PROGRAM, INFORMATION PROCESSING APPARATUS AND INFORMATION PROCESSING METHOD

A dual-authentication system ensures security by separating primary and secondary user authentication processes, maintaining usability by allowing users to engage in other activities during the process.

JP7733626B2Active Publication Date: 2025-09-03JCB CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022149172
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-09-20
Publication Date
2025-09-03
Estimated Expiration
2042-09-20

AI Technical Summary

Technical Problem

Existing user authentication methods that require multiple authentications increase processing time, impairing user usability.

Method used

Implement a system where primary authentication is performed by a server device and secondary authentication is performed by an in-store device, allowing users to proceed with their tasks while the authentication processes are conducted separately.

Benefits of technology

Ensures security while preventing a loss of usability by allowing users to engage in other activities during multiple authentication processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007733626000001
    Figure 0007733626000001
  • Figure 0007733626000002
    Figure 0007733626000002
  • Figure 0007733626000003
    Figure 0007733626000003
Patent Text Reader

Abstract

To provide a program, an information processing apparatus, and an information processing method capable of preventing damage to user usability while ensuring security when user authentication is performed multiple times in using a service.SOLUTION: A program causes a computer to realize: a reception function for receiving an authentication request for authenticating a service user from a first apparatus; a primary authentication function for performing primary processing based on primary information for performing the primary processing for user authentication in response to the authentication request; and a provision function for providing secondary information for performing secondary processing to a second apparatus that performs the secondary processing for the user authentication based on the result of the primary processing.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a program, an information processing device, and an information processing method. [Background technology]

[0002] When a user makes a transaction in a service, there is known a technology (such as two-factor authentication or two-step authentication) that authenticates the user (hereinafter also referred to as "user authentication") multiple times. Patent Document 1 discloses an authentication system that executes a first authentication process between an authentication server and a terminal that the user logs into when using the service, and a second authentication process between the user's smartphone and the authentication server. This technology can ensure a higher level of security than when user authentication is executed only once. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2021-144598 Summary of the Invention [Problem to be solved by the invention]

[0004] When using a service, it is necessary to ensure usability for users, such as efficiency. However, in the above-mentioned Patent Document 1, since user authentication is performed multiple times, the processing time from requesting user authentication to completion increases, and users have to wait accordingly. This may impair usability for users.

[0005] Therefore, in view of the above problems, the present invention aims to provide a program, an information processing device, and an information processing method that ensure security while preventing a loss of user usability when user authentication is performed multiple times to use a service. [Means for solving the problem]

[0006] A program according to one embodiment of the present invention causes a computer to implement the following: a reception function for receiving an authentication request from a first device to authenticate a user of a service; a primary authentication function for performing primary processing based on primary information for performing primary processing for authenticating the user in response to the authentication request; and a provision function for providing secondary information for performing secondary processing to a second device that performs secondary processing for authenticating the user based on the result of the primary processing.

[0007] An information processing device according to one embodiment of the present invention includes a reception unit that receives an authentication request from a first device to authenticate a user of a service, a primary authentication unit that performs primary processing based on primary information for performing primary processing for authenticating the user in response to the authentication request, and a provision unit that provides secondary information for performing secondary processing to a second device that performs secondary processing for authenticating the user based on the result of the primary processing.

[0008] An information processing method according to one embodiment of the present invention includes a computer receiving an authentication request from a first device to authenticate a user of a service, performing a primary process based on primary information for performing a primary process for authenticating the user in response to the authentication request, and providing secondary information for performing the secondary process to a second device that performs a secondary process for authenticating the user based on the results of the primary process. [Effects of the Invention]

[0009] According to the present invention, when user authentication is performed multiple times to use a service, it is possible to ensure security while preventing a loss of usability for the user. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram illustrating an example of a system configuration of an authentication system according to an embodiment of the present invention. [Figure 2]1 is a diagram for explaining an overview of an authentication system according to an embodiment of the present invention; [Figure 3] FIG. 2 is a diagram illustrating an example of a functional configuration of an authentication device according to the present embodiment. [Figure 4] FIG. 2 is a diagram illustrating an example of the operation of the authentication device according to the present embodiment. [Figure 5] FIG. 2 is a diagram illustrating an example of the operation of the authentication device according to the present embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of a hardware configuration of an authentication device according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] A preferred embodiment of the present invention (hereinafter referred to as "the present embodiment") will be described with reference to the accompanying drawings. In the drawings, components with the same reference numerals have the same or similar configurations.

[0012] In this invention, the terms "unit," "means," "device," or "system" do not simply mean physical means, but also include cases where the functions of the "unit," "means," "device," or "system" are realized by software. Furthermore, the functions of one "unit," "means," "device," or "system" may be realized by a combination of two or more physical means, devices, or software modules, and the functions of two or more "units," "means," "device," or "system" may be realized by a single physical means, device, or software module.

[0013] <1. System configuration> An example of the system configuration of an authentication system 1 according to this embodiment will be described with reference to FIG. 1. As shown in FIG. 1, the authentication system 1 includes a server device 100, a user device 200a of a user, a store device 200b of a store that uses a service linked with the authentication system 1 (hereinafter also referred to as an "linked service") or a store that provides the linked service, and a provider device 300 of a provider that provides the linked service. The user device 200a is one aspect of a first device that is a request source for an authentication request, which will be described later, and the user device 200a is one aspect of a second device that executes secondary processing, which will be described later. Note that the first device and the second device are typically different devices, but may also be the same device.

[0014] When a user uses a linked service, the authentication system 1 ensures security by performing authentication (hereinafter also referred to as "user authentication") multiple times to confirm the legitimacy of the user. Specifically, in the authentication system 1, in response to a request from the user device 200a, the server device 100 executes a primary process for user authentication (hereinafter also simply referred to as "primary process"). After the primary process is executed, the in-store device 200b executes a secondary process for user authentication of the same user (hereinafter also simply referred to as "secondary process").

[0015] Performing user authentication multiple times may mean, for example, performing multi-factor authentication such as two-factor authentication using multiple authentication factors, or performing multi-stage authentication such as two-stage authentication that performs authentication in stages. As another example, performing user authentication multiple times may mean performing two or more authentications with different authentication levels.

[0016] The authentication level may represent, for example, the strength of the authentication method. Also, the authentication level may represent, for example, whether or not it is multi-factor authentication. Also, the authentication level may represent, for example, whether or not it is multi-stage authentication. Also, the authentication level may represent, for example, whether or not it is multi-path authentication.

[0017] User authentication may be, for example, authentication specified by NIST SP 800-63-3. The authentication level applied to user authentication may be, for example, AAL (Authenticator Assurance Level) specified by NIST SP 800-63B as follows: Level 1: One or more of the three authentication factors (knowledge, possession, and biometrics) must be used, and there is a certain degree of confidence in the person's authentication. In other words, this can be achieved by performing at least single-factor authentication. Level 2: Of the three factors, multiple factors such as ID password + one-time password must be used, and there is a high degree of reliability in authenticating the person. Unlike Level 3, Level 2 can be achieved by using software as the second authentication factor. Level 3: Two-factor authentication, where the second factor must be authenticated using tamper-resistant hardware, and the authenticity of the person must be very high (specifically, a PIN code + a card with an IC chip (hereinafter also referred to as an "IC card") + My Number card, etc.).

[0018] The possession information may be, for example, device identification information that identifies a device (e.g., an information terminal such as a smartphone) that is possessed by the user, or location information that indicates the location of the possession (e.g., distance information that indicates the distance between the possession and the provider device 300, or information that indicates GPS coordinates measured by a GPS system using a GPS (Global Positioning System) device).

[0019] For example, information about belongings held by a user may be provided to the server device 100 and / or the store device 200b directly, or indirectly via the cloud, etc., as needed, by communication based on communication standards such as BLE (Bluetooth Low Energy), UWB (Ultra Wide Band), Wi-Fi (registered trademark), or near-field wireless communication (e.g., RFID (Radio Frequency Identification) or NFC (Near Field Communication)), or may be provided to these devices by other methods.

[0020] The biometric information may be information about the user's physical appearance, fingerprint, palm print, voice print, and / or iris, for example. The user may provide the biometric information of the user to the server device 100, for example, through the user device 200a, the store device 200b, or a detection device described later.

[0021] The stored information may be, for example, information that identifies a user in the authentication system 1 (hereinafter also referred to as "user identification information"), a card number used to settle a transaction, an account number, a telephone number, an account name such as an email address, a password, a signature or figure entered or selected by the user, a free-entry or multiple-choice answer to a predetermined question, or any other information that is stored by the user and can be obtained by the server device 100. The user enters or selects the stored information through, for example, an input device provided on the user device 200a or the in-store device 200b installed in the store, and provides the stored information to the server device 100.

[0022] The authentication method is a method by which the authentication system 1 authenticates a user. The authentication method may be based on at least one of possession information about an item possessed by the user (e.g., a terminal device such as the user device 200a described below), biometric information about the user's body, and stored information stored by the user. That is, the authentication method may be based only on any one of possession information, biometric information, and stored information, or may be based on two or more pieces of information selected from possession information, biometric information, and stored information. That is, when the authentication method is based on possession information and biometric information, the authentication system 1 authenticates a user who makes a payment for a transaction in a linked service (hereinafter simply referred to as a "transaction") based on the possession information and biometric information. The authentication method may also be based on information other than possession information, biometric information, and stored information. Hereinafter, authentication based on possession information will be referred to as "possession authentication," authentication based on biometric information will be referred to as "biometric authentication," and authentication based on stored information will be referred to as "storage authentication."

[0023] The server device 100, the user device 200a, the store device 200b, and the provider device 300 are connected to one another via a network N.

[0024] The server device 100 is an information processing device capable of communicating with the user device 200a, the in-store device 200b, and the provider device 300. By executing a predetermined program, the server device 100 provides a wallet function (hereinafter also referred to as an "online wallet") that users can use for various transactions in linked services in an online environment. For example, users can store payment method information (described below) in the online wallet. This allows users to access the online wallet from various devices in an online environment and make payments for transactions using the stored payment method information. The server device 100 also provides an authentication function for user authentication for linked services provided by the provider device 300 and / or the wallet function of its own device. This authentication function, for example, executes a primary process for user authentication.

[0025] The provider device 300 is an information processing device used by a provider and is capable of communicating with the user device 200a, the store device 200b, and the provider device 300. The provider device 300 executes a predetermined program to realize a server function that provides linked services to users.

[0026] The user device 200a is an information processing device used by a user, such as a mobile device such as a smartphone, laptop, or tablet. By executing a predetermined program, the user device 200a receives various requests from the user, cooperates with the server device 100 and / or the provider device 300, receives a request for user authentication when logging in to an integrated service, and, after logging in, outputs a screen of the website of the integrated service or an application dedicated to the integrated service.

[0027] The in-store device 200b is an information processing device used in a store, such as a POS register terminal, a tablet terminal, or a handheld terminal. The in-store device 200b may have a reader function that reads, for example, product information about products sold in the store where it is installed or information about services provided in the store. As another example, the in-store device 200b may not have the reader function, and an external device such as a card reader connected to the in-store device 200b may have the reader function. The in-store device 200b may have a POS register function that accepts input of information about products or services (hereinafter also referred to as "products, etc.") and calculates the total price of the accepted products, etc. (in other words, the transaction amount).

[0028] The network N is configured by a wireless network or a wired network. Examples of the network N include a mobile phone network, a PHS (Personal Handy-phone System) network, a wireless LAN (including a local area network, communication conforming to IEEE802.11 (so-called WI / Fi (registered trademark))), 3G (3rd Generation), LTE (Long Term Evolution), 4G (4th Generation), 5G (5th Generation), WiMax (registered trademark), infrared communication, visible light communication, Bluetooth (registered trademark), a wired LAN, a telephone line, a power line communication, a power line network, a network conforming to IEEE1394, etc.

[0029] <2. Overview> An overview of the primary processing and secondary processing for user authentication in the authentication system 1 will be described with reference to Figure 2. In this example, the following linked services are described: (a) a membership service that allows users who use services provided by a provider to join and accumulate points that can be used for various payments when using the service, and (b) a service that is provided face-to-face with a user at an existing store A (hereinafter also referred to as a "face-to-face service"). Also, in this example, the face-to-face service is a retail service that sells products at store A.

[0030] (0) As shown in FIG. 2, the provider device 300 provides the server device 100 with primary information for executing the primary processing prior to the primary processing. (1) When a user enters store A, the server device 100 receives an authentication request for user authentication (hereinafter also simply referred to as "authentication request") from the user device 200a through a detection device or the like for detecting the user who entered the store, and executes the primary processing. Specifically, the primary processing (a) identifies the user based on the primary information of the user's matching target included in the user authentication request, and (b) authenticates the identified user, specifically, by matching the primary information of the matching target with the pre-registered primary information of the matching source to determine whether or not the user is the user.

[0031] The primary information may include, for example, user identification information for identifying each user, primary authentication method information indicating the authentication method used in the user authentication of the primary process, information on possessions of each user according to the primary authentication method information, biometric information, and / or stored information. Furthermore, the primary information may include, for example, location information of the user (specifically, the user device 200a). Furthermore, the primary information may include a primary information validity period indicating the period during which the primary information is valid. Hereinafter, the user's possession information, biometric information, and / or stored information will be collectively referred to as "authentication information."

[0032] The detection device may be, for example, an imaging device such as a camera that captures a facial image of the user as the user's biometric information, an image sensor that processes the image captured by the imaging device to generate biometric information, a face authentication sensor that has an imaging device and an image sensor and performs face authentication by comparing the generated biometric information with the biometric information of the source to be matched, and / or a beacon that acquires location information of the user's user device 200a, etc. Furthermore, the detection device may be a device that is installed near the entrance of store A and that detects the user device 200a when the user enters store A using contact or contactless short-range communication (e.g., Wi-Fi, Bluetooth (registered trademark), or NFC, etc.) or a QR code (registered trademark).

[0033] (2) If the server device 100 successfully authenticates the user as a result of the primary processing (in other words, if it is determined that the user is the person in question), it provides the secondary information of the collation source to the in-store device 200b installed in store A, which is used to conduct sales transactions for products sold in store A, in order to execute the secondary processing of the user. During this information provision, the user can spend his or her free time selecting products to purchase in store A and trying out the selected products.

[0034] The secondary information may include, for example, like the primary information, user identification information of each user, secondary authentication method information indicating the authentication method used in user authentication in the secondary process, and authentication information of each user according to the secondary authentication method information. The primary authentication method information and the secondary authentication method information may indicate different authentication methods (for example, primary is possession authentication and secondary is knowledge authentication, etc.), or may indicate the same authentication method (for example, both primary and secondary are possession authentication, etc.). The secondary information may also include a secondary information validity period indicating the period during which the secondary information is valid.

[0035] For example, if the user authentication is successful as a result of the primary processing, the server device 100 may provide the in-store device 200b with transaction permission information indicating permission to execute a process related to the transaction (hereinafter also referred to as a "transaction process") or a process to finalize the details of the transaction (hereinafter also referred to as a "confirmation process"), together with the secondary information or separately from the secondary information. The transaction permission information may, for example, permit execution of the transaction process or the confirmation process if the user authentication is successful as a result of the secondary processing. The in-store device 200b may output on a screen a message indicating permission for the transaction indicated in the provided transaction permission information.

[0036] (3) When a user purchases a product, the in-store device 200b executes a secondary process to authenticate the user. Specifically, when the secondary information of the comparison target is input from the user or a possession of the user device 200a, the secondary process (a) identifies the user and (b) authenticates the identified user, specifically, by comparing the secondary information of the comparison target with the acquired secondary information of the comparison source to determine whether the user is the actual user. Furthermore, the in-store device 200b may delete the acquired secondary information, for example, immediately after the completion of the secondary process, or when a predetermined period of time has elapsed since the completion, or when a predetermined date has arrived. This predetermined period and / or the predetermined date may be set, for example, by the secondary information validity period.

[0037] (4) A user or a store clerk inputs product information for each of one or more products to be purchased and payment method information for the payment method to be used in the transaction of the products into the in-store device 200b as order details, i.e., transaction details. The in-store device 200b accepts a confirmation instruction from the user or store clerk regarding the input transaction details and executes a confirmation process to confirm the transaction details. The product information may include, for example, a JAN code indicated by a barcode attached to the product to be purchased.

[0038] (5) The in-store device 200b transmits transaction information indicating the result of the confirmation process of (4) above to the server device 100. The in-store device 200b also transmits secondary processing result information indicating the result of the secondary processing of (3) above to the server device 100 together with the transaction information or separately from the transaction information.

[0039] Transaction information is information related to a transaction. For example, the transaction information includes transaction identification information for identifying each transaction, details of each transaction (e.g., the product or service to be transacted, the transaction amount, and / or information on the payment method used for the transaction), the transaction date and time, the transaction processing status (e.g., whether the transaction details are being accepted, whether the confirmation process has been completed, whether the process is temporarily suspended to wait for transaction availability information or transaction conditions information, or whether the confirmation process has been suspended due to a processing error), and a payment instruction for settling each transaction (when the confirmation process has been completed). Transaction processing is processing related to a user's transaction in the linked service. For example, in the case of a purchase and sale transaction of goods, the transaction processing may include at least one of the following: (a) accepting an order for the goods, (b) calculating the subtotal and total amount (transaction amount) of the accepted order, (c) outputting the order details on the screen of the in-store device 200b, and (d) accepting a confirmation instruction from the user (or a store clerk) regarding the output order details.

[0040] Payment method information includes, for example, type information indicating the type of payment method (e.g., credit card payment, debit card payment, or electronic money payment, etc.), payment method identification information for identifying the payment method (e.g., card number or account number, etc.), payment service provider identification information providing the payment method, user identification information of the user using the payment method, security information for the security of the payment method, etc.

[0041] (6) The server device 100 executes a payment process to settle the confirmed transaction using the payment method based on the transaction confirmation information sent from the in-store device 200b and the payment method information regarding the payment methods available to the user.

[0042] (7) The server device 100 transmits to the provider device 300 the transaction confirmation information and the payment processing information indicating the result of the payment processing in (6) above.

[0043] According to the above configuration, the primary process for user authentication is executed by the server device 100 upon entering the store, and the secondary process is executed by the in-store device 200b on the edge side during the transaction. This means that the user does not have to wait in front of the in-store device 200b from the time of the authentication request until multiple user authentications are completed. This allows the user to spend their time freely selecting and trying out products. Therefore, the authentication system 1 can ensure security while preventing a loss of usability for the user when user authentication is performed multiple times to use an integrated service.

[0044] <3. Functional configuration> The functional configuration of the server device 100 according to this embodiment will be described with reference to Fig. 3. As shown in Fig. 3, the server device 100 includes a control unit 110, a communication unit 120, and a storage unit .

[0045] The control unit 110 includes a reception unit 111, a provision unit 112, and an authentication unit 113. The control unit 110 may also include, for example, an acquisition unit 114, a payment processing unit 115, an identity verification unit 116, and / or a registration unit 117.

[0046] [Reception] The reception unit 111 receives various information and / or various requests from a first device (e.g., the user device 200a), a second device (e.g., the store device 200b), and / or the provider device 300. The reception unit 111 may receive various information and / or requests in any manner. For example, the reception unit 111 may receive a message indicating an authentication request including primary information or secondary information of the matching target from these devices. As another example, the reception unit 111 may receive the primary information or secondary information of the matching target by having the user input it on a screen output on the first device or the second device. Furthermore, the reception unit 111 may receive various information and / or requests by using, for example, an API implemented by the server device 100 or an SDK library corresponding to the authentication system 1. For example, the reception unit 111 receives an authentication request for authenticating a service user from a first device such as the user device 200a.

[0047] The receiving unit 111 may receive a higher-level determination request from the second device to request a determination of whether or not the transaction is possible, for example, when the second device cannot determine whether or not the transaction is possible based on the transaction conditions (hereinafter also simply referred to as "transaction conditions") indicated in the transaction condition information. The case where it cannot be determined whether or not the transaction is possible may be, for example, when the second device is unable to determine whether or not the transaction is possible and / or when it is determined that the transaction is impossible because the transaction conditions are not satisfied.

[0048] [Provider] The providing unit 112 provides various information to the first device, the second device, and / or the provider device 300, etc. The providing unit 112 may provide various information in any manner. For example, the providing unit 112 may send a data file or a message including the secondary information to these devices in an event-driven manner. As another example, the providing unit 112 may provide the secondary information and / or the transaction information to these devices via an API or SDK library implemented by the providing unit 112 itself. As another example, the providing unit 112 may cause the secondary information and / or the transaction information to be referenced on a screen output on the user device 200a. Based on the result of the primary processing, the providing unit 112 provides the secondary information for executing the secondary processing to the second device that executes the secondary processing for user authentication. For example, when user authentication is successful as a result of the primary processing, the providing unit 112 may provide the second device with the secondary information to be used as a matching source.

[0049] According to the above configuration, the providing unit 112 provides the second device with secondary information for the secondary processing based on the result of the primary processing for user authentication, thereby enabling the second device to execute the secondary processing for user authentication. For example, since the secondary information is provided only if the user authentication of the primary processing is successful, security can be ensured. Furthermore, by executing the primary processing and the secondary processing on separate devices rather than executing the primary processing and the secondary processing together on the same device, i.e., the server device 100, the user can effectively utilize the time between these processes. Therefore, when user authentication is performed multiple times to use an integrated service, it is possible to ensure security while preventing a loss of usability for the user.

[0050] The providing unit 112 may provide the second device with transaction permission information based on, for example, the result of the primary processing. Specifically, the providing unit 112 may provide the second device with transaction permission information if user authentication in the primary processing is successful. The transaction permission information may, for example, permit execution of a transaction process or a confirmation process based on the result of the secondary processing. Specifically, the transaction permission information may permit execution of a confirmation process if user authentication is successful as a result of the secondary processing. The transaction permission information may, for example, permit execution of a transaction process or a confirmation process for each transaction, or may permit execution of one or more transaction processes or one or more confirmation processes executed within a predetermined period. The second device may execute a transaction process or a confirmation process for each transaction, for example, with the successful user authentication in the secondary processing and the acquisition of the provided transaction permission information as conditions for executing the transaction process or the confirmation process.

[0051] The providing unit 112 may provide, for example, primary processing result information indicating the result of the primary processing to the provider device 300. The primary processing result information may include, for example, (a) information about the identified user (e.g., user identification information, etc.), (b) information indicating the result of determining whether the identified user is the user in the user authentication of the primary processing, i.e., information indicating whether the authentication was successful or unsuccessful, and (c) information indicating the authentication method used in the user authentication in (b) above. Furthermore, for example, when the confirmation process of the user's transaction in the linked service has been completed, the providing unit 112 may provide transaction information to the provider device 300 together with or instead of the primary processing result information.

[0052] The providing unit 112 may provide the second device with the secondary information depending on whether the transaction is possible or not indicated by the transaction possibility information acquired by the acquiring unit 114, for example. Specifically, when the transaction possibility information indicates that the transaction is possible, the providing unit 112 may provide the second device with the secondary information. On the other hand, when the transaction possibility information indicates that the transaction is not possible, the providing unit 112 may cancel providing the secondary information to the second device. When canceling the provision of the secondary information in this way, the providing unit 112 may provide the second device with information indicating that the transaction is not possible instead of the secondary information.

[0053] According to the above configuration, the providing unit 112 can provide secondary information based on information stored (i.e., stored) by the provider device 300 indicating whether the user is available for a transaction. In this case, the second transaction device may determine whether the transaction is available based on acquiring the provided secondary information. For example, if the provider device 300 is inquired about whether the transaction is available for the first time when a transaction process is executed on the second device, the user will have to wait for the time required for the inquiry and response. Therefore, the provider device 300 can be inquired about whether the transaction is available in advance before the transaction is executed on the second device, and secondary information can be provided based on the result, thereby preventing a loss of user usability. Furthermore, rather than storing secondary information in the second device in advance, secondary information can be provided only when the transaction is available for each transaction. This minimizes the amount of secondary information stored on the second device, ensuring security.

[0054] The providing unit 112 may, for example, provide the second device with the transaction condition information acquired from the provider device 300. In this case, the second device may execute transaction processing related to the transaction based on the provided transaction condition information. Specifically, the second device may execute transaction processing when the transaction information and / or transaction history information of the user satisfy the transaction conditions indicated by the transaction condition information.

[0055] According to the above configuration, the second device located on the edge side can determine whether or not a transaction can be performed based on the transaction conditions without inquiring about the provider device 300. This reduces the waiting time for the user and prevents impairment of user usability. Furthermore, when the second device is connected to the server device 100 or the provider device 300 via a wide-area communication network such as the Internet as the network N, the second device can determine whether or not a transaction can be performed regardless of the state of the connection. Therefore, even if communication between the second device and the server device 100 or the provider device 300 is unavailable, particularly when the transaction is settled by cash, by debiting from the balance deposited in the local wallet function of the user device 200a, or by debiting from the balance on the user's IC card, the transaction can be settled.

[0056] The providing unit 112 may, for example, provide the second device with the higher-level determination result information acquired by the acquiring unit 114. In this case, the second device may execute transaction processing for the transaction based on the provided higher-level determination result information. The higher-level determination result information is information indicating the result of the determination made by the provider device 300 as to whether the transaction is possible (e.g., whether the transaction is possible or not). With this configuration, even for high-value transactions or special transactions for which the second device on the edge side cannot determine whether the transaction is possible, it is possible to query the higher-level provider device 300 and execute transaction processing based on the response. This makes it possible to handle a wide variety of transactions.

[0057] [Authentication section] In response to the authentication request received by the reception unit 111, the authentication unit 113 executes processing related to user authentication.

[0058] The authentication unit 113 includes a primary authentication unit 113a. In response to an authentication request, the primary authentication unit 113a executes primary processing for user authentication based on primary information.

[0059] [Acquisition Department] The acquiring unit 114 acquires various information from the first device, the second device, and / or the provider device 300. For example, the acquiring unit 114 may acquire from the provider device 300 transaction propriety information indicating whether or not a transaction to be executed on the second device is permitted, which information is provided in accordance with the primary processing result information and / or transaction information.

[0060] The acquiring unit 114 may acquire, for example, secondary information provided in response to primary processing result information from the provider device 300. Specifically, the acquiring unit 114 may acquire secondary information provided from the provider device 300 when user authentication is successful as a result of the primary processing. With this configuration, rather than having the server device 100 store the secondary information in advance, the secondary information is acquired only when the primary authentication is successful, so that the storage of secondary information in the server device 100 can be kept to a necessary minimum, thereby ensuring security.

[0061] The acquiring unit 114 may acquire, for example, from the provider device 300, transaction condition information indicating transaction conditions for determining whether or not a transaction in the linked service is permitted. The transaction conditions include, for example, an upper limit on the transaction amount (hereinafter also referred to as "amount upper limit"), an upper limit on the number of transactions that can be performed after determining that the transaction conditions have been satisfied by the second device, and permitted types of transactions (for example, buying and selling transactions involving the provision of services or products, loans, factoring, remittance transactions, transfer of value such as electronic money, etc.).

[0062] The acquiring unit 114 may acquire the higher-level determination result information from the provider device 300 as a response to the higher-level determination request transmitted by the transmitting unit 121, for example.

[0063] For example, when the transaction conditions indicate that a transaction is permitted on the condition that additional authentication of the user is performed, the acquiring unit 114 may acquire additional authentication information for performing the additional authentication from the provider device 300. The additional authentication information may include, for example, user identification information of each user, additional authentication method information indicating an authentication method used in the additional authentication, and authentication information of each user according to the additional authentication method information, similar to the primary information. The additional authentication method information may indicate an authentication method different from or the same as the primary authentication method information and the secondary authentication method information. The acquiring unit 114 may, for example, refer to the transaction conditions information and, if applicable, transmit an acquisition request for additional authentication information to the provider device 300 and acquire the additional authentication information in response thereto.

[0064] The second device may execute a confirmation process to confirm the details of the transaction in the linked service based on the result of the secondary process. In this case, the acquisition unit 114 may acquire, for example, from the second device, secondary process result information indicating the result of the secondary process executed in the confirmation process and transaction confirmation information indicating the result of the confirmation process.

[0065] [Payment processing section] The payment processing unit 115 executes a payment process to settle the transaction using the payment method indicated in the payment method information, based on the payment method information and the transaction information indicating that the confirmation process has been completed. The payment processing unit 115 may also execute a payment process to settle the transaction, based on, for example, secondary processing result information.

[0066] For example, if the payment method indicated in the payment method information is credit card payment, the payment processing unit 115 may send a credit card payment instruction including the transaction amount and payee information to the server of the credit card company based on the credit card information (e.g., card number, member name, expiration date, security code, etc.) among the user's payment method information managed in the online wallet. Also, for example, if the payment method indicated in the payment method information is direct deposit, the payment processing unit 115 may send an instruction to transfer the transaction amount from the user's account to the account of a business partner (e.g., the owner of store A) or the like to the server of a financial institution such as a bank that manages the user's account.

[0067] [Identity Verification Department] The identity verification unit 116 verifies the identity of the user based on the user's verification information. This identity verification electronically verifies the authenticity of the user as a real person (so-called eKYC), and may be, for example, identity proofing specified by NIST (National Institute of Standards and Technology) SP 800-63-3. The verification information is information related to the user's identity verification, and may include, for example, the user's name, address, contact information, information related to the user's My Number card used for identity verification, and / or information related to the user's driver's license used for identity verification.

[0068] The timing when the identity verification unit 116 performs identity verification may be, for example, (a) when an account is issued for the user to use the wallet function and / or authentication function of the server device 100, (b) when an account is issued for the user in an linked service, or (c) when the receiving unit 111 receives a request for additional identity verification of the user from the second device. In case (c), for example, if a store clerk determines that the user's appearance or behavior is suspicious, the request for additional verification may be sent from the in-store device 200b, which is the second device, to the server device 100.

[0069] [Registration Department] The registration unit 117 registers user information about a user provided from the user device 200a or the like in the storage unit 130. For example, the registration unit 117 may register the user information in the storage unit 130 in association with the primary information, secondary information, and / or transaction information of the same user.

[0070] The user information may include, for example, user identification information for identifying the user (e.g., an account ID issued by the server device 100, etc.), the user's personal information (e.g., name, address, telephone number, email address, password), and information about the card or device (e.g., the user device 200a) used for the user's payment (e.g., a card number, the device's MAC address, or IP address, etc.). The user information may also include, for example, authentication method information indicating one or more authentication methods available to the user, and authentication information corresponding to the one or more authentication methods indicated by the authentication method information. The user information may also include, for example, information about the user's account issued by the linked service (e.g., an account ID, payment method information linked to the account, etc.).

[0071] [Communications Department] The communication unit 120 transmits and receives various information and / or various requests to and from a first device (e.g., a user device 200a), a second device (e.g., a store device 200b), and / or a provider device 300, etc. via the network N.

[0072] The communication unit 120 may include, for example, a transmission unit 121. The transmission unit 121 transmits the higher-level determination request received from the second device to the provider device 300. The transmission unit 121 may also transmit, for example, additional authentication information acquired by the acquisition unit 114 to the second device. With this configuration, for transactions requiring a higher authentication level or security, the second device on the edge side can perform additional authentication to satisfy the higher authentication level or ensure higher security.

[0073] [Storage] The storage unit 130 stores, for example, user information, payment method information, primary information, secondary information, and / or transaction information in association with each other.

[0074] <4. Example of operation> An example of the operation of the authentication system 1 will be described with reference to Figures 4 and 5. The order of processing and the units of processing shown in Figures 4 and 5 are merely examples and may be changed as appropriate.

[0075] 4 is a sequence diagram showing the process flow from an authentication request to the execution of the first process in the authentication system 1, and the interactions between the devices. As shown in FIG. 4, the user device 200a accepts an authentication request operation for user authentication from a service user (S10). The user device 200a transmits the accepted authentication request to the in-store device 200b (S11). The in-store device 200b further transmits the transmitted authentication request to the server device 100 (S12).

[0076] The reception unit 111 of the server device 100 receives the transmitted authentication request (S13). In response to this authentication request, the primary authentication unit 113a of the server device 100 executes primary processing based on the primary information (S14).

[0077] If user authentication is successful as a result of the primary processing, the user device 200a, the in-store device 200b, the server device 100, and the provider device 300 execute processing within the upper portion of the area indicated by the combined fragment alt1 (alternative1). Specifically, the providing unit 112 of the server device 100 provides the secondary information and transaction permission information to the in-store device 200b (in other words, transmits them to the in-store device 200b; the same applies below) (S15). The providing unit 112 also provides the provider device 300 with primary processing result information indicating that user authentication was successful as a result of the primary processing (S17). The provider device 300 extracts transaction conditions for determining whether or not to permit a transaction for the corresponding user based on the provided primary processing result information (S18). The provider device 300 provides transaction condition information indicating the extracted transaction conditions to the server device 100 (S19). The acquiring unit 114 of the server device 100 acquires the provided transaction condition information (S20). The providing unit 112 of the server device 100 provides the acquired transaction condition information and first processing result information to the in-store device 200b (S21). The in-store device 200b acquires the provided first processing result information and transaction condition information (S22). The in-store device 200b provides the acquired first processing result information to the user device 200a (S23). The user device 200a outputs on a screen or the like a message indicating that the user authentication indicated by the first processing result information was successful (S24).

[0078] If user authentication fails as a result of the first processing, the user device 200a, the store device 200b, the server device 100, and the provider device 300 execute the processing within the area indicated by the combined fragment alt1. Specifically, the providing unit 112 of the server device 100 provides the store device 200b with first processing result information indicating that user authentication failed as a result of the first processing (S25). The store device 200b provides the provided first processing result information to the user device 200a (S26). The user device 200a outputs on a screen or the like a message indicating that user authentication failed, as indicated by the first processing result information (S27).

[0079] 5 is a sequence diagram showing the process flow and interactions between devices in the authentication system 1 from transaction acceptance through secondary processing to transaction settlement processing after the completion of the primary processing in FIG. 4. As shown in FIG. 5, the in-store device 200b accepts an input operation of transaction information for a transaction in the linked service from a user or a store clerk (S30). The in-store device 200b determines whether the transaction indicated by the transaction information satisfies the transaction conditions indicated by the transaction condition information (S31).

[0080] If the transaction satisfies the transaction conditions indicated by the acquired transaction condition information, the user device 200a, the in-store device 200b, the server device 100, and the provider device 300 execute the processing within the upper part of the area indicated by the combined fragment alt2 (alternative2). Specifically, the in-store device 200b accepts an input operation of the secondary information of the comparison target from the user (S32). The in-store device 200b executes a secondary process of user authentication, such as comparing the accepted secondary information of the comparison target with the acquired secondary information of the comparison source (S33).

[0081] If the user authentication is successful as a result of the secondary processing, the user device 200a, the in-store device 200b, the server device 100, and the provider device 300 execute the processing within the upper part of the area indicated by the combined fragment alt3 (alternative3). Specifically, the in-store device 200b executes a confirmation process to confirm the details of the transaction indicated in the transaction information based on the acquired transaction permission information (S34). The in-store device 200b transmits to the server device 100 secondary processing result information indicating that the user authentication was successful as a result of the secondary processing, and transaction information indicating the result of the confirmation process it executed (S35). The payment processing unit of the server device 100 executes a payment process to settle the transaction using the user's available payment method based on the transmitted secondary processing result information and transaction information and the user's payment method information stored in the storage unit 130 as an online wallet function (S36). The transmission unit 121 of the server device 100 transmits payment processing result information indicating the result of the payment processing to the in-store device 200b (S37). The in-store device 200b outputs the result of the payment process indicated by the transmitted payment process result information on a screen or the like (S38).

[0082] If user authentication fails as a result of the secondary processing, the user device 200a, the in-store device 200b, the server device 100, and the provider device 300 execute the processing in the upper part of the area indicated by the combined fragment alt3. Specifically, the in-store device 200b outputs a message on a screen or the like indicating that user authentication has failed (S39).

[0083] If the transaction satisfies the transaction conditions indicated in the acquired transaction condition information, the user device 200a, the in-store device 200b, the server device 100, and the provider device 300 execute the processing in the lower part of the area indicated by the combined fragment alt2. Specifically, the in-store device 200b outputs an error message indicating that the transaction is not possible on a screen or the like (S40).

[0084] <5. Hardware Configuration> 6, an example of a hardware configuration in which the above-described server device 100 is realized by a computer 800 will be described. Note that the functions of each device can also be realized by dividing them into multiple devices.

[0085] As shown in FIG. 6, the computer 800 includes a processor 801, a memory 803, a storage device 805, an input I / F unit 807, a data I / F unit 809, a communication I / F unit 811, and a display device 813.

[0086] The processor 801 controls various processes in the computer 800 by executing programs stored in the memory 803. For example, each functional unit included in the control unit 110 of the server device 100 can be realized by the processor 801 executing a program temporarily stored in the memory 803.

[0087] The memory 803 is a storage medium such as a RAM (Random Access Memory), etc. The memory 803 temporarily stores the program code of the program executed by the processor 801 and data required when the program is executed.

[0088] The storage device 805 is a non-volatile storage medium such as a hard disk drive (HDD) or flash memory. The storage device 805 stores an operating system and various programs for implementing the above-mentioned configurations. In addition, the storage device 805 can also store tables for registering various information such as user information, and a DB for managing the tables. Such programs and data are loaded into the memory 803 as needed and can be referenced by the processor 801.

[0089] The input I / F unit 807 is a device for receiving input from a user. Specific examples of the input I / F unit 807 include a keyboard, a mouse, a touch panel, various sensors, and a wearable device. The input I / F unit 807 may be connected to the computer 800 via an interface such as a USB (Universal Serial Bus).

[0090] The data I / F unit 809 is a device for inputting data from outside the computer 800. A specific example of the data I / F unit 809 is a drive device for reading data stored in various storage media. The data I / F unit 809 may be provided outside the computer 800. In this case, the data I / F unit 809 is connected to the computer 800 via an interface such as a USB.

[0091] The communication I / F unit 811 is a device for performing data communication via the Internet N, either wired or wirelessly, with devices external to the computer 800. The communication I / F unit 811 may be provided outside the computer 800. In this case, the communication I / F unit 811 is connected to the computer 800 via an interface such as a USB.

[0092] The display device 813 is a device for displaying various types of information. Specific examples of the display device 813 include a liquid crystal display, an organic EL (Electro-Luminescence) display, and a display of a wearable device. The display device 813 may be provided outside the computer 800. In this case, the display device 813 is connected to the computer 800 via, for example, a display cable. Furthermore, when a touch panel is adopted as the input I / F unit 807, the display device 813 can be configured as an integral part of the input I / F unit 807.

[0093] It should be noted that the present embodiment is an example for explaining the present invention, and is not intended to limit the present invention to only this embodiment. Furthermore, the present invention can be modified in various ways without departing from the gist of the present invention. Furthermore, those skilled in the art can adopt embodiments in which the elements described below are replaced with equivalents, and such embodiments are also within the scope of the present invention.

[0094] The components of the server device described in the above embodiment are assumed to be implemented in cooperation with other hardware by the processor 801 executing a program stored in the storage device 805. In other words, these components can be considered as software or firmware, or as corresponding hardware, and in both of these concepts, they can also be described as "functions," "means," "parts," "processing circuits," "units," or "modules," and can be interpreted as such.

[0095] [Variations] Although the present invention has been described based on the above embodiment, the following cases are also included in the present invention.

[0096] [Variation 1] Although not shown in the above embodiment, a detection device may detect people, including people other than the user, who enter a store that uses or provides an integrated service, and identify the user from among the detected people. In this example, the first device is a detection device for detecting users who enter the store. The detection device, for example, detects the belongings or living bodies of each person in or near the store. Based on the detection results, the detection device generates possession information about the detected possessions or biometric information about the living bodies, and transmits this to the server device 100. The server device 100 obtains the transmitted possession information or biometric information. Based on the obtained possession information or biometric information, the server device 100 may identify the user from among people in or near the store and authenticate the identified user.

[0097] The linked service may include, for example, a face-to-face service in a store. In this case, the acquisition unit 114 may acquire, for example, possession information regarding possessions of each person in the store or near the store and / or biometric information regarding each person's living body. The control unit 110 of the server device 100 may also include, for example, an identification unit (not shown), which identifies the user from among people in the store or near the store based on user information regarding the user, possession information, and / or biometric information. The primary authentication unit 113a may perform primary processing for the user identified by the identification unit, for example, even if the acceptance unit 111 does not accept an authentication request from the first device.

[0098] According to the above configuration, in face-to-face services at a store, the detection device can automatically detect a user who enters the store and execute primary processing without the user having to manually request authentication on the user device 200a or the like. This improves usability for users. In particular, when biometric authentication such as facial recognition of the user is used as primary authentication, there is a possibility that people other than the user may be detected. Even in such cases, the user can be identified and authenticated.

[0099] The transmitting unit 121 may, for example, transmit to the provider device 300 an acquisition request requesting acquisition of primary information of the user identified by the identification unit. The acquiring unit 114 may, for example, acquire the primary information from the provider device 300 as a response to the acquisition request. The primary authentication unit 113a may execute primary processing for authenticating the identified user based on the acquired primary information. With this configuration, even if the server device 100 does not hold the primary information of the identified user, the primary information can be acquired as needed, such as when the user enters a store. This makes it possible to strengthen security (particularly confidentiality) for the primary information.

[0100] [Variation 2] In the above embodiment, an example has been described in which the primary processing involves (a) identifying a user and (b) authenticating the identified user based on the primary information of the user's matching target included in the user authentication request. However, the primary processing of the present invention is not limited to this. The primary processing may, for example, only identify the above-mentioned (a) user or its candidates (hereinafter also referred to as "user candidates"). For example, the identification unit of the server device 100 identifies one or more people detected by the detection device as user candidates. The acquisition unit 114 transmits a request to acquire secondary information from the provider device 300 for the identified one or more user candidates and acquires the secondary information as the acquisition request. The identification unit may identify a user candidate from whom secondary information has been acquired (i.e., a candidate whose secondary information is stored in the provider device 300 as a user of the linked service) as a user. The provision unit 112 may then provide the acquired secondary information to a second device that executes secondary processing for authenticating the identified user.

[0101] For example, when a face authentication sensor or the like is used as a detection device, the server device 100 may be able to acquire biometric information such as a user's face image from the detection device, but may not be able to acquire information that can identify the user (e.g., user identification information). Furthermore, in biometric authentication using the user's biometric information, the user may not be uniquely identified. According to the above configuration, even in such a case, if the user's secondary information can be acquired from the provider device 300, the secondary information can be provided to the second device, enabling user authentication. This can improve usability for users.

[0102] [Variation 3] At least some of the components included in the server device 100 according to the above embodiment may be included in a first device such as the user device 200a, a second device such as the store device 200b, and / or the provider device 300.

[0103] [Variation 4] In the above embodiment, an example was described in which a secondary process was executed to authenticate a user when a transaction in the linked service was made, but the authentication system according to the present invention can also be applied to cases in which no transaction occurs in the linked service. For example, if the linked service is an access control service, when this access control service manages access to a specified building and / or a specified area, authentication system 1 may be used to authenticate users who are allowed to enter and exit the building and / or a specified area.

[0104] The authentication system according to the present invention can also be applied to, for example, authentication of contractual actions that do not involve payment. The linked service may be, for example, a service related to a contractual action that does not involve payment, such as a points transaction service, a remittance transaction service, and / or a service related to the exchange of coupons.

[0105] [Variation 5] In the above embodiment, the following two methods (A) and (B) have been described as examples for determining whether or not a transaction is permitted, but these two methods may be used selectively depending on the situation. (A) The upper provider device 300 determines whether the transaction is permitted and transmits transaction propriety information indicating the determination result to the second device on the edge side via the server device 100. The second device executes the transaction processing according to the propriety of the transaction indicated by the transaction propriety information. (a) The transaction condition information is transmitted to the second device on the edge side, and the second device determines whether or not to accept the transaction based on the transaction conditions indicated by the transaction condition information.

[0106] As an example of selectively using the above two methods (A) and (B) depending on the situation, for example, when the server device 100 executes a primary process and transmits primary process result information of the primary process to the provider device 300, the server device 100 may issue an acquisition request to acquire transaction information from a second device that executes transaction processing of a transaction in the linked service. In response to this acquisition request, if the transaction information cannot be acquired because it has not yet been accepted by the second device, or if the transaction information can be acquired but the transaction processing status of the transaction information is not "processing completed (of confirmation processing)," the server device 100 may select and execute the above method (B). On the other hand, if the transaction information can be acquired and the transaction processing status of the transaction information is "processing completed (of confirmation processing)," the server device 100 may select and execute the above method (A). With this configuration, an efficient method can be selected depending on the status of the transaction processing, such as having a higher-level device determine whether or not to accept the transaction, or having a second device on the edge side determine whether or not to accept the transaction using transaction conditions.

[0107] [Variation 6] In the above embodiment, a face-to-face service for conducting face-to-face transactions has been described as an example of one of the linked services, but the transactions of the present invention are not limited thereto. The transactions of the present invention may be, for example, transactions of online services provided online. The online services may be, for example, social networking services such as the Metaverse and / or e-commerce services. When the authentication system of the present invention is applied to transactions of online services, the second device that performs the secondary processing may be (a) a user device used by a user (in this case, the first device and the second device may be the same device), or (b) a device that performs transaction processing of online transactions other than the server device 100 (hereinafter also referred to as a "transaction device"). For example, the server device 100 may provide secondary information for performing the secondary processing to a user device or a transaction device that performs secondary processing for user authentication based on the result of the primary processing. The user device or the transaction device performs the secondary processing based on the provided secondary information. [Explanation of symbols]

[0108] 1...authentication system, 100...server device, 110...control unit, 111...reception unit, 112...providing unit, 113...authentication unit, 114...acquisition unit, 115...payment processing unit, 116...identity verification unit, 117...registration unit, 120...communication unit, 130...storage unit, 200a...user device, 200b...store device, 300...provider device, 800...computer, 801...processor, 803...memory, 805...storage device, 807...input I / F unit, 809...data I / F unit, 811...communication I / F unit, 813...display device.

Claims

1. On the computer, a reception function for receiving an authentication request for authenticating a user of the service from the first device; a primary authentication function that executes a primary process for authenticating the user in response to the authentication request based on primary information for executing the primary process; a providing function of providing secondary information for executing a secondary process to a second device that executes a secondary process for authenticating the user based on a result of the primary process, the providing function, when user authentication is successful as a result of the primary processing, provides the secondary information to the second device regardless of whether a transaction order of the user in the service has been accepted by the second device; the reception function receives the authentication request for authenticating the user of the service from the first device via the second device; program.

2. the second device executes transaction processing related to the user's transaction in the service; the providing function provides primary processing result information indicating a result of the primary processing to a provider device of a provider of the service; causing the computer to realize an acquisition function of acquiring, from the provider device, transaction propriety information indicating whether the transaction is propriety or not, which information is provided in accordance with the primary processing result information; the providing function provides the secondary information to the second device depending on whether the transaction is possible or not indicated by the transaction possibility information. The program according to claim 1.

3. the acquisition function acquires the secondary information provided in response to the primary processing result information from the provider device, The providing function provides the acquired secondary information to the second device. The program according to claim 2.

4. The computer is caused to realize an acquisition function of acquiring transaction condition information indicating transaction conditions for determining whether or not a transaction for the service is possible from a provider device of the service provider, the providing function provides the second device with the transaction terms information; the second device executes transaction processing for the transaction based on the transaction condition information; The program according to claim 1.

5. the reception function, when the second device cannot determine that the transaction is possible under the transaction conditions, receives from the second device a higher-level determination request requesting a determination of whether the transaction is possible; causing the computer to realize a transmission function of transmitting the higher-level determination request to the provider device; the acquiring function acquires, from the provider device, higher-level determination result information indicating a result of the determination as a response to the higher-level determination request; the providing function provides the higher-level determination result information to the second device; the second device executes a transaction process for the transaction based on the higher-level determination result information. The program according to claim 4.

6. the acquiring function acquires, when the transaction conditions indicate that the transaction is permitted on the condition that additional authentication of the user is performed, additional authentication information for performing the additional authentication from the provider device; causing the computer to realize a transmission function of transmitting the acquired additional authentication information to the second device; The program according to claim 4.

7. the second device executes a confirmation process to confirm the content of the transaction for the service based on the result of the secondary process; causing the computer to realize an acquisition function of acquiring, from the second device, secondary processing result information indicating a result of the secondary processing and transaction information indicating a result of the confirmation processing; and a payment processing function that executes a payment process for settling the transaction by the payment means based on payment means information related to the payment means available to the user, the secondary processing result information, and the transaction information. The program according to claim 1.

8. The service includes face-to-face service at a store, an acquisition function for acquiring personal belongings information about personal belongings of each person in the store or near the store and / or biometric information about each person; an identification function for identifying the user from among people present in or near the store based on user information about the user, the belongings information, and / or the biometric information; the primary authentication function executes the primary processing for the identified user even if the reception function does not receive the authentication request. The program according to claim 1.

9. causing the computer to realize a transmission function of transmitting an acquisition request to a provider device of the service provider, the acquisition request requesting acquisition of the primary information of the specified user; the acquisition function acquires the primary information from the provider device in response to the acquisition request; The primary authentication function executes the primary processing based on the acquired primary information. The program according to claim 8.

10. a reception unit that receives an authentication request for authenticating a user of the service from the first device; a primary authentication unit that executes a primary process for authenticating the user based on primary information in response to the authentication request; a providing unit that provides secondary information for executing a secondary process to a second device that executes a secondary process for authenticating the user based on a result of the primary process, the providing unit, when user authentication is successful as a result of the primary processing, provides the secondary information to the second device regardless of whether a transaction order of the user in the service has been accepted by the second device; the reception unit receives the authentication request for authenticating the user of the service from the first device via the second device; Information processing device.

11. The computer receiving an authentication request for authenticating a user of the service from the first device; In response to the authentication request, a primary process is performed based on primary information for performing the primary process for authenticating the user; providing secondary information for executing a secondary process to a second device that executes a secondary process for authenticating the user based on a result of the primary process; If the user authentication is successful as a result of the primary processing, the secondary information is provided to the second device regardless of whether the second device has accepted the user's transaction order for the service; When receiving the authentication request, the authentication request for authenticating the user of the service is received from the first device via the second device. Information processing methods.

Citation Information

Patent Citations

  • Computer program and payment method

    JP2019061472A

  • Settlement system, first settlement server, second settlement server, computer program, and settlement method

    JP2020135742A

  • Two-factor authentication system, two-factor authentication method, two-factor authentication program, and authentication operation application

    JP2021144598A

  • JPP6928694B

  • JPP7036300B