Authentication system, authentication method, and program
The authentication system addresses the inefficiency in authenticating groups by setting personalized group conditions, enhancing processing speed and accuracy for family or predefined groups.
Patent Information
- Application Number
- JP2024510769
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-29
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2042-03-29
AI Technical Summary
Existing authentication systems do not efficiently authenticate predetermined groups, such as families, and lack the ability to adjust authentication conditions based on group member attributes.
An authentication system that performs biometric authentication on an individual and sets group-specific authentication conditions based on the attributes of the authenticated person, allowing for efficient authentication of other group members.
The system efficiently authenticates groups by adjusting authentication thresholds for different members, improving processing time and accuracy, particularly for families or other predefined groups.
Smart Images

Figure 0007810255000001 
Figure 0007810255000002 
Figure 0007810255000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an authentication system, an authentication method, and a computer-readable medium. [Background technology]
[0002] There is a demand for efficient authentication of a group of people at a predetermined passage gate that requires authentication.
[0003] For example, the image processing device described in Patent Document 1 holds registered images grouped by attribute, matches an input image with a registered image included in the attribute group using the discrimination characteristics corresponding to the attribute, identifies the object in the input image, and performs output based on the discrimination results.
[0004] The surveillance system described in Patent Document 2 authenticates whether a passing person is a person to be notified based on the characteristics of the person captured in an image, and if the passing person is authenticated as a person to be notified, it controls the system so that a warning is not issued if the conditions for not issuing a warning are met.
[0005] The entry management system described in Patent Document 3 opens the managed door and allows tailgating entry, where a person who is permitted to enter the room brings a person who is not permitted to enter, when a specific action is authenticated. On the other hand, when the specific action is not authenticated, the entry management system does not open the managed door and does not allow tailgating entry, where a person who is permitted to enter the room brings a person who is not permitted to enter. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2018-005574 [Patent Document 2] Japanese Patent Publication No. 2020-160573 [Patent Document 3] Japanese Patent Publication No. 2020-088462 Summary of the Invention [Problem to be solved by the invention]
[0007] The above-mentioned technology proposes exception processing when performing authentication, but does not focus on the member composition of a predetermined group such as a family.
[0008] In view of the above-mentioned problems, an object of the present disclosure is to provide an authentication system and the like that efficiently authenticates a predetermined group. [Means for solving the problem]
[0009] An authentication system according to one aspect of the present disclosure includes an authentication means and a condition setting means. The authentication means performs biometric authentication of a person based on predetermined personal authentication standards. The condition setting means sets group authentication conditions for other members in a group to which the authenticated person belongs based on attribute information of the authenticated person. The authentication means also authenticates the other members based on the set group authentication conditions.
[0010] In an authentication method according to one aspect of the present disclosure, a computer executes the following processes: the computer performs biometric authentication of a person based on predetermined personal authentication standards; the computer sets group authentication conditions for other members in a group to which the authenticated person belongs based on attribute information of the authenticated person; and the computer authenticates the other members based on the set group authentication conditions.
[0011] A non-transitory computer-readable medium according to one aspect of the present disclosure causes a computer to execute the following method: the computer performs biometric authentication of a person based on predetermined personal authentication criteria, the computer sets group authentication conditions for other members in a group to which the person belongs based on attribute information of the authenticated person, and the computer authenticates the other members based on the set group authentication conditions. [Effects of the Invention]
[0012] The present disclosure makes it possible to provide an authentication system or the like that efficiently authenticates a predetermined group. [Brief explanation of the drawings]
[0013] [Figure 1] 1 is a block diagram of an authentication system according to a first embodiment. [Figure 2] 1 is a flowchart showing an authentication method according to the first embodiment. [Figure 3] FIG. 10 is a diagram showing a usage mode of an authentication system and related configurations according to a second embodiment. [Figure 4] FIG. 10 is a block diagram of an authentication system according to a second embodiment. [Figure 5] FIG. 10 is a block diagram of a person information management system according to a second embodiment. [Figure 6] 10 is a table showing personal information according to the second embodiment. [Figure 7] 10 is a table showing group authentication conditions according to the second embodiment. [Figure 8] 10 is a first flowchart showing an authentication method according to a second embodiment. [Figure 9] 10 is a second flowchart showing the authentication method according to the second embodiment. [Figure 10] 10 is a flowchart showing an authentication method according to a third embodiment. [Figure 11] 10 is a flowchart showing an authentication method according to a fourth embodiment. [Figure 12] FIG. 10 is a block diagram of an authentication system according to a fifth embodiment. [Figure 13] 10 is a flowchart showing an authentication method according to a fifth embodiment. [Figure 14] FIG. 2 is a block diagram illustrating an example of a hardware configuration of a computer. DETAILED DESCRIPTION OF THE INVENTION
[0014] The present disclosure will be described below through embodiments, but the disclosure according to the claims is not limited to the following embodiments. Furthermore, not all of the configurations described in the embodiments are necessarily essential as means for solving the problems. In each drawing, the same elements are denoted by the same reference numerals, and redundant explanations are omitted as necessary.
[0015] <Embodiment 1> A first embodiment of the present disclosure will be described. Fig. 1 is a block diagram of an authentication system according to the first embodiment. The authentication system 1 shown in Fig. 1 is a system for performing authentication at a predetermined passage gate or the like. The predetermined passage gate is installed, for example, at customs at an airport, a gate at a theme park, or an event hall for a concert or conference.
[0016] The authentication system 1 may be configured, for example, by a computer or server with communication capabilities. In the following description, the term "computer" may encompass any one of a server device, a blade, and a cloud computing system. The authentication system 1 acquires image data of an image captured by a camera installed at a specified passage gate, and authenticates a person attempting to pass through the passage gate based on the acquired image data. The authentication system 1 mainly comprises an authentication unit 11 and a condition setting unit 12.
[0017] The authentication unit 11 performs biometric authentication of a person from an image of the person included in the acquired image data. The image data may be a still image or a video captured at predetermined intervals (for example, every 1 / 30th of a second). The image of the person may be any image that can be used for biometric authentication. If the authentication unit 11 performs biometric authentication using a facial image, the image of the person includes at least the person's face. If the authentication unit 11 performs biometric authentication using a fingerprint image, the image of the person includes at least the person's fingers. The biometric authentication may use the above-mentioned facial image or fingerprint. The biometric authentication may also use the iris or gait. The biometric authentication may also be performed using a combination of these. The biometric authentication may also use, for example, the person's voice in addition to an image.
[0018] When biometric authentication is performed, the authentication unit 11 extracts feature points from an image related to biometric authentication and calculates feature amounts from the extracted feature points. Furthermore, the authentication unit 11 determines whether the calculated feature amounts are unique to a specific person. At this time, for example, the authentication unit 11 compares the calculated feature amounts with unique feature amounts of people that the authentication system 1 can search for.
[0019] If the calculated feature quantity and the retrieved feature quantity match or are similar with a reasonable degree of accuracy, the authentication unit 11 determines to authenticate the person associated with the extracted feature quantity. Similar with a reasonable degree of accuracy means, for example, that the similarity of the feature quantities to be matched is greater than a predetermined value (or a predetermined ratio). In this case, the similarity may be calculated quantitatively or qualitatively.
[0020] At this time, the authentication unit 11 performs this biometric authentication in accordance with a predetermined personal authentication standard. The predetermined personal authentication standard is a standard for performing biometric authentication of a person as an individual. The personal authentication standard includes, for example, a threshold value for the degree of similarity between the feature calculated by the authentication unit 11 and the unique feature of the searched person.
[0021] The condition setting unit 12 acquires information about the group to which the authenticated person belongs from the attribute information of the authenticated person. The attribute information of the authenticated person may include the person's name, address, age, sex, nationality, etc. This attribute information may also include information about the group to which the person belongs. The information about the group to which the person belongs may include, for example, information about whether the group is a family, a group travel group, or whether the person belongs to a specific organization such as a school or a company.
[0022] When the condition setting unit 12 acquires information about the group, it sets group authentication conditions for other members in the group to which the person belongs. The group authentication conditions are authentication conditions when the authentication unit 11 performs biometric authentication on other members. The group authentication conditions may include, for example, a threshold value for the similarity when comparing feature amounts.
[0023] The group authentication conditions set by the condition setting unit 12 do not have to be constant, that is, the condition setting unit 12 may set group authentication conditions for each member of a group related to a person authenticated according to the personal authentication standard.
[0024] When the condition setting unit 12 sets group authentication conditions, the authentication unit 11 authenticates other members using the set group authentication conditions. That is, in this case, the authentication system 1 assumes that after a person authenticated by the authentication unit 11 based on personal authentication standards, members of the group to which this person belongs will undergo biometric authentication, sets group authentication conditions, and performs biometric authentication on the members of this group. By performing group authentication in this manner, the authentication system 1 can perform authentication smoothly. The authentication system 1 may have a means for notifying the person to be authenticated or an administrator of the authentication system 1, etc., of the authentication result.
[0025] The feature quantities searched by the authentication unit 11 are not limited to the feature quantities unique to a person as described above. The feature quantities searched by the authentication unit 11 may be feature quantities for estimating age or gender. In this case, when authenticating a person or a member of a group, the authentication unit 11 can require that the age or gender meets a predetermined standard.
[0026] Next, processing executed by the authentication system 1 will be described with reference to Fig. 2. Fig. 2 is a flowchart showing the authentication method according to the first embodiment. The flowchart shown in Fig. 2 is started, for example, when the authentication system 1 acquires image data.
[0027] First, the authentication unit 11 performs biometric authentication of a person based on a predetermined personal authentication standard (step S11). After authenticating the person, the authentication unit 11 supplies a signal indicating that authentication has been performed to the condition setting unit 12.
[0028] Next, the condition setting unit 12 sets group authentication conditions for other members in the group to which the authenticated person belongs based on the attribute information of the authenticated person (step S12). After setting the group authentication conditions, the condition setting unit 12 supplies the authentication unit 11 with a signal indicating that the group authentication conditions have been set and information about the group authentication conditions.
[0029] Next, when the authentication unit 11 receives the group authentication conditions from the condition setting unit 12, it authenticates the other members based on the set group authentication conditions (step S13). When the authentication unit 11 completes the authentication of the other members, the authentication system 1 ends the series of processes.
[0030] The above describes the authentication method executed by the authentication system 1. In the above process, the authentication system 1 also executes a process for notifying the authentication result to the person to be authenticated or the administrator of the authentication system 1. By executing the above process, the authentication system 1 can smoothly execute group authentication.
[0031] The authentication system according to the first embodiment has been described above. The authentication system 1 may have a processor and a storage device as components not shown. The storage device included in the authentication system 1 includes a storage device including a nonvolatile memory such as a flash memory or an SSD (Solid State Drive). In this case, the storage device included in the authentication system 1 may be the above-mentioned certification The storage device stores a computer program (hereinafter simply referred to as a program) for executing the method. The processor reads the computer program from the storage device into a buffer memory such as a dynamic random access memory (DRAM) and executes the program.
[0032] Each component of the authentication system 1 may be realized by dedicated hardware. Furthermore, some or all of the components may be realized by general-purpose or dedicated circuits, processors, etc., or a combination of these. These may be configured by a single chip, or by multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-mentioned circuits, etc., and a program. Furthermore, a CPU (Central Processing Unit), GPU (Graphics Processing Unit), FPGA (Field-Programmable Gate Array), etc. may be used as the processor. The description of the components described herein may also be applied to other devices or systems described below in this disclosure.
[0033] Furthermore, when some or all of the components of the authentication system 1 are realized by a plurality of authentication systems, circuits, etc., the plurality of authentication systems, circuits, etc. may be centrally or decentralized. For example, the authentication systems, circuits, etc. may be realized as a client-server system, a cloud computing system, etc., each connected via a communication network. Authentication System The functions of the above may be provided in a form of Software as a Service (SaaS). The above method may be stored on a computer-readable medium for causing a computer to execute the above method.
[0034] According to this embodiment, it is possible to provide an authentication system or the like that efficiently authenticates a predetermined group.
[0035] <Embodiment 2> A second embodiment of the present disclosure will now be described. Fig. 3 is a diagram showing a usage mode of an authentication system and related configurations according to the second embodiment. Fig. 3 shows an authentication system 2, a person information management system 30, and an entry / exit control terminal 40. The authentication system 2, the person information management system 30, and the entry / exit control terminal 40 are each connected to a network N1 so as to be able to communicate with each other.
[0036] Fig. 3 shows a situation in which a family group G01 is about to pass through an entrance / exit control terminal 40 installed at an airport A10. Group G01 is made up of members P11, P12, P13, and P14. Fig. 3 also shows a situation in which person P11 is being authenticated. After the situation shown in Fig. 3, following person P11, people P12, P13, and P14 will also be authenticated.
[0037] In this case, if it is known in advance that group G01 is attempting to pass through gate 43 with a family, authentication system 2 can incorporate this into the authentication conditions. More specifically, authentication system 2 can efficiently authenticate P11's family members by setting group authentication conditions after authenticating person P11 based on the individual authentication standard. For example, persons P13 and P14 are young children. Generally, authenticating young children using biometric authentication may take more time than authenticating adults, or the accuracy may be lower. Therefore, authentication system 2 can individually set authentication conditions for persons P13 and P14, who are members of person P11's family.
[0038] 3, the authentication system 2 is communicatively connected to the entrance / exit control terminal 40. The authentication system 2 receives image data acquired by the entrance / exit control terminal 40 and performs biometric authentication on the person included in the received image data. The authentication system 2 also supplies a signal indicating the result of the biometric authentication to the entrance / exit control terminal 40. The authentication system 2 is also communicatively connected to the personal information management system 30 and receives attribute information related to the authenticated person from the personal information management system 30.
[0039] The personal information management system 30 is a system that manages airline tickets at airport A10 and stores predetermined information related to group G01. The personal information management system 30 is communicably connected to the authentication system 2 and provides attribute information related to authenticated persons to the authentication system 2 as appropriate.
[0040] The entrance / exit control terminal 40 is a terminal device for performing authentication when passing through customs, etc. The entrance / exit control terminal 40 mainly comprises a camera 41, a display unit 42, a gate unit 43, and an entrance / exit control unit 44.
[0041] The camera 41 photographs a person passing through the gate unit 43 in order to perform biometric authentication on the person. The display unit 42 displays information such as the result of authentication to the person passing through the gate unit 43. The gate unit 43 is a door-like or rod-like member that is set up so as to be able to open and close in the passage through which the person passes, and is driven in response to instructions from the entry / exit control unit 44.
[0042] The entrance / exit control unit 44 includes a computing device that controls each component of the entrance / exit control terminal 40, and a communication device that communicates with the authentication system 2 via the network N1. The entrance / exit control unit 44 causes the camera 41 to take an image of a person attempting to pass through the gate unit 43, and supplies the image taken by the camera 41 to the authentication system 2. Furthermore, when the entrance / exit control unit 44 receives a signal from the authentication system 2 indicating that the person has been authenticated, it drives the gate unit 43 to a state that allows the person to pass through.
[0043] The configuration of the authentication system 2 will be described with reference to Fig. 4. Fig. 4 is a block diagram of the authentication system according to embodiment 2. The authentication system 2 mainly includes an authentication unit 11, a condition setting unit 12, an image data acquisition unit 13, a communication unit 14, a message output unit 15, and a storage unit 16.
[0044] The authentication unit 11 is as described in the first embodiment, but will be described in more detail here. The authentication unit 11 includes a feature image extraction unit 111 and a feature point extraction unit 112 as functional components for authentication.
[0045] The characteristic image extraction unit 111 receives image data from the entrance / exit control terminal 40 and extracts a characteristic image related to biometric authentication of a person from the image of the received image data. In this embodiment, the authentication system 2 authenticates a person using a facial image. Therefore, the characteristic image extraction unit 111 extracts the facial image of the person included in the image as a characteristic image.
[0046] The feature point extraction unit 112 extracts feature points from the facial image, which is the feature image extracted by the feature image extraction unit 111. More specifically, the feature point extraction unit 112 extracts the positions of points that are facial features according to a predetermined algorithm. Note that the extraction of feature points described above and the subsequent biometric authentication performed by the authentication unit 11 are techniques already known to those skilled in the art. Therefore, a detailed description thereof will be omitted here.
[0047] Using the above-described technology, the authentication unit 11 can also estimate, for example, whether or not a person's age is below a predetermined threshold age. With this function, the authentication system 2 can, for example, estimate the age of infants, who are relatively difficult to authenticate among group members, and authenticate them by comparing the estimated age with the attribute information of the infants who are group members.
[0048] The authentication unit 11 may perform biometric authentication using an image or voice of a member. For example, when authenticating a member of a group associated with a person authenticated based on personal authentication standards, the authentication system 2 may perform authentication using voice. The authentication unit 11 may also extract one of a face image, an iris image, or a fingerprint image from the member's image as biometric information, and perform biometric authentication based on the extracted biometric information.
[0049] The condition setting unit 12 queries the personal information management system 30 about the attribute information of the person authenticated by the authentication unit 11. More specifically, the condition setting unit 12 supplies the personal information management system 30 with a personal ID (Identifier) of the person authenticated by the authentication unit 11. The personal information management system 30 supplies the condition setting unit 12 with attribute information corresponding to the person ID received from the condition setting unit 12. As a result, the condition setting unit 12 acquires the attribute information of the person authenticated according to the personal authentication standard.
[0050] The condition setting unit 12 then sets group authentication conditions, which are authentication conditions for other members of the group, based on this attribute information. Because authentication conditions for other members can be set in this way, the authentication system 2 can, for example, lower the predetermined threshold for authenticating other members. With this configuration, the authentication system 2 can easily authenticate other members of a group to which a person authenticated based on personal authentication standards belongs, and can process authentication of the entire group in a shorter time.
[0051] The condition setting unit 12 may specify that the person authenticated by the authentication unit 11 based on the personal authentication standard is the group representative. More specifically, the condition setting unit 12 reads that the person authenticated by the authentication unit 11 is the group representative from information included in the attribute information received from the personal information management system 30. Similarly, the condition setting unit 12 may specify that the person authenticated by the authentication unit 11 is not the group representative. Then, the condition setting unit 12 may determine whether to set a group authentication condition depending on whether the authenticated person is the group representative.
[0052] That is, in this case, if the authenticated person is the representative, the authentication unit 11 authenticates the other members based on the group authentication conditions. On the other hand, if the authenticated person is not the representative, the authentication unit 11 authenticates the other members based on the individual authentication standards, not the group authentication conditions. With this configuration, the authentication system 2 can easily process authentication of the entire group by using the prerequisite that the representative has been authenticated.
[0053] The condition setting unit 12 may set group authentication conditions according to the ages of the group members included in the attribute information. With this configuration, the authentication system 2 can lower the authentication level for infants and young children based on the group authentication conditions set after the group representative is authenticated. This allows the authentication system 2 to efficiently authenticate the entire group.
[0054] The image data acquisition unit 13 acquires image data from the entrance / exit control terminal 40. The image data acquisition unit 13 supplies the received image data to the authentication unit 11. The image data acquisition unit 13 may perform predetermined processing such as trimming or tone adjustment on the received image data before supplying the image data to the authentication unit 11.
[0055] The communication unit 14 is an interface that enables the authentication system 2 to communicate with the person information management system 30 or the entrance / exit control terminal 40 via the network N1. For example, the communication unit 14 supplies the person ID of the authenticated person to the person information management system 30, and in response receives the person's attribute information from the person information management system 30. The communication unit 14 also receives image data from the entrance / exit control terminal 40, for example. The communication unit 14 also supplies the predetermined message output by the message output unit 15 to the entrance / exit control terminal 40.
[0056] The message output unit 15 generates a predetermined message related to authentication and outputs the generated message to the entrance / exit control terminal 40. The predetermined message may include, for example, a message indicating that authentication has been successful. The predetermined message may also include a message indicating that authentication has failed. The predetermined message may also include various other messages.
[0057] For example, if the authenticated person is not the group representative, the message output unit 15 may output a message prompting the representative to authenticate. By outputting such a message, the authentication system 2 can preferably appeal to users of the authentication system about an efficient authentication procedure.
[0058] Furthermore, when the age of the person estimated by the authentication unit 11 is less than the threshold age and the authentication means performs biometric authentication based on personal authentication standards, the message output unit 15 can output a message urging the person to authenticate the representative. With this configuration, the authentication system 2 can urge the person to authenticate, for example, an adult before authenticating an infant.
[0059] The memory unit 16 is a storage device including a non-volatile memory such as a flash memory, SSD, or HDD (Hard Disk Drive). The memory unit 16 includes at least authentication information 161. The authentication information 161 is information for authenticating a person, and is stored with biometric feature data and a person ID linked to each other. The biometric feature data includes data related to feature points of a facial image. The person ID is unique identification information for the person to be authenticated. The memory unit 16 supplies the biometric feature data to the authentication unit 11. The memory unit 16 also supplies the person ID of a person who has been successfully authenticated to the communication unit 14. The communication unit 14 supplies the person ID received from the memory unit 16 to the person information management system 30.
[0060] 5 is a block diagram of a personal information management system 30 according to a second embodiment. The personal information management system 30 according to this embodiment manages a person's ID, information about an airline ticket reserved by the person, and attribute information about the person in association with each other. The personal information management system 30 is, for example, a computer installed in an arbitrary location. The personal information management system 30 mainly includes a communication unit 31, a control unit 32, and a personal information storage unit 34.
[0061] The communication unit 31 is an interface for connecting the personal information management system 30 to the network N1. For example, the communication unit 31 receives a personal ID related to authentication as an inquiry from the authentication system 2. In response to the inquiry, the communication unit 31 may also provide the authentication system 2 with attribute information of the person linked to the received personal ID.
[0062] The control unit 32 is an arithmetic device (arithmetic circuit) for controlling the personal information management system 30, and includes a personal information management unit 33. The personal information management unit 33 generates and updates personal information 341 to be stored in the personal information storage unit .
[0063] The person information storage unit 34 is a storage device including a nonvolatile memory, and stores at least person information 341.
[0064] The person information 341 will be described with reference to FIG. 6. FIG. 6 is a table showing the person information according to the second embodiment. The table shown in FIG. 6 shows a part of the person information 341. The person information 341 shown in FIG. 6 is information related to the group G01 shown in FIG. 3. The person information 341 stores "person ID," "group ID," "group representative flag," "group attribute," "age," and "gender" in a linked state. For example, person ID 0011 corresponds to person P11 in FIG. 3. The attribute information of person P11 indicates that the group ID is G01, the group representative flag is 1, the group attribute is family, the age is 36, and the gender is male.
[0065] 3 is 0012, and the attribute information in the person information 341 is shown as a group ID of G01, a group representative flag of 1, a group attribute of family, an age of 34, and a gender of female. Furthermore, the person ID corresponding to person P13 is 0013, and the attribute information in the person information 341 is shown as a group ID of G01, a group representative flag of 0, a group attribute of family, an age of 5, and a gender of male. The person ID corresponding to person P14 in FIG. 3 is 0014, and the attribute information in the person information 341 is shown as a group ID of G01, a group representative flag of 0, a group attribute of family, an age of 3, and a gender of female.
[0066] In this way, the person information 341 includes information about the person's group as attribute information. By receiving the attribute information from the person information management system 30, the authentication system 2 can obtain, for example, information that the successfully authenticated person P11 is the representative of the group G01, or information such as the ages of the other members of the group G01.
[0067] Next, an example of group authentication conditions will be described with reference to Fig. 7. Fig. 7 is a table showing group authentication conditions according to the second embodiment. Fig. 7 shows a "representative member authentication score X1" and a corresponding "other member authentication threshold X2." The representative member authentication score is the authentication score of the authenticated representative of the group.
[0068] The authentication score is an index showing the degree of similarity between the feature amount extracted by the authentication unit 11 from the image of the person captured by the entrance / exit control terminal 40 and the biometric feature data included in the authentication information 161. In this example, the authentication score has a minimum value of 0 (zero) and a maximum value of 1.0. In other words, the higher the authentication score, the higher the certainty of the authentication.
[0069] The authentication threshold for other members is the degree of similarity with biometric feature data that indicates the conditions for successful authentication when authenticating other members. The authentication threshold in this example is a value that, like the authentication score, has a minimum value of 0 (zero) and a maximum value of 1.0. The higher the authentication threshold value, the higher the degree of similarity with biometric feature data, meaning that the accuracy of authentication will be higher.
[0070] 7, when the "representative member authentication score X1" is 0.7 or more and 1.0 or less, the corresponding "other member authentication threshold X2" is set to 0.4 or more. Also, when the "representative member authentication score X1" is 0.6 or more and less than 0.7, the corresponding "other member authentication threshold X2" is set to 0.6 or more.
[0071] In other words, if the representative's score when authenticated is relatively high, the authentication accuracy of the other members is set relatively low. By setting group authentication conditions in this way, the authentication system 2 lowers the authentication accuracy of the other members as the representative's authentication accuracy increases, making authentication of the entire group smoother. On the other hand, if the representative's authentication accuracy is not relatively high, the authentication of the other members is performed relatively carefully. In this way, the authentication system 2 can adjust the balance between authentication efficiency and authentication accuracy.
[0072] The group authentication conditions set by the authentication system 2 are not limited to those described above. The authentication system 2 may employ various group authentication conditions. For example, instead of the two types of group authentication conditions shown in FIG. 7, the authentication system 2 may have one type or three or more types of group authentication conditions.
[0073] The group authentication conditions may also be set according to the attributes of the person to be authenticated. For example, if it can be determined from the attribute information that a non-representative of the group is an infant, the authentication system 2 may set a low threshold. The group authentication conditions may also be such that the authentication method used by the group representative and the authentication method used by the non-representative are different. For example, in this case, the authentication system 2 may perform biometric authentication using a facial image for the representative and biometric authentication using irises for the other non-representative members. With this configuration, the authentication system 2 can suitably authenticate parents and children in cases such as infant vaccinations and authentication for vaccination certification.
[0074] Furthermore, for example, the authentication system 2 may set the "representative member authentication score X1" as a statistical value of all representatives. For example, in the case of group G01, the representatives are persons P11 and P12. In this case, the "representative member authentication score X1" may be the average value of the authentication score for person P11 and the authentication score for P12. Furthermore, for example, the authentication system 2 may set the "representative member authentication score X1" as the maximum or minimum value of the authentication scores of all representatives.
[0075] Furthermore, for example, as the number of successful authentications of the group increases, the condition setting unit 12 may accordingly lower the value of the "other member authentication threshold X2." By setting it in this way, the authentication system 2 can improve the efficiency of authentication of the entire group.
[0076] Fig. 8 is a first flowchart showing an authentication method according to embodiment 2. The flowchart shown in Fig. 8 shows processing executed by the authentication system 2. The flowchart in Fig. 8 starts, for example, when the authentication system 2 receives image data from the entry / exit control terminal 40.
[0077] First, the authentication unit 11 performs biometric authentication of a person based on predetermined personal authentication standards (step S21). Next, the authentication unit 11 determines whether or not the authentication of this person was OK (successful) (step S22). If it is not determined that the authentication was OK (step S22: NO), the authentication system 2 proceeds to an authentication NG processing routine. Note that, since well-known techniques can be used for processing when authentication is NG, detailed description thereof will be omitted here. On the other hand, if it is determined that the authentication was OK (step S22: YES), the authentication system 2 proceeds to step S23.
[0078] In step S23, the condition setting unit 12 inquires of the personal information management system 30 about the personal ID of the person who has been successfully authenticated (step S23). In response to this inquiry, the authentication system 2 receives attribute information corresponding to the personal ID from the personal information management system 30.
[0079] Next, the condition setting unit 12 determines whether or not there is a group authentication condition based on the attribute information of the authenticated person (step S24). A group authentication condition exists when the person to be authenticated belongs to a group and the attribute information includes information about the group. On the other hand, a group authentication condition does not exist when the person to be authenticated does not belong to a group. In other words, if the attribute information of the person to be authenticated does not include information about the group, the authentication system 2 does not set a group authentication condition.
[0080] If it is determined that the authenticated person does not have the relevant group authentication condition (step S24: NO), the authentication system 2 ends the process. If it is determined that the authenticated person has the relevant group authentication condition (step S24: YES), the authentication system 2 proceeds to step S25.
[0081] In step S25, the authentication unit 11 authenticates the other members in accordance with the group authentication conditions set by the condition setting unit 12 (step S25). When the authentication unit 11 completes the authentication of the other members, the authentication system 2 ends the series of processes.
[0082] The above-mentioned step S25 will be described with reference to Fig. 9. Fig. 9 is a second flowchart showing the authentication method according to the second embodiment. The flowchart shown in Fig. 9 shows details of step S25 in Fig. 8.
[0083] First, the condition setting unit 12 sets authentication conditions for other members (step S251), and then the image data acquisition unit 13 acquires image data of images taken of other members (step S252).
[0084] Next, the authentication unit 11 performs biometric authentication of the other member person according to the set group authentication conditions (step S253). Next, the authentication unit 11 determines whether or not the authentication of this person was OK (successful) (step S254). If it is not determined that the authentication was OK (step S254: NO), the authentication system 2 proceeds to an authentication NG processing routine. On the other hand, if it is determined that the authentication was OK (step S254: YES), the authentication system 2 proceeds to step S255.
[0085] In step S255, the authentication system 2 determines whether authentication of all group members has been completed (step S255). If it is determined that authentication of all group members has not been completed (step S255: NO), the authentication system 2 returns to step S252 and repeats authentication of other members whose authentication has not been completed. If it is determined that authentication of all group members has been completed (step S255: YES), the authentication system 2 ends the series of authentication processes.
[0086] The second embodiment has been described above. In FIGS. 8 and 9 , if authentication is successful or unsuccessful, the authentication system 2 may output a message indicating successful or unsuccessful authentication to the entrance / exit control terminal 40. The above-described authentication system 2 may include at least a part of the personal information management system 30 and the entrance / exit control terminal 40. The above-described configuration of the authentication system 2 can shorten the processing time required to authenticate a group. This allows the authentication system 2 to complete authentication while the group is walking through the gate 43, for example. In other words, the authentication system 2 can authenticate more people in a given period of time. Therefore, this embodiment can provide an authentication system or the like that efficiently authenticates a given group.
[0087] <Embodiment 3> Next, a third embodiment will be described with reference to Fig. 10. Fig. 10 is a flowchart showing an authentication method according to the third embodiment. The authentication method of the authentication system 2 according to the third embodiment differs from that shown in Fig. 8. More specifically, the flowchart shown in Fig. 10 differs from the flowchart shown in Fig. 8 in that the processing of steps S211 to S2131 is performed instead of step S21. Note that in the authentication system 2 according to the third embodiment, the authentication unit 11 includes a function for estimating the age of the person to be authenticated.
[0088] In step S21, the authentication unit 11 performs biometric authentication of a person based on personal authentication standards, and estimates the age of the person to be authenticated (step S211).
[0089] Next, the authentication unit 11 determines whether the estimated age of the person is less than a predetermined threshold (step S212). The estimated age for the predetermined threshold is, for example, about 0 to 10 years old. That is, the authentication system 2 according to this embodiment identifies the person to be authenticated as an infant or a child.
[0090] If it is not determined that the person's estimated age is less than the predetermined threshold (step S212: NO), the authentication system 2 proceeds to step S22, and thereafter performs the same processing as that shown in Fig. 8. If it is determined that the person's estimated age is less than the predetermined threshold (step S212: YES), the authentication system 2 proceeds to step S213.
[0091] In step S213, the message output unit 15 of the authentication system 2 outputs a message prompting authentication of the representative to the entrance / exit control terminal 40 (step S213). When the message output unit 15 outputs the message, the authentication system 2 proceeds to step S22, and thereafter performs the same processing as that shown in FIG.
[0092] The third embodiment has been described above. According to this embodiment, the authentication system 2 can prompt the representative to authenticate, and perform group authentication more efficiently. Therefore, this embodiment can provide an authentication system or the like that can efficiently authenticate a predetermined group.
[0093] <Embodiment 4> Next, a fourth embodiment will be described with reference to Fig. 11. Fig. 11 is a flowchart showing an authentication method according to the fourth embodiment. The flowchart according to the fourth embodiment differs from the flowchart shown in Fig. 8 in the processing after step S23.
[0094] In step S23, the condition setting unit 12 inquires of the personal information management system 30 about the personal ID of the person who has been successfully authenticated (step S23). In response to this inquiry, the authentication system 2 receives attribute information corresponding to the personal ID from the personal information management system 30.
[0095] After step S23, the authentication system 2 receives attribute information corresponding to the person ID from the person information management system 30, reads the attribute information, and determines whether the authenticated person, i.e., the person to be authenticated, is a member of a specified group (step S231).
[0096] If the authentication system 2 determines that the person to be authenticated is not a member of the predetermined group (step S231: NO), the authentication system 2 ends the series of processes. On the other hand, if the authentication system 2 determines that the person to be authenticated is a member of the predetermined group (step S231: YES), the authentication system 2 proceeds to step S232.
[0097] In step S232, the authentication system 2 determines whether the person to be authenticated is the group representative (step S232). If it is determined that the person to be authenticated is the group representative (step S232: YES), the authentication system 2 proceeds to step S25 and authenticates other members using the same process as in Fig. 8. On the other hand, if it is not determined that the person to be authenticated is the group representative (step S232: NO), the authentication system 2 proceeds to step S233.
[0098] In step S233, the message output unit 15 outputs a message prompting the representative to be authenticated (step S233). When the message output unit 15 outputs this message, the authentication system 2 ends the series of processes.
[0099] The fourth embodiment has been described above. The authentication system 2 according to this embodiment authenticates members belonging to a group, but if the person to be authenticated is not the representative of the group, the authentication system 2 does not authenticate the person to be authenticated. table The authentication system 2 continues authentication based on the personal authentication standard while prompting the authentication of the representative. With this configuration, the authentication system 2 can give priority to authenticating the representative. Therefore, according to this embodiment, it is possible to provide an authentication system or the like that can efficiently authenticate a predetermined group.
[0100] <Embodiment 5> Next, a fifth embodiment will be described. Fig. 12 is a block diagram of an authentication system according to the fifth embodiment. The authentication system 3 shown in Fig. 12 differs from the authentication system 2 shown in Fig. 3 in that it has personal information. The authentication system 3 also has a personal information management unit 17 and an update information reception unit 18. The authentication system 3 shown in Fig. 12 is communicably connected to an entry / exit control terminal 40 via a network N1.
[0101] The storage unit 16 according to this embodiment has person information 162. The person information 162 is information that links authentication information of a person with attribute information related to a group to which the person belongs. Furthermore, the condition setting unit 12 according to this embodiment reads the attribute information stored in the storage unit 16 and sets group authentication conditions for the person to be authenticated from the read attribute information.
[0102] Furthermore, the storage unit 16 according to this embodiment includes history information 163. The history information 163 includes information for updating the group authentication conditions.
[0103] The personal information management unit 17 included in the authentication system 3 generates or updates the personal information 162 stored in the storage unit 16.
[0104] The update information receiving unit 18 included in the authentication system 3 receives predetermined information for updating the group authentication conditions. That is, the authentication system 3 can set the group authentication conditions by taking into account the update information received by the update information receiving unit 18 in addition to the attribute information included in the person information 162.
[0105] For example, when a person's attribute information includes multiple different groups, the update information receiving unit 18 receives a selection operation for performing group authentication under one group authentication condition, which enables the authentication system 3 to efficiently perform authentication of a person who belongs to multiple groups.
[0106] The update information receiving unit 18 may receive update information by any means. For example, the update information receiving unit 18 may include an information input means for the person to be authenticated to perform a predetermined operation. The information input means for the person to be authenticated to perform a predetermined operation may be, for example, an information input device such as a keyboard or a touch panel, or a device that detects the voice or gestures of the person to be authenticated.
[0107] The update information receiving unit 18 may also receive registration of a group to which a person belongs. This allows the update information receiving unit 18 to flexibly handle group authentication. For example, when a person requiring specific assistance passes through the gate unit 43, a facility staff member managing the entrance / exit control terminal 40 can register a new group as a representative of the group. This allows the authentication system 3 to flexibly and efficiently authenticate people.
[0108] The update information receiving unit 18 may also receive historical information on the history of authentication of a person. At this time, the condition setting unit 12 may set group authentication conditions according to the historical information received by the update information receiving unit 18. This allows the authentication system 3 to, for example, match the authentication conditions of an authenticatee who has been repeatedly authenticated to the most recent feature amount. Therefore, the authentication system 3 can efficiently authenticate a person related to the historical information.
[0109] The update information receiving unit 18 may also receive, as history information, a first authentication level, which is the authentication level of the group on a predetermined outbound journey. In this case, the condition setting unit 12 sets the second authentication level of the group on the return journey corresponding to the outbound journey to a level lower than the first authentication level. With this configuration, the authentication system 3 can more efficiently authenticate a group of the same members as on the outbound journey.
[0110] As described above, the update information receiving unit 18 according to this embodiment receives update information for updating the group authentication conditions. The update information receiving unit 18 stores the received update information in the storage unit 16 as history information 163. When authenticating other members in the group, the condition setting unit 12 reads the update information and updates the group authentication conditions in accordance with the read update information. With this configuration, the authentication system 3 can efficiently perform group authentication while adapting to various situations.
[0111] Next, an example of an authentication method executed by the authentication system 3 will be described with reference to Fig. 13. Fig. 13 is a flowchart showing an authentication method according to embodiment 5. The flowchart shown in Fig. 13 differs from the flowchart shown in Fig. 8 in that it includes steps S241 and S242 between steps S24 and S25.
[0112] 13, the condition setting unit 12 determines whether or not there is a group authentication condition based on the attribute information of the authenticated person (step S24). If it is determined that there is no group authentication condition related to the authenticated person (step S24: NO), the authentication system 3 ends the processing. If it is determined that there is a group authentication condition related to the authenticated person (step S24: YES), the authentication system 3 proceeds to step S241.
[0113] In step S241, the authentication system 3 reads the history information 163 and determines whether or not the group authentication conditions have been updated (step S241). If it is determined that the group authentication conditions have not been updated (step S241: NO), the authentication system 3 proceeds to step S25 and authenticates other members in the same manner as the process shown in Fig. 8. On the other hand, if it is determined that the group authentication conditions have been updated (step S241: YES), the authentication system 3 updates the group authentication conditions in accordance with the history information 163 before authenticating other members (step S242). After updating the group authentication conditions, the authentication system 3 proceeds to step S25.
[0114] The fifth embodiment has been described above. The authentication system 3 according to this embodiment is not limited to the above-described configuration. For example, the authentication system 3 may be Multiple The authentication system 3 may include at least a part of the entrance / exit control terminal 40. Alternatively, the authentication system 3 may include a plurality of Entrance / exit control terminal 40. According to this embodiment, it is possible to provide an authentication system or the like that efficiently authenticates a predetermined group.
[0115] <Example of hardware configuration> Hereinafter, a case will be described in which each functional configuration of the determination device according to the present disclosure is realized by a combination of hardware and software.
[0116] 14 is a block diagram illustrating a hardware configuration of a computer. Authentication System The above-described functions can be realized by a computer 500 including the hardware configuration shown in the figure. The computer 500 may be a portable computer such as a smartphone or tablet terminal, or a stationary computer such as a PC. The computer 500 may be a dedicated computer designed to realize each device, or may be a general-purpose computer. The computer 500 can realize desired functions by installing a predetermined program.
[0117] The computer 500 has a bus 502, a processor 504, a memory 506, a storage device 508, an input / output interface 510 (an interface is also called an I / F (Interface)), and a network interface 512. The bus 502 is a data transmission path through which the processor 504, the memory 506, the storage device 508, the input / output interface 510, and the network interface 512 transmit and receive data to and from each other. However, the method of connecting the processor 504 and other components to each other is not limited to a bus connection.
[0118] The processor 504 is one of various processors such as a CPU, a GPU, an FPGA, etc. The memory 506 is a main storage device realized using a RAM (Random Access Memory) or the like.
[0119] The storage device 508 is an auxiliary storage device realized using a hard disk, an SSD, a memory card, a ROM (Read Only Memory), or the like. The storage device 508 stores programs for realizing desired functions. The processor 504 reads the programs into the memory 506 and executes them to realize the respective functional components of each device.
[0120] The input / output interface 510 is an interface for connecting the computer 500 with input / output devices. For example, the input / output interface 510 is connected to an input device such as a keyboard and an output device such as a display device.
[0121] The network interface 512 is an interface for connecting the computer 500 to a network.
[0122] Although an example of a hardware configuration in the present disclosure has been described above, the above-described embodiment is not limited to this. Any processing in the present disclosure can also be realized by causing a processor to execute a computer program.
[0123] In the above examples, the program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technology, CD-ROM, digital versatile disc (DVD), Blu-ray disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals.
[0124] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the invention.
[0125] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. (Appendix 1) an authentication means for performing biometric authentication of a person based on a predetermined personal authentication standard; a condition setting means for setting group authentication conditions for other members in a group to which the authenticated person belongs based on attribute information of the authenticated person, The authentication means authenticates the other members based on the set group authentication conditions. (Appendix 2) the condition setting means specifies whether the authenticated person is a representative of the group based on the attribute information; the authentication means, if the person is the representative, authenticates the other members based on the group authentication conditions, and, if the person is not the representative, authenticates the other members based on the personal authentication standards; 1. An authentication system as described in Appendix 1. (Appendix 3) further comprising a message output means for outputting a message prompting authentication of the representative when the authenticated person is not the representative; 1. The authentication system described in Appendix 2. (Appendix 4) The authentication means estimates whether the age of the person is less than a predetermined threshold age, the message output means outputs a message prompting authentication of the representative when the age of the person estimated by the authentication means is less than the threshold age and when the authentication means performs the biometric authentication based on the personal authentication standard. 1. The authentication system described in Appendix 3. (Appendix 5) the condition setting means sets the group authentication condition according to the ages of the members of the group included in the attribute information. An authentication system according to any one of Supplementary Notes 1 to 4. (Appendix 6) the authentication means performs the biometric authentication using an image of the member or the voice of the member; An authentication system according to any one of appendices 1 to 5. (Appendix 7) the authentication means extracts one of a face image, an iris image, and a fingerprint image from the image of the member as biometric information, and performs the biometric authentication based on the extracted biometric information; 1. The authentication system described in Appendix 6. (Appendix 8) The system further includes a storage means for storing personal information that links the authentication information of the person with the attribute information related to the group to which the person belongs, the condition setting means sets the group authentication condition based on the attribute information stored in the storage means. An authentication system according to any one of appendices 1 to 7. (Appendix 9) further comprising an update information receiving means for receiving predetermined information for updating the group authentication conditions. An authentication system according to any one of appendices 1 to 8. (Appendix 10) the update information receiving means receives a selection operation for performing authentication based on one of the group authentication conditions when the attribute information of the person includes a plurality of different groups; 10. The authentication system described in Appendix 9. (Appendix 11) the update information receiving means receives registration of the group to which the person belongs; 10. The authentication system described in Appendix 9. (Appendix 12) the update information receiving means receives history information on a history of authentication of the person; the condition setting means sets the group authentication condition in accordance with the history information. 10. The authentication system described in Appendix 9. (Appendix 13) the update information receiving means receives, as the history information, a first authentication level that is an authentication level for a predetermined outbound route of the group; the condition setting means sets a second authentication level of the group on the return journey corresponding to the outbound journey to a level lower than the first authentication level. 12. The authentication system described in Appendix 12. (Appendix 14) The computer Perform biometric authentication of a person based on predetermined personal authentication standards, setting group authentication conditions for other members in a group to which the person belongs based on attribute information of the authenticated person; and authenticating the other members based on the set group authentication conditions. Authentication method. (Appendix 15) Perform biometric authentication of a person based on predetermined personal authentication standards, setting group authentication conditions for other members in a group to which the person belongs based on attribute information of the authenticated person; and authenticating the other members based on the set group authentication conditions. A non-transitory computer-readable medium storing a program for causing a computer to execute an authentication method. [Explanation of symbols]
[0126] 1. Authentication System 2. Authentication System 3. Authentication System 11 Authentication Section 12 Condition setting section 13 Image data acquisition unit 14 Communications Department 15 Message output section 16 Memory section 17 Person Information Management Department 18 Update Information Reception Department 30 Person Information Management System 31 Communications Department 32 Control section 33 Person Information Management Department 34 Person information storage section 40. Entrance / exit control terminal 41 Camera 42 Display section 43 Gate 44 Entrance / Exit Control Unit 111 Feature Image Extraction Unit 112 Feature point extraction unit 161 Authentication Information 162 Person information 163 History Information 341 Person information 500 computers 504 processor 506 memory 508 Storage Devices 510 Input / Output Interface 512 network interface N1 Network
Claims
1. an authentication means for performing biometric authentication of a person based on a predetermined personal authentication standard; a condition setting means for setting group authentication conditions for other members in a group to which the authenticated person belongs based on attribute information of the authenticated person, the condition setting means specifies whether the authenticated person is a representative of the group based on the attribute information; the condition setting means sets the group authentication condition so that, when the authenticated person is identified as the representative, an authentication level for infants and young children is lower than an authentication level for adults; the authentication means, if the authenticated person is the representative, authenticates the other members based on the set group authentication conditions, and, if the authenticated person is not the representative, authenticates the other members based on the personal authentication standards. Authentication system.
2. further comprising a message output means for outputting a message prompting authentication of the representative when the authenticated person is not the representative; The authentication system of claim 1 .
3. The authentication means estimates whether the age of the person is less than a predetermined threshold age, the message output means outputs a message prompting authentication of the representative when the age of the person estimated by the authentication means is less than the threshold age and when the authentication means performs the biometric authentication based on the personal authentication standard. The authentication system of claim 2 .
4. the authentication means performs the biometric authentication using an image of the member or the voice of the member; The authentication system according to any one of claims 1 to 3.
5. the authentication means extracts one of a face image, an iris image, and a fingerprint image from the image of the member as biometric information, and performs the biometric authentication based on the extracted biometric information; The authentication system according to claim 4.
6. The system further includes a storage means for storing personal information that links the authentication information of the person with the attribute information related to the group to which the person belongs, the condition setting means sets the group authentication condition based on the attribute information stored in the storage means. The authentication system according to any one of claims 1 to 5.
7. The computer Perform biometric authentication of a person based on predetermined personal authentication standards, Identifying whether the authenticated person is a representative of a group to which the person belongs based on attribute information of the person; when the authenticated person is identified as the representative, setting group authentication conditions for other members in the group based on attribute information of the authenticated person so that an authentication level for infants is lower than an authentication level for adults; If the authenticated person is the representative, the other members are authenticated based on the set group authentication conditions, and if the authenticated person is not the representative, the other members are authenticated based on the personal authentication standards. Authentication method.
8. Perform biometric authentication of a person based on predetermined personal authentication standards, Identifying whether the authenticated person is a representative of a group to which the person belongs based on attribute information of the person; when the authenticated person is identified as the representative, setting group authentication conditions for other members in the group based on attribute information of the authenticated person so that an authentication level for infants is lower than an authentication level for adults; If the authenticated person is the representative, the other members are authenticated based on the set group authentication conditions, and if the authenticated person is not the representative, the other members are authenticated based on the personal authentication standards. A program that causes a computer to execute an authentication method.
Citation Information
Patent Citations
Face authentication device, personal image search system, face authentication control program, computer-readable recording medium, and control method for face authentication device
JP2010218060A
Crime prevention system
JP2015130155A
State notification control device and state notification system
JP2016148998A
Image processing device, control method and program of image processing device
JP2018005574A
Authentication system, authentication method and information processor
JP2019057004A