Authentication device, authentication method, and authentication system

The authentication system addresses inefficiencies in single-server processing by distributing authentication tasks across multiple devices, enhancing efficiency and speed through inter-device communication and information sharing.

JP7836980B2Active Publication Date: 2026-03-30PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-23
Publication Date
2026-03-30

AI Technical Summary

Technical Problem

Existing authentication systems face inefficiencies due to the concentration of processing on a single server device, leading to prolonged authentication times as the number of terminal devices increases, making it difficult to perform authentication processes quickly and efficiently.

Method used

An authentication system comprising multiple authentication devices that distribute processing tasks across a network, allowing for cooperative authentication information sharing and reducing the load on individual devices through inter-device communication.

Benefits of technology

This approach enhances authentication efficiency by distributing processing loads, enabling faster and more efficient identity verification across multiple devices, thereby improving overall system performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007836980000001
    Figure 0007836980000001
  • Figure 0007836980000002
    Figure 0007836980000002
  • Figure 0007836980000003
    Figure 0007836980000003
Patent Text Reader

Abstract

To provide an authentication device capable of improving the efficiency of authentication processing for objects to be authenticated while avoiding concentrating processing on specific devices.SOLUTION: The authentication device that is included in an authentication system including N (N: a constant that is an integer greater than or equal to 2) authentication devices includes: an authentication unit that executes a series of authentication processing for a target to be authenticated based on authentication information of the target to be authenticated; and a communication unit that transmits authentication information to at least one of (N-1) other authentication devices other than the own device out of N authentication devices via a network.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an authentication device, an authentication method, and an authentication system.

Background Art

[0002] Patent Document 1 discloses a face authentication system including a terminal device and a server device for face authentication. The terminal device includes an image acquisition unit that acquires an image of a person to be authenticated, an image processing unit that specifies a face region of the person to be authenticated from the acquired image and cuts out an image of a central portion of the face in a range narrower than the face contour from the specified face region, and a transmission unit that transmits the image of the central portion of the face to the server device. The server device includes a reception unit that receives the transmitted image of the central portion of the face and an authentication processing unit that executes face authentication processing based on the received image of the central portion of the face.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In Patent Document 1, the authentication process related to the identification of a person is executed by the server device rather than the terminal device. Here, in view of the possibility that the number of terminal devices may increase due to an increase in the number of authentication targets (for example, persons), an authentication system using a plurality of terminal devices and one server device is defined. In this case, the server device may receive and acquire authentication information sent from each of the plurality of terminal devices and perform authentication processing using each authentication information in parallel. Therefore, the load on the server device becomes large, and it takes a long time to perform the authentication process in the server device, making it difficult to perform the authentication process quickly. For this reason, improvement in the efficiency of the authentication process is required.

[0005] This disclosure was devised in light of the aforementioned conventional circumstances and aims to avoid the over-concentration of processing execution on a single device and to improve the efficiency of the authentication process for the object being authenticated. [Means for solving the problem]

[0006] This disclosure relates to an authentication device belonging to an authentication system including N (N: a constant integer greater than or equal to 2) authentication devices, the authentication unit which performs an authentication process for the object to be authenticated based on the authentication information of the object to be authenticated, A storage unit that stores the authentication information of the subject to authentication and the cooperation information between the N authentication devices, and based on the cooperation information between the N authentication devices stored in the storage unit, the authentication information At least one of the (N-1) other authentication devices among the N authentication devices, excluding itself, is connected via the network. Send We provide an authentication device that includes a communication unit.

[0007] Furthermore, this disclosure relates to an authentication method performed by an authentication device belonging to an authentication system including N (N: a constant integer greater than or equal to 2) authentication devices, wherein the authentication process for the object to be authenticated is performed based on the authentication information of the object to be authenticated. Based on the communication information between the N authentication devices stored in the storage unit of the authentication device, the authentication information is processed as follows: At least one of the (N-1) other authentication devices among the N authentication devices, excluding itself, is connected via the network. Send To trust and provide authentication methods.

[0008] Furthermore, this disclosure provides an authentication system comprising a server device and N (N: a constant integer greater than or equal to 2) authentication devices, wherein each authentication device performs an authentication process for the object to be authenticated based on the authentication information of the object to be authenticated, and transmits and receives the authentication information between the server device and at least one of the (N-1) other authentication devices among the N authentication devices that are not its own device.

[0009] These comprehensive or specific embodiments may be implemented as systems, devices, methods, integrated circuits, computer programs, or recording media, or as any combination of systems, devices, methods, integrated circuits, computer programs, and recording media. [Effects of the Invention]

[0010] According to this disclosure, it is possible to avoid concentrating processing on a single device and to improve the efficiency of the authentication process for the device being authenticated. [Brief explanation of the drawing]

[0011] [Figure 1] Diagram showing the authentication system according to this embodiment. [Figure 2] Block diagram of the client authentication terminal of this embodiment [Figure 3] Block diagram of the server authentication device of this embodiment [Figure 4] Block diagram of a server authentication device with authentication information input function. [Figure 5] Flowchart of the process for authenticating a person at a client authentication terminal [Figure 6] Flowchart of the client-to-client information sharing process performed by the client authentication terminal. [Figure 7] A diagram illustrating an example of client-to-client communication information. [Figure 8] A diagram illustrating an example of the recipient of client-to-client communication information based on conditions. [Figure 9] Sequence diagram showing a person performing authentication by moving between multiple client authentication terminals. [Figure 10] Sequence diagram showing the process when a person is authenticated using an authentication system that includes a server authentication device with an authentication information input function. [Figure 11] Flowchart for person authentication in a server authentication device [Modes for carrying out the invention]

[0012] Hereinafter, with appropriate reference to the drawings, embodiments specifically disclosing an authentication device, an authentication method, and an authentication system according to the present disclosure will be described in detail. However, detailed descriptions that are more than necessary may be omitted. For example, detailed descriptions of well-known matters and redundant descriptions of substantially the same configurations may be omitted. This is to avoid making the following description unnecessarily redundant and to facilitate the understanding of those skilled in the art. Note that the accompanying drawings and the following description are provided to enable those skilled in the art to fully understand the present disclosure, and are not intended to limit the subject matter described in the claims thereby.

[0013] Referring to FIG. 1, the concept of the authentication system according to this embodiment will be described. FIG. 1 is a diagram showing the authentication system according to this embodiment.

[0014] The authentication system 1 includes client authentication terminals CLA, CLB, CLC, CLD, CLE, CLF, and a server authentication device 20. In the following description, for convenience of explanation, each client authentication terminal is provided with a respective serial number (specifically, 1, 2, 3, 4, 5, 6), and the client authentication terminals CLA, CLB, CLC, CLD, CLE, CLF may be referred to as client authentication terminals 1, 2, 3, 4, 5, 6, respectively. The client authentication terminals CLA, CLB, CLC, CLD, CLE, CLF, and the server authentication device 20 are communicably connected via a network NW. Note that although the number of client authentication terminals constituting the authentication system 1 is shown as 6 in FIG. 1, it is not limited to this number.

[0015] The authentication system 1 is installed so as to be available in a certain area such as a tourist destination. Each of a plurality of client authentication terminals is installed in a tourist facility or a tourist spot within the tourist destination. A person (for example, a tourist) performs authentication for identity verification using the client authentication terminal installed in each tourist facility or the like. The person may visit a plurality of tourist facilities existing within the tourist destination and receive services provided at those tourist facilities. Therefore, the authentication system 1 coordinates information related to the authentication of the person (hereinafter referred to as authentication information) among the plurality of client authentication terminals. The information related to authentication is, for example, information used for the authentication process. The authentication information will be described in detail in FIG. 2. Thereby, even when the person visits another tourist facility and performs authentication using the client authentication terminal installed in that tourist facility, the authentication for identity verification can be smoothly performed. Note that the case where the authentication system 1 is used is not limited to a tourist destination, and it may be an amusement park, a theme park, a stadium, or the like. Further, the authentication system 1 may be installed across a plurality of tourist destinations.

[0016] In the authentication system 1 according to the present embodiment, at least one group of client authentication terminals is defined when coordinating among the plurality of client authentication terminals. For example, in FIG. 1, two groups (for example, group GR1 and GR6) are defined.

[0017] Group GR1 is a group of client authentication terminals that are pre-configured for client authentication terminal CLA to share authentication information. Client authentication terminal CLA shares (in other words, exchanges) authentication information with client authentication terminals CLB, CLC, and CLD. Client authentication terminals CLB, CLC, and CLD are referred to as fixed destinations for client authentication terminal CLA. In other words, according to Group GR1, client authentication terminals CLB, CLC, and CLD receive authentication information from client authentication terminal CLA. Note that client authentication terminal CLA may also send authentication information to other client authentication terminals in addition to fixed destinations (see Figure 7). Furthermore, client authentication terminal CLA does not necessarily have to share authentication information with all fixed destinations (see Figure 7).

[0018] Group GR6 is a pre-configured group of client authentication terminals that a client authentication terminal CLF uses to share authentication information. Client authentication terminal CLF shares (in other words, transmits) authentication information to client authentication terminals CLD and CLE, which are fixed recipients. However, client authentication terminal CLF may also transmit authentication information to other client authentication terminals in addition to its fixed recipients (see Figure 7). Furthermore, client authentication terminal CLF does not necessarily have to transmit authentication information to all fixed recipients (see Figure 7).

[0019] The client authentication terminal will be explained using the client authentication terminal CLA as an example. The client authentication terminal CLA performs identity verification of person hm when, for example, person hm approaches the client authentication terminal CLA. Note that the timing of identity verification of person hm is not limited to when person hm approaches the client authentication terminal CLA. The method of authenticating a person's identity is described in detail in Figure 2. If the authentication of person hm is successful, the client authentication terminal CLA sends authentication information (information interface) to a fixed recipient (for example, client authentication terminal CLB, client authentication terminal CLC, and client authentication terminal CLD). The client authentication terminal CLA may also send the information interface to the server authentication device 20. Note that other client authentication terminals operate similarly in terms of the authentication of a person's identity and the exchange of authentication information.

[0020] Next, the hardware configuration of the client authentication terminal in this embodiment will be described with reference to Figure 2. Figure 2 is a block diagram of the client authentication terminal in this embodiment.

[0021] The client authentication terminal 10 includes at least a communication interface 100, a feature database DBa, a collaborative information database DBb, a processor 103, an input device 101, and memory 102. The client authentication terminal 10 may further include a display unit 104. The client authentication terminal 10 is a tablet, a PC (Personal Computer), a mobile terminal, or a housing equipped with a biometric authentication device. The client authentication terminal 10 is one of N (N: a constant integer of 2 or more) client authentication terminals belonging to the authentication system 1.

[0022] The communication interface (I / F) 100 is a network interface circuit that communicates wirelessly or via wired connection with the network (NW). Here, I / F stands for interface. The client authentication terminal 10 is connected to the server authentication device (see Figure 1) and other client authentication terminals via the communication interface (I / F) 100 and the network (NW). The client authentication terminal 10 may also communicate directly with the server authentication device or other client authentication terminals without going through the network (NW). The communication interface (I / F) 100 transmits authentication information via the network (NW) to at least one of the (N-1) other client authentication terminals that are not its own device. The communication interface (I / F) 100 may also send and receive multiple types of authentication information. The communication methods used for communication at the communication interface (I / F) 100 include, for example, WAN (Wide Area Network), LAN (Local Area Network), LTE (Long Term Evolution), 5G and other mobile communications, power line communications, short-range wireless communications (e.g., Bluetooth® communications), and mobile phone communications.

[0023] The feature database DBa is constructed using a storage medium (e.g., flash memory, HDD (Hard Disk Drive), SSD (Solid State Drive)). The feature database DBa stores data that represents characteristic data of a person used in the authentication process (hereinafter referred to as registered features), and data that is input to the input device 101 and extracted by the feature extraction unit 1035 (hereinafter referred to as extracted features). Registered features and extracted features together are referred to as feature data. Feature data is an example of authentication information. Registered features are data used to verify the identity of a person in the authentication process, and include information such as the person's name, ID, or facial photograph, or biometric information such as fingerprints previously extracted from the person. However, registered features are not limited to these. Extracted features are data used to verify the identity of a person in the authentication process, and include, for example, fingerprints, facial data, or voice data. However, extracted features are not limited to these. In short, the feature database DBa stores the authentication information of the person to be authenticated. The feature database DBa transmits feature data to the feature database management unit 1031. The feature database DBa also continuously stores feature data obtained from the feature database management unit 1031.

[0024] The linked information database DBb is constructed using a storage medium (e.g., flash memory, HDD, SSD). The linked information database DBb stores information related to the linking (more specifically, sharing or passing) of person authentication information between client authentication terminals 10 and other client authentication terminals (hereinafter referred to as inter-client linked information). Inter-client linked information includes, for example, information on fixed delivery destinations, information on the installation location of each client authentication terminal, information on the conditions for determining the delivery destination of various types of information, information on determining the data used for person matching, and information on linked information or expiration dates of various types of information associated with each person. Here, information on determining the data used for person matching refers to information on whether to use registered features, extracted features, or both for matching. Furthermore, linked information associated with each person is, for example, linked information determined based on the person's gender, nationality, or preferences. In addition, inter-client linked information includes information on the expiration dates of authentication information and inter-client linked information. Note that the examples of inter-client linked information are just examples and are not limited to these. In other words, the linked information database DBb stores inter-client linked information between N authentication devices. The collaboration information database DBb transmits data to the collaboration information management unit 1033. The collaboration information database DBb also continuously stores client-to-client collaboration information obtained from the collaboration information management unit 1033.

[0025] The input device 101 inputs information about a person who has visited the location where the client authentication terminal 10 is installed. For example, the input device 101 may be a camera, a fingerprint authentication device, a microphone, a scanner, or a touch panel display. Note that the examples of input devices 101 are just examples and are not limited to these. Also, the client authentication terminal 10 may have more than one input device 101. If the input device 101 is a camera, it captures an image of the person's face and acquires facial data. If the input device 101 is a camera, it may also acquire vital information (e.g., body temperature or pulse). If the input device 101 is a microphone, it acquires the person's voice. If the input device 101 is a touch panel display, it accepts input of the person's information (e.g., name, ID, password). If the input device 101 is a scanner, it reads a barcode or QR code (registered trademark) possessed by the person. The input device 101 transmits the acquired data to the feature extraction unit 1035.

[0026] Memory 102 includes, for example, RAM (Random Access Memory) used as work memory when executing each process of processor 103, and ROM (Read Only Memory) which stores programs and data that define the operation of processor 103. Data or information generated or acquired by processor 103 is temporarily stored in RAM. Programs that define the operation of processor 103 are written in ROM.

[0027] The processor 103 is configured using, for example, a CPU (Central Processing Unit), a DSP (Digital Signal Processor), a GPU (Graphical Processing Unit), or an FPGA (Field Programmable Gate Array), and works in cooperation with the memory 102 to perform various processing and control operations. Specifically, the processor 103 refers to the programs and data held in the memory 102 and executes those programs to perform various operations.

[0028] The processor 103 provides comprehensive control over the client authentication terminal 10. The processor 103 implements the functions of the feature database management unit 1031, the server authentication processing unit 1032, the collaboration information management unit 1033, the matching judgment processing unit 1034, the feature extraction unit 1035, and the authentication status operation processing unit 1036. During operation, the processor 103 uses the RAM of memory 102 to temporarily store data generated or acquired by each part of the processor 103.

[0029] The feature database management unit 1031 manages the feature data. The feature database management unit 1031 transmits the feature data obtained from the feature database DBa to the matching and judgment processing unit 1034. The feature database management unit 1031 manages the transmission and reception of feature data with the communication interface 100. The feature database management unit 1031 obtains the extracted features extracted by the feature extraction unit 1035 from the matching and judgment processing unit 1034 and transmits the extracted features to the feature database DBa. Alternatively, the feature database management unit 1031 may directly obtain the extracted features from the feature extraction unit 1035.

[0030] The server authentication processing unit 1032 manages instructions to the server authentication device 20 (see Figure 3). If the matching judgment fails in the matching judgment processing unit 1034, the server authentication processing unit 1032 generates an instruction to cause the server authentication device 20 to perform a matching judgment. The server authentication processing unit 1032 sends the generated instruction and feature data to the server authentication processing unit 1032 via the communication interface 100. The server authentication processing unit 1032 obtains the result of the authentication process performed by the server authentication device 20 from the communication interface 100. The server authentication processing unit 1032 outputs the result of the authentication process in the server authentication device 20 to the matching judgment processing unit 1034. Alternatively, the server authentication processing unit 1032 may output the result of the authentication process in the server authentication device 20 to the authentication status operation processing unit 1036.

[0031] The Linked Information Management Unit 1033 manages inter-client linked information. The Linked Information Management Unit 1033 manages inter-client linked information, including expiration date information, and authentication information of the authenticated entity. The Linked Information Management Unit 1033 transmits the linked information obtained from the linked information database DBb to the matching determination processing unit 1034. The Linked Information Management Unit 1033 transmits the inter-client linked information to the communication I / F 100 in order to transmit it to other client authentication terminals and server authentication devices 20. The Linked Information Management Unit 1033 also obtains inter-client linked information transmitted from other client authentication terminals. The Linked Information Management Unit 1033 deletes authentication information of the authenticated entity and inter-client linked information that have expired.

[0032] The matching determination processing unit 1034 performs a person matching determination based on registered features obtained from the feature database management unit 1031 and / or extracted features extracted by the feature extraction unit 1035. In other words, the matching determination processing unit 1034 executes the authentication process for the person to be authenticated based on the authentication information of the person to be authenticated. The matching determination processing unit 1034 may also perform multi-factor authentication. Multi-factor authentication here means performing matching from multiple feature data, such as performing matching determination from two types of data: facial data and fingerprint data. The matching determination processing unit 1034 transmits the result of the matching determination to the authentication status operation processing unit 1036. The matching determination processing unit may also transmit the result of the matching determination on the server to the authentication status operation processing unit 1036 if it has obtained it from the server authentication processing unit 1032.

[0033] The feature extraction unit 1035 extracts features from the data acquired from the input device 101. The feature extraction unit 1035 transmits the extracted features to the matching judgment processing unit 1034.

[0034] The authentication status operation processing unit 1036 performs actions according to the results of the matching judgment obtained from the matching judgment processing unit 1034. These actions include, for example, opening a gate installed near the client authentication terminal 10 and displaying "Authentication successful" on the display unit 104 if the matching judgment is successful. Other actions include, for example, sounding a buzzer from the speaker installed in the client authentication terminal 10, closing the gate, and displaying "Authentication failed" on the display unit 104 if the matching judgment is unsuccessful.

[0035] The display unit 104 is, for example, a display. It displays the result of the matching judgment or the status of the matching judgment process. Note that the client authentication terminal 10 does not necessarily have to be equipped with a display unit 104.

[0036] Next, the hardware configuration of the server authentication device of this embodiment will be described with reference to Figure 3. Figure 3 is a block diagram of the server authentication device of this embodiment.

[0037] The server authentication device 20 includes a communication interface 200, a feature database DBc, a collaborative information database DBd, memory 201, and a processor 202.

[0038] The communication interface (I / F) 200 is a network interface circuit that communicates wirelessly or via wired connection with the network (NW). The server authentication device 20 is connected to the client authentication terminal 10 (see Figure 2) via the communication interface (I / F) 200 and the network (NW). The server authentication device 20 may be connected to multiple client authentication terminals as shown in the example in Figure 1, or it may be connected to other server authentication devices. The server authentication device 20 may also communicate directly with the client authentication terminal 10 without going through the network (NW). The communication methods used for communication at the communication interface (I / F) 200 include, for example, mobile communications such as WAN, LAN, LTE, and 5G, power line communications, short-range wireless communications (e.g., Bluetooth® communications), and communications for mobile phones. The communication interface (I / F) 200 acquires feature data transmitted from the client authentication terminal 10 via the network (NW). The communication interface (I / F) 200 transmits the acquired feature data to the feature database management unit 2021.

[0039] The feature database DBc is configured using a storage medium (e.g., flash memory, HDD, SSD). The feature database DBc stores feature data. The feature database DBc may hold all registered features, or all or some of the extracted features obtained from client authentication terminals or servers with authentication information input functions connected via a network NW. For example, in the example shown in Figure 1, the feature database DBc holds all features. Alternatively, the feature database DBc may hold all extracted features held by client authentication terminals CLA, CLB, CLC, CLD, CLE, and CLF, respectively. Or, the feature database DBc may only hold the extracted features obtained from the first server authentication device or client authentication terminal with authentication information input function visited. Alternatively, the feature database DBc may only hold the most recent extracted features, or may not hold any extracted features at all. The feature database DBc transmits the feature data to the feature database management unit 2021. Furthermore, the feature database DBc continuously stores feature data acquired from the feature database management unit 2021.

[0040] The collaboration information database DBd is configured using a storage medium (e.g., flash memory, HDD, SSD). The collaboration information database DBd holds inter-client collaboration information for all or some of the multiple client authentication terminals to which the server authentication device 20 is connected for communication. For example, in the example shown in Figure 1, the collaboration information database DBd holds the inter-client collaboration information held by client authentication terminals CLA, CLB, CLC, CLD, CLE, and CLF. The collaboration information database DBd transmits this information to the collaboration information management unit 2022. The collaboration information database DBd also saves inter-client collaboration information obtained from the collaboration information management unit 2022 as it is received.

[0041] Memory 201 includes, for example, RAM as work memory used when executing each process of processor 202, and ROM which stores programs and data that define the operation of processor 103. Data or information generated or acquired by processor 202 is temporarily stored in RAM. Programs that define the operation of processor 202 are written to ROM.

[0042] The processor 202 is configured using, for example, a CPU, DSP, GPU, or FPGA, and works in cooperation with the memory 201 to perform various processing and control operations. Specifically, the processor 202 refers to the programs and data held in the memory 201 and executes the programs, thereby performing various operations that the processor 202 is supposed to do. The processor 202 comprehensively controls the server authentication device 20. The processor 202 implements the functions of the feature database management unit 2021, the collaboration information management unit 2022, and the matching judgment processing unit 2023. During operation, the processor 202 uses the RAM of the memory 201 to temporarily store data generated or acquired by each part of the processor 202.

[0043] The Feature Database Management Unit 2021 manages the feature data. The Feature Database Management Unit 2021 transmits the feature data obtained from the feature database DBc to the Matching and Determination Processing Unit 2023. The Feature Database Management Unit 2021 manages the transmission and reception of feature data with the communication interface 200. The Feature Database Management Unit 2021 transmits the feature data obtained from the communication interface 200 to the Matching and Determination Processing Unit 2023 and the feature database DBc.

[0044] The Linked Information Management Unit 2022 manages linked information. The Linked Information Management Unit 2022 transmits linked information obtained from the linked information database DBd to the matching and judgment processing unit 2023. The Linked Information Management Unit 2022 transmits inter-client linked information to the communication interface 200 in order to send it to the client authentication terminal 10. The Linked Information Management Unit 1033 also obtains inter-client linked information transmitted from the client authentication terminal 10. The Linked Information Management Unit 2022 deletes inter-client linked information that has expired.

[0045] The matching determination processing unit 2023 performs a person matching determination based on the feature data obtained from the feature database management unit 2021. The matching determination processing unit 2023 may also perform multi-factor authentication, which uses multiple types of authentication information (for example, facial image data for facial recognition, fingerprint data for fingerprint recognition). The matching determination processing unit 2023 transmits the matching determination result to the communication interface 200.

[0046] Next, with reference to Figure 4, the hardware configuration of the server authentication device with authentication information input functionality will be described. Figure 4 is a block diagram of the server authentication device with authentication information input functionality.

[0047] The server authentication device 21 shown in Figure 4 is a server authentication device when the client authentication terminal 10 shown in Figure 2 has the same functionality as the server authentication device 20. In other words, the server authentication device 21 is a device that has feature data for all other client authentication terminals in its feature database DBe and is equipped with an input device 211.

[0048] The server authentication device 21 is installed in facilities such as amusement parks or theme parks. In such facilities, there are limited entrances, and those to be authenticated must be authenticated at the entrance before entering. By making the server authentication device 21 the authentication terminal at the entrance, the server authentication device 21 can perform authentication using all authentication information initially. Subsequently, the server authentication device 21 can perform smooth authentication by transmitting information to multiple client authentication terminals installed within the facility based on inter-client communication information.

[0049] The communication interface 210 is a network interface circuit that communicates wirelessly or via wired connection with the network NW. The server authentication device 21 is connected to other client authentication terminals 10 (see Figure 2) via the communication interface 210 and the network NW. The server authentication device 21 may also be connected to server authentication device 20 in a communication manner. The communication methods used for communication at the communication interface 200 include, for example, mobile communications such as WAN, LAN, LTE, and 5G, power line communications, short-range wireless communications (e.g., Bluetooth® communications), and communications for mobile phones. The communication interface 200 acquires feature data transmitted from the client authentication terminals 10 via the network NW. The communication interface 210 transmits the acquired feature data to the feature database management unit 2131.

[0050] The feature database DBe is configured using a storage medium (e.g., flash memory, HDD, SSD). Similar to the feature database DBc of the server authentication device 20, the feature database DBe holds feature data for all other client authentication terminals. The feature database DBe transmits feature data to the feature database management unit 2131.

[0051] The inter-client information database DBf is configured using a storage medium (e.g., flash memory, HDD, SSD). Similar to the inter-client information database DBd of the server authentication device 20, it holds inter-client inter-client information for all of the multiple client authentication terminals. The inter-client inter-client information database DBf transmits the inter-client inter-client information to the inter-client information management unit 2132.

[0052] The input device 211 inputs information about a person who has visited the location where the server authentication device 21 is installed. For example, the input device 211 may be a camera, a fingerprint authentication device, a microphone, a scanner, or a touch panel display. Note that the examples of input devices 211 are just examples and are not limited to these. The server authentication device 21 may also be equipped with multiple devices as input devices 211. The input device 211 transmits the acquired data to the feature extraction unit 2134.

[0053] Memory 212 includes, for example, RAM as work memory used when executing each process of processor 213, and ROM which stores programs and data that define the operation of processor 213. Data or information generated or acquired by processor 213 is temporarily stored in RAM. Programs that define the operation of processor 213 are written in ROM.

[0054] The processor 213 is configured using, for example, a CPU, DSP, GPU, or FPGA, and works in cooperation with the memory 212 to perform various processing and control operations. Specifically, the processor 213 refers to the programs and data held in the memory 212 and executes the programs, thereby performing various operations that the processor 213 is supposed to do. The processor 213 comprehensively controls the server authentication device 21. The processor 213 implements the functions of the feature database management unit 2131, the linkage information management unit 2132, the matching judgment processing unit 2133, the feature extraction unit 2134, and the authentication status operation processing unit 2135. During operation, the processor 213 uses the RAM of the memory 212 to temporarily store data generated or acquired by each part of the processor 213.

[0055] The feature database management unit 2131 manages the feature data. The feature database management unit 2131 transmits the feature data obtained from the feature database DBe to the matching and judgment processing unit 2133. The feature database management unit 2131 manages the transmission and reception of feature data with the communication interface 210. The feature database management unit 2131 transmits the feature data obtained from the communication interface 210 to the matching and judgment processing unit 2133 and the feature database.

[0056] The Linkage Information Management Unit 2132 manages the linkage information. The Linkage Information Management Unit 2132 transmits the client-to-client linkage information obtained from the linkage information database DBf to the matching and judgment processing unit 2023. The Linkage Information Management Unit 2022 transmits the client-to-client linkage information to the communication interface 200 in order to send the linkage information to the client authentication terminal 10. The Linkage Information Management Unit 1033 also obtains the client-to-client linkage information transmitted from the client authentication terminal 10. The Linkage Information Management Unit 2132 deletes the authentication information and client-to-client linkage information of the authenticated target that have expired.

[0057] The matching determination processing unit 2133 performs a person matching determination based on the feature data obtained from the feature database management unit 2131 and the extracted features extracted from the feature extraction unit 2134. The matching determination processing unit 2133 may also perform multi-factor authentication. The matching determination processing unit 2133 transmits the matching determination result to the communication interface 210.

[0058] The feature extraction unit 2134 extracts features from the data acquired from the input device 211. The feature extraction unit 2134 transmits the extracted features to the matching judgment processing unit 2133.

[0059] The authentication status operation processing unit 2135 performs operation processing according to the result of the matching determination obtained from the matching determination processing unit 2133.

[0060] The display unit 214 is, for example, a display. It displays the result of the matching judgment or the status of the matching judgment process. Note that the server authentication device 21 does not necessarily have to include the display unit 214.

[0061] Next, the process of authenticating a person in the client authentication terminal will be explained with reference to Figure 5. Figure 5 is a flowchart of the process of authenticating a person in the client authentication terminal. Each step in Figure 5 is performed by the processor 103 of the client authentication terminal 10.

[0062] The matching determination processing unit 1034 obtains all the feature data necessary for matching from the feature database management unit 1031 and reads the feature data (step St101).

[0063] The feature extraction unit 1035 extracts features from the data input to the input device 101 (step St102). The feature extraction unit 1035 transmits the extracted features to the matching judgment processing unit 1034.

[0064] The matching determination processing unit 1034 performs a matching determination based on all the feature data obtained in step St101 and the extracted features extracted in step St102 (step St103).

[0065] If the matching determination processing unit 1034 determines in step St103 that the matching determination for authenticating a person is successful (step St104, YES), it sends a signal indicating that the matching determination was successful to the linked information management unit 1033 and the authentication status operation processing unit 1036. When the linked information management unit 1033 receives the signal based on the processing in step St104, it executes the processing of inter-client linked information (step St109). The processing in step St109 is described in detail in Figure 6.

[0066] The authentication status operation processing unit 1036 executes an operation process (step St110) based on the signal obtained in step St104, which indicates that authentication was successful.

[0067] If the matching determination processing unit 1034 determines in step St103 that the matching determination for person authentication has failed (step St104, NO), it sends a signal to the server authentication processing unit 1032 indicating that authentication has failed. Based on the signal received from the matching determination processing unit 1034, the server authentication processing unit 1032 sends feature data to the server authentication device 20 (step St105).

[0068] The server authentication device 20 receives a signal indicating authentication failure and feature data from the client authentication terminal 10. The matching determination processing unit 2023 of the server authentication device 20 performs a matching determination based on the acquired feature data. The matching determination processing unit 2023 outputs the result of the matching determination to the communication I / F 200 and sends it to the client authentication terminal 10. The matching determination processing unit 1034 of the client authentication terminal 10 receives the result of the matching determination performed by the server authentication device 20 from the server authentication device 20 (step St106).

[0069] The matching determination processing unit 1034 determines whether the matching determination result for authenticating the person obtained in step St106 was successful or not. If the matching determination processing unit 1034 determines that the matching determination result was a failure (step St107, NO), it sends a signal to the authentication status operation processing unit 1036 indicating that the matching determination result was a failure.

[0070] The authentication status operation processing unit 1036 executes an operation process for when authentication fails based on the signal obtained in step St107 (step St108).

[0071] If the matching determination processing unit 1034 determines that the matching determination is successful (step St107, YES), the matching determination processing unit 1034 proceeds to the process in step St109.

[0072] Next, with reference to Figure 6, the client-to-client information sharing process performed by the client authentication terminal will be described. Figure 6 is a flowchart of the client-to-client information sharing process performed by the client authentication terminal. Each process shown in Figure 6 is executed by the processor 103 of the client authentication terminal 10.

[0073] The Linkage Information Management Unit 1033 reads client-to-client linkage information from the linkage information database DBb (step St201).

[0074] The inter-client inter-client inter-client information management unit 1033 determines whether the read inter-client inter-client information is the latest information (step St202). In other words, step St202 determines whether the inter-client inter-client inter-client information held by the client authentication terminal 10, which was read in step St201, has expired. If the inter-client inter-client inter-client information management unit 1033 determines that the information is the latest information (in other words, it is not expired) (step St202, YES), it determines the destination of the authentication information based on the inter-client inter-client inter-client information. After this, the processor 103 proceeds to the process in step St206.

[0075] If the Inter-Client Inter-Client Inter-Client Information Management Unit 1033 determines that the information is not up-to-date (in other words, it is expired) (Step St202, NO), it requests the Server Authentication Device 20 to send the information (Step St203).

[0076] When the server authentication device 20 receives a request to send inter-client communication information in step St203, it sends the inter-client communication information stored in the communication information database DBd of the server authentication device 20 to the client authentication terminal 10. The communication information management unit 1033 of the client authentication terminal 10 obtains the inter-client communication information from the server authentication device 20 (step St204).

[0077] The Inter-Client Inter-Client Information Management Unit 1033 saves the inter-client inter-client information obtained in step St204 to the inter-client information database DBb (step St205). Based on the inter-client inter-client information, the Inter-Client Information Management Unit 1033 determines the destination for sending authentication information. The processing of the Inter-Client Information Management Unit 1033 then moves on to step StSt206.

[0078] The Inter-Client Information Management Unit 1033 determines whether or not to use the registered features based on the inter-client information (step St206). If the Inter-Client Information Management Unit 1033 determines that the registered features should be used (step St206, YES), it transmits the registered features to the communication interface 100 based on the inter-client information. The communication interface 100 transmits the registered features to other client authentication terminals (step St207).

[0079] If the Linked Information Management Unit 1033 determines, based on the inter-client linkage information, that the registered features will not be used (step St206, NO), the Linked Information Management Unit 1033 proceeds to step St208.

[0080] The inter-client information management unit 1033 determines whether or not to use the extracted features based on the inter-client information (step St208). If the inter-client information management unit 1033 determines to use the extracted features (step St208, YES), it transmits the extracted features to the communication interface 100 based on the inter-client information. The communication interface 100 transmits the extracted features to other client authentication terminals and server authentication devices 20 (step St209).

[0081] As a result of the processing in steps St207 and St209, the communication I / F 100 transmits authentication information to at least one of the (N-1) other client authentication terminals if the authentication by the matching determination processing unit 1034 is successful.

[0082] Next, an example of inter-client communication information will be explained with reference to Figure 7. Figure 7 is a diagram showing an example of inter-client communication information. The client authentication terminals in Figure 7 represent the client authentication terminals shown in the example in Figure 1. The relative positions of each client authentication terminal are assumed to be as shown in Figure 1.

[0083] Cases (1) through (4) all involve inter-client communication information related to client authentication terminal 1. The parameters of inter-client communication information are those used to determine the destination of feature data. Examples of parameters include environmental parameters, personal parameters, or location parameters. Environmental parameters include, for example, weather, the time a person visited the client authentication terminal, or information about the location where the client authentication terminal is installed. Personal parameters include, for example, a person's gender, age, or information about client authentication terminals that have been authenticated in the past. Location parameters include, for example, the address of the client authentication terminal or GPS (Global Positioning System) information. Note that the examples of environmental parameters, personal parameters, and location parameters are not limited to those mentioned above.

[0084] The destination for client-to-client communication information in Case No. (1) is a fixed destination. Case No. (1) has no parameters. The client authentication terminals to which feature data is sent in Case No. (1) are the fixed destinations Client Authentication Terminal 2, Client Authentication Terminal 3, and Client Authentication Terminal 4. When Group GR1 is created, it is set that there are three fixed destinations from Client Authentication Terminal CLA, which corresponds to Client Authentication Terminal 1: Client Authentication Terminal CLB (Client Authentication Terminal 2), Client Authentication Terminal CLC (Client Authentication Terminal 3), and Client Authentication Terminal CLD (Client Authentication Terminal 4).

[0085] In Case No. (2), the destinations for client-to-client communication information are fixed destinations and destinations determined by conditions for adding or removing destinations due to parameters. Case No. (2) has at least one parameter from among environment parameters, personal parameters, and location parameters. The client authentication terminals to which the feature data in Case No. (2) is sent are the fixed destinations Client Authentication Terminal 2, Client Authentication Terminal 3, Client Authentication Terminal 4, and destinations determined by conditions. Therefore, depending on the parameters, for example, Client Authentication Terminal 2 may be removed from the destinations, or Client Authentication Terminal 5 may be added to the destinations.

[0086] In Case No. (3), the destination for the inter-client communication information is determined by the conditions for adding or deleting destinations due to the parameters. In Case No. (3), client authentication terminal 1 is fixed in place and does not move. In Case No. (3), the parameters include at least one of the following: environment parameters, personal parameters, and location parameters. In Case No. (3), the destination client authentication terminal for the feature data is one of client authentication terminals 2, 3, 4, 5, or 6.

[0087] In Case No. (4), the destination for client-to-client communication information is determined by the conditions for adding or deleting destinations based on parameters. In Case No. (4), client authentication terminal 1 is installed on a moving object (e.g., a bus, car, etc.), and the location of client authentication terminal 1 moves. It has at least one parameter from among environment parameters, personal parameters, and location parameters. In Case No. (4), the destination client authentication terminal for the feature data is one of client authentication terminal 2, client authentication terminal 3, client authentication terminal 4, client authentication terminal 5, or client authentication terminal 6.

[0088] Next, with reference to Figure 8, an example of a destination for condition-based inter-client communication information will be explained. Figure 8 is a diagram showing an example of a destination for condition-based inter-client communication information. Case No. (2) in Figure 8 represents the same case as Case No. (2) in Figure 7. The same applies to Case No. (3) and Case No. (4).

[0089] Case No. (2)-A is a case where a person visits the location where client authentication terminal 1 is installed. In case No. (2)-A, the person is male and visited client authentication terminal 1 in the early morning. Therefore, the parameters are "early morning" and "male". In case No. (2)-A, client authentication terminal 6 is added as a destination for feature data based on past statistical data. The fixed destinations for client authentication terminal 2, client authentication terminal 3, and client authentication terminal 4 in case No. (2)-A are client authentication terminal 2, client authentication terminal 3, client authentication terminal 4, and client authentication terminal 6. This is because, based on past data, it is predicted that a male who visited client authentication terminal 1 in the early morning is likely to also visit client authentication terminal 6 next.

[0090] Case No. (2)-B is a case where a person visits the location where client authentication terminal 1 is installed. In case No. (2)-B, the person is female and visits client authentication terminal 1 at night. Therefore, the parameters are "night" and "female". In case No. (2)-B, client authentication terminal 4 is removed from the destination of feature data from past statistical data. The fixed destinations for case No. (2)-B are client authentication terminal 2, client authentication terminal 3, and client authentication terminal 4. The final destinations for feature data in case No. (2)-A are client authentication terminal 2 and client authentication terminal 3. This is because, based on past data, it is predicted that a woman who visited client authentication terminal 1 at night is unlikely to visit client authentication terminal 4 next.

[0091] Case No. (3)-A is a case where a person visits the location where client authentication terminal 1 is installed. In Case No. (3)-A, client authentication terminal 1 is installed in a city. Therefore, the parameters are "installed in a city" and "location of client authentication terminal 1". In Case No. (3)-A, client authentication terminals within walking distance from client authentication terminal 1 are determined as destinations for the feature data. In Case No. (3)-A, there are no fixed destinations. The final destination for the feature data in Case No. (3)-A is client authentication terminal 2. In Case No. (3)-A, the person's mode of transportation is estimated based on the location of client authentication terminal 1, and the destination is determined accordingly.

[0092] Case No. (3)-B is a case where a person visits the location where client authentication terminal 1 is installed. In Case No. (3)-B, client authentication terminal 1 is installed in a suburban area. Therefore, the parameters are "installed in a suburban area" and "location of client authentication terminal 1". In Case No. (3)-B, client authentication terminals within a reasonable driving distance from client authentication terminal 1 are determined as destinations for the feature data. In Case No. (3)-B, there are no fixed destinations. The final destinations for the feature data in Case No. (3)-B are client authentication terminals 2, 3, 4, 5, and 6. In Case No. (3)-B, the mode of transportation of the person is estimated based on the location of client authentication terminal 1, and the destinations for the feature data are determined accordingly.

[0093] Case No. (3)-C is a case where a person visits the location where client authentication terminal 1 is installed. In Case No. (3)-C, the person has authenticated at client authentication terminal 1 within the past 24 hours. In other words, the parameter is "authentication at client authentication terminal 1 within the past 24 hours". In Case No. (3)-C, the destination of the feature data is determined from past statistical data and authentication history. In Case No. (3)-C, there is no fixed destination. The final destination of the feature data in Case No. (3)-C is client authentication terminal 6. In Case No. (3)-C, for example, a person who has visited client authentication terminal 1 within the past 24 hours from a popular tourist route is likely to visit client authentication terminal 6 afterward, and therefore the destination of the feature data is determined.

[0094] Case No. (4) is a case where a person authenticates with client authentication terminal 1. Case No. (4) is a case where the location where client authentication terminal 1 is installed moves. For example, this is the case when client authentication terminal 1 is installed inside a bus. Note that this is not the only specific example of case No. (4). The parameter for case No. (4) is "location of client authentication terminal 1". In case No. (4), the destination of the feature data is determined for each location of client authentication terminal 1. In case No. (4), there is no fixed destination. The final destinations of the feature data in case No. (4) are client authentication terminal 2, client authentication terminal 3, client authentication terminal 4, and client authentication terminal 5. In case No. (4), the feature data is sent from the new location of client authentication terminal 1 to the next client authentication terminal that the person may visit.

[0095] In this way, authentication system 1 modifies client-to-client information based on predetermined conditions. Furthermore, it modifies client-to-client information based on the personal information of the person being authenticated using authentication system 1.

[0096] Next, with reference to Figure 9, we will explain the process when a person moves between multiple client authentication terminals and performs authentication. Figure 9 is a sequence diagram of when a person moves between multiple client authentication terminals and performs authentication.

[0097] The server shown in Figure 9 is the server authentication device 20. Terminal 1 is client authentication terminal 1. Terminal 2 is client authentication terminal 2. Terminal 3 is client authentication terminal 3. Terminal 4 is client authentication terminal 4. Terminal 5 is client authentication terminal 5. Terminal 6 is client authentication terminal 6. Hereinafter, the server authentication device 20 will be referred to as the "server," and each client authentication terminal will be referred to as a "terminal."

[0098] When person hm1 performs authentication on terminal 1, terminal 1 performs a verification check for person hm1 (step St301). Hereinafter, the verification check performed on the terminal will be referred to as terminal verification. Assume that terminal verification is successful on terminal 1.

[0099] Terminal 1 determines the destination for sending feature data based on inter-client communication information (step St302).

[0100] Terminal 1 determines the feature data to send to other terminals (step St303).

[0101] Terminal 1 performs an action (step St304) according to the result of terminal verification performed in step St301. This action may include, for example, opening a gate or displaying text on a display indicating successful authentication.

[0102] Terminal 1 transmits the feature data determined in step St303 to the destination terminal determined in step St302. Terminal 1 transmits the feature data to terminals 2, 3, and 4 (step St3041).

[0103] Next, person hm1 moves to the location where terminal 4 is installed and performs authentication. Terminal 4 has previously obtained the feature data transmitted in step St3041. Terminal 4 performs terminal matching of person hm1 (step St305). In other words, terminal 4 authenticates person hm1 using the authentication information of person hm1, who is the person to be authenticated, obtained via the communication I / F100 from at least one of the (N-1) other client authentication terminals. Terminal 4 succeeds in terminal matching because it obtained the feature data of person hm1 in step St3041.

[0104] Terminal 4 determines the destination for sending the feature data based on the inter-client communication information (step St306).

[0105] Terminal 4 determines the feature data to send to other terminals (step St307).

[0106] Terminal 4 performs an action according to the result of the terminal verification performed in step St305 (step St308).

[0107] Terminal 4 transmits the feature data determined in step St306 to the destination terminal determined in step St306. Terminal 4 transmits the feature data to terminals 3 and 5 (step St3081).

[0108] Next, person hm1 moves to the location where terminal 6 is installed and performs authentication. Terminal 6 performs terminal matching of person hm1 (step St309). Terminal 6 does not have the feature data of person hm1, so terminal matching fails.

[0109] When terminal 6 performs terminal matching in step St309, it sends feature data acquired from the input device installed on terminal 6 to the server (step St3091).

[0110] When the server obtains the feature data of person hm1 in step St3091, it performs a match on the server (hereinafter referred to as server match) (step St301).

[0111] The server sends the result of the server verification related to the processing in step St310 to terminal 6 (step St3101).

[0112] Terminal 6 performs an action according to the result of the server verification process in step St310 (step St311). If the server verification process in step St310 is successful, terminal 6 transmits the authentication information used for server verification to other client authentication terminals based on the inter-client communication information.

[0113] As a result, the client authentication terminal 10 transmits authentication information to at least one of the (N-1) other client authentication terminals if at least one of the authentication processes performed by its own device or by the server authentication device 20 is successful.

[0114] Next, with reference to Figure 10, we will explain the process when a person is authenticated using an authentication system that includes a server authentication device with an authentication information input function. Figure 10 is a sequence diagram of when a person is authenticated using an authentication system that includes a server authentication device with an authentication information input function.

[0115] The representative server shown in Figure 10 is the server authentication device 20. The terminals are the same as in Figure 9. Terminal 1 has the same functions as the server authentication device 21. Hereafter, the server authentication device 20 will be referred to as the "representative server," and each client authentication terminal will be referred to as a "terminal."

[0116] When person hm1 performs authentication on terminal 1, terminal 1 performs server verification for person hm1 (step St401). Since terminal 1, which is the server authentication device 21, has the authentication information of all persons to be authenticated, authentication is successful.

[0117] Terminal 1 determines the destination for sending feature data based on inter-client communication information (step St402).

[0118] Terminal 1 determines the feature data to send to other terminals (step St403).

[0119] Terminal 1 performs an action according to the result of the server matching performed in step St401 (step St404).

[0120] Terminal 1 transmits the feature data determined in step St403 to the destination terminal determined in step St402. Terminal 1 transmits the feature data to terminals 2, 3, and 4 (step St4041).

[0121] Next, person hm1 moves to terminal 4 and performs authentication. Terminal 4 obtains the feature data transmitted in step St4041. Terminal 4 performs terminal matching of person hm1 (step St405). Terminal 4 succeeds in terminal matching because it obtained the feature data of person hm1 in step St4041.

[0122] Terminal 4 determines the destination for sending the feature data based on the inter-client communication information (step St406).

[0123] Terminal 4 determines the feature data to send to other terminals (step St407).

[0124] Terminal 4 performs an action according to the result of the terminal verification performed in step St405 (step St408).

[0125] Terminal 4 transmits the feature data determined in step St306 to the destination terminal determined in step St406. Terminal 4 transmits the feature data to terminals 3 and 5 (step St4081).

[0126] Next, person hm1 moves to terminal 6 and performs authentication. Terminal 6 performs terminal matching of person hm1 (step St409). Terminal 6 does not have the feature data of person hm1, so terminal matching fails.

[0127] When terminal 6 performs terminal matching in step St409, it sends feature data acquired from the input device installed on terminal 6 to the server (step St4091).

[0128] When the server obtains the feature data of person hm1 in step St4091, it performs server matching (step St301).

[0129] The server sends the result of the server verification related to the processing in step St410 to terminal 6 (step St4101).

[0130] Terminal 6 performs an action according to the result of the server verification related to the processing in step St410 (step St411).

[0131] Next, the process of authenticating a person in the server authentication device will be explained with reference to Figure 11. Figure 11 is a flowchart of the authentication process in the server authentication device. Each step in the flowchart shown in Figure 11 is executed by the processor 202 of the server authentication device 20.

[0132] The feature database management unit 2021 acquires the feature data transmitted from the client authentication terminal 10 (step St501). The feature database management unit 2021 transmits the feature data acquired in step St501 to the matching judgment processing unit 2023.

[0133] The matching determination processing unit 2023 performs a matching determination of the person (step St502).

[0134] The matching determination processing unit 2023 determines whether authentication was successful or not based on the result of the matching determination related to the processing in step St502 (step St503).

[0135] If the matching determination processing unit 2023 determines that authentication has failed (step St503, NO), it sends a signal to the communication interface 200 indicating that authentication has failed (step St504). The communication interface 200 then sends the signal indicating that authentication has failed, obtained in step St504, to the client authentication terminal 10.

[0136] If the verification processing unit 2023 determines that authentication was successful in step St503 (step St503, YES), it sends a signal to the communication interface 200 indicating that authentication was successful (step St505). The communication interface 200 then sends the signal indicating successful authentication, obtained in step St505, to the client authentication terminal 10.

[0137] As described above, the client authentication terminal 10 according to this embodiment is a client authentication terminal belonging to an authentication system 1 that includes N (N: a constant integer of 2 or more) client authentication terminals. The client authentication terminal 10 includes a matching determination processing unit 1034 that executes an authentication process for the device to be authenticated based on the authentication information of the device to be authenticated, and a communication I / F 100 that transmits authentication information via a network NW to at least one of the (N-1) other client authentication terminals among the N client authentication terminals that are not the device itself.

[0138] This allows the client authentication terminal 10 to share authentication information with other client authentication terminals and perform the authentication of the target being authenticated on the client authentication terminal. This avoids over-reliance on a single device and improves the efficiency of the authentication process for the target being authenticated.

[0139] Furthermore, the communication I / F 100 in this embodiment transmits authentication information to at least one of the (N-1) other client authentication terminals when authentication by the matching determination processing unit 1034 is successful. As a result, the client authentication terminal 10 can share authentication information with other client authentication terminals when the authentication of the device to be authenticated is successful. This avoids over-reliance on a single device and improves the efficiency of the authentication process for the device to be authenticated.

[0140] Furthermore, the matching determination processing unit 1034 of the client authentication terminal 10 according to this embodiment authenticates the target to be authenticated using the authentication information of the target to be authenticated obtained from at least one of the (N-1) other client authentication terminals via the communication I / F 100. As a result, the client authentication terminal 10 can execute the authentication process of the target to be authenticated that has been authenticated by the other client authentication terminals. The client authentication terminal 10 can efficiently execute the authentication process of the target to be authenticated in cooperation with the other client authentication terminals.

[0141] Furthermore, the client authentication terminal 10 according to this embodiment further includes a cooperation information database DBb that stores authentication information of the person to be authenticated and inter-client cooperation information between N client authentication terminals. The communication I / F 100 transmits the authentication information to at least one of the (N-1) other client authentication terminals based on the inter-client cooperation information stored in the cooperation information database DBb. As a result, the client authentication terminal 10 transmits the authentication information only to other client authentication terminals that the person to be authenticated is expected to visit next, thereby reducing the communication load.

[0142] Furthermore, the client authentication terminal 10 according to this embodiment further includes a linkage information management unit 1033 that manages inter-client linkage information, including expiration date information, and authentication information of the person being authenticated. The linkage information management unit 1033 deletes inter-client linkage information that has expired. This prevents the data capacity of the feature database DBa and the linkage information database DBb from increasing too much. In addition, the client authentication terminal 10 can improve the accuracy of authentication by deleting old authentication information of the person being authenticated.

[0143] Furthermore, the client-to-client communication information according to this embodiment includes at least one of the following: the destination for sending authentication information, environmental parameters, personal parameters, and location parameters. This allows the client authentication terminal 10 to efficiently share authentication information with other client authentication terminals based on each parameter of the client-to-client communication information.

[0144] Furthermore, the authentication information in this embodiment consists of extracted features extracted from the object to be authenticated or registered features that have been previously extracted and registered from the object to be authenticated. As a result, the client authentication terminal 10 can perform the authentication process of the object to be authenticated based on the extracted features or registered features.

[0145] Furthermore, the authentication system 1 according to this embodiment comprises a server authentication device 20 or a server authentication device 21 and N (N: a constant integer of 2 or more) client authentication terminals 10. The client authentication terminals 10 execute the authentication process for the object to be authenticated based on the authentication information of the object to be authenticated, and send and receive authentication information with the server authentication device 20, or with at least one of the (N-1) other client authentication terminals among the N client authentication terminals 10 that are not their own device. As a result, the authentication system 1 can perform the authentication of the object to be authenticated in cooperation with the server authentication device 20 and the N client authentication terminals 10. As a result, the authentication system 1 can efficiently perform the authentication of the object to be authenticated by sharing authentication information between the server authentication device 20 and the client authentication terminals 10. This avoids over-reliance on a single device and improves the efficiency of the authentication process for the object to be authenticated.

[0146] Furthermore, the server authentication device 20 or server authentication device 21 according to this embodiment uses the authentication information sent from the client authentication terminal 10 to perform the authentication process of the person to be authenticated. As a result, the authentication system 1 can perform authentication of the person to be authenticated using all the authentication information.

[0147] Furthermore, the client authentication terminal 10 in this embodiment transmits authentication information to at least one of the (N-1) other client authentication terminals 10 when at least one of the authentication processes for the target being authenticated by its own device or by the server authentication device 20 or server authentication device 21 is successful. As a result, the authentication system 1 can share authentication information with other client authentication terminals when the authentication of the target being authenticated is successful. This avoids over-reliance on a single device and improves the efficiency of the authentication process for the target being authenticated.

[0148] Furthermore, the server authentication device 20 or server authentication device 21 and the N client authentication terminals 10 in this embodiment have inter-client communication information between the server authentication device 20 or server authentication device 21 and the N client authentication terminals 10. As a result, the authentication system 1 can share authentication information between the server authentication device 20 or server authentication device 21 and the client authentication terminals based on the inter-client communication information.

[0149] Furthermore, the client-to-client communication information includes at least one of the following: the recipient of the authentication information, environmental parameters, personal parameters, and location parameters. This allows the authentication system 1 to efficiently share authentication information based on each parameter of the client-to-client communication information.

[0150] Furthermore, the server authentication device 20 or server authentication device 21, or the client authentication terminal 10, which has successfully performed the authentication process for the target to be authenticated according to the authentication system 1 of this embodiment, retains at least one of the extracted feature quantities extracted from the target to be authenticated or the registered feature quantities that have been previously extracted from the target to be authenticated and registered. As a result, the authentication system 1 can perform the authentication process for the target to be authenticated based on at least one of the extracted feature quantities or the registered feature quantities.

[0151] Furthermore, the client-to-client communication information according to this embodiment includes expiration date information for the client-to-client communication information. This allows the authentication system 1 to delete the client-to-client communication information based on the expiration date information.

[0152] Furthermore, the authentication system 1 according to this embodiment deletes expired client-to-client communication information between the server authentication device 20 or server authentication device 21 and the N client authentication terminals 10 based on expiration date information. This prevents the authentication system 1 from over-increasing the database capacity of the server authentication device 20, server authentication device 21, or client authentication terminals 10. In addition, the authentication system 1 can improve the accuracy of authentication by deleting old authentication information of the person being authenticated.

[0153] Furthermore, the server authentication device 20 or server authentication device 21 according to this embodiment and the N client authentication terminals 10 change the inter-client communication information based on predetermined conditions. This allows the authentication system 1 to change the inter-client communication information according to the conditions of the location where the client authentication terminals 10 are installed.

[0154] Furthermore, the server authentication device 20 or server authentication device 21 according to this embodiment and the N client authentication terminals 10 modify the inter-client communication information based on the personal information of the person being authenticated using the authentication system 1. As a result, the authentication system 1 can flexibly share authentication information by using the inter-client communication information that is presumed to be optimal according to the person being authenticated.

[0155] Furthermore, the conditions defining the client-to-client communication information in this embodiment belong to the entity being authenticated. This allows the authentication system 1 to flexibly share authentication information by using client-to-client communication information that is presumed to be optimal according to the characteristics of the entity being authenticated.

[0156] Furthermore, the authentication system 1 according to this embodiment sends and receives multiple types of authentication information used in multi-factor authentication to a server authentication device 20 or server authentication device 21 capable of performing multi-factor authentication, based on inter-client communication information. As a result, the authentication system 1 can perform authentication of the person to be authenticated with higher accuracy using the multi-factor authentication function.

[0157] While embodiments have been described above with reference to the attached drawings, this disclosure is not limited to such examples. It is clear to those skilled in the art that various modifications, alterations, substitutions, additions, deletions, and equivalents can be conceived within the scope of the claims, and these are also understood to fall within the technical scope of this disclosure. Furthermore, the components of the embodiments described above can be combined in any way without departing from the spirit of the invention. [Industrial applicability]

[0158] The technology disclosed herein is useful as an authentication device, authentication method, and authentication system that avoids the concentration of processing execution on a single device and improves the efficiency of the authentication process for the object being authenticated. [Explanation of Symbols]

[0159] 1. Authentication System 10 Client Authentication Terminals 20,21 Server Authentication Device 100, 200, 210 Communication I / F 101,211 Input Devices 102,201,212 memory 103,202,213 processors 104,214 Display section 1031,2021,2131 Feature Database Management Department 1032 Server Authentication Processing Unit 1033,2022,2132 Information Management Department 1034,2023,2133 Matching and determination processing unit 1035,2134 Feature extraction unit 1036,2135 Authentication status operation processing unit DBa, DBc, DBe Feature Database DBb, DBd, DBf Linked Information Database CLA Client Authentication Terminal 1 CLB Client Authentication Terminal 2 CLC Client Authentication Terminal 3 CLD Client Authentication Terminal 4 CLE Client Authentication Terminal 5 CLF Client Authentication Terminal 6 GR1, GR6 Group IF information NW Network hm,hm1 person

Claims

1. An authentication device belonging to an authentication system that includes N (N: a constant integer greater than or equal to 2) authentication devices, An authentication unit that performs the authentication process for the subject to be authenticated based on the authentication information of the subject to be authenticated, A storage unit that stores the authentication information of the object to be authenticated and the coordination information between the N authentication devices, The system includes a communication unit that transmits the authentication information to at least one of the (N-1) other authentication devices (excluding itself) from the N authentication devices, based on the cooperation information between the N authentication devices stored in the storage unit, via a network. Authentication device.

2. The communication unit transmits the authentication information to at least one of the (N-1) other authentication devices when the authentication by the authentication unit is successful. The authentication device according to claim 1.

3. The authentication unit authenticates the target to be authenticated using the authentication information of the target to be authenticated obtained from at least one of the (N-1) other authentication devices via the communication unit. The authentication device according to claim 1.

4. The system further comprises a management unit that manages the linked information, including expiration date information, and the authentication information of the subject to authentication, The management unit deletes the linked information whose expiration date has passed. The authentication device according to claim 1.

5. The aforementioned linked information includes at least one of the following: the recipient of the authentication information, environmental parameters, personal parameters, and location parameters. The authentication device according to claim 4.

6. The authentication information is either a feature extracted from the subject to be authenticated or a registered feature that has been previously extracted from the subject to be authenticated and registered. The authentication device according to any one of claims 1 to 5.

7. An authentication method performed by authentication devices belonging to an authentication system that includes N (N: a constant integer greater than or equal to 2) authentication devices, Based on the authentication information of the subject to be authenticated, the authentication process for the subject to be authenticated is executed. Based on the interoperability information between the N authentication devices stored in the storage unit of the authentication device, the authentication information is transmitted via the network to at least one of the (N-1) other authentication devices among the N authentication devices, excluding the device itself. Authentication method.

8. The system comprises a server device and N (N: a constant integer greater than or equal to 2) authentication devices. The authentication device is Based on the authentication information of the subject to be authenticated, the authentication process for the subject to be authenticated is executed. The authentication information is transmitted and received between the server device and at least one of the (N-1) other authentication devices among the N authentication devices, excluding the device itself. Authentication system.

9. The server device uses the authentication information sent from the authentication device to perform the authentication process of the object to be authenticated. The authentication system according to claim 8.

10. The authentication device transmits the authentication information to at least one of the (N-1) other authentication devices when at least one of the authentication process of the object to be authenticated by the device itself or the authentication process of the object to be authenticated by the server device is successful. The authentication system according to claim 8.

11. The server device and the N authentication devices have communication information between the server device and the N authentication devices. The authentication system according to claim 8.

12. The aforementioned linked information includes the recipient of the authentication information and at least one of the environmental parameters, personal parameters, and location parameters. The authentication system according to claim 11.

13. The server device or authentication device that has successfully performed the authentication process on the target to be authenticated retains at least one of the feature quantities extracted from the target to be authenticated or the registered feature quantities that have been previously extracted from the target to be authenticated and registered. The authentication system according to claim 11.

14. The aforementioned linked information includes the expiration date information of the linked information, The authentication system according to claim 11.

15. The server device and the N authentication devices delete the expired linkage information based on the expiration date information. The authentication system according to claim 14.

16. The server device and the N authentication devices modify the linked information based on predetermined conditions. The authentication system according to claim 11.

17. The server device and the N authentication devices modify the linked information based on the personal information of the person being authenticated using the authentication system. The authentication system according to claim 15.

18. The conditions defining the aforementioned linked information belong to the subject being authenticated. The authentication system according to claim 11.

19. The authentication device transmits and receives multiple types of authentication information used in the multi-factor authentication to the server device capable of performing multi-factor authentication, based on the linked information. The authentication system according to claim 11.

Citation Information

Patent Citations

  • Personal identification method and system therefor

    JP2006011650A

  • Personal identification apparatus and personal identification method

    JP2008021071A

  • Method and device for authenticating a person, and computer product

    US20080013795A1

  • Facial authentication system, terminal device, facial authentication method, and computer-readable recording medium

    WO2019244663A1