Personal authentication device, personal authentication method, and program
The personal authentication device simplifies the authentication process by using user behavior information and interactive methods to facilitate easy recall and input of authentication details, improving security and efficiency.
Patent Information
- Application Number
- JP2022049323
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-25
- Publication Date
- 2025-09-03
- Estimated Expiration
- 2042-03-25
AI Technical Summary
Existing personal authentication methods often require users to remember complex authentication images, making it difficult for them to perform authentication accurately.
A personal authentication device that acquires related information about user behavior, outputs this information to the user, and allows them to select or input specific information for authentication, using guidance and benefits to facilitate easy recall of authentication details.
Enables secure and efficient personal authentication by allowing users to easily remember and input authentication information, enhancing the authentication process with user-friendly interaction and motivation through benefits.
Smart Images

Figure 0007733600000001 
Figure 0007733600000002 
Figure 0007733600000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an authentication device, an authentication method, and a program for authenticating that a user who uses the device is the user who has been registered in advance. [Background technology]
[0002] For example, there is known a configuration of an identity authentication system that acquires credit card usage information of the person to be authenticated and, based on the credit card usage information, extracts a combination of authentication images from images of the store where the credit card was used (see, for example, Patent Document 1 below). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 6021264 Summary of the Invention [Problem to be solved by the invention]
[0004] For example, when performing personal authentication as described in Patent Document 1, it may be difficult for the person to be authenticated to remember the authentication image used for personal authentication.
[0005] An object of the present invention is to provide an authentication device, an authentication method, and a program that can perform authentication using authentication information that can be easily remembered by a person to be authenticated. [Means for solving the problem]
[0006] The personal authentication device of the first invention is an personal authentication device comprising: a related information acquisition unit that acquires related information related to the behavior of the person to be authenticated; a specific information acquisition unit that acquires specific information input by the person to be authenticated that identifies one or more pieces of related information; an authentication information storage unit that stores the related information identified by the specific information as authentication information corresponding to the person to be authenticated; an input information acceptance unit that accepts authentication input information input by the user; and an personal authentication unit that authenticates that the user is the person to be authenticated corresponding to the authentication information based on the correspondence between the authentication input information and the authentication information stored in the authentication information storage unit.
[0007] With this configuration, personal authentication can be performed using authentication information that the person to be authenticated can easily remember.
[0008] In addition, the personal authentication device of the second invention is an authentication device that, compared to the first invention, is equipped with a related information output unit that outputs related information acquired by the related information acquisition unit to the person to be authenticated when a predetermined output condition is satisfied, and the specific information acquisition unit acquires specific information input in response to the output of the related information by the related information output unit.
[0009] With this configuration, the person to be authenticated can easily specify the authentication information to be used for personal authentication.
[0010] In addition, the personal authentication device of the third invention is an authentication device in which, compared to the second invention, the related information output unit outputs a selection screen displaying two or more pieces of related information to the person to be authenticated, and the specific information output unit acquires the specific information based on a selection operation on the selection screen.
[0011] With this configuration, the person to be authenticated can easily specify the authentication information to be used for personal authentication.
[0012] In addition, the personal authentication device of the fourth invention is an personal authentication device in which, compared to the second or third invention, the related information output unit acquires related information to be recommended to the person to be authenticated from the related information acquired by the related information acquisition unit, and outputs the related information to the person to be authenticated.
[0013] With this configuration, the person to be authenticated can easily specify the authentication information to be used for personal authentication.
[0014] In addition, the personal authentication device of the fifth invention is an personal authentication device in which, compared to the fourth invention, the related information output unit acquires historical information regarding the behavioral history of the person to be authenticated, and acquires related information to be recommended to the person to be authenticated based on the historical information.
[0015] With this configuration, it is possible to propose authentication information that is likely to be easily remembered by the person to be authenticated.
[0016] Furthermore, the personal authentication device of the sixth invention is the personal authentication device of any one of the second to fifth inventions, wherein the output conditions include that personal authentication of the person to be authenticated has been performed.
[0017] With this configuration, it is possible to output relevant information to the person to be authenticated after his / her identity has been authenticated.
[0018] Furthermore, the seventh invention is an identity authentication device in which, compared to any of the second to sixth inventions, the output condition includes the person being authenticated having performed a specified action, and the related information output unit outputs to the person being authenticated guidance information used to input specific information that identifies related information related to the action of the person being authenticated.
[0019] With this configuration, the person to be authenticated can easily specify the authentication information related to the behavior based on the guide information.
[0020] In addition, the eighth invention is an identity authentication device in which, compared to the seventh invention, the related information output unit outputs benefit information regarding the granting of benefits to the person to be authenticated when outputting guidance information.
[0021] With this configuration, it is possible to effectively motivate the person to be authenticated to input specific information.
[0022] In addition, the personal authentication device of the ninth invention is an personal authentication device that, compared to the seventh or eighth invention, performs a process of granting a benefit to the person to be authenticated when the specific information acquisition unit acquires specific information input using guidance information.
[0023] With this configuration, it is possible to effectively motivate the person to be authenticated to input specific information.
[0024] Furthermore, the personal authentication device of the tenth invention is an personal authentication device configured in accordance with any one of the first to ninth inventions, in which the specific information acquisition unit acquires specific information input by the person to be authenticated for each behavioral scene of the person to be authenticated, the authentication information storage unit stores authentication information in correspondence with information identifying the behavioral scene, and the personal authentication unit performs personal authentication based on the authentication information corresponding to an identifier identifying the behavioral scene for which personal authentication is performed.
[0025] With this configuration, it is possible to perform personal authentication more securely using authentication information that the person to be authenticated can more easily remember. [Effects of the Invention]
[0026] According to the present invention, it is possible to provide an authentication device, an authentication method, and a program that can perform authentication using authentication information that the person to be authenticated can easily remember. [Brief explanation of the drawings]
[0027] [Figure 1] FIG. 1 is a diagram showing a schematic configuration of an information processing system according to an embodiment of the present invention. [Figure 2] Block diagram of the personal authentication device [Figure 3] FIG. 10 is a diagram showing a first example of user information stored in a user information storage unit in the personal authentication device. [Figure 4] FIG. 10 is a diagram showing a second example of user information stored in the user information storage unit of the personal authentication device. [Figure 5] FIG. 10 is a diagram showing a first example of authentication information stored in an authentication information storage unit in the personal authentication device. [Figure 6] FIG. 10 is a diagram showing a second example of authentication information stored in the authentication information storage unit in the personal authentication device. [Figure 7] A flowchart showing an example of the operation of the personal authentication device [Figure 8] A flowchart showing an example of related information output processing of the personal authentication device [Figure 9] A flowchart showing an example of personal authentication processing by the personal authentication device. [Figure 10] FIG. 10 is a diagram illustrating a specific example of a payment completion screen displayed on the terminal device. [Figure 11] FIG. 10 is a diagram illustrating a specific example of a selection screen displayed on the terminal device. [Figure 12] FIG. 10 is a diagram illustrating a specific example of an authentication screen displayed on the terminal device. [Figure 13] FIG. 10 is a diagram illustrating a specific example of an authentication completion screen displayed on the terminal device. [Figure 14] Overview of the computer system in the above embodiment [Figure 15] Block diagram of the computer system DETAILED DESCRIPTION OF THE INVENTION
[0028] Hereinafter, embodiments of an identity authentication device and the like will be described with reference to the drawings. Note that components with the same reference numerals in the embodiments perform similar operations, and therefore repeated description may be omitted.
[0029] The terms used below are generally defined as follows: The meanings of these terms should not always be interpreted as shown here, but rather, when they are individually explained below, they should be interpreted in light of that explanation.
[0030] A user is a person who uses an authentication device. A person to be authenticated who is authenticated by the authentication device is said to be the user of the authentication device. A user who can be authenticated as the person in the authentication by the authentication device is said to be the person to be authenticated. It can also be said that the authentication device is capable of determining whether a user is the person to be authenticated.
[0031] A reward is a benefit given to a user on a given occasion, such as a coupon code that can be exchanged for goods, money, merchandise or other items, points with monetary value, or other economic benefits.
[0032] An identifier for a certain item is a character or code that uniquely identifies that item. An identifier could be, for example, an ID, but any type of information can be used as long as it can identify the corresponding item. In other words, an identifier could be the name of the thing it represents, or a combination of codes that uniquely identify the thing.
[0033] Acquisition may include acquiring information entered by a user or the like, or acquiring information stored in one's own device or another device (which may be pre-stored information or information generated by information processing performed on the device). Acquiring information stored in another device may include acquiring information stored in another device via an API or the like, or acquiring the contents of a document file (including the contents of a web page) provided by another device. It may also include acquiring information in a format different from the original information, such as acquiring information by performing optical character reading on an image. It may also include reading an image of a one-dimensional code, multi-dimensional code, or the like to acquire information represented by the code.
[0034] Furthermore, a so-called machine learning technique may be used to acquire information. The machine learning technique can be used, for example, as follows: That is, a learning device (learning information) that receives a specific type of input information as an input and outputs a desired type of output information is configured using the machine learning technique. For example, two or more pairs of input information and output information are prepared in advance, and the two or more pairs of information are provided to a module for configuring a machine learning learning device to configure the learning device, and the configured learning device is stored in a storage unit. The learning device can also be called a classifier. Note that any machine learning technique may be used, such as deep learning, random forest, SVR, etc. Furthermore, functions in various machine learning frameworks, such as fastText, tinySVM, random forest, and TensorFlow, and various existing libraries can be used for machine learning.
[0035] Furthermore, the learning device is not limited to one obtained by machine learning. The learning device may be, for example, a table showing the correspondence between input vectors based on input information and output information. In this case, output information corresponding to a feature vector based on the input information may be obtained from the table, or two or more input vectors in the table and parameters for weighting each input vector may be used to generate a vector approximating the feature vector based on the input information, and the final output information may be obtained using the output information and parameters corresponding to each input vector used for generation. Furthermore, the learning device may be, for example, a function expressing the relationship between an input vector based on input information and information for generating output information. In this case, for example, information corresponding to a feature vector based on the input information may be obtained using a function, and the obtained information may be used to obtain output information.
[0036] Outputting information is a concept that includes displaying on a display, projecting using a projector, printing on a printer, outputting sound, transmitting to an external device, storing on a recording medium, transferring the processing results to another processing device or another program, etc. Specifically, it includes, for example, making it possible to display information on a web page, transmitting as e-mail, etc., and outputting information for printing.
[0037] The concept of accepting information includes accepting information entered from input devices such as a keyboard, mouse, or touch panel, receiving information transmitted from other devices via wired or wireless communication lines, and accepting information read from recording media such as optical disks, magnetic disks, and semiconductor memories.
[0038] With regard to various types of information stored in personal authentication devices, etc., the concept of "updating" includes not only changing the stored information, but also adding new information to the stored information, and deleting part or all of the stored information.
[0039] (Embodiment)
[0040] In this embodiment, the authentication device acquires related information relating to the behavior of the person to be authenticated and specific information by the person to be authenticated that identifies one or more pieces of related information, and sets the related information identified by the specific information as authentication information corresponding to the person to be authenticated. Based on the correspondence between the authentication input information input by the user and the authentication information, the authentication device authenticates that the user is the person to be authenticated that corresponds to the authentication information.
[0041] For example, the personal authentication device may be configured to output the acquired related information to the person to be authenticated when a predetermined output condition is satisfied, and acquire specific information input corresponding to the output information. The personal authentication device may be configured to output a selection screen displaying two or more pieces of related information, and acquire specific information based on a selection operation on the selection screen. The personal authentication device may be configured to output suggested content of related information to be used as authentication information, or to acquire historical information regarding the behavioral history of the person to be authenticated and determine the suggested related information based on the historical information. The output condition may include that the person to be authenticated has been authenticated. The personal authentication device may also be configured to output guidance information to the person to be authenticated, at a timing corresponding to the behavior of the person to be authenticated, which is used to input specific information identifying related information related to the behavior. The personal authentication device may output information regarding the granting of a benefit together with the guidance information, or may perform a process of granting a benefit to the person to be authenticated when specific information input using the guidance information is acquired. The personal authentication device may be configured to acquire specific information input for each behavioral scene of the person to be authenticated, and use authentication information corresponding to the behavioral scene of the personal authentication.
[0042] An information processing system using the personal authentication device configured as above will be described below.
[0043] FIG. 1 is a diagram showing a schematic configuration of an information processing system 1 according to the present embodiment.
[0044] The information processing system 1 includes an authentication device 100 and a terminal device 600. In this embodiment, the information processing system 1 is used together with an external device 700. The information processing system 1 functions as an authentication infrastructure that performs authentication of a person to be authenticated who uses the terminal device 600, using the authentication device 100. In the information processing system 1, the external device 700 or the like can perform various processes on the person to be authenticated using the result of the authentication. Note that the external device 700 may or may not be interpreted as being included in the information processing system 1. In short, the authentication device 100 may be configured to be able to authenticate whether a user accessing the information processing system 1 using the terminal device 600 or the like is a person to be authenticated who has been registered in advance. The functions performed by the external device 700 may be performed by the authentication device 100.
[0045] In this embodiment, the information processing system 1 realizes, for example, a payment system. For example, the external device 700 is a device used in a point-of-sale information management system at an e-commerce website or a store, and the personal authentication device 100 is configured to be able to authenticate that a user of a credit card or code payment method at such a website or store is a registered individual. However, the uses of the information processing system and the personal authentication device 100 are not limited to this. For example, the external device 700 may be used as an authentication infrastructure that authenticates that a user is the owner of a predetermined account in the external device 700 that provides various web services.
[0046] In the information processing system 1, the personal authentication device 100 can communicate with external devices such as the terminal device 600 and the external device 700 via a network such as the Internet. Note that the network is not limited to this and may be a LAN or other communication network. Furthermore, the connection mode and communication method between the personal authentication device 100 and the terminal device 600, and the connection mode and communication method between the personal authentication device 100 and the external device 700, etc. are not limited to this. For example, the network through which the personal authentication device 100 and the terminal device 600 communicate may be different from the network through which the personal authentication device 100 and the external device 700 communicate.
[0047] In this embodiment, the terminal device 600 is a device used by a user to perform identity authentication by the identity authentication device 100. Note that the configuration may also be such that the user performs identity authentication using a device (for example, a display) included in or connected to the identity authentication device 100, without using the terminal device 600.
[0048] The electronic computer used in the terminal device 600 may be a personal computer, a portable information terminal device such as a smartphone, a tablet-type information terminal device, or any other suitable device. In the following examples, the electronic computer used in the terminal device 600 may be a portable information terminal device such as a smartphone, but is not limited to this. The terminal device 600 may be, for example, a device constituting a point-of-sale information management system used in a store.
[0049] The terminal device 600 has a display unit 661, which is, for example, a touch panel. The terminal device 600 is configured to be able to display various information on the display unit 661 and to accept operations by a user. The terminal device 600 is configured to be able to transmit information to the personal authentication device 100 in response to, for example, a user operation or the operation of predetermined software or the like.
[0050] FIG. 2 is a block diagram of the personal authentication device 100. As shown in FIG.
[0051] As shown in FIG. 2, the personal authentication device 100 includes a storage unit 110, a receiving unit 120, an accepting unit 130, a processing unit 140, and a transmitting unit 170. The personal authentication device 100 is, for example, a server device. The personal authentication device 100 may be configured by a single server, or may be configured by multiple servers operating in cooperation with each other, or may be a computer or the like built into other equipment. The server may be a so-called cloud server, an ASP server, or the like, and its type does not matter. A user of the personal authentication device 100 can use the personal authentication device 100 by communicating with the personal authentication device 100 using a terminal device 600. The user may use the personal authentication device 100 by directly operating the device.
[0052] The storage unit 110 includes a user information storage unit 115 and an authentication information storage unit 117. A non-volatile recording medium is preferable for the storage unit 110, but a volatile recording medium can also be used. For example, information received by the reception unit 130 and information acquired by the processing unit 140 are stored in each unit of the storage unit 110. However, the information stored in each unit of the storage unit 110 and the process by which the information is stored are not limited to this. For example, information may be stored in the storage unit 110 via a recording medium, information transmitted via a communication line may be stored in the storage unit 110, or information input via an input device may be stored in the storage unit 110.
[0053] User information is stored in the user information storage unit 115. The user information is information relating to a person to be authenticated who can be authenticated as the person by the personal authentication device 100. The user information may also be called authentication-subject information.
[0054] In this embodiment, the user information is information in which a user identifier (authentication subject identifier), which is an identifier for identifying a user using the authentication device 100, i.e., an authentication subject, is associated with information about the user. The user information may include various types of information. For example, it may include information transmitted from the terminal device 600 used by the user and information about the user acquired by the authentication device 100 as described below. The information transmitted from the terminal device 600 used by the user may include, for example, basic information about the user, as well as specific information as described below. The basic information may include, for example, the user's name, date of birth, gender, address, contact information, user questionnaire responses, and information generated based on the responses. Furthermore, the information about the user acquired by the authentication device 100 may include, for example, related information as described below. The user information storage unit 115 may store user information transmitted from other devices, etc. The user information may be updated using, for example, information transmitted from the user or information acquired by the processing unit 140.
[0055] In this embodiment, the user information includes related information related to the behavior of the person to be authenticated. The related information is, for example, acquired by the related information acquisition unit 141 described below, associated with a user identifier, and stored in the user information storage unit 115. The related information is, for example, information that can be used as authentication information described below. Specifically, the related information may include, for example, the names of stores that the person to be authenticated has used in the past (which may also be information such as the name of a facility or the other party to a payment), the names of products purchased, the amount paid, the date and time or time period when a predetermined behavior occurred, etc. Furthermore, the related information may also include, for example, images of stores or products related to the person to be authenticated. The related information is not limited to these, and may include information related to various behaviors of the person to be authenticated. For example, the related information may include information related to the amount of activity or health of the person to be authenticated, which is acquired by a wearable device or the like worn by the person to be authenticated. The related information may also be a related information identifier that identifies such information.
[0056] Furthermore, in this embodiment, scene information on scenes related to the relationship information may be stored in association with the relationship information. The scene information is, for example, an identifier that identifies a behavioral scene corresponding to the relationship information. The scene information is, for example, information indicating the chain of stores from which the relationship information was obtained. For example, when the relationship information is a store name, the scene information may be information indicating the location (area) of the store or information indicating the store category (for example, but not limited to, a supermarket, a convenience store, a bookstore, etc.). Note that the scene information is not limited to this, and may be, for example, information regarding the time period of the behavior of the authenticated person corresponding to the relationship information, information regarding the weather, information regarding the behavioral scene, information regarding the season, etc. The behavioral scene may be, for example, but not limited to, whether the person is on the move or not, whether the person is indoors or outdoors, etc.
[0057] FIG. 3 is a diagram showing a first example of user information stored in the user information storage unit 115 in the personal authentication device 100. As shown in FIG.
[0058] In the figure, for the sake of explanation, the user information is divided into information indicating the user's attribute values, etc., and related information recorded in association with the user, but the data management method is not limited to this. In the first example, as user information, for example, each attribute value such as the user's name, date of birth, and contact information is recorded in association with a user identifier. Also, as described below, each attribute value such as the related information acquired by the related information acquisition unit 141, a related information identifier that identifies the related information, and situation information associated with the related information is recorded in association with the user identifier of the user corresponding to the related information. Note that with regard to the related information, the date and time when the related information was acquired, the date and time of the authenticatee's behavior related to the related information, the type of related information, etc. may also be recorded.
[0059] As shown in the figure, in the first example, an image showing the exterior of a store is used as the relationship information. The user information includes, for example, a code indicating the location where the image is stored, but the image data itself may also be recorded. In addition, in this embodiment, for example, information indicating the store chain from which the relationship information was obtained or the store category is used as the scene information. For example, with respect to the relationship information of each store in the "ABC Supermarket" chain, "ABC Supermarket" is associated as the scene information. Furthermore, with respect to the relationship information of each store in the "DRT Convenience Store" chain, "DRT Convenience Store" is associated as the scene information. With respect to the relationship information of a store that is not a predetermined chain store, for example, a category previously set as corresponding to the store (e.g., "pharmacy") is used as the scene information, or other category such as "other stores" is used as the scene information.
[0060] FIG. 4 is a diagram showing a second example of the user information stored in the user information storage unit 115 in the personal authentication device 100. As shown in FIG.
[0061] In the second example shown in the figure, relationship information recorded in association with a user is shown. In the second example, the attribute values of the relationship information acquired by the relationship information acquisition unit 141 as described below and the acquisition date and time of the relationship information are recorded in association with the user identifier of the user corresponding to the related information. In the second example, the name of the store where the user has done shopping, etc. is used as the relationship information. Furthermore, in the second example, situation information is not used. The relationship information may be stored, for example, as in this second example.
[0062] Returning to FIG. 2, the authentication information storage unit 117 stores related information identified by identification information (described later) as authentication information corresponding to the person to be authenticated. In this embodiment, for example, a related information identifier of the related information used as authentication information is stored in association with a user identifier that identifies the person to be authenticated. Also, in this embodiment, the authentication information storage unit 117 may store each piece of authentication information in association with scene information that identifies a behavior scene. That is, scene information related to a scene in which the authentication information is used may be stored in association with information that identifies the authentication information. Note that the authentication information may be used or stored as authentication information obtained by converting related information into a meaningless string by using a hash function or the like, as appropriate.
[0063] FIG. 5 is a diagram showing a first example of authentication information stored in the authentication information storage unit 117 in the personal authentication device 100. As shown in FIG.
[0064] The first example shown in the figure corresponds to the first example shown for user information. In the figure, a relationship information identifier used as authentication information is recorded in association with a user identifier and scene information. Note that the authentication information does not have to be associated with specific scene information. In this case, one piece of authentication information can be identified for a user identified by a corresponding user identifier, regardless of whether it corresponds to scene information.
[0065] FIG. 6 is a diagram showing a second example of the authentication information stored in the authentication information storage unit 117 in the personal authentication device 100. As shown in FIG.
[0066] The second example shown in the figure corresponds to the second example shown for user information. In the figure, a character string converted from related information using a predetermined method is recorded as authentication information in association with a user identifier. The personal authentication device 100 can convert information to be compared with the authentication information into a character string using the same predetermined method, thereby comparing the information with the authentication information.
[0067] 2, the receiving unit 120 receives information transmitted from another device. The receiving unit 120 stores the received information in, for example, the storage unit 110. The receiving unit 120 is typically implemented by a wireless or wired communication means, but may also be implemented by a means for receiving broadcasts.
[0068] In this embodiment, for example, a user inputs information using the terminal device 600 and transmits the information to the personal authentication device 100. The receiving unit 120 can store each piece of transmitted information in the storage unit 110 in association with a user identifier. When receiving information from the terminal device 600, the receiving unit 120 can identify the user identifier of the user related to the transmission based on the transmitted information. For example, when the terminal device 600 is a device used in a point-of-sale information management system, the terminal device 600 may be configured to be able to identify the user identifier based on information read from a credit card or the like.
[0069] The reception unit 130 receives information input using an input means (not shown) connected to the authentication device 100. The reception unit 130 receives, for example, operations by an administrator of the authentication device 100. The reception unit 130 stores the received information in, for example, the storage unit 110. The input means may be any means, such as a numeric keypad, keyboard, mouse, or menu screen. The reception unit 130 may also receive information input by an input operation (including, for example, information read by a reading device) connected to the authentication device 100 (for example, a code reader). The reception unit 130 may be realized by a device driver for an input means such as a numeric keypad or keyboard, or control software for a menu screen. The reception unit 130 may also receive information such as voice input via a microphone.
[0070] It may be said that the accepting unit 130 accepts the information received by the receiving unit 120 as information input to the identity authentication device 100. It may be said that the accepting unit 130 accepts a user operation performed using the terminal device 600. In other words, inputting information to the identity authentication device 100 may be interpreted as meaning that the information is indirectly input to the identity authentication device 100 by the user via the terminal device 600 or the like, or may be interpreted as meaning that the information is directly input to the identity authentication device 100 by the user using an input means. Furthermore, inputting information to the identity authentication device 100 may be understood as the user providing information to the identity authentication device 100 by executing a program that automatically generates information or by providing various information to a program to make it function.
[0071] In this embodiment, the receiving unit 120 can receive specific information from the user that identifies related information used for personal authentication. The specific information can be, for example, access from the user using a predetermined method, transmission of predetermined information, etc., and the receiving unit 120 can receive this information. When the receiving unit 120 receives a start instruction, the accepting unit 130 accepts it. This makes it possible for the personal authentication device 100 to acquire the specific information.
[0072] The processing unit 140 can usually be realized by an MPU, memory, etc. The processing procedure of the processing unit 140 is usually realized by software, and the software is recorded on a recording medium such as a ROM. However, it may also be realized by hardware (dedicated circuit). The processing unit 140 performs various types of processing. The various types of processing are, for example, processing performed by each part of the processing unit 140 as follows.
[0073] In this embodiment, processing unit 140 includes related information acquisition unit 141 , related information output unit 143 , specific information acquisition unit 145 , authentication information storage unit 147 , input information reception unit 151 , and personal authentication unit 153 .
[0074] The related information acquisition unit 141 acquires related information related to the behavior of the person to be authenticated. The related information acquisition unit 141 acquires, for example, related information transmitted from an external device to the identity authentication device 100. For example, the related information acquisition unit 141 acquires related information transmitted from the terminal device 600 or related information transmitted from the external device 700. The related information acquisition unit 141 stores the acquired related information in the user information storage unit 111 in association with the user identifier.
[0075] For example, when the person to be authenticated makes a purchase at a store using a credit card or the like, the information is stored in a device of the credit card company (an example of external device 700). Of that information, the related information acquisition unit 141 is configured to be able to acquire information that can be used as related information. Note that information that can be used as related information is, for example, a preset type of information, but it may also be configured such that, for example, each time an instruction is given by the person to be authenticated, information that can be used as related information is specified in accordance with the instruction. Information that can be used as related information may include, for example, the name of the store where the credit card was used, the name of the product purchased, etc., but is not limited to these.
[0076] The related information acquisition unit 141 may be configured to acquire related information that is an image based on related information acquired from the terminal device 600 or the external device 700. For example, when acquiring a store name, the related information acquisition unit 141 may be configured to acquire a photo of the exterior of the store corresponding to the store name from a predetermined database or from various websites. Similarly, when acquiring a product name, product number, or the like, the related information acquisition unit 141 may be configured to acquire a photo of the corresponding product.
[0077] When a predetermined output condition is satisfied, the related information output unit 143 outputs the related information acquired by the related information acquisition unit 141 to the person to be authenticated. The related information is output, for example, to the terminal device 600 used by the person to be authenticated. When the related information output unit 143 outputs the related information, the person to be authenticated can confirm the related information that can be used as authentication information. That is, as will be described later, in this embodiment, the person to be authenticated can confirm the related information and then perform an operation to input specific information to be used as authentication information.
[0078] The method for outputting the related information can be set as appropriate. As an example, the related information may be output by being included in a web page provided by accessing the identity authentication device 100 using the terminal device 600. Also, the related information may be output as information that can be read by a predetermined application running on the terminal device 600, and may be displayed by the predetermined application.
[0079] Here, various predetermined output conditions can be set. For example, the output conditions may include that the person to be authenticated has performed a predetermined action.
[0080] More specifically, for example, the output condition may include that the person to be authenticated has been authenticated by the authentication device 100. In other words, the output condition may include that the person to be authenticated has been authenticated using the authentication device 100. In this case, it may be considered that the person to be authenticated has been authenticated for a purpose other than the purpose of setting the authentication information. In this way, by outputting the related information at the timing when the person to be authenticated has been authenticated, it is possible to accept input of specific information from the person to be authenticated who has been authenticated, and it is possible to easily set the authentication information.
[0081] However, the output condition is not limited to this, and may include, for example, the fact that the person to be authenticated performs an operation on the authentication device 100 requesting the setting of authentication information, the fact that a predetermined period of time has passed since a predetermined timing (for example, the last time authentication information was set), the fact that a predetermined store, website, etc. is being used, etc. Also, in a case where the device is configured to output guidance information indicating an access destination for displaying a selection screen described later, it is also possible to interpret that the output condition is that access is made using the guidance information.
[0082] In this embodiment, the related information output unit 143 is configured to output a selection screen displaying two or more pieces of related information to the person to be authenticated, for example, and allow the person to select which piece of related information to use as authentication information. The person to be authenticated can use the selection screen to perform an operation to input specific information that identifies the related information to be used as authentication information. The person to be authenticated can select the related information to be used as authentication information after checking two or more pieces of related information on the selection screen, so that the person to be authenticated can perform identity authentication using the related information that the person considers appropriate for identity authentication. Note that the selection screen may be a screen that allows the person to select whether or not to use one piece of related information as authentication information.
[0083] Furthermore, in this embodiment, when outputting the related information, the related information output unit 143 preferably outputs to the authenticatee guidance information used to input the specific information. The guidance information is, for example, information indicating an access destination, such as a webpage, used to input the specific information. The webpage used to input the specific information may also output the related information. For example, the webpage may present one or more pieces of related information to the authenticatee and allow the authenticatee to select whether or not to use the related information as authentication information. This webpage may be considered to be the selection screen described above. The information indicating the access destination may be displayed, for example, as a hyperlink or as an image such as a multidimensional code. The related information may be included in the guidance information. For example, the guidance information may be output so as to be included in a webpage displayed when identity authentication is performed and payment is made on an e-commerce website or the like. Furthermore, for example, the guidance information may be output so as to be displayed on a receipt, a credit card receipt, or other certificate output from a cash register or the like when purchasing a product. In this case, identity authentication may also be performed for credit card use. The person to be authenticated can input specific information that identifies the relevant information into the identity authentication device 100 by performing a predetermined operation using the terminal device 600 based on the guide information.
[0084] Here, the related information output unit 143 may be configured to acquire related information to be recommended to the person to be authenticated from the related information acquired by the related information acquisition unit 141, and output the related information to the person to be authenticated. That is, the related information output unit 143 may be configured to recommend to the person to be authenticated that one or more pieces of related information be used as authentication information by selecting and outputting one or more pieces of related information from the related information stored in the user information storage unit 115. The person to be authenticated can easily set the authentication information to be usable by performing an operation to input specific information specifying that the outputted related information be used as authentication information. Note that the related information output unit 143 may acquire two or more pieces of recommended related information and output a selection screen to the person to be authenticated using them.
[0085] In this case, the related information to be recommended (selection of related information) may be obtained, for example, as follows. That is, the related information output unit 143 may obtain history information regarding the behavioral history of the person to be authenticated, and obtain related information to be recommended to the person to be authenticated based on the history information. The history information regarding the behavioral history may include, for example, the related information of the person to be authenticated stored in the user information storage unit 115 and the acquisition date and time of the information, but is not limited to this. For example, information such as the user's location and purchase history of products, which are stored by the user in a device other than the personal authentication device 100 (for example, the external device 700 or the terminal device 600), may be obtained as the history information. Furthermore, the related information to be recommended based on the history information may be obtained, for example, based on the frequency of similar behavior or based on the distance traveled (for example, the distance from the starting point of the movement to the destination). The acquisition of related information based on the distance traveled may include, for example, obtaining related information obtained when the distance traveled from the base is long, or obtaining related information obtained when the distance traveled from the base is short. In addition, obtaining related information according to the frequency with which similar behavior has been performed may involve, for example, obtaining related information associated with a high frequency of behavior (such as the names of frequently visited stores) or obtaining related information associated with a low frequency of behavior.
[0086] Furthermore, when outputting guidance information, the related information output unit 143 may be configured to output benefit information regarding the provision of a benefit to the authenticated person. Benefit information is, for example, information used by the user to receive the benefit. The benefit information may be, for example, the benefit itself. Furthermore, for example, the benefit information may be a coupon code that can be exchanged for a predetermined benefit, or information for carrying out procedures to receive delivery of the benefit. The benefit information may be information for conducting a lottery to select authenticated people who will receive the benefit. The benefit information may be output to the authenticated person (for example, by transmitting it to the terminal device 600), or may be stored in the storage unit 110 in association with a user identifier. In this way, by making it possible to output benefit information, it is possible to effectively motivate authenticated people to check the guidance information.
[0087] The related information output unit 143 may be configured to output, as benefit information, information informing the user that a benefit will be granted if a predetermined condition is satisfied. By making it possible to output such benefit information, it is possible to effectively motivate the user to perform operations related to the authentication information. In this case, the specific information acquisition unit 145, which will be described later, may be configured to perform processing to grant a benefit to the user in response to acquiring specific information input using the guidance information.
[0088] The specific information acquisition unit 145 acquires specific information that identifies one or more pieces of related information based on information about the person to be authenticated. The specific information can be, for example, information for identifying related information to be used as authentication information. The specific information is, for example, one or more pieces of related information or their related information identifiers, but is not limited to this. For example, when the time, etc. at which the related information is acquired is recorded in the user information storage unit 115, etc., the specific information may be information that can identify one or more pieces of related information based on the time, etc.
[0089] The specific information acquiring unit 145 acquires, for example, specific information input by the person to be authenticated. For example, in this embodiment, the specific information acquiring unit 145 acquires specific information input in response to the output of related information by the related information output unit 143. For example, when the related information output unit 143 outputs related information using a selection screen or the like as described above, and an operation for selecting related information to be used as authentication information is performed using the selection screen or the like, the specific information acquiring unit 145 acquires the selected related information or information corresponding thereto as specific information.
[0090] Here, in this embodiment, the specific information acquisition unit 145 may be configured to acquire specific information input by the person to be authenticated for each behavioral scene of the person to be authenticated. In other words, the specific information acquisition unit 145 acquires the specific information in association with scene information that identifies the behavioral scene. Examples of scene information include those described above. That is, an example of a behavioral scene is the store or store chain where the payment is made. The behavioral scene and the scene information are not limited to this. The behavioral scene may be, for example, an amount range to which the payment amount belongs, a payment method (e.g., time period, timing, etc.), a predetermined personality (persona) in a service that uses the results of personal authentication, etc.
[0091] When specific information is acquired for each behavior scene in this way, it is preferable that the related information output unit 143 outputs, to the authentication-subject, related information corresponding to each behavior scene of the authentication-subject.
[0092] By acquiring specific information for each behavior scene in this way, it is possible to set authentication information for each behavior scene. Since personal authentication can be performed for each behavior scene using authentication information that is easy for the person to use, the convenience of the personal authentication device 100 can be further improved.
[0093] The authentication information accumulation unit 147 stores the related information identified based on the specific information acquired by the specific information acquisition unit 145 as authentication information in the authentication information storage unit 117 in association with the user identifier of the person to be authenticated. When specific information is acquired for each behavior scene, the authentication information accumulation unit 147 stores the scene information and the authentication information in association with the user identifier.
[0094] The input information receiving unit 151 receives authentication input information input by a user. The authentication input information is input, for example, in response to a predetermined instruction transmitted from the personal authentication device 100 to the user when personal authentication is performed.
[0095] The identity authentication unit 153 performs identity authentication using authentication input information received from a user by the input information receiving unit 151 and authentication information stored in the authentication information storage unit 117 and associated with the user identifier of the user. The identity authentication unit 153 performs identity authentication based on the correspondence between the authentication input information and the authentication information. That is, the identity authentication unit 153 authenticates that the user is the person to be authenticated corresponding to the authentication information. For example, if the authentication input information input by the user matches the authentication information, the identity authentication unit 153 authenticates that the user is the person to be authenticated identified by the user identifier corresponding to the authentication information. The identity authentication unit 153 outputs the authentication result to, for example, the external device 700, etc. This allows the external device 700, etc. to perform processing using the identity authentication result.
[0096] The personal authentication unit 153 may be configured to request the user to input authentication input information. The request to input authentication input information can be made, for example, by outputting an input screen to the terminal device 600 or by outputting to the terminal device 600 a guide on how to input authentication input information.
[0097] The correspondence between the authentication input information and the authentication information may be confirmed using a method different from that described above. Correspondence between the authentication input information and the authentication information may be determined based on whether the authentication input information or information based thereon matches the authentication information or information based thereon. For example, correspondence between the authentication input information and the authentication information may be determined based on whether information generated using the authentication input information matches information generated using the authentication information. Correspondence between the authentication input information and the authentication information may be determined based on whether the authentication input information matches information generated using the authentication information or whether information generated using the authentication input information matches the authentication information. The authentication input information or information based on the authentication information may also be referred to as information generated using the authentication input information or information generated using the authentication information. The information generated using the authentication input information or the authentication information may be, for example, a character string converted using a predetermined method such as a hash value, a character string obtained by image recognition, or the like, but is not limited to these.
[0098] Here, in this embodiment, the personal authentication unit 153 may be configured to perform personal authentication based on an identifier that identifies a behavioral scene for which personal authentication is performed, i.e., authentication information corresponding to scene information. In this case, it is sufficient that authentication information is stored for each behavioral scene. For example, when making a payment requiring personal authentication at a store of a predetermined chain, the personal authentication unit 153 may be configured to perform personal authentication using authentication information associated with the user identifier, which is associated with scene information corresponding to the chain or store. Since personal authentication can be performed for each behavioral scene using authentication information that is easy for the person to authenticate to use, the convenience of the personal authentication device 100 can be further improved.
[0099] The transmitting unit 170 transmits information to other devices constituting the information processing system 1 via a network. The transmitting unit 170 is usually realized by wireless or wired communication means, but may also be realized by broadcasting means. The transmitting unit 170 transmits information to, for example, the terminal device 600. In other words, the transmitting unit 170 outputs information to, for example, the terminal device 600.
[0100] Next, an example of the operation of the personal authentication device 100 performed when a user uses the information processing system 1 according to this embodiment will be described.
[0101] In this embodiment, when a user performs an action involving personal authentication using the terminal device 600, for example, the user can cause the personal authentication device 100 to perform personal authentication by transmitting authentication input information to the personal authentication device 100. In addition, the user can set authentication information to be used for personal authentication by transmitting specific information to the personal authentication device using the terminal device 600.
[0102] When the information processing system 1 is used in this way, the personal authentication device 100 performs various operations, for example, as follows. These operations are performed by the processing unit 140 executing control operations and the like using each unit.
[0103] FIG. 7 is a flowchart showing an example of the operation of the personal authentication device 100. As shown in FIG.
[0104] (Step S1) The processing unit 140 determines whether or not related information has been acquired. If related information has been acquired, the process proceeds to step S2, and if not, the process proceeds to step S3.
[0105] (Step S2) The processing unit 140 stores the related information in association with the user identifier in the user information storage unit 115. The process proceeds to step S3.
[0106] (Step S3) Processing unit 140 determines whether a predetermined output condition is satisfied. For example, if the output condition is that the person to be authenticated has been authenticated, processing unit 140 determines whether the person to be authenticated has been authenticated. If it is determined that the output condition is satisfied, processing proceeds to step S4; if not, processing proceeds to step S5.
[0107] (Step S4) The processing unit 140 performs a related information output process. The related information output process will be described in detail later. The process proceeds to step S5.
[0108] (Step S5) Processing unit 140 determines whether or not the specific information input by the person to be authenticated has been acquired. If it is determined that the specific information has been acquired, the process proceeds to step S6; if not, the process proceeds to step S7.
[0109] (Step S6) Based on the identification information, processing unit 140 stores authentication information in association with the user identifier of the person to be authenticated in authentication information storage unit 117. The process proceeds to step S7.
[0110] (Step S7) The processing unit 140 determines whether or not to perform identity authentication. For example, when there is a request from the external device 700 or the like to perform identity authentication for one user to determine whether or not the person to be authenticated is the person to be authenticated, the processing unit 140 determines to perform identity authentication. If it is determined to perform identity authentication, the processing proceeds to step S8; if not, the series of processes ends.
[0111] (Step S6) The processing unit 140 performs an identity authentication process. The identity authentication process will be described in detail later. After that, the series of processes ends.
[0112] This process is configured to be executed repeatedly at regular intervals, but the order of the decisions and the corresponding processes is not limited to this.
[0113] FIG. 8 is a flowchart showing an example of the related information output process of the personal authentication device 100.
[0114] (Step S101) Processing unit 140 acquires related information to be recommended to the person to be authenticated from related information associated with the user identifier of the person to be authenticated. For example, as described above, related information is acquired based on history information regarding the behavior history of the person to be authenticated.
[0115] (Step S102) The processing unit 140 creates a selection screen using the recommended related information.
[0116] (Step S103) Processing unit 140 outputs guidance information used for inputting specific information to the person to be authenticated.
[0117] (Step S104) Processing unit 140 determines whether or not there has been access from the person to be authenticated to display the selection screen. In other words, processing unit 140 determines whether or not there has been a request from the person to be authenticated to output related information. If it is determined that there has been access to display the selection screen, processing proceeds to step S105; if not, processing ends the related information output process and returns to the upper level processing.
[0118] (Step S105) Processing unit 140 outputs a selection screen to the person to be authenticated. This allows the person to input specific information using the selection screen. Thereafter, the related information output process ends, and the process returns to the upper level process.
[0119] FIG. 9 is a flowchart showing an example of the personal authentication process of the personal authentication device 100. As shown in FIG.
[0120] (Step S151) The processing unit 140 outputs an input screen for inputting authentication input information to the user who is to be authenticated.
[0121] (Step S152) Processing unit 140 determines whether or not authentication input information entered by the user has been accepted. The processing of step S152 is repeatedly executed (waits) until it is determined that authentication input information has been accepted, and if it is determined that authentication input information has been accepted, processing proceeds to step S153. Note that if it is not determined that authentication input information has been accepted within a predetermined time, processing may be terminated.
[0122] (Step S153) Processing unit 140 acquires authentication information stored in authentication information storage unit 117 and corresponding to the user identifier of the person to be authenticated.
[0123] (Step S154) Processing unit 140 determines whether the authentication input information entered by the user corresponds to the authentication information of the person to be authenticated. For example, processing unit 140 determines whether the authentication input information or information based thereon matches the authentication information or information based thereon. If it is determined that the authentication input information corresponds to the authentication information, the process proceeds to step S155; if not, the process proceeds to step S156.
[0124] (Step S155) Processing unit 140 outputs the authentication result that identifies the user as the person to be authenticated, and then ends the authentication process, returning to the upper level process.
[0125] (Step S156) Processing unit 140 outputs an authentication result indicating that the user is not the person to be authenticated, and then ends the personal authentication process, returning to the upper level process.
[0126] In this embodiment, various screens for using the identity authentication device 100, which are output by the identity authentication device 100, are displayed on the display unit 661 of the user's terminal device 600. These displayed screens are used to present information to the user and accept information input from the user. That is, the user can use the identity authentication device 100 while displaying various screens on the terminal device 600. Screen transitions are realized by appropriate communication between the terminal device 600 and the identity authentication device 100, or by the processing unit or processing unit 140 of the terminal device 600 performing control operations in response to user operations accepted by the acceptance unit of the terminal device 600. This can be achieved, for example, by the identity authentication device 100 providing a web page that can be displayed on the terminal device 600. Alternatively, the identity authentication device 100 may transmit and receive information that can be handled by a predetermined application, such as a predetermined client application or an instant messaging service client application, running on the terminal device 600.
[0127] Below, specific examples of typical display screens are explained. The following example shows a case where a person to be authenticated performs identity authentication and sets authentication information when paying for a product purchase on an e-commerce site. That is, when setting authentication information, the following payment completion screen C10 and selection screen C20 are displayed, and when performing identity authentication, the identity authentication screen C30 and authentication completion screen C40 are displayed.
[0128] FIG. 10 is a diagram illustrating a specific example of the payment completion screen C10 displayed on the terminal device 600. As shown in FIG.
[0129] FIG. 10 shows an example of a state in which a payment completion screen C10 is displayed on the display unit 661 of the terminal device 600 of the person to be authenticated. Such a screen is displayed when payment is completed for the person to be authenticated. In this specific example, the payment completion screen C10 includes guidance information C11 and benefit information C15. The guidance information C11 includes information indicating that the person to be authenticated can set authentication information, i.e., perform an operation to input specific information. The guidance information C11 also includes a setting button C13 for transitioning to a selection screen C20. The person to be authenticated can display the next selection screen C20 by operating the setting button C13. In this specific example, the benefit information C15 displays, for example, information informing the person to be authenticated that a benefit will be granted if the authentication information is set or updated (reset). By including such a display, the person to be authenticated can be effectively motivated to set or update authentication information.
[0130] FIG. 11 is a diagram illustrating a specific example of the selection screen C20 displayed on the terminal device 600. In FIG.
[0131] FIG. 11 shows an example of a state in which a selection screen C20 is displayed on the display unit 661 of the terminal device 600 of the person to be authenticated. In this specific example, the selection screen C20 includes a selection area C21 including two or more (e.g., four) images that are related information, and a send button C23. The selection area C21 is configured to allow the person to be authenticated to perform an operation to select an image to be used as authentication information. The send button C23 is a button for transmitting specific information that identifies the image (related information) selected in the selection area C21 to the personal authentication device 100. The person to be authenticated can transmit specific information that identifies the selected image to the personal authentication device 100 by operating the send button C23 with a desired image selected in the selection area C21. As a result, the specified image is stored in the personal authentication device 100 as authentication information for the person to be authenticated.
[0132] FIG. 12 is a diagram illustrating a specific example of the personal authentication screen C30 displayed on the terminal device 600. In FIG.
[0133] FIG. 12 shows an example of a state in which an authentication screen C30 is displayed on the display unit 661 of the terminal device 600 of the person to be authenticated. Such a screen is displayed when a user attempts to make a payment as the person to be authenticated. In this specific example, the authentication screen C30 includes a selection area C31 including two or more (e.g., four) images and an authentication button C33. The selection area C31 includes candidate images that the user can input for authentication. The user can perform an operation to select an image to be used as authentication input information in the selection area C31. The authentication button C33 is a button for transmitting the image selected in the selection area C31 to the authentication device 100 as authentication input information. The information transmitted as authentication input information may be the image itself, or an identifier that identifies the image, etc. The user can transmit the authentication input information for the selected image to the authentication device 100 by operating the authentication button C33 after selecting a desired image in the selection area C31. This allows personal authentication to be performed using the authentication input information and authentication information entered by the user in the personal authentication device 100. When the authentication button C33 is operated, the next authentication completion screen C40 can be displayed.
[0134] FIG. 13 is a diagram illustrating a specific example of an authentication completion screen C40 displayed on the terminal device 600. In FIG.
[0135] FIG. 13 shows an example of a state in which an authentication completion screen C40 is displayed on the display unit 661 of the terminal device 600 of the person to be authenticated. The authentication completion screen C40 shown in FIG. 13 shows an example in which the user who operated the authentication button C33 has been authenticated as the person to be authenticated (i.e., the person authentication has been successful). That is, in this specific example, the authentication completion screen C40 displays information indicating that the person authentication has been successful. Furthermore, as information for carrying out the payment procedure in response to successful person authentication, the screen C40 includes, for example, information for requesting the person to be authenticated to confirm the payment details and a button for executing the payment. After completing the person authentication, the user can perform an operation to execute the payment. Note that if the person authentication has not been successful, for example, information indicating this may be displayed.
[0136] As described above, according to this embodiment, personal authentication can be performed using authentication information that the person to be authenticated can easily remember. The authentication information can be easily set using related information about the behavior of the person to be authenticated, and the authentication information can also be easily updated. Therefore, the person to be authenticated can be provided with an authentication experience that places less strain and stress on the person to be authenticated.
[0137] The processing in this embodiment may be implemented by software. This software may be distributed by software download or the like. Furthermore, this software may be recorded on a recording medium such as a CD-ROM and distributed. The software implementing the identity authentication device 100 in this embodiment is the following program. That is, this program is executed on a computer of the identity authentication device 100 that can access the authentication information storage unit 117, and causes the computer of the identity authentication device 100 to function as: a related information acquisition unit that acquires related information related to the behavior of the person to be authenticated; a specific information acquisition unit that acquires specific information input by the person to be authenticated that identifies one or more pieces of related information; an authentication information storage unit that stores the related information identified by the specific information in the authentication information storage unit as authentication information corresponding to the person to be authenticated; an input information acceptance unit that accepts authentication input information input by a user; and an identity authentication unit that authenticates the user as the person to be authenticated corresponding to the authentication information, based on the correspondence between the authentication input information and the authentication information stored in the authentication information storage unit.
[0138] (others)
[0139] Fig. 14 is a schematic diagram of a computer system 800 according to the embodiment, and Fig. 15 is a block diagram of the computer system 800.
[0140] These figures show the configuration of a computer that executes the program described in this specification to realize the personal authentication device etc. of the above-mentioned embodiment. The above-mentioned embodiment can be realized by computer hardware and a computer program executed on the computer hardware.
[0141] Computer system 800 includes a computer 801 that includes a CD-ROM drive, a keyboard 802, a mouse 803, and a monitor 804.
[0142] In addition to the CD-ROM drive 8012, the computer 801 includes an MPU 8013, a bus 8014 connected to the CD-ROM drive 8012 etc., a ROM 8015 for storing programs such as a boot-up program, a RAM 8016 connected to the MPU 8013 for temporarily storing instructions of application programs and providing temporary storage space, and a hard disk 8017 for storing application programs, system programs, and data. Although not shown here, the computer 801 may further include a network card for providing connection to a LAN.
[0143] A program that causes computer system 800 to execute the functions of the personal authentication device and the like of the above-described embodiments may be stored on CD-ROM 8101, inserted into CD-ROM drive 8012, and then transferred to hard disk 8017. Alternatively, the program may be transmitted to computer 801 via a network (not shown) and stored on hard disk 8017. The program is loaded into RAM 8016 when executed. The program may also be loaded directly from CD-ROM 8101 or the network.
[0144] The program does not necessarily include an operating system (OS) or a third-party program that causes the computer 801 to execute the functions of the personal authentication device of the above-described embodiment. The program only needs to include instructions that call appropriate functions (modules) in a controlled manner to achieve the desired results. How the computer system 800 operates is well known, and a detailed description thereof will be omitted.
[0145] In addition, in the above program, the sending step of sending information and the receiving step of receiving information do not include processing performed by hardware, such as processing performed by a modem or interface card in the sending step (processing that can only be performed by hardware).
[0146] The computer that executes the program may be a single computer or a plurality of computers, that is, it may perform centralized processing or distributed processing.
[0147] Furthermore, in the above-described embodiments, two or more components present in one device may be physically realized on one medium.
[0148] Furthermore, in the above embodiments, each process (each function) may be realized by centralized processing by a single device (system), or may be realized by distributed processing by multiple devices (in this case, the entire system consisting of multiple devices performing distributed processing can be understood as a single "device").
[0149] Furthermore, in the above embodiments, the transfer of information between components may be performed, for example, by one component outputting information and the other component receiving information if the two components transferring the information are physically different, or by moving from a processing phase corresponding to one component to a processing phase corresponding to the other component if the two components transferring the information are physically the same.
[0150] Furthermore, in the above-described embodiments, information related to the processing performed by each component, such as information accepted, acquired, selected, generated, transmitted, or received by each component, and information such as thresholds, formulas, and addresses used in processing by each component, may be temporarily or long-term stored in a recording medium (not shown), even if not explicitly stated in the above description. Furthermore, the storage of information in the recording medium (not shown) may be performed by each component or a storage unit (not shown). Furthermore, the reading of information from the recording medium (not shown) may be performed by each component or a reading unit (not shown).
[0151] Furthermore, in the above-described embodiments, if the information used by each component, such as thresholds, addresses, and various setting values used by each component in processing, may be changed by the user, the user may or may not be able to change the information as appropriate, even if not explicitly stated in the above description. If the information is changeable by the user, the change may be realized, for example, by a receiving unit (not shown) that receives a change instruction from the user and a changing unit (not shown) that changes the information in accordance with the change instruction. The change instruction may be received by the receiving unit (not shown), for example, from an input device, by receiving information transmitted via a communication line, or by receiving information read from a predetermined recording medium.
[0152] The present invention is not limited to the above-described embodiment, and various modifications are possible, and these modifications are also included within the scope of the present invention.
[0153] Some of the components and functions of the above-described embodiments may be omitted.
[0154] The specific information is not limited to information input by the authenticated person, but may be acquired based on various information related to the authenticated person. For example, the specific information may be acquired using attribute values related to predetermined attributes pre-stored in the user information storage unit as user information related to the authenticated person. For example, the specific information may be identified from related information related to products purchased by the authenticated person, the related information corresponding to information indicating the authenticated person's preferences (an example of specific information) stored as user information. More specifically, for example, if the authenticated person's liking of pudding is stored as user information, the specific information acquisition unit may be configured to acquire specific information identifying related information related to pudding or related information related to Western-style confectionery based on the user information. This reduces the number of operations required of the user, making the personal authentication device easier to use. [Industrial Applicability]
[0155] As described above, the personal authentication device according to the present invention has the effect of being able to perform personal authentication using authentication information that the person to be authenticated can easily remember, and is useful as a personal authentication device, etc. [Explanation of symbols]
[0156] 100 Personal authentication device 110 Storage area 115 User information storage section 117 Authentication information storage section 120 Receiver 130 Reception 140 Processing section 141 Related Information Acquisition Unit 143 Related information output unit 145 Specific information acquisition department 147 Authentication information storage unit 151 Input information reception unit 153 Personal authentication unit 170 Transmitter 600 Terminal Equipment
Claims
1. a related information acquisition unit that acquires related information related to the behavior of a person to be authenticated, the related information being of a predetermined type, without requiring the person to be authenticated to input information; a specific information acquisition unit that acquires specific information that identifies one or more pieces of related information input by the person to be authenticated based on information about the person to be authenticated; an authentication information storage unit in which the related information specified by the specific information is stored as authentication information corresponding to the person to be authenticated; an input information receiving unit that receives authentication input information input by a user; an identity authentication unit that authenticates that the user is an authenticatee corresponding to the authentication information based on a correspondence relationship between the authentication input information and the authentication information stored in the authentication information storage unit, An identity authentication device in which the related information acquisition unit acquires, as the related information, at least one of information other than an image that is related to the behavior of the person being authenticated, and an image that is prepared in advance and corresponds to the information other than an image, but is not an image taken by the person being authenticated.
2. The behavior of the person to be authenticated is The use of a store or facility by the authenticated person; a purchase of a product by the authenticated person; An activity that affects the amount of activity acquired by a device worn by the person to be authenticated; Activities that affect the health of the certified person; The personal authentication device according to claim 1 , comprising at least one of:
3. a related information output unit that outputs the related information acquired by the related information acquisition unit to the person to be authenticated when a predetermined output condition is satisfied; The personal authentication device according to claim 1 , wherein the specific information acquisition unit acquires the specific information input in response to the output of the related information by the related information output unit.
4. the related information output unit outputs a selection screen displaying two or more pieces of related information to the person to be authenticated; The personal authentication device according to claim 3 , wherein the specific information acquisition unit acquires the specific information based on a selection operation on the selection screen.
5. The personal authentication device according to claim 3 or 4, wherein the related information output unit acquires related information to be recommended to the person to be authenticated from the related information acquired by the related information acquisition unit, and outputs the related information to the person to be authenticated.
6. 6. The personal authentication device according to claim 5, wherein the related information output unit acquires history information relating to a behavioral history of the person to be authenticated, and acquires related information to be recommended to the person to be authenticated based on the history information.
7. 7. The personal authentication device according to claim 3, wherein the output condition includes that personal authentication of the person to be authenticated has been performed.
8. the output condition includes that the person to be authenticated has performed a predetermined action; 8. The personal authentication device according to claim 3, wherein the related information output unit outputs, to the person to be authenticated, guidance information used for inputting specific information that identifies related information related to the behavior of the person to be authenticated.
9. The personal authentication device according to claim 8 , wherein the related information output unit outputs benefit information regarding the provision of a benefit to the person to be authenticated when outputting the guidance information.
10. 10. The personal authentication device according to claim 8, wherein when the specific information acquisition unit acquires the specific information input using the guidance information, a process of granting a benefit to the person to be authenticated is performed.
11. the specific information acquisition unit acquires the specific information input by the person to be authenticated for each behavior scene of the person to be authenticated, the authentication information storage unit stores the authentication information in association with information identifying the behavior scene; 11. The personal authentication device according to claim 1, wherein the personal authentication unit is configured to perform the personal authentication based on the authentication information corresponding to an identifier that identifies a behavior scene for which personal authentication is performed.
12. An authentication method performed using a related information acquisition unit, a specific information acquisition unit, an authentication information storage unit, an authentication information accumulation unit, an input information acceptance unit, and an authentication unit, a related information acquisition step in which the related information acquisition unit acquires related information related to the behavior of the person to be authenticated, the related information being of a predetermined type, without the person to be authenticated having to perform an information input operation; a specific information acquisition step in which the specific information acquisition unit acquires specific information input by the person to be authenticated that identifies one or more pieces of related information; an authentication information accumulation step in which the authentication information accumulation unit accumulates the related information identified by the identification information in the authentication information storage unit as authentication information corresponding to the person to be authenticated; an input information receiving step in which the input information receiving unit receives authentication input information input by a user; an authentication step in which the authentication unit authenticates that the user is a person to be authenticated corresponding to the authentication information based on a correspondence relationship between the authentication input information and the authentication information stored in the authentication information storage unit; In the related information acquisition step, the related information acquisition unit acquires, as the related information, at least one of information other than an image that is related to the behavior of the person being authenticated, and an image that is prepared in advance and corresponds to the information other than an image, but is not an image taken by the person being authenticated.
13. A computer that can access the authentication information storage unit, a related information acquisition unit that acquires related information related to the behavior of a person to be authenticated, the related information being of a predetermined type, without requiring the person to be authenticated to input information; a specific information acquisition unit that acquires specific information that identifies one or more pieces of related information input by the person to be authenticated; an authentication information storage unit that stores the related information identified by the identification information in the authentication information storage unit as authentication information corresponding to the person to be authenticated; an input information receiving unit that receives authentication input information input by a user; an identity authentication unit that authenticates that the user is a person to be authenticated corresponding to the authentication information based on a correspondence relationship between the authentication input information and the authentication information stored in the authentication information storage unit; The related information acquisition unit is a program that acquires, as the related information, at least one of information other than an image that is related to the behavior of the person being authenticated, and an image that is prepared in advance and corresponds to the information other than an image, but is not an image taken by the person being authenticated.
Citation Information
Patent Citations
Electrode structure of thermal printer head
JP1985021264A
Personal identification system using image
JP2004157675A
Personal identification system
JP2006163825A
Authentication program, information processing apparatus, and authentication system
JP2013196222A
User authentication system, user authentication method, server and program
JP2015158860A