Authentication control device, authentication system, authentication control method, and authentication control program

The authentication control device optimizes multimodal biometric authentication by selectively using secondary authentication based on primary success and user attributes, enhancing convenience by minimizing unnecessary steps.

JP7718754B2Active Publication Date: 2025-08-05NEC CORP
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2022545212
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-08-28
Publication Date
2025-08-05
Estimated Expiration
2040-08-28

AI Technical Summary

Technical Problem

Multimodal biometric authentication systems can inconvenience users by requiring multiple biometric inputs, such as face and iris scans, especially when wearing masks, leading to decreased convenience.

Method used

An authentication control device and system that determines whether to use the result of a secondary biometric authentication based on the success of a primary authentication, adjusting the authentication process according to user attributes, installation location, and purpose, allowing for flexible multimodal authentication.

Benefits of technology

Enhances user convenience by optimizing the number and type of biometric authentications required, ensuring seamless access without unnecessary additional steps.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007718754000001
    Figure 0007718754000001
  • Figure 0007718754000002
    Figure 0007718754000002
  • Figure 0007718754000003
    Figure 0007718754000003
Patent Text Reader

Abstract

The purpose of the present invention is to provide an authentication control device which can reduce deterioration in the convenience of a user in multimodal authentication. This authentication control device (10) comprises: a biological information acquisition means (11) which acquires first biological information and second biological information about a prescribed user; an authentication control means (12) which controls at least one among first biometric authentication using the first biological information and second biometric authentication using the second biological information; and a determination means (13) which, when at least one among the first biometric authentication and the second biometric authentication succeeds, determines whether to use the other biometric authentication result.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an authentication control device, an authentication system, an authentication control method, and a non-transitory computer-readable medium. [Background technology]

[0002] In recent years, biometric authentication has been used in a variety of situations. In particular, due to concerns about infectious diseases, there are high expectations for the use of contactless biometric authentication methods such as facial recognition and iris recognition.

[0003] For example, Patent Document 1 discloses an authentication system that is installed at the entrance to a special area set further inside a closed space and controls entry by facial recognition. The authentication system in Patent Document 1 aims to speed up facial recognition processing by narrowing the search range for facial images to be searched based on the results of matching identification information, etc. obtained from the ID card of each visitor.

[0004] Furthermore, Patent Document 2 discloses a hotel system that determines whether or not to permit entry to a room by checking the facial information of the user. In the hotel system of Patent Document 2, the user can enter the room without carrying a room key.

[0005] Furthermore, in recent years, the use of multimodal authentication, which combines multiple methods in addition to the single biometric authentication method described above, has been considered. The adoption of multimodal authentication offers benefits such as dramatically improving authentication accuracy. For example, Patent Document 3 discloses a biometric authentication device that uses a user's fingerprint and palm veins as biometric information. By using multiple pieces of biometric information in this way, it becomes possible to more reliably verify the user's identity. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] International Publication No. 2018 / 110012 [Patent Document 2] Japanese Patent Application Laid-Open No. 2003-256583 [Patent Document 3] Patent No. 5796523 Summary of the Invention [Problem to be solved by the invention]

[0007] While multimodal authentication enables highly accurate biometric authentication, it can also place a burden on users by requiring them to present multiple pieces of biometric information. For example, when biometric authentication is performed using a face image and an iris image, face authentication may fail if the user is wearing a mask. In such cases, the user must remove the mask to be authenticated. This is particularly inconvenient when the user is carrying luggage in both hands. As described above, if multimodal authentication is uniformly adopted regardless of the situation in which biometric authentication is performed, there is a risk that user convenience will decrease. The technologies disclosed in Patent Documents 1 to 3 do not take such a problem into consideration.

[0008] The present disclosure has been made to solve such problems, and aims to provide an authentication control device, an authentication system, an authentication control method, and a non-transitory computer-readable medium that can reduce the reduction in user convenience in multimodal authentication. [Means for solving the problem]

[0009] The authentication control device according to the present disclosure includes: a biometric information acquisition means for acquiring first biometric information and second biometric information of a predetermined user; an authentication control means for controlling at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; a determination means for determining whether or not to use the result of the other biometric authentication when at least one of the first biometric authentication and the second biometric authentication is successful; Equipped with It is something.

[0010] The authentication system according to the present disclosure comprises: an authentication terminal that acquires multiple types of biometric information from a predetermined user; an authentication control device connected to the authentication terminal; Equipped with The authentication control device acquiring first biometric information and second biometric information of the user from the authentication terminal; controlling at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; If at least one of the first biometric authentication and the second biometric authentication is successful, it is determined whether or not to use the result of the other biometric authentication. It is something.

[0011] The authentication control method according to the present disclosure includes: The computer Acquire first biometric information and second biometric information of a predetermined user; controlling at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; If at least one of the first biometric authentication and the second biometric authentication is successful, it is determined whether or not to use the result of the other biometric authentication. It is something.

[0012] A non-transitory computer-readable medium storing an authentication control program according to the present disclosure includes: a biometric information acquisition process for acquiring first biometric information and second biometric information of a predetermined user; an authentication control process for controlling at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; a determination process for determining whether or not to use the result of the other biometric authentication when at least one of the first biometric authentication and the second biometric authentication is successful; Have your computer run It is something. [Effects of the Invention]

[0013] The present disclosure makes it possible to provide an authentication control device, an authentication system, an authentication control method, and a non-transitory computer-readable medium that can reduce the decrease in user convenience in multimodal authentication. [Brief explanation of the drawings]

[0014] [Figure 1] 1 is a block diagram showing a configuration of an authentication control device according to a first embodiment. [Figure 2] 4 is a flowchart showing the processing of the authentication control device according to the first embodiment. [Figure 3] FIG. 10 is a block diagram showing the configuration of an authentication system according to a second embodiment. [Figure 4] FIG. 10 is a block diagram showing the configuration of an authentication device according to a second embodiment. [Figure 5] 10 is a flowchart showing a biometric information registration process of the authentication device according to the second embodiment. [Figure 6] 10 is a flowchart showing a biometric authentication process of the authentication device according to the second embodiment. [Figure 7] FIG. 10 is a block diagram showing the configuration of an authentication terminal according to a second embodiment. [Figure 8] FIG. 10 is a block diagram showing the configuration of an authentication control device according to a second embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of a biometric authentication method used in the authentication control system according to the second embodiment. [Figure 10] 10 is a flowchart showing the processing of the authentication control device according to the second embodiment. [Figure 11] 11 is a flowchart showing the processing of the authentication control device according to the third embodiment. [Figure 12] FIG. 10 is a block diagram showing the configuration of an authentication control device according to a fourth embodiment. [Figure 13] FIG. 10 is a block diagram showing the configuration of an authentication control device according to a fifth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0015] Hereinafter, a first embodiment of the present disclosure will be described in detail with reference to the drawings. In each drawing, the same or corresponding elements are denoted by the same reference numerals, and for clarity of explanation, duplicate explanations will be omitted as necessary.

[0016] <Embodiment 1> 1 is a block diagram showing the configuration of an authentication control device 10 according to this embodiment. As shown in FIG. 1, the authentication control device 10 includes a biometric information acquisition unit 11, an authentication control unit 12, and a determination unit 13. The biometric information acquisition unit 11 acquires first biometric information and second biometric information of a predetermined user. The authentication control unit 12 controls at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information. When at least one of the first biometric authentication and the second biometric authentication is successful, the determination unit 13 determines whether or not to use the result of the other biometric authentication. Note that when the authentication control unit 12 controls (executes) only one of the first biometric authentication and the second biometric authentication, the determination unit 13 naturally determines whether or not the executed biometric authentication is successful, regarding the executed biometric authentication as "one." Furthermore, "using the result of the other biometric authentication" includes, for example, providing a service or performing various controls according to the result. Furthermore, when the other biometric authentication has not been executed and it is determined that "the result of the other biometric authentication is used," the authentication control unit 12 may control (execute) the other biometric authentication.

[0017] FIG. 2 is a flowchart showing the flow of the authentication control method according to the first embodiment. First, the biometric information acquisition unit 11 acquires first biometric information and second biometric information of a predetermined user (S11). Next, the authentication control unit 12 controls at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information (S12). If at least one of the first biometric authentication and the second biometric authentication is successful (Yes in S13), the determination unit 13 determines whether or not to use the result of the other biometric authentication (S14). If both the first and second biometric authentications fail (No in S13), the authentication control device 10 ends the process.

[0018] As described above, according to the authentication control device 10 of this embodiment, when at least one of the first biometric authentication and the second biometric authentication is successful, it is determined whether or not to use the result of the other biometric authentication, thereby reducing the decrease in convenience for users in multimodal authentication.

[0019] The authentication control device 10 includes a processor, a memory, and a storage device, which are not shown in the figure. The storage device stores a computer program that implements the processing of the authentication control method according to the first embodiment. The processor then loads the computer program from the storage device into the memory and executes the computer program. As a result, the processor realizes the functions of a biometric information acquisition unit 11, an authentication control unit 12, and a determination unit 13.

[0020] Alternatively, the biometric information acquisition unit 11, the authentication control unit 12, and the determination unit 13 may each be realized by dedicated hardware. Furthermore, some or all of the components of each device may be realized by general-purpose or dedicated circuits, processors, etc., or a combination of these. These may be configured by a single chip, or by multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-mentioned circuits, etc., and programs. Furthermore, a CPU (Central Processing Unit), GPU (Graphics Processing Unit), FPGA (Field-Programmable Gate Array), etc., may be used as the processor.

[0021] Furthermore, when some or all of the components of the authentication control device 10 are realized by multiple information processing devices, circuits, etc., the multiple information processing devices, circuits, etc. may be centrally or decentralized. For example, the information processing devices, circuits, etc. may be realized as a client-server system, a cloud computing system, or the like, connected via a communication network. Furthermore, the functions of the authentication control device 10 may be provided in the form of SaaS (Software as a Service).

[0022] <Embodiment 2> The second embodiment is a specific example of the above-described first embodiment. Fig. 3 is a block diagram showing the overall configuration of an authentication system 1000 according to the second embodiment. The authentication system 1000 includes an authentication device 100, an authentication control device 200, and authentication terminals 400a to 400g. The authentication device 100, the authentication control device 200, and the authentication terminals 400a to 400g are connected to each other via a network N. Here, the network N is a wired or wireless communication line.

[0023] In the second embodiment, a case will be described in which the authentication system 1000 is implemented in an accommodation facility such as a hotel. First, an outline of the present embodiment will be described with reference to FIG.

[0024] As shown in Fig. 3, authentication terminals 400a to 400g are installed in locations within the hotel where biometric authentication is required. Each authentication terminal 400 performs biometric authentication on user U for its respective purpose and installation location. Each authentication terminal 400 supports multimodal authentication and can perform authentication using, for example, either face authentication or iris authentication. Each authentication terminal 400 is, for example, a digital signage and includes a display unit 440 that displays a message prompting user U to perform biometric authentication and a display showing the authentication result.

[0025] Here, a user U who is a customer of the hotel will be described as user U1. User U1 registers information required for accommodation (date of stay, name, contact information, etc.) in advance in the authentication control device 200 via a reservation website or the like. The authentication control device 200 also stores the fact that user U1 is a customer as an attribute of user U1 in association with his / her user ID. User U1 also registers a facial image of user U1 in advance in the authentication device 100 via a reservation website or the like. This allows user U1 to use facial authentication within the hotel.

[0026] The authentication terminals 400a-400g compare the facial image pre-registered in the authentication device 100 with a facial image captured within the hotel by comparing their characteristic information to perform biometric authentication for user U1. If biometric authentication is successful at each authentication terminal 400, user U1 can receive designated services within the hotel. While user U1 may pre-register an iris image along with a facial image, since a dedicated camera (infrared camera) is required to acquire an iris image, the following description assumes that user U1 pre-registers only a facial image. Therefore, user U1 registers only a facial image via a website or the like, and registers the iris image using the authentication terminal 400 after arriving at the hotel. User U1 may pre-register whether or not he or she consents to the use of iris authentication, including iris photography, when booking a stay. This allows for a rapid iris registration procedure after arriving at the hotel.

[0027] When user U1 arrives at the hotel, authentication terminal 400a installed at the entrance performs biometric authentication on user U1. Authentication terminal 400a can prompt user U1 to perform facial authentication by displaying a message on display unit 440. Furthermore, authentication terminal 400a may also provide guidance to user U1 by voice using a speaker or the like along with the display.

[0028] The authentication terminal 400a takes a picture of the face of the user U1 with a built-in camera and performs facial authentication of the user U1 using the captured facial image. Specifically, the authentication terminal 400a transmits a biometric authentication request to the authentication control device 200 along with the captured facial image. The authentication control device 200 receives the biometric authentication request from the authentication terminal 400a, performs predetermined processing, and transmits the biometric authentication request to the authentication device 100. The authentication device 100 receives the biometric authentication request from the authentication control device 200, performs biometric authentication, and returns the result to the authentication control device 200. The authentication control device 200 returns the result to the authentication terminal 400a. Through the above processing, the authentication terminal 400a can receive the authentication result for the user U1. These processing steps will be described in more detail later.

[0029] If the face authentication of user U1 is successful, the authentication terminal 400a displays a message such as "Face authentication was successful" or "Welcome, Mr. / Ms. XX" on the display unit 440. This allows user U1 to understand that face authentication was successful based on the face image registered at the time of reservation.

[0030] Next, user U1 checks in using authentication terminal 400b installed at the counter. First, authentication terminal 400b captures a picture of user U1's face using its built-in camera and performs facial authentication of user U1 using the captured facial image. If facial authentication is successful, the counter staff completes the check-in procedure for user U1. Next, authentication terminal 400b displays a message prompting user U1 to take a picture of their iris in order to use iris authentication when providing various services within the building. If user U1 has previously registered their consent to the use of iris authentication, authentication terminal 400b displays a message such as "Next, we will perform iris registration processing based on your permission to use iris authentication" on display 440 and takes a picture of user U1's iris. If user U1 has not previously consented to the use of iris authentication, authentication terminal 400b displays the necessary information on display 440 to confirm with user U1 whether or not they agree to the use of iris authentication. User U1 responds whether or not he or she agrees to iris authentication by, for example, pressing a button displayed on display unit 440. When user U1 agrees to having his or her iris photographed, authentication terminal 400b photographs the iris of user U1 using a built-in infrared camera.

[0031] The captured iris image is stored in the authentication device 100 in association with the user ID etc. via the network N. This allows the user U1 to use iris authentication in subsequent procedures. Therefore, the user U1 can not only use face authentication and iris authentication independently, but also can handle cases where multimodal authentication using multiple authentication methods is required. The above iris registration process may be performed by any authentication terminal 400 other than authentication terminal 400b. Furthermore, regardless of whether or not user U1 has previously agreed to the use of iris authentication, a message such as "Iris authentication is available. Please register your iris" may be displayed on display unit 440 to prompt user U1, whose iris is not registered, to register the iris. Furthermore, authentication terminal 400 may not display the above message thereafter to user U, who has input that he or she does not agree to the use of iris authentication.

[0032] After completing the check-in procedure, user U1 undergoes biometric authentication using the authentication terminal 400c at the entrance to the accommodation building as he or she moves from the entrance to the accommodation building. Since entry and exit to the accommodation building must be strictly controlled, multimodal authentication is performed here. The authentication terminal 400c performs facial authentication and iris authentication on user U1. If the authentication is successful, the door to the accommodation building opens and user U1 can enter the building. The display unit 440 displays a message such as, "Mr. / Ms. XX, facial authentication and iris authentication have been successful."

[0033] Next, user U1 enters the accommodation room that he or she has reserved. As shown in FIG. 3, authentication terminals 400d to 400f are installed at the entrances to rooms A to C, respectively. User U1 performs authentication using the authentication terminal 400 installed in front of the room that he or she has reserved. Since strict identity verification is performed using multimodal authentication at the entrance to the accommodation building, user U1 is authenticated here using only facial authentication.

[0034] For example, if the room where user U1 will be staying is room A, user U1 performs authentication using authentication terminal 400d installed in front of room A. If facial authentication is successful, room A is unlocked and user U1 can enter room A. If user U1 attempts authentication using authentication terminal 400 installed in front of a room where user U1 is not planning to stay, authentication will fail. In this case, authentication terminal 400 may display a message on display unit 440 that authentication has failed and prompt user U1 to confirm the room number.

[0035] Furthermore, when user U1 makes a purchase at a souvenir shop, payment processing is required, and strict identity verification is therefore required. For this reason, an authentication terminal 400g installed at the cash register of the souvenir shop performs multimodal authentication using face authentication and iris authentication.

[0036] When the customer checks out, user U1 is authenticated by the authentication terminal 400b installed at the counter, just as when checking in. Checking out also involves payment of accommodation fees, etc., so multimodal authentication using facial recognition and iris recognition is performed, just like at the souvenir shop.

[0037] Up to this point, we have explained the biometric authentication methods used in each situation, assuming that the user U is a customer staying at a hotel. Below, we will explain the case where the user U is not a customer but a hotel employee.

[0038] In the following description, user U, who is an employee, is referred to as user U2. User U2 takes images of his / her face and iris using the authentication terminal 400 or the like, and registers this biometric information in advance in the authentication device 100. This allows user U2 to use face authentication and iris authentication at each authentication terminal 400 in the hotel. Furthermore, the authentication control device 200 stores, as an attribute of user U2, that user U2 is an employee, in association with his / her user ID.

[0039] As with user U1, biometric authentication is performed on user U2 at each authentication terminal 400. However, even if the authentication terminals 400 are installed in the same location, different biometric authentication methods are used for user U1, who is a customer, and user U2, who is an employee. The specific processing content will be described later, but the following explains the differences depending on the attributes of user U.

[0040] Fig. 9 is a diagram showing an example of biometric authentication required depending on the attributes of user U and the installation location of authentication terminal 400. The upper part of the table shown in Fig. 9 shows the biometric authentication required for user U1, which has already been mentioned. As shown in Fig. 9, user U1 and user U2 use different authentication methods, for example, in accommodation buildings or accommodation rooms. For example, in the example of user U1 described above, authentication was performed using face authentication and iris authentication at the authentication terminal 400c at the entrance to the accommodation building. However, user U2 can pass through the same accommodation building entrance with only successful iris authentication. Therefore, user U2 can enter the accommodation building from the entrance even while wearing a mask. When user U2 succeeds in iris authentication at the authentication terminal 400c, the display unit 440 displays a message such as, for example, "Employee ID: XX No. Mr. / Ms. △△ Iris authentication successful."

[0041] On the other hand, in the example of user U1 described above, user U1 was able to enter room A with only facial authentication, whereas user U2 needs to succeed in facial authentication and iris authentication to enter rooms A to C. This is because, unlike user U1, user U2 only had facial authentication performed at the entrance to the accommodation building, and therefore must undergo strict identity verification when entering the accommodation room.

[0042] Furthermore, when user U2 purchases an item at a souvenir shop, he or she must undergo multimodal authentication using facial recognition and iris recognition, just like user U1. This is because strict identity verification is required for transactions including payment, even for employees.

[0043] As described above, according to the authentication system 1000 of this embodiment, the number and methods of biometric authentication to be performed at each authentication terminal 400 can be determined according to the attributes of the user U, the installation locations of the authentication terminals 400, and the purpose of the biometric authentication. This allows appropriate multimodal authentication to be performed without reducing the convenience for the user U.

[0044] The above is an overview of the processing performed by the authentication system 1000 according to this embodiment. Next, the authentication device 100, the authentication terminal 400, and the authentication control device 200 that constitute the authentication system 1000 will be described in detail.

[0045] The authentication device 100 is an information processing device that, in response to a biometric authentication request received from outside, compares an image of a face, iris, or the like included in the request or biometric feature information thereof with biometric feature information of each user U and returns the comparison result (authentication result) to the request source. The authentication device 100 stores biometric feature information of multiple users U. The authentication device 100 can also store multiple pieces of biometric feature information for one user U and perform authentication using each piece of biometric feature information. Biometric feature information is feature information of biometric information used for biometric authentication. Examples of biometric information include face, iris, fingerprint, and vein. In the second embodiment, face authentication and iris authentication are used as examples of biometric authentication.

[0046] 4 is a block diagram showing the configuration of an authentication device 100 according to embodiment 2. The authentication device 100 includes a biometric information DB (DataBase) 110, a detection unit 120, a feature point extraction unit 130, a registration unit 140, and an authentication unit 150.

[0047] The biometric information DB 110 stores a user ID 111, biometric feature information 112 for the user ID, and a biometric authentication method 113 in association with each other. The biometric feature information 112 is a collection of feature points extracted from a face image or an iris image. The biometric authentication method 113 is an authentication method such as face authentication, iris authentication, or vein authentication. The authentication device 100 may delete the biometric feature information 112 from the biometric information DB 110 at the request of a registered user U of the biometric feature information 112. Alternatively, the authentication device 100 may delete the biometric feature information 112 after a certain period of time has elapsed since its registration.

[0048] The detection unit 120 detects face and iris areas included in a registration image for registering biometric information, and outputs the detected areas to the feature point extraction unit 130. The feature point extraction unit 130 extracts feature points from the face area, etc. detected by the detection unit 120, and outputs biometric feature information to the registration unit 140. The feature point extraction unit 130 also extracts feature points included in the face image, etc. received from the authentication control device 200, and outputs the biometric feature information to the authentication unit 150.

[0049] The registration unit 140 issues a new user ID 111 when registering biometric feature information. The registration unit 140 associates the issued user ID 111 with biometric feature information 112 extracted from a registered image and registers them in the biometric information DB 110. The authentication unit 150 performs biometric authentication using the biometric feature information 112. Specifically, the authentication unit 150 compares the biometric feature information extracted from a face image or the like with the biometric feature information 112 in the biometric information DB 110. The authentication unit 150 returns a notification of whether or not the biometric feature information matches to the authentication control device 200. The presence or absence of a match in the biometric feature information corresponds to the success or failure of authentication. Note that a match in the biometric feature information (match present) refers to a case where the degree of match is equal to or greater than a predetermined value.

[0050] Next, a biometric information registration process and an authentication process according to the second embodiment will be described. FIG. 5 is a flowchart showing the flow of the biometric information registration process according to the second embodiment. First, the authentication device 100 acquires a registration image included in a biometric information registration request (S21). For example, the authentication device 100 receives a biometric information registration request from the authentication terminal 400, a hotel website, or the like via the network N. Next, the detection unit 120 detects a face region or the like included in the registration image (S22). Next, the feature point extraction unit 130 extracts feature points from the face region or the like detected in step S22, and outputs biometric feature information to the registration unit 140 (S23). Finally, the registration unit 140 issues a user ID 111, and associates the user ID 111, biometric feature information 112, and biometric authentication method 113 with each other and registers them in the biometric information DB 110 (S24). The authentication device 100 may receive biometric feature information 112 from a terminal or the like owned by the user U, and register the biometric feature information 112 in the biometric information DB 110 in association with the user ID 111 and the biometric authentication method 113.

[0051] 6 is a flowchart showing the flow of biometric authentication processing by the authentication device 100 according to the second embodiment. First, the feature point extraction unit 130 acquires a face image for authentication, etc., included in a biometric authentication request (S31). For example, the authentication device 100 receives a biometric authentication request from the authentication control device 200 via the network N, and extracts biometric feature information from the biometric image included in the biometric authentication request as in steps S21 to S23. Alternatively, the authentication device 100 may receive biometric feature information from the authentication control device 200.

[0052] Next, the authentication unit 150 compares the acquired biometric feature information with the biometric feature information 112 in the biometric information DB 110 (S32). If the biometric feature information matches, that is, if the degree of match between the biometric feature information is equal to or greater than a predetermined value (Yes in S33), the authentication unit 150 identifies the user ID 111 of the user U whose biometric feature information matches (S34). Then, the authentication unit 150 returns a message to the authentication control device 200 indicating that the biometric authentication was successful and the identified user ID 111 (S35). If no matching biometric feature information exists (No in S33), the authentication unit 150 returns a message to the authentication control device 200 indicating that the biometric authentication failed (S36).

[0053] In step S32, the authentication unit 150 does not need to attempt matching with all biometric feature information 112 in the biometric information DB 110. For example, the authentication unit 150 can receive the biometric authentication request including the biometric authentication method 113 and perform matching among the biometric authentication methods 113 that match. Alternatively, the authentication unit 150 may preferentially attempt matching with biometric feature information registered between the day the biometric authentication request was received and several days prior. This can improve the matching speed. Furthermore, if the preferential matching fails, it is preferable to perform matching with all remaining biometric feature information.

[0054] Next, the authentication terminal 400 will be described in detail. Fig. 7 is a block diagram showing the configuration of the authentication terminal 400 according to the second embodiment. Note that the authentication terminals 400a to 400g are the same as the authentication terminal 400, and therefore are not shown in the figures. The authentication terminal 400 includes a first camera 410, a second camera 411, a storage unit 420, a communication unit 430, a display unit 440, and a control unit 450.

[0055] The first camera 410 and the second camera 411 are photographing devices that photograph under the control of the control unit 450. In the second embodiment, the first camera 410 photographs the face of the user U, and the second camera 411 photographs the iris of the user U. The second camera 411 is an infrared camera that can photograph the iris.

[0056] The storage unit 420 is a storage device that stores programs for realizing the functions of the authentication terminal 400. The communication unit 430 is a communication interface with the network N. The display unit 440 is at least a display device. Alternatively, the display unit 440 may be an input / output unit including a display device and an input device, such as a touch panel.

[0057] The control unit 450 controls the hardware of the authentication terminal 400. The control unit 450 includes a photography control unit 451, a registration unit 452, an authentication control unit 453, and a display control unit 454.

[0058] The photographing control unit 451 controls the first camera 410 and the second camera 411 to photograph a registration image or an authentication image of the user U. The registration image and the authentication image photographed by the first camera 410 and the second camera 411 are images that include at least the face area and the iris area of the user U, respectively. The photographing control unit 451 outputs the registration image to the registration unit 452. The photographing control unit 451 also outputs the authentication image to the authentication control unit 453.

[0059] The registration unit 452 transmits a biometric information registration request including a registration image to the authentication device 100 via the network N.

[0060] The authentication control unit 453 transmits a biometric authentication request including an authentication image to the authentication control device 200 via the network N. The authentication control unit 453 also transmits the biometric authentication request to the authentication control device 200, including a location ID that identifies the location where the authentication terminal 400 is installed and the purpose of the biometric authentication. The purpose includes, for example, information on whether the purpose includes payment processing or personal identification. The authentication control unit 453 may also transmit the biometric authentication request to the authentication control device 200, including a terminal ID that identifies the authentication terminal 400 instead of the location ID. In this case, the authentication control device 200 associates the terminal ID of the authentication terminal 400 with the location ID of the installation location of the authentication terminal 400 and stores them in advance in the storage unit 210. As a result, the authentication control device 200 can refer to the storage unit 210 based on the terminal ID included in the received biometric authentication request and acquire the location ID of the authentication terminal 400.

[0061] The authentication control unit 453 receives the biometric authentication result and outputs it to the display control unit 454. If the authentication result is successful, the authentication control unit 453 outputs an instruction signal to a control device for a predetermined service to cause the control device to execute the service. Examples of predetermined services include opening and closing a door (gate), unlocking a lock, executing a payment process, executing a check-in process, and executing a check-out process. The predetermined services are not limited to these, but include various services that are provided in response to successful authentication of the user U. This allows the user U to use the biometric authentication result to receive predetermined services that require authentication, such as entering a hotel room or executing a payment process.

[0062] The display control unit 454 displays on the display unit 440 display content corresponding to the biometric authentication result. For example, the display control unit 454 displays to the user U that the authentication was successful or unsuccessful. The display control unit 454 may also display the biometric authentication method, the user U's name, and the like along with the authentication result on the display unit 440. For example, the display control unit 454 displays, "Mr. / Ms. XX, face authentication was successful," or "Mr. / Ms. XX, face authentication and iris authentication were successful." Information such as the name may be hidden or in a format that does not identify the individual, as necessary. Furthermore, if the user U is an employee, the display control unit 454 may also display information such as the employee ID and affiliation, such as, for example, "Employee ID: No. XX, Mr. / Ms. △△, iris authentication was successful." In addition, the display control unit 454 may guide the user U through actions required for biometric authentication (such as removing a mask or facing the face toward the authentication terminal 400).

[0063] Returning to Figure 3, the explanation will continue. The authentication control device 200 is an information processing device that controls the biometric authentication process of the user U in the authentication terminal 400. The authentication control device 200 may be redundantly configured with multiple servers, and each functional block may be realized by multiple computers.

[0064] Specifically, first, the authentication control device 200 receives a biometric authentication request including biometric information of the user U, the location ID of the authentication terminal 400, and the purpose of biometric authentication from the authentication terminal 400. The authentication control device 200 determines a first biometric authentication method from among multiple biometric authentication methods depending on the installation location of the authentication terminal 400 or the purpose of biometric authentication, and transmits a first biometric authentication request according to the determined method to the authentication device 100.

[0065] When the authentication control device 200 receives from the authentication device 100 a notification that the first biometric authentication was successful, it identifies the attributes of the user U. The authentication control device 200 determines whether to use the result of the second biometric authentication, taking into account the installation location of the authentication terminal 400, the purpose of the biometric authentication, and the attributes of the user U. If it is determined that the result of the second biometric authentication is to be used, the authentication control device 200 determines to perform the second biometric authentication on the user U, and controls the second biometric authentication.

[0066] If it is determined that the second biometric authentication is to be performed, the authentication control device 200 transmits a second biometric authentication request to the authentication device 100. When the authentication control device 200 receives from the authentication device 100 a message that the second biometric authentication has been successful, the authentication control device 200 transmits that message to the authentication terminal 400. Through the above process, the user U who has successfully passed the biometric authentication can receive the desired services, such as entering the accommodation room and making a payment.

[0067] Next, a detailed description will be given of the authentication control device 200. Fig. 8 is a block diagram showing the configuration of the authentication control device 200 according to the second embodiment. The authentication control device 200 includes a storage unit 210, a memory 220, a communication unit 230, and a control unit 240.

[0068] The storage unit 210 is a storage device such as a hard disk, a flash memory, etc. The storage unit 210 stores a program 211, attribute information 212, and authentication method information 213. The program 211 is a computer program in which the processing of the authentication control method according to the second embodiment is implemented.

[0069] The attribute information 212 is attribute information of each user U. Specifically, the attribute information 212 is information that associates a user ID 2121 with an attribute 2122. The user ID 2121 is information that identifies the user U. The attribute 2122 is information that indicates the attribute of the user U, and includes, for example, whether the user is a customer or an employee.

[0070] The authentication method information 213 is information that associates a location ID 2131, a purpose 2132, an attribute 2133, and an authentication method 2134. As already explained using Fig. 9, the authentication methods and their combinations to be performed on the user U are determined depending on the installation location of the authentication terminal 400, the purpose of the biometric authentication, and the attributes of the user U. The authentication method information 213 stores these in association with each other. 9 is an example and is not limiting. For example, the number of authentication methods to be combined may be increased or decreased depending on the accuracy of the biometric authentication, or the attributes of user U may be further subdivided. For example, for employees, the combination of authentication methods may be adjusted depending on their job title or years of service, or iris authentication may be applied differently to those who wear masks less frequently, such as those who do cleaning work, and those who wear masks more frequently.

[0071] The memory 220 is a volatile storage device such as a RAM (Random Access Memory), and is a storage area for temporarily storing information when the control unit 240 is operating. The communication unit 230 is a communication interface with the network N.

[0072] The control unit 240 is a processor, i.e., a control device, that controls each component of the authentication control device 200. The control unit 240 loads the program 211 from the storage unit 210 into the memory 220 and executes the program 211. As a result, the control unit 240 realizes the functions of a biometric information acquisition unit 241, an authentication control unit 242, a judgment unit 243, and a decision unit 244.

[0073] The biometric information acquisition unit 241 is an example of the above-mentioned biometric information acquisition unit 11. The biometric information acquisition unit 241 acquires first biometric information and second biometric information of a predetermined user U who is to undergo biometric authentication. Specifically, the biometric information acquisition unit 241 acquires the first and second biometric information from the authentication terminal 400 via the network N. The first and second biometric information are, for example, biometric information of the face and iris of the user U captured by the first camera 410 and the second camera 411.

[0074] The authentication control unit 242 is an example of the above-mentioned authentication control unit 12. The authentication control unit 242 controls at least one of a first biometric authentication using first biometric information and a second biometric authentication using second biometric information. In this embodiment, first, the authentication control unit 242 controls the first biometric authentication using the first biometric information acquired by the biometric information acquisition unit 241. Specifically, the authentication control unit 242 transmits a first biometric authentication request to the authentication device 100 via the network N. The first biometric authentication request includes the first biometric information. The first biometric authentication method is determined by the determination unit 244, which will be described later. Note that the first biometric authentication request may include information about the first biometric authentication method. This can improve the matching speed in the authentication device 100.

[0075] Next, when the determination unit 243, which will be described later, determines that the second biometric authentication should be performed on the user U, the authentication control unit 242 controls the second biometric authentication. Specifically, the authentication control unit 242 transmits a second biometric authentication request to the authentication device 100 via the network N. The second biometric authentication request includes second biometric information of the user U. As in the above, the second biometric authentication request may also include information on the second biometric authentication method.

[0076] The determination unit 243 is an example of the above-mentioned determination unit 13. When at least one of the first biometric authentication and the second biometric authentication is successful, the determination unit 13 determines whether to use the result of the other biometric authentication. In this embodiment, when the first biometric authentication is successful, the determination unit 243 determines whether to use the result of the second biometric authentication. Specifically, the determination unit 243 identifies attributes of the user U who succeeded in the first biometric authentication, and determines whether to use the result of the second biometric authentication based on the identified attributes. Furthermore, when it is determined that the result of the second biometric authentication is to be used, the determination unit 243 determines to perform the second biometric authentication.

[0077] The determination unit 243 determines whether or not to use the result of the second biometric authentication, based on the conditions, for example, as shown in the table of Fig. 9. That is, the determination unit 243 determines whether or not to use the result of the second biometric authentication, depending on the attributes of the user U, the installation location of the authentication terminal 400, and the purpose of the biometric authentication, and then determines whether or not to perform the second biometric authentication.

[0078] For example, in the example shown in FIG. 9, it is assumed that the authentication terminal 400 is installed at the entrance to an accommodation building (a common entrance to a plurality of service provision locations for a plurality of recipients of services that are provided in response to successful authentication), and that the user U1 has successfully passed face authentication as the first biometric authentication. The determination unit 243 identifies the attribute of the user U1 as a customer (a recipient of the service) based on the attribute information 212. Furthermore, based on the identified attribute of the user U1, the determination unit 243 refers to the authentication method information 213 and determines whether or not to use the result of the second biometric authentication for the user U1. At the entrance to the accommodation building, the user U1, who is a customer, requires not only face authentication but also iris authentication, so the determination unit 243 determines to use the result of the second biometric authentication and also determines to perform the second biometric authentication. Similarly, when user U is an employee (service provider), the determination is made based on the authentication method information 213. For user U2 who has succeeded in iris authentication, which is the first biometric authentication, the determination unit 243 identifies the attribute of user U2 as an employee, and based on the identified attribute, determines not to use the result of the second biometric authentication for user U2 by referring to the authentication method information 213, and also determines not to perform the second biometric authentication.

[0079] By making such a determination, customers can be strictly identified using facial and iris authentication when entering the accommodation building, preventing non-customers from entering the accommodation building. Employees can be allowed to enter the accommodation building using only iris authentication, so even if an employee is wearing a mask, for example, identity can be efficiently confirmed without the employee having to remove the mask. Since iris authentication has higher authentication accuracy than facial authentication, it is believed possible to perform strict identity confirmation even when entering the accommodation building using only iris authentication.

[0080] In the example shown in FIG. 9, the authentication terminal 400 is installed in front of the guest room (at the entrance to the location where services are provided in response to successful biometric authentication), and the user U1 has successfully passed face authentication as the first biometric authentication. As described above, the determination unit 243 identifies the attribute of user U1 as a customer based on the attribute information 212. Based on the identified attribute of user U1, the determination unit 243 refers to the authentication method information 213 and determines not to use the result of the second biometric authentication for user U1, and also determines not to perform the second biometric authentication. Furthermore, if the user U2 has succeeded in face authentication as the first biometric authentication, the determination unit 243 identifies the attribute of the user U2 as an employee, and determines to use the result of the second biometric authentication based on the identified attribute by referring to the authentication method information 213. Then, the determination unit 243 determines to perform the second biometric authentication.

[0081] By making such a judgment, customers who have already undergone multimodal authentication at the entrance to the accommodation building can be allowed to enter their rooms with just facial recognition.In addition, for employees, identity verification can be carried out more strictly than at the entrance to the accommodation building.

[0082] Furthermore, when the use of the authentication terminal 400 includes payment processing, the determination unit 243 may determine to use the second biometric authentication regardless of the attributes of the user U, and may also determine to perform the second biometric authentication. In the example shown in Fig. 9, the souvenir shop requires the second biometric authentication regardless of whether the attribute of the user U is a customer or an employee. This allows for stricter identity verification for payment processing compared to the provision of other services.

[0083] The determination unit 244 determines a first biometric authentication method from among a plurality of biometric authentication methods depending on the purpose or installation location of the authentication terminal 400. For example, in the example shown in FIG. 9, iris authentication is required at the entrance to the accommodation building regardless of the attributes of user U. Therefore, the determination unit 244 determines to use iris authentication as the first biometric authentication method. Similarly, in the accommodation room, the determination unit 244 determines to use face authentication as the first biometric authentication.

[0084] The determination unit 244 may determine the first biometric authentication method in consideration of the accuracy of the authentication method. For example, even if only face authentication is required as the first biometric authentication, if the user U is wearing a mask and only an iris image can be acquired, the determination unit 244 may determine iris authentication, which has higher authentication accuracy, as the first biometric authentication method. Furthermore, if either authentication method is acceptable and multiple pieces of biometric information can be obtained from the authentication terminal 400, the multiple pieces of biometric information may be obtained, and the authentication method with the higher accuracy may be prioritized and determined as the first biometric authentication.

[0085] 10 is a flowchart showing the flow of authentication control processing according to the present embodiment 2. First, the biometric information acquisition unit 241 receives a biometric authentication request from the authentication terminal 400 and acquires the first and second biometric information (S401).

[0086] Next, the determination unit 244 determines the first biometric authentication method according to the purpose or installation location of the authentication terminal 400 (S402). The authentication control unit 242 transmits a first biometric authentication request corresponding to the determined first biometric authentication method to the authentication device 100 (S403).

[0087] The authentication control unit 242 receives the result of the first biometric authentication from the authentication device 100, and determines whether the first biometric authentication is successful (S404). If the first biometric authentication is successful (Yes in S404), the determination unit 243 identifies the attributes of the user U (S405). The determination unit 243 also determines whether to use the result of the second biometric authentication, and determines whether to perform the second biometric authentication according to the determination result (S406). For example, the determination unit 243 makes the determination by referring to the authentication method information 213.

[0088] If it is determined that the second biometric authentication is to be performed (Yes in S406), the authentication control unit 242 transmits a second biometric authentication request to the authentication device 100 (S407).

[0089] The authentication control unit 242 receives the result of the second biometric authentication from the authentication device 100 and determines whether the second biometric authentication is successful (S408). If the second biometric authentication is successful (Yes in S408), the authentication control unit 242 returns a message to the authentication terminal 400 indicating that the biometric authentication is successful (S409).

[0090] If the first biometric authentication fails in step S404 (No in S404) and if the second biometric authentication fails in step S408 (No in S408), the authentication control unit 242 replies to the authentication terminal 400 that the biometric authentication has failed (S410).

[0091] Furthermore, if it is determined in step S406 that the second biometric authentication is not to be performed (No in S406), the authentication control unit 242 returns a message to the authentication terminal 400 indicating that the biometric authentication has been successful (S409).

[0092] If the biometric authentication is successful (S409), the authentication terminal 400 outputs an instruction signal to the control device of each service to execute processes such as opening / closing the door (gate), unlocking the lock, executing payment processing, executing check-in processing, and executing check-out processing. This allows the user U to receive the desired services, such as entering each facility and processing payments.

[0093] As described above, according to the authentication system 1000 of this embodiment, the attributes of the user U are identified based on the success of the first biometric authentication, and it is possible to determine whether to use the results of the second biometric authentication and whether to perform the second biometric authentication based on the identified attributes. Furthermore, the first biometric authentication method can be determined depending on the purpose or installation location of the authentication terminal 400. Therefore, for example, even if the user U is wearing a mask, the identity of the user U can be appropriately confirmed without removing the mask depending on the attributes of the user U and the purpose or installation location of the authentication terminal 400. Furthermore, for example, in payment processing, strict identity confirmation can be performed depending on the purpose of the biometric authentication, such as requiring multimodal authentication regardless of the attributes of the user U. As described above, the authentication system 1000 according to this embodiment can appropriately verify the identity of the user U while reducing the decrease in convenience for the user U in multimodal authentication.

[0094] <Embodiment 3> The third embodiment is a modification of the second embodiment. In the second embodiment, the authentication control device 200 first controls the first biometric authentication, and then controls the second biometric authentication depending on the success of the first biometric authentication. In contrast, the authentication control device 200 according to the present embodiment first controls both the first and second biometric authentications, and when at least one of the biometric authentications is successful, determines whether to use the result of the other biometric authentication.

[0095] The configuration of the authentication control device 200 according to this embodiment is the same as that of the second embodiment, and therefore a description thereof will be omitted. 11 is a flowchart showing the flow of authentication control processing according to this embodiment. First, the biometric information acquisition unit 241 receives a biometric authentication request from the authentication terminal 400 and acquires first and second biometric information (S501).

[0096] Next, the authentication control unit 242 transmits first and second biometric authentication requests using the acquired first and second biometric information, respectively, to the authentication device 100 (S502). Note that, as in the second embodiment, the determination unit 244 may determine the first biometric authentication method, but since both the first and second biometric authentications are performed in this embodiment, a description thereof will be omitted here.

[0097] The authentication control unit 242 receives the results of the first and second biometric authentications from the authentication device 100, and determines whether or not at least one of the biometric authentications has been successful (S503). If either of the biometric authentications has been successful (Yes in S503), the determination unit 243 identifies the attributes of the user U (S504). Furthermore, the determination unit 243 determines whether or not to use the result of the other biometric authentication based on the identified attributes (S505). For example, the determination unit 243 makes the determination by referring to the authentication method information 213.

[0098] If it is determined that the result of the other biometric authentication is to be used (Yes in S505), the authentication control unit 242 determines whether the other biometric authentication has been successful (S506).

[0099] If the other biometric authentication is successful (Yes in S506), the authentication control unit 242 returns a message to the authentication terminal 400 indicating that the biometric authentication was successful (S507).

[0100] If the first biometric authentication fails in step S503 (No in S503) and if the other biometric authentication fails in step S506 (No in S506), the authentication control unit 242 replies to the authentication terminal 400 that the biometric authentication has failed (S508).

[0101] Furthermore, in step S505, if it is determined that the result of the other biometric authentication is not to be used (No in S505), the authentication control unit 242 returns a message to the authentication terminal 400 indicating that the biometric authentication was successful (S507).

[0102] If the biometric authentication is successful (S507), the user U can receive the desired service, such as opening and closing a door (gate).

[0103] As described above, the authentication control device 200 according to this embodiment performs both the first and second biometric authentications, and if at least one of them is successful, identifies the attributes of the user U and determines whether to use the result of the other biometric authentication based on the identified attributes. For example, suppose that the user U performs face authentication and iris authentication while wearing a mask. It is considered that the user U fails face authentication but succeeds iris authentication, but if the iris authentication is successful, the authentication control device 200 can identify the attributes of the user U and determine whether to use the result (failure) of face authentication based on the attributes. Therefore, for example, in a situation where authentication is successful only if the iris authentication is successful, by determining not to use the result of face authentication, the user U can receive the desired service even if the face authentication fails. Therefore, the authentication control device 200 according to this embodiment can achieve the same effects as those of the second embodiment.

[0104] <Embodiment 4> The present embodiment 4 is a modification of the above-described embodiment 2. The authentication control device 200a according to the present embodiment performs authentication processing in response to a biometric authentication request received from the authentication terminal 400 without going through the authentication device 100, and returns the result to the authentication terminal 400.

[0105] Fig. 12 is a block diagram showing the configuration of an authentication control device 200a according to this embodiment. As shown in Fig. 12, the authentication control device 200a includes a storage unit 210, a memory 220, a communication unit 230, and a control unit 240. The storage unit 210 stores a program 211, attribute information 212, authentication method information 213, and further stores biometric information 214.

[0106] The biometric information 214 corresponds to the biometric information DB 110 of the authentication device 100 described above, and stores a user ID 2141, biometric feature information 2142, and a biometric authentication method 2143 in association with each other.

[0107] The biometric information acquisition unit 241a determines whether second biometric information is registered in the biometric information 214 for the user U who has succeeded in the first biometric authentication, and if the second biometric information is not registered, acquires the second biometric information from the user U. For example, if the user U has registered only face information and not iris information, the biometric information acquisition unit 241a acquires iris information of the user U. Then, the biometric information acquisition unit 241a associates the user ID, the face information that is the registered first biometric information, and the iris information that is the acquired second biometric information, and registers them in the biometric information 214.

[0108] As described in the second embodiment, the second biometric information can be acquired by displaying a message on the display unit 440 to the effect that an iris image will be taken, and obtaining consent from the user U. When the user U consents to having their iris imaged, the second camera 411 takes a picture of the iris of the user U, and the biometric information acquisition unit 241a acquires the iris image via the network N.

[0109] The biometric information acquisition unit 241a also has the functions of the detection unit 120, feature point extraction unit 130, registration unit 140, and authentication unit 150 in the authentication device 100. That is, the biometric information acquisition unit 241a detects an iris area from an iris image included in a biometric information registration request received from the authentication terminal 400, extracts iris feature information, and issues a user ID. The biometric information acquisition unit 241a also registers in the storage unit 210 biometric information 214 that associates a user ID 2141 with first and second biometric feature information 2142 and a biometric authentication method 2143.

[0110] The authentication control unit 242a controls biometric authentication by comparing feature information extracted from areas such as the face and iris of the user U contained in the acquired captured image with the biometric feature information 2142 stored in the memory unit 210. The configuration other than the above is the same as that of the second embodiment, and therefore the description thereof will be omitted.

[0111] As described above, the authentication control device 200a according to this embodiment can achieve the same effects as those of the second embodiment.

[0112] <Embodiment 5> The fifth embodiment is a modification of the second embodiment. An authentication control device 200b according to the fifth embodiment has the functions of the authentication terminal 400 described in the second embodiment.

[0113] 13 is a block diagram showing the configuration of an authentication control device 200b according to this embodiment. As shown in FIG. 13, the authentication control device 200b includes a storage unit 210, a memory 220, a communication unit 230, a control unit 240, a first camera 250, a second camera 251, and a display unit 260. Furthermore, the control unit 240 can realize the functions of an imaging control unit 245, a registration unit 246, and a display control unit 248 in addition to the functions described in the second embodiment.

[0114] First camera 250, second camera 251, and display unit 260 correspond to first camera 410, second camera 411, and display unit 440 in embodiment 2, respectively. That is, first camera 250 captures, for example, the face of user U, and second camera 251 captures the iris of user U. Display unit 260 is at least a display device, and may also be an output unit including an input device, for example, a touch panel.

[0115] The biometric information acquisition unit 241b acquires the first and second biometric information of the user U from the face image and iris image of the user U captured by the first camera 250 and the second camera 251.

[0116] The photographing control unit 245, the registration unit 246, and the display control unit 248 correspond to the photographing control unit 451, the registration unit 452, and the display control unit 454, respectively, described in the second embodiment. However, the photographing control unit 245 outputs the registration image to the registration unit 246, but outputs the authentication image to the authentication control unit 242b.

[0117] The determination unit 244b determines a first biometric authentication method from among a plurality of biometric authentication methods depending on the purpose or installation location of the authentication control device 200b. The authentication control unit 242b controls the first biometric authentication corresponding to the determined first biometric authentication method. The configuration other than the above is the same as that of the second embodiment, and therefore the description thereof will be omitted.

[0118] As described above, the authentication control device 200b according to this embodiment can achieve the same effects as those of the second embodiment.

[0119] Although the above-described embodiment has been described as a hardware configuration, the present disclosure is not limited to this. Any processing in the present disclosure can also be realized by causing a CPU to execute a computer program.

[0120] In the above example, the program can be stored and supplied to a computer using various types of non-transitory computer-readable media. Non-transitory computer-readable media include various types of tangible storage media. Examples of non-transitory computer-readable media include magnetic storage media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical storage media (e.g., magneto-optical disks), CD-ROMs (Read Only Memory), CD-Rs, CD-R / Ws, DVDs (Digital Versatile Discs), and semiconductor memories (e.g., mask ROMs, PROMs (Programmable ROMs), EPROMs (Erasable PROMs), flash ROMs, and RAMs (Random Access Memory)). The program may also be supplied to a computer by various types of transitory computer-readable media. Examples of transitory computer-readable media include electrical signals, optical signals, and electromagnetic waves. The transitory computer-readable media can be supplied to a computer via wired communication paths such as electrical wires and optical fibers, or via wireless communication paths.

[0121] The present disclosure is not limited to the above-described embodiments, and may be modified as appropriate without departing from the spirit and scope of the present disclosure. In addition, the present disclosure may be implemented by appropriately combining the respective embodiments. For example, although the above description has been given using face authentication and iris authentication as the first and second biometric authentication methods, other biometric authentication methods may be used. Furthermore, biometric authentication may be performed using three or more authentication methods. Furthermore, instead of using multiple biometric authentication methods, biometric authentication may be combined with a technology other than biometric authentication. For example, in the example shown in FIG. 9, in the authentication before entering the guest room, user U2, who is an employee, must succeed in face authentication and iris authentication. Here, the authentication terminal 400, for example, photographs the uniform or employee name tag worn by user U2 and determines whether user U2 is an employee through image recognition or the like. If user U2 is determined to be an employee, the authentication control device 200 may perform only iris authentication on user U2 without performing face authentication. This allows user U2 to be authenticated and enter the guest room without removing the mask, even if he or she is wearing a mask.

[0122] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes. (Appendix 1) a biometric information acquisition means for acquiring first biometric information and second biometric information of a predetermined user; an authentication control means for controlling at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; a determination means for determining whether or not to use the result of the other biometric authentication when at least one of the first biometric authentication and the second biometric authentication is successful; Equipped with Authentication control device. (Appendix 2) The authentication control means controls the other biometric authentication when it is determined that the result of the other biometric authentication is to be used. 10. The authentication control device according to claim 1. (Appendix 3) The determination means Identifying an attribute of the user who has successfully passed one of the biometric authentications; Determine whether to use the result of the other biometric authentication based on the identified attribute. 3. An authentication control device according to claim 1 or 2. (Appendix 4) the biometric information acquisition means acquires the first biometric information and the second biometric information from a predetermined authentication terminal; a determination unit that determines a first biometric authentication method from among a plurality of biometric authentication methods according to the purpose or installation location of the authentication terminal; The authentication control means controls the first biometric authentication corresponding to the determined first biometric authentication method. 4. An authentication control device according to claim 3. (Appendix 5) The determination means determines to use the result of the other biometric authentication when the use of the authentication terminal includes payment processing. 5. An authentication control device according to claim 4. (Appendix 6) the authentication terminal is installed at an entrance of a location where a service is provided in response to successful biometric authentication; The determination means If the attribute of the user who has succeeded in the one biometric authentication is that of the service provider, it is determined that the result of the other biometric authentication is to be used; If the attribute of the user is a person to whom the service is to be provided, it is determined that the result of the other biometric authentication is not to be used. 6. An authentication control device according to claim 4 or 5. (Appendix 7) the authentication terminal is installed at a common entrance to a plurality of service provision locations for a plurality of recipients of services that are provided in response to successful biometric authentication; The determination means If the attribute of the user who has succeeded in one of the biometric authentications is a person to whom the service is to be provided, it is determined that the result of the other of the biometric authentications is to be used; If the attribute of the user is that of the service provider, it is determined that the result of the other biometric authentication is not to be used; The one biometric authentication has higher authentication accuracy than the other biometric authentication. 7. An authentication control device according to any one of appendixes 4 to 6. (Appendix 8) Further, a storage means is provided for storing at least the user and the first biological information in association with each other, The biometric information acquisition means If the second biometric information of a user who has succeeded in the first biometric authentication is not registered in the storage means, the second biometric information is acquired from the user; The user and the first biometric information are associated with the acquired second biometric information and registered in the storage means. 8. An authentication control device according to any one of appendices 1 to 7. (Appendix 9) The authentication control means determines a first biometric authentication method from among a plurality of biometric authentication methods according to the purpose or installation location of the authentication control device, and controls the first biometric authentication corresponding to the determined first biometric authentication method. 4. An authentication control device according to any one of claims 1 to 3. (Appendix 10) an authentication terminal that acquires multiple types of biometric information from a predetermined user; an authentication control device connected to the authentication terminal; Equipped with The authentication control device acquiring first biometric information and second biometric information of the user from the authentication terminal; controlling at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; If at least one of the first biometric authentication and the second biometric authentication is successful, it is determined whether or not to use the result of the other biometric authentication. Authentication system. (Appendix 11) The authentication control device When it is determined that the result of the other biometric authentication is to be used, the other biometric authentication is controlled. 10. The authentication system described in Appendix 10. (Appendix 12) The computer Acquire first biometric information and second biometric information of a predetermined user; controlling at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; If at least one of the first biometric authentication and the second biometric authentication is successful, it is determined whether or not to use the result of the other biometric authentication. Authentication control methods. (Appendix 13) a biometric information acquisition process for acquiring first biometric information and second biometric information of a predetermined user; an authentication control process for controlling at least one of a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; a determination process for determining whether or not to use the result of the other biometric authentication when at least one of the first biometric authentication and the second biometric authentication is successful; A non-transitory computer-readable medium storing an authentication control program that causes a computer to execute the above. [Explanation of symbols]

[0123] 10 Authentication control device 11 Biometric information acquisition unit 12 Authentication control section 13 Judgment section 100 Authentication Device 110 Biometric Information DB 111 User ID 112 Biometric characteristics information 113 Biometric authentication methods 120 Detector 130 Feature point extraction unit 140 Registration Department 150 Authentication Department 200, 200a, 200b Authentication control device 210 Storage section 211 Program 212 Attribute information 213 Authentication method information 214 Biometric Information 220 memory 230 Communications Department 240 Control Unit 241, 241a Biometric information acquisition unit 242, 242a, 242b Authentication control unit 243 Judgment section 244 Decision Section 400, 400a~400g authentication terminal 410 First Camera 411 Second Camera 420 Storage section 430 Communications Department 440 Display section 450 control section 451 Imaging control unit 452 Registration Department 453 Authentication control unit 454 Display control unit 1000 Authentication System 2121 User ID 2122 Attributes 2131 Location ID 2132 Purpose 2133 attributes 2134 Authentication Method 2141 User ID 2142 Biometric characteristics information 2143 Biometric authentication method N Network U User

Claims

1. a biometric information acquiring means for acquiring first biometric information and second biometric information of a predetermined user from a predetermined authentication terminal; an authentication control means for controlling a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; a determination means for determining whether or not to use the result of the other biometric authentication when at least one of the first biometric authentication and the second biometric authentication is successful; Equipped with a biometric authentication method corresponding to each of the first biometric authentication and the second biometric authentication is determined regardless of a selection by the user; The determination means identifies an attribute of the user who has succeeded in one of the biometric authentications, and determines whether or not to use the result of the other biometric authentication based on the attribute of the user and the purpose of the authentication terminal or the installation location of the authentication terminal. Authentication control device.

2. The determination means determines to use the result of the other biometric authentication when the use of the authentication terminal includes payment processing. The authentication control device according to claim 1 .

3. the authentication terminal is installed at an entrance of a location where a service is provided in response to successful biometric authentication; The determination means If the attribute of the user who has succeeded in the one biometric authentication is that of the service provider, it is determined that the result of the other biometric authentication is to be used; If the attribute of the user is a person to whom the service is to be provided, it is determined that the result of the other biometric authentication is not to be used. The authentication control device according to claim 1 or 2.

4. the authentication terminal is installed at a common entrance to a plurality of service provision locations for a plurality of recipients of services that are provided in response to successful biometric authentication; The determination means If the attribute of the user who has succeeded in one of the biometric authentications is a person to whom the service is to be provided, it is determined that the result of the other of the biometric authentications is to be used; If the attribute of the user is the service provider, it is determined that the result of the other biometric authentication is not to be used. The authentication control device according to claim 1 or 2.

5. an authentication terminal that acquires multiple types of biometric information from a predetermined user; an authentication control device connected to the authentication terminal; Equipped with The authentication control device acquiring first biometric information and second biometric information of the user from the authentication terminal; controlling a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; If at least one of the first biometric authentication and the second biometric authentication is successful, determining whether to use the result of the other biometric authentication; a biometric authentication method corresponding to each of the first biometric authentication and the second biometric authentication is determined regardless of a selection by the user; In determining whether to use the result of the other biometric authentication, the attributes of the user who has succeeded in the one biometric authentication are identified, and the determination is made whether to use the result of the other biometric authentication based on the attributes of the user and the purpose of the authentication terminal or the installation location of the authentication terminal. Authentication system.

6. The computer acquiring first biometric information and second biometric information of a predetermined user from a predetermined authentication terminal; controlling a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; If at least one of the first biometric authentication and the second biometric authentication is successful, determining whether to use the result of the other biometric authentication; a biometric authentication method corresponding to each of the first biometric authentication and the second biometric authentication is determined regardless of a selection by the user; In determining whether to use the result of the other biometric authentication, the attributes of the user who has succeeded in the one biometric authentication are identified, and the determination is made whether to use the result of the other biometric authentication based on the attributes of the user and the purpose of the authentication terminal or the installation location of the authentication terminal. Authentication control methods.

7. a biometric information acquisition process for acquiring first biometric information and second biometric information of a predetermined user from a predetermined authentication terminal; an authentication control process for controlling a first biometric authentication using the first biometric information and a second biometric authentication using the second biometric information; a determination process for determining whether to use the result of the other biometric authentication when at least one of the first biometric authentication and the second biometric authentication is successful; on the computer, a biometric authentication method corresponding to each of the first biometric authentication and the second biometric authentication is determined regardless of a selection by the user; In the determination process, the attributes of the user who has succeeded in one biometric authentication are identified, and it is determined whether or not to use the result of the other biometric authentication based on the attributes of the user and the purpose of the authentication terminal or the installation location of the authentication terminal. Authentication control program.

Citation Information

Patent Citations

  • Jig for containing wafer

    JP1982096523A

  • Hotel system

    JP2003256583A

  • Authentication control device and method

    JP2005173805A

  • Personal authentication system and method

    JP2005317049A

  • User authentication system, method, program, and device

    JP2013030124A