Authentication device, authentication method, and authentication program

The authentication device addresses the inefficiencies of existing systems by using a divided screen to determine attendance processing based on user position, reducing costs and enhancing convenience in workplaces with flexible schedules.

JP7845013B2Active Publication Date: 2026-04-14TOPPAN HOLDINGS INC
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-04-15
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing authentication systems face challenges in efficiently managing attendance in workplaces with varying shifts and flexible working hours, leading to increased costs and effort due to the need for multiple terminals, button operations, and difficulty in distinguishing arrival and departure times.

Method used

An authentication device that captures a user's image and displays it on a divided screen, determining subsequent processing based on the user's position, allowing for intuitive clock-in or clock-out operations without additional hardware or buttons.

Benefits of technology

Enables efficient attendance management with reduced implementation costs and improved user convenience by using a single terminal to differentiate between arrival and departure without requiring additional hardware or button presses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007845013000001
    Figure 0007845013000001
  • Figure 0007845013000002
    Figure 0007845013000002
  • Figure 0007845013000003
    Figure 0007845013000003
Patent Text Reader

Abstract

To provide an authentication device, authentication method, and an authentication program, which enables effective use of authentication processing while minimizing labor and costs required for introduction.SOLUTION: An authentication device 100 disclosed herein has a control unit 130 comprising an image capturing unit 132 for capturing an image of an authentication target user, a display control unit 133 for displaying an image of the user captured by the image capturing unit 132 on a display unit, and a determination unit 135 configured to determine content of subsequent processing to be executed when the user is authenticated according to a position or range of the user displayed on the display unit 140.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , , , , , ,

[0006] , , , ,

[0005] , , , , ,

[0001] The present disclosure relates to an authentication apparatus, an authentication method, and an authentication program that execute a process for authenticating an individual's identity.

Background Art

[0002] As a means for performing identity verification, an authentication means that uses the feature information of the person reflected in the image is known. In such authentication, biometric information such as a face image or a fingerprint is used as information for proving the uniqueness of the person. For example, in face authentication processing, a face image of a user is registered in advance, and identity verification is performed by comparing the face image acquired at the time of authentication with the registered image.

[0003] As an example of a technique for improving face authentication processing, for example, a technique for improving accuracy by using a plurality of face authentication engines is known.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] According to the prior art, the authentication process can be realized with high accuracy. On the other hand, there are also problems that are difficult to solve only by improving the accuracy of the authentication process.

[0006] For example, when operating a system that manages attendance by authenticating individuals at the workplace entrance, improving authentication accuracy can prevent authentication errors and enable faster authentication processing. However, in workplaces such as factories that operate 24 hours a day, the different shifts make it difficult to effectively utilize an authentication-based attendance system, as it may be impossible to distinguish who is arriving and who is leaving. Measures such as having each person select their attendance or departure time using buttons in conjunction with the authentication process, or providing separate authentication terminals for attendance and departure, can be considered, but these measures are time-consuming and costly.

[0007] Therefore, this disclosure proposes an authentication device, an authentication method, and an authentication program that can effectively utilize authentication processing while minimizing the effort and cost involved in implementation. [Means for solving the problem]

[0008] To solve the above problems, one form of authentication device according to this disclosure comprises: an imaging unit that captures an image of a user to be authenticated; a display control unit that displays the user captured by the imaging unit on a display unit; and a determination unit that determines the content of subsequent processing to be performed when the user is authenticated, according to the position or range in which the user is displayed on the display unit. [Effects of the Invention]

[0009] According to one embodiment of the system, authentication processing can be effectively utilized while reducing the effort and cost involved in implementation. [Brief explanation of the drawing]

[0010] [Figure 1] This figure shows an overview of the authentication process according to the embodiment. [Figure 2] This figure shows an example configuration of an authentication device according to the embodiment. [Figure 3] This figure shows an example of an authentication information storage unit according to the embodiment. [Figure 4]This figure shows an example of a region storage unit according to the embodiment. [Figure 5] This figure shows an example of an authentication log storage unit according to the embodiment. [Figure 6] This is a flowchart showing the procedure for the authentication process according to the embodiment. [Figure 7] This diagram shows an overview of the authentication process related to modifications. [Figure 8] This figure shows an example of a modified region memory unit. [Figure 9] This is a hardware configuration diagram showing an example of a computer that implements the functions of an authentication device. [Modes for carrying out the invention]

[0011] Embodiments of the present disclosure will be described in detail below with reference to the drawings. In the following embodiments, the same parts will be denoted by the same reference numerals to avoid redundant descriptions.

[0012] (1. Embodiments) (1-1. Overview of the authentication process according to the embodiment) Figure 1 is a diagram illustrating an overview of the authentication process according to the embodiment. The authentication process according to the embodiment is performed by the authentication device 100 shown in Figure 1.

[0013] The authentication device 100 is an information processing device that performs the authentication process according to the embodiment. For example, the authentication device 100 detects (senses) the user 10 to be authenticated and acquires authentication information, which is information used for authentication. As an example, the authentication device 100 uses a facial image obtained by capturing the user 10 using a camera 150 as authentication information. Figure 1 shows an example where the authentication device 100 is a tablet terminal installed at the entrance of the workplace where the user 10 works.

[0014] In this embodiment, user 10's attendance management is performed by authentication processing by the authentication device 100. That is, user 10, upon arriving at the workplace, stands in front of the authentication device 100 installed at the entrance. The authentication device 100 detects user 10's face using a known face detection process and captures an image of the detected face. The authentication device 100 then compares the acquired face image with pre-registered correct data (for example, feature quantities generated from user 10's face image), and if the feature quantities match above a predetermined value, it authenticates that the captured user 10 is indeed user 10. Once user 10 is authenticated, the authentication device 100 determines that user 10 has arrived at or left work, and stores the arrival or departure time and the time as an attendance record. Attendance management using this type of authentication eliminates the hassle of punching a time card as in the past, and prevents third parties from fraudulently recording attendance on behalf of the user by requiring user authentication. Therefore, it is actively introduced in workplaces with many people coming and going, such as factories.

[0015] On the other hand, there are several challenges in effectively utilizing such attendance management systems. For example, when linking authentication processing with attendance management as described above, it is necessary to associate the time of authentication with the type of time stamp (such as clocking in or clocking out). Several methods can be considered for this association. One example is to display "clock in" or "clock out" buttons on the authentication terminal, and the terminal would determine whether the user has "clocked in" or "clocked out" by pressing the button before or after authentication. However, this method has problems such as time loss due to button pressing, unhygienic conditions due to each person touching the terminal, and the need to introduce terminals with touch panels or physical buttons.

[0016] Alternatively, as another example, there may be means such as setting the "clock-in" and "clock-out" times on the authentication terminal, and automatically determining, for example, that a user authenticated in the morning is "clocked in" and a user authenticated in the evening is "clocked out". However, such means are difficult to apply to users with flexible working hours or workplaces that adopt shift work with multiple personnel changes during the day. Also, instead of time setting, it is possible to identify each user and associate the first authentication time with "clock-in" and the next authentication time with "clock-out", but such means require prior setting according to the shift of each user, which is laborious to manage. Also, such means cannot handle sudden shift changes, etc. As another means, it is also conceivable to select the clock-in type by performing a predetermined operation (such as a peace sign) in addition to authentication, but there are problems such as users who do not know the operation cannot use it, some users are resistant to performing the operation, and the operation has individual differences and thus cannot be recognized. Thus, in a management system or the like that utilizes authentication processing, there are needs and issues to realize appropriate operations suitable for the workplace of introduction while suppressing the labor and costs involved in the introduction.

[0017] Therefore, the authentication device 100 solves the above problems by the authentication process according to the embodiment. That is, the authentication device 100 captures an image of the user 10 to be authenticated and displays it on the screen, and determines the content of the subsequent process to be executed when the user 10 is authenticated according to the position or range where the user 10 is displayed. Specifically, the authentication device 100 branches the subsequent process based on where the coordinates of the face are on the screen during face authentication using a face authentication terminal with a screen. More specifically, when the authentication device 100 executes the authentication process of the user 10 on the left side facing the screen, it determines that the user 10 is "clocked in". Also, when the authentication device 100 executes the authentication process of the user 10 on the right side facing the screen, it determines that the user 10 is "clocked out". Thus, the authentication device 100 can improve the convenience of the operation of the system such as clock-in and clock-out without taking much labor or cost by varying the subsequent process based on the screen area where the authentication target (in the example of FIG. 1, the face of the user 10) is located.

[0018] The above process will be described with reference to FIG. 1. In the example shown in FIG. 1, a user 10 who intends to record arrival or departure stands in front of an authentication device 100 and causes the authentication device 100 to execute an authentication process.

[0019] At this time, as shown in FIG. 1, an authentication screen with a pre-divided display area is displayed on a display unit 140 which is a display of the authentication device 100. Specifically, the display unit 140 displays an authentication screen divided into a first area 160 and a second area 165. For example, the first area 160 contains the characters "Arrival" and the second area 165 contains the characters "Departure". The display unit 140 clearly displays on the authentication screen a line that separates the first area 160 and the second area 165 and the characters contained in each so that the user 10 can recognize the areas and characters.

[0020] When the authentication device 100 detects the face of the user 10, it displays a detection mark 170 on the display unit 140. At this time, when the user 10 desires to record arrival, while visually recognizing his or her own face reflected on the display unit 140, the user 10 moves the face closer to the first area 160 side. As a result, the detection mark 170 moves to the first area 160 side.

[0021] When the user 10 stops moving the face, the authentication device 100 performs an authentication process on the detected face image. Specifically, the authentication device 100 compares the detected face image of the user 10 with the correct data of the user 10 registered in advance to verify whether the detected person is the user 10 himself or herself. Note that the authentication device 100 may wait for a predetermined time (for example, 1 second) to elapse after the user 10 stops moving the face and then perform the authentication process in order to determine in which area the user 10 stops the face. As a result of the verification, if it is confirmed that the user is the user 10 himself or herself, the authentication device 100 authenticates the identity of the user 10.

[0022] At this time, the authentication device 100 displays an authentication result 180 on the display unit 140, indicating that authentication was successful. The authentication result 180 also includes information on subsequent processing after authentication, such as whether the user registered as an arrival or departure (in the example in Figure 1, the correspondence between the authentication time and the time stamp type, such as arrival or departure). This allows the user 10 to understand on the screen that authentication was successful and that their attendance has been registered.

[0023] Furthermore, the authentication device 100 displays a time display 182 showing the time of authentication, i.e., the user 10's arrival time, and a user display 184 on the display unit 140, which includes the name and photograph of the authenticated user 10. This allows user 10 to confirm their registered arrival time and that the registration was definitely made by themselves and not by a third party.

[0024] Thus, the authentication device 100 branches subsequent processing based on which of the divided screen areas the user 10 was in, or in other words, at which coordinates (or range) on the screen the authentication information was detected. In other words, the authentication device 100 can execute multiple subsequent processes with a single terminal, thus reducing the implementation costs in system operation. Furthermore, as described above, the authentication process according to the embodiment does not change the authentication process itself from the conventional one, and only requires acquiring information on the position range (area) in which the user was detected on the display unit 140, so it does not require significant changes to the conventional system and is easy to implement. Moreover, the authentication process according to the embodiment is hygienic because the user 10 does not touch the screen or buttons, and it does not require the hassle of having the sensor read other information. The user 10 can perform different registrations simply by shifting their face while confirming the information displayed on the display unit 140, making it intuitive to use and allowing for quick authentication. Thus, the authentication device 100 makes it possible to realize a system that effectively utilizes authentication processing while reducing the effort and cost involved in implementation.

[0025] In the process illustrated in Figure 1, the authentication device 100 may, as appropriate, alert the user 10 to prevent the execution of incorrect subsequent processes. For example, if the authentication device 100 cannot clearly determine whether the user 10's face is in the first area 160 or the second area 165, it may output a voice guide such as, "Please move your face towards the clock-in side (or clock-out side)." The authentication device 100 may also output a voice guide indicating the result, such as, "Clock-in registered," when clock-in is registered. If the registration is incorrect, the user 10 may request to re-authenticate using voice input or request to change the registration to the other side. Furthermore, the authentication device 100 may output a voice guide or warning message to users such as the user 10 who authenticated on the "clock-in" side when clocking out, even though there is a clock-in log for the same day, to confirm whether the registration is correct.

[0026] (1-2. Configuration of the authentication device according to the embodiment) Next, the configuration of the authentication device 100 that performs the authentication process according to the embodiment will be described. Figure 2 is a diagram showing an example of the configuration of the authentication device 100 according to the embodiment.

[0027] As shown in Figure 2, the authentication device 100 includes a communication unit 110, a storage unit 120, a control unit 130, a display unit 140, and a camera 150. The authentication device 100 may also have an input unit (for example, a touch panel, keyboard, or mouse) that accepts various operations from an administrator or other person who authenticates the authentication device 100.

[0028] The communication unit 110 is implemented, for example, by a NIC (Network Interface Card) or a network interface controller. The communication unit 110 is connected to a network N (e.g., the Internet) by wire or wireless connection and transmits and receives information with external devices via the network N. For example, the communication unit 110 may transmit and receive information using any communication standard or technology such as Wi-Fi (registered trademark), Bluetooth, SIM (Subscriber Identity Module), or LPWA (Low Power Wide Area).

[0029] The storage unit 120 is implemented by, for example, semiconductor memory elements such as RAM (Random Access Memory) and flash memory, or by storage devices such as hard disks and optical discs. The storage unit 120 includes an authentication information storage unit 121, a region storage unit 122, and an authentication log storage unit 123.

[0030] The following will explain each memory unit in order, using Figures 3 to 5. In the examples shown in Figures 3 to 5, the information stored in memory unit 120 is sometimes conceptually represented as "A01," but in reality, each piece of information described later will be stored in memory unit 120.

[0031] The authentication information storage unit 121 stores information about the user using the authentication device 100. Figure 3 shows an example of the information stored by the authentication information storage unit 121. Figure 3 is a diagram showing an example of the authentication information storage unit 121 according to this embodiment. In the example shown in Figure 3, the authentication information storage unit 121 has items such as "user ID", "attributes", "authentication means", and "correct answer data".

[0032] "User ID" indicates identification information that identifies the user. "Attributes" indicate the user's attributes (e.g., whether they are a regular employee or a guest). "Authentication method" indicates the type of authentication information used in the authentication process. For example, the authentication method may be a facial image, iris scan, vein scan, gesture, ID device (employee ID, etc.). If multiple authentication methods are registered, the authentication device 100 can perform authentication using any of the authentication information presented by the user. The authentication method may be any known method, such as a fingerprint. "Ground truth data" indicates the ground truth data for each authentication method. For example, if the authentication method is a facial image, the ground truth data is the feature quantities extracted from multiple facial images of the user that have been registered in advance.

[0033] Next, the area storage unit 122 will be described using Figure 4. Figure 4 is a diagram showing an example of the area storage unit 122 according to the embodiment. The area storage unit 122 stores the division of areas associated with a certain authentication process and information of subsequent processes linked to those areas.

[0034] In the example shown in Figure 4, the area storage unit 122 has items such as "authentication purpose," "authentication area," and "management information."

[0035] "Authentication Purpose" indicates the purpose for which the authentication process by the authentication device 100 is used. "Authentication Area" indicates the division information for each area on the screen that is given different subsequent processing for the authentication purpose. The authentication area item may store various information about the area, such as how the screen is divided, how large an area occupies, what color or representation the area will be displayed in, and the text to be displayed to explain the area. "Management Information" indicates the information that the authentication device 100 manages in association with the authentication when authentication is performed in a certain area.

[0036] For example, in the example shown in Figure 4, if the authentication purpose is "attendance and departure management for factory B01," the authentication area is divided into a "first area" and a "second area." In this example, the first area is associated with "attendance" registration, and if authentication is successful, it registers the "attendant (e.g., user ID)" and "attendance date and time." Similarly, in this example, the second area is associated with "departure" registration, and if authentication is successful, it registers the "departureee (e.g., user ID)" and "departure date and time."

[0037] Next, the authentication log storage unit 123 will be described using Figure 5. Figure 5 is a diagram showing an example of the authentication log storage unit 123 according to the embodiment. The authentication log storage unit 123 stores information (authentication log) registered in a certain authentication process for each authentication process.

[0038] In the example shown in Figure 5, the authentication log storage unit 123 has items such as "authentication log ID," "authentication time," "user ID," and "log data."

[0039] The "Authentication Log ID" is identification information that identifies the authentication log. The Authentication Log ID may also include information indicating the purpose of the authentication process. The "Authentication Time" is the time the authentication process was performed. The "User ID" is identification information that identifies the user who attempted authentication. The "Log Data" is various pieces of information registered in association with the authentication process.

[0040] For example, in the example shown in Figure 5, the log with authentication log ID "C01" indicates that the authentication took place at time "T01" and the person being authenticated was "User U01". Furthermore, the authentication was "successful," indicating that the user "registered their attendance and clocked in at time T01." In another example, the log with authentication log ID "C21" indicates that the authentication took place at time "T21" and the person being authenticated was "User U01". Furthermore, the authentication was "successful," indicating that the user "registered their departure and clocked in at time T21."

[0041] Furthermore, if the authentication process according to this embodiment is used for attendance management, attendance information may be managed by other cloud services contracted by each business using the attendance management system. In this case, the authentication log storage unit 123 may be provided by the other cloud service instead of the authentication device 100.

[0042] Returning to Figure 2, let's continue the explanation. The control unit 130 is implemented by, for example, a CPU (Central Processing Unit), MPU (Micro Processing Unit), GPU (Graphics Processing Unit), etc., which executes a program stored inside the authentication device 100 using RAM (Random Access Memory) or the like as a working area. The control unit 130 is also a controller and is implemented by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array).

[0043] As shown in Figure 2, the control unit 130 includes a registration unit 131, an imaging unit 132, a display control unit 133, an authentication unit 134, and a determination unit 135.

[0044] Prior to the authentication process, the registration unit 131 registers various information. For example, in order to realize the authentication process, the registration unit 131 receives images and various other data from the user that will serve as the basis for the correct answer data that the authentication engine will use for matching. Specifically, the registration unit 131 receives registration of a face image from the user for use by the face recognition engine for matching.

[0045] Furthermore, the registration unit 131 accepts settings for each screen area to suit its purpose, such as using the authentication process for attendance management. Specifically, as explained using Figure 4, the registration unit 131 accepts various settings from the administrator regarding the authentication process and subsequent processes, such as determining that an attendance has occurred if authentication is performed in one part of the screen, and determining that an attendance has ended if authentication is performed in another part of the screen.

[0046] The imaging unit 132 captures an image of the user to be authenticated during the authentication process. Specifically, the imaging unit 132 controls the camera 150 to capture an image of the user that is within the camera 150's field of view. In this case, the user may not be the user's actual appearance, but rather authentication information presented by the user (for example, the user's fingerprint or an ID card owned by the user).

[0047] The display control unit 133 controls the display unit 140 to display the user captured by the imaging unit 132. The display control unit 133 also displays an authentication screen divided into multiple areas based on the information registered by the registration unit 131.

[0048] For example, the display control unit 133 displays the captured user's face in one of the areas on the authentication screen. The display control unit 133 may also detect authentication information based on known technology and display a detection mark on the screen to indicate detection. For example, the display control unit 133 displays a face detection mark on the screen to indicate that the user's face has been detected. This allows the user to determine whether or not their face has been detected by the authentication device 100.

[0049] The authentication unit 134 authenticates the user's identity based on a comparison between the authentication information presented by the user, captured by the imaging unit 132, and pre-registered correct answer data.

[0050] For example, the authentication unit 134 authenticates the user's identity using at least one of the user's facial image, iris, fingerprint, or gestures made by the user as authentication information. In order to support various authentication methods, the authentication unit 134 may also perform the authentication process using a predetermined authentication engine provided by a third party (an authentication program that models feature extraction processing and matching processing between authentication information and extracted features).

[0051] Furthermore, the authentication unit 134 sends information to the subsequent determination unit 135 indicating which of the multiple regions the location or range where the authentication information presented by the user was detected on the display unit 140 falls into. This allows the authentication device 100 to branch subsequent processing based on information indicating which region was authenticated, even when performing authentication processing on the same terminal.

[0052] The determination unit 135 determines the content of the subsequent processing to be performed when the user is authenticated, based on the position or range in which the user was displayed on the display unit 140. For example, the determination unit 135 determines whether to register the authenticated user as an employee who has arrived at work or as an employee who has left work, based on the position or range in which the user was displayed at the time of authentication.

[0053] More specifically, when a user is authenticated by the authentication unit 134, the determination unit 135 determines the content of subsequent processing based on which of the multiple areas pre-set on the display unit 140 the position or range in which the authentication information used for the authentication is detected on the display unit 140 is included.

[0054] For example, the determination unit 135 determines which area on the screen the detected area representing the user's face (for example, the detection mark 170 shown in Figure 1) belongs to, and determines the content of subsequent processing based on the determination result. In this case, the determination unit 135 may determine that the user's authentication position is included in a predetermined area if all pixels included in the detection mark 170 belong to that area, or it may determine that the user's authentication position is included in a predetermined area if the majority of pixels included in the detection mark 170 belong to that area. The determination unit 135 may also determine whether the center point of the area detected as the detection mark 170 belongs to a certain area. Furthermore, if the determination unit 135 cannot clearly determine which area the detection mark 170 is in, it may prompt the user to move or request that the authentication process be repeated.

[0055] Furthermore, if the decision unit 135 has determined a subsequent process, it may notify the user that it has determined the content of the subsequent process, and may also accept a request from the user to change the determined subsequent process. For example, if the user's attendance and departure times are incorrectly registered because the user was in the wrong position, the user may input to the authentication device 100 by voice or other means that they wish to change the registered content. In this case, the decision unit 135 may accept the request for change and change the registered content, or it may re-authenticate the user with the correct position.

[0056] (1-3. Procedure for authentication processing according to the embodiment) Next, the procedure for the authentication process according to the embodiment will be explained using Figure 6. Figure 6 is a flowchart showing the procedure for the authentication process according to the embodiment.

[0057] As shown in Figure 6, the authentication device 100 waits for the user to be authenticated to enter the field of view of the camera 150 before proceeding with the authentication process (step S101).

[0058] Subsequently, the authentication device 100 determines whether or not it has detected an object to be authenticated (step S102). If it does not detect an object to be authenticated (step S102; No), the authentication device 100 continues to wait.

[0059] On the other hand, if an object to be authenticated is detected (step S102; Yes), the authentication device 100 determines whether the object to be authenticated is contained in any of the areas (step S103). If the object to be authenticated is not contained in any of the areas (step S103; No), for example, if the object to be authenticated is not displayed on the screen or if it is not possible to determine which area the object to be authenticated is displayed in, the authentication device 100 continues to detect objects to be authenticated.

[0060] On the other hand, if the object to be authenticated is included in any area (step S103; Yes), the authentication device 100 performs the authentication process for the object to be authenticated displayed on the screen (step S104). Subsequently, the authentication device 100 determines whether the authentication process was successful or not (step S105). If authentication is unsuccessful (step S105; No), the authentication device 100 displays an authentication failure or error, and waits until the object to be authenticated enters the field of view again.

[0061] On the other hand, if authentication is successful (step S105; Yes), the authentication device 100 determines the area on the screen that contains the detected object based on the position or range in which the object was displayed at the time of authentication (step S106).

[0062] If authentication is performed while the detected object is displayed in the first area, the authentication device 100 executes the process associated with the first area (step S107). If authentication is performed while the detected object is displayed in the second area, the authentication device 100 executes the process associated with the second area (step S108).

[0063] Note that the authentication process according to this embodiment does not necessarily have to be performed in the order shown in Figure 6. For example, the authentication device 100 may skip the step of determining which area the object to be authenticated belongs to (step S103) and attempt to authenticate the detected object (step S105).

[0064] (1-4. Modified Examples of Embodiments) (1-4-1. Setting conditions for each area) The above embodiment shows an example of applying the authentication process according to the embodiment to an attendance management system. However, the authentication process according to the embodiment may be applied to various systems.

[0065] Figure 7 shows a modified example of the embodiment. Figure 7 is a diagram illustrating the overview of the authentication process related to the modified example. In Figure 7, the authentication device 100 authenticates the user 10 using an authentication screen divided into two areas, similar to the process in Figure 1.

[0066] In the example shown in Figure 7, the first area of ​​the authentication screen is assigned permission to enter the first room 200, and the second area of ​​the authentication screen is assigned permission to enter the second room 210. For example, if user 10 performs authentication in the first area and is authenticated as a pre-registered user, the authentication device 100 unlocks the electronic lock on the first room 200. Alternatively, if user 10 performs authentication in the second area and is authenticated as a pre-registered user, the authentication device 100 unlocks the electronic lock on the second room 210.

[0067] Thus, the authentication process related to modification can be used for authentication in multiple areas to manage access to different rooms. This allows administrators to manage access to multiple rooms with a single authentication terminal, without having to prepare multiple authentication terminals for each room.

[0068] Furthermore, in such an example, the authentication device 100 may perform more advanced management, such as setting different authentication strengths for each area or employing different authentication engines. This point will be explained using Figure 8. Figure 8 shows an example of a modified area storage unit 122A.

[0069] In the example shown in Figure 8, the area storage unit 122A includes the items "authentication strength" and "authentication engine" in addition to those in the example in Figure 4.

[0070] "Authentication strength" indicates the authentication strength set for each area. For example, if the authentication strength is set to "high," the authentication device 100 will strictly determine authentication by setting a high matching threshold or requiring multiple authentication methods (such as facial images and fingerprints). This allows the authentication device 100 to strictly control access to rooms corresponding to the first area (e.g., offices where trade secrets are stored) while allowing access to rooms corresponding to the second area (e.g., general offices) through normal authentication processing, thus enabling flexible use.

[0071] The term "authentication engine" refers to the authentication engine used for authentication processing in each domain. Generally, different authentication engines are modeled based on different training data, so they may have different strengths in terms of the objects they are best suited to authenticate, the authentication methods they are best suited to, and the authentication strength they offer. Therefore, the authentication device 100 can limit the authentication methods used for authentication or vary the authentication strength by setting the authentication engine for each domain.

[0072] In other words, the authentication unit 134 of the authentication device 100 may authenticate the user using different thresholds or different authentication engines for each region, depending on which of the multiple regions the location or range in which the authentication information presented by the user is detected on the display unit 140 falls into. This allows the authentication device 100 to change the content of subsequent processing for each region and to change the required authentication strength for each region, thereby enabling more effective use of the authentication process.

[0073] (1-4-2. Other application examples) In addition to the embodiments and modifications described above, the authentication process relating to this disclosure is applicable to a variety of situations.

[0074] For example, the authentication device 100 may set the first area as "for regular staff" and the second area as "for guests" when managing access to a designated room. In this case, the authentication device 100 can manage access so that third parties cannot easily enter by setting the authentication strength of the second area to a relatively high level. For example, if authentication is performed using only one condition (authentication strength), setting the authentication threshold too high will increase security, but authentication errors will occur frequently, making the system difficult to use for frequent users (regular staff, etc.). On the other hand, setting the authentication threshold too low will raise security concerns. In the authentication process according to this embodiment, by dividing the area into two, the authentication strength can be set separately, thus realizing a system that enhances security without compromising convenience.

[0075] (1-4-3. Pre-processing for authentication) The authentication device 100 may output some kind of warning to the user before performing the authentication process. For example, if the authentication device 100 performs authentication as soon as the user enters the field of view, there is a possibility that authentication will be performed before the user has time to select an area. For this reason, the authentication device 100 may perform authentication with some kind of pre-processing, such as outputting a voice message saying, "I will now authenticate you." Alternatively, the authentication device 100 may start the authentication process when the user takes some kind of explicit action, such as inputting a voice message saying, "Please." This allows the authentication device 100 to prevent authentication from being performed in the wrong area.

[0076] Furthermore, the administrator of the authentication device 100 may create two lines of traffic aligned with the area displayed by the authentication device 100 for attendance management, and have users authenticate themselves. In this case, the authentication device 100 can simultaneously record the attendance and departure of individuals by detecting separate faces displayed in the two areas. This allows the authentication device 100 to quickly perform authentication even in workplaces where a very large number of people are attending.

[0077] (1-4-4.Device configuration) In the above embodiment, an example was shown in which the authentication device 100 includes a display unit 140 and a camera 150. However, the display unit 140 and camera 150 may be provided by other devices. In this case, the authentication device 100 realizes the authentication process according to the embodiment by controlling the imaging process of the camera 150, which is an external device, and controlling the display on the display unit 140, which is an external display. For example, the authentication device 100 may be a cloud server, or a device that controls edge terminals installed in each workplace, etc.

[0078] Furthermore, the authentication device 100 may perform authentication using an external authentication engine, or it may perform authentication using a pre-trained authentication model provided by the device itself. In other words, the authentication device 100 may perform the processing according to the embodiment in an on-premise environment, where it operates the authentication engine itself, rather than receiving the authentication engine from a provider (authentication provider).

[0079] (2. Other Embodiments) The processing according to the above-described embodiment may be carried out in various other forms besides those described above.

[0080] For example, among the processes described in the above embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically by known methods. In addition, the processing procedures, specific names, and information including various data and parameters shown in the above document and drawings can be changed at will unless otherwise specified. For example, the various information shown in each figure is not limited to the information shown.

[0081] Furthermore, the components of each illustrated device are functionally conceptual and do not necessarily need to be physically configured as shown. In other words, the specific forms of distribution and integration of each device are not limited to those shown, and all or part of them can be functionally or physically distributed and integrated in any unit according to various loads and usage conditions.

[0082] Furthermore, the embodiments and modifications described above can be combined as appropriate, provided that the processing content is not inconsistent.

[0083] Furthermore, the effects described herein are merely illustrative and not limiting; other effects may also occur.

[0084] (3. Effects of the authentication device related to this disclosure) As described above, the authentication device according to this disclosure (authentication device 100 in the embodiment) includes an imaging unit (imaging unit 132 in the embodiment), a display control unit (display control unit 133 in the embodiment), and a determination unit (determination unit 135 in the embodiment). The imaging unit captures an image of the user to be authenticated. The display control unit displays the user captured by the imaging unit on the display unit (display unit 140 in the embodiment). The determination unit determines the content of subsequent processing to be performed when the user is authenticated, according to the position or range in which the user is displayed on the display unit.

[0085] Thus, the authentication device described in this disclosure does not simply authenticate the user, but performs different subsequent processes depending on the user's position displayed on the screen. In other words, since the authentication device can perform multiple different processes with only one unit and without increasing the number of authentication attempts or authentication methods, it is possible to realize a system that effectively utilizes authentication processing while keeping the effort and cost of implementation low.

[0086] Furthermore, the authentication device may also include an authentication unit (authentication unit 134 in this embodiment) that authenticates the identity of the user based on a comparison between the authentication information presented by the user, captured by the imaging unit, and pre-registered correct answer data.

[0087] In this way, the authentication device can perform authentication on its own and determine the content of subsequent processing based on the result. As a result, the authentication device can perform authentication and subsequent processing using only the equipment installed in the workplace, etc., thus reducing the effort and cost of implementation.

[0088] Furthermore, the authentication unit authenticates the user's identity using at least one of the following as authentication information: the user's facial image, iris, fingerprint, or gestures made by the user.

[0089] Thus, an authentication device can perform authentication using multiple means. This allows the authentication device to realize a highly convenient authentication system that is not limited to specific authentication methods.

[0090] Furthermore, when a user is authenticated by the authentication unit, the determination unit determines the content of subsequent processing based on which of the multiple areas pre-set on the display unit the location or range in which the authentication information used for the authentication is detected on the display unit falls.

[0091] Thus, the authentication device determines the content of subsequent processing based on which region the location where authentication information (face, iris, fingerprint, etc.) is detected falls into. Since this does not require changing the authentication process itself, it enables the realization of an authentication system that is easy to implement.

[0092] Furthermore, the authentication unit authenticates the user using different thresholds or different authentication engines for each region, depending on which of the multiple regions the location or range in which the authentication information presented by the user is detected on the display unit falls within.

[0093] In this way, the authentication device can vary the authentication strength for each domain by using different thresholds and authentication engines for each domain, allowing for more flexible configuration of subsequent processes associated with each domain.

[0094] Furthermore, the decision unit notifies the user that it has decided on the content of the subsequent processing, and also accepts requests from the user to change the decided subsequent processing.

[0095] Thus, with an authentication device, the authentication result is notified to the user, allowing the user to immediately recognize, for example, that authentication was performed in the wrong area, and to request a correction or request to re-authenticate.

[0096] (4. Hardware Configuration) The information devices such as the authentication device 100 according to the embodiment described above are realized by a computer 1000 having a configuration such as that shown in Figure 9. The following explanation will use the authentication device 100 according to the embodiment as an example. Figure 9 is a hardware configuration diagram showing an example of a computer 1000 that realizes the functions of the authentication device 100. The computer 1000 has a CPU 1100, RAM 1200, ROM (Read Only Memory) 1300, HDD (Hard Disk Drive) 1400, a communication interface 1500, and an input / output interface 1600. The various parts of the computer 1000 are connected by a bus 1050.

[0097] The CPU 1100 operates based on programs stored in the ROM 1300 or HDD 1400, and controls various parts. For example, the CPU 1100 loads the programs stored in the ROM 1300 or HDD 1400 into the RAM 1200 and executes processing corresponding to the various programs.

[0098] ROM1300 stores boot programs such as the BIOS (Basic Input Output System) executed by CPU1100 when computer 1000 starts up, as well as programs that depend on the computer 1000's hardware.

[0099] HDD1400 is a computer-readable recording medium that non-temporarily records programs executed by CPU1100 and data used by such programs. Specifically, HDD1400 is a recording medium that records a program that performs the authentication process related to this disclosure, which is an example of program data 1450.

[0100] The communication interface 1500 is an interface for the computer 1000 to connect to an external network 1550 (e.g., the Internet). For example, the CPU 1100 can receive data from other devices or transmit data it generates to other devices via the communication interface 1500.

[0101] The input / output interface 1600 is an interface for connecting the input / output device 1650 and the computer 1000. For example, the CPU 1100 receives data from input devices such as a keyboard or mouse via the input / output interface 1600. The CPU 1100 also transmits data to output devices such as a display, speaker, or printer via the input / output interface 1600. The input / output interface 1600 may also function as a media interface for reading programs recorded on a predetermined recording medium (media). Examples of media include optical recording media such as DVDs (Digital Versatile Discs) and PDs (Phase Change Rewritable Disks), magneto-optical recording media such as MOs (Magneto-Optical Disks), tape media, magnetic recording media, or semiconductor memory.

[0102] For example, when computer 1000 functions as an authentication device 100 according to the embodiment, the CPU 1100 of computer 1000 realizes functions such as the control unit 130 by executing an authentication program loaded on RAM 1200. The HDD 1400 stores the program that executes the authentication process according to this disclosure and the data in the storage unit 120. The CPU 1100 reads and executes the program data 1450 from the HDD 1400, but as another example, these programs may be obtained from other devices via an external network 1550.

[0103] Although embodiments of the present application have been described in detail based on the drawings, these are illustrative examples, and the present invention can be implemented in various other forms with modifications and improvements based on the knowledge of those skilled in the art, starting with the embodiments described in the disclosure section of the invention. [Explanation of Symbols]

[0104] 10 users 100 Authentication Devices 110 Communications Department 120 Storage section 121 Authentication Information Storage Unit 122 Area storage section 123 Authentication log storage unit 130 Control Unit 131 Registration Department 132 Imaging Unit 133 Display Control Unit 134 Authentication Department 135 Decision Section 140 Display section 150 Cameras 160 1st area 165 Second area 170 detection marks 180 Authentication Results 182 Time display 184 users displayed

Claims

1. An imaging unit that captures images of the user to be authenticated, A display control unit that displays the user captured by the imaging unit on the display unit, An authentication unit authenticates the identity of the user based on a comparison between the authentication information presented by the user, captured by the imaging unit, and pre-registered correct answer data. The system includes a determination unit that, when the user is authenticated by the authentication unit, determines the content of subsequent processing to be performed when the user is authenticated, based on which of a plurality of areas pre-set on the display unit the position or range in which the authentication information used for the authentication is detected on the display unit falls within, The aforementioned determination unit, The system determines which of the multiple regions the authentication information is contained in, based on at least one of the following criteria: whether all of the pixels constituting the authentication information are contained in any of the multiple regions; whether the majority of the pixels constituting the authentication information are contained in any of the multiple regions; or whether the center point of the pixels constituting the authentication information is contained in any of the multiple regions; and if the user cannot identify the location or range displayed on the display unit, the system alerts the user. Authentication device.

2. The authentication unit, The user's identity is authenticated using at least one of the user's facial image, iris, fingerprint, or gestures made by the user as authentication information. The authentication device according to feature 1.

3. The authentication unit, Depending on which of the multiple regions the location or range in which the authentication information presented by the user is detected on the display unit falls within, the user is authenticated using different thresholds or different authentication engines for each region. The authentication device according to feature 1.

4. The aforementioned determination unit, The system notifies the user that the content of the subsequent processing has been determined, and accepts requests from the user to change the determined subsequent processing. The authentication device according to any one of features 1 to 3.

5. Computers The user to be authenticated is captured in an image, The captured user is displayed on the display unit. Based on the comparison of the captured authentication information presented by the user with the pre-registered correct answer data, the user's identity is authenticated. When the user is authenticated, the system determines the content of subsequent processing to be performed when the user is authenticated, based on which of the multiple areas pre-set on the display unit the location or range in which the authentication information used for the authentication is detected falls within, and further, The system determines which of the multiple regions the authentication information is contained in, based on at least one of the following criteria: whether all of the pixels constituting the authentication information are contained in any of the multiple regions; whether the majority of the pixels constituting the authentication information are contained in any of the multiple regions; or whether the center point of the pixels constituting the authentication information is contained in any of the multiple regions; and if the user cannot identify the location or range displayed on the display unit, the system alerts the user. An authentication method characterized by including the following.

6. Computers, An imaging unit that captures images of the user to be authenticated, A display control unit that displays the user captured by the imaging unit on the display unit, An authentication unit authenticates the identity of the user based on a comparison between the authentication information presented by the user, captured by the imaging unit, and pre-registered correct answer data. When the user is authenticated by the authentication unit, a determination unit determines the content of the subsequent processing to be performed when the user is authenticated, based on which of the multiple areas pre-set on the display unit the position or range in which the authentication information used for the authentication is detected on the display unit falls. An authentication program characterized by functioning as an authentication device equipped with, The aforementioned determination unit, The system determines which of the multiple regions the authentication information is contained in, based on at least one of the following criteria: whether all of the pixels constituting the authentication information are contained in any of the multiple regions; whether the majority of the pixels constituting the authentication information are contained in any of the multiple regions; or whether the center point of the pixels constituting the authentication information is contained in any of the multiple regions; and if the user cannot identify the location or range displayed on the display unit, the system alerts the user. Authentication program.

Citation Information

Patent Citations

  • Face authenticating device, and entering and leaving managing device

    JP2006236244A

  • Information processing device and log-in control method

    JP2017091059A

  • Face authentication device

    JP2019124999A

  • Information processing device, information processing system, and information processing method

    JP2022149373A

  • Facial authentication method, program, recording medium, and facial authentication system

    JP6839313B1