Authentication devices, sales systems, transit systems, and automated teller systems
The authentication device verifies facial data and additional identification information against a server database to prevent misidentification, addressing vulnerabilities in tampered identification documents.
Patent Information
- Application Number
- JP2022159451
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-08-10
- Filing Date
- 2022-10-03
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2042-07-15
AI Technical Summary
Existing authentication devices are vulnerable to erroneous authentication when facial photographs or recorded data on identification documents are tampered with, leading to potential misidentification.
An authentication device that acquires both displayed and recorded facial data, along with identification information, and verifies it against a server's face database to ensure authenticity, using feature data comparison within predetermined ranges.
Prevents misidentification by comparing multiple facial data points and additional identification information, reducing authentication time and enhancing security against tampering.
Smart Images

Figure 0007731137000001 
Figure 0007731137000002 
Figure 0007731137000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an authentication device, a sales system, a transit system, and an automated teller system. [Background technology]
[0002] Patent Document 1 discloses in claim 1 that "an identity authentication device for verifying the identity of a user, comprising: a photographed image acquisition unit that photographs the user with a camera and acquires a first facial image; a photographed image acquisition unit that reads a facial photo attached to the user's identification document and acquires a second facial image; a recorded image acquisition unit that reads facial photo data recorded on an IC chip attached to the identification document and acquires a third facial image; and a matching processing unit that compares the first facial image, the second facial image, and the third facial image, and determines that the user is the user if the matching rate of the three facial images is equal to or greater than a predetermined value."
[0003] Here, referring to paragraphs
[0024] ,
[0029] , etc. of the specification of Patent Document 1, this matching processing unit can be understood to, for example, (1) extract a plurality of feature points from each of the first facial image, the second facial image, and the third facial image, (2) compare the plurality of feature points of these facial images, and (3) determine that the facial images are of the same person if there is a certain number or more of matching feature points in these images.
[0004] The above-mentioned personal authentication device disclosed in Patent Document 1 is as follows:
[0005] and
[0006] According to the document, "In the future, it is expected that various transactions will be conducted via online terminals such as ATMs, and it will be necessary to be able to efficiently perform highly accurate personal authentication that complies with the Act on Prevention of Transfer of Criminal Proceeds," and therefore "the purpose is to provide an authentication device that can efficiently perform highly accurate personal authentication."
[0005] However, with the personal authentication device disclosed in Patent Document 1, if another person tampers with the facial photograph attached to the personal identification document or the facial photograph data recorded on the IC chip to falsely represent themselves as the person identified by the personal identification document, there is a risk that the person will be mistakenly authenticated as the person, since it is unlikely that there will be any difference in the facial image. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Patent No. 6513866 specification Summary of the Invention [Problem to be solved by the invention]
[0007] The present invention has been made in consideration of the problems of the conventional technology, and aims to provide an authentication device that can prevent an identification device from being erroneously authenticated even if the facial photograph displayed on the identification device or its recorded facial data is tampered with. [Means for solving the problem]
[0008] According to a first aspect of the present invention, there is provided an authentication device that can prevent erroneous authentication of an identification device even if the facial photograph displayed on the identification device or its recorded facial data is tampered with. This authentication device is used to authenticate an identification device that includes a facial photograph displayed on the exterior and recorded facial data recorded in a memory unit in correspondence with the facial photograph. the authentication device comprises: a first image acquisition unit that acquires an image of at least a part of the outer surface of the identification body; a displayed face data acquisition unit that acquires displayed face data corresponding to the facial photograph from the image acquired by the first image acquisition unit; an identification information acquisition unit that acquires identification information for identifying the identification body from the image acquired by the first image acquisition unit or from the memory unit of the identification body; a recorded face data acquisition unit that acquires the recorded face data from the memory unit of the identification body; a transceiver unit that transmits the identification information acquired by the identification information acquisition unit to a server having a face database to request stored face data associated with the identification information, and receives from the server in response to the request the stored face data stored in the face database or data indicating that the requested stored face data does not exist in the face database; and an authentication unit that authenticates the identification body based at least on the displayed face data acquired by the displayed face data acquisition unit, the recorded face data acquired by the recorded face data acquisition unit, and the response from the server received by the transceiver unit.
[0009] According to a second aspect of the present invention, there is provided a sales system including the authentication device of any one of configurations 1 to 9 above, and a sales device communicatively connected to the authentication device and configured to sell merchandise. The sales device is configured to, when the authentication unit of the authentication device affirms the authentication of the personal identification body, receive information indicating this affirmation from the authentication device, thereby enabling the sale of the merchandise.
[0010] According to a third aspect of the present invention, there is provided a passing system comprising: an authentication device according to any one of configurations 1 to 9; and a passing device communicatively connected to the authentication device, for permitting a user to pass through a communication passage between one area and another area or for monitoring the user's passage. The passing device is configured such that, when the authentication unit of the authentication device affirms the authentication of the personal identification body, the passing device receives information indicating this from the authentication device and permits the user to pass through the communication passage; and, when the authentication unit denies the authentication of the personal identification body, the passing device disables the user from passing through the communication passage or issues an alert.
[0011] According to a fourth aspect of the present invention, there is provided an automated teller system comprising: an authentication device according to any one of configurations 1 to 9 above; and an automated teller machine communicably connected to the authentication device. The automated teller machine is configured so that, when the authentication unit of the authentication device affirms the authentication of the personal identification body, it receives information indicating this from the authentication device, and enables a user to perform an automated teller operation. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a schematic diagram showing a sales system including an authentication device according to a first embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing the functional configuration of the sales device and authentication device in the sales system shown in FIG. [Figure 3] FIG. 3 is a diagram schematically illustrating a My Number card as an example of an identity verification device used in the sales system shown in FIG. [Figure 4] FIG. 4 is a flowchart of the operation of the authentication device in the sales system shown in FIG. [Figure 5] FIG. 5 is a flowchart of the operation of the server of the sales system shown in FIG. [Figure 6] FIG. 6 is a flowchart of the operation of the authentication device according to the second embodiment of the present invention. [Figure 7]FIG. 7 is a schematic diagram showing a sales system including an authentication device according to the third embodiment of the present invention. [Figure 8] FIG. 8 is a block diagram showing the functional configuration of the sales device and authentication device in the sales system shown in FIG. [Figure 9] FIG. 9 is a flowchart of the operation of the authentication device in the sales system shown in FIG. [Figure 10] FIG. 10 is a schematic diagram showing a passing device that can be used with an authentication device according to the present invention. [Figure 11] FIG. 11 is a schematic diagram illustrating an automated teller machine that can be used with an authentication device according to the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0013] An embodiment of an authentication device according to the present invention will be described in detail below with reference to FIGS. 1 to 11. In FIGS. 1 to 11, identical or corresponding components are denoted by the same reference numerals, and duplicate descriptions will be omitted. In addition, in FIGS. 1 to 11, the scale and dimensions of each component may be exaggerated, and some components may be omitted. In the following description, unless otherwise specified, terms such as "first" and "second" are used merely to distinguish components from one another, and do not represent a particular order or ranking.
[0014] A sales system including an authentication device according to a first embodiment of the present invention will be described below with reference to the drawings. First, the functions and configuration of the sales system according to this embodiment will be described. Next, the sales operation of the sales system according to this embodiment will be described. Next, the effects of the sales system according to this embodiment will be described.
[0015] Fig. 1 is a schematic diagram showing a sales system 10 including an authentication device 30 according to a first embodiment of the present invention. As shown in Fig. 1, the sales system 10 of this embodiment includes a plurality of sales devices 20 installed at a plurality of locations, an authentication device 30 connected to each of the sales devices 20, and a server 50 connected to the plurality of authentication devices 30 via a network 40 such as the Internet. Fig. 2 is a block diagram showing the functional configuration of the sales devices 20 and the authentication device 30.
[0016] [Sales Device 20] The vending device 20 is, for example, a vending machine for selling products (not shown). The products sold by the vending device 20 are, for example, cigarettes and alcohol, but are not limited to cigarettes and alcohol as long as authentication (including age verification) of the user of the vending device 20, who is the purchaser, is required to purchase the product.
[0017] One example of the vending device 20 is a vending machine. Although a detailed description of its configuration will be omitted in this specification, the vending device 20 is communicably connected to the authentication device 30. Specifically, the vending device 20 is equipped with a control unit 22 that controls the main body of the vending device 20 (the controllable components other than the control unit 22). The control unit 22 is configured to enable the main body of the vending device 20 to sell products by receiving information from the authentication device 30 indicating that a positive determination has been made, as described below. As shown in FIG. 1, the vending device 20 is equipped with, for example, a product display 24 that displays samples S of multiple products to be sold, and a product removal slot 26 through which the user can remove the purchased products.
[0018] [Authentication device 30] The authentication device 30 is configured, for example, by a computer, and as shown in FIG. 1, is equipped with a confirmation object photographing unit 34 configured, for example, by a camera or scanner, a storage unit 35 including ROM, RAM, flash memory, etc., a reading unit 36 configured by an RFID-type reading device, etc., a communication unit 37 for connecting to the network 40 and communicating data with the server 50, a communication unit 38 for communicating data with the vending device 20, and a control unit 39 for controlling the operation of each component.
[0019] The storage unit 35 stores an OS (Operating System), programs for controlling the authentication device 30, programs for performing authentication according to the present invention, and various other data. The control unit 39 includes a processor (CPU), ROM, RAM, etc., and realizes various functions (such as the functions of the display face data acquisition unit 61, display information acquisition unit 62, authentication unit 63, and transmission / reception unit 64 shown in FIG. 2) by loading programs stored in the storage unit 35 into the RAM and executing them with the processor. Each unit of the authentication device 30 will be described below, and the functions of each unit are described such that the control unit 39 controls the operation of each unit based on the program P.
[0020] The authentication device 30 has a function of authenticating an identity verification object, and is communicatively connected to the control unit 22 of the vending device 20 via the communication unit 38. In this specification, "communicatively connected" means that data transfer is possible. Therefore, examples of this connection may be a wired connection using a cable or the like, a wireless connection using electromagnetic waves such as infrared or ultraviolet, or a combination of a wired connection and a wireless connection, such as an internet connection.
[0021] Examples of identity verification devices include driver's licenses, My Number cards, cash cards, credit cards, employee ID cards, transportation cards, electronic money cards, etc., which have a photograph of the face, basic information such as name and address, and other information displayed on the outside, and which are equipped with a recording medium as a memory unit inside. In the following explanation, we will mainly explain an example in which a My Number card is used as an identity verification device, but the following explanation can be applied to other types of identity verification devices as well.
[0022] 3 is a diagram schematically illustrating a My Number card M as an example of an identification device used in this embodiment. On the outer surface of the My Number card M, a facial photograph 70 of the owner of the My Number card M, the owner's name 71, the owner's address 72, the owner's gender 73, the owner's date of birth 74, the My Number card M's expiration date 75, the My Number card M's serial number 76, and a security code 77 are displayed. This information can be attached or printed on the outer surface of the identification device.
[0023] The name 71, address 72, gender 73, and date of birth 74 displayed on the exterior of the My Number Card M are part of the basic information about the owner of the My Number Card M, and are referred to here as the "basic display information." The types of information used as the basic display information are not limited to the four listed here; only some of these may be used as the basic display information, or other information may be added to these pieces of information, or different information may be used as the basic display information. The serial number 76 of the My Number Card M is a number assigned to each My Number Card and can be used as identification information to identify the My Number Card. For example, if the identification device is a driver's license, the license number can be used as identification information.
[0024] The Individual Number Card M, which serves as an identification device, is provided with a recording medium as a storage unit inside, and this recording medium stores image data (recorded face data) of the facial photograph 70 displayed on the outside. This recording medium also stores image data and text data of the basic display information displayed on the outside as recorded basic information. In addition to the above information, this recording medium also stores an electronic certificate that can be used by entering a personal identification number (PIN).
[0025] The identification device may be, for example, an information communication terminal such as a smartphone. In this case, the facial photograph and basic information displayed on the identification device may be displayed on an output device such as a display of the identification device. Furthermore, the recording medium of the identification device may be configured to be able to communicate with an external database, and image data of the facial photograph received from the external database may be stored in the recording medium as recorded face data.
[0026] The identification object photographing unit 34 functions as a (first) image acquiring unit that photographs the identification object that the user is about to use and acquires an image of at least a part of the outer surface of the identification object. This identification object photographing unit 34 may be any device that is capable of photographing the object and acquiring image data thereof. One example of the identification object photographing unit 34 is a digital camera that is capable of acquiring photographed data. However, as long as it can perform the above-mentioned functions, the identification object photographing unit 34 does not have to be a digital camera, and may be, for example, a scanner.
[0027] The display face data acquisition unit 61, which is realized by the program P of the control unit 39, acquires the portion of the image data of the outer surface of the identification body photographed by the identification body photographing unit 34, in which the facial photograph 70 (see Figure 3) is displayed, as display face data.
[0028] Furthermore, the display information acquisition unit 62 realized by the program P extracts the portions displaying the respective information (name 71, address 72, gender 73, date of birth 74, expiration date 75, serial number 76, and security code 77) from the image of the outer surface of the identification object photographed by the identification object photographing unit 34, and recognizes the characters written in these portions to acquire the data. Therefore, the display information acquisition unit 62 can function as an identification information acquisition unit that acquires the serial number 76 as identification information from the image data acquired by the identification object photographing unit 34, and as a display basic information acquisition unit that acquires the display basic information (name 71, address 72, gender 73, and date of birth 74) from the image data acquired by the identification object photographing unit 34.
[0029] The reading unit 36 has the function of reading data stored in the recording medium of the identification device and storing the read data. That is, the reading unit 36 can function as a recorded face data acquisition unit that reads and acquires image data (recorded face data) of the facial photograph 70 from the recording medium of the identification device, and as a recorded basic information acquisition unit that reads and acquires recorded basic information from the recording medium of the identification device. For example, if the identification device is a card or the like and data is stored in the memory (not shown) of an RFID tag, the reading unit 36 may be an RFID-type reading device that can store the read data.
[0030] For security reasons, access to the data stored on the recording medium of the identification device may be restricted. For example, if the identification device is a My Number card M, the recorded face data and recorded basic information can be read by the reading unit 36 by inputting a matching number that combines the date of birth 74, expiration date 75, and security code 77 acquired by the display information acquisition unit 62.
[0031] Furthermore, for example, if the identification device is an information and communication device such as a smartphone, the reading unit 36 may read data (for example, recorded face data or recorded basic information) from the identification device by data transfer using a communication method such as the Internet or infrared rays, and store the read data. In either case, the reading unit 36 may be capable of reading data using a method suited to the type of identification device.
[0032] The authentication unit 63, which is realized by the program P of the control unit 39, makes a positive judgment that the personal identification body is genuine (not tampered with) or a negative judgment that the personal identification body is fake (tampered with) based on the multiple facial data acquired as described below.
[0033] Any method can be used for authenticating the identification body based on multiple pieces of face data. For example, the authentication unit 63 may (1) calculate feature data for each piece of target face data, and (2) (i) make a positive determination that the identification body is genuine (not tampered with) if the feature values obtained from each calculated feature data are within a predetermined range, or (ii) make a negative determination that the identification body is fake (tampered with) if not.
[0034] Alternatively, the authentication unit 63 may (1) calculate multiple feature points for each of the target face data, (2) compare these feature points, and (i) if the number of matching feature points is equal to or greater than a predetermined number, make a positive determination that the identification body is genuine (not tampered with), or (ii) if not, make a negative determination that the identification body is fake (tampered with).
[0035] The "feature data" or "feature points" is, for example, data obtained from an image of a portion of a face including both eyes. More specifically, the "feature data" or "feature points" is one or more pre-selected data from the following values: (1) facial structure, (2) the distance between the outer edge of one eye and the outer edge of the other eye, (3) the distance between the inner edge of one eye and the inner edge of the other eye, (4) the angle of a second imaginary line connecting the inner edge of one eye and the inner edge of the other eye relative to a first imaginary line connecting the outer edge of one eye and the outer edge of the other eye, (5) the distance between the center of the eyeball of one eye and the center of the eyeball of the other eye, (6) the angle of a third imaginary line relative to the first imaginary line, (7) the maximum width of each eye, (8) the ratio of the maximum widths of the eyes to each other, (9) the shape of the nose, (10) the position of the nose relative to both eyes, (11) the position of the mouth relative to both eyes, etc.
[0036] The "feature value obtained from each calculated feature data" means a value calculated by a function incorporated in the program P of the control unit 39 using the aforementioned predetermined feature data. For example, it may be a value calculated by a function with parameters (2), (4), and (5), or a value calculated by a function with parameters (2), (3), and (6). It may also be a value expressed as an n × m matrix (n and m are integers equal to or greater than 1) consisting of these multiple values.
[0037] The above function in this embodiment is a function derived by the inventors of the present application by collecting parameters related to the position, size, angle, etc. of each of the above-mentioned exemplary facial features using a large number of human samples, both for the same person and for different people. Also, the above-mentioned "predetermined range" is a range determined by adjusting the feature value calculated from the function when the inventors of the present application derived the function.
[0038] The transmitting / receiving unit 64, which is realized by the program P of the control unit 39, has a function of transmitting the identification information (serial number 76) acquired by the display information acquisition unit 62 to the server 50 via the communication unit 37, and of requesting stored face data associated with this identification information from the server 50. The transmitting / receiving unit 64 also has a function of transmitting the displayed face data acquired by the displayed face data acquisition unit 61 or the recorded face data acquired by the reading unit 36 to the server 50, and a function of transmitting information other than the serial number 76 acquired by the display information acquisition unit 62 to the server 50. The transmitting / receiving unit 64 is configured to receive a response from the server 50 via the communication unit 37.
[0039] [Server 50] 1, the server 50 includes a storage unit 51 including a ROM, RAM, flash memory, etc., a communication unit 52 for connecting to the network 40 and performing data communication, and a control unit 53 for controlling the operation of each component. The storage unit 51 stores an OS, programs for controlling the server 50, a face database 54 (described later), and various other data. The control unit 53 includes a processor (CPU), ROM, RAM, etc., and realizes various functions by loading programs stored in the storage unit 51 into the RAM and executing them with the processor.
[0040] The face database 54 stored in the storage unit 51 of the server 50 includes records containing identification information of the personal identification body and face data (stored face data) associated with the identification information. In this embodiment, the serial number 76 displayed on the outer surface of the My Number card M is used as the identification information included in the face database 54.
[0041] The server 50 is communicably connected to the control unit 39 of the authentication device 30 via the communication unit 52 (and the communication unit 37 of the authentication device 30). The server 50 is configured to receive, via the communication unit 52, a request to acquire stored face data transmitted from the authentication device 30 together with the serial number 76 as identification information, and to search for a corresponding record in the face database 54 using the received identification information as a key. The server 50 transmits the search results for this record to the authentication device 30 via the communication unit 52. The server 50 can also receive the displayed face data or recorded face data transmitted from the authentication device 30, and store the data in the face database 54 as stored face data in association with the received serial number 76.
[0042] Next, the sales operation of sales system 10 of this embodiment will be described mainly with reference to Figures 4 and 5. Figure 4 is a flowchart of the operation of authentication device 30 of sales system 10 of this embodiment, and Figure 5 is a flowchart of the operation of server 50. As mentioned above, with regard to the operation of authentication device 30, control unit 39 controls the operation of each unit of authentication device 30 based on program P, with regard to the operation of vending device 20, control unit 22 controls the operation of each unit of vending device 20, and with regard to the operation of server 50, control unit 53 controls the operation of each unit of server 50; the following explanation will be made based on this premise.
[0043] First, when a person who wishes to purchase a product from one of the multiple vending machines 20 positions himself / herself in front of that vending machine 20, the vending system 10 instructs the person who wishes to purchase the product to insert his / her personal identification device (My Number card M) into the card insertion slot of the identification device photographing unit 34. Then, the user of the vending machine 20 who wishes to purchase the product follows this instruction and inserts his / her personal identification device (My Number card M) into the card insertion slot. Then, the authentication device 30 starts the sales operation flow shown in Figure 4.
[0044] First, the identification object photographing unit 34 of the authentication device 30 photographs the outer surface of the identification object (My Number card M) and acquires the photographed image as photographed data (see step S10 in FIG. 4). Then, the displayed face data acquiring unit 61 extracts the portion of the photographed data where the facial photograph 70 is displayed and acquires it as displayed face data, and the displayed information acquiring unit 62 extracts the portion of the photographed data where each piece of information (name 71, address 72, gender 73, date of birth 74, expiration date 75, serial number 76, and security code 77) is displayed, recognizes the characters written in these portions, and acquires the data (see step S11 in FIG. 4).
[0045] Furthermore, the reading unit 36 reads the recorded face data and recorded basic information stored in the recording medium of the identification device (My Number card M) and stores the read recorded face data and recorded basic information (see step S12 in FIG. 4). At this time, if required for security reasons of the identification device, part or all of the information acquired by the display information acquiring unit 62 is input into the identification device as a security key in order to read the recorded face data and recorded basic information.
[0046] The order of the above operations may be reversed. For example, steps S10 and S11 may be performed after step S12. Furthermore, the operations of steps S10 and S11 may be performed in parallel with step S12. In either case, steps S10 to S12 only need to be completed before step S20, which will be described later.
[0047] Next, the transmitter / receiver unit 64 of the authentication device 30 transmits the identification information (the serial number 76 of the My Number card M) from the information acquired by the display information acquisition unit 62 to the server 50, and also transmits a request to the server 50 to acquire face data (saved face data) associated with this identification information from the face database 54 (see step S20 in Figure 4).
[0048] When the communication unit 52 of the server 50 receives the identification information and data acquisition request transmitted from the authentication device 30 (see step S50 in FIG. 5), the control unit 53 of the server 50 searches for a corresponding record in the face database 54 stored in the storage unit 51 using the received identification information (serial number 76) as a key (see step S51 in FIG. 5). If a corresponding record is found by this search, the control unit 53 of the server 50 transmits the stored face data in the corresponding record to the authentication device 30 via the communication unit 52 (see step S52 in FIG. 5). On the other hand, if a corresponding record is not found, the control unit 53 of the server 50 transmits data indicating that the requested stored face data does not exist in the face database 54 to the authentication device 30 via the communication unit 52 (see step S53 in FIG. 5).
[0049] Next, the transceiver 64 of the authentication device 30 receives a response from the server 50 (see step S21 in FIG. 4) and determines whether the response from the server 50 is stored face data (see step S30 in FIG. 4). If the response from the server 50 is stored face data, the authentication unit 63 of the authentication device 30 authenticates the Individual Number card M based on (1) the displayed face data acquired in step S11, (2) the recorded face data acquired in step S12, and (3) the stored face data received in step S21. For example, the authentication unit 63 calculates feature data for each of the displayed face data, the recorded face data, and the stored face data (see step S31 in FIG. 4), and determines whether the feature values obtained from each calculated feature data are within a predetermined range, thereby authenticating the Individual Number card M (see step S32 in FIG. 4).
[0050] If the authentication unit 63 makes a positive determination in step S32, it considers the identification device to be authentic. Next, the control unit 39 of the authentication device 30 transmits information to that effect (information that the identification device is authentic) to the control unit 22 of the vending device 20, and upon receiving the information, the control unit 22 starts the operation of selling the product to the user (see step S40 in FIG. 4). Then, as the sale of the product to the user by the vending device 20 ends, the selling operation of this embodiment also ends.
[0051] In contrast, if the authentication unit 63 makes a negative determination in step S32, it considers the identification device to be unauthentic. Next, the control unit 39 of the authentication device 30 transmits information to that effect (information that the identification device is unauthentic) to the control unit 22 of the vending device 20, and upon receiving the information, the control unit 22 terminates the vending operation of this embodiment without selling the product to the user via the vending device 20. In this case, the vending system 10 may notify the user of this effect, i.e., that the product cannot be sold because the identification device could not be authenticated, using a display device (not shown), a speaker (not shown), or other notification means.
[0052] On the other hand, if it is determined in step S30 that the response from the server 50 is not stored face data, i.e., if data indicating that the requested stored face data does not exist in the face database 54 of the server 50 is received from the server 50, the transmitter / receiver 64 transmits the displayed face data acquired by the displayed face data acquisition unit 61 to the server 50 to store it in the face database 54 of the server 50 (see step S33 in Figure 4).
[0053] When the communication unit 52 of the server 50 receives the displayed face data transmitted from the authentication device 30 in step S33, the control unit 53 of the server 50 stores the received displayed face data in the face database 54 in association with the identification information (serial number 76) received in step S50. The displayed face data stored here will be referenced as stored face data in step S31 the next time authentication is performed using the same identification information. Therefore, if, for example, the facial photograph 70 on the exterior of the identification device is tampered with before the next authentication, it becomes difficult for the displayed face data acquired in step S11 (image data of the tampered facial photograph 70) to match the stored face data received in step S21 (image data of the facial photograph 70 before tampering), making it more likely that a negative determination will be made in step S32. Therefore, even if the facial photograph displayed on the identification device has been tampered with, it is possible to prevent a person from being mistakenly identified as the person in question. This also applies when the recorded face data stored in the recording medium of the identification device has been tampered with.
[0054] As described above, after the displayed face data is transmitted to the server 50 in step S33 and stored in the face database 54, the authentication unit 63 of the authentication device 30 authenticates the My Number card M based on (1) the displayed face data acquired in step S11 and (2) the recorded face data acquired in step S12. For example, the authentication unit 63 calculates feature data for each of the displayed face data and the recorded face data (see step S34 in FIG. 4), and authenticates the My Number card M by determining whether the feature values obtained from each calculated feature data are within a predetermined range (see step S35 in FIG. 4).
[0055] If the authentication unit 63 makes a positive determination in step S35, the personal identification device is deemed to be authentic. Next, the control unit 39 of the authentication device 30 transmits information to that effect to the control unit 22 of the vending device 20. Upon receiving the information, the control unit 22 starts the operation of selling the product to the user (see step S40 in FIG. 4). Then, as the vending device 20 finishes selling the product to the user, the sales operation of this embodiment also ends.
[0056] On the other hand, if the authentication unit 63 makes a negative determination in step S35, it determines that the user is not the owner of the identification device. Next, the control unit 39 of the authentication device 30 transmits information to that effect to the control unit 22 of the vending device 20. Upon receiving the information, the control unit 22 ends the vending operation of this embodiment without selling the product to the user by the vending device 20.
[0057] For example, in the case of the personal authentication device disclosed in Patent Document 1 (hereinafter referred to as the comparative form), as described above, (1) a plurality of feature points is extracted from each of a first face image (a face image attached to the personal identification device) and a second face image (a face image saved in a recording medium on the personal identification device), (2) the plurality of feature points possessed by each of the two face images are compared, and (3) if there are a certain number or more of matching feature points between the two images, it is determined that the face images are of the same person. Therefore, in the case of the comparative form, personal authentication requires at least the time for the process of extracting a plurality of feature points from each of the two face images in (1) above, and the time for the process of comparing the feature points between the two face images in (2) above.
[0058] In contrast, for example, if the authentication unit 63 (1) calculates feature data for each of the displayed face data, recorded face data, and saved face data, or for each of the displayed face data and recorded face data, and (2) (i) makes a positive determination that the identification body is authentic if the feature values obtained from each calculated feature data are within a predetermined range, or (ii) makes a negative determination that the identification body is not authentic if the feature values are not within a predetermined range, authentication can be performed simply by comparing feature values based on predetermined feature data, without extracting multiple feature points from two or more face images or comparing the multiple feature points of each face image. Therefore, the authentication device 30 of this embodiment can shorten the authentication time compared to the comparative embodiment. Accordingly, the sales system 10 equipped with the authentication device 30 of this embodiment can shorten the time from the start of a user's operation to the end of the sale of a product compared to the comparative embodiment. Furthermore, the program P of this embodiment can shorten the authentication time compared to the comparative embodiment.
[0059] In this embodiment, an image of a portion of the face including both eyes is used as an example to calculate the feature value. Therefore, this embodiment is effective in that authentication can be performed even if an accurate image of the entire face is not available. For example, in this embodiment, even if an attachment that masks part of the face is attached to a portion of the first face image (displayed face data displayed on the identification device) other than the portion used for authentication (in this embodiment, the portion including both eyes, which is part of the face), authentication can be performed. This effect cannot be achieved in the comparative embodiment.
[0060] Furthermore, as described above, in the personal authentication device of the comparative embodiment, if the facial photograph or the like attached to the personal identification document is tampered with, there is a risk that the person may be mistakenly authenticated as the actual person. However, according to this embodiment, authentication is performed using not only the displayed face data corresponding to the facial photograph displayed on the personal identification device and the recorded face data recorded corresponding to this facial photograph, but also the stored face data associated with the identification information for identifying the personal identification device and stored in the face database of the server. Therefore, even if both the facial photograph displayed on the personal identification device and the recorded face data recorded corresponding to this facial photograph are tampered with, it becomes difficult for the untampered stored face data to match the displayed face data and the recorded face data, making it less likely that the person will be mistakenly authenticated as the actual person.
[0061] 6 is a flowchart of the operation of an authentication device according to a second embodiment of the present invention. This embodiment differs from the first embodiment in that an additional authentication determination step S111 or S112 is performed when a positive determination is made in the authentication determination step S32 or S35 in the first embodiment.
[0062] More specifically, after making a positive determination in authentication determination step S32, the authentication unit 63 further determines whether the display basic information acquired by the display information acquisition unit 62 in step S11 matches the recorded basic information acquired by the reading unit 36 in step S12 in part (for example, name 71 and date of birth 74) or in whole (see step S111 in FIG. 6). If it is determined that the display basic information matches the recorded basic information, the sales operation (step S40) is performed; if it is determined that they do not match, the authentication unit 63 considers that the personal identification device has been tampered with. Then, this sales operation flow ends.
[0063] After the affirmative determination is made in authentication determination step S35, an additional authentication determination step S112 is performed in the same manner, and if it is determined that the displayed basic information and the recorded basic information match, the sales operation (step S40) is performed, but if it is determined that they do not match, the authentication unit 63 considers that the personal identification device has been tampered with, and the sales operation flow then ends.
[0064] In the first embodiment described above, even if the displayed face data and the recorded face data are of different people, if the feature values obtained from the two face data are extremely similar (e.g., the case of very similar twins), that is, if the feature values of the two face data are within a predetermined range, the identification body is authenticated as authentic. However, in this embodiment, after so-called face authentication is performed in authentication judgment step S32 or step S35, a determination is made as to whether the displayed basic information and the recorded basic information match in part or in whole, which is authentication from a different perspective than face authentication (step S111 or step S112). Therefore, in this embodiment, even if a positive determination is made in image authentication, a negative determination can be made that the identification body has been tampered with. From another perspective, this embodiment can detect tampering of the identification body, which cannot be detected by face image authentication.
[0065] Fig. 7 is a schematic diagram showing a sales system 210 including an authentication device 230 according to a third embodiment of the present invention, and Fig. 8 is a block diagram showing the functional configuration of the sales device 20 and authentication device 230 shown in Fig. 7. Authentication device 230 in this embodiment differs from authentication device 30 in the first embodiment described above in that it has a user photographing unit 231 constituted by, for example, a camera, and a user face data acquisition unit 261 realized by program P of control unit 39.
[0066] User photographing unit 231 functions as a (second) image acquiring unit that photographs the user of vending device 20 and acquires an image of the user's face. This user photographing unit 231 may be any device that is capable of photographing an object and acquiring image data thereof. One example of user photographing unit 231 is a digital camera that is capable of acquiring photographed data. However, as long as it can perform the above-described functions, an example of user photographing unit 231 does not have to be a digital camera.
[0067] The user face data acquisition unit 261 realized by the program P of the control unit 39 is configured to acquire user face data obtained by capturing an image of the user's face from the image captured by the user photographing unit 231.
[0068] The authentication unit 63 in this embodiment is configured to authenticate the identity verification object using the face data used in the first embodiment as well as the user face data acquired by the user face data acquisition unit 261. In addition to the functions described in the first embodiment, the transmission / reception unit 64 in this embodiment also has a function of transmitting the user face data acquired by the user face data acquisition unit 261 to the server 50.
[0069] 9 is a flowchart of the operation of authentication device 230 in this embodiment. When the flow of the sales operation is started in authentication device 230, first, user photographing unit 231 of vending device 20 photographs the user and acquires the photographed image as photographed data (see step S210 in FIG. 9). Then, user face data acquisition unit 261 extracts the user's face from this photographed data and acquires it as user face data (see step S211 in FIG. 9).
[0070] Furthermore, the identification object photographing unit 34 of the authentication device 230 photographs the outer surface of the identification object (My Number card M) and acquires the photographed image as photographed data (see step S10 in FIG. 9). Then, the displayed face data acquiring unit 61 extracts the portion of the photographed data where the facial photograph 70 is displayed and acquires it as displayed face data, and the displayed information acquiring unit 62 extracts the portion of the photographed data where each piece of information (name 71, address 72, gender 73, date of birth 74, expiration date 75, serial number 76, and security code 77) is displayed, recognizes the characters written in these portions, and acquires the data (see step S11 in FIG. 9).
[0071] Furthermore, the reading unit 36 reads the recorded face data and recorded basic information stored in the recording medium of the identification device (My Number card M) and stores the read recorded face data and recorded basic information (see step S12 in FIG. 9). At this time, if required for security reasons of the identification device, part or all of the information acquired by the display information acquiring unit 62 is input into the identification device as a security key in order to read the recorded face data and recorded basic information.
[0072] The order of these operations may be reversed. For example, steps S10 and S11 may be performed after step S12, and then steps S210 and S211 may be performed. Also, the operations of steps S210 and S211 and the operations of steps S10 and S11 may be performed in parallel with step S12. In either case, steps S210, S211, and steps S10 to S12 only need to be completed before step S20, which will be described later.
[0073] Next, the transmitter / receiver unit 64 of the authentication device 30 transmits the identification information (the serial number 76 of the My Number card M) from the information acquired by the display information acquisition unit 62 to the server 50, and also transmits a request to the server 50 to acquire face data (saved face data) associated with this identification information from the face database 54 (see step S20 in Figure 9).
[0074] As in the first embodiment, when the communication unit 52 of the server 50 receives the identification information and data acquisition request transmitted from the authentication device 30, the control unit 53 of the server 50 searches for a corresponding record in the face database 54 stored in the storage unit 51 using the received identification information (serial number 76) as a key. If a corresponding record is found by this search, the control unit 53 of the server 50 transmits the stored face data in the corresponding record to the authentication device 30 via the communication unit 52. On the other hand, if a corresponding record is not found, the control unit 53 of the server 50 transmits data indicating that the requested stored face data does not exist in the face database 54 to the authentication device 30 via the communication unit 52.
[0075] Next, the transceiver 64 of the authentication device 30 receives a response from the server 50 (see step S21 in FIG. 9 ) and determines whether the response from the server 50 is stored face data (see step S30 in FIG. 9 ). If the response from the server 50 is stored face data, the authentication unit 63 authenticates the Individual Number card M based on (1) the user face data acquired in step S211, (2) the displayed face data acquired in step S11, (3) the recorded face data acquired in step S12, and (4) the stored face data transmitted from the server 50. For example, the authentication unit 63 calculates predetermined feature data for each of the user face data, the displayed face data, the recorded face data, and the stored face data (see step S231 in FIG. 9 ), and determines whether the feature values obtained from each calculated feature data are within a predetermined range, thereby authenticating the Individual Number card M (see step S32 in FIG. 9 ).
[0076] If the authentication unit 63 makes a positive determination in decision step S32, it considers the identification device to be authentic. Next, the control unit 39 of the authentication device 30 transmits information to that effect (information that the identification device is authentic) to the control unit 22 of the vending device 20, and upon receiving the information, the control unit 22 starts the operation of selling the product to the user (see step S40 in FIG. 9). Then, as the vending device 20 finishes selling the product to the user, the selling operation of this embodiment also ends.
[0077] In contrast, if authentication unit 63 makes a negative determination in step S32, it considers the personal identification body to be unauthentic. Next, control unit 39 of authentication device 30 transmits information to that effect (information that the personal identification body is unauthentic) to control unit 22 of vending device 20, and upon receiving the information, control unit 22 ends the sales operation of this embodiment without vending device 20 selling the product to the user.
[0078] On the other hand, if it is determined in step S30 that the response from the server 50 is not stored face data, i.e., if data indicating that the requested stored face data does not exist in the face database 54 of the server 50 is received from the server 50, the transmitter / receiver 64 transmits the displayed face data acquired by the displayed face data acquisition unit 61 to the server 50 to store it in the face database 54 of the server 50 (see step S33 in Figure 9).
[0079] When the communication unit 52 of the server 50 receives the display face data transmitted by the transmission / reception unit 64 in step S33, the control unit 53 of the server 50 stores the received display face data in the face database 54 in association with the received identification information. The stored display face data will be referenced as stored face data in authentication step S231 the next time authentication is performed using the same identification information. Therefore, if, for example, the facial photograph 70 on the exterior of the identification device is tampered with before the next authentication, it becomes difficult for the display face data acquired in step S11 (image data of the tampered facial photograph 70) to match the stored face data received in step S21 (image data of the facial photograph 70 before tampering), making it more likely that a negative determination will be made in decision step S32. Therefore, even if the facial photograph displayed on the identification device has been tampered with, it is possible to prevent a person from being mistakenly authenticated as the person in question. This also applies when the recorded face data stored in the recording medium of the identification device has been tampered with.
[0080] After the displayed face data is transmitted to the server 50 in step S33 and stored in the face database 54 as described above, the authentication unit 63 of the authentication device 230 authenticates the My Number card M based on (1) the user face data acquired in step S211, (2) the displayed face data acquired in step S11, and (3) the recorded face data acquired in step S12. For example, the authentication unit 63 calculates predetermined feature data for each of the user face data, the displayed face data, and the recorded face data (see step S34 in FIG. 9), and authenticates the My Number card M by determining whether the feature values obtained from each calculated feature data are within a predetermined range (see step S35 in FIG. 9).
[0081] If the authentication unit 63 makes a positive determination in step S35, the identification device is deemed to be authentic. Next, the control unit 39 of the authentication device 30 transmits information to that effect to the control unit 22 of the vending device 20, and upon receiving the information, the control unit 22 starts the operation of selling the product to the user (see step S40 in FIG. 9). Then, as the vending device 20 finishes selling the product to the user, the sales operation of this embodiment also ends.
[0082] On the other hand, if the authentication unit 63 makes a negative determination in step S35, it determines that the user is not the owner of the identification device. Next, the control unit 39 of the authentication device 30 transmits information to that effect to the control unit 22 of the vending device 20. Upon receiving the information, the control unit 22 ends the vending operation of this embodiment without selling the product to the user by the vending device 20. As described above, according to this embodiment, authentication is performed using user face data obtained by photographing the face of the user of vending device 20, in addition to displayed face data corresponding to the facial photograph displayed on the identification device, recorded face data recorded corresponding to this facial photograph, and saved face data saved in the server's face database, so it is possible to authenticate whether the owner of the identification device and the user of vending device 20 are the same person.
[0083] In this embodiment, as in the second embodiment, after the authentication unit 63 makes a positive determination in authentication determination step S32, it further determines whether the display basic information acquired by the display information acquisition unit 62 in step S11 matches, in part or in whole, the recorded basic information acquired by the reading unit 36 in step S12, and performs a selling operation (step S40) if it is determined that they match, and may consider the identification object to have been tampered with if it is determined that they do not match. Similarly, after making a positive determination in authentication determination step S35, it may perform an additional authentication determination step, and may perform a selling operation if it is determined that the display basic information and the recorded basic information match, and may consider the identification object to have been tampered with if it is determined that they do not match.
[0084] In each of the above-described embodiments, when the stored face data requested by the authentication device 30 is not present in the face database 54 of the server 50, the displayed face data acquired by the displayed face data acquisition unit 61 is transmitted from the authentication device 30 to the server 50 to be stored in the face database 54 of the server 50 (step S33). However, instead of or in addition to this displayed face data, recorded face data acquired by the reading unit 36 and / or user face data acquired by the user face data acquisition unit 261 in the third embodiment may be transmitted from the authentication device 30 to the server 50 and stored in the face database 54 as stored face data.
[0085] In particular, if user face data obtained by photographing the user of vending device 20 is stored in face database 54 of server 50, the stored face data stored in face database 54 of server 50 will be a recent photograph of the user's face, so if either the face photo displayed on the identification device or the recorded face data recorded corresponding to this face photo is tampered with, it is highly likely that the stored face data will not match the tampered displayed face data or recorded face data. Therefore, if the identification device is tampered with, it is possible to more effectively prevent a person from being mistakenly authenticated as the person in question.
[0086] In addition to the above-mentioned functions, the transmitting / receiving unit 64 may also have a function of transmitting the display basic information acquired in S11 or the record basic information acquired in S12 to the server 50 for storage in the face database 54 of the server 50. The server 50 may receive the display basic information or the record basic information transmitted from the transmitting / receiving unit 64 via the communication unit 52 and store it in the face database 54 in association with the serial number 76 serving as an identification number. If such display basic information or record basic information is stored in the face database 54, the next time authentication is performed using the same identification information, it becomes possible to compare the display basic information or record basic information acquired from the identification device with the display basic information or record basic information stored in the face database 54. Therefore, it becomes possible to detect any tampering of the basic information displayed on the exterior of the identification device or the basic information stored in the recording medium before the next authentication.
[0087] In this embodiment, step S231 or S234 uses (1) the user face data acquired in step S211, (2) the displayed face data acquired in step S11, and (3) the recorded face data acquired in step S12. However, step S231 or S234 may be performed to authenticate the identification body without using either the displayed face data or the recorded face data. For example, step S231 may be performed to authenticate the identification body based on (1) the user face data, (2) the recorded face data, and (3) the saved face data, and step S234 may be performed to authenticate the identification body based on (1) the user face data and (2) the saved face data. In this case, steps S10 and S11 are unnecessary. Alternatively, step S231 may be performed to authenticate the identification body based on (1) the user face data, (2) the displayed face data, and (3) the saved face data, and step S234 may be performed to authenticate the identification body based on (1) the user face data and (2) the displayed face data. In this case, there is no need to obtain the recorded face data in step S12.
[0088] In this embodiment, the user photographing unit 231 may have the function of photographing the face of the user of the vending device 20 at a predetermined frame rate and acquiring multiple images of the photographed face as frame data. That is, the user photographing unit 231 may have the function of photographing the user's face over a predetermined period and acquiring video data, which is a bundle of multiple still images recorded in chronological order. In this case, the user photographing unit 231 may be capable of continuously photographing the subject (the user's face in this example) and acquiring the data. An example of such a user photographing unit 231 is a digital camera or digital video camera capable of acquiring photographed data. However, as long as the above-described function can be performed, the user photographing unit 231 does not have to be a digital camera or digital video camera. The "predetermined frame rate" referred to here may be, for example, a fixed time interval such as 0.05 seconds or 0.1 seconds, or multiple different time intervals. In any case, the user photographing unit 231 may be capable of acquiring at least two or more still images of the user's face during a period of photographing the user, such as 2 seconds.
[0089] When the user photographing unit 231 acquires the user's face as frame data consisting of a plurality of images (for example, N images (N is a positive integer greater than or equal to 1)), the user face data acquisition unit 261 may acquire the user face data from one of the plurality of frame data acquired by the user photographing unit 231. In this case, prior to the authentication judgment step S32 or S35, the control unit 39 initializes the counter using its own counter (not shown). This counter is used to identify the frame data to be judged in the authentication judgment step S32 or S35. In the counter initialization, the first of the plurality of frame data acquired in step S210 (the first image taken among the plurality of images taken during a specified period) is set. If a negative determination is made in step S32 or S35, the counter is incremented by one, the user face data acquisition unit 261 acquires user face data from another frame data among the plurality of frame data acquired by the user photographing unit 231, the authentication unit 63 calculates feature data from this user face data, and the authentication determination step S32 or S35 may be repeated again until the counter reaches a predetermined value. This process can be repeated up to a maximum of N-th frame data to authenticate the personal identification object.
[0090] When the authentication unit 63 performs authentication based on user face data acquired from a single captured image, it is possible that authentication may not be confirmed even when it should be, depending on the state of the face at the time of capture (for example, the state of muscles that change facial expressions, such as the degree of eye opening). As described above, by acquiring frame data consisting of multiple images with the user capture unit 231 and acquiring multiple pieces of user face data from these frame data with the user face data acquisition unit 261, it may be possible to confirm authentication even in cases where authentication would be denied due to the state of the face at the time of capture. In this way, it is possible to perform authentication of the personal identification device with high accuracy and perform more appropriate sales operations.
[0091] In this case, the authentication device 230 may have an imparting unit that has the function of suggesting or stimulating the user to continuously change their facial expression while the user imaging unit 231 is capturing the user's face at a predetermined frame rate. Such an imparting unit may be a speaker that generates sound based on audio data. In this case, the speaker may generate sound to the captured user to suggest, for example, opening and closing one or both eyes or opening and closing the mouth. Furthermore, for example, the imparting unit may display video or text on a display device such as a monitor that suggests continuously changing facial expressions. Furthermore, video or still images displayed on a display device such as a monitor may stimulate the user's five senses to suggest continuously changing facial expressions. Using frame data of multiple facial images capturing such continuously changing facial states allows for more accurate authentication.
[0092] In the above-described embodiments, an example has been described in which the serial number 76 (FIG. 3) of the My Number card is used as the identification information for identifying the My Number card, but the identification information for identifying the My Number card is not limited to the serial number, and for example, part of the information acquired by the display information acquisition unit 62 (for example, a combination of the name 71 and the date of birth 74) may be used as the identification information. Alternatively, a combination of basic information (name, address, sex, and date of birth) that can be acquired by the reading unit 36 from the recording medium of the My Number card M, or a personal number that can be acquired by the reading unit 36 from the recording medium of the My Number card M may be used as the identification information.
[0093] The authentication unit 63 of the authentication device 30 described above extracts feature points from the data of the entire face in each piece of face data, but it may also extract feature points from data of "part" of the face. Extracting feature points from data of "part" of the face in this way shortens the time required to extract feature points compared to the above-described embodiment, thereby shortening the authentication time.
[0094] In this case, when feature points are extracted from the data of a "part" of the face, the authentication unit 63 may extract feature points from the data of a "part" of the face and then perform authentication again after extracting feature points from the data of a "part" of the face and reaching a negative judgment. For example, after the authentication unit 63 performs authentication based on both eyes as a "part" of the face, it may perform re-authentication based on the nose, both eyelashes, bone structure, and other parts of the face other than the eyes as the "other parts" of the face. Furthermore, it may perform re-authentication based on a combination of both eyes and parts other than the eyes as the "other parts" of the face. By performing such re-authentication, more accurate authentication can be performed even when the authentication unit 63 does not make a positive judgment even though the user is the owner. In particular, if a positive judgment is not made in the previous judgment step S31 or step S34, a positive judgment can be made more reliably by considering the part that was the target of the previous judgment step S31 or step S34 (both eyes in the above example) as part of a different face image.
[0095] This re-authentication may be performed multiple times. In this case, the second and subsequent re-authentications may be performed by digitizing the facial image of a portion that is not identical to the "other portion" previously digitized.
[0096] Furthermore, in each of the above-described embodiments, when the verification subject photographing unit 34 photographs the facial photograph 70 of the outer surface of the identification subject, the verification subject photographing unit 34 may photograph multiple facial images by varying the illumination conditions of the illumination light irradiated onto the facial photograph 70, and the displayed facial data acquiring unit 61 may acquire displayed facial data from one of the facial images. If a negative determination is made in step S32 or S35, the displayed facial data acquiring unit 61 may acquire displayed facial data from a facial image photographed under illumination conditions different from those of the facial image used for authentication, and repeat the authentication determination step S32 or S35. In this way, for example, even if the outer surface of the identification subject is darkened due to dirt, and authentication is denied due to a problem with the contrast of the facial image, it may be possible to confirm authentication by performing authentication based on displayed facial data acquired from another facial image photographed under different illumination conditions. In other words, the probability of correct authentication is increased. Examples of illumination conditions of the illumination light include the amount (or light intensity) of the illumination light, its wavelength, or its wavelength distribution.
[0097] In each of the above-described embodiments, for example, the personal identification device (for example, an information communication device such as a smartphone) and the authentication device 30 may be connectable to each other via a network, for example, the Internet, and the personal identification device may be able to communicate with the authentication device 30 via an application. In this case, the authentication unit 63 may be able to perform one-stage or multi-stage personal identification device authentication using an authentication ID (for example, a password) via an application for the personal identification device, and if personal identification device authentication via the application is not successful, may make a negative judgment that the user is not the owner of the personal identification device, without making a positive judgment or a second positive judgment.
[0098] In the above-described embodiments, the sales system 10 or 210 is configured by the sales device 20 and the authentication device 30 or 230. However, as described below, the system can also be constructed by combining a different device with the authentication device 30 or 230 instead of the sales device 20.
[0099] 10 is a schematic diagram showing a passing device 320 that can be used together with the above-described authentication device 30 or 230. Such a passing device 320 and the above-described authentication device 30 or 230 can form a passing system.
[0100] The passing device 320 is communicably connected to the authentication device 30 or 230, and has an opening / closing bar 321 arranged in a communication path (not shown) between one area and another area. When the authentication unit 63 of the authentication device 30 or 230 affirmatively authenticates the personal identification device, the passing device 320 has the function of receiving information indicating the affirmative judgment from the authentication device 30 or 230, and moving the opening / closing bar 321 from a blocking position in the communication path to an opening position to allow the user to pass through.
[0101] With this type of passage system, it is possible to determine whether the user can pass through the connecting passage in a short time after the user starts their action. Furthermore, even if either the facial photograph displayed on the identification device or the recorded facial data recorded corresponding to this facial photograph is tampered with, it becomes difficult for the tampered displayed facial data or recorded facial data to match the un-tampered stored facial data, so there is less chance of the user being mistaken for the person in question and being allowed to pass through.
[0102] In the example shown in Figure 10, the passing device 320 has the function of moving the opening / closing bar 321 from a blocking position to an opening position of the communication passage to allow the user to pass through the communication passage. However, for example, the passing device 320 may be capable of emitting electromagnetic waves such as infrared rays across the communication passage, and if a positive judgment is made, the infrared rays are turned off to allow the user to pass, and if a negative judgment is made, the infrared rays are turned on to alert the user of unauthorized passage by being interrupted by the user's passage. In either case, if a positive judgment is made, the passing device 320 may be allowed to pass, and if a negative judgment is made, the passing device 320 may be prohibited from passing or may alert the user of unauthorized passage. In this case, the alert of unauthorized passage may be made by an alert device (not shown) provided in the passing device 320.
[0103] 11 is a schematic diagram showing an automated teller machine 420 that can be used together with the above-described authentication device 30 or 230. Such an automated teller machine 420 and the above-described authentication device 30 or 230 can form an automated teller system.
[0104] The automated teller machine 420 is communicably connected to the authentication device 30 or 230, and when the authentication unit 63 of the authentication device 30 or 230 affirmatively authenticates the personal identification body, it receives information from the authentication device 30 or 230 indicating that a positive judgment has been made, and has the function of enabling the user to perform automated teller operations using, for example, the monitor 421 as a user interface.
[0105] According to such an automated teller system, it is possible to determine whether the user is permitted to perform an automated teller operation in a short time after the user starts the operation. Furthermore, even if either the facial photograph displayed on the identification device or the recorded facial data recorded corresponding to this facial photograph is tampered with, it becomes difficult for the tampered displayed facial data or recorded facial data to match the untampered stored facial data, so that the automated teller operation is less likely to be permitted because the user is mistaken for the person in question.
[0106] Although the embodiments have been described herein as being different from one another, it is possible to combine some components of one embodiment with components of another embodiment.
[0107] As described above, according to the first aspect of the present invention, there is provided an authentication device that can prevent erroneous authentication of an identification device even if the facial photograph displayed on the identification device or its recorded facial data is tampered with. Specifically, the authentication device according to the present invention can employ the following configuration.
[0108] (Configuration 1) The authentication device is used to authenticate an identity verification body including a facial photograph displayed on an exterior surface and recorded facial data recorded in a memory unit in correspondence with the facial photograph. the authentication device comprises: a first image acquisition unit that acquires an image of at least a part of the outer surface of the identification body; a displayed face data acquisition unit that acquires displayed face data corresponding to the facial photograph from the image acquired by the first image acquisition unit; an identification information acquisition unit that acquires identification information for identifying the identification body from the image acquired by the first image acquisition unit or from the memory unit of the identification body; a recorded face data acquisition unit that acquires the recorded face data from the memory unit of the identification body; a transceiver unit that transmits the identification information acquired by the identification information acquisition unit to a server having a face database to request stored face data associated with the identification information, and receives from the server in response to the request the stored face data stored in the face database or data indicating that the requested stored face data does not exist in the face database; and an authentication unit that authenticates the identification body based at least on the displayed face data acquired by the displayed face data acquisition unit, the recorded face data acquired by the recorded face data acquisition unit, and the response from the server received by the transceiver unit.
[0109] According to this configuration, authentication is performed using not only displayed face data corresponding to the facial photograph displayed on the identification device and recorded face data recorded corresponding to this facial photograph, but also stored face data associated with identification information for identifying the identification device and stored in the face database of the server. Therefore, even if either the facial photograph displayed on the identification device or the recorded face data recorded corresponding to this facial photograph is tampered with, the tampered displayed face data or recorded face data is unlikely to match the untampered stored face data, making it less likely that the person will be mistakenly authenticated as the person in question.
[0110] (Configuration 2) In the above configuration 1, when the transmitting / receiving unit receives the stored face data stored in the face database from the server, the authentication unit can be configured to authenticate the identity verification object based on (1) the displayed face data acquired by the displayed face data acquisition unit, (2) the recorded face data acquired by the recorded face data acquisition unit, and (3) the stored face data received by the transmitting / receiving unit, and when the transmitting / receiving unit receives data from the server indicating that the requested stored face data does not exist in the face database, authenticate the identity verification object based on (1) the displayed face data acquired by the displayed face data acquisition unit and (2) the recorded face data acquired by the recorded face data acquisition unit.
[0111] (Configuration 3) In the above configuration 1 or 2, the transmitting / receiving unit may be configured to further transmit at least one of the displayed face data acquired by the displayed face data acquiring unit and the recorded face data acquired by the recorded face data acquiring unit to the server for storage in the face database.
[0112] (Configuration 4) In the above configuration 1 or 2, when the transmitting / receiving unit receives data from the server indicating that the requested saved face data does not exist in the face database, the transmitting / receiving unit may be configured to further transmit at least one of the displayed face data acquired by the displayed face data acquisition unit and the recorded face data acquired by the recorded face data acquisition unit to the server to be stored in the face database.
[0113] (Configuration 5) In any of the above configurations 1 to 4, the identification object may further include display basic information displayed on the exterior as basic information about the owner of the identification object, and recorded basic information recorded in the memory unit as the basic information. The authentication device may further include a display basic information acquisition unit that acquires the display basic information from the image acquired by the first image acquisition unit, and a recorded basic information acquisition unit that acquires the recorded basic information from the memory unit of the identification object. The authentication unit may be configured to deny authentication of the identification object when the authentication of the identification object is affirmative and the display basic information acquired by the display basic information acquisition unit and the recorded basic information acquired by the recorded basic information acquisition unit do not match in part or in whole. This configuration makes it possible to detect tampering with the identification object, which cannot be detected by authentication using a facial image.
[0114] (Configuration 6) In any one of the above configurations 1 to 5, the transmitting / receiving unit may be further configured to transmit the display basic information or the recording basic information to the server for storage in the face database.
[0115] (Configuration 7) In any of the above configurations 1 to 6, the authentication device may further include a second image acquisition unit that acquires an image of a user, and a user face data acquisition unit that acquires user face data of the user's face from the image acquired by the second image acquisition unit. The authentication unit may be configured to authenticate the identification object based on the user face data acquired by the user face data acquisition unit in addition to the displayed face data, the recorded face data, and the response from the server.
[0116] According to this configuration, authentication is performed using user face data obtained by photographing the user's face in addition to displayed face data corresponding to the facial photograph displayed on the identification device, recorded face data recorded corresponding to this facial photograph, and saved face data saved in the server's face database, so it is possible to authenticate whether the owner of the identification device and the user are the same person.
[0117] (Configuration 8) In the above configuration 7, when the transmitting / receiving unit receives the stored face data stored in the face database from the server, the authentication unit can be configured to authenticate the identity verification object based on (1) the user face data acquired by the user face data acquisition unit, (2) the displayed face data acquired by the displayed face data acquisition unit, (3) the recorded face data acquired by the recorded face data acquisition unit, and (4) the stored face data received by the transmitting / receiving unit, and when the transmitting / receiving unit receives data from the server indicating that the requested stored face data does not exist in the face database, authenticate the identity verification object based on (1) the user face data acquired by the user face data acquisition unit, (2) the displayed face data acquired by the displayed face data acquisition unit, and (3) the recorded face data acquired by the recorded face data acquisition unit.
[0118] (Configuration 9) In the above configurations 7 and 8, the transceiver may be further configured to transmit the user face data acquired by the user face data acquisition unit to the server for storage in the face database. By storing the user face data, which is a photograph of the user's face, in the server's face database, the stored face data stored in the server's face database will be a recent photograph of the user's face. Therefore, even if either the facial photograph displayed on the identification device or the recorded face data recorded corresponding to this facial photograph is tampered with, the stored face data is unlikely to match the tampered displayed face data or recorded face data. Therefore, it is possible to more effectively prevent a person from being mistakenly identified as the person in question when the identification device has been tampered with.
[0119] (Configuration 10) According to a second aspect of the present invention, there is provided a sales system including the authentication device of any one of configurations 1 to 9 above, and a sales device communicatively connected to the authentication device and configured to sell merchandise. The sales device is configured to, when the authentication unit of the authentication device affirms the authentication of the personal identification body, receive information indicating this affirmation from the authentication device, thereby enabling the sale of the merchandise.
[0120] (Configuration 11) According to a third aspect of the present invention, there is provided a passing system comprising: an authentication device according to any one of configurations 1 to 9; and a passing device communicatively connected to the authentication device, for permitting a user to pass through a communication passage between one area and another area or for monitoring the user's passage. The passing device is configured such that, when the authentication unit of the authentication device affirms the authentication of the personal identification body, the passing device receives information indicating this from the authentication device and permits the user to pass through the communication passage; and, when the authentication unit denies the authentication of the personal identification body, the passing device disables the user from passing through the communication passage or issues an alert.
[0121] (Configuration 12) According to a fourth aspect of the present invention, there is provided an automated teller system comprising: an authentication device according to any one of configurations 1 to 9 above; and an automated teller machine communicably connected to the authentication device. The automated teller machine is configured so that, when the authentication unit of the authentication device affirms the authentication of the personal identification body, it receives information indicating this from the authentication device, and enables a user to perform an automated teller operation.
[0122] Although the preferred embodiments of the present invention have been described above, it goes without saying that the present invention is not limited to the above-described embodiments and may be embodied in various different forms within the scope of the technical concept thereof. [Explanation of symbols]
[0123] 10,210 Sales System 20 Vending Machine 22 Control Unit 24 Product Display 26 Product removal port 30,230 Authentication Device 34 Confirmation Body Photography Department 35 Storage section 36 Reading unit 37,38 Communications Department 39 Control Unit 40 Network 50 servers 51 Storage section 52 Communications Department 53 Control Unit 54 Face Database 61 Display face data acquisition unit 62 Display information acquisition unit 63 Authentication Section 64 Transmitter / Receiver 70 Photo 231 User Photography Department 261 User face data acquisition unit 320 Passage device 321 Opening and Closing Bar 420 Cleaning device 421 Monitor M My Number Card (identification document) P Program S Sample
Claims
1. An authentication device for authenticating an identity verification object including recorded face data recorded in a storage unit, an identification information acquisition unit that acquires identification information for identifying the personal identification object from an image of at least a part of the outer surface of the personal identification object or from the storage unit of the personal identification object; a recorded face data acquisition unit that acquires the recorded face data from the storage unit of the personal identification device; an image acquisition unit that acquires an image of a user; a user face data acquisition unit that acquires user face data obtained by capturing a face of the user from the image acquired by the image acquisition unit; a transceiver that transmits the identification information acquired by the identification information acquisition unit to a server having a face database to request stored face data associated with the identification information, and receives from the server in response to the request the stored face data stored in the face database or data indicating that the requested stored face data does not exist in the face database; an authentication unit that authenticates the personal identification body based on at least the user face data acquired by the user face data acquisition unit, the recorded face data acquired by the recorded face data acquisition unit, and the response from the server received by the transmitting / receiving unit; An authentication device comprising:
2. The authentication unit When the transmitting / receiving unit receives the stored face data stored in the face database from the server, the transmitting / receiving unit authenticates the identity verification body based on (1) the user face data acquired by the user face data acquisition unit, (2) the recorded face data acquired by the recorded face data acquisition unit, and (3) the stored face data received by the transmitting / receiving unit; When the transmitting / receiving unit receives data from the server indicating that the requested stored face data does not exist in the face database, the transmitting / receiving unit authenticates the personal identification body based on (1) the user face data acquired by the user face data acquisition unit and (2) the recorded face data acquired by the recorded face data acquisition unit. It is configured as follows: The authentication device according to claim 1 .
3. 2. The authentication device according to claim 1, wherein the transmitting / receiving unit is further configured to transmit at least one of the user face data acquired by the user face data acquisition unit and the recorded face data acquired by the recorded face data acquisition unit to the server for storage in the face database.
4. 2. The authentication device according to claim 1, wherein the transmitting / receiving unit is configured, when receiving data from the server indicating that the requested stored face data does not exist in the face database, to further transmit at least one of the user face data acquired by the user face data acquisition unit and the recorded face data acquired by the recorded face data acquisition unit to the server for storage in the face database.
5. An authentication device for authenticating an identification body including a facial photograph displayed on an exterior thereof, a first image acquisition unit that acquires an image of at least a portion of the outer surface of the identification device; a display face data acquisition unit that acquires display face data corresponding to the facial photograph from the image acquired by the first image acquisition unit; an identification information acquisition unit that acquires identification information for identifying the identification object from the image acquired by the first image acquisition unit or from a storage unit of the identification object; a second image acquisition unit that acquires an image of the user; a user face data acquisition unit that acquires user face data obtained by capturing a face of the user from the image acquired by the second image acquisition unit; a transceiver that transmits the identification information acquired by the identification information acquisition unit to a server having a face database to request stored face data associated with the identification information, and receives from the server in response to the request the stored face data stored in the face database or data indicating that the requested stored face data does not exist in the face database; an authentication unit that authenticates the personal identification body based on at least the user face data acquired by the user face data acquisition unit, the display face data acquired by the display face data acquisition unit, and the response from the server received by the transmission / reception unit; An authentication device comprising:
6. The authentication unit When the transmitting / receiving unit receives the stored face data stored in the face database from the server, the transmitting / receiving unit authenticates the personal identification body based on (1) the user face data acquired by the user face data acquisition unit, (2) the display face data acquired by the display face data acquisition unit, and (3) the stored face data received by the transmitting / receiving unit; When the transmitting / receiving unit receives data from the server indicating that the requested stored face data does not exist in the face database, the transmitting / receiving unit authenticates the personal identification body based on (1) the user face data acquired by the user face data acquisition unit and (2) the displayed face data acquired by the displayed face data acquisition unit. It is configured as follows: The authentication device according to claim 5 .
7. 6. The authentication device according to claim 5, wherein the transceiver is further configured to transmit at least one of the user face data acquired by the user face data acquisition unit and the display face data acquired by the display face data acquisition unit to the server for storage in the face database.
8. 6. The authentication device according to claim 5, wherein the transceiver is configured, when receiving data from the server indicating that the requested stored face data does not exist in the face database, to further transmit at least one of the user face data acquired by the user face data acquisition unit and the displayed face data acquired by the displayed face data acquisition unit to the server for storage in the face database.
9. The identity verification body is basic information to be displayed on the outer surface as basic information about the owner of the personal identification device; Recorded basic information to be recorded in the storage unit as the basic information; further comprising a display basic information acquisition unit that acquires the display basic information from an image of at least a part of the outer surface of the personal identification device; a recording basic information acquisition unit that acquires the recording basic information from the storage unit of the personal identification body; Furthermore, the authentication unit is configured to deny the authentication of the personal identification body when the authentication of the personal identification body is affirmed and the display basic information acquired by the display basic information acquisition unit and the record basic information acquired by the record basic information acquisition unit do not match in part or in whole. The authentication device according to any one of claims 1 to 8.
10. The authentication device according to claim 9 , wherein the transceiver is further configured to transmit the display basic information or the record basic information to the server for storage in the face database.
11. An authentication device according to any one of claims 1 to 8; a sales device communicably connected to the authentication device and configured to sell merchandise; Equipped with the vending device is configured to, when the authentication unit of the authentication device affirms the authentication of the personal identification body, receive information indicating the affirmation from the authentication device, and enable the sale of the product. Sales system.
12. An authentication device according to any one of claims 1 to 8; a passage device that is communicably connected to the authentication device and that permits a user to pass through a communication passage between one area and another area or monitors the user's passage; Equipped with The passing device is configured such that, when the authentication unit of the authentication device affirms the authentication of the personal identification body, the passing device receives information indicating this affirmation from the authentication device and permits the user to pass through the communication passage, and when the authentication unit denies the authentication of the personal identification body, the passing device prohibits the user from passing through the communication passage or notifies the user. Passing system.
13. An authentication device according to any one of claims 1 to 8; an automated teller machine communicably connected to the authentication device; Equipped with the automated teller machine is configured to, when the authentication unit of the authentication device affirms the authentication of the personal identification body, receive information indicating the affirmation from the authentication device and allow the user to perform an automated teller operation. Automated teller system.
Citation Information
Patent Citations
IC card and IC card authentication system
JP2005141626A
Method for manufacturing, issuing and examining booklet with IC, and the booklet
JP2005199533A
Entrance management system and entrance management method
JP2007249819A
Personal authentication device and program
JP6513866B1
JPP6513866B