Usage control terminal, usage control method, and non-transitory computer-readable medium storing usage control program

By allowing users to retain biometric data locally and verifying user IDs against a database, the system addresses user reluctance, ensuring security and promoting biometric authentication through discounted services.

JP7779377B2Active Publication Date: 2025-12-03NEC CORP
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2024510803
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-29
Publication Date
2025-12-03
Estimated Expiration
2042-03-29

Smart Images

  • Figure 0007779377000001
    Figure 0007779377000001
  • Figure 0007779377000002
    Figure 0007779377000002
  • Figure 0007779377000003
    Figure 0007779377000003
Patent Text Reader

Abstract

A use control terminal (1) comprises: an acquisition unit (11) for acquiring, by a prescribed scheme of short-range wireless communication, a user ID and first biological information from a storage medium that a prescribed user carries and in which the user ID and first biological information of the user are stored; a preservation unit (12) for preserving the user ID and first biological information in association in a storage device; an authentication unit (13) for performing biometric authentication on the basis of second biological information extracted from an image in which the user is imaged and the first biological information preserved in the storage device; an identification unit (14) for identifying a user ID from the storage device that is associated with the first biological information that has successfully passed the biometric authentication; a determination unit (15) for referring to a database in which user IDs and qualification information regarding the use of services by the users are registered in association and determining whether or not the use of services by the user is possible, on the basis of the qualification information associated with the identified user ID; and an output unit (16) for outputting information that corresponds to the result of determination by the determination unit (15).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a usage control terminal, a system, a method, and a program, and a usage management server, a method, and a program. [Background technology]

[0002] With the improvement of facial recognition technology, it has become possible to determine whether or not a person can pass through a security gate by using facial recognition. Patent Document 1 discloses technology related to an automatic gate system that allows users to pass through a gate using facial recognition. Patent Document 2 discloses technology that allows users to pass through an automatic ticket gate using facial recognition. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2003-331323 [Patent Document 2] Patent Publication No. 2021-060775 Summary of the Invention [Problem to be solved by the invention]

[0004] In order for a specific person to receive various services, including passing through a gate, they must have the appropriate qualifications. Using biometric authentication to verify their identity makes it possible to accurately and easily determine whether they are qualified. However, many users are reluctant to have their biometric information used for biometric verification held by an external organization, and the benefits of using biometric authentication are difficult to convey, hindering the widespread adoption of biometric authentication.

[0005] In view of the above-mentioned problems, the purpose of the present disclosure is to provide a usage control terminal, system, method, and program, as well as a usage management server, method, and program, for promoting the spread of service use using biometric authentication. [Means for solving the problem]

[0006] The usage control terminal according to the present disclosure includes: an acquisition means carried by a predetermined user and configured to acquire the user ID and the first biometric information of the user from a storage medium storing the user ID and the first biometric information of the user by a predetermined method of short-range wireless communication; a storage means for storing the user ID and the first biometric information in a storage device in association with each other; an authentication means for performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; an identification means for identifying, from the storage device, a user ID associated with the first biometric information that has been successfully biometrically authenticated; a determination means for referring to a database in which the user ID and the user's qualification information for using the service are registered in association with each other, and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; an output means for outputting information according to the determination result by the determination means; Equipped with.

[0007] The usage control system according to the present disclosure includes: a database in which the user ID of a predetermined user is registered in association with the user's qualification information for using a service; a usage control terminal capable of short-range wireless communication using one or more methods; Equipped with The usage control terminal an acquisition means carried by the user and configured to acquire the user ID and the first biometric information from a storage medium storing the user ID and the first biometric information by a predetermined method of short-range wireless communication; a storage means for storing the user ID and the first biometric information in a storage device in association with each other; an authentication means for performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; an identification means for identifying, from the storage device, a user ID associated with the first biometric information that has been successfully biometrically authenticated; a determination means for referring to the database and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; an output means for outputting information according to the determination result by the determination means; Equipped with.

[0008] The usage control method according to the present disclosure includes: The computer acquiring the user ID and the first biometric information from a storage medium carried by a predetermined user and storing the user ID and the first biometric information of the user, by a predetermined method of short-range wireless communication; storing the user ID and the first biometric information in association with each other in a storage device; performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; Identifying, from the storage device, a user ID associated with the first biometric information that has been successfully authenticated; referencing a database in which the user ID and the user's qualification information for using a service are registered in association with each other, and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; Information according to the result of the determination by the determining means is output.

[0009] The usage control program according to the present disclosure includes: an acquisition process of acquiring the user ID and the first biometric information of the user from a storage medium carried by a predetermined user and storing the user ID and the first biometric information of the user, by a predetermined method of short-range wireless communication; a storage process of storing the user ID and the first biometric information in a storage device in association with each other; an authentication process for performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; an identification process for identifying, from the storage device, a user ID associated with the first biometric information that has been successfully authenticated; a determination process of referring to a database in which the user ID and the user's qualification information for using the service are registered in association with each other, and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; an output process for outputting information according to the determination result by the determination means; to be executed by the computer.

[0010] The usage management server according to the present disclosure includes: a calculation means for calculating a discounted usage fee for a predetermined service based on attribute information of a predetermined user when an electronic application for use of the predetermined service including a user ID corresponding to first biometric information of the predetermined user is received; a registration means for registering the user ID and the qualification information for using the service in a database in association with each other when the user has paid the usage fee; a response means for, when receiving from the usage control terminal of the service a user ID identified by the user having succeeded in biometric authentication based on the first biometric information, referring to the database and making a response to the usage control terminal based on the qualification information associated with the received user ID; Equipped with.

[0011] The usage management method according to the present disclosure includes: The computer When an electronic application for use of a predetermined service including a user ID corresponding to the first biometric information of a predetermined user is received, a discounted usage fee for the service is calculated based on attribute information of the user; When the user has paid the usage fee, the user ID is associated with the qualification information for using the service and registered in a database; When the service usage control terminal receives a user ID identified by the user having successfully passed biometric authentication based on the first biometric information, the database is referenced and a response based on the qualification information associated with the received user ID is sent to the usage control terminal.

[0012] The usage management program disclosed herein is a calculation process for calculating a discounted usage fee for a predetermined service based on attribute information of a predetermined user when an electronic application for use of the predetermined service including a user ID corresponding to first biometric information of the predetermined user is received; a registration process for registering the user ID and the qualification information for using the service in a database in association with each other when the user has paid the usage fee; a response process for, when receiving from the usage control terminal of the service a user ID identified by the user having succeeded in biometric authentication based on the first biometric information, referring to the database and sending a response based on the qualification information associated with the received user ID to the usage control terminal; to be executed by the computer. [Effects of the Invention]

[0013] The present disclosure makes it possible to provide a usage control terminal, a system, a method, and a program, as well as a usage management server, a method, and a program, for promoting the widespread use of services that use biometric authentication. [Brief explanation of the drawings]

[0014] [Figure 1] FIG. 2 is a block diagram showing the configuration of a usage control terminal according to the first embodiment. [Figure 2] 1 is a flowchart showing the flow of a usage control method according to the first embodiment. [Figure 3] FIG. 10 is a block diagram showing the configuration of a usage management server according to the second embodiment. [Figure 4]10 is a flowchart showing the flow of a usage management method according to the second embodiment. [Figure 5] FIG. 10 is a block diagram showing the configuration of a usage control system according to a third embodiment. [Figure 6] FIG. 10 is a block diagram showing the configuration of a contactless IC card according to a third embodiment. [Figure 7] FIG. 11 is a block diagram showing the configuration of a user terminal according to the third embodiment. [Figure 8] FIG. 11 is a block diagram showing the configuration of a usage management server according to a third embodiment. [Figure 9] FIG. 11 is a block diagram showing the configuration of an edge terminal according to the third embodiment. [Figure 10] FIG. 11 is a sequence diagram showing the flow of face information registration processing according to the third embodiment. [Figure 11] 13A to 13C are diagrams illustrating an example of screen transitions in the face information registration process on the user terminal according to the third embodiment. [Figure 12] FIG. 11 is a sequence diagram showing the flow of electronic application processing according to the third embodiment. [Figure 13] FIG. 11 is a diagram showing an example of screen transitions in a ticket purchasing process on a user terminal according to the third embodiment. [Figure 14] FIG. 10 is a diagram for explaining the concept of an entrance process using a user terminal according to Example 3-1 of the third embodiment. [Figure 15] FIG. 10 is a sequence diagram showing the flow of an entrance process using a user terminal according to Example 3-1 of the third embodiment. [Figure 16] FIG. 10 is a diagram showing an example of screen transitions in the entrance process on the user terminal according to Example 3-1 of the present embodiment 3. [Figure 17] FIG. 10 is a diagram for explaining the concept of entrance processing using a contactless IC card according to Example 3-2 of the third embodiment. [Figure 18] FIG. 10 is a sequence diagram showing the flow of an entrance process using a contactless IC card according to Example 3-2 of the third embodiment. [Figure 19]FIG. 11 is a diagram showing an example of display of guidance information for a short-range wireless communication method on an edge terminal according to the third embodiment. [Figure 20] FIG. 11 is a diagram showing an example of display of short-range wireless communication methods that can be supported by each edge terminal according to the third embodiment. [Figure 21] FIG. 10 is a diagram for explaining the concept of the reserved seat ticket confirmation process by the conductor according to the fourth embodiment. [Figure 22] FIG. 11 is a sequence diagram showing the flow of a reserved seat ticket confirmation process by a conductor according to the fourth embodiment. [Figure 23] 13A to 13C are diagrams showing an example of screen transitions in the process of writing characteristic information into a contactless IC card according to the fifth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0015] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In each drawing, the same or corresponding elements are designated by the same reference numerals, and for clarity of explanation, duplicate explanations will be omitted as necessary.

[0016] <Embodiment 1> Fig. 1 is a block diagram showing the configuration of a usage control terminal 1 according to the first embodiment. The usage control terminal 1 is an information processing device that determines whether a predetermined user is qualified to use a predetermined service using biometric authentication, and performs control according to the service if it is determined that the user is qualified. Use of a predetermined service means, for example, entering a facility or floor with admission restrictions, or receiving a paid service such as watching a movie. The predetermined service may also be a free service.

[0017] It is assumed that a specific user carries a storage medium. Here, the storage medium stores the user's user ID and first biometric information. The storage medium may be, for example, a storage device built into a portable information terminal such as a smartphone or a tablet terminal. Alternatively, the storage medium may be built into a contactless IC (Integrated Circuit) card. The information terminal or the contactless IC card is capable of communicating using a specific method of short-range wireless communication and is capable of transmitting the user ID and first biometric information stored in the storage medium using that method. Note that the information terminal or the contactless IC card may support two or more methods of short-range wireless communication. Furthermore, the first biometric information is associated with the user ID in the storage medium. The "biometric information" is data including a plurality of feature points extracted from an image capturing at least a part of the user's body and the distances between the feature points.

[0018] The usage control terminal 1 includes an acquisition unit 11, a storage unit 12, an authentication unit 13, an identification unit 14, a determination unit 15, and an output unit 16. The acquisition unit 11 acquires a user ID and first biometric information from a storage medium carried by a predetermined user using a predetermined method of short-range wireless communication.

[0019] The saving unit 12 associates the user ID and the first biometric information acquired by the acquiring unit 11 and saves them in a storage device. Here, the storage device may be either one built into the usage control terminal 1 or an external storage device connected to the usage control terminal 1.

[0020] The authentication unit 13 performs biometric authentication based on the second biometric information extracted from the captured image of the user and the first biometric information stored in the storage device. Specifically, the authentication unit 13 compares the second biometric information with the first biometric information to calculate the degree of match, and determines that the biometric authentication has been successful if the degree of match is equal to or greater than a threshold.

[0021] The identification unit 14 identifies, from the storage device, the user ID associated with the first biometric information that has been successfully biometrically authenticated by the authentication unit 13.

[0022] The determination unit 15 determines whether a user can use a service based on the user's qualification information for using the service. The qualification information here refers to information proving whether the user is qualified to use the service or that the fee for the paid service has been paid. For example, the qualification information may be ticket information for a paid service. The usage control terminal 1 is connected to a database. The database is configured to store user IDs and user qualification information for using the service in advance, in association with each other. The usage control terminal 1 then refers to the database and determines whether the user can use the service based on the qualification information associated with the user ID identified by the identification unit 14. For example, if the database contains qualification information associated with the user ID, the determination unit 15 may determine that the user can use the service. Alternatively, if the qualification information associated with the user ID satisfies a predetermined condition, the determination unit 15 may determine that the user can use the service. The database may be managed by a predetermined server. The determination unit 15 may then transmit the user ID to the server to inquire about the user's availability. In this case, the server may refer to a database to search for the qualification information associated with the received user ID, and determine whether the service can be used based on whether the qualification information is found or whether the qualification information satisfies a predetermined condition. In this case, the server may return the determination result to the usage control terminal 1. Then, the determination unit 15 determines whether the user can use the service based on the received determination result.

[0023] The output unit 16 outputs information according to the determination result by the determination unit 15. For example, the output unit 16 may output the determination result itself. Alternatively, the output unit 16 may output a control signal for another device according to the determination result. Alternatively, the output unit 16 may output information according to the determination result to a user terminal or an administrator terminal.

[0024] 2 is a flowchart showing the flow of the usage control method according to the first embodiment. First, the acquisition unit 11 acquires a user ID and first biometric information from a storage medium carried by a predetermined user using a predetermined method of short-range wireless communication (S11). That is, when the user carrying the storage medium enters the range of the usage control terminal 1 using the predetermined method of short-range wireless communication, the data in the storage medium is transferred to the usage control terminal 1 using the predetermined method.

[0025] Next, the storage unit 12 associates the user ID with the first biometric information and stores them in the storage device (S12). Then, for a user within range of short-range wireless communication of a predetermined method, an area including the face is photographed by a camera built into the usage control terminal 1 or a camera connected to the usage control terminal 1. The authentication unit 13 performs biometric authentication based on the second biometric information extracted from the photographed image of the user and the first biometric information stored in the storage device (S13).

[0026] Here, it is assumed that the biometric authentication has been successful. Therefore, the identification unit 14 identifies, from the storage device, the user ID associated with the first biometric information for which the biometric authentication has been successful (S14). Then, the determination unit 15 refers to the database and determines whether the user is permitted to use the service based on the qualification information associated with the user ID identified in step S14 (S15). Then, the output unit 16 outputs information according to the determination result in step S15 (S16).

[0027] As described above, in this embodiment, the user side retains at least the user ID and their own biometric information, and the user ID and qualification information are stored in advance in a database on the service provider side. In other words, by separating the management of the biometric information and the qualification information, it is not necessary to provide the biometric information to the service provider side. Then, when using a service, a pair of the user ID and biometric information is transferred from a storage medium carried by the user to the usage control terminal 1 via short-range wireless communication, and the usage control terminal 1 at least temporarily stores the pair of the user ID and biometric information in a storage device. Then, the usage control terminal 1 simultaneously captures a facial image of the user. Then, the usage control terminal 1 can perform biometric authentication based on the first biometric information stored in the storage device and the second biometric information extracted from the facial image. Then, if the biometric authentication is successful, the qualification information associated with the user ID can be identified from the database on the service provider side and whether or not the user is allowed to use the service can be determined. As a result, the security of the storage of biometric information can be ensured, and concerns about an external institution holding biometric information used for biometric authentication matching can be alleviated. This can promote the widespread use of services using biometric authentication.

[0028] The usage control terminal 1 includes a processor, a memory, and a storage device (not shown). The storage device stores a computer program that implements the processing of the usage control method according to this embodiment. The processor then loads the computer program from the storage device into the memory and executes the computer program. This allows the processor to implement the functions of an acquisition unit 11, a storage unit 12, an authentication unit 13, an identification unit 14, a determination unit 15, and an output unit 16.

[0029] Alternatively, each component of the usage control terminal 1 may be realized by dedicated hardware. Furthermore, some or all of the components of each device may be realized by general-purpose or dedicated circuits, processors, etc., or a combination of these. These may be configured by a single chip, or by multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-mentioned circuits, etc., and programs. Furthermore, a CPU (Central Processing Unit), GPU (Graphics Processing Unit), FPGA (Field-Programmable Gate Array), quantum processor (quantum computer control chip), etc., may be used as the processor.

[0030] <Embodiment 2> FIG. 3 is a block diagram showing the configuration of the usage management server 2 according to the second embodiment. The usage management server 2 is an information processing device that calculates the usage fee for using a predetermined service according to the attribute information of a predetermined user, registers the user's qualification information in a database, and responds by referring to the database when a service usage request is made. Here, the attribute information includes the user's age (date of birth), gender, identification information, etc. The identification information is, for example, certification information on disability or care level issued by a public institution, information equivalent to a student ID, etc. The database is the same as that of the first embodiment described above, and is pre-registered in association with the user ID and the user's qualification information for using the service. The usage management server 2 may have the database built-in, or may be connected to an external database server or storage device that manages the database.

[0031] The usage management server 2 includes a calculation unit 21, a registration unit 22, and a response unit 23. When the calculation unit 21 receives an electronic application for use of a predetermined service including a user ID corresponding to the first biometric information of a predetermined user, the calculation unit 21 calculates a discounted usage fee for the service based on the attribute information of the user. For example, when the attribute information indicates an elderly person, a person with a disability, a student, etc., the calculation unit 21 calculates a usage fee that takes into account a discount according to each attribute.

[0032] When the user has paid the usage fee, the registration unit 22 associates the user ID with the qualification information for using the service and registers them in the database.

[0033] When the response unit 23 receives a user ID from the usage control terminal of the service, it refers to the database and sends a response to the usage control terminal based on the qualification information associated with the received user ID. Here, the usage control terminal may be, for example, the usage control terminal 1 of the first embodiment described above. The user ID received by the response unit 23 is identified when the user successfully undergoes biometric authentication based on the first biometric information at the usage control terminal. The response unit 23 may transmit a determination result, based on the qualification information, as a response to the usage control terminal, as to whether the user is permitted to use the service. Alternatively, the response unit 23 may read the qualification information associated with the received user ID from the database and send the read qualification information as a response to the usage control terminal.

[0034] 4 is a flowchart showing the flow of the usage management method according to the present embodiment 2. First, when the calculation unit 21 receives an electronic application for using a predetermined service including a user ID corresponding to the first biometric information of a predetermined user, the calculation unit 21 calculates a discounted usage fee for the service based on the attribute information of the user (S21).

[0035] Next, when the user has paid the usage fee, the registration unit 22 associates the user ID with the qualification information for using the service and registers them in the database (S22).

[0036] Thereafter, the response unit 23 receives from the usage control terminal a user ID identified when the user has succeeded in biometric authentication based on the first biometric information. When the response unit 23 receives the user ID from the usage control terminal of the service, it refers to the database and sends a response to the usage control terminal based on the qualification information associated with the received user ID (S23).

[0037] In this way, in this embodiment, by allowing users to receive a discount on usage fees based on attribute information when applying electronically, it becomes easier to communicate the benefits of using biometric authentication and promotes the widespread use of services that use biometric authentication.

[0038] The usage management server 2 includes a processor, a memory, and a storage device (not shown). The storage device stores a computer program that implements the processing of the usage management method according to this embodiment. The processor then loads the computer program from the storage device into the memory and executes the computer program. This allows the processor to implement the functions of a calculation unit 21, a registration unit 22, and a response unit 23.

[0039] Alternatively, each component of the usage management server 2 may be realized by dedicated hardware. Furthermore, some or all of the components of each device may be realized by general-purpose or dedicated circuits, processors, etc., or a combination of these. These may be configured by a single chip, or by multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-mentioned circuits, etc., and programs. Furthermore, a CPU (Central Processing Unit), GPU (Graphics Processing Unit), FPGA (Field-Programmable Gate Array), quantum processor (quantum computer control chip), etc., may be used as the processor.

[0040] Furthermore, when some or all of the components of the usage management server 2 are realized by multiple information processing devices, circuits, etc., the multiple information processing devices, circuits, etc. may be centrally or decentralized. For example, the information processing devices, circuits, etc. may be realized as a client-server system, a cloud computing system, or the like, each connected via a communication network. Furthermore, the functions of the usage management server 2 may be provided in a SaaS (Software as a Service) format.

[0041] <Embodiment 3> The third embodiment is a specific example of the first and second embodiments described above. FIG. 5 is a block diagram showing the configuration of an access control system 1000 according to the third embodiment. The access control system 1000 is an information system that allows a user U who has purchased a movie ticket in advance via a website to pass through the entrance gate of a movie theater using facial recognition and credential information. Note that entering a movie theater and watching a movie after entering are examples of using a predetermined service. Examples of using other services include, but are not limited to, checking in at an airport, checking in baggage, passing through a boarding gate, using transportation such as a train, bus, or ship, and using various services at preferential rates.

[0042] A user U carries a user terminal 101. The user terminal 101 has a built-in storage medium 100-1 and is capable of communicating using one or more short-range wireless communication methods. The storage medium 100-1 stores a user ID 1111 and facial feature information 1112. The detailed configuration of the user terminal 101 will be described later.

[0043] In the usage control system 1000, the edge terminal 200, the authentication infrastructure system 400, and the usage management server 500 are communicatively connected to each other via a network N. The entrance control device 300 may also be communicatively connected to the network N. Here, the network N is a wired or wireless communication line or communication network, such as a LAN (Local Area Network), the Internet, a wireless communication network, a mobile phone network, etc. Furthermore, the network N may use any type of communication protocol.

[0044] The edge terminal 200 is an example of the above-mentioned usage control terminal 1. The edge terminal 200 acquires a user ID 1111 and facial feature information 1112 from the user terminal 101 via a short-range wireless communication IF (Interface) 231 using a predetermined short-range wireless communication method. The edge terminal 200 may also acquire the user ID 1111 and facial feature information 1112 from a contactless IC card 102 (described later). The edge terminal 200 associates the acquired user ID 2111 and facial feature information 2112 and stores them as user information 211 in a built-in storage device. The edge terminal 200 also photographs the user U using the camera 260 and performs facial authentication by comparing facial feature information extracted from the facial image with the facial feature information 2112. If the facial authentication is successful, the edge terminal 200 transmits the user ID 2111 to the usage management server 500 via the network N, determines whether the user is eligible to enter the movie theater, and controls the admission control device 300 according to the determination result. For example, if the determination result indicates that the user U is qualified (allowed to use the movie theater, allowed to watch a movie, etc.), the edge terminal 200 controls the entrance control device 300 to open the gate 301. The detailed configuration of the edge terminal 200 will be described later.

[0045] The entrance control device 300 is a device for controlling the opening and closing of a gate 301, which is an entrance to the movie theater, in response to instructions from the edge terminal 200. The gate 301 is not limited to a flapper gate.

[0046] The authentication infrastructure system 400 is an information system that extracts facial feature information from a facial image of a user U and issues a user ID corresponding to the facial feature information. The authentication infrastructure system 400 may have a database that associates facial feature information with user IDs.

[0047] The usage management server 500 is an example of the above-mentioned usage management server 2. The usage management server 500 is an information processing device that includes a usage management DB 512 that associates a user ID 5121 of a user U with qualification information 5122. The usage management DB 512 may be managed outside the usage management server 500, that is, by a database server or storage device connected to the usage management server 500.

[0048] FIG. 6 is a block diagram showing the configuration of a contactless IC card 102 according to the third embodiment. The contactless IC card 102 corresponds to a digital identification card of a user U. The contactless IC card 102 includes a storage medium 100-2, a short-range wireless communication IF 1021, and an RW (Reader-Writer) control unit 1022. The contactless IC card 102, including the storage medium 100-2, the short-range wireless communication IF 1021, and the RW control unit 1022, has a so-called IC chip built in and can be considered as an IC tag capable of communicating by a predetermined short-range wireless communication method. The storage medium 100-2 stores a user ID 1111, facial feature information 1112, and attribute information 1113 in association with each other. The user ID 1111 is identification information of the user U and may be the same as the ID (such as a My Number) in the digital identification card. However, the user ID 1111 may be different from the ID in the digital identification card, but must at least be associated with facial feature information 1112 and must be identical to or uniquely correspond to the user ID 5121 managed in the usage management DB 512. The facial feature information 1112 is data including multiple feature points extracted from the facial image of the user U by the authentication infrastructure system 400 and the distances between the feature points, in other words, feature amounts calculated from the facial image. In the following description, the above-mentioned storage medium 100-1 and storage medium 100-2 may be collectively referred to as "storage medium 100."

[0049] The short-distance wireless communication IF 1021 establishes a connection and performs communication with an IF of another device of the same type within a predetermined range by a short-distance wireless communication method Y. The short-distance wireless communication IF 1021 may be realized by an antenna, an interface circuit, etc. The method Y may correspond to a standard or method such as, for example, NFC (Near Field Communication) or RFID (Radio Frequency IDentification), but is not limited to these.

[0050] The RW control unit 1022 performs wireless communication between the IC tag on the contactless IC card 102 and a reader / writer device capable of short-range wireless communication in method Y. Specifically, when the contactless IC card 102 enters the communication range of the reader / writer of method Y of the edge terminal 200, the RW control unit 1022 performs communication with the edge terminal 200 in method Y via the short-range wireless communication IF 1021. That is, the RW control unit 1022 reads out the user ID 1111 and the facial feature information 1112 from the storage medium 100-2, and transmits the user ID 1111 and the facial feature information 1112 to the edge terminal 200 via the short-range wireless communication IF 1021.

[0051] FIG. 7 is a block diagram showing the configuration of a user terminal 101 according to the third embodiment. The user terminal 101 is a mobile information processing device such as a tablet terminal or a smartphone. The user terminal 101 includes a storage unit 110, a memory 120, a communication unit 130, a control unit 140, a display unit 150, and a camera 160. The storage unit 110 includes the storage medium 100-1 described above and is an example of a storage device such as a flash memory. The storage unit 110 stores user information 111, payment information 112, and a program 113. The user information 111 is information that associates a user ID 1111 of a user U with facial feature information 1112. The payment information 112 is information used by the user U to make an electronic payment. The payment information 112 is, for example, bank account information, credit card information, etc. Note that the payment information 112 does not necessarily have to be stored in the storage unit 110. The program 113 is a computer program in which face information registration processing, electronic application processing (ticket purchase processing), various information display processing, and the like according to the second embodiment are implemented.

[0052] The memory 120 is a volatile storage device such as a random access memory (RAM), and serves as a storage area for temporarily storing information when the control unit 140 is operating. The communication unit 130 is a wireless communication interface with the network N. The communication unit 130 may be connected to the Internet via a wireless communication network or a mobile phone network. The communication unit 130 is capable of wireless communication using multiple short-range wireless communication methods. Specifically, the communication unit 130 includes short-range wireless communication IFs 131 and 132. The short-range wireless communication IF 131 establishes a connection and communicates with an IF of another device using the same method within a predetermined range using a short-range wireless communication method X. The method X may correspond to, for example, a standard or method such as Bluetooth (registered trademark) or Bluetooth Low Energy (BLE), but is not limited to these. The short-range wireless communication IF 132 establishes a connection and communicates with an IF of another device using the same method within a predetermined range using a short-range wireless communication method Y. The method Y is the same method as the short-range wireless communication IF 1021 described above.

[0053] Display unit 150 is a screen such as a liquid crystal display or an organic electro-luminescence (EL) display. Display unit 150 displays information instructed by control unit 140. Camera 160 is one or more imaging devices that capture images of user U's face or the like in response to an operation by user U or an instruction from control unit 140, outputs the captured image to control unit 140, and also displays the image on display unit 150.

[0054] The control unit 140 is a processor, i.e., a control device, that controls each component of the user terminal 101. The control unit 140 loads the program 113 from the storage unit 110 into the memory 120 and executes the program 113. In this way, the control unit 140 realizes the functions of a registration unit 141, a purchase unit 142, a confirmation unit 143, and a short-range wireless transmission / reception unit 144.

[0055] The registration unit 141 performs a facial information registration process for the user U. The registration unit 141 controls the camera 160 in response to an operation by the user U to capture an image of the user U's face. The registration unit 141 transmits the facial image of the user U to the authentication infrastructure system 400 via the network N, and receives facial feature information extracted by the authentication infrastructure system 400 and the issued user ID. The registration unit 141 associates the received user ID 1111 with the facial feature information 1112 and stores them in the storage unit 110 as user information 111. The registration unit 141 also transmits the attribute information read from the contactless IC card 102 by the short-range wireless transmission / reception unit 144 and the received user ID to the usage management server 500 via the network N, and receives a notification of completion of registration to the usage management DB 512.

[0056] The purchasing unit 142 performs electronic application processing (ticket purchasing processing). In this example, the purchasing unit 142 transmits reservation information for movie tickets, transmits payment information for the usage fee, and accepts reservation completion.

[0057] The confirmation unit 143 accepts input of a personal identification number for the contactless IC card 102 from the user U, and outputs the personal identification number to the short-range wireless transceiver 144. The confirmation unit 143 also acquires attribute information from the contactless IC card 102 via the short-range wireless transceiver 144. The confirmation unit 143 may also generate code information corresponding to the user ID 1111 and display it on the display unit 150. The confirmation unit 143 may also acquire ticket information, etc. corresponding to the reservation information from the usage management server 500 and display it on the display unit 150.

[0058] The short-range wireless transceiver 144 performs wireless communication with a reader / writer device capable of short-range wireless communication in scheme X and scheme Y. Specifically, when the user terminal 101 with scheme X turned on enters the communication range of the reader / writer of scheme X in the edge terminal 200, the short-range wireless transceiver 144 communicates with the edge terminal 200 via the short-range wireless communication IF 131 in scheme X. That is, the short-range wireless transceiver 144 reads out the user ID 1111 and facial feature information 1112 from the storage unit 110 and transmits the user ID 1111 and the facial feature information 1112 to the edge terminal 200 via the short-range wireless communication IF 131. Furthermore, when the user terminal 101 with scheme Y turned on enters the communication range of the reader / writer of scheme Y in the edge terminal 200, the short-range wireless transceiver 144 communicates with the edge terminal 200 via the short-range wireless communication IF 132 in scheme Y. or When the contactless IC card 102 is held over the user terminal 101 in which scheme Y is ON, that is, when the contactless IC card 102 comes within the communication range of the short-range wireless communication IF 132, the short-range wireless transmitting / receiving unit 144 communicates with the contactless IC card 102. For example, the short-range wireless transmitting / receiving unit 144 outputs a personal identification number to the contactless IC card 102 via the short-range wireless communication IF 132 to perform authentication. When authentication of the personal identification number by the contactless IC card 102 is successful, the short-range wireless transmitting / receiving unit 144 acquires attribute information 1113 from the contactless IC card 102.

[0059] 8 is a block diagram showing the configuration of the usage management server 500 according to the third embodiment. The usage management server 500 may be configured redundantly with multiple servers, and each functional block may be implemented by multiple computers. The usage management server 500 includes a storage unit 510, a memory 520, a communication unit 530, and a control unit 540. The storage unit 510 is an example of a storage device such as a hard disk or flash memory. The storage unit 510 stores a program 511 and a usage management DB 512. The program 511 is a computer program (usage management program) that implements processing for registering and updating the usage management DB, search processing, processing related to the availability of services, and the like.

[0060] The usage management DB 512 is a database that associates and manages a user ID 5121, qualification information 5122, attribute information 5123, usage fee 5124, and usage history 5125. The user ID 5121 is assumed to be identical to or uniquely correspond to the above-mentioned user ID 1111. The qualification information 5122 is information that proves whether a user corresponding to the user ID 5121 is qualified to use a service, or that the usage fee for a paid service has been paid. The qualification information 5122 is information issued based on the attribute information 5123. The qualification information 5122 according to this embodiment is movie ticket information, but is not limited to this. The attribute information 5123 is information that corresponds to the above-mentioned attribute information 1113. The usage fee 5124 is a paid amount calculated taking into account the attribute information 5123. The usage history 5125 is history information regarding the use of a service. The usage history 5125 includes, for example, the actual date and time of service usage, the location, and the type of short-range wireless communication by which the edge terminal 200 acquired the facial feature information.

[0061] The memory 520 is a volatile storage device such as a RAM, and is a storage area for temporarily storing information during operation of the control unit 540. The communication unit 530 is a communication interface with the network N.

[0062] The control unit 540 is a processor, i.e., a control device, that controls each component of the usage management server 500. The control unit 540 loads the program 511 from the storage unit 510 into the memory 520 and executes the program 511. As a result, the control unit 540 realizes the functions of a registration unit 541, a calculation unit 542, a payment processing unit 543, a reservation processing unit 544, and a response unit 545.

[0063] The registration unit 541 is an example of the above-mentioned registration unit 22. The registration unit 541 receives a user ID and attribute information from the user terminal 101, associates the received user ID 5121 with the attribute information 5123, and registers them in the usage management DB 512. Here, the user terminal 101 transmits the user ID and the attribute information to the usage management server 500 when the attribute information 1113 of the user U is read from the first storage medium 100-2 in which the attribute information 1113 is stored as a result of successful authentication (using a PIN or the like).

[0064] Furthermore, when the user U has paid the usage fee, the registration unit 541 associates the user ID 5121 with the qualification information 5122 for using the service and registers them in the usage management DB 512. Furthermore, when the user U uses the service, for example, if it is determined that the service is available, the registration unit 541 associates the user ID 5121 with the usage history 5125 and registers them in the usage management DB 512.

[0065] The calculation unit 542 is an example of the above-mentioned calculation unit 21. When the calculation unit 542 receives an electronic application for use of a predetermined service, including a user ID, from the user terminal 101, the calculation unit 542 calculates a discounted usage fee for the service based on the attribute information of the user U. Note that the received user ID corresponds to the first biometric information 1112 of the user U, as described above. In particular, the calculation unit 542 may identify attribute information 5123 associated with the user ID 5121 included in the electronic application from the usage management DB 512, and calculate the usage fee for the service based on the identified attribute information 5123.

[0066] The payment processing unit 543 performs payment processing for the usage fee based on the payment information received from the user terminal 101.

[0067] The reservation processing unit 544 makes a provisional reservation based on the reservation information included in the electronic application. Furthermore, when the payment processing unit 543 has performed payment processing for the usage fee, the reservation processing unit 544 issues qualification information as a reservation confirmation process.

[0068] The response unit 545 is an example of the response unit 23 described above. When the response unit 545 receives a user ID from the edge terminal 200, it refers to the usage management DB 512 and sends a response to the edge terminal 200 based on the qualification information 5122 associated with the received user ID 5121. Here, the user ID received by the response unit 545 is identified when the edge terminal 200 successfully performs biometric authentication of the user U based on the first biometric information. The edge terminal 200 acquires the user ID and the first biometric information from the second storage medium using a predetermined method of short-range wireless communication, and performs biometric authentication based on the second biometric information extracted from an image of the user U and the first biometric information. The second storage medium is carried by the user U and stores the user ID and the first biometric information, and is, for example, the storage medium 100 described above.

[0069] In response to the request, the response unit 545 may return to the request source the short-range wireless communication methods that each of the edge terminals 200 can support. For example, when the response unit 545 receives the request from the user terminal 101, it returns to the user terminal 101 the short-range wireless communication methods that each edge terminal 200 can support.

[0070] The response unit 545 may also identify the qualification information 5122 associated with the received user ID 5121 from the usage management DB 512, and return the identified qualification information 5122 as a response to the edge terminal 200. Alternatively, the response unit 545 may refer to the usage management DB 512, determine whether or not the service is available based on the qualification information 5122 associated with the received user ID 5121, and return the determination result as a response to the edge terminal 200.

[0071] FIG. 9 is a block diagram showing the configuration of an edge terminal 200 according to the third embodiment. The edge terminal 200 is an information processing device connected to the entrance control device 300. The edge terminal 200 may be a tablet terminal or the like. The edge terminal 200 includes a storage unit 210, a memory 220, a communication unit 230, a control unit 240, a display unit 250, a camera 260, a human presence sensor 270, and a reading unit 280. The storage unit 210 is an example of a storage device such as a flash memory. The storage unit 210 stores user information 211, a usage history 212, and a program 213. The user information 211 is information in which a user ID 2111 and facial feature information 2112, which are acquired from the storage medium 100 by a predetermined method of short-range wireless communication, are associated with each other. The usage history 212 is history information on the use of the edge terminal 200 and the entrance control device 300. The usage history 212 is information that associates, for example, a date and time 2121, a user ID 2122, a wireless method 2123, and a determination result 2124. The date and time 2121 is the date and time when face authentication was successful. The user ID 2122 is the user ID identified by successful face authentication. The wireless method 2123 is the method of short-range wireless communication by which the user ID 2111 and the facial feature information 2112 were acquired. The determination result 2124 is the result of determination as to whether the service can be used. The program 213 is a computer program (usage control program) in which the usage control processing etc. according to the second embodiment are implemented.

[0072] It is sufficient that the storage unit 210 stores at least the program 213. Therefore, both or one of the user information 211 and the usage history 212 may be saved in an external storage device connected to the edge terminal 200. Furthermore, the memory 220 may store both or one of the user information 211 and the usage history 212.

[0073] The memory 220 is a volatile storage device such as RAM, and is a storage area for temporarily storing information when the control unit 240 is operating. The communication unit 230 is a communication interface with the network N. The communication unit 230 may also be connected to the network N via wired or wireless communication. The communication unit 230 is also a communication interface with the entrance control device 300.

[0074] Furthermore, the communication unit 230 is capable of wireless communication using a plurality of short-range wireless communication methods. Specifically, the communication unit 230 includes short-range wireless communication IFs 231 and 232. The short-range wireless communication IF 231 establishes a connection with an IF of another device using the same method within a predetermined range by using short-range wireless communication method X, and performs communication. Method X is the same method as the short-range wireless communication IF 131 described above. The short-range wireless communication IF 232 establishes a connection with an IF of another device using the same method within a predetermined range by using short-range wireless communication method Y, and performs communication. Method Y is the same method as the short-range wireless communication IF 1021 and the short-range wireless communication IF 132 described above.

[0075] The display unit 250 is a screen such as a liquid crystal display or an organic electroluminescence (EL) display. The display unit 250 displays information instructed by the control unit 240. The camera 260 is one or more imaging devices that captures an image of the face of the user U in response to detection by the human presence sensor 270, outputs the captured image to the control unit 240, and displays the image on the display unit 250. The human presence sensor 270 is a sensor that detects a person within a predetermined range, and when detected, outputs a signal to the camera 260 to that effect. The reading unit 280 is a wireless communication transmitter / receiver via the near-field wireless communication IF 132 according to near-field wireless communication method Y. For example, when the contactless IC card 102 is present within the communication range of method Y, the reading unit 280 reads data from the contactless IC card 102 according to method Y.

[0076] The control unit 240 is a processor, i.e., a control device, that controls each component of the edge terminal 200. The control unit 240 loads the program 213 from the storage unit 210 into the memory 220 and executes the program 213. In this way, the control unit 240 realizes the functions of an acquisition unit 241, a storage unit 242, an authentication unit 243, an identification unit 244, a determination unit 245, and an output unit 246.

[0077] The acquisition unit 241 is an example of the acquisition unit 11 described above. The acquisition unit 241 acquires a user ID and first biometric information from a storage medium 100 carried by a user U using a predetermined short-range wireless communication method. In particular, the acquisition unit 241 is in standby mode with acquisition enabled using each of a plurality of short-range wireless communication methods. That is, the acquisition unit 241 is in standby mode with short-range wireless communication methods X and Y turned on and with wireless communication established and communication enabled using both the short-range wireless communication IFs 231 and 232. Therefore, when the user terminal 101 with method X enabled enters the communication range of the short-range wireless communication IF 231, the acquisition unit 241 acquires the user ID 1111 and facial feature information 1112 from the storage medium 100-1 using method X via the short-range wireless communication IF 231. Furthermore, when the user terminal 101 with method Y enabled enters the communication range of the short-range wireless communication IF232, the acquisition unit 241 acquires the user ID 1111 and the facial feature information 1112 from the storage medium 100-1 by method Y via the short-range wireless communication IF232. That is, the acquisition unit 241 acquires the user ID and the first biometric information by short-range wireless communication with the user terminal 101 by method X or Y. Furthermore, when the contactless IC card 102 enters the communication range of the short-range wireless communication IF232, the acquisition unit 241 acquires the user ID 1111 and the facial feature information 1112 from the storage medium 100-1 by method Y via the short-range wireless communication IF232. That is, the acquisition unit 241 acquires the user ID and the first biometric information by short-range wireless communication with the contactless IC card 102 by method Y.

[0078] The storage unit 242 is an example of the storage unit 12 described above. The storage unit 242 associates the user ID 2111 and the first biometric information 2112 acquired by the acquisition unit 241 and stores them in the storage unit 210 as user information 211. In particular, when the acquisition unit 241 acquires the user ID and the first biometric information by using one of a plurality of short-range wireless communication methods, the storage unit 242 associates the acquired user ID 2111 and the first biometric information 2112 and stores them in the storage unit 210. Note that the storage unit 242 may delete the user information 211 after a certain period of time has elapsed after storing the user information 211. In other words, the storage unit 242 may temporarily store the user information 211 in the storage unit 210. Note that the user information 211 is sequentially stored and deleted in the storage unit 210, but there may be cases where a plurality of pieces of user information 211, i.e., two or more pieces of facial feature information 2112, are temporarily stored.

[0079] The authentication unit 243 is an example of the above-mentioned authentication unit 13. The authentication unit 243 performs biometric authentication based on second biometric information extracted from an image of the user U captured by controlling the camera 260 and the first biometric information stored in the user information 211 of the storage unit 210. Specifically, the authentication unit 243 includes a face detection unit 2431, a feature information extraction unit 2432, and an authentication processing unit 2433.

[0080] The face detection unit 2431 detects a facial region from an image of the user U captured by the camera 260, and outputs a facial image corresponding to the detected facial region to the feature information extraction unit 2432. The feature information extraction unit 2432 extracts a plurality of feature points indicative of a person's facial features from the facial region (facial image) detected by the face detection unit 2431, and calculates the distance between each of the feature points. The feature information extraction unit 2432 then extracts a set of the positions of the extracted feature points and a set of the calculated distances between each of the feature points as facial feature information, and outputs the extracted facial feature information to the authentication processing unit 2433. The authentication processing unit 2433 compares the facial feature information extracted by the feature information extraction unit 2432 with one or more pieces of facial feature information 2112 in the user information 211 and calculates the degree of match. The authentication processing unit 2433 then determines that facial authentication has been successful if the degree of match is equal to or greater than a threshold, and determines that facial authentication has failed if the degree of match is less than the threshold.

[0081] The identification unit 244 is an example of the above-mentioned identification unit 14. The identification unit 244 identifies, from the storage unit 210, the user ID 2111 associated with the facial feature information 2112 for which the authentication processing unit 2433 has successfully performed facial authentication. The identification unit 244 may also identify the short-range wireless communication method used at the time of acquisition by the acquisition unit 241 and register the identified method in the acquisition history. For example, when the identification unit 244 identifies short-range wireless communication method X after successful facial authentication, the identification unit 244 associates the date and time 2121, the user ID 2122 for which the facial authentication has succeeded, and the wireless method 2123 for which method X has been used, and registers these in the usage history 212. The identification unit 244 may also refer to the usage management DB 512 to identify attribute information attributed to the qualification information 5122 associated with the identified user ID 5121. Specifically, the identification unit 244 identifies the attribute information 5123 associated with the identified user ID 5121 from the usage management DB 512 via the network N.

[0082] The determination unit 245 is an example of the determination unit 15 described above. The determination unit 245 refers to the usage management DB 512, and determines whether the user U can use the service based on the qualification information 5122 associated with the user ID 5121 identified by the identification unit 244. For example, the determination unit 245 may transmit the user ID to the usage management server 500 and receive from the usage management server 500 the qualification information 5122 associated with the user ID 5121 in the usage management DB 512. In this case, the determination unit 245 may determine whether the user U is qualified to use the service based on the received qualification information. Alternatively, the determination unit 245 may transmit the user ID to the usage management server 500 and receive a determination result on whether the user U can use the service from the usage management server 500. The determination unit 245 may then determine whether the user U can use the service based on the received determination result.

[0083] The output unit 246 is an example of the output unit 16 described above. The output unit 246 outputs information according to the determination result by the determination unit 245. Specifically, if the determination result indicates that the service is available, the output unit 246 outputs an admission permission notification to the admission control device 300. Furthermore, if the determination result indicates that the service is available, the output unit 246 may output display information indicating that the service is available. For example, the output unit 246 may output display information indicating that the user U is allowed to enter or watch a movie to the display unit 250 or a display device (not shown) of the admission control device 300 for display. Alternatively, the output unit 246 may output display information indicating that the user U is allowed to enter or watch a movie to a user terminal 101 within the communication range using a predetermined method of short-range wireless communication through which the acquisition unit 241 has acquired facial feature information, etc. Furthermore, the output unit 246 may output a message regarding service use to a user terminal 101 within the communication range. Alternatively, the output unit 246 may transmit, via the network N, to a terminal of a movie theater staff member or the like, display information indicating that the user U is permitted to enter or watch the movie.

[0084] Furthermore, when the identifying unit 244 identifies attribute information attributable to the qualification information of a user whose face has been successfully authenticated, the output unit 246 may output the identified attribute information. Then, the output unit 246 outputs the attribute information to an output destination according to the attribute information. For example, when the attribute information indicates an elderly person or a person requiring care, the output unit 246 may output the attribute information to a terminal of a staff member or the like. Also, when the attribute information indicates an elementary school student or younger (a person subject to the child fee), the output destination may be the entrance control device 300 in order to light up a lamp on the entrance control device 300 or to output an alarm sound from a speaker.

[0085] Furthermore, the output unit 246 may output guidance information about the short-range wireless communication method used to acquire the user ID and the first biometric information. For example, the output unit 246 may display on the display unit 250 of the edge terminal 200 or the entrance control device 300 that short-range wireless communication will be performed using method Y. In particular, if face authentication by the authentication unit 243 fails, the output unit 246 may output guidance information. This allows the user U to hold the user terminal 101 over the short-range wireless communication IF 232 of the edge terminal 200, or to take out the contactless IC card 102 and hold it over the short-range wireless communication IF 232, in order to perform short-range wireless communication using method Y.

[0086] Fig. 10 is a sequence diagram showing the flow of face information registration processing according to the present embodiment 3. Fig. 11 is a diagram showing an example of screen transitions in the face information registration processing on the user terminal according to the present embodiment 3. In the following description, Fig. 11 will be referred to as appropriate in the description of Fig. 10.

[0087] Here, it is assumed that user U operates user terminal 101 to register his / her own facial information as a pre-registration for using a predetermined service, for example, a movie theater. It is also assumed that user U possesses user terminal 101 and contactless IC card 102. It is also assumed that user information 111 (user ID 1111 and facial feature information 1112) is not registered in storage medium 100-1 of user terminal 101. It is also assumed that attribute information 1113 is registered in storage medium 100-2 of contactless IC card 102, and that the ID of user U's identification information is also registered, but that user ID 1111 and facial feature information 1112 used for facial authentication are not registered.

[0088] First, the user U holds the contactless IC card 102 over the reader of the short-distance wireless communication IF 132 (method Y) of the user terminal 101. Then, the user terminal 101 displays a personal identification number input screen for the contactless IC card 102 on the display unit 150. In response to this, the user terminal 101 receives the personal identification number from the user U. Input field The user terminal 101 accepts input of a personal identification number into 601 and accepts pressing of an authentication button 602. Then, the user terminal 101 transmits the personal identification number to the contactless IC card 102 via the short-range wireless communication IF 132, and causes the contactless IC card 102 to perform authentication (S301).

[0089] If authentication using the contactless IC card 102 is successful, the user terminal 101 reads the attribute information 1113 from the contactless IC card 102 via the short-range wireless communication IF 132 (by method Y) (S302). Then, the user terminal 101 displays the attribute information 603 on the display unit 150 (S303). Then, the user terminal 101 accepts a press of the face capture button 604 from the user U, and controls the camera 160 to capture a face image of the user U (S304). For example, a face image of the user U is captured as shown in the face area 605 in FIG. 11 . In response, the user terminal 101 accepts a press of the face registration button 606 from the user U, and transmits the captured face image to the authentication infrastructure system 400 via the network N (S305).

[0090] The authentication infrastructure system 400 receives a facial image from the user terminal 101 via the network N. The authentication infrastructure system 400 then detects a facial area from the received facial image (S306). The authentication infrastructure system 400 then extracts a plurality of feature points that indicate the person's facial features from the detected facial area and calculates the distances between each of the feature points. The authentication infrastructure system 400 then extracts a set of the positions of the extracted feature points and a set of the calculated distances between each of the feature points as facial feature information (S307). The authentication infrastructure system 400 then issues a new user ID (S308). Thereafter, the authentication infrastructure system 400 returns the issued user ID and the extracted facial feature information to the user terminal 101 via the network N (S309).

[0091] The user terminal 101 associates the user ID 1111 and facial feature information 1112 received from the authentication infrastructure system 400 and stores them in the storage unit 210 as user information 211 (S310). Next, the user terminal 101 transmits the received user ID and the attribute information read in step S302 to the usage management server 500 via the network N (S311). The usage management server 500 then associates the received user ID 5121 and attribute information 5123 and registers them in the usage management DB 512 (S312). Thereafter, the usage management server 500 transmits a registration completion notification to the user terminal 101 via the network N (S313). The user terminal 101 displays the received notification of registration completion on the display unit 150 (S314). At this time, the user terminal 101 may generate two-dimensional code information 607 corresponding to the user ID 1111 and display it on the display unit 150. FIG. 11 also shows that wireless method X is available to the user terminal 101, that is, the setting is ON.

[0092] Fig. 12 is a sequence diagram showing the flow of electronic application processing according to the third embodiment. Fig. 13 is a diagram showing an example of screen transitions in ticket purchase processing on a user terminal according to the third embodiment. In the following explanation, Fig. 13 will be referred to as appropriate during the explanation of Fig. 12. It is assumed that user U has already performed the face information registration processing of Fig. 10 described above.

[0093] First, a user U uses the user terminal 101 to make a reservation and make an electronic payment by electronic application in order to purchase a ticket to watch a specific movie at a pre-registered movie theater.

[0094] The user terminal 101 accepts reservation information input by the user U (S321). For example, the user terminal 101 accepts a selection of a movie and date and time from the user U, and displays reservation information 611 on the display unit 150. The user terminal 101 then accepts a press of a reservation button 612 from the user U. In response, the user terminal 101 transmits an electronic application including the user U's user ID 1111 and reservation information to the usage management server 500 via the network N. The reservation information includes the type of movie, date and time, theater, etc.

[0095] The usage management server 500 then accepts an electronic application from the user terminal 101 via the network N and makes a provisional reservation based on the reservation information (S323). For example, the reservation processing unit 544 of the usage management server 500 works in conjunction with a reservation system (not shown) to issue a reservation ID and make a provisional reservation if a reservation is currently possible. Specifically, the reservation processing unit 544 determines whether there are any seats available based on the type of movie, date and time, movie theater, etc. included in the reservation information, and if a reservation is currently possible, issues a reservation ID, reserves a seat as a provisional reservation, and specifies the standard usage fee. The usage management server 500 then Usage management DB512 From the attribute information 5123 associated with the user ID 5121 included in the electronic application, the attribute information 5123 associated with the user ID 5121 is identified (S324). The usage management server 500 then calculates a discounted usage fee based on the identified attribute information 5123 (S325). For example, if the attribute information indicates an elderly person, a disabled person, a student, etc., the calculation unit 542 of the usage management server 500 calculates the usage fee by applying a discount amount or discount rate according to each attribute information to the standard usage fee. Note that the usage fee for the movie theater may be the list price (standard) in the case of over-the-counter sales, or an amount to which a discount amount or discount rate lower than that of the electronic application is applied in the case of vending machines installed in the movie theater, etc. This can contribute to promoting the use of services that use electronic applications and facial recognition.

[0096] Thereafter, the usage management server 500 returns the tentative reservation information and the usage fee to the user terminal 101 via the network N (S326). Then, the user terminal 101 displays the received tentative reservation information and the usage fee 613 on the display unit 150 (S327). Then, the user terminal 101 accepts pressing of the payment button 614 from the user U (S328). In this case, the user terminal 101 transmits the reservation ID and the payment information 112 to the usage management server 500 via the network N (S329). Note that if the payment information 112 is not stored in the memory unit 110, the user terminal 101 may accept input of the payment information from the user U.

[0097] The usage management server 500 receives the reservation ID and payment information from the user terminal 101 via the network N and performs payment processing for the usage fee based on the payment information (S330). Then, the usage management server 500 performs reservation confirmation processing (S331). That is, the usage management server 500 issues digital ticket information for the confirmed reservation ID to the user U as qualification information. Then, the usage management server 500 associates the user ID 5121 received in step S322 with the qualification information 5122 issued in step S331 and registers them in the usage management DB 512 (S332). Thereafter, the usage management server 500 returns an application (reservation) completion notification to the user terminal 101 via the network N (S333). The user terminal 101 displays the received reservation completion information on the display unit 150 (S334). FIG. 13 shows that reservation confirmation information 615 is displayed on the display unit 150 of the user terminal 101. The reservation confirmation information 615 includes, for example, the name of the movie, the date and time, the room (screen), the seat number, etc., but is not limited to these.

[0098] Next, the entrance process using face authentication according to the third embodiment will be described in the case where a user terminal is used (Example 3-1) and in the case where a contactless IC card is used (Example 3-2).

[0099] First, Example 3-1 will be described, in which a user terminal is used in entrance processing using facial authentication. FIG. 14 is a diagram for explaining the concept of entrance processing using a user terminal according to Example 3-1 of the present embodiment 3. With the edge terminal 200 and the entrance control device 300 installed, it shows that a user Ua carrying a user terminal 101a is permitted to enter through facial authentication and qualification determination by the edge terminal 200. Next, it shows that a user Ub carrying a user terminal 101b is about to enter using the short-range wireless communication method X, and then a user Uc carrying a contactless IC card 102c is waiting to enter, a predetermined distance away (for example, 5 m). Note that the predetermined distance is not limited to 5 m.

[0100] Fig. 15 is a sequence diagram showing the flow of entrance processing using a user terminal according to Example 3-1 of Embodiment 3. Fig. 16 is a diagram showing an example of screen transitions in entrance processing on a user terminal according to Example 3-1 of Embodiment 3. In the following explanation, Fig. 16 will be referred to as appropriate during the explanation of Fig. 15.

[0101] First, the user terminal 101b displays reservation information in response to an operation by user Ub (S341). Specifically, the user terminal 101b displays the above-mentioned reservation confirmation information 615 on the display unit 150. Then, the user terminal 101b receives a press of the Start Use button 616 from user Ub, and displays code information and a message on the display unit 150 indicating that the available short-range wireless communication is method X. For example, the user terminal 101b may turn on method X in response to the press of the Start Use button 616. At this point, it is sufficient that at least the user terminal 101b is in a state where short-range wireless communication is possible using method X. The code information may include the user ID and reservation ID of user Ub. This is because, if short-range wireless communication does not work well, the entrance process can be performed by having the edge terminal 200 read the code information.

[0102] Then, the user Ub, carrying the user terminal 101b, moves to the entrance gate (edge ​​terminal 200 and entrance control device 300) of the movie theater (S342). Then, it is assumed that the user terminal 101b enters the communication range of the short-range wireless communication IF 231 of the edge terminal 200 using method X. At this time, the user ID 1111 and the facial feature information 1112 are transferred from the user terminal 101b to the edge terminal 200 using method X of short-range wireless communication (S343). That is, the user terminal 101b transmits the user ID 1111 and the facial feature information 1112 read from the storage medium 100-1 to the edge terminal 200 using method X of short-range wireless communication. Note that the user terminal 101b may transmit the user ID 1111 and the facial feature information 1112 in response to a read request from the edge terminal 200 using method X of short-range wireless communication.

[0103] Then, the edge terminal 200 associates the received user ID 2111 and facial feature information 2112 (facial feature information A) and stores them in the storage unit 210 as user information 211 (S344). In addition, the edge terminal 200 detects the presence of the user Ub with the human presence sensor 270 and captures an image of the face of the user Ub with the camera 260 (S345).

[0104] The face detection unit 2431 then detects a facial region from the image of the user Ub captured by the camera 260 (S346). The feature information extraction unit 2432 then extracts facial feature information B of the user Ub from the detected facial region (S347). The authentication processing unit 2433 then compares the facial feature information A in the storage unit 210 with the facial feature information B extracted in step S347 (S348) and calculates the degree of match. If the degree of match is equal to or greater than a threshold, the authentication processing unit 2433 determines that facial authentication has been successful, and if the degree of match is less than the threshold, the authentication processing unit 2433 determines that facial authentication has failed.

[0105] Here, the description will continue assuming that the facial authentication of user Ub has been successful. Therefore, the identification unit 244 identifies, from the storage unit 210, the user ID 2111 (of user Ub) associated with the facial feature information 2112 (facial feature information A) for which facial authentication has been successful (S349).

[0106] Next, the determination unit 245 transmits a qualification confirmation request including the user ID identified in step S349 to the usage management server 500 via the network N (S350). The response unit 545 of the usage management server 500 identifies the user ID included in the received qualification confirmation request, and searches the usage management DB 512 for qualification information 5122 associated with the identified user ID 5121. The response unit 545 then determines whether or not usage is permitted based on the searched qualification information 5122 (S351). The response unit 545 then returns the determination result of whether or not usage is permitted to the edge terminal 200 via the network N (S352). Note that the response unit 545 may also return the searched qualification information 5122 to the edge terminal 200.

[0107] The determination unit 245 of the edge terminal 200 determines the determination result received from the usage management server 500 as the result of the determination of service usage for user Ub. Here, it is assumed that user Ub is determined to be permitted to use the service for watching (appreciating) movies. Then, the output unit 246 displays the determination result on the display unit 150 (S353). FIG. 16 shows an example in which a result message 619 is displayed on the display unit 250 of the edge terminal 200. The result message 619 shows an example in which the result message 619 displays information indicating successful authentication, the short-range wireless communication method used to transfer the user ID and facial feature information, as well as the user's attribute information (such as name), qualification information (such as ticket information, movie title, date and time, room, seat number, etc.), the reason for the discount on the usage fee, and discount information. The reason for the discount may be, in addition to "student discount," elderly, disabled, multiple use, etc. The discount information may include the discount amount and discount rate (how many discounts there are), etc. At the same time, the output unit 246 outputs an admission permission notification to the admission control device 300 (S354). In response to this, the admission control device 300 opens the gate 301. As a result, the user Ub is allowed to enter.

[0108] Furthermore, the output unit 246 transmits the determination result and a message regarding service usage to the user terminal 101b via short-range wireless communication method X (S355). In response, the user terminal 101b displays the received determination result and message regarding service usage on the display unit 150 (S356). FIG. 16 shows an example in which result messages 617 and 618 are displayed on the display unit 150 of the user terminal 101b. The result message 617 shows an example in which the user ID and the short-range wireless communication method by which the facial feature information was transferred are displayed. The result message 618 shows an example in which a message indicating successful authentication and notes to take after sitting down are displayed.

[0109] Next, Example 3-2 will be described, in which a contactless IC card is used in entrance processing using facial authentication. FIG. 17 is a diagram for explaining the concept of entrance processing using a contactless IC card according to Example 3-2 of the present embodiment 3. With the edge terminal 200 and the entrance control device 300 installed, user Ub carrying the user terminal 101b is permitted to enter through facial authentication and qualification determination by the edge terminal 200. Next, user Uc carrying the contactless IC card 102c enters using short-range wireless communication method Y, and then user Ud carrying the user terminal 101d, who is a predetermined distance away (for example, 5 m), is waiting to enter. Note that the predetermined distance is not limited to 5 m. Note that the storage medium 100-2 of the contactless IC card 102c stores a user ID 1111, facial feature information 1112, and attribute information 1113. For example, it is assumed that the contactless IC card 102 possessed by the user Uc writes the user ID 1111 and facial feature information 1112 of the user Uc to the contactless IC card 102c by method Y in step S310 of FIG.

[0110] 18 is a sequence diagram showing the flow of entrance processing using a contactless IC card according to Example 3-2 of the third embodiment. First, the user Uc holds the contactless IC card 102c over the reading unit of the short-range wireless communication IF 232 (method Y) of the edge terminal 200 (S342-2). As a result, the contactless IC card 102c enters the communication range of the short-range wireless communication IF 232 (method Y) according to method Y. Therefore, the user ID 1111 and the facial feature information 1112 are transferred from the contactless IC card 102c to the edge terminal 200 by the short-range wireless communication method Y (S343-2). That is, the contactless IC card 102c transmits the user ID 1111 and the facial feature information 1112 read from the storage medium 100-2 to the edge terminal 200 by the short-range wireless communication method Y. The contactless IC card 102c may transmit the user ID 1111 and the facial feature information 1112 read from the storage medium 100-2 in response to a read request from the edge terminal 200 using the short-range wireless communication method Y. Steps S344 to S3554 are the same as those in Fig. 15 described above, and therefore redundant explanations will be omitted.

[0111] As described above, this embodiment achieves the same effects as the first and second embodiments. Furthermore, in this embodiment, since the edge terminal 200 supports multiple short-range wireless communication methods, it is possible to flexibly determine whether or not a user can use a service using facial authentication, depending on the user's circumstances. Furthermore, instead of using a database of facial feature information stored in an authentication infrastructure DB on the network, the facial feature information is transferred from a storage medium carried by the user to the edge terminal via short-range wireless communication, stored in the edge terminal, and used for matching with facial feature information extracted from facial images of users present in the vicinity at that time. In other words, facial authentication is achieved by local authentication. This allows the authentication process to continue even if communication with the authentication infrastructure DB fails. Furthermore, using biometric authentication for personal authentication can highly effectively prevent spoofing.

[0112] Furthermore, while many services offer discounts on service fees upon presentation of identification, personal information is often written, engraved, or printed on the identification, which can lead to users being hesitant to present their identification when using the service. In contrast, this embodiment supports a relatively long-distance short-range wireless communication method, Method X, allowing users to receive discounts without presenting identification when using the service. This can promote the widespread use of services using biometric authentication. Furthermore, by providing greater discounts on service fees when making electronic applications, such as purchasing digital tickets via the Internet, the widespread use of services using biometric authentication can be further promoted. Meanwhile, by supporting multiple short-range wireless communication methods and existing code authentication, the system can flexibly accommodate a variety of situations.

[0113] It should be noted that the edge terminal 200 performs face authentication when it detects a user with the human presence sensor 270, regardless of whether or not the user ID and facial feature information are acquired by short-range wireless communication. can be performed Therefore, if face authentication fails in step S348, the user whose face was photographed while attempting to enter may be different from the actual owner of the user terminal 101 or contactless IC card 102 carried by the user. Alternatively, if face authentication fails in step S348, transfer via short-range wireless communication between the edge terminal 200 and the user terminal 101 or the contactless IC card 102 may have failed. For example, if method X is turned off in the user terminal 101 or if the user has put the user terminal 101 in their bag, the edge terminal 200 and the user terminal 101 may be outside the communication range of method X, and transfer may not have been possible. Therefore, if face authentication fails in step S348, the edge terminal 200 may output guidance information about the short-range wireless communication method.

[0114] 19 is a diagram showing an example of display of guidance information for short-range wireless communication methods in the edge terminal 200 according to the third embodiment. The guidance information 620 includes, for example, a message indicating authentication failure, a confirmation message asking whether method X of the user terminal is ON, and a message urging the user to hold a storage medium for method Y (user terminal or contactless IC card) over the reading unit 280. However, the guidance information 620 is not limited to these.

[0115] Note that if there are multiple edge terminals 200, the user U may be able to check the short-range wireless communication methods supported by each edge terminal before entering. For example, the usage management server 500 stores, in a storage unit 510, information on the short-range wireless communication methods supported by each of multiple edge terminals 200-1 to 200-3 installed at the entrance gate of a movie theater. Then, in response to an operation by the user U, the user terminal 101 transmits a request for the short-range wireless communication methods supported by each edge terminal to the usage management server 500 via the network N. When the response unit 545 of the usage management server 500 receives the request from the user terminal 101, it identifies the short-range wireless communication methods supported by each edge terminal 200 from the storage unit 510, generates display information including the identified information, and returns the display information to the user terminal 101.

[0116] FIG. 20 is a diagram showing an example of a display of short-range wireless communication methods supported by each edge terminal according to the third embodiment. Here, the user terminal 101 displays supported method information 621 on the display unit 150. The supported method information 621 indicates that a pair of the edge terminal 200-1 and the entrance control device 300-1, a pair of the edge terminal 200-2 and the entrance control device 300-2, and a pair of the edge terminal 200-3 and the entrance control device 300-3 are arranged according to their installation locations. The information indicates that the edge terminal 200-1 supports method X and code authentication, the edge terminal 200-2 supports method X, method Y, and code authentication, and the edge terminal 200-3 supports method Y and code authentication. In this way, the user U can use the edge terminal 200 after first confirming that it supports the short-range wireless communication method he or she wants to use. Note that "code authentication" refers to a method in which the camera 260 reads code information corresponding to the user ID described above to identify the user ID and perform eligibility determination. Therefore, since code authentication does not use facial recognition, no discounts are applied. This can motivate user U to use method X or method Y, which use facial recognition. On the other hand, by ensuring code authentication, it is possible to flexibly respond to unforeseen circumstances, such as a failure of short-range wireless communication.

[0117] <Embodiment 4> The fourth embodiment is a modification of the third embodiment described above. The usage control terminal (edge ​​terminal) according to the fourth embodiment is a mobile terminal. Therefore, for example, a staff member of the service provider can carry the edge terminal and check whether or not a user can use the service by short-range wireless communication with a storage medium carried by the user and by facial recognition. In the following, an example will be described in which the service is a reserved seat on a train and the staff member is a conductor. However, the fourth embodiment can also be applied to other services and staff members.

[0118] FIG. 21 is a diagram for explaining the concept of the reserved seat ticket confirmation process by the conductor U0 according to the fourth embodiment. First, it is assumed that a user Ue is using a reserved seat in a reserved seat car of a certain train. It is assumed that the user Ue carries a user terminal 101e or a contactless IC card 102e. It is also assumed that the user Ue has previously performed the face information registration process and the reserved seat ticket purchase process on the usage management server 500 in order to purchase the reserved seat ticket. In this case, the usage management server 500 has registered in the usage management DB 512 the user ID 5121 of the user Ue, the qualification information 5122 which is the reserved seat ticket purchase information, and the attribute information 5123 of the user Ue in association with each other.

[0119] Conductor U0 patrols the train carrying edge terminal 200e. Here, edge terminal 200e is a mobile terminal, and unlike the above-mentioned edge terminal 200, it does not need to have a human sensor 270, and is not connected to the entrance control device 300. Other basic configurations of edge terminal 200e are assumed to be equivalent to those of edge terminal 200.

[0120] Fig. 22 is a sequence diagram showing the flow of the reserved seat ticket confirmation process by the conductor according to the fourth embodiment. In the following explanation, Fig. 21 will be referred to as appropriate when explaining Fig. 22. First, the conductor U0 calls out to the user Ue in the reserved seat car and confirms whether the user Ue has purchased a reserved seat ticket and is using it legitimately. For example, the user terminal 101e displays the digital reserved seat ticket 630 in response to the operation of the user Ue (S342-3).

[0121] Then, the conductor U0 brings the user terminal 101e of the user Ue close to the communication range of the edge terminal 200e for method X and presses the reserved seat ticket confirmation button 631 displayed on the screen of the edge terminal 200e. In response, the user ID 1111 and facial feature information 1112 (facial feature information A) are transferred from the user terminal 101e to the edge terminal 200e by method X of short-range wireless communication (S343-3). The edge terminal 200e then acquires the user ID and facial feature information from the user terminal 101e by method X of short-range wireless communication, and stores the user ID 2111 and the facial feature information 2112 in association with each other in the storage unit 210 (S344).

[0122] When the user Ue presents the contactless IC card 102e, the conductor U0 brings the contactless IC card 102e of the user Ue close to the communication range of the edge terminal 200e (near the reading unit 280) of the method Y, and presses the reserved seat ticket confirmation button 631 displayed on the screen of the edge terminal 200e. In this case, the user ID 1111 and facial feature information 1112 (facial feature information A) are transferred from the user terminal 101e to the edge terminal 200e by the short-range wireless communication method Y.

[0123] In response to these, the edge terminal 200e photographs the face of the user Ue using the camera 260 (S345), and performs face authentication by comparing the facial feature information A stored in the storage unit 210 with the facial feature information B extracted from the facial image (S346 to S348). If the face authentication is successful, the edge terminal 200e identifies the user ID 2111 (of the user Ue) associated with the facial feature information 2112 for which face authentication was successful from the storage unit 210 (S349). Then, the edge terminal 200e transmits an eligibility confirmation request including the identified user ID to the usage management server 500 via the network N (S350), and confirms whether the user Ue has already purchased a reserved seat ticket. For example, the edge terminal 200e may check the usage management DB 512 fromThe edge terminal 200e acquires the qualification information 5122 associated with the user ID 5121 of the user Ue (S352) and displays it on the display unit 250 (S353). For example, the edge terminal 200e displays the information about the reserved seat ticket received from the usage management server 500 as a result message 632. The result message 632 includes information such as a notification that the user Ue has successfully passed facial authentication and information about the reserved seat ticket purchased by the user Ue. However, the result message 632 is not limited to these. For example, the edge terminal 200e may determine the legitimacy of the reserved seat ticket from the qualification information received from the usage management server 500. Alternatively, the edge terminal 200e may receive the determination result determined by the usage management server 500. This allows the conductor U0 to confirm that the user Ue has purchased a reserved seat ticket and is using it legitimately.

[0124] Furthermore, if the user Ue has registered face information and purchased a reserved seat ticket but the seat is incorrect, the conductor U0 can guide the user Ue to the correct seat by looking at the result message 632. In this case, when the edge terminal 200e has accepted input of the reserved seat number from the conductor U0, it may display in the result message 632 a determination result indicating that the seat location is incorrect based on the received qualification information.

[0125] Furthermore, if the user Ue has registered face information but has not yet purchased a reserved seat ticket, the edge terminal 200e may receive from the usage management server 500 a determination result indicating that the qualification information has not been registered, and may display a message indicating that the reserved seat ticket has not been purchased as a result message 632. Furthermore, if the user Ue has not registered face information, the edge terminal 200e may display a message indicating that face authentication has failed in the result message 632.

[0126] In this way, this embodiment also provides the same effects as those of the above-described embodiments 1 and 2. Furthermore, in this embodiment, like the above-described embodiment 3, the edge terminal 200e supports multiple short-range wireless communication methods and realizes local authentication. Therefore, it is possible to provide the same effects as those of embodiment 3.

[0127] Furthermore, by offering a larger discount when purchasing a reserved seat ticket through an electronic application compared to purchasing at a counter or ticket machine, it is possible to achieve the same effect as in embodiment 3. Furthermore, in embodiment 4, since the edge terminal 200e is a mobile terminal, staff and the like can flexibly and easily determine eligibility to use various services without being tied to a specific location.

[0128] Furthermore, according to this embodiment, the conductor can easily ascertain the user's qualification information (seat information) by performing facial authentication between facial information (facial feature information) acquired through communication with the user's user terminal or contactless IC card and facial information (facial feature information) captured by photographing the user, without having to ask the user to present a ticket or reserved seat ticket, etc. This allows the conductor to easily confirm whether the user is sitting in the appropriate seat. Therefore, if a person boards the train holding another person's user terminal or contactless IC card, an error will occur in the identity verification by facial authentication, thereby preventing impersonation and unauthorized boarding.

[0129] <Embodiment 5> The fifth embodiment is an additional example of the above-mentioned third or fourth embodiment. The user terminal 101 may write the issued user ID and facial feature information into the non-contact IC card .

[0130] 23 is a diagram showing an example of screen transitions in the process of writing feature information to the contactless IC card 102 according to the fifth embodiment. As a premise, it is assumed that the face information registration process has been performed in the same manner as in steps S301 to S304 of FIG. 10 described above. Then, the user U presses the face registration button 606f on the user terminal 101. In response to this, in the user terminal 101, the authentication infrastructure system 400 extracts facial feature information from the face image in the same manner as in steps S305 to S309 described above, and the user terminal 101 receives the issued user ID and the extracted facial feature information.

[0131] At this time, the user terminal 101 continues to perform a process of writing facial feature information to the contactless IC card 102 (S310a). Specifically, the user terminal 101 associates the received user ID 1111 and facial feature information 1112, and writes them to the storage medium 100-2 of the contactless IC card 102 by method Y via the short-range wireless communication IF 132. The user terminal 101 then displays a message indicating that face registration to the card has been completed (face registration completion message 608). Thereafter, the user terminal 101 executes the above-described steps S311 and onwards.

[0132] As a result, instead of using the user terminal 101, the user U can have his / her face authenticated and his / her eligibility to use the service determined by holding the non-contact IC card 102 over the reading unit 280 of the edge terminal 200 or the like.

[0133] <Other embodiments> The user terminal 101 may write the qualification information to the storage medium 100. For example, in step S333 of Fig. 12 described above, the user terminal 101 may receive the qualification information issued by the usage management server 500 and store the qualification information in the storage medium 100 in association with the user ID. Furthermore, the user terminal 101 or the contactless IC card 102 may transfer the qualification information together with the user ID and facial feature information (biometric information) via short-range wireless communication with the edge terminal 200 or the like.

[0134] Furthermore, in the above-described second to fifth embodiments, a set of a user ID and qualification information is registered in the database (usage management DB) of the usage management server at the time of registration or reservation, but the qualification information does not have to be registered in the usage management DB. Instead, as described above, the user terminal 101 may register the qualification information in association with the user ID in the storage medium 100. This allows the edge terminal to acquire the above qualification information and attribute information, along with facial feature information and user ID, from the user terminal or contactless IC card when the user uses a service. This allows the edge terminal to output the determination result only through local communication between the user terminal and the edge terminal, without communicating with the usage management server.

[0135] Furthermore, if there is a discount on the usage fee based on attribute information, it is not necessary to perform actual payment processing at the time of reservation, as in step S330 in Figure 12 described above. In that case, for example, payment processing may be performed when it is confirmed that a user who has successfully passed facial authentication when using the service is a pre-registered user eligible for the discount (student, senior citizen). This prevents fraudulent use (impersonation) by a user who is not eligible for the discount, who fraudulently makes a reservation as eligible for the discount and completes payment, and then actually uses the service.

[0136] Furthermore, when making a reservation via electronic application as shown in FIG. 12, the user terminal may acquire attribute information from a digital ID and transmit the electronic application including the attribute information along with the user ID and reservation information. In other words, the attribute information recorded on a digital ID such as a driver's license, passport, student ID, or My Number card may be used to indicate and prove that the person making the reservation is eligible for the discount. Furthermore, the user terminal may read facial feature information from the digital ID and transmit the electronic application including the facial feature information along with the user ID, reservation information, and attribute information. Furthermore, the user may be proven eligible for the discount by comparing the facial feature information acquired from the digital ID with photographed face information.

[0137] In the above-described embodiment, personal authentication (authentication of identity confirmation, identity authentication, identity identification processing, etc.) has been described as face authentication. However, other biometric authentication methods using biometric information may be used. Other technologies using captured images of a person may be applied to biometric authentication and biometric information. For example, biometric information may be data (features) calculated from physical characteristics unique to an individual, such as fingerprints, voiceprints, veins, retinas, irises, and palm patterns. Furthermore, biometric authentication may involve extracting feature information indicating a person's physical characteristics from a captured image of a portion of the user's body, comparing the extracted feature information with pre-registered feature information, and determining that authentication is successful if the degree of match is equal to or greater than a threshold. For example, biometric authentication may be based on a person's external shape. In this case, the feature information may be information related to the person's external shape, such as information indicating characteristics such as body shape, height, and clothing. Furthermore, other personal authentication methods may be applied instead of biometric authentication, and the biometric information may also be other personal authentication information. For example, the personal authentication information may include, but is not limited to, a user ID, a combination of ID and password, the contents (identification number and password) of an identification card such as a My Number or a driver's license, an electronic certificate, code information, etc. The code information may be a two-dimensional code, for example, a QR code (registered trademark).

[0138] In the above examples, the program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technology, CD-ROM, digital versatile disc (DVD), Blu-ray® disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals.

[0139] The present disclosure is not limited to the above-described embodiments, and may be modified as appropriate without departing from the spirit and scope of the present disclosure. In addition, the present disclosure may be implemented by appropriately combining the respective embodiments.

[0140] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. (Appendix A1) an acquisition means carried by a predetermined user and configured to acquire the user ID and the first biometric information of the user from a storage medium storing the user ID and the first biometric information of the user by a predetermined method of short-range wireless communication; a storage means for storing the user ID and the first biometric information in a storage device in association with each other; an authentication means for performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; an identification means for identifying, from the storage device, a user ID associated with the first biometric information that has been successfully biometrically authenticated; a determination means for referring to a database in which the user ID and the user's qualification information for using the service are registered in association with each other, and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; an output means for outputting information according to the determination result by the determination means; A usage control terminal comprising: (Appendix A2) the acquiring means is on standby and capable of acquiring the information by each of the plurality of short-range wireless communication methods; When the acquisition means acquires the user ID and the first biometric information by any of the plurality of methods, the storage means associates the acquired user ID and the first biometric information and stores them in the storage device. The access control terminal described in Appendix A1. (Appendix A3) The qualification information is information issued based on the attribute information of the user. A usage control terminal as described in Appendix A1 or A2. (Appendix A4) The specifying means specifies the method of the short-range wireless communication at the time of acquisition by the acquiring means, and registers the specified method in the acquisition history. 10. The access control terminal according to any one of appendices A1 to A3. (Appendix A5) When the determination result indicates that the service is available, the output means outputs an admission permission notice to an admission control device that controls admission of the user. 10. The access control terminal according to any one of appendices A1 to A4. (Appendix A6) When the determination result indicates that the service is available, the output means outputs display information indicating that the service is available. 10. The access control terminal according to any one of appendices A1 to A5. (Appendix A7) The identification means refers to the database and identifies attribute information resulting from the qualification information associated with the identified user ID, The output means outputs the specified attribute information. 10. The access control terminal according to any one of appendices A1 to A6. (Appendix A8) The output means outputs the attribute information to an output destination corresponding to the specified attribute information. The usage control terminal described in Appendix A7. (Appendix A9) The output means outputs guidance information about the short-range wireless communication method used to acquire the user ID and the first biometric information. 10. The access control terminal according to any one of appendices A1 to A8. (Appendix A10) The output means outputs the guidance information when the biometric authentication fails. The usage control terminal described in Appendix A9. (Appendix A11) the storage medium is installed in a user terminal capable of short-range wireless communication using a predetermined method; The acquiring means acquires the user ID and the first biometric information by short-distance wireless communication with the user terminal according to the predetermined method. 10. The access control terminal according to any one of appendices A1 to A10. (Appendix A12) The output means outputs a message regarding the use of the service to the user terminal when the determination result indicates that the service is available. The usage control terminal described in Appendix A11. (Appendix A13) the storage medium is a contactless IC (Integrated Circuit) card capable of short-range wireless communication using a predetermined method, The acquiring means acquires the user ID and the first biometric information by short-distance wireless communication with the contactless IC card according to the predetermined method. 10. The access control terminal according to any one of appendices A1 to A10. (Appendix A14) The usage control terminal is a mobile terminal. 10. The access control terminal according to any one of appendices A1 to A13. (Appendix B1) a database in which the user ID of a predetermined user is registered in association with the user's qualification information for using a service; a usage control terminal capable of short-range wireless communication using one or more methods; Equipped with The usage control terminal an acquisition means carried by the user and configured to acquire the user ID and the first biometric information from a storage medium storing the user ID and the first biometric information by a predetermined method of short-range wireless communication; a storage means for storing the user ID and the first biometric information in a storage device in association with each other; an authentication means for performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; an identification means for identifying, from the storage device, a user ID associated with the first biometric information that has been successfully biometrically authenticated; a determination means for referring to the database and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; an output means for outputting information according to the determination result by the determination means; A usage control system comprising: (Appendix B2) the acquiring means is on standby and capable of acquiring the information by each of the plurality of short-range wireless communication methods; When the acquisition means acquires the user ID and the first biometric information by any of the plurality of methods, the storage means associates the acquired user ID and the first biometric information and stores them in the storage device. 1. The access control system described in Appendix B1. (Appendix C1) The computer acquiring the user ID and the first biometric information from a storage medium carried by a predetermined user and storing the user ID and the first biometric information of the user, by a predetermined method of short-range wireless communication; storing the user ID and the first biometric information in association with each other in a storage device; performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; Identifying, from the storage device, a user ID associated with the first biometric information that has been successfully authenticated; referencing a database in which the user ID and the user's qualification information for using a service are registered in association with each other, and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; outputting information according to the determination result; Usage control methods. (Appendix D1) an acquisition process of acquiring the user ID and the first biometric information of the user from a storage medium carried by a predetermined user and storing the user ID and the first biometric information of the user, by a predetermined method of short-range wireless communication; a storage process of storing the user ID and the first biometric information in a storage device in association with each other; an authentication process for performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; an identification process for identifying, from the storage device, a user ID associated with the first biometric information that has been successfully authenticated; a determination process of referring to a database in which the user ID and the user's qualification information for using the service are registered in association with each other, and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; an output process for outputting information according to a determination result of the determination process; A non-transitory computer-readable medium storing a usage control program that causes a computer to execute the above. (Appendix E1) a calculation means for calculating a discounted usage fee for a predetermined service based on attribute information of a predetermined user when an electronic application for use of the predetermined service including a user ID corresponding to first biometric information of the predetermined user is received; a registration means for registering the user ID and the qualification information for using the service in a database in association with each other when the user has paid the usage fee; a response means for, when receiving from the usage control terminal of the service a user ID identified by the user having succeeded in biometric authentication based on the first biometric information, referring to the database and making a response to the usage control terminal based on the qualification information associated with the received user ID; A usage management server comprising: (Appendix E2) The registration means receiving the user ID and the attribute information from a user terminal from which the attribute information of the user has been read as a result of successful authentication from a first storage medium in which the attribute information of the user has been stored; registering the received user ID and the attribute information in the database in association with each other; The calculation means Identifying attribute information associated with the user ID included in the electronic application from the database; Calculating a usage fee for the service based on the identified attribute information The usage management server described in Appendix E1. (Appendix E3) The response means The user ID and the first biometric information are acquired by a predetermined method of short-distance wireless communication from a second storage medium carried by the user and storing the user ID and the first biometric information, and the user ID identified by the successful biometric authentication is received from the usage control terminal that has performed biometric authentication based on the second biometric information extracted from an image of the user and the first biometric information. A usage management server as described in Appendix E1 or E2. (Appendix E4) The response means, in response to the request, returns to the request source a short-range wireless communication method that each of the plurality of access control terminals can support. 2. The usage management server according to any one of appendices E1 to E3. (Appendix E5) The response means identifies the qualification information associated with the received user ID from the database, and returns the identified qualification information to the usage control terminal as the response. 2. The usage management server according to any one of appendices E1 to E4. (Appendix E6) The response means refers to the database, determines whether the service can be used based on the qualification information associated with the received user ID, and returns the determination result to the usage control terminal as the response. 2. The usage management server according to any one of appendices E1 to E4. (Appendix F1) The computer When an electronic application for use of a predetermined service including a user ID corresponding to the first biometric information of a predetermined user is received, a discounted usage fee for the service is calculated based on attribute information of the user; When the user has paid the usage fee, the user ID is associated with the qualification information for using the service and registered in a database; When receiving a user ID identified by the user having succeeded in biometric authentication based on the first biometric information from the usage control terminal of the service, refer to the database and make a response to the usage control terminal based on the qualification information associated with the received user ID. Usage management method. (Appendix G1) a calculation process for calculating a discounted usage fee for a predetermined service based on attribute information of a predetermined user when an electronic application for use of the predetermined service including a user ID corresponding to first biometric information of the predetermined user is received; a registration process for registering the user ID and the qualification information for using the service in a database in association with each other when the user has paid the usage fee; a response process for, when receiving from the usage control terminal of the service a user ID identified by the user having succeeded in biometric authentication based on the first biometric information, referring to the database and sending a response based on the qualification information associated with the received user ID to the usage control terminal; A non-transitory computer-readable medium storing a usage management program that causes a computer to execute the above.

[0141] Although the present invention has been described above with reference to the embodiments (and examples), the present invention is not limited to the above-described embodiments (and examples). Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. [Explanation of symbols]

[0142] 1. Usage control terminal 11 Acquisition Department 12 Storage section 13 Authentication Section 14 Specific part 15 Judgment section 16 Output section 2. Usage management server 21 Calculation section 22 Registration Department 23 Response section 1000 Usage Control System N Network U User 101 User terminal 102 Contactless IC card 100 storage medium 100-1 Storage medium 100-2 Storage medium 1111 User ID 1112 Facial feature information 1113 Attribute information 1021 Near field wireless communication IF 1022 RW control unit 110 Storage section 111 User Information 112 Payment Information 113 Programs 120 memory 130 Communications Department 131 Near field communication IF 132 Near field wireless communication IF 140 Control Unit 141 Registration Department 142 Purchasing Department 143 Verification Department 144 Short-range wireless transmitter / receiver 150 Display section 160 Camera 200 edge devices 210 Storage section 211 User Information 2111 User ID 2112 Facial feature information 212 Usage History 2121 Date and Time 2122 User ID 2123 Wireless method 2124 Judgment result 213 Program 220 memory 230 Communications Department 231 Near field communication IF 232 Near field wireless communication IF 240 Control Unit 241 Acquisition Department 242 Preservation Department 243 Authentication Department 2431 Face detection unit 2432 Feature Information Extraction Unit 2433 Authentication processing unit 244 Specific part 245 Judgment section 246 Output Section 250 Display section 260 Camera 270 Human Sensor 280 Reading Unit 300 Entrance control device Gate 301 400 Authentication Infrastructure System 500 Usage Management Server 510 Storage section 511 Program 512 Usage management DB 5121 User ID 5122 Credentials 5123 Attribute information 5124 Usage Fee 5125 Usage History 520 memory 530 Communications Department 540 Control Unit 541 Registration Department 542 Calculation Unit 543 Payment Processing Unit 544 Reservation Processing Unit 545 Response Section 601 PIN 602 Authentication button 603 Attribute information 604 Face capture button 605 Face Area 606 Face registration button 606f Face registration button 607 Code Information 608 Face registration complete message 611 Reservation Information 612 Reservation button 613 Usage Fee 614 Payment button 615 Confirmed Reservation Information 616 Start using button 617 Result Message 618 Result Message 619 Result Message 620 Information 621 Supported Method Information 630 Digital reserved seat ticket 631 Reserved seat ticket confirmation button 632 Result Message Ua User Ub User Uc User Ud User Ue User U0 Conductor 101a User terminal 101b User terminal 102c Contactless IC card 101d User terminal 101e user terminal 102e Contactless IC card 200e Edge Terminal

Claims

1. an acquisition means carried by a predetermined user and configured to acquire the user ID and the first biometric information of the user from a storage medium storing the user ID and the first biometric information of the user by a predetermined method of short-range wireless communication; a storage means for storing the user ID and the first biometric information in a storage device in association with each other; an authentication means for performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; an identification unit that identifies, from the storage device, a user ID associated with the first biometric information that has been successfully authenticated; a determination means for referring to a database in which the user ID and the user's qualification information for using a service are registered in association with each other, and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; an output means for outputting information according to the determination result by the determination means; Equipped with The identification means refers to the database and identifies attribute information resulting from qualification information associated with the identified user ID, The output means outputs the specified attribute information. Usage control terminal.

2. 2. The usage control terminal according to claim 1, wherein said output means outputs said specified attribute information to an output destination according to said specified attribute information.

3. The computer acquiring the user ID and the first biometric information from a storage medium carried by a predetermined user and storing the user ID and the first biometric information of the user, by a predetermined method of short-range wireless communication; storing the user ID and the first biometric information in a storage device in association with each other; performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; Identifying, from the storage device, a user ID associated with the first biometric information that has been successfully authenticated; referencing a database in which the user ID and the user's qualification information for using a service are registered in association with each other, and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; Output information according to the judgment result, The computer further comprises: referring to the database to identify attribute information attributable to the qualification information associated with the identified user ID; outputting the identified attribute information; Usage control methods.

4. The usage control method described in Claim 3, wherein the computer further outputs the identified attribute information to an output destination corresponding to the attribute information.

5. an acquisition process of acquiring the user ID and the first biometric information of the user from a storage medium carried by the user and storing the user ID and the first biometric information of the user, by a predetermined method of short-range wireless communication; a storage process of storing the user ID and the first biometric information in a storage device in association with each other; an authentication process for performing biometric authentication based on second biometric information extracted from an image of the user and the first biometric information stored in the storage device; an identification process for identifying, from the storage device, a user ID associated with the first biometric information that has been successfully authenticated; a determination process of referring to a database in which the user ID and the user's qualification information for using a service are registered in association with each other, and determining whether the user is permitted to use the service based on the qualification information associated with the specified user ID; a first output process for outputting information according to the determination result; a process of referring to the database and identifying attribute information attributable to the qualification information associated with the identified user ID; a second output process for outputting the specified attribute information; A usage control program that causes a computer to execute the above.

6. The usage control program described in Claim 5, wherein the second output process includes a process of outputting the attribute information to an output destination according to the identified attribute information.

Citation Information

Patent Citations

  • Ticketless system and method for processing and recording medium readable by computer for recording ticketless processing program

    JP1998143683A

  • Identity authentication device and automatic vending device provided therewith

    JP2003151016A

  • Automatic gate system

    JP2003331323A

  • Ticket issuing system

    JP2006201997A

  • Authentication device, authentication system, and authentication method

    JP2020013525A