Authentication system, authentication system operation method, authentication system operation program

The authentication system provides a decentralized, immediate, and user-friendly ID card issuance and verification process by printing authentication codes and facial images, addressing the limitations of mobile-dependent systems.

JP7750882B2Active Publication Date: 2025-10-07FUJIFILM CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022578324
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-01-26
Filing Date
2022-01-21
Publication Date
2025-10-07
Estimated Expiration
2042-01-21

AI Technical Summary

Technical Problem

Existing authentication systems that rely on displaying authentication codes on mobile devices are inaccessible to users without a mobile device or those unfamiliar with its use, and cannot function in environments without communication connectivity.

Method used

An authentication system that issues an ID card with a printed authentication code and facial image, using a digital camera with printer to capture and print facial features, and a separate authentication terminal to decrypt and compare facial feature information for verification.

Benefits of technology

Enables convenient authentication for all users, including those without mobile devices, in various environments, and allows immediate issuance and verification of ID cards without network-dependent central management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007750882000001
    Figure 0007750882000001
  • Figure 0007750882000002
    Figure 0007750882000002
  • Figure 0007750882000003
    Figure 0007750882000003
Patent Text Reader

Abstract

This authentication system is provided with a processor and a memory connected to or built into the processor, wherein the processor has a first processor responsible for a card-issuing task in which an ID card is issued for a user, and a second processor responsible for an authentication task in which the ID card is used to determine whether the user is authenticated as a legitimate user. As the card-issuing task, the first processor acquires a first facial image of the user, extracts first facial feature information from the first facial image, generates an authentication code representing the first facial feature information, and generates an ID card by printing the authentication code and a facial image for display of the user on a card medium by means of a printer. As the authentication task, the second processor acquires the authentication code printed on the ID card held by the user, and a second facial image of the user, decodes the first facial feature information from the authentication code, extracts second facial feature information from the second facial image with the same algorithm used when the first facial feature information was extracted from the first facial image, compares the first facial feature information and the second facial feature information, and makes a determination on the basis of the comparison result.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to an authentication system, an operation method of an authentication system, and an operation program of an authentication system. [Background technology]

[0002] Japanese Patent Laid-Open Publication No. 2014-222445 describes an authentication system that authenticates a user using an authentication code representing facial feature information extracted from a user's facial image. In the authentication system described in Japanese Patent Laid-Open Publication No. 2014-222445, the authentication code is transmitted to the user's mobile terminal and displayed on a display unit of the mobile terminal. The displayed authentication code and a facial image of the user are then photographed, and the facial feature information decoded from the photographed authentication code is compared with the facial feature information extracted from the photographed facial image to perform authentication. Summary of the Invention [Problem to be solved by the invention]

[0003] As mentioned above, in JP 2014-222445 A, an authentication code is sent to the user's mobile device and displayed on the display of the mobile device. This makes it difficult to use for people who do not own a mobile device or who own a mobile device but are unfamiliar with it. Furthermore, authentication cannot be performed in situations where a mobile device cannot be used, such as in places where a communication environment is not established.

[0004] One embodiment of the technique of the present disclosure provides a highly convenient authentication system, an operation method for the authentication system, and an operation program for the authentication system. [Means for solving the problem]

[0005] The authentication system disclosed herein includes a processor and a memory connected to or built in the processor, and the processor has a first processor that handles a card issuance task of issuing an ID card to a user, and a second processor that handles an authentication task of using the ID card to determine whether or not to authenticate the user as a legitimate user. As the card issuance task, the first processor acquires a first facial image of the user, extracts first facial feature information from the first facial image, generates an authentication code representing the first facial feature information, and creates an ID card by printing the authentication code and the user's display facial image on card media using a printer. As an authentication task, the second processor acquires the authentication code printed on an ID card held by the user and a second facial image of the user, decrypts the first facial feature information from the authentication code, extracts second facial feature information from the second facial image using the same algorithm as when the first facial feature information was extracted from the first facial image, compares the first facial feature information with the second facial feature information, and makes a determination based on the comparison result.

[0006] The ID card is provided with first identification information indicating that it was issued by a card issuance task, and if the first identification information is invalid, the second processor preferably determines that the user is not a legitimate user regardless of the matching result.

[0007] For a user attempting to be authenticated for the first time, the second processor preferably accepts input of second identification information indicating that a qualified person has confirmed that the ID card was issued by the card issuance task.

[0008] It is preferable that the second processor stores third identification information in a memory unit, which indicates that the ID card was issued by the card issuance task, and invalidates the third identification information for a user who has lost his or her status as a legitimate user.

[0009] The first facial image is preferably an image that satisfies a predetermined standard. The display facial image is preferably the first facial image. The display facial image is preferably an image that is not restricted by the standard.

[0010] Preferably, the first processor controls the operation of the digital camera with printer to cause the digital camera with printer to take the first facial image and print the authentication code and the display facial image on card media.

[0011] The operation method of the authentication system disclosed herein carries out a card issuance task of issuing an ID card to a user and an authentication task of using the ID card to determine whether or not to authenticate the user as a legitimate user, and includes the card issuance task of acquiring a first facial image of the user, extracting first facial feature information from the first facial image, generating an authentication code representing the first facial feature information, and printing the authentication code and the user's display facial image on card media using a printer to create an ID card.The authentication task includes acquiring the authentication code printed on an ID card held by the user and a second facial image of the user, decrypting the first facial feature information from the authentication code, extracting the second facial feature information from the second facial image using the same algorithm as when the first facial feature information was extracted from the first facial image, comparing the first facial feature information with the second facial feature information, and making a determination based on the comparison result.

[0012] The operating program of the authentication system disclosed herein performs a card issuance task of issuing an ID card to a user and an authentication task of using the ID card to determine whether or not to authenticate the user as a legitimate user. The operating program causes a computer to execute processes for the card issuance task, including acquiring a first facial image of the user, extracting first facial feature information from the first facial image, generating an authentication code representing the first facial feature information, and printing the authentication code and the user's display facial image on card media using a printer to create an ID card. The operating program causes the computer to execute processes for the authentication task, including acquiring an authentication code printed on an ID card held by the user and a second facial image of the user, decrypting the first facial feature information from the authentication code, extracting the second facial feature information from the second facial image using the same algorithm as when the first facial feature information was extracted from the first facial image, comparing the first facial feature information with the second facial feature information, and making a determination based on the comparison result. [Effects of the Invention]

[0013] According to the technology of the present disclosure, it is possible to provide a highly convenient authentication system, an operation method for an authentication system, and an operation program for an authentication system. [Brief explanation of the drawings]

[0014] [Figure 1] FIG. 1 illustrates an authentication system. [Figure 2] FIG. 1 is a diagram showing a digital camera with a built-in printer. [Figure 3] FIG. 2 is a block diagram showing a computer that constitutes a card issuing terminal and an authentication terminal. [Figure 4] FIG. 2 is a diagram illustrating a processing unit of a CPU of a card issuing terminal. [Figure 5] 10A and 10B are diagrams illustrating processing when a control unit receives a shooting instruction from a touch panel display. [Figure 6] FIG. 10 is a diagram illustrating a process when a print instruction is received by a control unit from a touch panel display. [Figure 7]FIG. 2 is a diagram illustrating a processing unit of a CPU of the authentication terminal. [Figure 8] FIG. 10 is a diagram illustrating a process performed when the identification ID decrypted by the decryption unit matches the identification ID stored in the storage. [Figure 9] FIG. 10 is a diagram illustrating a process performed when the identification ID decrypted by the decryption unit does not match the identification ID stored in the storage. [Figure 10] FIG. 10 is a diagram illustrating a process performed when the decryption unit does not decrypt the identification ID from the authentication code. [Figure 11] FIG. 10 is a diagram showing a process when the collation result indicates that the first facial feature information and the second facial feature information match. [Figure 12] FIG. 10 is a diagram showing processing when the collation result indicates that the first facial feature information and the second facial feature information do not match. [Figure 13] 10 is a flowchart showing a processing procedure for a card issuance task by a CPU of the card issuance terminal. [Figure 14] 10 is a flowchart showing a processing procedure of an authentication task by a CPU of the authentication terminal. [Figure 15] 10 is a flowchart showing a processing procedure of an authentication task by a CPU of the authentication terminal. [Figure 16] FIG. 10 is a diagram illustrating an overview of a second embodiment. [Figure 17] FIG. 10 is a diagram illustrating an overview of a third embodiment. [Figure 18] FIG. 10 is a diagram showing a plurality of ID cards with different display face images. [Figure 19] FIG. 10 is a diagram showing another example of an ID card. DETAILED DESCRIPTION OF THE INVENTION

[0015] [First embodiment] As an example, as shown in Figure 1, authentication system 2 is a system that authenticates user 11 using ID (Identification) card 10. Authentication system 2 is made up of card issuing unit 12 and authentication unit 13. Card issuing unit 12 and authentication unit 13 operate independently (standalone), and no data is exchanged between them.

[0016] The card issuance unit 12 is used in the card issuance phase, which is the phase for issuing the ID card 10. The card issuance unit 12 is installed, for example, in a security room of a facility that has installed the authentication system 2. Facilities that have installed the authentication system 2 include shopping malls, buildings, companies, medical facilities, and research facilities. Here, a shopping mall called "Fuji Mall" is used as an example of an installed facility.

[0017] The authentication unit 13 is used in the authentication phase, which is a phase in which it is determined whether or not the user 11 is authenticated as an authorized user by the ID card 10. An authorized user is a user 11 who is permitted to enter and exit a facility that has the authentication system 2 installed. The authentication unit 13 is installed, for example, at the entrance side of the entrance and exit gate for authorized users.

[0018] The card issuing unit 12 includes a digital camera with printer 14 and a card issuing terminal 15. Under the control of the card issuing terminal 15, the digital camera with printer 14 takes a photograph of the face of a user 11, who will be working as a new employee at the facility where the card is being introduced, for example. The digital camera with printer 14 then prints the resulting first facial image 16 on an instant film 17 (see also FIG. 2 ). The digital camera with printer 14 also prints an authentication code 18 on the instant film 17 in addition to the first facial image 16. Here, a QR (Quick Response) Code (registered trademark) is used as the authentication code 18. The instant film 17, on which the first facial image 16, the authentication code 18, and the store name, facility name, etc. are printed, is then distributed to the user 11 as the ID card 10. The digital camera with printer 14 is an example of a "printer" according to the technology of the present disclosure. The instant film 17 is an example of a "card medium" according to the technology of the present disclosure. The first facial image 16 is an example of a "display facial image" according to the technology of the present disclosure.

[0019] The card issuing terminal 15 has a touch panel display 19. A guide screen that guides the user 11 in capturing the first facial image 16 is displayed on the touch panel display 19. The user 11 captures the first facial image 16 according to the guide screen. A through image captured by the digital camera with printer 14 is displayed on the guide screen. The guide screen also displays a frame indicating the position and size of the face according to preset standards, such as those for general ID photos, as well as important notices. The guide screen also displays input boxes for the store name and facility name to be printed on the ID card 10, a shooting instruction button that instructs the user to capture the first facial image 16, and other important notices. Examples of important notices include facing the user head-on, removing a hat, not wearing a mask or sunglasses, not covering the eyes with hair, not closing the eyes, and not shading the eyes. The shooting instruction button can be operated only when the user 11's face fits within the frame and all important notices are observed. Therefore, the first facial image 16 will be an image that meets the preset standards. Whether the first facial image 16 meets the standards may be determined by a dedicated application program.

[0020] After the photographing instruction button on the guide screen is operated to photograph the first facial image 16, a print instruction screen for instructing printing of the first facial image 16 etc. onto instant film 17 is displayed on the touch panel display 19. A sample image of the ID card 10 to be printed and a print instruction button for instructing printing of the first facial image 16 etc. are displayed on the print instruction screen.

[0021] The authentication unit 13 includes a code reader 20, an authentication camera 21, a security door 22, a speaker 23, and an authentication terminal 24. The code reader 20 reads the authentication code 18 from the ID card 10 of the user 11 who is to be authenticated. The authentication camera 21, under the control of the authentication terminal 24, captures a second facial image 95 (see FIG. 7) of the user 11 standing in front of it. The security door 22 is an automatic door that opens and closes the entrance and exit for authorized users, and is normally locked. The speaker 23 outputs audio related to authentication. The authentication terminal 24 is installed in a location away from the security door 22, for example, a security room.

[0022] When the user 11 approaches the security door 22, the speaker 23 outputs a voice guidance such as "Please hold the authentication code on your ID card over the code reader." Also, when the authentication code 18 is read by the code reader 20, the speaker 23 outputs a voice guidance such as "Please face the camera."

[0023] As an example, as shown in Figure 2, the digital camera with printer 14 has a rounded box-shaped main body 30 as a whole. The main body 30 is provided with a camera unit 31 for taking the first facial image 16, a printer unit 32 for printing the first facial image 16 and the like on instant film 17, and a film pack 33 for the instant film 17. The film pack 33 is replaceably loaded into the main body 30. The film pack 33 contains a plurality of unused instant film sheets 17, for example, ten sheets. An outlet 34 is formed at the top of the main body 30, through which the instant film sheets 17 on which the first facial image 16 and the like have been printed are ejected.

[0024] 3, the computers that make up card issuing terminal 15 and authentication terminal 24 basically have the same configuration, and include storage 40, memory 41, a CPU (Central Processing Unit) 42, and a communication unit 43. These are interconnected via a bus line 44.

[0025] Storage 40 is a hard disk drive built into the computer that constitutes card issuing terminal 15 and authentication terminal 24, or connected via a cable or network. Alternatively, storage 40 is a disk array consisting of multiple hard disk drives. Storage 40 stores control programs such as an operating system, various application programs, and various data associated with these programs. Note that a solid state drive may be used instead of a hard disk drive.

[0026] The memory 41 is a work memory for the CPU 42 to execute processing. The CPU 42 loads programs stored in the storage 40 into the memory 41 and executes processing in accordance with the programs. In this way, the CPU 42 comprehensively controls each part of the computer. The communication unit 43 is an interface that controls the transmission of various data with other devices.

[0027] In the following explanation, the parts of the computer that make up the card issuing terminal 15 are distinguished by adding the suffix "A" to the reference numerals, and the parts of the computer that make up the authentication terminal 24 are distinguished by adding the suffix "B" to the reference numerals.

[0028] As an example, as shown in FIG. 4, an operating program 50A is stored in storage 40A of card issuing terminal 15. Operating program 50A is an application program for causing a computer constituting card issuing terminal 15 to function as part of authentication system 2. In other words, operating program 50A is an example of an "authentication system operating program" according to the technology of the present disclosure. An identification ID 51 is also stored in storage 40A. Identification ID 51 is an example of "first identification information" according to the technology of the present disclosure.

[0029] When the operating program 50A is started, the CPU 42A of the computer constituting the card issuance terminal 15 works in cooperation with the memory 41 and the like to function as an acquisition unit 60, an extraction unit 61, a generation unit 62, and a control unit 63. The CPU 42A performs the card issuance task of issuing the ID card 10 using these processing units. In other words, the CPU 42A is an example of a "first processor" according to the technology of the present disclosure.

[0030] The acquisition unit 60 acquires the first facial image 16 from the digital camera with printer 14. The acquisition unit 60 outputs the first facial image 16 to the extraction unit 61.

[0031] The extraction unit 61 extracts first facial feature information 70 from the first facial image 16. More specifically, the extraction unit 61 identifies the facial area of ​​the user 11 appearing in the first facial image 16 and performs a well-known feature extraction process on the identified facial area. The feature extraction process extracts, for example, the sizes of each of the facial features, such as the eyebrows, eyes, nose, mouth, and ears, as the first facial feature information 70. The feature extraction process also extracts, as the first facial feature information 70, the positions of feature points of each facial feature, such as the end of the eyebrows, the inner corners and outer corners of the eyes, the tip of the nose, and the corners of the mouth, as well as the positional relationship between each facial feature, such as the distance between the inner corners of the eyes. The extraction unit 61 outputs the first facial feature information 70 to the generation unit 62.

[0032] The generation unit 62 receives the first facial feature information 70 from the extraction unit 61 and also receives the identification ID 51 from the storage 40A. The identification ID 51 is, for example, a facility ID of the facility where the authentication system 2 is installed, and is stored in the storage 40A when the authentication system 2 is installed. The generation unit 62 generates an authentication code 18 representing the first facial feature information 70 and the identification ID 51. The generation unit 62 encrypts the first facial feature information 70 and the identification ID 51 to generate the authentication code 18. The generation unit 62 outputs the authentication code 18 to the control unit 63. Note that the identification ID 51 may be the store ID of the store to which the user 11 belongs, or the device ID of the printer-equipped digital camera 14, or the like.

[0033] The control unit 63 controls the display of various screens on the touch panel display 19. The control unit 63 also accepts various instructions input via the touch panel display 19. The various instructions include an instruction 75 to capture the first facial image 16 via the capture instruction button on the guide screen (see FIG. 5), and an instruction 78 to print the first facial image 16, etc. via the print instruction button on the print instruction screen (see FIG. 6). The control unit 63 controls the operation of the digital camera with printer 14 in accordance with the various instructions.

[0034] 5, when the photographing instruction button on the guide screen is operated and a photographing instruction 75 is input from the touch panel display 19, the control unit 63 transmits a photographing instruction signal 76 to the digital camera with printer 14. When the photographing instruction signal 76 is received, the digital camera with printer 14 operates the camera unit 31 to photograph the first facial image 16.

[0035] 6, when the print instruction button on the print instruction screen is operated and a print instruction 78 is input from the touch panel display 19, the control unit 63 transmits a print instruction signal 79 to the digital camera with printer 14. The print instruction signal 79 includes the authentication code 18. When the digital camera with printer 14 receives the print instruction signal 79, it operates the printer unit 32 to print the first facial image 16, the authentication code 18, etc. on the instant film 17, and creates the ID card 10.

[0036] 7, an operating program 50B is stored in storage 40B of authentication terminal 24. Operating program 50B is an application program for causing a computer constituting authentication terminal 24 to function as part of authentication system 2. In other words, operating program 50B is an example of an "authentication system operating program" according to the technology of the present disclosure. Storage 40B stores an identification ID 51, just like storage 40A of card issuing terminal 15.

[0037] When the operating program 50B is started, the CPU 42B of the computer constituting the authentication terminal 24, in cooperation with the memory 41 and the like, functions as a first acquisition unit 85, a decryption unit 86, a second acquisition unit 87, an extraction unit 88, a matching unit 89, a determination unit 90, and a control unit 91. With these processing units, the CPU 42B is responsible for the authentication task of determining whether or not to authenticate the user 11 as a legitimate user using the ID card 10. In other words, the CPU 42B is an example of a "second processor" according to the technology of the present disclosure.

[0038] The first acquisition unit 85 acquires the authentication code 18 read by the code reader 20. The first acquisition unit 85 outputs the authentication code 18 to the decryption unit 86.

[0039] The decryption unit 86 decrypts the authentication code 18. The decryption unit 86 outputs first facial feature information 70D decrypted from the authentication code 18 to the matching unit 89. The decryption unit 86 also outputs the identification ID 51D decrypted from the authentication code 18 to the determination unit 90.

[0040] The second acquisition unit 87 acquires a second facial image 95 of the user 11 captured by the authentication camera 21. The second acquisition unit 87 outputs the second facial image 95 to the extraction unit 88.

[0041] The extraction unit 88 extracts second facial feature information 96 from the second facial image 95 using the same algorithm as when the extraction unit 61 of the card issuing terminal 15 extracted the first facial feature information 70 from the first facial image 16. The extraction unit 88 outputs the second facial feature information 96 to the matching unit 89.

[0042] The matching unit 89 matches the first facial feature information 70D decoded from the authentication code 18 by the decoding unit 86 with the second facial feature information 96 extracted from the second facial image 95 by the extraction unit 88. The matching unit 89 outputs a matching result 97 between the first facial feature information 70D and the second facial feature information 96 to the determination unit 90.

[0043] The determination unit 90 receives the identification ID 51 from storage 40B in addition to the identification ID 51D from the decryption unit 86 and the matching result 97 from the matching unit 89. The determination unit 90 determines whether or not to authenticate the user 11 as a legitimate user based on the matching result 97 and the identification IDs 51 and 51D. The determination unit 90 outputs a determination result 98 indicating whether or not to authenticate the user 11 as a legitimate user to the control unit 91.

[0044] The control unit 91 controls the operation of the authentication camera 21 to cause the authentication camera 21 to capture a second facial image 95. The control unit 91 also controls the locking and unlocking of the security door 22, as well as the opening and closing of the security door 22. Furthermore, the control unit 91 controls the operation of the speaker 23.

[0045] As an example, as shown in FIG. 8, if the identification ID 51D decrypted by the decryption unit 86 matches the identification ID 51 stored in the storage 40B, the determination unit 90 determines that the identification ID 51 is valid.

[0046] On the other hand, as shown in FIG. 9 as an example, when the ID 51D decrypted by the decryption unit 86 does not match the ID 51 stored in the storage 40B, the determination unit 90 determines that the ID 51 is inappropriate. Positive In this case, regardless of the collation result 97, the determination unit 90 outputs a determination result 98 indicating that the user 11 is not a legitimate user.

[0047] 10, if the identification ID 51 is not registered in the authentication code 18 and the decryption unit 86 does not decrypt the identification ID 51D from the authentication code 18, the determination unit 90 also determines that the identification ID 51 is inappropriate. Positive Then, the determination result 98 is output, indicating that the user 11 is not a legitimate user.

[0048] 11 , if the identification ID 51 is correct and the matching result 97 from the matching unit 89 indicates that the first facial feature information 70D and the second facial feature information 96 match, the determination unit 90 outputs a determination result 98 indicating that the user 11 is an authorized user. When the determination result 98 indicating that the user 11 is an authorized user is input from the determination unit 90, the control unit 91 transmits an unlock instruction signal 100 to the security door 22. When the unlock instruction signal 100 is received, the security door 22 unlocks and temporarily opens the entrance / exit gate.

[0049] As an example, as shown in FIG. 12, if the identification ID 51 is correct and the matching result 97 from the matching unit 89 indicates that the first facial feature information 70D and the second facial feature information 96 do not match, the determination unit 90 outputs a determination result 98 indicating that the user 11 is not a legitimate user. When the control unit 91 receives the determination result 98 indicating that the user 11 is not a legitimate user from the determination unit 90, the control unit 91 does not transmit anything to the security door 22, but instead transmits a warning audio output instruction signal 103 to the speaker 23. When the warning audio output instruction signal 103 is received, the speaker 23 outputs a warning audio such as "The ID card is invalid. You cannot enter." In this case, since nothing is transmitted to the security door 22, the security door 22 remains locked. As shown in FIG. 9, the identification ID 51D decoded by the decoding unit 86 does not match the identification ID 51 stored in the storage 40B, indicating that the identification ID 51 is invalid. Positive If the determination unit 90 determines that the identification ID 51 is invalid, the control unit 91 also transmits a warning sound output instruction signal 103 to the speaker 23. Also, if the decoding unit 86 does not decode the identification ID 51D from the authentication code 18 as shown in FIG. Positive Even if the determination unit 90 determines that the warning sound is not output, the control unit 91 transmits the warning sound output instruction signal 103 to the speaker 23. The warning sound may be a siren, a beep, or the like.

[0050] Next, the operation of the above configuration will be described with reference to the flowcharts shown in FIGS.

[0051] First, the procedure of the card issuance task performed by the CPU 42A of the card issuance terminal 15 will be described with reference to the flowchart shown in FIG.

[0052] When the operating program 50A is started in the card issuing terminal 15, the CPU 42A of the card issuing terminal 15 functions as an acquisition unit 60, an extraction unit 61, a generation unit 62, and a control unit 63, as shown in FIG.

[0053] 5, when the photographing instruction button on the guide screen is operated, control unit 63 accepts photographing instruction 75 (YES in step ST100). As a result, control unit 63 transmits photographing instruction signal 76 to digital camera with printer 14, and first facial image 16 of user 11 is captured by camera unit 31 of digital camera with printer 14 (step ST110). First facial image 16 is transmitted from digital camera with printer 14 to card issuing terminal 15.

[0054] The first facial image 16 from the digital camera with printer 14 is input to and acquired by the acquisition unit 60 (step ST120). The first facial image 16 is output from the acquisition unit 60 to the extraction unit 61.

[0055] The extraction unit 61 extracts the first facial feature information 70 from the first facial image 16 (step ST130). The first facial feature information 70 is output from the extraction unit 61 to the generation unit 62.

[0056] The generation unit 62 generates the authentication code 18 representing the first facial feature information 70 and the identification ID 51 (step ST140). The generation unit 62 outputs the authentication code 18 to the control unit 63.

[0057] 6, when the print instruction button on the print instruction screen is operated, the control unit 63 accepts the print instruction 78 (YES in step ST150). This causes the control unit 63 to send a print instruction signal 79 to the digital camera with printer 14, and the printer unit 32 of the digital camera with printer 14 prints the first facial image 16, the authentication code 18, etc. on the instant film 17, creating the ID card 10 (step ST160). The ID card 10 is distributed to the user 11.

[0058] Next, the procedure of the authentication task performed by the CPU 42B of the authentication terminal 24 will be described with reference to the flowcharts shown in FIGS.

[0059] When the operating program 50B is started in the authentication terminal 24, as shown in Figure 7, the CPU 42B of the authentication terminal 24 functions as a first acquisition unit 85, a decryption unit 86, a second acquisition unit 87, an extraction unit 88, a matching unit 89, a judgment unit 90, and a control unit 91.

[0060] When the user 11 holds the authentication code 18 of the ID card 10 over the code reader 20 and the authentication code 18 is read by the code reader 20 (YES in step ST200), the authentication code 18 is input to and acquired by the first acquisition unit 85 (step ST210). The authentication code 18 is output from the first acquisition unit 85 to the decryption unit 86.

[0061] The decryption unit 86 decrypts the authentication code 18 (step ST220). The first facial feature information 70D decrypted from the authentication code 18 is output from the decryption unit 86 to the matching unit 89. Furthermore, the identification ID 51D decrypted from the authentication code 18 is output from the decryption unit 86 to the determination unit 90.

[0062] 8, if the identification ID 51D decrypted by the decryption unit 86 matches the identification ID 51 stored in the storage 40B, the determination unit 90 determines that the identification ID 51 is valid (YES in step ST230). In this case, the control unit 91 activates the authentication camera 21, and a second face image 95 of the user 11 is captured (step ST240).

[0063] The second facial image 95 is input to and acquired by the second acquisition unit 87 (step ST250). The second facial image 95 is output from the second acquisition unit 87 to the extraction unit 88.

[0064] The extraction unit 88 extracts the second facial feature information 96 from the second facial image 95 (step ST260). The second facial feature information 96 is output from the extraction unit 88 to the matching unit 89.

[0065] The matching unit 89 matches the first facial feature information 70D decoded from the authentication code 18 by the decoding unit 86 with the second facial feature information 96 extracted from the second facial image 95 by the extraction unit 88 (step ST270). A matching result 97 is output from the matching unit 89 to the determination unit 90.

[0066] 11, when the matching result 97 indicates that the first facial feature information 70D and the second facial feature information 96 match (YES in step ST280), the determination unit 90 determines that the user 11 is a legitimate user (step ST290). In this case, the determination unit 90 outputs a determination result 98 indicating that the user 11 is a legitimate user to the control unit 91.

[0067] When the control unit 91 receives a determination result 98 indicating that the user 11 is an authorized user, the control unit 91 transmits an unlock instruction signal 100 to the security door 22. This unlocks the security door 22, temporarily opening the entrance / exit gate (step ST300).

[0068] 9, if the identification ID 51D decrypted by the decryption unit 86 does not match the identification ID 51 stored in the storage 40B, the determination unit 90 determines that the identification ID 51 is inappropriate (NO in step ST230). Also, as shown in FIG. 10, if the decryption unit 86 does not decrypt the identification ID 51D from the authentication code 18, the determination unit 90 determines that the identification ID 51 is inappropriate (NO in step ST230). In these cases, the determination unit 90 determines that the user 11 is not an authorized user (step ST310). Then, the determination unit 90 outputs a determination result 98 indicating that the user 11 is not an authorized user to the control unit 91.

[0069] 12, when the matching result 97 indicates that the first facial feature information 70D and the second facial feature information 96 do not match (NO in step ST280), the determination unit 90 also determines that the user 11 is not a legitimate user (step ST310). Then, a determination result 98 indicating that the user 11 is not a legitimate user is output from the determination unit 90 to the control unit 91.

[0070] When the control unit 91 receives a determination result 98 indicating that the user 11 is not a legitimate user, the control unit 91 transmits a warning sound output instruction signal 103 to the speaker 23. This causes the speaker 23 to output a warning sound (step ST320).

[0071] As described above, the CPU 42A of the card issuing terminal 15 includes an acquisition unit 60, an extraction unit 61, a generation unit 62, and a control unit 63. The acquisition unit 60 acquires the first facial image 16 of the user 11. The extraction unit 61 extracts first facial feature information 70 from the first facial image 16. The generation unit 62 generates an authentication code 18 representing the first facial feature information 70. The control unit 63 causes the digital camera 14 with a printer to print the authentication code 18 and the first facial image 16 on instant film 17, thereby creating the ID card 10.

[0072] The CPU 42B of the authentication terminal 24 also includes a first acquisition unit 85, a decryption unit 86, a second acquisition unit 87, an extraction unit 88, a matching unit 89, and a determination unit 90. The first acquisition unit 85 acquires the authentication code 18 printed on the ID card 10 carried by the user 11. The decryption unit 86 decrypts the first facial feature information 70D from the authentication code 18. The second acquisition unit 87 acquires a second facial image 95 of the user 11. The extraction unit 88 extracts second facial feature information 96 from the second facial image 95 using the same algorithm as used to extract the first facial feature information 70 from the first facial image 16. The matching unit 89 matches the first facial feature information 70D with the second facial feature information 96. The determination unit 90 determines whether to authenticate the user 11 as a legitimate user based on a matching result 97 from the matching unit 89.

[0073] Therefore, unlike the authentication system described in JP 2014-222445 A, which displays an authentication code on the display unit of a mobile device, the authentication system 2 of the present disclosure allows even users 11 who do not own a mobile device or users 11 who own a mobile device but are unfamiliar with using it to be authenticated. This makes it possible to realize the social inclusion that has been advocated in recent years (i.e., protecting all people from loneliness, isolation, exclusion, and friction, and embracing and supporting each other as members of society to lead to the realization of healthy and cultured lives). Furthermore, authentication can be performed even in situations where a mobile device cannot be used. Therefore, it can be said that the authentication system 2 of the present disclosure is more convenient than the authentication system described in JP 2014-222445 A.

[0074] Card issuing unit 12 and authentication unit 13 operate independently. Therefore, unlike conventional authentication systems, there is no need for a server that connects to card issuing terminal 15 and authentication terminal 24 via a network and centrally manages the IDs of authorized users. This also saves the trouble of matching the IDs of all authorized users stored in the server with the ID of user 11 attempting to be authenticated.

[0075] The card issuing unit 12 has a simple configuration consisting of a digital camera 14 with a printer and a card issuing terminal 15. Therefore, there are no restrictions on the installation location and it can be installed in a small space. Therefore, by installing card issuing units 12 in multiple locations, it is possible to issue ID cards 10 in a decentralized manner at multiple locations.

[0076] Furthermore, the control unit 63 controls the operation of the printer-equipped digital camera 14, causing the printer-equipped digital camera 14 to take a first facial image 16 and print the authentication code 18 and the first facial image 16 on the instant film 17. Therefore, unlike conventional authentication systems, it does not take several days to issue an ID card 10, and the ID card 10 can be immediately issued at the location where the card issuing unit 12 is installed and distributed to the user 11.

[0077] The ID card 10 is designed so that only the user 11 can be authenticated as a legitimate user. For this reason, multiple ID cards 10 can be issued. Furthermore, if the ID card 10 is lost, a conventional authentication system requires a complicated procedure to make the ID card 10 unusable, but in this example, such a procedure is not necessary. The ID card 10 can simply be reissued. If the ID card 10 is forgotten, the ID card 10 can be reissued on the spot.

[0078] An identification ID 51 indicating that the ID card 10 was issued by a card issuance task of the CPU 42A of the card issuance terminal 15 is attached to the ID card 10. As shown in Figures 9 and 10, if the identification ID 51 is incorrect, the determination unit 90 determines that the user 11 is not a legitimate user regardless of the matching result 97. This makes it possible to avoid erroneously determining that a user 11 who belongs to a facility other than the facility where the authentication system 2 is installed, or a user 11 who attempts to be authenticated with an ID card 10 that was not issued by the card issuance task, such as a counterfeit ID card 10, is a legitimate user.

[0079] The first facial image 16 is an image that meets a predetermined standard. Therefore, it is possible to extract first facial feature information 70 suitable for authentication. In addition, the first facial image 16 is printed on the ID card 10 as a facial image for display. Therefore, it is possible to immediately compare the face of the user 11 with the first facial image 16, and it is easy to detect any impersonation of the user 11.

[0080] For users 11 who have lost their authorized user status, such as retirees or employees of a closed store, the ID card 10 is collected from the users 11 when they leave work on the day they lose their authorized user status. For employees of closed stores, the identification ID 51 may include the store ID, and users 11 who have the store ID of a closed store registered in the authentication code 18 may be excluded by determining that they are not authorized users.

[0081] Instead of, or in addition to, outputting a warning sound from the speaker 23, a display unit may be provided, for example, on the top of the security door 22, to display symbols or letters representing the judgment result 98, such as "◯" or "OK", "×" or "NG (No Good)", etc.

[0082] [Second embodiment] In the first embodiment, the identification ID 51 indicating that the ID card 10 has been issued by a card issuance task is added to the ID card 10, but this is not limiting. As a method for ensuring that the ID card 10 has been issued by a card issuance task, the second embodiment shown in Fig. 16 may be adopted.

[0083] 16 as an example, in the second embodiment, a reception unit 110 is configured in addition to the processing units 85 to 91 of the first embodiment in the CPU 42B of the authentication terminal 24. Then, new employee information 111, which is information about a new employee who will be working at the introducing facility, is sent in advance to a security guard 112 of the introducing facility. The new employee information 111 includes a first facial image 16, name, and affiliated store of the new employee user 11.

[0084] When a new employee user 11 who is about to be authenticated for the first time comes to work for the first time, a security guard 112 stands in front of the authentication unit 13 and compares the new employee information 111 with the face of the user 11 and the ID card 10 possessed by the user 11. Then, depending on the circumstances, the security guard 112 may ask the user 11 to submit a driver's license or other document that can verify the user's name, and visually confirms that the user 11 is a person registered in the new employee information 111.

[0085] If the security guard 112 determines through visual confirmation that the user 11 is a person registered in the new employee information 111, the security guard 112 inputs confirmed information 113 into the authentication terminal 24. The confirmed information 113 includes an authentication code 18 read by a code reader 20 from an ID card 10 carried by the new employee user 11. On the other hand, if the security guard 112 determines through visual confirmation that the user 11 is not a person registered in the new employee information 111, the security guard 112 takes appropriate action, such as urging the user 11 to leave. The security guard 112 is an example of a "qualified person" according to the technology of the present disclosure. The confirmed information 113 is an example of "second identification information" according to the technology of the present disclosure.

[0086] The reception unit 110 receives the confirmed information 113. The reception unit 110 registers the confirmed information 113 in a confirmed list 114 of the storage 40B. The confirmed list 114 registers the authentication code 18 included in the confirmed information 113, the second facial image 95 captured by the authentication camera 21, and the registration date. Note that the second facial image 95 does not have to be registered.

[0087] When performing authentication after the initial authentication, the determination unit 90 searches whether the authentication code 18 acquired by the first acquisition unit 85 is registered in the confirmed list 114. If the authentication code 18 acquired by the first acquisition unit 85 is registered in the confirmed list 114, the determination unit 90 determines that the ID card 10 has been issued by a card issuance task, as in the case of the identification ID 51 in the first embodiment.

[0088] If the authentication code 18 acquired by the first acquisition unit 85 has not been registered in the confirmed list 114, that is, if it is the first authentication, the security guard 112 performs visual confirmation as described above.

[0089] As described above, in the second embodiment, for a user 11 attempting to be authenticated for the first time, the reception unit 110 receives input of confirmation information 113 indicating that the security guard 112 has confirmed that the ID card 10 was issued by the card issuance task. Therefore, similar to the case of the identification ID 51 in the first embodiment, it is possible to avoid erroneously determining that a user 11 attempting to be authenticated with an ID card 10 that was not issued by the card issuance task is a legitimate user.

[0090] The qualified person is not limited to the security guard 112. It may be the supervisor of the store to which the new employee user 11 belongs. The number of qualified people is not limited to one. The security guard 112 and the supervisor may double-check.

[0091] [Third embodiment] For users 11 who have lost their status as regular users, such as retirees or employees of closed stores, the method of the third embodiment shown in Figure 17 may be applied instead of or in addition to collecting the ID card 10.

[0092] As an example, as shown in FIG. 17, in the third embodiment, an invalidation unit 120 is configured in the CPU 42B of the authentication terminal 24 in addition to the processing units 85 to 91 of the first embodiment and the reception unit 110 of the second embodiment. The invalidation unit 120 receives retired employee information 121 input to the authentication terminal 24 by, for example, a security guard 112. The retired employee information 121 includes the first facial image 16, authentication code 18, name, and affiliated store of the retired user 11. It is sufficient that the retired employee information 121 includes at least the authentication code 18.

[0093] The invalidation unit 120 searches for the authentication code 18 described in the retiree information 121 from the confirmed list 114 of the storage 40B, which was created based on the confirmed information 113. The searched authentication code 18 is then invalidated by deleting it together with the second facial image 95 and the registration date from the confirmed list 114. The storage 40B is an example of a "storage unit" according to the technology of the present disclosure. The confirmed information 113 is an example of "third identification information" according to the technology of the present disclosure.

[0094] As described above, in the third embodiment, the confirmed information 113 indicating that the ID card 10 was issued by the card issuance task is stored in the storage 40B. Then, for a user 11 who has lost his / her authorized user status, the confirmed information 113 is invalidated by the invalidation unit 120. This makes it possible to avoid erroneously determining that a user 11 who has lost his / her authorized user status is an authorized user.

[0095] The following method may be employed to invalidate the confirmed information 113. That is, in addition to the confirmed list 114, a list of users 11 who have lost their authorized user status (hereinafter referred to as a disqualified user list) is prepared in storage 40B. For users 11 who have lost their authorized user status, the invalidation unit 120 transfers the authentication code 18, etc. from the confirmed list 114 to the disqualified user list. In this way, the authentication code 18, etc. of users 11 who have lost their authorized user status can be left in storage 40B. When a closed store resumes business, for example, the authentication code 18 for the store's employees can be restored from the disqualified user list to the confirmed list 114.

[0096] Instead of or in addition to the former employee information 121, the invalidation unit 120 may accept information about employees of closed stores, and invalidate the confirmed information 113 about employees of closed stores.

[0097] The confirmed list 114 may be created by connecting the card issuing terminal 15 and the authentication terminal 24 and sending the authentication code 18 from the card issuing terminal 15 to the authentication terminal 24. This eliminates the need for confirmation by a qualified person such as a security guard 112 at the time of initial authentication.

[0098] In the above-described embodiments, the first facial image 16 satisfying a preset standard has been exemplified as the display facial image, but this is not limiting. As an example, as shown in FIG. 18, in addition to the ID card 10_1 having the first facial image 16 as the display facial image, an ID card 10_2 having a facial image 130_1 that is not bound by a standard as the display facial image, and an ID card 10_3 having a facial image 130_2 that is not bound by a standard as the display facial image may be issued. The facial image 130_1 is an image taken when the user 11 watched a soccer game. The facial image 130_2 is an image taken when the user 11 went snowboarding. Both the facial images 130_1 and 130_2 are images provided by the user 11 to the card issuing terminal 15.

[0099] The display face image is only for visual confirmation of the face of the user 11, and the authentication code 18 is responsible for authenticating the user 11. Therefore, even if the face image 130, which is not bound by the standard, is used as the display face image, there is no problem with authentication itself.

[0100] In this way, the display facial image printed on the ID card 10 may be a facial image 130 that is not bound by any standard. Therefore, the display facial image 130 can be a facial image that matches the preferences of the user 11. Also, the variety of ID cards 10 can be increased.

[0101] The non-standard facial image 130 may be, for example, a facial image decorated with a commercially available image processing application program. Both the first facial image 16 and the non-standard facial image 130 may be printed on one ID card 10.

[0102] 19, an illustration 135 such as an image character of the facility where the ID card 10 is installed may be printed in addition to the first facial image 16 and the authentication code 18. The authentication code 18 may also include the expiration date of the ID card 10 in addition to the first facial feature information 70 and the identification ID 51.

[0103] Instead of or in addition to the mascot character of the introducing facility, the illustration 135 may be an anime or game character affiliated with a campaign, the logo of a sponsored sports event, or the logo of the introducing facility and / or store. Furthermore, instead of illustration 135, characters indicating an event or campaign currently being held at the introducing facility or store may be printed on the ID card 10. Furthermore, patterns such as a waffle pattern, houndstooth, or checkerboard pattern may be printed on the ID card 10.

[0104] For example, the authentication code 18 may contain information that limits the locations where the ID card 10 can be used, such as permitting use at only one of two entrance / exit gates. Furthermore, for the purpose of maintaining the digital camera with printer 14, the authentication code 18 may contain the cumulative number of prints made by the digital camera with printer 14 on which the ID card 10 was printed. In this case, when the cumulative number of prints approaches the usable number of prints for the digital camera with printer 14, a notification is sent to the administrator of the authentication system 2 urging the replacement of the digital camera with printer 14.

[0105] The validity period of the ID card 10 may be set to a short period such as one day or one week, which can eliminate the need to collect the ID card 10 from the user 11 who has lost his / her authorized user status.

[0106] In the above embodiments, an example was shown in which the digital camera 14 with a printer was used, but this is not limited to this. A printer for printing the ID card 10 and a digital camera for taking the first facial image 16 may be prepared separately. Therefore, the card medium is not limited to the instant film 17 shown in the example. It may also be a plastic plate or the like.

[0107] The authentication code 18 is not limited to the QR code shown in the example, but may be a barcode.

[0108] Information on the issued ID card 10, such as the first facial image 16, the authentication code 18, the name and store of the user 11, the illustration 135, characters, and patterns, may be stored in a database connected to the card issuing terminal 15. In addition, the history of the matching result 97 and the determination result 98 may be stored in a database connected to the authentication terminal 24 together with the authentication code 18 and the second facial image 95.

[0109] A film ID that uniquely identifies each instant film 17 may be attached to the instant film 17, and this film ID may be used in the authentication task.

[0110] In each of the above embodiments, the following various processors may be used as the hardware configuration of processing units that perform various processes, such as the acquisition unit 60, extraction units 61 and 88, generation unit 62, control units 63 and 91, first acquisition unit 85, decryption unit 86, second acquisition unit 87, matching unit 89, determination unit 90, reception unit 110, and invalidation unit 120. As described above, the various processors include CPUs 42A and 42B, which are general-purpose processors that execute software (operation programs 50A and 50B) and function as various processing units, as well as dedicated electrical circuits that are processors having a circuit configuration specifically designed to perform specific processes, such as programmable logic devices (PLDs) that are processors whose circuit configuration can be changed after manufacture, such as field programmable gate arrays (FPGAs), and application specific integrated circuits (ASICs).

[0111] A single processing unit may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (e.g., a combination of multiple FPGAs and / or a combination of a CPU and an FPGA). Also, multiple processing units may be configured with a single processor.

[0112] Examples of configuring multiple processing units with a single processor include, first, a form in which one processor is configured with a combination of one or more CPUs and software, and this processor functions as multiple processing units, as typified by client and server computers. Second, a form in which a processor is used to realize the functions of an entire system including multiple processing units with a single IC (Integrated Circuit) chip, as typified by System on Chip (SoC). In this way, various processing units are configured using one or more of the above-mentioned various processors as a hardware structure.

[0113] Furthermore, more specifically, the hardware structure of these various processors can be an electric circuit that combines circuit elements such as semiconductor elements.

[0114] The technology of the present disclosure can be appropriately combined with the various embodiments and / or various modified examples described above. Furthermore, it is not limited to the above-described embodiments, and various configurations can be adopted without departing from the spirit of the present disclosure. Furthermore, the technology of the present disclosure extends not only to programs but also to storage media that non-temporarily store programs.

[0115] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.

[0116] In this specification, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0117] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.

Claims

1. a processor; a memory connected to or embedded in the processor; The processor: a first processor that handles a card issuance task of issuing an ID card for a user; a second processor that performs an authentication task of determining whether to authenticate the user as a legitimate user using the ID card; The first processor performs, as the card issuance task, acquiring a first facial image of the user; extracting first facial feature information from the first facial image; generating an authentication code representing the first facial feature information; The authentication code and the face image of the user for display are printed on a card medium by a printer to create the ID card; The second processor performs the authentication task as follows: acquiring the authentication code printed on the ID card held by the user and a second facial image of the user; Decrypting the first facial feature information from the authentication code; extracting second facial feature information from the second facial image using the same algorithm as that used to extract the first facial feature information from the first facial image; Matching the first facial feature information with the second facial feature information; making the determination based on the collation result; For the user attempting to be authenticated for the first time, input of second identification information indicating that a qualified person has confirmed that the ID card was issued by the card issuance task is accepted. Authentication system.

2. A processor; a memory connected to or embedded in the processor; The processor: a first processor that handles a card issuance task of issuing an ID card for a user; a second processor that performs an authentication task of determining whether to authenticate the user as a legitimate user using the ID card; The first processor performs, as the card issuance task, acquiring a first facial image of the user; extracting first facial feature information from the first facial image; generating an authentication code representing the first facial feature information; The authentication code and the face image of the user for display are printed on a card medium by a printer to create the ID card; The second processor performs the authentication task as follows: acquiring the authentication code printed on the ID card held by the user and a second facial image of the user; Decrypting the first facial feature information from the authentication code; extracting second facial feature information from the second facial image using the same algorithm as that used to extract the first facial feature information from the first facial image; Matching the first facial feature information with the second facial feature information; making the determination based on the collation result; storing third identification information in a storage unit, the third identification information indicating that the ID card was issued by the card issuance task; invalidating the third identification information of the user who has lost the qualification of the authorized user; Authentication system.

3. First identification information indicating that the ID card was issued by the card issuance task is added to the ID card, The second processor 3. The authentication system according to claim 1, wherein if the first identification information is invalid, the user is determined to be an unauthorized user regardless of the result of the comparison.

4. The second processor The authentication system of claim 2, wherein for the user attempting to be authenticated for the first time, input of second identification information indicating that a qualified person has confirmed that the ID card was issued by the card issuance task is accepted.

5. The authentication system according to claim 1 , wherein the first facial image is an image that satisfies a predetermined standard.

6. The authentication system according to claim 5 , wherein the display facial image is the first facial image.

7. 7. The authentication system according to claim 5, wherein the display face image is an image that is not bound by the standard.

8. The first processor An authentication system as described in any one of claims 1 to 7, wherein the operation of a digital camera with a printer is controlled to cause the digital camera with a printer to take the first facial image and print the authentication code and the display facial image on the card media.

9. a card issuance task for issuing an ID card for a user; an authentication task of determining whether or not to authenticate the user as a legitimate user using the ID card; The card issuing task includes: acquiring a first facial image of the user; extracting first facial feature information from the first facial image; generating an authentication code representing the first facial feature information; and creating the ID card by printing the authentication code and the face image of the user for display on a card medium using a printer; Including, The authentication task includes: acquiring the authentication code printed on the ID card held by the user and a second facial image of the user; Decrypting the first facial feature information from the authentication code; extracting second facial feature information from the second facial image using the same algorithm as that used to extract the first facial feature information from the first facial image; Matching the first facial feature information with the second facial feature information; making the determination based on the matching result; and For the user attempting to be authenticated for the first time, receiving input of second identification information indicating that a qualified person has confirmed that the ID card was issued by the card issuance task; Contains How the authentication system works.

10. A card issuing task for issuing an ID card to a user; an authentication task of determining whether or not to authenticate the user as a legitimate user using the ID card; The card issuing task includes: acquiring a first facial image of the user; extracting first facial feature information from the first facial image; generating an authentication code representing the first facial feature information; and creating the ID card by printing the authentication code and the face image of the user for display on a card medium using a printer; Including, The authentication task includes: acquiring the authentication code printed on the ID card held by the user and a second facial image of the user; Decrypting the first facial feature information from the authentication code; extracting second facial feature information from the second facial image using the same algorithm as that used to extract the first facial feature information from the first facial image; Matching the first facial feature information with the second facial feature information; making the determination based on the collation result; storing third identification information in a storage unit, the third identification information indicating that the ID card was issued by the card issuance task; and invalidating the third identification information for the user who has lost the qualification of the authorized user; Contains How the authentication system works.

11. a card issuance task for issuing an ID card for a user; an authentication task of determining whether or not to authenticate the user as a legitimate user using the ID card; The card issuing task includes: acquiring a first facial image of the user; extracting first facial feature information from the first facial image; generating an authentication code representing the first facial feature information; and creating the ID card by printing the authentication code and the face image of the user for display on a card medium using a printer; causing a computer to execute a process including The authentication task includes: acquiring the authentication code printed on the ID card held by the user and a second facial image of the user; Decrypting the first facial feature information from the authentication code; extracting second facial feature information from the second facial image using the same algorithm as that used to extract the first facial feature information from the first facial image; Matching the first facial feature information with the second facial feature information; making the determination based on the matching result; and For the user attempting to be authenticated for the first time, receiving input of second identification information indicating that a qualified person has confirmed that the ID card was issued by the card issuance task; An operating program of an authentication system for causing a computer to execute a process including the steps of:

12. A card issuing task for issuing an ID card to a user; an authentication task of determining whether or not to authenticate the user as a legitimate user using the ID card; The card issuing task includes: acquiring a first facial image of the user; extracting first facial feature information from the first facial image; generating an authentication code representing the first facial feature information; and creating the ID card by printing the authentication code and the face image of the user for display on a card medium using a printer; causing a computer to execute a process including The authentication task includes: acquiring the authentication code printed on the ID card held by the user and a second facial image of the user; Decrypting the first facial feature information from the authentication code; extracting second facial feature information from the second facial image using the same algorithm as that used to extract the first facial feature information from the first facial image; Matching the first facial feature information with the second facial feature information; making the determination based on the collation result; storing third identification information in a storage unit, the third identification information indicating that the ID card was issued by the card issuance task; and invalidating the third identification information for the user who has lost the qualification of the authorized user; An operating program of an authentication system for causing a computer to execute a process including the steps of:

Citation Information

Patent Citations

  • Certification photograph and individual authentication medium

    JP2002281275A

  • Face picture photographing apparatus

    JP2005148537A

  • Information processing apparatus and biometric authentication system

    JP2020181473A