Program, information processing method, and information processing system

The information processing system addresses the issue of multiple device operation in user authentication by using a single terminal for biometric verification, ensuring robust identity confirmation with reduced user inconvenience.

JP7865365B2Active Publication Date: 2026-05-26NEC CORP
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
NEC CORP
Filing Date
2024-11-07
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing user authentication methods require users to operate multiple devices, imposing a burden and lacking rigorous identity verification.

Method used

An information processing system that acquires and performs biometric authentication using first and second biometric information linked to certification information from a user terminal, enabling both possession and biometric verification without requiring additional devices.

Benefits of technology

This approach allows for rigorous user identity verification while minimizing user burden by utilizing a single device for both possession and biometric authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007865365000001
    Figure 0007865365000001
  • Figure 0007865365000002
    Figure 0007865365000002
  • Figure 0007865365000003
    Figure 0007865365000003
Patent Text Reader

Abstract

To provide an information processing system that strictly performs identity verification of a user when using service while suppressing a burden on the user.SOLUTION: An information processing system includes: an acquisition unit that acquires first biometric information, which is information related to biological information of a user, read by a user terminal including certification information, which is information related to a public certificate of the user, and second biometric information, which is information related to the biological information of the user and is associated with the certification information; an authentication unit that performs, on the basis of the first biometric information and the second biometric information, biometric authentication of the user; a registration unit that registers information related to the user authenticated by the biometric authentication; and a service provision unit that, when the information related to the user is registered, in response to a request from the user terminal, provides service to the user.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to technology for user authentication.

Background Art

[0002] Various services may be provided using a user's terminal. For example, Patent Document 1 discloses a technique for obtaining the location information of a user's terminal and performing settlement of the user's food and beverage bill when the terminal is located more than a predetermined distance from a predetermined area of a restaurant. Further, Patent Document 2 discloses a technique for awarding points generated during product purchase using user identification information read from the user's mobile terminal.

[0003] User authentication may be performed for a user who wishes to use such services. As a technique related to user authentication, Patent Document 3 discloses a technique for authenticating a user by obtaining the user's authentication information from an external server and transmitting the obtained authentication information to an authentication server.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0005] A user who wishes to use the above services may be required to perform user registration in advance. Strict user authentication is required during user registration.

[0006] In the technology disclosed in Patent Document 3, a processing device operated by the user obtains user authentication information from an external server via a terminal operated by the user, and the processing device transmits the authentication information to the authentication server. Thus, in the technology disclosed in Patent Document 3, the user needs to own and operate multiple devices in order to verify their identity. In other words, there is a risk of placing a burden on the user.

[0007] Patent documents 1 and 2 do not disclose any information regarding user identity verification.

[0008] This disclosure was made in consideration of the above-mentioned issues, and one of its purposes is to provide an information processing system, etc., that can strictly verify the identity of users when using the service, while suppressing the burden on users. [Means for solving the problem]

[0009] An information processing system according to one aspect of this disclosure includes: acquisition means for acquiring first biometric information, which is information about the user's biometrics, and second biometric information, which is information about the user's biometrics, linked to the certification information, which are read by a user terminal equipped with certification information, which is information about the user's public certificate; authentication means for performing biometric authentication on the user based on the first biometric information and the second biometric information; registration means for registering information about the user authenticated by the biometric authentication; and service provision means for providing services to the user in response to a request from the user terminal when information about the user has been registered.

[0010] An information processing method according to one aspect of this disclosure acquires first biometric information, which is information about the user's biometrics, and second biometric information, which is information about the user's biometrics, linked to the certification information, read from a user terminal equipped with certification information, which is information about the user's public certificate; performs biometric authentication on the user based on the first biometric information and the second biometric information; registers information about the user authenticated by the biometric authentication; and, when the information about the user is registered, provides services to the user in response to a request from the user terminal.

[0011] A computer-readable storage medium according to one aspect of this disclosure stores a program that causes a computer to execute the following: a process of acquiring first biometric information, which is information about the user's biometrics, and second biometric information, which is information about the user's biometrics, linked to the certification information, which are read by a user terminal equipped with certification information, which is information about the user's public certificate; a process of performing biometric authentication on the user based on the first biometric information and the second biometric information; a process of registering information about the user authenticated by the biometric authentication; and a process of providing services to the user in response to a request from the user terminal when the information about the user has been registered. [Effects of the Invention]

[0012] According to this disclosure, it is possible to strictly verify the identity of users when they use the service while minimizing the burden on users. [Brief explanation of the drawing]

[0013] [Figure 1] This diagram schematically shows an example of the configuration of the information processing system according to the first embodiment. [Figure 2] This is a block diagram showing an example of the functional configuration of an information processing system according to the first embodiment. [Figure 3] This is a flowchart illustrating an example of the operation of the information processing system according to the first embodiment. [Figure 4] It is a diagram schematically showing an example of the configuration of the information processing system according to the second embodiment. [Figure 5] It is a block diagram showing an example of the configuration of the information processing system according to the second embodiment. [Figure 6] It is a diagram showing an example of information about a user according to the second embodiment. [Figure 7] It is a diagram showing an example of the relationship between the authentication level and the services provided according to the second embodiment. [Figure 8] It is a flowchart showing an example of the operation of user registration in the information processing system according to the second embodiment. [Figure 9] It is a flowchart showing an example of the continuation of the operation of user registration in the information processing system according to the second embodiment. [Figure 10] It is a sequence diagram showing an example of the operation when the information processing system according to the second embodiment provides a store reservation service to a user. [Figure 11] It is a sequence diagram showing an example of the operation when the information processing system according to the second embodiment provides an order service to a user. [Figure 12] It is a sequence diagram showing an example of the operation when the information processing system according to the second embodiment provides a payment service to a user. [Figure 13] It is a block diagram showing an example of the configuration of the information processing system according to Modification 1. [Figure 14] It is a block diagram showing an example of the configuration of the information processing system according to Modification 4. [Figure 15] It is a diagram schematically showing an example of the configuration of the information processing system in other application examples. [Figure 16] It is a block diagram showing an example of the hardware configuration of a computer device that realizes the information processing system according to the first and second embodiments of the present disclosure.

Mode for Carrying Out the Invention

[0014] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.

[0015] <First Embodiment> An overview of the information processing system of the first embodiment will be described.

[0016] Figure 1 is a schematic diagram illustrating an example of the configuration of an information processing system 1000. The information processing system 1000 includes, for example, a user terminal 100 and a server 200. The user terminal 100 and the server 200 are connected in a communication manner. Note that the configuration example of the information processing system 1000 is not limited to this example, and may include other devices.

[0017] User terminal 100 is a terminal operated by the user. For example, user terminal 100 may be a smartphone, tablet, or laptop personal computer. Server 200 is, for example, a device that provides services. Server 200 provides services to registered users, for example. User terminal 100 receives user information through user operations, for example. User terminal 100 sends user information to the server, for example. Server 200 then registers the user by registering the user information. In this disclosure, "service" refers to, for example, interactions between a private company or public institution and a user using user terminal 100. For example, services include, but are not limited to, reservations, product orders, and payments at restaurants and retail stores.

[0018] User terminal 100 is equipped with identification information, which is information related to the user's public identification. Public identification refers to a document that can verify the user's identity and contains information such as the user's name and date of birth. For example, public identification may be a My Number Card or a driver's license. The identification information is information related to the public identification. The identification information may also include information such as the name, date of birth, gender, and address listed on the public identification. Furthermore, the identification information may also include the individual number on the My Number Card and the license number on the driver's license.

[0019] The authentication information is linked to biometric information, which is information about the user's biological characteristics. This biometric information is used in biometric authentication, which will be described later. The biometric information may be, for example, information that shows the features of the user's biological characteristics, or an image of the user's biological characteristics, but is not limited to these examples. Examples of biological characteristics include the user's face, iris, fingerprints, palm print, and veins. The biometric information may be included in the authentication information, or it may be associated with the authentication information and stored in the user terminal 100 or other device.

[0020] Figure 2 is a block diagram showing an example of the functional configuration of the information processing system 1000. As shown in Figure 2, the information processing system 1000 includes an acquisition unit 110, an authentication unit 120, a registration unit 130, and a service provision unit 140.

[0021] The acquisition unit 110 acquires biometric information read by the user terminal 100 and biometric information linked to the certification information. In this disclosure, the biometric information read by the user terminal 100 is referred to as first biometric information, and the biometric information linked to the certification information is referred to as second biometric information. For example, suppose the user terminal 100 is equipped with a camera. In this case, for example, the user's face is photographed by the camera of the user terminal 100. The acquisition unit 110 may then acquire, for example, the photographed image showing the user's face as first biometric information. Alternatively, suppose the user terminal 100 is equipped with a fingerprint sensor. In this case, the acquisition unit 110 may then acquire, for example, an image of the fingerprint read by the sensor or information indicating the feature quantities of the fingerprint as first biometric information. The acquisition unit 110 then acquires second biometric information linked to the certification information. Thus, the acquisition unit 110 acquires first biometric information, which is information about the user's biometrics, and second biometric information, which is information about the user's biometrics, linked to the certification information, both of which are read from the user terminal 100 which is equipped with certification information, which is information about the user's public certificate. The acquisition unit 110 is an example of an acquisition means.

[0022] The authentication unit 120 performs biometric authentication. For example, the authentication unit 120 performs facial recognition on the user. In this case, for example, the first biometric information is an image of the user's face, and the second biometric information is an image of the face photograph on the official identification document. The authentication unit 120 extracts facial features from each image and compares the extracted features. Alternatively, for example, the first biometric information may be facial features extracted from an image of the user's face, and the second biometric information may be facial features extracted from an image of the face photograph on the official identification document. In this case, the authentication unit 120 compares the first biometric information and the second biometric information. If the comparison matches, the authentication unit 120 determines that the user operating the user terminal 100 is the person on the official identification document (i.e., the authentication unit 120 authenticates the user). Note that the method of user authentication is not limited to this example. In this way, the authentication unit 120 performs biometric authentication on the user based on the first biometric information and the second biometric information. The authentication unit 120 is an example of an authentication method.

[0023] The registration unit 130 registers information about the user. For example, the registration unit 130 receives input information about the user from a user authenticated by the authentication unit 120. User information refers to personal information entered by the user in order to receive services. For example, user information includes the user's name, age, gender, address, email address, telephone number, and credit card information. The registration unit 130 then registers the entered user information. In this way, the registration unit 130 registers information about the user authenticated by biometric authentication. The registration unit 130 is an example of a registration method.

[0024] The service provision unit 140 provides services. For example, suppose a user places an order for goods at a restaurant using a user terminal 100. In this case, for example, the user terminal 100 makes a request to the server 200 regarding the order. The server 200, for example, receives the order from the user terminal 100 and notifies the terminal in the restaurant. Alternatively, for example, the user makes a payment for goods at the restaurant using the user terminal 100. In this case, for example, the user terminal 100 makes a request to the server 200 regarding the payment. The server 200, for example, receives the payment request from the user terminal 100 and completes the payment. In this way, when information about a user is registered, the service provision unit 140 provides services to the user in response to a request from the user terminal. The service provision unit 140 is an example of a service provision means.

[0025] Next, an example of the operation of the information processing system 1000 will be explained using Figure 3. In this disclosure, each step of the flowchart will be represented by a number assigned to it, such as "S1".

[0026] Figure 3 is a flowchart illustrating an example of the operation of the information processing system 1000. The acquisition unit 110 acquires the first biometric information read by the user terminal equipped with the authentication information, and the second biometric information linked to the authentication information (S1). The authentication unit 120 performs biometric authentication on the user based on the first biometric information and the second biometric information (S2). The registration unit 130 registers information about the user authenticated by biometric authentication (S3). When information about the user is registered, the service provision unit 140 provides services to the user in response to a request from the user terminal (S4).

[0027] As described above, the information processing system 1000 of the first embodiment acquires first biometric information, which is information about the user's biometrics, and second biometric information, which is information about the user's biometrics, linked to the certification information, both of which are read from a user terminal equipped with certification information, which is information about the user's public certificate. The information processing system 1000 also performs biometric authentication on the user based on the first biometric information and the second biometric information, and registers information about the user authenticated by biometric authentication. When information about the user is registered, the information processing system 1000 provides services to the user in response to a request from the user terminal.

[0028] The information processing system 1000 authenticates users who possess a user terminal containing authentication information, which is information related to the user's official identification document, during user registration. Therefore, users must use a user terminal containing authentication information when registering. This allows the information processing system 1000 to perform authentication equivalent to authentication of the user's possession. Furthermore, the information processing system 1000 performs biometric authentication of the user using biometric information read by the user terminal. In other words, the information processing system 1000 authenticates users using both possession authentication and biometric authentication. In addition, the information processing system 1000 performs authentication based on information from the user terminal during user authentication. To put it another way, the information processing system 1000 does not require users to operate multiple devices during user registration. In other words, the information processing system 1000 of the first embodiment can strictly verify the identity of users when using the service while suppressing the burden on the user.

[0029] <Second Embodiment> Next, the information processing system 1000 of the second embodiment will be described. In the second embodiment, the information processing system 1000 described in the first embodiment will be described in more detail. Note that some explanations that overlap with the first embodiment will be omitted.

[0030] Figure 4 is a schematic diagram showing an example of a configuration including the information processing system 1000 in the second embodiment. As shown in Figure 4, the user terminal 100 is connected to the server 200 so as to be able to communicate with it. The server 200 is also connected to the store terminal 300 so as to be able to communicate with it. The user terminal 100 is a device used by a user who wants to use the service. The server 200 is a device used by a service provider (such as a company or public institution) to provide the service. The store terminal 300 is a terminal located in a facility such as a restaurant, retail store, government office, or hospital. The store terminal 300 may be a personal computer, smartphone, or tablet terminal. There may also be multiple store terminals 300, and each of the multiple store terminals 300 may have different functions. The store terminal 300 may also be connected to other devices such as a camera and a two-dimensional barcode reader. In this embodiment, an example in which the information processing system 1000 is applied in a restaurant is described, but the application of the information processing system 1000 is not limited to this example.

[0031] [Details of Information Processing System 1000] Figure 5 is a block diagram showing an example of the configuration of the information processing system 1000 according to the second embodiment. First, the user terminal 100 will be described. As shown in Figure 5, the user terminal 100 includes a reading unit 10, an input unit 11, an output unit 12, and an acquisition unit 110. The user terminal 100 also has a storage device 19.

[0032] The reading unit 10 performs readings on the user's biometric data. For example, the reading unit 10 takes a photograph and generates a captured image. In this case, the reading unit 10 has the function of a camera mounted on the user terminal 100, for example. That is, in this disclosure, photographing the user is also referred to as "reading". Not limited to this example, the reading unit 10 performs readings on the user's biometric data such as iris, fingerprints, palm prints, and veins. In the second embodiment, an example is described in which the information processing system 1000 photographs the user's face with the reading unit 10 and performs facial authentication with the authentication unit 120. Examples of other biometric authentication will be described later.

[0033] The input unit 11 accepts various types of input in response to user operations. For example, the input unit 11 accepts the input of user information as described above.

[0034] The output unit 12 outputs various types of information. For example, it displays information transmitted from the server 200 on the display installed in the user terminal 100.

[0035] The acquisition unit 110 acquires the first biometric information and the second biometric information linked to the certification information. Specifically, the acquisition unit 110 acquires the captured image taken by the reading unit 10 as the first biometric information. Then, the acquisition unit 110 acquires the second biometric information linked to the certification information, which is information about the user's public certificate. Here, the public certificate is a document containing the user's personal information and may be a document issued by a government agency. For example, a public certificate is a My Number Card. However, public certificates are not limited to this and may be a driver's license, national health insurance card, passport, basic resident register card, residence card, etc. The certification information is information that shows the validity of the public certificate and may be an electronic certificate issued by an external certification authority, etc. Among cards containing an IC (Integrated Circuit) chip such as a My Number Card, there are cards that become usable when an electronic certificate is installed on the IC chip. That is, a user terminal 100 with an electronic certificate installed becomes a terminal that has the function of a public certificate. Such a terminal that has the function of a public certificate is sometimes called a public certificate integrated terminal. For example, a user terminal 100 equipped with an electronic certificate for a My Number Card has the functionality of a My Number Card and is sometimes called a My Number Card integrated terminal.

[0036] The authentication information is linked to a second biometric information, which is the user's biometric information. As described above, the second biometric information is used when performing biometric authentication. The second biometric information may be an image showing part of the user, or it may be information that shows the characteristic quantities of part of the user. The second biometric information may be, for example, a facial photograph included in an official document. The second biometric information may be associated with the authentication information, or it may be included in the authentication information. In this embodiment, the authentication information and the second biometric information are associated and stored in the storage device 19. The storage device 19 is an example of a storage means.

[0037] Here, the acquisition unit 110 may acquire second biometric information when authentication is performed using a predetermined password. For example, when a user attempts to access the authentication information of the user terminal 100, the output unit 12 requests the user to enter a password. At this time, the output unit 12 displays a message on the user terminal 100's display indicating that a password is required. The input unit 11 then accepts the password from the user. The password may be, for example, a personal identification number (PIN). The acquisition unit 110 can access the authentication information and acquire second biometric information associated with the authentication information when, for example, the entered password matches the setting information. Here, the setting information is information indicating a pre-set password. The setting information is stored, for example, in the storage device 19. Thus, the acquisition unit 110 may acquire second biometric information when the password entered by the user matches the pre-set setting information.

[0038] Next, the server 200 will be described. The server 200 includes an authentication unit 120, a registration unit 130, and a service provision unit 140. The server 200 also has a storage device 29. The storage device 29 is an example of a storage means.

[0039] The authentication unit 120 performs authentication on the user. Specifically, the authentication unit 120 obtains, for example, first biometric information and second biometric information from the user terminal 100. Then, the authentication unit 120 performs biometric authentication based on the first biometric information and second biometric information. The authentication unit 120 may accept a selection of authentication method from the user in advance. For example, if an authentication method other than biometric authentication using certificate information, such as SMS (Short Message Service) authentication, is selected, the authentication unit 120 performs authentication according to the selected authentication method. The authentication method other than biometric authentication using certificate information may be an existing method.

[0040] The registration unit 130 registers information about the user. Figure 6 shows an example of information about a user. In the example in Figure 6, the information about the user includes the user's identification information, name, gender, date of birth, address, email address, and credit card information. The identification information is unique to each user and identifies the user. Furthermore, in the example in Figure 6, the information about the user includes a captured image of the user and information indicating the authentication level. If a user is authenticated by biometric authentication using authentication information, the registration unit 130 may register the first biometric information used for biometric authentication as information about the user. When facial recognition is performed as biometric authentication, the first biometric information to be registered is, for example, a captured image of the user's face. The biometric information registered at this time is also referred to as registered biometric information. The registration unit 130 may also register information about users who have been authenticated by an authentication method different from biometric authentication using authentication information, and users who have not been authenticated. In this case, the information about the user includes information indicating the authentication method performed on the user. In this disclosure, the information indicating the type of authentication performed on the user is also referred to as the authentication level. For example, the registration unit 130 registers user information, assigning authentication level 2 to users authenticated by biometric authentication using certification information, authentication level 1 to users authenticated by other authentication methods, and authentication level 0 to users who have not undergone authentication. In the example in Figure 6, information for authentication level 2, indicating a user authenticated by biometric authentication using certification information, is registered. User information is stored, for example, in the storage device 29.

[0041] The service provider unit 140 provides services using the user terminal 100. For example, in the case of a restaurant, the service provider unit 140 provides services such as making reservations, ordering products, making payments, and awarding points in response to requests from the user terminal 100. For example, suppose a user makes a reservation request using the user terminal 100. The reservation request may include information such as the user's identification information, the reservation date and time, and the number of people in the reservation. In this case, the service provider unit 140 accepts the reservation in response to the request and generates a reservation code. The service provider unit 140 then transmits the reservation code to the user terminal 100. Here, the reservation code is information that indicates that the user made the reservation. For example, the reservation code may be data converted from information about the reservation, including information about the user who made the reservation, the reservation date and time, and the number of people in the reservation. The user can prove that they are the user who made the reservation by, for example, displaying the reservation code on the user terminal 100 and having the store terminal 300 read it. The reservation code may be, for example, a one-dimensional barcode or a two-dimensional barcode. Sometimes, customers who make reservations at restaurants and other establishments fail to show up without canceling their reservations. This is called "reservation default." Reservation defaults cause losses for restaurants. Information processing system 1000 can deter reservation defaults by accepting reservations from users who have undergone strict identity verification.

[0042] For example, suppose a user uses user terminal 100 to request an order for goods. Service provision unit 140 accepts the order and displays order information, which is information about the ordered goods, to store terminal 300 used by restaurant employees. This allows the user to place an order using user terminal 100. At this time, service provision unit 140 may configure user terminal 100 to allow the user to place an order only after it has scanned a code, such as a two-dimensional barcode, placed on the table where the user is seated or on the menu. In this case, the code may include information that identifies the table. The order request from the user terminal may also include information that identifies the table. This allows service provision unit 140 to associate the order information with the table to which the goods will be delivered.

[0043] Furthermore, for example, suppose a user makes a payment request using user terminal 100. The payment request may include, for example, information on the amount the user will pay. For example, input unit 11 may obtain the amount information by receiving the information entered by the user. In this case, input unit 11 may obtain the amount information by reading a code such as a two-dimensional code that contains the amount information. Service provision unit 140 performs the payment processing using, for example, the user's credit card information. The service provision unit 140 may then notify user terminal 100 of the completion of the payment. The service provision unit 140 may also perform a dummy payment when an order for goods is placed. That is, if the service provision unit 140 receives an order request from user terminal 100, it may perform a dummy payment related to the order, and if the user terminal 100 requests payment, it may complete the payment related to the order. In this case, the payment request does not need to include information on the amount. Furthermore, even if there is no payment request from user terminal 100, the service provision unit 140 may complete the payment related to the order if there is no order request for a predetermined period of time. This allows the information processing system 1000 to prevent users from dine-and-dash.

[0044] Furthermore, the service provider unit 140 may award points to the user in proportion to the amount paid. Points are data that represent economic value. Points may be data that represents monetary value, such as being exchangeable for goods or services. Points may be included, for example, in information about the user.

[0045] In this way, the information processing system 1000 can reduce the opportunities for users to come into contact with restaurant staff when using a restaurant, for example. This allows the information processing system 1000 to contribute to infectious disease control.

[0046] Beyond the examples described above, the service provider 140 provides services in response to requests from the user terminal 100. The services provided may be set according to the authentication level. Figure 7 shows an example of the relationship between the authentication level and the services provided. For example, it is shown that users with authentication level 2 can receive points, make reservations using the user terminal 100, place orders using the user terminal 100, and make payments using the user terminal 100. It is also shown that users with authentication level 1 can receive points and place orders using the user terminal 100. Furthermore, it is shown that users with authentication level 0 can receive points only. In this way, the service provider 140 may gradually increase the services available according to the authentication level. Moreover, it is not limited to this, but the service provider 140 may also provide services that favor users according to their authentication level, such as increasing the points awarded according to the authentication level. In other words, the service provider 140 may set the services that can be provided to users according to their authentication level.

[0047] [Operation 1 of Information Processing System 1000] Next, an example of the operation of the information processing system 1000 will be described. First, using Figures 8 and 9, the scene in which the information processing system 1000 performs user registration will be explained. In this example, it is assumed that the correspondence between the authentication level and the authentication method is the same as that shown in the example in Figure 7.

[0048] Figure 8 is a flowchart illustrating an example of the user registration operation of the information processing system 1000. First, the authentication unit 120 accepts the selection of an authentication method (S101). At this time, for example, the output unit 12 of the user terminal 100 displays the authentication level and the authentication method corresponding to the authentication level on the display of the user terminal 100. Then, the input unit 11 accepts the user's input regarding the selection of the authentication method. If the authentication level of the selected authentication method is 2 (Yes in S102), the acquisition unit 110 acquires the second biometric information associated with the authentication information (S103). At this time, the acquisition unit 110 may acquire the second biometric information if the password entered by the user matches the configured information. The acquisition unit 110 also acquires the first biometric information (S104). At this time, the acquisition unit 110 acquires, for example, a captured image of the user as the first biometric information. The capture is performed by the reading unit 10. If the biometric authentication is facial recognition, the captured image is a facial image of the user. At this time, the output unit 12 may, for example, display on the user terminal 100's display a message indicating that the user should operate the user terminal 100 so that a face can be captured.

[0049] The authentication unit 120 then obtains the first biometric information and the second biometric information from the user terminal 100 and performs biometric authentication based on the first biometric information and the second biometric information (S105). If the user is not authenticated (No in S106), the authentication unit 120 notifies the user terminal 100 that authentication was not successful (S107). If the user is authenticated (Yes in S106), the input unit 11 accepts input information about the user (S108). At this time, the user terminal 100 sends the input information to the server 200. The registration unit 130 registers the information about the user (S109).

[0050] In the process of S102, if the authentication level is not 2 ("No" in S102), the information processing system 1000 proceeds to the operation shown in Figure 9. Figure 9 is a flowchart showing an example of the continuation of the user registration operation of the information processing system 1000. If the authentication level of the selected authentication is 1 ("Yes" in S110), the authentication unit 120 performs authentication different from biometric authentication using certification information. The authentication method at this time is not particularly limited and may be an existing method. If the user is not authenticated ("No" in S111), the authentication unit 120 notifies the user terminal 100 that authentication was not performed (S114). If the user is authenticated ("Yes" in S106), the input unit 11 accepts input of information about the user (S112). Then the registration unit 130 registers the information about the user (S113).

[0051] If the authentication level is 0, that is, if no authentication is performed (No in S110), the input unit 11 accepts input of information about the user (S112). Then the registration unit 130 registers the information about the user (S113).

[0052] [Operation of Information Processing System 1000 2] Next, an example of the operation of the information processing system 1000 when providing a service will be explained using Figures 10 to 12. In this example, the user is assumed to be a user who has undergone authentication level 2. Furthermore, this example is an example of the operation when the information processing system 1000 is applied to a restaurant.

[0053] Figure 10 is a sequence diagram showing an example of the operation when the information processing system 1000 provides a reservation service to a user. The user terminal 100 makes a request for a reservation (S201). At this time, for example, the input unit 11 may accept input of information regarding the reservation through the user's operation and send this information to the server 200 to make the request for the reservation. The service provision unit 140 of the server 200 accepts the reservation (S202). At this time, the service provision unit 140 may store information regarding the reservation, such as information about the user who made the reservation, the reservation date and time, and the number of people who made the reservation, in the storage device 29. Then, the service provision unit 140 generates a reservation code and sends the reservation code to the user terminal 100 (S203). The user terminal 100 receives the reservation code (S204). Then, the output unit 12 of the user terminal displays the reservation code (S205). At this time, the user, for example, when visiting a restaurant, operates the user terminal 100 and presents the reservation code. The store terminal 300 reads the reservation code (S206). This allows the store terminal 300 to confirm that the visiting user is the user who made the reservation.

[0054] Figure 11 is a sequence diagram showing an example of the operation when the information processing system 1000 provides an order service to a user. In this case, the user does not need to have made a reservation to visit the restaurant as shown in the example in Figure 10. The user is, for example, seated at a table in a restaurant. At this time, the user terminal 100 reads a code at the user's operation (S211). For example, the input unit 11 of the user terminal 100 reads a code placed on the table. The service provision unit 140 of the server 200 transmits product information to the user terminal 100 (S212). Here, the product information is, for example, information showing the restaurant's menu. The product information may be stored in advance in the storage device 29. The output unit 12 of the user terminal 100 displays the product information on the display (S213). The user terminal 100 requests an order. At this time, for example, the input unit 11 may accept the input of the product order at the user's operation and send order information including information on the ordered products and table information to the server 200, thereby requesting a reservation to visit the restaurant. When the service provision unit 140 receives order information, it performs a pre-payment according to the order information (S215). Then, the service provision unit 140 transmits the order information to the store terminal 300 (S216). The store terminal 300 displays the order information (S217). At this time, the store terminal 300 may display the order information on a display or the like, or it may print out the order information. This allows restaurant employees to confirm the order that the user placed using the user terminal 100.

[0055] Figure 12 is a sequence diagram showing an example of the operation when the information processing system 1000 provides a payment service to a user. In this situation, it is assumed that a blank payment is being made in response to an order, as shown in the example in Figure 11. The user terminal 100 makes a payment request (S221). At this time, for example, the input unit 11 may make a payment request by receiving information for payment input through the user's operation and sending this information to the server 200. The service provision unit 140 performs the payment processing (S222). For example, the service provision unit 140 confirms payment of the amount using the user's credit card. At this time, the service provision unit 140 may award points to the user according to the amount. Then, the service provision unit 140 notifies the user that the payment is complete (S223). The output unit 12 of the user terminal 100 displays that the payment is complete (S224).

[0056] In this way, the information processing system 1000 of the second embodiment acquires first biometric information, which is information about the user's biometrics, and second biometric information, which is information about the user's biometrics, linked to the certification information, both of which are read from a user terminal equipped with certification information, which is information about the user's official certificate. The information processing system 1000 also performs biometric authentication on the user based on the first biometric information and the second biometric information, and registers information about the user authenticated by biometric authentication. When information about the user is registered, the information processing system 1000 provides services to the user in response to a request from the user terminal.

[0057] This configuration allows the information processing system 1000 to require users to use a user terminal equipped with authentication information during user registration. In other words, the information processing system 1000 can perform both authentication equivalent to user possession authentication and biometric authentication. Furthermore, the information processing system 1000 performs authentication based on information from the user terminal during user authentication. In other words, the information processing system 1000 does not require users to operate multiple devices during user registration. Thus, the information processing system 1000 of the second embodiment can strictly verify the identity of users when using the service while suppressing the burden on the user.

[0058] Furthermore, in the second embodiment, the information processing system 1000 may acquire second biometric information if the password entered by the user matches pre-configured settings. This allows the information processing system 1000 to perform authentication equivalent to knowledge authentication. In other words, the information processing system 1000 authenticates the user using possession authentication, knowledge authentication, and biometric authentication, thereby enabling more rigorous verification of the user's identity.

[0059] Furthermore, in the second embodiment, the user information includes an authentication level indicating the type of authentication performed on the user, and the information processing system 1000 registers user information for users who have not undergone biometric authentication and sets the services that can be provided to the user according to the user's authentication level. In this way, the information processing system 1000 registers users even if they do not perform biometric authentication using a user terminal equipped with authentication information. In other words, the information processing system 1000 does not uniformly require all users to perform all authentications. In addition, since the information processing system 1000 sets the services that can be provided according to the authentication level, it can promote user registration while ensuring appropriate security.

[0060] [Example 1] In the example described above, the server 200 performed biometric authentication, but biometric authentication may also be performed on the user terminal 100. In other words, the authentication unit 120 that performs biometric authentication may also be provided on the user terminal 100.

[0061] Figure 13 is a block diagram showing an example of the configuration of the information processing system 1000 in Modification 1. As shown in Figure 13, the user terminal 100 of Modification 1 includes a reading unit 10, an input unit 11, an output unit 12, an acquisition unit 110, and an authentication unit 120. The server 200 of Modification 1 also includes a registration unit 130 and a service provision unit 140.

[0062] In this case, the first biometric information and the second biometric information are acquired at the user terminal 100. Then, biometric authentication is performed at the user terminal 100 based on the first biometric information and the second biometric information. For example, in the process of S105 in the flowchart of Figure 8, the authentication unit 120 performs biometric authentication at the user terminal 100.

[0063] [Differentiation 2] The above examples mainly described cases where facial recognition is used as biometric authentication, but biometric authentication is not limited to facial recognition. The biometric data used for biometric authentication may include, for example, iris scans, fingerprints, palm prints, and vein patterns.

[0064] For example, when the authentication unit 120 performs iris authentication, the acquisition unit 110 acquires information about the iris. In this case, the reading unit 10 has the function of reading information about the iris. For example, the reading unit 10 may have the function of an infrared camera. That is, the user terminal 100 may be equipped with an infrared camera. The acquisition unit 110 acquires the iris image captured by the infrared camera, or information indicating the characteristic quantities of the iris, as the first biometric information. In this case, the authentication information is pre-associated with the user's iris image or information indicating the characteristic quantities of the iris.

[0065] For example, when the authentication unit 120 performs fingerprint authentication, the acquisition unit 110 acquires information about the fingerprint. In this case, the acquisition unit 110 has the function of reading information about the fingerprint. For example, the reading unit 10 may have the function of a camera that takes a picture of the fingerprint, or it may have the function of a sensor that reads the fingerprint. The acquisition unit 110 acquires the fingerprint image generated by the reading unit 10, or information indicating the feature quantities of the fingerprint, as the first biometric information. In this case, the authentication information is pre-associated with the user's fingerprint image or information indicating the feature quantities of the fingerprint.

[0066] Similarly, when performing palm print authentication or vein authentication, the acquisition unit 110 acquires information about palm prints and veins obtained using cameras and sensors provided in the user terminal 100.

[0067] Thus, the information processing system 1000 of this disclosure may perform authentication using the user's face, iris, fingerprint, palm print, and vein patterns as biometric authentication. Depending on the authentication method, the acquisition unit 110 may acquire biometric information obtained from various cameras and sensors provided in the user terminal 100 as first biometric information.

[0068] [Difference 3] In the example in Figure 11, an example of placing an order from a user terminal 100 was described, but the method of placing an order is not limited to this example. For example, in the example in Figure 11, suppose a store terminal 300 for placing orders is installed on the table. In this case, when the user terminal 100 reads a code containing information that identifies the table (S211), the service provision unit 140 sets the store terminal 300 associated with that table to enable orders from the user. The store terminal 300 associated with that table is, for example, a terminal for placing orders installed on the table where the user is seated. For example, the service provision unit 140 associates the order from the store terminal 300 with the user's identification information. Then, the user makes an order request from the store terminal 300 through an operation. The information processing system 1000 then performs the processing from S215 onwards.

[0069] [Differentiation Example 4] The information processing system 1000 may perform biometric authentication when providing services.

[0070] Figure 14 is a block diagram showing an example of the configuration of the information processing system 1000 in modified example 4. As shown in Figure 14, the server 200 of modified example 3 includes a second authentication unit 150 in addition to the authentication unit 120, registration unit 130, and service provision unit 140.

[0071] The second authentication unit 150 performs biometric authentication on the user when a request is received from the user terminal 100. For example, in the example in Figure 10, suppose the user makes a request to make a store visit reservation using the user terminal 100 (S201). At this time, the second authentication unit 150 requests the user terminal 100 to read biometric information. For example, the second authentication unit 150 requests the user terminal 100 to take a photograph. Here, the information about the user's biometrics generated by the reading requested by the second authentication unit 150 is also called the third biometric information. The reader unit 10 of the user terminal 100 takes a photograph of the user and generates a photographed image. The second authentication unit 150 performs biometric authentication based on the third biometric information, which is the photographed image transmitted from the user terminal 100, and the registered biometric information. If the user is authenticated, the server 200 performs the processing from S202 onwards in Figure 10. If the user is not authenticated, the second authentication unit 150 sends a notification to the user terminal 100 indicating that the user was not authenticated. In this case, the server 200 does not perform the processing from S202 onwards in Figure 10. That is, the second authentication unit 150 performs biometric authentication based on the registered image and the third biometric information, which is information about the user's biometrics that was read when a request was made from the user terminal 100. The second authentication unit 150 is an example of a second authentication means.

[0072] As described above, the information processing system 1000 in the modified example 4 performs biometric authentication based on registered biometric information and third biometric information, which is information about the user's biometrics read when a request is made from the user terminal. When the user is authenticated by this biometric authentication, the information processing system 1000 provides services in response to a request from the user terminal. As a result, the information processing system 1000 can verify the user's identity even when providing services, thereby suppressing fraudulent use such as impersonation of a user.

[0073] Furthermore, for example, in the example in Figure 10, suppose the store terminal 300 reads the reservation code (S206). At this time, the store terminal 300 may take a picture of the user and generate a captured image of the user (i.e., third biometric information). In this case, the second authentication unit 150 obtains the third biometric information from the store terminal 300. Then, the second authentication unit 150 performs biometric authentication based on the third biometric information and the registered biometric information. In this way, the second authentication unit 150 may perform biometric authentication using third biometric information generated at a terminal different from the user terminal 100.

[0074] [Difference 5] The information processing system 1000 may provide services to multiple users. For example, suppose a user is using a restaurant with another user who is different from the user. And the user and the other user want to split the bill.

[0075] In such a case, for example, the input unit 11 of the user terminal 100 accepts input of information about other users through user operation. At this time, the input unit 11 may accept input of information about other users by reading a two-dimensional code indicating information about other users displayed on the other user's user terminal. Here, the information about other users may include the identification information of other users, or it may be information as shown in Figure 6. The input unit 11 of the user terminal 100 may accept input of the amount to be paid by the user and the amount to be paid by other users through user operation. The input unit 11 of the user terminal 100 then makes a payment request that includes information about other users and information indicating the amount to be paid by the user and the amount to be paid by other users. The service provision unit 140 then performs payment processing for the amount to be paid by the user for the user and performs payment processing for the amount to be paid by other users for other users.

[0076] Thus, in the modified example 5, the information processing system 1000 may provide services to both the user and the other user if the request from the user terminal includes information about another user different from the user.

[0077] [Other application examples] The above examples primarily described the application of the information processing system 1000 in a restaurant setting, but the information processing system 1000 can be applied in other situations as well.

[0078] For example, if a user is using a retail store, the service provision unit 140 may provide services such as making a reservation to visit the store, ordering products, making payments, and awarding points in response to a request from the user terminal 100.

[0079] Furthermore, the information processing system 1000 can also be applied to delivery-type restaurants. For example, the service provision unit 140 may provide services such as ordering products, payment, and point accrual in response to requests from the user terminal 100. Figure 15 schematically shows an example of the configuration of the information processing system 1000 in other application examples. Specifically, Figure 15 schematically shows an example of the configuration of the information processing system 1000 when applied to a delivery-type restaurant. As shown in Figure 15, the user terminal 100 is connected to the server 200 so as to be able to communicate. The server 200 is also connected to the store terminal 300 and the delivery person terminal 400 so as to be able to communicate. The delivery person terminal 400 is a terminal used by a delivery person who delivers products. The delivery person terminal 400 may be a portable terminal such as a smartphone or a tablet.

[0080] When the user terminal 100 requests an order through user operation, the service provision unit 140 performs a preliminary payment (S215) and transmits the order information to the store terminal 300 (S216), similar to the example in Figure 11. In this way, the user can place an order for goods using the user terminal 100.

[0081] Furthermore, when a delivery person delivers a product to a user, the user's terminal 100 requests payment. Then, similar to the example in Figure 12, the service provision unit 140 performs the payment processing (S222) and notifies the user terminal 100 of the completion of payment (S223). The service provision unit 140 may also perform the payment processing when both the payment request from the user terminal 100 and the delivery completion notification from the delivery person terminal 400 are sent to the server 200. In this case, the delivery person's terminal 400 notifies the server 200 of the completion of delivery. This ensures that the information processing system 1000 can complete payment only when the delivery has been successfully completed.

[0082] Similarly, the information processing system 1000 can also be applied to courier services. For example, suppose a cash-on-delivery item is delivered to a user by courier. In this case, for example, the delivery person's terminal 400 displays a two-dimensional barcode containing payment information, etc. When the input unit 11 of the user terminal 100 reads the two-dimensional barcode, the output unit 12 of the user terminal 100 displays the payment information, etc. Subsequently, when the user terminal 100 requests payment, the service provision unit 140 performs the payment processing. After that, the service provision unit 140 may, for example, notify the user terminal 100 and the delivery person terminal 400 that the payment has been completed.

[0083] <Example of hardware configuration for an information processing system> The hardware constituting the information processing system of the first and second embodiments described above will now be explained. Figure 16 is a block diagram showing an example of the hardware configuration of a computer device that realizes the information processing system in each embodiment. The computer device 30 realizes the information processing system and information processing method described in each embodiment and each modified example. For example, each of the user terminals and servers described in each embodiment and each modified example may have the hardware configuration shown in Figure 16.

[0084] As shown in Figure 16, the computer device 30 includes a processor 31, RAM (Random Access Memory) 32, ROM (Read Only Memory) 33, storage device 34, input / output interface 35, bus 36, and drive device 37. Note that the information processing system may be implemented using multiple electrical circuits.

[0085] The storage device 34 stores a program (computer program) 38. The processor 31 executes the program 38 of this information processing system using the RAM 32. Specifically, for example, the program 38 includes a program that causes the computer to execute the processes shown in Figures 3, 8, 9, 10, 11, and 12. The functions of each component of this information processing system are realized in response to the processor 31 executing the program 38. The program 38 may also be stored in the ROM 33. Alternatively, the program 38 may be recorded on the storage medium 40 and read using the drive device 37, or it may be transmitted to the computer device 30 from an external device (not shown) via a network (not shown).

[0086] The input / output interface 35 exchanges data with peripheral devices (keyboard, mouse, display device, etc.) 39. The input / output interface 35 functions as a means of acquiring or outputting data. The bus 36 connects each component.

[0087] Furthermore, there are various variations in how information processing systems are implemented. For example, an information processing system can be implemented as a dedicated device. Alternatively, an information processing system can be implemented based on a combination of multiple devices.

[0088] The processing method for recording a program to realize each component of the function in each embodiment onto a storage medium, reading the program recorded on the storage medium as code, and executing it on a computer is also included within the scope of each embodiment. In other words, a computer-readable storage medium is also included within the scope of each embodiment. Furthermore, the storage medium on which the above-mentioned program is recorded, and the program itself, are also included within each embodiment.

[0089] The storage medium is, but is not limited to, a floppy disk, hard disk, optical disk, magneto-optical disk, CD (Compact Disc)-ROM, magnetic tape, non-volatile memory card, or ROM. Furthermore, the programs recorded on the storage medium are not limited to programs that perform processing on their own, but also include programs that operate on the OS (Operating System) in cooperation with other software and the functions of expansion boards to perform processing, and these are also included in the scope of each embodiment.

[0090] Although the present invention has been described above with reference to embodiments, the present invention is not limited to the above embodiments. Various modifications to the structure and details of the present invention can be made within the scope of the present invention as can be understood by those skilled in the art. Furthermore, the above embodiments and modifications can be appropriately combined in various applications.

[0091] This application claims priority based on Japanese Patent Application No. 2021-125258, filed on 30 July 2021, and incorporates all of its disclosures herein. [Explanation of Symbols]

[0092] 10 Reading section 11 Input section 12 Output section 100 user terminals 110 Acquisition Department 120 Authentication Department 130 Registration Department 140 Service Provision Department 150 Second Certification Department 200 servers

Claims

1. One or more computers, A means for performing a comparison between facial information captured in a first image taken using a user terminal equipped with identification information, which is information related to the user's official identification document, and facial information linked to the said identification information. A means for registering information about the user in accordance with the results of the aforementioned verification, It operates as a means of performing authentication based on facial information captured in a second image taken using the terminal and registered information about the user. The information relating to the user includes the information used in the matching process. program.

2. The program according to claim 1, wherein the user terminal and the terminal are the same terminal.

3. The program according to claim 1, wherein the user terminal is a terminal different from the aforementioned terminal.

4. The program according to claim 1, wherein the information used for the matching is information based on the face information captured in the first image.

5. The program according to claim 1, wherein the means for registration registers information about the user in a storage device different from the storage device of the user terminal.

6. The program according to claim 1, wherein the aforementioned public certificate includes a document capable of verifying identity.

7. The program according to claim 6, wherein the aforementioned public certificate includes at least one of a My Number Card or a driver's license.

8. One or more computers, The system performs a comparison between the facial information captured in a first image taken using a user terminal equipped with identification information, which is information related to the user's official identification document, and the facial information linked to the said identification information. Based on the results of the aforementioned verification, information about the user is registered. Authentication is performed based on the facial information captured in the second image taken using the terminal and the registered information about the user. The information relating to the user includes the information used in the matching process. Information processing methods.

9. A first authentication means that performs a comparison based on facial information in a first image taken using a user terminal equipped with certification information which is information relating to the user's official identification document, and facial information linked to the certification information, A registration means for registering information about the user in accordance with the results of the aforementioned verification, The system includes a second authentication means that performs authentication based on facial information captured in a second image taken using a terminal and registered information about the user, The information relating to the user includes the information used in the matching process. Information processing system.