Management device, management method, and management program

The management device ensures accurate and efficient face image registration by determining image quality for multiple facial recognition engines, addressing the challenges of failed registrations and user burden in existing technologies.

JP7775752B2Active Publication Date: 2025-11-26TOPPAN HOLDINGS INC
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2022037822
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-11
Publication Date
2025-11-26
Estimated Expiration
2042-03-11

AI Technical Summary

Technical Problem

Existing facial recognition technologies face challenges in accurately registering face images due to quality issues, leading to failed registrations and increased user burden, particularly when images are processed to fit specific mediums, which can render them unusable for recognition.

Method used

A management device that receives and determines the quality of face images for multiple facial recognition engines, registering only if the image meets the criteria of all engines, thereby ensuring accurate and efficient registration.

Benefits of technology

The solution enhances authentication accuracy and reduces user burden by ensuring high-quality image registration for multiple engines, preventing failed registrations and optimizing the registration process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007775752000001
    Figure 0007775752000001
  • Figure 0007775752000002
    Figure 0007775752000002
  • Figure 0007775752000003
    Figure 0007775752000003
Patent Text Reader

Abstract

To provide a management apparatus, a management method, and a management program, configured to accurately register a face image with less burden on a user.SOLUTION: A management apparatus according to the present disclosure includes: a receiving unit which receives, from a user, a registration image which is a basis of ground truth data to be used for collation by each of multiple face authentication engines, for executing authentication processing using the face authentication engines; a quality determination unit which determines whether the registration image has quality equivalent to the ground truth data for authentication processing through the face authentication engines, for each of the face authentication engines; and a registration unit which registers, on the basis of results determined by the quality determination unit, the registration image when a determination is made that the registration image has quality equivalent to the ground truth data for authentication processing, for all the face authentication engines.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a management device, a management method, and a management program for managing authentication processing. [Background technology]

[0002] Facial recognition processing is known as a means for identity verification. In facial recognition processing, a facial image of a user is registered in advance, and identity verification is performed by comparing the facial image acquired during authentication with the registered image.

[0003] In facial recognition processing, a user registers a facial image beforehand using a device such as a smartphone. As a technology related to the registration of a facial photo, a technology is known that supports efficient registration by determining the suitability of the facial image and then processing the facial photo to match the medium to be registered (for example, Patent Document 1). Also, a technology is known that improves authentication accuracy by using multiple facial recognition engines in facial recognition processing (for example, Patent Document 2). [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-81141 [Patent Document 2] Patent No. 6839313 Summary of the Invention [Problem to be solved by the invention]

[0005] According to the technology of Patent Document 1, it is possible to efficiently register facial images to be used in facial image-bearing media.

[0006] However, the technology of Patent Document 1 may not be suitable for registering face images to be used in face recognition processing. In face recognition processing, authentication is performed based on features extracted from a face image. Therefore, when registering a face image, it is necessary to determine whether the image is one from which features can be extracted (for example, whether the face is included in an appropriate range within the entire image, whether the brightness of the image is appropriate, etc.). Therefore, if the face image is processed, such as by cropping, to fit the medium after determining its suitability, depending on the degree of processing, the processed image may become unusable for face recognition processing, and registration may fail. Retrying registration due to a failed registration may increase the load on the server and burden the user.

[0007] Therefore, the present disclosure proposes a management device, a management method, and a management program that can accurately register face images with less burden on the user. [Means for solving the problem]

[0008] In order to solve the above problem, a management device of one embodiment according to the present disclosure includes: a reception unit that receives from a user a registration image that serves as the source of correct answer data used for matching by each of a plurality of facial recognition engines in order to execute authentication processing by the plurality of facial recognition engines; a quality determination unit that determines for each of the plurality of facial recognition engines whether the registration image is of a quality that allows it to be used as correct answer data for the authentication processing of the plurality of facial recognition engines; and a registration unit that registers the registration image when it is determined, based on the determination result by the quality determination unit, that the registration image is of a quality that allows it to be used as correct answer data for the authentication processing for all of the plurality of facial recognition engines. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 10 is a diagram illustrating a flow of a registration process according to the embodiment. [Figure 2] FIG. 2 is a diagram schematically illustrating a flow of face authentication processing according to the embodiment. [Figure 3] FIG. 1 is a diagram (1) for explaining a registration process according to an embodiment. [Figure 4] FIG. 10 is a diagram (2) for explaining the registration process according to the embodiment. [Figure 5] FIG. 10 is a sequence diagram showing the procedure of a registration process according to the embodiment. [Figure 6] FIG. 10 is a sequence diagram showing a procedure of face authentication processing according to the embodiment. [Figure 7] 10 is a flowchart illustrating a determination procedure of face authentication processing according to the embodiment. [Figure 8] FIG. 2 is a diagram illustrating an example of the configuration of a management device according to the embodiment. [Figure 9] FIG. 4 is a diagram illustrating an example of a user information storage unit according to the embodiment. [Figure 10] FIG. 4 is a diagram illustrating an example of a quality check item storage unit according to the embodiment. [Figure 11] FIG. 4 is a diagram illustrating an example of a face photo storage unit according to the embodiment. [Figure 12] FIG. 2 is a diagram illustrating an example of an external service information storage unit according to the embodiment. [Figure 13] FIG. 2 is a hardware configuration diagram illustrating an example of a computer that realizes the functions of a management device. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the following embodiments, the same components are designated by the same reference numerals, and redundant description will be omitted.

[0011] (1. Embodiment) (1-1. Example of management process according to embodiment) 1 and 2 schematically show the flow of management processing according to the embodiment. The management processing according to the embodiment is executed by a management device 100 included in a management system 1 shown in Fig. 1. As shown in Fig. 1, the management system 1 includes the management device 100, a user terminal 20, and a face authentication provider 50.

[0012] The management device 100 is an information processing device that executes management processing according to the embodiment. For example, the management device 100 is a cloud server or the like that can communicate with the user terminal 20 and the face authentication provider 50 via a network.

[0013] The user terminal 20 is an information processing terminal used by the user 10. For example, the user terminal 20 is a smartphone, a tablet terminal, a PC (Personal Computer), etc. The user terminal 20 according to the embodiment is equipped with a camera and is capable of capturing a facial image of the user 10.

[0014] The face authentication provider 50 is a general term for businesses that provide face authentication engines for executing face authentication processing. The face authentication provider 50 includes, for example, a first provider that provides a first face authentication engine 60, a second provider that provides a second face authentication engine 70, and a third provider that provides a third face authentication engine 80.

[0015] The first provider, second provider, and third provider are businesses that provide different facial recognition engines. The facial recognition engines provided by each provider have different characteristics in various aspects, such as the method of detecting the area of ​​a face in an image, extracting facial features, and matching the features. In other words, each facial recognition engine excels at different image features (image brightness, the proportion of the area of ​​the image that the face occupies, and features such as the skin color and facial features of the user to be authenticated). In the following description, when there is no need to distinguish between the first provider, second provider, and third provider, they may be collectively referred to as facial recognition provider 50.

[0016] The management device 100 according to the embodiment increases the accuracy and reliability of authentication by registering and matching with these multiple face recognition engines when the user 10 registers a face image or when performing authentication. In other words, the management device 100 serves as a platform for executing authentication processing using multiple face recognition engines.

[0017] Specifically, in order to execute authentication processes by the multiple face recognition engines, the management device 100 receives from the user 10 a face image that serves as the basis for supervised data used for matching by each of the multiple face recognition engines. The management device 100 also provides a processing means for the user 10 to process the received face image. The management device 100 then determines whether the processed image, which is the processed face image, is of a quality that allows it to be used as supervised data for the authentication processes of the multiple face recognition engines.

[0018] In this way, the management device 100 uses an image processed by the user 10 to determine whether it can be used with each face recognition engine, thereby preventing the user 10 from having to redo the process. The management device 100 may also verify the quality of the face image for each of multiple face recognition engines, and register the face image only if it is verified as having usable quality for all of the face recognition engines used for authentication. This allows the management device 100 to perform highly accurate authentication using multiple face recognition engines, while smoothly proceeding with the registration of face images, which can often be cumbersome.

[0019] Regarding such management processing, first, a flow of processing for registering face images to a plurality of face recognition engines will be described with reference to Fig. 1. Fig. 1 is a diagram schematically showing the flow of registration processing according to an embodiment.

[0020] 1, a user 10 accesses the management device 100 using a user terminal 20 and requests registration of a face image to be used in face authentication (step S1). For example, the user 10 requests registration of a face image via a website provided by the management device 100.

[0021] Upon receiving the request, the management device 100 provides the user terminal 20 with a web page or the like for facial image registration. The user 10 takes a picture of himself / herself using a camera provided in the user terminal 20 and transmits the facial image to be registered to the management device 100. Details of facial image registration using a camera will be described later with reference to FIG. 3.

[0022] The management device 100 stores the facial image acquired from the user 10 in a storage unit as facial photograph data 30. At this time, the management device 100 may determine whether the facial image satisfies the quality required by each facial recognition engine, and may store the facial image as facial photograph data 30 only if it is determined that the quality is satisfied. Furthermore, if the management device 100 determines that the facial image does not satisfy the quality, it may request the user 10 to retake the photograph or to adjust the facial image by processing it.

[0023] If the face image satisfies the quality of each face recognition engine and is eligible for registration, the management device 100 notifies the user 10 of this (step S2).

[0024] When the management device 100 acquires the facial photo data 30, it registers the facial photo data 30 in each face recognition engine. For example, the management device 100 transmits the facial photo data 30 to a first provider having a first face recognition engine 60, and requests registration to enable the first face recognition engine 60 to be used for facial recognition of the user 10 (step S3).

[0025] The first provider extracts features from the acquired facial photo data 30 through a feature extraction process executed by the first face recognition engine 60 and stores the features in the feature storage unit 62. For example, the first face recognition engine 60 extracts facial features of the user 10 as parameters by hashing the facial image included in the facial photo data 30, and stores the extracted values ​​as features in the feature storage unit 62. After this, the first provider may discard the facial photo data 30 itself. As a result, the first provider does not retain personal information such as the facial photo data 30, but retains only the features, thereby reducing resources and labor required for data management.

[0026] Similarly, the management device 100 transmits the facial photograph data 30 to the second provider and requests registration to enable the second face recognition engine 70 to be used for facial recognition of the user 10 (step S4). The second provider, like the first provider, extracts features from the acquired facial photograph data 30 and stores them in the feature storage unit 72.

[0027] Similarly, the management device 100 transmits the facial photograph data 30 to the third provider and requests registration to enable the third face recognition engine 80 to be used for facial recognition of the user 10 (step S5). The third provider, like the first and second providers, extracts features from the acquired facial photograph data 30 and stores them in the feature storage unit 82.

[0028] The management device 100 registers the facial photo data 30 of the user 10 for the number of facial recognition engines to be used. When registration is complete, the management device 100 associates information such as the user 10, the registered facial photo data 30, and the registered facial recognition engine, and stores the information in a storage unit.

[0029] Next, the flow of confirming the identity of a user 10 using face authentication (matching process) will be described with reference to Fig. 2. Fig. 2 is a diagram schematically showing the flow of face authentication process according to an embodiment. The management system 1 shown in Fig. 2 further includes an authentication terminal 40 and a service provider 200.

[0030] The authentication terminal 40 is an information processing terminal installed in a place where identity verification is required. The authentication terminal 40 can communicate with the management device 100 via a network, and for example, transmits an image captured by a camera provided in the authentication terminal 40 to the management device 100. The authentication terminal 40 then obtains the authentication result from the management device 100 and notifies the person who requested authentication whether their identity has been verified (whether the face image matches a registered face image). Furthermore, the authentication terminal 40 determines whether to provide a predetermined service based on the matching result.

[0031] Service provider 200 is a business that provides various services. For example, service provider 200 manages authentication terminal 40 and provides various services to users whose identities have been verified. In this disclosure, a service is not limited to a commercial service, but is a general term for any mechanism or system that user 10 intends to use, such as a factory entrance / exit control gate. For example, services include permission to enter and exit a specific facility, attendance management, and settlement of financial products. Service provider 200 has user information 212, which is information about users who use the service, and business data 214, which stores the type and content of the service.

[0032] 2, when user 10 attempts to use a service provided by service provider 200, user 10 photographs himself / herself using authentication terminal 40 and attempts facial authentication. For example, when user 10 enters a facility where admission is controlled, user 10 requests authentication processing from authentication terminal 40 to verify his / her identity.

[0033] When the authentication terminal 40 photographs the user 10, it transmits the photographed facial image for authentication to the management device 100 (step S11). The management device 100 transmits the acquired facial image for authentication to each face authentication provider.

[0034] For example, the management device 100 transmits the authentication-use facial image to the first provider and causes the first face recognition engine 60 to perform face recognition based on the authentication-use facial image (step S12). Specifically, the first face recognition engine 60 compares the feature amounts of the registered user 10 with the feature amounts extracted from the authentication-use facial image. The first face recognition engine 60 then transmits a result (matching result) indicating the comparison result between the feature amounts of the user 10 and the feature amounts extracted from the authentication-use facial image to the management device 100. If the similarity between the feature amounts acquired from the first face recognition engine 60 is higher than a predetermined value, the management device 100 determines that matching between the pre-registered user 10 and the person (user 10 in this example) in the authentication-use facial image has been successful. On the other hand, if the similarity is lower than the predetermined value, the management device 100 determines that matching between the pre-registered user 10 and the person in the authentication-use facial image has not been achieved and that the identity of the person cannot be confirmed.

[0035] When face authentication by the first face recognition engine 60 is completed, the management device 100 stores the matching result in the authentication log 32. Note that the first face recognition engine 60 may perform matching after recognizing that the person to be matched is the user 10 using an ID card or the like, or may perform matching between an unspecified number of users registered in advance and the authentication face image. In the latter case, it is expected that the first face recognition engine 60 will extract, as a matching target, a user 10 who is determined to have a higher similarity than other targets as a result of the matching.

[0036] Next, the management device 100 transmits the authentication facial image to the second provider and causes the second face recognition engine 70 to perform face recognition based on the authentication facial image (step S13). When the face recognition is completed, the second face recognition engine 70 transmits the matching result to the management device 100. The management device 100 determines whether matching of the user 10 is successful or not based on the similarity between the feature amounts acquired as the matching result by the second face recognition engine 70, and stores the result in the authentication log 32. Similarly, the management device 100 transmits the authentication facial image to the third provider and causes the third face recognition engine 80 to perform face recognition based on the authentication facial image (step S14). When the face recognition is completed, the third face recognition engine 80 transmits the matching result to the management device 100. The management device 100 determines whether matching of the user 10 is successful or not based on the similarity between the feature amounts acquired as the matching result by the third face recognition engine 80, and stores the result in the authentication log 32.

[0037] Then, the management device 100 transmits the authentication result for the user 10 to the authentication terminal 40 based on the matching results from the multiple face recognition engines (step S15). In other words, the management device 100 transmits to the authentication terminal 40 the result of determining whether or not the service requested by the user 10 may be provided to the user 10.

[0038] At this time, the management device 100 may refer to the external service affiliation information 34 to determine the authentication result for the user 10. For example, the external service affiliation information 34 includes the security level required by the external service. That is, the management device 100 compares the security level required by the service provider 200 with the matching results from the multiple face recognition engines, and then transmits the authentication result for the user 10 to the authentication terminal 40 (step S15).

[0039] In terms of service operation, various security levels can be set for the service. For example, when using the authentication process according to the embodiment for daily attendance management, if the authentication strength required is too high and authentication errors (situations in which it is difficult to confirm the identity of a user attempting authentication) occur frequently, usability may be reduced even if security is high. On the other hand, when using the authentication process according to the embodiment for payment processing at a financial institution, it is desirable to set the authentication strength extremely high to prevent fraudulent use.

[0040] For this reason, the management device 100 manages information such as the authentication strength required for each service. For example, if the service has low authentication strength, the management device 100 may permit provision of the service to the user 10 if at least one of the multiple face recognition engines has successfully authenticated the user. Alternatively, if the service has high authentication strength, the management device 100 may not permit provision of the service to the user 10 unless all of the multiple face recognition engines have successfully authenticated the user.

[0041] The management device 100 acquires information on the authentication strength and the like from the service provider 200. Then, the management device 100 transmits to the service provider 200 a determination result as to whether or not the service is available based on the result of matching the authentication face image with the user 10 (step S16). The service provider 200 provides a predetermined service to the user 10 whose identity has been confirmed based on the determination result by the management device 100 (step S17). As an example, the service provider 200 notifies the user 10 that the identity of the user 10 has been confirmed via the authentication terminal 40, and activates a gate opening / closing device to permit entry of the user 10. Note that provision of such a service may be performed by the management device 100 entrusted by the service provider 200.

[0042] As shown in FIG. 2 , the management device 100 determines whether to permit a request from the user 10 based on the authentication results of each of the multiple face recognition engines that authenticated the face image. In other words, by using multiple face recognition engines, the management device 100 can improve the accuracy of identity authentication and flexibly configure services involving authentication according to the authentication strength. In the above example, the management device 100 acquires the similarity determined by each face recognition engine and determines whether authentication of the user 10 has been successful by evaluating the acquired similarity. However, the success or failure of face recognition may be determined by each face recognition engine, rather than by the management device 100. In this case, each face recognition engine holds a reference value for the similarity. Each face recognition engine then compares the registered feature values ​​of the user 10 with the feature values ​​extracted from the authentication face image. If the similarity between the compared feature values ​​is higher than a predetermined value, the engine determines that matching of the user 10 has been successful and transmits the determination result to the management device 100. In other words, the entity that performs the success or failure of face recognition may be either the management device 100 or each face recognition engine.

[0043] Next, the registration of a face image according to the embodiment will be described in detail with reference to Fig. 3 and Fig. 4. Fig. 3 is a diagram (1) for explaining the registration process according to the embodiment.

[0044] The management device 100 provides a predetermined registration page to the user 10 who wishes to register a facial image, and accepts the registration request. Screen 300 shown in Fig. 3 shows a dedicated page for facial image registration, displayed on the user terminal 20.

[0045] On screen 300, user 10 sets an ID and password for registration and proceeds with the facial image registration process. When user 10 inputs the ID and password, screen 300 transitions to screen 302 (step S21).

[0046] Screen 302 includes a preview image 304 to be captured by a camera provided on user terminal 20. Management device 100 displays guide 306 on preview image 304. Guide 306 indicates the desired area for a face to occupy in the captured image. Because face recognition processing includes a step in which a face recognition engine detects a face from an image, it is desirable that all parts that make up the face are included in the image. For this reason, management device 100 displays guide 306, such as a guide for the area that the face should occupy and lines that serve as a guide for user 10 to center their face in the image, to encourage user 10 to take an appropriate photograph.

[0047] For example, the user 10 takes a picture of himself / herself using a camera provided inside (on the screen side of) the user terminal 20, adjusts the image while looking at the preview image 304 so that his / her face fits within the guide 306, and then presses the capture button 308. When the user 10 takes a picture in accordance with this operation, the management device 100 can acquire the face image for registration via the user terminal 20.

[0048] When the image capture is completed, screen 302 transitions to screen 310 (step S22). At this stage, management device 100 may provide user 10 with a processing means for processing the captured image. Specifically, management device 100 provides a trimming tool or the like for removing unnecessary portions of the captured image.

[0049] For example, if the user 10 intends to use a captured image as a passport photo with a specified size, the user 10 can crop the captured image to the specified size. Furthermore, the trimming tool also allows the user 10 to move the captured image. Therefore, if the user 10's face is not within the circle of the guide 306, the user 10 can shift the entire image to adjust the face so that it is within the circle of the guide 306. The user 10 may also zoom in or out on the image by pinching in or out, adjusting the face to an appropriate size within the circle of the guide 306. The management device 100 may also automatically perform the trimming process. For example, the management device 100 detects the user 10's face through face detection processing and automatically adjusts the position of the detected face so that the coordinates of the detected face fit within the circle of the guide 306. The management device 100 also automatically adjusts the size of the detected face so that it fits within the circle of the guide 306. Furthermore, the management device 100 may remove any unnecessary parts (such as the background) other than the detected face. In this way, the management device 100 automatically performs trimming, so that the user 10 can automatically obtain an image suitable for registration by simply taking an image including the user's face. This allows the management device 100 to reduce the burden on the user 10 of face registration.

[0050] Furthermore, the management device 100 may provide other processing means. This will be described with reference to Fig. 4. Fig. 4 is a diagram (2) for explaining the registration process according to the embodiment.

[0051] When user 10 finishes trimming, management device 100 transitions screen 310 of FIG. 3 to screen 320 shown in FIG. 4. On screen 320, user 10 can adjust the brightness of the entire image. For example, user 10 can adjust the overall brightness to be brighter or darker by operating brightness adjustment bar 322. Furthermore, when user 10 presses automatic brightness adjustment button 324, management device 100 may automatically adjust the brightness of the current image to a brightness that can be registered in the face recognition engine, by referring to the brightness of the current image and a reference value of brightness required by the face recognition engine. This allows user 10 to adjust the brightness of the image to a brightness that can be registered without complex steps.

[0052] When user 10 finishes adjusting the brightness, management device 100 transitions screen 320 to screen 326 (step S31). On screen 326, user 10 can select the background of the image. For example, if user 10 wants to delete an unnecessary background that is included in the captured image, user 10 can change the captured image to processed image 328 in which the background has been changed to a solid white color, for example, by pressing background selection button 330. Alternatively, if user 10 intends to use the captured image as an identification photo with a specified background, user 10 can change the background to a specified background (for example, a solid light blue color).

[0053] When the user 10 has finished adjusting the background, the management device 100 transitions the screen 326 to a screen 332 (step S32). At this stage, the management device 100 determines the quality of the processed image, which is the captured image after processing.

[0054] As will be described in detail later, the management device 100 determines for each face recognition engine whether the processed image satisfies the criteria that each face recognition engine requires for a registered image. If the management device 100 determines that the processed image satisfies the criteria for registration requests from all face recognition engines, it displays a determination result 336 indicating that the criteria are met. After checking the determination result 336, if the user 10 wishes to register this processed image, the user presses a save button 334. When the user 10 presses the save button 334, the management device 100 stores this processed image in a storage unit as a registration image to be used for registration.

[0055] If the processed image does not satisfy the criteria, the management device 100 transitions the screen 326 to a screen 338. On the screen 338, the management device 100 displays a determination result 340 indicating that the processed image does not satisfy the criteria of the registration request of any of the face recognition engines and cannot be registered. As shown in FIG. 4, the management device 100 may display the content of the criteria that the processed image did not satisfy in the determination result 340 based on the quality determination result. This allows the user 10 to obtain information on what points to pay attention to when creating a new processed image when redoing shooting or editing.

[0056] When the management device 100 saves the processed image in the memory unit as a registration image to be used for registration, it transitions the screen 332 to a screen 342, displays a display 344 indicating that the registration of the facial image is complete, and notifies the user 10 that the registration is complete (step S33).

[0057] In this way, the management device 100 determines the quality of the image based on the processed image, which determines whether or not it is suitable for registration processing in the face recognition engine, and therefore can prevent situations from occurring that would cause inconvenience to the user 10, such as cropping being performed after the quality determination, which would change the determination result. Furthermore, the management device 100 can perform processing such as cropping and quality determination processing together on the server-side platform, making it possible to acquire high-quality face images, which can lead to improved accuracy in feature extraction in the subsequent stage.

[0058] (1-2. Procedure of management process according to embodiment) Next, the procedure of the management process according to the embodiment will be described with reference to Fig. 5 to Fig. 7. First, the flow of the registration process will be described with reference to Fig. 5. Fig. 5 is a sequence diagram showing the procedure of the registration process according to the embodiment.

[0059] 5, the user 10 applies for registration of a facial image via a website or the like provided by the management device 100 (step S40). Next, the user 10 takes a photograph of the facial image to be applied for. If the user 10 has a previously taken image, the user 10 may select the image as the image to be used for registration (step S41).

[0060] When the user 10 takes a photograph or selects an image, the facial image is transmitted to the management device 100 (step S42). The management device 100 accepts the facial image transmitted from the user 10 (step S43).

[0061] Thereafter, the user 10 performs a series of processes on the facial image using the processing means provided by the management device 100. For example, the user 10 performs a trimming operation to cut out the facial portion (step S44). The management device 100 performs the trimming process on the facial image in accordance with the user's operation (step S45).

[0062] Furthermore, the user 10 adjusts the brightness of the facial image using processing means provided by the management device 100 (step S46). The management device 100 adjusts the brightness of the facial image, for example, by brightening or darkening it, in accordance with the user's operation (step S47).

[0063] Furthermore, the user 10 changes the background of the facial image using processing means provided by the management device 100 (step S48). The management device 100 changes the background of the facial image in accordance with the user's operation (step S49).

[0064] When the user 10 finishes processing the facial image and generates the processed image, the user 10 sends a quality check request for the processed image to the management device 100 (step S50). When the quality check request is sent from the user 10, the management device 100 sends the processed image to the face authentication provider 50 (step S51).

[0065] The face authentication provider 50 performs a quality check to determine whether the processed image can be used for authentication processing in the face authentication engine (step S52). This process is performed for each face authentication engine of each provider. The face authentication provider 50 transmits the result of the quality check to the management device 100 (step S53).

[0066] The management device 100 refers to the quality check results from the multiple face recognition engines and determines whether there are any problems with all the results (step S54). If it is determined that there is a quality problem with any of the face recognition engines (step S54; No), the management device 100 notifies the user 10 that registration is NG and the reason for this, as shown on screen 338 in FIG. 4 (step S55).

[0067] On the other hand, if it is determined that there is no problem with the quality in all face recognition engines (step S54; Yes), the management device 100 notifies the user that the registration judgment is OK, as shown on screen 332 in FIG. 4 (step S56).

[0068] After checking the notified result, the user 10 requests the management device 100 to register the authentication face image by, for example, pressing the save button 334 displayed on the screen 332 (step S57).

[0069] When the management device 100 receives a registration request from the user 10, it registers the facial image whose quality has been judged as a facial image for authentication (step S58). Then, the management device 100 transmits the registered facial image for authentication to each facial authentication provider 50 (step S59). The facial authentication provider 50 reads the facial image for authentication into a facial authentication engine, extracts features, and then associates the features with a user ID and registers them (step S60). Thereafter, the facial authentication provider 50 may discard the raw data of the acquired facial image for registration.

[0070] Next, the procedure of the authentication process according to the embodiment will be described with reference to Fig. 6. Fig. 6 is a sequence diagram showing the procedure of the face authentication process according to the embodiment.

[0071] 6, the authentication terminal 40 photographs the user 10 requesting face authentication and acquires a face image (step S70). The authentication terminal 40 transmits the acquired face image to the management device 100 (step S71).

[0072] When the management device 100 acquires the face image, it transmits the acquired face image to the first face recognition engine 60 (step S72). The first face recognition engine 60 compares the acquired face image with a registered face image and executes face recognition processing (step S73). The management device 100 acquires the comparison result (first comparison result) by the first face recognition engine 60 (step S74).

[0073] Next, the management device 100 transmits the facial image acquired in step S72 to the second face recognition engine 70 (step S75). The second face recognition engine 70 compares the acquired facial image with a registered face image and executes face recognition processing (step S76). The management device 100 acquires the comparison result (second comparison result) by the second face recognition engine 70 (step S77).

[0074] The management device 100 similarly transmits the facial image to all face recognition engines in which the authentication facial image is registered, and obtains all matching results (step S80). That is, the management device 100 similarly transmits the facial image to the third face recognition engine 80 (not shown) and other registered face recognition engines, and obtains matching results.

[0075] The management device 100 then judges the matching result (step S81). As described above, the success or failure of authentication by each face recognition engine is determined based on whether the similarity between the feature amounts transmitted from the face recognition engine exceeds a predetermined similarity. Details of the judgment process for determining whether or not to allow the user 10 to use the service based on multiple authentication judgments will be described later with reference to FIG. 7. After this judgment, the management device 100 transmits the judgment result to the authentication terminal 40 (step S82). The authentication terminal 40 displays the result transmitted from the management device 100 on a screen or the like (step S83).

[0076] Next, a determination procedure of the face authentication processing according to the embodiment will be described with reference to Fig. 7. Fig. 7 is a flowchart showing the determination procedure of the face authentication processing according to the embodiment.

[0077] 7, the management device 100 identifies a service that the user intends to use (step S101). For example, the management device 100 identifies the service that the user intends to use based on external service collaboration information linked to the authentication terminal 40 or information on the service provider.

[0078] Then, the management device 100 refers to the criteria set for the service that the user is going to use. For example, the management device 100 refers to a criterion that the use of the service is not permitted unless the matching results are OK in all face recognition engines based on the authentication strength of the service, or a criterion that the use of the service is permitted if the matching result is OK in any one face recognition engine (step S102).

[0079] The management device 100 then determines whether the matching results obtained from the multiple face recognition engines satisfy the service's criteria (step S103). If the service's criteria are satisfied (step S103; Yes), the management device 100 determines that the face recognition is successful (step S104). In other words, the management device 100 determines that the authenticated user should be permitted to use the service. On the other hand, if the service's criteria are not satisfied (step S103; No), the management device 100 determines that the face recognition is a failure (step S105). In other words, the management device 100 determines that the authenticated user should not be permitted to use the service.

[0080] (1-3. Configuration of management device according to embodiment) Next, a configuration of the management device 100 that executes the management process according to the embodiment will be described. Fig. 8 is a diagram showing an example of the configuration of the management device 100 according to the embodiment.

[0081] 8, the management device 100 includes a communication unit 110, a storage unit 120, and a control unit 130. The management device 100 may also include an input unit (e.g., a keyboard, a mouse, etc.) that accepts various operations from an administrator who manages the management device 100, and a display unit (e.g., a liquid crystal display, etc.) that displays various information.

[0082] The communication unit 110 is realized by, for example, a network interface card (NIC) or a network interface controller. The communication unit 110 is connected to a network N (for example, the Internet) by wire or wirelessly, and transmits and receives information to and from the user terminal 20, the authentication terminal 40, the face authentication provider 50, and the like via the network N. For example, the communication unit 110 may transmit and receive information using any communication standard or communication technology, such as Wi-Fi (registered trademark), Bluetooth, a subscriber identity module (SIM), or low power wide area (LPWA).

[0083] The storage unit 120 is realized by, for example, a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk. The storage unit 120 has a user information storage unit 121, a quality check item storage unit 122, a facial photo storage unit 123, an authentication log storage unit 124, and an external service information storage unit 125.

[0084] Each storage unit will be described below in order using Figures 9 to 12. In the examples shown in Figures 9 to 12, information stored in storage unit 120 may be conceptually shown as "A01", but in reality, each piece of information described below is stored in storage unit 120.

[0085] The user information storage unit 121 stores information about users who use face authentication. FIG. 9 shows an example of information stored in the user information storage unit 121. FIG. 9 is a diagram showing an example of the user information storage unit 121 according to the embodiment. In the example shown in FIG. 9, the user information storage unit 121 has items such as "user ID," "login information," "face photo registration," and "external service information."

[0086] "User ID" indicates identification information that identifies the user. "Login information" indicates login information required for facial photo registration, such as a password linked to the user ID. "Facial photo registration" indicates whether the user has registered a facial photo. "External service information" indicates information about the external services used by the user.

[0087] The quality check item storage unit 122 stores information about quality check items for each face recognition engine. Fig. 10 is a diagram showing an example of the quality check item storage unit 122 according to the embodiment. In the example shown in Fig. 10, the quality check item storage unit 122 has items such as "check item," "first face recognition engine," "second face recognition engine," and "third face recognition engine."

[0088] The quality check items shown in FIG. 10 indicate the quality check items that each face recognition engine uses to check the quality of a face image and output a result of whether registration is OK or NG. The example shown in FIG. 10 shows that the first face recognition engine determines the horizontal, vertical, and tilt of the face angle in the image and determines whether they fall within predetermined standards. In other words, the first face recognition engine requires that the face in the image be facing accurately forward for registration, and this face angle is used as a quality check item. On the other hand, the example shown in FIG. 10 shows that the third face recognition engine checks only tilt, regardless of the horizontal or vertical direction of the face angle in the image. As such, each face recognition engine excels at different facial angles and features, which contribute to different authentication results. When the management device 100 receives a registration NG determination from the first face recognition engine, it acquires the check items that were failed. The management device 100 can list the acquired information as, for example, the determination result 340 shown in FIG. 4, and notify the user of the items in which the processed image to be registered was inappropriate.

[0089] The quality check items shown in FIG. 10 are just an example, and the management device 100 may store information relating to various quality check items other than the example shown in FIG.

[0090] The face photo storage unit 123 stores face photo data including a face image used in face authentication. Fig. 11 is a diagram showing an example of the face photo storage unit 123 according to the embodiment. In the example shown in Fig. 11, the face photo storage unit 123 has items such as "user ID," "registered face photo data," "for authentication," and "for ID photo."

[0091] "User ID" indicates identification information for identifying a user. "Registered facial photo data" indicates facial photo data registered by a user. "For authentication" indicates facial photo data used for facial authentication. "For ID photo" indicates facial photo data that has been cropped or the background changed for ID photos. In other words, the management device 100 can store a user's facial photo data separately for authentication and ID photos.

[0092] The authentication log storage unit 124 stores a log of when a user has performed facial authentication. For example, the authentication log storage unit 124 stores the date and time when the user attempted facial authentication, the result of the facial authentication, etc. The authentication log storage unit 124 may also store a log of when the user used a service. For example, the authentication log storage unit 124 may store the user's attendance record, etc.

[0093] The external service information storage unit 125 stores information about external services that can be used by a user after verifying the user's identity through facial authentication or the like. Fig. 12 is a diagram showing an example of the external service information storage unit 125 according to the embodiment. In the example shown in Fig. 12, the external service information storage unit 125 has items such as "service ID," "type," and "determination criteria."

[0094] The "service ID" indicates identification information for identifying the service. The "type" indicates the type of service. The "determination criteria" indicate criteria for determining whether or not a user is allowed to use a service based on the authentication strength related to facial recognition. For example, if the determination criteria are "OR determination," the user can use the service if the matching result is OK in any one of the multiple facial recognition engines. If the determination criteria are "AND determination," the user can use the service only if the matching result is OK in all of the multiple facial recognition engines. If the determination criteria are "OK determination in two or more," the user can use the service if the matching result is OK in two or more of the multiple facial recognition engines. Note that the determination criteria shown in FIG. 12 are merely examples, and external services may register various determination criteria in the management device 100 based on their desired authentication strength.

[0095] Returning to Fig. 8, the explanation will be continued. The control unit 130 is realized by, for example, a central processing unit (CPU), a micro processing unit (MPU), a graphics processing unit (GPU), or the like executing a program stored inside the management device 100 using a random access memory (RAM) or the like as a work area. The control unit 130 is also a controller, and is realized by, for example, an integrated circuit such as an application specific integrated circuit (ASIC) or a field programmable gate array (FPGA).

[0096] 8, the control unit 130 includes a registration processing unit 130A and an authentication processing unit 130B. The registration processing unit 130A controls processing related to the registration of a facial image. The registration processing unit 130A includes a reception unit 131, a provision unit 132, a quality determination unit 133, and a registration unit 134. The authentication processing unit 130B controls processing related to authentication processing. The authentication processing unit 130B includes an acquisition unit 135, a transmission unit 136, and a result determination unit 137.

[0097] The receiving unit 131 receives, from the user, a face image that is the source of correct answer data that each of the face recognition engines uses for matching in order to execute authentication processing by the face recognition engines. Note that the correct answer data that each face recognition engine uses for matching is not the face image itself, but feature amounts extracted from the face image.

[0098] For example, the receiving unit 131 provides the user with a page (such as a website) for registering a facial image, and receives the facial image from the user via the page. The facial image is used as a registration image to be registered in the face recognition engine. Note that, when the facial image is processed by processing means provided by the providing unit 132 (described later), the receiving unit 131 receives the processed image, which is the image after processing, as the registration image.

[0099] The providing unit 132 provides a processing means for the user to process the face image accepted by the accepting unit 131.

[0100] For example, the providing unit 132 provides processing means for changing at least one of the size of a facial image, the area occupied by the face in the facial image, the brightness of the facial image, and the background of the facial image. Specifically, as shown in FIGS. 3 and 4, the providing unit 132 provides an editing tool on a page for registering a facial image that allows the user to perform operations such as trimming, adjusting brightness, and changing the background. Note that the types of processing are not limited to those described above, and the providing unit 132 may provide, for example, a tool that can perform tooth whitening or facial whitening on a facial image. For these processes, the user may operate the tool to adjust the teeth or facial color to a desired color, or the providing unit 132 may automatically adjust the color to an appropriate color.

[0101] Furthermore, the providing unit 132 may provide reference information for processing an image into a processed image suitable for a plurality of face recognition engines or a service used by the user after authentication processing. The reference information is, for example, a guide 306, as shown in FIG. 3, displayed on the screen of the user terminal 20 to allow the user to process the image into a suitable processed image. The guide 306 is displayed based on, for example, the proportion of the size and position of the face included in the facial image. The reference information may also include horizontal lines for checking the parallelism of the face and vertical lines for checking the center of the image.

[0102] 3 and 4. For example, if it is clear that the user will not use the processed image for an ID photo, the providing unit 132 may skip the background change page that is mainly used for creating an ID photo and proceed with the registration process.

[0103] Furthermore, if it is difficult for the user to select the brightness, size, etc. of the image, the providing unit 132 may automatically adjust the brightness and size. That is, the providing unit 132 may convert at least one of the size of the facial image, the area occupied by the face in the facial image, the brightness of the facial image, and the background of the facial image in accordance with the user's request, and automatically generate an edited image that can be used as correct answer data for the authentication process of multiple facial recognition engines. In this case, the providing unit 132 may, for example, refer to the quality check item storage unit 122 to acquire information such as the brightness required for the facial image, the image size, and the position where the face should be located in the image. Then, the providing unit 132 automatically edits the facial image to meet these requirements and generates an edited image. In this case, the providing unit 132 may use known techniques, such as a process for detecting faces included in an image. This allows the providing unit 132 to generate an edited image that ensures the required quality without requiring the user's effort.

[0104] Furthermore, when the quality determination unit 133 (described later) determines that a predetermined quality check item related to the processed image does not satisfy the quality, the providing unit 132 may convert information in the processed image related to the quality check item so that the quality is satisfied. For example, when the quality determination unit 133 determines that the brightness of the processed image is insufficient, the providing unit 132 may automatically convert the processed image to be brighter so that the quality is satisfied, and generate a converted image. In this case, the providing unit 132 may present the converted image to the user once, or may automatically replace the original processed image with the converted image and proceed with the registration process.

[0105] The quality determination unit 133 determines whether or not the registration images, such as the facial images accepted by the accepting unit 131 and processed images, which are facial images processed by a processing means, are of a quality that allows them to be used as correct answer data for the authentication processing of multiple facial recognition engines.

[0106] Specifically, the quality determining unit 133 determines for each of the plurality of face recognition engines whether the registration image has a quality that allows it to be used as correct answer data for the recognition process of the plurality of face recognition engines.

[0107] More specifically, the quality determination unit 133 determines whether the registration image satisfies the criteria for the specified quality check items set for each of the multiple face recognition engines, and based on the determination result, determines whether the registration image is of a quality that allows it to be used as correct data for the recognition processing of the multiple face recognition engines.

[0108] The registration unit 134 registers the registration image when it is determined based on the determination result by the quality determination unit 133 that the registration image is of a quality that can be used as correct answer data for the authentication process for all of the multiple face recognition engines.

[0109] When the quality determination unit 133 determines that any of the predetermined quality check items related to the registration image does not satisfy the quality standard, the registration unit 134 may notify the user which quality check item does not satisfy the standard. For example, the registration unit 134 notifies the user which quality check item does not satisfy the standard by displaying a screen 338 and a determination result 340 shown in FIG. 4 on the user terminal 20.

[0110] If the registration unit 134 determines, based on the determination result by the quality determination unit 133, that the registration image is not of a quality that can be used as correct answer data for authentication processing for any of the multiple face recognition engines, it notifies the user that the registration image cannot be registered as an authentication face image. In other words, if there are multiple face recognition engines specified for a service, etc., the registration unit 134 registers only face images that can be registered in all of the face recognition engines. This allows the registration unit 134 to ensure safety in the face recognition processing.

[0111] Furthermore, when registering a registration image, the registration unit 134 may associate a second facial image with the registration image, the second facial image being different from the registration image in at least one of the following: facial image size, area occupied by the face in the facial image, brightness of the facial image, and background of the facial image. Specifically, when registering a user, the registration unit 134 may store a facial image for an identification photograph together with a facial image for authentication. This allows the management device 100 to provide the facial image for an identification photograph to the service side as needed, such as for creating an ID card for the service.

[0112] The acquisition unit 135 acquires a face image from the user for use in executing authentication processing on a plurality of face recognition engines. For example, the acquisition unit 135 acquires a face image for use in executing authentication processing via the authentication terminal 40 that has captured an image of the user.

[0113] The transmission unit 136 transmits the face image acquired by the acquisition unit 135 to each of the face recognition engines.

[0114] Note that the transmitting unit 136 does not necessarily need to transmit the facial image to all facial recognition engines, depending on the characteristics of the acquired facial image and the service request. Some facial recognition engines may have high matching accuracy for bright images (e.g., images taken during the day) or dark images (e.g., images taken at night), or may be trained to have high accuracy for matching specific races. Therefore, if the acquired facial image has a brightness lower or higher than a predetermined reference value, or if the facial image shows a specific race, the transmitting unit 136 may preferentially transmit the facial image to a facial recognition engine with high accuracy for such cases. The service that the user intends to use after authentication may specify a specific facial recognition engine (e.g., a facial recognition engine that is highly reliable for the service). In such cases, the transmitting unit 136 may select a facial recognition engine to which the facial image is to be transmitted depending on the type of user request (i.e., the service the user intends to use).

[0115] That is, the transmitting unit 136 may select which face recognition engine to send the face image to based on information about the face image or a user request. For example, the transmitting unit 136 may select which face recognition engine to send the face image to based on the brightness of the face image or the user's characteristic information (skin color, race, etc.) included in the face image.

[0116] The result determination unit 137 determines whether or not to permit the user's request depending on the number of face recognition engines that have succeeded in matching the face image with the correct answer data among the plurality of face recognition engines.

[0117] For example, the result determination unit 137 determines whether to permit a user's request based on whether the number of face recognition engines among a plurality of face recognition engines that have successfully matched a face image with correct answer data satisfies a determination criterion set by the service used by the user after the authentication process. Specifically, the result determination unit 137 refers to the external service information storage unit 125, and when a matching result that satisfies the determination criterion required by the service is obtained, the result determination unit 137 determines that the identity of the user has been authenticated and permits use of the service. Note that, if the service does not specify a determination criterion, the result determination unit 137 may permit the user's request if any face recognition engine has successfully matched the face image (OR determination), or may permit the user's request if all face recognition engines have successfully matched the face image (AND determination).

[0118] In addition, when the facial image is transmitted by the transmission unit 136 only to a specific facial recognition engine, the result determination unit 137 may determine whether to permit the user's request based on the authentication result of the facial recognition engine to which the facial image was transmitted.

[0119] (2. Modifications of the embodiment) (2-1.Device configuration) In the above embodiment, an example has been shown in which the user terminal 20 is used to register a face image and the authentication terminal 40 is used to perform authentication processing in the management system 1. However, the configuration and roles of the devices in the management system 1 can be changed as appropriate.

[0120] For example, when a user attempts to use a service on a website displayed on the user terminal 20, the user terminal 20 may take on the role of the authentication terminal 40. That is, the user terminal 20 may transmit a photographed facial image of the user to the management device 100 and execute a facial authentication process for the user. For example, when the user terminal 20 receives a result from the management device 100 indicating that the facial authentication is OK, the user terminal 20 may execute an operation after the service usage is permitted, such as making the service that the user attempted to access displayable.

[0121] In the above embodiment, each facial recognition provider is operated by a different business operator than the management device 100. However, the management device 100 may execute the processing according to the embodiment in an on-premise environment where multiple facial recognition engines function on its own, rather than receiving facial recognition engines from the facial recognition provider. In this case, the management device 100 may be provided with multiple facial recognition engines with different characteristics, for example, by generating the multiple facial recognition engines using different learning methods. This allows the management device 100 to execute management processing using multiple facial recognition engines without necessarily relying on multiple businesses. Furthermore, the management device 100 does not necessarily have to be a cloud server, but may function as a platform for managing multiple facial recognition engines in a system built on a local network.

[0122] (3. Other embodiments) The processing according to the above-described embodiment may be implemented in various different forms other than the above embodiment.

[0123] For example, among the processes described in the above embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method. Furthermore, the information including the processing procedures, specific names, various data, and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified. For example, the various information shown in each drawing is not limited to the information shown in the drawings.

[0124] Furthermore, the components of each device shown in the figure are conceptual functional components and do not necessarily have to be physically configured as shown in the figure. In other words, the specific form of distribution and integration of each device is not limited to that shown in the figure, and all or part of them can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc.

[0125] Furthermore, the above-described embodiments and modifications can be combined as appropriate within the scope of not causing any contradiction in the processing content.

[0126] Furthermore, the effects described in this specification are merely examples and are not limiting, and other effects may also be present.

[0127] (4. Effects of the Management Device According to the Present Disclosure) As described above, the management device according to the present disclosure (the management device 100 in the embodiment) includes a reception unit (the reception unit 131 in the embodiment), a provision unit (the provision unit 132 in the embodiment), and a quality determination unit (the quality determination unit 133 in the embodiment). The reception unit receives from the user a facial image that serves as the basis for supervised data used for matching by each of the plurality of facial recognition engines in order to execute authentication processing by the plurality of facial recognition engines. The provision unit provides processing means that enables the user to process the facial image received by the reception unit. The quality determination unit determines whether the processed image, which is a facial image processed by the processing means, is of a quality that allows it to be used as supervised data for the authentication processing of the plurality of facial recognition engines.

[0128] In this way, the management device according to the present disclosure provides a means for processing facial images received from a user and also determines the quality of the processed images to determine whether the facial recognition engine can use them for authentication processing. In this way, the management device 100 can perform processing such as trimming and quality determination processing simultaneously on the server-side platform, thereby enabling high-quality facial images to be acquired, leading to improved accuracy in feature extraction in the subsequent stage. Furthermore, by checking the quality of the processed images, the management device can prevent the need to retake images, thereby reducing the burden on the user and enabling accurate facial image registration.

[0129] The providing unit also provides reference information for processing the image into a processed image suitable for a plurality of face recognition engines or a service used by the user after authentication processing.

[0130] In this way, by providing the user with reference information indicating the face size, etc. along with the processing means, the management device can standardize the size and quality of the registration images received from the user, allowing registration to proceed smoothly.

[0131] The providing unit also provides processing means for converting at least one of the size of the face image received by the receiving unit, the area occupied by the face in the face image, the brightness of the face image, and the background of the face image.

[0132] In this way, the management device provides a means for processing images taken by the user, thereby providing an environment in which the user can edit images as desired.

[0133] In addition, the providing unit converts at least one of the size of the face image accepted by the accepting unit, the area occupied by the face in the face image, the brightness of the face image, and the background of the face image in accordance with the user's request, and generates a processed image that can be used as correct answer data for the authentication processing of multiple face recognition engines.

[0134] In this way, the management device can automatically process facial images, so that processed images that ensure the required quality can be generated without requiring the user to take time and effort.

[0135] In addition, if the quality determination unit determines that a specified quality check item related to the processed image does not meet the quality, the providing unit converts the information in the processed image related to the specified quality check item so that the quality meets the requirement.

[0136] In this way, the management device can automatically convert images to maintain quality, thereby generating processed images that guarantee the required quality without requiring the user to go through the trouble of doing so.

[0137] The management device may also be configured to include an acquisition unit (acquisition unit 135 in the embodiment), a transmission unit (transmission unit 136 in the embodiment), and a result determination unit (result determination unit 137 in the embodiment). The acquisition unit acquires a facial image from the user to cause a plurality of facial recognition engines to execute authentication processing. The transmission unit transmits the facial image acquired by the acquisition unit to each of the plurality of facial recognition engines. The result determination unit determines whether to permit the user's request based on the authentication results of each of the plurality of facial recognition engines that authenticated the facial image.

[0138] In this way, the management device executes authentication processing using multiple face recognition engines, which improves authentication accuracy and security, and also enables flexible authentication, such as setting different criteria for each service.

[0139] The result determination unit determines whether to permit the user's request depending on the number of face recognition engines that have successfully matched the face image with the correct answer data among the plurality of face recognition engines.

[0140] In this way, the management device performs authentication using multiple face recognition engines, and can perform authentication by taking advantage of the strengths of various face recognition engines, such as a face recognition engine that is strong in a certain environment or a face recognition engine that is strong for a certain race.

[0141] In addition, the result determination unit determines whether to grant the user's request based on whether the number of face recognition engines among the multiple face recognition engines that successfully match the face image with the correct answer data satisfies the determination criteria set by the service used by the user after the authentication process.

[0142] In this way, the management device can determine whether or not to permit a user's request based on the service's criteria, so rather than simply recognizing the user's identity based on a successful match by one facial recognition engine, it can perform flexible authentication processing according to the authentication strength and needs of the service.

[0143] The transmission unit selects which face recognition engine to transmit the face image to based on information about the face image or a user request. The result determination unit determines whether to permit the user request based on the authentication result of the face recognition engine to which the face image was transmitted.

[0144] In this way, the management device can take advantage of the advantage of using multiple face recognition engines and selectively use the face recognition engines based on the image characteristics that each engine is good at. This allows the management device to perform authentication with greater consideration given to safety, such as using only the face recognition engine with the highest accuracy.

[0145] The transmitting unit also selects to which face recognition engine the face image is to be transmitted based on the brightness of the face image or the user's characteristic information contained in the face image.

[0146] In this way, the management device can select a face recognition engine according to the characteristics of the image, and selectively transmit face images that are suitable for each face recognition engine.

[0147] The management device may also be configured to include a reception unit, a quality determination unit, and a registration unit (registration unit 134 in this embodiment). The reception unit receives from a user a registration image that serves as the source of correct answer data used for matching by each of a plurality of face recognition engines in order to execute authentication processing by the plurality of face recognition engines. The quality determination unit determines for each of the plurality of face recognition engines whether the registration image is of a quality that allows it to be used as correct answer data for the authentication processing of the plurality of face recognition engines. The registration unit registers the registration image when it is determined, based on the determination result by the quality determination unit, that the registration image is of a quality that allows it to be used as correct answer data for the authentication processing for all of the plurality of face recognition engines.

[0148] In this way, the management device registers only face images that satisfy the quality requirements of all face recognition engines used, allowing the management device to smoothly carry out authentication processing using multiple face recognition engines.

[0149] In addition, the quality judgment unit judges whether the registration image satisfies the standards for the specified quality check items set for each of the multiple face recognition engines, and based on the judgment result, judges whether the registration image is of a quality that can be used as correct data for the recognition processing of the multiple face recognition engines.

[0150] In this way, the management device sets items to be checked in the quality judgment and performs quality judgment in accordance with the items, thereby enabling the management device to reliably register face images of a quality that can be used by the face recognition engine.

[0151] In addition, if the quality determination unit determines that any of the specified quality check items related to the registration image does not meet the quality standards, the registration unit notifies the user which quality check item does not meet the standards.

[0152] In this way, the management device notifies the user that the quality does not meet the requirements for each item, and therefore can clearly communicate to the user how to correct the registration image.

[0153] In addition, if the registration unit determines, based on the judgment result by the quality judgment unit, that the registration image is not of a quality that can be used as correct data for the authentication process for any of the multiple face recognition engines, it notifies the user that the registration image cannot be registered as an authentication face image.

[0154] In this way, the management device can prompt the user to properly register with all face recognition engines by notifying the user that registration with one of the face recognition engines has failed.

[0155] In addition, when registering a registration image, the registration unit stores a second face image (for example, an image for a passport photo) that differs from the registration image in at least one of the size of the face image, the area occupied by the face in the face image, the brightness of the face image, and the background of the face image, in association with the registration image.

[0156] In this way, the management device may store an image for a passport photo separately from the image for authentication, which allows the management device to provide a face image for a passport photo to the service side as needed, such as for creating an ID card for the service, thereby enabling flexible responses as a platform.

[0157] (5. Hardware Configuration) Information devices such as the management device 100 and user terminal 20 according to the above-described embodiments are realized by a computer 1000 having a configuration such as that shown in FIG. 13. The following description will be given taking the management device 100 according to the embodiment as an example. FIG. 13 is a hardware configuration diagram showing an example of a computer 1000 that realizes the functions of the management device 100. The computer 1000 has a CPU 1100, a RAM 1200, a ROM (Read Only Memory) 1300, a HDD (Hard Disk Drive) 1400, a communication interface 1500, and an input / output interface 1600. The components of the computer 1000 are connected by a bus 1050.

[0158] The CPU 1100 operates and controls each unit based on programs stored in the ROM 1300 or the HDD 1400. For example, the CPU 1100 loads the programs stored in the ROM 1300 or the HDD 1400 into the RAM 1200 and executes processing corresponding to the various programs.

[0159] The ROM 1300 stores boot programs such as a Basic Input Output System (BIOS) executed by the CPU 1100 when the computer 1000 is started, and programs that depend on the hardware of the computer 1000 .

[0160] HDD 1400 is a computer-readable recording medium that non-temporarily records programs executed by CPU 1100 and data used by such programs. Specifically, HDD 1400 is a recording medium that records a program that executes management processing according to the present disclosure, which is an example of program data 1450.

[0161] The communication interface 1500 is an interface for connecting the computer 1000 to an external network 1550 (e.g., the Internet). For example, the CPU 1100 receives data from other devices and transmits data generated by the CPU 1100 to other devices via the communication interface 1500.

[0162] The input / output interface 1600 is an interface for connecting the input / output device 1650 and the computer 1000. For example, the CPU 1100 receives data from an input device such as a keyboard or a mouse via the input / output interface 1600. The CPU 1100 also transmits data to an output device such as a display, a speaker, or a printer via the input / output interface 1600. The input / output interface 1600 may also function as a media interface for reading programs and the like recorded on a predetermined recording medium. Examples of media include optical recording media such as a DVD (Digital Versatile Disc) or a PD (Phase Change Rewritable Disk), magneto-optical recording media such as an MO (Magneto-Optical disk), tape media, magnetic recording media, and semiconductor memories.

[0163] For example, when the computer 1000 functions as the management device 100 according to the embodiment, the CPU 1100 of the computer 1000 executes a management processing program loaded onto the RAM 1200, thereby realizing functions such as the control unit 130. The HDD 1400 stores a program for executing the management processing according to the present disclosure and data in the storage unit 120. The CPU 1100 reads and executes program data 1450 from the HDD 1400, but as another example, the CPU 1100 may obtain these programs from another device via an external network 1550.

[0164] The embodiments of the present application have been described in detail above with reference to the drawings, but these are merely examples, and the present invention can be implemented in other forms that include the embodiments described in the Disclosure of the Invention section and that have been modified and improved in various ways based on the knowledge of those skilled in the art. [Explanation of symbols]

[0165] 1 Management System 10 users 20 User terminal 40 Authentication Terminal 50 facial recognition providers 60 First face recognition engine 70 Second face recognition engine 80 Third face recognition engine 100 Management device 110 Communications Department 120 Storage section 121 User information storage unit 122 Quality check item memory section 123 Face Photo Memory Section 124 Authentication log storage unit 125 External service information storage unit 130 Control Unit 131 Reception 132 Provision Department 133 Quality Judgment Department 134 Registration Department 135 Acquisition Department 136 Transmitter 137 Result judgment section 200 Service Provider

Claims

1. a reception unit that receives, from a user, a registration image that is a source of correct answer data that each of the plurality of face recognition engines uses for matching in order to execute an authentication process using the plurality of face recognition engines; a quality determination unit that determines, for each of the plurality of face recognition engines, whether the registration image is of a quality that allows it to be used as correct answer data for the recognition process of the plurality of face recognition engines; a registration unit that registers the registration image when it is determined based on the determination result by the quality determination unit that the registration image has a quality that can be used as correct answer data for authentication processing for all of the plurality of face recognition engines; and A management device comprising:

2. The quality determination unit determining whether the registration image satisfies standards for predetermined quality check items set for each of the plurality of face recognition engines, and determining, based on the determination result, whether the registration image is of a quality that can be used as correct answer data for the recognition processing of the plurality of face recognition engines; The management device according to claim 1 .

3. The registration unit If the quality determination unit determines that any of the predetermined quality check items related to the registration image does not satisfy the quality standard, the user is notified of which quality check item does not satisfy the standard.

3. The management device according to claim 2.

4. The registration unit If it is determined based on the determination result by the quality determination unit that the registration image is not of a quality that can be used as correct answer data for authentication processing for any of the plurality of face recognition engines, notify the user that the registration image cannot be registered as an authentication face image.

4. The management device according to claim 1, wherein the management device is a device for managing a plurality of data.

5. The registration unit When registering the registration image, a second face image that is different from the registration image in at least one of the size of the face image, the area occupied by the face in the face image, the brightness of the face image, and the background of the face image is stored in association with the registration image.

5. The management device according to claim 1, wherein the management device is a device for managing a plurality of data.

6. The computer In order to execute authentication processing by a plurality of face recognition engines, a registration image is received from a user, which serves as a source of correct answer data used for matching by each of the plurality of face recognition engines; determining, for each of the plurality of face recognition engines, whether the registration image is of a quality that allows it to be used as correct answer data for the recognition process of the plurality of face recognition engines; If it is determined based on the result of the determination that the registration image is of a quality that can be used as correct answer data for authentication processing for all of the plurality of face recognition engines, the registration image is registered. A management method comprising:

7. Computer, a reception unit that receives, from a user, a registration image that is a source of correct answer data that each of the plurality of face recognition engines uses for matching in order to execute an authentication process using the plurality of face recognition engines; a quality determination unit that determines, for each of the plurality of face recognition engines, whether the registration image is of a quality that allows it to be used as correct answer data for the recognition process of the plurality of face recognition engines; a registration unit that registers the registration image when it is determined based on the determination result by the quality determination unit that the registration image has a quality that can be used as correct answer data for authentication processing for all of the plurality of face recognition engines; and A management program that causes the device to function as a management device comprising:

Citation Information

Patent Citations

  • Safety judging method, safety judgment system, authentication device, program and safety judging device

    JP2006236358A

  • Authentication device, authentication method, program for authentication, and computer-readable recording medium

    JP2007034505A

  • Information processor and information processing method

    JP2015088098A

  • Method and system for accepting application of medium with face image

    JP2016081141A

  • Face authentication system and face authentication method

    JP2020126334A