Authentication server, system, authentication server control method and program

An authentication server integrating biometric information with provider IDs and public data enables cross-provider authentication, simplifying the introduction of biometric services and promoting their widespread use.

JP7757983B2Active Publication Date: 2025-10-22NEC CORP
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2022566819
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-03
Filing Date
2021-11-15
Publication Date
2025-10-22
Estimated Expiration
2041-11-15

AI Technical Summary

Technical Problem

Current biometric authentication systems are often specialized for each business, making it difficult to introduce biometric authentication across different providers, whether private or public institutions.

Method used

An authentication server that stores biometric information in association with provider IDs and public information identification data, enabling cross-provider authentication and information access, allowing seamless integration of biometric authentication systems across private businesses and public institutions.

Benefits of technology

Facilitates the widespread adoption of biometric authentication by eliminating the need for individual businesses to build their own authentication systems, thereby simplifying the introduction of biometric services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007757983000001
    Figure 0007757983000001
  • Figure 0007757983000002
    Figure 0007757983000002
  • Figure 0007757983000003
    Figure 0007757983000003
Patent Text Reader

Abstract

In order to provide an authentication server that further promulgates biometric authentication, the authentication server of the present invention comprises a database, an authentication means, and an information provision means. The database stores the following in association with each other: biometric information of a user; a first ID for distinguishing an operator that provides a service to the user; and a second ID that is uniquely established by combining the user and the operator. The database also stores the following in association with each other: the biometric information of the user; and public information-specifying data for specifying public information for which provision has been granted by the user. The authentication means executes authentication processing in response to receiving an authentication request, and transmits the second ID, of a person who has been successfully authenticated, to a first operator. The information provision means receives, from a second operator, a public information provision request that includes the type of public information that the second operator desires to reference. The information provision means acquires the public information, that the second operator desires to reference, from a public server that retains said public information, and transmits the acquired public information to the second operator.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an authentication server, a system, a control method for an authentication server, and a recording medium. [Background technology]

[0002] In recent years, various services using biometric information have begun to become popular. For example, facial recognition is used for various procedures at airports (check-in, baggage drop-off, etc.) and hotel check-ins. In recent years, various technological developments related to biometric authentication have been underway.

[0003] For example, Patent Document 1 describes that it is possible to centralize biometric information used for biometric authentication. The information processing terminal described in Patent Document 1 includes an acquisition unit that acquires biometric information for biometric authentication and identification information of a device to which a service is provided, and a transmission unit that transmits the identification information in response to success of the biometric authentication.

[0004] Patent Document 2 describes that the system efficiently authenticates users when they perform various procedures. The authentication system in Patent Document 2 accesses a management device from the user's mobile terminal and performs initial registration, including a video image of the user. In this authentication system, when the user receives a service at a financial institution's branch or convenience store, the system transmits a video image to the management device, performs authentication processing according to the type of use, and notifies the user of the authentication result.

[0005] Patent Document 3 describes making shopping at duty-free facilities for foreign tourists efficient and comfortable. The payment support server in Patent Document 3 includes a communication device, a storage device, and a computing device. The communication device communicates with other devices. The storage device stores the traveler's passport information, information on the means of transportation or facilities used during the trip, and biometric authentication information in association with each other. The computing device compares the traveler's biometric information included in the payment information received from the terminal at the duty-free facility with the biometric authentication information stored in the storage device that is associated with passport information and information on the means of transportation or facilities used and that indicates a predetermined validity. If biometric authentication information matching the biometric information is registered, the computing device returns payment permission information to the terminal. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] International Publication No. 2018 / 096772 [Patent Document 2] Japanese Patent Publication No. 2020-113107 [Patent Document 3] Japanese Patent Application Publication No. 2017-123202 Summary of the Invention [Problem to be solved by the invention]

[0007] As mentioned above, technological developments related to biometric authentication have progressed in recent years, and various services using biometric authentication are being provided to users. More specifically, private businesses such as accommodation providers and public institutions such as local governments are providing or considering providing services using biometric authentication.

[0008] Here, biometric authentication is achieved by comparing the biometric information of the person to be authenticated with biometric information registered in a database, and the basic mechanism of authentication is the same whether the authenticator (authenticating entity; service provider) is a private business or a public institution. However, current authentication systems are often configured to be specialized for each business, which makes it more difficult to introduce biometric authentication.

[0009] A primary object of the present invention is to provide an authentication server, a system, a control method for an authentication server, and a recording medium that contribute to the further spread of biometric authentication. [Means for solving the problem]

[0010] According to a first aspect of the present invention, an authentication server is provided, comprising: a database that stores, in association with each other, a user's biometric information, a first ID (identifier) ​​that identifies a provider that provides a service to the user, a second ID that is uniquely determined by the combination of the user and the provider, and public information identification data that identifies public information the user has authorized to be provided; an authentication means that performs an authentication process in response to receiving an authentication request from a first provider that includes the biometric information of the person to be authenticated and the first ID of the first provider, and sends the second ID of the person who is successfully authenticated to the first provider; and an information providing means that, when the second provider receives a public information provision request from a second provider that includes the biometric information of the user whose public information the second provider wishes to access and the type of public information the second provider wishes to access, uses the public information identification data to obtain the public information the second provider wishes to access from a public server that stores the public information the second provider wishes to access, and sends the obtained public information to the second provider.

[0011] According to a second aspect of the present invention, a system is provided, comprising: a first terminal installed at a first provider; a second terminal installed at a second provider; and an authentication server connected to the first and second terminals, wherein the authentication server comprises a database that stores, in association with each other, a user's biometric information, a first ID that identifies a provider that provides a service to the user, a second ID that is uniquely determined by the combination of the user and the provider, and public information identification data for identifying public information the user has authorized to be provided; an authentication means that performs an authentication process in response to receiving from the first terminal an authentication request including the biometric information of the person to be authenticated and the first ID of the first provider, and sends the second ID of the successfully authenticated person to the first terminal; and an information provision means that, when the second provider receives from the second terminal a public information provision request including the biometric information of a user who wishes to access public information and the type of public information desired to access, uses the public information identification data to obtain the public information desired to access from a public server that stores the public information, and sends the obtained public information to the second terminal.

[0012] According to a third aspect of the present invention, there is provided a control method for an authentication server having a database that stores, in association with each other, a user's biometric information, a first ID that identifies a provider that provides a service to the user, a second ID that is uniquely determined by the combination of the user and the provider, and public information identification data that identifies public information that the user has authorized to be provided.The control method for the authentication server performs an authentication process in response to receiving an authentication request from a first provider, the authentication request including the biometric information of the person to be authenticated and the first ID of the first provider, and transmits the second ID of the person who is successfully authenticated to the first provider.When the second provider receives a public information provision request from a second provider, the public information is included in the biometric information of the user who wishes to access public information and the type of public information that the second provider wishes to access, and the public information is obtained using the public information identification data from a public server that stores the public information that the user wishes to access, and transmits the obtained public information to the second provider.

[0013] According to a fourth aspect of the present invention, a computer-readable recording medium is provided having recorded thereon a program to cause a computer mounted on an authentication server having a database that stores, in association with each other, a user's biometric information, a first ID that identifies a provider that provides a service to the user, a second ID that is uniquely determined by the combination of the user and the provider, and public information identification data that identifies public information the user has authorized to be provided, to perform an authentication process in response to receiving from a first provider an authentication request including the biometric information of the person to be authenticated and the first ID of the first provider, and send the second ID of the person who was successfully authenticated to the first provider, and when the second provider receives from a second provider a public information provision request including the biometric information of the user who wishes to access public information and the type of public information that the second provider wishes to access, to use the public information identification data to obtain the public information that the second provider wishes to access from a public server that stores the public information that the user wishes to access, and send the obtained public information to the second provider. [Effects of the Invention]

[0014] According to each aspect of the present invention, an authentication server, a system, a method for controlling an authentication server, and a recording medium are provided that contribute to further popularizing biometric authentication. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]

[0015] [Figure 1] FIG. 1 is a diagram for explaining an overview of an embodiment. [Figure 2] 1 is a diagram illustrating an example of a schematic configuration of an authentication system according to a first embodiment. [Figure 3] FIG. 2 is a diagram for explaining the operation in the user registration phase of the authentication system according to the first embodiment. [Figure 4] FIG. 2 is a diagram for explaining the operation in the service information registration phase of the authentication system according to the first embodiment. [Figure 5]FIG. 2 is a diagram for explaining the operation of the authentication system according to the first embodiment in the public information provision permission phase. [Figure 6] FIG. 2 is a diagram for explaining the operation of the authentication system according to the first embodiment in a service provision phase. [Figure 7] FIG. 2 is a diagram for explaining the operation of the authentication system according to the first embodiment in a service provision phase. [Figure 8] FIG. 2 is a diagram illustrating an example of a processing configuration of an authentication server according to the first embodiment. [Figure 9A] FIG. 2 is a diagram illustrating an example of a business information database according to the first embodiment. [Figure 9B] FIG. 2 is a diagram illustrating an example of a business information database according to the first embodiment. [Figure 9C] FIG. 2 is a diagram illustrating an example of a business information database according to the first embodiment. [Figure 10A] FIG. 2 is a diagram showing an example of a public information database according to the first embodiment. [Figure 10B] FIG. 2 is a diagram showing an example of a public information database according to the first embodiment. [Figure 11] 6 is a flowchart showing an example of the operation of an authentication unit according to the first embodiment. [Figure 12] 10 is a flowchart showing an example of the operation of a public information providing unit according to the first embodiment. [Figure 13] FIG. 2 is a diagram illustrating an example of a processing configuration of a management server according to the first embodiment. [Figure 14] FIG. 2 is a diagram illustrating an example of a user information database according to the first embodiment. [Figure 15] FIG. 2 is a diagram illustrating an example of a processing configuration of an authentication terminal according to the first embodiment. [Figure 16] FIG. 3 is a diagram illustrating an example of a processing configuration of a staff terminal according to the first embodiment. [Figure 17] FIG. 4 is a diagram for explaining the operation of an information request unit according to the first embodiment. [Figure 18]FIG. 4 is a diagram for explaining the operation of an information request unit according to the first embodiment. [Figure 19] FIG. 4 is a diagram for explaining the operation of a message output unit according to the first embodiment. [Figure 20] FIG. 2 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment. [Figure 21] FIG. 4 is a diagram for explaining the operation of a user support unit according to the first embodiment. [Figure 22] FIG. 4 is a diagram for explaining the operation of a user registration support unit according to the first embodiment. [Figure 23] FIG. 4 is a diagram for explaining the operation of a user registration support unit according to the first embodiment. [Figure 24] FIG. 4 is a diagram for explaining the operation of a service registration support unit according to the first embodiment. [Figure 25] FIG. 4 is a diagram for explaining the operation of a service registration support unit according to the first embodiment. [Figure 26] FIG. 4 is a diagram for explaining the operation of a service registration support unit according to the first embodiment. [Figure 27] FIG. 4 is a diagram for explaining the operation of a provision license support unit according to the first embodiment. [Figure 28] FIG. 4 is a diagram for explaining the operation of a provision license support unit according to the first embodiment. [Figure 29] FIG. 3 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment. [Figure 30] FIG. 3 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment. [Figure 31] FIG. 3 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment. [Figure 32] FIG. 3 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment. [Figure 33] FIG. 2 is a diagram illustrating an example of a hardware configuration of an authentication server disclosed herein. [Figure 34] FIG. 10 is a diagram illustrating an example of an authentication information database according to a modified example of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0016] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0017] An authentication server 100 according to one embodiment includes a database 101, an authentication unit 102, and an information providing unit 103 (see FIG. 1). The database 101 stores a user's biometric information, a first ID identifying a service provider providing a service to the user, and a second ID uniquely determined by the combination of the user and the service provider, in association with each other. Furthermore, the database 101 stores a user's biometric information and other information in association with public information identification data for identifying public information the user has authorized to be provided. The authentication unit 102 executes authentication processing in response to receiving an authentication request from a first service provider, the authentication request including the biometric information of the person to be authenticated and the first ID of the first service provider, and transmits the second ID of the successfully authenticated person to the first service provider. The information providing unit 103 receives a public information provision request from a second service provider, the public information provision request including the biometric information of the user whose public information the second service provider wishes to access and the type of public information the second service provider wishes to access. The information providing unit 103 acquires the public information that the user wishes to refer to from a public server that stores the public information that the user wishes to refer to, using the public information identification data, and transmits the acquired public information to the second business operator.

[0018] When the authentication server 100 receives an authentication request from a first business operator (e.g., a private business operator), it transmits a second ID (service user ID) uniquely determined from the combination of the user and the business operator to the first business operator. The first business operator stores the second ID in association with service information required to provide the user, thereby identifying the required service information based on the second ID obtained from the authentication server 100. Furthermore, when the authentication server 100 receives a request for public information from the second business operator (e.g., a public institution such as a city hall), it identifies the user through biometric authentication and obtains data (e.g., a passport number) for identifying the public information requested. The authentication server 100 obtains the corresponding public information (e.g., passport information) by transmitting the public information identification data to a public server that stores and manages the public information. The authentication server 100 transmits the obtained public information to the second business operator. The second business operator can provide the user with a service using the obtained public information. In this way, the authentication server 100 processes requests from private businesses and public institutions by performing authentication and matching processes using the database 101. In other words, neither private businesses nor public institutions need to build their own authentication systems, lowering the barrier to introducing biometric authentication. As a result, biometric authentication will become even more widespread.

[0019] Specific embodiments will be described in more detail below with reference to the drawings. [First embodiment] The first embodiment will be described in more detail with reference to the drawings. [System Configuration] Fig. 2 is a diagram showing an example of a schematic configuration of an authentication system according to the first embodiment. As shown in Fig. 2, the authentication system includes at least one or more businesses, an authentication center, and a group of public servers.

[0020] Each business participating in the authentication system will provide services using biometric authentication.

[0021] The business operator (service provider) that provides the service to the user may be a private business operator or a public institution.

[0022] Examples of private businesses include retail stores, accommodation providers, event companies, and medical institutions. For example, retail stores provide payment services using biometric authentication. Accommodation providers use biometric authentication to manage check-in procedures and guest room entry and exit. Event companies use biometric authentication to manage entry and exit to event venues.

[0023] Examples of public institutions include city halls, health centers, hospitals, etc. For example, biometric authentication is used when city hall employees verify the identity of users (residents). Biometric authentication may also be used to verify eligibility for benefits, etc.

[0024] The business entity disclosed in this application may be either a private business entity or a public institution, as long as it can provide any service using biometric authentication.

[0025] 2, each business operator has various internal configurations. For example, the internal configuration of a business operator may include a management server 20 and an authentication terminal 30, as in the case of business operator S1.

[0026] The management server 20 is a server that controls and manages the overall business of the business. For example, if the business is a retail store, the management server 20 performs inventory management of products and payment processing. Alternatively, if the business is an accommodation business, the management server 20 manages reservation information of guests, etc.

[0027] The management server 20 has a control function and a management function related to the biometric authentication of users in addition to the functions related to the provision of the above services.

[0028] The authentication terminal 30 is a device (first terminal) that serves as an interface for users (customers) who visit a business. The users receive various services via the authentication terminal 30. For example, if the business is a retail store, the users use the authentication terminal 30 to pay for their purchases. Alternatively, if the business is an accommodation business, the users use the authentication terminal 30 to complete check-in procedures.

[0029] In the first embodiment, the authentication terminal 30 will be described as a terminal used by the user himself (self-terminal). However, this is not intended to limit the manner in which the authentication terminal 30 is used, and an employee or staff member of a business may use the authentication terminal 30 to provide a service to a user, or both the user and the employee may use the authentication terminal 30.

[0030] As with business operator S2 shown in Fig. 2, an internal configuration of a business operator may not have a server installed, but may instead have an employee terminal 31. For example, employee terminal 31 is a terminal (second terminal) installed at the reception desk of a city hall, hospital, etc. An employee of the city hall, etc., provides services to users while operating employee terminal 31. For example, an employee of the city hall, etc., uses employee terminal 31 to confirm the service eligibility, etc., of a user who wishes to receive administrative services.

[0031] In the first embodiment, the staff terminal 31 is described as a terminal used by a third party other than the user. However, the staff terminal 31 can also be a terminal used by the user, similar to the authentication terminal 30, or a terminal used by both the user and the staff.

[0032] The authentication center provides authentication services and information provision services. An authentication server 10 is installed in the authentication center. The authentication server 10 operates as an authentication authority for authentication using biometric information. The authentication server 10 may be installed on the premises of the authentication center, or may be installed on the cloud.

[0033] The biometric information of a user may be, for example, data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, or iris pattern. Alternatively, the biometric information of a user may be image data such as a face image or fingerprint image. The biometric information of a user may be any information that includes the user's physical characteristics. In the first embodiment, a face image or features generated from a face image will be described as biometric information.

[0034] The authentication server 10 is a server device for realizing services based on biometric authentication. The authentication server 10 provides authentication services and information provision services to each business operator.

[0035] The public server group is a collection of servers (public servers) that handle public information. For example, the public server group includes a passport server 41 that stores and manages passport information and an insurance card server 42 that stores and manages insurance card information. Public servers are managed and operated by government agencies such as the Ministry of Foreign Affairs or by businesses commissioned by those agencies.

[0036] The devices shown in Fig. 2 are interconnected. For example, the authentication server 10 and the management server 20 are connected by wired or wireless communication means and are configured to be able to communicate with each other.

[0037] The configuration shown in FIG. 2 is an example and is not intended to limit the configuration of the authentication system disclosed herein. For example, the authentication center may include two or more authentication servers 10. Alternatively, the functions of the management server 20 and the authentication terminal 30 may be integrated, and services using biometric authentication may be provided by this single integrated device. Furthermore, each public server included in the public server group may handle two or more pieces of public information. For example, the passport server 41 and the health insurance card server 42 may be integrated, and this single integrated server may handle the public information of passports and health insurance cards. [System operation overview] Next, the general operation of the authentication system according to the first embodiment will be described.

[0038] The operation of the authentication system involves four phases.

[0039] The first phase is a phase in which users are registered in the system (user registration phase).

[0040] The second phase is the phase in which information necessary for users to receive services, in particular service information necessary to receive services from private businesses, is registered in the system (service information registration phase).

[0041] The third phase is the phase (public information provision permission phase) in which the authentication center registers (gives) the user's permission to provide the user's public information to the business operator.

[0042] The fourth phase is the phase (service provision phase) in which each business operator provides users with services that use biometric authentication. The service provision phase includes service provision using service information registered by users in the system and service provision using the users' own public information. [User registration phase] FIG. 3 is a diagram for explaining the operation in the user registration phase of the authentication system according to the first embodiment.

[0043] Users who wish to use services using biometric authentication must register in advance. The user then enters their biometric information (e.g., a facial image) and identity verification documents into the system. Note that identity verification documents that can be used in this disclosure are documents that contain biometric information, such as a passport or driver's license.

[0044] The user inputs the above two pieces of information (biometric information and identity document) into the system using any means. For example, the user may mail a document containing the above two pieces of information to the authentication center, and an employee of the authentication center may enter the above two pieces of information into the authentication server 10. Alternatively, the user may mail an external storage device, such as a USB (Universal Serial Bus), on which the above two pieces of information are stored to the authentication center.

[0045] Alternatively, the user may input the above two pieces of information to the authentication server 10 using an application installed on the terminal 40. Examples of the terminal 40 include mobile terminal devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, laptop computers), etc.

[0046] In the first embodiment, a case will be described in which a user performs the above user registration etc. using an application installed on the terminal 40. In the following description, the above application will be referred to as a "user assistance application" or simply as an "assistance app." The user assistance application is an application that assists a user in inputting information etc. required when receiving a service from a business operator.

[0047] The terminal 40 (support application) transmits a "user registration request" including the user's biometric information (for example, a face image) and an identification document (for example, a copy of a passport) to the authentication server 10.

[0048] For example, the authentication server 10 performs identity verification using the acquired face image and the face image recorded on the passport (hereinafter referred to as the passport face image). If the two face images are of substantially the same person, the authentication server determines that identity verification has been successful.

[0049] If the identity verification is successful, the authentication server 10 generates a feature amount (a feature vector consisting of multiple feature amounts) from the acquired face image. After that, the authentication server 10 generates an ID (user ID) for uniquely identifying the user.

[0050] The authentication server 10 associates the generated feature amount (biometric information) with the user ID and stores them in a database. More specifically, the authentication server 10 adds entries to each of the business information database and the public information database, and stores the generated biometric information and user ID. In the first embodiment, the authentication server 10 manages the user's biometric information using two databases. However, the authentication server 10 may manage the user's biometric information, authentication information, etc. using a database that integrates the two databases.

[0051] The business information database is a database required when processing authentication requests from businesses that use service information. Details of this database will be described later. Service information is information required by businesses (particularly private businesses) to provide services to users. Examples of service information include reservation information required by hotel businesses when providing accommodation services, and ticket information issued by event organizers.

[0052] The official information database is a database that stores biometric information and information necessary for providing official information in association with each other. Details of the database will be described later. Official information is information that is generated, issued, and managed by a public institution. For example, the information written on a passport or an insurance card is exemplified as official information.

[0053] Furthermore, the authentication server 10 issues the generated user ID to the terminal 40. The terminal 40 (assistance application) stores the acquired user ID. [Service information registration phase] FIG. 4 is a diagram for explaining the operation in the service information registration phase of the authentication system according to the first embodiment.

[0054] A user who wishes to receive a service from a business operator registers service information in the system. More specifically, the user selects a business from which the user wishes to receive services through biometric authentication, and registers the selected business and the service information to be used (referenced) by the business in the system.

[0055] For example, in Figure 2, if a user wishes to receive a service from business operator S1, the user registers business operator S1 and the service information required by business operator S1 in the system. For example, if business operator S1 is an accommodation business operator, the user registers in the system the fact that he or she will receive a service from the accommodation business operator (business operator S1) and the service information required by the accommodation business operator when providing the service (reservation information; name, date of stay, etc.).

[0056] In addition, the user registers the user ID issued in the user registration phase along with the above service information in the system.

[0057] In the present disclosure, service information is defined as information that does not include biometric information of the user (person to be authenticated). In other words, biometric information and features generated from the biometric information are excluded from the "service information" disclosed in the present disclosure.

[0058] The user inputs the above two pieces of information (user ID and service information) to the business operator using any means. In the first embodiment, as shown in FIG. 4, a case will be described in which the user operates the terminal 40 to input the above two pieces of information to the management server 20. In this case, the user inputs the above two pieces of information to the management server 20 via a support app installed on the terminal 40. Specifically, the terminal 40 transmits a "service information registration request" including the user's user ID and service information to the management server 20.

[0059] The management server 20 receives a service information registration request including the above two pieces of information (user ID, service information). In response to receiving the service information registration request, the management server 20 transmits a "business registration request" to the authentication server 10. Specifically, the management server 20 transmits a business registration request including the user ID and the business ID to the authentication server 10.

[0060] The provider ID is identification information that uniquely identifies a provider included in the authentication system (an entity participating in the authentication infrastructure that uses biometric authentication). In the example of Figure 2, different provider IDs are assigned to providers S1 and S2.

[0061] Note that the business operator ID is an ID assigned to each business operator, not to each service. For example, in Figure 2, even if businesses S1 and S2 are businesses that provide the same type of service (e.g., accommodation services), if they are managed by different entities, different IDs will be assigned to these businesses.

[0062] The authentication server 10 and the management server 20 share the business ID by any method. For example, when a business participates in the authentication infrastructure, the authentication server 10 generates a business ID and distributes (notifies) the generated servicer ID to the business.

[0063] When receiving a business registration request, the authentication server 10 searches the business information database using the user ID included in the request as a key to identify the corresponding user. Then, the authentication server 10 generates a "service user ID."

[0064] The service user ID is identification information that uniquely defines the correspondence (combination) between a user and a business. For example, in the example of Fig. 2, different values ​​are generated for the service user ID determined from the combination of user U1 and business S1 and the service user ID determined from the combination of user U1 and business S2.

[0065] The authentication server 10 associates the user ID, biometric information (feature amount), business ID, and the generated service user ID and stores them in the business information database.

[0066] The authentication server 10 transmits the generated service user ID to the sender of the business registration request. The authentication server 10 transmits a response including the service user ID to the management server 20, and issues the service user ID.

[0067] The management server 20 stores the service user ID acquired from the authentication server 10 in association with the service information acquired from the user. The management server 20 adds a new entry to the user information database and stores the above information (service user ID, service information).

[0068] The user repeats the above-described registration process for each business from which the user wishes to receive services using biometric authentication. In other words, the user does not need to register with businesses from which the user does not need to receive services. Furthermore, a user who does not plan to receive services from a business does not need to perform the service information registration phase. [Public Information Provision Permission Phase] FIG. 5 is a diagram for explaining the operation of the authentication system according to the first embodiment in the official information provision permission phase.

[0069] A user who consents to the provision of their public information (for example, passport details, health insurance card details) to a business operator gives consent to the provision of that public information to the system. More specifically, the user selects the type of public information (passport details, health insurance card details) that they consent to be provided. The user registers data (hereinafter referred to as "identifying public information data") to identify the type of public information (passport, health insurance card) they have selected in the system. For example, when consenting to the provision of their passport details to a business operator (third party), the user registers their passport number in the system as identifying public information data.

[0070] In addition, the user registers the user ID issued in the user registration phase in the system along with the above-mentioned public information identification data.

[0071] The user inputs the above two pieces of information (user ID and public information identification data) to the authentication server 10 by any means. In the first embodiment, as shown in FIG. 5, a case will be described in which the user operates the terminal 40 to input the above two pieces of information to the authentication server 10. In this case, the user inputs the above two pieces of information to the authentication server 10 via a support app installed on the terminal 40. Specifically, the terminal 40 transmits a public information provision permission including the user ID and the public information identification data to the authentication server 10.

[0072] Upon receiving the permission to provide public information, the authentication server 10 searches the public information database using the user ID included in the permission as a key to identify the corresponding user.

[0073] The authentication server 10 associates the user ID, the biometric information (feature amount), and the official information identification data (for example, a passport number) and stores them in the official information database.

[0074] When the information is registered in the public information database, the authentication server 10 transmits a positive response indicating that the process has been completed successfully to the terminal 40. If the information cannot be registered in the public information database, the authentication server 10 transmits a negative response to the terminal 40 indicating that the process has not been completed successfully.

[0075] The terminal 40 that receives the response from the authentication server 10 outputs a message or the like according to the content of the response.

[0076] Users who do not consent to their public information being provided to the business operator do not need to go through the public information consent phase. [Service provision phase] The service provision phase includes providing a service using service information and providing a service using public information.

[0077] First, the provision of a service using service information will be described. Fig. 6 is a diagram for explaining the operation in the service provision phase of the authentication system according to the first embodiment.

[0078] After completing the service information registration (service information registration phase), the user visits the business operator. The user moves to the authentication terminal 30.

[0079] The authentication terminal 30 acquires biometric information from a user in front of the user. Specifically, the authentication terminal 30 captures an image of the user and acquires a facial image. The authentication terminal 30 transmits the acquired facial image to the management server 20.

[0080] The management server 20 generates features from the acquired face image, and transmits an authentication request including the generated features (biometric information) and the business ID to the authentication server 10.

[0081] The authentication server 10 extracts the feature amount from the authentication request, and executes a matching process (one-to-N matching; N is a positive integer, the same applies below) using the extracted feature amount and the feature amount registered in the business information database.

[0082] The authentication server 10 identifies the user through a matching process, and identifies a service user ID corresponding to the business ID included in the authentication request from among a plurality of service user IDs associated with the identified user.

[0083] The authentication server 10 transmits the identified service user ID to the sender of the authentication request, and transmits a response (a positive response to the authentication request) including the identified service user ID to the management server 20.

[0084] The management server 20 searches the user information database using the acquired service user ID as a key to identify the service information corresponding to the service user ID. The business (management server 20, authentication terminal 30) provides the user with a service (e.g., payment settlement, check-in procedures, etc.) based on the identified service information.

[0085] Next, the provision of a service using public information will be described. Fig. 7 is a diagram for explaining the operation in the service provision phase of the authentication system according to the first embodiment.

[0086] After completing the official information provision permission (official information provision permission phase), the user visits the business operator. The user moves to an area where an employee terminal 31 is located (for example, the reception area of ​​a city hall, etc.). In that area, there are employees of the business operator, who use the employee terminal 31 to provide services to the user.

[0087] After listening to a user's story (request), a staff member or the like may determine that it is necessary to refer to the user's official information. For example, it may be determined that it is necessary to refer to official information in order to verify the user's identity or eligibility to receive administrative services. In this case, the staff member or the like operates the staff terminal 31 to acquire the user's biometric information (face image). The staff terminal 31 generates feature quantities from the face image.

[0088] The employee also determines the type of official information to be referenced (e.g., passport, health insurance card). The employee operates the employee terminal 31 to transmit an "official information provision request" including biometric information (feature amount) and the type of official information (official document) to the authentication server 10.

[0089] The authentication server 10 extracts the feature amount from the public information provision request, and executes a matching process (1:N matching) using the extracted feature amount and the feature amount registered in the public information database.

[0090] The authentication server 10 identifies the user through a matching process, and identifies official information identification data that is associated with the identified user and corresponds to the type of official information included in the official information provision request. For example, when a passport is requested from the staff terminal 31, the authentication server 10 reads the passport number from the official information database.

[0091] The authentication server 10 transmits the acquired public information identification data to the public servers. More specifically, the authentication server 10 transmits the identified public information identification data to the public server corresponding to the identified public information identification data. In the above passport example, the passport number is transmitted to the passport server 41.

[0092] The official server transmits official information corresponding to the acquired official information identification data to the authentication server 10. In the above passport example, the passport server 41 transmits to the authentication server 10 the information written on the passport (such as name, date of birth, nationality, and passport facial image) corresponding to the acquired passport number.

[0093] When the authentication server 10 acquires public information from the public server group, it transmits a response (positive response; response to the public information request) including the acquired public information to the staff terminal 31. When the authentication server 10 cannot acquire public information from the public server group, it transmits a negative response indicating this to the staff terminal 31.

[0094] The staff terminal 31 that has acquired the public information takes action such as displaying the acquired public information. Staff members refer to the displayed public information and provide administrative services.

[0095] Next, each device included in the authentication system according to the first embodiment will be described in detail. [Authentication Server] 8 is a diagram showing an example of a processing configuration (processing module) of the authentication server 10 according to the first embodiment. Referring to FIG. 8, the authentication server 10 includes a communication control unit 201, a user registration unit 202, a business registration unit 203, a specific data registration unit 204, an authentication unit 205, a public information provision unit 206, and a storage unit 207.

[0096] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the management server 20. The communication control unit 201 also transmits data to the management server 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201.

[0097] The user registration unit 202 is a means for realizing the above-mentioned user registration (system registration of a user). The user registration unit 202 acquires biometric information (facial image) and identification documents of a user (a user who wishes to receive services using biometric authentication; a system user).

[0098] The user registration unit 202 acquires the above two pieces of information (biometric information and identification document) by any means. For example, the user registration unit 202 acquires the above two pieces of information by receiving a user registration request sent by the terminal 40.

[0099] When the user registration unit 202 acquires biometric information (face image), it generates a feature amount (a feature vector consisting of a plurality of feature amounts) from the face image.

[0100] Since existing technology can be used for the process of generating feature quantities, detailed explanations thereof will be omitted. For example, the user registration unit 202 extracts the eyes, nose, mouth, etc. from the face image as feature points. The user registration unit 202 then calculates the positions of the feature points and the distances between the feature points as feature quantities, and generates a feature vector (vector information that characterizes the face image) consisting of multiple feature quantities.

[0101] The user registration unit 202 verifies that the generated feature does not overlap with any feature that has already been registered. The user registration unit 202 executes a matching process (one-to-many matching) using the generated feature and feature registered in two databases (a service information database and a public information database). If the matching process fails, the user registration unit 202 determines that the above-mentioned overlap does not occur.

[0102] If no duplication occurs, the user registration unit 202 performs identity verification of the user. Specifically, the user registration unit 202 acquires a face image for identity verification (hereinafter referred to as a verification face image) from the identification document. The user registration unit 202 extracts the verification face image from a predetermined area of ​​the identification document using a technique such as template matching.

[0103] When verifying the identity of the user, the user registration unit 202 performs one-to-one matching using the user's biometric information included in the user registration request and the biometric information obtained from the identification document. If the matching process is successful, the user registration unit 202 determines that the user's identity has been successfully verified.

[0104] Specifically, the user registration unit 202 generates features from each of the acquired face image and the verification face image. Next, the user registration unit 202 calculates the similarity between the two images. The user registration unit 202 performs threshold processing on the similarity and determines whether the user's identity has been verified based on the result of the threshold processing.

[0105] If the similarity is higher than the threshold, the user registration unit 202 determines that the identity verification is successful. On the other hand, if the similarity is equal to or lower than the threshold, the user registration unit 202 determines that the identity verification is unsuccessful.

[0106] If the identity verification is successful, the user registration unit 202 generates a user ID to be assigned to the user (issued to the user). For example, the user registration unit 202 generates a user ID by assigning a unique value each time it processes a user registration request.

[0107] The user registration unit 202 stores the generated user ID and feature amount in the business information database and the public information database.

[0108] More specifically, the user registration unit 202 adds a new entry to the two databases and stores the user ID and biometric information (features) in each database. For example, when performing user registration for user U1, the user registration unit 202 adds the entry shown in the bottom row of Figures 9A and 10A. At the user registration stage, the business operator ID, service user ID, and public information identification data have not been entered into the system, so nothing is set in these fields.

[0109] The user registration unit 202 transmits a response to the user registration request to the terminal 40. When the user registration unit 202 stores the user ID and biometric information in the business information database and the public information database, it transmits an affirmative response to the terminal 40 indicating that the user registration was successful. If the user ID and biometric information cannot be stored in the two databases, the user registration unit 202 transmits a negative response to the terminal 40 indicating that the user registration has failed. For example, if the user has already been registered or if identity verification has failed, a negative response is transmitted to the terminal 40. The user registration unit 202 may transmit a negative response to the terminal 40 including the above-mentioned reason why the user registration has failed.

[0110] In this way, when the user registration unit 202 receives a user registration request including the user's biometric information and the user's identification document, it verifies the user's identity based on the identification document. If the user registration unit 202 has successfully verified the user's identity, it registers the biometric information and user ID (third ID) of the user in the database. If the user registration unit 202 has successfully verified the user's identity, it issues the user ID to the user.

[0111] The business registration unit 203 is a means for processing business registration requests sent from each business and registering the business in the system. When the business registration unit 203 receives a business registration request including a business ID and a user ID from a first business (e.g., a private business), it generates a service user ID. The business registration unit 203 issues the generated service user ID to the first business.

[0112] The business registration unit 203 searches the business information database using the user ID included in the acquired business registration request as a key. The business registration unit 203 checks the business ID field of the user identified by the search.

[0113] The business registration unit 203 determines whether the business ID included in the business registration request acquired from the management server 20 is set in the business ID field. If the business ID acquired from the management server 20 is already registered in the business information database, the business registration unit 203 notifies the management server 20 of this fact. In this case, the service (business) that the user is attempting to register is already registered in the business information database, so the business registration unit 203 sends a "negative response" in response to the business registration request.

[0114] On the other hand, if the business ID included in the business registration request is not set in the business ID field of the identified user, the business registration unit 203 generates a service user ID corresponding to the user and business.

[0115] As described above, the service user ID is identification information that is uniquely determined from a combination of a user and a business. For example, the business registration unit 203 calculates a hash value using the user ID and the business ID, and sets the calculated hash value as the service user ID. Specifically, the business registration unit 203 calculates a concatenated value of the user ID and the business ID, and then calculates a hash value of the calculated concatenated value to generate the service user ID.

[0116] Note that the generation of the service user ID using the hash value described above is merely an example and is not intended to limit the method of generating the service user ID. The service user ID may be any information that can uniquely identify a combination of a system user and a business. For example, the business registration unit 203 may assign a unique value each time it processes a business registration request and use this value as the service user ID.

[0117] When the service user ID is generated, the business registration unit 203 registers the two IDs (business ID, service user ID) in the business information database. For example, when user U1 registers service information for business S1, the two IDs are added to the entry shown at the bottom of Fig. 9B.

[0118] Since service information is registered for each business operator, multiple business operator IDs and service user IDs may be set for one user. For example, if user U1 registers service information for each of businesses S1 and S2, the entries in the second and third lines of Figure 9C are generated. Note that if user U2 registers service information for business operator S1, the entry in the bottom row of Figure 9C is generated.

[0119] After processing the business registration request, the business registration unit 203 transmits a response to the request to the management server 20. Specifically, if the service user ID is successfully generated and stored in the business information database, the business registration unit 203 transmits an affirmative response including the generated service user ID to the management server 20.

[0120] On the other hand, if a service user ID is not generated, the business registration unit 203 transmits a negative response to the management server 20. At that time, the business registration unit 203 may transmit a negative response to the management server 20 including the reason why the business registration request was not processed normally (for example, business registration has already been performed, etc.).

[0121] The specific data registration unit 204 is a means for processing the public information provision permission sent from the user (terminal 40 possessed by the system user) and registering the public information specification data in the system. When the specific data registration unit 204 receives the public information provision permission including the user ID and the public information specification data, it stores the public information specification data in the entry corresponding to the user ID.

[0122] The specific data registration unit 204 searches the public information database using the user ID included in the acquired public information provision permission as a key. If the search fails (if the user ID is not registered in the public information database), the specific data registration unit 204 determines that the user ID is not registered in the system.

[0123] If the search is successful, the specific data registration unit 204 stores the public information specific data included in the obtained public information provision permission in the entry of the identified user. More specifically, the specific data registration unit 204 determines the public information corresponding to the data based on the public information specific data, and writes the public information specific data in the corresponding field of the public information database. For example, when user U1 gives consent for the provision of information regarding the items written in his / her passport, the acquired passport number is written in the passport number field of the entry shown at the bottom of FIG. 10B.

[0124] After processing the public information provision permission, the specific data registration unit 204 transmits a response to the permission to the terminal 40. Specifically, when the public information specific data is stored in the public information database, the specific data registration unit 2034 transmits an affirmative response to the terminal 40 indicating that the permission has been processed normally.

[0125] On the other hand, if the public information identification data is not stored in the public information database for reasons such as the user ID acquired from the terminal 40 not being registered in the public information database, the identification data registration unit 204 transmits a negative response to the terminal 40. At that time, the identification data registration unit 204 may transmit a negative response to the terminal 40 including the reason why the public information provision permission was not processed normally (for example, the user is not registered in the system, etc.).

[0126] The business information databases and public information databases shown in Figures 9A to 9C, 10A to 10B, etc. are merely examples and are not intended to limit the information stored in these databases. For example, facial images may be registered in each database instead of features for authentication. That is, features may be generated from facial images registered in each database each time authentication is performed.

[0127] The authentication unit 205 is a means for processing an authentication request from a business operator. The operation of the authentication unit 205 will be described below with reference to the drawings. Fig. 11 is a flowchart showing an example of the operation of the authentication unit 205 according to the first embodiment.

[0128] The authentication unit 205 extracts the feature amount and the business ID included in the authentication request, searches the business information database using the extracted feature amount and the business ID as keys, and identifies the corresponding service user ID.

[0129] Specifically, the authentication unit 205 sets the feature extracted from the authentication request as the feature on the matching side and the feature stored in the business information database as the feature on the registration side, and performs one-to-many matching (step S101). At this time, the authentication unit 205 calculates the similarity between the feature on the matching side and each of the multiple registration sides. The similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0130] The authentication unit 205 determines whether or not there is a feature whose similarity with the feature to be compared is equal to or greater than a predetermined value among the multiple feature amounts registered in the business information database (step S102). If there is no such feature amount (step S102, No branch), the authentication unit 205 sets the authentication result to "authentication failed" (step S103).

[0131] If such a feature exists (step S102, Yes branch), the authentication unit 205 identifies the entry (user) with the feature that has the highest similarity (step S104).The authentication unit 205 determines whether or not there is a business ID that matches the business ID included in the authentication request among at least one or more business IDs associated with the identified user. That is, the authentication unit 205 determines whether the business ID acquired from the business is registered in the specified user (entry) in the business information database (step S105).

[0132] If the business ID is registered (step S105, Yes branch), the authentication unit 205 determines that the authentication of the user has been successful and sets the authentication result to "authentication successful" (step S106). On the other hand, if the business ID is not registered (step S105, No branch), the authentication unit 205 sets the authentication result to "authentication failed" (step S103).

[0133] The authentication unit 205 transmits the result of processing the authentication request to the management server 20 (step S107). If the authentication result is "authentication successful", the authentication unit 205 transmits a positive response including the biometric information and the service user ID identified by the business operator ID to the management server 20. If the authentication result is "authentication failed", the authentication unit 205 transmits a negative response to the management server 20.

[0134] 9C, when the authentication request includes the feature "FV1" and the provider ID "S1," the entries (users) in the second and third lines are identified by the feature FV1, and the entry in the second line is identified by the provider ID "S1." As a result, the authentication request is processed normally, and an affirmative response including the service user ID "U1S1" is sent to the management server 20.

[0135] On the other hand, if the authentication request contains the feature of "FV2" and the provider ID of "S2," the feature identifies the bottom entry, but the provider ID of that entry is "S1," not "S2," so the authentication request is not processed normally. As a result, a negative response is sent to the management server 20.

[0136] In this way, the authentication unit 205 executes authentication processing in response to receiving an authentication request including biometric information of the person to be authenticated and the business ID (first ID) of the first business from a first business (for example, a private business), and transmits the service user ID (second ID) of the person who has been successfully authenticated (the person to be authenticated who has been determined to have been successfully authenticated) to the first business. At this time, the authentication unit 205 executes one-to-N matching using the biometric information stored in the business information database and the biometric information of the person to be authenticated included in the authentication request. The authentication unit 205 determines that the authentication processing is successful when the business ID included in the authentication request is stored in the business information database in association with the user identified by the one-to-N matching.

[0137] The public information providing unit 206 is a means for processing a public information provision request from a business operator and providing the business operator with public information. The operation of the public information providing unit 206 will be described below with reference to the drawings. Fig. 12 is a flowchart showing an example of the operation of the public information providing unit 206 according to the first embodiment.

[0138] The public information providing unit 206 extracts the feature amount and the public information type included in the public information request, and executes a matching process (1:N matching process) using the extracted feature amount and the feature amount registered in the public information database (step S201).

[0139] The public information providing unit 206 determines whether or not there is a feature whose similarity with the feature to be compared is equal to or greater than a predetermined value among the multiple feature quantities registered in the public information database (step S202). If such a feature quantity does not exist (step S202, No branch), the public information providing unit 206 transmits a negative response to the staff terminal 31 indicating that the requested public information cannot be provided (step S203).

[0140] If such a feature exists (step S202, Yes branch), the public information providing unit 206 identifies the entry (user) with the feature that has the highest similarity (step S204). The public information providing unit 206 attempts to read a setting value from the field corresponding to the public information type of the public information provision request among the public information specifying data fields of the identified entry. That is, the public information providing unit 206 determines whether public information specifying data corresponding to the public information type is registered for the identified user (entry) in the public information database (step S205).

[0141] If the public information specifying data is not registered (step S205, No branch), the public information providing unit 206 transmits a negative response to the staff terminal 31 indicating that the requested public information cannot be provided (step S203).

[0142] If the public information specifying data is registered (step S205, Yes branch), the public information providing unit 206 transmits the registered public information specifying data to the corresponding public server in the public server group (step S206).

[0143] The official information providing unit 206 acquires official information (e.g., passport information) corresponding to the official information identification data from the official server (step S207). In response to the information acquisition, the official information providing unit 206 transmits an affirmative response including the requested official information to the staff terminal 31 (step S208).

[0144] For example, in the example of FIG. 10B, if the feature "FV1" is included in the official information provision request, the feature FV1 identifies the final entry (user). Furthermore, if the official information type included in the official information provision request is "passport", corresponding official information identification data (passport number) exists, and therefore the official information provision unit 206 can obtain the corresponding passport information by transmitting the passport number to the passport server 41. The official information provision unit 206 transmits an affirmative response including the obtained passport information to the staff terminal 31.

[0145] On the other hand, when a request for providing official information is received in which the feature amount is "F1V" and the official information type is "health insurance card," the feature amount identifies the entry in the last row of Figure 10B. However, since the official information identification data (health insurance card number) corresponding to the health insurance card is not set in the entry in the last row, the official information providing unit 206 transmits a negative response to the staff terminal 31 indicating that the official information cannot be provided.

[0146] In this way, the public information providing unit 206 receives a public information request from a second business (e.g., a city hall) that includes biometric information of a user whose public information the second business wishes to view and the type of public information the second business wishes to view. The public information providing unit 206 uses the public information identification data to acquire the public information the user wishes to view from a public server that stores the public information. The public information providing unit 206 transmits the acquired public information to the second business. The public information providing unit 206 also identifies the user whose public information the second business wishes to view (a user who visited a city hall, etc.) by performing one-to-many matching using the biometric information stored in the public information database and the biometric information included in the public information request. At this time, the public information providing unit 206 transmits to the public server the public information identification data corresponding to the type of public information included in the public information request, among the multiple public information identification data of the identified user.

[0147] The storage unit 207 stores information necessary for the operation of the authentication server 10. An operator information database and a public information database are constructed in the storage unit 207. Using these two databases, the storage unit 207 stores the user's biometric information, an operator ID (first ID) that identifies the operator that provides the service to the user, and a service user ID (second ID) that is uniquely determined by the combination of the user and the operator, in association with each other. Furthermore, the storage unit 207 stores the user's biometric information, etc., in association with public information identification data for identifying public information the provision of which is permitted by the user. The public information database can store multiple public information identification data for each user. [Administration Server] 13 is a diagram showing an example of a processing configuration (processing module) of the management server 20 according to the first embodiment. Referring to FIG. 13, the management server 20 includes a communication control unit 301, a service information acquisition unit 302, a service information registration unit 303, an authentication request unit 304, and a storage unit 305.

[0148] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the authentication server 10 and the authentication terminal 30. The communication control unit 301 also transmits data to the authentication server 10 and the authentication terminal 30. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301.

[0149] The service information acquisition unit 302 is a means for acquiring service information required when a business provides a service. For example, if the business is a "retail store," the service information acquisition unit 302 acquires payment-related information (e.g., credit card information, bank account information) in addition to the user's name, etc. Alternatively, if the business is an "accommodation business," the service information acquisition unit 302 acquires reservation information regarding accommodation (e.g., the date of stay, etc.) in addition to the user's name, etc.

[0150] In addition to the above-mentioned name, etc., the service information acquisition unit 302 acquires the user ID that was assigned when the user registered with the system.

[0151] The service information acquisition unit 302 acquires the user ID and the service information by any means. In the first embodiment, the service information acquisition unit 302 acquires the above two pieces of information from a service information registration request transmitted by the terminal 40.

[0152] The service information acquisition unit 302 passes the acquired user ID and service information to the service information registration unit 303 .

[0153] The service information registration unit 303 is a means for registering the acquired service information in the user information database.

[0154] The service information registration unit 303 transmits a business registration request including the user ID and business ID acquired from the service information acquisition unit 302 to the authentication server 10 .

[0155] The service information registration unit 303 acquires a response to the business registration request from the authentication server 10. If the acquired response is a "negative response," the service information registration unit 303 notifies the user of this. For example, the service information registration unit 303 transmits a negative response (negative response to the service information registration request) including a message that the service registration has already been completed to the terminal 40.

[0156] If the acquired response is an "affirmative response," the service information registration unit 303 transmits an affirmative response to the service information registration request to the terminal 40. The service information registration unit 303 also registers the service user ID included in the response and the service information acquired from the service information acquisition unit 302 in the user information database. For example, when the management server 20 of the business operator S1 processes the service information registration request from the user U1, the entry shown in the bottom row of Fig. 14 is added to the user information database.

[0157] The authentication request unit 304 is a means for requesting the authentication server 10 to authenticate the user.

[0158] When the authentication request unit 304 acquires biometric information (face image) from the authentication terminal 30, it generates features from the face image. The authentication request unit 304 transmits an authentication request including the generated features and the business ID to the authentication server 10.

[0159] If the response from the authentication server 10 is a "negative response" (if the authentication has failed), the authentication request unit 304 notifies the authentication terminal 30 of this fact.

[0160] If the response from the authentication server 10 is an "affirmative response" (if authentication is successful), the authentication request unit 304 extracts the service user ID included in the affirmative response from the authentication server 10. The authentication request unit 304 searches the user information database using the service user ID as a key, and identifies the corresponding entry.

[0161] The authentication request unit 304 reads out the service information set in the service information field of the identified entry and transmits it to the authentication terminal 30. For example, in the example of FIG. 14, if the service user ID is "U1S1", the service information "SI01" at the bottom is transmitted to the authentication terminal 30.

[0162] The storage unit 305 stores information necessary for the operation of the management server 20. A user information database is constructed in the storage unit 305. [Authentication terminal] 15 is a diagram showing an example of the processing configuration (processing modules) of the authentication terminal 30 according to the first embodiment. Referring to FIG. 15, the authentication terminal 30 includes a communication control unit 401, a biometric information acquisition unit 402, a service providing unit 403, a message output unit 404, and a storage unit 405.

[0163] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the management server 20. The communication control unit 401 also transmits data to the management server 20. The communication control unit 401 passes data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401.

[0164] The biometric information acquisition unit 402 is a means for controlling the camera and acquiring biometric information (face image) of the user. The biometric information acquisition unit 402 captures an image in front of the device periodically or at a predetermined timing. The biometric information acquisition unit 402 determines whether the acquired image contains a human face image, and if a face image is included, extracts the face image from the acquired image data.

[0165] Since existing technologies can be used for the facial image detection process and facial image extraction process by the biometric information acquisition unit 402, detailed description thereof will be omitted. For example, the biometric information acquisition unit 402 may extract a facial image (face region) from image data using a learning model trained by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 402 may extract a facial image using a method such as template matching.

[0166] The biometric information acquisition unit 402 passes the extracted facial image to the service provision unit 403 .

[0167] The service providing unit 403 is a means for providing a predetermined service to a user. The service providing unit 403 transmits the face image acquired from the biometric information acquiring unit 402 to the management server 20. The management server 20 returns service information corresponding to the facial image (for example, hotel reservation information including the user's name, etc.). The service providing unit 403 uses the returned service information to provide the user with a service.

[0168] A detailed description of the service providing unit 403 that uses the service information will be omitted. The service providing unit 403 may perform processing according to the content of the service to be provided. For example, if the authentication terminal 30 is a check-in terminal installed in a hotel lobby, the service providing unit 403 may perform check-in processing according to the acquired reservation information (service information).

[0169] The message output unit 404 is a means for outputting various messages to the user. For example, the message output unit 404 outputs a message regarding the authentication result of the user, a message regarding the provision of a service, etc. The message output unit 404 may display the message using a display device such as a liquid crystal monitor, or may play an audio message using an audio device such as a speaker.

[0170] The storage unit 405 stores information necessary for the operation of the authentication terminal 30 . [Staff terminal] 16 is a diagram showing an example of the processing configuration (processing module) of the staff terminal 31 according to the first embodiment. Referring to FIG. 16, the staff terminal 31 includes a communication control unit 501, an information request unit 502, a message output unit 503, and a storage unit 504.

[0171] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the authentication server 10. The communication control unit 501 also transmits data to the authentication server 10. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 501.

[0172] The information request unit 502 is a means for requesting the authentication server 10 to provide information related to the user's public information. The information request unit 502 displays a GUI (Graphical User Interface) for selecting public information to be acquired from the authentication server 10 in response to an operation by a business employee or the like. For example, the information request unit 502 displays a GUI such as that shown in Fig. 17. The information request unit 502 acquires the type of public information (public information type) required when providing a service using the GUI such as that shown in Fig. 17.

[0173] The information requesting unit 502 may change the options displayed in FIG. 17 depending on the location where the information requesting unit 502 is installed, etc. For example, if the employee terminal 31 is a terminal installed in a local government such as a city hall, the information requesting unit 502 displays a screen as shown in FIG. 17. On the other hand, if the employee terminal 31 is a terminal installed in a private business, a display may be displayed that allows selection of documents necessary for the business of the private business. For example, if the employee terminal 31 is a terminal installed in a duty-free shop, only options related to passports may be displayed. Alternatively, when an employee performs an operation related to a request for official information, the information requesting unit 502 may automatically send a predetermined request for official information.

[0174] Furthermore, the information requesting unit 502 acquires biometric information of the user before or after the selection of the above-mentioned official information. For example, the information requesting unit 502 acquires biometric information (facial image) of the user using a GUI such as that shown in FIG. 18. The camera provided in the staff terminal 31 (the camera connected to the staff terminal 31) is installed so as to be able to capture images of users who visit the staff. Furthermore, when acquiring the facial image of the user, the information requesting unit 502 preferably notifies the user to that effect. The information requesting unit 502 generates features from the acquired facial image.

[0175] The information request unit 502 transmits to the authentication server 10 a public information request including the acquired public information type and the generated feature amount.

[0176] The information request unit 502 passes the response (response to the public information request) acquired from the authentication server 10 to the message output unit 503 .

[0177] The message output unit 503 is a means for outputting various messages to staff members and the like. If a negative response is received from the authentication server 10, the message output unit 503 notifies the staff member or the like that acquisition of the official information has failed.

[0178] When an affirmative response is received from the authentication server 10, the message output unit 503 outputs the public information included in the affirmative response. For example, the message output unit 503 displays a message as shown in FIG.

[0179] The storage unit 504 stores information necessary for the operation of the staff terminal 31 . [Device] 20 is a diagram illustrating an example of a processing configuration (processing module) of the terminal 40 according to the first embodiment. Referring to FIG. 20, the terminal 40 includes a communication control unit 601, a user support unit 602, and a storage unit 603.

[0180] The communication control unit 601 is a means for controlling communication with other devices. For example, the communication control unit 601 receives data (packets) from the authentication server 10. The communication control unit 601 also transmits data to the authentication server 10. The communication control unit 601 passes data received from other devices to other processing modules. The communication control unit 601 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 601.

[0181] The user support unit 602 is a means for supporting a user who wishes to receive a service through biometric authentication.

[0182] The user support unit 602 starts operation when the support application installed in the terminal 40 is started. After starting operation, the user support unit 602 displays a menu (GUI display) as shown in Fig. 21 and acquires the operation desired by the user.

[0183] The user support unit 602 includes sub-modules including a user registration support unit 611 , a service registration support unit 612 , and a provision permission support unit 613 .

[0184] The user registration support unit 611 is started in response to the selection of "user registration" shown in Fig. 21. The user registration support unit 611 is a means for supporting (realizing) the user's system registration.

[0185] User registration requires users to enter their biometric information and identity documents into the system. The user registration support unit 611 displays a GUI for acquiring this information.

[0186] For example, the user registration support unit 611 displays a GUI as shown in Fig. 22. For example, the user presses the "Select File" button shown in Fig. 22 to specify image data of a face image to be registered in the system. The specified face image is displayed in the preview area (displayed as a selected face image in Fig. 22). When registering the previewed face image, the user presses the "Enter" button.

[0187] Following acquisition of the facial image, the user registration support unit 611 acquires an identification document. For example, the user registration support unit 611 displays a GUI such as that shown in FIG. 23. For example, the user takes an image of the identification document using the camera of the terminal 40. The user presses the "Select File" button and specifies the image of the captured identification document. Thereafter, the user presses the "Enter" button and inputs the identification document.

[0188] Examples of identity verification documents that can be registered in the system include documents with a facial image such as a passport or driver's license (documents issued by public institutions that contribute to identity verification).Identity verification documents include not only paper documents but also electronic documents.

[0189] The user registration support unit 611 transmits a user registration request including the acquired biometric information (face image) and identification document to the authentication server 10.

[0190] When receiving an affirmative response (a response indicating that the user registration has been successfully completed) from the authentication server 10, the user registration support unit 611 stores in the storage unit 603 the user ID included in the affirmative response.

[0191] Furthermore, the user registration support unit 611 outputs a message or the like in response to a response (positive response, negative response) received from the authentication server 10.

[0192] The service registration support unit 612 is activated in response to the selection of "service information registration" shown in Fig. 21. The service registration support unit 612 is a means for supporting (realizing) the registration of service information by the user.

[0193] The service registration support unit 612 displays the business types of businesses participating in the system, allowing the user to select the business type in which the user wishes to receive service. For example, the service registration support unit 612 displays a GUI such as that shown in Fig. 24, allowing the user to select the type of service they wish to receive.

[0194] Thereafter, the service registration support unit 612 displays a GUI that allows the user to select a specific business (service provider). For example, if the user selects "hotel" in Fig. 24, the service registration support unit 612 displays a GUI such as that shown in Fig. 25. Using the GUI such as that shown in Fig. 25, the service registration support unit 612 acquires information about a business that the user wishes to use (a business that will register service information) from among the businesses participating in the authentication infrastructure.

[0195] The service registration support unit 612 acquires service information corresponding to the business selected by the user. For example, if the user selects a hotel business, the service registration support unit 612 displays a GUI for acquiring hotel reservation information (see FIG. 26).

[0196] The service registration support unit 612 transmits a service information registration request including the service information acquired using a GUI such as that shown in Fig. 26 and the user's user ID (user ID issued by the authentication server 10) to the management server 20 of the provider selected by the user. For example, in the example of Fig. 2, if the user wishes to receive a service from provider S1, the service registration support unit 612 transmits the service information registration request to the management server 20 of provider S1. The service registration support unit 612 determines the management server 20 to which the service information registration request is to be transmitted by referring to table information or the like that associates the provider selected using a GUI such as that shown in Fig. 25 with the addresses of the management servers 20 of the provider.

[0197] The service registration support unit 612 determines the service information to be acquired by referring to information associating the selected business with the service information to be acquired. Alternatively, the service registration support unit 612 may inquire about the items to be acquired from the management server 20 of the business selected by the user, or may acquire an input form for entering the service information. In the above example, after the user selects the business S1, the service registration support unit 612 may acquire the items to be acquired, the input form, etc. from the management server 20 of the business S1.

[0198] Furthermore, the service registration support unit 612 outputs a message or the like in response to a response (positive response, negative response) received from the management server 20.

[0199] The provision permission support unit 613 is activated in response to the selection of "Provision permission for public information" shown in Fig. 21. The provision permission support unit 613 is a means for supporting (realizing) the user's permission to provide public information.

[0200] The provision permission support unit 613 displays a GUI that enables the user to select the public information to be provided. For example, the provision permission support unit 613 displays a GUI as shown in FIG.

[0201] When the public information (public information type) to be provided is selected, the provision permission support unit 613 displays a GUI for inputting public information identification data corresponding to the public information. For example, the provision permission support unit 613 acquires the public information identification data using a GUI such as that shown in FIG.

[0202] The provision permission support unit 613 transmits the public information provision permission including the user ID of the user and the public information specifying data to the authentication server 10.

[0203] The provision permission support unit 613 outputs a message or the like according to the response (positive response, negative response) received from the authentication server 10.

[0204] The storage unit 603 is a means for storing information necessary for the operation of the terminal 40 . [Public Server] A description of the internal configuration of the public server will be omitted. The public server only needs to have a database that stores public information identification data in association with public information. The public server searches the database using the public information identification data as a key and transmits the corresponding public information to the authentication server 10. [System Operation] Next, a description will be given of the operation of the authentication system according to the first embodiment. Note that the operation will be described for the service information registration phase, the official information provision permission phase, and the service provision phase, and a description of the user registration phase will be omitted.

[0205] FIG. 29 is a sequence diagram showing an example of operations related to the service information registration phase of the authentication system according to the first embodiment.

[0206] The management server 20 acquires service information (information necessary to provide the service) and a user ID from the user (terminal 40) (step S01).

[0207] The management server 20 transmits a business registration request including the acquired user ID and business ID to the authentication server 10 (step S02).

[0208] The authentication server 10 generates a service user ID using the acquired user ID and business ID (step S03).

[0209] The authentication server 10 stores the business ID and the service user ID in the business information database (step S04).

[0210] The authentication server 10 transmits a response (a positive response to the business registration request) including the service user ID to the management server 20 (step S05).

[0211] The management server 20 associates the service information acquired in step S01 with the service user ID acquired from the authentication server 10 and stores them in the user information database (step S06).

[0212] FIG. 30 is a sequence diagram showing an example of operations related to the official information provision permission phase of the authentication system according to the first embodiment.

[0213] The terminal 40 acquires the type of public information and public information identification data that the user consents to be provided using a GUI or the like (step S11).

[0214] The terminal 40 transmits a public information provision permission including the user's user ID and public information identification data to the authentication server 10 (step S12). The terminal 40 may transmit a public information provision permission including the public information type to the authentication server 10. That is, the terminal 40 may clearly indicate to the authentication server 10 the type of public information that the user has permitted to be provided.

[0215] The authentication server 10 identifies the user who is giving permission to provide information based on the user ID (step S13).

[0216] The authentication server 10 stores the public information identification data in the public information identification field of the identified user (step S14).

[0217] The authentication server 10 transmits an affirmative response to the public information provision permission to the terminal 40 (step S15).

[0218] The terminal 40 displays a message or the like according to the acquired response (step S16).

[0219] 31 is a sequence diagram showing an example of the operation relating to the service provision phase of the authentication system according to the first embodiment. With reference to FIG. 31, the system operation when a service is provided using service information will be described.

[0220] The authentication terminal 30 acquires a facial image (biometric information) of the user, and transmits the acquired facial image to the management server 20 (step S21).

[0221] The management server 20 generates a feature amount from the acquired face image (step S22).

[0222] The management server 20 transmits an authentication request including the generated feature amount and the business ID to the authentication server 10 (step S23).

[0223] The authentication server 10 executes authentication processing using the feature amount and the business ID included in the authentication request, and identifies the corresponding service user ID (step S24).

[0224] The authentication server 10 transmits an affirmative response including the identified service user ID to the management server 20 (transmitting the service user ID; step S25).

[0225] The management server 20 searches the user information database using the acquired service user ID, and identifies the corresponding service information (step S26).

[0226] The management server 20 transmits the identified service information to the authentication terminal 30 (step S27).

[0227] The authentication terminal 30 provides the service using the acquired service information (step S28).

[0228] 32 is a sequence diagram showing an example of operations relating to the service provision phase of the authentication system according to the first embodiment. With reference to FIG. 32, the system operations when a service is provided using public information will be described.

[0229] The staff terminal 31 acquires the biometric information (face image) of the user (user receiving the service) and the type of official information to be referenced in response to an operation by a staff member or the like (step S31). The staff terminal 31 generates feature amounts from the face image.

[0230] The staff terminal 31 transmits a request for providing public information including the feature amount of the user and the type of public information to the authentication server 10 (step S32).

[0231] The authentication server 10 executes a matching process using the feature amount included in the request for public information provision, and identifies the corresponding user (step S33).

[0232] The authentication server 10 reads out from the public information database, among the public information specifying data of the identified user, data corresponding to the public information type included in the public information provision request (obtaining public information specifying data; step S34).

[0233] The authentication server 10 transmits the acquired public information identification data to the corresponding public server (step S35).

[0234] The public server reads out public information corresponding to the received public information identification data from the database, and transmits the public information to the authentication server 10 (step S36).

[0235] The authentication server 10 transmits an affirmative response to the official information provision request, including the official information, to the staff terminal 31 (transmission of official information; step S37).

[0236] The staff terminal 31 outputs the received official information (step S38). For example, the staff terminal 31 presents the acquired official information to the staff member.

[0237] As described above, in the authentication system according to the first embodiment, the authentication server 10 can process requests from private businesses and public institutions. In other words, whether a private business or a public institution is required to build its own authentication system, biometric authentication can be easily used. Specifically, a private business (a service provider using service information) only needs to acquire the user's user ID and service information and request the authentication server 10 to register the business when providing a service. By entrusting the actual processing of biometric authentication to an authentication center, the private business can easily provide a service using biometric authentication. Similarly, a public institution (a service provider using public information) only needs to request permission from the user to provide public information in advance when providing a service. By notifying the authentication server 10 of the user's biometric information and necessary public information, the public institution can access the user's public information without actually performing the biometric authentication processing. Furthermore, by registering in advance in the system the public information (public information specific data; for example, a passport number) for which users consent to the provision of information, they can receive administrative services from public institutions even if they do not carry official documents (identification documents; passports, etc.). Furthermore, users can select the public information for which they consent to the provision of information, allowing for flexible consent to the provision of information according to the nature of the public information, etc.

[0238] Furthermore, the user's biometric information is stored in the authentication server 10, and each business does not possess this biometric information. The user's service information (personal information such as name) is stored in the management server 20 managed and operated by the business, and the authentication server 10 does not possess this service information. By distributing information in this manner, the authentication system according to the first embodiment provides an authentication infrastructure that is robust against information leaks. That is, biometric information (especially feature values) that is not linked to service information is simply a list of numbers and is of little value to criminals and the like. Therefore, even if information leaks from the authentication server 10, the impact is limited. Furthermore, the authentication server 10 does not store the actual content of public information about each user. Since the authentication server 10 obtains public information from the corresponding public server each time it is needed, the possibility of public information leaking from the authentication server 10 is low. The configuration of the authentication system according to the first embodiment allows participants in the authentication system (users receiving services and businesses providing services) to use the authentication system with peace of mind.

[0239] Next, the hardware of each device constituting the authentication system will be described. Fig. 33 is a diagram showing an example of the hardware configuration of the authentication server 10.

[0240] The authentication server 10 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 33. For example, the authentication server 10 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0241] However, the configuration shown in Fig. 33 is not intended to limit the hardware configuration of the authentication server 10. The authentication server 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the authentication server 10 is not intended to be limited to the example shown in Fig. 33, and for example, the authentication server 10 may include multiple processors 311.

[0242] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0243] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0244] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.

[0245] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0246] The functions of the authentication server 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by a semiconductor chip.

[0247] The management server 20, authentication terminal 30, staff terminal 31, terminal 40, etc. can also be configured using information processing devices, similar to the authentication server 10, and their basic hardware configurations are no different from those of the authentication server 10, so a description thereof will be omitted. For example, the authentication terminal 30 may be equipped with a camera for capturing images of users.

[0248] The authentication server 10 is equipped with a computer, and the functions of the authentication server 10 can be realized by causing the computer to execute a program. The authentication server 10 also executes a control method for the authentication server by the program. [Variations] The configuration, operation, etc. of the authentication system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0249] In the above embodiment, the case where the authentication server 10 has a business information database and a public information database has been described. However, these databases may be constructed in a database server different from the authentication server 10. Furthermore, the authentication system may include the various means (authentication unit 205, public information providing unit 206, etc.) described in the above embodiment.

[0250] In the above embodiment, a case has been described in which two databases are used to store and manage biometric information, etc., of a user. However, the authentication server 10 may manage biometric information, etc., of a user using a database in which the two databases are integrated. For example, the authentication server 10 may perform biometric authentication and provide information using an authentication information database (corresponding to database 101) as shown in FIG. 34.

[0251] In the above embodiment, it has been described that official documents (passports, health insurance cards) issued domestically are the subject of information provision, but the subject of information provision is not limited to documents issued by domestic public institutions. That is, official information regarding official documents issued by foreign public institutions may be provided from the authentication system. Even in this case, it is sufficient that official information identification data corresponding to the foreign official information is registered in the authentication system. Furthermore, from a similar perspective, the users of the present disclosure may be not only Japanese people but also foreigners. In the above embodiment, the operation of the authentication system was described using a public institution as an example of the entity requesting the provision of official information. However, the entity requesting the provision of official information may also be a private business. For example, when a duty-free shop checks a customer's passport, the request for official information described in the above embodiment may be sent from a terminal of the duty-free shop (a terminal equivalent to the staff terminal 31) to the authentication server 10.

[0252] In addition, a public institution may provide a service using the service information. For example, hospital reservation information may be registered as service information at a hospital, and the reservation information may be identified by the biometric authentication described in the above embodiment.

[0253] In the above embodiment, it has been described that when a user registers, the authentication server 10 generates a user ID and issues the generated user ID to the user. However, the user ID may be determined by the user and input by the user into the system. For example, the ID, password, or a combination thereof used by the user to log in to the authentication server 10 may be used as the user ID.

[0254] In the above embodiment, it has been described that the user registration phase and the service information registration phase are executed at different times, but these phases may be executed substantially at the same time. For example, the above two registration phases may be executed using an authentication terminal 30 installed at a business operator to which the user wishes to provide a service. Specifically, the user may use the authentication terminal 30 to perform user registration (input of biometric information and identification documents) and then continuously register service information (input of user ID and service information).

[0255] Similarly, the user registration phase and the official information provision permission phase may be executed at substantially the same time. The user may operate the terminal 40 to input biometric information, identification documents, and the type of official information that the user is willing to provide to the authentication server 10.

[0256] In the above embodiment, one operator ID is assigned to one operator, but one operator ID may be assigned to multiple operators. Multiple operators may be grouped together and an operator ID may be issued for each group. For example, if operators S1 and S2 cooperate to provide the same service, a common operator ID may be issued to these operators S1 and S2.

[0257] In the above embodiment, a case has been described in which biometric information related to "features generated from a facial image" is transmitted from the management server 20 or the staff terminal 31 to the authentication server 10. However, biometric information related to a "facial image" may also be transmitted from the management server 20 or the like to the authentication server 10. In this case, the authentication server 10 may generate features from the acquired facial image and execute the authentication process (matching process).

[0258] In the above embodiment, the authentication terminal 30 acquires a facial image and the management server 20 generates features from the facial image. However, the authentication terminal 30 may generate features from the facial image and transmit the generated features to the management server 20. In other words, the management server 20 does not have to generate features.

[0259] When processing the public information provision permission from the terminal 40, the authentication server 10 may verify the validity of the public information identification data (or may verify whether the public information identification data is correct). If a checksum or the like is attached to the public information identification data, the authentication server 10 may verify the validity of the public information identification data using the checksum. Alternatively, the authentication server 10 may transmit the acquired public information identification data to the corresponding public server and request verification of its validity.

[0260] Staff terminal 31 may provide authentication server 10 with information on multiple types of official information. For example, staff terminal 31 may send a request to authentication server 10 for official information regarding the information written on the passport and health insurance card of the same user. In this case, authentication server 10 may transmit the passport number and health insurance card number to passport server 41 and health insurance card server 42, respectively, and obtain the necessary official information. For example, consider a case where staff terminal 31 is installed in a drugstore. In this case, a staff member (pharmacist) may operate staff terminal 31 to obtain health insurance card information when providing medicine to a patient, or to obtain passport information when processing a product purchaser's tax exemption. In this way, staff terminal 31 can be a hybrid terminal that obtains different official information from authentication server 10 depending on the user's (staff member's) operation, etc.

[0261] In the above embodiment, it has been described that the authentication terminal 30 transmits an authentication request (biometric information) of a user to the authentication server 10 via the management server 20. However, the authentication terminal 30 may transmit an authentication request directly to the authentication server 10. That is, the authentication terminal 30 may transmit an authentication request (biometric information) to the authentication server 10 directly or indirectly.

[0262] Furthermore, in the above embodiment, a case has been described in which the staff terminal 31 sends a request for official information directly to the authentication server 10. However, the staff terminal 31 may also send the request for official information to the authentication server 10 via a server connected between the authentication server 10 and the staff terminal 31. In other words, the staff terminal 31 may send the request for official information (biometric information) to the authentication server 10 directly or indirectly.

[0263] A single terminal (authentication terminal 30, staff terminal 31) may transmit a user's authentication request and a request for official information provision to the authentication server 10. For example, consider a case where the authentication terminal 30 shown in FIG. 2 is installed in a hotel. In this case, the authentication terminal 30 may have the function of a check-in terminal that handles user check-in processing and the function of a tax-free terminal that handles tax-free processing. When functioning as a check-in terminal, the authentication terminal 30 directly or indirectly transmits an authentication request including biometric information of a guest visiting the hotel to the authentication server 10. The authentication terminal 30 proceeds with the check-in procedure based on the user's service information (reservation information). When functioning as a tax-free terminal, the authentication terminal 30 directly or indirectly transmits biometric information of a tax-free purchaser and a request for official information provision related to the passport to the authentication server 10. The authentication terminal 30 proceeds with tax-free processing according to the information on the passport obtained from the authentication server 10. In this way, a terminal may selectively transmit an authentication request or a request for official information provision to the authentication server 10 depending on the function to be realized. Furthermore, the authentication server 10 notifies the terminal of the service user ID or public information depending on the type of the received request.

[0264] In the above embodiment, for example, as shown in Fig. 27, a case has been described in which a user gives consent to the provision of information in units of official information (e.g., passport, health insurance card). However, an interface may be provided to the user that allows the user to input whether or not to consent to the provision of each item of official information. For example, a GUI may be provided to the user that allows input such as consenting to the provision of only the name and nationality of the items listed on a passport.

[0265] When obtaining the user's permission to provide official information, the terminal 40 may notify the user of the benefits of providing the information. For example, the terminal 40 may output a message such as "If you provide your passport information, the tax exemption procedure will be completed easily" on the display shown in Fig. 27.

[0266] The authentication server 10 may store the identification document acquired during user registration in a public information database or the like. In this case, if the official document authorized by the user to be provided is the same as the identification document registered in the database, the authentication server 10 may not need to acquire public information identifying data from the user. For example, consider a case where a "passport" is acquired as an identification document and the user has authorized the provision of the information written on the passport. In this case, the authentication server 10 may read the passport number from the passport (identification document associated with the user ID and biometric information) registered in the database.

[0267] Each device included in the authentication system may attach a digital signature when transmitting information (authentication request, public information request, etc.). A device that acquires the information (e.g., authentication server, public server) may verify the attached digital signature and process only information whose identity has been correctly confirmed.

[0268] The form of data transmission and reception between each device (authentication server 10, management server 20, authentication terminal 30, and staff terminal 31) is not particularly limited, but data transmitted and received between these devices may be encrypted. Biometric information is transmitted and received between these devices, and in order to appropriately protect the biometric information, it is desirable to transmit and receive encrypted data.

[0269] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0270] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0271] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to authentication systems for authenticating users of private businesses and public institutions.

[0272] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. [Appendix 1] a database that stores, in association with each other, a user's biometric information, a first ID that identifies a business that provides a service to the user, a second ID that is uniquely determined by a combination of the user and the business, and public information identification data that identifies public information the provision of which is permitted by the user; an authentication unit that executes authentication processing in response to receiving an authentication request from a first business entity, the authentication request including biometric information of a person to be authenticated and the first ID of the first business entity, and transmits the second ID of the person who has been successfully authenticated to the first business entity; an information providing unit that, when the second business receives a public information provision request from a second business, the public information provision request including biometric information of a user who wishes to access public information and the type of public information that the second business wishes to access, acquires the public information that the user wishes to access from a public server that stores the public information that the user wishes to access using the public information identification data, and transmits the acquired public information to the second business; An authentication server comprising: [Appendix 2] the database further stores a third ID for identifying the user; The authentication server described in Appendix 1 further comprises a user registration unit that, upon receiving a user registration request including the user's biometric information and the user's identification document, verifies the user's identity based on the identification document, and registers the biometric information and the third ID of the user whose identity has been successfully verified in the database. [Appendix 3] 3. The authentication server according to claim 2, wherein the user registration unit issues the third ID to the user when the user's identity is successfully verified. [Appendix 4] The authentication server described in Appendix 2 or 3, wherein the user registration unit determines that the identity of the user has been successfully verified if one-to-one matching is successful using the user's biometric information included in the user registration request and the biometric information obtained from the identification document. [Appendix 5] An authentication server as described in any one of Appendices 2 to 4, further comprising a business registration unit that, upon receiving a business registration request including the first ID and the third ID from the first business, generates the second ID and issues the generated second ID to the first business. [Appendix 6] An authentication server described in any one of Appendices 2 to 5, further comprising a specific data registration unit that, upon receiving a public information provision consent including the third ID and the public information identification data, stores the public information identification data in an entry corresponding to the third ID. [Appendix 7] An authentication server described in any one of Appendices 1 to 6, wherein the authentication unit performs a one-to-N (N is a positive integer) match using the biometric information stored in the database and the biometric information of the person to be authenticated included in the authentication request. [Appendix 8] The authentication server described in Appendix 7, wherein the authentication unit determines that the authentication process is successful if the first ID included in the authentication request is stored in the database in correspondence with the user identified by the one-to-N matching. [Appendix 9] An authentication server described in any one of Appendices 1 to 8, wherein the information providing unit identifies the user for whom the second business operator wishes to access public information by performing a one-to-N (N is a positive integer) match using the biometric information stored in the database and the biometric information included in the public information provision request. [Appendix 10] The database stores a plurality of the public information identification data for each user; The authentication server described in Appendix 9, wherein the information providing unit transmits to the public server public information identification data corresponding to the type of public information included in the public information provision request from among the multiple public information identification data of the identified user. [Appendix 11] 11. The authentication server according to claim 1, wherein the biometric information is a face image or a feature amount generated from the face image. [Appendix 12] a first terminal installed at a first carrier; a second terminal installed at a second carrier; an authentication server connected to the first and second terminals; Including, The authentication server a database that stores, in association with each other, a user's biometric information, a first ID that identifies a business that provides a service to the user, a second ID that is uniquely determined by a combination of the user and the business, and public information identification data that identifies public information the provision of which is permitted by the user; an authentication unit that executes authentication processing in response to receiving an authentication request including biometric information of a person to be authenticated and the first ID of the first business operator from the first terminal, and transmits the second ID of a person who has been successfully authenticated to the first terminal; an information providing unit that, when the second business receives from the second terminal a request for public information provision including biometric information of a user who wishes to access public information and the type of public information that the second business wishes to access, acquires the public information that the user wishes to access from a public server that stores the public information that the user wishes to access using the public information identification data, and transmits the acquired public information to the second terminal; A system comprising: [Appendix 13] An authentication server having a database that stores biometric information of a user, a first ID that identifies a business that provides a service to the user, a second ID that is uniquely determined by a combination of the user and the business, and public information identification data that identifies public information the provision of which is permitted by the user, in association with each other; receiving, from a first business entity, an authentication request including biometric information of the person to be authenticated and the first ID of the first business entity, executing an authentication process, and transmitting the second ID of the person who has been successfully authenticated to the first business entity; A control method for an authentication server, in which, when the second business receives a request for public information from a second business operator, the request includes biometric information of a user who wishes to access public information and the type of public information the user wishes to access, the method uses the public information identification data to obtain the public information the user wishes to access from a public server that holds the public information the user wishes to access, and sends the obtained public information to the second business operator. [Appendix 14] A computer installed in an authentication server having a database that stores, in association with each other, biometric information of a user, a first ID that identifies a business that provides a service to the user, a second ID that is uniquely determined by a combination of the user and the business, and public information identification data that identifies public information the provision of which is permitted by the user, a process of executing an authentication process in response to receiving an authentication request including biometric information of a person to be authenticated and the first ID of the first business entity from a first business entity, and transmitting the second ID of the person who has been successfully authenticated to the first business entity; When the second business receives a request for public information from a second business operator, the request includes biometric information of the user who wishes to access public information and the type of public information the user wishes to access, the second business operator uses the public information identification data to acquire the public information the user wishes to access from a public server that stores the public information the user wishes to access, and transmits the acquired public information to the second business operator; A program to execute.

[0273] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof.

[0274] This application claims priority based on Japanese Patent Application No. 2020-201061, filed on December 3, 2020, the disclosure of which is incorporated herein in its entirety. [Explanation of symbols]

[0275] 10, 100 authentication servers 20 Management Server 30 Authentication Terminal 31 Staff terminal 40 terminals 41 Passport Server 42 Health insurance card server 101 Database 102, 205 Authentication Department 103 Information Provision Department 201, 301, 401, 501, 601 Communication control unit 202 User Registration Department 203 Business Registration Department 204 Specific Data Registration Department 206 Public Information Department 207, 305, 405, 504, 603 Storage section 302 Service Information Acquisition Unit 303 Service Information Registration Department 304 Authentication Request Section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface 402 Biometric information acquisition unit 403 Service Provision Department 404, 503 message output section 502 Information Provision Request Department 602 User Support Department 611 User Registration Support Department 612 Service Registration Support Department 613 Provision Permission Support Department

Claims

1. a database that stores, in association with each other, biometric information of a user, a first ID that identifies a business that provides a service to the user, a second ID that is uniquely determined by a combination of the user and the business, and public information identification data that identifies public information the provision of which is permitted by the user; an authentication means for executing an authentication process in response to receiving an authentication request from a first business entity, the authentication request including biometric information of a person to be authenticated and the first ID of the first business entity, and transmitting the second ID of a person who has been successfully authenticated to the first business entity; an information providing means for, when the second business receives from a second business a request for public information provision including biometric information of a user who wishes to refer to public information and the type of public information that the second business wishes to refer to, acquiring the public information that the user wishes to refer to from a public server that stores the public information that the user wishes to refer to using the public information identification data, and transmitting the acquired public information to the second business; An authentication server comprising:

2. the database further stores a third ID for identifying the user; The authentication server according to claim 1, further comprising a user registration means for, upon receiving a user registration request including the user's biometric information and the user's identification document, verifying the identity of the user based on the identification document, and registering the biometric information and the third ID of the user whose identity has been successfully verified in the database.

3. 3. The authentication server according to claim 2, wherein said user registration means issues said third ID to said user when said user's identity is successfully verified.

4. The authentication server according to claim 2 or 3, wherein the user registration means determines that the identity of the user has been successfully verified when one-to-one matching is successful using the biometric information of the user included in the user registration request and the biometric information obtained from the identification document.

5. 5. The authentication server according to claim 2, further comprising a business registration means for generating the second ID upon receiving a business registration request including the first ID and the third ID from the first business and issuing the generated second ID to the first business.

6. An authentication server as described in any one of claims 2 to 5, further comprising a specific data registration means that, upon receiving a public information provision permission including the third ID and the public information identification data, stores the public information identification data in an entry corresponding to the third ID.

7. 7. The authentication server according to claim 1, wherein the authentication means performs one-to-N (N is a positive integer) matching using the biometric information stored in the database and the biometric information of the person to be authenticated included in the authentication request.

8. a first terminal installed at a first carrier; a second terminal installed at a second carrier; an authentication server connected to the first and second terminals; Including, The authentication server a database that stores, in association with each other, biometric information of a user, a first ID that identifies a business that provides a service to the user, a second ID that is uniquely determined by a combination of the user and the business, and public information identification data that identifies public information the provision of which is permitted by the user; an authentication means for executing an authentication process in response to receiving an authentication request including biometric information of a person to be authenticated and the first ID of the first business operator from the first terminal, and transmitting the second ID of a person who has been successfully authenticated to the first terminal; an information providing means for, when the second business receives from the second terminal a request for public information provision including biometric information of a user who wishes to refer to public information and the type of public information that the second business wishes to refer to, acquiring the public information that the user wishes to refer to from a public server that stores the public information that the user wishes to refer to using the public information identification data, and transmitting the acquired public information to the second terminal; A system comprising:

9. An authentication server having a database that stores biometric information of a user, a first ID that identifies a business that provides a service to the user, a second ID that is uniquely determined by a combination of the user and the business, and public information identification data that identifies public information the provision of which is permitted by the user, in association with each other; receiving, from a first business entity, an authentication request including biometric information of the person to be authenticated and the first ID of the first business entity, executing an authentication process, and transmitting the second ID of the person who has been successfully authenticated to the first business entity; A control method for an authentication server, in which, when the second business receives a request for public information from a second business operator, the request includes biometric information of a user who wishes to access public information and the type of public information the user wishes to access, the method uses the public information identification data to obtain the public information the user wishes to access from a public server that holds the public information the user wishes to access, and sends the obtained public information to the second business operator.

10. a computer installed in an authentication server that has a database that stores, in association with each other, biometric information of a user, a first ID that identifies a business that provides a service to the user, a second ID that is uniquely determined by a combination of the user and the business, and public information identification data that identifies public information the provision of which is permitted by the user; a process of executing an authentication process in response to receiving an authentication request including biometric information of a person to be authenticated and the first ID of the first business entity from a first business entity, and transmitting the second ID of the person who has been successfully authenticated to the first business entity; When the second business receives a request for public information from a second business, the request includes biometric information of the user who wishes to access public information and the type of public information that the second business wishes to access, the process of acquiring the public information that the user wishes to access from a public server that stores the public information that the user wishes to access using the public information identification data, and transmitting the acquired public information to the second business; A program to execute.

Citation Information

Patent Citations

  • Medical expense payment method, device and system

    CN111539833A

  • Output device, output system, output method, and output program

    JP2015215767A

  • Settlement support system for traveler and settlement support method for traveler

    JP2017123202A

  • Authentication system, management device, and authentication method

    JP2020113107A

  • Personal information management server, personal information management method, and personal information management system

    JP2020181275A