Account Management Device
The account management device uses image recognition and face ID technology to allow users to create accounts across services using compatible ID cards, addressing the need for manual input and enhancing accessibility.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- NTT DOCOMO INC
- Filing Date
- 2022-08-10
- Publication Date
- 2026-04-23
AI Technical Summary
Existing systems require manual re-entry of personal information when using an ID card for a service incompatible with the original service, posing difficulties for elderly users with IT equipment.
An account management device that utilizes image recognition to generate a string of characters and a face ID from a captured image, allowing users to create accounts without manual input by using an ID card compatible with a different service.
Enables users to create accounts seamlessly across services without manually inputting personal information, improving accessibility for elderly users.
Smart Images

Figure 0007850627000001 
Figure 0007850627000002 
Figure 0007850627000003
Abstract
Description
Technical Field
[0004] , , , , , , , , ,
[0005] , , , , , ,
[0001] The present invention relates to an account management device.
Background Art
[0002] For example, by using ICT (Information and Communication Technology) technology to solve the problems faced by cities, efforts such as smart cities aiming for sustainable city building are expected to increase the opportunities to use digital services. When providing digital services according to individual users, it becomes necessary to register the accounts of individual users.
[0003] For example, Patent Document 1 discloses a technology related to a business method for setting fees using personal information, which is the user's authentication information, when a car dealer or an insurance company provides services using vehicle history information such as a vehicle's driving history. In this technology, a personal ID card storing personal authentication information including a driver's license number, issue date, expiration date, license conditions, name, date of birth, place of origin, address, vehicle type, fingerprint data, face photo data, and password is used. That is, a user using the technology according to Patent Document 1 uses personal information including name, address, and face photo data as his / her account information.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the technology described in Patent Document 1, if the owner of a personal ID card uses the personal information recorded on the personal ID card in a second service different from the above service and which is not compatible with the personal ID card, the owner must manually re-enter the personal information into the system providing the second service. In this case, for example, it may be difficult for elderly users to enter their personal information using IT equipment.
[0006] Therefore, the present invention aims to provide an account management device that, when an ID card corresponding to the first service is not corresponding to the second service, allows a user to create an account for use in the second service by using the ID card corresponding to the first service, without having to manually input their personal information into an IT device. [Means for solving the problem]
[0007] An account management device according to a preferred embodiment of the present invention is an account management device comprising: an image recognition unit that generates a first string of characters indicating personal information by image recognition of a first captured image generated when a first terminal device captures a printed document of the personal information of a first person when an account corresponding to the first person is registered; a face ID management unit that generates a face ID, which is an identifier that corresponds one-to-one with the face image of the first person, based on the face image of the first person when an account corresponding to the first person is registered, and manages the generated face ID in association with feature quantities related to the features of the face image; and an account management unit that generates account information of the first person including the first string of characters and the face ID when an account corresponding to the first person is registered, and manages the generated account information. [Effects of the Invention]
[0008] According to the present invention, when an ID card corresponding to a first service is not compatible with a second service, an account management device is provided that allows a user to create an account for use with the second service without having to manually input their personal information into an IT device, by using the ID card corresponding to the first service. [Brief explanation of the drawing]
[0009] [Figure 1] A diagram showing the overall configuration of account management system 1. [Figure 2] A block diagram showing an example configuration of terminal device 20-1. [Figure 3] A block diagram showing an example configuration of the account management device 10. [Figure 4] A table showing an example configuration of a facial ID database (FDB). [Figure 5] A table showing an example configuration for the account database ADB. [Figure 6] A sequence diagram showing the operation of account management system 1 during account registration. [Figure 7] A sequence diagram showing the operation of account management system 1 during user authentication. [Figure 8] A sequence diagram showing the operation of account management system 1 during user authentication. [Modes for carrying out the invention]
[0010] 1: First Embodiment Hereinafter, an account management system 1 equipped with an account management device 10 according to the first embodiment of the present invention will be described with reference to Figures 1 to 8.
[0011] 1-1: Configuration of the First Embodiment 1-1-1: Overall structure Figure 1 shows the overall configuration of the account management system 1 according to the first embodiment. As shown in Figure 1, the account management system 1 comprises an account management device 10, a terminal device 20-1, and a terminal device 20-2. In this embodiment, terminal devices 20-1 and 20-2 have the same configuration. However, terminal devices 20-1 and 20-2 do not have to have the same configuration as long as they have the functions described later. Hereinafter, terminal devices 20-1 and 20-2 may be collectively referred to as "terminal device 20". Furthermore, the account management device 10, terminal device 20-1, and terminal device 20-2 may be, for example, a smartphone or tablet, or a PC (Personal Computer). Here, terminal device 20-1 is an example of a "first terminal device". Also, terminal device 20-2 is an example of a "second terminal device". Furthermore, terminal device 20-2 is an example of an "external device".
[0012] In the account management system 1, the account management device 10, terminal device 20-1, and terminal device 20-2 are connected to each other via the communication network NET so that they can communicate with one another.
[0013] The account management device 10 generates account information associated with user U's account when user U uses terminal device 20-1. Here, "account" refers to a unique identifier or right of user U that allows the user to use the computer through the OS (Operating System) or network. If user U's account is a unique identifier for user U, user U's account is used on the computer to identify user U and manage information unique to user U. "Account information" includes, for example, at least one of user U's name, address, telephone number, date of birth, email address, password, or credit card number. Here, user U is an example of "the first person".
[0014] In addition, when the user U uses the terminal device 20-2, the account management device 10 performs authentication of the user U using the already generated account information. Here, "authentication of the user himself" means that when a computer provides a service to the user U through an OS or a network, the computer authenticates that the user U is a legitimate user of the service. At the time of authentication of the user U, the user U inputs his / her account to the computer. The computer authenticates that the user U is a legitimate user based on the account input by the user U.
[0015] As an example, when the service is a book lending service provided by a local government, the user U inputs his / her account to the account management device 10. As will be described later, in this embodiment, the user U inputs his / her face image to the account management device 10 as his / her account. As a result, the user U is authenticated as a legitimate user of the lending service. Thereafter, the account management device 10 outputs, for example, the name and address of the user U included in the account information of the user U to the terminal device 20-2. As a result, on the terminal device 20-2, the name and address of the user U are automatically input to the input fields of the screen for using the above lending service.
[0016] When the account management device 10 is linked with the server that provides the above lending service, the account management device 10 may output the name and address of the user U to the server instead of the terminal device 20-2. Alternatively, when the account management device 10 is incorporated in the system that provides the above lending service, the account management device 10 may not output the name and address of the user U to an external device.
[0017] The terminal device 20-1 is a device used when user U registers an account. The terminal device 20-1 is, for example, a PC installed in a public place and is preferably shared by a plurality of users U. However, the terminal device 20-1 is not limited to a terminal device installed in a public place and may be a terminal device privately used by user U.
[0018] The terminal device 20-2 is a device used when user U performs authentication using already generated account information. The terminal device 20-2 is, for example, a smartphone, tablet, or PC owned by user U and is preferably privately used by user U. However, the terminal device 20-2 is not limited to a terminal device privately used by user U and may be a terminal device installed in a public place.
[0019] 1-1-2: Configuration of Terminal Device 20-1 FIG. 2 is a block diagram showing a configuration example of the terminal device 20-1. The terminal device 20-1 includes a processing device 21, a storage device 22, a communication device 23, a display 24, an input device 25, and an imaging device 26. Each element of the terminal device 20-1 is interconnected by one or more buses for communicating information.
[0020] The processing device 21 is a processor that controls the entire terminal device 20-1. Also, the processing device 21 is configured using, for example, one or more chips. The processing device 21 is configured using, for example, a central processing unit (CPU) including an interface with peripheral devices, an arithmetic unit, and registers. Note that part or all of the functions of the processing device 21 may be realized by hardware such as a DSP, ASIC, PLD, or FPGA. The processing device 21 executes various processes in parallel or sequentially.
[0021] The storage device 22 is a recording medium that can be read and written by the processing device 21. Also, the storage device 22 stores a plurality of programs including a control program PR2 executed by the processing device 21.
[0022] The communication device 23 is hardware that acts as a transmitting and receiving device for communicating with other devices. The communication device 23 is also called, for example, a network device, network controller, network card, or communication module. The communication device 23 may be equipped with a connector for wired connection and an interface circuit corresponding to the connector. The communication device 23 may also be equipped with a wireless communication interface. Examples of connectors and interface circuits for wired connection include products compliant with wired LAN, IEEE1394, and USB. Examples of wireless communication interfaces include products compliant with wireless LAN and Bluetooth®.
[0023] The display 24 is a device that displays images and text information. The display 24 displays various images under the control of the processing unit 21. For example, various display panels such as liquid crystal display panels and organic EL (Electro-Luminescence) display panels are preferably used as the display 24.
[0024] The input device 25 receives input from user U of terminal device 20-1. For example, the input device 25 includes a pointing device such as a keyboard, touchpad, touch panel, or mouse. If the input device 25 includes a touch panel, it may also function as the display 24.
[0025] The imaging device 26 images the external space in which an object exists. The imaging device 26 also outputs imaging information indicating the image obtained by imaging the external space. The imaging device 26 includes, for example, a lens, an image sensor, an amplifier, and an AD converter. Light focused through the lens is converted by the image sensor into an analog imaging signal. The amplifier amplifies the imaging signal and outputs it to the AD converter. The AD converter converts the amplified analog imaging signal into digital imaging information. The converted imaging information is output to the processing device 21.
[0026] In particular, in this embodiment, the imaging device 26 images a printed document containing user U's personal information and generates an image of the printed document. Here, the image of the printed document is an example of the "first image." The "printed document containing user U's personal information" is, for example, an ID card on which user U's personal information is printed. The "personal information of user U" is information about user U that can identify user U from other users. The "personal information of user U" includes, for example, at least one of user U's name, address, telephone number, date of birth, email address, password, and credit card number. The "ID card" is, for example, a driver's license, health insurance card, passport, or My Number card. Furthermore, the imaging device 26 outputs the generated image of the printed document containing user U's personal information to the processing device 21.
[0027] Furthermore, the imaging device 26 captures the face of user U and generates a facial image of user U. The imaging device 26 then outputs the generated facial image of user U to the processing device 21.
[0028] The processing unit 21 functions as an acquisition unit 211, an output unit 212, a generation unit 213, and a display control unit 214 by reading and executing the control program PR2 from the storage device 22.
[0029] The acquisition unit 211 acquires a facial image of user U and an image of a printed document containing user U's personal information from the imaging device 26. This image is an example of the "first image".
[0030] The output unit 212 outputs the first captured image, which is an image of user U's face and an image of a printed document containing user U's personal information, acquired by the acquisition unit 211, to the account management device 10.
[0031] Subsequently, as described later, the account management device 10 generates a string representing user U's personal information by performing image recognition on the first captured image, which is an image of a printed document containing user U's personal information. This string is an example of the "first string". The account management device 10 also outputs the generated string to the terminal device 20-1. The acquisition unit 211 acquires the first string from the account management device 10.
[0032] The generation unit 213 generates a hash value by transforming the first string obtained by the acquisition unit 211 using a hash function. This hash value is an example of the "first hash value". The first hash value corresponds one-to-one with the first string. The output unit 212 outputs the first hash value generated by the generation unit 213 to the account management device 10.
[0033] The display control unit 214 causes the display 24 to display a message for user U. For example, if terminal device 20-1 instructs user U to take an image of user U's face using imaging device 26, it displays a message indicating this instruction on display 24. The same applies if terminal device 20-1 instructs user U to take an image of a printed document containing user U's personal information using imaging device 26.
[0034] 1-1-3: Configuration of Account Management Device 10 Figure 3 is a block diagram showing an example configuration of the account management device 10. The account management device 10 comprises a processing unit 11, a storage device 12, a communication device 13, a display 14, and an input device 15. Each element of the account management device 10 is interconnected by one or more buses for communicating information.
[0035] The processing unit 11 is a processor that controls the entire account management device 10. The processing unit 11 is configured using, for example, one or more chips. The processing unit 11 is configured using, for example, a central processing unit (CPU) that includes interfaces with peripheral devices, an arithmetic unit, and registers. Some or all of the functions of the processing unit 11 may be implemented by hardware such as a DSP, ASIC, PLD, and FPGA. The processing unit 11 executes various processes in parallel or sequentially.
[0036] The storage device 12 is a recording medium that the processing unit 11 can read and write to. The storage device 12 also stores multiple programs, including the control program PR1 that the processing unit 11 executes.
[0037] Furthermore, the storage device 12 stores the face ID database FDB and the account database ADB. The face ID database FDB is a database of face IDs. Here, "face ID" is an identifier generated by the account management device 10 from the face image of user U obtained from the terminal device 20-1, and it corresponds one-to-one with the face image of user U.
[0038] Figure 4 is a table showing an example of the configuration of the Face ID Database (FDB). The Face ID Database (FDB) stores a set of a face image, a face ID, feature quantities related to the features of the face image, and a first hash value. Here, "feature quantities related to the features of the face image" refers to data that represents the features of the face image. These feature quantities include, for example, the contour of the face, the area of the face, the parts included in the face, and the relative positions between those parts. The Face ID Database (FDB) stores a set of, for example, a face image file with the filename "001.jpg", a face ID represented by the string "C87K91", a feature quantity file with the filename "001.csv", and a first hash value represented by the numerical value "733673904".
[0039] The Account Database (ADB) is a database of user accounts. The account information for user U includes user U's user ID, a first string related to user U, and user U's face ID. Here, "user ID" is the identifier for user U. There is a one-to-one correspondence between user ID and user U.
[0040] Figure 5 is a table showing an example of the configuration of the account database (ADB). The account database (ADB) stores pairs of user IDs, a first string, and a face ID. For example, the account database (ADB) stores a pair of user IDs represented by the string "AAA", a first string represented by the string "BJUGHSK", and a face ID represented by the string "C87K91". In the table in Figure 5, for the sake of explanation, the "first string" is listed as a random combination of letters. However, in reality, the "first string" is a string that represents the personal information of user U, as described above.
[0041] Returning to Figure 3, the communication device 13 is hardware acting as a transmitting and receiving device for communicating with other devices. The communication device 13 is also called, for example, a network device, network controller, network card, or communication module. The communication device 13 may be equipped with a connector for wired connection and an interface circuit corresponding to the connector. The communication device 13 may also be equipped with a wireless communication interface. Examples of connectors and interface circuits for wired connection include products compliant with wired LAN, IEEE 1394, USB, etc. Examples of wireless communication interfaces include products compliant with wireless LAN and Bluetooth®, etc.
[0042] The display 14 is a device that displays images and text information. The display 14 displays various images under the control of the processing unit 11. For example, various display panels such as liquid crystal display panels and organic EL (Electro-Luminescence) display panels are preferably used as the display 14.
[0043] The input device 15 receives operations from the administrator of the account management device 10. For example, the input device 15 includes a keyboard, touchpad, touch panel, or pointing device such as a mouse. If the input device 15 includes a touch panel, it may also function as the display 14.
[0044] The processing unit 11 functions as an acquisition unit 111, an extraction unit 112, an image recognition unit 113, an output unit 114, a face ID management unit 115, and an account management unit 116 by reading and executing the control program PR1 from the storage device 12. Of the functions of the acquisition unit 111, the extraction unit 112, the image recognition unit 113, the output unit 114, the face ID management unit 115, and the account management unit 116, the function during account registration will be explained first.
[0045] The acquisition unit 111 acquires a first image from the terminal device 20-1, which is an image of user U's face and an image of a printed document containing user U's personal information.
[0046] The extraction unit 112 extracts feature quantities related to the characteristics of the face image from the face image of user U acquired by the acquisition unit 111.
[0047] The image recognition unit 113 performs image recognition on the image of the printed document containing user U's personal information acquired by the acquisition unit 111, thereby generating a first string that represents the personal information.
[0048] The output unit 114 outputs the first string generated by the image recognition unit 113 to the terminal device 20-1. Subsequently, the acquisition unit 111 retrieves the first hash value generated using the first string from the terminal device 20-1.
[0049] The face ID management unit 115 generates a face ID based on the face image of user U. The face ID management unit 115 also manages the generated face ID in association with the feature quantities of the face image. For example, the face ID management unit 115 associates the face ID, the feature quantities of the face image, and the first hash value with each other and stores them in the face ID database FDB stored in the storage device 12.
[0050] The account management unit 116 generates account information for user U, including user U's user ID, a first string related to user U, and user U's face ID. Here, user U's face ID is the same as the face ID for user U stored in the face ID database FDB. The account management unit 116 also manages the generated account information for user U. For example, the account management unit 116 stores the generated account information for user U in the account database ADB stored in the storage device 12.
[0051] As a result, if an ID card corresponding to the first service is not compatible with the second service, the user can use the ID card corresponding to the first service to create an account for the second service without having to manually enter their personal information into an IT device. For example, if user U's ID card is a My Number Card, user U can use the My Number Card to use the services provided by government agencies as the first service. In addition, user U can use the same My Number Card to create an account for an e-commerce site as the second service.
[0052] Next, we will explain the operation of each component during user authentication.
[0053] The acquisition unit 111 acquires a facial image of user U from the terminal device 20-2.
[0054] The extraction unit 112 extracts feature quantities related to the features of the face image of user U from the face image of user U acquired by the acquisition unit 111 from the terminal device 20-2.
[0055] The Face ID Management Unit 115 identifies the Face ID corresponding to the face image of user U obtained from the terminal device 20-2 based on the degree of agreement between the feature quantities related to the features of the face image of user U obtained from the terminal device 20-2, which are extracted by the Extraction Unit 112, and the feature quantities stored in the Face ID Database FDB. Specifically, the Face ID Management Unit 115 identifies the Face ID that corresponds to the feature quantity that is closest to the feature quantity related to the features of the face image of user U obtained from the terminal device 20-2 among the Face IDs stored in the Face ID Database FDB. Alternatively, the Face ID Management Unit 115 identifies the Face ID that corresponds to the feature quantity whose difference from the feature quantity related to the features of the face image of user U obtained from the terminal device 20-2 is within a threshold among the Face IDs stored in the Face ID Database FDB.
[0056] The account management unit 116 identifies account information that includes the face ID identified by the face ID management unit 115 from among the account information stored in the account database ADB.
[0057] The output unit 114 outputs the first string included in the account information identified by the account management unit 116 to the terminal device 20-2.
[0058] As a result, user U can perform identity verification without having to manually enter the personal authentication information recorded on their ID card into IT equipment.
[0059] Next, we will explain the operation of each component when there are multiple face IDs corresponding to user U's face image during the user authentication process described above.
[0060] As a prerequisite, the account management device 10 is assumed to have already registered account information corresponding to multiple individuals. Specifically, the terminal device 20-1 is assumed to have output multiple first captured images to the account management device 10 by capturing images of printed materials containing multiple pieces of personal information that correspond one-to-one with multiple individuals. Furthermore, the image recognition unit 113 of the account management device 10 is assumed to have performed image recognition on the multiple first captured images, thereby generating multiple first strings that correspond one-to-one with multiple pieces of personal information and represent multiple pieces of personal information. Furthermore, the face ID management unit 115 of the account management device 10 is assumed to have generated multiple face IDs that correspond one-to-one with the face images of multiple individuals based on the face images of multiple individuals. In addition, the face ID management unit 115 manages multiple hash values generated from the generated multiple face IDs, feature quantities related to the features of the face images of multiple individuals, and multiple first strings, which correspond one-to-one with the multiple first strings, by associating them with each other.
[0061] Here, we assume that when user U is authenticated, the face IDs corresponding to the face image obtained from terminal device 20-2, which is a second terminal device, are included among the multiple face IDs stored in the face ID database FDB. As an example, when one person among several people whose faces are similar, such as twins, performs identity authentication, we assume that the face IDs corresponding to their own face image include not only their own face ID but also the face IDs of others, resulting in multiple face IDs.
[0062] The output unit 114 outputs specific information to the terminal device 20-2 indicating that multiple face IDs corresponding to the face images acquired from the terminal device 20-2 are included in the face ID database FDB.
[0063] In this case, as described later, the terminal device 20-2 captures a printed document containing user U's personal information and generates an image of the document. This image is an example of a "second image." The acquisition unit 111 in the account management device 10 acquires the second image from the terminal device 20-2.
[0064] The image recognition unit 113 performs image recognition on the second captured image acquired by the acquisition unit 111 to generate a second string representing the personal information of user U.
[0065] The face ID management unit 115 generates a hash value by transforming the second string generated by the image recognition unit 113 using a hash function. This hash value is an example of the "second hash value". The face ID management unit 115 also identifies one face ID from multiple face IDs corresponding to user U's face image based on the similarities and differences between the first and second hash values. Specifically, the face ID management unit 115 identifies one face ID from multiple face IDs corresponding to user U's face image in the face ID database FDB whose first hash value is matched with the second hash value.
[0066] As a result, the account management device 10 can eliminate the possibility that the facial ID identified as the user's facial ID is not limited to one, for example, when one person among several people with similar faces, such as twins, performs identity authentication. On the other hand, if the facial ID identified as the user's facial ID can be uniquely identified from the beginning, the account management device 10 can omit the generation of a second string by image recognition using a second captured image, and the generation of a second hash value corresponding to the second string. As a result, the account management device 10 can reduce its processing load.
[0067] 1-1-4: Configuration of terminal device 20-2 Since the configuration of terminal device 20-2 is the same as the example configuration of terminal device 20-1 shown in Figure 2, its illustration is omitted. For the sake of simplicity, the following explanation will mainly focus on the components included in the processing unit 21 among the components included in terminal device 20-2.
[0068] The acquisition unit 211 acquires a facial image of user U from the imaging device 26.
[0069] The output unit 212 outputs the user U's face image acquired by the acquisition unit 211 to the account management device 10. Subsequently, the acquisition unit 211 acquires a first string from the account management device 10.
[0070] Furthermore, if the account management device 10 has multiple face IDs corresponding to user U's face image, the display control unit 214 will display a message on the display 24 instructing the user U to capture a printed document of their personal information using the imaging device 26. User U will then capture a printed document of their personal information using the imaging device 26.
[0071] In this case, the acquisition unit 211 acquires an image of the printed document containing user U's personal information from the imaging device 26. As described above, this image is an example of a "second image". The output unit 212 outputs the second image to the account management device 10. Subsequently, the acquisition unit 211 acquires the first string from the account management device 10.
[0072] 1-2: Operation of the First Embodiment The operation of the account management system 1 according to the first embodiment will be described below with reference to Figures 6 to 8.
[0073] 1-2-1: Actions during account registration Figure 6 is a sequence diagram showing the operation of the account management system 1 during account registration.
[0074] In step S1, the processing unit 21 provided in the terminal device 20-1 functions as an acquisition unit 211. The processing unit 21 acquires a facial image of user U from the imaging device 26.
[0075] In step S2, the processing unit 21 in the terminal device 20-1 functions as an output unit 212. The processing unit 21 outputs the face image of user U acquired in step S1 to the account management device 10. The processing unit 11 in the account management device 10 functions as an acquisition unit 111. The processing unit 11 acquires the face image of user U from the terminal device 20-1.
[0076] In step S3, the processing unit 11 of the account management device 10 functions as an extraction unit 112. The processing unit 11 extracts feature quantities related to the features of the face image of user U, which was acquired in step S2.
[0077] In step S4, the processing unit 21 provided in the terminal device 20-1 functions as an acquisition unit 211. The processing unit 21 acquires a first image from the imaging device 26, which is an image of a printed document containing user U's personal information.
[0078] In step S5, the processing unit 21 in the terminal device 20-1 functions as an output unit 212. The processing unit 21 outputs the first image, which is an image of the printed document containing user U's personal information, acquired in step S4, to the account management device 10. The processing unit 11 in the account management device 10 functions as an acquisition unit 111. The processing unit 11 acquires the first image, which is an image of the printed document containing user U's personal information, from the terminal device 20-1.
[0079] In step S6, the processing unit 11 of the account management device 10 functions as an image recognition unit 113. The processing unit 11 performs image recognition on a first image, which is an image of a printed document containing the personal information of user U acquired in step S5, and generates a first string of characters representing the personal information.
[0080] In step S7, the processing unit 11 of the account management device 10 functions as an output unit 114. The processing unit 11 outputs the first string generated in step S6 to the terminal device 20-1. The processing unit 21 of the terminal device 20-1 functions as an acquisition unit 211. The processing unit 21 acquires the first string from the account management device 10.
[0081] In step S8, the processing unit 21 provided in the terminal device 20-1 functions as a generation unit 213. The processing unit 21 generates a first hash value by converting the first string obtained in step S7 using a hash function.
[0082] In step S9, the processing unit 21 in the terminal device 20-1 functions as an output unit 212. The processing unit 21 outputs the first hash value generated in step S8 to the account management device 10. The processing unit 11 in the account management device 10 functions as an acquisition unit 111. The processing unit 11 acquires the first hash value from the terminal device 20-1.
[0083] In step S10, the processing unit 21 in the terminal device 20-1 functions as a face ID management unit 115. The processing unit 21 generates a face ID based on the face image of user U.
[0084] In step S11, the processing unit 11 of the account management device 10 functions as a face ID management unit 115. The processing unit 21 associates the face ID generated in step S10, the feature quantities related to the features of the face image extracted in step S3, and the first hash value obtained in step S9, and stores them in the face ID database FDB stored in the storage device 12.
[0085] In step S12, the processing unit 11 of the account management device 10 functions as an account management unit 116. The processing unit 11 generates account information for user U, including user U's user ID, the first string generated in step S6, and the face ID generated in step S11.
[0086] In step S13, the processing unit 11 of the account management device 10 functions as an account management unit 116. The processing unit 11 stores the account information of user U generated in step S12 in the account database ADB stored in the storage device 12.
[0087] The order of the operations in steps S1 to S13 may be rearranged as appropriate, as long as it allows for the generation of user U's account information.
[0088] 1-2-2: First action during user authentication Figure 7 is a sequence diagram showing the operation of the account management system 1 during user authentication. Note that the operation shown in Figure 7 is the operation when there is only one face ID corresponding to the face image of user U obtained from the terminal device 20-2.
[0089] In step S21, the processing unit 21 in the terminal device 20-2 functions as an acquisition unit 211. The processing unit 21 acquires a facial image of user U from the imaging device 26.
[0090] In step S22, the processing unit 21 in the terminal device 20-2 functions as an output unit 212. The processing unit 21 outputs the face image of user U acquired in step S21 to the account management device 10. The processing unit 11 in the account management device 10 functions as an acquisition unit 111. The processing unit 11 acquires the face image of user U from the terminal device 20-2.
[0091] In step S23, the processing unit 11 of the account management device 10 functions as an extraction unit 112. The processing unit 11 extracts feature quantities related to the features of the face image of user U from the face image of user U acquired in step S22.
[0092] In step S24, the processing unit 11 of the account management device 10 functions as a face ID management unit 115. Based on the degree of agreement between the features extracted in step S23 and the features stored in the face ID database FDB, the processing unit 11 identifies the face ID corresponding to the face image of user U obtained from the terminal device 20-2. Here, it is assumed that only one face ID is identified.
[0093] In step S25, the processing unit 11 of the account management device 10 functions as an account management unit 116. The processing unit 11 identifies account information, including the face ID identified in step S24, from among the account information stored in the account database ADB.
[0094] In step S26, the processing unit 11 of the account management device 10 functions as an output unit 114. The processing unit 11 outputs the first string contained in the account information identified in step S25 to the terminal device 20-2. The processing unit 21 of the terminal device 20-2 functions as an acquisition unit 211. The processing unit 21 acquires the first string from the account management device 10.
[0095] The order of the operations in steps S21 to S26 may be rearranged as appropriate, as long as the account management device 10 can output the first string to the terminal device 20-2.
[0096] 1-2-3: Second action during user authentication Figure 8 is a sequence diagram showing the operation of the account management system 1 during user authentication. Note that the operation shown in Figure 8 is the operation when there are multiple face IDs corresponding to the face image of user U obtained from the terminal device 20-2.
[0097] In step S31, the processing unit 21 in the terminal device 20-2 functions as an acquisition unit 211. The processing unit 21 acquires a facial image of user U from the imaging device 26.
[0098] In step S32, the processing unit 21 in the terminal device 20-2 functions as an output unit 212. The processing unit 21 outputs the face image of user U acquired in step S31 to the account management device 10. The processing unit 11 in the account management device 10 functions as an acquisition unit 111. The processing unit 11 acquires the face image of user U from the terminal device 20-2.
[0099] In step S33, the processing unit 11 of the account management device 10 functions as an extraction unit 112. The processing unit 11 extracts feature quantities related to the features of the face image of user U from the face image of user U acquired in step S32.
[0100] In step S34, the processing unit 11 of the account management device 10 functions as a face ID management unit 115. Based on the degree of agreement between the feature quantities related to the features of user U's face image extracted in step S33 and the feature quantities stored in the face ID database FDB, the processing unit 11 identifies the face ID corresponding to the face image of user U obtained from the terminal device 20-2. Here, it is assumed that there are multiple identified face IDs.
[0101] In step S35, the processing unit 11 of the account management device 10 functions as an output unit 114. The processing unit 11 outputs specific information to the terminal device 20-2 indicating that the face ID corresponding to the face image acquired from the terminal device 20-2 is included in multiple face IDs stored in the face ID database FDB. The processing unit 21 of the terminal device 20-2 functions as an acquisition unit 211. The processing unit 21 outputs specific information from the account management device 10 indicating that the face ID corresponding to the face image acquired from the terminal device 20-2 is included in multiple face IDs stored in the face ID database FDB.
[0102] In step S36, the processing unit 21 provided in the terminal device 20-2 functions as an acquisition unit 211. The processing unit 21 acquires a second image from the imaging device 26, which is an image of a printed document containing user U's personal information.
[0103] In step S37, the processing unit 21 in the terminal device 20-2 functions as an output unit 212. The processing unit 21 outputs the second image, which is an image of the printed document containing user U's personal information, acquired in step S36, to the account management device 10. The processing unit 11 in the account management device 10 functions as an acquisition unit 111. The processing unit 11 acquires the second image, which is an image of the printed document containing user U's personal information, from the terminal device 20-2.
[0104] In step S38, the processing unit 11 of the account management device 10 functions as an image recognition unit 113. The processing unit 11 performs image recognition on a second image, which is an image of a printed document containing user U's personal information, acquired in step S37, and generates a second string of characters representing the personal information.
[0105] In step S39, the processing unit 11 of the account management device 10 functions as a face ID management unit 115. The processing unit 11 generates a second hash value by converting the second string generated in step S38 using a hash function.
[0106] In step S40, the processing unit 11 of the account management device 10 functions as a face ID management unit 115. From the multiple face IDs identified in step S34, the processing unit 11 identifies one face ID in which the first hash value corresponding to that face ID matches the second hash value generated in step S39.
[0107] In step S41, the processing unit 11 of the account management device 10 functions as an account management unit 116. The processing unit 11 identifies account information, including the face ID identified in step S40, from among the account information stored in the account database ADB.
[0108] In step S42, the processing unit 11 of the account management device 10 functions as an output unit 114. The processing unit 11 outputs the first string contained in the account information identified in step S41 to the terminal device 20-2. The processing unit 21 of the terminal device 20-2 functions as an acquisition unit 211. The processing unit 21 acquires the first string from the account management device 10.
[0109] The order of the operations in steps S31 to S42 may be rearranged as appropriate, as long as the account management device 10 can output the first string to the terminal device 20-2.
[0110] 1-3: Effects of the First Embodiment As described above, the account management device 10 according to this embodiment comprises an image recognition unit 113, a face ID management unit 115, and an account management unit 116. When registering an account corresponding to user U as a first person, the image recognition unit 113 generates a first captured image, which is generated when terminal device 20-1, as a first terminal device, captures a printed document containing user U's personal information, by image recognition, thereby generating a first string of characters indicating the personal information. When registering an account corresponding to user U as a first person, the face ID management unit 115 generates a face ID, which is an identifier that corresponds one-to-one with the face image of user U, based on the face image of user U, and manages the generated face ID in association with feature quantities related to the features of the face image. When registering an account corresponding to user U, the account management unit 116 generates account information for user U, including the first string of characters and the face ID, and manages the generated account information.
[0111] By having the above configuration, the account management device 10 allows a user to create an account for the second service without having to manually input their personal information into an IT device, even if the ID card corresponding to the first service is not corresponding to the second service, by using the ID card corresponding to the first service. For example, an elderly person unfamiliar with operating IT devices can easily create an account for the second service based on simple operations. Furthermore, by using an ID card that anyone can obtain, such as a My Number Card, as printed personal information, user U can create an account to use digital services even without possessing an IT device such as a smartphone or an email address for using IT devices. Moreover, since keyboard input is not required when creating an account, the account management device 10 can prevent malicious third parties from inputting information.
[0112] Furthermore, in the account management device 10 according to this embodiment, when authenticating user U as a first person, the face ID management unit 115 identifies a face ID corresponding to the face image acquired from terminal device 20-2 as a second terminal device, based on the degree of agreement between the feature quantities related to the features of the face image acquired from terminal device 20-2 as a second terminal device and the feature quantities related to the features of the face image acquired from terminal device 20-1 as a first terminal device. Also, when authenticating user U as a first person, the account management unit 116 identifies account information corresponding to the identified face ID and outputs a first string contained in the identified account information to terminal device 20-2.
[0113] By having the above configuration, the account management device 10 allows user U to authenticate their identity without having to manually enter their personal information. In particular, user U only needs to take a picture of their face with the imaging device 26 provided in the terminal device 20-2, thus increasing the convenience of identity authentication.
[0114] Furthermore, in the account management device 10 according to this embodiment, when registering accounts corresponding to multiple people, the image recognition unit 113 performs image recognition on multiple first captured images generated by the terminal device 20-1, which is a first terminal device, capturing printed materials of multiple pieces of personal information that correspond one-to-one with multiple people, thereby generating multiple first strings that correspond one-to-one with multiple pieces of personal information and represent multiple pieces of personal information. Also, when registering accounts corresponding to multiple people, the face ID management unit 115 generates multiple face IDs that correspond one-to-one with the face images of multiple people based on the face images of multiple people, and manages multiple first hash values generated from the generated multiple face IDs, feature quantities related to the features of the face images of multiple people, and multiple first strings that correspond one-to-one with the multiple first strings, in association with each other. When authenticating user U as the first person, if the face ID management unit 115 finds that the face ID corresponding to the face image acquired from terminal device 20-2 as the second terminal device is included in multiple face IDs, the image recognition unit 113 generates a second string representing user U's personal information by performing image recognition on a second captured image generated when terminal device 20-2 takes an image of a printed document containing user U's personal information. When authenticating user U, the face ID management unit 115 generates a second hash value from the second string and identifies one face ID from the multiple face IDs based on the similarity or difference between the first and second hash values.
[0115] By having the above configuration, the account management device 10 can eliminate the possibility that, for example, when one person among several people with similar faces, such as twins, attempts to authenticate themselves, the facial ID identified as their own facial ID may not be limited to just one. In other words, the account management device 10 can eliminate the possibility that it may identify not only the facial ID uniquely associated with user U, but also multiple facial IDs as the facial ID of user U. In such cases, user U only needs to capture images of their face and printed personal information using the imaging device 26 provided in the terminal device 20-2, thus increasing the convenience of authentication.
[0116] 2: Variant This disclosure is not limited to the embodiments illustrated above. Specific variations are illustrated below. Two or more embodiments arbitrarily selected from the following examples may be combined.
[0117] 2-1: Variation 1 As described above, when user U is authenticated, if multiple face IDs are initially identified as face IDs corresponding to user U's face image, the face ID management unit 115 in the account management device 10 generates a second hash value by converting the second string using a hash function. In this modified example 1, the second hash value may be output from the account management device 10 to the terminal device 20-2 and then stored in the terminal device 20-2. In this case, when user U authenticates for the second time or later using the terminal device 20-2, the terminal device 20-2 outputs the second hash value to the account management device 10 instead of the second captured image. The face ID management unit 115 in the account management device 10 identifies one face ID based on the similarities and differences between the first hash value corresponding to each of the multiple face IDs and the second hash value obtained from the terminal device 20-2. Specifically, the face ID management unit 115 identifies one face ID from among multiple face IDs whose first hash value matches the second hash value.
[0118] As a result, since multiple facial IDs were identified, after user U has authenticated their identity by having the printed personal information photographed by the second terminal device, they do not need to have the printed personal information photographed again by the terminal device 20-2 when performing further authentication.
[0119] 2-2: Variation 2 As described above, user U uses terminal device 20-1 when registering an account and terminal device 20-2 when authenticating their identity. In the first embodiment, terminal devices 20-1 and 20-2 are different devices. However, in this modified example 2, terminal devices 20-1 and 20-2 may be the same terminal device 20.
[0120] As a result, user U can use the same terminal device 20 for both account registration and identity verification. For example, user U can perform both account registration and identity verification by using terminal device 20, which is owned by the user.
[0121] 2-3: Variation 3 In the first embodiment described above, during user authentication, the account management device 10 outputs a first string to the terminal device 20-2. However, the target to which the account management device 10 outputs the first string is not limited to the terminal device 20-2. For example, the account management device 10 may output the first string to a server that provides services using the Internet. Such a server is an example of an "external device".
[0122] 2-4: Modification 4 In the first embodiment described above, during user authentication, if multiple facial IDs were initially identified, the terminal device 20-2 captured an image of user U's personal information printout. However, the terminal device 20-2 may capture both user U's face and user U's personal information printout, rather than being limited to cases where multiple facial IDs are identified. In this case, the account management device 10 uses both user U's facial image and a second captured image, which is an image of user U's personal information printout, to perform user U's authentication through multi-factor authentication.
[0123] 3: Others (1) In the embodiments described above, ROM and RAM were given as examples for the storage devices 12 and 22, but other suitable storage media include flexible disks, magneto-optical disks (e.g., compact disks, digital multipurpose disks, Blu-ray® disks), smart cards, flash memory devices (e.g., cards, sticks, key drives), CD-ROMs (Compact Disc-ROMs), registers, removable disks, hard disks, floppy® disks, magnetic strips, databases, servers, and other appropriate storage media. The program may also be transmitted from a network via a telecommunications line. The program may also be transmitted from a communication network NET via a telecommunications line.
[0124] (2) In the embodiments described above, the information, signals, etc. may be represented using any of the various different techniques. For example, the data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be mentioned throughout the above description may be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.
[0125] (3) In the embodiments described above, the input and output information may be stored in a specific location (e.g., memory) or managed using a management table. The input and output information may be overwritten, updated, or appended to. The output information may be deleted. The input information may be transmitted to other devices.
[0126] (4) In the embodiments described above, the determination may be made by a value represented using 1 bit (0 or 1), by a boolean value (true or false), or by a numerical comparison (for example, a comparison with a predetermined value).
[0127] (5) The processing procedures, sequences, flowcharts, etc., exemplified in the embodiments described above may be rearranged in order, as long as they do not contradict each other. For example, the methods described in this disclosure present various step elements using an exemplary order and are not limited to the specific order presented.
[0128] (6) Each function illustrated in Figures 1 to 8 is implemented by any combination of at least one of hardware and software. Furthermore, the method of implementing each functional block is not particularly limited. That is, each functional block may be implemented using one device that is physically or logically coupled, or it may be implemented using two or more physically or logically separated devices that are directly or indirectly connected (for example, using wired or wireless connections). A functional block may also be implemented by combining the above one device or the above multiple devices with software.
[0129] (7) The programs illustrated in the embodiments described above should be broadly interpreted to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, etc., whether they are called software, firmware, middleware, microcode, hardware description languages or by other names.
[0130] Furthermore, software, instructions, information, etc., may be transmitted and received via a transmission medium. For example, if software is transmitted from a website, server, or other remote source using at least one of wired technology (such as coaxial cable, fiber optic cable, twisted pair, or digital subscriber line (DSL)) and wireless technology (such as infrared or microwave), then at least one of these wired and wireless technologies is included in the definition of a transmission medium.
[0131] (8) In each of the above-mentioned forms, the terms “system” and “network” shall be used interchangeably.
[0132] (9) The information, parameters, etc. described in this disclosure may be expressed using absolute values, relative values from a given value, or other corresponding information.
[0133] (10) In the embodiments described above, the account management device 10 and terminal devices 20-1 to 20-2 may be mobile stations (MS). A mobile station may also be referred to by those skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or several other appropriate terms. In this disclosure, terms such as “mobile station,” “user terminal,” “user equipment (UE),” and “terminal” may be used interchangeably.
[0134] (11) In the embodiments described above, the terms “connected,” “coupled,” or any variation thereof means any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are “connected” or “coupled” with each other. The coupling or connection between elements may be a physical coupling or connection, a logical coupling or connection, or a combination thereof. For example, “connection” may be reinterpreted as “access.” As used in this disclosure, two elements are considered to be “connected” or “coupled” with each other using at least one of one or more wires, cables and printed electrical connections, and, in some non-limiting and non-exclusive examples, electromagnetic energy having wavelengths in the radio frequency domain, microwave domain and optical (both visible and invisible) domain.
[0135] (12) In the embodiments described above, the phrase “based on” does not mean “based solely on” unless otherwise specified. In other words, the phrase “based on” means both “based solely on” and “based at least on.”
[0136] (13) The terms “determining” and “determining” as used in this disclosure may encompass a wide variety of actions. “Determining” may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, inquiry (e.g., searching in a table, database or other data structure), and ascertaining. “Determining” may also include, for example, receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, and accessing (e.g., accessing data in memory). Furthermore, "judgment" and "decision" can include considering something as having been "judged" or "decided" after resolving, selecting, choosing, establishing, comparing, etc. In other words, "judgment" and "decision" can include considering something as having been "judged" or "decided" after some action. Also, "judgment (decision)" can be reinterpreted as "assuming," "expecting," "considering," etc.
[0137] (14) Where the terms “include,” “including,” and variations thereof are used in the embodiments described above, these terms are intended to be inclusive, as is the term “comprising.” Furthermore, the term “or” as used in this disclosure is not intended to be exclusive OR.
[0138] (15) In the present disclosure, if articles are added by translation, such as a, an, and the in English, the present disclosure may include the fact that the noun following these articles is plural.
[0139] (16) In this disclosure, the term “A and B are different” may mean “A and B are different from each other.” The term may also mean “A and B are each different from C.” Terms such as “separate” and “combine” may be interpreted in the same way as “different.”
[0140] (17) Each aspect / embodiment described herein may be used individually, in combination, or switched between as needed in practice. Furthermore, notification of certain information (e.g., notification that "X is") is not limited to explicit notification, but may also be implicit (e.g., by not providing such notification).
[0141] Although the present disclosure has been described in detail above, it will be clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the intent and scope of the present disclosure as defined by the claims. Accordingly, the descriptions in the present disclosure are illustrative and not restrictive in any way. [Explanation of symbols]
[0142] 1...Account management system, 10...Account management device, 11...Processing device, 12...Storage device, 13...Communication device, 14...Display, 15...Input device, 20...Terminal device, 21...Processing device, 22...Storage device, 23...Communication device, 24...Display, 25...Input device, 26...Imaging device, 111...Acquisition unit, 112...Extraction unit, 113...Image recognition unit, 114...Output unit, 115...Face ID management unit, 116...Account management unit, 211...Acquisition unit, 212...Output unit, 213...Generation unit, 214...Display control unit, PR1...Control program, PR2...Control program
Claims
1. When registering an account corresponding to a first person, an image recognition unit generates a first captured image by image recognition of a first captured image generated when a first terminal device captures a printed document containing the personal information of the first person, thereby generating a first string of characters representing the personal information. A face ID management unit generates a face ID, which is an identifier that corresponds one-to-one with the face image of the first person, when registering an account corresponding to the first person, and manages the generated face ID in association with feature quantities related to the features of the face image. An account management unit generates account information for the first person, including the first string and the face ID, when registering an account corresponding to the first person, and manages the generated account information. Equipped with, When authenticating the first person, the face ID management unit identifies the face ID corresponding to the face image acquired from the second terminal device based on the degree of agreement between the feature quantities relating to the features of the face image acquired from the second terminal device and the feature quantities relating to the features of the face image acquired from the first terminal device. When authenticating the first person, the account management unit identifies account information corresponding to the identified facial ID, and outputs the first string contained in the identified account information to an external device. When registering an account for multiple individuals, the image recognition unit performs image recognition on multiple first captured images generated by the first terminal device capturing printed materials containing multiple pieces of personal information that correspond one-to-one with the multiple individuals, thereby generating multiple first strings that correspond one-to-one with the multiple pieces of personal information and represent the multiple pieces of personal information. When registering accounts corresponding to the aforementioned multiple persons, the face ID management unit generates multiple face IDs that correspond one-to-one with the face images of the aforementioned multiple persons based on the face images of the aforementioned multiple persons, and manages the generated multiple face IDs, feature quantities relating to the features of the face images of the aforementioned multiple persons, and multiple first hash values generated from the aforementioned multiple first strings that correspond one-to-one with the aforementioned multiple first strings, in association with each other. When authenticating the first person, if the face ID management unit finds that multiple face IDs corresponding to the face image acquired from the second terminal device are included among the multiple face IDs, the image recognition unit generates a second string of characters indicating the personal information of the first person by performing image recognition on a second captured image generated when the second terminal device captures a printed document containing the personal information of the first person. An account management device that, upon authentication of the first person, generates a second hash value from the second string, and identifies one face ID from the multiple face IDs based on the similarity or difference between the first hash value and the second hash value.
2. When authenticating the first person, the facial ID management unit outputs the generated second hash value to the second terminal device. Upon further authentication of the first person, the facial ID management unit obtains the second hash value stored in the second terminal device from the second terminal device, and identifies the one facial ID based on the similarity or difference between the first hash value and the obtained second hash value. The account management device according to claim 1.
3. The account management device according to claim 1, wherein the first terminal device and the second terminal device are the same terminal device.
Citation Information
Patent Citations
Business technique based on vehicle history information, and storage medium
JP2002279298A
Automatic input method of information by organismic authentication, its automatic input system and its automatic input program
JP2003150557A
Cloud service providing system
JP2015032108A
JPP7108243B
Account management system, and account management system control method and program
WO2013001573A1