Information processing device and method

The system addresses user operational burden in identity verification by offering tailored verification methods based on terminal capabilities and data availability, improving user experience and efficiency.

JP7761689B2Active Publication Date: 2025-10-28NTT DOCOMO INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024032431
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-03-04
Publication Date
2025-10-28
Estimated Expiration
2044-03-04

AI Technical Summary

Technical Problem

Existing identity verification methods for user terminals impose a significant operational burden on users due to unfamiliarity with the procedures.

Method used

A system that presents users with identity verification methods suitable for their terminal capabilities and data availability, offering first and second verification methods via communication networks using different data types, including eKYC and Japanese Public Key Infrastructure (JPKI), guided by the user terminal's hardware and software configuration.

Benefits of technology

Reduces the user burden by providing tailored identity verification processes, enhancing user convenience and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007761689000001
    Figure 0007761689000001
  • Figure 0007761689000002
    Figure 0007761689000002
  • Figure 0007761689000003
    Figure 0007761689000003
Patent Text Reader

Abstract

To reduce the burden on a user when verifying the user's identity.SOLUTION: An information processing device obtains a request of a service provided from a user's terminal through identity verification, and in response to the request, presents information on an identity verification method most suitable for the user to the user on a terminal among a first identity verification method, which verifies the user's identity via a communication network using first data related to the user, and a second identity verification method, which verifies the user's identity via the communication network using second data that is related to the user and different from the first data.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technology for verifying the identity of a user who uses a service. [Background technology]

[0002] With the widespread use of user terminals such as smartphones, payment services that use the user terminals to make electronic payments are becoming widely used. This type of service requires user identity verification, and Patent Document 1, for example, describes that when a payment device on the store side accepts a payment request, it outputs multiple countermeasures based on user attribute information, such as suspending the transaction for a certain period of time until the user's identity can be verified. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent No. 7000503 Summary of the Invention [Problem to be solved by the invention]

[0004] There are multiple methods for verifying a user's identity, but since users are not necessarily familiar with the procedures for each method, there may be cases where the burden of user operations, etc. when verifying identity is heavy.

[0005] Therefore, an object of the present invention is to reduce the burden on the user when verifying the user's identity. [Means for solving the problem]

[0006] In order to solve the above problem, the present invention provides a system including an acquisition unit that acquires, from a user terminal, a request for a service to be provided after identity verification, and a presentation unit that presents to the user at the terminal, in response to the request, information on an identity verification method suitable for the user, between a first identity verification method that performs identity verification via a communication network using first data related to the user, and a second identity verification method that performs identity verification via a communication network using second data related to the user that is different from the first data. When the terminal does not have a function for reading data stored in a storage medium, the presentation unit presents to the user information about the first identity verification method that does not use the data; when the terminal has a function for reading data stored in a storage medium and the user remembers a personal identification number for the data stored in the storage medium, the presentation unit presents to the user information about the second identity verification method that uses the data as the second data; and when the user does not remember the personal identification number for the data stored in the storage medium, the presentation unit presents to the user information about the first identity verification method. The present invention also provides an information processing device comprising: a step of acquiring, from a user terminal, a request for a service to be provided after identity verification; and a step of presenting to the user, in response to the request, information on an identity verification method suitable for the user, from the terminal, of a first identity verification method for verifying the identity of the user via a communication network using first data related to the user, and a second identity verification method for verifying the identity of the user via a communication network using second data related to the user that is different from the first data, In the presenting step, if the terminal does not have a function to read data stored in a storage medium, information regarding the first identity verification method performed without using the data is presented to the user; if the terminal has a function to read data stored in a storage medium and the user remembers the PIN number of the data stored in the storage medium, information regarding the second identity verification method performed using the data as the second data is presented to the user; and if the user does not remember the PIN number of the data stored in the storage medium, information regarding the first identity verification method is presented to the user. The present invention provides an information processing method. [Effects of the Invention]

[0007] According to the present invention, it is possible to reduce the burden on the user when verifying the user's identity. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a diagram showing an example of a configuration of an information processing system 1 according to an embodiment of the present invention. [Figure 2] FIG. 2 is a diagram illustrating an example of a hardware configuration of a server device 30 according to the embodiment. [Figure 3] 1 is a diagram illustrating an example of a hardware configuration of a user terminal 10 according to an embodiment. [Figure 4] FIG. 2 is a diagram illustrating an example of a functional configuration of a server device 30 according to the embodiment. [Figure 5] 10 is a flowchart showing an example of the operation of the server device 30. [Figure 6]FIG. 2 is a diagram showing a display example of the user terminal 10 according to the embodiment. [Figure 7] FIG. 2 is a diagram showing a display example of the user terminal 10 according to the embodiment. [Figure 8] FIG. 2 is a diagram showing a display example of the user terminal 10 according to the embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of a functional configuration of a server device 30a according to a modified example. DETAILED DESCRIPTION OF THE INVENTION

[0009] [Embodiment] [composition] FIG. 1 is a diagram illustrating an example of the configuration of an information processing system 1 according to an embodiment of the present invention. The information processing system 1 is a system for providing various financial services to users, such as electronic money charging and remittance, and electronic settlement for purchasing goods and services at stores. As shown in FIG. 1, the information processing system 1 includes a user terminal 10 used by a user, an IC chip 20, which is a storage medium embedded in a user's driver's license, My Number card, or other card, a server device 30 corresponding to the information processing device of the present invention, an online authentication system 40 that verifies the user's identity via a communication network 2 using first data related to the user, a public personal authentication system 50 that verifies the user's identity via the communication network 2 using second data related to the user that is different from the first data, and a communication network 2, including a wireless communication network or a wired communication network, that communicatively connects these systems. The first data and second data include data stored in the IC chip 20 and various data such as personal identification numbers memorized by the user, as will be described in detail below. The server device 30 may be configured as a single computer or multiple computers. Although FIG. 1 shows one each of the user terminal, IC chip, server device, online authentication system 40, and public personal authentication system 50, there may be a plurality of each of these.

[0010] FIG. 2 is a diagram showing the hardware configuration of the server device 30. The server device 30 is physically configured as a computer including a processor 3001, a memory 3002, a storage 3003, a communication device 3004, an input device 3005, an output device 3006, and a bus connecting these devices. Each of these devices operates using power supplied from a battery (not shown). In the following description, the term "device" can be interpreted as a circuit, a device, a unit, or the like. The hardware configuration of the server device 30 may be configured to include one or more of the devices shown in FIG. 2, or may be configured without including some of the devices. Furthermore, the server device 30 may be configured by communicating with multiple devices each having a different housing.

[0011] Each function in the server device 30 is realized by loading predetermined software (programs) onto hardware such as the processor 3001 and memory 3002, causing the processor 3001 to perform calculations, control communication via the communication device 3004, and control at least one of reading and writing data in the memory 3002 and storage 3003.

[0012] The processor 3001 controls the entire computer by running, for example, an operating system. The processor 3001 may be configured as a central processing unit (CPU) including an interface with peripheral devices, a control device, an arithmetic unit, a register, etc. Furthermore, for example, a baseband signal processing unit, a call processing unit, etc. may be realized by the processor 3001.

[0013] The processor 3001 reads programs (program codes), software modules, data, etc. from at least one of the storage 3003 and the communication device 3004 into the memory 3002, and executes various processes in accordance with these. The programs used are those that cause a computer to execute at least some of the operations described below. The functional blocks of the server device 30 may be implemented by a control program stored in the memory 3002 and running on the processor 3001. Various processes may be executed by one processor 3001, or may be executed simultaneously or sequentially by two or more processors 3001. The processor 3001 may be implemented by one or more chips. The programs may be transmitted to the server device 30 via a telecommunications line.

[0014] The memory 3002 is a computer-readable recording medium and may be configured by, for example, at least one of a ROM (Read Only Memory), an EPROM (Erasable Programmable ROM), an EEPROM (Electrically Erasable Programmable ROM), a RAM (Random Access Memory), etc. The memory 3002 may also be called a register, a cache, a main memory (primary storage device), etc. The memory 3002 can store an executable program (program code), a software module, etc. for implementing the method according to this embodiment.

[0015] Storage 3003 is a computer-readable recording medium, and may be constituted by at least one of, for example, an optical disk such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (e.g., a compact disk, a digital versatile disk, a Blu-ray (registered trademark) disk), a smart card, a flash memory (e.g., a card, a stick, a key drive), a floppy (registered trademark) disk, a magnetic strip, etc. Storage 3003 may also be referred to as an auxiliary storage device.

[0016] The communication device 3004 is hardware (transmission / reception device) for communicating between computers via at least one of a wired network and a wireless network, and is also called, for example, a network device, a network controller, a network card, or a communication module. Each device, such as the processor 3001 and the memory 3002, is connected by a bus for communicating information. The bus may be configured using a single bus, or may be configured using different buses between each device.

[0017] The server device 30 may be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a programmable logic device (PLD), or a field programmable gate array (FPGA), and some or all of the functional blocks may be realized by the hardware. For example, the processor 3001 may be implemented using at least one of these pieces of hardware.

[0018] 3 is a diagram showing an example of the hardware configuration of the user terminal 10. The user terminal 10 is a computer such as a smartphone, a mobile phone, a tablet, or a wearable terminal. The user terminal 10 is physically configured as a computer device including a processor 1001, a memory 1002, a storage 1003, a communication device 1004, an input device 1005, an output device 1006, and a bus connecting these. The processor 1001, the memory 1002, and the storage 1003 are the same hardware as the processor 3001, the memory 3002, and the storage 3003 of the server device 30.

[0019] The communication device 1004 may be configured to include a high-frequency switch, a duplexer, a filter, a frequency synthesizer, etc., to realize at least one of Frequency Division Duplex (FDD) and Time Division Duplex (TDD). For example, a transmitting / receiving antenna, an amplifier unit, a transmitting / receiving unit, a transmission path interface, etc. may be realized by the communication device 1004. The transmitting / receiving unit may be implemented as a transmitting unit and a receiving unit that are physically or logically separated.

[0020] The input device 1005 is an input device (e.g., a key, a microphone, a switch, a button, a sensor, etc.) that accepts input from the outside, and in particular includes an IC chip reader 10051 that reads data stored in the IC chip 20. The output device 1006 is an output device (e.g., a display, a speaker, an LED lamp, etc.) that performs output to the outside. Note that the input device 1005 and the output device 1006 may be integrated into one device (e.g., a touch screen).

[0021] Among the multiple user terminals 10, there are user terminals 10 equipped with an IC chip reader 10051 and user terminals 10 not equipped with an IC chip reader 10051.

[0022] 4 is a block diagram showing the functional configuration of server device 30. In server device 30, processor 3001 reads programs and the like from storage 3003 into memory 3002 and executes them, thereby realizing the functions of request acquisition unit 31, presentation unit 32, confirmation unit 33, and storage unit 34.

[0023] The request acquisition unit 31 acquires a request for a service to be provided after identity verification from the user terminal 10 via the communication network 2. Here, the service to be provided after identity verification refers to a predetermined type of financial service, such as a service for charging electronic money from a bank account registered for the user to the user's electronic wallet, or a service for transferring money from the electronic wallet to another user's electronic wallet. When a user requests this type of service from the server device 30, identity verification is required to determine whether the requesting user is a genuine user.

[0024] In response to the request, the presentation unit 32 presents to the user on the user terminal 10 information regarding the identity verification method that is most suitable for the user, between a first identity verification method that uses the aforementioned first data to verify the identity of the user in cooperation with the online authentication system 40 via the communication network 2, and a second identity verification method that uses the aforementioned second data to verify the identity of the user in cooperation with the public personal authentication system 50 via the communication network 2.

[0025] The first identity verification method includes, for example, eKYC (electronic Know Your Customer). As stipulated in Article 6, Paragraph 1, Clause 1 of the Act on Prevention of Transfer of Criminal Proceeds in Japan, eKYC includes two methods: (e) in which a user takes a photograph of their own face and the facial image contained in an identity verification document such as a driver's license and uploads it; and (f) in which a user takes a photograph of their own face and uses a user terminal to read the IC chip embedded in the identity verification document such as a driver's license to verify their identity.

[0026] The second identity verification method includes, for example, Japanese Public Key Infrastructure (JPKI), which is an identity verification method used to prevent impersonation and data tampering by others during online procedures by utilizing the "digital signature certificate" or "digital user certificate" recorded on the IC chip of the My Number Card.

[0027] The presenting unit 32 presents an identity verification method suitable for the user depending on whether the user terminal 10 related to the request has a reading function for reading data stored in the IC chip 20. Here, whether the user terminal 10 has a reading function is determined taking into consideration the presence or absence of hardware for reading data stored in the IC chip 20 as well as the version of software such as the OS (Operating System) in the user terminal 10. The presenting unit 32 also asks questions to the user at the user terminal 10 and presents an identity verification method suitable for the user depending on the user's answers to the questions. Specific presentation of identity verification methods by the presenting unit 32 will be described in detail later in the operation description.

[0028] When the user performs a predetermined task in accordance with the identity verification method presented by the presentation unit 32, the verification unit 33 cooperates with the online authentication system 40 or the public personal authentication system 50 to perform a process for verifying the identity of the user.

[0029] The storage unit 34 stores the result of the user identity verification performed by the verification unit 33 in association with the user identification information of the user.

[0030] [Operation] Next, the operation of the information processing system 1 according to the embodiment will be described with reference to Fig. 5. In the following description, for example, when the server device 30 is described as the subject of processing, this specifically means that the processor 3001 performs calculations by loading predetermined software (programs) onto hardware such as the processor 3001 and memory 3002, and controls communication via the communication device 3004 and reading and / or writing of data from and to the memory 3002 and storage 3003, thereby executing processing. The same applies to the user terminal 10.

[0031] First, in response to a user's operation, the user terminal 10 transmits a request for a service to be provided after identity verification to the server device 30. When this request is received by the server device 30, the processing of FIG.

[0032] 5, the presenting unit 32 of the server device 30 determines whether the user terminal 10 related to the request has a reading function for reading data stored in the IC chip 20 (step S11). Specifically, the presenting unit 32 stores in advance information indicating whether the user terminal 10 has the reading function for each model of the user terminal 10. The request includes model information indicating the model of the user terminal 10, and the presenting unit 13 determines whether the model indicated by the model information included in the request has the reading function based on the stored content. At this time, as described above, the presenting unit 13 may make the above determination by checking the version of the OS of the user terminal 10 based on the UA (User Agent) included in the request, etc.

[0033] If the presenting unit 32 determines that the user terminal 10 related to the request does not have a reading function for reading data stored in the IC chip 20 (step S11; NO), it presents the user with the procedure of the eKYC method E as an identity verification method suitable for the user (step S17). Specifically, the presenting unit 32 transmits data for displaying a screen D1 as illustrated in FIG. 6 to the user terminal 10 and displays it on the display. This screen D1 indicates that identity verification is completed by photographing and uploading an identity verification document, such as a driver's license containing a facial image, and an image of the user's face. When the user selects the soft button SB1 on the screen D1, the screen transitions to a guidance screen for the user to perform the above operations, such as photographing, according to the procedure of the eKYC method E. The procedure from this point onward is well known, so a description thereof will be omitted. The data (first data) required for this eKYC method E is, for example, image data of an identity verification document, such as a driver's license, and image data of the user's face.

[0034] In step S11, if the presentation unit 32 determines that the user terminal 10 related to the request has a reading function to read the data stored in the IC chip 20 (step S11; YES), it displays a message on the display of the user terminal 10 asking the user whether or not they have a My Number card (step S12).

[0035] When the user inputs an answer to this question into the user terminal 10 that they have a My Number card (step S12; YES), the presentation unit 32 receives a notification corresponding to the input from the user terminal 10 and displays a message on the display of the user terminal 10 asking the user whether they remember the PIN number for the My Number card's signature electronic certificate (or user authentication electronic certificate) (step S13).

[0036] When the user responds to this question by inputting into the user terminal 10 that he or she remembers the PIN (step S13; YES), the presenting unit 32 receives a notification from the user terminal 10 in response to the input and presents the user with a procedure for public personal authentication as an identity verification method suitable for the user (step S15). Specifically, the presenting unit 32 transmits data for displaying screen D2, as illustrated in FIG. 7, to the user terminal 10 and displays it on the display. This screen D2 indicates that identity verification is completed by holding the user terminal 10 over the My Number card and reading and uploading the signature electronic certificate (or user authentication electronic certificate) recorded in the My Number card's IC chip 20. When the user selects soft button SB2 on screen D2, the screen transitions to a screen where the user can perform operations such as reading and entering the PIN according to the procedure for public personal authentication. The subsequent procedures are well known and will not be described further. The data (second data) required for this official personal authentication is, for example, data recorded in the IC chip 20 of the My Number card and the personal identification number of the electronic signature certificate (or the electronic user certificate).

[0037] In step S12, if the user inputs into the user terminal 10 an answer to the question that they do not have a My Number card (step S12; NO), the presentation unit 32 receives a notification corresponding to the input from the user terminal 10 and displays a message on the display of the user terminal 10 asking the user whether they remember the PIN number for their driver's license (step S14).

[0038] When the user inputs a response to this question into the user terminal 10 that they remember their PIN (step S14; YES), the presentation unit 32 receives a notification from the user terminal 10 in response to the input and presents the user with the procedure for the eKYC method using a driver's license as an identity verification method suitable for the user (step S16). Specifically, the presentation unit 32 transmits data for displaying screen D3, as exemplified in FIG. 8, to the user terminal 10 and displays it on the display. This screen D3 indicates that identity verification is completed by reading the IC chip 20 of the driver's license and taking and uploading a photograph of the user's face. Then, when the user selects soft button SB3 on screen D3, the screen transitions to a screen where the user can perform operations such as taking the photograph and entering the PIN in accordance with the procedure for the eKYC method. The procedure from this point on is well known, so a description thereof will be omitted. The data (first data) required in this eKYC method using a driver's license are, for example, the data recorded on the IC chip 20 of the driver's license (name, date of birth, address), and two sets of PIN numbers (four-digit numbers) set when the driver's license was issued or renewed in order to read data from the IC chip 20.

[0039] In step S14, if the user inputs into the user terminal 10 an answer that he or she does not remember the PIN (step S14; NO), the presentation unit 32 receives a notification corresponding to the input from the user terminal 10 and presents to the user the procedure for eKYC method E as an identity verification method suitable for that user (step S17).

[0040] Furthermore, in step S13, if the user inputs into the user terminal 10 an answer that they do not remember their PIN (step S13; NO), the presenting unit 32 receives a notification corresponding to the input from the user terminal 10 and presents to the user the procedure for the eKYC method using the My Number card as an identity verification method suitable for the user (step S16). Data (first data) required for the eKYC method using the My Number card is, for example, data recorded in the IC chip 20 of the My Number card and information written on the My Number card for reading data from the IC chip 20 (date of birth, expiration date (year), security code).

[0041] Then, when the user performs a predetermined operation or task in accordance with the identity verification method presented by the presentation unit 32, the confirmation unit 33 of the server device 30 performs processing for verifying the identity of the user in cooperation with the online authentication system 40 or the public personal authentication system 50. After this, the storage unit 34 of the server device 30 stores the result of the identity verification of the user by the confirmation unit 33 in association with the user identification information of the user.

[0042] According to the embodiment described above, the user is guided to the identity verification method that is most suitable for the user from among multiple identity verification methods that use different data to verify the user's identity, thereby reducing the burden on the user when verifying the user's identity.

[0043] [Variations] The present invention is not limited to the above-described embodiment. The above-described embodiment may be modified as follows. Furthermore, two or more of the following modifications may be combined and implemented.

[0044] [Variation 1] A user who has already been identified may not be identified again. In other words, if a user has been identified in the past, thereafter, even if there is a request from the user terminal 10 of that user, the presenting unit 32 will not present the information and the confirming unit 33 will not confirm the information. This makes it possible to avoid duplicate identification.

[0045] Conversely, the presentation unit 32 may present an identity verification method suitable for the user according to the history of identity verification methods used when the user's identity was verified in the past. For example, the presentation unit 32 may always present to the user the same identity verification method used in the past when the user's identity was verified. Alternatively, the presentation unit 32 may present to the user the identity verification method that has been used most frequently among the history of the user's past identity verification. In this way, it is possible to present to the user an identity verification method that the user is likely to use.

[0046] [Variation 2] The presenting unit 32 may present an identity verification method suitable for the user according to information about the location of the user terminal 10. The information about the location of the user terminal 10 may be, for example, information about whether the location of the user terminal 10 (i.e., the user's location) is a location corresponding to a space where an unspecified number of people may be present, such as a train or bus, or whether it is a private space such as a home. In this case, the presenting unit 32 includes a database that stores and updates the running locations of trains and buses and the home locations of each user. When the user terminal 10 transmits a request for a service to be provided after identity verification to the server device 30 in response to a user's operation, the user terminal 10 also transmits the location determined by the user terminal 10's positioning function (e.g., GPS or base station presence information). The presenting unit 32 compares the location of the user terminal 10 with the content stored in advance, and determines whether the location of the user terminal 10 is a location corresponding to a space where an unspecified number of people may be present, such as a train or bus, or whether it is a private space such as a home. If the location of the user terminal 10 is not a location corresponding to a space where an unspecified number of people may be present, such as a train or bus, or if it is a private space such as a home, the presentation unit 32 presents the eKYC method (f) and public personal authentication, which require the input of a PIN. On the other hand, if the location of the user terminal 10 is a location corresponding to a space where an unspecified number of people may be present, such as a train or bus, or if it is not a private space such as a home, the presentation unit 32 presents the eKYC method (e), which does not require the input of a PIN, rather than the eKYC method (f) and public personal authentication, which require the input of a PIN. In this way, it is possible to prevent the PIN, information that should only be known to the user, from being seen by others.

[0047] [Variation 3] Identity verification may be performed using a method according to the risk assessment of the user. In this case, as shown in FIG. 9, the server device 30a according to this modification includes a risk information acquisition unit 35 that acquires information about the risk assessment of the user, and the presentation unit 32 presents an identity verification method suitable for the user according to changes in the risk assessment identified by the information acquired by the risk information acquisition unit 35. The information about the risk assessment of the user is, for example, a risk assessment value of the user calculated using a method known in the field of CCD (Customer Due Diligence). The risk information acquisition unit 35 acquires a risk assessment value for each user from a device that generates this type of risk assessment value. For example, the presentation unit 32 may present the eKYC method E when the risk assessment value of a certain user changes over time to decrease, and present a public personal authentication method that enables stricter identity verification when the risk assessment value changes over time to increase. In addition, the presenting unit 32 may present one of the public personal authentication and the eKYC method E and method F when the risk assessment value of a certain user changes over time to become smaller, and may present two of the public personal authentication and the eKYC method E and method F when the risk assessment value changes over time to become larger. In this way, the user's identity can be verified by an appropriate method according to the change in the user's risk.

[0048] [Variation 4] In the above embodiment, the eKYC methods F and E and public personal authentication are exemplified as the first and second identity verification methods. The present invention is not limited to these examples, and it is sufficient that the first identity verification method is a method of verifying identity via a communication network using first data related to a user, and the second identity verification method is a method of verifying identity via a communication network using second data related to the user that is different from the first data.

[0049] Therefore, in the above embodiment, the data (first data) required in the eKYC method (e) is, for example, image data of an identification document such as a driver's license and image data of the user's face; the data (first data) required in the eKYC method (f) using a driver's license is, for example, data recorded in the IC chip 20 of the driver's license (name, date of birth, address) and two sets of PIN numbers (four-digit numbers) set when the driver's license was issued or renewed in order to read data from the IC chip 20; the data (first data) required in the eKYC method (f) using a My Number card is, for example, data recorded in the IC chip 20 of the My Number card and information written on the My Number card in order to read data from the IC chip 20 (date of birth, expiration date (year), security code); and the data (second data) required in public personal authentication is, for example, data recorded in the IC chip 20 of the My Number card and the PIN number of the signature electronic certificate (or user authentication electronic certificate), but these are merely examples. For example, instead of the eKYC method (e) exemplified in the embodiment, an identity verification method using, for example, image data of an identification document containing an image of the individual's face and image data of the user's face may be used, or instead of the eKYC method (f), an identity verification method using, for example, data recorded on the IC chip 20 and image data of the user's face may be used. Furthermore, instead of the public personal authentication exemplified in the embodiment, an identity verification method other than public personal authentication using a public key cryptosystem may be used. Also, an identity verification method using a residence card may be used. The data required in an identity verification method using a residence card are the data recorded on the IC chip 20 of the residence card, the residence card number written on the residence card, image data captured from the back of the residence card, and image data of the user's face.

[0050] [Other variations] The block diagrams used to explain the above embodiments show functional blocks. These functional blocks (components) are realized by any combination of at least one of hardware and software. Furthermore, the method for realizing each functional block is not particularly limited. That is, each functional block may be realized using a single device that is physically or logically coupled, or may be realized using two or more physically or logically separated devices that are directly or indirectly connected (for example, using wires, wirelessly, etc.) and these multiple devices. The functional block may also be realized by combining the single device or multiple devices with software.

[0051] Functions include, but are not limited to, judgment, determination, assessment, calculation, computation, processing, derivation, investigation, search, confirmation, reception, transmission, output, access, resolution, selection, election, establishment, comparison, assumption, expectation, consideration, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocating, mapping, and assignment. For example, a functional block (component) that performs transmission is called a transmitting unit or transmitter. As mentioned above, there are no particular limitations on how these functions are implemented.

[0052] For example, the server device 30 in one embodiment of the present disclosure may function as a computer that performs the processing of the present disclosure.

[0053] Each aspect / embodiment described in the present disclosure may be applied to at least one of systems using LTE (Long Term Evolution), LTE-Advanced (LTE-A), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), FRA (Future Radio Access), NR (New Radio), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark), IEEE 802.20, UWB (Ultra-Wideband), Bluetooth (registered trademark), or other appropriate systems, and next-generation systems extended based on these. Furthermore, a combination of multiple systems (e.g., a combination of at least one of LTE and LTE-A with 5G, etc.) may also be applied.

[0054] The order of the procedures, sequences, flowcharts, etc. of each aspect / embodiment described in this disclosure may be changed unless it is consistent. For example, the methods described in this disclosure present elements of various steps using an example order, and are not limited to the particular order presented.

[0055] Input and output information may be stored in a specific location (for example, memory) or may be managed using a management table. Input and output information may be overwritten, updated, or added to. Output information may be deleted. Input information may be sent to another device.

[0056] The determination may be made based on a value represented by one bit (0 or 1), a Boolean value (true or false), or a numerical comparison (e.g., comparison with a predetermined value).

[0057] Although the present disclosure has been described in detail above, it is clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the description of the present disclosure is intended to be illustrative and does not have any limiting meaning on the present disclosure.

[0058] Software, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise, shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc. Additionally, software, instructions, information, etc. may be transmitted or received over a transmission medium. For example, if software is transmitted from a website, server, or other remote source using wired technologies (such as coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL)), and / or wireless technologies (such as infrared, microwave), then such wired and / or wireless technologies are included within the definition of a transmission medium.

[0059] The information, signals, etc. described in this disclosure may be represented using any of a variety of different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof. In addition, terms explained in this disclosure and terms necessary for understanding this disclosure may be replaced with terms having the same or similar meanings.

[0060] Furthermore, the information, parameters, etc. described in this disclosure may be expressed using absolute values, may be expressed using relative values ​​from a predetermined value, or may be expressed using other corresponding information.

[0061] As used in this disclosure, the phrase "based on" does not mean "based only on," unless expressly stated otherwise. In other words, the phrase "based on" means both "based only on" and "based at least on."

[0062] As used in this disclosure, any reference to an element using a designation such as "first," "second," etc. does not generally limit the quantity or order of those elements. These designations may be used in this disclosure as a convenient method of distinguishing between two or more elements. Thus, a reference to a first and a second element does not imply that only two elements may be employed or that the first element must in some way precede the second element.

[0063] The "unit" in the configuration of each of the above devices may be replaced with "means," "circuit," "device," etc.

[0064] When used in this disclosure, the terms "include," "including," and variations thereof are intended to be inclusive, similar to the term "comprising." Furthermore, when used in this disclosure, the term "or" is not intended to be an exclusive or.

[0065] In this disclosure, where articles are added by translation, such as a, an, and the in English, the disclosure may include that the nouns following these articles are in the plural form.

[0066] In the present disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "coupled" may also be interpreted in the same way as "different." [Explanation of symbols]

[0067] 100: Information processing system, 2: Communication network, 10: User terminal, 1001: Processor, 1002: Memory, 1003: Storage, 1004: Communication device, 1005: Input device, 1006: Output device, 20: Store terminal, 30: Server device, 31: Request acquisition unit, 32: Presentation unit, 33: Verification unit, 34: Memory unit, 35: Risk information acquisition unit, 3001: Processor, 3002: Memory, 3003: Storage, 3004: Communication device, 40: Online authentication system, 50: Public personal authentication system.

Claims

1. an acquisition unit that acquires a request for a service to be provided after identity verification from a user's terminal; a presentation unit that, in response to the request, presents to the user at the terminal information on an identity verification method suitable for the user, out of a first identity verification method that uses first data related to the user to verify the identity via a communication network, and a second identity verification method that uses second data related to the user that is different from the first data to verify the identity via a communication network; Equipped with The presentation unit If the terminal does not have a function to read the data stored in the storage medium, presenting the user with information regarding the first identity verification method that does not use the data; In the case where the terminal has a function for reading data stored in a storage medium, if the user remembers the personal identification number of the data stored in the storage medium, the terminal presents the user with information regarding the second personal identification method using the data as the second data, whereas if the user does not remember the personal identification number of the data stored in the storage medium, the terminal presents the user with information regarding the first personal identification method.

1. An information processing device comprising:

2. The presentation unit asks the user a question at the terminal, and presents an identity verification method suitable for the user depending on the answer to the question.

2. The information processing apparatus according to claim 1, wherein:

3. The presenting unit presents an identity verification method suitable for the user in accordance with a history of identity verification methods used when identity verification of the user was performed in the past.

2. The information processing apparatus according to claim 1, wherein:

4. The presenting unit presents an identity verification method suitable for the user according to information about the location of the user's terminal.

2. The information processing apparatus according to claim 1, wherein:

5. an acquisition unit that acquires information regarding a risk assessment for the user; The presenting unit presents an identity verification method suitable for the user in accordance with a change in the risk assessment identified by the acquired information.

2. The information processing apparatus according to claim 1, wherein:

6. acquiring a request for a service to be provided after identity verification from a user's terminal; in response to the request, presenting to the user at the terminal information on an identity verification method suitable for the user, out of a first identity verification method for verifying the identity of the user via a communication network using first data related to the user, and a second identity verification method for verifying the identity of the user via a communication network using second data related to the user that is different from the first data; Equipped with In the presenting step, If the terminal does not have a function to read the data stored in the storage medium, presenting the user with information regarding the first identity verification method that does not use the data; An information processing method characterized in that, when the terminal has a function to read data stored on a storage medium, if the user remembers the PIN number of the data stored on the storage medium, information regarding the second identity verification method using the data as the second data is presented to the user, while if the user does not remember the PIN number of the data stored on the storage medium, information regarding the first identity verification method is presented to the user.

Citation Information

Patent Citations

  • Portable information terminal, its control method, and program

    JP2015159560A

  • Personal authentication system, authentication unit, program and personal authentication method

    JP2020087438A

  • Information processing apparatus, information processing method, and program

    JP2023011388A

  • Program, information processor, and information processing method

    JP2023151796A

  • Payment device, program, and information processing method

    JP7000503B2