Information processing device, information processing method, and recording medium

Facial authentication and password generation from possession and biometric information address the insecurity and complexity of traditional access methods, ensuring secure and convenient access management.

JP7861844B2Active Publication Date: 2026-05-19NEC CORP
View PDF 12 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
NEC CORP
Filing Date
2022-06-20
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing information access methods, such as passwords and one-time passwords, are cumbersome and insecure, particularly when confidentiality is compromised.

Method used

Facial authentication using a stored facial image and a captured facial image, combined with password generation based on possession information and biometric information, to enhance security and reduce user burden.

Benefits of technology

Facial recognition ensures secure access management, reduces the need for remembering passwords, and prevents unauthorized access even if the password is known, while generating passwords from possession and biometric information further enhances security and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007861844000001
    Figure 0007861844000001
  • Figure 0007861844000002
    Figure 0007861844000002
  • Figure 0007861844000003
    Figure 0007861844000003
Patent Text Reader

Abstract

This information processing device (10) comprises: a password acquisition means (110) that acquires a password set for an object held by a user; a first image acquisition means (120) that acquires a first image, which is a face image of the user and is stored in the held object, by using the password; a second image acquisition means (130) that images the face of the user to acquire a second image, which is a face image of the user; and an authentication means (140) that compares the first image and the second image to execute facial authentication of the user. Such an information processing device makes it possible to suitably manage information by using a password.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the technical field of information processing apparatuses, information processing methods, and recording media.

Background Art

[0002] When accessing recorded information, for example, an input such as a password may be required. For example, in Patent Document 1, it is disclosed that a personal identification number, a security code, or the like is used to access a unique information storage device storing data of various personal information.

[0003] As other related technologies, for example, in Patent Document 2, it is disclosed that a one-time password is generated using an OTP generation key. In Patent Document 3, it is disclosed that authentication of an individual is performed based on a photograph read from a public certificate or the like and an image of a user.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0005] This disclosure aims to improve the technologies disclosed in the prior art documents.

Means for Solving the Problems

[0006] One aspect of the information processing device disclosed herein includes: password acquisition means for acquiring a password set on a user's possession; first image acquisition means for acquiring a first image, which is a facial image of the user stored in the possession, using the password; second image acquisition means for capturing the user's face and acquiring a second image, which is a facial image of the user; and authentication means for comparing the first image and the second image to perform facial authentication of the user.

[0007] One aspect of the information processing method of this disclosure involves using at least one computer to obtain a password set on a user's possession, using the password to obtain a first image which is a facial image of the user stored in the possession, taking a photograph of the user's face to obtain a second image which is a facial image of the user, and performing facial authentication of the user by comparing the first image and the second image.

[0008] One aspect of the recording medium of this disclosure includes recording on at least one computer a computer program that causes the computer to execute an information processing method which involves obtaining a password set on a user's possession, using the password to obtain a first image which is a facial image of the user stored in the possession, taking a photograph of the user's face to obtain a second image which is a facial image of the user, and comparing the first image and the second image to perform facial authentication of the user.

[0009] Another aspect of the information processing device of this disclosure includes: an item information acquisition means for acquiring item information from a user's possessions; a biometric information acquisition means for acquiring biometric information from the user; and a password generation means for generating a password to be set for the user's possessions by combining the item information and the biometric information.

[0010] Another aspect of the information processing method of this disclosure involves using at least one computer to obtain possession information from a user's possessions, obtain biometric information from the user, and combine the possession information and the biometric information to generate a password to be set for the user's possessions.

[0011] Another aspect of the recording medium of this disclosure includes recording on at least one computer a computer program that causes the computer to execute an information processing method that retrieves possession information from a user's possessions, retrieves biometric information from the user, and combines the possession information and the biometric information to generate a password to be set for the user's possessions. [Brief explanation of the drawing]

[0012] [Figure 1] This is a block diagram showing the hardware configuration of the information processing device according to the first embodiment. [Figure 2] This is a block diagram showing the functional configuration of the information processing apparatus according to the first embodiment. [Figure 3] This is a flowchart showing the operation flow of the information processing device according to the first embodiment. [Figure 4] This is a block diagram showing the functional configuration of the information processing device according to the second embodiment. [Figure 5] This is a flowchart showing the flow of authentication operations by the information processing device according to the second embodiment. [Figure 6] This is a block diagram showing the functional configuration of the information processing device according to the third embodiment. [Figure 7] This is a flowchart showing the flow of the password generation operation by the information processing device according to the third embodiment. [Figure 8] This is a block diagram showing the functional configuration of the information processing apparatus according to the fourth embodiment. [Figure 9] This is a flowchart showing the flow of the password generation operation by the information processing device according to the fourth embodiment. [Figure 10] This is a block diagram showing the functional configuration of the information processing apparatus according to the fifth embodiment. [Figure 11] This is a flowchart showing the flow of the password generation operation by the information processing device according to the fifth embodiment. [Figure 12] This is a block diagram showing the functional configuration of the information processing apparatus according to the sixth embodiment. [Figure 13] This is a flowchart showing the operation flow of the information processing apparatus according to the sixth embodiment.

Embodiments for Carrying Out the Invention

[0013] Hereinafter, embodiments of an information processing apparatus, an information processing method, and a recording medium will be described with reference to the drawings.

[0014] <First Embodiment> The information processing apparatus according to the first embodiment will be described with reference to FIGS. 1 to 3.

[0015] (Hardware Configuration) First, the hardware configuration of the information processing apparatus according to the first embodiment will be described with reference to FIG. 1. FIG. 1 is a block diagram showing the hardware configuration of the information processing apparatus according to the first embodiment.

[0016] As shown in FIG. 1, the information processing apparatus 10 according to the first embodiment includes a processor 11, a RAM (Random Access Memory) 12, a ROM (Read Only Memory) 13, and a storage device 14. The information processing apparatus 10 may further include an input device 15, an output device 16, and a camera 18. The above-described processor 11, RAM 12, ROM 13, storage device 14, input device 15, output device 16, and camera 18 are connected via a data bus 17.

[0017] The processor 11 reads a computer program. For example, the processor 11 is configured to read a computer program stored in at least one of the RAM 12, ROM 13, and storage device 14. Alternatively, the processor 11 may read a computer program stored in a computer-readable storage medium using a storage medium reading device (not shown). The processor 11 may also obtain (i.e., read) a computer program from a device (not shown) located outside the information processing device 10 via a network interface. The processor 11 controls the RAM 12, storage device 14, input device 15, and output device 16 by executing the read computer program. In this embodiment in particular, when the processor 11 executes the read computer program, a functional block for obtaining a password and performing authentication processing is realized within the processor 11. That is, the processor 11 may function as a controller that executes each control in the information processing device 10.

[0018] The processor 11 may be configured as, for example, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (field-programmable gate array), a DSP (Demand-Side Platform), or an ASIC (Application Specific Integrated Circuit). The processor 11 may consist of one of these, or it may be configured to use multiple of them in parallel.

[0019] RAM12 temporarily stores computer programs executed by processor 11. RAM12 also temporarily stores data that processor 11 uses temporarily while executing computer programs. RAM12 may be, for example, D-RAM (Dynamic Random Access Memory) or SRAM (Static Random Access Memory). Alternatively, other types of volatile memory may be used instead of RAM12.

[0020] ROM 13 stores computer programs executed by processor 11. ROM 13 may also store other static data. ROM 13 may be, for example, P-ROM (Programmable Read Only Memory) or EPROM (Erasable Read Only Memory). Alternatively, other types of non-volatile memory may be used instead of ROM 13.

[0021] The storage device 14 stores data that the information processing device 10 will save for a long period of time. The storage device 14 may also operate as a temporary storage device for the processor 11. The storage device 14 may include, for example, at least one of a hard disk drive, a magneto-optical disk drive, an SSD (Solid State Drive), and a disk array device.

[0022] The input device 15 is a device that receives input instructions from the user of the information processing device 10. The input device 15 may include, for example, at least one of a keyboard, a mouse, and a touch panel. The input device 15 may be configured as a mobile terminal such as a smartphone or tablet. The input device 15 may also be a device capable of voice input, for example, including a microphone.

[0023] The output device 16 is a device that outputs information related to the information processing device 10 to the outside. For example, the output device 16 may be a display device (e.g., a display) capable of displaying information related to the information processing device 10. Alternatively, the output device 16 may be a speaker or the like capable of outputting information related to the information processing device 10 as sound. The output device 16 may be configured as a mobile terminal such as a smartphone or tablet. Furthermore, the output device 16 may be a device that outputs information in a format other than an image. For example, the output device 16 may be a speaker that outputs information related to the information processing device 10 as sound.

[0024] Camera 18 is configured to capture images of the user's face. Camera 18 may be, for example, a camera installed on the system, or a camera built into a device owned by the user (for example, a smartphone or tablet). Multiple cameras 18 may be provided.

[0025] Although Figure 1 shows an example of an information processing device 10 comprising multiple devices, all or some of these functions may be implemented in a single device. In that case, the information processing device may be configured to include only the processor 11, RAM 12, and ROM 13 described above, and the other components (i.e., storage device 14, input device 15, output device 16, camera 18) may be provided by external devices connected to the information processing device. Furthermore, the information processing device may implement some of its computational functions through external devices (e.g., external servers or cloud services).

[0026] (Functional configuration) Next, the functional configuration of the information processing device 10 according to the first embodiment will be described with reference to Figure 2. Figure 2 is a block diagram showing the functional configuration of the information processing device according to the first embodiment.

[0027] The information processing device 10 according to the first embodiment is configured as a device that manages information using passwords regarding possessions owned by the user. Possessions are configured to store various types of information, and examples include terminals such as smartphones and tablets, or cards equipped with IC chips.

[0028] As shown in Figure 2, the information processing device 10 according to the first embodiment is configured to include a password acquisition unit 110, a first image acquisition unit 120, a second image acquisition unit 130, and an authentication unit 140 as components for realizing its functions. Each of the password acquisition unit 110, the first image acquisition unit 120, the second image acquisition unit 130, and the authentication unit 140 may be a processing block realized by, for example, the processor 11 (see Figure 1) described above.

[0029] The password acquisition unit 110 is configured to acquire the password set for the user's possession. The password may be, for example, a password for accessing information stored in the possession. The password acquisition unit 110 may acquire the password entered by the user, for example. Alternatively, the password acquisition unit 110 may read and acquire the password. Alternatively, the password acquisition unit 110 may generate and acquire a password using the input information. The configuration for generating a password will be explained in detail in other embodiments described later. The password acquired by the password acquisition unit 110 is output to the first image acquisition unit 120.

[0030] The first image acquisition unit 120 is configured to acquire a first image, which is a user's facial image stored in an item, using the password acquired by the password acquisition unit 110. The first image is only obtainable using the password and is protected so that it cannot be acquired (accessed) if the password is not known. An example of the first image is a facial image stored in a driver's license or My Number card, but the first image in this embodiment is not limited to these. The first image acquired by the first image acquisition unit 120 is output to the authentication unit 140.

[0031] The second image acquisition unit 130 is configured to capture a second image, which is a facial image of the user, by photographing the user who is holding the item. The second image may be automatically captured by, for example, an installed camera 18, or it may be captured by the user using a camera 18 owned by the user (for example, a smartphone camera). When the user takes the second image, the second image acquisition unit 130 may display a message prompting the user to take a picture of their own face. The second image acquired by the second image acquisition unit 130 is output to the authentication unit 140.

[0032] The authentication unit 140 performs facial recognition by comparing the first image acquired by the first image acquisition unit 120 (i.e., the image stored in the possession) with the second image acquired by the second image acquisition unit 130 (i.e., the image acquired by photographing the user). Note that a detailed explanation of the specific facial recognition method is omitted here, as existing technologies can be appropriately adopted. The authentication unit 140 may also have a function to output the facial recognition result (hereinafter referred to as "authentication result" as appropriate). In this case, the authentication unit 140 may output the authentication result via a display, speaker, etc. Furthermore, the authentication unit 140 may be configured to execute various processes depending on the success or failure of the authentication result.

[0033] (Flow of operations) Next, with reference to Figure 3, the overall operation flow of the information processing device 10 according to the first embodiment will be described. Figure 3 is a flowchart showing the operation flow of the information processing device according to the first embodiment.

[0034] As shown in Figure 3, when the operation of the information processing device 10 according to the first embodiment is started, the password acquisition unit 110 first acquires a password (step S101). Then, the first image acquisition unit 120 acquires a first image using the password acquired by the password acquisition unit 110 (step S102).

[0035] Next, the second image acquisition unit 130 takes a picture of the user holding the item and acquires a second image (step S103). Note that the process in step S103 may be executed simultaneously with and in parallel with the processes in steps S101 and S102 described above. Alternatively, the process in step S103 may be executed before the processes in steps S101 and S102 described above.

[0036] Next, the authentication unit 140 compares the first image acquired by the first image acquisition unit 120 with the second image acquired by the second image acquisition unit 130 to perform face authentication (step S104). Then, the authentication unit 140 outputs the authentication result (step S105).

[0037] (Technical effects) Next, the technical effects obtained by the information processing device 10 according to the first embodiment will be described.

[0038] As explained in Figures 1 to 3, in the information processing device 10 according to the first embodiment, facial recognition is performed using a first image obtained using a password and a second image obtained by photographing the user. In this way, information stored in the device can be properly managed regardless of the confidentiality of the password. For example, even if the password is misused, if the user whose facial image is stored in the device does not match the user who was photographed, facial recognition will fail. Therefore, by allowing or denying access to the information stored in the device according to the authentication result, information can be properly managed.

[0039] Furthermore, since confidentiality is guaranteed by facial recognition, the need for confidentiality in passwords disappears. This means, for example, that there is no need to remember passwords. Specifically, even if a password is known and usable by an unspecified number of users, the information stored on the device will be protected by facial recognition.

[0040] <Second Embodiment> The information processing device 10 according to the second embodiment will be described with reference to Figures 4 and 5. Note that the second embodiment differs from the first embodiment described above only in some configurations and operations; other parts may be identical to the first embodiment. Therefore, the following will describe in detail the parts that differ from the first embodiment already described, and will omit explanations of other overlapping parts as appropriate.

[0041] (Functional configuration) First, the functional configuration of the information processing device 10 according to the second embodiment will be described with reference to Figure 4. Figure 4 is a block diagram showing the functional configuration of the information processing device according to the second embodiment. Note that in Figure 4, the same reference numerals are used for elements similar to those shown in Figure 2.

[0042] As shown in Figure 4, the information processing device 10 according to the second embodiment is configured to include a password acquisition unit 110, a first image acquisition unit 120, a second image acquisition unit 130, an authentication unit 140, and a invalidation unit 150 as components for realizing its functions. That is, the information processing device 10 according to the second embodiment further includes a invalidation unit 150 in addition to the configuration of the first embodiment (see Figure 2). The invalidation unit 150 may be, for example, a processing block realized by the processor 11 (see Figure 1) described above.

[0043] The invalidation unit 150 is configured to invalidate the password set for the possessed item. Specifically, the invalidation unit 150 is configured to invalidate the password when facial recognition by the authentication unit 140 fails. The invalidation unit 150 may also be configured to invalidate the password if facial recognition fails multiple times in a row. Furthermore, the invalidation of the password by the invalidation unit 150 may be temporary. For example, the invalidation unit 150 may invalidate the password until a predetermined period of time has elapsed since the facial recognition by the authentication unit 140 failed.

[0044] (Authentication process) Next, with reference to Figure 5, the flow of the authentication operation by the information processing device 10 according to the second embodiment (i.e., the operation when performing facial recognition using the first and second images) will be explained. Figure 5 is a flowchart showing the flow of the authentication operation by the information processing device according to the second embodiment.

[0045] As shown in Figure 5, when the authentication operation by the information processing device 10 according to the second embodiment is started, the authentication unit 140 first determines whether the first image and the second image match (step S201). If the first image and the second image match (step S201: YES), the authentication unit 140 outputs a result indicating successful authentication (step S202). In this case, the invalidation unit 150 does not invalidate the password.

[0046] On the other hand, if the first image and the second image match (step S201: YES), the authentication unit 140 outputs a result indicating authentication failure (step S203). In this case, the invalidation unit 150 executes a process to invalidate the password (step S204).

[0047] The invalidation unit 150 may, in addition to or instead of invalidating the password, perform other processing (i.e., processing to protect information in the event of a failure in facial recognition). For example, the invalidation unit 150 may perform processing to output an alert, processing to temporarily lock the user's possessions, etc., in the event of a failure in facial recognition.

[0048] (Technical effects) Next, the technical effects obtained by the information processing device 10 according to the second embodiment will be described.

[0049] As explained in Figures 4 and 5, in the information processing device 10 according to the second embodiment, the password is invalidated if facial recognition fails. In this way, if a user other than the user who possesses the item uses the password, the password will be invalidated and they will not be able to access the information stored in the item. Thus, it is possible to prevent unauthorized use of the password. This effect is particularly evident, for example, when the password is known.

[0050] <Third Embodiment> The information processing device 10 according to the third embodiment will be described with reference to Figures 6 and 7. Note that the third embodiment differs from the first and second embodiments described above only in some configurations and operations; other parts may be identical to those of the first and second embodiments. Therefore, the following will provide a detailed explanation of the parts that differ from the embodiments already described, while other overlapping parts will be omitted as appropriate.

[0051] (Functional configuration) First, the functional configuration of the information processing device 10 according to the third embodiment will be described with reference to Figure 6. Figure 6 is a block diagram showing the functional configuration of the information processing device according to the third embodiment. Note that in Figure 6, the same reference numerals are used for elements similar to those shown in Figure 2.

[0052] As shown in Figure 6, the information processing device 10 according to the third embodiment is configured to include a password acquisition unit 110, a first image acquisition unit 120, a second image acquisition unit 130, an authentication unit 140, and a first password generation unit 160 as components for realizing its functions. That is, the information processing device 10 according to the third embodiment further includes a first password generation unit 160 in addition to the configuration of the first embodiment (see Figure 2). The first password generation unit 160 may be, for example, a processing block realized by the processor 11 (see Figure 1) described above.

[0053] The first password generation unit 160 is configured to generate a password based on possession information obtained from the possession. Possession information may be characters written on the possession. For example, possession information may be characters (name, address, various numbers, etc.) that can be read from the surface of a driver's license, My Number card, passport, and various other cards. Alternatively, possession information may be the color, pattern, design, or shape of the possession itself. Alternatively, possession information may be information stored in the possession information. For example, possession information may be information stored in the magnetic stripe or IC chip of a card, or information indicating the unique ID of a terminal such as a smartphone. As for the specific algorithm for generating a password from possession information, existing algorithms can be adopted as appropriate, so a detailed explanation is omitted here.

[0054] (Password generation process) Next, with reference to Figure 7, the flow of the password generation operation by the information processing device 10 according to the third embodiment (i.e., the operation when the first password generation unit 160 generates a password) will be explained. Figure 7 is a flowchart showing the flow of the password generation operation by the information processing device according to the third embodiment.

[0055] As shown in Figure 7, when the password generation operation by the information processing device 10 according to the third embodiment is started, the first password generation unit 160 first acquires possession information from the user's possessions (step S301). Then, the first password generation unit 160 seeds the possession information acquired from the possessions (step S302). That is, it performs a process to convert the possession information, which is in its acquired state, into a state in which a password can be generated (for example, a process to convert it into a string).

[0056] Next, the first password generation unit 160 generates a password using the seed generated from the possession information (step S303). The first password generation unit 160 may generate a password using multiple types of seeds. For example, the first password generation unit 160 may acquire multiple types of possession information, convert each of them into multiple seeds, and combine the multiple seeds to generate a password. In addition, the first password generation unit 160 may generate a password using seeds converted from information other than possession information (for example, low-load memory information) in addition to the seeds converted from possession information.

[0057] (Technical effects) Next, the technical effects obtained by the information processing device 10 according to the third embodiment will be described.

[0058] As explained in Figures 6 and 7, in the information processing device 10 according to the third embodiment, a password is generated based on the information of the possessed item. In this way, even if the password is not memorized, a password can be appropriately generated from the information of the possessed item. Therefore, the burden on the user to remember the password can be reduced. It should be noted that enabling password generation from the information of the possessed item may compromise the confidentiality of the password (for example, the password may be misused by another user who has illegally obtained the possessed item), but as already explained, the information stored in the possessed item is ultimately protected by facial recognition, so no inconvenience occurs.

[0059] <Fourth Embodiment> The information processing device 10 according to the fourth embodiment will be described with reference to Figures 8 and 9. Note that the fourth embodiment differs from the first to third embodiments described above only in some configurations and operations; other parts may be identical to those of the first to third embodiments. Therefore, the following will describe in detail the parts that differ from the embodiments already described, while omitting explanations of other overlapping parts as appropriate.

[0060] (Functional configuration) First, the functional configuration of the information processing device 10 according to the fourth embodiment will be described with reference to Figure 8. Figure 8 is a block diagram showing the functional configuration of the information processing device according to the fourth embodiment. Note that in Figure 8, the same reference numerals are used for elements similar to those shown in Figure 2.

[0061] As shown in Figure 8, the information processing device 10 according to the fourth embodiment is configured to include a password acquisition unit 110, a first image acquisition unit 120, a second image acquisition unit 130, an authentication unit 140, and a second password generation unit 170 as components for realizing its functions. That is, the information processing device 10 according to the fourth embodiment further includes a second password generation unit 170 in addition to the configuration of the first embodiment (see Figure 2). The second password generation unit 170 may be, for example, a processing block realized by the processor 11 (see Figure 1) described above.

[0062] The second password generation unit 170 is configured to generate a password based on biometric information obtained from the user. The biometric information may be features obtainable from the user's body. For example, the biometric information may be features representing the user's face, fingerprints, palm print, iris, or ear acoustics. These features may be obtained from images captured by the camera 18, or from various scanners or sensors. When obtaining biometric information, processing to prevent perjury (e.g., impersonation detection or liveness detection) may be performed. As for the specific algorithm for generating a password from biometric information, existing algorithms can be appropriately adopted, so a detailed explanation is omitted here.

[0063] (Password generation process) Next, with reference to Figure 9, the flow of the password generation operation by the information processing device 10 according to the fourth embodiment (i.e., the operation when the second password generation unit 170 generates a password) will be explained. Figure 9 is a flowchart showing the flow of the password generation operation by the information processing device according to the fourth embodiment.

[0064] As shown in Figure 9, when the password generation operation by the information processing device 10 according to the fourth embodiment is started, the second password generation unit 170 first acquires biometric information from the user (step S401). Then, the second password generation unit 170 seeds the biometric information acquired from the user (step S402). That is, it performs a process to convert the biometric information, which is in its acquired state, into a state in which a password can be generated (for example, a process to convert it into a string).

[0065] Next, the second password generation unit 170 generates a password using the seed generated from the biometric information (step S403). The second password generation unit 170 may generate a password using multiple types of seeds. For example, the second password generation unit 170 may acquire multiple types of biometric information, convert each of them into multiple seeds, and combine the multiple seeds to generate a password. In addition, the second password generation unit 170 may generate a password using seeds converted from information other than biometric information (for example, low-load stored information) in addition to seeds converted from biometric information.

[0066] (Technical effects) Next, the technical effects obtained by the information processing device 10 according to the fourth embodiment will be described.

[0067] As explained in Figures 8 and 9, in the information processing device 10 according to the fourth embodiment, a password is generated based on biometric information. In this way, even if the password is not memorized, a password can be appropriately generated from the biometric information. Therefore, the burden on the user to remember passwords can be reduced. In addition, since biometric information is difficult to forge, the reliability of the password can be increased. Furthermore, even if the biometric information used to generate the password is forged, the information stored in the possession will ultimately be protected by facial recognition, so no problems will occur.

[0068] <Fifth Embodiment> The information processing device 10 according to the fifth embodiment will be described with reference to Figures 10 and 11. Note that the fifth embodiment differs from the first to fourth embodiments described above only in some configurations and operations; other parts may be identical to the first to fourth embodiments. Therefore, the following will describe in detail the parts that differ from the embodiments already described, while other overlapping parts will be omitted as appropriate.

[0069] (Functional configuration) First, the functional configuration of the information processing device 10 according to the fifth embodiment will be described with reference to Figure 10. Figure 10 is a block diagram showing the functional configuration of the information processing device according to the fifth embodiment. Note that in Figure 10, the same reference numerals are used for elements similar to those shown in Figure 2.

[0070] As shown in Figure 10, the information processing device 10 according to the fifth embodiment is configured to include a password acquisition unit 110, a first image acquisition unit 120, a second image acquisition unit 130, an authentication unit 140, and a third password generation unit 180 as components for realizing its functions. That is, the information processing device 10 according to the fifth embodiment further includes a third password generation unit 180 in addition to the configuration of the first embodiment (see Figure 2). The third password generation unit 180 may be, for example, a processing block realized by the processor 11 (see Figure 1) described above.

[0071] The third password generation unit 180 is configured to generate a password based on both possession information obtained from possessions and biometric information obtained from the user themselves. The possession information here may be the same as the possession information described in the third embodiment (i.e., the information used by the first password generation unit 160). The biometric information may be the same as the biometric information described in the fourth embodiment (i.e., the information used by the second password generation unit 170). As for the specific algorithm for generating a password from possession information and biometric information, existing algorithms can be appropriately adopted, so a detailed explanation is omitted here.

[0072] (Password generation process) Next, with reference to Figure 11, the flow of the password generation operation by the information processing device 10 according to the fifth embodiment (i.e., the operation when the third password generation unit 180 generates a password) will be described. Figure 11 is a flowchart showing the flow of the password generation operation by the information processing device according to the fifth embodiment.

[0073] As shown in Figure 11, when the password generation operation by the information processing device 10 according to the fifth embodiment is started, the third password generation unit 180 first acquires possession information from the user's possessions (step S501). Then, the third password generation unit 180 seeds the possession information acquired from the possessions (step S502).

[0074] Furthermore, the third password generation unit 180 obtains biometric information from the user (step S503). Then, the third password generation unit 180 seeds the biometric information obtained from the user (step S504). Note that the processes in steps S501 and S502 described above (i.e., the process of obtaining and seeding possession information) and the processes in steps S503 and S504 (i.e., the process of obtaining and seeding biometric information) may be executed simultaneously and in parallel, or they may be executed one before the other.

[0075] Next, the third password generation unit 180 generates a password by combining a seed generated from possession information and a seed generated from biometric information (step S505). The third password generation unit 180 may also generate a password using multiple types of seeds generated from possession information and multiple types of seeds generated from biometric information. Furthermore, the third password generation unit 180 may generate a password using seeds converted from information other than possession information and biometric information (for example, low-load memory information) in addition to seeds converted from possession information and biometric information.

[0076] (Technical effects) Next, the technical effects obtained by the information processing device 10 according to the fifth embodiment will be described.

[0077] As explained in Figures 10 and 11, the information processing device 10 according to the fifth embodiment generates a password based on both possession information and biometric information. In this way, even if the user does not remember the password, a password can be appropriately generated from the possession information and biometric information. Therefore, the burden on the user to remember the password can be reduced. Furthermore, a more secure password can be generated compared to when a password is generated using only possession information or only biometric information.

[0078] The information processing device 10 may be configured to include at least two of the first password generation unit 160 described in the third embodiment, the second password generation unit 170 described in the fourth embodiment, and the third password generation unit 180 described in the fifth embodiment. That is, the information processing device 10 may be configured to appropriately select and execute password generation using possession information, password generation using biometric information, and password generation using both possession information and biometric information.

[0079] <Sixth Embodiment> The information processing device 20 according to the sixth embodiment will be described with reference to Figure 12. Unlike the first to fifth embodiments described above, the information processing device 20 according to the sixth embodiment is configured as a device for generating passwords. However, the information processing device 20 according to the sixth embodiment has many parts in common with the first to fifth embodiments, and for example, the hardware configuration may be the same as that of the first embodiment (see Figure 1). For this reason, the following will describe in detail the parts that differ from each embodiment already described, and will omit explanations of other overlapping parts as appropriate.

[0080] (Functional configuration) First, the functional configuration of the information processing device 20 according to the sixth embodiment will be described with reference to Figure 12. Figure 12 is a block diagram showing the functional configuration of the information processing device according to the sixth embodiment.

[0081] As shown in Figure 12, the information processing device 20 according to the sixth embodiment is configured to include, as components for realizing its functions, a possession information acquisition unit 210, a biometric information acquisition unit 220, and a password generation unit 230. Each of the possession information acquisition unit 210, the biometric information acquisition unit 220, and the password generation unit 230 may be a processing block realized by, for example, the processor 11 (see Figure 1) described above.

[0082] The possession information acquisition unit 210 is configured to acquire possession information from the user's possessions. The possession information acquired by the possession information acquisition unit 210 may be the same as the possession information described in the third embodiment (i.e., the information used by the first password generation unit 160). The possession information acquisition unit 210 may also have a function to seed the possession information. The possession information acquired by the possession information acquisition unit 210 is output to the password generation unit 230.

[0083] The biometric information acquisition unit 220 is configured to acquire biometric information from the user. The biometric information acquired by the biometric information acquisition unit 220 may be the same as the biometric information described in the fourth embodiment (i.e., the information used by the second password generation unit 170). The biometric information acquisition unit 220 may also have a function to seed the biometric information. The biometric information acquired by the biometric information acquisition unit 220 is output to the password generation unit 230.

[0084] The password generation unit 230 is configured to generate a password based on both the possession information acquired by the possession information acquisition unit 210 and the biometric information acquired by the biometric information acquisition unit 220. A detailed explanation of the specific algorithm for generating a password from the possession information and biometric information is omitted here, as existing algorithms can be appropriately adopted.

[0085] (Flow of operations) Next, with reference to Figure 13, the overall operation flow of the information processing device 20 according to the sixth embodiment will be described. Figure 13 is a flowchart showing the operation flow of the information processing device according to the sixth embodiment.

[0086] As shown in Figure 13, the information processing device 20 according to the sixth embodiment first determines whether or not there is a password generation request (step S601). This password generation request may be, for example, initiated by a user operation or output from another device. If there is no password generation request (step S601: NO), the information processing device 20 may omit the subsequent processing and terminate the series of operations.

[0087] If a password generation request is made (step S601: YES), the possession information acquisition unit 210 acquires possession information from the user's possessions (step S602). Then, the possession information acquisition unit 210 seeds the possession information acquired from the possessions (step S603).

[0088] On the other hand, the biometric information acquisition unit 220 acquires biometric information from the user (step S604). The biometric information acquisition unit 220 then seeds the biometric information acquired from the user (step S605). The processes in steps S602 and S603 described above (i.e., the process of acquiring and seeding possession information) and the processes in steps S604 and S605 (i.e., the process of acquiring and seeding biometric information) may be executed simultaneously and in parallel, or they may be executed one before the other.

[0089] Next, the password generation unit 230 generates a password by combining the seed generated by the possession information acquisition unit 210 and the seed generated by the biometric information acquisition unit 220 (step S606). The password generation unit 230 may also generate a password using multiple types of seeds generated from possession information and multiple types of seeds generated from biometric information. In addition, the password generation unit 230 may generate a password using seeds converted from information other than possession and biometric information (for example, low-load memory information) in addition to seeds converted from possession information and biometric information.

[0090] Next, the password generation unit 230 outputs the generated password (step S607). The password generation unit 230 may, for example, output the generated password to a display and present it to the user. Alternatively, the password generation unit 230 may output the generated password to an external device (for example, a device that uses the password).

[0091] (Technical effects) Next, the technical effects obtained by the information processing device 20 according to the sixth embodiment will be described.

[0092] As explained in Figures 12 and 13, the information processing device 20 according to the sixth embodiment generates a password by combining possession information and biometric information. In this way, even if the user does not remember the password, a password can be appropriately generated from the possession information and biometric information. Therefore, the burden on the user to remember the password can be reduced. Furthermore, by combining possession information and biometric information, a more secure password can be generated.

[0093] The processing method of recording a program that operates the configuration of each embodiment in order to realize the functions of each embodiment described above on a recording medium, reading the program recorded on the recording medium as code, and executing it on a computer is also included in the scope of each embodiment. In other words, a computer-readable recording medium is also included in the scope of each embodiment. Furthermore, not only the recording medium on which the above-mentioned program is recorded, but also the program itself is included in each embodiment.

[0094] Examples of recording media that can be used include floppy disks, hard disks, optical disks, magneto-optical disks, CD-ROMs, magnetic tapes, non-volatile memory cards, and ROMs. Furthermore, the scope of each embodiment is not limited to programs that perform processing on the recording media alone, but also includes programs that operate on the OS and perform processing in cooperation with other software and the functions of expansion boards. In addition, the program itself may be stored on a server, and part or all of the program may be made available for download from the server to the user terminal.

[0095] <Note> The embodiments described above may also be described in the following appendix, but are not limited to these.

[0096] (Note 1) The information processing device described in Appendix 1 is an information processing device comprising: password acquisition means for acquiring a password set on an item owned by a user; first image acquisition means for acquiring a first image, which is a facial image of the user stored in the item, using the password; second image acquisition means for capturing the user's face and acquiring a second image, which is a facial image of the user; and authentication means for comparing the first image and the second image to perform facial authentication of the user.

[0097] (Note 2) The information processing device described in Appendix 2 is the same as the information processing device described in Appendix 1, further comprising a means for invalidating the password in the event that the facial recognition fails.

[0098] (Note 3) The information processing device described in Appendix 3 further comprises a first password generation means that generates the password based on the possession information obtained from the possession, and the password acquisition means acquires the password generated by the first password generation means, as described in Appendix 1 or 2.

[0099] (Note 4) The information processing device described in Appendix 4 further comprises a second password generation means that generates the password based on biometric information obtained from the user, and the password acquisition means acquires the password generated by the second password generation means, as described in Appendix 1 or 2.

[0100] (Note 5) The information processing device described in Appendix 5 further comprises a third password generation means that generates the password by combining the possession information obtained from the possession and the biometric information obtained from the user, and the password acquisition means acquires the password generated by the third password generation means, and is the information processing device described in Appendix 1 or 2.

[0101] (Note 6) The information processing method described in Appendix 6 is an information processing method which involves at least one computer obtaining a password set on the user's possession, using the password to obtain a first image which is the user's face image stored on the possession, taking a picture of the user's face to obtain a second image which is the user's face image, and comparing the first image and the second image to perform facial recognition of the user.

[0102] (Note 7) The recording medium described in Appendix 7 is a recording medium on which a computer program is recorded that causes at least one computer to execute an information processing method that retrieves a password set on a user's possession, uses the password to retrieve a first image which is a facial image of the user stored on the possession, takes a picture of the user's face to retrieve a second image which is a facial image of the user, compares the first image and the second image to perform facial recognition of the user.

[0103] (Note 8) The information processing system described in Appendix 8 is an information processing system comprising: password acquisition means for acquiring a password set on a user's possession; first image acquisition means for acquiring a first image, which is a facial image of the user stored in the possession, using the password; second image acquisition means for capturing the user's face and acquiring a second image, which is a facial image of the user; and authentication means for comparing the first image and the second image to perform facial authentication of the user.

[0104] (Note 9) The computer program described in Appendix 9 is a computer program that causes at least one computer to execute an information processing method which includes obtaining a password set on a user's possession, using the password to obtain a first image which is a facial image of the user stored in the possession, taking a picture of the user's face to obtain a second image which is a facial image of the user, and comparing the first image and the second image to perform facial authentication of the user.

[0105] (Note 10) The information processing device described in Appendix 10 is an information processing device comprising: an item information acquisition means for acquiring item information from a user's possessions; a biometric information acquisition means for acquiring biometric information from the user; and a password generation means for generating a password to be set for the user's possessions by combining the item information and the biometric information.

[0106] (Note 11) The information processing method described in Appendix 11 is an information processing method that uses at least one computer to obtain possession information from the user's possessions, obtain biometric information from the user, and combine the possession information and the biometric information to generate a password to be set for the user's possessions.

[0107] (Note 12) The recording medium described in Appendix 11 is a recording medium on which a computer program is recorded that causes at least one computer to execute an information processing method that acquires possession information from the user's possessions, acquires biometric information from the user, and combines the possession information and the biometric information to generate a password to be set for the user's possessions.

[0108] (Note 13) The information processing system described in Appendix 13 is an information processing system comprising: an item information acquisition means for acquiring item information from a user's possessions; a biometric information acquisition means for acquiring biometric information from the user; and a password generation means for generating a password to be set for the user's possessions by combining the item information and the biometric information.

[0109] (Note 14) The computer program described in Appendix 14 is a computer program that causes at least one computer to execute an information processing method that obtains possession information from the user's possessions, obtains biometric information from the user, and combines the possession information and the biometric information to generate a password to be set for the user's possessions.

[0110] This disclosure may be modified as appropriate, insofar as it does not contradict the gist or idea of ​​the invention as can be inferred from the claims and the specification as a whole, and information processing devices, information processing methods, and recording media with such modifications are also included in the technical idea of ​​this disclosure. [Explanation of symbols]

[0111] 10, 20 Information Processing Devices 11 processors 18 Cameras 110 Password Acquisition Section 120 First Image Acquisition Unit 130 Second Image Acquisition Unit 140 Authentication Department 150 Disabling section 160 First Password Generation Unit 170 Second Password Generation Unit 180 Third Password Generation Unit 210 Property Information Acquisition Department 220 Biological Information Acquisition Unit 230 Password generation unit

Claims

1. A password acquisition means that is set on the user's possessions and acquires a password for accessing information stored in said possessions, A first image acquisition means that uses the password to acquire a first image which is the user's face image stored in the possession, A second image acquisition means that captures the user's face and acquires a second image which is the user's face image, Authentication means that performs facial recognition of the user by comparing the first image and the second image, If the facial recognition fails, a means for invalidating the password, A third password generation means that generates the password by combining the possession information obtained from the possession and the biometric information obtained from the user, Equipped with, The password acquisition means acquires the password generated by the third password generation means. Information processing device.

2. The system further comprises a first password generation means that generates the password based on the possession information obtained from the possession, The password acquisition means acquires the password generated by the first password generation means. The information processing apparatus according to claim 1.

3. The system further comprises a second password generation means that generates the password based on the biometric information obtained from the user, The password acquisition means acquires the password generated by the second password generation means. The information processing apparatus according to claim 1.

4. By at least one computer, By combining the possession information obtained from the user's possessions with the biometric information obtained from the user, a password is generated to access the information set on the possessions and stored in the possessions. Obtain the aforementioned password, Using the aforementioned password, the first image, which is the user's face image stored in the aforementioned possession, is obtained. The user's face is photographed to obtain a second image which is the user's face image. The first image and the second image are compared to perform facial recognition of the user. If the aforementioned facial recognition fails, the password is invalidated. Information processing methods.

5. On at least one computer, By combining the possession information obtained from the user's possessions with the biometric information obtained from the user, a password is generated to access the information set on the possessions and stored in the possessions. Obtain the aforementioned password, Using the aforementioned password, the first image, which is the user's face image stored in the aforementioned possession, is obtained. The user's face is photographed to obtain a second image which is the user's face image. The first image and the second image are compared to perform facial recognition of the user. If the aforementioned facial recognition fails, the password is invalidated. A computer program that executes information processing methods.

6. A means for obtaining possession information from the user's possessions, A means for acquiring biometric information from the user, A password generation means that combines the possession information and the biometric information to generate a password set on the user's possession and for accessing information stored in the possession, which is invalidated if the user's facial recognition fails, An information processing device equipped with the following features.

7. By at least one computer, Obtain ownership information from the user's possessions, Obtain biometric information from the aforementioned user, The system combines the possession information and the biometric information to generate a password that is set on the user's possession and used to access information stored in the possession, and that is invalidated if the user's facial recognition fails. Information processing methods.

8. On at least one computer, Obtain ownership information from the user's possessions, Obtain biometric information from the aforementioned user, The system combines the possession information and the biometric information to generate a password that is set on the user's possession and used to access information stored in the possession, and that is invalidated if the user's facial recognition fails. A computer program that executes information processing methods.