Authentication terminal, system, authentication terminal control method and program

The authentication terminal addresses the issue of user confusion by performing dual verifications and offering targeted guidance, enhancing convenience by addressing both fraudulent use and service eligibility issues.

JP7772078B2Active Publication Date: 2025-11-18NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023550926
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-30
Publication Date
2025-11-18
Estimated Expiration
2041-09-30

AI Technical Summary

Technical Problem

Existing automated gate systems do not provide guidance to users who are unable to pass through the gate, leading to confusion and inconvenience.

Method used

An authentication terminal that performs dual biometric verifications - one using biometric information from a user's device and another using service provision eligibility determination data - and provides tailored responses based on the failure of each verification to guide the user on necessary actions.

Benefits of technology

Enhances user convenience by providing clear instructions on how to rectify authentication failures, distinguishing between fraudulent use and lack of service eligibility, thus improving the overall user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007772078000001
    Figure 0007772078000001
  • Figure 0007772078000002
    Figure 0007772078000002
  • Figure 0007772078000003
    Figure 0007772078000003
Patent Text Reader

Abstract

Provided is an authentication terminal which contributes to an improvement in user convenience. The authentication terminal comprises a first acquisition unit, a second acquisition unit, an authentication unit, and a service providing unit. When the distance between its own device and the user becomes a first distance, the first acquisition unit acquires, from another device, first biometric information about the user and determination data for determining whether to provide a service to the user. The second acquisition unit acquires second biometric information about the user, when the distance between the own device and the user becomes a second distance. The authentication unit authenticates the user on the basis of first verification using the first biometric information and the second biometric information, and second verification using the determination data. When the authentication result is successful, the service providing unit provides a service to the authenticated person. When the authentication result is a failure, the service providing unit determines a response for the unauthenticated person according to which of the first verification and the second verification has failed.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an authentication terminal, a system, a control method for an authentication terminal, and a storage medium. [Background technology]

[0002] Various services using biometric authentication are available.

[0003] For example, Patent Document 1 describes an automated gate system that allows users to pass through a gate without having to wave a card or other such action. When a user carrying a user device that stores passage authority data and facial data enters the communication area of ​​a wireless communication unit, the automated gate system of Patent Document 1 receives data from the user device and stores the data and the validity / invalidity determination result of the passage authority data in a data storage unit. When a user passes through the gate, the automated gate system identifies the user by comparing the user's facial data acquired from an image captured by a camera with the facial data stored in the data storage unit in a user authentication unit. The automated gate system allows the user to pass when the determination result of the identified user's passage authority data is valid. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2003-331323 Summary of the Invention [Problem to be solved by the invention]

[0005] The automated gate system disclosed in Patent Document 1 determines whether to allow or deny a user's passage based on whether the user's passage authority data is valid or invalid. However, this automated gate system only denies passage through the gate to users who do not have valid passage authority data. In other words, there is no guidance for users who are unable to pass through the gate, so users who are unable to pass through the gate do not know what to do next.

[0006] A primary object of the present invention is to provide an authentication terminal, a system, a control method for an authentication terminal, and a storage medium that contribute to improving convenience for users. [Means for solving the problem]

[0007] According to a first aspect of the present invention, there is provided an authentication terminal comprising: a first acquisition unit that acquires, from another device, first biometric information of the user and judgment data for determining whether to provide a service to the user when the distance between the device and the user reaches a first distance; a second acquisition unit that acquires second biometric information of the user when the distance between the device and the user reaches a second distance; an authentication unit that authenticates the user based on a first verification using the first biometric information and the second biometric information and a second verification using the judgment data; and a service provision unit that, if the authentication result is successful, provides a service to a person who has been successfully authenticated, and, if the authentication result is unsuccessful, determines how to respond to a person who has failed authentication depending on whether the first verification or the second verification failed.

[0008] According to a second aspect of the present invention, there is provided a system including a terminal carried by a user and an authentication terminal, wherein the authentication terminal comprises a first acquisition unit that acquires from the terminal first biometric information of the user and judgment data for determining whether to provide a service to the user when the distance between the authentication terminal and the user reaches a first distance, a second acquisition unit that acquires second biometric information of the user when the distance between the authentication terminal and the user reaches a second distance, an authentication unit that authenticates the user based on a first verification using the first biometric information and the second biometric information and a second verification using the judgment data, and a service provision unit that, if the authentication result is successful, provides a service to a person who is successfully authenticated, and, if the authentication result is unsuccessful, determines how to respond to a person who is unsuccessful in authentication depending on whether the first verification or the second verification failed.

[0009] According to a third aspect of the present invention, there is provided a control method for an authentication terminal, in which, when the distance between the authentication terminal and a user reaches a first distance, the authentication terminal acquires from another device first biometric information of the user and judgment data for determining whether to provide a service to the user, and when the distance between the authentication terminal and the user reaches a second distance, the authentication terminal acquires second biometric information of the user, authenticates the user based on a first verification using the first biometric information and the second biometric information and a second verification using the judgment data, and if the authentication result is successful, provides a service to those who are successfully authenticated, and if the authentication result is unsuccessful, determines how to respond to those who are unsuccessful in authentication depending on whether the first verification or the second verification failed.

[0010] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on an authentication terminal to execute the following processes: when the distance between the device and a user reaches a first distance, acquire first biometric information of the user and judgment data for determining whether to provide a service to the user from another device; when the distance between the device and the user reaches a second distance, acquire second biometric information of the user; authenticate the user based on a first verification using the first biometric information and the second biometric information and a second verification using the judgment data; and, if the authentication result is successful, provide a service to a person who has been successfully authenticated; and, if the authentication result is unsuccessful, determine how to respond to a person who has failed authentication depending on whether the first verification or the second verification failed. [Effects of the Invention]

[0011] According to each aspect of the present invention, an authentication terminal, a system, a control method for an authentication terminal, and a storage medium are provided that contribute to improving user convenience. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is a diagram for explaining an outline of an embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of a schematic configuration of an authentication system according to the first embodiment. [Figure 3] FIG. 3 is a diagram illustrating a digital wallet of a terminal according to the first embodiment. [Figure 4] 4A and 4B are diagrams for explaining the operation of the authentication system according to the first embodiment. [Figure 5] FIG. 5 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment. [Figure 6] FIG. 6 is a diagram showing an example of a display on the terminal according to the first embodiment. [Figure 7] FIG. 7 is a diagram illustrating an example of a processing configuration of an authentication terminal according to the first embodiment. [Figure 8] FIG. 8 is a diagram illustrating an example of the matched person database according to the first embodiment. [Figure 9] 9A and 9B are diagrams showing an example of a display on the authentication terminal according to the first embodiment. [Figure 10] FIG. 10 is a diagram showing an example of a display on the authentication terminal according to the first embodiment. [Figure 11] 11A and 11B are diagrams showing an example of a display on the authentication terminal according to the first embodiment. [Figure 12] FIG. 12 is a flowchart showing an example of the operation of the authentication terminal according to the first embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of a display on a terminal according to a modification of the first embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of a schematic configuration of an authentication system according to the second embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of a processing configuration of a terminal according to the second embodiment. [Figure 16] FIG. 16 is a diagram illustrating an example of a processing configuration of a server device according to the second embodiment. [Figure 17] FIG. 17 is a diagram showing an example of a display on a terminal according to the second embodiment. [Figure 18] FIG. 18 is a diagram showing an example of an authentication-subjected user information database according to the second embodiment. [Figure 19] FIG. 19 is a sequence diagram showing an example of the operation of the authentication system according to the second embodiment. [Figure 20] FIG. 20 is a diagram illustrating an example of the hardware configuration of an authentication terminal according to the present disclosure. [Figure 21] FIG. 21 is a diagram showing an example of a display on an authentication terminal according to a modification of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0013] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0014] An authentication terminal 100 according to one embodiment includes a first acquisition unit 101, a second acquisition unit 102, an authentication unit 103, and a service providing unit 104 (see FIG. 1). When the distance between the authentication terminal 100 and a user reaches a first distance, the first acquisition unit 101 acquires the user's first biometric information and determination data for determining whether to provide a service to the user from another device. When the distance between the authentication terminal 100 and the user reaches a second distance, the second acquisition unit 102 acquires the user's second biometric information. The authentication unit 103 authenticates the user based on a first verification using the first biometric information and the second biometric information and a second verification using the determination data. If the authentication result is successful, the service providing unit 104 provides a service to the authenticated user. If the authentication result is unsuccessful, the service providing unit 104 determines how to handle the unsuccessful authentication depending on whether the first verification or the second verification failed.

[0015] The authentication terminal 100 acquires, for example, biometric information of a user from a terminal carried by the user and determination data for determining whether to provide the user with a service. The authentication terminal 100 authenticates the user by performing a first verification using the biometric information and a second verification using the determination data. If authentication fails, the authentication terminal 100 changes its response (operation) depending on whether the first verification or the second verification failed. For example, if the first verification fails, the authentication terminal 20 suspects unauthorized use by a third party other than the terminal owner, and notifies a security guard or other person of this fact. If the second verification fails, the authentication terminal 20 determines that the user does not meet the information required to receive the service (e.g., pass through a gate), and provides guidance on the actions the user needs to take to receive the service. In this way, if authentication fails, the authentication terminal 100 provides the user with information according to the details of the authentication failure, so the user can know the actions they need to take to receive the service. This improves user convenience.

[0016] Specific embodiments will be described in more detail below with reference to the drawings.

[0017] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0018] [System Configuration] 2 is a diagram showing an example of a schematic configuration of an authentication system (information processing system) according to the first embodiment. As shown in FIG. 2, the authentication system includes a terminal 10 and an authentication terminal 20.

[0019] A user carries a terminal 10. The terminal 10 is, for example, a mobile terminal such as a smartphone or a tablet.

[0020] The authentication terminal 20 is a terminal that provides predetermined services to users who have been successfully authenticated. For example, the authentication terminal 20 is installed at the entrances and exits of an event venue or at various locations in an airport, and allows users who have been successfully authenticated to pass through.

[0021] In the first embodiment, a gate device installed in an airport will be described as an example of the authentication terminal 20. More specifically, the authentication terminal 20 allows passage to users who possess a negative certificate for infectious diseases and denies passage to users who do not possess such certificate. However, the authentication terminal 20 is not intended to be limited to a gate device installed in an airport. For example, the authentication terminal 20 may be a ticket issuing machine that issues tickets.

[0022] The terminal 10 and each authentication terminal 20 are configured to be able to communicate with each other via a short-range wireless communication means such as Bluetooth (registered trademark).

[0023] The configuration of the authentication system shown in Fig. 2 is an example and is not intended to be limiting. For example, the authentication system may include at least one authentication terminal 20. Also, although Fig. 2 illustrates one user (one terminal 10), it goes without saying that the number of users or terminals 10 is not intended to be limiting.

[0024] [Operation overview] Next, an outline of the operation of the authentication system according to the first embodiment will be described.

[0025] <Preparing data to determine whether service can be provided> Before being authenticated by authentication terminal 20, the user prepares the information (data) necessary to pass through authentication terminal 20. More specifically, authentication terminal 20 is a gate device installed at an airport, and the user is required to present a valid negative certificate, so the user prepares a valid negative certificate. In other words, the user prepares the information (data) necessary to receive services from authentication terminal 20.

[0026] The data required to pass through the authentication terminal 20 (data required to receive the service provided by the authentication terminal 20) is referred to as "service provision eligibility determination data." Alternatively, the service provision eligibility determination data may be simply referred to as "determination data." The authentication terminal 20 uses the service provision eligibility determination data to authenticate the user. In other words, based on the service provision eligibility determination data, it is confirmed that the user (person to be authenticated) has the authority to pass through the gate, etc.

[0027] The user manages the assessment data using a so-called digital wallet. The user installs an application to realize the digital wallet on the terminal 10 that the user owns. By creating a digital wallet on the terminal 10, the user stores electronic money, credit card information, identification documents such as a passport or driver's license, and various certificates such as vaccination certificates and negative certificates (Common Pass) on the terminal 10.

[0028] For example, the user's terminal 10 stores digital information such as that shown in Figure 3. In the following explanation, the information (data) stored in the digital wallet of the terminal 10 will be referred to as "electronic wallet data." Electronic wallet data refers to digital data corresponding to cards, etc. stored in a regular wallet. In other words, electronic wallet data refers to digital data related to the user's qualifications, assets, status, condition, attributes, etc.

[0029] Examples of electronic wallet data include account information for electronic money or cryptocurrency as payment methods, credit card information, official identification such as a driver's license, and health certificates such as vaccination certificates and negative test results. Examples of electronic wallet data include digital data such as patient registration cards from hospitals, membership cards from retail stores, point cards, coupons, employee ID cards, and student ID cards.

[0030] The user selects the determination data to be presented to the authentication terminal 20 from the electronic wallet data managed by the digital wallet of the terminal 10. For example, in the example of Figure 3, a negative certificate is selected as the "service provision eligibility determination data."

[0031] The terminal 10 stores the user's user ID and biometric information in addition to the electronic wallet data. For example, the user operates the terminal 10 to take a picture of their own face. The terminal 10 stores the face image or features generated from the face image as the user's biometric information.

[0032] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, or iris pattern. Alternatively, the biometric information may be image data such as a face image or fingerprint image. The biometric information may be any information that includes the user's physical characteristics. In this disclosure, a case where biometric information related to a person's "face" (a face image or features generated from a face image) is used will be described.

[0033] <Authentication Operation> The user, while still carrying the terminal 10, approaches the authentication terminal 20 (see FIG. 4A). When the distance between the terminal 10 and the authentication terminal 20 reaches a predetermined distance (a distance at which communication is possible via short-range wireless communication; for example, a distance of several meters), the terminal 10 transmits a "user information notification" to the authentication terminal 20.

[0034] Specifically, the terminal 10 transmits a user information notification including the user's biometric information and determination data to the authentication terminal 20. The authentication terminal 20 stores the biometric information and determination data included in the notification in a matching subject database. Details of the matching subject database will be described later.

[0035] Thereafter, the user carrying the terminal 10 arrives at the authentication terminal 20 (see FIG. 4B). When the user arrives, the authentication terminal 20 authenticates the user. The authentication process of the authentication terminal 20 consists of two verifications.

[0036] The first verification is verification using biometric information. The authentication terminal 20 determines whether the owner of the terminal 10 is legitimate or not through the first verification.

[0037] When a user arrives at the authentication terminal 20, the authentication terminal 20 acquires biometric information of the user. For example, the authentication terminal 20 photographs the user and acquires a facial image.

[0038] The authentication terminal 20 executes a matching process (one-to-N matching; N is a positive integer, the same applies below) using the biometric information acquired from the terminal 10 (biometric information included in the user information) and the biometric information acquired by photographing. If the matching process (biometric authentication) is successful, the authentication terminal 20 determines that the first verification is successful. In other words, the authentication terminal 20 determines that the user who possesses the terminal 10 is legitimate.

[0039] If the matching process (biometric authentication) fails, the authentication terminal 20 determines that the first verification has failed. That is, the authentication terminal 20 determines that the user who possesses the terminal 10 is invalid.

[0040] If the biometric information (facial image, features) that the user has registered in advance in the terminal 10 substantially matches the biometric information acquired from the user who appears in front of the authentication terminal 20, the authentication terminal 20 can determine that the legitimate owner or possessor of the terminal 10 has appeared in front of its device.

[0041] The second verification is a verification using service provision availability determination data. The authentication terminal 20 determines whether or not a service can be provided to the user through the second verification. In other words, the authentication terminal 20 determines whether or not the user has the qualifications, authority, etc. to receive the service.

[0042] The authentication terminal 20 determines whether the determination data included in the user information notification is valid. Specifically, if the user possesses a valid negative certificate (a negative certificate whose validity period has not expired; for example, a negative certificate stating that 72 hours have not passed since the specimen was collected), the authentication terminal 20 determines that the second verification of the user has been successful.

[0043] If the validity period of the negative certificate has expired or if the terminal 10 does not store the negative certificate, the authentication terminal 20 determines that the second verification of the user has failed.

[0044] If the two verifications are successful, authentication terminal 20 determines that authentication of the person to be authenticated has been successful. Specifically, authentication terminal 20 permits the user (person to be authenticated) to pass through the gate.

[0045] If at least one of the two verifications fails, the authentication terminal 20 changes its response (processing, operation) depending on the verification method that failed.

[0046] If the first verification (biometric authentication) fails, the authentication terminal 20 determines that the person to be authenticated may have fraudulently obtained and used someone else's terminal 10. In this case, the authentication terminal 20 notifies a staff member, security guard, or the like that an event suspected of fraudulent use of the terminal 10 has occurred. For example, the authentication terminal 20 notifies a terminal carried by a security guard of the possibility of the fraudulent use. Alternatively, the authentication terminal 20 displays the possibility of the fraudulent use on a monitor installed in a waiting room where the security guard, or the like, is waiting.

[0047] If the second verification (verification using the service provision eligibility determination data) fails, the authentication terminal 20 notifies the user that the information required for authentication (information required to pass through the gate) was not obtained. Alternatively, the authentication terminal 20 may provide the user with information that will enable the authentication to be determined as successful. For example, the authentication terminal 20 may provide the user with information regarding a PCR (Polymerase Chain Reaction) test to obtain a negative certificate.

[0048] Next, each device included in the authentication system according to the first embodiment will be described in detail.

[0049] [Device] Examples of the terminal 10 include a mobile terminal device such as a smartphone, a mobile phone, a game console, a tablet, etc. The terminal 10 can be any equipment or device that can accept user operations and communicate with the authentication terminal 20.

[0050] 5 is a diagram showing an example of the processing configuration (processing modules) of the terminal 10 according to the first embodiment. Referring to FIG. 5, the terminal 10 includes a communications control unit 201, an electronic wallet control unit 202, a biometric information acquisition unit 203, a user information notification unit 204, and a storage unit 205.

[0051] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the authentication terminal 20. The communication control unit 201 also transmits data to the authentication terminal 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0052] The communication control unit 201 supports short-range wireless communication such as Bluetooth (registered trademark), and communicates with the authentication terminal 20 via this short-range wireless communication. When the communication control unit 201 completes connection with the authentication terminal 20, it notifies the user information notification unit 204 to that effect. Note that it is assumed that the pairing process required for the terminal 10 and the authentication terminal 20 to communicate via Bluetooth (registered trademark) has been completed in advance.

[0053] The electronic wallet control unit 202 is a means for managing and controlling the digital wallet. The electronic wallet control unit 202 acquires various electronic wallet data in response to user operations and stores them in the storage unit 205.

[0054] The electronic wallet control unit 202 is implemented by an application installed on the terminal 10. Detailed explanations of the installation of the application to implement the digital wallet and the registration of specific electronic wallet data are omitted here, as these operations are outside the scope of this disclosure.

[0055] For example, when registering electronic wallet data, the user may operate the terminal 10 to access a homepage provided by an entity that issues various types of information, and register the electronic wallet data in the digital wallet from that homepage.

[0056] For example, regarding vaccination certificates and negative certificates, the electronic wallet control unit 202 accesses websites managed by certificate issuers such as local governments and medical institutions. The electronic wallet control unit 202 acquires vaccination certificates and negative certificates by inputting the user's ID or other information into the website in response to a user's operation, and stores the information in the storage unit 205. Alternatively, the electronic wallet control unit 202 may acquire vaccination certificates and negative certificates by photographing a two-dimensional code printed on the vaccination certificate or other document in response to a user's operation. In this way, the electronic wallet control unit 202 may acquire vaccination certificates and negative certificates by accessing local governments or medical institutions, or the user may register the vaccination certificate or other document in their digital wallet.

[0057] Alternatively, for identification documents such as passports and driver's licenses, the electronic wallet control unit 202 may take an image of the document in response to a user's operation and store the image data as electronic wallet data relating to the passport, driver's license, etc.

[0058] The electronic wallet control unit 202 also generates a user ID to identify the user who owns the digital wallet. The user ID may be any information that can uniquely identify the user. For example, the electronic wallet control unit 202 may obtain an email address from the user and use that email address as the user ID. The electronic wallet control unit 202 stores the user ID in the storage unit 205.

[0059] Furthermore, in response to a specific action by the user (e.g., pressing a button on a menu for registering service provision eligibility determination data), the electronic wallet control unit 202 displays a GUI or other screen for selecting information to be provided to the authentication terminal 20. For example, the electronic wallet control unit 202 displays a GUI such as that shown in Fig. 3 and acquires the determination data to be provided to the authentication terminal 20.

[0060] In the example of FIG. 3, a negative certificate has been selected, so the electronic wallet control unit 202 stores the "negative certificate" in the storage unit 205 as the "service provision availability determination data."

[0061] The biometric information acquisition unit 203 is a means for acquiring biometric information of a user. For example, the biometric information acquisition unit 203 acquires biometric information (face image) using a GUI (Graphical User Interface) as shown in Fig. 6. The biometric information acquisition unit 203 generates feature amounts from the acquired face image and stores the generated feature amounts in the storage unit 205.

[0062] Note that, since existing technology can be used for the process of generating feature amounts, detailed description thereof will be omitted. For example, the biometric information acquisition unit 203 extracts the eyes, nose, mouth, etc. from the face image as feature points. Thereafter, the biometric information acquisition unit 203 calculates the position of each feature point and the distance between each feature point as feature amounts, and generates a feature vector (vector information that characterizes the face image) consisting of multiple feature amounts.

[0063] The user information notification unit 204 is a means for notifying the authentication terminal 20 of user information. When the terminal 10 and the authentication terminal 20 start communication, the user information notification unit 204 reads out the biometric information (features generated from a facial image) and determination data stored in the storage unit 205. The user information notification unit 204 transmits a "user information notification" including the read biometric information and determination data to the authentication terminal 20. That is, the user information notification unit 204 transmits to the authentication terminal 20 the determination data of various certificates such as electronic money, credit card information, identification documents such as a passport or a driver's license, a vaccination certificate or a negative certificate (Common Pass), and the user's biometric information.

[0064] In this way, when the user information notification unit 204 starts communication with the authentication terminal 20 via short-range wireless communication means, it transmits biometric information (first biometric information; for example, feature amount) and service provision eligibility determination data to the authentication terminal 20.

[0065] The storage unit 205 is a means for storing information necessary for the operation of the terminal 10.

[0066] [Authentication terminal] 7 is a diagram showing an example of the processing configuration (processing modules) of the authentication terminal 20 according to the first embodiment. Referring to FIG. 7, the authentication terminal 20 includes a communication control unit 301, a user information processing unit 302, a biometric information acquisition unit 303, an authentication unit 304, a service providing unit 305, and a storage unit 306.

[0067] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the terminal 10. The communication control unit 301 also transmits data to the terminal 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0068] The communication control unit 301 supports short-distance wireless communication such as Bluetooth (registered trademark), and communicates with the terminal 10 via the short-distance wireless communication.

[0069] The user information processing unit 302 is a means (first acquisition unit) for acquiring biometric information (first biometric information) and determination data of a user from another device when the distance between the device and the user reaches a first distance (for example, the communication distance of Bluetooth (registered trademark)). As described above, the determination data (service provision availability determination data) is data for determining whether or not to provide a service to the user.

[0070] More specifically, the user information processing unit 302 performs processing related to the user information notification received from the terminal 10. Upon receiving the user information notification, the user information processing unit 302 registers the biometric information (feature amount) and determination data included in the notification in the matching target database (see FIG. 8).

[0071] As shown in Fig. 8, the matching target database includes a biometric information field and a service provision eligibility determination data field. Note that the matching target database shown in Fig. 8 is an example and is not intended to limit the items stored therein. For example, the registration date and time of an entry may be stored in the database.

[0072] The biometric information acquisition unit 303 is a means for controlling a camera device (a camera device provided in the authentication terminal 20) and acquiring biometric information (for example, a facial image) of a user who has arrived at the authentication terminal 20 (a user who has arrived at a predetermined area in front of the authentication terminal 20). The biometric information acquisition unit 303 is a second acquisition unit that acquires biometric information of a user (second biometric information) when the distance between the biometric information acquisition unit 303 and the user becomes a second distance (shorter than the first distance; the distance between the user who has arrived at the authentication terminal 20 and the authentication terminal 20).

[0073] The biometric information acquisition unit 303 periodically or at a predetermined timing captures an image of the area in front of the device. The biometric information acquisition unit 303 determines whether the captured image contains a human face image, and if a face image is included, extracts the face image from the captured image data.

[0074] Note that since existing technologies can be used for the facial image detection process and facial image extraction process by the biometric information acquisition unit 303, detailed description thereof will be omitted. For example, the biometric information acquisition unit 303 may extract a facial image (face region) from image data using a learning model trained by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 303 may extract a facial image using a method such as template matching.

[0075] The biometric information acquisition unit 303 generates a feature amount from the extracted face image and passes the generated feature amount (biometric information) to the authentication unit 304.

[0076] The authentication unit 304 is a means for authenticating a user who has arrived at its own device (authentication terminal 20). As described above, the authentication unit 304 authenticates the user using two verifications. The authentication unit 304 authenticates the user based on the result of the first verification using the first biometric information acquired from the terminal 10 and the second biometric information obtained by photographing the user, and the result of the second verification using the determination data.

[0077] Upon acquiring the biometric information from the biometric information acquisition unit 303, the authentication unit 304 performs a first verification using the biometric information. As the first verification, the authentication unit 304 executes a matching process using the biometric information acquired from the biometric information acquisition unit 303 and the biometric information stored in the matching target database.

[0078] The authentication unit 304 calculates the similarity between the feature amount of the user who arrived at its own device and the feature amount registered in the matching target database. The similarity can be calculated using chi-square distance, Euclidean distance, etc. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0079] If the similarity is equal to or greater than a predetermined value, the authentication unit 304 determines that the matching process is successful. If the matching process is successful, the authentication unit 304 determines that the first verification (verification using biometric information) of the person to be authenticated is successful.

[0080] If there is no similarity equal to or greater than a predetermined value, the authentication unit 304 determines that the matching process has failed. If the matching process has failed, the authentication unit 304 determines that the first verification (verification using biometric information) of the person to be authenticated has failed.

[0081] The authentication unit 304 performs a matching process (using the first and second biometric information) to verify (confirm) the authenticity of the user who arrives at the authentication terminal 20. For example, even if a third party other than the owner of the terminal 10 arrives at the authentication terminal 20 carrying the terminal 10, the biometric information stored in the terminal 10 and the biometric information acquired by the authentication terminal 20 do not match, and the matching process fails.

[0082] If the first verification is successful, the authentication unit 304 reads out the service provision eligibility determination data of the entry with the highest similarity (the entry in the database of persons to be matched) from the database of persons to be matched.

[0083] The authentication unit 304 performs a second verification using the read determination data. More specifically, as the second verification, the authentication unit 304 determines the validity of the determination data. If the determination data is valid, the authentication unit 304 determines that the second verification has been successful. If the determination data is invalid, the authentication unit 304 determines that the second verification has failed.

[0084] The method for determining the validity of the determination data differs depending on the functions assigned to the authentication terminal 20. For example, the authentication unit 304 checks the validity period of the negative certificate obtained from the terminal 10, and determines that "the determination data is valid" if the period has not passed, and that "the determination data is invalid" if the period has passed.

[0085] Alternatively, the authentication unit 304 may determine the validity of the determination data based on whether the test method etc. described in the acquired negative certificate matches the test method preset in the authentication terminal 20.

[0086] The authentication unit 304 sets the authentication result based on the results of the two verifications. If the two verifications are successful, the authentication unit 304 sets the authentication result of the person to be authenticated to "authentication successful." If at least one of the two verifications fails, the authentication unit 304 sets the authentication result of the person to be authenticated to "authentication failed."

[0087] The authentication unit 304 notifies the service providing unit 305 of the determined authentication result. When notifying the service providing unit 305 of an authentication failure, the authentication unit 304 notifies the service providing unit 305 of the cause of the authentication failure (verification method) as accompanying information accompanying the authentication result. Specifically, the authentication unit 304 notifies the service providing unit 305 of the authentication failure, along with "first verification failed" or "second verification failed."

[0088] The service providing unit 305 is a means for providing a service assigned to the authentication terminal 20. The service providing unit 305 executes the task (operation, processing) assigned to the authentication terminal 20. In the first embodiment, the service providing unit 305 allows a user who has been successfully authenticated to pass through the gate. The service providing unit 305 denies a user who has failed authentication from passing through the gate.

[0089] If the authentication by the authentication unit 304 results in success, the service providing unit 305 provides a service to the authenticated person (the person to be authenticated who is determined to have been successfully authenticated). If the authentication by the authentication unit 304 results in failure, the service providing unit 305 determines how to handle the person to be authenticated who is unsuccessful (the person to be authenticated who is determined to have failed authentication) depending on whether the first verification or the second verification has failed.

[0090] The service providing unit 305 outputs a message according to the authentication result and its accompanying information (the failed verification method).

[0091] For example, if the authentication is successful, the service providing unit 305 displays a message as shown in Fig. 9A. Alternatively, if the authentication terminal 20 is a kiosk terminal, the service providing unit 305 displays a message indicating the location of a passable gate (see Fig. 9B).

[0092] If authentication fails and the cause is the first verification (verification using biometric information), the service providing unit 305 displays, for example, a message as shown in Fig. 10. Since the fact that the first verification failed suggests that the terminal 10 is being used fraudulently, the service providing unit 305 instructs the person to stay where they are.

[0093] Furthermore, the service providing unit 305 notifies a staff member, a security guard, or the like that an event has occurred that suggests a suspected fraudulent use of the terminal 10. For example, the service providing unit 305 notifies a terminal carried by a security guard of the possibility of the fraudulent use.

[0094] Here, if authentication fails due to a failure in the first verification using biometric authentication, the service providing unit 305 may reacquire the user's biometric information or attempt matching using other biometric information. If other biometric information (for example, iris information, fingerprint, palm print) is used, this biometric information is stored in the terminal 10 in advance. By taking such measures, it is possible to appropriately deal with cases where a clear face image cannot be acquired due to the installation environment of the authentication terminal 20, etc.

[0095] Regardless of the result of the second verification (verification of the validity of the service provision determination data), if the first verification (biometric authentication) fails, the service providing unit 305 notifies the terminal 10 of unauthorized use.

[0096] In this way, if the first verification fails, the service providing unit 305 notifies a predetermined person (such as a staff member or security guard) of the unauthorized use (possibility of unauthorized use) of the terminal 10 by the person who failed the authentication.

[0097] If authentication fails due to the second verification (verification using the judgment data), the service providing unit 305 displays a message such as that shown in Fig. 11A. By using the message shown in Fig. 11A, the service providing unit 305 notifies the user that the information required for authentication (the information required to pass through the gate) has not been obtained.

[0098] Furthermore, if the second verification fails, unlike the failure of the first verification, there is no reason to suspect fraudulent use of the terminal 10, and therefore the service providing unit 305 may provide the user with information to determine that the authentication is successful. For example, as shown in FIG. 11B, the service providing unit 305 may provide the user with detailed guidance regarding a PCR (Polymerase Chain Reaction) test or the like for obtaining a negative certificate. Furthermore, as shown in FIG. 11B, the service providing unit 305 may display a button or the like for booking a PCR test or the like. In this case, the service providing unit 305 notifies the testing institution of the information of the user who has booked the test.

[0099] In this way, if the first verification is successful and the second verification is unsuccessful, the service providing unit 305 may provide the unsuccessful authentication user with information about the procedures required to receive the service.

[0100] The storage unit 306 is a means for storing information necessary for the operation of the authentication terminal 20. In the storage unit 306, a database of persons to be verified is constructed.

[0101] The operation of the authentication terminal 20 can be summarized as shown in the flowchart of Fig. 12. Fig. 12 is a flowchart showing an example of the operation of the authentication terminal 20 according to the first embodiment.

[0102] The authentication terminal 20 receives the user information notification from the terminal 10 (step S101).

[0103] The authentication terminal 20 stores the biometric information and the service provision availability determination data (determination data) included in the user information notification in the verification target database (step S102).

[0104] When the user arrives at the authentication terminal 20, the authentication terminal 20 acquires the biometric information of the user (step S103).

[0105] The authentication terminal 20 executes a first verification using the biometric information. Specifically, the authentication terminal 20 executes a matching process using the acquired biometric information and the biometric information stored in the matching target person database (step S104).

[0106] If the matching process fails (step S105, No branch), the authentication terminal 20 sets the authentication result of the user to "authentication failed" (step S106).

[0107] If the matching process is successful (step S105, branch Yes), the authentication terminal 20 performs a second verification. Specifically, the authentication terminal 20 verifies the validity of the service provision availability determination data (step S107).

[0108] If the determination data is invalid (step S108, No branch), the authentication terminal 20 sets the authentication result of the user to "authentication failed" (step S106).

[0109] If the determination data is valid (step S108, Yes branch), the authentication terminal 20 sets the authentication result of the user to "authentication successful" (step S109).

[0110] The authentication terminal 20 outputs a message according to the authentication result (step S110). The authentication terminal 20 provides services to the person who has been successfully authenticated.

[0111] <Modification 1 of the First Embodiment> In the above embodiment, it is assumed that Bluetooth (registered trademark) is turned on in the terminal 10. However, there may be cases where the Bluetooth (registered trademark) function of the terminal 10 is turned off.

[0112] In this case, the terminal 10 may prompt the user to turn on the Bluetooth (registered trademark) function when the terminal 10 approaches the authentication terminal 20. For example, the user information notification unit 204 of the terminal 10 may display a GUI as shown in Fig. 13 to prompt the user to enable the Bluetooth (registered trademark) function.

[0113] The terminal 10 (user information notification unit 204) acquires the location where the authentication terminal 20 is installed (location information; X coordinate, Y coordinate) from an external server on the Internet. The user information notification unit 204 also receives GPS signals from GPS (Global Positioning System) satellites to perform positioning and generate location information including the latitude and longitude of the terminal. Alternatively, the user information notification unit 204 may communicate with a wireless access point and treat the location of the wireless access point as the location of the terminal. Alternatively, the user information notification unit 204 may generate location information based on the strength of radio waves received from the wireless access point.

[0114] The user information notification unit 204 uses the location information of the authentication terminal 20 acquired from the external server and the location information of the own terminal generated above to determine whether the own terminal is close to the authentication terminal 20. Specifically, the user information notification unit 204 determines that the authentication terminal 20 is nearby if the authentication terminal 20 is installed within a predetermined range centered on the own terminal.

[0115] In this way, the terminal 10 may prompt the user to enable the short-range wireless communication means when the distance between the terminal 10 and the authentication terminal 20 reaches the third distance.

[0116] Note that the trigger for prompting the user to turn on Bluetooth (registered trademark) may be something other than the terminal 10 coming close to the authentication terminal 20. For example, the user may be prompted to turn on Bluetooth (registered trademark) based on the date and time. For example, if the user has booked an airline ticket, the terminal 10 estimates the date and time when the user will arrive at the departure airport based on the reservation information for the airline ticket. The terminal 10 may prompt the user to turn on Bluetooth (registered trademark) based on the estimated date and time. For example, the terminal 10 may prompt the user to turn on Bluetooth (registered trademark) several hours before the departure time. For example, if the user has booked a flight departing at 2:00 p.m., the terminal 10 may prompt the user to turn on Bluetooth (registered trademark) at 12:00 p.m.

[0117] Note that the use of location information and time information is not limited to enabling the function of a short-range wireless communication means such as Bluetooth (registered trademark). For example, the terminal 10 may use the location information and time information to confirm whether data stored in the digital wallet can be transmitted to the authentication terminal 20 or to prompt the user to select the data to be transmitted. For example, when the user (terminal 10) moves to a predetermined location or when a predetermined time arrives, the terminal 10 may display a GUI or the like that confirms the user's intention to transmit data in the digital wallet to the authentication terminal 10. Similarly, when the user moves to a predetermined location or when a predetermined time arrives, the terminal 10 may display a GUI with content that prompts the user to select data to be transmitted to the authentication terminal 20 from the data stored in the digital wallet.

[0118] <Modification 2 of the First Embodiment> In the above embodiment, it has been described that the terminal 10 and the authentication terminal 20 communicate using Bluetooth (registered trademark). However, the communication means between the terminal 10 and the authentication terminal 20 may be a communication means with a short communication distance such as NFC (Near Field Communication) instead of a communication means with a relatively long communication distance such as Bluetooth (registered trademark). Note that when a communication means with a short communication distance such as NFC is used, the first distance and the second distance are substantially the same.

[0119] In this case, the user's terminal 10 and the authentication terminal 20 can communicate after the user arrives at the authentication terminal 20. Specifically, the user holds the terminal 10 over (touches) the authentication terminal 20 like a transportation IC (Integrated Circuit) card, and the terminal 10 and the authentication terminal 20 can communicate.

[0120] As described above, in the authentication system according to the first embodiment, the authentication terminal 20 acquires biometric information and determination data of a user from the terminal 10 carried by the user. The authentication terminal 20 performs a first verification using the biometric information and a second verification using the determination data, and then performs authentication processing for the user who has arrived at the authentication terminal 20. If authentication fails, the authentication terminal 20 changes its response (operation) depending on whether the first or second verification failed. Specifically, if the first verification fails, the authentication terminal 20 suspects unauthorized use by a third party other than the owner of the terminal 10, and notifies a security guard or the like of this fact. If the second verification fails, the authentication terminal 20 determines that the user does not meet the conditions for receiving the service, and the authentication terminal 20 provides guidance on the necessary steps for the user to receive the service. In this way, if authentication fails, the authentication terminal 20 provides the user with appropriate information according to the details of the authentication failure, so that the user knows what action to take to receive the service.

[0121] Furthermore, in the authentication system according to the first embodiment, a series of authentication processes are completed by transmitting and receiving data between the authentication terminal 20 and the terminal 10. That is, the authentication process is performed without using a server that stores various certificates and the like. In this way, a more secure authentication system is provided by performing the authentication process using information stored in the terminal 10 (information distributed to each terminal 10) without using a server. That is, if a server is used to store and manage the certificates and the like of multiple users, a leak of information from the server could result in the leakage of the certificates and the like of the multiple users, causing significant damage. Furthermore, the authentication terminal 20 prevents unauthorized use of the terminal 10 by performing a matching process using biometric information of the owner of the terminal 10 and the user who possesses the terminal 10 and is attempting to receive services.

[0122] [Second embodiment] Next, the second embodiment will be described in detail with reference to the drawings.

[0123] In the first embodiment, a case has been described in which the terminal 10 transmits biometric information and service provision eligibility determination data to the authentication terminal 20. In the second embodiment, a case will be described in which biometric information and service provision eligibility determination data are transmitted from a server to the authentication terminal 20.

[0124] The following description will focus on the differences between the first and second embodiments.

[0125] Fig. 14 is a diagram showing an example of the configuration of an authentication system according to the second embodiment. As shown in Fig. 14, the authentication system according to the second embodiment includes a server device 30 in addition to a terminal 10 and an authentication terminal 20.

[0126] The server device 30 stores the user ID, biometric information, and service provision availability determination data of the user in association with each other.

[0127] The terminal 10 according to the second embodiment stores electronic wallet data and a user ID. However, the terminal 10 does not store the user's biometric information. When a user carrying the terminal 10 approaches the authentication terminal 20, the terminal 10 transmits a user information notification including the user ID to the authentication terminal 20.

[0128] Authentication terminal 20 transmits to server device 30 a "request for authentication-subject information" including the user ID.

[0129] Server device 30 transmits to authentication terminal 20 the biometric information and determination data corresponding to the user ID included in the request for providing authentication-subject information.

[0130] The authentication terminal 20 registers the biometric information and determination data acquired from the server device 30 in a database of persons to be matched.

[0131] The subsequent operations of the terminal 10 and the authentication terminal 20 can be the same as those described in the first embodiment.

[0132] Next, each device included in the authentication system according to the second embodiment will be described in detail.

[0133] [Device] Fig. 15 is a diagram showing an example of a processing configuration (processing module) of the terminal 10 according to the second embodiment. Referring to Fig. 15, the biometric information acquisition unit 203 is deleted from the configuration of the terminal 10 according to the first embodiment, and an authentication-subject information registration unit 206 is added.

[0134] The authentication-subject information registration unit 206 is a means for registering the user ID, biometric information, and judgment data of a user (future authentication-subject) in the server device 30. The authentication-subject information registration unit 206 accesses the server device 30 in response to an operation by the user. The authentication-subject information registration unit 206 inputs the user ID, biometric information (e.g., a facial image), and service provision eligibility judgment data (e.g., a negative certificate) of the user to the server device 30.

[0135] The user information notification unit 204 according to the second embodiment transmits a user information notification including a user ID to the authentication terminal 20.

[0136] [Authentication terminal] The processing configuration (processing module) of the authentication terminal 20 according to the second embodiment can be the same as the processing configuration of the authentication terminal 20 according to the first embodiment shown in FIG.

[0137] When the user information processing unit 302 according to the second embodiment receives a user information notification from the terminal 10, the user information processing unit 302 transmits the user ID included in the notification to the server device 30. More specifically, the user information processing unit 302 transmits a request for providing authenticated user information including the user ID to the server device 30.

[0138] The user information processing unit 302 receives a response to the request for authentication-subject information. If the user information processing unit 302 receives a negative response, it does not perform any special processing. If the user information processing unit 302 receives a positive response, it stores the biometric information and determination data included in the response in the matching target database.

[0139] In this way, the user information processing unit 302 according to the second embodiment acquires the biometric information and determination data of the user from the server device 30.

[0140] [Server device] 16 is a diagram showing an example of a processing configuration (processing module) of server device 30 according to the second embodiment. Referring to FIG. 16, server device 30 includes a communication control unit 401, an authentication-subjected user information registration control unit 402, an authentication-subjected user information provision control unit 403, and a storage unit 404.

[0141] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the authentication terminal 20. The communication control unit 401 also transmits data to the authentication terminal 20. The communication control unit 401 hands over data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0142] Authentication-subjected user information registration control unit 402 is a means for controlling the registration of information about the authentication-subjected user. For example, when a user performs a predetermined action using terminal 10 on a homepage provided by server device 30, authentication-subjected user information registration control unit 402 acquires the user ID, biometric information, and judgment data of the user.

[0143] For example, authentication-subjected user information registration control unit 402 displays a GUI such as that shown in Fig. 17 on terminal 10 and acquires the user ID, biometric information (facial image), and judgment data of the user. Authentication-subjected user information registration control unit 402 generates features from the acquired facial image. Authentication-subjected user information registration control unit 402 associates the user ID, the generated features (biometric information), and service provision eligibility judgment data, and stores them in the authentication-subjected user information database (see Fig. 18).

[0144] Authentication-subjected user information provision control unit 403 is a means for processing an authentication-subjected user information provision request from authentication terminal 20. When an authentication-subjected user information provision request is received, authentication-subjected user information provision control unit 403 searches the authentication-subjected user information database using the user ID included in the request as a key, and identifies the corresponding biometric information and judgment data.

[0145] If biometric information and judgment data corresponding to the user ID exist, authentication-subjected user information provision control unit 403 transmits an affirmative response including the biometric information and judgment data to authentication terminal 20. If biometric information and judgment data corresponding to the user ID do not exist, authentication-subjected user information provision control unit 403 transmits a negative response indicating this to authentication terminal 20.

[0146] Storage unit 404 is a means for storing information necessary for the operation of server device 30. An authentication-subject information database is constructed in storage unit 404.

[0147] 19 is a sequence diagram showing an example of the operation of the authentication system according to the second embodiment. The operation of the authentication system according to the second embodiment will be described with reference to FIG.

[0148] When the terminal 10 and the authentication terminal 20 start communication, the terminal 10 transmits a user information notification including a user ID to the authentication terminal 20 (step S01).

[0149] Authentication terminal 20 transmits the user ID included in the user information notification to server device 30. Authentication terminal 20 transmits an authentication-subject information provision request including the user ID to server device 30 (step S02).

[0150] Server device 30 searches the authentication-subjected user information database using the user ID as a key, and identifies the corresponding biometric information and judgment data. Server device 30 transmits the identified biometric information and judgment data to authentication terminal 20 (step S03).

[0151] When the user arrives at the authentication terminal 20, the authentication terminal 20 acquires the user's biometric information (step S04).

[0152] The authentication terminal 20 executes a first verification using the acquired biometric information and the biometric information notified from the server device 30 (biometric information stored in the database of persons to be verified) (step S05).

[0153] If the first verification is successful, the authentication terminal 20 verifies the validity of the judgment data of the user (performs the second verification; step S06).

[0154] The authentication terminal 20 provides a service to the successfully authenticated person while outputting a message based on the first verification result and the second verification result (step S07).

[0155] As described above, in the second embodiment using the server device 30, the biometric information and judgment data required for authentication processing are transmitted to the authentication terminal 20. The authentication terminal 20 executes the first verification and the second verification using the information (biometric information, judgment data) acquired from the server device 30. In the second embodiment as well, the authentication terminal 20 changes its operation depending on the results of the first verification and the second verification, and can provide appropriate information to those who have failed authentication.

[0156] Next, the hardware of each device constituting the authentication system will be described. Fig. 20 is a diagram showing an example of the hardware configuration of authentication terminal 20.

[0157] The authentication terminal 20 can be configured by an information processing device (so-called computer), and has the configuration shown in Fig. 20. For example, the authentication terminal 20 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0158] However, the configuration shown in Fig. 20 is not intended to limit the hardware configuration of the authentication terminal 20. The authentication terminal 20 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the authentication terminal 20 is not intended to be limited to that shown in Fig. 20; for example, the authentication terminal 20 may include multiple processors 311. Furthermore, the authentication terminal 20 may be provided with a camera device for photographing the person to be authenticated, a gate for restricting the passage of users, and the like.

[0159] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0160] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0161] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a keyboard, a mouse, a touch panel, or the like that accepts user operations.

[0162] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0163] The functions of the authentication terminal 20 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the processing modules can be realized by a semiconductor chip.

[0164] The terminal 10 and the server device 30 can also be configured by information processing devices, just like the authentication terminal 20, and their basic hardware configurations are no different from those of the authentication terminal 20, so a description thereof will be omitted.

[0165] The authentication terminal 20 is equipped with a computer, and the functions of the authentication terminal 20 can be realized by causing the computer to execute a program. Also, the authentication terminal 20 executes a control method for the authentication terminal 20 by the program.

[0166] [Variations] The configuration, operation, etc. of the authentication system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0167] In the above embodiment, the authentication terminal 20 is a gate device installed in an airport, and a service is provided to a user who has been successfully authenticated (permitting passage through the gate). However, the authentication terminal 20 may be a terminal installed in a facility other than an airport. For example, the authentication terminal 20 may be a terminal installed at an event venue that permits passage to a user who presents a valid ticket as the determination data. Alternatively, the authentication terminal 20 may be a check-in terminal installed in an airport that provides check-in procedures to a user who presents a valid passport and airline ticket as the determination data. In this way, the authentication terminal 20 may be any device that provides a service based on the determination data.

[0168] In the above embodiment, with reference to Figures 11A and 11B, etc., it has been described that a user who fails the second verification using the determination data is guided through the procedures for receiving the service. Here, as mentioned above, more detailed information than that shown in Figure 11A may be included. For example, taking the acquisition of a negative certificate as an example, the authentication terminal 20 may display information necessary to acquire the certificate, such as the location and time (time zone) to take the test to obtain the negative certificate (see Figure 11B).

[0169] Alternatively, the authentication terminal 20 may cooperate with a medical institution that conducts PCR (Polymerase Chain Reaction) tests and the like, and allow a user who does not have a negative certificate to make a reservation to undergo a PCR test or the like.

[0170] Alternatively, the authentication terminal 20 may work in conjunction with a Departure Control System (DCS) managed by the airline to change the content of the guidance provided based on the boarding schedule of the authentication-failed person, etc. More specifically, the authentication terminal 20 transmits the biometric information of the user (authentication-failed person) to the DCS and acquires the corresponding boarding pass information (e.g., departure time). For users who have ample time before departure, the authentication terminal 20 provides guidance regarding pre-determined regular testing institutions. On the other hand, for users who are short on time before departure, the authentication terminal 20 provides guidance regarding testing institutions that perform tests that require an additional fee but can provide test results quickly (see FIG. 21). In this way, when providing guidance regarding procedures for receiving services to a user who has failed verification using determination data, the authentication terminal 20 may change the content of the guidance provided based on information about the user.

[0171] In the above embodiment, the terminal 10 transmits one piece of determination data to the authentication terminal 20. However, the terminal 10 may transmit multiple pieces of determination data (multiple types of determination data) to the authentication terminal 20. For example, the terminal 10 may transmit a vaccination certificate and a negative certificate to the authentication terminal 20. In this case, the authentication terminal 20 sets the authentication result of the user (person to be authenticated) to success if the acquired multiple pieces of determination data are valid.

[0172] The authentication terminal 20 (user information processing unit 302) may access the database of persons to be verified periodically or at a predetermined timing, and delete entries that have been registered for a predetermined time.

[0173] In the above embodiment, the authentication terminal 20 performs the second verification using the determination data. However, the verification using the determination data (verification of the validity of the determination data) may be performed by a device other than the authentication terminal 20. For example, the authentication terminal 20 may transmit the determination data to an external server and request verification of the validity of the determination data (the external server may perform the second verification). The authentication terminal 20 receives the verification result from the external server and stores it internally before the user arrives at the authentication terminal 20 (before performing the first verification). The authentication terminal 20 performs the first verification when the user arrives at the authentication terminal 20 and determines how to handle the user based on the result of the first verification and the result of the second verification already obtained. In this way, even if the authentication terminal 20 requests an external server to verify the determination data, it changes the response to the user depending on the method for which the verification failed. The authentication (verification using the determination data) may be performed by the external server, and the authentication terminal 20 may receive the verification result and output a message or the like depending on the method for which the verification failed. That is, a population relating to the verification result may be transferred in advance from an external server to the authentication terminal, and the authentication terminal 20 may determine the final authentication result according to the first verification result.

[0174] In the above embodiment, the case where the terminal 10 and the authentication terminal 20 communicate via Bluetooth (registered trademark) has been described. In this case, the authentication terminal 20 may transmit and receive Bluetooth (registered trademark) radio waves using a transceiver that is not limited in its installation location. Specifically, the transceiver may be installed in a location farther than the communication range of Bluetooth (registered trademark), and the authentication terminal 20 may communicate with the terminal 10 using the transceiver.

[0175] In the above embodiment, the authentication terminal 20 performs one-to-N authentication using the biometric information of the user that arrives at the terminal 20 and the biometric information stored in the matching target database. However, the authentication terminal 20 may perform one-to-one authentication using the user's biometric information, assuming that the users arrive at the terminal 20 in the order in which the user information notifications are sent. In this case, the authentication terminal 20 may perform one-to-one authentication using the biometric information acquired when the user arrives at the terminal 20 and the biometric information stored earliest in the matching target database, to confirm the authenticity of the owner of the terminal 10. After performing the authentication process, the authentication terminal 20 deletes the entry used in the authentication process from the matching target database. In this way, the authenticity of the owner of the terminal 10 is confirmed by one-to-one authentication, thereby improving authentication accuracy.

[0176] In the second embodiment, the authentication terminal 20 may not perform biometric authentication (matching process using biometric information), but the server device 30 may perform the matching process. In this case, the authentication terminal 20 acquires the user's biometric information that has arrived at the authentication terminal 20, and transmits the acquired biometric information to the server device 30. The server device 30 transmits the user ID of the user identified by the matching process to the authentication terminal 20. In response to receiving the user ID, the authentication terminal 20 determines that the authenticity of the owner of the terminal 10 has been confirmed.

[0177] The terminal 10 and the authentication terminal 20 may communicate with each other by means other than Bluetooth (registered trademark). For example, the terminal 10 and the authentication terminal 20 may communicate by ZigBee (registered trademark) or the like. Alternatively, the terminal 10 and the authentication terminal 20 may communicate by a standard corresponding to a wireless LAN (Local Area Network).

[0178] In the above embodiment, a case has been described in which the database of persons to be matched is configured inside the authentication terminal 20, but the database may also be constructed in an external database server or the like. That is, some of the functions of the authentication terminal 20 may be implemented in another device. More specifically, it is sufficient that the above-described "authentication unit (authentication means)" and the like are implemented in any of the devices included in the system.

[0179] In the above embodiment, a case has been described in which feature amounts generated from a facial image are transmitted as biometric information from the terminal 10 to the authentication terminal 20. However, a facial image may be transmitted as biometric information from the terminal 10 to the authentication terminal 20. In this case, the authentication terminal 20 may generate feature amounts from the facial image and register them in the database of persons to be matched.

[0180] The form of data transmission and reception between the devices (terminal 10, authentication terminal 20, server device 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Biometric information and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.

[0181] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0182] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0183] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to an authentication system for authenticating a user.

[0184] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. [Appendix 1] a first acquisition unit that acquires, when a distance between the device and a user reaches a first distance, first biometric information of the user and determination data for determining whether or not to provide a service to the user from another device; a second acquisition unit that acquires second biometric information of the user when the distance between the device and the user reaches a second distance; an authentication unit that authenticates the user based on a first verification using the first biometric information and the second biometric information and a second verification using the determination data; a service providing unit that provides a service to a person who has been successfully authenticated if the result of the authentication is successful, and that determines how to handle a person who has failed to be authenticated if the result of the authentication is unsuccessful depending on whether the first verification or the second verification has failed; An authentication terminal comprising: [Appendix 2] 2. The authentication terminal according to claim 1, wherein the first acquisition unit acquires the first biometric information and the judgment data from a terminal carried by the user. [Appendix 3] 3. The authentication terminal according to claim 2, wherein the authentication unit performs a matching process using the first biometric information and the second biometric information as the first verification. [Appendix 4] 4. The authentication terminal according to claim 2, wherein the authentication unit determines the validity of the determination data as the second verification. [Appendix 5] 5. The authentication terminal according to claim 2, wherein, if the first verification fails, the service providing unit notifies a predetermined person of unauthorized use of the terminal by the person who failed the authentication. [Appendix 6] The authentication terminal according to any one of appendices 2 to 5, wherein, if the first verification is successful and the second verification is unsuccessful, the service providing unit provides the unsuccessful authentication person with guidance on the procedures required to receive the service. [Appendix 7] 7. The authentication terminal according to claim 2, wherein the first acquisition unit communicates with the terminal via short-range wireless communication. [Appendix 8] The authentication terminal according to claim 1, wherein the first acquisition unit acquires the first biometric information and the judgment data from a server device that stores the first biometric information and the judgment data of the user. [Appendix 9] The authentication terminal according to any one of Supplementary Notes 1 to 8, wherein the biometric information is a facial image or a feature generated from the facial image. [Appendix 10] A device owned by the user, An authentication terminal; Including, The authentication terminal a first acquisition unit that acquires, when a distance between the device itself and a user reaches a first distance, first biometric information of the user and determination data for determining whether or not to provide a service to the user from the terminal; a second acquisition unit that acquires second biometric information of the user when the distance between the device and the user reaches a second distance; an authentication unit that authenticates the user based on a first verification using the first biometric information and the second biometric information and a second verification using the determination data; a service providing unit that provides a service to a person who has been successfully authenticated if the result of the authentication is successful, and that determines how to handle a person who has failed to be authenticated if the result of the authentication is unsuccessful depending on whether the first verification or the second verification has failed; A system comprising: [Appendix 11] The system described in Appendix 10, wherein when the terminal starts communication with the authentication terminal via short-range wireless communication means, it transmits the first biometric information and the judgment data to the authentication terminal. [Appendix 12] The system described in Appendix 11, wherein the terminal prompts the user to enable the short-range wireless communication means when the distance between the terminal and the authentication terminal reaches a third distance. [Appendix 13] At the authentication terminal, When the distance between the device and the user reaches a first distance, the device acquires, from another device, first biometric information of the user and determination data for determining whether or not to provide a service to the user; When the distance between the device and the user reaches a second distance, second biometric information of the user is acquired; authenticating the user based on a first verification using the first biometric information and the second biometric information and a second verification using the determination data; A control method for an authentication terminal, which provides services to those who have been successfully authenticated if the authentication result is successful, and determines how to handle those who have failed to authenticate depending on whether the first verification or the second verification has failed if the authentication result is unsuccessful. [Appendix 14] The computer installed in the authentication terminal When the distance between the device and a user reaches a first distance, the device acquires, from another device, first biometric information of the user and determination data for determining whether or not to provide a service to the user; a process of acquiring second biometric information of the user when the distance between the device and the user reaches a second distance; a process of authenticating the user based on a first verification using the first biometric information and the second biometric information and a second verification using the determination data; a process of providing a service to a person who has been successfully authenticated if the result of the authentication is successful, and determining how to handle a person who has failed to be authenticated if the result of the authentication is unsuccessful depending on whether the first verification or the second verification has failed; A computer-readable storage medium that stores a program for executing the above.

[0185] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]

[0186] 10 devices 20 Authentication Terminal 30 Server device 100 authentication terminals 101 First Acquisition Section 102 Second Acquisition Section 103 Authentication Department 104 Service Provision Department 201 Communication control unit 202 Electronic wallet control unit 203 Biometric information acquisition unit 204 User information notification department 205 Storage section 206 Authentication Subject Information Registration Unit 301 Communication Control Unit 302 User Information Processing Unit 303 Biometric Information Acquisition Unit 304 Authentication Section 305 Service Provision Department 306 Storage section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface 401 Communication control unit 402 Authentication subject information registration control unit 403 Authenticated person information provision control unit 404 Storage section

Claims

1. A first acquisition unit that acquires first biometric information of a user and determination data for determining whether or not to provide a service to the user from another device; a second acquisition unit that acquires second biometric information of the user by photographing the user using a camera device; an authentication unit that authenticates the user based on a first verification using the first biometric information and the second biometric information and a second verification using the determination data; a service providing unit that provides a service to a person who has been successfully authenticated if the result of the authentication is successful, and that determines how to handle a person who has failed to be authenticated if the result of the authentication is unsuccessful depending on whether the first verification or the second verification has failed; Equipped with The authentication terminal, wherein the service providing unit, if the first verification is successful and the second verification is unsuccessful, provides the unsuccessful authentication person with guidance on a procedure required to receive the service.

2. the first acquisition unit acquires the first biometric information and the determination data from a terminal carried by the user when the distance between the device and the user reaches a first distance; The authentication terminal according to claim 1 , wherein the second acquisition unit acquires the second biometric information of the user when a distance between the authentication terminal and the user reaches a second distance.

3. The authentication terminal according to claim 2 , wherein the authentication unit performs a matching process using the first biometric information and the second biometric information as the first verification.

4. The authentication terminal according to claim 2 , wherein the authentication unit determines validity of the determination data as the second verification.

5. The authentication terminal according to claim 2 , wherein the service providing unit notifies a predetermined person of unauthorized use of the terminal by the person who failed the authentication if the first verification fails.

6. The authentication terminal according to claim 2 , wherein the first acquisition unit communicates with the terminal by short-range wireless communication.

7. The authentication terminal according to claim 1 , wherein the first acquisition unit acquires the first biometric information and the determination data from a server device that stores the first biometric information and the determination data of the user.

8. The authentication terminal according to claim 1 , wherein the biometric information is a facial image or a feature amount generated from the facial image.

9. A device owned by the user, An authentication terminal; Including, The authentication terminal a first acquisition unit that acquires, from the terminal, first biometric information of the user and determination data for determining whether or not to provide a service to the user; a second acquisition unit that acquires second biometric information of the user by photographing the user using a camera device; an authentication unit that authenticates the user based on a first verification using the first biometric information and the second biometric information and a second verification using the determination data; a service providing unit that provides a service to a person who has been successfully authenticated if the result of the authentication is successful, and that determines how to handle a person who has failed to be authenticated if the result of the authentication is unsuccessful depending on whether the first verification or the second verification has failed; Equipped with The system further comprises: if the first verification is successful and the second verification is unsuccessful, the service providing unit provides the unsuccessful authentication person with guidance on the procedures required to receive the service.

10. The system according to claim 9 , wherein the terminal transmits the first biometric information and the determination data to the authentication terminal when the terminal starts communication with the authentication terminal using a short-range wireless communication standard.

11. The system according to claim 10 , wherein the terminal prompts the user to enable the short-range wireless communication standard when the distance between the terminal and the authentication terminal reaches a predetermined distance.

12. At the authentication terminal, Acquire first biometric information of the user and determination data for determining whether or not to provide a service to the user from another device; acquiring second biometric information of the user by photographing the user using a camera device; authenticating the user based on a first verification using the first biometric information and the second biometric information and a second verification using the determination data; A control method for an authentication terminal, the method comprising: providing a service to a person who has been successfully authenticated if the result of the authentication is successful; and determining how to handle a person who has failed to authenticate if the result of the authentication is unsuccessful depending on whether the first verification or the second verification has failed; a control method for an authentication terminal, which, if the first verification is successful and the second verification is unsuccessful, provides the unsuccessful authentication user with information about a procedure required to receive the service;

13. The computer installed in the authentication terminal A process of acquiring first biometric information of a user and determination data for determining whether or not to provide a service to the user from another device; a process of acquiring second biometric information of the user by photographing the user using a camera device; a process of authenticating the user based on a first verification using the first biometric information and the second biometric information and a second verification using the determination data; a process of providing a service to a person who has been successfully authenticated if the result of the authentication is successful, and determining how to handle a person who has failed to be authenticated if the result of the authentication is unsuccessful depending on whether the first verification or the second verification has failed; A program for executing The computer, a program for executing a process of providing the unsuccessful authentication user with guidance on the procedures required to receive the service when the first verification is successful and the second verification is unsuccessful;

Citation Information

Patent Citations

  • Automatic gate system

    JP2003331323A

  • Electronic certificate creating apparatus, method, and program, and electronic certificate verifying apparatus and program

    JP2005252621A

  • Information processing system, terminal device, image forming apparatus, and information processing program

    JP2016042668A

  • Identity verification program, identity verification method and information processing apparatus

    JP2020064541A

  • Authentication device, authentication system, authentication method and program

    WO2016035402A1