Authentication Device
The authentication device verifies and authenticates avatars using image matching and deletion processes, addressing unauthorized avatar creation and protecting individual reputations.
Patent Information
- Application Number
- JP2024531935
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-07-05
- Filing Date
- 2023-05-10
- Publication Date
- 2025-11-26
- Estimated Expiration
- 2043-05-10
AI Technical Summary
Conventional technologies allow unauthorized users to create avatars resembling others, posing risks to the reputation of celebrities and deceiving ordinary users, necessitating a method to authenticate whether an avatar closely resembling a person was created by that person.
An authentication device that generates avatar data, adds authentication data if genuine, and deletes it based on predetermined conditions, using image verification and matching algorithms to ensure the avatar is created by the person it represents.
Enables authentication of avatars resembling a person, preventing unauthorized use and protecting the reputation of individuals by ensuring only the person can create or modify their avatars.
Smart Images

Figure 0007776646000001 
Figure 0007776646000002 
Figure 0007776646000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an authentication device. [Background technology]
[0002] In virtual spaces using XR (Cross Reality) technology, including VR (Virtual Reality), AR (Augmented Reality), and MR (Mixed Reality), services are sometimes provided that use "3D avatars" to represent the user using three-dimensional images. 3D avatars include those created using a photograph of the user's face. Avatars include "real avatars" that closely resemble the user, and avatars that are animated to capture the user's features.
[0003] For example, Patent Document 1 discloses a method for creating and editing an avatar, which accepts photographic data of a user's face transmitted over a network from a terminal device used by the user, and uses the photographic data to create facial features of the avatar. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2009-223419 Summary of the Invention [Problem to be solved by the invention]
[0005] However, with conventional technology, it has been possible for a malicious user to use a photograph of another person's face without permission to create a real avatar or an animated avatar of that person.
[0006] For this reason, for example, if an avatar with the same appearance as a celebrity is created by someone other than the celebrity, there is a risk that the celebrity's reputation may be damaged by the avatar's inappropriate remarks and actions. Also, because the avatar's appearance closely resembles that of a celebrity, there is a risk that ordinary users may be deceived by the remarks and actions of the avatar that closely resembles the celebrity and suffer disadvantages.
[0007] In light of these risks, there is a need for technology that can determine whether an avatar that closely resembles a person was created by that person.
[0008] SUMMARY OF THE INVENTION It is therefore an object of the present invention to provide an authentication device that can add or delete authentication that an avatar that closely resembles a certain person has been created by that person. [Means for solving the problem]
[0009] An authentication device according to a preferred embodiment of the present invention is an avatar data authentication device that includes an avatar generation unit that generates avatar data representing an avatar of a service user who uses an avatar-related service using a user image obtained by capturing the user image; an authentication unit that generates authentication data to be added to the avatar data if the avatar data is authenticated as being genuine; and an authentication deletion unit that deletes the authentication data from the avatar data if deletion conditions are met. [Effects of the Invention]
[0010] According to the present invention, it is possible to add or remove authentication that an avatar that closely resembles a person was created by that person. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram showing the overall configuration of an avatar system 1. [Figure 2] FIG. 10 is a diagram showing an example of an avatar AK. [Figure 3] FIG. 2 is a block diagram showing an example of the configuration of a terminal device 30-K. [Figure 4] FIG. 1 is a block diagram showing an example of the configuration of an authentication device 10. [Figure 5] 10 is a flowchart showing an example of the operation of authentication device 10 when generating avatar data AD. [Figure 6] 10 is a flowchart showing an example of the operation of the authentication device 10 when deleting authentication data. [Figure 7] FIG. 2 is a block diagram showing an example of the configuration of an authentication device 10A. [Figure 8] FIG. 2 is a functional block diagram showing the configuration of a request receiving unit 118A. [Figure 9] FIG. 2 is a functional block diagram showing the configuration of a request determination unit 120. [Figure 10] 10 is a flowchart showing an example of the operation when authentication device 10A forcibly deletes authentication data. [Figure 11] 10 is a flowchart showing an example of the operation when authentication device 10A forcibly generates authentication data. [Figure 12] FIG. 10 is a functional block diagram showing the configuration of a request determination unit 120B. [Figure 13] 10 is a flowchart showing an example of the operation when authentication device 10B forcibly deletes authentication data. DETAILED DESCRIPTION OF THE INVENTION
[0012] 1: First embodiment An avatar system 1 including an authentication device 10 according to a first embodiment of the present invention will be described below with reference to FIGS.
[0013] The authentication device 10 according to this embodiment first generates avatar data representing an avatar that has not been authenticated by the person in question, and then later certifies that the avatar data is authentic.
[0014] 1-1: Configuration of the first embodiment 1-1-1: Overall structure FIG. 1 shows the overall configuration of an avatar system 1 according to the first embodiment. As shown in FIG. 1, the avatar system 1 includes an authentication device 10 and terminal devices 30-1, 30-2, ... 30-K, ... 30-N. N is an integer equal to or greater than 2. K is an integer equal to or greater than 1 and equal to or less than N. In this embodiment, the terminal devices 30-1 to 30-N have the same configuration. However, terminal devices with different configurations may be included. Note that, hereinafter, the terminal devices 30-1 to 30-N may be collectively referred to as "terminal device 30." Furthermore, the authentication device 10 and the terminal devices 30-1 to 30-N may be, for example, smartphones or tablets, or may be PCs (Personal Computers).
[0015] In the avatar system 1, the authentication device 10 and the terminal devices 30-1 to 30-N are connected to each other via a communication network NET so as to be able to communicate with each other. K uses terminal device 30-K. In the following, a user who uses any of terminal devices 30-1 to 30-N may be collectively referred to as "user U."
[0016] The authentication device 10 is a device used by the user U to generate an avatar, and also a device that adds and deletes authentication to the avatar data representing the generated avatar. The "authentication" here refers to verifying that the avatar data is genuine avatar data generated by the user U himself.
[0017] For example, user U K When a user U generates an avatar using the authentication device 10, the authentication device 10 K The authentication device 10 generates avatar data representing an avatar that closely resembles the user U. K When a user U creates an avatar, the avatar data representing the avatar is sent to the user U. K The authentication device 10 certifies that the data is genuine and created by the user, and generates authentication data to be added to the avatar data. Furthermore, if a predetermined deletion condition is met, the authentication device 10 deletes the authentication data from the avatar data.
[0018] Figure 2 shows the user U K Avatar A is an avatar created by the user using the authentication device 10, and the avatar data representing the avatar is authenticated as authentic. K As shown in Figure 2, avatar A K In this case, avatar A K The avatar data is then given a certification mark M, which indicates that the avatar data is authentic. K is depicted in a simplified manner.
[0019] The terminal device 30 is a device that displays an avatar A. Specifically, the terminal device 30 is provided with a display 34, which will be described later. The avatar A is displayed on the display 34. Note that the user U K is generated by the user U K Avatar A corresponding to yourself K is not limited to the terminal device 30-K, but is also displayed on other terminal devices 30, and K A user U other than the user A displays an avatar A on the display 34 of the other terminal device 30. K Furthermore, XR glasses, XR goggles, or an HMD (Head Mounted Display) using XR technology may be connected to the terminal device 30.
[0020] 1-1-2: Terminal device configuration 3 is a block diagram showing an example configuration of a terminal device 30-K. The terminal device 30-K includes a processing device 31, a storage device 32, a communication device 33, a display 34, an input device 35, and an imaging device 36. The elements of the terminal device 30 are connected to each other by one or more buses for communicating information.
[0021] The processing device 31 is a processor that controls the entire terminal device 30-K. The processing device 31 is configured, for example, using one or more chips. The processing device 31 is configured, for example, using a central processing unit (CPU) that includes an interface with peripheral devices, an arithmetic unit, a register, etc. Some or all of the functions of the processing device 31 may be realized by hardware such as a DSP, an ASIC, a PLD, and an FPGA. The processing device 31 executes various processes in parallel or sequentially.
[0022] The storage device 32 is a recording medium that can be read and written by the processing device 31. The storage device 32 also stores a plurality of programs including a control program PR3 executed by the processing device 31. The storage device 32 also stores a plurality of programs including a control program PR3 executed by the processing device 31. K The account information for logging in to the avatar system 1 is stored in the avatar system 1. The account information includes, for example, the user U K Account ID, user U K Phone number of user U K Email address of user U K fingerprints and other biometric information of the user U K Password, authentication pattern, and user U set by the user K Driver's license photo and User U K The account information is transmitted from the terminal device 30-K to the authentication device 10 and stored in the storage device 12 of the authentication device 10. As an example, the user U K When the user logs in to the avatar system 1 by the terminal device 30-K, the account information stored in the terminal device 30-K is compared with the account information stored in the authentication device 10.
[0023] The communication device 33 is hardware serving as a transmitting / receiving device for communicating with other devices. The communication device 33 is also called, for example, a network device, a network controller, a network card, a communication module, etc. The communication device 33 may include a connector for wired connection and an interface circuit corresponding to the connector. The communication device 33 may also include a wireless communication interface. Examples of the connector and interface circuit for wired connection include products that comply with wired LAN, IEEE1394, and USB. Examples of the wireless communication interface include products that comply with wireless LAN, Bluetooth (registered trademark), etc.
[0024] The display 34 is a device that displays images and text information. The display 34 displays various images under the control of the processing device 31. For example, various display panels such as a liquid crystal display panel and an organic EL (Electro Luminescence) display panel are suitably used as the display 34. Note that, as described above, when XR glasses, XR goggles, or an HMD using XR technology is connected to the terminal device 30-K, the XR glasses, XR goggles, or HMD using XR technology may be used instead of the display 34.
[0025] The input device 35 is K For example, the input device 35 includes a keyboard, a touchpad, a touch panel, or a pointing device such as a mouse. If the input device 35 includes a touch panel, it may also function as the display 34.
[0026] User U K Avatar A K At the time of generation, avatar A K The user image used to generate the user ID is uploaded to the authentication device 10. At the time of uploading, the input device 35 inputs the user ID of the user U. K is used to input the user image to the terminal device 30. The user image may be, for example, a user UK It is preferable that the photograph be a face photograph or a full-body photograph.
[0027] The imaging device 36 outputs imaging information obtained by capturing an image of the outside world. The imaging device 36 also includes, for example, a lens, an imaging element, an amplifier, and an AD converter. Light collected through the lens is converted into an imaging signal, which is an analog signal, by the imaging element. The amplifier amplifies the imaging signal and outputs it to the AD converter. The AD converter converts the amplified imaging signal, which is an analog signal, into imaging information, which is a digital signal. The converted imaging information is supplied to the processing device 31. The imaging information supplied to the processing device 31 is output to the authentication device 10 via the communication device 33.
[0028] Avatar A K When generating the user U K When authenticating the user U, the image capture device 36 K When authenticity is verified, the image capturing device 36 captures the image of the user U. K It is preferable that the head of the user U is imaged. The image information indicating the image captured by the image capturing device 36 is supplied to the processing device 31. The image information output to the processing device 31 is transmitted from the terminal device 30-K to the processing device 31. K is transmitted to the authentication device 10 as information indicating a first confirmation image, which is an image for confirming that the user is a service user who will use the service.
[0029] Furthermore, when deleting the authentication data, the authentication device 10 K When verifying the identity of the user, the image capture device 36 K When verifying the identity of the user, the image capturing device 36 captures the image of the user U. K It is preferable that the head of the person is imaged. Image information indicating the image captured by the image capturing device 36 is supplied to the processing device 31. The image information output to the processing device 31 is output to the authentication device 10 as information indicating a second confirmation image, which is an image for identity verification. In this embodiment, the second confirmation image is an example of a "confirmation image."
[0030] The processing device 31 functions as an acquisition unit 311, a display control unit 312, and a communication control unit 313 by reading and executing the control program PR3 from the storage device 32.
[0031] Acquisition unit 311 acquires information indicating a user image from input device 35. Acquisition unit 311 also acquires information indicating a first check image and information indicating a second check image from imaging device 36.
[0032] Furthermore, the authentication device 10 K Avatar A corresponding to K When avatar data indicating the above is generated, acquisition unit 311 acquires the avatar data from authentication device 10 via communication device 33.
[0033] The display control unit 312 uses the avatar data acquired by the acquisition unit 311 to display avatar A on the display 34. K Display.
[0034] The communication control unit 313 causes the authentication device 10 to transmit the information indicating the user image, the information indicating the first confirmation image, and the information indicating the second confirmation image acquired by the acquisition unit 311 to the communication device 33. The communication control unit 313 also causes the authentication device 10 to transmit a deletion request requesting deletion of the authentication.
[0035] 1-1-3: Authentication device configuration 4 is a block diagram showing an example of the configuration of the authentication device 10. The authentication device 10 includes a processing device 11, a storage device 12, a communication device 13, a display 14, and an input device 15. The elements of the authentication device 10 are connected to each other by one or more buses for communicating information.
[0036] The processing device 11 is a processor that controls the entire authentication device 10. The processing device 11 is configured, for example, using one or more chips. The processing device 11 is configured, for example, using a central processing unit (CPU) that includes an interface with peripheral devices, an arithmetic unit, a register, etc. Some or all of the functions of the processing device 11 may be realized by hardware such as a DSP, ASIC, PLD, or FPGA. The processing device 11 executes various processes in parallel or sequentially.
[0037] The storage device 12 is a recording medium that can be read and written by the processing device 11. The storage device 12 also stores a plurality of programs including a control program PR1 executed by the processing device 11. The storage device 12 also stores avatar data AD generated by an avatar generation unit 116 (described later). The storage device 12 also stores a user U K Avatar A K The storage device 12 stores user images used to generate avatar data AD representing the avatar A corresponding to each user U. When each of multiple users U generates avatar data AD representing the avatar A corresponding to the user U using the method described below, it is preferable that each image, information, and data stored in the storage device 12 be confirmed, collated, created, managed, and stored in association with the account of each user U. The data stored in the storage device 12 can be read out from the terminal device 30.
[0038] The communication device 13 is hardware serving as a transmitting / receiving device for communicating with other devices. The communication device 13 is also called, for example, a network device, a network controller, a network card, or a communication module. The communication device 13 may include a connector for wired connection and an interface circuit corresponding to the connector. The communication device 13 may also include a wireless communication interface. Examples of the connector and interface circuit for wired connection include products that comply with wired LAN, IEEE1394, and USB. Examples of the wireless communication interface include products that comply with wireless LAN, Bluetooth (registered trademark), etc.
[0039] The display 14 is a device that displays images and text information. The display 14 displays various images under the control of the processing device 11. For example, various display panels such as a liquid crystal display panel and an organic EL (Electro Luminescence) display panel are suitably used as the display 14.
[0040] The input device 15 accepts operations from an administrator of the authentication device 10. For example, the input device 15 includes a keyboard, a touchpad, a touch panel, or a pointing device such as a mouse. Here, if the input device 15 includes a touch panel, it may also serve as the display 14.
[0041] The processing device 11 reads and executes the control program PR1 from the storage device 12, thereby functioning as an acquisition unit 111, an image determination unit 112, an image reception unit 113, a matching unit 114, an authentication unit 115, an avatar generation unit 116, a communication control unit 117, a request reception unit 118, and an authentication deletion unit 119. For ease of explanation, of these components, the acquisition unit 111, the image determination unit 112, the image reception unit 113, the matching unit 114, the authentication unit 115, the avatar generation unit 116, and the communication control unit 117 are collectively referred to as a "functional unit FU1."
[0042] When generating the avatar data AD, the acquisition unit 111 receives the user U from the terminal device 30-K via the communication device 13. K The service user acquires information showing a first confirmation image for confirming that the user is a user who will use the service. Note that the "user who will use the service" is an example of a "service user."
[0043] Furthermore, when deleting the authentication data from the avatar data AD, the acquisition unit 111 receives the user U from the terminal device 30-K via the communication device 13. K acquires information indicating a second verification image, which is an image for verifying the identity of the user.
[0044] The image determination unit 112 determines whether the first confirmation image acquired by the acquisition unit 111 when generating the avatar data AD is an image obtained by capturing an image of the user of the terminal device 30-K at the current time. The image determination unit 112 determines whether the person appearing in the first confirmation image is not, for example, a person included in an image printed on paper, a person included in a two-dimensional photograph displayed on a display, or a person wearing a mask with another person's face printed on it, but rather a human being currently being imaged by the imaging device 36 provided in the terminal device 30-K. Specific methods of determination include, for example, K In addition, as a method for determining whether or not the data showing the face captured by the user U moving his / her face back and forth and left and right in front of the image capturing device 36 is data showing a three-dimensional image, the method for determining whether or not the data showing the face is a three-dimensional image is also applicable. K The way the light is shed on users, especially K A method for determining a change in the way light hits the face or body when the user U moves his / her face or body in front of the image capturing device 36 is also an example of such a determination method. K For example, when a user moves their face in front of the image capture device 36, it is determined whether there are minute movements of the parts of the face and whether there are blinking movements. If the user of the terminal device 30-K is wearing a mask with another person's face printed on it, physiological movements of the face will not be detected, and therefore masked impersonation will be ruled out. Note that the "user of the terminal device 30-K" is an example of the "terminal user of the terminal device 30-K."
[0045] In addition, when deleting authentication data from avatar data AD, image determination unit 112 uses the same method as when generating avatar data AD to determine whether the second confirmation image acquired by acquisition unit 111 is an image obtained by capturing an image of the user of terminal device 30-K at the current time.
[0046] When generating the avatar data AD, the image receiving unit 113 receives the user U K Avatar A KAs described above, the user image is used to generate avatar data AD representing the user U. K The image receiving unit 113 stores the received user image in the storage device 12.
[0047] When generating avatar data AD, matching unit 114 matches the person appearing in the first confirmation image with the person appearing in the user image. For example, matching unit 114 matches the two people based on whether facial features included in face data representing the face of the person appearing in the first confirmation image match the facial features representing the face of the person appearing in the user image. Examples of the facial features include the shape of the eyebrows, eyes, nose, and mouth, and the distance between facial features.
[0048] When deleting the authentication data from avatar data AD, matching unit 114 also matches the person appearing in the second confirmation image with the person appearing in the user image using the same method as when generating avatar data AD.
[0049] If predetermined authentication conditions are satisfied, authentication unit 115 certifies that avatar data AD generated by avatar generation unit 116 (described later) is authentic. Furthermore, if authentication unit 115 certifies that avatar data AD is authentic, it generates authentication data to be attached to the avatar data AD. For example, the "predetermined authentication conditions" are that the image determination unit 112 determines that the avatar data AD is authentic and that the matching unit 114 matches that the avatar data AD is authentic. If authentication unit 115 certifies that the avatar data AD is authentic, it may attach the authentication data to the avatar data AD. Conversely, if authentication unit 115 cannot verify that the avatar data AD is authentic, it may generate non-authentication data indicating that the avatar data AD has not been authenticated and attach the non-authentication data to the avatar data AD. Alternatively, authentication unit 115 may generate data indicating a correspondence between the ID of avatar data AD that identifies the avatar data AD and whether or not the avatar data has been authenticated, and store the data indicating the correspondence in storage device 12. The authentication data, non-authentication data, and data indicating the correspondence relationship may be managed by the authentication unit 115 or by an authentication information management unit (not shown). K The authentication information management unit determines whether to add the authentication mark M to the avatar A K The determination may be made based on the presence or absence of authentication data or non-authentication data linked to the avatar data AD indicating the above.
[0050] The avatar generation unit 116 generates avatar data AD using the user image. Specifically, the avatar generation unit 116 generates avatar data AD representing avatar A that resembles a person appearing in the user image, or avatar A that has the characteristics of that person. For example, the avatar generation unit 116 generates avatar data AD representing avatar A that has a face that closely resembles that of the person, or avatar A that has the facial characteristics of that person. As described above, when the authentication unit 115 certifies that the avatar data AD is authentic and generates authentication data, the avatar generation unit 116, for example, adds the authentication data to the avatar data AD.
[0051] As a result, the authentication device 10 can authenticate that avatar A, which has an appearance that closely resembles a certain person, was created by that person himself.
[0052] The communication control unit 117 causes the communication device 13 to transmit the avatar data AD generated by the avatar generation unit 116 to the terminal device 30.
[0053] The processing device 11 may execute the generation of avatar data AD by the avatar generation unit 116 after the authentication by the authentication unit 115, or may execute the authentication by the authentication unit 115 after the generation of avatar data AD by the avatar generation unit 116. Furthermore, the processing device 11 may execute the determination by the image determination unit 112, the matching by the matching unit 114, and the authentication by the authentication unit 115 after the generation of avatar data AD by the avatar generation unit 116. As a result, it is possible to perform post-authentication on avatar data AD that was generated in advance but has not been authenticated as authentic, and then add information indicating that the avatar data AD has been authenticated. As a result, the user U K Even after generating avatar A without authentication, it can be changed to avatar A with authentication without changing the appearance of avatar A. For example, user U K But first, Avatar A K When generating K This eliminates the need for authentication and allows you to easily create an avatar without authentication. K Then, user U K By performing authentication when there is time, the user can use the pre-generated avatar A K Avatar A with the same appearance as K Authentication can be granted without changing the password.
[0054] Request receiving unit 118 receives a deletion request instructing the deletion of authentication data from avatar data AD from terminal device 30. Request receiving unit 118 is an example of a "receiving unit."
[0055] Triggered by the request receiving unit 118 receiving a deletion request, the authentication deletion unit 119 deletes the authentication data from the avatar data AD if a predetermined deletion condition is met.
[0056] The "predetermined deletion condition" is, for example, that the determination result of image determination unit 112 is positive and the collation result of collation unit 114 is positive.
[0057] When predetermined deletion conditions are satisfied, authentication deletion unit 119 may not only delete authentication data from avatar data AD but also add non-authentication data to avatar data AD. Alternatively, when predetermined deletion conditions are satisfied, authentication deletion unit 119 may rewrite data stored in storage device 12 that indicates the correspondence between the ID of avatar data AD that identifies avatar data AD and the presence or absence of authentication.
[0058] Furthermore, the authentication data deleted by authentication deletion unit 119 is not limited to authentication data generated by authentication unit 115. For example, even when authentication device 10 acquires avatar data AD from an external source and authentication data has already been added to the avatar data AD by a system different from avatar system 1, authentication deletion unit 119 can delete the authentication data.
[0059] As a result, the authentication device 10 can add or delete authentication that avatar A, which has an appearance very similar to a certain person, was created by that person himself.
[0060] 1-2: Operation of the first embodiment 1-2-1: Avatar data AD generation 5 is a flowchart showing an example of the operation of authentication device 10 when generating avatar data AD. Hereinafter, an example of the operation of authentication device 10 will be described with reference to FIG.
[0061] In step S1, the processing device 11 functions as an acquisition unit 111. The processing device 11 receives the user U K The user acquires information showing a first confirmation image CP1 for confirming that the user is a user who will use the service.
[0062] In step S2, the processing device 11 functions as the image determination unit 112. The processing device 11 determines whether the first check image CP1 acquired in step S1 is an image currently obtained by capturing an image of the user of the terminal device 30-K.
[0063] In step S3, the processing device 11 functions as the image receiving unit 113. The processing device 11 receives, from the terminal device 30-K, an image of a user U who uses the service. K Avatar A K A user image UP is received to be used for generating avatar data AD representing the user.
[0064] In step S4, the processing device 11 functions as the matching unit 114. The processing device 11 matches the person appearing in the first check image CP1 with the person appearing in the user image UP.
[0065] If the authentication condition is met in step S5, that is, if both the determination result in step S2 and the matching result in step S4 are positive, the processing device 11 executes the process of step S6. On the other hand, if the authentication condition is not met, that is, if at least one of the determination result in step S2 and the matching result in step S4 is negative, the processing device 11 ends all processes.
[0066] In step S6, the processing device 11 functions as the authentication unit 115. The processing device 11 certifies that the generated avatar data AD is authentic. Furthermore, the processing device 11 generates authentication data CD.
[0067] In step S7, the processing device 11 functions as the avatar generation unit 116. The processing device 11 generates avatar data AD using the user image UP received in step S3. As an example, the authentication data CD generated in step S5 is added to the avatar data AD. Also, as an example, the processing device 11 stores the generated avatar data AD with the authentication data CD added in the storage device 12.
[0068] In step S8, processing device 11 functions as communication control unit 117. Processing device 11 causes communication device 13 to transmit avatar data AD generated in step S7 to terminal device 30-K.
[0069] 1-2-2: Behavior when deleting authentication data 6 is a flowchart showing an example of the operation when the authentication device 10 deletes the authentication data CD. Hereinafter, an example of the operation of the authentication device 10 will be described with reference to FIG.
[0070] In step S11, the processing device 11 functions as the request receiving unit 118. The processing device 11 receives, via the communication device 13, from the terminal device 30-K, a deletion request DD for requesting deletion of the authentication data CD.
[0071] In step S12, the processing device 11 functions as an acquisition unit 111. The processing device 11 receives the user U K The user then acquires information showing a second confirmation image CP2 for confirming that the user is a user who will use the service.
[0072] In step S13, the processing device 11 functions as the image determination unit 112. The processing device 11 determines whether the second check image CP2 acquired in step S12 is an image currently obtained by capturing an image of the user of the terminal device 30-K.
[0073] In step S14, the processing device 11 functions as the image receiving unit 113. The processing device 11 receives, from the terminal device 30-K, an image of a user U who uses the service. K Avatar A K Alternatively, if the user image UP is stored in the storage device 12, the processing device 11 may read the user image UP from the storage device 12, thereby receiving the user image UP.
[0074] In step S15, the processing device 11 functions as the matching unit 114. The processing device 11 matches the person appearing in the second check image CP2 with the person appearing in the user image UP.
[0075] If the deletion condition is met in step S16, that is, if both the determination result in step S13 and the comparison result in step S15 are positive, the processing device 11 executes the process of step S17. On the other hand, if the deletion condition is not met, that is, if at least one of the determination result in step S13 and the comparison result in step S15 is negative, the processing device 11 ends all processes.
[0076] In step S17, the processing device 11 functions as the authentication deletion unit 119. The processing device 11 deletes the authentication data CD from the avatar data AD.
[0077] 1-3: Effects of the First Embodiment According to the above description, the authentication device 10 according to this embodiment includes an avatar generation unit 116, an authentication unit 115, and an authentication deletion unit 119. The avatar generation unit 116 generates an avatar for a user U who uses a service. K The user image UP obtained by capturing the user U K Avatar A KIf the authentication unit 115 authenticates that the avatar data AD is authentic, it generates authentication data CD. If the deletion condition is met, the authentication deletion unit 119 deletes the authentication data CD.
[0078] The authentication device 10 has the above configuration, and therefore it is possible to add or delete authentication that avatar A, which has an appearance very similar to a certain person, was created by that person himself.
[0079] In addition, the authentication device 10 uses the avatar A, which has been authenticated. K Even after generating Avatar A K Avatar A without changing appearance and without identity verification K As a result, avatar A with personal authentication can be changed to K User U no longer feels the need to use K is the pre-generated avatar A. K Same as Avatar A K It is possible to remove personal authentication without changing the password.
[0080] As described above, the authentication device 10 includes a request receiving unit 118 as a receiving unit, an acquisition unit 111, an image determination unit 112, and a matching unit 114. The request receiving unit 118 receives a deletion request DD for deleting authentication data CD from the terminal device 30-K. The acquisition unit 111 receives the user U from the terminal device 30-K. K acquires a second confirmation image CP2 as a confirmation image for identity verification. Image determination unit 112 verifies that second confirmation image CP2 is an image obtained by currently capturing an image of the terminal user of terminal device 30-K. Matching unit 114 matches the person appearing in second confirmation image CP2 with the person appearing in user image UP. The deletion condition is that the determination result of image determination unit 112 is positive and the matching result of matching unit 114 is positive.
[0081] The authentication device 10 has the above configuration, and therefore deletes the authentication data CD based on a first condition that the second confirmation image CP2 is an image obtained by capturing an image of the user of the terminal device 30-K, and a second condition that the person appearing in the second confirmation image CP2 is the same person as the person appearing in the user image UP. This makes it possible for the authentication device 10 to prevent a third party from deleting the authentication data CD by impersonating another person.
[0082] 2: Second embodiment An avatar system 1A including an authentication device 10A according to a second embodiment of the present invention will be described below with reference to Figures 7 to 11. For the sake of simplicity, the same components of the avatar system 1A as those of the avatar system 1 will be denoted by the same reference numerals, and their description may be omitted.
[0083] When a request for generating or deleting authentication data CD is received from a terminal device 30 serving as an external device, the authentication device 10A according to this embodiment forcibly generates or deletes the authentication data CD.
[0084] 2-1: Configuration of the second embodiment 2-1-1: Overall structure Avatar system 1A differs from avatar system 1 in that it includes authentication device 10A instead of authentication device 10. In other respects, the overall configuration of avatar system 1A is the same as the overall configuration of avatar system 1 shown in Fig. 1, and therefore will not be illustrated. The following mainly describes the configuration of authentication device 10A.
[0085] 2-1-2: Authentication device configuration 7 is a block diagram showing an example configuration of an authentication device 10A. Compared to authentication device 10, authentication device 10A includes a processing device 11A instead of processing device 11 and a storage device 12A instead of storage device 12. Storage device 12A stores a control program PR1A instead of control program PR1. By reading and executing control program PR1A from storage device 12A, processing device 11A functions as functional unit FU1, i.e., a functional unit having an acquisition unit 111, an image determination unit 112, an image reception unit 113, a matching unit 114, an authentication unit 115, an avatar generation unit 116, and a communication control unit 117, as well as a request reception unit 118A, an authentication deletion unit 119, and a request determination unit 120.
[0086] The request receiving unit 118A receives requests from the terminal device 30. Fig. 8 is a functional block diagram showing the configuration of the request receiving unit 118A. The request receiving unit 118A includes a first receiving unit 118A-1 and a second receiving unit 118A-2.
[0087] The first reception unit 118A-1 receives from the terminal device 30 a deletion request DD instructing the terminal device 30 to delete the authentication data CD.
[0088] The second reception unit 118A-2 receives a generation request from the terminal device 30 instructing the generation of authentication data CD.
[0089] Returning to the explanation of Fig. 7, request determination unit 120 determines whether or not a forcing instruction is included in the request received by request reception unit 118A. Fig. 9 is a functional block diagram showing the configuration of request determination unit 120. Request determination unit 120 includes first request determination unit 120-1 and second request determination unit 120-2.
[0090] The first request determination unit 120-1 determines whether the user U KThe authentication deletion unit 119 determines whether the deletion request DD received by the first reception unit 118A-1 contains a forcible instruction to forcibly delete the authentication data CD without the approval of the first reception unit 118A-1. Note that the above-mentioned "predetermined deletion condition" used by the authentication deletion unit 119 is that the determination result of the first request determination unit 120-1 is positive. In other words, when the determination result of the first request determination unit 120-1 is positive, the authentication deletion unit 119 deletes the authentication data CD.
[0091] The second request determination unit 120-2 determines whether the user U K The second reception unit 118A-2 determines whether the generation request received by the second reception unit 118A-2 includes a compulsory instruction to forcibly generate authentication data CD without approval from the authentication unit 115. Note that the above-mentioned "predetermined authentication condition" used by the authentication unit 115 is that the determination result of the second request determination unit 120-2 is positive. In other words, if the determination result of the second request determination unit 120-2 is positive, the authentication unit 115 generates authentication data CD.
[0092] 2-2: Operation of the second embodiment 2-2-1: Avatar data AD generation An example of the operation when authentication device 10A generates avatar data AD is the same as the example of the operation when authentication device 10 generates avatar data AD, as shown in FIG. 5, and therefore a description thereof will be omitted.
[0093] 2-2-2: Normal behavior when deleting authentication data An example of the operation when the authentication device 10A normally deletes the authentication data CD is the same as the example of the operation when the authentication device 10 deletes the authentication data CD shown in FIG. 6, and therefore a description thereof will be omitted.
[0094] 2-2-3: Behavior when forcibly deleting authentication data 10 is a flowchart showing an example of the operation of authentication device 10A when authentication data CD is forcibly deleted. Hereinafter, an example of the operation of authentication device 10A will be described with reference to FIG.
[0095] In step S21, the processing device 11A functions as the first reception unit 118A-1. The processing device 11A receives, via the communication device 13, from the terminal device 30, a deletion request DD for requesting deletion of the authentication data CD.
[0096] If the deletion condition is met in step S22, the processing device 11A executes the process of step S23. On the other hand, if the deletion condition is not met, the processing device 11A ends all the processes described in Fig. 10. In this case, the processing device 11A may execute the processes from step S12 onwards in the flowchart shown in Fig. 6.
[0097] Specifically, the processing device 11A functions as a first request determination unit 120-1. The processing device 11A determines whether or not a forcible instruction is included in the deletion request DD received in step S21. If a forcible instruction is included in the deletion request DD, the processing device 11A executes the process of step S23. On the other hand, if a forcible instruction is not included in the deletion request DD, the processing device 11A ends all processes. In this case, the processing device 11A may execute the processes from step S12 onwards in the flowchart shown in FIG. 6.
[0098] In step S23, the processing device 11A functions as the authentication deletion unit 119. The processing device 11A deletes the authentication data CD from the avatar data AD.
[0099] 2-2-4: Behavior when forced authentication data generation 11 is a flowchart showing an example of the operation of authentication device 10A when authentication data CD is forcibly generated. Hereinafter, an example of the operation of authentication device 10A will be described with reference to FIG.
[0100] In step S31, the processing device 11A functions as the second reception unit 118A-2. The processing device 11A receives, via the communication device 13, from the terminal device 30, a generation request GD for requesting the generation of authentication data CD.
[0101] If the authentication condition is met in step S32, the processing device 11A executes the process of step S33. On the other hand, if the authentication condition is not met, the processing device 11A ends all the processes shown in FIG.
[0102] Specifically, the processing device 11A functions as a second request determination unit 120-2. The processing device 11A determines whether or not a forced instruction is included in the generation request GD received in step S32. If a forced instruction is included in the generation request GD, the processing device 11A executes the process of step S33. On the other hand, if a forced instruction is not included in the generation request GD, the processing device 11A ends all processes.
[0103] In step S33, the processing device 11A functions as the authentication unit 115. The processing device 11A generates authentication data CD.
[0104] 2-3: Effects of the second embodiment According to the above description, the authentication device 10A according to this embodiment includes a first reception unit 118A-1 and a first request determination unit 120-1. The first reception unit 118A-1 receives a deletion request DD from the terminal device 30, which instructs the deletion of authentication data CD. The first request determination unit 120-1 receives a deletion request DD from the user U. K The first request determining unit 120-1 determines whether the deletion request DD includes a compulsory instruction to forcibly delete the authentication data CD without approval from the first request determining unit 120-2. The deletion condition is that the determination result of the first request determining unit 120-1 is positive.
[0105] Since the authentication device 10A has the above configuration, when a request to delete the authentication data CD is received from the terminal device 30 as an external device, the authentication device 10A can forcibly delete the authentication data CD.
[0106] As a result, when avatar A to which authentication mark M has been mistakenly added is being used by another person, authentication device 10A can forcibly delete authentication data CD from avatar data AD representing avatar A, thereby preventing the use of avatar A by another person. Furthermore, when the creator of avatar A becomes unable to use avatar A for some reason, authentication device 10A can forcibly delete authentication data CD from avatar data AD representing avatar A, thereby reducing the risk that another person will use avatar A by impersonating the creator.
[0107] According to the above description, the authentication device 10A according to this embodiment includes a second reception unit 118A-2 and a second request determination unit 120-2. The second reception unit 118A-2 receives a generation request GD from the terminal device 30, the generation request GD instructing the terminal device 30 to generate authentication data CD. The second request determination unit 120-2 determines whether the generation request GD includes a compulsory instruction instructing the terminal device 30 to forcibly generate authentication data CD without satisfying the authentication conditions. If the determination result of the second request determination unit 120-2 is affirmative, the authentication unit 115 generates the authentication data CD.
[0108] Since the authentication device 10A has the above configuration, when a request for generation of authentication data CD is received from the terminal device 30 as an external device, the authentication device 10A can forcibly execute generation of the authentication data CD.
[0109] The authentication device 10A detects, for example, that the user U is trying to create an avatar A. K Despite being the person in question, user U K If the user is not authenticated, an avatar A is generated without the authentication mark M. In such a case, the authentication device 10A forcibly adds the authentication data CD to the avatar data AD corresponding to the avatar A, thereby authenticating the user U. K The person can use avatar A with authentication mark M attached.
[0110] 3: Third embodiment An avatar system 1B including an authentication device 10B according to a third embodiment of the present invention will be described below with reference to Figures 12 and 13. For the sake of simplicity, the same components of the avatar system 1B as those of the avatar systems 1 and 1A will be denoted by the same reference numerals, and their description may be omitted.
[0111] Authentication device 10B according to this embodiment stores first confirmation image CP1 used when avatar data AD was generated. If, for example, thereafter, it is suspected that spoofing occurred when avatar data AD was generated, authentication device 10B uses the stored first confirmation image CP1 to re-determine whether the user was properly authenticated when avatar data AD was generated, and deletes authentication data CD if the deletion condition is met.
[0112] 3-1: Configuration of the third embodiment 3-1-1: Overall structure Avatar system 1B differs from avatar system 1 in that it includes authentication device 10B instead of authentication device 10. In other respects, the overall configuration of avatar system 1B is the same as the overall configuration of avatar system 1 shown in Fig. 1, and therefore will not be illustrated. The following mainly describes the configuration of authentication device 10B.
[0113] 3-1-2: Authentication device configuration Compared to authentication device 10, authentication device 10B includes a processing device 11B instead of processing device 11 and a storage device 12B instead of storage device 12. Storage device 12B stores a control program PR1B instead of control program PR1. By reading and executing control program PR1B from storage device 12B, processing device 11B functions as functional unit FU1B, including an acquisition unit 111B, an image determination unit 112B, an image reception unit 113B, a matching unit 114B, an authentication unit 115B, an avatar generation unit 116, and a communication control unit 117, as well as a request reception unit 118, an authentication deletion unit 119, and a request determination unit 120B. In other respects, the overall configuration of authentication device 10B is the same as the configuration of authentication device 10A according to the second embodiment shown in FIGS. 7 and 8, and therefore is not shown in the figures.
[0114] Similar to acquisition unit 111, acquisition unit 111B acquires first confirmation image CP1 from terminal device 30-K when avatar data AD is generated. Acquisition unit 111B then stores the acquired first confirmation image CP1 in storage device 12B. In this embodiment, first confirmation image CP1 is an example of a "confirmation image." Terminal device 30-K is an example of an "external device."
[0115] Similar to the image determination unit 112, the image determination unit 112B determines whether the first confirmation image CP1 acquired by the acquisition unit 111B at the time of generating the avatar data AD is an image obtained by capturing an image of the user of the terminal device 30-K at the current time.
[0116] When deleting authentication data CD from avatar data AD, image determination unit 112B performs the above determination using first check image CP1 read from storage device 12B. Specifically, image determination unit 112B determines whether first check image CP1 read from storage device 12B is an image obtained by capturing an image of the user of terminal device 30-K when avatar data AD was generated.
[0117] Similarly to the image receiving unit 113, the image receiving unit 113B receives the user U from the terminal device 30-K when generating the avatar data AD. K Avatar A K Image receiving unit 113B receives user image UP to be used for generating avatar data AD representing the user. Image receiving unit 113B stores the received user image UP in storage device 12B.
[0118] Furthermore, when the authentication data CD is deleted from the avatar data AD, the image accepting unit 113B reads out the user image UP from the storage device 12B, and accepts the read out user image UP.
[0119] Similar to matching unit 114, matching unit 114B matches the person appearing in first check image CP1 with the person appearing in user image UP when generating avatar data AD.
[0120] When deleting authentication data CD from avatar data AD, matching unit 114B performs the above matching using first check image CP1 and user image UP read from storage device 12B. Specifically, matching unit 114B matches the person appearing in first check image CP1 with the person appearing in user image UP.
[0121] Similar to authentication unit 115, authentication unit 115B certifies the authenticity of avatar data AD using first confirmation image CP1 acquired by acquisition unit 111B when generating avatar data AD. Specifically, authentication unit 115B determines whether both the determination result based on the first criterion by image determination unit 112B and the matching result based on the second criterion by matching unit 114B are positive. Specifically, the first criterion is a criterion used to determine whether the first confirmation image CP1 acquired by acquisition unit 111B is an image obtained by capturing an image of the user of terminal device 30-K when generating avatar data AD. The second criterion is a criterion used to determine whether the person appearing in first confirmation image CP1 and the person appearing in user image UP accepted by image acceptance unit 113 are the same person. The "predetermined authentication condition" refers to whether both the determination result based on the first criterion and the matching result based on the second criterion are positive.
[0122] Fig. 12 is a functional block diagram showing the configuration of the request determination unit 120B. As shown in Fig. 12, compared to the request determination unit 120 according to the second embodiment, the request determination unit 120B includes a reference determination unit 120-3 instead of the second request determination unit 120-2.
[0123] When deleting authentication data CD from avatar data AD, criterion determination unit 120-3 makes a determination based on a first criterion similar to the first criterion used by authentication unit 115B. Furthermore, criterion determination unit 120-3 makes a determination based on a second criterion similar to the second criterion used by authentication unit 115B. Specifically, the first criterion is a criterion used to determine whether first confirmation image CP1 read from storage device 12B is an image obtained by capturing an image of the user of terminal device 30-K as an external device. The second criterion is a criterion used to determine whether the person appearing in first confirmation image CP1 read from storage device 12B and the person appearing in user image UP read from storage device 12B are the same person. If both the determination based on the first criterion and the determination based on the second criterion are positive, the determination result by criterion determination unit 120-3 is positive. On the other hand, if at least one of the determination based on the first criterion and the determination based on the second criterion is negative, the determination result by criterion determination section 120-3 is negative.
[0124] Here, the first criterion used by authentication unit 115B and the criterion used by criterion determination unit 120-3 are different in strictness. For example, when confirming whether or not first check image CP1 is an image obtained by capturing an image of the user of terminal device 30-K as an external device, image determination unit 112B, at the time of authentication by authentication unit 115B, K The image determination unit 112B only verifies that the data representing the face captured by moving the face back and forth and left and right in front of the image capture device 36 is data representing a three-dimensional image. On the other hand, when the reference determination unit 120-3 makes a determination, the image determination unit 112B not only verifies that the data representing the face is data representing a three-dimensional image, but also determines the minute movements of the parts that make up the face and the movements of blinks.
[0125] Furthermore, the second criteria used by authentication unit 115B and the second criteria used by criterion determination unit 120-3 differ in strictness. For example, both during authentication by authentication unit 115B and during determination by criterion determination unit 120-3, matching unit 114B matches the person appearing in first check image CP1 with the person appearing in user image UP to determine that they are the same. However, unless the degree of similarity between the two people is higher during determination by criterion determination unit 120-3 than during authentication by authentication unit 115B, matching unit 114B will not determine that the two people are the same.
[0126] The "predetermined deletion condition" used by the authentication deletion unit 119 is that the determination result by the first request determination unit 120-1 is positive and the determination result by the criterion determination unit 120-3 is negative. That is, when the determination result by the first request determination unit 120-1 is positive and the determination result by the criterion determination unit 120-3 is negative, the authentication deletion unit 119 deletes the authentication data CD.
[0127] 3-2: Operation of the third embodiment 3-2-1: Avatar data AD generation An example of the operation when authentication device 10B generates avatar data AD is basically the same as the example of the operation when authentication device 10 generates avatar data AD, as shown in Fig. 5, and therefore is not shown in the figure. Below, we will explain the differences between the example of the operation when authentication device 10B generates avatar data AD and the example of the operation when authentication device 10 generates avatar data AD.
[0128] In step S1, the processing device 11B functions as an acquisition unit 111B. The processing device 11B receives the user U from the terminal device 30-K via the communication device 13. K The processing device 11B then acquires information indicating a first confirmation image CP1 for verifying that the user is a user who will use the service. The processing device 11B then stores the acquired first confirmation image CP1 in the storage device 12A. The terminal device 30-K is an example of an "external device."
[0129] In step S6, processing device 11B functions as authentication unit 115B. Processing device 11B uses first check image CP1 to certify that the avatar data AD to be generated is authentic. Specifically, the "authentication condition" in step S5 includes a determination by image determination unit 112B that the first check image CP1 acquired by acquisition unit 111B at the time of generating avatar data AD is an image obtained by capturing an image of the user of terminal device 30-K at the current time. In step S6, processing device 11B certifies that the avatar data AD to be generated is authentic based on the authentication condition using first check image CP1 as the criterion in step S5. Furthermore, processing device 11B generates authentication data CD.
[0130] 3-2-2: Behavior when deleting authentication data 13 is a flowchart showing an example of the operation of authentication device 10B when deleting authentication data CD. Hereinafter, an example of the operation of authentication device 10B will be described with reference to FIG.
[0131] In step S41, processing device 11B functions as request receiving unit 118. Processing device 11B receives, via communication device 13, a deletion request DD requesting deletion of authentication data CD from terminal device 30 different from terminal device 30-K used to generate avatar data AD.
[0132] For example, user U K A user U different from user U K If the user U impersonates the user and generates the avatar data AD by using the terminal device 30-K, K There may be a case where the terminal device 30-K requests the processing device 11A to delete the authentication data CD from the terminal device 30-K. In such a case, the processing device 11A may receive a deletion request DD from the terminal device 30-K to request the deletion of the authentication data CD.
[0133] In step S42, the processing device 11B functions as an acquisition unit 111B. The processing device 11B acquires the user UK The user acquires information showing a first confirmation image CP1 for confirming that the user is a user who will use the service.
[0134] In step S43, processing device 11B functions as image determination unit 112B. Processing device 11B determines whether first check image CP1 acquired in step S42 is an image obtained by capturing an image of the user of terminal device 30-K when avatar data AD was generated.
[0135] In step S44, the processing device 11B functions as the image receiving unit 113B. The processing device 11A receives, from the storage device 12B, the image data of the user U who uses the service. K Avatar A K The user image UP used to generate the avatar data AD representing the user is received.
[0136] In step S45, the processing device 11A functions as the matching unit 114B. The processing device 11B matches the person appearing in the first check image CP1 with the person appearing in the user image UP.
[0137] In step S46, if the deletion condition is met, that is, if the determination result when the processing device 11B functions as the first request determination unit 120-1 is positive and the determination result when the processing device 11B functions as the reference determination unit 120-3 is negative, the processing device 11B executes the process of step S47. On the other hand, if the deletion condition is not met, the processing device 11B ends all processes.
[0138] In step S47, the processing device 11B functions as the authentication deletion unit 119. The processing device 11B deletes the authentication data CD from the avatar data AD.
[0139] According to the above description, in authentication device 10B according to this embodiment, user image UP is acquired from terminal device 30-K, which serves as an external device, along with first confirmation image CP1, which serves as a confirmation image, when avatar data AD is generated. User image UP is stored in storage device 12B along with first confirmation image CP1. Authentication unit 115B certifies that avatar data AD is authentic if first confirmation image CP1 is an image obtained by capturing an image of the user of terminal device 30-K and the person appearing in first confirmation image CP1 is the same person as the person appearing in user image UP. Authentication device 10B also includes a criterion determination unit 120-3. Criterion determination unit 120-3 determines whether first confirmation image CP1 read from storage device 12B is an image obtained by capturing an image of the user of terminal device 30-K. Furthermore, the criterion determination unit 120-3 determines whether the person appearing in the first check image CP1 read from the storage device 12B is the same person as the person appearing in the user image UP read from the storage device 12B. The deletion condition is that the determination result of the first request determination unit 120-1 is positive, and at least one of the two determination results of the criterion determination unit 120-3 is negative.
[0140] Since authentication device 10B has the above configuration, for example, if it is suspected that impersonation occurred when avatar data AD was generated, authentication device 10B can use the stored first confirmation image CP1 to re-determine whether the person was properly authenticated when avatar data AD was generated, and if the deletion conditions are met, can delete authentication data CD.
[0141] 4: Variation The present disclosure is not limited to the above-exemplified embodiments. For example, two or more aspects arbitrarily selected from the above-exemplified embodiments may be combined. Furthermore, specific modified aspects are exemplified below. Two or more aspects arbitrarily selected from the following examples may be combined.
[0142] 4-1: Variation 1 The avatar system 1 according to the first embodiment uses avatar data AD to verify the identity of the user U. K The identity of the person may be verified using facial information of the person.
[0143] As an example, the authentication device 10 receives a user U K The account information of the user U is acquired and stored in the storage device 12. K Account ID, user U K Phone number of user U K Email address of user U K fingerprints and other biometric information of the user U K Driver's license photo, User U K It includes one or more of the following facial photo databases:
[0144] The authentication device 10 is K If you authorize the use of avatar data AD after authenticating that you are a genuine user, the above account information, such as user U, K Driver's license photo and User U K From the database of facial photos of user U K Then, the authentication device 10 acquires a confirmation image such as a facial photograph of the user U. K If the result of the above check is positive, the authentication device 10 verifies that the verification image, such as a facial photograph, of the user U corresponds to the image currently captured by capturing an image of the user of the terminal device 30-K. K After authenticating that the user is a genuine user, the avatar data AD is permitted to be used.
[0145] As another example, the authentication device 10 may assign, to the avatar data AD, K The authentication device 10 embeds user image data indicating a user image UP, such as a face photo, as a digital watermark. KIf the authentication device 10 is to authenticate the user as a genuine user and then permit the use of the avatar data AD, it extracts user image data from the avatar data AD. Furthermore, the authentication device 10 compares the person appearing in the user image UP indicated by the user image data with the person appearing in an image obtained by capturing an image of the user of the terminal device 30-K. If the result of the comparison is positive, the authentication device 10 identifies the user U. K After authenticating that the user is a genuine user, the avatar data AD is permitted to be used.
[0146] When the authentication device 10 according to the first embodiment deletes the authentication data CD from the avatar data AD, the authentication device 10 deletes the user U from the storage device 12. K Alternatively, the authentication device 10 may delete the user image data embedded in the avatar data AD. This also applies to the second and third embodiments.
[0147] 5:Other (1) In the above-described embodiment, authentication devices 10 to 10B and terminal device 30 are exemplified. However, the storage devices provided in authentication devices 10 to 10B and terminal device 30 may be flexible disks, magneto-optical disks (e.g., compact disks, digital versatile disks, Blu-ray (registered trademark) discs), smart cards, flash memory devices (e.g., cards, sticks, key drives), CD-ROMs (Compact Disc-ROMs), registers, removable disks, hard disks, floppy (registered trademark) disks, magnetic strips, databases, servers, or other suitable storage media. Furthermore, the programs executed by the external devices may be transmitted from a network via telecommunications lines. Furthermore, the programs may be transmitted from a communications network NET via telecommunications lines.
[0148] (2) In the above-described embodiments, the described information, signals, etc. may be represented using any of a variety of different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.
[0149] (3) In the above-described embodiment, input and output information may be stored in a specific location (for example, a memory) or may be managed using a management table. Input and output information may be overwritten, updated, or added to. Output information may be deleted. Input information may be transmitted to another device.
[0150] (4) In the above-described embodiment, the determination may be made by a value (0 or 1) represented using one bit, by a Boolean value (true or false), or by a comparison of numerical values (e.g., comparison with a predetermined value).
[0151] (5) The order of the process procedures, sequences, flowcharts, etc. illustrated in the above-described embodiments may be rearranged unless inconsistent. For example, the methods described in this disclosure present elements of various steps using an example order, and are not limited to the particular order presented.
[0152] (6) Each function illustrated in Figures 1, 3, 4, 7 to 9, and 12 is realized by any combination of at least one of hardware and software. Furthermore, the method for realizing each functional block is not particularly limited. That is, each functional block may be realized using a single device that is physically or logically coupled, or may be realized using two or more physically or logically separated devices that are connected directly or indirectly (for example, by wire, wirelessly, etc.) and these multiple devices. A functional block may also be realized by combining software with the single device or the multiple devices.
[0153] (7) The programs exemplified in the above-described embodiments should be broadly construed to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, etc., regardless of whether they are called software, firmware, middleware, microcode, hardware description language, or by other names.
[0154] Software, instructions, information, etc. may also be transmitted or received over a transmission medium. For example, if software is transmitted from a website, server, or other remote source using wired technologies (such as coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL)), and / or wireless technologies (such as infrared, microwave), then these wired and / or wireless technologies are included within the definition of transmission media.
[0155] (8) In each of the foregoing embodiments, the terms "system" and "network" are used interchangeably.
[0156] (9) The information, parameters, etc. described in this disclosure may be expressed using absolute values, relative values from a predetermined value, or corresponding other information.
[0157] (10) In the above-described embodiments, the authentication devices 10 to 10B and the terminal device 30 may be mobile stations (MS). A mobile station may also be referred to by those skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other appropriate term. In addition, in the present disclosure, terms such as "mobile station," "user terminal," "user equipment (UE)," and "terminal" may be used interchangeably.
[0158] (11) In the above-described embodiments, the terms "connected," "coupled," or any variations thereof refer to any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are "connected" or "coupled" to each other. The coupling or connection between elements may be a physical coupling or connection, a logical coupling or connection, or a combination thereof. For example, "connected" may be read as "access." As used in this disclosure, two elements may be considered to be "connected" or "coupled" to each other using at least one of one or more wires, cables, and printed electrical connections, as well as electromagnetic energy having wavelengths in the radio frequency range, microwave range, and optical (both visible and invisible) range, as some non-limiting and non-exhaustive examples.
[0159] (12) In the above embodiments, the phrase "based on" does not mean "based only on," unless otherwise specified. In other words, the phrase "based on" means both "based only on" and "based at least on."
[0160] (13) As used in this disclosure, the terms "determining" and "determining" may encompass a wide variety of actions. "Determining" and "determining" may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, inquiring (e.g., searching in a table, database, or other data structure), ascertaining, and the like. "Determining" and "determining" may also include receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, accessing (e.g., accessing data in memory), and the like. Furthermore, "judgment" and "decision" can include regarding resolving, selecting, choosing, establishing, comparing, etc. as having been "judged" or "decided." In other words, "judgment" and "decision" can include regarding some action as having been "judged" or "decided." Furthermore, "judgment (decision)" can be interpreted as "assuming," "expecting," "considering," etc.
[0161] (14) In the above embodiments, when "include," "including," and variations thereof are used, these terms are intended to be inclusive, similar to the term "comprising." Furthermore, the term "or" as used in this disclosure is not intended to be an exclusive or.
[0162] (15) In this disclosure, where articles are added by translation, such as a, an, and the in English, this disclosure may include the nouns following these articles being plural.
[0163] (16) In this disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "combined" may also be interpreted in the same way as "different."
[0164] (17) Each aspect / embodiment described in this disclosure may be used alone, in combination, or switched depending on the implementation. Notification of predetermined information (e.g., notification that "X is true") is not limited to explicit notification, but may be implicit (e.g., not notifying the predetermined information).
[0165] Although the present disclosure has been described in detail above, it is clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the description of the present disclosure is intended to be illustrative and does not have any limiting meaning on the present disclosure. [Explanation of symbols]
[0166] DESCRIPTION OF SYMBOLS 1-1B... Avatar system, 10-10B... Authentication device, 11-11B... Processing device, 12-12B... Storage device, 13... Communication device, 14... Display, 15... Input device, 30... Terminal device, 31... Processing device, 32... Storage device, 33... Communication device, 34... Display, 35... Input device, 36... Imaging device, 111, 111B... Acquisition unit, 112, 112B... Image determination unit, 113, 113B... Image reception unit, 114, 114B... Matching unit, 115, 115B... Authentication unit, 116... Avatar Generation unit, 117...communication control unit, 118, 118A...request reception unit, 118A-1...first reception unit, 118A-2...second reception unit, 119...authentication deletion unit, 120, 120B...request determination unit, 120-1...first request determination unit, 120-2...second request determination unit, 120-3...criteria determination unit, 311...acquisition unit, 312...display control unit, 313...communication control unit, FU1, FU1B...functional unit, CP1...first confirmation image, CP2...second confirmation image, PR1, PR1A, PR1B, PR3...control program
Claims
1. an avatar generation unit that generates avatar data representing an avatar of a service user using a user image obtained by capturing an image of the service user who uses a service related to the avatar; an authentication unit that generates authentication data to be added to the avatar data when authenticating the avatar data; an authentication deletion unit that deletes the authentication data from the avatar data when a deletion condition is satisfied; a receiving unit that receives a deletion request from a terminal device to instruct the terminal device to delete the authentication data; an acquisition unit that acquires a verification image for verifying the identity of the service user from the terminal device; an image determination unit that determines whether the confirmation image is an image currently obtained by capturing an image of a terminal user of the terminal device; a matching unit that matches a person appearing in the confirmation image with a person appearing in the user image, The deletion condition is that the determination result of the image determination unit is positive and the matching result of the matching unit is positive. Avatar data authentication device.
2. An avatar generation unit that generates avatar data representing an avatar of a service user using a user image obtained by capturing an image of the service user using an avatar-related service; an authentication unit that generates authentication data to be added to the avatar data when authenticating the avatar data; an authentication deletion unit that deletes the authentication data from the avatar data when a deletion condition is satisfied; a first receiving unit that receives a deletion request from a terminal device to instruct the terminal device to delete the authentication data; a first request determination unit that determines whether the deletion request includes a compulsory instruction to forcibly delete the authentication data without the approval of the service user; Equipped with The deletion condition is at least that the determination result of the first request determination unit is affirmative. Avatar data authentication device.
3. a second receiving unit that receives a generation request from a terminal device to instruct the terminal device to generate the authentication data; a second request determination unit that determines whether the generation request includes a compulsory instruction to forcibly generate the authentication data without the service user's approval; Furthermore, the authentication unit generates the authentication data when the determination result of the second request determination unit is positive. The avatar data authentication device according to claim 2 .
4. the user image is acquired from an external device together with a verification image when the avatar data is generated; the user image is stored in a storage device together with the verification image; the authentication unit certifies that the avatar data is authentic if the verification image is an image obtained by capturing an image of a user of the external device and if a person appearing in the verification image is the same person as a person appearing in the user image; a reference determination unit that determines whether the confirmation image read from the storage device is an image obtained by capturing an image of a user of the external device, and that determines whether a person appearing in the confirmation image read from the storage device and a person appearing in the user image read from the storage device are the same person; at least one of a first determination criterion used to determine whether the confirmation image is an image obtained by capturing an image of a user of the external device and a second determination criterion used to determine whether a person appearing in the confirmation image and a person appearing in the user image are the same person is different between when the authentication unit authenticates the avatar data and when the criterion determination unit makes a determination; the deletion condition is that the determination result by the first request determination unit is positive and at least one of the two determination results by the reference determination unit is negative; The avatar data authentication device according to claim 2 .
Citation Information
Patent Citations
Biometric authentication system and its authentication means in dotcity
JP2007249317A
Information processor, information processing method, monitoring system and program
JP2007328590A
Creation editing method for avatar in network chat service, chat service system and creation editing method for image data
JP2009223419A
Disposal management system, disposal management method, and printing equipment
JP2019009740A
Information processing device, program, and image processing system
JP2022073172A