit that generates, in response to a request from the management terminal, a first management screen for confirming or changing the matching group information for each facial recognition device managed by the matching group management unit, and a second management screen for confirming or changing the first information and the second information managed by the user management unit, wherein the screen generation unit is configured to generate the second management screen including an input section for the matching group information corresponding to the facial recognition device with which the user will undergo facial authentication, as the first information.
[0012] According to this, a face recognition management server connected to the management terminal via a network can manage the face recognition status of multiple face recognition devices. Identify one or more face matching servers that request face authentication of the user Settings related to matching group information can be managed, and matching group information corresponding to the facial recognition device through which the user will undergo facial recognition can be confirmed or changed, thereby enabling appropriate management of matching group information required for facial recognition of facility users.
[0013] In a second aspect of the present invention, the screen generation unit includes an input unit for affiliation information corresponding to business card information of the user as the second information. Second management screen The configuration is to generate the following.
[0014] This makes it possible to check and change the affiliation information corresponding to the user's business card information.
[0015] In a third aspect of the present invention, the screen generation unit includes an input unit for inputting an effective date for the first information or the second information. Second management screen The configuration is to generate the following.
[0016] According to this, it becomes possible to input the effective date for the first information or the second information regarding the facility user.
[0017] Further, in the fourth invention, the screen generation unit includes an input unit for the invalid date for the first information or the second information, and generates the following. Second management screen It is configured to generate.
[0018] According to this, it becomes possible to input the invalid date for the first information or the second information regarding the facility user.
[0019] Further, in the fifth invention, prior to face authentication for an event based on the behavior of a user by a face authentication management server connected to a management terminal via a network, Associate a face authentication device that executes face authentication of the user with a face matching server, and A face authentication management method for accumulating and managing management information regarding the face authentication of the user, which manages settings regarding, integrates and manages first information including a face image for registration of the user acquired by the registration device of the user and second information other than the face image and used for identifying the user, and in response to a request from the management terminal, generates a first management screen for confirming or changing the collation group information for each face authentication machine and a second management screen for confirming or changing the first information and the second information, and is configured to confirm or change the collation group information corresponding to the face authentication machine for which the user undergoes face authentication from the second management screen. collation group information that is set according to the installation location of each of a plurality of face authentication devices and that identifies one or more of the face matching servers that request face authentication of the user According to this, by a face authentication management server connected to a management terminal via a network, settings regarding collation group information for each of a plurality of face authentication machines are managed, confirmation or change of the collation group information corresponding to the face authentication machine for which the user undergoes face authentication is performed, and the collation group information necessary for face authentication of the facility user can be appropriately managed.
[0020] According to this, by a face authentication management server connected to a management terminal via a network, for each of a plurality of face authentication machines Identify one or more face matching servers that request face authentication of the user Settings regarding collation group information are managed, confirmation or change of the collation group information corresponding to the face authentication machine for which the user undergoes face authentication is performed, and the collation group information necessary for face authentication of the facility user can be appropriately managed.
[0021] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.
[0022] Figure 1 is an overall configuration diagram of the face recognition system according to this embodiment.
[0023] This face recognition system includes a face recognition device 1, a management terminal 2, a face recognition server 3 (cloud server), and a registration device 4 (face recognition registration device). The face recognition server 3 includes a face management server 5 (face recognition management server) and a face verification server 6.
[0024] The face recognition device 1, the management terminal 2, the registration device 4, the face management server 5, and the face verification server 6 are connected via a network such as the Internet. The face recognition system is constructed for each provider (operator) of the face recognition service. A plurality of face recognition devices 1 are installed at each location where face recognition is required, such as the entrance of a building or the entrance of a room. The registration device 4 is arranged at a reception counter or the like for receiving visitors to the facility. The number of face verification servers 6 provided is determined according to the number of face recognition devices 1 and the like.
[0025] The face recognition device 1 is equipped with a camera 11, and this camera 11 is used to acquire a photographed image of a user (such as a visitor to the facility or an employee in a company or store within the facility). The face recognition device 1 also has a display 12, and this display 12 is used to display the face recognition result obtained from the face verification server 6 and notify the user of the face recognition result.
[0026] The management terminal 2 is operated by the administrator of the face recognition system. It is composed of a PC, and a management application for managing the operations of the face recognition device 1, the registration device 4, the face management server 5, and the face verification server 6 is installed. With this management application, the administrator can perform various management tasks. The management application is implemented as a web application. Note that multiple administrator groups with different access rights to each piece of information in the face recognition system are set for the administrator.
[0027] The registration device 4 acquires information used for the face authentication process of the user (hereinafter referred to as authentication information). The authentication information may include not only the face images for registration of each user but also specific information other than the face images and used for identifying the user.
[0028] As the specific information, information displayed on the business card of the user, information displayed on the payment card (for example, credit card or cash card) held by the user, and information indicating the staying location of the user in the facility can be used. Note that the specific information may include information that can permanently identify the user, such as the name of the user. However, the specific information may be information that can temporarily identify the user, such as the user number assigned to the facility user, the number of the conference room (including any space where interviews are possible) used by the user in the facility, or the number of the room where the user stays in an accommodation facility or the like.
[0029] The face management server 5 centrally manages the information (including personal information) of the user. Specifically, the face management server 5 accumulates and manages the data of the face images for registration and the specific information in association with each user. The face management server 5 acquires the face images for registration and the specific information from the registration device 4 at the time of user registration. Also, the face management server 5 may acquire at least a part of the information included in the face images for registration and the specific information from the management terminal 2 (that is, the administrator).
[0030] At the time of face authentication, the face verification server 6 acquires the data of the face image for authentication of the person to be face - authenticated from the face authentication device 1, generates the face feature amount data of the person from the data of the face image, and performs face verification by comparing the face feature amount data of the person with the face feature amount data of the registered persons (registered users) stored in the device itself, and performs face authentication to determine whether the person to be authenticated is a registered person.
[0031] Also, prior to face authentication, the face verification server 6 acquires, from the face management server 5 (or the registration device 4), the data of the face image for user registration at the time of user registration, generates the face feature amount data of the user from the data of the face image, and stores it in its own device. In some cases, the face verification server 6 can also acquire the photographed image of the user from the management terminal 2 (i.e., the administrator) and obtain the data of the face image from the photographed image.
[0032] In this embodiment, the face management server 5 (face image management unit) and the face verification server 6 (face image verification unit) are assumed to exist in physically different information processing devices, but they may also exist in a single information processing device.
[0033] Also, in this embodiment, the management terminal 2 and the face management server 5 are provided, but the management terminal 2 and the face management server 5 can be configured by a single information processing device. For example, by installing a management application in the face management server 5, the face management server 5 can also serve as the management terminal 2. In addition, an administrator (for example, an employee in a company or store within a facility, etc.) whose access authority to the information of the face authentication system is limited can access the face management server 5 from his or her own information processing terminal (PC, tablet, etc.) and refer to information with a lower need for confidentiality compared to the personal information of the user (for example, information regarding meetings attended by the user described later, information regarding the user's network, etc.).
[0034] Also, in this embodiment, face feature amount verification is performed, but face verification is not limited to face feature amount verification, and a verification method applying machine learning or the like may be adopted. Furthermore, this embodiment can also be applied to biometric authentication other than face authentication.
[0035] Next, an example of an event generated by the behavior of a user of a facility to which the face authentication system is applied will be described. FIG. 2 is an explanatory diagram showing an example of an event occurring in the facility.
[0036] As shown in FIG. 2, the facility user 10 can perform an operation of registering as a facility user (i.e., registering information used for face verification processing) using the registration device 4 arranged at the reception. For registered users who revisit the facility within a predetermined period, the registration by the registration device 4 can be omitted.
[0037] In the facility, face verification is executed for each of various events (refer to the area within the two-dot chain line in FIG. 2) generated by the actions of people (including registered users) within the facility.
[0038] For example, the registered user 10 can pass through the security gate by undergoing face verification in front of the security gate that manages the passage of the user 10 within the facility. A face verification machine 1 that cooperates with the gate device 16 (i.e., controls the opening and closing state of the door portion) can be installed at the security gate.
[0039] Also, for example, the registered user 10 can enter the conference room by undergoing face verification in front of the conference room within the facility. A face verification machine 1 that cooperates with the lock device that locks the door of the conference room (i.e., controls the locking or unlocking of the door) can be arranged in front of the conference room. In a lodging facility such as a hotel, for example, instead of a conference room, a face verification machine 1 that cooperates with the lock device of the door of the room where the user stays can be installed.
[0040] Also, for example, the registered user 10 can automatically settle the usage fee of the restaurant by undergoing face verification within the restaurant in the facility. A camera 11 capable of photographing the face of the user 10 is installed in the restaurant, and the face verification machine 1 cooperates with a settlement terminal device (or settlement system) used for paying the usage fee in the restaurant.
[0041] For example, the registered user 10 can have the usage fees for the gym in the facility automatically settled by undergoing face authentication at the gym. A camera 11 capable of photographing the face of the user is installed in the gym, and the face authentication device 1 is linked with a settlement terminal device (or settlement system) used for paying the usage fees at the gym.
[0042] Note that the events occurring within the facility are not limited to the above examples, and can include various events such as the settlement of usage fees at the facility's parking lot, the settlement of usage fees for the laundry service within the facility, the settlement of usage fees for the bathhouse within the facility, and so on.
[0043] Also, for example, when an employee of a company providing services within the facility is registered as a user, by arranging the face authentication device 1 at the entrance and exit of the facility's backyard (such as a warehouse, workplace, etc.), it becomes possible to ensure security in the backyard.
[0044] Next, the collation group will be described. FIG. 3 is an explanatory diagram showing the outline of the collation group.
[0045] In this embodiment, according to the installation location of the face authentication device 1 where the user undergoes face authentication, etc., the users are grouped and a collation group is set for each user. Also, similar to the users, according to the installation location of the face authentication device 1, etc., the face authentication devices 1 are grouped and a collation group is set for each face authentication device 1. Furthermore, the face collation server 6 corresponding to the face authentication device 1, that is, the face collation server 6 that receives face collation inquiries (requests) from the face authentication device 1, is grouped in the same way as the face authentication device 1, and a collation group is set for each face collation server 6.
[0046] For example, in a face recognition device 1 installed at the entrance of a multi-tenant building where multiple companies are located, users belonging to multiple companies undergo face recognition. On the other hand, the information of users belonging to different organizations cannot be managed in the same database. Therefore, in such a case, collation groups are formed for each of the multiple companies, and the registered information of users is stored in units of collation groups. The face recognition device 1 makes a face collation inquiry to the face collation server 6 of the collation group for each company.
[0047] A user can only be authenticated by the face recognition device 1 corresponding to the collation group to which the user belongs. Therefore, even a registered user cannot be authenticated by a face recognition device 1 that does not belong to their collation group, for example, a face recognition device 1 in a building where their entry is not permitted. For example, when a user working at a certain office is seconded to another office, they cannot be authenticated by the face recognition device 1 of that office.
[0048] Next, the face collation inquiry from the face recognition device 1 to the face collation server 6 will be described. FIG. 4 is an explanatory diagram showing an overview of the face collation inquiry performed by the face recognition device 1.
[0049] The face recognition device 1 makes a face collation inquiry to the face collation server 6 belonging to the same collation group as itself, and sends a face collation request (a processing request for face recognition) to the face collation server 6 that is the inquiry destination (request destination). In addition, the face recognition device 1 holds the network address (IP address) of the face collation server 6 as collation group information, and based on this network address, makes a face collation inquiry to the face collation server 6 corresponding to the device itself.
[0050] This face recognition inquiry method includes a batch inquiry shown in FIG. 4(A), a random inquiry shown in FIG. 4(B), and a sequential inquiry (inquiry destination switching) shown in FIG. 4(C).
[0051] As shown in Fig. 4(A), in the case of a batch inquiry, the face authentication device 1 makes a batch face verification inquiry to the face verification servers 6 corresponding to each of a plurality of verification groups. For example, when the face authentication device 1 is installed at the entrance of a multi-tenant building and users of a plurality of verification groups receive face authentication, the face authentication device 1 sends a face verification request to the face verification servers 6 of each group in a batch.
[0052] In order to reduce the load on one face verification server 6, it is also possible to divide and store the face feature data of the users belonging to one verification group in a plurality of face verification servers 6. Also in this case, the face authentication device 1 makes a face verification inquiry to all the face verification servers 6 within the same verification group having different registered contents at the same time.
[0053] As shown in Fig. 4(B), in the case of a random inquiry, the face authentication device 1 randomly selects the face verification server 6 to which the face verification inquiry is to be made from among a plurality of face verification servers 6 within the same verification group. The registered contents of the plurality of face verification servers 6 are the same. That is, the same user is the verification target, and the face feature data of the same user is stored. In such an inquiry method, since the inquiries from the face authentication device 1 are distributed to each face verification server 6, the load on each face verification server 6 can be reduced, and load distribution can be achieved.
[0054] As shown in Fig. 4(C), in the case of a sequential inquiry, the face authentication device 1 sequentially selects the face verification inquiry destination from among a plurality of face verification servers 6 within the same verification group. Specifically, a sequence (priority) is assigned to the face verification servers 6, and the face authentication device 1 selects the face verification servers 6 in that sequence. If there is no response from the face verification server 6 with a higher rank, the transmission destination is switched to another face verification server 6. That is, the face authentication device 1 selects the first-ranked face verification server 6 within the verification group and requests face authentication from that face verification server 6. Then, if there is no response from the face verification server 6, the face authentication device 1 selects another face verification server 6 with the next rank within the same verification group and requests face authentication from that face verification server 6. By such control, redundancy (backup) can be achieved.
[0055] Next, the face verification unit will be described. FIG. 5 is an explanatory diagram showing an overview of the face verification unit.
[0056] The face verification server 6 can be provided with a plurality of face verification units for performing face verification. This face verification unit has a face verification process for executing a face verification program and a face verification database in which user information (face feature amount data) to be compared for face verification is registered.
[0057] This face verification unit is provided for each verification group and performs face verification in response to a face verification request from the face recognition device 1 belonging to the verification group. Therefore, one face verification server 6 can correspond to a plurality of verification groups.
[0058] Here, the face recognition device 1 holds the network address (IP address) of the face verification server 6 as verification group information, and based on this network address, it can make a face verification inquiry to the face verification server 6 corresponding to its own device. Further, in the present embodiment, the face recognition device 1 holds the network address (IP address) of the face verification unit unit, and based on this network address, it can make a face verification inquiry to the face verification unit corresponding to its own device.
[0059] Also, since the face verification database is provided for each verification group, the face feature amount data of the user can be stored in units of verification groups. The face verification process executes a verification process between the face feature amount data stored in group units and the face feature amount data generated from the face image data acquired from the face recognition device 1 of the same group.
[0060] Here, there are various modes for the correspondence relationship between the face recognition device 1 and the face verification unit.
[0061] In the example shown in Fig. 5(A), one face verification unit of the verification group to which the face authentication device 1 belongs is provided in the face verification server 6, and the face authentication device 1 and the face verification server 6 correspond one-to-one.
[0062] In the example shown in Fig. 5(B), the face authentication device 1 and the face verification server 6 correspond one-to-one, but two face verification units of the verification group to which the face authentication device 1 belongs are provided in the face verification server 6. In this case, in the case of the face authentication device 1 installed at the entrance of a multi-tenant building, information of users belonging to different organizations (for example, user A and user B) can be managed in different verification databases.
[0063] In the example shown in Fig. 5(C), the face authentication device 1 and the face verification server 6 correspond one-to-two, and the face authentication device 1 makes a face verification inquiry (user verification request) to two face verification servers 6. In this case, by providing two or more face verification units that perform face verification with the same face verification unit, that is, the face feature amount data of the same user, in different face verification servers 6, load distribution and life-and-death response of the face verification server 6 can be achieved.
[0064] Next, the schematic configuration of the face authentication device 1 will be described. Fig. 6 is a block diagram showing the schematic configuration of the face authentication device 1.
[0065] The face authentication device 1 includes a camera 11 (face image acquisition unit), a display 12 (display unit), a communication unit 13 (transmission unit, reception unit), a storage unit 14, a control unit 15, and a control signal transmission unit 17.
[0066] The camera 11 constantly photographs a predetermined photographing area, and when a person enters the photographing area, the person is photographed, and a photographed image of a face authentication target person (including registered users) can be obtained. For power saving, a human sensor (not shown) may be provided to detect the arrival of a person and activate the camera 11.
[0067] The display 12 displays the progress and results of face authentication, allowing the person undergoing face authentication to confirm them. Additionally, a speaker may be provided as an output unit to output the authentication result of the subject, and the face authentication result may be notified audibly. Also, depending on the installation location of the face authentication device 1 (for example, when installing the face authentication device 1 at a security gate), the display 12 can be omitted.
[0068] The communication unit 13 communicates with the face verification server 6 via a network. In this embodiment, face image data is transmitted to the face verification server 6. Also, the authentication result of the user is received from the face verification server 6. Further, the communication unit 13 communicates with the face management server 5 via a network. In this embodiment, collation group information and the like are received from the face management server 5.
[0069] The storage unit 14 stores data of the captured image (face image) of the user, collation group information, a control program executed by the processor constituting the control unit 15, and the like.
[0070] The control unit 15 includes a startup processing unit 21, a face image extraction unit 22, a face verification request unit 23, an authentication result notification unit 24, an authentication result adjustment unit 25 (history information generation unit), and an operation status monitoring unit 26. This control unit 15 is constituted by a processor, and each part of the control unit 15 is realized by the processor executing the program stored in the storage unit 14.
[0071] The startup processing unit 21 acquires collation group information from the face management server 5 when the face authentication device 1 starts up and stores it in the storage unit 14. Note that the acquisition of the collation group information is not limited to this, and the collation group information may be distributed from the face management server 5 to the target face authentication device 1 in accordance with an update of the collation group information or the like.
[0072] The face image extraction unit 22 acquires a captured image of the person to be face - authenticated from the camera 11 (camera image capture), detects the face of the person from the captured image (face detection), determines whether the size of the detected face is appropriate (face size check), cuts out the face area from the captured image (face cutting), and can obtain data of the face image (face image for authentication) of the target person. Note that the face image data may be only the data of the image of the face area, or may be a combination of the data of the captured image (image of a predetermined capture area) and the position information (face frame information) of the face area on the data of the captured image.
[0073] The face matching request unit 23 transmits a face matching request to the face matching server 6 whose matching group matches the own device through the communication unit 13.
[0074] The authentication result notification unit 24 notifies the user of the face authentication result by displaying the face authentication result acquired from the face matching server 6 by the communication unit 13 on the display 12.
[0075] The authentication result adjustment unit 25 performs control for cooperation with the external device 16 based on the face matching result of the user acquired from the face matching server 6. As the external device 16, for example, a gate device that manages the passage of users in a facility (see Figure 2), a door lock device that manages the entry and exit of users to and from a conference room or a predetermined area in the facility, and a settlement terminal device for making payments for services, purchases, etc. received by the user in the facility can be used. Also, when the authentication result adjustment unit 25 cooperates with the door lock device of the conference room, it can generate information on the entry history associating a plurality of users who entered the conference room.
[0076] The face authentication device 1 and the external device 16 are directly connected by a communication cable or the like, or are communicably connected via a known network. The authentication result adjustment unit 25 is configured by a connection application, and can notify the face matching result of the user to a server of an external system including the external device 16.
[0077] The operation status monitoring unit 26 monitors the operation status of its own device and notifies the face management server 5 of the operation status of its own device.
[0078] The control signal transmission unit 17 transmits a control signal for controlling the operation of the external device 16 to the external device 16.
[0079] Next, the management terminal 2 will be described. FIG. 7 is a block diagram showing the schematic configuration of the management terminal 2.
[0080] The management terminal 2 includes a communication unit 31, a display 32 (display unit), an input device 33 (operation unit), a storage unit 34, and a control unit 35.
[0081] The communication unit 31 communicates with the face management server 5 via a network. In this embodiment, the communication unit 31 receives screen information and the like from the face management server 5 and transmits the operation information of the administrator corresponding thereto to the face management server 5.
[0082] The display 32 displays various screens. The input device 33 is a mouse, a keyboard, or the like, and operates on the screen displayed on the display 32.
[0083] The storage unit 34 stores a program (management application) executed by a processor constituting the control unit 35 and the like.
[0084] The control unit 35 includes a GUI control unit 38. This control unit 35 is composed of a processor, and each part of the control unit 35 is realized by executing a program (management application) stored in the storage unit 34 by the processor.
[0085] The GUI control unit 38 displays various operation screens distributed from the face management server 5 on the display 32. Also, in response to an input operation by the administrator using the input device 33, it acquires input information and performs screen control. In the present embodiment, the GUI control unit 38 performs display input control related to a screen related to login, specifically, a login screen. Also, the GUI control unit 38 performs display input control related to a screen related to user management, specifically, a screen related to registration (individual registration, batch registration), reference, update, and deletion of user information. Also, the GUI control unit 38 performs display input control related to a screen related to collation group management, specifically, a screen related to registration (individual registration, batch registration), reference, update, and deletion of collation groups. Also, the GUI control unit 38 performs display input control related to a screen related to authentication device management, specifically, a screen related to registration, reference, update, and deletion of the association between authentication devices and collation groups. Also, the GUI control unit 38 performs display input control related to a reference screen for authentication logs (face authentication history information).
[0086] Next, the schematic configuration of the registration device 4 will be described. FIG. 8 is a block diagram showing the schematic configuration of the registration device 4.
[0087] The registration device 4 includes a camera 41A for face photography and a camera 41B for information acquisition (personal information acquisition unit), a display 42 (display unit), a communication unit 43, a storage unit 44, and a control unit 45.
[0088] The camera 41A for face photography can acquire a photographed image of a user by photographing the face of a user who has stopped by the facility reception, for example.
[0089] The camera 41B for information acquisition can obtain a photographed image of a business card by photographing the business card presented by the user. However, the camera 41B for information acquisition is not limited to business cards, and can also photograph the user's belongings on which information capable of identifying the user is displayed (for example, the user's payment card, a card on which the information of the user's accommodation destination is described, etc.) and obtain the photographed image thereof. The registration device 4 can be provided with a mounting table (mounting surface) 116 (see FIG. 14(C)) on which the user can easily place a business card or the like within the photographing area of the camera 41B in order to surely perform the photographing of the camera 41B for information acquisition.
[0090] Note that in the registration device 4, one camera may be configured as the cameras 41A and 41B for face photographing and information acquisition. Also, regarding the photographing timing of the camera 41A for face photographing and the camera 41B for information acquisition, it can be determined by the operation of the user in the registration device 4 (for example, pressing the photographing button). Alternatively, the reception staff of the facility may determine the photographing timing.
[0091] Furthermore, the registration device 4 can also be provided with an information reading device (for example, an RFID reader) capable of wirelessly reading the user's specific information from an information recording medium (for example, an RFID tag) held by the user.
[0092] The display 42 can display the registration procedure of authentication information (including the user's personal information) to the user (see FIGS. 14(A)-(F)). Also, by attaching a speaker to the display 42, the registration procedure or the like may be guided to the user by voice. Also, by configuring the display 42 with a touch panel, it becomes possible to acquire the information input by the user through a touch operation.
[0093] The communication unit 43 communicates with the face management server 5 via a network. In the present embodiment, the face image data and the specific information are transmitted to the face management server 5.
[0094] The memory unit 44 stores data of the user's captured images (face images), the user's specific information, and control programs executed by the processor that constitutes the control unit 45, etc.
[0095] The control unit 45 includes a face image extraction unit 46, a specific information acquisition unit 47, a registration request unit 48, a GUI control unit 49, and an operation status monitoring unit 50. This control unit 45 is constituted by a processor, and each part of the control unit 45 is realized by the processor executing the program stored in the memory unit 44.
[0096] The face image extraction unit 46 can acquire a captured image of the person to be face - authenticated from the camera 41A for face capture, detect the face of the person from the captured image, and determine whether the user's face image has been appropriately acquired. Also, when the acquired face image is inappropriate, the face image extraction unit 46 can display a message prompting the user to retake the photo on the display 42. Note that the face image extraction unit 46 may have functions of camera image capture, face detection, face size check, and face cropping, similar to the face image extraction unit 22 of the above - mentioned face authentication device 1.
[0097] The specific information acquisition unit 47 has an OCR (Optical Character Recognition) function and generates specific information (here, business card description information) from characters, symbols, etc. extracted from the captured image of the camera 41B for information acquisition.
[0098] The registration request unit 48 sends a registration request for the user to the face management server 5 through the communication unit 43.
[0099] The GUI control unit 49 displays various guidance screens for the user distributed from the face management server 5 on the display 42. Also, in response to the user's input operation using the input function of the display 42 (here, a touch panel), it acquires input information and performs screen control.
[0100] The operation status monitoring unit 50 monitors the operation status of the self - device and notifies the face management server 5 of the operation status of the self - device.
[0101] Next, the schematic configuration of the face management server 5 will be described. FIG. 9 is a block diagram showing the schematic configuration of the face management server 5.
[0102] The face management server 5 includes a communication unit 51, a storage unit 52, and a control unit 53.
[0103] The communication unit 51 communicates with the management terminal 2 via a network. Also, the communication unit 51 communicates with the face authentication device 1 via a network. Also, the communication unit 51 communicates with the registration device 4. Also, the communication unit 51 communicates with the face verification server 6.
[0104] The storage unit 52 stores a face information database, a database regarding the association information between the face authentication device 1 and the verification group, a database regarding the association information between the face verification server 6 and the verification group, an administrator access log, a control program executed by the processor constituting the control unit 53, and the like.
[0105] In the face information database, registration face images are accumulated as information regarding each registered user. Also, in the face information database, specific information of each user is accumulated in association with the registration face images. Also, verification groups and the like are registered in the face information database. Note that the face images and specific information of users may be stored in an encrypted state for privacy protection. Further, in the face information database, a part of the face images and specific information of users may be stored in a state where they are replaced with anonymized information.
[0106] The control unit 53 includes an administrator access management unit 61, a user management unit 62, a matching group management unit 63, a device management unit 64, a face matching server management unit 65, a face information management unit 66, a database management unit 67, an operation status monitoring unit 68, an authentication log presentation unit 69, an encryption unit 70, an anonymization information generation unit 80, and an image generation unit 90. This control unit 53 is composed of a processor, and each part of the control unit 53 is realized by the processor executing a program stored in the storage unit 52. Each part of the control unit 53 is configured as a Web API (Web Application Programming Interface).
[0107] The administrator access management unit 61 permits or rejects the access (login) of an administrator who accesses the own device from the management terminal 2 according to the access authority of the administrator. The administrator access management unit 61 monitors the status of access (login) from the management terminal 2 to the face management server 5 and the face matching server 6, and when detecting access from the management terminal 2, records information regarding the access (such as the accessing administrator and the date and time) as an administrator access log (history information). Thereby, the face management server 5 provides the administrator access log to the management terminal 2 in response to a request for reference to the administrator access log from the management terminal 2, and the administrator can view the administrator access log.
[0108] In addition, the administrator access management unit 61 manages the access from the management terminal 2 to the own device, and when an administrator operates the management terminal 2 to access the own device, accumulates the information at that time in the storage unit 52 as an administrator access log (history information). Also, in response to a reference request from the management terminal 2, the administrator access log is presented to the management terminal 2.
[0109] The user management unit 62 manages information related to users such as registration face images and specific information, and performs necessary processing related to users in response to requests from the management terminal 2. In this embodiment, requests for registration, reference, update, and deletion related to users are made from the management terminal 2, and the user management unit 62 performs necessary processing in response to the requests. In addition, the user management unit 62 manages information related to meetings attended by users and information related to the user's network.
[0110] The matching group management unit 63 manages information related to the matching group, and performs necessary processing related to the matching group in response to requests from the management terminal 2. In this embodiment, requests for registration, reference, update, and deletion related to the matching group are made from the management terminal 2, and necessary processing is performed in response to the requests. In addition, matching group information, that is, information necessary for the face authentication device 1 to request face authentication from the face authentication server 6 that matches its own matching group, is generated for each face authentication device 1, and the matching group information is provided to the face authentication device 1.
[0111] The device management unit 64 manages information related to the face authentication device 1 and the registration device 4, and performs necessary processing related to the face authentication device 1 and the registration device 4 in response to requests from the management terminal 2. In this embodiment, requests for registration, reference, update, and deletion related to the association between the face authentication device 1 and the matching group are made from the management terminal 2, and necessary processing is performed in response to the requests.
[0112] The face authentication server management unit 65 manages information related to the face authentication server 6, and performs necessary processing related to the face authentication server 6 in response to requests from the management terminal 2. In this embodiment, requests for registration, reference, and deletion related to the association between the face authentication server 6 and the matching group are made from the management terminal 2, and necessary processing is performed in response to the requests.
[0113] The face information management unit 66 synchronizes the face information (such as face images and specific information) of the user stored in its own device with the face information (the face feature quantity data of the user) stored in the face verification server 6 so as to maintain a consistent state. In addition, the face information management unit 66 makes a copy of the face information (the face feature quantity data of the user).
[0114] The database management unit 67 manages the database provided in its own device and performs backup and restoration of the database.
[0115] The operation status monitoring unit 68 monitors the operation status of its own device, and also receives the operation status notifications from the face authentication device 1, the registration device 4, and the face verification server 6. According to the operation of the administrator on the management terminal 2, the operation status of the face authentication device 1, the registration device 4, its own device (face management server 5), and the face verification server 6 is displayed on the management terminal 2 in a screen.
[0116] The authentication log presentation unit 69, in response to a reference request from the management terminal 2, acquires the authentication log from the face verification server 6 and presents the authentication log to the management terminal 2.
[0117] The encryption unit 70 can encrypt at least a part of the user's face image and specific information. The encrypted information is stored in the storage unit 52. Note that in the face management server 5, the original information (the information before the encryption process) corresponding to the information encrypted by the encryption unit 70 may be deleted from the storage unit 52.
[0118] The anonymization information generation unit 80 can perform a process of anonymizing at least a part of the user's face image and specific information. As an anonymization process, the anonymization information generation unit 80 can, for example, replace a part of the user's face image and specific information with dummy information. Also, in the anonymization process, dummy information may be used for information missing in the user's face image and specific information (for example, information rejected by the user). The anonymized information is stored in the storage unit 52. Note that the encryption unit 70 may encrypt only the original information (information before the anonymization process) corresponding to the information anonymized by the anonymization information generation unit 80.
[0119] The image generation unit 90 generates a management screen for the administrator to confirm or change the information management status by the user management unit 62 and the device management unit 64. The management screen is distributed to the management terminal 2 or the like.
[0120] Next, the schematic configuration of the face verification server 6 will be described. FIG. 10 is a block diagram showing the schematic configuration of the face verification server 6.
[0121] The face verification server 6 includes a communication unit 71, a storage unit 72, and a control unit 73.
[0122] The communication unit 71 communicates with the face authentication device 1 via a network. In this embodiment, face image data and the like are received from the face authentication device 1. Also, the authentication result of the user and the like are transmitted to the face authentication device 1. Further, the communication unit 71 communicates with the face management server 5 via a network. In this embodiment, requests for various processes and the like are received from the face management server 5, and responses corresponding thereto are transmitted to the face management server 5.
[0123] The storage unit 72 stores a face verification database, association information between users and feature amounts, information regarding the verification group of the own device, an authentication log, a control program executed by a processor constituting the control unit 73, and the like.
[0124] In the face verification database, user face feature data and the like are registered as information regarding each registered user. Further, the face verification database is provided for each verification group, and stores the user face feature data in group units. Here, the registered user face feature data may be backup stored in a non-volatile memory such as an HDD or SSD provided in the face verification server 6 in case of unexpected disappearance from the face verification database.
[0125] The control unit 73 includes a verification group management unit 81, an image quality check unit 82, a face image extraction unit 83, a face feature amount generation unit 84, a face feature amount management unit 85, a face feature amount verification unit 86, an authentication log management unit 87, a database management unit 88, and an operation status monitoring unit 89. This control unit 73 is composed of a processor, and each unit of the control unit 73 is realized by the processor executing a program stored in the storage unit 72. Each unit of the control unit 73 is configured as a Web API.
[0126] The verification group management unit 81 manages the verification group to which the own device belongs, and performs registration and deletion processing related to the verification group in response to a request from the face management server 5.
[0127] The image quality check unit 82 determines whether the image of the face area in the captured image satisfies a predetermined quality. Specifically, it detects the presence or absence of wearing a mask and the presence or absence of wearing sunglasses from the target image, and also calculates a face authentication fitness (evaluation value based on the orientation and expression of the face).
[0128] The face image extraction unit 83 extracts a face image from the captured image of the user acquired by the registration device 4 at the time of user registration. At this time, if necessary, the face image extraction unit 83 detects the face of a person from the captured image (face detection), determines whether the size of the detected face is appropriate (face size check), cuts out the face area from the captured image (face cutting), and acquires the face image of the person. Note that the face image extraction unit 83 can also extract a face image from the captured image of the target person acquired by the face authentication machine 1 at the time of face authentication.
[0129] The face feature quantity generation unit 84 detects face feature points from the data of the face image for registration and the face image for authentication at the time of user registration and face authentication, and generates face feature quantity data respectively.
[0130] The face feature quantity management unit 85 registers the face feature quantity data of the user generated by the face feature quantity generation unit 84 in the face collation database corresponding to the collation group of the user at the time of user registration. Also, at the time of update or deletion, in response to a request from the face management server 5, the face feature quantity data registered in the face collation database is deleted. Also, when the version of the program related to the algorithm for face feature quantity generation or face collation is updated, in response to a request from the face management server 5, the face feature quantity data registered in the face collation database is updated to correspond to the new program.
[0131] The face feature quantity collation unit 86 compares the face feature quantity data of the subject generated from the data of the face image for authentication acquired from the face authentication device 1 at the time of face authentication with the face feature quantity data of the registrant (registered user) stored in its own device, and determines whether the subject is the registrant. This face feature quantity collation unit 86 corresponds to the collation group associated with its own device, and when a plurality of collation groups are associated with its own device, it has a plurality of face feature quantity collation units 86 for each collation group. This face feature quantity collation unit 86 (face collation process) constitutes a face collation unit in combination with the face collation database.
[0132] Note that the face feature quantity collation unit 86 calculates the similarity (collation score) between the subject and the registrant. By comparing this similarity with a predetermined threshold value, it is possible to determine the success or failure of face authentication. In addition to notifying the face authentication device 1 of the determination result of this success or failure as the collation result, the person ID and similarity of the registrant with a high similarity may be notified to the face authentication device 1 as the collation result.
[0133] When the authentication log management unit 87 receives a face authentication request from the face authentication device 1, it accumulates the information at that time, that is, the device ID of the face authentication device 1 that is the source of the face authentication request, the face matching result, and other information, as an authentication log in the storage unit 72. In addition, in response to a request from the face management server 5, it provides the authentication log to the face management server 5.
[0134] The database management unit 88 manages the database provided in its own device and performs backup and restore of the database.
[0135] The operation status monitoring unit 89 monitors the operation status of its own device and notifies the face management server 5 of the operation status of its own device.
[0136] In this embodiment, as the main functions of the face matching server 6, it has functions of face image extraction, face feature quantity generation, and face feature quantity matching. However, these functions can be configured by separate information processing devices independent of each other. For example, the function of face image extraction may be configured by a separate information processing device independent of other functions such as face feature quantity generation and face feature quantity matching.
[0137] Next, the schematic configuration of the external device 16 will be described. FIG. 11 is a block diagram showing the schematic configuration of the external device 16.
[0138] The external device 16 includes a control signal receiving unit 91, a drive unit 92, a power supply unit 93, and a control unit 94.
[0139] The control signal receiving unit 91 receives a control signal (an operation command from the face authentication device 1 that cooperates with the external device 16) transmitted from the control signal transmitting unit 17 of the face authentication device 1.
[0140] The drive unit 92 is controlled by the control unit 94 based on the control signal from the face recognition device 1. For example, when the external device 16 is a gate device, the drive unit 92 supplies power for opening (or closing) the door of the gate device. Also, when the external device 16 is a door locking device, the drive unit 92 supplies power for locking (or unlocking) the locking device. Note that when the external device 16 is a device that does not have a driven part (for example, a payment terminal device), the drive unit 92 can be omitted.
[0141] The power supply unit 93 supplies power to each part of the external device 16. Also, the power supply unit 93 is electrically connected to the power supply unit 97 of the face recognition device 1 and can supply power to the power supply unit 97 as well. The power supply unit 97 supplies power to each part of the face recognition device 1. Also, by being connected to the power supply unit 97 of the face recognition device 1 via a LAN cable, power can be supplied to the power supply unit 97 by PoE power supply.
[0142] Also, the power supply unit 93 can receive power supply from an uninterruptible power supply device (or emergency power) independent of the power supply line for the entire facility. Thereby, for example, the gate device as the external device 16 can perform normal operations even when a power outage occurs in the facility, and there is an advantage that the security of the facility can be maintained.
[0143] The control unit 94 controls the operations of each part of the external device 16. Also, the control unit 94 can execute the necessary processing for the external device 16. The control unit 94 is composed of a processor and is realized by the processor executing a program stored in a storage unit (memory) not shown in the figure.
[0144] Next, the face image extraction process will be described. FIG. 12 is an explanatory diagram showing the outline of the face image extraction process.
[0145] As described above, in the face image extraction unit 22 of the face authentication device 1, a process of generating face image data from the captured image data of the user is performed by face image extraction processing, that is, each process of face detection, face size check, and face cutting out. This face image extraction processing is also similarly performed in the face image extraction unit 83 of the face collation server 6.
[0146] At the time of user registration, data of the user's captured image is sent from the registration device 4 to the face collation server 6 via the face management server 5, and face image extraction processing is performed by the face image extraction unit 83 of the face collation server 6. In some cases, data of the user's captured image may be sent from the management terminal 2 to the face collation server 6 via the face management server 5.
[0147] On the other hand, at the time of face authentication, it is preferable to perform face image extraction processing only by the face authentication device 1 and not perform face image extraction processing in the face collation server 6. In this case, the face authentication device 1 is provided with a highly accurate face detection function. Also, the face authentication device 1 constantly captures the imaging area with the camera 11, and sends face image information (captured image data and face frame information) to the face collation server 6 at the timing when a face is detected. Thereby, the load of the face image extraction processing is dispersed to a plurality of face authentication devices 1, and the load on the face collation server 6 can be reduced. Also, since the communication volume can be reduced, the load on the network can be reduced. And since the response of face authentication can be performed at high speed, face authentication of the subjects appearing one after another can be efficiently performed.
[0148] That is, by sharing the face authentication process of the user between the face authentication device 1 and the face collation server 6, it is not necessary to provide a large number of expensive authentication devices that concentrate all of the user's face authentication processes on the face authentication device 1 as in the prior art. Also, even if updates of face feature amount data or the like occur, it is not necessary to perform maintenance work on a large-scale authentication device, and it is sufficient to perform the work on the face collation server 6. Therefore, according to the present embodiment, a face authentication system with an inexpensive configuration and excellent workability can be constructed.
[0149] However, a configuration in which the face authentication device 1 does not have a face image extraction function, that is, the face image extraction unit 22 may not be provided in the face authentication device 1.
[0150] FIG. 13 is an explanatory diagram showing an outline of an inquiry for face authentication based on collation group information.
[0151] The face management server 5 holds information regarding the collation group to which the user belongs, association information between the face authentication device 1 and the collation group, and association information between the face collation server 6 and the collation group. Also, in the collation group management unit 63 of the face management server 5, collation group information for each face authentication device 1 is generated based on the association information between the face authentication device 1 and the collation group and the association information between the face collation server 6 and the collation group.
[0152] This collation group information is information necessary for the face authentication device 1 to request face authentication from the face collation server 6 that matches its own collation group. This collation group information includes identification information (group number) of the collation group to which the face authentication device 1 belongs, and the face collation server 6 that requests face authentication from that face authentication device 1, that is, destination information of the face collation server 6 corresponding to the collation group of the face authentication device 1. Here, specifically, the destination information is the network address (for example, IP address) of the face collation server 6. Based on this destination information, the face collation server 6 that is the request destination for face authentication is specified, and the face authentication device 1 and the face collation server 6 that is the request destination for that face authentication are associated. When the face authentication device 1 belongs to a plurality of collation groups, addresses (IP addresses) for each of the corresponding plurality of face collation servers 6 are included in the collation group information.
[0153] In the face authentication device 1, at startup or the like, the startup processing unit 21 acquires the collation group information from the face management server 5 as operation setting information and stores it in its own device. In the face authentication device 1, when a person's face is detected, a face collation request is sent to the face collation server 6 that matches the collation group to which its own device belongs. This face collation request includes information such as the information of the collation group to which its own device belongs.
[0154] In addition, in the face authentication device 1, the timing for acquiring setting information regarding collation group information and the like from the face management server 5 may be, in addition to startup, at a predetermined timing or periodically at a predetermined interval, or a configuration may be adopted in which the face management server 5 distributes the collation group information.
[0155] The face collation server 6 holds association information between the face collation process of its own device and the collation group. When the face collation server 6 receives a face authentication request from the face authentication device 1, based on the association information between the collation group and the face authentication process and the collation group acquired from the face authentication device 1, it identifies the face authentication process corresponding to the face authentication device 1 and causes the face collation to be performed on that face authentication process. As a result, the face collation process corresponding to the designated collation group is used for the face collation process.
[0156] By the way, in the present embodiment, in the face collation server 6, a face collation database is provided for each collation group, and face feature amount data is stored in units of collation groups. Therefore, at the time of face collation, face collation may be performed on the face feature amount data registered in the face collation database corresponding to the collation group of the face authentication device 1. On the other hand, in the face collation server 6, face collation may be performed without regard to the collation group of the face authentication device 1, and then a filter may be applied to the collation result. That is, after performing face collation on the face feature amount data of all users stored in the face collation server 6, only the collation results with users belonging to the collation group of the face authentication device 1 may be extracted. In this case, it is not necessary to separately provide a face collation database for each collation group.
[0157] Next, the registration operation by the user in the registration device 4 will be described. FIG. 14 is an explanatory diagram showing an example of a registration screen displayed on the registration device 4.
[0158] When starting to use the facility (or when not revisiting the facility within a predetermined period after registration), the user can perform a registration operation for authentication by the registration device 4. In this embodiment, the user can perform the registration operation according to the guidance screen displayed on the display 42 (here, a touch panel) of the registration device 4. Note that for some parts of the registration operation for authentication described below (such as pressing a button), the receptionist who has obtained the user's consent may perform it.
[0159] An initial screen with a registration start button 101 is displayed on the display 42 of the registration device 4 (see Fig. 14(A)). Therefore, when the user presses (touches) the registration start button 101, a screen for explaining the handling of personal information in the face recognition system and requesting the user's consent is displayed (see Fig. 14(B)).
[0160] On the screen of Fig. 14(B), the user can consent to the handling of personal information in the face recognition system by pressing the consent button 102. Thereby, the registration device 4 starts to acquire the authentication information of the user. Therefore, a screen (the first screen) showing a method for acquiring specific information used to identify the user is displayed on the display 42 (see Fig. 14(C)). Note that the user can cancel the registration operation by pressing the cancel button 103. Note that the screen for requesting the user's consent may not be required by the user in some cases and can be omitted. Also, the operations of the photographing button 104, photographing button 107, and registration button 111 described later may be used instead of consent. Also, consent may be obtained through a predetermined procedure before using the registration device 4.
[0161] In the example shown in FIG. 14(C), a screen (first screen) showing a method of photographing the user's business card (here, guidance for placing the user's business card within the photographing area of the information acquisition camera 41B) is displayed. Therefore, when the user places the business card on the mounting table 116 of the registration device 4 and presses the photographing button 104, photographing of the business card is executed by the registration device 4. Note that the user can cancel the photographing of the business card by pressing the cancel button 105.
[0162] When the photographing of the business card is completed, subsequently, on the registration device 4, a screen (first screen) showing a method of photographing the user's registration face image (guidance for positioning the user's face within the photographing area of the face photographing camera 41A) is displayed (see FIG. 14(D)). At this time, on the registration device 4, the photographing frame 106 corresponding to the photographing area can be blinked to prompt the user to align the face. A live image (real-time moving image) photographed by the face photographing camera 41A is displayed within the photographing frame 106. Therefore, when the user positions their face within the photographing frame and presses the photographing button 107, photographing of the user's face is executed by the registration device 4. At this time, on the registration device 4, a shutter sound can be generated when the photographing button 107 is pressed. Note that the user can cancel the photographing of the face by pressing the cancel button 108.
[0163] When the photographing of the face is completed, subsequently, on the registration device 4, a screen (first screen) for the user to confirm the photographed face image is displayed (see FIG. 14(E)). This screen displays the photographed face image (still image). If the user determines that there is no problem with the photographed face image, the user presses the registration button 111. On the other hand, if the user determines that there is a problem with the photographed face image, the user can press the re-photographing button 112. As a result, on the registration device 4, the screen shown in FIG. 14(D) is displayed, and re-photographing of the face becomes possible. Note that the user can cancel the photographing of the face by pressing the cancel button 113.
[0164] When the face photographing is completed, the acquired face image and specific information (here, including the business card image and the business card description information extracted from the business card image by OCR) are transmitted to the face management server 5. In this case, for a user who does not desire to provide both the face image and the business card image, at least one of the face image and the business card image may be transmitted to the face management server 5. Thereby, in the face management server 5, a registration process regarding the user (see FIG. 15) is executed. When the registration process of the face management server 5 is normally completed, a screen (second screen) indicating that the registration has been completed is displayed on the registration device 4 (see "Display the processing result on the screen" in FIGS. 14(F) and 15). Therefore, when the user presses the end button 115, the registration operation in the registration device 4 ends. Note that the order of acquisition of the face image and the business card image may be reversed.
[0165] After the registration operation ends, the registration device 4 can delete the face image and specific information stored in the storage unit 44. Thereby, it is possible to avoid the personal information being stored in the registration device 4 used by unspecified persons for a long time, and it becomes possible to manage the personal information of the user more securely.
[0166] Note that instead of registering the user by the above-described registration device 4, the administrator can prepare a file of the face image for registering the user in advance and then perform the registration regarding the user using the management terminal 2. Further, the administrator can also correct the authentication information registered by the registration device 4 or add new information from the management terminal 2 in order to complement the registration by the registration device 4.
[0167] Next, the registration process regarding the user executed in response to the above-described user registration operation will be described. FIG. 15 is a sequence diagram showing the procedure of the registration process regarding the user.
[0168] When a user registration operation is performed in the registration device 4 as described above, the face management server 5 starts the registration process for the user as shown in FIG. 15. At this time, the face management server 5 receives the captured face image and specific information of the user together with the operation information from the registration device 4. In this registration process, first, the face management server 5 sends a request for face image extraction to the face matching server 6 whose matching group matches the target user. This request includes the captured face image of the user acquired from the registration device 4. At this time, if there are multiple face matching servers 6 whose matching group matches the target user, one face matching server 6 is selected and a request for face image extraction is sent to that one face matching server 6.
[0169] When the face matching server 6 receives the request for face image extraction from the face management server 5, it performs face image extraction processing. In this face image extraction processing, processing such as face detection and face cutting-out is performed on the captured face image of the user acquired from the face management server 5, and the face image of the user is extracted. Then, a response of face image extraction is sent to the face management server 5. This response includes the face image of the user.
[0170] When the face management server 5 receives the response of face image extraction from the face matching server 6, it sends a request for face registration to the face matching server 6 whose matching group matches the target user. This request can include the face image of the user acquired from a specific face matching server 6. At this time, if there are multiple face matching servers 6 whose matching group matches the target user, a request for face registration is sent to all (two in FIG. 15) face matching servers 6 including the face image of the user acquired from a specific face matching server 6.
[0171] Note that in the face management server 5, the request for face image extraction to the face matching server 6 described above may be omitted, and the captured face image of the user acquired from the registration device 4 together with the operation information may be added to the request for face registration to the face matching server 6.
[0172] When the face verification server 6 receives a face registration request from the face management server 5, it performs face registration processing. In this face registration processing, face feature amounts are generated from the face images of the users, and the face feature amounts are registered in the database. At this time, a face registration ID is assigned in association with the face feature amounts of the users. Then, a response to the face registration is sent to the face management server 5. This response includes a result indicating whether or not the face registration has been completed normally and the face registration ID. Note that with the completion of the registration of the face feature amounts in the database, the face images of the users in the face verification server 6 are deleted. Further, the data of the face feature amounts may be backup stored in a non-volatile memory such as an HDD or an SSD that is separately managed from the face verification DB of the face verification server 6.
[0173] When the face management server 5 receives a response to the face registration from the face verification server 6 and the processing has been completed normally, it performs registration processing regarding the user. In this registration processing, the face images of the users acquired from the registration device 4 are registered in the face information database. Further, in the face management server 5, the specific information of the users acquired from the face verification server 6 is registered in the face information database in association with the face images. Further, in the face management server 5, the face registration ID issued by the face verification server 6 is registered in the face information database as the information of the users.
[0174] Next, the face authentication processing of the user in the face authentication device 1 will be described. FIG. 16 shows a first example of the face authentication processing regarding the user. Here, an example is shown in which a gate device (security gate) for managing the passage of the user is used as the external device 16 that cooperates with the face authentication device 1.
[0175] When the face authentication device 1 detects a person's face from the captured image of the camera 11 and acquires a face image, it transmits a face verification request to the face verification server 6. This face verification request includes the device ID of the face authentication device 1 that is the request source, the verification group of the face authentication device 1, the data of the captured image (face image for authentication) of the person to be face-verified, the face frame information, and the verification conditions.
[0176] When the face verification server 6 receives a face verification request, first, the face feature quantity generation unit 84 generates the face feature quantity of the target person from the face image of the target person acquired from the face authentication device 1. Next, in the face feature quantity verification unit 86 of the face authentication unit corresponding to the verification group of the face authentication device 1, the face feature quantity of the target person is verified against the face feature quantity of the user registered in the face authentication database. At this time, the face verification process is performed in the face verification process in which the requesting face authentication device 1 and the verification group match. When the face verification process ends, the face verification server 6 transmits a face verification response to the requesting face authentication device 1. This face verification response includes a verification result (success, failure), a verification score, and a user code.
[0177] In the face feature quantity verification unit 86, a verification score representing the similarity between the target person of face authentication and the registered user is calculated. When this verification score is equal to or higher than a predetermined reference value, the target person of face authentication is regarded as the registered user himself / herself, and a verification result indicating that the face verification has succeeded is generated. On the other hand, when the verification score does not reach the reference value or higher for all users, it is determined that the target person of face authentication is not the registered user, and a verification result indicating that the face verification has failed is generated.
[0178] Note that the processing conditions (parameters for face verification) for face verification performed by the face verification server 6 may be added to the verification request. Thereby, the processing content of face verification performed by the face verification server 6 can be instructed from the face authentication device 1. For example, as the processing conditions for face verification, a threshold value related to the verification score is specified so that the verification result where the verification score is equal to or higher than a predetermined threshold value is included in the response. Also, as the processing conditions for face verification, the number of verification results is specified so that a predetermined number of verification results from the highest verification score are included in the response.
[0179] Also, when the face verification on the face verification server 6 is completed, the authentication log management unit 87 stores information such as the verification result obtained by the face verification in a database as an authentication log (history information of face authentication). At this time, only the result (success or failure) of the face authentication may be stored as the authentication log, or the matching score may be included in the authentication log. Also, the face image of the subject obtained from the face authentication device 1 may be included in the authentication log. In this case, it is advisable to encrypt and store the face image of the subject.
[0180] In addition, when a large number of valid verification results with a matching score exceeding the threshold are obtained, the verification results may be narrowed down to a predetermined number from the ones with higher matching scores and stored as the authentication log. Also, when the face verification does not end normally or when no valid verification result with a matching score exceeding the threshold is obtained, only the information included in the request from the face authentication device 1 may be stored as the authentication log.
[0181] Also, when the face authentication device 1 receives a face verification response indicating the success of face verification from the face verification server 6, it transmits an opening / closing control signal for the door portion to the associated gate device. That is, the face authentication device 1 converts the face verification response into an opening / closing control signal for the door portion, and thereby functions as a control device (gate opening / closing control device) that controls the operation of the door portion of the associated gate device. As a result, the gate device performs an operation of opening the door portion (that is, permitting the user to pass through) by the driving unit 92. Note that the face authentication device 1 deletes the face image of the user stored in the storage unit 14 upon completion of the transmission of the control signal (opening / closing control signal). Here, although the configuration is such that the face verification response is converted into an opening / closing control signal for the door portion, when the opening / closing control of the door portion of the gate device is performed by an entrance / exit management system constructed as an external system, a control signal is transmitted so that the face authentication result is reflected in the opening / closing control of the gate device to the entrance / exit management system.
[0182] FIG. 17 shows a second example of the face authentication process for a user. FIG. 18 is an explanatory diagram showing an example of an authentication screen (screen at the time of authentication) displayed on the face authentication device 1. Here, an example is shown in which a locking device provided on the door of a conference room is used as the external device 16 that cooperates with the face authentication device 1. Regarding the second example of the face authentication process, detailed descriptions of the same matters as those in the above-described first example are omitted.
[0183] The face authentication device 1 is installed, for example, on the wall of a corridor facing a conference room or the like. When the face authentication device 1 senses the approach of a person (that is, detects a user) by means of a human sensor or the like, it displays a standby screen (initial screen) of the authentication screen on the display 12 (see FIG. 18(A)). Here, the authentication screen (notification screen) displayed on the display 12 includes an image display area 121 for displaying a live image (real-time moving image) obtained by photographing a predetermined photographing area by the camera 11, and an information display area 122 for displaying information indicating the progress of the face authentication process.
[0184] After that, when the face authentication device 1 detects a person's face from the photographed image of the camera 11 and obtains a face image, it sends a face matching request to the face matching server 6. At this time, characters 123 and a figure 124 indicating that the authentication of the user is in progress are displayed in the information display area 122 (see FIG. 18(B)). Note that in the information display area 122, the display of either the character 123 or the figure 124 may be omitted. Also, in the case of the face authentication device 1 that does not have a display, for example, an LED lamp may be used, and the LED may be blinked during authentication and lit when authentication is successful to notify the progress of face authentication. Also, the progress of face authentication may be notified by the display color of the LED. Also, the display color of the LED may be changed according to the success or failure of the user's face authentication.
[0185] When the face matching server 6 receives the face matching request, it generates face feature amounts and executes a face matching process in the same manner as in the above-described first example. When the face matching process is completed, the face matching server 6 sends a face matching response to the requesting face authentication device 1.
[0186] Further, when the face authentication device 1 receives a face matching response indicating the success of face authentication from the face matching server 6, it displays a character 127 and a graphic 128 indicating that the authentication of the user is completed in the information display area 122 of the authentication screen (see Fig. 18(C)). At the same time, the face authentication device 1 transmits a control signal (an instruction to unlock the door) to the lock device of the associated door. That is, the face authentication device 1 functions as a control device that controls the operation of the associated lock device. As a result, the lock device performs an operation to unlock (i.e., permit the user to enter the room). Note that the face authentication device 1 deletes the face image of the user stored in the storage unit 14 upon completion of the transmission of the control signal.
[0187] The face authentication device 1 can also cooperate with an external device that only performs information processing without performing mechanical operations such as the above-described gate device or door lock device. Fig. 19 shows a third example of the face authentication process for a user.
[0188] Here, an example using a payment terminal device as the external device 16 that cooperates with the face authentication device 1 is shown. Regarding the third example of the face authentication process, detailed descriptions of the same matters as in the above-described first or second example are omitted.
[0189] In this third example of the face authentication process, when the face authentication device 1 receives a face matching response indicating the success of face authentication from the face matching server 6, it transmits a control signal to the associated payment terminal device (or payment system). As a result, the payment terminal device executes a process of associating the data of the usage fee for the service used by the corresponding user (for example, the provision of a meal in a restaurant) with the authenticated user, and as a result, the usage fee is added to the facility charge billing data for the user.
[0190] Next, the management operations by the administrator of the face authentication system will be described. Fig. 20 is an explanatory diagram showing a login screen displayed on the management terminal 2.
[0191] On the management terminal 2, when the administrator starts the management application and accesses the face management server 5, a login screen is displayed. On this login screen, the administrator can enter their user ID and password. When the administrator enters the user ID and password on this login screen and operates the login button, user authentication is performed on the face management server 5. If the login is successful, various management screens can be displayed. If the login fails, an error is displayed.
[0192] Next, registration, reference, update, and deletion regarding the association between the face authentication device 1 and the collation group in this system will be described. FIGS. 21 and 22 are explanatory diagrams showing the management screens displayed on the management terminal 2 during registration, reference, update, and deletion regarding the association between the face authentication device 1 and the collation group.
[0193] On the management terminal 2, when logging in to the face management server 5, during registration, reference, update, and deletion regarding the association between the face authentication device 1 and the collation group, the reference screen shown in FIG. 21(A), the registration screen shown in FIG. 21(B), and the deletion screen shown in FIG. 22 can be displayed.
[0194] The reference screen shown in FIG. 21(A) lists the association settings between the registered face authentication device 1 and the collation group. By viewing this reference screen, the administrator can confirm the registration details of the collation group.
[0195] This reference screen is provided with a list display section 211 and a face authentication device designation section 212. In the list display section 211, the device ID of each authentication device, the collation group (number) associated with each authentication device, and an explanation regarding the collation group are displayed. In the face authentication device designation section 212, the target face authentication device 1 (device ID) can be selected using a pull-down menu. As a result, the display content of the list display section 211 can be narrowed down to a specific face authentication device 1, and only the collation groups associated with the specific face authentication device 1 are displayed in the list display section 211. Note that when the face authentication device 1 is not designated in the face authentication device designation section 212, information regarding all face authentication devices 1 is displayed in the list display section 211.
[0196] Also, on this reference screen, sorting can be executed by designating items (device ID, face authentication device 1, explanation). Note that it may be possible to specify the number of display items (the number of face authentication devices 1) in the list display section 211, and the display range of the face collation server 6 and the collation group. Further, it may be possible to perform a search by designating search conditions regarding each item (device ID, face authentication device 1, explanation).
[0197] Note that in the example shown in FIG. 21(A), the face authentication devices 1 are grouped by the location where the face authentication devices 1 are installed (for example, the location of the business office).
[0198] The registration screen shown in FIG. 21(B) is for performing an association setting between the face authentication device 1 and the collation group. Information for associating a collation group with the authentication device can be registered.
[0199] This registration screen is provided with an authentication device specifying section 213, a matching group specifying section 214, and a registration button 215. In the authentication device specifying section 213, the target face authentication device 1 (device ID) can be selected using a pull-down menu. In the matching group specifying section 214, the matching group of the target face authentication device 1 can be selected using a pull-down menu. The registered matching groups are displayed in this pull-down menu. When the registration button 215 is operated after inputting the face authentication device 1 and the matching group on this registration screen, the face management server 5 performs a process of registering the matching group information with the input content.
[0200] Note that there may be cases where a plurality of matching groups are associated with one face authentication device 1. In this case, the registration operation of associating one matching group with one face authentication device 1 may be repeated on the registration screen. Also, a plurality of matching group specifying sections 214 may be provided on the registration screen.
[0201] The deletion screen shown in FIG. 22 is for deleting the association setting between the face authentication device 1 and the matching group.
[0202] This deletion screen is provided with a list display section 216, a face authentication device specifying section 217, and a deletion button 218. In the list display section 216, the device ID of each authentication device, the matching group (number) associated with each face authentication device 1, and the explanation regarding the matching group are displayed. Also, a check box is provided in this list display section 216 for each association setting. The association setting can be selected using the check box. When the deletion button 218 is operated after selecting the registration items to be deleted using the check box, the face management server 5 performs a process of deleting the selected registration items. In the face authentication device specifying section 217, the face authentication device 1 can be selected using a pull-down menu. Thereby, the display content of the list display section 216 is updated in a state where it is narrowed down to a specific face authentication device 1.
[0203] Here, by selecting "Reference" on the menu screen (not shown), the system transitions to the reference screen shown in Fig. 21(A). Also, by selecting "Registration" on the menu screen, the system transitions to the registration screen shown in Fig. 21(B). Further, by selecting "Deletion" on the menu screen, the system transitions to the deletion screen shown in Fig. 22. Additionally, by selecting "Update" on the menu screen, the system transitions to the update screen (not shown). Moreover, on the reference screen, when the administrator selects the association between the face recognition device 1 and the collation group, the system transitions to the update screen (not shown).
[0204] Note that in the example shown in Fig. 22, the registered associations are listed on the deletion screen, but deletion may also be possible on an individual editing screen. Also, the update screen (not shown) is the same as the registration screen (Fig. 21(B)).
[0205] Fig. 23 is an explanatory diagram showing an example of the user management screen displayed on the management terminal 2.
[0206] On the management terminal 2, when managing information related to users, the user management screen shown in Fig. 23 is displayed.
[0207] The user management screen shown in Fig. 23 is for the administrator to perform operations such as registering, referencing, updating, deleting, and searching for face images and specific information (here, business card information) related to users. The information (including images) input on the user management screen includes the information acquired by the registration device 4.
[0208] The user management screen includes an operation selection area 131, a user information area 132, and a business card information area 133.
[0209] In the operation selection area 131, the administrator can select the items to be executed (such as information registration, reference, update, deletion, and search). In Fig. 23, business card registration is selected as the item to be executed. Thereby, the administrator can newly input the business card description information displayed on the user management screen.
[0210] The user information area 132 includes the user's face image, name, and information used for face authentication. Here, the user information area 132 includes a face image display section 141, a name input section 142, a user ID input section 143, an identification ID input section 144, a matching group input section 145, an access permission group input section 146, an additional information input section 147, an activation date input section 148, and an inactivation date input section 149.
[0211] The face image display section 141 displays the user's face image. The administrator can delete the face image in the face image display section 141 by pressing the delete button 151. When the administrator cannot obtain the face image by the registration device 4, the administrator can select the prepared face image (image file) as the display target by pressing the image selection button 152. Alternatively, the administrator can also display the face image selected by the image selection button 152 in the face image display section 141 in place of the face image obtained by the registration device 4. The face image prepared by the administrator is not limited to the actual face image of the user, and may be a dummy image (for example, the user's avatar image).
[0212] The name input section 142 inputs the user's name. The user ID input section 143 inputs the user ID (for example, employee number, etc.). In the identification ID input section 144, an ID that can identify the user (for example, a series of unique numbers assigned in the order of user registration) is input. The matching group input section 145 inputs the matching group. The access permission group input section 146 inputs the access permission group indicating the administrator group that can access the user's information. In the additional information input section 147, additional information can be input. The activation date input section 148 inputs the date on which the face matching of the person can be made effective. The inactivation date input section 149 inputs the date on which the face matching can be made invalid. By setting these activation date and inactivation date, services for multiple users can be started or ended all at once.
[0213] The business card information area 133 includes the photographed image of the business card registered by the registration device 4 and the information extracted from the photographed image of the business card. Here, the business card information area 133 includes a business card image display section 161, an affiliation information input section 162, an activation date input section 163, and a deactivation date input section 164.
[0214] The business card image display section 161 displays the business card image of the user. Similar to the case of the face image described above, the administrator can delete the business card image or select a prepared business card image (image file) by pressing the delete button 171 or the image selection button 172.
[0215] In the affiliation information input section 162, the company name to which the user belongs, the department name of the user, the job title, the telephone number, the FAX number, the e-mail, the postal code, and the address are input. In the activation date input section 163, the date on which the information regarding the business card of the person can be made valid is input. In the deactivation date input section 164, the date on which the information regarding the business card of the person can be made invalid is input.
[0216] After the administrator finishes inputting to the desired input section and presses the registration button 167, the input (addition or change) information becomes valid.
[0217] In addition, on the management screen for the user, it is also possible to manage other specific information (for example, the information displayed on the payment card or the information indicating the user's staying location within the facility) together with or instead of the information described on the business card.
[0218] Also, the administrator can search for necessary information by selecting a search tab (for example, collation group search) in the operation selection area 131 of the management screen for the user. On the search screen for such information, each input section on the above-described management screen for the user is displayed as a blank field. For example, the administrator can search for the users belonging to the input collation group by inputting the collation group to be searched into the blank collation group input section 145.
[0219] When the manager enters search conditions with the necessary items on the search screen and presses a search button (not shown), the screen transitions to a list display screen (for example, a screen showing a list of the extracted users) reflecting the search results.
[0220] Next, the use of information about the user will be described. FIG. 24 is an explanatory diagram showing an example of a conference room search screen (meeting search screen) displayed as a management screen on the management terminal 2 or the like. FIG. 25 is an explanatory diagram showing an example of an attendee display screen displayed as a management screen on the management terminal 2.
[0221] The conference room search screen shown in FIG. 24 is for the manager to use (refer to) the information about the conference obtained in the face authentication process. Note that the manager can appropriately add information that cannot be obtained by the face authentication device 1 regarding the conferences held in the facility by accessing the face management server 5 from the management terminal 2.
[0222] On the conference room search screen, information such as the holding date, time, room number (conference room No.) regarding the conferences held in the facility's conference rooms in the past is displayed. To generate the conference room search screen, the information on the entry history obtained by the face authentication device 1 linked to the lock device of the conference room door can be used. When the manager selects a desired conference (in FIG. 24, click the check box of the conference shown at the top) and presses the selection button 173, the screen transitions to a search result display screen reflecting the search results.
[0223] As the search result display screen, for example, as shown in FIG. 25, an attendee display screen including an attendee list is displayed on the management terminal 2.
[0224] The attendee list includes an attendee information area 175 and a responder information area 176. In the attendee information area 175, the face images and specific information of the conference attendees (here, the company name to which the user belongs and the user's name) are displayed. Also, in the responder information area 176, information (here, the department and name) regarding the person who responded to the attendee (for example, an employee of a company occupying the facility) is displayed.
[0225] FIG. 26 is an explanatory diagram showing an example of a contact search screen displayed as a management screen on the management terminal 2.
[0226] The contact search screen shown in FIG. 26 is for the administrator to use (refer to) information regarding the contacts of the user 10 obtained in the face authentication process (here, information regarding the connection of people estimated from the information of the meeting attendees). The administrator can appropriately add necessary information regarding the contacts of the user by accessing the face management server 5 from the management terminal 2.
[0227] The contact search screen includes a correlation diagram display area 181 and a list display area 182. In the correlation diagram display area 181, a diagram visualizing the contacts regarding the person selected by the administrator is displayed. Also, in the list display area 182, a contact list 185 regarding the person (user 10) selected by the administrator is displayed. In this contact list 185, a face image of the person, affiliation information (company name, department, etc.), a numerical value indicating the strength of the contact (contact strength), etc. are displayed.
[0228] Such a contact search screen may be displayed, for example, when the administrator selects (clicks) the area of a desired attendee on the attendee display screen of FIG. 25.
[0229] Note that the use of the above-described meeting room search screen and contact search screen is not necessarily limited to being via the management terminal 2. For example, by granting the administrator access rights to the users of the facility (for example, employees of a company residing in the facility), the meeting room search screen and contact search screen may be viewable from the information processing terminals (such as PCs and tablets) owned by the users.
[0230] As described above, embodiments have been described as examples of the technology disclosed in the present application. However, the technology in the present disclosure is not limited to this, and can also be applied to embodiments with changes, replacements, additions, omissions, etc. Also, it is possible to form a new embodiment by combining the respective components described in the above embodiments.
[0231] In recent years, in the world of the Internet of Things (IoT), Cyber-Physical Systems (CPS), which is a new concept of creating new added value through information cooperation between the physical space and the cyber space, has been attracting attention. In such a situation, the CPS concept can also be adopted in this embodiment. That is, as a basic configuration of CPS, for example, an edge device arranged in the physical space and a cloud server arranged in the cyber space are connected via a network, and the face authentication process can be distributed and processed by processors mounted on the edge device and the cloud server. In this face authentication process, as the edge device, face image data of a user captured by a camera of an authentication device is acquired. Next, the cloud server executes a process of generating feature amount data from the face image data received from the edge device via the network, collates it with the feature amount data of a pre-registered user, executes the authentication process of the user, and passes on the authentication result related to the authentication process to face authentication application software, and displays it on a display or the like in an output format defined on the application. Here, each data generated in the edge device or the cloud server is preferably generated by a web application or the like mounted on a standardized platform. By using such a standardized platform, it is possible to improve the efficiency when constructing a system including various diverse sensor groups and IoT application software.
Industrial Applicability
[0232] The face authentication management server and the face authentication management method according to the present disclosure have an effect that information related to an event can be effectively utilized when face authentication is executed for each event generated by the behavior of a user in a facility, and are useful as a face authentication management server and a face authentication management method that accumulate and manage information related to face authentication such as image data obtained by photographing a target person.
Description of Reference Numerals
[0233] 1: Face recognition device 2: Management terminal 3: Face recognition server 4: Registration device 5: Face management server 6: Face matching server 10: User 11: Camera (face image acquisition unit) 12: Display (display unit) 15: Control unit (processor) 16: External device 25: Authentication result adjustment unit (history information generation unit) 41A: Camera for face photography (personal information acquisition unit) 41B: Camera for information acquisition (personal information acquisition unit) 42: Display (display unit) 45: Control unit (processor) 62: User management department 64: Equipment management department 90: Image generation unit
Claims
1. A face authentication management server that is connected to a management terminal via a network, associates a face authentication machine that executes face authentication of the user with a face matching server prior to face authentication for an event based on the user's behavior, and accumulates and manages management information related to the user's face authentication, comprising: a collation group management unit that manages settings related to collation group information that is set according to the installation location of each authentication machine for a plurality of face authentication machines and specifies one or more of the face matching servers that request face authentication of the user; a user management unit that integrates and manages first information including a registered face image of the user acquired by the user's registration device and second information other than the face image that is used to identify the user; a screen generation unit that generates a first management screen for confirming or changing the collation group information for each face authentication machine managed by the collation group management unit and a second management screen for confirming or changing the first information and the second information managed by the user management unit in response to a request from the management terminal; wherein the screen generation unit generates the second management screen including an input unit for the collation group information corresponding to the face authentication machine for which the user undergoes face authentication as the first information, characterized in that it is a face authentication management server.
2. wherein the screen generation unit generates the second management screen including an input unit for the affiliated information corresponding to the business card information of the user as the second information, characterized in that it is the face authentication management server according to Claim 1.
3. wherein the screen generation unit generates the second management screen including an input unit for the effective date for the first information or the second information, characterized in that it is the face authentication management server according to Claim 1.
4. wherein the screen generation unit generates the second management screen including an input unit for the expiration date for the first information or the second information, characterized in that it is the face authentication management server according to Claim 1.
5. A face authentication management method in which a face authentication management server connected to a management terminal via a network associates a face authentication machine that executes face authentication of the user with a face matching server prior to face authentication for an event based on the user's behavior, and accumulates and manages management information related to the user's face authentication, comprising: Manage settings related to collation group information that is set according to the installation location of each of a plurality of face authentication devices and identifies one or more of the face matching servers that request face authentication of the user. Integrate and manage first information including a face image for registration of the user acquired by the registration device of the user and second information other than the face image that is used for identifying the user. In response to a request from the management terminal, generate a first management screen for checking or changing the collation group information for each of the face authentication devices and a second management screen for checking or changing the first information and the second information. A face authentication management method, characterized in that confirmation or change of the collation group information corresponding to the face authentication device through which the user undergoes face authentication is performed from the second management screen.
Citation Information
Patent Citations
Circulating system
JP1978053147A
Visitor reception system, program and recording medium
JP2003122872A
Face picture recording system and method
JP2004265231A
Passage management device
JP2006039891A
Passage management system
JP2006185205A