Identity verification system, identity verification method and program

The identity verification system enhances authentication by using image analysis to detect and prevent the use of forged identity documents, ensuring secure and efficient network access.

JP7721359B2Active Publication Date: 2025-08-12ACSION CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021131261
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-11
Publication Date
2025-08-12
Estimated Expiration
2041-08-11

AI Technical Summary

Technical Problem

Existing identity verification methods, such as electronic certificates and two-step authentication, are cumbersome, costly, and vulnerable to impersonation due to the ease of registering legitimate devices for continuous authentication, making it difficult to prevent the use of forged identity documents.

Method used

An identity verification system that utilizes image analysis to compare facial images and personal identification information from official certificates with registered data, determining authenticity and preventing impersonation by detecting forged documents, even if they are leaked or cleverly counterfeited.

Benefits of technology

The system quickly and reliably identifies and prevents the use of forged identity documents, improving the accuracy of authentication processes and preventing fraudulent account openings or uses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007721359000001
    Figure 0007721359000001
  • Figure 0007721359000002
    Figure 0007721359000002
  • Figure 0007721359000003
    Figure 0007721359000003
Patent Text Reader

Abstract

To provide an identity verification system capable of preventing "spoofing" as others using false identity verification documents such as the reuse of official identity verification documents in an electronic procedure using a network such as an internet.SOLUTION: In an identification verification system, an authentication server device 10 carries out a given procedure on the premise of an identity verification when opening an account or continuing to use the account, and changing or updating information. The authentication server device identifies forgeries such as the reuse of identity verification documents while determining whether or not the identity verification certificate is forged by using the previous history when the authentication server device accepts electronically an identity verification certificate such as a driver's license or a passport via a network. And then, the authentication server can prevent unauthorized use of an account such as the unauthorized creation of a new account and the change of account information using the forged documents.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an identity verification system, an identity verification method, a program, and the like. [Background technology]

[0002] Conventionally, various application procedures such as opening a bank account or joining a network service have often been completed by submitting identification documents such as a driver's license or passport, even if they have been done electronically using the Internet.

[0003] However, in recent years, techniques for counterfeiting personal identification documents have become more sophisticated, and it is becoming increasingly difficult to detect counterfeit documents alone.

[0004] Furthermore, because such identity verification involves cumbersome work and takes time, various methods have recently been adopted, such as electronic certificates in which a third party (certification authority) electronically certifies the identity of the person, or two-step authentication using information terminal devices such as smartphones and mobile phones. Summary of the Invention [Problem to be solved by the invention]

[0005] However, with such identity verification methods that use electronic certificates, it takes time and money to obtain the electronic certificate, making it difficult to carry out the process and resulting in a complicated procedure.

[0006] Furthermore, although the above-mentioned two-step authentication method of identity verification is effective for authentication during continued use, if the user registers their own information terminal device as a legitimate information terminal device when registering to open an account, etc., they can be continuously authenticated, which means that they can impersonate someone else to verify their identity.

[0007] The present invention has been made to solve the above-mentioned problems, and its purpose is to provide an identity verification system that can prevent "impersonation" of another person using fake identity verification documents, such as the reuse of official identity verification documents, in electronic procedures using a network such as the Internet.

[0008] Furthermore, the present invention provides an identity verification system that can determine whether or not an already registered official identity verification document is forged after the fact, and can quickly and reliably prevent "impersonation" by malicious third parties using such documents, even if the identity verification document is leaked or cleverly forged identity verification documents are circulated. [Means for solving the problem]

[0009] (1) In order to solve the above problems, the present invention provides: An identity verification system that performs a process related to identity verification of a user as identity verification processing to enjoy a given network service by using a public certificate for verifying the identity of the user having a person image in which the person including a face is imaged and personal identification information, a management means for managing each registered official certificate information, which is information on the official certificate stored in a storage means as data, and which includes the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; a reception processing means for receiving input information including at least image information of the identity verification certificate obtained by imaging the official certificate of the specific user who desires the identity verification processing; an image analysis processing means for executing image analysis processing to detect, from the received image information of the personal identification certificate, an image of a person formation area including the person and the personal identification information imaged in the image information of the personal identification certificate as a detected person formation area image and a detected personal identification item, respectively; a determination processing means for executing a certificate information determination process for searching the registered official certificate information based on the detected person formation area image and detected personal identification information detected by the image analysis process, and determining whether or not at least one of the registered person formation area image and the registered personal identification information exists within a range that is identical to or considered to be identical to at least one of the detected person formation area image and detected personal identification information; an identification processing means for executing a given identification process based on the fact that the accepted input information is not authentic or is highly likely to be not authentic, when the certificate information determination process determines that one of the detected person formation area image and the detected personal identification information is the same or within a range where it is considered to be identical with one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and the other of the detected person formation area image and the detected personal identification information is not identical; The configuration includes:

[0010] With this configuration, when a given procedure is executed on the premise that identity verification will be performed, such as when opening an account, and when an identity verification certificate such as a driver's license (e.g., for a car) or a passport is accepted electronically via a network, the present invention can detect a forged identity verification certificate by utilizing past history, thereby identifying fraudulent use such as the reuse of identity verification documents and preventing the fraudulent opening of new accounts or fraudulent use of accounts.

[0011] Note that a "person image" is an image that includes all or part of a person, including a face, such as an image centered on the face from the shoulders up, an image of the upper body, or an image including the entire body of a person. In particular, a "person image" may include an image that includes a background, or an image in which the person is wearing accessories such as glasses.

[0012] "Personal identification information" includes, for example, name, date of birth, gender, identification information on certificates (such as passport number and driver's license number), place of residence (address or residence), and contact information (telephone number or email address).

[0013] Furthermore, "official documents" include, for example, passports, residence cards, alien registration certificates, driver's licenses, seaman's handbooks, seaman's licenses, personal identification cards (also known as My Number cards and Social Security numbers), and photo identification cards issued to employees by government agencies, independent administrative agencies, special corporations, and local independent administrative agencies.

[0014] The "input information" may be only the image information of the identification certificate, or may include a facial image different from the image information of the identification certificate, such as a selfie of the user, name, date of birth, gender, age or generation, address, email address, telephone number, information about the terminal device being used, IP address, and information about the place of employment.

[0015] Furthermore, the "detected person formation area image" includes at least an image of the area where a person image is detected, and may be an image that includes other images such as a background, or an image that includes images of other areas in the identity verification certificate.

[0016] In addition to the above, the "range considered to be identical" includes, for example, cases where the feature points of a person's image (the position and shape of the facial contour, hairstyle, or eyes, nose, and mouth based on color feature values) are quantified and the score format is used to determine that each person's image falls within a numerical range that is considered to be identical.

[0017] Furthermore, "given specific processing based on the information being non-genuine or being highly likely to be non-genuine" includes, for example, a non-approval processing that refuses approval in identity verification processing, a notification processing that notifies an administrator of information about a specific user who wishes to be verified as a malicious third party, and a registration processing that registers the specific user on a blacklist that will block them in subsequent identity verification processing.

[0018] (2) The present invention also provides The determination processing means executes a standard determination process for determining whether or not the detected person formation area image conforms to a standard defined in predetermined standard information; The identification processing means The identification process is executed when it is determined that the detected person formation area image does not conform to a standard defined in predetermined standard information.

[0019] With this configuration, if the image in the detected person formation area, such as the size of the person image (such as the ratio and position of the facial image to the detected person formation area), color (such as background color or skin color), facial orientation (such as front or tilt), facial expression (such as the position of the corners of the mouth), and the presence or absence of clothing or accessories (such as glasses or a hat), does not conform to predetermined standards, the present invention can perform specific processing such as a non-approval process that refuses approval in the identity verification process, assuming that the identity verification document itself is forged.

[0020] The "standard information" includes, for example, data on the standard for the image of the area portion where a person is formed and the standard for the image of the area portion where a person is not formed.

[0021] In particular, the "Information on Standards for Images of Areas in Which People are Formed..." (A1) A face image is placed at the center position of the detected person formation area; (A2) The face recognized by the facial image faces forward; (A3) The face image is not tilted left or right relative to the detected person formation area. (A4) Hair or accessories (glasses or hats) are formed in specific areas of the face image area (the frames of glasses do not cover the eyes or part of the face, and the eyes, head, or face outline are not hidden by glasses, hats, hairbands, hair, etc.), and (A5) The facial appearance is not significantly different from normal, such as the corners of the mouth being turned up, the eyes being closed, the eyes being narrowed, or teeth being visible. It includes data that specifies the following:

[0022] In addition, the "Information on standards for images of areas where people are not present" states: (B1) The area that is the background other than the face image or person image in the detected person formation area (hereinafter referred to as the “background area”) is not a predetermined background (e.g., not a specific color or not composed of one color), and (B2) The image is out of focus, has a shadow on the face, has noise (image distortion), has jagged edges (step-like jagged patterns), or has undergone image processing such as deformation or masking (edging). It includes information about standards such as:

[0023] (3) The present invention also provides The standards defined in the standards information include at least one of standards for images of area portions where people are formed and standards for images of area portions where people are not formed.

[0024] With this configuration, if the image in the detected person formation area does not conform to a predetermined standard, the present invention can determine that the identification document is forged and perform specific processing such as a non-approval process that refuses approval in the identification process.

[0025] (4) The present invention also provides The determination processing means execute the person determination process to determine whether or not the detected person formation area image is identical to or within a range that is considered to be identical to a person image of a malicious third party that is stored in advance in the storage means; The identification processing means If the person determination process determines that the detected person formation area image is identical or within a range that can be considered identical to a person image of a malicious third party that has been stored in advance in the storage means, the accepted input information is not legitimate public certificate information and the identification process is executed.

[0026] With this configuration, if the facial image recognized from the identity verification certificate image is listed on a list of malicious third parties (i.e., a blacklist), the present invention can execute specific processing such as a non-approval processing that denies approval in the identity verification processing without having to execute the certificate information judgment processing.

[0027] Therefore, the present invention can improve the accuracy of the certificate information determination process for permitting authentication, that is, the accuracy of executing specific processes such as a non-approval process for refusing approval in the identity verification process.

[0028] (5) The present invention also provides The determination processing means execute a process of detecting each face image information included in the registered public certificate information that is identical or within a range that is considered to be identical to the detected person formation area image determined to be not the legitimate public certificate information; The identification processing means When face image information contained in the registered public certificate information that is identical or within a range that is deemed to be identical to the detected person formation area image that has been determined to be not the genuine public certificate information is detected, the detected registered public certificate information is deemed not to be the genuine public certificate information and is updated and registered.

[0029] With this configuration, the present invention can execute identity verification processing for input information while subsequently determining that an already registered official identity verification document is not a genuine identity verification document, i.e., that it is a forgery. Therefore, even if an identity verification document is leaked or an ingenious forged identity verification document is circulated, it can provide an identity verification system etc. that can quickly and reliably prevent "impersonation" by malicious third parties using these documents.

[0030] (6) The present invention also provides The identification processing means When the certificate information determination process determines that both the detected person formation area image and the detected personal identification information are identical or within a range that is deemed to be identical to both the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, the identification process is configured to register the accepted input information in the storage means as the genuine registered public certificate information.

[0031] With this configuration, if the combination of the detected person formation area image and detected identity information detected from the identity verification certificate image has already been registered as registered public certificate information, the present invention can identify the registered public certificate information as a whitelist, which is information of a legitimate user.

[0032] Therefore, in the present invention, when a detected person formation area image, etc. is listed on a whitelist, specific processing such as an authentication permission processing that permits authentication in identity verification processing can be performed without having to perform a certificate information determination processing.

[0033] As a result, the present invention can improve the accuracy of the certificate information determination process for permitting authentication, that is, the accuracy of executing specific processes such as a non-approval process for refusing approval in the identity verification process.

[0034] (7) The present invention also provides The identification processing means If it is determined that both the detected person formation area image and the detected personal identification information detected by the image analysis process are identical to the genuine registered public certificate information or are within a range that is deemed to be identical, the input information is treated as the genuine public certificate information and an identification process is executed.

[0035] With this configuration, if the facial image recognized by the identity verification certificate image is whitelisted as legitimate, the present invention can execute specific processing such as authentication permission processing in identity verification processing without having to execute certificate information determination processing.

[0036] Therefore, the present invention can improve the accuracy of the certificate information determination process for permitting authentication, that is, the accuracy of executing specific processes such as a non-approval process for refusing approval in the identity verification process.

[0037] (8) The present invention also provides The input information includes, as input face image information, face image information of a face image of the specific user together with the image information of the personal identification certificate, The determination processing means The certificate information determination process is executed using the input face image information.

[0038] With this configuration, when a specific user desires to verify his / her identity, the present invention can determine whether the identity certificate is a forgery by comparing the self-face image sent by the specific user with the face image recognized by the identity certificate image.

[0039] In other words, when a specific user wishes to verify their identity, the present invention can determine whether the specific user is a malicious third party by comparing a self-portrait image sent by the specific user with a face image registered as a blacklist.

[0040] Therefore, the present invention improves the accuracy of the certificate information determination process that allows authentication, i.e., the accuracy of executing specific processes such as a non-approval process that denies approval in the identity verification process, and can also quickly execute the certificate information determination process.

[0041] (9) The present invention also provides An identity verification system that performs a process related to identity verification of a user as identity verification processing to enjoy a given network service by using a public certificate for verifying the identity of the user having a person image in which the person including a face is imaged and personal identification information, a management means for managing each registered official certificate information, which is information on the official certificate stored in a storage means as data, and which includes the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; a reception processing means for receiving input information including at least image information of the identity verification certificate obtained by imaging the official certificate of the specific user who desires the identity verification processing; an image analysis processing means for executing image analysis processing to detect an image of a person formation area that is imaged in the accepted image information of the personal identification certificate and that includes the person, and the personal identification item that is imaged in the image information of the personal identification certificate, as a detected person formation area image and a detected personal identification item, respectively; an identity verification determination processing means for executing a comparison process that compares the registered person formation area image and the registered person identification information included in the registered public certificate information with the detected person formation area image and the detected person identification information detected by the image analysis process, and for executing an identity verification determination process that determines whether or not the person can be recognized as the person in identity verification based on the accepted input information according to the comparison result; a specific processing means for executing a given specific processing depending on a result of the identity verification determination processing; a certificate information determination processing means for executing a registered certificate forgery determination process to determine whether the registered public certificate information is a forged certificate or a certificate that may be forged according to the comparison result; an update processing means for executing an update process to update and register the registered public certificate information as not being genuine public certificate information when the registered certificate counterfeit determination process determines that the registered public certificate information is a counterfeit certificate or a certificate that may be counterfeit, and to update and register the registered public certificate information as being genuine public certificate information when the certificate information determination process determines that the registered public certificate information is not a counterfeit certificate; The configuration includes:

[0042] With this configuration, when a given procedure is executed on the premise that identity verification will be performed, such as when opening an account, and a driver's license (e.g., for a car) or passport identity certificate is accepted electronically via a network, the present invention can perform identity verification processing based on the accepted identity certificate while determining whether or not an already registered identity document is forged or has the potential to be forged.

[0043] In other words, the present invention can perform identity verification processing on input information while determining whether or not an already registered official identity verification document is forged after the fact, thereby providing an identity verification system that can quickly and reliably prevent "impersonation" by malicious third parties using identity verification documents even if the identity verification document is leaked or clever counterfeit identity verification documents are circulated.

[0044] In addition, as the "comparison process", for example, the detected person formation area image and the detected person identification information are compared. , a registered person formation area image and a registered personal identification item corresponding to the registered person formation area image are compared.

[0045] In particular, the "comparison process" involves comparing whether the detected person formation area image and the registered person formation area image are identical (within a range that is considered to be identical), and whether the detected personal identification information and the registered personal identification information corresponding to the registered person formation area image are identical.

[0046] (10) The present invention also provides The certificate determination processing means The registered certificate counterfeit determination process is configured to determine that, when it is determined that either one of the detected person formation area image and the detected personal identification information is identical or within a range that is deemed identical to either the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and the other of the detected person formation area image and the detected personal identification information is not identical to either the detected person formation area image and the detected personal identification information, the combination of the registered person formation area image and the registered personal identification information being determined is public certificate information used or public certificate information that may have been used by a malicious third party.

[0047] With this configuration, the present invention can perform identity verification processing on input information while determining whether or not an already registered official identity verification document is forged after the fact, thereby providing an identity verification system that can quickly and reliably prevent "impersonation" by malicious third parties using identity verification documents even if the identity verification document is leaked or clever counterfeit identity verification documents are circulated.

[0048] (11) The present invention also provides The certificate determination processing means The registered certificate counterfeit determination process is configured to determine that, if it is determined that a combination of the registered person formation area image that is identical to the detected person formation area image or within a range that is considered to be identical, and the registered personal identification information that matches the detected personal identification information, the combination of the registered person formation area image and registered personal identification information that is the subject of determination is the genuine official certificate information.

[0049] With this configuration, the present invention can perform identity verification processing on input information while determining whether or not an already registered official identity verification document is forged after the fact, thereby providing an identity verification system that can quickly and reliably prevent "impersonation" by malicious third parties using identity verification documents even if the identity verification document is leaked or clever counterfeit identity verification documents are circulated.

[0050] (12) The present invention also provides A program for executing a process for verifying the identity of a user as an identity verification process in order to enjoy a given network service using a public certificate for verifying the identity of the user having a person image in which the person includes a face and personal identification information, a management means for managing each registered official certificate information, which is information on the official certificate stored in a storage means as data, and which includes the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; a reception processing means for receiving input information including at least image information of the identity verification certificate obtained by imaging the official certificate of the specific user who desires the identity verification processing; an image analysis processing means for executing image analysis processing to detect, from the received image information of the personal identification certificate, an image of a person formation area including the person and the personal identification details visualized in the image information of the personal identification certificate as a detected person formation area image and a detected personal identification detail, respectively; a determination processing means for executing a certificate information determination process that searches the registered official certificate information based on the detected person formation area image and detected personal identification information detected by the image analysis process, and determines whether or not at least one of the registered person formation area image and the registered personal identification information exists within a range that is identical or deemed to be identical to at least one of the detected person formation area image and detected personal identification information; and an identification processing means that executes a given identification process based on the fact that the accepted input information is not authentic or is highly likely to be not authentic, when the certificate information determination process determines that one of the detected person formation area image and the detected personal identification information is the same as or within a range where it is considered to be identical to one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and that the other of the detected person formation area image and the detected personal identification information is not identical to the other of the detected person formation area image and the detected personal identification information; The computer has a configuration that causes the computer to function as a

[0051] With this configuration, when a given procedure is executed on the premise that identity verification will be performed, such as when opening an account, and when an identity verification certificate such as a driver's license (e.g., for a car) or a passport is accepted electronically via a network, the present invention can detect a forged identity verification certificate by utilizing past history, thereby identifying fraudulent use such as the reuse of identity verification documents and preventing the fraudulent opening of new accounts or fraudulent use of accounts.

[0052] (13) The present invention also provides A program for executing a process for verifying the identity of a user as an identity verification process in order to enjoy a given network service using a public certificate for verifying the identity of the user having a person image in which the person includes a face and personal identification information, a management means for managing each registered official certificate information, which is information on the official certificate stored in a digital form in a storage means, and which includes the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; a reception processing means for receiving input information including at least image information of the identity verification certificate obtained by imaging the official certificate of the specific user who desires the identity verification processing; an image analysis processing means for executing image analysis processing to detect an image of a person formation area that is imaged in the accepted image information of the personal identification certificate and that includes the person, and the personal identification item that is imaged in the image information of the personal identification certificate, as a detected person formation area image and a detected personal identification item, respectively; an identity verification determination processing means for executing a comparison process that compares the registered person formation area image and the registered person identification information included in the registered public certificate information with the detected person formation area image and the detected person identification information detected by the image analysis process, and for executing an identity verification determination process that determines whether or not the person can be recognized as the person in identity verification based on the accepted input information according to the comparison result; a specific processing means for executing a given specific processing depending on a result of the identity verification determination processing; a certificate information determination processing means for executing a registered certificate counterfeit determination process for determining whether the registered public certificate information is a counterfeit certificate or a certificate that may be counterfeit, depending on the result of the comparison; and The registered public certificate information is found to be forged by the registered certificate forgery determination process. an update processing means for executing an update process to update and register the registered public certificate information as not being genuine public certificate information when it is determined that the registered public certificate information is a certificate or a certificate that may be forged, and to update and register the registered public certificate information as being genuine public certificate information when it is determined that the registered public certificate information is not a forged certificate by the certificate information determination process; The computer has a configuration that causes the computer to function as a

[0053] With this configuration, the present invention can perform identity verification processing on input information while determining whether or not an already registered official identity verification document is forged after the fact, thereby providing an identity verification system that can quickly and reliably prevent "impersonation" by malicious third parties using identity verification documents even if the identity verification document is leaked or clever counterfeit identity verification documents are circulated.

[0054] (14) The present invention also provides 1. An identity verification method for performing identity verification of a user as identity verification processing to enjoy a given network service using a public certificate for verifying the identity of the user having a person image in which the person including a face is imaged and identity identification information, managing each registered public certificate information held by the user, the public certificate information being digitized and stored in a storage means, the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; receiving input information including at least image information of the identity verification certificate in which the official certificate of the specific user who desires the identity verification process is imaged; executing an image analysis process to detect, from the received image information of the personal identification certificate, an image of a person formation area including the person and the personal identification information imaged in the image information of the personal identification certificate as a detected person formation area image and a detected personal identification item, respectively; Executing a certificate information determination process to search the registered public certificate information based on the detected person formation area image and detected personal identification information detected by the image analysis process, and to determine whether or not at least one of the registered person formation area image and the registered personal identification information exists within a range that is identical or deemed to be identical to at least one of the detected person formation area image and detected personal identification information; and When the certificate information determination process determines that one of the detected person formation area image and the detected personal identification information is the same as or within a range where it is considered to be the same as one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and the other of the detected person formation area image and the detected personal identification information is not the same as the other of the detected person formation area image and the detected personal identification information, a given identification process is executed based on the fact that the accepted input information is not authentic information or is highly likely to be not authentic information; The present invention has a configuration including the following.

[0055] With this configuration, when a given procedure is executed on the premise that identity verification will be performed, such as when opening an account, and when an identity verification certificate such as a driver's license (e.g., for a car) or a passport is accepted electronically via a network, the present invention can detect a forged identity verification certificate by utilizing past history, thereby identifying fraudulent use such as the reuse of identity verification documents and preventing the fraudulent opening of new accounts or fraudulent use of accounts.

[0056] (15) The present invention also provides 1. An identity verification method for performing identity verification of a user as identity verification processing to enjoy a given network service using a public certificate for verifying the identity of the user having a person image in which the person including a face is imaged and identity identification information, managing each registered public certificate information held by the user, the public certificate information being digitized and stored in a storage means, the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; receiving input information including at least image information of the identity verification certificate in which the official certificate of the specific user who desires the identity verification process is imaged; executing an image analysis process to detect an image of a person formation area that is imaged in the accepted image information of the personal identification certificate and that includes the person, and the personal identification item that is imaged in the image information of the personal identification certificate, as a detected person formation area image and a detected personal identification item, respectively; Execute a comparison process to compare the registered person formation area image and the registered personal identification information included in the registered public certificate information with the detected person formation area image and the detected personal identification information detected by the image analysis process, and execute an identity verification determination process to determine whether or not the person can be recognized as the person in identity verification based on the accepted input information according to the comparison result. Executing a given specific process depending on the result of the identity verification determination process; Executing a registered certificate counterfeit determination process to determine whether the registered public certificate information is a counterfeit certificate or a certificate that may be counterfeit, depending on the comparison result; and executing an update process to update and register the registered public certificate information as not being genuine public certificate information when the registered certificate forgery determination process determines that the registered public certificate information is a forged certificate or a certificate that may be forged, and to update and register the registered public certificate information as being genuine public certificate information when the certificate information determination process determines that the registered public certificate information is not a forged certificate; The present invention has a configuration including the following.

[0057] With this configuration, the present invention can perform identity verification processing on input information while determining whether or not an already registered official identity verification document is forged after the fact, thereby providing an identity verification system that can quickly and reliably prevent "impersonation" by malicious third parties using identity verification documents even if the identity verification document is leaked or clever counterfeit identity verification documents are circulated. [Brief explanation of the drawings]

[0058] [Figure 1] 1 is a system configuration diagram showing a configuration of an authentication management communication system according to an embodiment. [Figure 2] FIG. 2 is a functional block diagram illustrating a configuration of an authentication server device according to an embodiment. [Figure 3] FIG. 2 is a functional block diagram illustrating an example of a configuration of a terminal device according to an embodiment. [Figure 4] FIG. 10 is a diagram (part 1) for explaining the identity verification process in the identity verification process server device of the embodiment; [Figure 5] FIG. 10 is a diagram (part 2) for explaining the identity verification process in the identity verification process server device of the embodiment; [Figure 6] FIG. 2 is a diagram showing an example of information stored in a first database 0 in one embodiment, the information being public certificate information that is digitized and stored in the first database. [Figure 7] FIG. 10 is a diagram illustrating an example of image information of a personal identification certificate according to an embodiment. [Figure 8] 10 is a flowchart showing the operation of the personal identification process (standard specification) executed by the personal identification process server device in one embodiment. [Figure 9] 10 is a flowchart (part 1) showing the operation of the identity verification process (specifications including blacklist registration and whitelist registration) executed by the identity verification server device in one embodiment. [Figure 10] 10 is a flowchart (part 2) showing the operation of the identity verification process (specifications including blacklist registration and whitelist registration) executed by the identity verification server device in one embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0059] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. The embodiment described below is an embodiment in which the identity verification system of the present application is applied to a network service providing system using a network that includes a terminal device used by a user, an identity verification server device that performs identity verification, and a network service server device that provides network services.

[0060] [1] Network service provision system First, an overview of a network service providing system 1 according to this embodiment will be described with reference to FIG.

[0061] FIG. 1 is a system configuration diagram showing the configuration of a network service providing system 1 in this embodiment.

[0062] In addition, to prevent the diagram from becoming too complicated, FIG. 1 shows only terminal devices 20 used by some users and some network service server devices (hereinafter also referred to as "service server devices") 30.

[0063] That is, in the actual network service providing system 1, there are many more terminal devices 20 and service server devices 30 than are shown in FIG.

[0064] The network service providing system 1 of this embodiment is a system that performs identity verification processing to confirm whether or not a user who wishes to use a network service or who wishes to continue using the network service (hereinafter referred to as an "applicant user" or "specific user") is the user himself / herself when the user performs user registration such as opening an account, or when the user updates or changes the user registration.

[0065] The network service providing system 1 of this embodiment is configured to, when it is confirmed that the applying user is the correct user, approve the user registration of the applying user for a given network service and provide the network service.

[0066] In particular, the network service providing system 1 of this embodiment is configured to perform identity verification processing by using a public certificate for verifying the identity of the applying user, which contains an image of the person, including the face of the applying user, and personal identification information.

[0067] Conventionally, typical methods for verifying identity on a network include using an electronic certificate and using a terminal device or application different from the terminal device or application performing the user registration process (so-called two-step authentication).

[0068] However, in the case of such an identity verification method using electronic certificates, Obtaining a digital certificate requires time and expense, and is not an easy process, making the initial procedures complicated.

[0069] Furthermore, although two-step authentication is an effective method of verifying identity for continued use, if a user registers their own information terminal device as a legitimate information terminal device when registering to open an account, etc., they can be continuously authenticated, which makes it easy to forge a false name or register by impersonating someone else.

[0070] Therefore, the network service providing system 1 of this embodiment is configured to compare an identity verification certificate (hereinafter referred to as "identity verification certificate image information") as input information received electronically with public certificate information that has already been registered (hereinafter referred to as "registered public certificate information"), and if the comparison result satisfies a given judgment condition, it is configured to execute a given specific process such as a process of not recognizing the person as the identity of the person in the identity verification process (i.e., a rejection process) based on the fact that the input information received as confirmation is not genuine information or is highly likely to be not genuine information.

[0071] Therefore, the network service providing system 1 of this embodiment is capable of identifying forgery such as the reuse of personal identification documents, and preventing the fraudulent opening of new accounts or the fraudulent use of accounts using such forgery.

[0072] Furthermore, the network service providing system 1 of this embodiment has a configuration in which, in the process of executing the identity verification process, it is determined after the fact whether or not an already registered official identity verification document is forged.

[0073] Furthermore, the network service providing system 1 of this embodiment is capable of quickly and reliably preventing "impersonation" by malicious third parties using personal identification documents even if they are leaked or cleverly forged personal identification documents are circulated.

[0074] Specifically, as shown in FIG. 1, the network service providing system 1 of this embodiment is composed of a server device 10 for identity verification processing that executes various processes such as the identity verification processing described above, a terminal device 20 (e.g., terminal devices 20A, 20B, 20C) that is connected to the server device 10 for identity verification processing via a network such as the Internet and is owned by a user who is the subject of identity verification processing and accepts user operations from that user, and a service server device 30 that provides a given network service to the user if the user is recognized as the user through the identity verification processing.

[0075] The identity verification processing server device 10 is an information processing device that works in conjunction with each terminal device 20 and the service server device 30, and executes various processes including identity verification processing using, for example, an API (application programming interface) or a predetermined platform.

[0076] Furthermore, the personal identification processing server device 10 may be configured as one (device, processor) or as multiple (devices, processors).

[0077] The personal identification processing server device 10 has various databases (broadly speaking, storage devices, memories) in which various information used in personal identification processing is stored. However, the personal identification processing server device 10 of this embodiment may be connected to a database (broadly speaking, storage devices, memories) connected via a network (intranet or internet), or to another server device (broadly speaking, storage devices, memories) that manages, for example, a database of real estate or a map. (not shown) may be accessed.

[0078] The terminal device 20 is a communication terminal device configured by an information processing device such as a PC (personal computer), a tablet-type information communication terminal device, a smartphone, a mobile phone, or a game device used by a user.

[0079] In addition, the terminal device 20 is a device that can be connected to the identity verification processing server device 10 via a network such as the Internet (WAN) or LAN, and is configured to establish a communication line with the identity verification processing server device 10 via wired or wireless means to exchange various types of data.

[0080] The terminal device 20 is configured to have a communication control function for communicating with the identity verification processing server device 10 and the service server device 30, such as transmitting input information entered by the user, and a display function for performing display control using data received from the identity verification processing server device 10 and the service server device 30.

[0081] The service server device 30 is a server device for providing various network services including banking services that provide financial institution-related services, reservation services for restaurants, inns, transportation, etc., product sales services, SNS (social networking services), content provision services such as games, music, and videos, cloud services such as various applications such as email, and information provision services such as search and advertisements.

[0082] In particular, the service server device 30 is configured to, when the user is successfully authenticated by the identity verification processing server device 10, log in the authenticated terminal device 20 to the network service it provides and execute various processes to provide the corresponding service to the user.

[0083] The service server device 30 may have various functions related to authentication such as the identity verification process of the identity verification process server device 10.

[0084] [2] Identity verification server device Next, the personal identification processing server device 10 of this embodiment will be described with reference to Fig. 2. Fig. 2 is an example of a functional block diagram showing the configuration of the personal identification processing server device 10 of this embodiment.

[0085] The server device 10 for identity verification processing of this embodiment has a processing unit 100, a first database 140, a second database 150, a memory unit 170, an information storage medium 180, and a communication unit 196, as illustrated in Figure 2.

[0086] The personal identification processing server device 10 does not need to include all of the components shown in FIG. 2, and may have a configuration in which some of them are omitted.

[0087] The first database 140 and the second database 150, together with the storage unit 170, constitute the storage means of the present invention.

[0088] The storage unit 170 serves as a work area for the processing unit 100 and the like, and its function can be realized by hardware such as RAM (VRAM). In particular, the storage unit 170 functions as a work area used when various processes are executed.

[0089] For example, the storage unit 170 stores standard information that defines a given standard to be used in the identity verification process. It is prescribed.

[0090] The information storage medium 180 is computer-readable, and stores programs, data, etc. In other words, the information storage medium 180 stores programs for causing a computer to function as each unit of this embodiment (programs for causing a computer to execute the processing of each unit).

[0091] The processing unit 100 can perform various processes of this embodiment based on data read from a program (data) stored in this information storage medium 180.

[0092] For example, the information storage medium 180 is an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.

[0093] The first database 140 is formed by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.

[0094] In particular, the first database 140 stores information about the official certificate of each user that has been used in the identity verification process that has already been executed (hereinafter referred to as "official certificate information").

[0095] That is, in the first database 140, public certificate information is registered as registered public certificate information, which is associated with a person image in which a person including the face of each user is imaged and personal identification information for identifying each user.

[0096] Like the first database 140, the second database 150 is formed by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, or a memory (ROM), a memory card, etc.

[0097] The second database 150 is a database in which data of images of malicious third parties is registered as blacklist information (hereinafter referred to as "blacklist information").

[0098] The second database 150 may be partially incorporated into the first database 140.

[0099] The communication unit 196 performs various controls for communicating with the outside (for example, the terminal device 20 or the service server device 30), and its functions are configured by hardware such as various processors or communication ASICs, programs, etc.

[0100] The processing unit 100 performs various processes of this embodiment based on programs (data) stored in the storage unit 170. Note that the processing unit 100 of this embodiment may read out programs and data stored in the information storage medium 180, temporarily store the read out programs and data in the storage unit 170, and perform processing based on the programs and data.

[0101] The processing unit 100 (processor) performs various processes using the main memory in the memory unit 170 as a work area. The functions of the processing unit 100 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.

[0102] Specifically, the processing unit 100 includes a communication control unit 101 , a DB management control unit 102 , an image analysis processing unit 103 , a personal identification processing unit 104 , a specific processing control unit 105 , and a timer management unit 110 .

[0103] For example, the communication control unit 101 of this embodiment constitutes a receiving unit of the present invention, the image analysis processing unit 103 constitutes an image analysis processing unit of the present invention, the personal identification processing unit 104 of this embodiment constitutes a determination processing unit of the present invention, and the identification processing control unit 105 constitutes an identification processing unit of the present invention.

[0104] The communication control unit 101 establishes a communication line with the terminal device 20, the service server device 30, etc. via the network, and communicates with them.

[0105] In particular, the communication control unit 101 of this embodiment works in conjunction with the terminal device 20 and the service server device 30, and acquires information (hereinafter referred to as "input information") for applying for and updating user registration entered into the terminal device 20 when each user performs identity verification.

[0106] The DB management control unit 102 executes processes such as reading, writing, deleting, and updating of each piece of data in the first database 140 and the second database 150.

[0107] The image analysis processing unit 103 performs various image analyses on the official certificate image information contained in the acquired input information, and identifies the applicant user's personal image and personal identification information from the image information contained in the acquired input information, as personal image information and personal identification information, respectively.

[0108] The identity verification processing unit 104 works in conjunction with the terminal device 20 and the service server device 30, and performs identity verification processing on the relevant user (e.g., the applying user) when the user performs a procedure that requires identity verification, such as new registration for a service provided by the service server device 30 or updating registration details to continue receiving the service.

[0109] In addition, when performing the above-mentioned identity verification process, the identity verification processing unit 104 also performs a process (hereinafter referred to as "certificate information determination process") to determine whether or not the registered public certificate information is forged or the possibility of forgery based on the application information.

[0110] The specific processing control unit 105 performs a given specific processing based on the result of the certificate information determination processing.

[0111] Specifically, the identification processing control unit 105 performs identification processing such as identifying malicious third parties, notifying information about the identified malicious third parties, updating a blacklist based on the information, registering a whitelist based on the information, or registering information about unauthorized access.

[0112] The timer management unit 110 has a function of measuring the current date and time and from a predetermined timing, and outputs the current time and the measurement result when the predetermined timing arrives.

[0113] [3] Terminal device Next, the functions of the terminal device 20 will be described with reference to Fig. 3. Fig. 3 is a functional block diagram showing an example of the configuration of the terminal device 20 of this embodiment.

[0114] As shown in FIG. 3, the terminal device 20 of this embodiment has a processing unit 200, an imaging unit 250, an operation input unit 260 consisting of a touch panel or the like, a memory unit 270, an information storage medium 280, a display unit 290 consisting of a display element such as a liquid crystal panel, a communication unit 296, and a sound output unit 292.

[0115] The imaging unit 250 is made up of an imaging camera having a predetermined imaging angle and focal length and a predetermined imaging element such as a CCD, and an image generating unit that converts the output of the imaging camera into an image.

[0116] The operation input unit 260 is a device for inputting input information from the player, and outputs the input information from the player to the processing unit 200 .

[0117] The operation input unit 260 of this embodiment includes a detection unit 262 that detects input information (input signals) from the user, and is configured by, for example, a lever, a button, a microphone, a touch panel display, a keyboard, a mouse, and the like.

[0118] In addition, the operation input unit 260 works in conjunction with the processing unit 200 to transmit application information, which is information entered by the user when performing new registration for a service provided by the service server device 30, to the identity verification processing server device 10.

[0119] The storage unit 270 serves as a work area for the processing unit 200 and the like, and its function can be realized by hardware such as RAM (VRAM).

[0120] The storage unit 270 of this embodiment includes a main storage unit 271 used as a work area, an image buffer 272 in which the final display image and the like are stored, and a user information storage unit 273 in which user information is stored. Note that a configuration in which some of these components are omitted may also be adopted.

[0121] The information storage medium 280 is computer-readable, and stores various applications, an OS (operating system), and, in particular, in this embodiment, various data including the user ID of the user corresponding to the terminal device 20.

[0122] That is, the information storage medium 280 stores applications for causing a computer to function as each unit of this embodiment (applications for causing a computer to execute the processing of each unit) and a user ID.

[0123] For example, the information storage medium 280 is an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk drive, a flash memory, a magnetic tape, a memory (ROM), a memory card, or the like.

[0124] The communication unit 296 performs various controls for communicating with the outside (e.g., other terminal devices 20, the identity verification processing server device 10, and the service server device 30), and its functions are configured by hardware such as various processors or communication ASICs, programs, etc.

[0125] The processing unit 200 can perform various processes of this embodiment by reading and executing the applications stored in this information storage medium 280. Note that the types of applications stored in the information storage medium 280 are arbitrary.

[0126] The processing unit 200 performs various processes of this embodiment based on the application stored in the information storage medium 280. Note that the processing unit 200 of this embodiment may read out programs and data stored in the information storage medium 280, temporarily store the read out programs and data in the storage unit 270, and perform processing based on the programs and data.

[0127] The processing unit 200 (processor) performs various processes using the main memory in the memory unit 270 as a work area. The functions of the processing unit 200 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.

[0128] The processing unit 200 includes a communication control unit 210, a web browser 211, a display control unit 213, an input reception processing unit 214, a drawing unit 220, and a sound processing unit 230. Note that some of these may be omitted.

[0129] The communication control unit 210 performs processing to send and receive data to and from the personal identification processing server device 10 or the service server device 30. The communication control unit 210 also receives data transmitted from the personal identification processing server device 10 or the service server device 30, and performs processing to store the received data in the storage unit 270, processing to analyze the received data, and other control processing related to the transmission and reception of data.

[0130] The communication control unit 210 may store and manage destination information (IP address, port number) of the identity verification processing server device 10 and the service server device 30 in the information storage medium 280. The communication control unit 210 may then communicate with the identity verification processing server device 10 or the service server device 30 when receiving input information from the user to start communication.

[0131] In particular, the communication control unit 210 transmits user identification information and input information to the identity verification processing server device 10 and the service server device 30, and performs processing to receive information related to identity verification processing and information for receiving specified services from the identity verification processing server device 10 and the service server device 30.

[0132] In addition, the communication control unit 210 may send and receive data with the identity verification processing server device 10 and the service server device 30 at a predetermined interval, or may send and receive data with the identity verification processing server device 10 when input information is received from the operation input unit 260.

[0133] The web browser 211 is an application program for viewing web pages (authentication screen, unlock screen, or service enjoyment screen), and downloads HTML files, image files, etc. from a web server (personal authentication processing server device 10 or service server device 30), analyzes the layout, and controls the display.

[0134] Furthermore, the Web browser 211 transmits data to the Web server (personal identification processing server device 10 or service server device 30) using an input form (links, buttons, text boxes, etc.).

[0135] The terminal device 20 can display information from a web server (for example, the service server device 30) specified by a URL via the Internet using the web browser 211. For example, the terminal device 20 can display each content (data such as HTML) received from the identity verification processing server device 10 using the web browser 211.

[0136] The display control unit 213 performs processing to display on the display unit 290. For example, the display control unit 213 may be displayed using the web browser 211.

[0137] The input reception processing unit 214 recognizes input information input by the user from the operation input unit 260, and executes various processes based on the recognized information.

[0138] The drawing unit 220 performs drawing processing based on various processes performed by the processing unit 200, thereby generating an image, which is output to the display unit 290 by the display control unit 213.

[0139] The sound processing unit 230 performs sound processing based on the results of various processes performed by the processing unit 200 , generates background music, sound effects, voice, or the like, and outputs them to the sound output unit 292 .

[0140] [4] Method of this embodiment [4.1] Overview Next, the personal identification process in the personal identification process server device 10 of this embodiment will be described with reference to FIGS.

[0141] 4 and 5 are diagrams for explaining the identity verification process in the identity verification process server device 10 of this embodiment.

[0142] The identity verification processing server device 10 is a server device for performing identity verification processing when opening an account or registering as a user for various network services such as online banking, SNS, content (games, music, etc.) provision services, or online shopping, or for membership services at a store.

[0143] And, in this embodiment For identity verification processing The server device 10 is a server device that executes identity verification processing for a user in order to enjoy a given network service, using a public certificate for verifying the identity of the user, which contains an image of the person, including the face, and personal identification information (information for identifying the person).

[0144] In particular, the identity verification processing server device 10 of this embodiment is configured to be able to, when a given procedure is carried out on the premise that identity verification will be performed when an account is opened or when an update such as continued use or information change is made, and when an identity verification certificate such as a driver's license (e.g., for a car) or a passport is accepted electronically via a network, determine whether the identity verification certificate is a forged one using past history, identify forgeries such as the reuse of identity verification documents, and prevent the fraudulent opening of new accounts and the fraudulent use of accounts such as changes to account information.

[0145] Specifically, the identity verification processing server device 10 manages each registered public certificate information it has, which is information on public certificates that has been digitized and stored, and which includes a person's image and information on personal identification details associated with the person's image, as registered person image information and registered personal identification details information.

[0146] As shown in FIG. 4, when the identity verification processing server device 10 receives input information including at least identity verification certificate image information in which an official certificate for a specific user who wishes to undergo identity verification processing is imaged, the server device 10 is configured to execute an image analysis process to detect an image of a person formation area that is imaged in the received identity verification certificate image information and that includes a person, and identity identification information that is imaged in the identity verification certificate image information, as a detected person formation area image and a detected identity identification information, respectively (see [1] in FIG. 4).

[0147] Then, the identity verification processing server device 10 performs the following as shown in FIG. (A1) While searching for each registered official certificate information based on the detected person formation area image and detected personal identification information detected by the image analysis process, a process is performed to determine whether or not at least one of a registered person formation area image and registered personal identification information exists within a range that is identical or deemed to be identical to at least one of the detected person formation area image and detected personal identification information (hereinafter referred to as a "certificate information determination process"); (A2) When the certificate information determination process determines that either one of the detected person formation area image and the detected personal identification information is identical or within a range that is deemed identical with either one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and the other of the detected person formation area image and the detected personal identification information is not identical with the other of the detected person formation area image and the detected personal identification information, a given identification process is executed based on the fact that the accepted input information is not authentic information or is highly likely to be not authentic information. The structure is shown in [2A] and [2B] in Figure 4.

[0148] In particular, the identity verification processing server device 10 executes, as specific processing, a rejection processing for rejecting the identity verification as the person, a rejection notification processing for notifying that the identity verification has been rejected, and a blacklist registration processing for registering a combination of the face image of the detected person formation area image contained in the input information and the detected identity identification information in the blacklist information in the second database 150 (see [3] in Figure 4).

[0149] On the other hand, as shown in FIG. 5, the personal identification processing server device 10 performs the following processing instead of or in addition to the above certificate information determination processing: (B1) A comparison process is performed to compare the registered person formation area image and registered personal identification information included in the registered schoolyard certificate information with the detected person formation area image and detected personal identification information detected by the image analysis process, and a counterfeit determination process is performed to determine whether the registered public certificate information is a forged certificate or a certificate that may be forged, depending on the comparison result. (B2) Execute a given specific process based on the result of the counterfeit determination process; The configuration may be as follows (see [1] and [2] in FIG. 5).

[0150] Then, the identity verification processing server device 10 performs the following as shown in FIG. (C1) When the counterfeiting determination process determines that the registered public certificate information is a counterfeit certificate or a certificate that may be counterfeit, update and register the registered public certificate information as not being genuine public certificate information; (C2) If the counterfeiting determination process determines that the registered public certificate information is not a counterfeit certificate, the registered public certificate information is updated and registered as genuine public certificate information (see [3] and [4] in Figure 5).

[0151] In particular, [3] in Figure 5 shows an example in which, when the detected person formation area image and the registered person formation area image are the same (or not the same), and the detected personal identification information and the registered personal identification information registered in association with the registered person formation area image are not the same (or not the same), the relevant registered person formation area and the corresponding registered personal identification information (i.e., registered public certification information) are registered as blacklist information.

[0152] In addition, Figure 5 [4] shows an example in which, when the detected person formation area image and the registered person formation area image are identical (or not identical), and the detected personal identification information and the registered personal identification information registered in association with the registered person formation area image are also identical (or not identical), the relevant registered person formation area and the corresponding registered personal identification information (i.e., registered schoolyard certification information) are registered as whitelist information.

[0153] By having such a configuration, the identity verification processing server device 10 of this embodiment can detect forged identity verification certificates by utilizing past history when a given procedure is executed on the premise that identity verification will be performed, such as when opening an account, and when identity verification certificates such as a driver's license (e.g., for a car) or a passport are accepted electronically via a network, thereby identifying forgery such as the reuse of identity verification documents and preventing the fraudulent opening of new accounts or the fraudulent use of accounts.

[0154] Furthermore, by virtue of having such a configuration, the identity verification processing server device 10 of this embodiment can subsequently determine whether or not an already registered official identity verification document has been forged. Therefore, even if an identity verification document is leaked or an ingeniously forged identity verification document is circulated, it is possible to quickly and reliably prevent "impersonation" by a malicious third party using such a document.

[0155] [4.2] Various Information [4.2.1] Registered public certificate information Next, the public certificate information of this embodiment will be described with reference to Fig. 6. Fig. 6 is a diagram showing an example of information stored in the first database 140, that is, public certificate information that has been converted into data and stored in the first database.

[0156] The registered public certificate information in this embodiment is information stored in the first database 140, and is information on public certificates that has been converted into data and stored in the first database.

[0157] In particular, the registered public certificate information in this embodiment is information on a public certificate, as shown in Figure 6, and includes information on a person's image including a facial image of the corresponding user (hereinafter referred to as "person image information") and information on personal identification information for identifying the person (hereinafter referred to as "person identification information").

[0158] For example, official documents include passports, residence cards, alien registration certificates, driver's licenses, seaman's handbooks, seaman's licenses, personal identification cards, and photo identification cards issued to employees by government agencies, independent administrative agencies, special corporations, and local independent administrative agencies.

[0159] Specifically, as shown in FIG. 6, the registered public certificate information includes a person image and information on personal identification details associated with the person image, as registered person image information and registered personal identification details information, respectively.

[0160] For example, a person image is an image that includes all or part of a person, such as an image that focuses on the face from the shoulders up, an image of the upper body, or an image that includes the person's entire body, and includes a face.

[0161] The person image may include a background, or may be an image in which the person is wearing accessories such as glasses.

[0162] In addition, personal identification information is information used to identify the applicant for a public certificate, such as name, date of birth, gender, certificate identification information (such as passport number and driver's license number), place of residence (address or residence), and contact information (telephone number and email address).

[0163] FIG. 6 is a diagram for explaining the relationship between the person image information and the personal identification information formed in the person formation area when a driver's license is used as the official certificate.

[0164] [4.2.2] Identity verification certificate image information Next, the personal identification certificate image information of this embodiment will be described with reference to Fig. 7. Fig. 7 is a diagram showing an example of the personal identification certificate image information of this embodiment.

[0165] The personal identification certificate image information in this embodiment is information input when an applicant user (specific user) who applies for a new account or the like executes personal identification processing.

[0166] Specifically, as shown in FIG. 7, the personal identification certificate image information includes an image of a person formation area containing a person analyzed by the image analysis process described below, and personal identification information, which are respectively a detected person formation area image (information) and detected personal identification information (information).

[0167] In particular, the detected person formation area image includes an image of at least the area where the person image is detected, and may be an image that includes the background, etc., or may include images of other areas in the identification certificate.

[0168] The detected personal identification information is a data group similar to the registered personal identification information included in the registered official certificate information.

[0169] FIG. 7 is a diagram for explaining the relationship between the person image (information) and the personal identification items (information) of the detected person formation area image information with respect to the image information of the personal identification certificate using a driver's license.

[0170] [4.2.3] Standards information Next, the standard information of this embodiment will be described.

[0171] The standard information in this embodiment is information pre-stored in the memory unit 170, and is composed of information (hereinafter referred to as "person formed area image standard information") regarding the standard of the image of the area portion where a person is formed (hereinafter also referred to as "person formed area image", for example, the above-mentioned detected person formed area image), and information (hereinafter referred to as "person formed area image standard information") regarding the standard of the image of the area portion where a person is not formed (hereinafter also referred to as "non-person formed area image", for example, the above-mentioned detected person identification items).

[0172] In particular, the standard information relating to a portrait image defines conditions for conforming to the standard and the numerical data of the standard itself.

[0173] For example, the conditions for the standard information regarding human-formed images are as follows: (A1) A face image is not positioned at the center of the detected person formation area; (A2) The face recognized by the facial image is not facing forward; (A3) The face image is tilted left or right with respect to the detected person formation area; (A4) Hair or accessories (glasses or hats) are formed in specific areas of the face image area (glasses frames covering the eyes or part of the face, glasses, hats, hairbands, hair, etc. hiding all or part of the eyes, head, or face outline) thing) , and (A5) The corners of the mouth are turned up, the eyes are closed, the eyes are squinting, the teeth are I can see it The facial appearance is significantly different from normal, The condition data includes the following:

[0174] For example, the numerical data of the standard information regarding the person formation image is This includes the size, coordinate position (absolute coordinates or relative position to the non-human area), the ratio of the facial image area to the human area and its relative position, and the relative positions and number of eyes, nose, and mouth.

[0175] On the other hand, the standard information regarding the non-human image defines the conditions for recognizing the personal identification information and the numerical data of the standard itself.

[0176] For example, the conditions for the standard information regarding images without people are as follows: (B1) The area that is the background other than the face image or person image in the detected person formation area (hereinafter referred to as the “background area”) is not a predetermined background (e.g., not a specific color or not composed of one color), and (B2) The image is out of focus, has a shadow on the face, has noise (image distortion), has jagged edges (step-like jagged patterns), or has undergone image processing such as deformation or masking (edging). The condition data includes the following:

[0177] Furthermore, for example, the numerical data of the standard information regarding the non-person forming image includes the size of the non-person forming area, the coordinate position (absolute coordinates or relative position to the non-person forming area), the relative position and number of each specific item formed, etc.

[0178] [4.2.4] Blacklist and whitelist information Next, the blacklist information and the whitelist information of this embodiment will be described.

[0179] (Blacklist information) The blacklist information is information stored in the second database 150, and is information in which face image data is listed for each malicious third party who is not a legitimate user and who has been specified in advance.

[0180] In particular, the blacklist information includes facial image data of malicious third parties and facial images of the facial image portion of the personal image of the applying user who has been determined to be a malicious third party by the person determination process described below.

[0181] The blacklist information may be stored in the first database 140 or in the storage unit 170.

[0182] In addition, each facial image data included in the blacklist information may be facial image data detected by another security system (which does not have to be a front-facing image), or, as described below, may be data of a person's image detected from registered public certificate information.

[0183] Furthermore, forged personal identification information may be registered in the blacklist information in association with a face image or alone, and in this case, the personal identification process is performed not only using the person's image but also using the personal identification information alone or a combination of the person's image and the personal identification information.

[0184] (Whitelist information) The whitelist information is information stored in the second database 150, and is information in which a combination of face image data and text content of personal identification information is listed for each pre-specified authorized user.

[0185] In particular, the whitelist information stores facial image data of authorized users and facial image portions of personal images of applicant users who have been determined to be authorized users by the person determination process described below.

[0186] The whitelist information may be stored in the first database 140, or may be constructed by adding flag information indicating that the user has been determined to be a legitimate user to the registered public certificate information stored in the first database 140.

[0187] In addition, the whitelist information may also include personal identification information registered in association with a facial image, in which case personal identification processing is performed using not only the person's image but also a combination of the person's image and personal identification information.

[0188] [4.3] Reception process Next, the reception process in this embodiment will be described.

[0189] When the communication control unit 101 receives an instruction from an applicant user who wishes to undergo identity verification processing to request execution of identity verification processing, it executes a reception process to receive input information including a new or already registered user ID and password, and identity verification certificate image information that is an image of the official certificate held by the applicant user.

[0190] For example, the communication control unit 101 receives, as the personal identification certificate image information, image data of a passport, residence card, alien registration certificate, driver's license, seaman's notebook, seaman's license, personal identification number card, and photo identification issued to employees by government agencies, independent administrative agencies, special corporations, and local independent administrative agencies, as described above.

[0191] In addition, the input information in this embodiment may include, in addition to the identity verification certificate image information, information on a facial image (e.g., a selfie image) of the applying specific user captured by the terminal device 20 (hereinafter referred to as "auxiliary facial image information").

[0192] For example, when executing the identity verification process of this embodiment, if the identity verification process server device 10 requests auxiliary facial image information different from the identity verification certificate image information, the communication control unit 101 may receive input information including the auxiliary facial image information.

[0193] [4.4] Image analysis processing Next, the reception process in this embodiment will be described.

[0194] The image analysis processing unit 103 performs various image analyses on the official certificate image information contained in the input information, and detects an image of the person formation area in which the person of a specific user is formed and personal identification information from the image information contained in the acquired input information.

[0195] Specifically, the image analysis processing unit 103 identifies the color feature amount of each pixel in the official certificate image, and executes given image processing such as edge detection and spatial filtering.

[0196] Then, the image analysis processing unit 103 performs image analysis processing to detect an image of a person formation area containing a person (hereinafter referred to as a "person formation area image") from the acquired personal identification certificate image information and the personal identification information imaged in the personal identification certificate image information, as a detected person formation area image and a detected personal identification information, respectively.

[0197] In particular, the image analysis processing unit 103 only needs to detect an image of an area in which at least a person image is detected as the detected person formation area image, and it is not necessary to detect an image that includes other images such as a background. Alternatively, an image of another area of the personal identification certificate may be included.

[0198] For example, for a person formation area image, the image analysis processing unit 103 detects skin color areas using the Y·Cr·Cb color system (Y (brightness), Cr (redness), Cb (blueness)), and performs facial image recognition processing to recognize the detected parts as facial areas, and compares each area with a predetermined template image to detect areas with a high degree of matching as facial image areas.

[0199] Furthermore, the image analysis processing unit 103 executes OCR (optical character recognition) processing on the detected personal identification information, and converts the text portion in the image data into text data.

[0200] In this embodiment, the methods for recognizing face images and person images, and the image analysis techniques such as OCR techniques are the same as conventional techniques, and therefore a description thereof will be omitted.

[0201] [4.5] Identity Verification Processing [4.5.1] Overview of identity verification process Next, an overview of the identity verification process including the certificate determination process and the identification process in this embodiment will be described.

[0202] The identity verification processing unit 104 works in conjunction with the terminal device 20 and the service server device 30, and performs identity verification processing for a specific user (e.g., an applying user) when the user performs a procedure that requires identity verification, such as new registration for a service provided by the service server device 30 or updating registration details to continue receiving the service.

[0203] In particular, the identity verification processing unit 104 acquires input information through the reception process, and then performs identity verification processing based on the detected person formation area image detected by performing image analysis processing on the acquired input information, and the detected identity information as text data (hereinafter referred to as "detected identity information information").

[0204] Specifically, the identity verification processing unit 104 executes a certificate information determination process to determine whether at least one of the detected person formation area image and detected identity information detected by the image analysis process is identical to or within a range that is deemed to be identical to at least one of the registered person formation area image and registered identity information stored in the first database 140.

[0205] Then, the identity verification processing unit 104 performs a certificate information determination process to determine whether (A1) Either one of the detected person formation area image and the detected personal identification information is the same as or within a range that is deemed to be the same as either one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and (A2) When it is determined that the other of the detected person formation area image and the detected person identification information is not the same as the other of the detected person formation area image and the detected person identification information, It is determined that the received input information is not authentic or is highly likely to be authentic, and a given specific process is executed.

[0206] [4.5.2] Certificate information judgment process Next, the certificate information determination process in this embodiment will be described.

[0207] (Basic principle) The identity verification processing unit 104 performs the following as the certificate information determination process: (A1) A detected person formation area image and detected person identification information detected by image analysis processing, and a registered person formation area image and registered person identification information stored in the first database 140. Compare specific items with (A2) Determine whether the facial images in the detected person formation area image and the registered person formation area image are the same, or whether they are within a range that can be considered to be the same, and whether the personal identification information in the detected person formation area image and the registered person formation area image are the same.

[0208] In particular, the personal identification processing unit 104 determines not only whether the facial images are the same, but also whether they are in the same range, that is, whether they are the same person.

[0209] Specifically, the identity verification processing unit 104: (B1) The facial images in the detected person formation area image and the registered person formation area image are the same or within the same range, and the contents of the detected personal identification information and the registered personal identification information are the same. (B2) The face images in the detected person formation area image and the registered person formation area image are the same or within the same range, and the contents of the detected personal identification information and the registered personal identification information are not the same (different), (B3) The facial images in the detected person formation area image and the registered person formation area image are not identical (including not being within the same range), and the contents of the detected personal identification information and the registered personal identification information are the same, or (B4) The face images in the detected person formation area image and the registered person formation area image are not identical, and the contents of the detected personal identification information and the registered personal identification information are not identical (different), Determine whether:

[0210] For example, when determining a face image, the identity verification processing unit 104 detects the color features of each pixel (specifically, each pixel in the area determined to be a face) that constitutes each of the detected person formation area images and the registered person formation area images, and for each image, digitizes the shape and position (relative position and absolute position) of each part of the face, such as the face outline, hairstyle, eyes, nose, mouth, ears, and eyebrows, and digitizes each feature of the face, such as the color of each part (i.e., color features).

[0211] Then, the identity verification processing unit 104 compares the feature points of each part, calculates the similarity, and if the similarity satisfies given conditions, determines that the detected person formation area image and the registered person formation area image are identical or within a range that can be considered identical.

[0212] In the certificate information determination process of this embodiment, the determination of the identity of a person using an image is a conventional technique, and therefore a description thereof will be omitted.

[0213] In addition, in this embodiment, the method is not limited to the above, as long as it is possible to determine the identity of the face image.

[0214] (Certificate information determination process using standard information) In addition to or instead of the certificate information determination process for the face image described above, the identity verification processing unit 104 may execute a certificate information determination process for determining whether or not the identity verification certificate image information as input information is forged using standard information pre-stored in the memory unit 170.

[0215] That is, in the certificate information determination process, in addition to or instead of comparing the detected person formation area image with the registered person formation area image, the identity verification processing unit 104 may perform a process to determine whether or not the facial image of the detected person formation area image conforms to the standards (numerical data) and conditions specified in the standard information.

[0216] For example, if the image in the detected person formation area does not conform to predetermined standards, such as the size of the detected person image area (the ratio and position of the facial image to the detected person formation area, and the background color, etc.), the direction of the face (forward, tilted, etc.), the facial expression (position of the corners of the mouth, etc.), and the presence or absence of clothing or accessories (glasses or a hat), it is possible to determine that the identification document in question is forged.

[0217] Therefore, in this embodiment, by using standard information when executing the certificate information determination process, it is possible to reinforce the determination result of the determination process without comparing the detected person formation area image with a registered person formation area image, or based on the comparison result.

[0218] Specifically, when performing the identity verification process, the identity verification processing unit 104 uses data regarding the standards for the image of the area where a person is formed and the standards for the image of the area where a person is not formed as standard information pre-stored in the memory unit 170.

[0219] For example, the personal identification processing unit 104 determines whether or not the person is present based on the data on the image standard of the area where the person is present. (A1) A face image is placed at the center position of the detected person formation area; (A2) The face recognized by the facial image faces forward; (A3) The face image is not tilted left or right relative to the detected person formation area. (A4) Hair or accessories (glasses or hats) are formed in specific areas of the face image area (the frames of glasses do not cover the eyes or part of the face, and glasses, hats, hairbands, hair, etc. do not hide all or part of the eyes, head, or face outline) thing) , and (A5) The corners of the mouth are turned up, the eyes are closed, the eyes are squinting, the teeth are I can see it The facial appearance is not significantly different from normal, etc. are used.

[0220] When the personal identification processing unit 104 executes the above-mentioned certificate information determination process on the face image instead, if it determines that the image does not conform to any of the standards (A1)-(A5) above, it determines that the personal identification certificate image information as input information is forged.

[0221] Furthermore, for example, when the personal identification processing unit 104 performs the above-mentioned process in addition to the certificate information determination process on the face image, when converting the numerical difference between each feature point of the face image into an overall similarity by a predetermined calculation, it performs a given calculation based on the determination results of (A1)-(A5) above to calculate a score, and determines whether the personal identification certificate image information as input information is forged or not based on the similarity and the calculated score.

[0222] On the other hand, for example, the personal identification processing unit 104 determines whether or not a person is present based on the data on the image standard of the area where the person is not present. (B1) The area that is the background other than the face image or person image in the detected person formation area (hereinafter referred to as the “background area”) is not a predetermined background (e.g., not a specific color or not composed of one color), and (B2) The image is out of focus, has a shadow on the face, has noise (image distortion), has jagged edges (step-like jagged patterns), or has undergone image processing such as deformation or masking (edging). Whether or not the product complies with the standards is determined.

[0223] Then, when the personal identification processing unit 104 executes the above-mentioned certificate information determination process on the face image instead, it determines that the face image does not conform to any of the standards (B1)-(B2). Then, it is determined that the image information of the personal identification certificate as input information is forged.

[0224] Furthermore, for example, when the personal identification processing unit 104 performs the above-mentioned certificate information determination process on the face image in addition to converting the numerical difference between each feature point of the face image into an overall similarity by a predetermined calculation, it also performs a given calculation based on the determination results of (B1)-(B2) above to calculate a score, and determines whether the personal identification certificate image information as input information is forged or not based on the converted similarity and the calculated score.

[0225] (Certificate information judgment process using blacklist information) In addition to or instead of the above-mentioned certificate information determination process for the face image, the personal identification processing unit 104 performs a process for determining the certificate information for the face image. Blacklist Information The certificate information determination process may be performed using the above.

[0226] That is, in the certificate information determination process, in addition to or instead of comparing the detected person formation area image with each registered person formation area image, the identity verification processing unit 104 may execute a process to determine whether or not the facial image in the detected person formation area image is identical to or within a range that is considered to be identical to each facial image listed in the blacklist information.

[0227] Specifically, if the face image in the detected person image area is originally included in the blacklist information, it is possible to determine that the personal identification document itself is a forgery.

[0228] Therefore, in this embodiment, by using blacklist information when executing the certificate information determination process, it is possible to reinforce the determination result of the determination process without comparing the detected person formation area image with a registered person formation area image, or based on the comparison result.

[0229] For example, when performing identity verification processing instead of certificate determination processing using a facial image, the identity verification processing unit 104 uses the image's feature points as described above to calculate the similarity between the image and each facial image listed in the blacklist information stored in the second database 150, and if the similarity satisfies predetermined conditions, performs a person determination process to determine that the facial image in the detected person image area is identical (including the range within which it is considered identical) to the facial image of a malicious third party listed in the blacklist information.

[0230] (Certificate information determination process used for whitelist information) In addition to or instead of the above-mentioned certificate information determination process for the face image, the personal identification processing unit 104 performs a process for determining the personal identification information for the face image, which is configured from a combination of a plurality of face image data and personal identification items stored in the second database 150. Whitelist Information The certificate information determination process may be performed using the above.

[0231] That is, in the certificate information determination process, the identity verification processing unit 104 may perform a process to determine whether or not the facial image of the detected person formation area image and the information of the detected person formation area image match a combination of a facial image and a person identification item listed in the whitelist information, in addition to or instead of comparing the detected person formation area image with the registered person formation area image.

[0232] Specifically, if the face image in the detected person image area and the detected personal identification information are originally included in the whitelist information, it can be determined that the document is the personal identification document itself.

[0233] Therefore, in this embodiment, by using whitelist information when executing the certificate information determination process, it is possible to reinforce the determination result of the determination process without comparing the detected person formation area image with a registered person formation area image, or based on the comparison result.

[0234] For example, when performing identity verification processing, the identity verification processing unit 104 compares each combination of face image and identity verification items listed in the whitelist information stored in the second database 150, and determines whether the combination of face image and detected identity verification items in the detected person image area is the same as the combination of face image and identity verification items listed in the whitelist information.

[0235] In this case, as described above, the identity verification processing unit 104 calculates the similarity between facial images by using the feature points of the images, and if the similarity satisfies predetermined conditions, it determines that the images are identical or within a range that can be considered identical.

[0236] [4.5.3] Specific Processing Next, the specification process in this embodiment will be described.

[0237] (Basic principles of specific processing) Depending on the result of the certificate information determination process, the specific process control unit 105 executes a given specific process based on whether the received input information is not legitimate information or is highly likely to be not legitimate information.

[0238] Specifically, the specific process control unit 105 determines, as a result of the certificate information determination process, (A1) When it is determined that the face images in the detected person formation area image and the registered person formation area image are the same or within the same range, and the contents of the detected personal identification information and the registered personal identification information are not the same, and (B2) When it is determined that the face images in the detected person formation area image and the registered person formation area image are not identical or within a range of non-identity, and the contents of the detected personal identification information and the registered personal identification information are identical, Depending on the result of the certificate information determination process, a given specific process is executed based on whether the accepted input information is not authentic or is highly likely to be authentic.

[0239] In particular, the specific processing control unit 105 performs the following specific processing: (B1) Rejection processing of not recognizing the identity of the person in the identity verification processing; (B2) Notification process for notifying the administrator of information about a specific user who requests identity verification, regarding the specific user as a malicious third party (hereinafter referred to as "rejection notification process"); (B3) A registration process for registering the specific user as a blacklist that will be blocked in subsequent identity verification processes (hereinafter referred to as the "blacklist registration process"); or (B4) Two or more processes among (B1)-(B2) Execute.

[0240] In addition, if both the detected person formation area image and the detected identity information match the already registered whitelist information, the identification process control unit 105 executes, as identification processes, identity recognition processing (including processing related to the start of provision of network services) to recognize the identity of the person in identity verification based on the input information, and approval notification processing to notify the person of the recognition.

[0241] (Specific process 1: Disapproval process) In this case, the specific processing control unit 105 works in conjunction with the DB management control unit 102 to perform the personal authentication process. The process is stopped and processing is performed to reject the approval of the personal identification certificate based on the input information.

[0242] If the specific processing control unit 105 rejects the product of the personal identification certificate, it stops or controls various processes so that the terminal device 20 that sent the accepted input information cannot log in to the network service.

[0243] (Specific Processing 2: Malicious Third-Party Report Processing) As a malicious third party notification process, the specific processing control unit 105 may notify an administrator by email, chat, or an information terminal device such as a smartphone that the person has not been recognized as the person in the identity verification process (i.e., that identity verification has failed), and may also perform a malicious third party notification process to notify the specific user who entered the input information that the person has not been recognized as the person in the identity verification process.

[0244] (Specific process 3: Blacklist registration process) The identification process control unit 105 may work in conjunction with the DB management control unit 102 to execute a blacklist registration process that registers a combination of the face image of the detected person formation area image and the detected person identification information included in the received input information in blacklist information in the second database 150.

[0245] Specifically, as a identification process, the identification process control unit 105 detects registered person image information that is identical or deemed to be identical to the detected person formation area image when the face image of the detected person formation area image is identical or within a range that is deemed to be identical to each face image listed in the blacklist information.

[0246] Then, the specific process control unit 105 updates and registers the detected registered person image information in the blacklist information of the second database 150, assuming that the information is not authentic public certificate information that cannot be used for personal identification.

[0247] (others) When the identification process of the above embodiment is executed, the identification process control unit 105 may register the registered public certificate information as blacklist information when one of the detected person formation area image and the registered person formation area image, and the detected personal identification information and the registered personal identification information are identical and the other is not identical, and in addition, may execute processing to register the registered public certificate information as whitelist information when the person formation area images and the personal identification information are identical.

[0248] [4.6] Variations [4.6.1] Variation 1 (Outline of Acquired Falsification Determination for Personal Identification Documents) When the identification process of the above embodiment is executed, if one of the detected person formation area image and the registered person formation area image, and the detected person identification information and the registered person identification information are identical and the other is not identical, in addition to registering the registered public certificate information as blacklist information, an update registration process may be executed to register the registered public certificate information as whitelist information if the person formation area images and the person identification information are identical.

[0249] In other words, in this modified example, if the certificate information determination process determines that the registered public certificate information is not a forged certificate, the registered public certificate information may be registered as whitelist information, and the presence or absence of forgery may be determined subsequently for public identification documents that have already been registered as identification information.

[0250] Specifically, the identity verification processing server device 10, as in the above embodiment, (A1) Manage registered public certificate information that includes registered person image information and registered personal identification information; (A2) Accept the input information, (A3) The image analysis processing is performed to detect a person formation area image and personal identification information (that is, a detected person formation area image and detected personal identification information) from the received input information.

[0251] Then, the identity verification processing server device 10: (B1) A comparison process of comparing a registered person formation area image and registered personal identification information included in the registered public certificate information with a detected person formation area image and detected personal identification information detected by the image analysis process; (B2) an identity verification determination process that determines whether or not it is possible to confirm the identity of the person in the identity verification process based on the received input information, depending on the comparison result; (B3) A given specific process according to the result of the identity verification determination process; (B4) a registered certificate forgery determination process that determines whether the registered public certificate information is a forged certificate or a certificate that may be forged, based on the comparison result; (B5) A process for updating and registering the registered public certificate information as not genuine public certificate information (as blacklist information) when the registered public certificate information is determined to be a forged certificate or a certificate that may be forged by the registered certificate forgery determination process (hereinafter referred to as the "blacklist update registration process"); and (B6) A process for updating and registering the registered public certificate information as genuine public certificate information (as whitelist information) when the certificate information determination process determines that the registered public certificate information is not a forged certificate (hereinafter referred to as the "whitelist update registration process"); The above configuration may be implemented.

[0252] In particular, in the registered certificate counterfeit determination process, when the identity verification processing unit 104 determines that either one of the detected person formation area image and the detected personal identification information is identical or within a range that is deemed identical to either one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and the other of the detected person formation area image and the detected personal identification information is not identical to the other of the detected person formation area image and the detected personal identification information, the identity verification processing unit 104 determines that the combination of the registered person formation area image and the registered personal identification information being determined is public certificate information used by a malicious third party or public certificate information that may have been used by such a malicious third party (i.e., corresponds to blacklist information).

[0253] In addition, in the registered certificate forgery determination process, if the identity verification processing unit 104 determines that a combination of registered person formation area image that is identical to the detected person formation area image or within a range that is considered to be identical, and registered person identification information that matches the detected person identification information, the identity verification processing unit 104 determines that the combination of registered person formation area image and registered person identification information that is the subject of determination is legitimate public certificate information (i.e., corresponds to whitelist information).

[0254] In addition, for registered public certificate information that is determined to correspond to blacklist information or whitelist information as described above, the DB management control unit 102 updates and registers the corresponding information in the first database 140 as whitelist information, or updates and registers it as blacklist information in the second database 150.

[0255] Furthermore, the specific process control unit 105 performs the above-mentioned proof as the personal identification determination process including the comparison process. As with the certificate information determination process, (C1) comparing the detected person formation area image and detected personal identification information detected by the image analysis processing with the registered person formation area image and registered personal identification information stored in the first database 140; (C2) Determine whether the facial images in the detected person formation area image and the registered person formation area image are the same or within a range that can be considered to be the same, and whether the personal identification information in the detected person formation area image and the registered person formation area image are the same.

[0256] Then, the personal identification processing unit 104 determines not only whether the facial images are the same, but also whether they are in the same range, that is, whether they are the same person.

[0257] Furthermore, the specific process control unit 105 executes the disapproval process, the disapproval notification process, and the blacklist registration process as the given specific process, as described above. However, the specific process control unit 105 may also execute the approval process for confirming the identity of the person in the identity verification process and the approval notification process for notifying the person of the approval as the given specific process.

[0258] [4.6.2] Variation 2 In the above embodiment, the image information of the personal identification certificate before the image analysis process is obtained from the terminal device 20, but it is also possible to obtain a detected person formation area image and detected personal identification information in which image analysis process has already been performed on the personal identification certificate image information by the terminal device 20 or another server device not shown.

[0259] In this case, the identity verification processing unit 104 acquires the detected person formation area image and the detected identity identification information, which have already been subjected to image analysis processing on the identity verification certificate image information by the terminal device 20 that sent the input information or another server device not shown.

[0260] Then, the personal identification processing unit 104 executes the certificate information determination process using the acquired detected person formation area image and detected personal identification information.

[0261] [4.6.3] Variation 3 In the above embodiment, the certificate information determination process is performed based on input information and the input information together with standard information, blacklist information, or whitelist information. However, the certificate information determination process may also be performed based on a self-portrait image that is different from the identity verification certificate image information, such as a selfie.

[0262] In other words, in this modified example, by comparing the self-face image sent by a specific user with the face image recognized in the identity verification certificate image, or with the face image included in the blacklist information or whitelist information, it is possible to determine whether the identity verification certificate is a forgery.

[0263] Specifically, the input information includes, as input face image information, face image information of a face image of a specific user, along with image information of the personal identification certificate.

[0264] Then, the personal identification processing unit 104 executes a certificate information determination process using the input face image information.

[0265] For example, the personal identification processing unit 104 may perform the following operations: (1) determining the selfie face image information included in the input information; (2) determining the face image included in the detected person formation area image detected from the input information by the image analysis process; Registered person image information The identity (including the range in which they are considered to be identical) between the facial image in and is determined.

[0266] At this time, if the face image in the selfie face image information acquired by the identity verification processing unit 104 is the same as the image listed in the blacklist information, the specific processing control unit 105 performs the following specific processing, as in the above embodiment: (A1) Rejection processing of not recognizing the identity of the person in the identity verification processing, (A2) A disapproval notification process that notifies the administrator of information about a specific user who requests identity verification, regarding that specific user as a malicious third party. (A3) A blacklist registration process that registers the specific user as a blacklist that will be blocked in subsequent identity verification processes, or (A4) Two or more processes among (A1)-(A3) Execute.

[0267] [5] Operation in this embodiment [5.1] Identity Verification Process 1 (Standard Specifications) Next, referring to FIG. 8, Personal identification processing server device 10 This section explains the operation of the personal identification process 1 (standard specification) executed by the above.

[0268] FIG. 8 shows the configuration of this embodiment. Personal identification processing server device 10 Identity verification process performed by (standard specification) Actions related to 1 is a flowchart showing the steps of

[0269] In this operation, it is assumed that for each user registered to receive network services, multiple registered public certificate information consisting of registered person image information and personal identification information is already stored in the first database 140, associated with each user ID.

[0270] Note that this operation is an example in which supplementary information such as standard information, blacklist information, and whitelist information is not used.

[0271] In addition, this operation is an example of a case where, if it is determined that neither the detected person formation area image nor the detected personal identification information of a specific user is registered in the first database 140, processing related to new registration is performed as a new user registrant.

[0272] First, when the identity verification processing unit 104 receives input information transmitted from the terminal device 20 of a specific user via the communication control unit 101 (step S101), it causes the image analysis processing unit 103 to perform various image analyses on the official certificate image information contained in the input information, and detects the detected person formation area image and detected identity identification information of the specific user (step S102).

[0273] Next, the identity verification processing unit 104 searches the first database 140 based on the detected person formation area image of the specific user, and executes a process (hereinafter referred to as "identical image registration determination process") to determine whether or not a registered person formation area image that is identical to the detected person formation area image of the specific user or within a range that is considered to be identical to the detected person formation area image of the specific user is registered (step S103).

[0274] At this time, if the identity verification processing unit 104 determines that the first database 140 has a registration of an image, etc. that is identical to the detected person formation area image of the specific user, it proceeds to processing of step S104, and if it determines that the first database 140 does not have a registration of an image, etc. that is identical to the detected person formation area image of the specific user, it proceeds to processing of step S105.

[0275] Next, when the personal identification processing unit 104 determines that the same image as the detected person formation area image of the specific user is registered in the first database 140, it determines that the detected personal identification information is the same as the detected person formation area image in the same image registration determination process of step S103 (in the same range). (This includes determining whether the registered person identification information is within a range that can be considered to be the same as the registered person identification information registered in association with the registered person formation area image.) A process for determining whether the registered person identification information is the same as the registered person identification information registered in association with the registered person formation area image or within a range that can be considered to be the same is executed (hereinafter referred to as "identical person identification information determination process") (step S104).

[0276] At this time, if the identity verification processing unit 104 determines that the detected identity information is not identical to the corresponding registered identity information, it proceeds to processing in step S107, and if it determines that the detected identity information is identical to the corresponding registered identity information (including determining that they are within the same range), it proceeds to processing in step S110.

[0277] On the other hand, if the identity verification processing unit 104 determines in the process of step S103 that there is no registration of an image or the like identical to the detected person formation area image of the specific user in the first database 140, it searches the first database 140 based on the detected identity information of the specific user, as in step S104, and executes identical identity information registration determination process (step S105) to determine whether or not registered identity information identical to the detected identity information of the specific user is registered. However, the process of step S105 is the same as that of step S104, except that the prerequisites are different.

[0278] At this time, if the identity verification processing unit 104 determines that the first database 140 does not have registered identity information identical to the detected identity information of the specific user, the combination of the detected person formation area image and the detected identity information is new, so the combination is newly registered in the first database 140 (step S106) and the process proceeds to step S110.

[0279] At this time, if the personal identification processing unit 104 determines that the first database 140 has registered personal identification information identical to the detected personal identification information of the specific user, the process proceeds to step S107.

[0280] Next, if the identity verification processing unit 104 determines in step S104 that the detected identity information is not identical to the corresponding registered identity information, and if it determines in step S106 that the first database 140 contains registered identity information identical to the detected identity information of a specific user, it determines that the official certificate image information included in the input information is forged or may be forged (step S107).

[0281] Next, the specific processing control unit 105 executes the specific processing based on the official certificate image information included in the input information (step S108), and ends this operation.

[0282] As for the specific processing, as described above, (A1) Rejection processing of not recognizing the identity of the person in the identity verification process for the image information of the target public certificate; (A2) A disapproval notification process that notifies the administrator of information about a specific user who sent the input information, identifying the specific user as a malicious third party. (AB3) A blacklist registration process that registers the specific user as a blacklist that will block the specific user from subsequent identity verification processes, or (AB4) Two or more treatments of (A1)-(A2), Execute.

[0283] On the other hand, if the detected personal identification information and the corresponding registered personal identification information are determined to be identical in the process of step S104, or if the detected person formation area image and the detected personal identification information are determined to be identical, the personal identification processing unit 104 adds a new combination of the detected person formation area image and the detected personal identification information to the first database 140. If the user has been newly registered, the user's identity is confirmed based on the input information and the service server device 30 is notified of this fact (step S110), and the operation is terminated.

[0284] [5.2] Identity Verification Process 2 (Specifications including Blacklist and Whitelist Registration) Next, referring to FIGS. 9 and 10, Personal identification processing server device 10 This section explains the operation of the identity verification process 2 (specifications including blacklist registration and whitelist registration) executed by the above.

[0285] 9 and 10 show the configuration of this embodiment. Personal identification processing server device 10 10 is a flowchart showing the operation of the identity verification process 2 (specifications including blacklist registration and whitelist registration) executed by the

[0286] In this operation, it is assumed that for each user registered to receive network services, multiple registered public certificate information consisting of registered person image information and personal identification information is already stored in the first database 140, associated with each user ID.

[0287] This operation is an example of a case where identity verification processing is performed without using already registered standard information.

[0288] In addition, this operation is an example of a case where, if it is determined that neither the detected person formation area image nor the detected personal identification information of a specific user is registered in the first database 140, processing related to new registration is performed as a new user registrant.

[0289] Furthermore, this operation uses blacklist information and whitelist information and performs processing similar to the above-mentioned identity verification process 1, except for registering in the blacklist information or whitelist information, so the same processing will be described using the same step symbols.

[0290] First, when the identity verification processing unit 104 receives input information transmitted from the terminal device 20 of a specific user via the communication control unit 101 (step S101), it causes the image analysis processing unit 103 to perform various image analyses and detect the detected person formation area image and detected identity identification information of the specific user (step S102).

[0291] Next, the personal identification processing unit 104 determines whether or not the detected person formation area image is registered in the blacklist information (step S200).

[0292] At this time, if the identity verification processing unit 104 determines that the detected person formation area image is registered in the blacklist information, it proceeds to processing of step S108, and if it determines that neither the detected person formation area image nor the detected identity information is registered in the blacklist information, it proceeds to processing of step S201.

[0293] Next, it is determined whether or not the combination of the detected person formation area image and the detected personal identification information is registered in the whitelist information (step S201).

[0294] At this time, if the identity verification processing unit 104 determines that the combination of the detected person formation area image and the detected identity identification information is registered in the whitelist information, it proceeds to processing of step S110, and if it determines that the combination is not registered in the whitelist information, it proceeds to processing of step S103.

[0295] Next, the personal identification processing unit 104 executes the same image registration determination process using the detected person formation area image of the specific user and each registered person formation area image (step S103).

[0296] At this time, if the identity verification processing unit 104 determines that the first database 140 has a registration of an image, etc. that is identical to the detected person formation area image of the specific user, it proceeds to processing of step S104, and if it determines that the first database 140 does not have a registration of an image, etc. that is identical to the detected person formation area image of the specific user, it proceeds to processing of step S105.

[0297] Next, if the identity verification processing unit 104 determines that the first database 140 contains a registration of an image or the like that is identical to the detected person formation area image of the specific user, it executes an identical identity verification determination process (step S104) based on the detected identity verification information and the registered identity verification information that is registered in association with the registered person formation area image that was determined to be identical (including determining that it is the same range) in the identical image registration determination process of step S103.

[0298] At this time, if the identity verification processing unit 104 determines that the detected identity information and the corresponding registered identity information are not identical (including determining that they are within the same range), it proceeds to processing in step S107, and if it determines that the detected identity information and the corresponding registered identity information are identical, it proceeds to processing in step S202.

[0299] Next, the identity verification processing unit 104 registers the combination of the registered person formation area image that was determined to be identical (including determining that it is the same range) in the identical image registration determination process of step S103 and the corresponding registered identity information in the whitelist information (step S202), and proceeds to processing of step S110.

[0300] On the other hand, if the identity verification processing unit 104 determines in the processing of step S103 that there is no registration of an image, etc. identical to the detected person formation area image of the specific user in the first database 140, it searches the first database 140 based on the detected identity information of the specific user and executes a process to determine whether or not registered identity information identical to the detected identity information of the specific user is registered (hereinafter referred to as the "identical identity information registration determination process") (step S105).

[0301] At this time, if the identity verification processing unit 104 determines that the first database 140 does not have registered identity information identical to the detected identity information of the specific user, the combination of the detected person formation area image and the detected identity information is new, so the combination is newly registered in the first database 140 (step S106) and the process proceeds to step S110.

[0302] At this time, if the personal identification processing unit 104 determines that the first database 140 has registered personal identification information identical to the detected personal identification information of the specific user, the process proceeds to step S107.

[0303] Next, if the identity verification processing unit 104 determines in step S104 that the detected identity information is not identical to the corresponding registered identity information, and if it determines in step S106 that the first database 140 contains registered identity information identical to the detected identity information of a specific user, it determines that the official certificate image information included in the input information is forged or may be forged (step S107).

[0304] Next, the personal identification processing unit 104 registers the combination of the detected person formation area image and the detected personal identification information in the blacklist information (step S203). However, the detected person formation area image and the detected personal identification information may be registered separately.

[0305] Next, the specific processing control unit 105 executes the specific processing based on the official certificate image information included in the input information (step S108), and ends this operation.

[0306] On the other hand, if the identity verification processing unit 104 registers the relevant information in the whitelist information in the processing of step S202, or if the new combination of the detected person formation area image and the detected identity information is newly registered in the first database 140 in the processing of step S106, the identity verification processing unit 104 confirms that the person is the person in the identity verification based on the input information, notifies the service server device 30 of this fact (step S110), and terminates this operation.

[0307] [C] Other The present invention is not limited to the above-described embodiments, and various modifications are possible. For example, terms cited in the specification or drawings as broadly defined or synonymous terms can be replaced with broadly defined or synonymous terms in other descriptions in the specification or drawings.

[0308] The present invention includes configurations that are substantially the same as the configurations described in the embodiments (for example, configurations with the same functions, methods, and results, or configurations with the same purpose and effects). The present invention also includes configurations in which non-essential parts of the configurations described in the embodiments are replaced. The present invention also includes configurations that achieve the same effects as the configurations described in the embodiments or that can achieve the same purpose. The present invention also includes configurations in which publicly known technology is added to the configurations described in the embodiments.

[0309] Although the embodiments of the present invention have been described in detail as above, it will be readily apparent to those skilled in the art that many modifications can be made without substantially departing from the novel features and effects of the present invention. Therefore, all such modifications are intended to be included within the scope of the present invention. [Explanation of symbols]

[0310] 1, 2: Authentication management communication system 10, 11: Authentication server device 20: Terminal device 30: Service server device (information providing server device) 50: Server equipment for fake information providing site 100: Processing section 101: Communication control unit 102: DB management control unit 103: Authentication processing unit 104: User information management control unit 107: Timer management unit 140: First Database 141: Second database 142: Third Database 143: 4th Database 144: 5th Database 170: Storage section 180: Information storage medium 196: Communications Department 200: Processing section 210: Communication control unit 211: Web browser 212: Imaging control unit 213: Display control unit 214: Input reception processing unit 220: Drawing section 230: Sound processing unit 250: Imaging unit 260: Operation input section 262:Detection unit 270: Storage section 271: Main memory 272: Image buffer 273: User information storage unit 280: Information storage medium 290: Display section 292: Sound output unit 296: Communications Department

Claims

1. An identity verification system that performs a process related to identity verification of a user as identity verification processing to enjoy a given network service by using a public certificate for verifying the identity of the user having a person image in which the person, including a face, is imaged and identity identification information, a management means for managing each registered official certificate information, which is information on the official certificate stored in a storage means as data, and which includes the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; a reception processing means for receiving input information including at least image information of the identity verification certificate obtained by imaging the official certificate of the specific user who desires the identity verification processing; an image analysis processing means for executing image analysis processing to detect, from the received image information of the personal identification certificate, an image of a person formation area including the person and the personal identification information imaged in the image information of the personal identification certificate as a detected person formation area image and a detected personal identification item, respectively; a determination processing means for executing a certificate information determination process for searching the registered official certificate information based on the detected person formation area image and detected personal identification information detected by the image analysis process, and determining whether or not at least one of the registered person formation area image and the registered personal identification information exists within a range that is identical to or considered to be identical to at least one of the detected person formation area image and detected personal identification information; an identification processing means for executing a given identification process based on the fact that the accepted input information is not authentic or is highly likely to be not authentic, when the certificate information determination process determines that one of the detected person formation area image and the detected personal identification information is the same or within a range where it is considered to be identical with one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and the other of the detected person formation area image and the detected personal identification information is not identical; An identity verification system characterized by comprising:

2. 2. The personal identification system according to claim 1, The determination processing means executes a standard determination process for determining whether or not the detected person formation area image conforms to a standard defined in predetermined standard information; The identification processing means an identification system that executes the identification process when it is determined that the detected person formation area image does not conform to a standard defined in predetermined standard information;

3. 3. The personal identification system according to claim 2, An identity verification system, wherein the standards specified in the standards information include at least one of standards regarding images of area portions where people are formed and standards regarding images of area portions where people are not formed.

4. In the personal identification system according to any one of claims 1 to 3, The determination processing means execute a person determination process for determining whether the detected person formation area image is identical to or within a range that is considered to be identical to a person image of a malicious third party stored in advance in the storage means; The identification processing means If the person determination process determines that the detected person formation area image is identical or within a range that can be considered identical to a person image of a malicious third party that is pre-stored in the storage means, the accepted input information is not legitimate public certificate information, and the identification process is executed.

5. 5. The personal identification system according to claim 4, The determination processing means execute a process of detecting each face image information included in the registered public certificate information that is identical or within a range that is considered to be identical to the detected person formation area image determined to be not the legitimate public certificate information; The identification processing means When face image information contained in the registered public certificate information that is identical or within a range deemed to be identical to the detected person formation area image that has been determined not to be the genuine public certificate information is detected, the detected registered public certificate information is deemed not to be the genuine public certificate information and is updated and registered.

6. In the personal identification system according to any one of claims 1 to 5, The identification processing means When the certificate information determination process determines that both the detected person formation area image and the detected personal identification information are identical or within a range that is deemed to be identical to both the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, the identification process registers the accepted input information in the storage means as the registered official certificate information.

7. 7. The personal identification system according to claim 6, The identification processing means An identity verification system that, when it is determined that both the detected person formation area image and the detected identity information detected by the image analysis process are identical to the genuine registered public certificate information or are within a range that is deemed to be identical, performs identification processing on the accepted input information as the genuine public certificate information.

8. In the personal identification system according to any one of claims 1 to 7, The input information includes, as input face image information, face image information of a face image of the specific user together with the image information of the personal identification certificate, The determination processing means An identity verification system that executes the certificate information determination process using the input face image information.

9. An identity verification system that performs a process related to identity verification of a user as identity verification processing to enjoy a given network service by using a public certificate for verifying the identity of the user having a person image in which the person, including a face, is imaged and identity identification information, a management means for managing each registered official certificate information, which is information on the official certificate stored in a storage means as data, and which includes the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; a reception processing means for receiving input information including at least image information of the identity verification certificate obtained by imaging the official certificate of the specific user who desires the identity verification processing; an image analysis processing means for executing image analysis processing to detect an image of a person formation area that is imaged in the accepted image information of the personal identification certificate and that includes the person, and the personal identification item that is imaged in the image information of the personal identification certificate, as a detected person formation area image and a detected personal identification item, respectively; an identity verification determination processing means for executing a comparison process that compares the registered person formation area image and the registered person identification information included in the registered public certificate information with the detected person formation area image and the detected person identification information detected by the image analysis process, and for executing an identity verification determination process that determines whether or not the person can be recognized as the person in identity verification based on the accepted input information according to the comparison result; a specific processing means for executing a given specific processing depending on a result of the identity verification determination processing; a certificate information determination processing means for executing a registered certificate forgery determination process to determine whether the registered public certificate information is a forged certificate or a certificate that may be forged, depending on the result of the comparison; an update processing means for executing an update process to update and register the registered public certificate information as not being genuine public certificate information when the registered certificate counterfeit determination process determines that the registered public certificate information is a counterfeit certificate or a certificate that may be counterfeit, and to update and register the registered public certificate information as being genuine public certificate information when the registered public certificate information is determined to be not a counterfeit certificate by the certificate counterfeit determination process; An identity verification system characterized by comprising:

10. 10. The personal identification system according to claim 9, The certificate information determination processing means an identity verification system that, as the registered certificate counterfeit determination process, determines that one of the detected person formation area image and the detected personal identification information and one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image are identical or within a range that is deemed to be identical, and that the other of the detected person formation area image and the detected personal identification information and the other of the detected person formation area image and the detected personal identification information are not identical, determines that the combination of the registered person formation area image and the registered personal identification information that is the subject of the determination is public certificate information used by a malicious third party or public certificate information that may have been used.

11. 11. The personal identification system according to claim 9, The certificate information determination processing means In the registered certificate forgery determination process, if it is determined that a combination of the registered person formation area image that is identical to the detected person formation area image or within a range that is deemed to be identical, and the registered person identification information that matches the detected person identification information, is registered, the identity verification system determines that the combination of the registered person formation area image and registered person identification information that is the subject of the determination is the genuine official certificate information.

12. A program for executing a process for verifying the identity of a user as an identity verification process in order to enjoy a given network service, using a public certificate for verifying the identity of the user having a person image in which the person includes a face and personal identification information, a management means for managing each registered official certificate information, which is information on the official certificate stored in a storage means as data, and which includes the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; a reception processing means for receiving input information including at least image information of the identity verification certificate obtained by imaging the official certificate of the specific user who desires the identity verification processing; an image analysis processing means for executing image analysis processing to detect, from the received image information of the personal identification certificate, an image of a person formation area including the person and the personal identification details visualized in the image information of the personal identification certificate as a detected person formation area image and a detected personal identification detail, respectively; a determination processing means for executing a certificate information determination process that searches the registered official certificate information based on the detected person formation area image and detected personal identification information detected by the image analysis process, and determines whether or not at least one of the registered person formation area image and the registered personal identification information exists within a range that is identical or deemed to be identical to at least one of the detected person formation area image and detected personal identification information; and an identification processing means that executes a given identification process based on the fact that the accepted input information is not authentic or is highly likely to be not authentic, when the certificate information determination process determines that one of the detected person formation area image and the detected personal identification information is the same as or within a range where it is considered to be identical to one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and that the other of the detected person formation area image and the detected personal identification information is not identical to the other of the detected person formation area image and the detected personal identification information; A program characterized by causing a computer to function as a

13. A program for executing a process for verifying the identity of a user as an identity verification process in order to enjoy a given network service, using a public certificate for verifying the identity of the user having a person image in which the person includes a face and personal identification information, a management means for managing each registered official certificate information, which is information on the official certificate stored in a digital form in a storage means, and which includes the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; a reception processing means for receiving input information including at least image information of the identity verification certificate obtained by imaging the official certificate of the specific user who desires the identity verification processing; an image analysis processing means for executing image analysis processing to detect an image of a person formation area that is imaged in the accepted image information of the personal identification certificate and that includes the person, and the personal identification item that is imaged in the image information of the personal identification certificate, as a detected person formation area image and a detected personal identification item, respectively; The registered person formation area image and the registered an identity verification determination processing means for executing a comparison process of comparing the detected identity identification details with the detected person formation area image and the detected identity identification details detected by the image analysis process, and for executing an identity verification determination process of determining whether or not the person can be recognized as the person in identity verification based on the accepted input information, according to the result of the comparison; a specific processing means for executing a given specific processing depending on a result of the identity verification determination processing; a certificate information determination processing means for executing a registered certificate counterfeit determination process to determine whether the registered public certificate information is a counterfeit certificate or a certificate that may be counterfeit, depending on the result of the comparison; and an update processing means for executing an update process to update and register the registered public certificate information as not being genuine public certificate information when the registered certificate counterfeit determination process determines that the registered public certificate information is a counterfeit certificate or a certificate that may be counterfeit, and to update and register the registered public certificate information as being genuine public certificate information when the registered public certificate information is determined to be not a counterfeit certificate by the certificate counterfeit determination process; A program characterized by causing a computer to function as a

14. An identity verification method in which a computer executes a process for verifying the identity of a user having a person image including a face and personal identification information as identity verification processing in order to enjoy a given network service, using the person image and a public certificate for verifying the identity of the user, managing each registered public certificate information held by the user, the public certificate information being digitized and stored in a storage means, the person image and the information on the personal identification items associated with the person image, as registered person image information and registered personal identification item information; receiving input information including at least image information of the identity verification certificate in which the official certificate of the specific user who desires the identity verification process is imaged; executing an image analysis process to detect, from the received image information of the personal identification certificate, an image of a person formation area including the person and the personal identification information imaged in the image information of the personal identification certificate as a detected person formation area image and a detected personal identification item, respectively; Executing a certificate information determination process to search the registered public certificate information based on the detected person formation area image and detected personal identification information detected by the image analysis process, and to determine whether or not at least one of the registered person formation area image and the registered personal identification information exists within a range that is identical or deemed to be identical to at least one of the detected person formation area image and detected personal identification information; and When the certificate information determination process determines that one of the detected person formation area image and the detected personal identification information is the same as or within a range where it is considered to be the same as one of the registered person formation area image and the registered personal identification information corresponding to the registered person formation area image, and the other of the detected person formation area image and the detected personal identification information is not the same as the other of the detected person formation area image and the detected personal identification information, a given identification process is executed based on the fact that the accepted input information is not authentic information or is highly likely to be not authentic information; A method of identity verification characterized by including:

15. An identity verification method in which a computer executes a process for verifying the identity of a user having a person image including a face and personal identification information as identity verification processing in order to enjoy a given network service, using the public certificate for verifying the identity of the user, The information on the official certificate, which is digitized and stored in a storage means, includes the person image and the information on the personal identification items associated with the person image, and is stored as registered person image information. Manage the registered public certificate information held by the user as the registered personal identification information, receiving input information including at least image information of the identity verification certificate in which the official certificate of the specific user who desires the identity verification process is imaged; executing an image analysis process to detect an image of a person formation area that is imaged in the accepted image information of the personal identification certificate and that includes the person, and the personal identification item that is imaged in the image information of the personal identification certificate, as a detected person formation area image and a detected personal identification item, respectively; Execute a comparison process to compare the registered person formation area image and the registered personal identification information included in the registered public certificate information with the detected person formation area image and the detected personal identification information detected by the image analysis process, and execute an identity verification determination process to determine whether or not the person can be recognized as the person in identity verification based on the accepted input information according to the comparison result. Executing a given specific process depending on the result of the identity verification determination process; Executing a registered certificate counterfeit determination process to determine whether the registered public certificate information is a counterfeit certificate or a certificate that may be counterfeit, depending on the result of the comparison; and executing an update process to update and register the registered public certificate information as not being genuine public certificate information when the registered certificate counterfeit determination process determines that the registered public certificate information is a counterfeit certificate or a certificate that may be counterfeit; and to update and register the registered public certificate information as being genuine public certificate information when the registered certificate counterfeit determination process determines that the registered public certificate information is not a counterfeit certificate. A method of identity verification characterized by including:

Citation Information

Patent Citations

  • Authentication system

    JP2006092530A

  • Service system and optimal service provision method

    JP2006323728A

  • Information processing system, and processing method and program thereof

    JP2016157439A

  • Authenticity determination system, method and program for identity confirmation document

    JP2019003421A

  • Program, information processing method, and information processing device

    JP2020021291A