Authentication system, information processing device, information processing method, and program
The authentication system addresses issues with employee badges and biometric failures by integrating terminal and biometric authentication, ensuring reliable and convenient access control.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-07-30
- Publication Date
- 2026-04-14
AI Technical Summary
Authentication systems face challenges with employee badges requiring constant retrieval and biometric authentication prone to environmental failures.
An authentication system integrating a user terminal with biometric and terminal authentication capabilities, utilizing an authentication server to manage both types of authentication, allowing seamless switching between methods.
Enhances user convenience by providing alternative authentication methods, reducing environmental dependency and improving reliability.
Smart Images

Figure 0007845418000001 
Figure 0007845418000002 
Figure 0007845418000003
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication system, an information processing apparatus, an information processing method, and a program.
Background Art
[0002] In many cases, so-called employee badges are lent to employees or the like of a company. The employee badge is used for personal identification and authentication. For example, an employee touches the employee badge to a card reader provided in a gate device to open the gate and enter an office or the like.
[0003] In recent years, the spread of biometric authentication using biometric information has started (see Patent Document 1). Patent Document 1 describes that a series of processes including face authentication performed at the time of personal identification are performed in a short time. The face verification device in the document performs a face verification process of comparing a face image of an authenticated person or imaging face data which is a feature amount of the face image with a registered face image or registered face data which is a feature amount of the registered face image to confirm whether the authenticated person is the person in whom the registered face data is registered.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] As described above, authentication using an employee badge is biometric authentication using biometric information. Here, each of authentication by an employee badge and biometric authentication has merits and demerits. For example, in authentication by an employee badge, the user needs to take out the employee badge every time authentication is performed. Also, in biometric authentication, there is a possibility of authentication failure depending on the environmental conditions at the time of authentication.
[0006] The primary objective of this invention is to provide an authentication system, an authentication terminal, a control method for the authentication terminal, and a storage medium that contribute to achieving more convenient personal authentication. [Means for solving the problem]
[0007] According to a first aspect of the present invention, an authentication system is provided that includes a terminal owned by a user, an authentication server that stores first biometric information for performing biometric authentication of the user, and first terminal authentication information for performing terminal authentication by the terminal, and an authentication terminal corresponding to the biometric authentication and the terminal authentication.
[0008] According to a second aspect of the present invention, an authentication terminal is provided, comprising: a biometric information acquisition unit for acquiring a user's biometric information; a terminal access unit for accessing a terminal owned by the user and acquiring terminal authentication information for performing authentication by the terminal; and an authentication request unit for sending an authentication request including the biometric information to an authentication server when the biometric information is acquired, and for sending an authentication request including the terminal authentication information to the authentication server when the terminal authentication information is acquired.
[0009] A third aspect of the present invention provides a method for controlling an authentication terminal, which includes acquiring a user's biometric information, accessing a terminal owned by the user, acquiring terminal authentication information for performing authentication by the terminal, sending an authentication request including the biometric information to an authentication server when the biometric information is acquired, and sending an authentication request including the terminal authentication information to the authentication server when the terminal authentication information is acquired.
[0010] A fourth aspect of the present invention is provided, which is a computer-readable storage medium that stores a program for causing a computer mounted on an authentication terminal to execute the following: a process for acquiring a user's biometric information; a process for accessing a terminal owned by the user and acquiring terminal authentication information for performing authentication by the terminal; and a process for sending an authentication request including the biometric information to an authentication server when the biometric information is acquired, and sending an authentication request including the terminal authentication information to the authentication server when the terminal authentication information is acquired. [Effects of the Invention]
[0011] From each perspective of the present invention, an authentication system, an authentication terminal, a method for controlling an authentication terminal, and a storage medium are provided that contribute to achieving more convenient personal authentication. However, the effects of the present invention are not limited to those described above. The present invention may also produce other effects in place of or in conjunction with the effects described above. [Brief explanation of the drawing]
[0012] [Figure 1] This is a diagram illustrating the outline of one embodiment. [Figure 2] This figure shows an example of a schematic configuration of the authentication system according to the first embodiment. [Figure 3] This is a diagram illustrating the general operation of the authentication system according to the first embodiment. [Figure 4] This figure shows an example of an authentication terminal ID list according to the first embodiment. [Figure 5] This figure shows an example of the processing configuration of an authentication terminal according to the first embodiment. [Figure 6] This is a diagram illustrating the operation of the authentication control unit according to the first embodiment. [Figure 7] This figure shows an example of an authentication request according to the first embodiment. [Figure 8] This is a diagram illustrating the operation of the authentication control unit according to the first embodiment. [Figure 9] This figure shows an example of a registration request according to the first embodiment. [Figure 10] It is a diagram showing an example of the processing configuration of the authentication server according to the first embodiment. [Figure 11] It is a diagram for explaining the operation of user registration according to the first embodiment. [Figure 12] It is a diagram showing an example of the user information database according to the first embodiment. [Figure 13] It is a diagram showing an example of the behavior history database according to the first embodiment. [Figure 14] It is a diagram showing an example of the processing configuration of the terminal according to the first embodiment. [Figure 15] It is a diagram for explaining the operation of the browsing request section according to the first embodiment. [Figure 16] It is a diagram for explaining the operation of the output section according to the first embodiment. [Figure 17] It is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment. [Figure 18] It is a diagram for explaining the operation of the authentication control section according to the second embodiment. [Figure 19] It is a diagram showing an example of the processing configuration of the authentication server 10 according to the third embodiment. [Figure 20] It is a diagram for explaining the operation of the behavior history analysis section according to the third embodiment. [Figure 21] It is a diagram showing an example of the hardware configuration of the authentication terminal. [Figure 22] It is a diagram for explaining the operation of the authentication control section according to the modification example of the present disclosure. [Figure 23] It is a diagram for explaining the operation of the output section according to the modification example of the present disclosure.
Mode for Carrying Out the Invention
[0013] First, an overview of one embodiment will be described. The reference numerals in the drawings attached to this overview are provided for convenience as examples to aid understanding, and this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. The connecting lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows schematically indicate the flow of the main signal (data) and do not exclude bidirectional flow. In this specification and in the drawings, elements that can be similarly described are given the same reference numerals to avoid redundant explanation.
[0014] An authentication system according to one embodiment includes a terminal 101 possessed by a user, an authentication server 102, and an authentication terminal 103 (see Figure 1). The authentication server 102 stores first biometric information for performing biometric authentication of the user and first terminal authentication information for performing terminal authentication by terminal 101. The authentication terminal 103 supports biometric authentication and terminal authentication.
[0015] The authentication terminal 103 included in the above authentication system supports both authentication by terminal 101 and authentication using biometric information. For example, even if biometric authentication fails at authentication terminal 103, the user can still be authenticated by terminal 101. In other words, user convenience is improved.
[0016] Specific embodiments will be described in more detail below with reference to the drawings.
[0017] [First Embodiment] The first embodiment will be described in more detail with reference to the drawings.
[0018] [System Configuration] Figure 2 shows an example of a schematic configuration of an authentication system according to the first embodiment. Referring to Figure 2, the authentication system includes an authentication server 10, a plurality of authentication terminals 20-1 to 20-3, and a terminal 30 held by the user.
[0019] In the following explanation, unless there is a particular reason to distinguish between authentication terminals 20-1 to 20-3, they will simply be referred to as "authentication terminal 20." Similarly, for other components, the code on the left, separated by a hyphen, will be used to represent that component.
[0020] The devices shown in Figure 2 are interconnected. For example, the authentication server 10 and the authentication terminal 20 are connected by wired or wireless communication means and are configured to communicate with each other.
[0021] The authentication server 10 may be located on the same floor or in the same building as the authentication terminal 20, or it may be located on a network (on the cloud).
[0022] The authentication system shown in Figure 2 enables authentication (identity verification) during work activities in the office. More specifically, the authentication system supports authentication using the user's biometric information (biometric authentication) and authentication using the terminal 30 carried by the user (hereinafter referred to as terminal authentication).
[0023] The authentication server 10 is a device that implements the two authentication methods described above. The authentication server 10 stores biometric information (for example, a facial image or features generated from a facial image) for implementing biometric authentication. Furthermore, the authentication server stores information for implementing terminal authentication (hereinafter referred to as terminal authentication information; for example, the user ID described later).
[0024] Biometric information includes facial images, fingerprint images, iris images, finger vein images, palm print images, palm vein images, etc. There may be one or more pieces of biometric information. In this disclosure, the term "biometric information" refers to images that include all or part of a living organism and the features extracted from such images.
[0025] The authentication terminal 20 is a device that provides specified services to authenticated users (those who have successfully authenticated). The authentication terminal 20 is a terminal (hybrid terminal) that supports both biometric authentication and terminal authentication.
[0026] The authentication terminal 20-1 is a gate device installed at entrances and exits of buildings, floors, etc. The authentication terminal 20-1 permits passage for those who have successfully authenticated.
[0027] Authentication terminal 20-2 is a copier. Authentication terminal 20-2 allows the authenticated user to make copies of documents, etc.
[0028] The authentication terminal 20-3 is a vending machine. The authentication terminal 20-3 identifies the product purchaser (user) through authentication and sells the product to the identified user.
[0029] Users (employees, etc., who use the authentication system) carry terminal 30 instead of their employee ID card. Terminal 30 has a built-in NFC (Near Field Communication) compatible IC (Integrated Circuit) chip. This NFC chip stores the same type of information (user ID) as the terminal authentication information stored by the authentication server 10. Terminal 30 functions as a "digital employee ID" that replaces the existing employee ID card.
[0030] The authentication system configuration shown in Figure 2 is illustrative and not intended to limit the system's configuration. For example, Figure 2 shows three authentication terminals 20, but this does not limit the number of authentication terminals 20. Also, the functions of each authentication terminal 20 are illustrative, and the system may include authentication terminals 20 with other functions. For example, the system may include an authentication terminal 20 that controls entry and exit to a conference room. Alternatively, the system may include multiple authentication terminals 20 with similar functions. For example, the system may include multiple copiers that support both biometric authentication and terminal authentication.
[0031] [System Operation Overview] Next, we will explain the general operation of the authentication system, referring to Figure 3.
[0032] Prior to using the authentication system, users must register as system users. Specifically, users operate their terminal 30 to register their facial image, name, employee number, etc., with the authentication server 10.
[0033] Upon obtaining the above information, the authentication server 10 generates a unique user ID (Identifier) for each user. The authentication server 10 stores the generated user ID, the user's biometric information (features generated from the facial image), and personal information (name, employee number, etc.) in a user information database (DB; Database).
[0034] The authentication server 10 issues the generated user ID to the user (terminal 30). Terminal 30 stores the acquired user ID in its internal NFC chip. The authentication server 10 also distributes the "authentication terminal ID list" (described later) to terminal 30 during user registration.
[0035] Once user registration is complete, the user is permitted to pass through the gate and use the various devices. The user moves in front of the authentication terminal 20. The authentication terminal 20 acquires the user's facial image and generates feature vectors from the facial image. The authentication terminal 20 sends an "authentication request" containing the generated feature vectors to the authentication server 10.
[0036] The authentication server 10 performs a matching process (one-to-many matching; N is a positive integer, the same applies hereafter) using the acquired features and the features registered in the user information database. The authentication server 10 determines "authentication successful" if there are registered features that substantially match the acquired features. The authentication server 10 determines "authentication failed" if there are no registered features that substantially match the acquired features.
[0037] The authentication server 10 sends the authentication result (authentication successful, authentication failed) to the authentication terminal 20. When sending a successful authentication, the authentication server 10 sends a response (authentication result) including the user ID of the person who successfully authenticated to the authentication terminal 20.
[0038] The authentication terminal 20 performs actions according to the authentication result. For example, if authentication terminal 20-1 successfully authenticates the user, it opens the gate and allows the user to pass through.
[0039] Users can also undergo terminal authentication using terminal 30. The user touches (or brings close to) terminal 30 to the card reader provided on authentication terminal 20. Authentication terminal 20 reads terminal authentication information (user ID) from the NFC chip built into terminal 30 via the card reader. Authentication terminal 20 sends an "authentication request" containing the read user ID to authentication server 10.
[0040] The authentication server 10 determines "authentication successful" if the acquired user ID is registered in the user information database. The authentication server 10 determines "authentication failed" if the acquired user ID is not registered in the database.
[0041] The authentication server 10 sends the authentication result (authentication successful, authentication failed) to the authentication terminal 20. The authentication terminal 20 performs an action according to the authentication result, similar to the case of biometric authentication.
[0042] The authentication terminal 20 requests the authentication server 10 to register detailed information about the user's (successfully authenticated) actions on its device (hereinafter referred to as "action details"). Specifically, the authentication terminal 20 sends a "registration request" to the authentication server 10 that includes the above action details, the identification information assigned to its device (authentication terminal ID), and the user ID of the successfully authenticated user.
[0043] Detailed behavioral information includes examples such as the date and time of authentication and the authentication method (biometric authentication, device authentication). Detailed behavioral information specific to each authentication terminal 20 includes examples such as the number and format (color, monochrome) of documents copied by the copier (authentication terminal 20-2). In addition, detailed behavioral information generated by the vending machine (authentication terminal 20-3) includes the name of the product purchased, the price, and the quantity.
[0044] The authentication terminal ID is identification information shared among all devices included in the authentication system (authentication server 10, authentication terminal 20, terminal 30). The authentication terminal ID is identification information determined according to the type of authentication terminal 20 (gate device, copier, vending machine, etc.). For example, a system administrator determines the authentication terminal ID and generates an "authentication terminal ID list" (see Figure 4). The system administrator inputs this authentication terminal ID list into the authentication server 10 and sets the authentication terminal ID corresponding to each authentication terminal 20. As mentioned above, the authentication terminal ID list is distributed to terminal 30 during user registration.
[0045] Upon receiving a registration request (a request including the authentication terminal ID, user ID, and detailed activity information), the authentication server 10 associates the information contained in the registration request and stores it in the activity history database. Once the information is stored in the database, the authentication server 10 sends an affirmative response to the authentication terminal 20. If registration to the database fails, the authentication server 10 sends a negative response to the authentication terminal 20.
[0046] Users can operate terminal 30 to view their activity history on authentication terminal 20 (information consisting of details of at least one activity). Specifically, terminal 30 sends a "viewing request" to authentication server 10 that includes the user ID and the authentication terminal ID of the authentication terminal 20 whose activity history it wishes to view.
[0047] The authentication server 10 searches the activity history database using the user ID and authentication terminal ID included in the viewing request as keys, and identifies the corresponding activity history. The authentication server 10 sends the identified activity history to the terminal 30.
[0048] Next, we will describe the details of each device included in the authentication system according to the first embodiment.
[0049] [Authentication device] The authentication terminal 20 is a hybrid terminal that supports biometric authentication and terminal authentication.
[0050] Figure 5 shows an example of the processing configuration (processing module) of the authentication terminal 20 according to the first embodiment. Referring to Figure 5, the authentication terminal 20 comprises a communication control unit 201, an authentication control unit 202, a function implementation unit 203, a registration request unit 204, and a storage unit 205.
[0051] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the authentication server 10. The communication control unit 201 also transmits data to the authentication server 10. The communication control unit 201 passes the data received from other devices to other processing modules. The communication control unit 201 transmits the data obtained from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 201.
[0052] The authentication control unit 202 is a means for controlling user authentication. The authentication control unit 202 decides whether to request either biometric authentication or terminal authentication from the authentication server 10. Various methods and schemes are possible for the authentication control unit 202 to make this decision.
[0053] For example, when the authentication control unit 202 detects a user in front of it using a motion sensor or the like, it obtains the user's preference regarding whether to use biometric authentication or terminal authentication. For example, the authentication control unit 202 generates a GUI (Graphical User Interface) as shown in Figure 6 to obtain the user's preference.
[0054] As shown in Figure 5, the authentication control unit 202 includes a submodule consisting of a biometric information acquisition unit 211, a terminal access unit 212, and an authentication request unit 213.
[0055] If the user requests biometric authentication, the authentication control unit 202 activates the biometric information acquisition unit 211 and acquires the user's facial image.
[0056] The biometric information acquisition unit 211 controls the camera device (the camera device provided by the authentication terminal 20) and acquires the user's face image. Specifically, the biometric information acquisition unit 211 extracts the face image from the image data. Note that existing technologies can be used for the face image detection and face image extraction processes by the biometric information acquisition unit 211, so a detailed explanation is omitted. For example, the biometric information acquisition unit 211 may use a learning model trained by a CNN (Convolutional Neural Network) to extract the face image (face region) from the image data. Alternatively, the biometric information acquisition unit 211 may use a method such as template matching to extract the face image.
[0057] The biometric information acquisition unit 211 generates feature quantities from the face image. The biometric information acquisition unit 211 generates feature quantities (feature vectors consisting of multiple feature quantities) that characterize the face image from the acquired face image. Specifically, the biometric information acquisition unit 211 extracts feature points from the acquired face image. Note that existing technologies can be used for the feature point extraction process, so a detailed explanation is omitted. For example, the biometric information acquisition unit 211 extracts eyes, nose, mouth, etc., as feature points from the face image. Then, the biometric information acquisition unit 211 calculates the position of each feature point and the distance between each feature point as feature quantities, and generates a feature vector (vector information that characterizes the face image) consisting of multiple feature quantities.
[0058] The biometric information acquisition unit 211 passes the generated feature quantities to the authentication request unit 213.
[0059] If a user requests terminal authentication, the authentication control unit 202 activates the terminal access unit 212.
[0060] The terminal access unit 212 controls the card reader and reads terminal authentication information (user ID) from the NFC chip of the terminal 30. The terminal access unit 212 then passes the read user ID to the authentication request unit 213.
[0061] The authentication request unit 213 is a means for sending an authentication request to the authentication server 10. Specifically, the authentication request unit 213 generates an authentication request that includes feature quantities generated from the facial image or a user ID, and sends the authentication request to the authentication server 10. Alternatively, the authentication request unit 213 may send an authentication request that includes an authentication terminal ID assigned to its own device to the authentication server 10 (see Figure 7).
[0062] The authentication control unit 202 receives the authentication result (authentication success, authentication failure) from the authentication server 10.
[0063] If the authentication control unit 202 receives an authentication failure, it notifies the user accordingly. For example, the authentication control unit 202 notifies the user of the authentication failure using an LCD panel, speaker, or the like. Alternatively, the authentication control unit 202 may request the authentication server 10 to re-authenticate using the authentication method that was not attempted. For example, if biometric authentication fails, the authentication control unit 202 may display a message as shown in Figure 8 and send an authentication request including the acquired terminal authentication information (user ID) to the authentication server 10.
[0064] When authentication success is received, the authentication control unit 202 notifies the function implementation unit 203 of the user ID, authentication method (biometric authentication, terminal authentication), and the fact that authentication was successful, as included in the response from the authentication server 10.
[0065] The function implementation unit 203 is a means for implementing the functions assigned to the authentication terminal 20. The details of the function implementation unit 203 differ depending on the functions of each terminal and are different from the intent of this disclosure, so a detailed explanation is omitted.
[0066] For example, the functional implementation unit 203 of authentication terminal 20-1, which is a gate device, opens the gate when successful authentication is obtained. The functional implementation unit 203 of authentication terminal 20-2, which is a copier, permits the user to make copies of documents, etc. The functional implementation unit 203 of authentication terminal 20-3, which is a vending machine, processes product dispensing and payment processing.
[0067] The function implementation unit 203 generates detailed action information (detailed information about the actions taken by the user on the authentication terminal 20).
[0068] For example, the functional implementation unit 203 of authentication terminal 20-1 generates detailed behavioral information including the time the gate was opened and the authentication method (biometric authentication, terminal authentication). The functional implementation unit 203 of authentication terminal 20-2 generates detailed behavioral information including the authentication method, the number of copies made, the time, the method (color, monochrome), etc. The functional implementation unit 203 of authentication terminal 20-3 generates detailed behavioral information including the authentication method, the name of the purchased product, the price, the date and time of purchase, etc.
[0069] The function implementation unit 203 hands over the generated detailed behavior information and the user ID of the authenticated user to the registration request unit 204.
[0070] The registration request unit 204 is a means for requesting the authentication server 10 to register detailed behavior information. The registration request unit 204 sends a "registration request" to the authentication server 10 that includes the authentication terminal ID, the user ID of the person who successfully authenticated, and detailed behavior information (see Figure 9).
[0071] If the authentication server 10 provides an affirmative response, the registration request unit 204 does not perform any special action. If the authentication server 10 provides a negative response, the registration request unit 204 performs retransmission processing of the registration request, etc.
[0072] The memory unit 205 is a means for storing information necessary for the operation of the authentication terminal 20.
[0073] [Authentication Server] The authentication server 10 stores biometric information (first biometric information) for performing biometric authentication of the user and terminal authentication information (first terminal authentication information) for performing terminal authentication by the terminal 30. The authentication server 10 authenticates the user using either the biometric information or the terminal authentication information.
[0074] Figure 10 shows an example of the processing configuration (processing module) of the authentication server 10 according to the first embodiment. Referring to Figure 10, the authentication server 10 comprises a communication control unit 301, a user registration unit 302, an authentication request processing unit 303, a registration request processing unit 304, a browsing request processing unit 305, and a storage unit 306.
[0075] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the authentication terminal 20. The communication control unit 301 also transmits data to the authentication terminal 20. The communication control unit 301 passes the data received from other devices to other processing modules. The communication control unit 301 transmits the data obtained from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 301.
[0076] The user registration unit 302 is a means for registering system users. The user registration unit 302 acquires the user's facial image (biometric information) and personal information (name, employee number, etc.). The user registration unit 302 acquires the facial image and personal information by any means necessary.
[0077] For example, when terminal 30 accesses authentication server 10, user registration unit 302 displays a GUI as shown in Figure 11 on terminal 30. The user enters the information shown in Figure 11. After entering all the information, the user presses the "Submit" button and enters their facial image and personal information into authentication server 10.
[0078] The user registration unit 302 acquires facial images and personal information and generates a user ID to assign to the system user. For example, the user registration unit 302 may calculate a hash value of the acquired user information (facial image, personal information) and use that hash value as the user ID to assign to the user. Alternatively, the user registration unit 302 may assign a unique value each time a user is registered and use that as the user ID.
[0079] The user registration unit 302 generates feature quantities that characterize the acquired face image from the face image.
[0080] The user registration unit 302 stores the generated user ID, feature quantities, and personal information in the user information database. The user registration unit 302 then associates the above information (user ID, feature quantities, and personal information) and adds a new entry to the user information database (see Figure 12).
[0081] The user registration unit 302 issues the generated user ID to the terminal 30. At the same time, the user registration unit 302 sends the "authentication terminal ID list" to the terminal 30.
[0082] In this manner, the user registration unit 302 generates a user ID for the user upon obtaining biometric information from the user, and stores the generated user ID as terminal authentication information. The user registration unit 302 then transmits the generated user ID to the terminal 30. The transmitted user ID is stored in the terminal 30 as terminal authentication information (second terminal authentication information).
[0083] The authentication request processing unit 303 is a means for processing authentication requests received from the authentication terminal 20. The authentication request processing unit 303 obtains the authentication request from the authentication terminal 20. The authentication request processing unit 303 extracts feature quantities (biometric information) or user IDs (terminal authentication information) from the authentication request.
[0084] When a feature is extracted, the authentication request processing unit 303 sets the feature as the matching target and performs a matching process with the feature registered in the user information database. More specifically, the authentication request processing unit 303 sets the above feature (feature vector) as the matching target and performs a one-to-many matching with multiple feature vectors registered in the user information database.
[0085] The authentication request processing unit 303 calculates the similarity between the feature quantity to be matched and each of the multiple feature quantities on the registration side. This similarity can be calculated using methods such as the chi-squared distance or the Euclidean distance. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0086] The authentication request processing unit 303 determines whether there are any features among the multiple features registered in the user information database whose similarity to the feature to be matched is greater than or equal to a predetermined value. If such a feature exists, the authentication request processing unit 303 sets the result of the authentication process to "authentication successful". If such a feature does not exist, the authentication request processing unit 303 sets the result of the authentication process to "authentication failed".
[0087] If a user ID is obtained from the authentication request, the authentication request processing unit 303 searches the user information database using the obtained user ID as a key and determines whether there is an entry that matches the user ID. If such an entry exists, the authentication request processing unit 303 sets the result of the authentication process to "authentication successful". If no such entry exists, the authentication request processing unit 303 sets the result of the authentication process to "authentication failed".
[0088] The authentication request processing unit 303 sends the authentication result (authentication successful, authentication failed) to the authentication terminal 20, which is the source of the authentication request. If authentication is successful, the authentication request processing unit 303 sends a response to the authentication terminal 20 that includes the user ID of the person who successfully authenticated. In addition to the authentication result, the authentication request processing unit 303 may also send the personal information of the person who successfully authenticated (name, etc.) to the authentication terminal 20 that sent the request.
[0089] The registration request processing unit 304 is a means for processing registration requests received from the authentication terminal 20. The registration request processing unit 304 receives a registration request from the authentication terminal 20. The registration request processing unit 304 extracts the user ID from the registration request.
[0090] The registration request processing unit 304 searches the activity history database using the retrieved user ID as a key, and if a corresponding entry does not exist, it adds a new entry.
[0091] Figure 13 shows an example of an activity history database. As shown in Figure 13, the activity history database stores activity history (at least one or more activity details) for each user (user ID) for each authentication terminal 20 (for each authentication terminal ID). For example, for a user with user ID "ID01", activity details H11, H12, and H13 are stored as activity history at the gate device (authentication terminal 20-1). Each of the activity details H11 to H13 includes information on the date and time of passing through the gate device and the authentication method (biometric authentication, terminal authentication).
[0092] The registration request processing unit 304 searches the activity history database using the user ID extracted from the registration request as a key, and if a corresponding entry exists, it adds the activity details to the corresponding activity history field of that entry.
[0093] If the registration request from the authentication terminal 20 is processed successfully, the registration request processing unit 304 sends an affirmative response to the authentication terminal 20. If the registration request from the authentication terminal 20 cannot be processed successfully, the registration request processing unit 304 sends a negative response to the authentication terminal 20.
[0094] The browsing request processing unit 305 is a means for processing browsing requests received from terminal 30. The browsing request processing unit 305 extracts the user ID and authentication terminal ID from the browsing request received from terminal 30.
[0095] The access request processing unit 305 searches the activity history database using the extracted user ID and authentication terminal ID as keys and identifies the corresponding activity history (at least one activity details). The access request processing unit 305 then transmits the identified activity history to the terminal 30.
[0096] The memory unit 306 is a means for storing information necessary for the operation of the authentication server 10.
[0097] [Terminal] Figure 14 shows an example of the processing configuration (processing module) of terminal 30 according to the first embodiment. Referring to Figure 14, terminal 30 comprises a communication control unit 401, a user registration unit 402, a browsing request unit 403, an output unit 404, and a storage unit 405.
[0098] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the authentication server 10. The communication control unit 401 also transmits data to the authentication server 10. The communication control unit 401 passes the data received from other devices to other processing modules. The communication control unit 401 transmits the data obtained from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 401.
[0099] The user registration unit 402 is a means of realizing user registration for using the authentication system. The user registration unit 402 operates in conjunction with the user registration unit 302 of the authentication server 10. The user registration unit 402 obtains the information shown in Figure 11 from the user and transmits the obtained information to the authentication server 10.
[0100] When the authentication server 10 completes user registration, the user registration unit 402 obtains the user ID and authentication terminal ID list from the authentication server 10. The user registration unit 402 stores the user ID and authentication terminal ID list in the storage unit 405. Furthermore, the user registration unit 402 stores the user ID in the NFC chip.
[0101] The browsing request unit 403 is a means for sending a browsing request to the authentication server 10. The browsing request unit 403 generates a GUI, for example, as shown in Figure 15, and obtains information of the authentication terminal 20 whose activity history the user wants to check.
[0102] The viewing request unit 403 refers to the authentication terminal ID list and obtains the authentication terminal ID of the authentication terminal 20 that the user wishes to view the activity history of. The viewing request unit 403 sends a viewing request including the user ID and authentication terminal ID to the authentication server 10. The viewing request unit 403 passes the activity history obtained from the authentication server 10 to the output unit 404.
[0103] The output unit 404 is a means for outputting various messages and the like to the outside. For example, the output unit 404 outputs the activity history obtained from the viewing request unit 403 to the LCD panel or the like (see Figure 16).
[0104] The memory unit 405 is a means for storing information necessary for the operation of the terminal 30.
[0105] [System operation] Next, the operation of the access control system according to the first embodiment will be described.
[0106] Figure 17 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment. It is assumed that the system user has been registered prior to the operation shown in Figure 17.
[0107] When a user stands in front of the authentication terminal 20, the authentication terminal 20 obtains the user's preference regarding the authentication method (step S01).
[0108] The authentication terminal 20 sends an authentication request to the authentication server 10 according to the authentication method desired by the user (step S02). If the user desires biometric authentication, the authentication terminal 20 sends an authentication request to the authentication server 10 that includes the user's biometric information (second biometric information). If the user desires terminal authentication, the authentication terminal 20 sends an authentication request to the authentication server 10 that includes terminal authentication information (second terminal authentication information) obtained from terminal 30.
[0109] The authentication server 10 performs an authentication process (matching process) using the acquired biometric information or terminal authentication information (step S03). The authentication server 10 sends the result of the authentication process (authentication success, authentication failure) to the authentication terminal 20.
[0110] If authentication success is received, the authentication terminal 20 performs a predetermined function (for example, unlocking the gate, authorizing copying, etc.) (step S04).
[0111] The authentication terminal 20 sends a registration request to the authentication server 10 that includes detailed behavioral information obtained by performing the predetermined functions described above (step S05). More specifically, the authentication terminal 20 sends a registration request to the authentication server 10 that includes the authentication terminal ID assigned to its device and detailed information about the user's behavior on its device (detailed behavioral information).
[0112] The authentication server 10 stores the detailed behavior information in the behavior history database (step S06). More specifically, the authentication server 10 stores the detailed behavior information in the behavior history database, associating it with the authentication terminal ID.
[0113] Upon user action, terminal 30 sends a browsing request including the authentication terminal ID to the authentication server 10 at any time (step S11).
[0114] The authentication server 10 sends at least one piece of detailed information about an action corresponding to the authentication terminal ID included in the browsing request to the terminal 30 as "action history" (step S12).
[0115] Terminal 30 displays the received activity history (details of at least one activity) (step S13).
[0116] As described above, the authentication system according to the first embodiment supports both authentication using a mobile terminal (terminal 30) and authentication using biometric information for the use of various facilities. As a result, user convenience can be enhanced. For example, with authentication using only terminal 30, it is necessary to take out terminal 30 each time you pass through a gate. However, since the gate device supports biometric authentication, users can pass through the gate simply by moving in front of the gate device. Furthermore, with biometric authentication, there is a possibility of authentication failure due to changes in the environment or appearance when acquiring facial images. Even in such cases, if the user has terminal 30, they can enter and exit simply by holding terminal 30 over the gate device.
[0117] Furthermore, terminal 30 can also display information resulting from the authentication process (detailed activity information, activity history). For example, if a user passes through a gate using biometric authentication, the user can be aware of the fact that they have passed through. Alternatively, if a user makes a purchase using biometric authentication, the user can check the details of the purchase (purchased items, purchase price, purchase date and time, etc.) via terminal 30.
[0118] [Second Embodiment] Next, a second embodiment will be described in detail with reference to the drawings.
[0119] In the first embodiment, authentication was performed according to the authentication method selected by the user. In the second embodiment, a case in which the authentication terminal 20 automatically selects the authentication method will be described.
[0120] Since the configuration of the authentication system according to the second embodiment can be the same as that of the first embodiment, the explanation corresponding to Figure 2 is omitted. Also, since the processing configurations of the authentication server 10, authentication terminal 20, and terminal 30 according to the second embodiment can be the same as those of the first embodiment, their explanations are omitted.
[0121] The following will focus on explaining the differences between the first and second embodiments.
[0122] The authentication control unit 202 of the authentication terminal 20 executes the biometric information acquisition unit 211 and the terminal access unit 212 in parallel to attempt to acquire biometric information and terminal authentication information. The authentication request unit 213 sends an authentication request to the authentication server 10 corresponding to the biometric information and terminal authentication information that was acquired first. That is, if the user's face image is captured and the terminal authentication information (user ID) is successfully read from the terminal 30 before feature quantities are generated from the face image, the authentication request unit 213 sends an authentication request using terminal authentication. In this way, the authentication terminal 20 may request authentication from the authentication server 10 using an authentication method corresponding to the biometric information and terminal authentication information that was acquired first.
[0123] The authentication control unit 202 may determine the authentication method according to the elapsed time since detecting the user in front of it. For example, if terminal authentication information (user ID) can be obtained from terminal 30 within a predetermined time (e.g., 1 second) after detecting the user in front of it, the authentication control unit 202 instructs the authentication request unit 213 to send an authentication request by terminal authentication. On the other hand, if terminal authentication information cannot be obtained even after the predetermined time has elapsed (i.e., the user does not touch terminal 30 to the card reader), the authentication control unit 202 instructs the authentication request unit 213 to send an authentication request by biometric authentication. In this way, if the authentication terminal 20 can obtain terminal authentication information within a predetermined time after detecting the user, it may request authentication by terminal authentication from the authentication server 10.
[0124] The authentication control unit 202 may prioritize one of the two authentication methods. For example, as soon as the biometric information acquisition unit 211 finishes generating biometric information (features), the authentication control unit 202 instructs the authentication request unit 213 to send a biometric authentication request. Also, if the authentication control unit 202 recognizes that the terminal 30 has made contact with the card reader via the terminal access unit 212 before the biometric authentication result is obtained, it sends a cancellation notice for the previously sent authentication request (biometric authentication request) to the authentication server 10. Subsequently, the authentication control unit 202 instructs the authentication request unit 213 to send an authentication request including terminal authentication information obtained from the terminal 30. In this way, if the authentication terminal 20 obtains terminal authentication information before receiving the biometric authentication result from the authentication server 10, it sends a cancellation notice for biometric authentication to the authentication server 10. Subsequently, the authentication terminal 20 requests authentication from the authentication server 10 using the obtained terminal authentication information.
[0125] The authentication terminal 20 may perform pre-verification (verification performed before sending an authentication request) of the acquired biometric information and terminal authentication information, and take action according to the results. Specifically, the authentication terminal 20 may verify the validity of the biometric information and terminal authentication information, and determine the authentication method to request from the authentication server 10 according to the results of the validity verification.
[0126] For example, the biometric information acquisition unit 211 checks the quality of the face image before generating features. For example, the biometric information acquisition unit 211 calculates the size and brightness of the face region. If these values do not fall within a predetermined range, the authentication control unit 202 determines that the face image is unsuitable for biometric authentication. In this case, the authentication control unit 202 does not choose to send an authentication request using the acquired biometric information. For example, the authentication control unit 202 may display a message prompting the user to touch the terminal 30 to the card reader, as shown in Figure 18(a). Alternatively, the authentication control unit 202 may display a message prompting the user to adjust their position, etc., so that an appropriate face image can be obtained, as shown in Figure 18(b).
[0127] Alternatively, the authentication control unit 202 may verify the validity of the terminal authentication information (user ID) obtained from the terminal 30. For example, if a numerical range of user IDs that will succeed in authentication is predetermined, the authentication control unit 202 will not choose to send an authentication request using the obtained terminal authentication information if the obtained user ID does not fall within that numerical range. Alternatively, if an error detection code (checksum) is attached to the user ID stored in the terminal 30, the authentication control unit 202 may use the checksum to verify the validity of the terminal authentication information. If the obtained terminal authentication information is not valid, the authentication control unit 202 may choose biometric authentication or display a message prompting the terminal 30 to be touched again.
[0128] As described above, in the authentication system according to the second embodiment, feature quantities are extracted from the facial image captured by the authentication terminal 20, and the extracted feature quantities are compared with the feature quantities registered in the user information database to identify the user. Furthermore, in the authentication system according to the second embodiment, the authentication terminal 20 automatically selects the authentication method. As a result, user convenience can be further improved.
[0129] [Third Embodiment] Next, a third embodiment will be described in detail with reference to the drawings.
[0130] In the third embodiment, we will describe an authentication server 10 that makes it easy to understand the usage status of each authentication method when two authentication methods (biometric authentication and terminal authentication) are used in combination.
[0131] The configuration of the authentication system according to the third embodiment can be the same as that of the first embodiment, so the explanation corresponding to Figure 2 is omitted. Also, the processing configurations of the authentication terminals 20 and 30 according to the third embodiment can be the same as those of the first embodiment, so their explanations are omitted.
[0132] The following will focus on explaining the differences between the first to third embodiments.
[0133] Figure 19 shows an example of the processing configuration (processing module) of the authentication server 10 according to the third embodiment.
[0134] Referring to Figure 19, the authentication server 10 according to the third embodiment includes an activity history analysis unit 307.
[0135] The behavioral history analysis unit 307 is a means for analyzing the behavioral history of each user stored in the behavioral history database. For example, the behavioral history analysis unit 307 uses the detailed behavioral information stored in the behavioral history database to perform an analysis of the authentication method performed by the authentication terminal 20.
[0136] For example, the behavioral history analysis unit 307 calculates the ratio of biometric authentication to terminal authentication performed for each authentication terminal 20 over a predetermined period (e.g., 1 hour, 1 day, 1 month). Specifically, the behavioral history analysis unit 307 calculates the total number of authentications performed during the predetermined period (total number of behavioral details). The behavioral history analysis unit 307 calculates the ratio of each authentication method performed (usage ratio) by dividing the number of biometric authentications and terminal authentications performed at each authentication terminal 20 by the above total.
[0137] For example, the behavioral history analysis unit 307 outputs analysis results (implementation rate for each authentication method at each authentication terminal) as shown in Figure 20. Administrators and others who see the analysis results shown in Figure 20 investigate the causes of the varying usage rates for each authentication terminal 20 and consider improving or adding more authentication terminals 20 as necessary. Alternatively, the behavioral history analysis unit 307 may make suggestions such as changing the layout or number of authentication terminals 20 based on the analysis results.
[0138] The calculation of the implementation rate for each authentication method by the behavioral history analysis unit 307 is an example and is not intended to limit the scope of analysis by the behavioral history analysis unit 307. For example, the authentication server 10 stores the details of the authentication process (authentication method, authentication result) for each authentication terminal 20. The behavioral history analysis unit 307 may calculate the "authentication failure rate" for each authentication terminal 20 from the stored details of the authentication process.
[0139] Alternatively, the behavioral history analysis unit 307 may display the number of times each authentication method was performed (number of successful authentications) during a predetermined period, instead of the usage rate of each authentication method as shown in Figure 20. In this case, the behavioral history analysis unit 307 may also display the total number of authentications during the predetermined period (sum of biometric authentication and terminal authentication).
[0140] Furthermore, the analysis results from the behavioral history analysis unit 307 can be used for various purposes. For example, the behavioral history analysis unit 307 may send notifications to users (employees, etc.) who have a low rate of using biometric authentication, encouraging them to use biometric authentication more actively.
[0141] As described above, the authentication server 10 according to the third embodiment analyzes the accumulated behavioral history for each user and provides useful information to system administrators and others.
[0142] Next, we will describe the hardware of each device that makes up the authentication system. Figure 21 shows an example of the hardware configuration of the authentication terminal 20.
[0143] The authentication terminal 20 has the configuration illustrated in Figure 21. For example, the authentication terminal 20 includes a processor 311, memory 312, input / output interface 313, communication interface 314, camera 315, and card reader 316, etc. The components such as the processor 311 are connected by an internal bus or the like and are configured to communicate with each other.
[0144] However, the configuration shown in Figure 21 is not intended to limit the hardware configuration of the authentication terminal 20. The authentication terminal 20 may include hardware not shown, and it may not have an input / output interface 313 if necessary. Also, the number of processors 311 etc. included in the authentication terminal 20 is not intended to be limited to the example in Figure 21; for example, multiple processors 311 may be included in the authentication terminal 20.
[0145] The processor 311 is a programmable device such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), or DSP (Digital Signal Processor). Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit). The processor 311 executes various programs, including an operating system (OS).
[0146] Memory 312 includes RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), etc. Memory 312 stores the OS program, application programs, and various data.
[0147] The input / output interface 313 is an interface for a display device or input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user input such as a keyboard or mouse.
[0148] The communication interface 314 is a circuit, module, etc., that communicates with other devices. For example, the communication interface 314 includes a NIC (Network Interface Card), etc.
[0149] Camera 315 acquires the user's biometric information (facial image), and card reader 316 accesses the NFC chip of terminal 30.
[0150] The functions of the authentication terminal 20 are realized by various processing modules. These processing modules are realized, for example, by the processor 311 executing a program stored in memory 312. The program can also be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as semiconductor memory, hard disk, magnetic recording medium, or optical recording medium. In other words, the present invention can also be embodied as a computer program product. Furthermore, the program can be downloaded via a network or updated using the storage medium on which the program is stored. Moreover, the processing module may be realized by a semiconductor chip.
[0151] The authentication server 10 and terminal 30 can be configured in the same way as the authentication terminal 20, and their basic hardware configurations are identical to those of the authentication terminal 20, so their explanation will be omitted. The authentication server 10 and terminal 30 do not require cameras or card readers. Terminal 30 is equipped with an NFC chip.
[0152] The authentication terminal 20 is equipped with a computer, and its functions can be realized by having the computer execute a program. Furthermore, the authentication terminal 20 executes a control method for the authentication terminal through this program.
[0153] [Differentiation] The configuration and operation of the authentication system described in the above embodiment are illustrative examples and are not intended to limit the system configuration.
[0154] In the above embodiment, the authentication system was described using the example of identity verification in an office where a copier or the like is installed, but the authentication system disclosed in this application may also be applied to identity verification in a factory or the like.
[0155] In the above embodiment, the case in which a user ID is used as terminal authentication information was described, but other information may be used as terminal authentication information. For example, an employee number may be used as terminal authentication information. In other words, any information that can uniquely identify a user in the authentication system may be used as terminal authentication information.
[0156] In the above embodiment, an example was described in which an authentication terminal ID is determined according to the type of authentication terminal 20. However, the authentication terminal ID may be determined in a way that identifies each authentication terminal 20 included in the system. For example, each authentication terminal 20 may be distinguished by adding a sub-number to the authentication terminal ID described above. For example, if the system includes two gate devices, each gate device may be assigned an authentication terminal ID such as "T01-1" and "T01-2".
[0157] Alternatively, if an authentication terminal ID is determined in a way that distinguishes each authentication terminal 20, terminal 30 may request to view the activity history for an individual authentication terminal 20, or it may request to view the activity history for authentication terminals 20 of the same type. In the above example, if "T01-1" is included in the viewing request as the authentication terminal ID, the authentication server 10 returns the activity history for the gate device corresponding to that ID to terminal 30. Alternatively, if "T01" is included in the viewing request as the authentication terminal ID, the authentication server 10 returns the activity history for the entire gate device (two gate devices) to terminal 30.
[0158] The browsing request sent by terminal 30 may include information about the range of behavioral history that the user wishes to view. For example, terminal 30 may send a browsing request to the authentication server 10 that includes the period and number of behavioral history entries to be viewed. The authentication server 10 extracts behavioral history entries (at least one set of behavioral details) that fit the specified range and sends them to terminal 30.
[0159] Alternatively, the authentication method (biometric authentication, terminal authentication) to be performed for each authentication terminal 20 may be registered in advance. For example, for authentication at a gate device (authentication terminal 20-1), convenience is prioritized and biometric authentication is selected. In contrast, for authentication (payment processing) at a vending machine (authentication terminal 20-3), reliability is prioritized and terminal authentication is selected. In the authentication system disclosed in this application, a mechanism is provided to obtain the user's preference in order to realize the above pre-selection of authentication methods. Specifically, terminal 30 displays a GUI as shown in Figure 22 and obtains the authentication method to be performed at each authentication terminal 20. Terminal 30 and authentication terminals 20 communicate with each other using a proximity wireless communication means such as Bluetooth®. Authentication terminal 20 obtains the user's preferred authentication method from terminals 30 located near its own device and selects authentication using the obtained authentication method. The obtained authentication method may be treated as the preferred authentication method among the two authentication methods.
[0160] In the above embodiment, the case in which the user is provided with the activity history for each authentication terminal 20 (for the user to view) was described, but the user may be provided with an activity history that covers all authentication terminals 20. For example, terminal 30 adds an item called "All Terminals" to the display shown in Figure 15. When the authentication server 10 receives a viewing request that includes "All Terminals", it sends the activity history spanning multiple authentication terminals 20 related to the user ID included in the viewing request to terminal 30. In the example in Figure 13, when a viewing request including "ID01" as the user ID is received, the activity history (detailed activity information) for H11-H13, H21-H23, and H31-H33 is sent to terminal 30. Terminal 30 displays the acquired activity history. At that time, terminal 30 displays the acquired detailed activity information in chronological order (see Figure 23).
[0161] In the above embodiment, the authentication server 10 was described as collecting (storing) the user's activity history in accordance with the registration request received from the authentication terminal 20. However, the authentication server 10 may also store information obtained from devices, equipment, etc. other than the authentication terminal 20 as "activity history". For example, if camera equipment is installed in the elevator hall or cafeteria, the authentication server 10 may accumulate the user's activity history by analyzing the images obtained from the camera equipment. In this case, the time when the user used the elevator, etc., will be accumulated as activity history. The authentication server 10 only needs to identify the user (user ID) using the images obtained from the camera equipment.
[0162] In the above embodiment, the case in which the authentication server 10 stores the activity history was described, but this function may be handled by another server. Specifically, the system may include a server (database server) that has the function of processing registration requests from the authentication terminal 20, processing browsing requests from the terminal 30, and managing the activity history database. Alternatively, the authentication server 10 may not have a user information database as shown in Figure 12, and the system may include a database server that manages the user information database.
[0163] In the above embodiment, the case in which the authentication request includes either biometric information (feature) or terminal authentication information (user ID) has been described, but the authentication terminal 20 may include both of these pieces of information in a single authentication request. Specifically, if both pieces of information can be obtained within a predetermined period, the authentication terminal 20 may send an authentication request including both biometric information and terminal authentication information to the authentication server 10. In this case, the authentication server may determine "authentication successful" if authentication using either piece of information is successful, or it may determine "authentication successful" if authentication using both pieces of information is successful.
[0164] The user information database and behavioral history database described in the above embodiments are illustrative examples and are not intended to limit the contents stored in each database. For example, the user information database may store facial images in place of, or in addition to, feature quantities.
[0165] In the above embodiment, the case in which biometric information relating to "feature quantities generated from a face image" is transmitted from the authentication terminal 20 to the authentication server 10 was described. However, biometric information relating to the "face image" may also be transmitted from the authentication terminal 20 to the authentication server 10. In this case, the authentication server 10 only needs to generate feature quantities from the acquired face image and perform the authentication process (matching process).
[0166] The form of data transmission and reception between each device (authentication server 10, authentication terminal 20, terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Biometric information is transmitted and received between these devices, and in order to properly protect such biometric information, it is desirable that encrypted data be transmitted and received.
[0167] In the flowcharts (sequence diagrams) used in the above description, multiple processes (processes) are shown in order, but the execution order of the processes performed in the embodiment is not limited to the order in which they are shown. In the embodiment, the order of the illustrated processes can be changed to the extent that it does not impair the content, for example, by executing each process in parallel.
[0168] The embodiments described above are explained in detail to facilitate understanding of the disclosure, and it is not intended that all the configurations described above are necessary. Furthermore, when multiple embodiments are described, each embodiment may be used individually or in combination. For example, it is possible to replace parts of the configuration of one embodiment with those of another embodiment, or to add configurations from other embodiments to the configuration of one embodiment. In addition, it is possible to add, delete, or replace parts of the configuration of one embodiment with those of another.
[0169] As described above, the industrial applicability of the present invention is clear, and it is particularly suitable for applications such as identity verification in companies and other organizations.
[0170] Some or all of the above embodiments may also be described as follows, but are not limited to the following: [Note 1] The device owned by the user, An authentication server that stores first biometric information for performing biometric authentication of the user and first terminal authentication information for performing terminal authentication by the terminal, An authentication terminal corresponding to the aforementioned biometric authentication and terminal authentication, An authentication system that includes this. [Note 2] The authentication terminal transmits an authentication request to the authentication server, which includes the user's second biometric information, as described in Appendix 1. [Note 3] The authentication system described in Appendix 1, wherein the authentication terminal transmits an authentication request to the authentication server, which includes a second terminal authentication information obtained from the terminal. [Note 4] The authentication terminal is an authentication system according to any one of the appendices 1 to 3, which obtains the user's preference regarding which of the biometric authentication and terminal authentication methods to use. [Note 5] The authentication terminal sends a registration request to the authentication server that includes the authentication terminal ID assigned to the device and detailed information regarding the user's actions on the device. The authentication server is an authentication system according to any one of the appendices 1 to 4, which stores the authentication terminal ID in association with the detailed information. [Note 6] The terminal sends a browsing request including the authentication terminal ID to the authentication server. The authentication server transmits the detailed information corresponding to the authentication terminal ID to the terminal, as described in Appendix 5. [Note 7] The authentication system according to any one of Appendix 1 to 6, wherein the authentication server generates a user ID for the user in response to obtaining the first biometric information from the user, and stores the generated user ID as the first terminal authentication information. [Note 8] The authentication server transmits the generated user ID to the terminal. The authentication system described in Appendix 7, referencing Appendix 3, stores the user ID as the second terminal authentication information. [Note 9] The authentication system described in any one of Appendix 1 to 8, wherein the first biometric information is a facial image or a feature quantity generated from a facial image. [Note 10] The authentication system described in Appendix 3 stores the second terminal authentication information in an NFC (Near Field Communication) compatible IC (Integrated Circuit) chip. [Note 11] The authentication system described in Appendix 4, wherein the authentication terminal generates a GUI (Graphical User Interface) for obtaining the user's preference regarding which of the biometric authentication and terminal authentication methods to use. [Note 12] The authentication system according to any one of the appendices 1 to 3, wherein the authentication terminal requests the authentication server to perform authentication using an authentication method corresponding to the first biometric information and the first terminal authentication information that was obtained first. [Note 13] The authentication system according to any one of the appendices 1 to 3, wherein if the authentication terminal is able to obtain the first terminal authentication information within a predetermined time after detecting the user, it requests authentication by terminal authentication from the authentication server. [Note 14] The authentication system according to any one of Appendix 1 to 3, wherein if the authentication terminal obtains the first terminal authentication information before receiving the biometric authentication result from the authentication server, it sends a notification to the authentication server to revoke the biometric authentication and requests the authentication server to perform authentication using the obtained first terminal authentication information. [Note 15] The authentication system according to any one of Appendix 1 to 3, wherein the authentication terminal verifies the validity of the first biometric information and the first terminal authentication information, and determines the authentication method to request from the authentication server according to the result of the validity verification. [Note 16] The authentication system according to Appendix 5 or 6, further comprising an analysis unit that performs an analysis of the authentication method performed at the authentication terminal using the stored detailed information, wherein the authentication server is further a part of the analysis unit. [Note 17] The authentication system described in Appendix 16, wherein the analysis unit calculates the implementation ratio of biometric authentication and terminal authentication during a predetermined period. [Note 18] A biometric information acquisition unit that acquires the user's biometric information, A terminal access unit accesses the terminal owned by the user and obtains terminal authentication information for performing authentication using the terminal. An authentication request unit that, when it obtains the aforementioned biometric information, sends an authentication request including the aforementioned biometric information to the authentication server, and when it obtains the aforementioned terminal authentication information, sends the aforementioned authentication request including the aforementioned terminal authentication information to the authentication server, An authentication terminal equipped with the necessary components. [Note 19] On the authentication terminal, By acquiring the user's biometric information, Access the terminal owned by the user and obtain terminal authentication information for performing authentication using the terminal. A method for controlling an authentication terminal, comprising: when the aforementioned biometric information is obtained, sending an authentication request including the aforementioned biometric information to the authentication server; and when the aforementioned terminal authentication information is obtained, sending an authentication request including the aforementioned terminal authentication information to the authentication server. [Note 20] On the computer installed in the authentication terminal, The process of acquiring the user's biometric information, The process involves accessing the terminal owned by the user and obtaining terminal authentication information for performing authentication using the terminal, When the aforementioned biometric information is obtained, the authentication request including the aforementioned biometric information is sent to the authentication server; when the aforementioned terminal authentication information is obtained, the authentication request including the aforementioned terminal authentication information is sent to the authentication server; A computer-readable storage medium that stores a program for executing a computer.
[0171] Furthermore, each disclosure of the above-mentioned prior art documents cited herein is incorporated herein by reference. Although embodiments of the present invention have been described above, the present invention is not limited to these embodiments. It will be understood by those skilled in the art that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. That is, the present invention naturally includes the entire disclosure, including the claims, and various modifications and alterations that can be made by those skilled in the art in accordance with the technical idea. [Explanation of symbols]
[0172] 10, 102 Authentication Server 20, 20-1~20-3, 103 Authentication terminals 30, 101 terminals 201, 301, 401 Communication Control Unit 202 Authentication Control Unit 203 Functional Implementation Unit 204 Registration Request Section 205, 306, 405 Storage section 211 Biological Information Acquisition Unit 212 Terminal Access Section 213 Authentication Request Section Rooms 302 and 402: User Registration Section 303 Authentication Request Processing Unit 304 Registration Request Processing Unit 305 Viewing Request Processing Unit 307 Behavioral History Analysis Department 311 Processors 312 memory 313 Input / Output Interfaces 314 Communication Interface 315 Camera 316 Card Reader 403 Access Request Section 404 Output Section
Claims
1. An authentication control unit that controls biometric authentication using the user's first biometric information and media authentication using the first media authentication information of a medium possessed by the user, A receiving unit receives a registration request from the first authentication terminal, which includes the authentication terminal ID assigned to the first authentication terminal and information regarding the successful authentication method, when the biometric authentication using the first biometric information acquired by the first authentication terminal or the media authentication using the first media authentication information acquired by the first authentication terminal is successful. A registration unit registers the user by associating the authentication terminal ID with the details of the successful authentication method. An information processing apparatus comprising: an output unit that outputs the detailed information corresponding to the authentication terminal ID in response to receiving a viewing request that includes the authentication terminal ID.
2. The information processing apparatus according to claim 1, wherein the output unit outputs the detailed information corresponding to the authentication terminal ID to the medium in response to receiving a viewing request including the authentication terminal ID from the medium used by the user.
3. The information processing apparatus according to claim 1 or 2, wherein, in response to obtaining the first biometric information from the user, a user ID of the user is generated, and the generated user ID is stored as the first media authentication information.
4. The information processing apparatus according to claim 3, wherein the output unit outputs the generated user ID to the medium.
5. The information processing device is This system controls biometric authentication using the user's primary biometric information and media authentication using the primary media authentication information of a medium possessed by the user. When the biometric authentication using the first biometric information acquired by one authentication terminal or the media authentication using the first media authentication information acquired by one authentication terminal is successful, the authentication terminal receives a registration request from one authentication terminal that includes the authentication terminal ID assigned to the first authentication terminal and information regarding the successful authentication method. For the aforementioned user, the authentication terminal ID and detailed information regarding the successful authentication method are registered in association with each other. An information processing method that outputs the detailed information corresponding to the authentication terminal ID in response to receiving a viewing request that includes the authentication terminal ID.
6. On the computer, An authentication control process that controls biometric authentication using the user's first biometric information and media authentication using the first media authentication information of a medium possessed by the user, When the biometric authentication using the first biometric information acquired by one authentication terminal or the media authentication using the first media authentication information acquired by one authentication terminal is successful, a receiving process is performed to receive a registration request from one authentication terminal that includes the authentication terminal ID assigned to one authentication terminal and information regarding the successful authentication method. For the aforementioned user, a registration process is performed to register the authentication terminal ID and the detailed information regarding the successful authentication method in association with each other. Upon receiving a viewing request that includes the authentication terminal ID, an output process is performed to output the detailed information corresponding to the authentication terminal ID, A program to execute.
7. An authentication server equipped with an authentication control unit that controls biometric authentication using the user's first biometric information and media authentication using first media authentication information of a medium possessed by the user, An authentication terminal that acquires the first biometric information and the first media authentication information, Includes, When the authentication terminal successfully performs biometric authentication using the first biometric information acquired by its device or media authentication using the first media authentication information acquired by its device, it sends a registration request to the authentication server that includes the authentication terminal ID assigned to its device and information regarding the successful authentication method. The authentication server registers the user by associating the authentication terminal ID with the details of the successful authentication method, and the authentication system outputs the details corresponding to the authentication terminal ID when it receives a viewing request that includes the authentication terminal ID.
Citation Information
Patent Citations
System for collecting and managing usage history of user and subject of monitoring
JP2007086837A
Impersonation detection device
JP2008107942A
Image processing device
JP2015036975A
Information processing device and program
JP2016167111A
Image forming apparatus
JP2016196099A