Information processing device, information processing system, information processing method, and program
The information processing device and system streamline face-to-face authentication by remotely verifying identities using an issuing, inquiry, and output unit, reducing labor and preventing impersonation through efficient biometric data management.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-10-20
- Publication Date
- 2026-04-01
AI Technical Summary
Existing face-to-face visitor authentication systems, such as those described in Patent Document 1, are time-consuming and require central processing units to manage facial image data, leading to inefficiencies and laborious authentication processes.
An information processing device and system that includes an issuing unit, inquiry unit, and output unit to transmit and verify access information and biometric data remotely, eliminating the need for manual authentication by querying pre-stored member data and providing real-time identity verification.
This solution reduces the hassle and labor associated with authenticating individuals, preventing impersonation and ensuring a secure service environment by remotely verifying identities using biometric data and attribute information.
Smart Images

Figure 0007838665000001 
Figure 0007838665000002 
Figure 0007838665000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing apparatus, an information processing system, an information processing method, and a non-temporary computer-readable medium storing a program.
Background Art
[0002] Various techniques have been proposed to prevent the impersonation of face-to-face visitors including visitors. For example, Patent Document 1 discloses an entrance and exit management system that performs an appropriate determination of a visitor who has come to a facility using both a previously assigned visitor identification code and the face photo data of the visitor. In Patent Document 1, when a face-to-face visitor transmits information of a visitor scheduled for a face-to-face meeting to a central processing unit at the time of registration of a face-to-face case, the management control unit of the central processing unit first determines a face-to-face case registration number for the face-to-face case and a visitor identification code (two-dimensional code) to be assigned to the visitor. Then, the management control unit transmits an e-mail to the visitor's mobile phone and sends out the two-dimensional code.
[0003] In addition, the management control unit sends a request for transmitting the face photo data of the visitor himself / herself in such an e-mail. When receiving the request for transmitting the face photo data from the central processing unit, the visitor takes a photo of his / her own face using a camera function provided in the mobile phone and transmits it to the central processing unit. When the central processing unit receives the face photo data, it creates a face-to-face case data file.
[0004] When the visitor comes, the visitor presents the two-dimensional code stored in his / her own mobile phone to a shooting camera. When it is determined based on the two-dimensional code that there is a corresponding face-to-face case data file, a face photo of the visitor is taken by the shooting camera, and it is collated and compared with the face photo data of the visitor pre-registered in the face-to-face case data file to determine whether the current visitor matches the visitor pre-registered in advance.
Prior Art Documents
Patent Documents
[0005] [Patent Document 1] Japanese Patent Publication No. 2011-48817 [Overview of the project] [Problems that the invention aims to solve]
[0006] In Patent Document 1, the visitor must register information about the visitor's case, which is time-consuming. Furthermore, the facial image data transmitted by the visitor must be managed by a central processing unit.
[0007] The purpose of this disclosure is to provide an information processing device, an information processing system, an information processing method, and a program that can eliminate the effort involved in authenticating face-to-face individuals, including visitors, in light of the aforementioned issues. [Means for solving the problem]
[0008] An information processing device according to one aspect of this disclosure includes an issuing unit, an inquiry unit, and an output unit. The issuing unit issues access information in response to a request from a requested user terminal and transmits it to at least one of the requested user terminal and a different requesting user terminal. When the inquiry unit receives access based on the access information from the requesting user terminal and receives the requested user's inquiry data, it queries the inquiry data against member data pre-stored in a predetermined storage device and receives the inquiry result. The output unit outputs the inquiry result to the requesting user terminal.
[0009] An information processing system according to one aspect of this disclosure includes an information processing device and a terminal of a person being inquired about, which is certified by the information processing device. The information processing device comprises an issuing unit, an inquiry unit, and an output unit. The issuing unit issues access information in response to a request from the terminal of a person being inquired about and transmits it to at least one of the terminal of a person being inquired about and a terminal of a person requesting an inquiry that is different from the terminal of a person being inquired about. When the inquiry unit receives access based on the access information from the inquiry requesting terminal and receives the inquiry data of the person being inquired about, it queries the inquiry data against member data stored in advance in a predetermined storage device and receives the query result. The output unit outputs the query result to the inquiry requesting terminal.
[0010] An information processing method relating to one aspect of this disclosure involves a computer performing the following processes. A process of issuing access information in response to a request from the requested terminal and transmitting it to at least one of the requested terminal and a requesting terminal that is different from the requested terminal. When access is received from the inquiry requester terminal based on the access information and inquiry data of the person being inquired about is received, the process involves querying the inquiry data against the member data stored in advance in a predetermined storage device and receiving the query result. A process for outputting the inquiry result to the inquiry requester's terminal.
[0011] A program relating to one aspect of this disclosure causes a computer to perform the following processes. A process of issuing access information in response to a request from the requested terminal and transmitting it to at least one of the requested terminal and a requesting terminal that is different from the requested terminal. When access is received from the inquiry requester terminal based on the access information and inquiry data of the person being inquired about is received, the process involves querying the inquiry data against the member data stored in advance in a predetermined storage device and receiving the query result. A process for outputting the inquiry result to the inquiry requester's terminal. [Effects of the Invention]
[0012] According to the present disclosure, the laboriousness associated with the authentication of the person facing can be eliminated.
Brief Description of the Drawings
[0013] [Figure 1] It is a block diagram showing the configuration of the information processing apparatus according to Embodiment 1. [Figure 2] It is a flowchart for explaining the flow of the information processing method according to Embodiment 1. [Figure 3] It is a block diagram showing the overall configuration of the information processing system according to Embodiment 2. [Figure 4] It is a block diagram showing the configuration of the entrance / exit management device in FIG. 3. [Figure 5] It is a block diagram showing the configuration of the queried person terminal in FIG. 3. [Figure 6] It is a block diagram showing the configuration of the query requester terminal in FIG. 3. [Figure 7] It is a sequence diagram showing the flow of the query processing of the queried person in the information processing system according to Embodiment 2. [Figure 8] It is a diagram showing an example of the screen displayed on the query requester terminal. [Figure 9] It is a block diagram showing the overall configuration of the information processing system according to Embodiment 3. s [Figure 10] It is a block diagram showing the configuration of the management device in FIG. 9. [[ID=3s7]] [Figure 11] It is a block diagram showing the overall configuration of the information processing system according to Embodiment 4.
Modes for Carrying Out the Invention
[0014] ] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In each drawing, the same or corresponding elements are denoted by the same reference numerals, and redundant descriptions are omitted as necessary for clarity of explanation.
[0015] In home delivery services, home visit services, etc., in order to prevent impersonation by visitors, a technology for proving whether the identification card presented by a visitor is correct is desired. On the other hand, organizations such as companies routinely confirm identities by using an entrance / exit management device or the like to authenticate the members who enter the facility. The embodiment relates to a technology for proving identity to a third party by using the authentication data of members owned by an organization.
[0016] Embodiment 1. FIG. 1 is a block diagram showing the configuration of an information processing apparatus 1 according to Embodiment 1. The information processing apparatus 1 is, for example, an apparatus that proves the identity of a member of an organization that provides home visit services, home delivery services, etc. to a customer (third party) when the member visits the customer. The members include not only employees of the organization but also service personnel who contract the services provided by the organization. Examples of the services provided by the members include delivery of products purchased by the customer, inspection of electricity, water, and fire extinguishers, door-to-door sales, house-to-house visits by police officers, and operation of taxis.
[0017] Each organization to which a member belongs manages member data regarding each member. In the following description, it is assumed that the information processing apparatus 1 proves the identity of a member by biometric authentication using the biometric information of the member. The member data includes authentication data (biometric information) of the member. As biometric information, data (feature amounts) based on unique physical characteristics of an individual such as face, fingerprint, voiceprint, vein, retina, and iris of the pupil can be used. Various techniques using a photographed image can be applied as biometric authentication using biometric information.
[0018] Further, the member data may include attribute data such as the name of the organization to which the member belongs, the location of the organization, the telephone number, the name, age, and gender of the member. The information processing apparatus 1 can specify the attribute data regarding the member according to the result of proving the identity of the member.
[0019] The person being verified as an individual within an organization is the "person being verified," and the customer is the "requesting party" who requests verification of the organization's identity. The "person being verified" is the person who interacts with the customer directly or indirectly, such as through a monitor. The terminal owned by the person being verified is referred to as the "person being verified," and the terminal owned by the requesting party is referred to as the "requesting party." In the following explanation, the person being verified before receiving verification will be referred to as the "person interacting with," and the person being verified after their identity has been verified will be referred to as the "organization member."
[0020] The information processing device 1 communicates with external devices via a network. The network can be wired or wireless, and the type of communication protocol is irrelevant. Specifically, the information processing device 1 is connected via the network to a requested party terminal and a requesting party terminal (not shown). The requested party terminal and the requesting party terminal may be mobile devices owned by employees and customers, respectively. These terminals may include, for example, mobile phones, portable PCs, tablet devices, or smartphones.
[0021] As shown in Figure 1, the information processing device 1 mainly includes an issuing unit 11, an inquiry unit 12, and an output unit 13. The issuing unit 11 issues access information in response to a request from the inquired terminal and transmits it to at least one of the inquired terminal and the inquiring terminal.
[0022] When access information is transmitted to the inquired party's terminal, the person on the other end displays the access information on their own terminal and presents it to the customer. The customer uses their own inquiry requesting terminal to read the access information displayed on the inquired party's terminal and accesses the information processing device 1 based on that access information. Furthermore, when access information is transmitted to the inquiry requesting terminal, the customer can access the information processing device 1 based on the received access information.
[0023] Furthermore, the customer uses the inquiry requester terminal to capture biometric information of the person they are meeting and supplies the captured image data to the information processing device 1 as inquiry data. For example, the face image of the person they are meeting can be obtained by photographing the person with a camera mounted on the inquiry requester terminal. The inquiry requester terminal can transmit this image data to the information processing device 1 via the network. The inquiry requester terminal can also supply facial feature information, extracted from the captured image data, to the information processing device 1 as inquiry data.
[0024] When the inquiry unit 12 receives access information from an inquiry requesting terminal different from the inquired terminal, and also receives the inquired terminal's inquiry data, it queries the inquiry data against the affiliation data pre-stored in a predetermined storage device and receives the inquiry result. The output unit 13 outputs the inquiry result to the inquiry requesting terminal. By outputting the inquiry result to the inquiry requesting terminal in this way, the information processing device 1 can verify the identity of the person the customer is meeting.
[0025] For example, the inquiry unit 12 performs facial recognition on the acquired facial image using the facial feature information of the member stored in the storage device. If the authentication is successful, the inquiry unit 12 can also identify the attribute data of the member related to the facial recognition. The identified attribute data may be included in the inquiry result sent to the inquiry requester terminal. If the inquiry result includes attribute data, an electronic business card with the facial image of the verified member may be displayed on the inquiry requester terminal.
[0026] Next, the processing performed by the information processing device 1 will be described with reference to Figure 2. Figure 2 is a flowchart showing the information processing method performed by the information processing device 1 according to Embodiment 1. First, the information processing device 1 issues access information in response to a request from the inquired terminal and transmits it to the inquired terminal (S11).
[0027] Next, when the information processing device 1 receives access based on access information from an inquiry requester terminal different from the inquired terminal, and also receives the inquired party's inquiry data, the inquiry data is stored in a predetermined storage device. Members The system queries the data and receives the query results (S12). The biometric information of the person being queried may be automatically generated by the query requester's terminal or generated in response to customer input. The query results are then output to the query requester's terminal (S13).
[0028] Thus, according to the information processing device 1 of Embodiment 1, the identity of the person being met can be verified remotely, eliminating the hassle associated with authenticating the person visiting the customer. Furthermore, the information processing device 1 can prevent fraud such as impersonation of an employee by the person visiting the customer to provide the service, thereby realizing a safe service provision environment.
[0029] The information processing device 1 includes a processor, memory, and storage device (not shown in the diagram). The storage device stores a program that causes the computer to execute each process of the information processing method according to Embodiment 1. The processor loads the program from the storage device into memory and executes the program. In this way, the processor realizes the functions of the issuing unit 11, the inquiry unit 12, and the output unit 13.
[0030] Each component of the information processing device 1 may be implemented with dedicated hardware. In addition, some or all of the components of each device may be general-purpose or exclusive These may be implemented by circuits, processors, etc., or combinations thereof. These may be composed of a single chip or multiple chips connected via a bus. Some or all of the components of each device may be implemented by a combination of the aforementioned circuits, etc., and programs. Furthermore, as processors, CPUs (Central Processing Units), GPUs (Graphics Processing Units), FPGAs (Field-Programmable Gate Arrays), quantum processors (quantum computer control chips), etc., can be used.
[0031] Furthermore, if some or all of the components of the information processing device 1 are implemented by multiple information processing devices or circuits, these multiple information processing devices or circuits may be centrally located or distributed. For example, the information processing devices or circuits may be implemented in a form in which each is connected via a communication network, such as a client-server system or a cloud computing system. Also, the functions of the information processing device 1 may be provided in SaaS (Software as a Service) format.
[0032] Embodiment 2. Embodiment 2 is a specific example of Embodiment 1 described above. Figure 3 is a block diagram showing the overall configuration of the information processing system 100 according to Embodiment 2. The information processing system 100 includes an access control device 10 and a terminal 20 of the person being inquired about, which is certified by the access control device 10, and performs identity verification of the person being inquired about based on a request from a terminal 30 of the person making the inquiry under predetermined conditions. The access control device 10, the terminal 20 of the person being inquired about, and the terminal 30 of the person making the inquiry are each connected via a network N. Here, the network N is a wired or wireless communication line, for example, the Internet.
[0033] The information processing system 100 is accessed from the inquiry requester's terminal 30, which is held by the inquiry requester (customer), based on access information issued in response to a request from the inquiry recipient's terminal 20, which is held by the inquiry recipient. When the system receives the inquiry recipient's inquiry data, it performs identity verification of the inquiry recipient. Here, we will explain an example of using a facial image, which is an example of biometric information, as inquiry data and performing facial recognition.
[0034] <Entrance / exit control device 10> The access control device 10 manages the entry and exit of members belonging to an organization to the facility, thereby managing the work status of members, including arrival at the office, going out, returning to the office, and leaving the office. The access control device 10 includes the functional configuration of the information processing device 1 described above. The access control device 10 performs information registration processing, inquiry processing to verify the identity of the person being inquired about (the person being met) (information processing method according to Embodiment 2), and processing to identify the attribute data of the member. The access control device 10 performs identity authentication using the image of the person being met and outputs the inquiry result to the inquiry requester terminal 30.
[0035] Figure 4 is a block diagram showing the configuration of the access control device 10 shown in Figure 3. The access control device 10 includes a camera 110, a storage unit 120, a memory 130, a control unit 140, and a communication unit 150. The access control device 10 may be composed of multiple servers, and each functional block may be implemented by multiple computers.
[0036] Camera 110 is a camera that is installed, for example, within the organization's facilities and takes pictures of members entering and leaving the building in accordance with the control unit 26. Storage unit 120 is an example of a storage device such as a hard disk or flash memory. Storage unit 120 stores a program and an information database 121. The program is a computer program that implements some of the processes such as registering and querying member facial images and attribute data. Information database 121 is a database that manages member data, including member authentication data and attribute data. Information database 121 can manage authentication data and attribute data by linking them to, for example, an identification number individually assigned to each member.
[0037] Memory 130 is a volatile storage device such as RAM (Random Access Memory), and is a storage area for temporarily holding information when the control unit 140 is operating. The communication unit 150 is a communication interface with the network N.
[0038] The control unit 140 is a processor that controls each component of the access control device 10. The control unit 140 loads a program from the storage unit 120 into the memory 130 and executes the program. In this way, the control unit 140 realizes the functions of the registration unit 141, the issuance unit 142, the inquiry unit 143, and the output unit 144.
[0039] The registration unit 141 registers the facial image of the member captured by the camera 110 as authentication data, and also processes the input attribute data to be linked with the authentication data and registered in the information DB 121. This data may also be transmitted from the inquired user terminal 20 held by the member, as described later. For example, in order to register the facial feature information of the member, the registration unit 141 extracts feature quantities from the facial region included in the image data and registers them in the information DB 121 as authentication data.
[0040] The issuing unit 142 issues access information in response to a request from the inquired terminal 20 and transmits it to the inquired terminal 20. The issuing unit 11 can generate code information that can be displayed as an image, such as a barcode or a two-dimensional code (QR code (registered trademark)), as access information and transmit it to the inquired terminal 20. The inquired party can present the received access information as an image to the inquirer's terminal 30.
[0041] The inquiry requester terminal 30 can access the access control device 10 by reading the access information displayed on the inquired-recipient terminal 20. The issuing unit 11 may also transmit the access information to the inquiry requester terminal 30. In this case, the inquiry requester terminal 30 can access the access control device 10 using the received access information. The inquiry requester terminal 30 also takes a picture of the face of the person it is facing and supplies the captured image data (or features extracted from the image data) to the access control device 10 as inquiry data.
[0042] Furthermore, it is preferable that certain conditions are pre-set for the access information. These conditions include conditions related to restricting access based on the access information from the inquiry requester terminal 30. Examples of conditions related to restricting access include the validity period and number of uses of the access information.
[0043] Furthermore, the predetermined condition may be that the location information of the inquired terminal 20 substantially matches the location information of the inquiry requesting terminal 30, or is within a predetermined range. Alternatively, the predetermined condition may be that the inquiry requesting terminal 30 accesses the access control device 10 while the access control device 10 is being accessed by the inquired terminal 20. The access control device 10 can receive access based on access information from the inquiry requesting terminal 30 when the predetermined condition is met.
[0044] When the inquiry unit 143 receives an access request from an inquiry requester terminal 30 that is different from the inquired terminal 20, based on access information, and also receives the inquired data of the inquired person, it queries the inquiry data against the affiliation data pre-stored in a predetermined storage device and receives the inquiry result. The output unit 144 sends the inquiry result back to the inquiring terminal 30.
[0045] Specifically, when the inquiry unit 143 receives an authentication request from the inquiry requester terminal 30, it extracts facial feature information from the facial image included in the authentication request. The inquiry unit 143 then compares the facial feature information extracted from the facial image included in the facial authentication request with the authentication data in the information DB 121 and calculates the degree of match. If the degree of match of the facial feature information is above a threshold, the inquiry unit 143 outputs an inquiry result indicating that facial authentication was successful. In this case, the inquiry unit 143 may also identify the attribute data of the person being inquired about and send the identified attribute data to the inquiry requester terminal 30. The inquiry unit 143 can output at least one of the inquiry result and the attribute data.
[0046] If the degree of matching of the facial feature information is below the threshold, the inquiry unit 143 generates an inquiry result indicating that facial recognition failed. The output unit 144 sends the inquiry result back to the inquiry requester terminal 30 via the network N.
[0047] Furthermore, when the access control device 10 transmits the inquiry result to the inquiry requester terminal 30, it may create a face-to-face record indicating that the employee met with the customer. This allows employees to perform their duties fairly and equitably in their corporate activities without violating social norms.
[0048] Furthermore, the control unit 140 may receive the identification number of the person being inquired about from the inquired terminal 20 and change the order in which the inquiry data is queried against the affiliation data according to the received identification number. For example, the affiliation data corresponding to the received identification number may be stored in a cache, and when an inquiry request is received from the inquiry requester terminal 30, the affiliation data stored in the cache may be used as a priority for matching with the inquiry data. This can shorten the time required for authenticating the person being inquired about. Note that the affiliation data stored in the cache may be deleted after a predetermined period of time has elapsed.
[0049] <Inquired person's terminal 20> The inquired person terminal 20 is an information terminal that is held and operated by the person being inquired about (the person being met), and which transmits and receives data with the access control device 10 via wireless communication over the network N. The inquired person terminal 20 is a mobile device such as a mobile phone, smartphone, or tablet. Figure 5 is a block diagram showing the configuration of the inquired person terminal 20 in Figure 3.
[0050] The inquired user terminal 20 includes a camera 21, a storage unit 22, a memory 23, a communication unit 24, an input / output unit 25, and a control unit 26. The camera 21 is an imaging device that takes pictures according to the control unit 26. The storage unit 22 is an example of a storage device that includes non-volatile memory such as flash memory or an SSD (Solid State Drive). The storage unit 22 stores a program that implements processes including processing to request access information from the access control device 10 and processing to display the acquired access information.
[0051] Memory 23 is a volatile storage device such as RAM (Random Access Memory), and is a storage area for temporarily holding information when the control unit 26 is operating. The communication unit 24 is a communication interface with the network N. The communication unit 24 may also establish a short-range wireless communication connection with the inquiry requester terminal 30 and perform communication. Here, various standards such as Bluetooth®, BLE (Bluetooth Low Energy), and UWB (Ultra Wide Band) can be applied to the short-range wireless communication.
[0052] The input / output unit 25 includes a display device and an input device, such as a touch panel. The control unit 26 is a processor that controls the hardware of the inquired user terminal 20. The control unit 26 loads a program from the storage unit 22 into the memory 23 and executes it. In this way, the control unit 26 realizes the functions of the access information request unit 261 and the display control unit 262.
[0053] The request unit 261 requests the access control device 10 to issue access information via the network N, based on the information entered by the person being inquired about. The issue unit 11 can generate access information in response to the request and send it to the person being inquired about terminal 20. The display control unit 262 displays the received access information on the input / output unit 25. As will be described in detail later, the requester terminal 30 can read the access information displayed on the input / output unit 25 and access the access control device 10 based on that access information.
[0054] As described above, the facial feature information of the person being accessed is pre-registered as authentication data in the information DB 121 of the access control device 10. The attribute data of the person being accessed is also pre-registered in the information DB 121. The authentication data and attribute data are included in the affiliation data. Note that an authentication device for facial recognition may be provided separately from the access control device 10. In this case, the authentication data is registered in the authentication device's DB, and the authentication data and attribute data may be linked by an ID issued at the time of registration. The display control unit 262 can display access information received from the access control device 10 via the network N.
[0055] <Inquiry Requester Terminal 30> The inquiry requester terminal 30 is an information terminal owned and operated by the customer making the inquiry, and which transmits and receives data with the access control device 10 via wireless communication over the network N. The inquiry requester terminal 30 is a mobile device such as a mobile phone, smartphone, or tablet. Alternatively, the inquiry requester terminal 30 may be an intercom or surveillance camera installed at the requester's home or other location. The inquiry requester terminal 30 reads the access information displayed on the inquired terminal 20 and attempts to access the access control device 10 based on that access information. The inquiry requester terminal 30 also takes a picture of the inquired person's face and sends an authentication request including the face image to the access control device 10. The inquiry requester terminal 30 receives and displays the inquired person's inquiry result.
[0056] Figure 6 is a block diagram showing the configuration of the inquiry requester terminal 30 in Figure 3. As shown in Figure 6, the inquiry requester terminal 30 includes a camera 31, a storage unit 32, a memory 33, a communication unit 34, an input / output unit 35, and a control unit 36. This example shows a configuration in which the imaging device and the display terminal are integrated.
[0057] Camera 31 is an imaging device that takes pictures in accordance with the control of the control unit 36. The storage unit 32 is an example of a storage device that includes non-volatile memory such as flash memory or SSD (Solid State Drive). The storage unit 32 stores a program in which various processes, including the authentication request processing of the person being inquired about, which will be described later, are implemented.
[0058] Memory 33 is a volatile storage device such as RAM (Random Access Memory), and is a storage area for temporarily holding information when the control unit 36 is operating. Communication unit 34 is a communication interface with network N. Input / Output unit 35 includes a display device (display terminal) such as a screen and an input device, such as a touch panel.
[0059] The control unit 36 is a processor that controls the hardware of the inquiry requester terminal 30. The control unit 36 loads a program from the storage unit 32 into the memory 33 and executes it. In this way, the control unit 36 realizes the functions of the display control unit 361 and the authentication request unit 362.
[0060] The display control unit 361 displays the query results generated by the execution of the program on the input / output unit 35. The display control unit 361 may also display a message on the input / output unit 35 prompting the user to take a picture of the person being queried for facial recognition.
[0061] The authentication request unit 362 extracts the facial region from the image of the person being inquired about, captured by the camera 31, and sends an authentication request including the facial image to the access control device 10. Alternatively, the authentication request unit 362 may also send facial feature information, obtained by extracting feature quantities from the facial image, to the access control device 10. The access control device 10 then sends the inquiry result of the person being inquired about to the inquiry requester terminal 30. If authentication is successful, the display control unit 361 displays the inquiry result, which proves the identity of the person being inquired about, on the input / output unit 35. The inquiry requester can confirm the legitimacy of the person being inquired about by checking the display on the screen.
[0062] Thus, according to the information processing system 100, the access control device 10 installed in the organization to which the person belongs can be used to verify the identity of the person being inquired about in response to a request from the person making the inquiry, thereby eliminating the hassle associated with authenticating the person in person.
[0063] Figure 7 is a sequence diagram showing the flow of the inquiry process for the person being inquired about. First, the inquired person's terminal 20, which is authorized to access the access control device 10, requests the access control device 10 to issue access information (S20). The access control device 10 issues access information (S21) and transmits it to the inquired person's terminal 20. The inquired person can then display the access information on their terminal 20 (S22) and present it to the person making the inquiry. Alternatively, the access control device 10 may directly transmit the access information to the inquiry requester's terminal.
[0064] Then, the inquiry requester terminal 30 reads the access information displayed on the screen of the inquired party terminal 20 (S23). The inquiry requester terminal 30 may read the access information presented by the person it is directly facing, or it may read the access information presented through a monitor such as an intercom. If the inquiry requester terminal 30 is an intercom, it is also possible to read the access information presented by the person facing it using the intercom's camera.
[0065] Furthermore, the access control device 10 can also verify the identity of the caller when conducting video conferences, etc., by verifying their identity through a monitor. In this case, the inquiry requester terminal 30 can read the caller's access information displayed on the monitor. In addition, the terminal itself running the application program for conducting video conferences can access the access control device 10 based on the access information and acquire the caller's facial image.
[0066] Once the access information has been read, the inquiry requester terminal 30 accesses the access control device 10 based on the access information (S24). At this time, a message prompting the person being inquired about to be photographed may be displayed on the screen of the inquiry requester terminal 30. Subsequently, the inquiry requester terminal 30 uses the camera 31 to take a picture of the person being inquired about's face (S25). Then, the inquiry requester terminal 30 sends a face recognition request including the face image to the access control device 10 (S26). When the access control device 10 inquiry unit 143 receives the face recognition request, it performs the inquiry process (S27).
[0067] Specifically, the inquiry unit 143 extracts facial feature information from the facial image included in the facial recognition request, compares it with the authentication data in the information DB 121, and calculates the degree of match. When the inquiry requester terminal 30 transmits feature quantities (facial feature information) extracted from the facial image, the inquiry unit 143 compares the facial feature information with the authentication data. If the facial feature information matches, that is, if the degree of match of the facial feature information is above a threshold, the inquiry unit 143 sends a query result indicating that facial recognition was successful back to the inquiry requester terminal 30 via the network N (S28). In this case, the inquiry unit 143 may identify attribute data associated with the facial feature information and include the identified attribute data in the query result. Subsequently, the inquiry requester terminal 30 displays the received query result (S29).
[0068] If facial recognition fails, the access control device 10 can send an inquiry result indicating the authentication failure to the inquiry requester terminal 30. The inquiry requester terminal 30 displays on its screen that facial recognition has failed. The inquiry requester terminal 30 may also notify the inquired user terminal 20 of the facial recognition failure via short-range wireless communication or the like.
[0069] Thus, according to Embodiment 1, it is possible to verify the identity of the employee to the customer, providing the customer with a sense of security when receiving services. Furthermore, it is possible to prevent crimes such as fraud by impersonating an employee. In addition, face-to-face verification ensures transparency in corporate activities and strengthens compliance.
[0070] Furthermore, since the access control device 10 allows for centralized management of the biometric information (authentication data) of affiliated members, there is no need to perform complicated procedures or operations. In addition, when verifying the identity of affiliated members, access information is issued by the member's terminal 20 and authentication requests are made by the customer's terminal 30, thus preventing fraud.
[0071] The inquiry requester terminal 30 may display an electronic business card using attribute data output in response to successful biometric authentication. Figure 8 shows an example of a screen displayed on the inquiry requester terminal 30. The screen includes an image 2 related to the facial recognition of the person being inquired about, a display of the facial recognition result 3, and an information display 4.
[0072] The screen shown in Figure 8 is obtained when the owner of the inquiry requester terminal 30 makes an inquiry request to the person being inquired about based on the access information presented by the person being inquired about who has visited their home, and when facial recognition of the person being inquired about is successful. Information display 4 shows attribute data including the name of the person being inquired about. Note that the attribute data shown in Figure 8 is an example, and other information may be displayed in addition to or instead of the information shown here. The inquiry requester can refer to this information displayed on the inquiry requester terminal 30 and confidently accept the person being inquired about into their home.
[0073] Embodiment 3. Embodiment 3 is a modification of Embodiment 2 described above. Figure 9 is a block diagram showing the overall configuration of the information processing system 100A according to Embodiment 3. The information processing system 100A includes an access control device 10 and a terminal 20 of the person being inquired about, which has been certified by the access control device 10, and performs identity verification of the person being inquired about based on a request from an inquiry requester terminal 30 under predetermined conditions.
[0074] Furthermore, as a difference from Embodiment 2, in Embodiment 3, the management device 40 provides a cloud service that verifies the validity of access information issued by the access control device 10, and functions as an authentication infrastructure. In other words, the management device 40 becomes a trusted third party (TTP). The access control device 10, the inquired user terminal 20, the inquiry requester terminal 30, and the management device 40 are all connected via network N. The differences from Embodiment 2 will be explained below.
[0075] The management device 40 is, for example, a cloud server and an authentication infrastructure equipped with an authentication function to prove the validity of access information. In other words, the management device 40 proves whether the access information presented by the member was issued by a trusted access control device 10.
[0076] Figure 10 is a block diagram showing the functional configuration of the management device 40. As shown in Figure 10, the access control device 10 includes a reception unit 41, a response unit 42, and a storage unit 43. The storage unit 43 stores information related to the access control device 10 as authentication information. This information may include the company ID of the organization that has installed the access control device 10, access information issued to the inquired user terminal 20 that can access the access control device 10, and credit information obtained by the organization that has installed the access control device 10 through a prior screening process.
[0077] The reception unit 41 receives access information issued by the access control device 10 when the access control device 10 receives an access information issuance request from the inquired user terminal 20. In addition to or instead of receiving access information from the access control device 10, the reception unit 41 may also receive an inquiry request for access information when the inquiry requester terminal 30 accesses the access control device 10 based on the access information. The access information and inquiry request may include location information, time information, etc., of the inquired user terminal 20 and the inquiry requester terminal 30.
[0078] The response unit 42 queries the storage unit 43 for the received access information, determines whether the access information is valid, and returns the determination result to the inquiry requester terminal 30. For example, the access information may include a company ID indicating the organization that has installed the access control device 10. The response unit 42 can determine whether the company ID included in the access information matches a company ID stored in the storage unit 43. Alternatively, the response unit 42 may audit the URL represented by the two-dimensional code as access information.
[0079] Furthermore, the response unit 42 can also determine the validity of access information in response to an access information inquiry request from the inquiry requester terminal 30, and return the determination result to the inquiry requester terminal 30. This allows customers to access the access control device 10 with peace of mind, based on reliable access information.
[0080] Furthermore, the response unit 42 may determine that the access information is valid if, in addition to the access information, the location information and time information of the inquired terminal 20 and the inquiry requester terminal 30 match. This prevents the identification of the inquired person based on fraudulent access information.
[0081] Embodiment 4. Embodiment 4 is a further modification of Embodiment 2 described above. Figure 11 is a block diagram showing the overall configuration of the information processing system 100B according to Embodiment 4. The information processing system 100B includes an access control device 10 and a user terminal 20 certified by the access control device 10, and performs identity verification of the user based on a request from an access control device 50 different from the access control device 10 under predetermined conditions. The access control device 10, the user terminal 20, and the access control device 50 are each connected via a network N.
[0082] Here, the access control device 10 is a system that manages the entry and exit of employees belonging to company A to company A's facilities. The access control device 50 is a system that manages the entry and exit of employees belonging to company B, which is different from company A, to company B's facilities. The access control device 50 may include a configuration similar to the inquiry requester terminal 30 shown in Figure 6. For example, the access control device 50 may include a camera and monitor installed at the entrance of company B, a control unit that transmits the authentication request of the person being inquired about to the access control device 10, etc.
[0083] The access control device 50 can access the access control device 10 based on access information provided by an employee of Company A (the person being accessed) visiting Company B, using a camera installed at the entrance of Company B. The access control device 50 can also capture a photograph of the person being accessed using the camera installed at the entrance of Company B, generate a facial image, and send the facial image along with an authentication request to the access control device 10.
[0084] The verification results for employees of company A are transmitted from the access control device 10 to the access control device 50. If authentication is successful, the verification results, which prove the identity of the person being verified, can be displayed on a monitor installed at the entrance of company B, for example. This allows company B's access control device 50 to permit the visiting employee of company A to enter company B.
[0085] Furthermore, the access control device 50 may include substantially the same functional configuration as the access control device 10 described above. That is, both the access control device 10 and the access control device 50 may include the mechanical configuration of the information processing device 1. This makes it possible for an employee of company B to verify the identity of an employee of company B when they visit company A, using the employee data managed by company B's access control device 50. In other words, in this case, it becomes possible to verify the identity of visitors by mutually utilizing the employee data of company A and company B.
[0086] Furthermore, the information processing system 100B according to Embodiment 3 may be used as a system to verify the employment status of a person to whom an inquiry is made when company B is a financial institution and the person being inquired about is undergoing a loan application process at that financial institution. In addition, the information processing system 100B may also be used to verify the identity of bidders in public tenders by government agencies and other government organizations. That is, the inquiry results issued by the access control device 10 may be used as an official certificate of employment.
[0087] The program that performs the above-described processing includes, when loaded into a computer, a set of instructions (or software code) for causing the computer to perform one or more of the functions described in the embodiments. The program may be stored in a non-temporary computer-readable medium or a physical storage medium. Examples, but not limited to, include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray® disc or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices. The program may be transmitted over a temporary computer-readable medium or a communication medium. Examples, but not limited to, include electrical, optical, acoustic or other forms of propagating signals.
[0088] This disclosure is not limited to the embodiments described above, and may be modified as appropriate without departing from its spirit. Furthermore, this disclosure may be implemented by combining the respective embodiments as appropriate.
[0089] The above explanation states that by performing biometric authentication, you can join person While identity verification was performed in this example, it is not limited to this case. For example, when registering attribute data of an employee, the server managing the attribute data may issue an authentication ID and password associated with that attribute data. In this case, the customer can also verify their identity by entering the employee's ID and password. Furthermore, the information processing device of this embodiment can be integrated into an intercom or surveillance camera installed in a home.
[0090] Some or all of the above embodiments may also be described as follows, but are not limited to the following: (Note A1) An issuing unit that issues access information in response to a request from the inquired user's terminal and transmits it to the inquired user's terminal, When an inquiry requester terminal different from the inquired terminal receives access based on the access information and receives the inquired data of the inquired party, the inquiry unit queries the inquired data against the member data pre-stored in a predetermined storage device and receives the query result. An output unit that outputs the inquiry result to the inquiry requester terminal, An information processing device equipped with the following features. (Appendix A2) The aforementioned access information has predetermined conditions set in advance. The inquiry unit receives access based on the access information from the inquiry requester terminal when the predetermined conditions are met. The information processing device described in Appendix A1. (Note A3) The aforementioned predetermined conditions include conditions relating to restrictions on access based on the access information from the inquiry requester's terminal. The information processing device described in Appendix A2. (Note A4) The affiliation data is linked to attribute data about the affiliation. The output unit outputs at least one of the query result and the attribute data of the person being queried, if the query for the query data is successful. The information processing device described in Appendix A1. (Note A5) The aforementioned storage device manages the member data by associating it with an identification number. The system further includes a modification unit that receives the identification number of the person being inquired from the terminal and changes the order in which the inquiry data is queryed against the member data according to the received identification number. The information processing device described in Appendix A1. (Note A6) The issuing unit provides the access information to the inquiry requester's terminal so that the inquiry requester can present the access information as image data to the inquiry requester's terminal. The information processing device described in Appendix A1. (Note A7) The aforementioned inquiry data includes biometric information obtained by the inquiry requester's terminal from the person being inquired about. The information processing device described in Appendix A1.
[0091] (Note B1) The information processing device includes an information processing device and a terminal of the person being inquired about, which is certified by the information processing device. The aforementioned information processing device is An issuing unit that issues access information in response to a request from the inquired user's terminal and transmits it to the inquired user's terminal, When an inquiry requester terminal different from the inquired terminal receives access based on the access information and receives the inquired data of the inquired party, the inquiry unit queries the inquired data against the member data pre-stored in a predetermined storage device and receives the query result. An output unit that outputs the inquiry result to the inquiry requester terminal, Equipped with, Information processing system.
[0092] (Note C1) Computers The process involves issuing access information in response to a request from the inquired user's terminal and transmitting it to the inquired user's terminal, When access is received from a requesting terminal different from the requested terminal, based on the access information, and the requested data is received, the requesting data is queryed against the member data pre-stored in a predetermined storage device, and the query result is received. A process to output the inquiry result to the inquiry requester terminal, An information processing method that performs [this action].
[0093] (Note D1) The process involves issuing access information in response to a request from the inquired user's terminal and transmitting it to the inquired user's terminal, When access is received from a requesting terminal different from the requested terminal, based on the access information, and the requested data is received, the requesting data is queryed against the member data pre-stored in a predetermined storage device, and the query result is received. A process to output the inquiry result to the inquiry requester terminal, Make the computer execute it. A non-temporary, computer-readable medium on which a program is stored.
[0094] (Note E1) The system includes an information processing device, a terminal of a person being inquired about which has been certified by the information processing device, and a terminal of a person requesting an inquiry which is different from the terminal of the person being inquired about, The aforementioned information processing device is An issuing unit that issues access information in response to a request from the inquired user's terminal and transmits it to the inquired user's terminal, When the inquiry requester terminal receives access based on the access information and the inquiry data of the person being inquired about, the inquiry unit queries the inquiry data against the member data stored in advance in a predetermined storage device and receives the inquiry result. An output unit that outputs the inquiry result to the inquiry requester terminal, Equipped with, Information processing system. [Explanation of symbols]
[0095] 1. Information Processing Device 10 Entrance / exit control device 11 Publishing Department 12. Inquiry Department 13 Output section 14 Storage device 20. Inquired person's terminal 21 Cameras 22 Memory section 23 memory 24 Communications Department 25 Input / output section 26 Control Unit 261 Request part 262 Display Control Unit 30 Inquiry Requester Terminal 31 Camera 32 Storage section 33 memory 34 Communications Department 35 Input / output section 36 Control Unit 361 Display Control Unit 362 Authentication Request Section 40 Management device 41 Reception Department 42 Response section 43 Storage section 50 Entrance / exit control device 100 Information Processing Systems 110 Camera 120 Storage section 121 Information DB 130 memory 140 Control Unit 141 Registration Department 142 Publishing Department 143 Inquiry Department Output section of 144 150 Communications Department N Network
Claims
1. When the person being inquired meets with the person making the inquiry, an issuing unit issues access information in response to a request from the terminal held by the person being inquired and transmits it to at least one of the terminals held by the person being inquired and a terminal held by the person making the inquiry, which is different from the terminal held by the person being inquired. When the inquiry requester terminal receives access based on the access information and the inquiry data of the person being inquired about, the inquiry unit queries the inquiry data against the affiliation data pre-stored in a predetermined storage device managed by the organization to which the person being inquired belongs, and receives the query result. An output unit that outputs the inquiry result to the inquiry requester terminal, An information processing device equipped with the following features.
2. The inquiry unit is, When the access information is transmitted to the inquired terminal, the requesting terminal reads the access information displayed on the inquired terminal and receives access based on the access information. When the access information is transmitted to the requesting terminal, the requesting terminal receives access based on the received access information. The information processing apparatus according to claim 1.
3. The aforementioned access information has predetermined conditions set in advance. The inquiry unit receives access based on the access information from the inquiry requester terminal when the predetermined conditions are met. The information processing apparatus according to claim 1.
4. The aforementioned predetermined conditions include conditions relating to restrictions on access based on the access information from the inquiry requester's terminal. The information processing apparatus according to claim 3.
5. The affiliation data is linked to attribute data about the affiliation. The output unit outputs at least one of the query result and the attribute data of the person being queried, if the query for the query data is successful. The information processing apparatus according to claim 1.
6. The aforementioned storage device manages the member data by associating it with an identification number. The system further includes a modification unit that receives the identification number of the person being inquired from the terminal of the person being inquired, stores the affiliation data corresponding to the received identification number in a cache, and, when querying the inquiry data against the affiliation data, prioritizes matching the inquiry data with the affiliation data stored in the cache. The information processing apparatus according to claim 1.
7. The issuing unit provides the access information to the inquiry requester's terminal so that the inquiry requester can present the access information as image data to the inquiry requester's terminal. The information processing apparatus according to claim 1.
8. The aforementioned inquiry data includes biometric information obtained by the inquiry requester's terminal from the person being inquired about. The information processing apparatus according to claim 1.
9. The information processing device includes an information processing device and a terminal of the person being inquired about, which is certified by the information processing device. The aforementioned information processing device is An issuing unit that, when the person being inquired meets with the person making the inquiry, issues access information in response to a request from the terminal held by the person being inquired and transmits it to at least one of the terminals held by the person being inquired and a terminal held by the person making the inquiry, which is different from the terminal held by the person being inquired. When the inquiry requester terminal receives access based on the access information and the inquiry data of the person being inquired about, the inquiry unit queries the inquiry data against the affiliation data pre-stored in a predetermined storage device managed by the organization to which the person being inquired belongs, and receives the query result. An output unit that outputs the inquiry result to the inquiry requester terminal, Equipped with, Information processing system.
10. Computers When the person being inquired about meets with the person making the inquiry, the process involves issuing access information in response to a request from the terminal held by the person being inquired about, and transmitting it to at least one of the terminals held by the person being inquired about and a terminal held by the person making the inquiry, which is different from the terminal held by the person being inquired about. When access is received from the inquiry requester terminal based on the access information and the inquiry data of the person being inquired about is received, the inquiry data is queryed against the member data pre-stored in a predetermined storage device managed by the organization to which the person being inquired about belongs, and the query result is received. A process to output the inquiry result to the inquiry requester terminal, An information processing method that performs [this action].
11. When the person being inquired meets with the person making the inquiry, the process of issuing access information in response to a request from the terminal held by the person being inquired and transmitting it to at least one of the terminals held by the person being inquired and a terminal held by the person making the inquiry, which is different from the terminal held by the person being inquired; When access is received from the inquiry requester terminal based on the access information and the inquiry data of the person being inquired about is received, the inquiry data is queryed against the member data pre-stored in a predetermined storage device managed by the organization to which the person being inquired about belongs, and the query result is received. A process to output the inquiry result to the inquiry requester terminal, Make the computer execute it. program.
Citation Information
Patent Citations
Entrance / exit management system
JP2011048817A
Facility admission / exit management system
JP2014006763A
Visitor management system and visitor management method
JP2022135182A