Terminal, system, terminal control method and program

The terminal's acquisition and transmission capabilities streamline biometric authentication by registering user information directly with a server, overcoming the challenge of integrating diverse service information without modifying existing systems, thus enhancing the usability of biometric services.

JP7794257B2Active Publication Date: 2026-01-06NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024118412
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-07-24
Publication Date
2026-01-06
Estimated Expiration
2043-04-03

AI Technical Summary

Technical Problem

Existing biometric authentication systems face challenges in efficiently registering diverse information required for providing services without significant modifications to existing service provider systems, hindering the spread of biometric authentication services.

Method used

A terminal equipped with an acquisition and transmission means to collect and transmit user biometric information and business information to a server device, facilitating token registration without requiring changes to the service provider's systems.

Benefits of technology

Enables easy system registration of information necessary for biometric authentication services, reducing the need for system modifications and enhancing the usability of biometric authentication across various service providers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007794257000001
    Figure 0007794257000001
  • Figure 0007794257000002
    Figure 0007794257000002
  • Figure 0007794257000003
    Figure 0007794257000003
Patent Text Reader

Abstract

To provide a terminal which easily enables system registration of information required for provision of services using biometric authentication.SOLUTION: A terminal disclosed herein comprises acquisition means and transmission means. The acquisition means acquires business information required for a user to receive provision of a service using biometric authentication from an application installed on a host device. The transmission means transmits a token registration request including the acquired business information and biometric information of the user to a server device.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a terminal, a system, a terminal control method, and a storage medium. [Background technology]

[0002] There are technologies related to biometric authentication and the provision of services using biometric authentication.

[0003] For example, Patent Document 1 describes that a system, a server device, an authentication method, and a storage medium that contribute to improving the accuracy of biometric authentication are provided. The system in Patent Document 1 includes a server device and at least one authentication terminal. The server device stores the ID and biometric information of each of multiple users in association with each other. The at least one authentication terminal holds an ID list that stores the ID of at least one visitor who is staying in a specified area. When authentication of a person to be authenticated becomes necessary, the at least one authentication terminal transmits an authentication request to the server device, the authentication request including the biometric information of the person to be authenticated and the ID list. The server device extracts an ID included in the ID list from the IDs of each of the multiple users, and performs biometric authentication using the biometric information corresponding to the extracted ID and the biometric information included in the authentication request.

[0004] Patent Document 2 describes that an authentication server is provided that improves convenience for users who have been awarded points. The authentication server in Patent Document 2 includes a user registration unit, a point management unit, and a database. The user management unit acquires a first ID that uniquely identifies a user and biometric information used for biometric authentication of the user. The point management unit uses the results of the biometric authentication to manage first points awarded to the user by a service provider that provides the user with a service, and second points awarded to the user by an online provider that provides the user with an online service. The database stores the first ID, biometric information, and the total value of the first and second points in association with each other. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Patent No. 7036300 [Patent Document 2] International Publication No. 2022 / 137954 Summary of the Invention [Problem to be solved by the invention]

[0006] In the systems disclosed in Patent Documents 1 and 2, biometric information of users who receive services using biometric authentication and information necessary for providing services using biometric information must be registered in a server. Here, the question arises as to how the server can obtain the information necessary for providing services using the biometric information.

[0007] For example, information required to provide services using biometric information includes information (e.g., member IDs and boarding pass information) managed by the systems of airport companies (airport operating companies) and airlines. When a server obtains this information from the systems of airport companies, the systems of the airport companies must be able to provide the information. Here, the information required to provide services using biometric information is diverse, and changing the systems that hold each piece of information incurs significant costs. As a result, the spread of services using biometric authentication is hindered.

[0008] The main object of the present invention is to provide a terminal, a system, a terminal control method, and a storage medium that contribute to easily realizing system registration of information required for providing services using biometric authentication. [Means for solving the problem]

[0009] According to a first aspect of the present invention, there is provided a terminal comprising: an acquisition means for acquiring business information required for a user to receive services using biometric authentication from an application installed on the terminal; and a transmission means for transmitting a token registration request including the acquired business information and the user's biometric information to a server device.

[0010] According to a second aspect of the present invention, there is provided a system including a server device and a terminal carried by a user, wherein the terminal acquires business information necessary for the user to receive services using biometric authentication from an application installed on the terminal, and transmits a token registration request including the acquired business information and the user's biometric information to the server device, and in response to receiving the token registration request, the server device associates the user's biometric information and business information and stores them in a first database.

[0011] According to a third aspect of the present invention, there is provided a method for controlling a terminal, in which the terminal acquires business information necessary for a user to receive services using biometric authentication from an application installed on the terminal, and transmits a token registration request including the acquired business information and the user's biometric information to a server device.

[0012] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on a terminal to execute the following processes: acquiring business information necessary for a user to receive services using biometric authentication from an application installed on the terminal; and transmitting a token registration request including the acquired business information and the user's biometric information to a server device. [Effects of the Invention]

[0013] According to each aspect of the present invention, a terminal, a system, a terminal control method, and a storage medium are provided that contribute to easily realizing system registration of information necessary for providing services using biometric authentication. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]

[0014] [Figure 1] FIG. 1 is a diagram for explaining an outline of an embodiment. [Figure 2] FIG. 2 is a flowchart illustrating the operation of one embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to the first embodiment. [Figure 4] FIG. 4 is a diagram illustrating the operation of the information processing system according to the first embodiment. [Figure 5] FIG. 5 is a diagram illustrating applications installed on a terminal according to the first embodiment. [Figure 6] FIG. 6 is a diagram showing an example of a display on the terminal according to the first embodiment. [Figure 7] FIG. 7 is a diagram showing an example of a display on the terminal according to the first embodiment. [Figure 8] FIG. 8 is a diagram for explaining the operation of the information processing system according to the first embodiment. [Figure 9] FIG. 9 is a diagram for explaining the operation of the information processing system according to the first embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment. [Figure 11] FIG. 11 is a flowchart illustrating an example of the operation of the token control unit according to the first embodiment. [Figure 12] FIG. 12 is a diagram illustrating an example of a processing configuration of the airport terminal according to the first embodiment. [Figure 13] FIG. 13 is a diagram showing an example of a display of the airport terminal according to the first embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of a processing configuration of a server device according to the first embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of a user management database according to the first embodiment. [Figure 16] FIG. 16 is a flowchart illustrating an example of the operation of the token control unit according to the first embodiment. [Figure 17] FIG. 17 is a flowchart showing an example of the operation of the authentication unit according to the first embodiment. [Figure 18] FIG. 18 is a diagram illustrating an example of table information according to the first embodiment. [Figure 19] FIG. 19 is a diagram illustrating an example of a processing configuration of an authentication terminal according to the first embodiment. [Figure 20] FIG. 20 is a sequence diagram illustrating an example of the operation of the information processing system according to the first embodiment. [Figure 21] FIG. 21 is a sequence diagram illustrating an example of the operation of the information processing system according to the first embodiment. [Figure 22] FIG. 22 is a diagram illustrating an example of a display on a terminal according to the second embodiment. [Figure 23] FIG. 23 is a diagram illustrating an example of a behavior history management database according to the third embodiment. [Figure 24] FIG. 24 is a diagram illustrating an example of a processing configuration of a server device according to the third embodiment. [Figure 25] FIG. 25 is a diagram illustrating an example of a hardware configuration of a terminal according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0015] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0016] A terminal 100 according to an embodiment includes an acquisition unit 101 and a transmission unit 102 (see FIG. 1). The acquisition unit 101 acquires business information necessary for a user to receive a service using biometric authentication from an application installed on the terminal (step S1 in FIG. 2). The transmission unit 102 transmits a token registration request including the acquired business information and the user's biometric information to the server device (step S2).

[0017] The terminal 100 acquires business information necessary for receiving services using biometric authentication from an application installed on the terminal 100's own device (smartphone). The terminal 100 then transmits the acquired business information and the user's biometric information to a server device and requests token registration. By adopting this configuration, business information that is centrally managed by the service provider's system does not need to be transmitted from the system to the server device. As a result, system registration of information necessary for providing services using biometric authentication can be easily achieved without requiring major changes to each service provider's system.

[0018] Specific embodiments will be described in more detail below with reference to the drawings.

[0019] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0020] [System Configuration] 3 is a diagram showing an example of a schematic configuration of an information processing system (authentication system) according to the first embodiment. The information processing system shown in FIG. 3 includes a server device 10, a plurality of authentication terminals 20-1 to 20-4, and an airport terminal 30.

[0021] In the following description, unless there is a particular reason to distinguish between the authentication terminals 20-1 to 20-4, they will simply be referred to as "authentication terminal 20."

[0022] The server device 10 is a device that provides services using biometric authentication to airport users. The server device 10 is operated by any organization. For example, the server device 10 is operated by an airport company, an airline, a public institution such as a national or local government, or a private company commissioned by an airport company or a public institution.

[0023] The server device 10 may be installed in an airport or in a cloud on a network.

[0024] The authentication terminal 20 is a terminal (touch point) that serves as an interface for users who receive services using biometric authentication. Businesses (service providers) that provide users with services using biometric authentication install authentication terminals 20 at various locations within the airport according to the services they provide. Users receive services using biometric authentication via the authentication terminal 20.

[0025] For example, the authentication terminal 20-1 is a POS (Point of Sale) terminal installed in a shop or the like. For example, an airport company installs the authentication terminal 20-1 (POS terminal) in a shop or the like. For example, the airport company provides a payment service using biometric authentication to its members (hereinafter also referred to as airport members) via the authentication terminal 20-1. For example, the authentication terminal 20-1 executes control related to facial payment, etc.

[0026] The authentication terminal 20-2 is, for example, a reception terminal installed in a lounge or the like. For example, an airport company installs the authentication terminal 20-2 (reception terminal) at the entrance / exit (reception) of the lounge. For example, the airport company permits its members (airport members) to use the lounge free of charge. For example, the authentication terminal 20-2 notifies an employee or the like waiting at the lounge reception whether a user identified by biometric authentication is eligible to use the lounge free of charge.

[0027] The authentication terminal 20-3 is, for example, a digital signage installed in a lobby in an airport. For example, an airline installs the authentication terminal 20-3 (digital signage) in a departure and arrival lobby. For example, the airline provides various information to its members (hereinafter also referred to as airline members). For example, the authentication terminal 20-3 guides a user identified by biometric authentication to the location of the boarding gate or provides information about tourist spots.

[0028] The authentication terminal 20-4 is, for example, a gate device installed at each boarding gate. For example, an airline company installs the authentication terminal 20-4 (gate device). If a user identified by biometric authentication does not have the qualifications to board an aircraft, the authentication terminal 20-4 denies the user passage.

[0029] The airport terminal 30 is a terminal installed in an airport. A user operates the airport terminal 30 to carry out check-in procedures and the like. The airport terminal 30 also has a function related to registering a user's token. Specifically, the airport terminal 30 requests the server device 10 to register a user's token (issue a token). Details regarding tokens will be described later.

[0030] A user owns a terminal 40. Various applications are installed on the terminal 40. For example, an airport application used by members of an airport company and an airline application used by members of an airline company are installed on the terminal 40.

[0031] Users use the airport application to enjoy various services and benefits provided by the airport company. For example, users use the airport application to make reservations at hotels affiliated with the airport company, check flight information, etc. Or, users use the airport application to register credit card information and the like in the airport company's system. Users can then use the registered credit card information to make purchases (e.g., online shopping).

[0032] Furthermore, the user uses the airline application to purchase an airline ticket, check-in procedures, etc. For example, the user uses the airline application to manage a boarding pass.

[0033] Furthermore, the terminal 40 has the above-mentioned function related to token registration.

[0034] The devices (server device 10, authentication terminal 20, etc.) included in the information processing system shown in Fig. 3 are configured to be able to communicate with each other via a network. For example, the server device 10 and the authentication terminal 20 are connected by wired or wireless communication means and are configured to be able to communicate with each other.

[0035] 3 is an example and is not intended to limit the configuration of the information providing system disclosed in the present application. For example, the information processing system may include two or more server devices 10. Furthermore, the number of authentication terminals 20 included in the information processing system is not limited to four. It is sufficient that the information processing system includes at least one authentication terminal 20.

[0036] 3 is merely an example and is not intended to limit the entity that installs the authentication terminal 20 or the purpose of installation. An airport may also have installed authentication terminals 20 that are used for purposes other than POS terminals, reception terminals, digital signage, and gate devices. Alternatively, there may be a mixture of digital signage installed by airport companies and digital signage installed by airlines.

[0037] [System Overview] Next, the general operation of the information processing system will be described.

[0038] <Token registration> As described above, the airport terminal 30 and the terminal 40 have functions related to token registration.

[0039] The token is information required when the server device 10 provides a service using biometric authentication to a user, and is information registered in the system. Specifically, the token is composed of a combination of the user's biometric information and business information, and is stored in the database of the server device 10.

[0040] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, and iris pattern. Alternatively, the biometric information may be image data such as a face image or fingerprint image. The biometric information may be any information that includes the user's physical characteristics. In this disclosure, a case where biometric information related to a person's "face" (a face image or features generated from a face image) is used will be described.

[0041] The business information is information that a service provider (e.g., an airport company or an airline) needs to provide a service to a user. The business information differs depending on the service provider and the type of service provided by the service provider.

[0042] For example, if a facial payment service is provided to an airport member, the airport company's member ID will be the business information. In the following explanation, the airport company's member ID will be referred to as the "airport member ID." Alternatively, if a free lounge access service is provided to an airport member, the airport member ID will also be the business information.

[0043] Alternatively, when useful information is provided to an airline member, the airline member ID and boarding pass information become the business information. In the following explanation, the airline member ID will be referred to as the "airline member ID." Alternatively, when a user passes through authentication terminal 20-4 to board an aircraft, the boarding pass information becomes the business information.

[0044] Before receiving services using biometric authentication at the airport, the user must register the token in the system. Specifically, the user requests the server device 10 to register the token using the airport terminal 30 installed in the airport or the user's own terminal 40.

[0045] First, a case where a user uses an airport terminal 30 to request the server device 10 to register a token will be described.

[0046] When a user requests token registration (token issuance), the airport terminal 30 acquires the user's biometric information. For example, the airport terminal 30 photographs the user in front of the user and acquires a facial image.

[0047] The airport terminal 30 also acquires biometric information from an identification card held by the user. Specifically, the airport terminal 30 acquires a facial image from an identification card equipped with an IC (Integrated Circuit), such as a passport, a driver's license, or a My Number card.

[0048] The airport terminal 30 performs identity verification using biometric information obtained by photographing the user and biometric information acquired from the user's identification card. The airport terminal 30 performs identity verification (one-to-one authentication) using two pieces of biometric information (face images).

[0049] If the identity verification is successful, the airport terminal 30 acquires business information necessary for providing services using biometric authentication. For example, the airport terminal 30 acquires from the user airport company membership information (airport membership ID), airline membership information (e.g., airline membership ID), boarding pass information (information obtained from the boarding pass), etc.

[0050] The airport terminal 30 sends a "token registration request" including the user's biometric information (for example, a facial image obtained by photographing or a facial image read from an identification card) and business information to the server device 10 (see Figure 4).

[0051] Upon receiving the token registration request, the server device 10 registers (issues) a token using the biometric information and business information included in the token registration request. The server device 10 registers the information (biometric information, business information) acquired from the airport terminal 30 in a user management database. Details of the user management database in which the server device 10 stores the token will be described later.

[0052] The server device 10 notifies the airport terminal 30 of the processing result for the token registration request. If the token registration is successful, the server device 10 transmits a positive response indicating that to the airport terminal 30. If the token registration fails, the server device 10 transmits a negative response indicating that to the airport terminal 30.

[0053] The airport terminal 30 notifies the user of the result of the token registration request.

[0054] Next, a case where a user uses the terminal 40 to request the server device 10 to register a token will be described.

[0055] As described above, various applications are installed on the user's terminal 40. For example, the above-mentioned airport application, airline application, etc. are installed on the terminal 40.

[0056] Furthermore, the user installs an application for managing and controlling token registration on the terminal 40. For example, the user downloads a token control application from an application store or the like and installs it on the terminal 40.

[0057] 5, various applications such as a token control application, an airport application, and an airline application are installed on the terminal 40. The applications installed on the terminal 40 are configured to be able to send and receive data to and from each other.

[0058] The token-controlled application can cooperate with other applications, specifically, the token-controlled application can receive data from other applications and send data to other applications.

[0059] Here, an application installed on terminal 40 stores and manages information necessary for executing the application. For example, an airport application manages and stores a user's airport membership ID. Or, an airline application manages and manages a user's airline membership ID, boarding pass information, etc.

[0060] When a user requests a service using biometric authentication, the airport application, airline application, etc. transmits business information corresponding to the requested service to the token control application. For example, when a user requests to purchase a product at an airport kiosk using facial payment, the airport application transmits the airport member ID to the token control application.

[0061] Alternatively, if there are services using biometric authentication that can be offered to the user, the airport application or airline application will introduce the available services to the user. If the user wishes to receive the offered service, the airline application or the like will send business information corresponding to the desired service to the token control application.

[0062] For example, when the airline application obtains a boarding pass from the airline's system, it proposes passing through the gate device using biometric authentication. The airport application informs the user that they can pass through the gate device and board the aircraft without presenting documents (media) such as a boarding pass to airline staff. In the following explanation, passing through the gate device without presenting a boarding pass will be referred to as "face pass." If the user accepts the proposal, the airline application sends the boarding pass information to the token control application.

[0063] When business information is acquired from another application (when a push notification is received from another application), the token control application acquires the user's biometric information. For example, the token control application may take a selfie of the user and acquire a facial image of the user.

[0064] The token control application then acquires biometric information from the user's identification card, such as a passport, driver's license, or My Number card, and reads a facial image from the IC chip.

[0065] The token control application performs identity verification (one-to-one authentication) using two pieces of biometric information.

[0066] If the identity verification is successful, the token control application obtains consent for providing personal information to a third party (server device 10). For example, the token control application obtains consent from the user for providing personal information (biometric information and business information) to a third party using a GUI (Graphical User Interface) such as those shown in Fig. 6 and Fig. 7.

[0067] Fig. 6 shows an example of a GUI when the token control application acquires business information for face payment from the airport application. Fig. 7 shows an example of a GUI when the token control application acquires business information for face pass from the airline application.

[0068] After obtaining the user's consent to providing the biometric information and business information to a third party, the token control application sends a "token registration request" including the user's biometric information and business information to the server device 10 (see FIG. 8).

[0069] The server device 10 processes the token registration request received from the terminal 40 in the same way as the token registration request received from the airport terminal 30. The server device 10 notifies the terminal 40 of the processing result of the token registration request (token registration successful, token registration failed). The server device 10 transmits a response (positive response, negative response) to the token registration request to the terminal 40.

[0070] The terminal 40 (token control application) notifies the user of the result of the token registration request.

[0071] In this way, the terminal 40 acquires business information necessary for the user to receive services using biometric authentication from an application installed on the terminal 40. The terminal 40 transmits a token registration request including the acquired business information and the user's biometric information to the server device 10. In response to receiving the token registration request, the server device 10 associates the user's biometric information with the business information and stores them in a first database (user management database).

[0072] <Provision of services> A user receives a service using biometric authentication via the authentication terminal 20. A user who wishes to receive a service using biometric authentication moves in front of the authentication terminal 20, for example.

[0073] The authentication terminal 20 acquires biometric information of a user in response to an operation (instruction) by an employee of a service provider or the user, or the authentication terminal 20 automatically acquires biometric information of a user in front of the terminal 20.

[0074] For example, when a user wishes to purchase a product using facial payment, the authentication terminal 20-1 (POS terminal) photographs the user and acquires a facial image in response to an operation by a store clerk or the user (product purchaser). Alternatively, when a user wishes to enter a lounge, the authentication terminal 20-2 (reception terminal) photographs the user and acquires a facial image in response to an operation by a staff member waiting at the lounge reception desk.

[0075] Alternatively, when the authentication terminal 20-3 (digital signage) or the authentication terminal 20-4 (gate device) detects a user in front of the device, it photographs the user and acquires a face image.

[0076] The authentication terminal 20 transmits an "authentication request" including the acquired biometric information and terminal ID to the server device 10 (see FIG. 9).

[0077] The terminal ID is an ID for identifying the authentication terminal 20. The MAC (Media Access Control) address or IP (Internet Protocol) address of the authentication terminal 20 can be used as the terminal ID.

[0078] The terminal ID is shared by any method between the server device 10 and each authentication terminal 20. For example, a system administrator determines a terminal ID and sets the determined terminal ID in the server device 10. The system administrator also sets the determined terminal ID in each authentication terminal 20.

[0079] Upon receiving the authentication request, the server device 10 performs biometric authentication using the biometric information included in the authentication request and the biometric information registered in the user management database. The server device 10 then performs a matching process (one-to-N matching, where N is a positive integer; the same applies below) using the biometric information to identify the person to be authenticated.

[0080] Furthermore, the server device 10 uses the terminal ID included in the authentication request to identify the authentication terminal 20 that is the sender of the authentication request (identify the type of authentication terminal 20). The server device 10 transmits to the authentication terminal 20 business information corresponding to the identified authentication terminal 20 (business information of the person to be authenticated identified by the matching process).

[0081] For example, when an authentication request is received from authentication terminal 20-1 (POS terminal) or authentication terminal 20-2 (reception terminal), server device 10 notifies authentication terminal 20-1 of the airport member ID of the airport company.

[0082] Alternatively, when an authentication request is received from authentication terminal 20-3 (digital signage), server device 10 transmits the airline member ID or boarding pass information to authentication terminal 20-3. Alternatively, when an authentication request is received from authentication terminal 20-4 (gate device), server device 10 notifies authentication terminal 20-4 of the boarding pass information, etc.

[0083] The server device 10 transmits a response to the authentication request to the authentication terminal 20.

[0084] Specifically, if the matching process is successful and the business information corresponding to the authentication terminal 20 is registered in the user management database, the server device 10 transmits an affirmative response indicating successful authentication to the authentication terminal 20. More specifically, the server device 10 transmits an affirmative response to the authentication terminal 20, including the business information corresponding to the authentication terminal 20 that is the sender of the authentication request.

[0085] If the matching process fails, or if the business information corresponding to the authentication terminal 20 is not registered in the user management database, the server device 10 transmits a negative response to the authentication terminal 20 indicating that the authentication has failed.

[0086] If a negative response (authentication failure) is received, the authentication terminal 20 notifies the user, staff, or the like to that effect.

[0087] If an affirmative response (authentication success) is received, the authentication terminal 20 uses the transaction information acquired from the server device 10 to provide the service to the user.

[0088] For example, authentication terminal 20-1 (POS terminal) transmits to the airport company's system (not shown) the airport member ID and payment information (product name and purchase amount of the product purchased by the user) acquired from server device 10. The airport company's system (a system that provides various services to its own members) identifies the product purchaser using the airport member ID, and performs payment processing using the credit card information and payment information of the identified product purchaser.

[0089] Alternatively, the authentication terminal 20-2 (reception terminal) transmits the airport member ID acquired from the server device 10 to the airport company system. The airport company system transmits the member information (e.g., the member's name, etc.) stored in association with the airport member ID to the authentication terminal 20-2. The authentication terminal 20-2 notifies the staff member, etc., that the person to be authenticated is a member of the airport company, along with the acquired member information. The staff member then authorizes the person to be authenticated to use the lounge free of charge.

[0090] Alternatively, the authentication terminal 20-3 (digital signage) transmits the airline member ID acquired from the server device 10 to an airline system (not shown) and acquires the corresponding member information. The authentication terminal 20-3 displays information using the acquired member information (for example, flight information related to the aircraft the user is planning to board). Alternatively, the authentication terminal 20-3 provides information based on the boarding pass information acquired from the server device 10. For example, the authentication terminal 20-3 displays the location of the boarding gate for the aircraft the user will board.

[0091] Alternatively, authentication terminal 20-4 (gate device) uses boarding pass information acquired from server device 10 to determine whether the user has the authority to board an aircraft parked beyond authentication terminal 20-4. When authentication terminal 20-4 acquires from server device 10 boarding pass information corresponding to the aircraft for which it is determining whether or not the user is permitted to board, it opens the gate and allows the user to pass. When authentication terminal 20-4 cannot acquire from server device 10 boarding pass information corresponding to the aircraft for which it is determining whether or not the user is permitted to board, it closes the gate and denies the user passage.

[0092] In this way, the server device 10 receives an authentication request including biometric information of the person to be authenticated from the authentication terminal 20. The server device 10 identifies the person to be authenticated by performing a matching process using the biometric information included in the received authentication request and the biometric information stored in the user management database. The server device 10 transmits to the authentication terminal 20 business information corresponding to the authentication terminal 20 from at least one piece of business information of the person to be authenticated stored in the user management database.

[0093] Next, details of each device included in the information processing system according to the first embodiment will be described.

[0094] [Device] Examples of the terminal 40 include mobile terminal devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, notebook computers), and the like.

[0095] 10 is a diagram illustrating an example of a processing configuration (processing module) of the terminal 40 according to the first embodiment. Referring to FIG. 10, the terminal 40 includes a communication control unit 201, a token control unit 202, and a storage unit 203.

[0096] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0097] The token control unit 202 is a means for controlling tokens in the terminal 40. Specifically, the token control unit 202 requests the server device 10 to register a token. The token control unit 202 is a module that realizes the above-mentioned token control application.

[0098] The token control unit 202 requests the server device 10 to register a token required for the user to receive services using biometric authentication inside and outside the airport.

[0099] The token control unit 202 has a function as an acquisition unit that acquires business information necessary for a user to receive services using biometric authentication from an application installed on the token control unit 202. The token control unit 202 also has a function as a transmission unit that transmits a token registration request including the acquired business information and the user's biometric information to the server device.

[0100] 11 is a flowchart showing an example of the operation of the token control unit 202 according to the first embodiment. The operation of the token control unit 202 will be described with reference to FIG.

[0101] The token control unit 202 receives business information from another application (step S101). Specifically, the token control unit 202 acquires the business information through a push notification from the other application.

[0102] For example, the token control unit 202 acquires an airport member ID from an airport application, or an airline member ID from an airline application.

[0103] The token control unit 202 acquires the business information using, for example, an inter-application linking technique called Deep Link. Alternatively, the token control unit 202 may acquire the business information using a predetermined API (Application Programming Interface). For example, the token control unit 202 receives the business information from another application using an API defined by the token control application.

[0104] When the transaction information is received, the token control unit 202 acquires biometric information for identity verification (step S102). Specifically, the token control unit 202 acquires a facial image of the user by photographing the user.

[0105] Furthermore, the token control unit 202 acquires biometric information from an identification card held by the user. For example, the token control unit 202 acquires a facial image from an IC chip mounted on an identification card such as a passport, driver's license, or My Number card. The token control unit 202 communicates with the IC chip via NFC (Near Field Communication) and acquires the facial image stored in the IC chip.

[0106] The token control unit 202 performs identity verification (step S103). Specifically, the token control unit 202 performs identity verification using a facial image obtained by photographing the user and a facial image read from the IC chip of the identification card. The token control unit 202 performs identity verification by determining whether the two sets of biometric information substantially match.

[0107] The token control unit 202 generates feature quantities from each of the face image acquired by photographing and the face image acquired from the identification card.

[0108] Since existing technology can be used for the process of generating features, a detailed description thereof will be omitted. For example, the token control unit 202 extracts the eyes, nose, mouth, etc. from a face image as feature points. Then, the token control unit 202 calculates the positions of the feature points and the distances between the feature points as feature amounts (generating a feature vector consisting of multiple feature amounts).

[0109] Next, the token control unit 202 executes authentication processing (one-to-one authentication) using the two generated feature amounts. Specifically, the token control unit 202 calculates the similarity between corresponding face images using the two feature amounts. Based on the result of threshold processing on the calculated similarity, the token control unit 202 determines whether the two images are face images of the same person. Note that the similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0110] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the token control unit 202 determines that the identity verification is successful. If the similarity is equal to or less than the predetermined value, the token control unit 202 determines that the identity verification is unsuccessful.

[0111] The token control unit 202 may also perform "liveness authentication" to prove that a user is actually present. Specifically, after successfully authenticating (matching) a face image obtained by photographing with a face image read from an identification card, the token control unit 202 instructs the user to perform a predetermined action and determines whether the user (person to be authenticated) follows the instruction. For example, the token control unit 202 may give an instruction such as "close your right eye" and determine whether the user actually exists based on whether the user follows the instruction.

[0112] If the identity verification fails (step S104, No branch), the token control unit 202 ends the process related to token registration. In this case, the token control unit 202 may notify the user that the token cannot be registered (issued) due to the failure of identity verification.

[0113] If the identity verification is successful (step S104, branch Yes), the token control unit 202 obtains the user's consent to the provision of personal information to a third party (step S105).

[0114] The token control unit 202 obtains the user's consent using a GUI that corresponds to the type (content) of the acquired business information and the application that is the provider of the business information. For example, the token control unit 202 obtains the user's consent regarding the provision of personal information to a third party using the GUI shown in Fig. 6 or 7.

[0115] If consent to the provision of personal information (biometric information and business information) is not obtained (step S106, No branch), the token control unit 202 terminates the process for token registration. In this case, the token control unit 202 may notify the user that the token cannot be registered unless the personal information is provided to a third party.

[0116] If consent to the provision of personal information is obtained (step S106, Yes branch), the token control unit 202 transmits a token registration request to the server device 10 (step S107). The token control unit 202 transmits a "token registration request" to the server device 10, which includes the user's biometric information (for example, a facial image obtained by photographing or a facial image read from an identification card) and business information.

[0117] The token control unit 202 receives a response (positive response or negative response) to the token registration request (step S108).

[0118] The token control unit 202 executes processing according to the result of the token registration request (step S109).

[0119] If a positive response (token registration success) is received, the token control unit 202 notifies the user that, for example, services using biometric authentication can be provided inside and outside the airport.

[0120] When a negative response (token registration failure) is received, the token control unit 202 notifies the user that the token registration has failed, for example.

[0121] With reference to FIG. 11, the token control unit 202 has been described as performing identity verification using biometric authentication (step S103) and then obtaining consent to providing personal information to a third party (step S105). However, the token control unit 202 may perform identity verification using biometric authentication after obtaining consent to providing personal information to a third party. For example, the token control application receives boarding pass information from an airline application. In response to receiving the boarding pass information, the token control application (token control unit 202) obtains the user's consent to providing the biometric information and boarding pass information to an external server while clearly indicating the purpose of use of the obtained boarding pass information. After obtaining consent, the token control application performs identity verification using the user's biometric information.

[0122] In this way, the token control unit 202 has a function as consent acquisition means that acquires the user's consent to providing the user's personal information (business information and biometric information) to a third party before sending a token registration request to the server device 10. Furthermore, the token control unit 202 has a function as identity verification means that performs identity verification using biometric information acquired from the user and biometric information acquired from an identification card held by the user. After successfully verifying the identity of the user who wishes to register a token, the token control unit 202 sends a token registration request to the server device 10.

[0123] The storage unit 203 is a means for storing information necessary for the operation of the terminal 40 .

[0124] Note that detailed explanations of processing modules for realizing the airport application, airline application, etc. will be omitted, as details of applications other than the token control application are outside the scope of the present disclosure.

[0125] [Airport terminal] 12 is a diagram showing an example of a processing configuration (processing module) of the airport terminal 30 according to the first embodiment. Referring to FIG. 12, the airport terminal 30 includes a communication control unit 301, a token control unit 302, and a storage unit 303.

[0126] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the server device 10. The communication control unit 301 also transmits data to the server device 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0127] The token control unit 302 is a means for controlling tokens in the airport terminal 30. The token control unit 302 performs identity verification using biometric information. The operations related to identity verification by the token control unit 302 can be the same as the operations related to identity verification by the token control unit 202 of the terminal 40, so a description thereof will be omitted.

[0128] The token control unit 302 acquires business information from the user. For example, the token control unit 302 acquires business information (for example, an airport member ID) using a GUI.

[0129] Alternatively, the token control unit 302 acquires business information from the terminal 40. For example, the token control unit 302 acquires business information using a GUI. For example, the token control unit 302 displays a list of services that can be provided using biometric authentication. The user selects a desired service from the displayed list. For example, the user selects "purchase a product using facial payment."

[0130] The token control unit 302 acquires business information according to the service selected by the user. For example, the token control unit 302 acquires the business information using a GUI such as that shown in FIG.

[0131] A user who encounters the GUI shown in Fig. 13 operates terminal 40 to launch an application instructed by airport terminal 30. The user performs a predetermined operation in the launched application. Terminal 40 displays a two-dimensional barcode into which the business information has been converted in response to the user's operation. For example, the airport application displays a two-dimensional barcode generated based on the airport member ID.

[0132] When the "OK" button is pressed in the GUI shown in FIG. 13, the token control unit 302 reads the two-dimensional barcode presented by the user and acquires the transaction information.

[0133] The token control unit 302 transmits a token registration request including the user's biometric information and business information to the server device 10. The token control unit 302 executes processing according to the response to the token registration request (token registration successful, token registration failed).

[0134] The storage unit 303 is a means for storing information necessary for the operation of the airport terminal 30 .

[0135] [Server device] 14 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to the first embodiment. Referring to FIG. 14, the server device 10 includes a communication control unit 401, a token control unit 402, an authentication unit 403, and a storage unit 404.

[0136] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the authentication terminal 20. The communication control unit 401 also transmits data to the authentication terminal 20. The communication control unit 401 hands over data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0137] The token control unit 402 is a means for controlling tokens in the server device 10. The token control unit 402 processes a token registration request received from the terminal 40 or the airport terminal 30.

[0138] When receiving a token registration request, the token control unit 402 registers the biometric information and business information included in the token registration request in the user management database (see FIG. 15). As shown in FIG. 15, the user management database stores the user ID, biometric information (feature amount), and business information of the user in association with each other.

[0139] As shown in Fig. 15, the user management database classifies and stores acquired business information into business information that is permanently stored and business information that is temporarily stored. For example, airport member IDs and airline member IDs are business information that is permanently stored, while boarding pass information is business information that is temporarily stored (for example, stored for only 24 hours after registration).

[0140] The system administrator or the like decides which storage method to classify each piece of business information into and sets it in the server device 10. The system administrator or the like can decide the storage method by taking into consideration the content (nature) of the business information. For example, an airport membership ID is business information that is used repeatedly, while boarding pass information is business information that ends its use once the user boards an aircraft. The system administrator or the like decides the storage method for each piece of business information by taking into consideration these circumstances.

[0141] 15 is an example and is not intended to limit the items to be stored, etc. For example, a "face image" may be registered in the user management database as biometric information.

[0142] 16 is a flowchart showing an example of the operation of the token control unit 402 according to the first embodiment. The operation of the token control unit 402 will be described with reference to FIG.

[0143] When receiving a token registration request, the token control unit 402 determines the quality of the biometric information (face image) included in the token registration request (step S201).

[0144] Specifically, the token control unit 402 determines whether the received facial image has sufficient quality for authentication purposes. For example, the token control unit 402 determines the quality of the facial image using a learning model prepared in advance. The token control unit 402 inputs the facial image into the learning model and obtains the determination result.

[0145] The learning model is obtained by machine learning using a large amount of training data in which labels (quality: good, bad) are assigned to image data (face images). Any algorithm such as a support vector machine, boosting, or neural network can be used to generate the learning model. Since known techniques can be used for the algorithms such as the support vector machine, a description thereof will be omitted.

[0146] If the quality of the facial image is poor (step S202, No branch), the token control unit 402 determines that the token registration has failed. In this case, the token control unit 402 transmits a negative response indicating that the token registration has failed to the sender of the token registration request (step S203).

[0147] If the quality of the facial image is good (step S202, Yes branch), the token control unit 402 determines whether or not an entry for the user who wishes to register a token exists in the user management database.

[0148] Specifically, the token control unit 402 performs a matching process (1:N matching; N is a positive integer, same below) using the biometric information included in the token registration request and the biometric information stored in the user management database (step S204).

[0149] The token control unit 402 generates features from the facial image included in the token registration request. The token control unit 402 sets the generated features (feature vector) as features on the matching side, and sets the features registered in the user management database as features on the registration side.

[0150] The token control unit 402 calculates the similarity between the feature on the matching side and each of the multiple feature on the registration side. Note that the similarity can be calculated using chi-square distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0151] The token control unit 402 determines that the matching process has been successful if there is a feature among the multiple feature quantities registered in the user management database that has a similarity with the feature quantity to be matched that is equal to or greater than a predetermined value. If there is no such feature quantity, the token control unit 402 determines that the matching process has failed.

[0152] If the matching process fails (step S205, No branch), the token control unit 402 adds a new entry to the user management database (step S206).

[0153] Thereafter, the token control unit 402 generates a user ID for identifying the user. The user ID may be any information that can uniquely identify the user. For example, the token control unit 402 may assign a unique value each time an entry is added and use the number as the user ID.

[0154] The token control unit 402 stores the user ID, biometric information (feature amount), and business information in the added entry (step S207).

[0155] If the matching process is successful (step S205, Yes branch), the token control unit 402 stores the transaction information in the entry identified by the matching process (the entry storing the biometric information with the highest similarity) (step S208).

[0156] After registering the token in the user management database, the token control unit 402 notifies the sender of the token registration request (airport terminal 30, terminal 40) of the success of the token registration. Specifically, the token control unit 402 sends an affirmative response indicating the success of the token registration to the sender of the token registration request (step S209).

[0157] The token control unit 402 has a function to delete business information registered in the user management database. The token control unit 402 accesses the user management database periodically or at a predetermined timing. The token control unit 402 deletes business information that is temporarily stored in each entry (token) of the database and for which a predetermined time (e.g., 24 hours) has passed since registration.

[0158] The authentication unit 403 is a means for authenticating a user (person to be authenticated) who wishes to receive a service via the authentication terminal 20. The authentication unit 403 processes authentication requests received from each authentication terminal 20 (touch point) installed inside and outside the airport.

[0159] 17 is a flowchart showing an example of the operation of the authentication unit 403 according to the first embodiment. The operation of the authentication unit 403 will be described with reference to FIG.

[0160] The authentication request includes the biometric information of the person to be authenticated and the terminal ID.

[0161] The authentication unit 403 executes a matching process (one-to-N matching; N is a positive integer, the same applies below) using the biometric information included in the authentication request and the biometric information stored in the user management database (step S301).

[0162] The matching process by the authentication unit 403 can be the same as the matching process by the token control unit 402, so a detailed description thereof will be omitted.

[0163] If the matching process fails (step S302, No branch), authentication unit 403 transmits a negative response indicating that authentication of the authenticatee has failed to authentication terminal 20 (step S303).

[0164] If the matching process is successful (step S302, Yes branch), the authentication unit 403 uses the terminal ID included in the authentication request to identify the authentication terminal 20 that sent the authentication request (the type of authentication terminal 20; for example, a POS terminal, a reception terminal, a digital signage, a gate device, etc.).

[0165] For example, the authentication unit 403 refers to table information that stores the type of authentication terminal 20 in association with the business information required by the authentication terminal 20 to provide the business, and identifies the business information corresponding to the authentication terminal 20 (see FIG. 18). Note that in FIG. 18, for ease of understanding, the terminal ID indicates the type of each authentication terminal 20 shown in FIG. 3.

[0166] The authentication unit 403 attempts to read out the business information corresponding to the identified authentication terminal 20 from the user management database (step S304).

[0167] If the business information corresponding to the authentication terminal 20 cannot be read from the user management database (step S305, No branch), the authentication unit 403 determines that the authentication of the person to be authenticated has failed. In this case, the authentication unit 403 transmits a negative response indicating that the authentication of the person to be authenticated has failed to the authentication terminal 20 (step S303).

[0168] If the business information corresponding to the authentication terminal 20 can be read from the user management database (step S305, Yes branch), the authentication unit 403 determines that the authentication of the person to be authenticated has been successful. In this case, the authentication unit 403 transmits an affirmative response indicating that the authentication of the person to be authenticated has been successful to the authentication terminal 20 (step S306). At that time, the authentication unit 403 transmits an affirmative response including the business information read from the user management database to the authentication terminal 20.

[0169] The storage unit 404 stores various information necessary for the operation of the server device 10. In the storage unit 404, a user management database is constructed.

[0170] [Authentication terminal] 19 is a diagram showing an example of the processing configuration (processing modules) of the authentication terminal 20 according to the first embodiment. Referring to FIG. 19, the authentication terminal 20 includes a communication control unit 501, a biometric information acquisition unit 502, an authentication request unit 503, a function realization unit 504, and a storage unit 505.

[0171] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the server device 10. The communication control unit 501 also transmits data to the server device 10. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 501. The communication control unit 501 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0172] The biometric information acquisition unit 502 is a means for controlling a camera (not shown) and acquiring biometric information of a user. For example, the biometric information acquisition unit 502 takes an image of a user in front of the device in response to an operation by a store staff member or the like. Alternatively, the biometric information acquisition unit 502 takes an image of an area in front of the device periodically or at a predetermined timing. The biometric information acquisition unit 502 determines whether the acquired image contains a human face image, and if a face image is included, extracts the face image from the acquired image data.

[0173] Note that since existing technologies can be used for the facial image detection process and facial image extraction process by the biometric information acquisition unit 502, detailed description thereof will be omitted. For example, the biometric information acquisition unit 502 may extract a facial image (face region) from image data using a learning model trained by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 502 may extract a facial image using a method such as template matching.

[0174] The biometric information acquisition unit 502 passes the extracted face image to the authentication request unit 503 .

[0175] The authentication request unit 503 is a means for requesting authentication of the user in front of the server device 10. The authentication request unit 503 generates an authentication request including the acquired face image and terminal ID, and transmits it to the server device 10.

[0176] The authentication request unit 503 receives a response (positive response, negative response) to the authentication request from the server device 10. The authentication request unit 503 passes the received response to the function implementation unit 504.

[0177] The function realization unit 504 is a means for realizing the functions assigned to each authentication terminal 20. A detailed explanation of the operation of the function realization unit 504 of each authentication terminal 20 will be omitted because the operation of each authentication terminal 20 differs from the gist of the present disclosure.

[0178] The storage unit 505 is a means for storing information necessary for the operation of the authentication terminal 20 .

[0179] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described. Fig. 20 is a sequence diagram showing an example of the operation of the information processing system according to the first embodiment. With reference to Fig. 20, the operation of the information processing system when a token registration request is transmitted from the terminal 40 will be described.

[0180] The terminal 40 acquires business information from an application installed in the terminal 40, and transmits a token registration request including the acquired business information and the like to the server device 10 (step S01).

[0181] In response to receiving the token registration request, the server device 10 registers the token (step S02).

[0182] The server device 10 transmits the result of the token registration process (token registration success, token registration failure) to the terminal 40 (step S03).

[0183] The terminal 40 executes processing according to the received result (token registration success, token registration failure) (step S04).

[0184] The user can request token registration from the server device 10 multiple times using the terminal 40 or the airport terminal 30. For example, the user may use the terminal 40 to request the server device 10 to register a token related to an airport member ID. Thereafter, the user may use the airport terminal 30 to request the server device 10 to register a token related to the airline member ID.

[0185] 21 is a sequence diagram showing an example of the operation of the information processing system according to the first embodiment. With reference to FIG. 21, the operation of the information processing system when the authentication process is performed will be described.

[0186] The authentication terminal 20 acquires biometric information of the user and transmits an authentication request including the acquired biometric information to the server device 10 (step S11).

[0187] The server device 10 executes authentication processing using the biometric information included in the authentication request and the biometric information and business information included in the user management database (step S12).

[0188] The server device 10 transmits the authentication result (authentication success, authentication failure) to the authentication terminal 20 (step S13).

[0189] The authentication terminal 20 executes processing according to the received authentication result (authentication success, authentication failure) (step S14).

[0190] Next, a modified example of the first embodiment will be described.

[0191] <Modification> In the above embodiment, the case has been described in which the server device 10 transmits business information relating to the installation entity of the authentication terminal 20 that transmits the authentication request to the authentication terminal 20. However, the business information transmitted by the server device 10 is not limited to business information relating to the installation entity of the authentication terminal 20.

[0192] For example, when an authentication request is received from authentication terminal 20-1 (POS terminal) installed by an airport company, server device 10 may transmit an airline member ID to authentication terminal 20-1 instead of or in addition to the airport member ID. By receiving the airline member ID of the person to be authenticated who has successfully passed biometric authentication, authentication terminal 20-1 determines that the person to be authenticated is a member of the airline. In this case, authentication terminal 20-1 can grant benefits to the airline member, such as a discount on merchandise prices.

[0193] In this way, in the information processing system according to the first embodiment, business information preset in the server device 10 is transmitted to the authentication terminal 20, regardless of the entity that installs the authentication terminal 20. As a result, business partnerships between different businesses (service providers) can be easily realized.

[0194] For example, consider a case where airport company A and airline B have formed a business partnership. Airport company A can easily build a system that gives preferential treatment to users (members) of airline B among multiple airlines. For example, if members of airline B are given a special benefit when they purchase products at a convenience store, server device 10 can send the airline member ID of airline B to authentication terminal 20-1 when an authentication request from authentication terminal 20-1 is successful. Alternatively, if members of airline B are also allowed to use Lauzin free of charge, server device 10 can send the airline member ID of airline B to authentication terminal 20-2 when processing an authentication request from authentication terminal 20-2 (reception terminal).

[0195] In order to realize the provision of such biometric authentication services across a plurality of service providers, the system administrator or the like only needs to rewrite the table information shown in FIG. 18 (reset the table information).

[0196] In this way, in response to receiving a token registration request including a first ID of a first business operator as business information, the server device 10 associates the user's biometric information with the first ID and stores them in the user management database. Furthermore, in response to receiving a token registration request including a second ID of a second business operator as business information, the server device 10 associates the user's biometric information, the first ID, and the second ID and stores them in the user management database.

[0197] As described above, the terminal 40 according to the first embodiment acquires business information necessary for receiving a service using biometric authentication from an application installed on the terminal 40 itself (for example, a smartphone). The terminal 40 transmits the acquired business information and the user's biometric information to the server device 10, and requests token registration. The information processing system according to the first embodiment registers business information stored in a distributed manner in the terminals 40 owned by individuals in the system (server device 10) via a token control application. Therefore, there is no need to transmit business information centrally managed by the service provider's system to the server device 10. As a result, system registration of information necessary for providing a service using biometric authentication can be easily realized.

[0198] When a service provider provides various services using biometric authentication to users, a problem arises as to how to register business information (e.g., membership information) corresponding to each service into the system. To address this problem, in the information processing system according to the first embodiment, a token control application collects business information stored in a distributed manner across terminals 40 and registers the collected business information in the server device 10. By adopting such a configuration, new services using biometric authentication can be easily launched. In recent years, users have become increasingly aware of personal information, leading to a trend toward registering necessary information on smartphones and other devices. This trend is expected to continue. If business information necessary for services using biometric authentication can be acquired from terminals 40, such as smartphones, it becomes possible to register the information necessary for biometric authentication into the system without implementing extensive system integration.

[0199] Furthermore, the server device 10 according to the first embodiment stores information of each service provider (e.g., information such as a member ID) in a linked manner via the user's biometric information. That is, the member information (member ID) of each service provider is in a "loosely coupled" state, being independent of but coupled with each system. By storing such member information (member ID) in a loosely coupled state, the server device 10 can easily realize collaboration between each service provider. Specifically, collaboration between each service provider can be easily realized by a system administrator or the like rewriting table information such as that shown in FIG. 18. When the authentication process is successful, the server device 10 may transmit the member information of other service providers that are linked with the service provider to the authentication terminal 20 (a device installed by the service provider) in accordance with the rewritten table information.

[0200] [Second embodiment] Next, the second embodiment will be described in detail with reference to the drawings.

[0201] In the first embodiment, a case where an application installed in the terminal 40 notifies (push notifies) the token control application of business information will be described. In the second embodiment, a case where a token control application requests another application to provide business information will be described.

[0202] The configuration of the information processing system according to the second embodiment can be the same as that of the first embodiment, and therefore the description corresponding to Fig. 3 will be omitted. Also, the processing configuration of the server device 10 and the like according to the second embodiment can be the same as that of the first embodiment, and therefore the description thereof will be omitted.

[0203] The following description will focus on the differences between the first and second embodiments.

[0204] The terminal 40 displays a list of biometric authentication-based services that can be provided to the user, and acquires the service that the user wishes to receive from the displayed list of services. The terminal 40 acquires business information necessary to provide the acquired service (the service selected by the user) from among the applications installed on the terminal 40.

[0205] Specifically, when a user performs a predetermined action, the token control unit 202 of the terminal 40 displays a list of services (services using biometric information) that can be provided to the user using business information obtained from an application installed on the device.

[0206] At this time, the token control unit 202 acquires information about the applications installed in the terminal 40. For example, the token control unit 202 acquires information such as the names and versions of the applications installed in the terminal 40 from the OS (Operating System).

[0207] Next, the token control unit 202 refers to table information that stores business information obtained from applications installed on the terminal 40 in association with services that can be provided to users. The token control unit 202 refers to the table information and generates a list of services that can be provided to users using business information obtained from other applications.

[0208] The token control unit 202 uses the generated list of services to display a GUI such as that shown in Fig. 22. The token control unit 202 uses the GUI to acquire information about the services that the user wishes to receive.

[0209] The token control unit 202 requests the application that stores the business information required for the service desired by the user to provide the business information. The token control unit 202 obtains the required business information from another application using Deep Link, API, etc.

[0210] After acquiring the transaction information, the token control unit 202 performs identity verification of the user. The token control unit 202 performs identity verification using a facial image obtained by photographing the user and a facial image obtained from an identification card.

[0211] If the identity verification is successful, the token control unit 202 obtains the user's consent to providing personal information (biometric information and business information) to a third party. The token control unit 202 obtains the user's consent using a GUI similar to that shown in FIG. 6 or FIG. 7.

[0212] Once the user's consent is obtained, the token control unit 202 transmits a token registration request including the biometric information and business information to the server device 10.

[0213] In the second embodiment, similarly to the first embodiment, the token control unit 202 may perform identity verification using the user's biometric information after obtaining consent for the provision of personal information to a third party. In this case, the token control unit 202 may obtain consent from the user for the provision of personal information to a third party on a list display screen such as that shown in Fig. 22. For example, the token control unit 202 may display "biometric information to be provided to a third party" together with "business information to be provided to a third party" and "purpose of use of personal information (biometric information, business information)" for each service that can be provided.

[0214] As described above, the terminal 40 according to the second embodiment presents the user with a list of services that can be provided based on business information that can be collected from applications installed on the terminal 40. The terminal 40 acquires business information corresponding to the service selected by the user from the application, and registers the acquired business information in the server device 10. In the second embodiment as well, system registration of information necessary for providing services using biometric authentication can be easily realized.

[0215] [Third embodiment] Next, the third embodiment will be described in detail with reference to the drawings.

[0216] In the third embodiment, a case will be described in which the server device 10 provides the behavior history of the user to a service provider or the like.

[0217] The configuration of the information processing system according to the third embodiment can be the same as that of the first and second embodiments, and therefore a description corresponding to FIG. 3 will be omitted.

[0218] The following description will focus on the differences between the first to third embodiments.

[0219] The authentication unit 403 according to the third embodiment stores details of the authentication process executed in response to the reception of the authentication request in the behavior history management database. The authentication unit 403 generates a behavior history of the user by storing the details of the authentication process.

[0220] For example, the authentication unit 403 stores the date and time when the biometric authentication was successful, information about the authentication terminal 20 used by the person to be authenticated (for example, the installation location and type) in the behavior history management database (see FIG. 23). Alternatively, when the authentication unit 403 can acquire accompanying information such as payment information in addition to the biometric information from the authentication terminal 20, it also stores the accompanying information in the behavior history management database.

[0221] If the authentication unit 403 succeeds in authenticating the person to be authenticated, it searches the behavior history management database using the user ID of the person to be authenticated as a key. If the search is successful, the authentication unit 403 stores the behavior history in the entry identified by the search.

[0222] If the search fails, the authentication unit 403 adds a new entry to the behavior history management database. In the added entry, the authentication unit 403 stores the user's user ID and information corresponding to the ID used by the service provider to manage the user from the business information stored in the user management database. In the example of the user management database shown in FIG. 15, the authentication unit 403 stores the airport company's member ID (airport member ID) and the airline's member ID (airline member ID) in the behavior history management database. Furthermore, the authentication unit 403 stores the user's behavior history in the added entry.

[0223] The authentication unit 403 generates a behavior history as shown in the behavior history management database of Fig. 23. Note that the behavior history management database shown in Fig. 23 is an example and is not intended to limit the items to be stored.

[0224] Fig. 24 is a diagram showing an example of a processing configuration (processing module) of the server device 10 according to the third embodiment. Referring to Fig. 24, an information provision control unit 405 is added to the configuration of the server device 10 according to the first embodiment.

[0225] The information provision control unit 405 is a means for providing information about user behavior based on requests from service providers participating in the system, etc. The information provision control unit 405 generates information to be provided using the behavior history stored in the behavior history management database, and outputs the generated information to be provided.

[0226] The information provision control unit 405 acquires a request for information provision from a service provider. For example, the information provision control unit 405 acquires a request for information provision from a service provider using a portal site or the like that can be accessed by a person in charge of the service provider.

[0227] The information provision control unit 405 acquires the IDs of users whose behavioral histories are to be known from the service provider. For example, an airport company inputs the IDs (list of IDs) of users who are members of the company and whose behavioral histories are to be known to a portal site.

[0228] The information provision control unit 405 searches the behavior history management database using the acquired ID (ID list) as a key and identifies the corresponding entry. The information provision control unit 405 provides the behavior history stored in the behavior history field of the identified entry to the service provider.

[0229] As described above, when the server device 10 according to the third embodiment successfully authenticates a person to be authenticated, the server device 10 generates a behavioral history of the person to be authenticated using at least information related to the authentication terminal 20. The server device 10 associates the first ID, second ID, and generated behavioral history of the person to be authenticated and stores them in a behavioral history management database (second database). When the server device 10 acquires a first ID from a first service provider, the server device 10 reads the behavioral history of the user corresponding to the first ID from the behavioral history management database and provides the read behavioral history to the first service provider. As a result, behavioral histories involving multiple service providers can be easily collected. In other words, by utilizing the information provided by the server device 10 according to the third embodiment, data across multiple service providers can be analyzed. For example, an airport company and a railway company can perform data analysis from the perspective of MaaS (Mobility as a Service). Note that the multiple service providers may or may not cooperate with each other.

[0230] Next, the hardware of each device constituting the information processing system will be described. Fig. 25 is a diagram showing an example of the hardware configuration of the terminal 40.

[0231] The terminal 40 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 25. For example, the terminal 40 has a processor 311, a memory 312, an input / output interface 313, a communication interface 314, etc. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0232] However, the configuration shown in Fig. 25 is not intended to limit the hardware configuration of the terminal 40. The terminal 40 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the terminal 40 is not intended to be limited to the example shown in Fig. 25, and for example, the terminal 40 may include multiple processors 311.

[0233] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0234] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0235] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.

[0236] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0237] The functions of the terminal 40 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by a semiconductor chip.

[0238] The server device 10 and the like can also be configured by an information processing device in the same way as the terminal 40, and the basic hardware configuration is no different from that of the terminal 40, so a description thereof will be omitted.

[0239] The terminal 40, which is an information processing device, is equipped with a computer, and the computer executes a program to realize the functions of the terminal 40. The terminal 40 also executes a control method for the terminal 40 by the program.

[0240] [Variations] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0241] In the above embodiment, the operation of the information processing system disclosed herein has been described using an authentication system in an airport as an example. However, the information processing system disclosed herein may be used in facilities other than airports. For example, the information processing system may be used in an authentication system in a large station such as a terminal station. Alternatively, the information processing system may be used in an authentication system at an event venue or the like.

[0242] In the above embodiment, the information processing system disclosed herein has been described using an airport where domestic flights take off and land as an example. However, the information processing system disclosed herein may also be used for an airport where international flights take off and land. In this case, the user simply registers the passport information stored in the terminal 40 as business information in the server device 10.

[0243] In the above embodiment, an airport application and an airline application have been described as examples of applications other than the token control application. However, it is of course not intended to limit the applications installed on the terminal 40 to these applications. The token control application can acquire business information from any application installed on the terminal 40. For example, the token control application may acquire business information from a train application used by members of a railway company.

[0244] In the above embodiment, a case has been described in which a system administrator sets a storage method (permanent storage, temporary storage) for each piece of business information in the server device 10. The storage method may be selected by the user himself / herself. For example, the terminal 40 may allow the user to select a storage method for business information when obtaining the user's consent regarding the provision of personal information to a third party through the GUI shown in FIG. 6 or FIG. 7.

[0245] In the second embodiment, it has been described that a list of services that can be provided to a user using business information obtained from an application installed on the terminal 40 is displayed (see FIG. 22). However, the terminal 40 may generate a list of services (services using biometric authentication) that can be provided to the user as a system and display a GUI. Furthermore, if a user selects a service that uses business information that can be obtained from an application not installed on the terminal 40, the terminal 40 may prompt the user to install the not-installed application. For example, if a "face pass for boarding gate" that uses boarding information obtainable from an airline application is selected and the airline application is not installed on the terminal 40, the terminal 40 prompts the user to install the airline application. Note that even when a list of services that can be provided to a user as a system is displayed to the user, the terminal 40 may perform identity verification using biometric information after obtaining the user's consent to providing personal information to a third party, as described in the second embodiment.

[0246] Alternatively, if the version of the application installed on the terminal 40 is old and appropriate business information cannot be acquired, the terminal 40 may prompt the user to upgrade the application.

[0247] In the above embodiment, the case where the quality check of the biometric information at the time of issuing the token (at the time of registering the token) is performed by the server device 10 has been described. However, the quality check may be performed by the airport terminal 30 or the terminal 40.

[0248] In the above embodiment, a case has been described in which biometric information related to a facial image is transmitted and received between the server device 10 and the authentication terminal 20. However, features generated from a facial image may also be transmitted and received between the devices. In this case, the receiving server device 10 may use the received features and utilize the received features in subsequent processing. Alternatively, the biometric information stored in the user management database may be features or a facial image. If a facial image is stored, features may be generated from the facial image as needed. Alternatively, both the facial image and features may be stored in the user management database.

[0249] In the above embodiment, the case where the user management database is configured inside the server device 10 has been described, but the user management database may also be configured in an external database server or the like. That is, some functions of the server device 10 or the like may be implemented in another server. More specifically, it is sufficient that the above-described "token control unit (token control means)" or the like is implemented in any of the devices included in the system.

[0250] The form of data transmission and reception between each device (server device 10, terminal 40, etc.) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Biometric information and the like is transmitted and received between these devices, and in order to appropriately protect personal information, it is desirable that encrypted data be transmitted and received.

[0251] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0252] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0253] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to information processing systems that provide users with services using biometric authentication.

[0254] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. [Appendix 1] an acquisition means for acquiring business information necessary for a user to receive a service using biometric authentication from an application installed on the user's own device; a transmitting means for transmitting a token registration request including the acquired business information and the biometric information of the user to a server device; A terminal comprising: [Appendix 2] The terminal described in Appendix 1, further comprising a consent acquisition means for acquiring the user's consent to providing the business information and biometric information to a third party before sending the token registration request to the server device. [Appendix 3] The system further comprises an identity verification unit that performs identity verification using biometric information acquired from the user and biometric information acquired from an identification card held by the user, 3. The terminal according to claim 2, wherein the transmitting means transmits the token registration request to the server device after the identity verification is successful. [Appendix 4] The acquisition means Displaying a list of services using biometric authentication that can be provided to the user, and selecting a service that the user wishes to receive from the displayed list of services; 4. The terminal according to claim 3, wherein business information necessary for providing the acquired service is acquired from among applications installed on the terminal. [Appendix 5] a server device; A device owned by the user, Including, The terminal acquires business information necessary for the user to receive a service using biometric authentication from an application installed on the device, and transmits a token registration request including the acquired business information and the user's biometric information to the server device; The server device In response to receiving the token registration request, the system associates the user's biometric information and business information and stores them in a first database. [Appendix 6] The server device In response to receiving the token registration request including a first ID of a first business operator as the business information, storing the biometric information of the user and the first ID in association with each other in the first database; The system described in Appendix 5, wherein, in response to receiving the token registration request including the second ID of a second business operator as the business information, the system associates the user's biometric information, the first ID, and the second ID and stores them in the first database. [Appendix 7] The server device receiving an authentication request including biometric information of a person to be authenticated from an authentication terminal; The system described in Appendix 6, which identifies the person to be authenticated by performing a matching process using the biometric information included in the received authentication request and the biometric information stored in the first database, and transmits to the authentication terminal business information corresponding to the authentication terminal from at least one of the business information of the person to be authenticated stored in the first database. [Appendix 8] The server device The system described in Appendix 7, wherein, when biometric authentication of the person to be authenticated is successful, a behavioral history of the person to be authenticated is generated using at least information regarding the authentication terminal, and the first ID, the second ID, and the generated behavioral history of the person to be authenticated are associated and stored in a second database. [Appendix 9] The server device The system described in Appendix 8, wherein, upon obtaining the first ID from the first business operator, the system reads the user's behavior history corresponding to the first ID from the second database and provides the read behavior history to the first business operator. [Appendix 10] The system according to any one of appendixes 5 to 9, wherein the biometric information is a facial image or a feature generated from the facial image. [Appendix 11] On the device, The business information required for the user to receive a service using biometric authentication is acquired from an application installed on the device; A terminal control method for transmitting a token registration request including the acquired business information and the user's biometric information to a server device. [Appendix 12] The computer installed in the device A process of acquiring business information necessary for a user to receive a service using biometric authentication from an application installed on the user's own device; a process of transmitting a token registration request including the acquired business information and the biometric information of the user to a server device; A computer-readable storage medium that stores a program for executing the above.

[0255] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]

[0256] 10 Server device 20 Authentication Terminal 20-1 Authentication terminal 20-2 Authentication terminal 20-3 Authentication Terminal 20-4 Authentication terminal 30 Airport Terminal 40 terminals 100 devices 101 Acquisition method 102 Transmission means 201 Communication control unit 202 Token Control Unit 203 Storage section 301 Communication Control Unit 302 Token control section 303 Storage section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface 401 Communication control unit 402 Token control section 403 Authentication 404 Storage section 405 Information provision control section 501 Communication control unit 502 Biometric information acquisition unit 503 Authentication Request Section 504 Functionality Realization Department 505 Storage section

Claims

1. a presentation means for presenting to a user a list of a plurality of services that the user can enjoy based on business information that can be collected from applications installed on the user's own terminal; an acquisition means for acquiring business information of a service selected by the user from the list of the presented plurality of services from a corresponding application; a transmitting means for transmitting a token registration request including the acquired business information to a server device; A terminal comprising:

2. The terminal according to claim 1 , wherein the transmission means transmits the token registration request, which includes the biometric information of the user and the acquired business information, to the server device.

3. The terminal according to claim 2 , further comprising a consent acquisition means for acquiring the user's consent to providing the business information and biometric information to a third party before transmitting the token registration request to the server device.

4. The system further comprises an identity verification unit that performs identity verification using biometric information acquired from the user and biometric information acquired from an identification card held by the user, The terminal according to claim 3 , wherein the transmission means transmits the token registration request to the server device after the identity verification is successful.

5. a server device; A device owned by the user, Including, The terminal a presentation means for presenting to the user a list of a plurality of services that the user can enjoy based on business information that can be collected from applications installed on the user's own terminal; an acquisition means for acquiring business information of a service selected by the user from the list of the presented plurality of services from a corresponding application; a transmitting means for transmitting a token registration request including the acquired business information to the server device; A system comprising:

6. On the device, presenting to the user a list of a plurality of services that the user can enjoy based on business information that can be collected from applications installed on the user's terminal; acquiring business information of a service selected by the user from the list of the presented plurality of services from a corresponding application; A terminal control method for transmitting a token registration request including the acquired business information to a server device.

7. The computer installed in the device A process of presenting to a user a list of multiple services that the user can enjoy based on business information that can be collected from applications installed on the user's own terminal; a process of acquiring business information of a service selected by the user from the list of the presented plurality of services from a corresponding application; a process of transmitting a token registration request including the acquired business information to a server device; A program to execute.

Citation Information

Patent Citations

  • Program, authentication system, and authentication cooperative system

    JP2018037025A

  • Information processing device, control method, and program

    JP2019046133A

  • System, authentication method, authentication terminal, authentication terminal control method and program

    JP7036300B1

  • Compliance and audit using biometric tokenization

    US10193884B1

  • Authentication server, authentication system, and authentication server control method and storage medium

    WO2022137954A1