Authentication device, authentication method, and authentication program
The authentication system generates avatars from full-body scan data and uses blockchain for decentralized identity, addressing forgery issues and enhancing security and privacy in biometric authentication.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- HUMANITY VISION CONTRACT CO LTD
- Filing Date
- 2025-03-06
- Publication Date
- 2026-04-14
AI Technical Summary
Existing biometric authentication technologies are insufficient to counter advanced forgery techniques and lack comprehensive security and privacy protection.
An authentication system that generates an avatar in a virtual space using full-body scan data and issues a certificate linked to this avatar, utilizing blockchain technology for decentralized identity to enhance security and reliability.
Provides more detailed personal authentication data, ensuring reliable authentication and preventing information tampering, while allowing users to manage their identity and choose preferred authentication methods for enhanced privacy.
Smart Images

Figure 0007845724000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication device, an authentication method, and an authentication program.
Background Art
[0002] In recent years, authentication technologies using personal physical characteristics have attracted attention. This includes fingerprint authentication, iris authentication, face authentication, etc. This biometric authentication is widely implemented because, unlike IC cards and one-time passwords, it does not get lost, has a low risk of theft, reduces the management burden, and enables speedy authentication by using physical characteristics. For example, Patent Document 1 discloses a technique for performing substantially continuous biometric authentication of an individual in real time using eye movements.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] These technologies are important from the viewpoints of enhancing security and protecting personal privacy. However, in these existing technologies, since only some physical characteristics are used, they may be insufficient to counter more advanced forgery techniques.
[0005] The present invention relates to an authentication device and method based on user body information. In particular, by generating an avatar in a virtual space using full-body scan data and issuing a certificate linked to this avatar, the user's physical characteristics can be comprehensively grasped, and more accurate authentication can be achieved. By utilizing blockchain technology in a decentralized identity, a system can be provided that can prevent information tampering and ensure reliability. [Means for solving the problem]
[0006] An authentication device according to one embodiment of the present invention may include a reception unit that receives body scan data obtained by scanning the user's entire body, an avatar generation unit that generates an avatar in a virtual space based on the body scan data, an issuing unit that issues a certificate based on a decentralized identity based on the body scan data, and an authentication unit that links the avatar with the certificate.
[0007] In an authentication device according to one embodiment of the present invention, the body scan data includes data scanned from the iris or data scanned from the pupil, and the receiving unit receives the iris scan data and the pupil scan data, and may perform eye-based authentication based on the iris scan data and the pupil scan data.
[0008] In an authentication device according to one embodiment of the present invention, the authentication unit may be capable of authentication based on a portion of body scan data selected by the user.
[0009] An authentication method according to one embodiment of the present invention may include a computer performing a reception step of receiving body scan data of a user, an avatar generation step of generating an avatar in a virtual space based on the body scan data, an issuance step of issuing a certificate based on a distributed identity based on the body scan data, and an authentication step of linking the avatar with the certificate.
[0010] An authentication program according to one embodiment of the present invention may cause a computer to execute a reception function for receiving body scan data of a user, an avatar generation function for generating an avatar in a virtual space based on the body scan data, an issuance function for issuing a certificate using decentralized identity based on the body scan data, and an authentication function for linking the avatar with the certificate. [Effects of the Invention]
[0011] As described above, the present invention provides a technology that scans the user's entire body and uses that data to generate an individual avatar, thereby obtaining more detailed personal authentication data and enabling more reliable authentication of the individual's presence. [Brief explanation of the drawing]
[0012] [Figure 1] Figure 1 is a schematic diagram of an authentication device according to one embodiment of the present invention. [Figure 2] Figure 2 is an example of a functional block diagram of an authentication device according to one embodiment of the present invention. [Figure 3] Figure 3 is a flowchart showing an example of an authentication method according to one embodiment of the present invention. [Modes for carrying out the invention]
[0013] Hereafter, an embodiment of the invention described herein (also referred to as the present invention) will be explained using the figures. Note that the figures are examples only, and the present invention is not limited to those shown in the figures. For example, the illustrated block diagrams of servers and user terminals, the flowcharts, etc., are examples only, and the present invention is not limited to these.
[0014] Furthermore, in this specification, "virtual space" refers to a virtual information space that does not exist physically, constructed on an authentication device (computer) or network, and includes the so-called "metaverse," which is a space in which users can interact with others by operating avatars. "Avatar" refers to a character object that personifies a person, animal, living creature, object, etc., and may also be called a "digital human (virtual human)."
[0015] Figure 1 shows a diagram of the configuration of an authentication device 10 according to one embodiment of the present invention. The authentication device 10 is an authentication device that generates an avatar in a virtual space and a certificate based on decentralized identity using the user's full-body scan data, and links them together. Alternatively, the authentication device 10 may be an authentication system that digitizes multiple data and creates an avatar in a virtual space.
[0016] The authentication device 10 includes at least a server 100, a database server 400, and user terminals 200 (200A, 200B). The server 100 is connected to the user terminals 200A and 200B via a network 500, and transmits and receives various information with the user terminals 200, as well as performing various processes related to the authentication device. In Figure 1, only one server 100 is shown, but it is not limited to this, and there may be multiple servers. Furthermore, the server 100 is a distributed server system that operates cooperatively by communicating via a network, and may include edge servers or so-called cloud servers. In other words, the server 100 is not limited to physical servers, but may also include virtual servers.
[0017] Network 500 may include wireless networks and wired networks, and may include, for example, wireless LANs (WLANs), wide area networks (WANs), ISDNs (integrated service digital networks), wireless LANs, CDMA (code division multiple access), LTE (long term evolution), LTE-Advanced, 4th generation communication (4G), 5th generation communication (5G), and 6th generation communication (6G) and later mobile communication systems, or combinations thereof.
[0018] The user terminals 200A and 200B may be the communication terminals of users who utilize the virtual space service provided by the authentication device 10. In FIG. 1, only two user terminals related to users A and B are shown as user terminals 200A and 200B respectively. However, the number of user terminals may be the same as the number of users who utilize the virtual space service, and when not particularly distinguished, they may simply be referred to as user terminal 200.
[0019] An application (hereinafter also referred to as "app") for utilizing the virtual space service provided by the authentication device 10 may be installed in the user terminal 200, and various types of information may be transmitted and received between the user terminal 200 and the server 100. Note that the installation of the app in the user terminal 200 is not essential, and the user terminal 200 and the server 100 may transmit and receive various types of information via a web browser.
[0020] In FIG. 1, a smartphone is shown as the user terminal 200A and a notebook computer is shown as the user terminal 200B. However, the user terminal 200 may be any terminal that can realize the functions described in the embodiments to be described hereinafter. For example, the user terminal 200 may be a computer (e.g., a tablet), a handheld computer device (by way of example and not limitation, a PDA (personal digital assistant), a wearable terminal (such as a glasses-type device, a watch-type device, etc.), an HMD (Head Mount Display)).
[0021] The database server 400 stores (holds) various types of information (data) used by the server 100. In FIG. 1, only one database server 400 is shown separately from the server 100, but it may be integrated into the server 100. That is, the database server 400 may be the volatile memory or non-volatile memory of the server 100. Also, the database server 400 may be composed of a plurality of storage devices. Note that the database server 400 may be connected to the server 100 via a dedicated internal network different from the network 500, or may be connected to the server 100 via the network 500.
[0022] <User terminal> FIG. 2 is a configuration diagram of a user terminal 200 according to an embodiment of the present invention. Using FIG. 2, the hardware configuration and functional configuration of the user terminal 200 according to an embodiment of the present invention will be described.
[0023] (1) Hardware configuration of the user terminal The user terminal 200 includes a control unit 210, a communication unit 220, a display unit 230, an input / output unit 240, a scan unit 250, and a storage unit 270.
[0024] The control unit 210 is typically a processor and is implemented by a central processing unit (CPU), a micro processing unit (MPU), a graphics processing unit (GPU), etc. The control unit 210 reads a program stored in the storage unit 270 and executes the code or instructions included in the read program to execute the functions and methods shown in each embodiment. <,
[0025] The communication unit 220 may be implemented as hardware such as a NIC (Network Interface Card), communication software, or a combination thereof, and may send and receive various data with the server 100 via the network 500. This communication may be performed via wired or wireless connection, and any communication protocol may be used as long as communication between the two parties is possible. If the communication unit 220 is composed of a physically structured circuit, it may be referred to as a communication circuit.
[0026] The display unit 230 is a monitor that displays data according to the display data written to the frame buffer, and may be, for example, a touch panel, a touch display, etc.
[0027] The input / output unit 240 may include an input device for inputting various operations to the user terminal 200, and an output device for outputting processing results processed by the user terminal 200. The input / output unit 240 may have the input device and output device integrated, or they may be separated into an input device and an output device. The input device may be any of all types of devices capable of receiving input operations from the user terminal 200 and transmitting information related to said input to the control unit 210, or a combination thereof. The input device may include, for example, a touch panel, a touch display, a camera, or a microphone. The output device may output processing results processed by the control unit 210. The output device may include, for example, a display, a touch panel, a speaker, or the like.
[0028] The scanning unit 250 may include a device that scans the user's body and creates scan data. Scanning may be the process of converting a physical object into digital data. Generally, scanning may be the process of making images and information readable by a computer and saved as a digital format. The scan data may be a full-body scan.
[0029] The storage unit 270 stores various programs and data necessary for the operation of the user terminal 200. The storage unit 270 may include, for example, flash memory, and may also include memory (such as RAM (Random Access Memory) or ROM (Read Only Memory)) that provides a working area for the control unit 210.
[0030] (2) Functional configuration of user terminals The user terminal 200 includes a control unit 210. The control unit 210 controls communication between the user terminal 200 and the server 100 via the network 500 by the communication unit 220, and performs the sending and receiving of various information. The control unit 210 also controls the display of data on the display unit 230, for example, by displaying a screen on the display unit 230 corresponding to the information transmitted from the server 100. Furthermore, the control unit 210 controls the transmission of various information to external devices via the input / output unit 240, for example, by transmitting various information to each functional unit in response to input operations of the user terminal 200 received by the input device, or by transmitting information from each functional unit to output devices (not shown) such as a touch panel, monitor, and speaker.
[0031] <server> Figure 2 is a configuration diagram of server 100 according to one embodiment of the present invention. The hardware configuration and functional configuration of server 100 according to one embodiment of the present invention will be explained using Figure 2.
[0032] (Server hardware configuration) Server 100 comprises a control unit 110, a communication unit 120, an input / output unit 130, and a storage unit 170 as its hardware configuration. Although not shown in the figures, Server 100 may also have a configuration that is typical of a standard server.
[0033] The control unit 110 is typically a processor, and may be a central processing unit (CPU), an MPU, or the like. The control unit 110 may perform the functions and methods shown in each embodiment by reading a program stored in the storage unit 170 and executing the code or instructions contained in the read program.
[0034] The communication unit 120 is implemented as hardware such as a NIC (Network Interface Card), communication software, or a combination thereof, and transmits and receives information between the server 100 and other devices.
[0035] The input / output unit 130 may include an input device for inputting various operations to the user terminal 200, and an output device for outputting processing results processed by the server 100. The input / output unit 130 may have the input device and output device integrated, or they may be separated into an input device and an output device. The input device may be any of all types of devices capable of receiving input operations from the server 100 and transmitting information related to said input to the control unit 110, or a combination thereof. The input device may include, for example, a touch panel, a touch display, a camera, or a microphone. The output device may output processing results processed by the control unit 110. The output device may include, for example, a display, a touch panel, a speaker, or the like.
[0036] The storage unit 170 stores various programs and data necessary for the server 100 to operate. For example, as will be described in detail later, the storage unit 170 may store scan data obtained by scanning the user's body. The storage unit 170 may include, for example, an HDD (Hard Disk Drive), an SSD (Solid State Drive), flash memory, etc. The storage unit 170 may also include memory that provides a workspace for the control unit 110.
[0037] (2) Server Functional Configuration The server 100 includes a reception unit 111, an avatar generation unit 112, an issuance unit 113, and an authentication unit 114, as functions implemented by the control unit 110. Note that in Figure 2, functional units that are not essential in the embodiments described later may be omitted.
[0038] The reception unit 111 can receive data from the user terminal 200 or other external terminals. The reception unit 111 can receive body scan data of the user's body. It may also receive additional iris scan data and pupil scan data. It may also receive scan data such as skeletal structure, skin information, body shape, walking style, posture, and unconscious habits.
[0039] The avatar generation unit 112 generates an avatar in the virtual space from the received body scan data. Here, avatar generation refers to creating a character or icon for use in the virtual space. This avatar may be used in games, social networking services, chat applications, etc.
[0040] The issuing unit 113 issues a certificate using decentralized identity based on body scan data. Here, decentralized identity refers to a system for managing an individual's identity (ID) on the internet, where an individual can own and control their own identity without a centralized administrator. Decentralized identity can utilize blockchain technology and encryption technology to enable secure online self-authentication while protecting the privacy of personal information.
[0041] The authentication unit 114 authenticates by linking the avatar with a certificate. The process of the authentication unit 114 is to link a virtual avatar with a digital certificate that proves the actual person and their attributes. By linking the avatar with the certificate, the authentication unit 114 can link the avatar from being merely a virtual entity to an actual verifiable person or achievement. For example, the authentication unit 114 may use decentralized identity or digital certificates to prove that the user's avatar is the real person in a game or virtual space.
[0042] The authentication unit 114 can verify that a certificate is legitimate and has not been tampered with. This may include checking its authenticity using digital signatures and public-key cryptography associated with the certificate. Furthermore, the authentication unit 114 can perform authentication within the virtual space using the certificate associated with the avatar. For example, when an avatar enters the virtual space, the certificate can be used to verify that the avatar truly belongs to that user. The authentication unit 114 is part of the system and is primarily responsible for "certificate verification" and "authentication within the virtual space." A "certificate" is an electronic document that guarantees digital identity and trustworthiness. The authentication unit 114 verifies that the certificate meets the conditions of legitimacy and tamper-proofing. In the virtual space, users act using "avatars." Certificates are used to verify that this avatar "truly belongs to that user." For example, when logging into the virtual space, when a user's avatar attempts to enter the virtual space, the authentication unit 114 verifies the certificate associated with that avatar.
[0043] The authentication unit 114 can detect feature quantities in the body scan data. If feature points are detected, the range of the division process may be shifted so that the feature points are not divided. To prevent the feature quantities of the feature points from shifting, four patterns of images may be created by rotating them by 90 degrees each. If the artificial intelligence determines that the feature points are the same with a 3 / 4 probability, it may be treated as identical and image recognition may be performed. Artificial intelligence is a technology that uses computers, which are computational concepts and tools, to perform intelligent actions such as language comprehension, reasoning, and problem solving. In the embodiment of the present invention, the image processing task may be performed by artificial intelligence, particularly deep learning. The system that processes feature quantities as described above achieves the effect of speeding up image processing.
[0044] Furthermore, the authentication unit 114 allows users to authenticate using a portion of the body scan data, and they can choose which information to use for authentication. The portion of the body scan data includes, for example, body dimensions, shape, or other biometric information (e.g., facial features, body pattern). Users can select which information from the acquired body scan data to use for authentication. This mechanism uses data about the user's body for authentication, but offers the flexibility for the user to choose which information to use. For example, if a user chooses to use only facial features during authentication, the system extracts the facial features and compares them with pre-registered data in the database to verify the user's identity. This allows users to share only the minimum necessary information, improving privacy.
[0045] In the authentication unit 114, users can select information such as body shape, facial features, gait, and posture. This system allows users to choose their preferred authentication method based on information related to their own body (body shape, facial features, gait, etc.), and this method is used for identity verification. This allows users to choose a more preferable authentication method or avoid using information they do not wish to use for privacy reasons. The authentication unit 114 can execute an authentication algorithm using the body scan information selected by the user. For example, a facial recognition algorithm, a body shape recognition algorithm, or a behavioral analysis algorithm is executed and compared with data registered by the user. This comparison verifies whether the user is the legitimate user. This allows users to avoid using information they do not wish to use (e.g., facial data) and choose an alternative method (e.g., body shape or gait). In this way, the optimal authentication method can be selected depending on the situation. By combining multiple authentication methods as needed, the risk of unauthorized access can be reduced.
[0046] In this way, the authentication unit 114 can perform multi-factor authentication using visual and cryptographic technologies by linking avatars with certificates. Furthermore, it can enhance security by performing decentralized identity authentication using biometric authentication such as facial recognition and iris recognition. An avatar's facial expression is a way of visually expressing the emotions and reactions that the character shows. An avatar's motion refers to the character physically moving or performing actions, and this includes all movements the avatar makes in the scene, such as walking, running, jumping, sitting, dancing, and waving. The authentication unit 114 can add the avatar's facial expression and motion as metaverse authentication elements.
[0047] The control unit 110 may perform authentication to comply with international data protection laws (for example, Europe's GDPR). Furthermore, the control unit 110 may perform a decentralized identity authentication process compliant with KYC (Know Your Customer) / AML (Anti-Money Laundering) regulations. Here, KYC means "customer verification" and is a process particularly used in the financial industry. It is an important procedure to verify the identity and transaction history of customers and prevent fraud, money laundering, terrorist financing, etc. This process is carried out by financial institutions and companies to identify customers and ensure trustworthiness. AML functions as part of anti-money laundering and is a comprehensive framework to prevent customers from using financial services for fraudulent purposes. KYC plays an initial role in identifying customers and assessing risks.
[0048] The control unit 110 may enable distributed identity compatibility across multiple chains and improve interoperability. It may also aim for open source development in cooperation with the W3C (World Wide Web Consortium), DIF (Decentralized Identity Foundation), and other standards organizations. Furthermore, it may promote integration with existing Web2 legacy systems and maintain compatibility with Web3 digital signature technology. Here, Web2 is a concept referring to the evolutionary stage of the internet, a transition from the traditional static web (Web1) to a more interactive and participatory web where users actively create, share, and communicate content. Web3 is a concept referring to the next evolutionary stage of the internet, a decentralized internet that moves away from centralized management and allows users to control their own data and digital assets.
[0049] Open-sourcing refers to making software and technology freely available, allowing anyone to use, improve, and distribute the code. Because open-source software allows anyone to examine the source code, transparency regarding security and reliability is ensured. This allows users and developers to trust and utilize the technology. Furthermore, open source enables rapid improvements and the addition of new features, as developers worldwide can contribute to the technology. This is especially important for new technologies such as decentralized identity, where improvements from many different perspectives are crucial.
[0050] Standardization bodies are organizations that develop guidelines and standards to promote the spread and interoperability of technologies. In the field of decentralized identity, the role of standardization bodies is crucial. Because different technologies and platforms operate based on unified standards, standardization bodies develop common protocols and specifications for decentralized identity. This allows users to authenticate and share information seamlessly across different services.
[0051] The control unit 110 can achieve decentralized identity compatibility across different blockchains. This means sharing decentralized identities across different blockchain networks. Specifically, it refers to enabling users to utilize a decentralized identity they have set up once across multiple blockchains and decentralized systems. Regarding technologies and approaches aimed at compatibility, dedicated protocols and standards have been created to ensure interoperability between different blockchains. For example, the W3C (World Wide Web Consortium) proposed decentralized identity specifications and the standardization of Verifiable Credentials (VC) are progressing. These are technologies that enable multiple blockchains to handle decentralized identities in a common format and authenticate them mutually. Furthermore, cross-chain technology is used to connect different blockchains. Cross-chain technology allows tokens, data, and identity authentication information to be exchanged between different blockchains, making decentralized identities compatible across multiple blockchains.
[0052] The control unit 110 can achieve high-speed processing and reduced processing load through a distributed system. By utilizing multiple computing resources (servers and computers), it can improve the overall system performance and distribute the processing load on individual nodes (servers). This allows the control unit 110 to operate scalably and efficiently. In particular, distributed architectures are widely used to process large amounts of data and complex calculations at high speed and reduce the load on a single computer. Load balancing is a technique that evenly distributes processing tasks across multiple servers or computers. This prevents any single node from becoming overloaded and optimizes the overall system performance. In web server load balancing, requests are distributed to multiple servers to ensure the system operates stably even during peak traffic. In the control unit 110, the distributed architecture and load balancing enable high-speed data processing and faster authentication.
[0053] The control unit 110 can perform decentralized identity management optimized for mobile devices. Decentralized identity management optimized for mobile devices allows for the secure and efficient management of personal identity information based on a decentralized identity system using mobile devices such as smartphones and tablets. This approach aims to enable users to manage their own identities and control their personal information without relying on centralized services. Decentralized identity management can be realized by leveraging the characteristics of mobile devices (portability, network connectivity, computing power). The control unit 110 can manage decentralized identities more smoothly by taking advantage of the mobility of mobile devices.
[0054] The control unit 110 can have an intuitive operating interface. Users can naturally understand how to use it and operate it in a predictable way without special learning or explanation. The intuitive interface is designed in line with user behavior and expectations, so that users can quickly achieve their goals without getting lost when using the application or device. The screen and operation are simple, with few unnecessary elements, and it is immediately clear to the user where to touch, without being bothered by excessive information or options. Visually clear hints are provided, such as icons, buttons, and gestures. For example, the "Home" button is displayed as a house icon, and pages are advanced with a swipe operation, providing visually predictable movements.
[0055] The control unit 110 can utilize technology to scan the entire body in a very short time, such as a full-body scan in 5 seconds, to understand the internal and external conditions in detail. 3D body scanners can scan the external appearance of the body in a very short time (a few seconds) to acquire body shape and body parameters. These are mainly used in the fashion industry, fitness, and entertainment. The control unit 110 can perform scans in a very short time by utilizing 3D body scanner technology.
[0056] The control unit 110 can utilize biometric authentication technology to identify a person using the characteristics of their pupils in a short time (approximately 1 minute). Advanced image processing technology is used to rapidly analyze eye photographs and videos. Specifically, a high-speed, high-resolution camera is used to instantly capture even the finest details of the eye. This allows for obtaining a detailed image of the pupil within a few seconds. In addition, a real-time image analysis algorithm is used to analyze the characteristics of the pupil. This extracts the eye pattern in a few seconds and matches it with a database. Furthermore, recent advances in sensor technology have made it possible to perform highly accurate pupil authentication in a short time. By utilizing infrared and near-infrared technology, the characteristics of the pupil can be captured stably regardless of eye movement or changes in light. The control unit 110 can perform pupil authentication using these technologies.
[0057] The control unit 110 can authenticate whether the user is who they claim to be by observing pupil movement in the authentication device and simultaneously answering secret questions based on facts only the user would know. These secret questions, known only to the user, can include not only questions about family and parents, but also uploading photos of the user's physical features (scars, moles, parts that are clearly different from others) taken with a smartphone. By observing pupil movement in response to these secret questions during authentication, it is possible to distinguish between truth and falsehood, regardless of brain or autonomic nervous system activity. It is known that pupil movement exhibits distinctive characteristics when lying.
[0058] The control unit 110 can perform high-speed image processing on distributed GPUs. In a distributed identity system, the technology of utilizing GPUs (graphics processing units) can be used to process image data (e.g., facial recognition or biometric recognition images) at high speed. GPUs are processors specialized in parallel computing and can process large amounts of data simultaneously, making them very effective for speeding up image processing. For example, in facial recognition or fingerprint recognition, a huge number of calculations are required to extract feature points of the face or fingerprint, but GPUs can process this at once with many computing units, making processing extremely fast.
[0059] The control unit 110 can perform information disclosure control using zero-knowledge proofs. When proving possession of certain information, it is possible to use a technique in which the certifying party (user) can prove to the other party (verifier) that they possess that information without disclosing the information itself. By using zero-knowledge proofs, a user can prove that they are a legitimate user without disclosing any passwords or personal information. For example, they can prove that they are a legitimate user of an online system without using a password. In this way, identity can be proven while disclosing only the minimum amount of information.
[0060] The control unit 110 employs a quantum-resistant encryption method, ensuring a security algorithm that can adapt to future technological advancements. To prevent conventional encryption technologies from being threatened by the advent of quantum computers, it is possible to employ encryption methods that cannot be deciphered by quantum computers, or are extremely difficult to decipher. Research into post-quantum cryptography (PQC) is progressing to prepare for the threat that quantum computers pose to conventional encryption algorithms. Quantum-resistant encryption is a new encryption algorithm that cannot be deciphered by quantum computers, or takes an extremely long time to decipher, and uses methods based on mathematical problems different from conventional encryption algorithms. This approach aims to enhance privacy, improve security, and increase user convenience.
[0061] The control unit 110 allows users to manage their own identity and control multiple authentication. Users manage their own identity (personal information and authentication information) and control access using multiple authentication methods. This approach aims to enhance privacy, improve security, and increase user convenience. Identity management allows users to manage their personal authentication information (IDs, passwords, certificates, etc.) and determine which resources they can access. Traditionally, this management was often performed by companies or service providers, but in decentralized identity, users themselves are responsible for managing their own identity. Multiple authentication (MFA) can provide users with two or more authentication methods when accessing systems and services. This significantly improves security and reduces the risk of unauthorized access.
[0062] The control unit 110 may include a mechanism for recovering and restoring identity data or authentication information if it is lost or becomes inaccessible using decentralized identity. Decentralized identity is a technology that enables individuals to manage their own identity information (e.g., name, address, qualifications, etc.) without relying on a centralized authority, but this requires a method for recovering that information if it is lost or accidentally deleted. In this regard, the owner of the decentralized identity can have backup means for recovering identity information, such as a private key or a seed phrase for recovery. This allows for restoration to the original state even if the private key is lost. The seed phrase may be a series of random words obtained when the user generates the decentralized identity. By storing this in a secure place, it can be retrieved even if the private key is lost.
[0063] The control unit 110, by making detailed use of body scan data, can capture even subtle individual differences that were difficult to identify with conventional methods, thereby reducing the risk of forgery and impersonation. This invention is expected to establish new security standards in the digital society and be applied to a variety of digital services. Specifically, it can be applied in a wide range of fields, including online games, virtual reality (VR) applications, secure online transactions in finance and securities, secure decentralized identity data sharing for government and academia, and patient data sharing and personalized medicine in healthcare.
[0064] Figure 3 is a flowchart of an authentication device 10 according to one embodiment of the present invention. In this embodiment, the authentication device 10 operates in cooperation with a user terminal 200 and a server 100. Each stage of the flowchart will be described in detail below.
[0065] Figure 3 is an example of a flowchart showing the processing by the authentication device 10 according to one embodiment. The user terminal consists of a control unit 210. The control unit 210 is typically a processor, and can be implemented as a central processing unit (CPU), MPU (Micro Processing Unit), GPU (Graphics Processing Unit), etc. The control unit 210 reads a program stored in the storage unit 270 and executes the code or instructions contained in the read program, thereby executing the functions and methods shown in each embodiment. The control unit 210 consists of a communication unit 220, a display unit 230, an input / output unit 240, a scan unit 250, and a storage unit 270. The communication unit 220 is implemented as hardware such as a NIC (Network Interface Card), communication software, or a combination thereof, and transmits and receives various data to and from the server 100 via the network 500. The display unit 230 is a monitor that displays data according to the display data written to the frame buffer, and may be, for example, a touch panel, a touch display, etc. The input / output unit 240 may include an input device for inputting various operations to the user terminal 200, and an output device for outputting processing results processed by the user terminal 200. The scanning unit 250 may include a device for scanning the user's body and creating scan data. The scanning unit 250 scans the user's entire body and creates scan data (step 5). The scanning unit 250 can measure the user's entire body in three dimensions and acquire the information as digital data. This data may accurately reflect the shape, size, and movement of the user's body.
[0066] The scanning unit 250 may utilize a 3D scanner. A 3D scanner can scan the user's entire body and capture its shape and dimensions as 3D data. This allows for high-precision capture of the user's body shape, pose, and other physical characteristics. The scanner may also use laser or optical technology to measure the body and generate point cloud data (a collection of 3D points). Based on this data, the user's body can be reconstructed in three dimensions.
[0067] The scanning unit 250 can utilize body scanning technology. The body scan may employ technology that allows measurement even through clothing. When a user stands in front of a special device to be scanned, their entire body may be scanned, and data regarding size and shape may be acquired. The scan can be completed in a few seconds to a few minutes.
[0068] The scanning unit 250 can perform dynamic scanning (motion capture). It can also scan the user's movements and capture them as data. By using motion capture, body movements and gestures can be captured in real time.
[0069] The server comprises a control unit 110, a communication unit 120, an input / output unit 130, and a storage unit 170. The control unit 110 is typically a processor, and may be a central processing unit (CPU) or MPU, etc. The communication unit 120 is implemented as hardware such as a NIC (Network Interface Card), communication software, or a combination thereof, and transmits and receives information between the server 100 and other devices. The input / output unit 130 may include an input device for inputting various operations to the user terminal 200, and an output device for outputting processing results processed by the server 100. The storage unit 170 stores (stores) various programs and data necessary for the operation of the server 100. The control unit 110 comprises a reception unit 111, an avatar generation unit 112, an issuance unit 113, and an authentication unit 114. The reception unit 111 receives data from a user scanning their entire body and starts processing (step 15). The scanned data may be transmitted as digital data from the scanning device. This data can be sent to the server 100, for example, via the network 500 or a communication interface. The receiving unit 111 can be responsible for receiving this transmitted body scan data. It can convert the received data into a format that can be appropriately processed within the system, or pass it on to the next process. The receiving unit 111 may also verify that the data is accurate and convert it into an appropriate format. For example, this may include verifying the integrity of the scan data and checking for errors.
[0070] The reception unit 111 can receive further iris scan data and pupil scan data. Iris scanning is a technology that uses the iris of the eye to identify individuals. Each person's iris has a unique pattern, and by utilizing this, highly accurate authentication can be performed. In iris scanning, a dedicated camera is used to capture an image of the iris while the eye is close to the camera, allowing for the capture of fine details of the iris.
[0071] Pupil scanning is a technology that identifies individuals by utilizing the size and response of their pupils. A specialized camera is used to capture the size and response of the pupils. In particular, pupillary response (response to light) and pupil shape may be observed in detail. Pupil dilation and contraction in response to changes in lighting or emotional responses may also be detected. Because pupil movement and response differ from person to person, identification can be performed with very high accuracy. Accuracy can be further improved by combining multiple pieces of information, such as response to light, emotions, and health status.
[0072] Next, the avatar generation unit 112 generates an avatar in the virtual space from the body scan data received by the reception unit 111 (step 25). The avatar generation unit 112 can create an avatar that can be used in a virtual space (for example, a game, virtual world, or VR environment) based on the user's scanned body data. Avatar generation can usually be created by selecting various elements to reflect the individual's appearance and personality. The avatar generation unit 112 may also reflect features such as body shape (creating an avatar that matches the user's height, build, and skeleton), facial features (creating an avatar that resembles the user's face by reflecting the position and shape of the eyes, nose, and mouth from the facial scan data), and skin color and texture (setting skin color and texture based on the scan data) in the avatar. The avatar generation unit 112 may also create a 3D model for the virtual space based on this information. This 3D model may be represented as vertex information or a mesh (a 3D structural framework) to determine how the avatar looks in the virtual space.
[0073] In avatar creation, appearance can be customized. Users can choose and adjust eyes, nose, mouth, ears, hairstyle, skin color, etc., to create an avatar that resembles their own face or their ideal appearance. Body type, height, and weight can also be customized. Movements and expressions can be added to avatars. By giving avatars specific movements (walking style, gestures) and expressions (joy, anger, surprise, etc.), emotions can be expressed in the virtual space, and the user's personality can be reflected. Voices and sounds can also be added to avatars. Some avatar creation systems allow users to select a voice that matches the avatar or convert text into speech.
[0074] Next, the issuing unit 113 issues a certificate that proves the user's identity using decentralized identity technology based on the user's physical characteristics (step 35). In the process of issuing a certificate based on body scan data, the user's physical characteristics (e.g., body type and facial features) may be used as identification information, and a certificate may be issued using decentralized identity based on that information. This certificate may include authentication information based on information about the physical characteristics scanned by the user (e.g., "This person is 175cm tall, has a muscular build, and has facial features that are..."). The issuing unit 113 may analyze the user's body scan data and generate a certificate using decentralized identity technology based on that data. This certificate may be used to prove to other third parties (e.g., administrators of online services or virtual spaces) that the user's identity is legitimate. This enables secure and reliable authentication while protecting the user's privacy.
[0075] Finally, the authentication unit 114 links the avatar in the virtual space with the certificate that represents the user's identity in the real world and performs authentication (step 45). Specifically, the following processes may be performed to prove that the avatar belongs to a legitimate user in the virtual space. (Associate avatar with certificate) The authentication unit 114 can link the avatar's digital profile with a certificate to confirm that it belongs to the same user. This may ensure that the avatar accurately reflects the user's identity. (Certificate verification) The authentication unit 114 can verify whether the certificate is legitimate and has not been tampered with. This may include checking its authenticity using digital signatures or public-key cryptography associated with the certificate. (Provision of authentication information) The authentication unit 114 can perform authentication within the virtual space using a certificate associated with the avatar. For example, when an avatar enters the virtual space, the certificate can be used to verify whether the avatar truly belongs to that user.
[0076] The authentication unit 114 can perform skeletal authentication. Unlike other biometric authentication methods such as facial recognition, fingerprint recognition, and iris recognition, skeletal authentication is characterized by identifying individuals using the position and arrangement of bones in the human body. The position of bones in the human body can be measured with high precision using 3D sensors or cameras. This makes it possible to identify individuals regardless of the user's posture or movement. For example, the skeletal authentication engine can detect 30 key points on the human body in real time at up to 60 FPS, perform real-time posture estimation and display on video, and perform posture estimation using electronic files of video and still images.
[0077] The authentication unit 114 can perform skin authentication. Skin authentication is a technology that authenticates a person using the characteristics of their skin (for example, skin temperature, skin texture, fine irregularities and patterns, etc.). Skin authentication focuses on the characteristics of the skin itself and may utilize features such as skin pattern, skin temperature, skin texture, or the arrangement of blood vessels. Because individual differences in skin are very subtle and unique, it is possible to perform authentication with higher accuracy than other authentication methods. By sensing skin temperature and texture, authentication can sometimes be performed without contact, making authentication more convenient and hygienic. For example, skin vein authentication (palm vein authentication) can be performed. Since skin veins carry blood, the shape of the veins can be detected using infrared light.
[0078] The above authentication program may be recorded on a processor-readable recording medium, and the recording medium can be a "non-temporary tangible medium," such as tape, disk, card, semiconductor memory, or programmable logic circuit. Furthermore, the authentication program may be supplied to the processor via any transmission medium capable of transmitting the information monitoring program (such as a communication network or broadcast wave). In other words, for example, the authentication program may be downloaded and executed from a network using an information processing device such as a smartphone. The present invention can also be realized in the form of a data signal embedded in a carrier wave, where the authentication program is embodied by electronic transmission.
[0079] The above authentication program can be implemented using scripting languages such as ActionScript and JavaScript (registered trademark), or object-oriented programming languages such as Objective-C, Java (registered trademark), C++, Python, and R. [Explanation of symbols]
[0080] 10 Authentication device 100 servers 110 Control Unit 111 Reception Department 112 Avatar Generation Section 113 Publishing Department 114 Authentication Department 120 Communications Department 130 Input / output section 170 Storage section 200 user terminals 200A User A 200B User B 210 Control Unit 220 Communications Department 230 Display section 240 Input / output section 250 Scanning Unit 270 Storage section 400 Database Servers 500 Networks
Claims
1. A reception area that receives body scan data of the user's entire body, An avatar generation unit generates an avatar in a virtual space based on the aforementioned body scan data, An issuing unit that issues a certificate based on decentralized identity associated with the avatar, based on the body scan data, An authentication unit that authenticates the user based on the certificate associated with the avatar, Equipped with, The reception unit further receives data scanned from the iris or data scanned from the pupil. The authentication device is characterized in that the issuing unit encrypts identification information generated based on the iris or pupil scan data included in the body scan data, and includes the encrypted identification information in the certificate as identification information in a distributed identity.
2. The authentication unit can authenticate based on a selection of body scan data chosen by the user. The authentication device according to feature 1.
3. Computers A reception step that receives body scan data of a user, An avatar generation step in which an avatar is generated in a virtual space based on the aforementioned body scan data, An issuance step of issuing a certificate based on decentralized identity associated with the avatar, based on the body scan data, Authentication step of authenticating the user based on the certificate associated with the avatar, Execute, The aforementioned reception step further receives data scanned from the iris or data scanned from the pupil. The issuance step is characterized by encrypting identification information generated based on data of scanning the iris or pupil included in the body scan data, and including the encrypted identification information in the certificate as identification information in a decentralized identity.
4. A computer, A reception function that accepts body scan data obtained by scanning a user, An avatar generation function that generates an avatar in a virtual space based on the aforementioned body scan data, An issuance function that issues a certificate based on decentralized identity associated with the avatar, based on the body scan data, An authentication function that authenticates the user based on the certificate associated with the avatar, Make it run, The aforementioned reception function further receives data scanned from the iris or data scanned from the pupil. The issuance function is characterized by encrypting identification information generated based on data of scanning the iris or pupil included in the body scan data, and including the encrypted identification information in the certificate as identification information in a decentralized identity.
Citation Information
Patent Citations
Information processing method, information processing device and control program
JP2021082114A
Information processing device, information processing method, and service providing method
JP7321622B1
Avatar management system, avatar management method, and program
JP7568171B2
Identity management system, identity management method, and program
WO2025005264A1
System and method for identifying eye signals, and continuous biometric authentication
JP2017526079A